2022-07-27 SEC Press pdf 326 KB 19,140 chars

In re J.P. MORGAN

summary

J.P. Morgan Securities LLC agreed to a cease-and-desist order and paid a $1.2 million civil penalty to the SEC for failing to maintain a compliant identity theft prevention program from 2017 to 2019 by lacking reasonable policies to identify, detect, respond to, and update red flags for covered accounts, as well as failing to train staff and oversee service providers.

paragraph

J.P. Morgan Securities LLC violated Rule 201 of Regulation S-ID from January 1, 2017, to December 31, 2019, by failing to develop and implement adequate identity theft prevention programs as a registered broker-dealer and investment adviser. The SEC found that JPMS’s programs merely restated regulatory language without establishing specific, reasonable policies to identify, detect, respond to, or update red flags, and neglected staff training and oversight of service providers. As part of the settlement, JPMS consented to a cease-and-desist order, a censure, and a $1.2 million civil penalty, while undertaking remedial actions including policy revisions and enhanced training.

narrative

J.P. Morgan Securities LLC (JPMS) agreed to a cease-and-desist order and paid a $1.2 million civil penalty to the SEC for violating Rule 201 of Regulation S-ID between January 1, 2017, and December 31, 2019, as a registered broker-dealer and investment adviser. The SEC found that JPMS’s identity theft prevention programs were deficient because they merely restated regulatory requirements and listed generic, illustrative red flags without establishing specific, reasonable policies to identify, detect, respond to, or update procedures for those red flags. JPMS also failed to exercise effective oversight of its service provider arrangements and did not adequately train staff in 2017 to implement the program. Furthermore, the firm neglected to periodically update its programs to reflect evolving identity theft risks and its own prior experiences with fraud. Although JPMS did not admit or deny the findings, it consented to the order, agreed to a censure, and committed to substantial remedial actions, including revising its policies, enhancing oversight mechanisms, and improving staff training. The SEC noted these remedial efforts as mitigating factors in determining the penalty amount. JPMS also agreed not to seek offsets for the penalty in related investor actions, and interest will accrue on any late payments.

Enriched metadata

Scheme
broker-dealer-fraud (85%)
Outcome
settled
Civil penalty
$1,200,000
Classified broker-dealer-fraud(confidence 85%). EDGAR detection: forms Form D· recall 29% / precision 9%. detection rule →
Statutes
31 U.S.C. §371717 C.F.R. § 248.20117 C.F.R. § 248.201(d)17 C.F.R. § 248.201(b)17 C.F.R. § 248.201(f)17 C.F.R. § 248.201(e)SECTIONS 15(b) AND 21C OF THE SECURITIES EXCHANGE ACTSECTIONS 15(b) AND 21C OF THE SECURITIES EXCHANGE ACTSECTIONS 203(e) AND 203(k) OF THE INVESTMENT ADVISERS ACTSECTIONS 203(e) AND 203(k) OF THE INVESTMENT ADVISERS ACT
Parties
Securities and Exchange CommissionJ.P. MORGAN SECURITIES LLC
Keywords
identity theftidentitytheftprogramtheft preventionregulation s-idprevention programredjpmsflagscommissionrespondentcovered accountssecurities exchangepolicies procedures

Extracted insights

Dollar amounts 1
  • $1.20M $1,200,000 $1M–$10M
Entities 5
  • company j.p. morgan securities llc ×2
  • person identity theft prevention program
  • company jpmorgan chase & co.
  • agency Securities and Exchange Commission
  • company subsidiary of jpmorgan chase & co.
Triples 8
  • SEC instituted Administrative and Cease-and-Desist Proceedings
  • J.P. Morgan Securities LLC submitted Offer of Settlement
  • SEC accepted Offer of Settlement
  • J.P. Morgan Securities LLC consented to Entry of Order
  • J.P. Morgan Securities LLC failed to develop Identity Theft Prevention Program
  • J.P. Morgan Securities LLC violated Rule 201 of Regulation S-ID
  • J.P. Morgan Securities LLC is Broker-Dealer and Investment Adviser
  • J.P. Morgan Securities LLC is Subsidiary of JPMorgan Chase & Co.
Text layers
Extracted body text (19,140c)

 
 
 
 UNITED STATES OF AMERICA 
 Before the 
 SECURITIES AND EXCHANGE COMMISSION 
 
 
SECURITIES EXCHANGE ACT OF 1934 
Release No. 95367 / July 27, 2022 
 
INVESTMENT ADVISERS ACT OF 1940 
Release No. 6073 / July 27, 2022 
 
ADMINISTRATIVE PROCEEDING 
File No. 3-20936 
 
 
In the Matter of 
 
J.P. MORGAN  
SECURITIES LLC,  
 
Respondent. 
 
ORDER INSTITUTING ADMINISTRATIVE AND 
CEASE-AND-DESIST PROCEEDINGS, PURSUANT 
TO SECTIONS 15(b) AND 21C OF THE 
SECURITIES EXCHANGE ACT OF 1934 AND 
SECTIONS 203(e) AND 203(k) OF THE 
INVESTMENT ADVISERS ACT OF 1940, MAKING 
FINDINGS, AND IMPOSING REMEDIAL 
SANCTIONS AND A CEASE-AND-DESIST ORDER  
   
 
I. 
 
 The Securities and Exchange Commission (“Commission”) deems it appropriate and in the 
public interest that public administrative and cease-and-desist proceedings be, and hereby are, 
instituted pursuant to Sections 15(b) and 21C of the Securities Exchange Act of 1934 (“Exchange 
Act”) and Sections 203(e) and 203(k) of the Investment Advisers Act of 1940 (the 
“Advisers Act”), against J.P. Morgan Securities LLC (“Respondent” or “JPMS”).  
 
II. 
 
 In anticipation of the institution of these proceedings, Respondent has submitted an Offer 
of Settlement (the “Offer”) which the Commission has determined to accept.  Solely for the 
purpose of these proceedings and any other proceedings brought by or on behalf of the 
Commission, or to which the Commission is a party and without admitting or denying the findings 
herein, except as to the Commission’s jurisdiction over it and the subject matter of these 
proceedings, which are admitted, Respondent consents to the entry of this Order Instituting 
Administrative and Cease-and-Desist Proceedings, Pursuant to Sections 15(b) and 21C of the 
Securities Exchange Act of 1934 and Sections 203(e) and 203(k) of the Investment Advisers Act of 

 
 2 
1940, Making Findings, and Imposing Remedial Sanctions and a Cease-and-Desist Order 
(“Order”), as set forth below. 
III. 
 
 On the basis of this Order and Respondent’s Offer, the Commission finds that: 
 
Summary 
 
1. These proceedings arise out of JPMS’s failure to adequately develop and implement 
a written identity theft prevention program as required by Rule 201 of Regulation S-ID (17 C.F.R. § 
248.201). 
2. JPMS is a broker-dealer and investment adviser registered with the Commission. 
From at least January 1, 2017, through December 31, 2019 (the “Relevant Period”), JPMS violated 
Rule 201 of Regulation S-ID because its written identity theft prevention programs for the 
applicable lines of business (the “Programs”) failed to include reasonable policies and procedures to 
(i) identify relevant red flags for the covered accounts that JPMS offered or maintained, and 
incorporate those red flags into the Programs, (ii) respond appropriately to detected red flags to 
prevent and mitigate identity theft, and (iii) ensure that each Program was updated periodically to 
reflect changes in identity theft risks to customers. 
3. JPMS also violated Rule 201 of Regulation S-ID during the Relevant Period because 
it did not provide for the continued administration of its Programs by failing to (i) exercise 
appropriate and effective oversight of all service provider arrangements; and (ii) train staff under 
one of its lines of business, as necessary, to effectively implement the Program in 2017.   
Respondent 
 
 4.  J.P. Morgan Securities LLC is a Delaware limited liability company with its 
principal place of business in New York, New York.  It has been a broker-dealer registered with 
the Commission pursuant to Section 15(b) of the Exchange Act since December 13, 1985, and an 
investment adviser registered with the Commission pursuant to Section 203 of the Advisers Act 
since April 3, 1965.  It is a wholly-owned subsidiary of JPMorgan Chase & Co. (“JPMC”), a 
global financial services firm incorporated in Delaware and headquartered in New York, New 
York. 
 
Background 
 
5. During the Relevant Period, JPMS’s Programs failed to comply with the 
requirements of Regulation S-ID. 
6. Regulation S-ID requires financial institutions, including broker-dealers and 
investment advisers registered with the Commission that offer or maintain one or more covered 
accounts, to develop and implement a written identity theft prevention program “that is designed to 
detect, prevent, and mitigate identity theft” in connection with the opening of a covered account or 

 
 3 
any existing covered account.
1
  The program “must be appropriate to the size and complexity of the 
financial institution...and the nature and scope of its activities.”
2
 
7. Under Regulation S-ID, an identity theft prevention program must include 
reasonable policies and procedures to:  (i) identify relevant “red flags”
3
 for the covered accounts 
and incorporate them into the program; (ii) detect the red flags that have been incorporated into the 
program; (iii) respond appropriately to any red flags that are detected pursuant to the program; and 
(iv) ensure that the program is updated periodically to reflect changes in risks to customers and to 
the safety and soundness of the firm from identity theft.
4
   
8. A written identity theft prevention program may incorporate by reference policies 
outside of the program in order to satisfy the requirements of Regulation S-ID, but such 
incorporation by reference must be explicit.
5
 
9. With respect to the identification of relevant red flags, Regulation S-ID requires 
firms to consider several factors specific to the firm in order to identify red flags that are relevant to 
the firm’s business and the nature and scope of its activities, such as the types of covered accounts 
it offers or maintains, methods it provides to open covered accounts, methods it provides to access 
covered accounts, and its previous experiences with identity theft.
6
 
10. Appendix A to Regulation S-ID, which contains guidelines intended to assist firms 
in the formulation and maintenance of an identity theft prevention program that satisfies the 
requirements of Regulation S-ID, lists categories of red flags that a firm should consider 
incorporating in its program “as appropriate.”
7
  Supplement A to Appendix A further provides a 
non-comprehensive list of examples of red flags from each of these categories that the firm “may 
consider incorporating into its Program, whether singly or in combination...in connection with 
                                                 
1
  17 C.F.R. § 248.201(d)(1).  The rule defines “identity theft” as a fraud committed or attempted using the 
identifying information of another person without authority.  17 C.F.R. § 248.201(b)(9). 
2
  17 C.F.R. § 248.201(d)(1). 
3
  “Red flags” are defined as “a pattern, practice, or specific activity that indicates the possible existence of 
identity theft.”  17 C.F.R. § 248.201(b)(10). 
4
  17 C.F.R. § 248.201(d)(2)(i)-(iv). 
5
  17 C.F.R. § 248.201 Appendix A, Section I. 
6
  17 C.F.R. § 248.201, Appendix A, Section II(a). 
7
  These categories are: (i) alerts, notifications, or warnings received from consumer reporting agencies; (ii) 
suspicious documents, such as documents that appear to have been altered or forged; (iii) suspicious 
personal identifying information, such as a suspicious address change; (iv) unusual use of, or other 
suspicious activity related to, a covered account; and (v) notice from customers, victims of identity theft, or 
law enforcement authorities.  17 C.F.R. § 248.201, Appendix A, Section II(c). 

 
 4 
covered accounts.”
8
  The firm must consider these examples of red flags and include in its identity 
theft prevention program those that are appropriate.
9
 
11. With respect to responding to detected red flags in order to prevent and mitigate 
identity theft, Regulation S-ID requires an identity theft prevention program to include policies and 
procedures that “provide for appropriate responses” to detected red flags “that are commensurate 
with the degree of risk posed.”
10
  In determining an appropriate response, a firm “should consider 
aggravating factors that may heighten the risk of identity theft, such as a data security incident that 
results in unauthorized access to a customer’s account records . . . or notice that a customer 
provided account information” to someone under false pretenses.
11
 
12. With respect to periodically updating a written identity theft prevention program, 
Appendix A provides that firms should consider factors such as: (i) the firm’s experiences with 
identity theft; (ii) changes in methods of identity theft; (iii) changes in methods to detect, prevent or 
mitigate identity theft; (iv) changes in the types of accounts offered or maintained; and (v) changes 
in the firm’s structure or service provider arrangements.
12
 
13. Regulation S-ID also requires firms to provide for the continued administration of 
the written identity theft prevention program by training staff, as necessary, to effectively 
implement the program, and by exercising appropriate and effective oversight of service provider 
arrangements.
13
  With respect to the oversight of service provider arrangements in connection with 
one or more covered accounts, the firm should take steps to ensure that the activity of the service 
provider is conducted in accordance with reasonable policies and procedures designed to detect, 
prevent and mitigate the risk of identity theft.
14
 
 
                                          JPMS’s Identity Theft Prevention Program 
14. JPMS is a registered broker-dealer and investment adviser that offers and maintains 
“covered accounts,” which are accounts offered or maintained primarily for personal, family, or 
household purposes that involve or are designed to permit multiple payments or transactions.
15
    
Accordingly, JPMS is required to develop and implement a written identity theft prevention 
program in accordance with the requirements of Rule 201 of Regulation S-ID.   
                                                 
8
  17 C.F.R. § 248.201, Appendix A, Supplement A. 
9
  17 C.F.R. § 248.201(f). 
10
  17 C.F.R. § 248.201(d)(2)(iii). 
11
  17 C.F.R. § 248.201, Appendix A, Section IV. 
12
  17 C.F.R. § 248.201, Appendix A, Section V. 
13
  17 C.F.R. § 248.201(e)(3)-(4). 
14
  17 C.F.R. § 248.201, Appendix A, Section VI(c). 
15
  17 C.F.R. § 248.201(b)(3). 

 
 5 
15. During the Relevant Period, JPMS offered covered accounts under two lines of 
business, each of which maintained an identity theft prevention program.   
16. During the Relevant Period, the Programs contained substantial deficiencies and 
thus failed to comply with the requirements of Regulation S-ID.   
17. During the Relevant Period, neither Program incorporated policies or procedures 
that described how identity theft red flags were to be identified or appropriately responded to once 
they were detected.  Rather, both Programs merely (i) restated the general legal requirements (such 
as “identify relevant red flags” and “respond appropriately to any red flags that are detected to 
prevent and mitigate identity theft”), (ii) listed verbatim all the illustrative examples of identity 
theft red flags provided in Appendix A to Regulation S-ID, and (iii) listed various firmwide 
policies and business procedures that were incorporated into the Programs.  None of the 
incorporated policies and procedures listed in either Program explained how JPMS was to identify 
any of the enumerated red flags or to respond to the red flags in order to prevent and mitigate 
identity theft.  Although JPMS did take actions to detect and respond to potential and actual 
incidents of identity theft, the procedures describing those actions were not included or 
incorporated by reference in either Program. 
18. During the Relevant Period, neither Program incorporated reasonable policies or 
procedures to ensure the Programs were updated periodically, including identifying any new red 
flags based on customers’ actual experiences or changes in methodology.  As a result, JPMS failed 
to update its procedures, or provide in the Programs a written process for determining whether any 
such updates were necessary as a result of JPMS’s own experiences with identity theft or changes 
in the manner in which brokerage accounts could be opened.   
19. During the Relevant Period, JPMS failed to exercise appropriate and effective 
oversight of all of its service provider arrangements under the Programs.  The Programs required 
JPMS (i) to assess all service providers annually and (ii) to ensure that the service providers that 
possessed customer information and were in a position to identify red flags had language in their 
contracts requiring those service providers to detect identity theft red flags and either report the red 
flags to JPMC or respond to the red flags themselves.  JPMS failed to satisfy this requirement 
because it did not follow its own policies and procedures to assess all service providers annually 
and to ensure that all the relevant service provider agreements had the required red flag contractual 
language.  Accordingly, JPMS did not appropriately monitor all of its service providers to ensure 
that their activities were being conducted in accordance with policies and procedures designed to 
detect, prevent and mitigate identity theft. 
20. From at least January 1, 2017 through December 31, 2017, JPMS failed to provide 
any identity theft prevention program-specific training to staff as necessary to effectively 
implement one of the Programs.     

 
 6 
Violation 
21. As a result of the conduct described above, Respondent willfully
16
 violated Rule 
201 of Regulation S-ID (17 C.F.R. § 248.201), which requires registered broker-dealers and 
investment advisers that offer or maintain covered accounts to, among other things, develop and 
implement a written identity theft prevention program that is designed to detect, prevent, and 
mitigate identity theft in connection with the opening of a covered account or any existing 
covered account, and provide for the continued administration of the identity theft prevention 
program. 
JPMS’s Remedial Efforts 
22. JPMS has undertaken substantial remedial acts, including auditing and revising its 
identity theft prevention program.   
23. Among other things, JPMS adopted improved applicable policies and procedures 
for identifying, detecting, and responding to red flags, and periodically updating its program.  
JPMS also revised its program to provide greater oversight over JPMS’s service provider 
arrangements and to improve training of staff.  JPMS, in addition, made detailed presentations to 
the Commission’s staff.   
24. In determining to accept the Offer, the Commission considered the remedial acts 
undertaken by Respondent.  
IV. 
 In view of the foregoing, the Commission deems it appropriate and in the public interest to 
impose the sanctions agreed to in Respondent’s Offer. 
 
 Accordingly, pursuant to Sections 15(b) and 21C of the Exchange Act and Sections 203(e) 
and 203(k) of the Advisers Act, it is hereby ORDERED that: 
 
 A. Respondent cease and desist from committing or causing any violations and any 
future violations of Rule 201 of Regulation S-ID (17 C.F.R. § 248.201).   
 
                                                 
16
  “Willfully,” for purposes of imposing relief under Section 15(b) of the Exchange Act and Section 203(e) of 
the Advisers Act, “‘means no more than that the person charged with the duty knows what he is 
doing.’”  Wonsover v. SEC, 205 F.3d 408, 414 (D.C. Cir. 2000) (quoting Hughes v. SEC, 174 F.2d 969, 977 
(D.C. Cir. 1949)).  There is no requirement that the actor “also be aware that he is violating one of the Rules 
or Acts.”  Tager v. SEC, 344 F.2d 5, 8 (2d Cir. 1965).  The decision in The Robare Group, Ltd. v. SEC, which 
construed the term “willfully” for purposes of a differently structured statutory provision, does not alter that 
standard.  922 F.3d 468, 478-79 (D.C. Cir. 2019) (setting forth the showing required to establish that a person 
has “willfully omit[ted]” material information from a required disclosure in violation of Section 207 of the 
Advisers Act). 
  

 
 7 
B. Respondent is censured.   
  
C. Respondent shall, within 30 days of the entry of this Order, pay a civil money 
penalty in the amount of $1,200,000 to the Securities and Exchange Commission for transfer to the 
general fund of the United States Treasury, subject to Exchange Act Section 21F(g)(3). If timely 
payment is not made, additional interest shall accrue pursuant to 31 U.S.C. §3717.   
 
Payment must be made in one of the following ways:   
 
(1) Respondent may transmit payment electronically to the Commission, which 
will provide detailed ACH transfer/Fedwire instructions upon request;  
 
(2) Respondent may make direct payment from a bank account via Pay.gov 
through the Commission website at 
http://www.sec.gov/about/offices/ofm.htm; or  
 
(3) Respondent may pay by certified check, bank cashier’s check, or United 
States postal money order, made payable to the Securities and Exchange 
Commission and hand-delivered or mailed to:  
 
Enterprise Services Center 
Accounts Receivable Branch 
HQ Bldg., Room 181, AMZ-341 
6500 South MacArthur Boulevard 
Oklahoma City, OK 73169 
 
Payments by check or money order must be accompanied by a cover letter identifying J.P. 
Morgan Securities LLC as the Respondent in these proceedings, and the file number of these 
proceedings; a copy of the cover letter and check or money order must be sent to Carolyn 
Welshhans, Associate Director, Division of Enforcement, Securities and Exchange Commission, 
100 F St., NE, Washington, DC 20549.   
 
D. Amounts ordered to be paid as civil money penalties pursuant to this Order shall be 
treated as penalties paid to the government for all purposes, including all tax purposes.  To 
preserve the deterrent effect of the civil penalty, Respondent agrees that in any Related Investor 
Action, it shall not argue that it is entitled to, nor shall it benefit by, offset or reduction of any 
award of compensatory damages by the amount of any part of Respondent’s payment of a civil 
penalty in this action ("Penalty Offset").  If the court in any Related Investor Action grants such a 
Penalty Offset, Respondent agrees that it shall, within 30 days after entry of a final order granting 
the Penalty Offset, notify the Commission's counsel in this action and pay the amount of the 
Penalty Offset to the Securities and Exchange Commission.  Such a payment shall not be deemed 
an additional civil penalty and shall not be deemed to change the amount of the civil penalty 
imposed in this proceeding.  For purposes of this paragraph, a "Related Investor Action" means a 
private damages action brought against Respondent by or on behalf of one or more investors based 

 
 8 
on substantially the same facts as alleged in the Order instituted by the Commission in this 
proceeding. 
 
 
 
 By the Commission. 
 
 
 
Vanessa A. Countryman 
        Secretary 
 
OCR text (19,423c · tika · 95% conf)
UNITED STATES OF AMERICA 

 Before the 

 SECURITIES AND EXCHANGE COMMISSION 

 

 

SECURITIES EXCHANGE ACT OF 1934 

Release No. 95367 / July 27, 2022 

 

INVESTMENT ADVISERS ACT OF 1940 

Release No. 6073 / July 27, 2022 
 

ADMINISTRATIVE PROCEEDING 

File No. 3-20936 

 

 

In the Matter of 

 

J.P. MORGAN  

SECURITIES LLC,  

 

Respondent. 

 

ORDER INSTITUTING ADMINISTRATIVE AND 

CEASE-AND-DESIST PROCEEDINGS, PURSUANT 

TO SECTIONS 15(b) AND 21C OF THE 

SECURITIES EXCHANGE ACT OF 1934 AND 

SECTIONS 203(e) AND 203(k) OF THE 

INVESTMENT ADVISERS ACT OF 1940, MAKING 

FINDINGS, AND IMPOSING REMEDIAL 

SANCTIONS AND A CEASE-AND-DESIST ORDER  

   

 

I. 
 

 The Securities and Exchange Commission (“Commission”) deems it appropriate and in the 

public interest that public administrative and cease-and-desist proceedings be, and hereby are, 

instituted pursuant to Sections 15(b) and 21C of the Securities Exchange Act of 1934 (“Exchange 

Act”) and Sections 203(e) and 203(k) of the Investment Advisers Act of 1940 (the 

“Advisers Act”), against J.P. Morgan Securities LLC (“Respondent” or “JPMS”).  

 

II. 
 

 In anticipation of the institution of these proceedings, Respondent has submitted an Offer 

of Settlement (the “Offer”) which the Commission has determined to accept.  Solely for the 

purpose of these proceedings and any other proceedings brought by or on behalf of the 

Commission, or to which the Commission is a party and without admitting or denying the findings 

herein, except as to the Commission’s jurisdiction over it and the subject matter of these 

proceedings, which are admitted, Respondent consents to the entry of this Order Instituting 

Administrative and Cease-and-Desist Proceedings, Pursuant to Sections 15(b) and 21C of the 

Securities Exchange Act of 1934 and Sections 203(e) and 203(k) of the Investment Advisers Act of 



 

 2 

1940, Making Findings, and Imposing Remedial Sanctions and a Cease-and-Desist Order 

(“Order”), as set forth below. 

III. 
 

 On the basis of this Order and Respondent’s Offer, the Commission finds that: 

 

Summary 
 

1. These proceedings arise out of JPMS’s failure to adequately develop and implement 

a written identity theft prevention program as required by Rule 201 of Regulation S-ID (17 C.F.R. § 

248.201). 

2. JPMS is a broker-dealer and investment adviser registered with the Commission. 

From at least January 1, 2017, through December 31, 2019 (the “Relevant Period”), JPMS violated 

Rule 201 of Regulation S-ID because its written identity theft prevention programs for the 

applicable lines of business (the “Programs”) failed to include reasonable policies and procedures to 

(i) identify relevant red flags for the covered accounts that JPMS offered or maintained, and 

incorporate those red flags into the Programs, (ii) respond appropriately to detected red flags to 

prevent and mitigate identity theft, and (iii) ensure that each Program was updated periodically to 

reflect changes in identity theft risks to customers. 

3. JPMS also violated Rule 201 of Regulation S-ID during the Relevant Period because 

it did not provide for the continued administration of its Programs by failing to (i) exercise 

appropriate and effective oversight of all service provider arrangements; and (ii) train staff under 

one of its lines of business, as necessary, to effectively implement the Program in 2017.   

Respondent 

 

 4.  J.P. Morgan Securities LLC is a Delaware limited liability company with its 

principal place of business in New York, New York.  It has been a broker-dealer registered with 

the Commission pursuant to Section 15(b) of the Exchange Act since December 13, 1985, and an 

investment adviser registered with the Commission pursuant to Section 203 of the Advisers Act 

since April 3, 1965.  It is a wholly-owned subsidiary of JPMorgan Chase & Co. (“JPMC”), a 

global financial services firm incorporated in Delaware and headquartered in New York, New 

York. 

 

Background 

 

5. During the Relevant Period, JPMS’s Programs failed to comply with the 

requirements of Regulation S-ID. 

6. Regulation S-ID requires financial institutions, including broker-dealers and 

investment advisers registered with the Commission that offer or maintain one or more covered 

accounts, to develop and implement a written identity theft prevention program “that is designed to 

detect, prevent, and mitigate identity theft” in connection with the opening of a covered account or 



 

 3 

any existing covered account.1  The program “must be appropriate to the size and complexity of the 

financial institution…and the nature and scope of its activities.”2 

7. Under Regulation S-ID, an identity theft prevention program must include 

reasonable policies and procedures to:  (i) identify relevant “red flags”3 for the covered accounts 

and incorporate them into the program; (ii) detect the red flags that have been incorporated into the 

program; (iii) respond appropriately to any red flags that are detected pursuant to the program; and 

(iv) ensure that the program is updated periodically to reflect changes in risks to customers and to 

the safety and soundness of the firm from identity theft.4   

8. A written identity theft prevention program may incorporate by reference policies 

outside of the program in order to satisfy the requirements of Regulation S-ID, but such 

incorporation by reference must be explicit.5 

9. With respect to the identification of relevant red flags, Regulation S-ID requires 

firms to consider several factors specific to the firm in order to identify red flags that are relevant to 

the firm’s business and the nature and scope of its activities, such as the types of covered accounts 

it offers or maintains, methods it provides to open covered accounts, methods it provides to access 

covered accounts, and its previous experiences with identity theft.6 

10. Appendix A to Regulation S-ID, which contains guidelines intended to assist firms 

in the formulation and maintenance of an identity theft prevention program that satisfies the 

requirements of Regulation S-ID, lists categories of red flags that a firm should consider 

incorporating in its program “as appropriate.”7  Supplement A to Appendix A further provides a 

non-comprehensive list of examples of red flags from each of these categories that the firm “may 

consider incorporating into its Program, whether singly or in combination…in connection with 

                                                 
1  17 C.F.R. § 248.201(d)(1).  The rule defines “identity theft” as a fraud committed or attempted using the 

identifying information of another person without authority.  17 C.F.R. § 248.201(b)(9). 

2  17 C.F.R. § 248.201(d)(1). 

3  “Red flags” are defined as “a pattern, practice, or specific activity that indicates the possible existence of 

identity theft.”  17 C.F.R. § 248.201(b)(10). 

4  17 C.F.R. § 248.201(d)(2)(i)-(iv). 

5  17 C.F.R. § 248.201 Appendix A, Section I. 

6  17 C.F.R. § 248.201, Appendix A, Section II(a). 

7  These categories are: (i) alerts, notifications, or warnings received from consumer reporting agencies; (ii) 

suspicious documents, such as documents that appear to have been altered or forged; (iii) suspicious 

personal identifying information, such as a suspicious address change; (iv) unusual use of, or other 

suspicious activity related to, a covered account; and (v) notice from customers, victims of identity theft, or 

law enforcement authorities.  17 C.F.R. § 248.201, Appendix A, Section II(c). 



 

 4 

covered accounts.”8  The firm must consider these examples of red flags and include in its identity 

theft prevention program those that are appropriate.9 

11. With respect to responding to detected red flags in order to prevent and mitigate 

identity theft, Regulation S-ID requires an identity theft prevention program to include policies and 

procedures that “provide for appropriate responses” to detected red flags “that are commensurate 

with the degree of risk posed.”10  In determining an appropriate response, a firm “should consider 

aggravating factors that may heighten the risk of identity theft, such as a data security incident that 

results in unauthorized access to a customer’s account records . . . or notice that a customer 

provided account information” to someone under false pretenses.11 

12. With respect to periodically updating a written identity theft prevention program, 

Appendix A provides that firms should consider factors such as: (i) the firm’s experiences with 

identity theft; (ii) changes in methods of identity theft; (iii) changes in methods to detect, prevent or 

mitigate identity theft; (iv) changes in the types of accounts offered or maintained; and (v) changes 

in the firm’s structure or service provider arrangements.12 

13. Regulation S-ID also requires firms to provide for the continued administration of 

the written identity theft prevention program by training staff, as necessary, to effectively 

implement the program, and by exercising appropriate and effective oversight of service provider 

arrangements.13  With respect to the oversight of service provider arrangements in connection with 

one or more covered accounts, the firm should take steps to ensure that the activity of the service 

provider is conducted in accordance with reasonable policies and procedures designed to detect, 

prevent and mitigate the risk of identity theft.14 

 

                                          JPMS’s Identity Theft Prevention Program 

14. JPMS is a registered broker-dealer and investment adviser that offers and maintains 

“covered accounts,” which are accounts offered or maintained primarily for personal, family, or 

household purposes that involve or are designed to permit multiple payments or transactions.15    

Accordingly, JPMS is required to develop and implement a written identity theft prevention 

program in accordance with the requirements of Rule 201 of Regulation S-ID.   

                                                 
8  17 C.F.R. § 248.201, Appendix A, Supplement A. 

9  17 C.F.R. § 248.201(f). 

10  17 C.F.R. § 248.201(d)(2)(iii). 

11  17 C.F.R. § 248.201, Appendix A, Section IV. 

12  17 C.F.R. § 248.201, Appendix A, Section V. 

13  17 C.F.R. § 248.201(e)(3)-(4). 

14  17 C.F.R. § 248.201, Appendix A, Section VI(c). 

15  17 C.F.R. § 248.201(b)(3). 



 

 5 

15. During the Relevant Period, JPMS offered covered accounts under two lines of 

business, each of which maintained an identity theft prevention program.   

16. During the Relevant Period, the Programs contained substantial deficiencies and 

thus failed to comply with the requirements of Regulation S-ID.   

17. During the Relevant Period, neither Program incorporated policies or procedures 

that described how identity theft red flags were to be identified or appropriately responded to once 

they were detected.  Rather, both Programs merely (i) restated the general legal requirements (such 

as “identify relevant red flags” and “respond appropriately to any red flags that are detected to 

prevent and mitigate identity theft”), (ii) listed verbatim all the illustrative examples of identity 

theft red flags provided in Appendix A to Regulation S-ID, and (iii) listed various firmwide 

policies and business procedures that were incorporated into the Programs.  None of the 

incorporated policies and procedures listed in either Program explained how JPMS was to identify 

any of the enumerated red flags or to respond to the red flags in order to prevent and mitigate 

identity theft.  Although JPMS did take actions to detect and respond to potential and actual 

incidents of identity theft, the procedures describing those actions were not included or 

incorporated by reference in either Program. 

18. During the Relevant Period, neither Program incorporated reasonable policies or 

procedures to ensure the Programs were updated periodically, including identifying any new red 

flags based on customers’ actual experiences or changes in methodology.  As a result, JPMS failed 

to update its procedures, or provide in the Programs a written process for determining whether any 

such updates were necessary as a result of JPMS’s own experiences with identity theft or changes 

in the manner in which brokerage accounts could be opened.   

19. During the Relevant Period, JPMS failed to exercise appropriate and effective 

oversight of all of its service provider arrangements under the Programs.  The Programs required 

JPMS (i) to assess all service providers annually and (ii) to ensure that the service providers that 

possessed customer information and were in a position to identify red flags had language in their 

contracts requiring those service providers to detect identity theft red flags and either report the red 

flags to JPMC or respond to the red flags themselves.  JPMS failed to satisfy this requirement 

because it did not follow its own policies and procedures to assess all service providers annually 

and to ensure that all the relevant service provider agreements had the required red flag contractual 

language.  Accordingly, JPMS did not appropriately monitor all of its service providers to ensure 

that their activities were being conducted in accordance with policies and procedures designed to 

detect, prevent and mitigate identity theft. 

20. From at least January 1, 2017 through December 31, 2017, JPMS failed to provide 

any identity theft prevention program-specific training to staff as necessary to effectively 

implement one of the Programs.     



 

 6 

Violation 

21. As a result of the conduct described above, Respondent willfully16 violated Rule 

201 of Regulation S-ID (17 C.F.R. § 248.201), which requires registered broker-dealers and 

investment advisers that offer or maintain covered accounts to, among other things, develop and 

implement a written identity theft prevention program that is designed to detect, prevent, and 

mitigate identity theft in connection with the opening of a covered account or any existing 

covered account, and provide for the continued administration of the identity theft prevention 

program. 

JPMS’s Remedial Efforts 

22. JPMS has undertaken substantial remedial acts, including auditing and revising its 

identity theft prevention program.   

23. Among other things, JPMS adopted improved applicable policies and procedures 

for identifying, detecting, and responding to red flags, and periodically updating its program.  

JPMS also revised its program to provide greater oversight over JPMS’s service provider 

arrangements and to improve training of staff.  JPMS, in addition, made detailed presentations to 

the Commission’s staff.   

24. In determining to accept the Offer, the Commission considered the remedial acts 

undertaken by Respondent.  

IV. 

 In view of the foregoing, the Commission deems it appropriate and in the public interest to 

impose the sanctions agreed to in Respondent’s Offer. 

 

 Accordingly, pursuant to Sections 15(b) and 21C of the Exchange Act and Sections 203(e) 

and 203(k) of the Advisers Act, it is hereby ORDERED that: 

 

 A. Respondent cease and desist from committing or causing any violations and any 

future violations of Rule 201 of Regulation S-ID (17 C.F.R. § 248.201).   

 

                                                 
16  “Willfully,” for purposes of imposing relief under Section 15(b) of the Exchange Act and Section 203(e) of 

the Advisers Act, “‘means no more than that the person charged with the duty knows what he is 

doing.’”  Wonsover v. SEC, 205 F.3d 408, 414 (D.C. Cir. 2000) (quoting Hughes v. SEC, 174 F.2d 969, 977 

(D.C. Cir. 1949)).  There is no requirement that the actor “also be aware that he is violating one of the Rules 

or Acts.”  Tager v. SEC, 344 F.2d 5, 8 (2d Cir. 1965).  The decision in The Robare Group, Ltd. v. SEC, which 

construed the term “willfully” for purposes of a differently structured statutory provision, does not alter that 

standard.  922 F.3d 468, 478-79 (D.C. Cir. 2019) (setting forth the showing required to establish that a person 

has “willfully omit[ted]” material information from a required disclosure in violation of Section 207 of the 

Advisers Act). 

  



 

 7 

B. Respondent is censured.   

  

C. Respondent shall, within 30 days of the entry of this Order, pay a civil money 

penalty in the amount of $1,200,000 to the Securities and Exchange Commission for transfer to the 

general fund of the United States Treasury, subject to Exchange Act Section 21F(g)(3). If timely 

payment is not made, additional interest shall accrue pursuant to 31 U.S.C. §3717.   

 

Payment must be made in one of the following ways:   

 

(1) Respondent may transmit payment electronically to the Commission, which 

will provide detailed ACH transfer/Fedwire instructions upon request;  

 

(2) Respondent may make direct payment from a bank account via Pay.gov 

through the Commission website at 

http://www.sec.gov/about/offices/ofm.htm; or  

 

(3) Respondent may pay by certified check, bank cashier’s check, or United 

States postal money order, made payable to the Securities and Exchange 

Commission and hand-delivered or mailed to:  

 

Enterprise Services Center 

Accounts Receivable Branch 

HQ Bldg., Room 181, AMZ-341 

6500 South MacArthur Boulevard 

Oklahoma City, OK 73169 

 

Payments by check or money order must be accompanied by a cover letter identifying J.P. 

Morgan Securities LLC as the Respondent in these proceedings, and the file number of these 

proceedings; a copy of the cover letter and check or money order must be sent to Carolyn 

Welshhans, Associate Director, Division of Enforcement, Securities and Exchange Commission, 

100 F St., NE, Washington, DC 20549.   

 

D. Amounts ordered to be paid as civil money penalties pursuant to this Order shall be 

treated as penalties paid to the government for all purposes, including all tax purposes.  To 

preserve the deterrent effect of the civil penalty, Respondent agrees that in any Related Investor 

Action, it shall not argue that it is entitled to, nor shall it benefit by, offset or reduction of any 

award of compensatory damages by the amount of any part of Respondent’s payment of a civil 

penalty in this action ("Penalty Offset").  If the court in any Related Investor Action grants such a 

Penalty Offset, Respondent agrees that it shall, within 30 days after entry of a final order granting 

the Penalty Offset, notify the Commission's counsel in this action and pay the amount of the 

Penalty Offset to the Securities and Exchange Commission.  Such a payment shall not be deemed 

an additional civil penalty and shall not be deemed to change the amount of the civil penalty 

imposed in this proceeding.  For purposes of this paragraph, a "Related Investor Action" means a 

private damages action brought against Respondent by or on behalf of one or more investors based 

http://www.sec.gov/about/offices/ofm.htm


 

 8 

on substantially the same facts as alleged in the Order instituted by the Commission in this 

proceeding. 

 

 

 

 By the Commission. 

 

 

 

Vanessa A. Countryman 

        Secretary