Checklist · Compliance
FTC Safeguards Rule Checklist
If your firm handles customers’ financial information — and “financial institution” under GLBA means far more than banks — the Safeguards Rule requires a written security program. Here are its nine required elements — §314.4(a) through (i) — in plain English.
The checklist
The rule has been fully enforceable since June 2023. These are the controls a regulator expects to see running.
How to use it. Score each line as in place, partly in place, or missing, and resist the urge to round up. The Safeguards Rule turns on documentation: a control you perform but never wrote down is hard to evidence when the FTC asks, and “we always do that” is not a written information security program. The lines businesses most often miss are the named Qualified Individual, the written risk assessment, and the service-provider oversight — none of which are technical, and all of which are the first things requested.
Who this applies to. Wider than most people expect. The rule treats a long list of businesses as financial institutions, including tax preparers, accountants, mortgage brokers, auto dealers, collection agencies and finders. If you handle customer financial information and are not sure whether you are in scope, that question is worth answering before someone answers it for you — the free 30-minute assessment covers it.
The nine required elements — 16 CFR §314.4(a)–(i)
- (a) Designate a Qualified Individual to implement and supervise the security program. They can be your employee or work for a service provider — but the accountability stays with you.
- (b) Conduct a written risk assessment, with criteria for evaluating the risks it identifies, and reassess it periodically.
- (c) Design and implement safeguards to control those risks. The Rule names eight: access controls, a data inventory, encryption at rest and in transit, secure development and app assessment, multi-factor authentication, secure disposal (generally within two years of last use), change management, and logging of authorized-user activity.
- (d) Regularly monitor and test the safeguards — either continuous monitoring, or annual penetration testing plus vulnerability assessments including system-wide scans every six months.
- (e) Train your staff, with security-awareness training plus specialized training for anyone running the program.
- (f) Monitor your service providers — select them for capability, write your security expectations into the contract, and reassess them periodically.
- (g) Keep the program current as operations, threats and personnel change. It is a living document, not a one-time file.
- (h) Create a written incident-response plan covering goals, internal processes, roles and decision authority, communications, remediation, documentation, and a post-mortem that feeds back into the program.
- (i) Have the Qualified Individual report in writing to the board or governing body at least annually — or, with no board, to a senior officer accountable for the program.
Don't forget
- §314.4(j): report a notification event — unauthorized acquisition of at least 500 consumers' unencrypted information — to the FTC as soon as possible and no later than 30 days after discovery.
- Firms holding customer information on fewer than 5,000 consumers are exempt from some provisions, not from the Rule.
- If you're a tax firm, your IRS WISP and this rule are largely the same project done once.
This checklist is a summary, not legal advice — the full rule governs. We operate the technical backbone the program stands on. See how →