<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>DealSafe Corporation blog</title>
    <link>http://www.dealsafe.com/resources</link>
    <description>Plain-English guides to the FTC Safeguards Rule, the Red Flags Rule, and dealership compliance, written for the F&amp;I office.</description>
    <language>en</language>
    <pubDate>Sun, 06 Sep 2026 20:35:05 GMT</pubDate>
    <dc:date>2026-09-06T20:35:05Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>The Red Flags Rule for Auto Dealers: What It Requires and How to Run It</title>
      <link>http://www.dealsafe.com/resources/red-flags-rule-auto-dealers</link>
      <description>&lt;p&gt;&lt;strong&gt;If your dealership finances vehicles or sends deals to lenders, you are a "creditor" under the FTC's Red Flags Rule. That means a written Identity Theft Prevention Program, staff who can spot red flags, and proof both exist. Here is the rule in plain English, and why synthetic identity fraud makes it more than paperwork.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;If your dealership finances vehicles or sends deals to lenders, you are a "creditor" under the FTC's Red Flags Rule. That means a written Identity Theft Prevention Program, staff who can spot red flags, and proof both exist. Here is the rule in plain English, and why synthetic identity fraud makes it more than paperwork.&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;By DealSafe | Reading time: 5 minutes | Last reviewed: September 2026. This article is information, not legal advice.&lt;/em&gt;&lt;/p&gt; 
&lt;h2&gt;Who the Red Flags Rule covers&lt;/h2&gt; 
&lt;p&gt;The Red Flags Rule (part of the Fair and Accurate Credit Transactions Act) applies to creditors and financial institutions that hold "covered accounts." In dealership terms: if you finance purchases, arrange financing through third-party lenders, or regularly pull consumer reports, you are in scope. Buy Here Pay Here stores are the clearest case: your accounts are covered accounts by design.&lt;/p&gt; 
&lt;p&gt;The rule requires a written Identity Theft Prevention Program with four parts:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Identify&lt;/strong&gt; the red flags of identity theft relevant to your store.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Detect&lt;/strong&gt; them when they occur.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Respond&lt;/strong&gt; appropriately when a flag fires.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Update&lt;/strong&gt; the program periodically as fraud patterns change.&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;A program on paper that nobody follows fails the "detect" and "respond" tests. A team that eyeballs licenses without a written program fails "identify" and "update." You need both halves.&lt;/p&gt; 
&lt;h2&gt;Why this is not just paperwork: the fraud math&lt;/h2&gt; 
&lt;p&gt;Identity fraud against auto lenders is at record levels, and the numbers are worth stating once, plainly:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;US lender exposure to synthetic identity fraud reached an all-time high of $3.3 billion at the end of 2024, according to TransUnion. Auto lending is the most exposed category, at roughly $2 billion.&lt;/li&gt; 
 &lt;li&gt;Auto-lending fraud exposure overall hit an estimated $9.2 billion in 2024 and $10.4 billion in 2025, according to Point Predictive.&lt;/li&gt; 
 &lt;li&gt;Consumers filed about 60,000 auto-loan identity theft reports with the FTC in 2024, and the pace accelerated in 2025. (FTC Consumer Sentinel data)&lt;/li&gt; 
 &lt;li&gt;Experian reports that 45 percent of dealers lose $10,000 to $20,000 on a single fraudulent deal, and that dealers average four fraudulent deals before detection.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;A synthetic identity is built, not stolen: a real Social Security number combined with a fabricated name, address, and history, seasoned until it passes bureau screens. It looks like a thin-file customer, and thin files are normal in auto. No salesperson can reliably spot one by eye. That is the argument for making verification a system step rather than a judgment call.&lt;/p&gt; 
&lt;h2&gt;What detection looks like at the desk&lt;/h2&gt; 
&lt;p&gt;The traditional dealership answer, photocopy the driver's license and drop it in the deal jacket, documents that you held a card. It does not show the card was genuine or that the person holding it owns the identity. A working detection layer has three pieces:&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Document authentication.&lt;/strong&gt; Scan the license and check it against known security features and barcode formats. A color copier cannot do this; software can.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Identity verification.&lt;/strong&gt; The buyer confirms their identity on their own phone: device and carrier checks, with out-of-wallet questions for flagged applicants. Remote shoppers complete the same step before they arrive. The check takes about a minute and runs while your F&amp;amp;I manager works the deal.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Consistent screening.&lt;/strong&gt; Red Flags checks run as a standard step on every transaction, not just the deals that feel off, and OFAC screening is available on demand for any deal you want it on. The fraudster's best friend is the regular customer everyone waves through.&lt;/p&gt; 
&lt;p&gt;The fear every GM has here is friction, and it is legitimate: 46 percent of dealers say verification steps slow down the deal and frustrate customers (Experian). The fix is not skipping the check. It is running the check on the customer's phone, in parallel with the deal, so verification adds seconds rather than a scene at the desk.&lt;/p&gt; 
&lt;h2&gt;The response and the record&lt;/h2&gt; 
&lt;p&gt;When a flag fires, your program must say what happens next, and the store must actually do it: additional verification, manager review, or decline. Whatever the outcome, record it. The resolution log is what turns a fraud attempt into evidence of a working program.&lt;/p&gt; 
&lt;p&gt;Documentation is also your protection with lenders. Fraud losses flow back to dealers through recourse and buybacks, and a dealer who can show a time-stamped verification record is in a different conversation than one holding a photocopy. Keep identity documents and verification results in the deal jacket. The jacket is the audit trail.&lt;/p&gt; 
&lt;h2&gt;Keeping the program current&lt;/h2&gt; 
&lt;p&gt;The fourth requirement, update the program periodically, is the one that quietly expires. Fraud patterns shift fast: synthetic identity attack rates on auto lenders more than doubled between 2020 and 2024, according to Point Predictive. Review your program at least annually: which red flags fired, how they were resolved, what changed in your sales process, and what new fraud patterns your detection needs to catch. Write down the review. Date it.&lt;/p&gt; 
&lt;h2&gt;Where to start&lt;/h2&gt; 
&lt;p&gt;Three questions tell you most of what you need to know:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;Do you have a written Identity Theft Prevention Program, reviewed in the last 12 months?&lt;/li&gt; 
 &lt;li&gt;Is identity verified, not just screened, on every deal, before funding?&lt;/li&gt; 
 &lt;li&gt;Can you produce the verification log for any deal from the past year in minutes?&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;Every "no" is a gap with a fix. DealSafe's &lt;a href="http://www.dealsafe.com/red-flags-id-verification"&gt;Red Flags and identity verification product&lt;/a&gt; runs detection at the desk and keeps the written program current automatically, and our &lt;a href="http://www.dealsafe.com/resources/ftc-safeguards-rule-checklist-auto-dealers"&gt;Safeguards checklist&lt;/a&gt; covers the companion security obligations. If you want an outside read first, the free gap assessment maps your store against both rules in one 30-minute session, with the findings in writing either way.&lt;/p&gt; 
&lt;p style="text-align: center; margin: 32px 0;"&gt;&lt;a href="http://www.dealsafe.com/gap-assessment" style="display: inline-block; background: #74C000; color: #1e293b; padding: 14px 28px; border-radius: 6px; font-weight: 600; text-decoration: none;"&gt;Get the free gap assessment&lt;/a&gt;&lt;/p&gt; 
&lt;h2&gt;Frequently asked questions&lt;/h2&gt; 
&lt;h3&gt;Does the Red Flags Rule apply to car dealerships?&lt;/h3&gt; 
&lt;p&gt;Yes. Dealers that finance purchases, arrange financing through lenders, or regularly obtain consumer reports are "creditors" under the rule and must maintain a written Identity Theft Prevention Program. BHPH dealers hold covered accounts by design.&lt;/p&gt; 
&lt;h3&gt;What are the four requirements of a Red Flags program?&lt;/h3&gt; 
&lt;p&gt;Identify the red flags relevant to your business, detect them in practice, respond appropriately when they fire, and update the program periodically. The program must be written and must actually operate.&lt;/p&gt; 
&lt;h3&gt;Is a credit bureau red flag alert enough?&lt;/h3&gt; 
&lt;p&gt;No. A bureau alert flags possible risk at the credit pull and leaves resolution to staff judgment. The rule expects detection plus a documented response. Verifying the identity itself, independent of the bureau pull, is the stronger control and the cleaner record.&lt;/p&gt; 
&lt;h3&gt;What is synthetic identity fraud?&lt;/h3&gt; 
&lt;p&gt;A fabricated identity combining a real Social Security number with invented personal details, seasoned until it passes standard credit screens. TransUnion puts US lender exposure at an all-time high of $3.3 billion, with auto lending the most exposed category. Synthetic identities are built to pass eyeball checks, which is why verification has to be systematic.&lt;/p&gt; 
&lt;h3&gt;What should a dealership do when a red flag fires?&lt;/h3&gt; 
&lt;p&gt;Follow the response steps in your written program: pause the deal at the verification step, run additional verification or manager review, and decline if the identity cannot be confirmed. Record the outcome on the deal. The log is your proof the program works.&lt;/p&gt; 
&lt;h2&gt;See also&lt;/h2&gt; 
&lt;p&gt;&lt;a href="http://www.dealsafe.com/safeguards-rule"&gt;FTC Safeguards Rule program for dealers&lt;/a&gt; · &lt;a href="http://www.dealsafe.com/pricing"&gt;Published per-rooftop pricing&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=247237480&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.dealsafe.com%2Fresources%2Fred-flags-rule-auto-dealers&amp;amp;bu=http%253A%252F%252Fwww.dealsafe.com%252Fresources&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Fri, 04 Sep 2026 01:49:41 GMT</pubDate>
      <guid>http://www.dealsafe.com/resources/red-flags-rule-auto-dealers</guid>
      <dc:date>2026-09-04T01:49:41Z</dc:date>
      <dc:creator>DealSafe</dc:creator>
    </item>
    <item>
      <title>The FTC Safeguards Rule for Auto Dealers: A Plain-English Checklist</title>
      <link>http://www.dealsafe.com/resources/ftc-safeguards-rule-checklist-auto-dealers</link>
      <description>&lt;p&gt;&lt;strong&gt;If your dealership finances or arranges financing or leasing, the FTC considers you a financial institution, and the Safeguards Rule has been fully mandatory since June 9, 2023. Here is the entire rule, translated into the ten things your store must do, what each one takes, and how to prove it is done.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;If your dealership finances or arranges financing or leasing, the FTC considers you a financial institution, and the Safeguards Rule has been fully mandatory since June 9, 2023. Here is the entire rule, translated into the ten things your store must do, what each one takes, and how to prove it is done.&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;By DealSafe | Reading time: 6 minutes | Last reviewed: September 2026. This article is information, not legal advice.&lt;/em&gt;&lt;/p&gt; 
&lt;h2&gt;Does the Safeguards Rule apply to your dealership?&lt;/h2&gt; 
&lt;p&gt;Almost certainly, yes. The FTC's own dealer-specific FAQ says it directly: most automobile dealers who finance or lease automobiles are financial institutions under the Safeguards Rule. If your F&amp;amp;I office sends deals to lenders, you are covered. If you are a Buy Here Pay Here store extending the credit yourself, you are covered twice over: as a financial institution under Safeguards and as a creditor under the Red Flags Rule.&lt;/p&gt; 
&lt;p&gt;There is one partial exemption. Dealerships holding customer information on fewer than 5,000 consumers are excused from four requirements: the written risk assessment, monitoring and testing, the written incident response plan, and the annual board report. Everything else (the Qualified Individual, access controls, encryption, multi-factor authentication, training, and vendor oversight) still applies.&lt;/p&gt; 
&lt;h2&gt;The stakes, stated once&lt;/h2&gt; 
&lt;p&gt;Violations of FTC rules carry civil penalties of up to $53,088 per violation, the inflation-adjusted figure effective January 17, 2025. Violations can be counted per affected consumer.&lt;/p&gt; 
&lt;p&gt;There is also a newer exposure many dealers miss. Since May 13, 2024, you must notify the FTC as soon as possible, and no later than 30 days after discovery, of any breach involving unencrypted customer information of 500 or more consumers. Reports go through an FTC online form and are posted in a public database. Unauthorized access is presumed to be acquisition unless you have reliable evidence otherwise.&lt;/p&gt; 
&lt;p&gt;That is the risk. Here is the checklist that closes it.&lt;/p&gt; 
&lt;h2&gt;The dealership Safeguards checklist&lt;/h2&gt; 
&lt;ol&gt; 
 &lt;ol&gt; 
  &lt;li&gt;&lt;strong&gt;Name your Qualified Individual.&lt;/strong&gt; One person accountable for the program. It can be your GM, your controller, or an outside service provider; the rule allows all three. Write the appointment down. Responsibility stays with the dealership either way.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Write your risk assessment.&lt;/strong&gt; Identify the reasonably foreseeable risks to customer information in your store: the showroom, the F&amp;amp;I office, the DMS, website leads, the service lane, shared logins on the sales floor. Record the criteria you used and how you will mitigate each risk. Reassess periodically and keep the versions.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Control access.&lt;/strong&gt; Limit customer information to people who need it for their job. Review access on a schedule. Kill shared DMS logins; five sales managers on one login is a finding waiting to happen.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Encrypt customer information.&lt;/strong&gt; At rest and in transit, or document a reasonable alternative. You cannot encrypt what you have not inventoried, so start with a list of every system that touches customer data.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Turn on multi-factor authentication.&lt;/strong&gt; MFA for anyone who accesses your information system: DMS, CRM, email, website backend. If a system genuinely cannot do MFA, the rule allows a reasonably equivalent control, but you must document the reasoning.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Monitor and test.&lt;/strong&gt; Continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months. NADA has estimated a standalone penetration test at roughly $23,000 per rooftop, which is why most stores coordinate testing through a program or their IT provider.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Train everyone.&lt;/strong&gt; Security awareness training for all staff, with specialized training for security personnel. This is where most stores quietly fail: sales consultant turnover hit 66 percent in 2024 per the NADA Dealership Workforce Study, so last year's training session no longer covers this year's sales floor. Training has to be assigned at hire and logged, or it does not count.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Oversee your vendors.&lt;/strong&gt; Choose service providers that can safeguard your data, require safeguards by contract, and reassess them periodically. Your DMS, CRM, website provider, and anyone else touching customer information belongs in the register. The DealerBuilt case is the cautionary tale: the FTC's flagship dealer-channel data-security action was against a dealership software provider whose exposed storage device compromised data on about 12.5 million consumers across 130 dealerships. It settled under a 20-year compliance order.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Write the incident response plan.&lt;/strong&gt; Roles, decision-making authority, remediation steps, documentation, and reporting procedures. Including the 30-day FTC clock from the section above. Drill it once a year. A plan nobody has opened since 2019 is a paper program, not a current one.&lt;/li&gt; 
  &lt;li&gt;&lt;strong&gt;Report to the board, annually, in writing.&lt;/strong&gt; The Qualified Individual reports on the program's status, incidents, testing, and training at least once a year to the board or equivalent governing body. For a single-point store, "the board" can be the dealer principal, but the report must exist, in writing, dated.&lt;/li&gt; ol&amp;gt;
 &lt;/ol&gt; 
&lt;/ol&gt; 
&lt;h2&gt;How to prove it: the Book of Evidence&lt;/h2&gt; 
&lt;p&gt;Compliance is not the activity. It is the proof of the activity. Accountants who work dealer audits call the assembled record your Book of Evidence: signed program documents, the current risk assessment, training logs for every employee, access reviews, vendor contracts, testing results, the incident plan, and the board report.&lt;/p&gt; 
&lt;p&gt;After an incident, that file is often the difference between the FTC reading your store as negligent versus grossly negligent. Build it as a byproduct of running the program, not as a scramble when someone asks. A good standard: be able to produce the whole book within 48 hours of being asked.&lt;/p&gt; 
&lt;h2&gt;What changed recently&lt;/h2&gt; 
&lt;p&gt;Two things worth knowing. First, the FTC's CARS Rule, the separate retail rule covering advertising and add-ons, was vacated by the Fifth Circuit in January 2025 and formally withdrawn in February 2026. The court ruled on procedure only; it never said the targeted conduct was lawful, and the FTC continues to enforce the same principles under Section 5 of the FTC Act, case by case. In March 2026 the agency put 97 dealer groups on written notice over advertised pricing.&lt;/p&gt; 
&lt;p&gt;Second, enforcement against dealers is real and recent: a $20 million judgment against Leader Automotive Group in December 2024, and in April 2026 an agreement with Lindsay Automotive covering refunds on more than $75 million in consumer charges plus a $3.1 million civil penalty. The Safeguards Rule itself is enforced the same way, through consent orders and penalties, and every public breach report invites scrutiny of the whole program.&lt;/p&gt; 
&lt;h2&gt;Where to start&lt;/h2&gt; 
&lt;p&gt;Print the ten items above. For each one, ask a single question: if an examiner asked tomorrow, could I hand over dated proof this is done? Every "no" is a gap. Every gap has an owner, a cost, and a fix.&lt;/p&gt; 
&lt;p&gt;If you want a second set of eyes, DealSafe offers a free gap assessment: a 30-minute working session that maps your store against this exact checklist, with the findings in writing whether or not you ever become a customer. You can also see how &lt;a href="http://www.dealsafe.com/safeguards-rule"&gt;our Safeguards program&lt;/a&gt; handles each requirement, or check our &lt;a href="http://www.dealsafe.com/pricing"&gt;published per-rooftop pricing&lt;/a&gt;.&lt;/p&gt; 
&lt;p style="text-align: center; margin: 32px 0;"&gt;&lt;a href="http://www.dealsafe.com/gap-assessment" style="display: inline-block; background: #74C000; color: #1e293b; font-weight: 600; padding: 14px 28px; border-radius: 6px; text-decoration: none;"&gt;Get the free gap assessment&lt;/a&gt;&lt;/p&gt; 
&lt;h2&gt;Frequently asked questions&lt;/h2&gt; 
&lt;h3&gt;Does the FTC Safeguards Rule apply to all car dealerships?&lt;/h3&gt; 
&lt;p&gt;It applies to dealers that finance or arrange financing or leasing for consumers, which covers most dealerships. The FTC's dealer FAQ says so explicitly. Dealers holding customer information on fewer than 5,000 consumers are exempt from four of the ten requirements, but not from the Qualified Individual, access controls, encryption, MFA, training, or vendor oversight.&lt;/p&gt; 
&lt;h3&gt;What is the penalty for violating the Safeguards Rule?&lt;/h3&gt; 
&lt;p&gt;Civil penalties run up to $53,088 per violation under FTC Act Section 5(m)(1)(A), effective January 17, 2025. Violations can be counted per affected consumer, so exposure compounds quickly across a customer database.&lt;/p&gt; 
&lt;h3&gt;When did the Safeguards Rule become mandatory for dealers?&lt;/h3&gt; 
&lt;p&gt;The amended rule's prescriptive provisions took effect June 9, 2023. The breach-notification requirement followed on May 13, 2024: report any breach of unencrypted information of 500 or more consumers to the FTC within 30 days of discovery.&lt;/p&gt; 
&lt;h3&gt;Who can be a dealership's Qualified Individual?&lt;/h3&gt; 
&lt;p&gt;An employee, someone at an affiliate, or a service provider. Many smaller stores assign the role to the GM or controller with outside support. The dealership keeps responsibility regardless of who holds the title.&lt;/p&gt; 
&lt;h3&gt;Is a written policy enough for Safeguards compliance?&lt;/h3&gt; 
&lt;p&gt;No. The rule requires a running program: current risk assessment, monitored controls, MFA, training with logs, vendor contracts and reviews, an incident response plan, and an annual written board report. A binder alone is a snapshot, not a program.&lt;/p&gt; 
&lt;h2&gt;See also&lt;/h2&gt; 
&lt;p&gt;&lt;a href="http://www.dealsafe.com/red-flags-id-verification"&gt;Red Flags &amp;amp; ID verification for dealers&lt;/a&gt; · &lt;a href="http://www.dealsafe.com/resources/red-flags-rule-auto-dealers"&gt;The Red Flags Rule for Auto Dealers&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track-na2.hubspot.com/__ptq.gif?a=247237480&amp;amp;k=14&amp;amp;r=http%3A%2F%2Fwww.dealsafe.com%2Fresources%2Fftc-safeguards-rule-checklist-auto-dealers&amp;amp;bu=http%253A%252F%252Fwww.dealsafe.com%252Fresources&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Fri, 04 Sep 2026 01:48:47 GMT</pubDate>
      <guid>http://www.dealsafe.com/resources/ftc-safeguards-rule-checklist-auto-dealers</guid>
      <dc:date>2026-09-04T01:48:47Z</dc:date>
      <dc:creator>DealSafe</dc:creator>
    </item>
  </channel>
</rss>
