Brokers, advisers fall short in protecting clients from identity theft

Brokers, advisers fall short in protecting clients from identity theft
The SEC finds that some firms use generic compliance programs that aren't tailored to the particular hacking dangers their accounts face.
DEC 06, 2022

Some brokerages and investment advisory firms are just going through the motions when it comes to protecting investors from identity theft, an SEC probe shows.

Financial firms are failing to establish and follow through on policies and procedures designed to prevent hackers from stealing their clients’ and customers' personal information, according to a risk alert released Monday by the Securities and Exchange Commission.

The SEC warning was based on the findings of an examination sweep to monitor compliance with Regulation S-ID, or the Identity Theft Red Flags Rule. The regulation was promulgated in 2013 and applies to so-called “covered accounts,” which are defined as those a financial institution maintains for personal, family or household purposes that permit multiple payments or transactions.

The red flag rule requires brokerages and advisory firms to develop and implement an identity theft protection program. SEC exam staff found that some firms failed to determine whether the rule applied to any of their accounts or failed to conduct a reassessment after merging with another firm.

The shortcomings led to online and retirement accounts being omitted from compliance with the red flag rule, the alert states.

Another deficiency involved implementing a generic program that didn’t target red flags specific to a firm’s business model.

“For example, some firms created written programs that had generic language for identifying, detecting and responding to and updating red flags but the programs did not include any actual red flags identified by the firms,” the alert states.

The SEC also noted training deficiencies.

"Some trainings appeared to be insufficient because the training was limited to a single sentence telling employees to be aware of identity theft," the alert states.

The SEC is not only looking for specificity in compliance but also wants to see that firms are adapting their policies and procedures as they go through mergers or consolidations, said Ignacio Sandoval, a partner at Morgan Lewis.

For instance, they may reduce their branch offices but take on new online accounts, which creates possible new hacking vulnerabilities.

“The threats are dynamic,” said Sandoval, a former special counsel in the SEC Division of Trading and Markets. “They change over time. Firms need to be cognizant of these changes. You need to go back and rework your policies and procedures, retrain folks and reconsider what your program looks like.”

The risk alert comes as the SEC is warning firms to strengthen their cyber defenses. It also follows an enforcement case earlier this year in which the agency imposed $2.5 million in fines on J.P. Morgan Securities, UBS Financial Services Inc. and TradeStation Securities Inc. for red-flag program deficiencies.

The SEC also is working on a cybersecurity proposal and has another one on its regulatory agenda.

“I think what comes out in the exam findings is going to inform rulemaking,” Sandoval said.

‘IN the Office’ with Stifel CEO Alex David

Latest News

Two US financial services firms in merger talks that could create $3T powerhouse
Two US financial services firms in merger talks that could create $3T powerhouse

Reports of potential combination follow discussions between CEOs, sources say.

Judge OKs more than $90 million in settlement money for GWG investors
Judge OKs more than $90 million in settlement money for GWG investors

Mayer Brown, GWG's law firm, agreed to pay $30 million to resolve conflict of interest claims.

Fintech bytes: Orion and eMoney add new planning, investment tools for RIAs
Fintech bytes: Orion and eMoney add new planning, investment tools for RIAs

Orion adds new model portfolios and SMAs under expanded JPMorgan tie-up, while eMoney boosts its planning software capabilities.

Retirement uncertainty cuts across generations: Transamerica
Retirement uncertainty cuts across generations: Transamerica

National survey of workers exposes widespread retirement planning challenges for Gen Z, Millennials, Gen X, and Boomers.

Does a merger or acquisition make sense for your firm? Why now is the perfect time to secure your firm’s future
Does a merger or acquisition make sense for your firm? Why now is the perfect time to secure your firm’s future

While the choice for advisors to "die at their desks" might been wise once upon a time, higher acquisition multiples and innovations in deal structures have created more immediate M&A opportunities.

SPONSORED RILAs bring stability, growth during volatile markets

Barely a decade old, registered index-linked annuities have quickly surged in popularity, thanks to their unique blend of protection and growth potential—an appealing option for investors looking to chart a steadier course through today's choppy market waters, says Myles Lambert, Brighthouse Financial.

SPONSORED Beyond the dashboard: Making wealth tech human

How intelliflo aims to solve advisors' top tech headaches—without sacrificing the personal touch clients crave