FCRA FCRA Identity Theft & Fraud Prevention 2 — Questions and Answers
Question 1: Under the FCRA's Red Flags Rule (implemented by the FTC and CFPB), which entities are required to develop and implement an Identity Theft Prevention Program?
- Financial institutions and creditors with covered accounts (Correct answer)
- Only banks with over $1 billion in assets
- Any business that accepts credit cards
- Only mortgage lenders and auto dealers
Correct answer: Financial institutions and creditors with covered accounts
The Red Flags Rule requires financial institutions and creditors that maintain covered accounts to create and operate a written Identity Theft Prevention Program.
Question 2: When a furnisher is notified by a CRA that a consumer has filed an identity theft block, what must the furnisher NOT do under FCRA §623(a)(6)?
- Re-furnish the blocked information unless it has a good-faith belief the information is correct (Correct answer)
- Accept any additional payments on the disputed account
- Contact the consumer about the account
- Report the account as disputed to other CRAs
Correct answer: Re-furnish the blocked information unless it has a good-faith belief the information is correct
FCRA §623(a)(6) prohibits furnishers from re-furnishing information that has been blocked as identity theft unless they reasonably believe the block was granted in error.
Question 3: Which document must a consumer submit to a CRA to trigger the 4-business-day identity theft information block under FCRA §605B?
- An identity theft report (such as an FTC Identity Theft Report) and proof of identity (Correct answer)
- A notarized affidavit only
- A police report only
- A letter from the creditor confirming fraud
Correct answer: An identity theft report (such as an FTC Identity Theft Report) and proof of identity
To trigger the §605B block, a consumer must provide an identity theft report (e.g., FTC IdentityTheft.gov report) plus proof of identity to the CRA.
Question 4: Under FCRA §605A, when a consumer places an initial fraud alert at one nationwide CRA, what must that CRA do?
- Notify the other nationwide CRAs so they can also place the alert (Correct answer)
- Send a physical letter to the consumer's last known address
- Immediately freeze the consumer's credit file
- Report the alert to the CFPB within 5 days
Correct answer: Notify the other nationwide CRAs so they can also place the alert
FCRA §605A requires the CRA receiving the initial fraud alert to promptly notify the other nationwide CRAs so all three files carry the alert.
Question 5: An identity theft victim requests a credit security freeze under the FCRA. How quickly must a CRA place the freeze after receiving a request?
- 1 business day for electronic/phone requests (Correct answer)
- 5 business days for all requests
- Immediately, within 24 hours
- 3 business days for all requests
Correct answer: 1 business day for electronic/phone requests
Under the Economic Growth Act amendments to the FCRA, CRAs must place a security freeze within 1 business day of an electronic or phone request, and 3 business days for a mail request.
Question 6: Under the FCRA, a credit freeze is now free for consumers nationwide due to which law?
- The Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018 (Correct answer)
- The Dodd-Frank Wall Street Reform Act of 2010
- The Fair and Accurate Credit Transactions Act of 2003
- The Credit CARD Act of 2009
Correct answer: The Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018
The Economic Growth, Regulatory Relief, and Consumer Protection Act (S.2155, 2018) amended the FCRA to make credit freezes free for all consumers at nationwide CRAs.
Under the FCRA's Red Flags Rule (implemented by the FTC and CFPB), which entities are required to develop and implement an Identity Theft Prevention Program?