SardineCon SF/2026

Learn More
Regulation & bodies4 分で読めます

FTCとは?

SUBSCRIBE

The FTC, the US Federal Trade Commission, is the consumer-protection and competition authority that tackles fraud, deceptive practices, and data-security failures. It is not an AML regulator, but its identity-theft and scam rules intersect directly with the account-opening and KYC controls fraud teams run.

What is the FTC, in plain English?

The FTC is the United States' main consumer-protection and competition regulator. It goes after unfair and deceptive business practices, consumer fraud and scams, and failures to protect personal data or privacy. It also enforces specific rules that touch financial firms, most notably the identity-theft red-flag requirements that oblige certain businesses to spot and respond to signs of identity theft.

The FTC is not a money-laundering regulator; it does not receive SARs or examine BSA programs. What it does is shape the expectations around scams, deceptive marketing, and data handling, which is exactly where consumer fraud and identity abuse live. Its enforcement actions and guidance set the tone for how firms are expected to treat victims and protect customer information.

For an operator, the useful framing is that fraud rarely stays neatly on one side of the AML-versus-consumer-protection line. The same stolen identity that fails your KYC check is an FTC identity-theft concern, so the two worlds overlap more than the org charts suggest.

FTC versus an AML regulator

It helps to see where the FTC's remit stops and an AML supervisor's begins:

What changes

AML regulator

FTC

Primary goal

Detect and report money laundering

Protect consumers from fraud and deceptive practices

Core tools

SAR and CTR filing, BSA exams

Enforcement actions, red-flag rules, data-security cases

Who it protects

The financial system

The individual consumer

Overlap point

Stolen identities failing KYC

Identity theft and scam victims

Who is involved?

Who

Their role

The FTC

Enforces against fraud, deception, and data failures, and administers identity-theft red-flag rules.

Covered firms

Businesses subject to red-flag rules that must detect and respond to identity-theft indicators.

Consumers

The victims of scams, identity theft, and data breaches the FTC exists to protect.

Fraud and KYC teams

Operators whose onboarding and monitoring controls line up with FTC identity-theft expectations.

What it looks like in practice

In practice

A lender's onboarding flow starts seeing applications that use real names and Social Security numbers paired with mismatched addresses and freshly created email accounts. These are classic identity-theft indicators, and the red-flag program is supposed to catch them.

The fraud team tightens step-up verification on the flagged pattern and routes suspected identity-theft cases to a dedicated queue for victim outreach and reporting. When the FTC later publishes guidance on the same scam wave, the team can show its red-flag response already covered the indicators, which keeps a consumer-protection issue from becoming an enforcement one and protects the customers whose identities were abused.

Why the FTC matters to operators

Even if AML is your main focus, the FTC shapes two things you cannot ignore: how you treat scam victims and how you handle personal data. Its identity-theft red-flag rules intersect directly with account opening and KYC, so a gap there is both a fraud problem and a potential FTC problem. Its data-security cases set expectations for protecting the very customer data your monitoring depends on.

The FTC also publishes rich consumer-fraud data and guidance that describe live scam trends, from imposter schemes to romance and investment fraud. Reading that material helps fraud teams anticipate the scams their customers are about to be hit with, which feeds both prevention and the way you support victims after the fact.

What to watch

  • Red-flag coverage. Confirm your account-opening controls actually detect and respond to identity-theft indicators, not just fraud loss.
  • Data-security expectations. FTC cases set the bar for protecting customer data; weak handling of KYC data is a real exposure.
  • Scam trend reports. The FTC's consumer-fraud data flags rising scam types before they peak in your own book.
  • Deceptive practices. Marketing and disclosure that mislead customers can draw FTC action independent of any fraud loss.
  • Victim handling. How you treat scam and identity-theft victims sits squarely in FTC territory, so align your response processes.

Quick questions

Does the FTC regulate AML?

No. The FTC is a consumer-protection and competition authority, not an AML regulator. It does not receive SARs or examine BSA programs, but its fraud, scam, and data rules overlap heavily with fraud-team work.

What are the identity-theft red-flag rules?

They require certain businesses to have a program to detect, prevent, and respond to indicators of identity theft in their accounts. These indicators map closely onto the signals fraud and KYC teams already watch at onboarding.

How does the FTC affect data handling?

Through enforcement of data-security and privacy expectations. Firms that fail to protect personal data can face FTC action, which matters because KYC and monitoring processes hold large amounts of that data.

Should an AML-focused team care about the FTC?

Yes, because fraud and identity abuse cross the line between consumer protection and AML constantly. A stolen identity that fails KYC is both an AML and an FTC concern, so the controls should account for both.

Does the FTC handle scam victims?

It collects consumer complaints, publishes scam data, and pursues the businesses behind deceptive practices. It does not reimburse individual victims, but its work shapes how firms are expected to prevent and respond to scams.

How is the FTC different from the SEC?

The SEC regulates securities markets and firms. The FTC covers general consumer protection and competition across most industries. Their remits can overlap on fraud, but their core mandates are distinct.

Go deeper

  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.
  • FinCEN ↗ — The US financial intelligence unit. Bank Secrecy Act rules, advisories, and SAR and CTR guidance.

FTCと併せて知っておきたい用語