CREATORS OF THE COMPLIANCE TUNE-UP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERS® | MISMO | NAMB

Showing posts with label Identity Theft Prevention Program. Show all posts
Showing posts with label Identity Theft Prevention Program. Show all posts

Monday, November 19, 2018

Identity Theft Prevention: How to Catch a Thief


Chairman & Managing Director

Here are four scenarios involving identity theft that mortgage originators encounter from time to time. Read them and then keep them in mind as I discuss how to ask for additional information in order to prevent identity theft.
1.       A law enforcement report containing detailed information about the identity theft and the signature, badge number, or other identification information of the individual law enforcement official taking the report should be sufficient on face value to support a victim’s request.
Question: Without an identifiable concern, such as an indication that the report was fraudulent, would it be reasonable for an information furnisher or Consumer Reporting Agency (CRA) to request additional information or documentation?
Answer: It would not be reasonable.
2.       A consumer might provide a law enforcement report similar to the above report, but certain important information such as the consumer’s date of birth or Social Security number may be missing because the consumer chose not to provide it.
Question: The information furnisher or CRA could accept this report, but would it be reasonable to require that the consumer provide the missing information?
Answer: It would be reasonable.
3.       A consumer might provide a law enforcement report generated by an automated system with a simple allegation that an identity theft occurred to support a request for a tradeline block or cessation of information furnishing.
Question: Would it be reasonable for an information furnisher or CRA to ask that the consumer fill out and have notarized the Commission’s ID Theft Affidavit or a similar form and provide some form of identification documentation?
Answer: It would be reasonable.
4.       A consumer might provide a law enforcement report generated by an automated system with a simple allegation that an identity theft occurred to support a request for an extended fraud alert.
Question: Would it be reasonable for a consumer reporting agency to require additional documentation or information, such as a notarized affidavit?
Answer: It would not be reasonable.
In these scenarios, a financial institution should be responsive in accordance with certain guidelines. Specificity of action must be appropriate, reasonable and proportional to the challenge. However, total reliance on the CRA is inappropriate.

Wednesday, February 23, 2011

FinCEN: Elder Abuse - Red Flags

On February 22, 2011, the Financial Crimes Enforcement Network (FinCEN) issued an advisory to assist the financial industry in reporting instances of financial exploitation of the elderly, a form of elder abuse.
Financial institutions can alert appropriate authorities to suspected elder financial exploitation. We have previously provided notification about the increase in elder abuse in financial transactions. And FinCEN has notified the public about this upward trend, using SARs as an important method to identify this form of financial exploitation.
There are important RED FLAGS relating to financial exploitation of the elderly, and we provide a list below and suggest appropriate action to implement them. 
FinCEN's Advisory states:
  • In the instances where elderly individuals experience declining cognitive or physical abilities, they may find themselves more reliant on specific individuals for their physical well-being, financial management, and social interaction.
  • Although anyone can be a victim of a financial crime such as identity theft, embezzlement, and fraudulent schemes, certain elderly individuals may be particularly vulnerable.
Post Separator-2-LCG
SUSPICIOUS ACTIVITY
Financial institutions may become aware of persons or entities:
Perpetrating illicit activity against the elderly through monitoring transaction activity that is not consistent with expected behavior of elderly customers.
Post Separator-2-LCG
ILLICIT ACTIVITY
Financial institutions should evaluate indicators of potential financial exploitation in combination with other red flags and expected transaction activity being conducted by or on behalf of the elder. Additional investigation and analysis may be necessary to determine if the activity is suspicious.
Post Separator-2-LCG
RED FLAGS
Erratic or unusual banking transactions, or changes in banking patterns:
  • Frequent large withdrawals, including daily maximum currency withdrawals from an ATM;
  • Sudden Non-Sufficient Fund activity;
  • Uncharacteristic nonpayment for services, which may indicate a loss of funds or access to funds;
  • Debit transactions that are inconsistent for the elder;
  • Uncharacteristic attempts to wire large sums of money;
  • Closing of CDs or accounts without regard to penalties.
Interactions with customers or caregivers:
  • A caregiver or other individual shows excessive interest in the elder's finances or assets, does not allow the elder to speak for himself, or is reluctant to leave the elder's side during conversations;
  • The elder shows an unusual degree of fear or submissiveness toward a caregiver, or expresses a fear of eviction or nursing home placement if money is not given to a caretaker;
  • The financial institution is unable to speak directly with the elder, despite repeated attempts to contact him or her;
  • A new caretaker, relative, or friend suddenly begins conducting financial transactions on behalf of the elder without proper documentation;
  • The customer moves away from existing relationships and toward new associations with other "friends" or strangers;
  • The elderly individual's financial management changes suddenly, such as through a change of power of attorney to a different family member or a new individual;
The elderly customer lacks knowledge about his or her financial status, or shows a sudden reluctance to discuss financial matters.
Post Separator-2-LCG
ACTION
A financial institution's Identity Theft Prevention Program - Red Flags (Program) should be updated immediately to include red flags that may indicate the financial exploitation of elderly customers.
  • Although the subject FinCEN issuance does not specifically require revision to the Identity Theft Prevention Program - Red Flags, the 26 Red Flags listed in 12 CFR Part 41, Supplement A to Appendix J are not meant to be comprehensive, and assume all applicable federal laws and regulations.
  • The Program's goal is to detect and identify Red Flags, and establish, implement, maintain, and update reasonable policies and procedures to identify, detect, and mitigate identity theft through a financial institution's own efforts and those of its loan originators, affiliates, and third party vendors.
  • A component of the Program is to ensure that it is updated, as needed and as appropriate to the specific financial institution, to reflect changes in the law, changes to the risks to customers, and to the safety and soundness of the financial institution from identity theft. 
  • Since forms of identity theft can occur in the financial exploitation of the elderly, it is important to update the Program for red flags involving such financial exploitation immediately.
Post Separator-2-LCG
Visit Library
Law Library Image

Advisory to Financial Institutions on Filing Suspicious Activity Reports
Regarding Elder Financial Exploitation
FIN-2011-A003
February 22, 2011
Line-Webpage
Contact Us-1(125x37)

Wednesday, December 8, 2010

Red Flags Rule: Deadline - This time they really mean it!

At the request of Congress, the Federal Trade Commission delayed enforcement of the "Red Flags" Rule through December 31, 2010.

We notified you of this deadline on June 3, 2010.

The FTC's Enforcement Policy Statement did not affect other federal agencies' enforcement of the original November 1, 2008 deadline for institutions subject to their oversight to be in compliance.

For those who have not been following the long timeframe to the deadline at the end of this month, the Red Flags Rule became effective on January 1, 2008, with full compliance for all covered entities originally required by November 1, 2008. The Commission issued several Enforcement Policies delaying enforcement of the Rule. Most recently, the Commission announced in October 2009 that at the request of certain members of Congress, it was delaying enforcement of the Rule until June 1, 2010, to allow Congress time to finalize legislation that would limit the scope of business covered by the Rule.

The Commission then received another request from Congress for another delay in enforcement of the Rule beyond June 1, 2010. In response, the Commission extended the stay through December 31, 2010.

The Commission continually urged Congress to pass legislation that will resolve any questions as to which entities are covered by the Rule, thereby obviating the need for further enforcement delays.

Barring Congress passing legislation limiting the scope of the Red Flags Rule with an effective date earlier than December 31, 2010, the Commission will begin enforcement as of that effective date.

Effective Date: December 31, 2010

Line-Webpage

Call to Action -

Time is Running Out!

Mortgage Loan Originators (Brokers, Lenders, "Creditors")

Implement immediately an Identity Theft Prevention Program, Red Flags Rule, and Customer Identification Program.

(1) The FTC provides information about designing and implementing some of these programs. FTC Red Flags website.

(2) There are many vendors that provide them for relatively low cost.

(3) Lenders Compliance Group provides the Identity Theft Prevention Program - Policies and Procedures - Red Flags Rule and Address Discrepancies, a low cost, comprehensive, easy to implement program that incorporates all three of the aforementioned areas.

Investors, Wholesale and Correspondent Lenders, Servicers, "Creditors"

You are not exempt from the proper due diligence to ensure that you are doing business with entities that are compliant with the Red Flags Rule! It should be part of your year-end updates and clients approval procedures to require some form of certification that your clients have actually implemented the statutory requirements.

(1) Develop a certification or attestation to be signed by the covered entities with which you conduct business.

(2) Lenders Compliance Group has developed a one-page Identity Theft Prevention Certification expressly for this purpose. We will offer this important Certification to you free as a courtesy. Please email your request to Jonathan Foxx, our Managing Director.

Line-Webpage

Visit Library for Issuances

Law Library Image
Identity Theft Prevention and Red Flags Rule

Line-Webpage

LENDERS COMPLIANCE GROUP is the first full-service, mortgage risk management firm in the country, specializing exclusively in mortgage compliance and offering a full suite of hands-on and automated services in residential mortgage banking.