Original questions written against the published FINRA and NASAA exam content outlines — not actual exam questions. Every choice is explained.
A broker-dealer maintains the identity theft prevention program required by Regulation S-ID. With respect to red flags, what three things must that program be designed to do?
- A.Detect them, prevent identity theft, and mitigate the harm when identity theft occurs.Correct. Those three verbs are the substance of the obligation, and detection by itself does not satisfy it.
- B.Detect them, report each one to the customer, and suspend the account until the customer replies.Wrong. Contacting the customer may be an appropriate response in some cases but is not a required element of every one.
- C.Detect them, log them for the annual audit, and disclose the totals in the firm's privacy notice.Wrong. The program is an operating control, not a disclosure item that belongs in a customer notice.
- D.Detect them, refer each one to law enforcement, and freeze all payments from the account.Wrong. Responses must be proportionate to the risk, and a blanket freeze on every flag is neither required nor workable.
Why: Regulation S-ID requires a written program that identifies relevant red flags, detects them in the firm's day-to-day operations, and then responds appropriately to prevent and mitigate identity theft. Detection alone is not compliance: a program that flags a suspicious address change but has no response step has failed the standard. The response must be appropriate to the degree of risk the flag presents, which is why neither reporting everything nor freezing everything states the requirement.
Fenwick Securities maintains ordinary retail brokerage accounts that permit multiple payments and transfers to third parties. Under the SEC's identity theft red flags rule, the firm must:
- A.Obtain a consumer credit report on every customer at account opening and annually thereafter.Wrong. No such requirement exists. Identification at account opening is governed by the customer identification program rules instead.
- B.Maintain a written identity theft prevention program - approved by the board or senior management - that identifies relevant red flags, detects them, responds appropriately and is updated periodically.Correct. Those four functions, in a written and formally approved program, are the substance of the rule.
- C.Report every suspected instance of identity theft to the SEC within one business day.Wrong. The rule requires an appropriate response under the firm's program, not a one-day regulatory report.
- D.Reimburse any customer who suffers a loss from identity theft, regardless of the customer's own conduct.Wrong. The rule imposes a prevention program. It does not create a strict-liability reimbursement obligation.
Why: Firms holding covered accounts must maintain a WRITTEN identity theft prevention program, appropriate to the firm's size and complexity and approved by the board or by appropriate senior management. The program has four functional requirements: identify relevant red flags for the firm's accounts, detect those red flags in day-to-day operations, respond appropriately when one appears, and update the program periodically to reflect changing risks. Typical red flags include mismatched identifying information, a sudden change of address followed by a request for a new account feature, and notices from customers or law enforcement.
A transfer instruction on a Wrayburn Brokerage account has been rejected and re-submitted several times in quick succession, each time with a slightly different spelling of the beneficiary name and a different supporting document. The receiving institution is the same throughout, and the branch is pressing the clerk to get it through. What is the appropriate response?
- A.Re-submit using the spelling that most closely matches the account record, since the rejections are a data-quality problem.Wrong. It treats the varying identifiers as noise to be cleaned when the variation is the signal itself.
- B.Stop and escalate the pattern, because repeated resubmission with changed identifying data is a red flag rather than a formatting issue.Correct. It names the sequence as the reportable fact and puts it in front of someone who can investigate it.
- C.Return the instruction to the branch and require the customer to sign a fresh letter of authorization.Wrong. A new authorization cures a documentation defect and would leave the underlying pattern intact and unreported.
- D.Process it and note the discrepancies on the transfer blotter for the next reconciliation.Wrong. Recording an anomaly where it will be read after the fact is not escalation, and the funds would already have moved.
Why: Red flags in operations rarely announce themselves; they appear as data that keeps changing until it clears a control. An instruction re-presented with its identifying details altered on each attempt is a pattern in which a control is being probed, and the pattern is what must be escalated. The clerk is not being asked to conclude anything, only to put in front of a reviewing function the one thing she can see and it cannot. Correcting the spelling, refreshing the authorization or annotating a blotter all leave the pattern unreported. A single rejection for a genuine clerical reason, with no subsequent variation in the identifying data, would be ordinary exception processing.
Peregrine Wealth Advisors maintains covered accounts for individual clients and is subject to Regulation S-ID. Its written Identity Theft Prevention Program must, at a minimum:
- A.Encrypt all client account data at rest and in transitEncryption is a safeguards concept associated with Regulation S-P, not a Regulation S-ID minimum.
- B.Deliver an annual privacy notice describing the firm's information-sharing practicesThe annual privacy notice is a Regulation S-P requirement.
- C.File the program with the state Administrator before implementationNo filing of the program is required.
- D.Identify, detect and respond to relevant red flags, and be updated periodically, with senior approval, staff training and service-provider oversightCorrect. These are the four required elements plus the administrative requirements of Regulation S-ID.
Why: Regulation S-ID requires SEC-regulated entities with covered accounts to maintain a written Identity Theft Prevention Program that identifies relevant red flags, detects them, responds appropriately to prevent and mitigate identity theft, and is updated periodically to reflect changing risks. The program must be approved by the board or an appropriate senior manager, must provide for staff training, and must include oversight of service provider arrangements.
5 questions in our bank involve Identity Theft Red Flags Rule. Practise them with instant explanations.