Compliance

The Red Flag Rule: Does It Apply to Your Business?

The red flag rule reaches fewer businesses than its name suggests, and catches some that have never heard of it. Here is the two-question test that decides coverage, and what a written identity theft prevention program actually has to contain.

A new account application with the consumer report line flagged, showing a fraud alert
A new account application with the consumer report line flagged, showing a fraud alert

The Red Flag Rule: Does It Apply to Your Business?

Two kinds of business search for this: the ones sure it applies to them, and the ones who have never heard of it. Both assumptions get made before anyone reads the definitions, and the definitions are narrower and stranger than the name suggests. Two questions settle it.

A note on the name before anything else. The Federal Trade Commission calls it the Red Flags Rule, plural, and it sits at 16 CFR Part 681 under the Fair Credit Reporting Act. Searching for the red flag rule gets you to the same place. This is a plain-English explainer of what the regulation requires. It is general information, not legal advice, and whether it covers your particular business is a question for a lawyer who knows your operations.

Does the red flag rule apply to your business?

Seven steps. The first one decides whether the other six apply to you at all, so do not skip it.

  • Work out whether the rule applies to you at all

  • Identify the red flags that fit your business

  • Build detection into how you open and service accounts

  • Decide what happens when a flag appears

  • Keep the program current

  • Get it approved, trained and reported

  • Cover your service providers by contract

1. Work out whether the rule applies to you at all

The rule reaches financial institutions and creditors that hold covered accounts. Both of those words are defined much more narrowly than they sound, and the narrowing is the whole story.

A creditor, since the Red Flag Program Clarification Act of 2010, is one that regularly obtains or uses consumer reports in connection with a credit transaction, furnishes information to consumer reporting agencies in connection with a credit transaction, or advances funds that the person is obligated to repay, or that are repayable from specific property pledged on their behalf. Crucially, the statute excludes a creditor that advances funds for expenses incidental to a service it provides. That sentence is why most doctors, lawyers and accountants who simply bill after the work is done are outside the rule, even though many still believe otherwise.

Decision chart showing the two questions that determine whether the FTC Red Flags Rule applies: whether you are a creditor or financial institution, and whether you hold covered accounts


A covered account is either a consumer account designed to allow multiple payments or transactions, such as a credit card or mortgage, or any other account carrying a reasonably foreseeable risk of identity theft, including risk to the safety and soundness of the business itself. The regulation expects you to reach that conclusion through a periodic risk assessment rather than assumption.

What to do: answer both questions in writing and keep the answer. A short documented assessment concluding that you hold no covered accounts is itself the compliance step, and it is far easier to produce later than to reconstruct.

2. Identify the red flags that fit your business

If you are covered, the first required element is identifying relevant red flags: the patterns, practices and specific activities that signal possible identity theft in the accounts you actually hold.

The regulation supplies 26 examples in five categories. They are illustrations, not a checklist to adopt wholesale, and copying all 26 into a program that does not fit your business is the most common way this element is done badly.

Reference chart of the 26 example red flags in 16 CFR Part 681 grouped into five categories, with counts of four, five, nine, seven and one

What to do: start from how accounts are opened, accessed and changed in your business, then pick the examples that map onto those moments. A program with eight well-chosen flags beats one with 26 borrowed ones.

3. Build detection into how you open and service accounts

The second element is detection. Identifying a red flag on paper achieves nothing if nobody encounters it in the ordinary course of work.

In practice this usually means verifying identity when accounts are opened, authenticating people who contact you about existing accounts, and checking address change requests before acting on them.

What to do: write the detection step into the procedure the staff member actually follows, not into a separate policy document nobody opens.

4. Decide what happens when a flag appears

The third element is response. The rule requires appropriate responses, scaled to the degree of risk, rather than one fixed reaction.

Options range from monitoring the account, contacting the customer, changing credentials, reopening an account under a new number, declining to open the account at all, notifying law enforcement, or concluding that no response is warranted. That last one is explicitly available, which surprises people.

What to do: write down who decides, because in most small businesses the person who spots the flag is not the person authorized to act on it.

5. Keep the program current

The fourth element is staying up to date as identity theft methods change. The scale of the problem is not shrinking. The FTC logged 1,135,291 identity theft reports in 2024, and total reported fraud losses reached $12.5 billion that year, the highest on record.

What to do: set a review date, and treat a new product, a new payment channel or a new vendor as a trigger to look again rather than waiting for the calendar.

6. Get it approved, trained and reported

Three administrative requirements sit around the four elements, and they are the ones most often skipped. Two are in the binding rule and one is not, which is worth knowing.

The rule itself requires that the initial program be approved by the board of directors or an appropriate committee, or by senior management if there is no board; that the board or senior management stay involved in oversight; and that staff be trained as necessary. Reporting to leadership at least annually on how the program is working comes from the Guidelines in Appendix A, which say should rather than must. It is the expected practice and worth doing, but a different cadence is not itself a violation of the rule.

What to do: minute the approval. An unapproved program is a defect that shows up immediately in any examination.

7. Cover your service providers by contract

If you outsource any activity involving covered accounts, you remain responsible for it. The binding requirement is that you exercise appropriate and effective oversight of the arrangement. The Guidelines then give the practical route: requiring the service provider by contract to have policies and procedures to detect red flags and either report them to you or take appropriate steps to prevent and mitigate identity theft. The oversight duty is mandatory; that specific clause is the illustrative way to discharge it, not the only one.

This is where a compliance obligation turns into a contract review job. The provision is easy to check for and easy to overlook, and it is frequently absent from agreements signed before anyone thought about the rule.

What to do: pull the contracts for every vendor that touches account opening, payment processing, billing, collections or customer service, and find the clause. If it is not there, that is a renewal conversation. You can run each agreement through RateMyContract to get the obligations, notice provisions and termination terms pulled out in plain English in about thirty seconds, which makes a stack of vendor contracts a manageable afternoon rather than a project. It reads contracts; it does not assess your compliance, and it is not a substitute for counsel.

What a written program has to contain

  • A documented assessment of whether you hold covered accounts

  • The specific red flags relevant to your accounts, drawn from the five categories

  • Procedures that detect those flags in day-to-day work

  • Appropriate responses, scaled to the risk

  • A method for keeping the program current

  • Board or senior management approval, on the record

  • Staff training as necessary

  • Service provider oversight, written into the contract

  • A report to leadership at least annually, which the Guidelines recommend rather than require

Nine items. A small business with one product line can document all of them in a handful of pages.

What happens if you do not comply

Enforcement is by federal agencies, not by customers. There is no private right of action for a failure to comply, and the FCRA states that enforcement is exclusive to the designated agencies. The FTC handles businesses not supervised elsewhere, the banking regulators handle the institutions they supervise, and the SEC and CFTC cover their own registrants under parallel rules.

The maximum civil penalty available to the FTC under this part of the FCRA is currently $4,983 per violation, a figure adjusted for inflation each year and last set for penalties assessed after January 17, 2025.

When to talk to a lawyer

Coverage is the question worth paying for. The definitions turn on how your business actually operates, the covered account test involves judgment about foreseeable risk, and getting it wrong in either direction is expensive: an unnecessary program wastes money, and a missing one is a finding. If you are close to the line, or you are in a sector where regulators have taken an interest, a short conversation with a lawyer who works in consumer financial regulation is money well spent.

The short version

Answer two questions. Are you a creditor or financial institution as the statute defines them, and do you hold covered accounts? If either answer is no, document that conclusion and move on. If both are yes, you need a written Identity Theft Prevention Program with four elements, board or senior management approval, annual reporting, and service provider obligations in your contracts.

That last item is the one that lives outside your own operations, which is exactly why it gets missed. If you want a fast read of what your vendor agreements actually say, paste them into RateMyContract and work from the plain-English summary. Our guides to reviewing a lease before you sign and NDA red flags take the same approach to other agreements.

Frequently asked questions about the red flag rule

Who has to comply with the red flag rule?

Financial institutions and creditors that hold covered accounts. Creditor is defined narrowly: you must regularly use consumer reports in a credit transaction, furnish information to consumer reporting agencies in a credit transaction, or advance funds that are repayable. Billing clients after providing a service does not make you a creditor.

Are doctors and lawyers covered by the red flag rule?

Generally not since 2010. The Red Flag Program Clarification Act excluded creditors that advance funds for expenses incidental to a service they provide, which took most medical, legal and accounting practices out of scope. A practice that offers genuine financing arrangements may still be caught.

What is a covered account?

Two types. A consumer account designed to permit multiple payments or transactions, such as a credit card, mortgage or checking account. Or any other account, consumer or business, that carries a reasonably foreseeable risk of identity theft. You determine this through a periodic risk assessment.

How many red flags does the regulation list?

Twenty-six examples, in five categories: alerts from consumer reporting agencies, suspicious documents, suspicious personal identifying information, unusual account activity, and notice from customers or law enforcement. They are illustrations. Your program should identify the ones relevant to your own accounts rather than adopting all of them.

Is the Red Flags Rule still in effect?

Yes. It was issued under the FACT Act in 2007, had its enforcement date pushed back several times before it was finally enforced, and was amended in 2012 to implement the 2010 Clarification Act. It remains in force at 16 CFR Part 681. The narrowed definition of creditor is the most significant change since it was written.

What does the rule require in vendor contracts?

The rule requires appropriate and effective oversight of service provider arrangements. The Guidelines suggest doing that by requiring the provider by contract to have procedures to detect red flags and either report them to you or act to prevent and mitigate identity theft. Outsourcing the activity does not outsource the responsibility.

Keep reading