The organization periodically identifies covered accounts using a documented risk assessment that considers account-opening methods, access methods, and identity-theft experience.
CRITICALeCFRDraft · internal validation
FTC Identity Theft Red Flags Rule
16 CFR Part 681 · Federal Trade Commission
Checks a covered-account determination and written identity theft prevention program against 16 CFR Part 681.
Requirements13atomic checksCRITICAL3severityHIGH10severityWith official link13/13eCFR section URLRule effectiveJan 1, 2008current textPack version0.1.0-draft.1authored Sep 26, 2026
Requirements
Showing 8 of 13 · official summariesA written, implemented, risk-scaled program detects, prevents, and mitigates identity theft for new and existing covered accounts.
CRITICALeCFRThe program identifies account-specific Red Flags and incorporates them into operating procedures.
HIGHeCFRThe program defines how incorporated Red Flags are detected.
HIGHeCFRThe program defines risk-appropriate responses to detected Red Flags.
HIGHeCFRThe program has a periodic and event-driven update process.
HIGHeCFRThe initial written program has approval from the required governing body.
HIGHeCFRRequired senior governance participates throughout the program lifecycle.
HIGHeCFR