There are several issues to deal with here.
1. timing- it has been a year since the incident.
2. authorization- was the person granted authorization to use the card.
1. technically, a Reg E complaint should have been filed when you were verbally notified that the customer had charges taken that weren't hers. Since it wasn't filed you are probably going to be out of compliance for that. Why did she wait so long to contact you? because she was waiting on the police? Either way you should probably reimburse her.
2. I don't think a user who is granted authorization to use a card can then extend the authorization to a third party. If the story is true, she should have a beef with her BF as well.