Mon - Sat: 9:00 AM - 6:00 PM
Call: 844-376-2274
F&I & Compliance
Red Flags Rule Compliance for Dealerships
No software makes you compliant. What software can do is create the records that show you were paying attention.
What the rule asks of a dealership
The Red Flags Rule sits under federal law and is enforced in the retail automotive world by the Federal Trade Commission. In plain terms, it requires covered businesses to maintain a written Identity Theft Prevention Program: a document, approved at a senior level, describing how the business spots warning signs of identity theft, what it does when one appears, and how the program is kept current.
Two things about that sentence catch stores out. The first is the word written. A store where the finance manager is genuinely careful, checks identification and asks good questions, but has nothing on paper, does not have a program. The second is the word maintained. A program written once in 2011, printed, filed and never reviewed since is a document rather than a program, and it will not read well to anyone reviewing it later.
Understand what the rule is aimed at. It is not primarily about protecting the store from a bad deal, although it does that. It is about preventing a real person from having a vehicle financed in their name by someone else, which is a serious event for that person and an expensive one for everybody downstream. Reading the rule with that purpose in mind makes the requirements feel less arbitrary.
Nothing here is legal advice and we are not your compliance counsel. Rules, thresholds and enforcement posture change. Have your program reviewed by an attorney or a qualified compliance professional who knows your state and your business model.
Does it apply to your store?
The rule reaches businesses that qualify as creditors and maintain covered accounts. In practice, most dealerships that arrange financing, take retail installment contracts, or carry paper themselves have concluded that it applies to them, and buy here pay here operations sit squarely inside it because they are the lender.
The stores that ask hardest are usually the small ones: a used lot doing forty cars a month, a broker, a single point independent. The honest answer is that the analysis depends on how your business is structured and on how you handle financing, and it is worth an hour of a qualified professional's time rather than a guess from a vendor's marketing page, including this one.
Here is the practical point, though. Almost every element of a sensible identity theft program is something a well run store should be doing regardless of whether the rule technically reaches it. Verifying that the person signing is the person on the identification, noticing when an application does not hang together, and keeping a record of what you checked are not compliance overhead. They are how you avoid financing a car for someone who is not who they say they are, which is a loss you eat directly.
The five parts of a written program
Programs vary in length and detail, but a defensible one generally covers the same ground. Use this as scaffolding for the conversation with whoever writes yours.
- Identify relevant red flags. The warning signs your specific operation is likely to encounter, given the customers you serve, the channels you take applications through, and the products you offer.
- Detect them. The procedures that surface those signs at the moment they matter, which for a dealership is at application intake and again before delivery.
- Respond appropriately. What happens when a red flag appears, who decides, and what the escalation path is. A program that identifies warning signs and then says nothing about the response is half a program.
- Update the program periodically. Because the tactics change. Review it on a schedule, note the review, and record what changed.
- Administer it. Senior approval, staff training, oversight of the program's operation, and oversight of service providers who touch the process on your behalf.
The last one is the most frequently skipped and the one that surprises people most in a review. If a vendor handles part of your intake, your program has to account for that.
The red flags a car store actually sees
Generic lists are easy to ignore because they read like they were written for a bank. Here is the version that shows up on a dealership floor, which is where a program either works or does not.
Identification that does not fit the person presenting it, or a document that looks altered, or a photo that requires a generous interpretation. An application where the pieces contradict each other: an address that does not match the identification, an employer that does not exist, a length of employment that does not square with the applicant's age. A social security number that does not match the name or the date of birth on the credit file, or a file that comes back with an address discrepancy notice attached.
Then the behavioral ones, which experienced finance managers already know. Unusual urgency about delivery tonight. Reluctance to provide a second form of identification, or a story about why it is not available. A buyer with no interest in the vehicle itself, only in how fast it can leave. A third party who does all the talking while the applicant says almost nothing. A remote deal where the person will not do a video call.
None of these mean fraud on their own. Plenty of honest customers are in a hurry and plenty of legitimate applications have errors in them. That is exactly why the response step matters: the program should tell your people to verify rather than to accuse.
Where software helps, and where it plainly does not
Let us be direct, because this category attracts vendors who blur the line. No product makes a dealership compliant with the Red Flags Rule. Compliance is a written program, senior approval, trained staff, consistent execution and periodic review. A vendor who tells you their software delivers compliance is describing something that cannot be sold.
What software can do is real and worth having. It can move identity capture to a point where the customer supplies it directly rather than a salesperson retyping it. It can hold the supporting documents attached to the application instead of as photographs in someone's text thread. It can record what was collected and when, in a form that survives staff turnover. And it can make the consistent path the easy path, which is the only way a procedure actually gets followed on a busy Saturday.
What it cannot do is judge a person standing in front of your finance manager, decide whether a story hangs together, or take responsibility for a decision. That is your team, and that is why the training element of the program is not filler. Our page on the FTC Safeguards Rule makes the parallel point about data security obligations, which are related but separate.
Identity and documents captured at intake, precisely described
Being specific about what SecureWebX does, because precision is the point of this whole page.
It provides secure online credit applications and shareable apply links, so the customer completes the application on their own device rather than at a desk with someone watching. Applications land in an application inbox tied to your company instead of an individual's email. Document collection is part of the same flow, so identification, proof of income and proof of residence arrive attached to the application. Document reading assists that capture, so a licence or an insurance card can be handled from a phone camera instead of a copier and a scanner.
Identity verification is supported at intake. Read that scope carefully: it is verification and record keeping at the application stage, not a substitute for your written program, your response procedures, your OFAC screening obligations or your staff training. It gives your program a consistent front door and a durable record. It does not replace the program. Our identity verification page covers the mechanics in more detail.
There is a quieter benefit that stores notice within a month. When intake is consistent, the exceptions become visible. A file missing a document stands out when every other file has one, and that visibility is worth more to your program than any single feature.
Consent versioning and the record you will want later
The compliance record is created at intake, and a weak record is a problem you discover at the worst possible moment, usually years later when nobody involved still works at the store.
SecureWebX includes a compliance module and a terms and consent gate with versioning. Versioning matters more than it sounds. When your disclosure language changes, you need to be able to say which version a specific customer accepted, and when, rather than only that they accepted something at some point. A system that overwrites its own terms cannot answer that question, and the inability to answer it is exactly the kind of gap that turns a manageable issue into an expensive one.
Alongside that sits the rest of the record keeping: role based permissions so access is deliberate rather than universal, login logging so you can answer who had access and when, and encrypted storage of personally identifiable information on the CRM side. Document management for the compliance file is covered on compliance document management.
Overseeing the vendors who touch your intake
The service provider element deserves its own section because it is where most programs are thin. If a third party handles any part of application intake, identity capture or document storage for you, your program has to address how you oversee them.
Ask every vendor in that chain, us included: what identity related data do you collect and where is it stored? How long do you retain it and what happens to it when we leave? Who at your company can access our customer records, and is that access logged? What is your notification process if you have a security incident? Can you produce, for a single named customer, everything you hold and every consent they gave, with dates? Do you subcontract any part of this, and to whom?
Get the answers in writing, keep them in your program file, and refresh them when you renew. A vendor uncomfortable answering those questions is telling you something useful. And be as demanding of the vendors you like as the ones you do not, because familiarity is not diligence.
A practical sequence, and what this costs
If you are starting from nothing, do it in this order. Establish whether the rule applies to your operation, with qualified help. Get the program written, aimed at your actual channels rather than copied from a template built for a bank. Get it approved at the level your structure requires and record that approval. Train the people who take applications, and record that too. Then make the daily execution consistent, which is where software finally enters the picture. Finally, put a review date on the calendar and keep it.
Most stores get this backwards. They buy a tool first, feel covered, and never write the document. The tool is the last step, not the first, and it only helps once there is a procedure for it to make easy.
On our side, SecureWebX and the CRM are sold together, month to month with no long term contract. CRM Only starts at $199 a month, and programs that include exclusive local leads start at $799. Current figures are on the pricing page. If you want to see what the intake record actually looks like before deciding whether it fits your program, contact us and ask for exactly that rather than a general demo.
Frequently Asked Questions
Does LeadLocate or SecureWebX make our store compliant with the Red Flags Rule?
No, and no product can. Compliance is a written Identity Theft Prevention Program with senior approval, trained staff, consistent execution and periodic review. Our software supports intake, identity verification at application, document collection and versioned consent records that your program can rely on.
Does the rule apply to a small independent lot?
It depends on whether your operation qualifies as a creditor with covered accounts, which turns on how you handle financing. Most stores that arrange financing or carry their own paper conclude that it applies. Confirm it with qualified counsel rather than with a vendor.
What has to be in the written program?
Generally five elements: identify relevant red flags, detect them, respond appropriately, update the program periodically, and administer it with senior approval, staff training and service provider oversight. The last element is the one most often missing.
What does identity verification at intake actually cover?
Verification and record keeping at the application stage, with supporting documents captured from the customer's own device and attached to the application. It is not a substitute for your program, your response procedures or your OFAC obligations.
Why does consent versioning matter for this?
Because you need to show which version of your disclosure language a specific customer accepted and when, not merely that they accepted something. A system that overwrites its own terms cannot answer that question later.
Is this page legal advice?
No. It is general information written for dealership operators. Have your program reviewed by an attorney or a qualified compliance professional familiar with your state and your business model.
See what a clean intake record looks like
Ask us to show the application, the documents and the versioned consent for one customer, end to end. Month to month, no long term contract.


LeadLocate® All rights reserved. Other product and company names mentioned herein are the property of their respective owners.
Answers to your questions:
LeadLocate is an all-in-one lead generation software and CRM platform. We generate in-market sales leads and provide you with all the tools necessary to sell that customer. All of your leads, texts, calls, emails, deals, and files are available in one place, accessible with a single login.
LeadLocate® All rights reserved. Other product and company names mentioned herein are the property of their respective owners.
Answers to your questions:
LeadLocate is an all-in-one lead generation software and CRM platform. We generate in-market sales leads and provide you with all the tools necessary to sell that customer. All of your leads, texts, calls, emails, deals, and files are available in one place, accessible with a single login.



