Independent exam preparation · Original questions, every answer explained Reviews
Finance Exam Pro

Identity Theft Prevention Program

Appears in our practice questions for: Series 24

A written program required under Regulation S-ID that a firm's board or senior management must approve, identifying relevant red flags of identity theft, and requiring periodic review and updating as risks change.

Practice questions using Identity Theft Prevention Program

Original questions written against the published FINRA and NASAA exam content outlines — not actual exam questions. Every choice is explained.

A firm's written identity-theft prevention program lists categories of red flags but has never been reviewed or updated since it was first adopted years ago, even as new types of account takeover schemes have become common industry-wide. What must the principal ensure?

  1. A.Nothing, as long as the program was approved by the board of directors when adoptedWrong. Initial board approval does not substitute for the ongoing obligation to update the program as risks evolve.
  2. B.Nothing, because identity-theft red flags programs are only required to be updated every ten yearsWrong. This invents a specific ten-year cycle that has no basis in the ongoing-currency obligation.
  3. C.Nothing, since the program was compliant when it was first adoptedWrong. Initial adoption alone does not satisfy the ongoing obligation to keep the program current against evolving risks.
  4. D.Ensure the program is periodically reviewed and updated to address new and evolving identity-theft risksCorrect. An identity-theft prevention program must be kept current through periodic review and updating, not left static after initial adoption.

Why: An identity-theft prevention program under Regulation S-ID should be periodically reviewed and updated to address changes in the types of risks the firm faces. The principal must ensure the program is actually kept current, not treat initial adoption as satisfying an ongoing obligation.

A firm's compliance department drafts a written identity-theft prevention program on its own and begins implementing it, without presenting it to the firm's board or senior management for approval. A principal reviewing the program's adoption process is asked whether this is sufficient. What is the concern?

  1. A.There is no concern, since the compliance department is the appropriate owner of an identity-theft prevention program and no further approval is needed.Wrong. This dismisses the board/senior-management approval expectation for the program.
  2. B.The identity-theft prevention program should be approved by the firm's board of directors or senior management, and compliance implementing a program on its own without that approval and ongoing oversight does not satisfy the governance expectations for the program.Correct. Board or senior management approval and ongoing oversight are expected for the program's governance.
  3. C.The concern is that the program should instead have been approved by outside legal counsel rather than the firm's own board or senior management.Wrong. This substitutes an incorrect approver rather than the actual expected governance structure.
  4. D.The concern applies only to firms with retail customers; firms serving only institutional customers have no governance requirement for their identity-theft prevention program.Wrong. This invents a customer-type-based exemption from governance oversight.

Why: The identity-theft prevention program should be approved by the firm's board of directors or senior management, and compliance implementing a program on its own without that approval and ongoing oversight does not satisfy the governance expectations for the program.

Related terms

Finance Exam Pro is not affiliated with FINRA, NASAA, or any exam sponsor. Practice questions are original and are not actual exam questions. Rules change — confirm current requirements with the relevant regulator.