Identity Theft Red Flags Rule: Lender Guide
Reglith Editorial Team · October 2026
The Identity Theft Red Flags Rule requires creditors with covered accounts to maintain a written Identity Theft Prevention Program. It stems from the Fair and Accurate Credit Transactions Act (FACTA), which directed the federal banking agencies and the Federal Trade Commission (FTC) to issue regulations and guidelines on identity theft. A related FTC fraud alert on insurance identification cards is covered in Cyber Fraud Alert Follow-Up: New York Insurance Identification (ID) Card Barcode Vulnerability.
Reglith tracks federal, agency and state regulatory changes in one feed, summarized and tagged for mortgage compliance teams. Reglith regulatory updates
What is the Identity Theft Red Flags Rule?
The Identity Theft Red Flags Rule is a set of requirements under the Fair and Accurate Credit Transactions Act (FACTA) that directs creditors and financial institutions to develop and implement a written Identity Theft Prevention Program. FACTA did not itself contain a single "red flags rule" section; instead it directed the federal banking agencies and the FTC to issue joint regulations and guidelines identifying red flags and prescribing the program elements. The result is a set of interagency guidelines and a parallel FTC rule. The interagency guidelines appear as an appendix to certain banking agency regulations (for example, the Federal Reserve Board's Regulation V and the OCC's and FDIC's parallel consumer protection rules), while the FTC's rule appears in its own part of the Code of Federal Regulations. The FTC rule and the banking agency guidelines are separate texts, and which one applies depends on the entity's charter and primary federal regulator.
The mandate is not simply to watch for fraud. The rule requires a program that identifies relevant red flags, detects them, prevents and mitigates identity theft, and updates the program over time. The program must be appropriate to the size and complexity of the creditor and the nature of its operations.
The rule generally applies to creditors that offer or maintain covered accounts. For mortgage lending, that includes lenders and servicers whose accounts involve multiple payments or transactions. Applicability can turn on the entity's charter, its primary federal regulator, the account types it holds and whether it is a financial institution or a non-bank creditor, so teams should confirm against the rule text and their primary regulator.
Who must comply with the Red Flags Rule?
The rule uses the concept of a "creditor"—an entity that regularly extends, renews or continues credit, or that regularly arranges for credit to be extended. Banks, credit unions and mortgage companies that originate or hold mortgage credit commonly fall within that definition, and the rule applies regardless of whether the creditor is a financial institution or a non-bank entity.
Some entities are generally outside the scope. Employers that advance payroll, utilities that bill in arrears and similar businesses that do not regularly extend credit are often not creditors for this purpose, though the analysis depends on the facts. A mortgage company that services loans it did not originate may still be covered if it maintains covered accounts, so servicing arrangements deserve a close look.
Licensing status does not determine applicability. A lender licensed through the National Mortgage Licensing System (NMLS) and a federally chartered bank may both be covered, but their primary regulators differ. Teams that track licensing can use Mortgage Licensing and NMLS: The Complete Compliance Guide as a reference for how NMLS records and state licensing interact with federal requirements.
| Entity type | Likely covered? | Notes |
|---|---|---|
| Mortgage lender holding loans | Yes, if covered accounts | Program required; regulator depends on charter |
| Mortgage servicer | Often yes | Depends on whether it maintains covered accounts |
| Bank or credit union | Yes, if covered accounts | Primary federal regulator supervises |
| Employer advancing payroll | Generally no | Not a creditor for this purpose |
| Utility billing in arrears | Generally no | Not a creditor for this purpose |
What are covered accounts under the rule?
A covered account is generally a consumer account designed to permit multiple payments or transactions, or any other account for which there is a reasonably foreseeable risk of identity theft. Mortgage loans fit the first category because they involve recurring payments over time. Home equity lines of credit, construction-to-permanent loans and similar products with ongoing transactions tend to fall in the same category.
Single-transaction accounts are typically not covered unless they involve multiple payments or present a reasonably foreseeable risk of identity theft. A one-time, single-payment obligation may fall outside the definition, but the same loan with recurring payments may fall inside it. The distinction is not about the product name; it is about how the account operates.
For mortgage compliance teams, the practical step is to inventory account types, map each to the covered-account definition and document the conclusion. That inventory should be revisited when new products launch, when servicing rights transfer or when systems change how payments are posted. More on federal requirements and how they fit together appears in The Complete Guide to Federal Mortgage Compliance Regulations.
What are the five categories of red flags?
The rule groups red flags into five categories: identity, account, billing, payment and enforcement. Each category points to warning signs that a mortgage lender or servicer can watch for.
- Identity red flags: inconsistent personal information, such as a mismatch between the applicant's stated identity and documents in the file, or a suspicious address history.
- Account red flags: unusual activity on an existing account, such as a change of address followed quickly by a request for a payoff statement or a new draw.
- Billing red flags: statements returned as undeliverable, or mail sent to an address the borrower did not provide.
- Payment red flags: payments from unfamiliar sources, partial payments paired with address changes, or a sudden shift in payment method.
- Enforcement red flags: notices from law enforcement or regulators, or a consumer report indicating a fraud alert or identity theft report.
The rule expects institutions to tailor the list to their business model and risk profile. A servicer with heavy call-center volume may weight account and billing red flags differently than a lender that mostly originates and sells. Whatever the mix, the program should describe the specific red flags and the sources used to identify them.
How do institutions implement a compliant program?
A compliant program has four required elements: identification, detection, prevention and response. Identification means listing the red flags relevant to the business. Detection means building the processes—system edits, exception reports, call-center scripts—that surface those red flags. Prevention and mitigation means the steps taken when a red flag appears, from contacting the customer to freezing the account. Response means the follow-up, including notifying law enforcement or the customer where appropriate.
The program must be approved by the board of directors or a designated senior manager, and it must be reviewed periodically. The review should consider changes in identity theft risks, changes in the business—new products, new channels, new servicing arrangements—and the institution's own experience with identity theft. Training and oversight of service providers are common program components, since third parties often handle account data.
Updates should be documented. When a new threat emerges or a business practice changes, the program should reflect the change and the approval trail should be maintained. A compliance management system that includes monitoring, testing and issue tracking gives the program a place to live, and regulatory change management feeds it when federal or state requirements shift. State rules by topic and Sources Reglith tracks can help teams keep an eye on state-level identity theft requirements that layer onto the federal rule. For disclosure-related controls that support the program, see TRID Compliance: The Complete Guide to TILA-RESPA Integrated Disclosures.
What are the penalties for non-compliance?
The rule is enforced by the FTC for entities within its jurisdiction, and by the federal banking agencies— the Office of the Comptroller of the Currency (OCC), the Federal Reserve Board, the Federal Deposit Insurance Corporation (FDIC) and the National Credit Union Administration (NCUA)—for the institutions they supervise. Enforcement typically proceeds through the agency's existing authority, which can include civil money penalties, cease-and-desist orders and supervisory actions depending on the agency and the facts. The rule text and the agency's enforcement authority, rather than a fixed schedule, govern what a particular violation may carry.
Failure to maintain a reasonable, written program can draw supervisory criticism even without a customer loss, and repeated or systemic weaknesses can escalate. State regulators may also act under state identity theft and consumer protection laws, which can layer additional requirements onto the federal rule; those state requirements vary and should be checked against the specific state's law.
Frequently asked questions
What are covered accounts in the identity theft red flag rule?
A covered account is generally a consumer account designed to permit multiple payments or transactions, or any other account with a reasonably foreseeable risk of identity theft. Mortgage loans, home equity lines and similar products usually qualify. A single-transaction account without recurring payments generally does not, unless the risk of identity theft makes it covered.
What is true regarding the identity theft red flag rule?
It requires a written Identity Theft Prevention Program, not just a fraud policy. The program must include identification, detection, prevention and response, be approved by the board or a designated senior manager, and be reviewed periodically. It applies to creditors with covered accounts, including many mortgage lenders and servicers, under FACTA's implementing regulations.
What are common red flags of identity theft?
Common red flags include inconsistent personal information, a new address followed by a payoff or draw request, returned mail, unusual payment sources or patterns, fraud alerts on consumer reports, and law enforcement notices. The rule groups these into identity, account, billing, payment and enforcement categories, and expects each institution to tailor the list to its own risk profile.
Does the Red Flags Rule apply to mortgage servicers?
Mortgage servicers are often covered because they maintain accounts with multiple payments or transactions. Whether a specific servicer is covered can turn on the accounts it services, its charter and its primary federal regulator. Servicers should confirm against the rule text and their regulator, and treat servicing transfers as a trigger to revisit the program.
How often must a Red Flags Program be reviewed?
The rule requires periodic review, which many institutions align with their annual compliance calendar. The right cadence depends on the size and complexity of the business and on changes in risk. Reviews should also be triggered by new products, new channels, servicing transfers or notable identity theft events.