Financial institutions ill-prepared for new law

NEEDHAM, Mass. – A Boston research firm is forecasting that less than one-third of U.S. financial institutions will be fully compliant with a new federal requirement regarding identity theft and fraud prevention by the Nov. 1 deadline.
TowerGroup said many banks mistakenly consider compliance with the rule, entitled “Identity Theft Red Flags and Address Discrepancies Under the Fair and Accurate Transactions Act of 2003,” merely an administrative exercise.
Under the “Red Flags” rules, financial institutions and creditors must develop a program that detects the warning signs of identity theft. According to the Federal Trade Commission, the program must also describe appropriate responses that would prevent and mitigate the crime and detail a plan to update the program. The program must be managed by the institution’s board of directors or senior employees or creditor, include appropriate staff training, and provide for oversight of any service providers.
Despite criticisms that some of the requirements of the “Red Flags” rules are ambiguous, the regulations will require financial services institutions to address the increasing threat of cross-channel fraud and ultimately necessitate that they implement appropriate technological and procedural frameworks, TowerGroup said.
TowerGroup estimated that ultimately the U.S. financial services industry will spend more than $200 million in both internally developed and vendor-supplied technology to comply with the “Red Flags” rules.

No posts to display