HOLLYWOOD, Fla. - Credit unions are being reminded that they have until Nov. 1 to comply with the identity theft “red flag” rules enacted by regulators.
Among the requirements is that a CU must develop prevention measures based on its own ID theft situation (CU Journal, March 17).
During CUNA Mutual’s Discovery Conference here, Ken Otsuka, risk manager for CUNA Mutual Group, and Jenny Champagne, VP-regulatory development and education NASCUS, reviewed the “red flag” requirements, which are part of sections 114 and 315 of the Fair and Accurate Credit Transactions Act of 2003 (FACT Act).
To meet Section 114, credit unions are required to develop a written Identity Theft Prevention Program to detect, prevent, and mitigate identity theft in connection with the opening of a covered account or any existing covered account, Champagne said. “Covered accounts include business and consumer accounts such as credit cards, mortgage loans, automobile loans, margin accounts, cell phone accounts, utility accounts, checking accounts, and savings accounts,” she said.
Supplement A to Appendix J of the FACT Act contains five categories of red flags with a number of examples within each category. These include: Alerts, notifications, or warnings from a consumer reporting agency; Suspicious documents; Suspicious personal identifying information; Unusual use of, or suspicious activity related to the covered account; and Notice from customers, victims of ID theft, law enforcement authorities, or other persons regarding possible ID theft in connection with covered accounts
Credit unions should be capable of responding appropriately to any red flags that are detected to prevent and mitigate identity theft and should update the procedures periodically to reflect changes in risks from identity theft,” Otsuka said.
The final red flag rules can be obtained at http://www.ftc.gov/opa/2007/10/redflag.shtm.(c) 2008 The Credit Union Journal and SourceMedia, Inc. All Rights Reserved.http://www.cujournal.com http://www.sourcemedia.com











