A firm's written identity-theft prevention program lists categories of red flags but has never been reviewed or updated since it was first adopted years ago, even as new types of account takeover schemes have become common industry-wide. What must the principal ensure?
- A.Nothing, as long as the program was approved by the board of directors when adoptedWrong. Initial board approval does not substitute for the ongoing obligation to update the program as risks evolve.
- B.Nothing, because identity-theft red flags programs are only required to be updated every ten yearsWrong. This invents a specific ten-year cycle that has no basis in the ongoing-currency obligation.
- C.Nothing, since the program was compliant when it was first adoptedWrong. Initial adoption alone does not satisfy the ongoing obligation to keep the program current against evolving risks.
- D.Ensure the program is periodically reviewed and updated to address new and evolving identity-theft risksCorrect. An identity-theft prevention program must be kept current through periodic review and updating, not left static after initial adoption.
Why: An identity-theft prevention program under Regulation S-ID should be periodically reviewed and updated to address changes in the types of risks the firm faces. The principal must ensure the program is actually kept current, not treat initial adoption as satisfying an ongoing obligation.