Two Democratic Senators have pushed the brokerage industry’s self regulator to require firms to give customers the ability to lock their accounts to help fight fraud.
Senators Elizabeth Warren (Massachusetts) and Ron Wyden (Oregon) warned the Financial Industry Regulatory Authority that their reviews of firms’ policies and practices had uncovered “a deeply concerning lack of standardized, consumer-controlled protections across the industry.”
In a letter dated August 20, the lawmakers, who are ranking minority members on the Committee on Finance, asked Finra Chief Executive Robert Cook to “take immediate regulatory action” to address the growing threat of fraud perpetrated through the Automated Customer Account Transfer Service, which allows clients to move assets from one brokerage to another.
ACATS, which are managed by the National Securities Clearing Corporation, allows customers to move funds, including stocks, bonds and cash, from one firm to another. Fraudsters can exploit the system by using stolen personal information to open an account in a victim’s name and then initiate a transfer from the victim’s legitimate account.
“[C]riminals are exploiting the complete lack of an outbound verification step by the account holder,” Warren and Wyden wrote in the letter, earlier reported by The New York Times.
In a press release about the letter, Wyden included a chart, shown below, based on his review of major brokerage firms, which showed that: “Only a few companies offer a way for consumers to protect their accounts.”
Finra recommends that firms notify customers before transferring assets but does not have a requirement in place, the lawmakers said. Brokerage firms typically have one day to validate or object to a transfer and three business days to complete it.
Some firms do not notify customers when an outgoing transfer has been initiated. Following inquiries from lawmakers, Interactive Brokers, Robinhood and Webull said they would develop self-service transfer locks, according to the letter.
A Wells Fargo spokesperson confirmed the information on the chart about the firm but did not address questions about any planned changes.
A Citi spokesperson declined to comment.
A Morgan Stanley spokesperson did not respond to questions about the chart and potential changes.
Bank of America spokespersons noted that the lock question did not pertain to advisor-led accounts and said in a statement that: “Merrill Edge customers can put a restriction on their account that blocks transfers by calling customer service.”
A Schwab spokesperson said the firm would be adding passkey authentication later this year and “additional capabilities designed to give clients greater visibility into and control over outbound account transfers.”
“Safeguarding our clients’ assets and information is our highest priority,” the Schwab spokesperson said.
WHAT ABOUT RAYMOND JAMES ACCOUNTS?
Is this really a problem? Been an advisor for 30+ yrs and I have never seen or heard an an account being stolen through ACATs – ever!! I’d think the issue should be the firm who allows a fraudulent account to be open. How does one open a fake account when you have Compliance all up FA’s arses about patriot act documentation. How about KYC procedures? It’s not an ACAT issue it’s idiot firms allowing identity theft to occur.
Facts Only
* Senators Elizabeth Warren (Massachusetts) and Ron Wyden (Oregon) advocated for regulatory action against fraud in ACATS.
* Lawmakers cited reviews of firm policies that found a lack of standardized, consumer-controlled protections across the industry.
* The focus was on the threat of fraud perpetrated through the Automated Customer Account Transfer Service (ACATS).
* Fraudsters exploit ACATS by using stolen personal information to open accounts and initiate transfers without an outbound verification step from the account holder.
* Finra recommends that firms notify customers before transferring assets, but this is not a regulatory requirement.
* Brokerage firms typically have one day to validate or object to a transfer and three business days to complete it.
* Interactive Brokers, Robinhood, and Webull stated they would develop self-service transfer locks.
* Wells Fargo confirmed information on a chart but did not address planned changes.
* Schwab announced plans for passkey authentication and additional capabilities for client control over outbound transfers.
* Bank of America noted that Merrill Edge customers can restrict transfers by calling customer service.
Executive Summary
Democratic Senators Elizabeth Warren and Ron Wyden urged the Financial Industry Regulatory Authority (Finra) to take immediate regulatory action regarding fraud in the Automated Customer Account Transfer Service (ACATS). The lawmakers cited reviews of brokerage firm policies that revealed a lack of standardized, consumer-controlled protections across the industry. They specifically highlighted that criminals exploit ACATS by using stolen personal information to open fraudulent accounts and initiate transfers from legitimate accounts without outbound verification steps.
The lawmakers noted that while Finra recommends firms notify customers before transferring assets, there is no mandate in place, and brokerage firms typically have one day for validation and three business days for completion of transfers. In response to the inquiries, some firms, including Interactive Brokers, Robinhood, and Webull, stated they would develop self-service transfer locks. Other firms provided varying responses regarding account controls; Wells Fargo confirmed information related to a chart but did not address planned changes, while Schwab announced plans to implement passkey authentication and additional controls for outbound transfers.
Full Take
The narrative frames the issue as a systemic failure of industry-wide consumer protection, where the lack of standardized controls creates an exploitable vulnerability in the ACATS mechanism for asset movement. The division between the lawmakers' focus on system-wide standards and the firms' focus on individual account security reveals a tension between regulatory oversight and operational implementation. The dissenting viewpoint introduces a crucial layer: the argument that the primary failure lies not in the transfer mechanism itself, but in the initial identity verification (KYC) procedures employed by the brokerage firms themselves. This suggests an underlying pattern where technical safeguards are insufficient if foundational identity controls are lax.
The reaction from financial institutions—offering piecemeal solutions like self-service locks or specific customer service restrictions—suggests a reluctance to accept full regulatory responsibility for structural changes, preferring mitigating tactical risks. The implication for cognitive sovereignty is that true protection requires moving beyond reactive fixes toward mandatory, standardized control mechanisms that treat account movement as a protected consumer right rather than an operational transaction subject to variable firm policies.
The pattern observed involves deflection: when confronted with broad systemic failures, institutions offer localized assurances. This suggests the potential for regulatory capture or operational inertia where incremental changes are favored over transformative structural reform. The question remains: if identity theft is the root cause, does focusing only on ACATS transfers successfully address the upstream problem of account onboarding integrity? What mechanisms are required to enforce standardized identity protocols across disparate brokerage operations effectively?
