Automotive

The Red Flags Rule: Identity Theft Checks Your F&I Desk Can't Skip

The FTC's Red Flags Rule requires dealers who extend or arrange credit to run a written identity theft program, and prove it happened, not just that it exists.

Lead Forward Deployed Engineer

· 7 min read

The FTC’s Red Flags Rule requires any dealer who regularly extends, arranges, or advances credit to run a written identity theft prevention program that identifies, detects, and responds to warning signs of fraud on covered accounts. Most stores that pull a Red Flags report on every deal already meet the letter of that requirement. What sinks them in an audit is proving someone actually looked at it.

4required program elements: identify, detect, respond, update
5categories of red flags under FTC guidance
2-parttest for whether your store counts as a "creditor"

What Is the Red Flags Rule, Exactly?

The Red Flags Rule (16 CFR Part 681) is an FTC regulation that requires “financial institutions” and certain “creditors” to maintain a written identity theft prevention program. It grew out of the Fair and Accurate Credit Transactions Act and is enforced by the FTC for most non-bank businesses, dealerships included. The FTC’s own guide for businesses lays out four required elements: policies to identify red flags in your day-to-day operations, procedures to detect them, a defined response when you find one, and a process to keep the program current as fraud patterns change.

That last part matters more than dealers usually treat it. A program is not a PDF you wrote once and filed. It is supposed to function as a live process, which is exactly where the paperwork and the practice tend to split.

Does the Rule Actually Apply to My Store?

Yes, if your dealership does any of the following as a regular part of business, per the FTC’s own two-part test:

  • Defers payment for a vehicle or bills a customer over time
  • Grants or arranges credit (including sending an application to a third-party lender)
  • Participates in the decision to extend, renew, or set the terms of credit
  • Advances funds someone has to repay you

Buy-here-pay-here stores clear that bar without question, since they hold the paper themselves. But the second bullet catches almost everyone else too: if your F&I desk arranges financing through outside lenders, the FTC counts that as “granting or arranging credit,” which makes you a creditor under the Rule. The narrow exception is a cash-only lot that never touches financing paperwork in any form, and even those stores usually end up covered once you count buyer’s orders that allow installment payments.

Once you’re a creditor, the second question is whether you have “covered accounts”: consumer accounts that allow multiple payments (an auto loan you originate or arrange is the FTC’s own example) or any other account where identity theft poses a reasonably foreseeable risk. An automobile loan file is about as textbook a covered account as the Rule contemplates.

What Counts as a Red Flag?

The FTC’s guidance groups warning signs into five categories, and Supplement A to the Rule lists specific examples under each. In an F&I context, the ones that come up most are:

  • Suspicious documents: an ID that looks altered or forged, a driver’s license photo that doesn’t match the person in the chair, or a credit application that looks like it’s been reassembled
  • Personal identifying information that doesn’t line up: an address that doesn’t match the credit report, a Social Security number already tied to a different customer file, or an applicant who can’t answer a basic authenticating question
  • Alerts from a credit reporting company: a fraud or active-duty alert, a credit freeze notice, or an address discrepancy flag returned with the pull
  • Account activity that doesn’t fit the pattern: a change-of-address request immediately followed by a request for additional credit, or a first payment that never comes
  • Direct notice: a victim, a law enforcement contact, or the customer themselves telling you something is wrong

None of these require special training to spot. Most F&I managers catch a mismatched name or a blurry ID by instinct after a few years on the desk. The Rule isn’t really testing whether your team can recognize a red flag. It’s testing whether your program can prove, after the fact, that the recognition step happened on every deal, not just the ones where the clerk remembers.

The Gap That Actually Fails Audits

The most common way a Red Flags program fails an audit has nothing to do with missing a flag: a red flag report gets pulled, but it never makes it into the deal jacket.

Failure mode

The check happened. The evidence that it happened did not make it into the file an auditor pulls later.

That gap is the real risk in most Red Flags programs, and it’s structural, not a training problem. The Rule requires a program, and a program is judged on documentation as much as on action. If your identity theft check lives as a step someone performs at a workstation, a report generated, glanced at, and set aside, you have satisfied the spirit of the requirement and failed the part an examiner or a plaintiff’s attorney actually tests: can you produce, for a specific deal, on a specific date, proof that the check ran and someone reviewed the result? An F&I manager who says “we always pull that report” is describing a habit. An auditor wants a record.

This is the same failure mode that shows up across dealership compliance audits generally: expired licenses that slip through, disclosures filed under the wrong deal number, a stipulation resolved by phone with no note in the file. The task got done. The proof didn’t survive the handoff between systems, or between people, or between the moment of the check and the moment someone archives the jacket. A Red Flags report that lives in one tool’s history log and a deal jacket that lives in another is a gap waiting for an audit to find it.

What a Defensible Program Actually Looks Like

The FTC’s four-step framework gives you the shape, but the part that survives an audit is the record layer underneath each step.

  1. Identify. Write down, in plain language, which red flags apply to your deal types: new-account fraud on a first-time financed buyer looks different from account-activity fraud on a return customer refinancing. This is a one-time document, reviewed annually.
  2. Detect. Run the check on every covered deal, not just the ones that feel off. This is where most stores are already compliant in practice; the gap is almost never “we didn’t run the check.”
  3. Respond. Define, in writing, what happens when a flag fires: who reviews it, what additional verification is required, and under what conditions the deal is held or declined. Vague language here (“F&I manager uses judgment”) is the first thing an examiner will push on.
  4. Update. Revisit the program at least annually, and document that you did, because “we’ve always done it this way” is not a compliance answer if the fraud patterns it’s meant to catch have changed since the program was written.

The connective tissue across all four steps is the same thing the FTC Safeguards Rule demands for the data underneath these checks: a record tied to the deal, not to someone’s memory of the deal. If the identity theft report, the reviewer’s sign-off, and the resulting action all land in the same file automatically, the program defends itself. If they live in three different places that someone has to remember to reconcile, the program only defends itself until the one deal where somebody forgot, and that’s usually the one an audit or a chargeback dispute picks to examine.

That connective-tissue problem isn’t unique to identity theft checks. It’s the same reason GLBA privacy obligations and Red Flags compliance tend to fail together at the same stores: both depend on a paper trail that has to survive a handoff between the person who did the work and the file an examiner eventually opens. Stores that treat compliance as a checklist of actions performed pass audits less often than stores that treat it as a checklist of records produced. The broader compliance stack most dealer groups are managing runs on the same principle: the requirement rarely changes year to year, but the evidence trail is what gets tested.

FAQ

What is the Red Flags Rule? An FTC requirement (16 CFR Part 681) for financial institutions and covered creditors, including dealers who extend or arrange credit, to maintain a written identity theft prevention program that detects and responds to warning signs of identity theft on covered accounts.

What counts as a “red flag” in this context? Warning signs like a mismatched address history, a suspiciously altered or reassembled document, an ID photo that doesn’t match the applicant, a Social Security number already tied to another file, or account activity (like a change of address immediately followed by a credit-limit increase request) that breaks the customer’s normal pattern.

If your identity theft checks already run reliably but the proof of them scatters across three systems by the time an auditor asks, that’s less a Red Flags problem than a record-keeping one, and it’s the kind of gap an AI-operated back office is built to close: every check, every reviewer action, and every deal tied together automatically, so the file an examiner opens already contains the answer.

This article summarizes public information for operations teams and is not legal advice. Requirements change; always confirm with the linked official FTC source or your compliance counsel.

Related articles