Red Flags Rule & ID verification
Verify the buyer before the deal funds. Not after.
- Most compliance tools check for identity red flags after the fact, in an audit.
- DealSafe verifies identity on the deal, while the customer is in the F&I office.
- Your Red Flags program runs itself, and every verification lands in the deal jacket.

Four steps. None of them slow the desk.
- Capture. The buyer scans the deal's QR code and photographs their driver's license on their own phone. The document is checked for authenticity, not just photocopied into the jacket.
- Verify. In the same session, the buyer confirms identity on their own phone, with out-of-wallet questions or carrier-based checks for flagged applicants. Remote shoppers verify the same way before they drive in.
- Screen. Red Flags screening runs as a standard step on every transaction, and OFAC screening is one click away on any deal you choose. No skipped steps, no exceptions for the regular customer everyone knows.
- Document. Every check, result, and resolution writes to the deal record. Your Identity Theft Prevention Program log updates itself.
- Dealers tell us their real constraint: 46 percent say verification steps slow down the deal and frustrate customers. DealSafe's check runs on the customer's phone while your F&I manager builds the menu. Verification adds seconds. A buyback adds weeks.
[video: Red Flags & ID verification walkthrough, 2–3 min, click-to-play, captions on]
An audit tells you a bad deal funded. Verification stops it at the desk.
The audit-only approach
Identity checks live inside a deal-jacket audit or a credit-bureau workflow. The findings arrive after funding. So does the recourse letter. The store eats the car, the chargeback, or both.
The DealSafe approach
Identity verification is a step in the deal itself. The customer verifies on their own phone in about a minute. Flagged deals pause before funding, not after. Cleared deals carry the proof in the jacket.
Experian reports that 45 percent of dealers lose $10,000 to $20,000 on a single fraudulent deal, and that dealers average four fraudulent deals before detection. One stopped deal can pay for a year of DealSafe.
Verification runs on the buyer's own phone.
At the desk, your salesperson generates a QR code for the deal. The buyer scans it and completes identity verification, the application, and every compliance approval on their own phone, in about two minutes, while your F&I manager works the deal. The moment they submit, the sensitive data locks down to general managers and finance managers only. See Secure Customer Intake for the full flow, the iPad option, and the access log.
Your Red Flags program, written and current.
The Red Flags Rule requires a written Identity Theft Prevention Program with four parts: identify the red flags relevant to your store, detect them, respond when they fire, and update the program periodically. If you finance deals or arrange financing, you are a covered creditor. BHPH stores, your accounts are covered accounts by design.
DealSafe drafts the program for your rooftop, maps each red flag to a detection step in the workflow, logs every response, and prompts the periodic review. When a lender or examiner asks for your ITPP, you export it.
Identity fraud in auto lending is at record levels.
You cannot train a busy sales floor to spot a synthetic identity by eye. The person looks real. That is the point of the product. So the check has to be a system step, not a judgment call.
See Secure Customer Intake · See the Safeguards Rule program · See training & audit support · Read the Red Flags guide
The fraud math, stated once.
We already get red flag alerts from our credit bureau. Is this different?
Yes. Bureau alerts fire at the credit pull and leave the resolution to your staff's judgment. DealSafe verifies the identity itself, before and independent of the bureau pull, and records how each flag was cleared. Screening tells you something might be wrong. Verification tells you who is actually standing in the box.
Does this replace our photocopy of the driver's license?
Yes. A photocopy proves you held a piece of plastic. It does not prove the plastic was real or that the person holding it owns the identity. Document authentication plus identity verification gives you both, and a record a lender's fraud department will accept.
What happens when a check fails?
The deal pauses at the verification step. Your manager gets a clear resolution path: additional verification, manager review, or decline. Every outcome is logged, which is what the Red Flags Rule's "respond" requirement actually demands.
Does it work for remote and online buyers?
Yes. Remote shoppers complete the same verification on their phone before they arrive or before delivery. Same standard, same record.
Will this slow down my deals?
The customer-side step takes about a minute and runs in parallel with your normal F&I workflow. Compare that to the time cost of one funded fraud deal: the recourse process, the unwound paperwork, the unit you may never recover.
Does collecting the application make DealSafe a lender or a credit bureau?
No. DealSafe captures the buyer's consent to a hard credit check and files it to the deal. Your store then initiates the pull through DealSafe using your existing bureau relationship, and DealSafe reports the results back into the deal file. We are not a bureau and not a lender. For the full intake flow, the iPad option, and the access log, see Secure Customer Intake.
