Why Its Worth Dedicating Resources To Red Flag

LATHRUP VILLAGE, Mich.-Red Flag technology is locked and loaded at Michigan First Credit Union here, in readiness for the Nov. 1 compliance deadline set by the "Red Flag" fraud and identity theft laws.

Processing Content

To the many credit unions that seem sure they'll miss the deadline, the $470-million credit union's announcement may come as a bit of a surprise. But readiness is simply a matter of course for Michigan First, considering that the credit union has spent more than five years arming itself with tools against fraud and identify theft, according to Cris Mattoon, risk management manager.

However, Michigan First probably is not alone, Mattoon continued. "Red Flag simply forces us to focus our attention on protecting member identity under one regulatory umbrella." The rules, under the Fair and Accurate Credit Transactions Act (FACT Act), define a Red Flag as any pattern, practice or activity that indicates possible identity theft.

"Red Flag is not a sea change, what with everything else we've been addressing since the FACT Act was passed almost five years ago," he said.

Information security officers who have put their ducks in a row over the years should be able to apply existing technologies to demonstrate that they are ready for the new regulations, Mattoon added.

"If credit unions were already in compliance with security information best practices, anti-money laundering regulations and the Bank Secrecy Act, then they are ready for Red Flag," said Mattoon. "It's a matter of assembling those policies under an overall identity theft program and performing a gap analysis to identify existing technologies, processes and procedures."

Beginning with the monitoring reports produced by its core system in the early part of the millennium, Michigan First has been slowly building its anti-fraud technologies across the organization, Mattoon said. "Belt-and-suspenders is the way to go from a risk management perspective."

Internally, the technologies include custom Red Flag reporting from the core; an early-warning system across the organization; and network security systems, he said. There's also intermittent and annual online employee training, which as of this month includes Red Flag training, and a comprehensive information security policy.

To monitor external risks, Mattoon said the credit union relies on tools such as multi-factor authentication and account-opening safeguards to protect members online; automatic alerts for members, and PINs for certain call center transactions. "None of these technologies is new," he added.

Plastics came up as one danger area during Michigan First's gap analysis, Mattoon said.

"The issue that concerned me the most was the reordering of plastic cards," he explained. "A certain number of members will change their address, and at the same time, will have to reorder plastic. We were already trying to safeguard plastic and make intelligent inquiries when we saw a red flag, but now we are documenting that we verify address changes within 30 days of a plastic reorder."

Michigan First also asked for help from its core processor in designing files that would monitor address changes after plastic card reorders, said Mattoon.

Red Flag technology is imperative, he suggested. "We'll never have enough human resources to look at every transaction in real-time. Technology helps us keep our transactions safe and processed at a speed expected by the member."


For reprint and licensing requests for this article, click here.
Technology
MORE FROM AMERICAN BANKER
Load More