ARTICLE
15 April 2013

"Red Flag" Compliance Requirements Come To Investment Advisors, Broker-Dealers

M
Mintz

Contributor

Mintz is a general practice, full-service Am Law 100 law firm with more than 600 attorneys. We are headquartered in Boston and have additional US offices in Los Angeles, Miami, New York City, San Diego, San Francisco, and Washington, DC, as well as an office in Toronto, Canada.
It has been several years since the Federal Trade Commission’s Red Flag Rule took effect, and the banking regulators have had the Red Flag Interagency Guidance in place since 2007.
United States Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

It has been several years since the Federal Trade Commission's Red Flag Rule took effect; and the banking regulators have had the Red Flag Interagency Guidance in place since 2007. Finally, entities regulated by the Securities and Exchange Commission (SEC), such as broker-dealers and investment advisers, and entities regulated by the Commodity and Futures Trade Commission (CFTC), such as futures commodity merchants, commodity trading advisers and commodity pool operators will be required to join the party.

In announcing the adoption of the rule, new SEC Chair Mary Jo White said, "Current estimates are that about five percent of American adults fall victim to identity theft fraud each year. It is a risk for everyone, and as technology continues to advance, the risks increase."

Section 1088 of the Dodd-Frank Wall Street Reform and Consumer Protection Act shifted certain oversight functions under the Fair Credit Reporting Act from the Federal Trade Commission to the SEC and the CFTC for entities regulated by those agencies. Last year the agencies issued a joint proposal on the identity theft provision. The final rules are "substantially identical" to the proposal, said Norm Champ, director of the SEC's Division of Investment Management.

Specifically, the rules require that covered entities set up programs that identify, detect, and respond to identity theft "red flags." Most of the SEC-regulated entities will not be surprised by these rules. Dodd-Frank essentially transferred oversight of already-existing Fair Credit Reporting Act requirements from the FTC to the SEC and the CFTC.

SEC Commissioner Luis Aguilar, however, noted that certain investment advisers, including advisers to hedge funds and private equity funds, may not have identity theft programs in place and will have to pay "particular attention" to the rules. Such entities were not required to register with the SEC until last year pursuant to Dodd-Frank.

The joint rules will become effective 30 days after publication in the Federal Register, and firms will be required to come into compliance six months after that date.

We are preparing a detailed Alert describing who is covered by these latest identity theft rules and what those covered entities need to do to reach compliance.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

ARTICLE
15 April 2013

"Red Flag" Compliance Requirements Come To Investment Advisors, Broker-Dealers

United States Privacy

Contributor

Mintz is a general practice, full-service Am Law 100 law firm with more than 600 attorneys. We are headquartered in Boston and have additional US offices in Los Angeles, Miami, New York City, San Diego, San Francisco, and Washington, DC, as well as an office in Toronto, Canada.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More