Compliance Program
With the November 1st, 2008 deadline fast approaching, dealers are in need of a complete update and implementation of their Information Security Program. Today’s Auto Dealer is looked at as a Financial Institution, which requires compliance with the Safeguards Rule and Red Flags Rules as well as other requirements imposed by Federal Laws pertaining to Financial Institutions regarding Protection of Non-Public Information and the prevention of Identity Theft.
Automotive Assurance Group, an independent General Agency, has developed a compliance program designed to address the needs of today’s Auto Dealer. This turnkey solution can be included in the cost of each vehicle a dealership delivers and may be passed on to the dealerships customers. This creates the potential for turning compliance into a profit center.
The Automotive Assurance Group Compliance Program includes the following:
- Designation of Program Coordinator: Appointment of the Compliance officer will be established to outline responsibilities and the duties, as well as creation of documents and reports to supervise the administration of the dealerships ITPP as well as the Safeguards policy.
- Review of Safeguards Policy: Dealer should have implemented a Safeguards policy to comply with 2003 Federal requirements. AAG will review and update that plan or if no plan is in place, establish a written Information Security Program for the dealership in order to comply with the Safeguards Act of 2003.
- Risk Assessment & Audit: AAG will perform a written Risk Assessment of the dealers operations to determine what issues need to be addressed for the Information Security Program. A written recommendations document will provide suggestions on areas to be addressed to comply.
- Policy & Procedures: AAG provides a legally based policy and procedures manual for use by dealerships and their counsel. This policy document has been developed to be consistent with dealer compliance issues, and addresses both the Safeguards rule as well as the Red Flags procedures
- Train staff to effectively implement the program: AAG provides training and an employee procedure manual that describes both the requirements of the Red Flags Rule and the dealership’s own policy document, as well as creates records of employees’ use of that training. All employees will be involved in training, and will receive the written policy, and sign a statement of their adherence to the companies Information Security Program.
- Oversight of Service Products: Dealers must oversee companies that provide services to the dealership by contractually obligating them to follow the Red Flags Rule as applicable. AAG provides contract forms and clauses to accomplish this task.
- Detect “Red Flags”: An automatic process can be provided by Menu Vantage or Dealer Trac that confirms the authenticity of the identity offered. An OFAC check is performed at the same time; which is required by regulations other than the Red Flags Rule.
- Prevent Identity Theft: In addition to confirming the authenticity of the identity offered, Menu Vantage or Dealer Trac generates challenge questions if determined necessary, to verify the person offering it is really the person represented by that identity. The systems also generate a written record as well as a computer stored copy.
- Mitigate the impact of identity theft: ID Advocates provides one year to seven years of fully managed ID theft recovery service for dealership customers. This can be offered as a pre load that is charged on the buyers order and then upgraded, or simply sold as an offering to all customers.
- Ensure the effectiveness of the dealership’s program: Dealerships must ensure that their program works over time and that their policies evolve to address the changing tactics of identity theft. Disposition forms will be issued to be added to the policy whenever an issue arises involving possible Identity Theft. Furthermore dealerships must generate an annual written report for their board of directors concerning the performance of their identity theft prevention programs. AAG can assist in this process to perform an annual compliance audit that includes Red Flags Rule compliance, generating the necessary report and disseminating necessary changes to the dealerships policy.
While many companies charge several thousands of dollars to address these issues as well as ongoing monthly fees, Automotive Assurance Group, as an independent General Agency provides a solution at a fraction of that cost. AAG having direct relationships with many of the largest Insurance and Finance oriented programs will customize a cost proposal for your store based on your needs that will in all cases be a fraction of what other providers charge. In many cases this program will end up becoming a profit to your organization rather than an expense.
We look forward to providing a turnkey solution for your store.
