Skip to content

The Red Flags Rule for Auto Dealers: What It Requires and How to Run It

DealSafe
DealSafe

If your dealership finances vehicles or sends deals to lenders, you are a "creditor" under the FTC's Red Flags Rule. That means a written Identity Theft Prevention Program, staff who can spot red flags, and proof both exist. Here is the rule in plain English, and why synthetic identity fraud makes it more than paperwork.

By DealSafe | Reading time: 5 minutes | Last reviewed: September 2026. This article is information, not legal advice.

Who the Red Flags Rule covers

The Red Flags Rule (part of the Fair and Accurate Credit Transactions Act) applies to creditors and financial institutions that hold "covered accounts." In dealership terms: if you finance purchases, arrange financing through third-party lenders, or regularly pull consumer reports, you are in scope. Buy Here Pay Here stores are the clearest case: your accounts are covered accounts by design.

The rule requires a written Identity Theft Prevention Program with four parts:

  1. Identify the red flags of identity theft relevant to your store.
  2. Detect them when they occur.
  3. Respond appropriately when a flag fires.
  4. Update the program periodically as fraud patterns change.

A program on paper that nobody follows fails the "detect" and "respond" tests. A team that eyeballs licenses without a written program fails "identify" and "update." You need both halves.

Why this is not just paperwork: the fraud math

Identity fraud against auto lenders is at record levels, and the numbers are worth stating once, plainly:

  • US lender exposure to synthetic identity fraud reached an all-time high of $3.3 billion at the end of 2024, according to TransUnion. Auto lending is the most exposed category, at roughly $2 billion.
  • Auto-lending fraud exposure overall hit an estimated $9.2 billion in 2024 and $10.4 billion in 2025, according to Point Predictive.
  • Consumers filed about 60,000 auto-loan identity theft reports with the FTC in 2024, and the pace accelerated in 2025. (FTC Consumer Sentinel data)
  • Experian reports that 45 percent of dealers lose $10,000 to $20,000 on a single fraudulent deal, and that dealers average four fraudulent deals before detection.

A synthetic identity is built, not stolen: a real Social Security number combined with a fabricated name, address, and history, seasoned until it passes bureau screens. It looks like a thin-file customer, and thin files are normal in auto. No salesperson can reliably spot one by eye. That is the argument for making verification a system step rather than a judgment call.

What detection looks like at the desk

The traditional dealership answer, photocopy the driver's license and drop it in the deal jacket, documents that you held a card. It does not show the card was genuine or that the person holding it owns the identity. A working detection layer has three pieces:

Document authentication. Scan the license and check it against known security features and barcode formats. A color copier cannot do this; software can.

Identity verification. The buyer confirms their identity on their own phone: device and carrier checks, with out-of-wallet questions for flagged applicants. Remote shoppers complete the same step before they arrive. The check takes about a minute and runs while your F&I manager works the deal.

Consistent screening. Red Flags checks run as a standard step on every transaction, not just the deals that feel off, and OFAC screening is available on demand for any deal you want it on. The fraudster's best friend is the regular customer everyone waves through.

The fear every GM has here is friction, and it is legitimate: 46 percent of dealers say verification steps slow down the deal and frustrate customers (Experian). The fix is not skipping the check. It is running the check on the customer's phone, in parallel with the deal, so verification adds seconds rather than a scene at the desk.

The response and the record

When a flag fires, your program must say what happens next, and the store must actually do it: additional verification, manager review, or decline. Whatever the outcome, record it. The resolution log is what turns a fraud attempt into evidence of a working program.

Documentation is also your protection with lenders. Fraud losses flow back to dealers through recourse and buybacks, and a dealer who can show a time-stamped verification record is in a different conversation than one holding a photocopy. Keep identity documents and verification results in the deal jacket. The jacket is the audit trail.

Keeping the program current

The fourth requirement, update the program periodically, is the one that quietly expires. Fraud patterns shift fast: synthetic identity attack rates on auto lenders more than doubled between 2020 and 2024, according to Point Predictive. Review your program at least annually: which red flags fired, how they were resolved, what changed in your sales process, and what new fraud patterns your detection needs to catch. Write down the review. Date it.

Where to start

Three questions tell you most of what you need to know:

  1. Do you have a written Identity Theft Prevention Program, reviewed in the last 12 months?
  2. Is identity verified, not just screened, on every deal, before funding?
  3. Can you produce the verification log for any deal from the past year in minutes?

Every "no" is a gap with a fix. DealSafe's Red Flags and identity verification product runs detection at the desk and keeps the written program current automatically, and our Safeguards checklist covers the companion security obligations. If you want an outside read first, the free gap assessment maps your store against both rules in one 30-minute session, with the findings in writing either way.

Get the free gap assessment

Frequently asked questions

Does the Red Flags Rule apply to car dealerships?

Yes. Dealers that finance purchases, arrange financing through lenders, or regularly obtain consumer reports are "creditors" under the rule and must maintain a written Identity Theft Prevention Program. BHPH dealers hold covered accounts by design.

What are the four requirements of a Red Flags program?

Identify the red flags relevant to your business, detect them in practice, respond appropriately when they fire, and update the program periodically. The program must be written and must actually operate.

Is a credit bureau red flag alert enough?

No. A bureau alert flags possible risk at the credit pull and leaves resolution to staff judgment. The rule expects detection plus a documented response. Verifying the identity itself, independent of the bureau pull, is the stronger control and the cleaner record.

What is synthetic identity fraud?

A fabricated identity combining a real Social Security number with invented personal details, seasoned until it passes standard credit screens. TransUnion puts US lender exposure at an all-time high of $3.3 billion, with auto lending the most exposed category. Synthetic identities are built to pass eyeball checks, which is why verification has to be systematic.

What should a dealership do when a red flag fires?

Follow the response steps in your written program: pause the deal at the verification step, run additional verification or manager review, and decline if the identity cannot be confirmed. Record the outcome on the deal. The log is your proof the program works.

See also

FTC Safeguards Rule program for dealers · Published per-rooftop pricing

Share this post