Q&A: New Fraud and Identity Theft Rules Are your customers safe from online scamsters? How to comply with the FTC's new 'Red Flags' program.

By Randy Myers

Q: I recently learned about the Federal Trade Commission's Red Flags Rule, requiring businesses to plan a response to identity theft and fraud. My business has an online store, so does this apply to me? What steps do I need to take to become compliant?

A: Whether you're subject to the Red Flags Rule depends largely on how you get paid. If your customers simply charge purchases to a bank credit card, you're probably exempt. If you offer your own credit card, or sell first and collect payment later, you probably need to comply.

The rule took effect at the end of last year. It requires financial institutions and certain "creditors" to implement a written program for detecting and dealing with warning signs, or "red flags," that can indicate someone is trying to commit identify theft. Examples include an alert from a consumer reporting agency, or the presentation of suspect identification documents.

If you're covered under the rule, your Red Flags Rule program must do four things:

  1. Identify red flags relevant to your business or industry.
  2. Spell out procedures for detecting those red flags.
  3. Detail how you will respond to a red flag. (Who will you notify, what will you tell them?)
  4. Provide for regular updates to your procedures and the education of your staff.

Physicians, attorneys, accountants and many other professionals and service providers are exempt from the rule under the Red Flag Program Clarification Act of 2010. Other businesses qualify as creditors if they maintain consumer accounts that permit multiple payments or transactions and offer the potential for identity theft, and they (a) obtain or use consumer credit reports in connection with credit transactions, (b) furnish information to consumer reporting agencies in connection with credit transactions, or (c) advance funds to or on behalf of someone else -- unless the funds relate to providing of a service.

The FTC has information about the Red Flags Rule on its website here. Although it was published prior to the Clarification Act, this FTC how-to guide also offers helpful compliance advice. Failure to comply could result in FTC penalties of up to $3,500 for each customer account you maintain.

A former reporter for The Wall Street Journal and Dow Jones and contributor to Barron's, Randy Myers is a contributing editor for CFO and Corporate Board Member magazines.

Want to be an BIZ Experiences Leadership Network contributor? Apply now to join.

Business Ideas

70 Small Business Ideas to Start in 2025

We put together a list of the best, most profitable small business ideas for BIZ Experiencess to pursue in 2025.

Science & Technology

OpenAI's Latest Move Is a Game Changer — Here's How Smart Solopreneurs Are Turning It Into Profit

OpenAI's latest AI tool acts like a full-time assistant, helping solopreneurs save time, find leads and grow their business without hiring.

Social Media

How To Start a Youtube Channel: Step-by-Step Guide

YouTube can be a valuable way to grow your audience. If you're ready to create content, read more about starting a business YouTube Channel.

Money & Finance

These Are the Expected Retirement Ages By Generation, From Gen Z to Boomers — and the Average Savings Anticipated. How Do Yours Compare?

Many Americans say inflation prevents them from saving enough and fear they won't reach their financial goals.

Starting a Business

I Built a $20 Million Company by Age 22 While Still in College. Here's How I Did It and What I Learned Along the Way.

Wealth-building in your early twenties isn't about playing it safe; it's about exploiting the one time in life when having nothing to lose gives you everything to gain.

Business Solutions

Boost Team Productivity and Security With Windows 11 Pro, Now $15 for Life

Ideal for BIZ Experiencess and small-business owners who are looking to streamline their PC setup.