FTC Safeguards Rule Requirements and Exemptions
The FTC Safeguards Rule requires non-bank financial institutions, including auto dealers, tax preparers and mortgage brokers, to run a written information security program with nine specific elements. Here is what each element requires, exactly what the fewer than 5,000 consumers exemption covers, and the breach notification duty in force since May 2024.
By the Scrutineer team
August 2026 · 9 min read
Try it while you read
No account, nothing to install.
Pick a framework or a vendor and run a scrutiny. You get per-control statuses, the evidence behind each one, and a prioritized gap list.
›
Illustrative sample · not an audit attestation
Last updated August 2026. The FTC Safeguards Rule (16 CFR Part 314) requires non-bank financial institutions to build, document and maintain a written information security program with nine specific elements, run by one named person. It applies far beyond banks: auto dealerships, tax preparers, mortgage brokers, collection agencies and investment advisers are all covered. Firms holding customer information on fewer than 5,000 consumers are excused from four specific provisions, not from the rule.
This guide covers who counts as a financial institution, what each of the nine elements requires, exactly what the small-firm exemption does and does not cover, and the breach notification duty that took effect in May 2024.
What is the FTC Safeguards Rule?
The Safeguards Rule implements the security half of the Gramm-Leach-Bliley Act. GLBA told financial institutions to protect customer information; the Safeguards Rule, codified at 16 CFR Part 314, says what that means in practice for the institutions the Federal Trade Commission supervises. Banks and credit unions answer to their own prudential regulators instead, under the Interagency Guidelines Establishing Information Security Standards, which is why the Rule is often described as covering non-bank financial institutions. The two texts aim at the same objectives, but they are not interchangeable: the FTC rule names multi-factor authentication and annual penetration testing as obligations, and the interagency guidelines name neither, setting risk-based objectives instead. Firms that sit near the line, or that hold both a state license and an FTC-supervised business, generally map once and evidence once rather than running two programs, which is what GLBA compliance software is for. That is the whole argument for treating this as one financial services compliance software problem instead of a Safeguards Rule project.
The version in force today is the substantially rewritten one. The FTC amended the Rule in 2021, replacing a short and largely principles-based text with prescriptive requirements, and full compliance became mandatory on June 9, 2023. A further amendment adding breach notification took effect May 13, 2024. If you are reading guidance written before 2023, it describes a rule that no longer exists.
Who does the FTC Safeguards Rule apply to?
It applies to any business "significantly engaged" in an activity that is financial in nature, that is not otherwise regulated by a federal banking agency. The phrase catches a lot of companies that do not think of themselves as financial at all. The Rule itself lists examples, and these are the ones that surprise people:
- Automobile dealerships that arrange financing or lease vehicles on a nonoperating basis for longer than 90 days. This is the single largest group brought in by the 2021 amendments.
- Tax preparation firms and accountants who prepare returns for customers.
- Mortgage brokers and mortgage lenders, plus real estate settlement service providers.
- Collection agencies and businesses that regularly wire money to and from consumers.
- Investment advisers not required to register with the SEC, and credit counseling services.
- Retailers that issue their own credit cards, check cashers, check printers and personal property or real estate appraisers.
- Finders, meaning businesses that bring together buyers and sellers of a financial product or service. This category was added in 2021 and is broad enough to catch lead generators and comparison sites.
The obligation attaches to customer information, defined as any record containing nonpublic personal information about a customer, in any form, handled or maintained by you or on your behalf. The "on your behalf" clause matters: information sitting with a vendor is still yours to protect.
What are the nine elements of the information security program?
Section 314.4 lists nine elements, lettered (a) through (i). This table is the part worth keeping, because most published checklists paraphrase them into a different order and drop the paragraph letters you need when someone asks you to evidence a specific one.
| Element | What it requires | What proves it |
|---|---|---|
| (a) Qualified Individual | Designate one qualified individual to oversee, implement and enforce the program. They may be an employee, an affiliate's employee, or supplied by a service provider, but you keep responsibility either way. | A written designation naming a person, not a committee or a department. |
| (b) Written risk assessment | A documented assessment identifying reasonably foreseeable internal and external threats to customer information, with criteria for evaluating and categorizing risk and for assessing the adequacy of your safeguards. Reassess periodically. | The dated assessment plus the criteria it used. Verbal or implied risk assessments do not satisfy this. |
| (c) Safeguards | Eight named controls: access controls, data and asset inventory, encryption of customer information in transit and at rest, secure development practices, MFA for anyone accessing information systems, secure disposal within two years of last use, change management, and logging of authorized user activity. | Configuration evidence for each, plus written approval from the Qualified Individual for any compensating control used in place of encryption. |
| (d) Testing and monitoring | Continuous monitoring of systems, or, if you do not have that, annual penetration testing plus vulnerability assessments at least every six months and after material changes. | Pen test reports and dated scan records, with remediation tracked. The six month cadence is the part most often missed. |
| (e) Personnel | Security awareness training for staff, qualified security personnel, ongoing updates for those personnel, and verification that they keep current knowledge. | Training completion records and evidence of how security staff maintain currency. |
| (f) Service providers | Select providers capable of appropriate safeguards, require those safeguards by contract, and periodically assess them based on the risk they present. | Due diligence records, executed contract security clauses, and dated periodic reassessments. |
| (g) Program evaluation | Adjust the program in light of testing results, changes to operations or business arrangements, and anything else that materially affects it. | A change history showing the program actually moved in response to findings. |
| (h) Incident response plan | A written plan covering goals, internal processes, roles and responsibilities, communications, remediation, documentation and post-incident revision. | The written plan, and evidence it was revised after any incident. |
| (i) Annual board report | The Qualified Individual reports in writing, at least annually, to the board or equivalent governing body on program status, compliance and material matters. | The dated written report and the minute recording that the board received it. |
Element (c) carries most of the real work, and its data inventory requirement is the one firms consistently underestimate. You cannot encrypt, control access to or securely dispose of customer information you have not located, and in most businesses it has quietly spread into shared drives, email archives, ticketing systems and spreadsheets nobody owns. Before writing safeguards, it is worth running a discovery pass to find where personal data actually lives across your systems, because the disposal clock in 314.4(c)(6) runs two years from last use whether or not you know the records exist.
What is the fewer than 5,000 consumers exemption?
Section 314.6 is short and precise, and it is narrower than the shorthand suggests. A financial institution that maintains customer information concerning fewer than 5,000 consumers is exempt from four things only:
- 314.4(b)(1), the requirement that the risk assessment be written and contain the specified criteria. You still have to assess risk; you just are not required to document it in that prescribed form.
- 314.4(d)(2), the annual penetration testing and semiannual vulnerability assessment requirement.
- 314.4(h), the written incident response plan.
- 314.4(i), the annual written report to the board.
Everything else still applies in full. A twelve-person mortgage brokerage with 900 customers still owes a Qualified Individual, access controls, an asset inventory, encryption in transit and at rest, multi-factor authentication, secure disposal, change management, logging, staff training, service provider oversight and the breach notification duty. The exemption removes the four heaviest documentation and testing burdens. It does not make you unregulated, and it is counted on consumers whose information you maintain, not customers you currently serve, so old records still count.
What is the FTC Safeguards Rule breach notification requirement?
Since May 13, 2024, a covered financial institution must notify the FTC as soon as possible, and no later than 30 days after discovery, of a notification event affecting 500 or more consumers. A notification event means acquisition of unencrypted customer information without the authorization of the individual it relates to.
Two details decide whether this bites. First, the notice goes to the FTC through its online form and the substance is published in a public database, so this is a disclosure obligation with reputational consequences, not a quiet filing. Second, the trigger is unencrypted information, which makes element (c)'s encryption requirement do double duty: encrypted data that is properly keyed does not produce a notification event. That is the strongest practical argument for encrypting at rest even where a compensating control would technically satisfy the Rule.
FTC Safeguards Rule for tax preparers
Tax preparation firms are explicitly named as financial institutions, and the IRS has folded the requirement into its own expectations: a written information security plan, commonly called a WISP, is required to obtain or renew a PTIN, and the IRS publishes a sample template through the Security Summit. Most single-office tax practices fall under the 5,000 consumer threshold, so they are exempt from the four provisions above, which is why the IRS sample plan is shorter than a full 314.4 program.
The gap worth naming: the IRS template is a starting document, not a compliance program. It gives you element (a) and a version of (b), but it does not itself deliver MFA, an asset inventory, secure disposal, vendor oversight or logging, all of which apply to a two-person practice exactly as they do to a national chain. A firm that downloads the template, signs it and files it away has a document, not a program, and the FTC has been clear that it evaluates what you actually do.
What does an FTC Safeguards Rule checklist look like?
A useful checklist is generated from your own systems rather than downloaded, but the sequence that works is consistent. Name the Qualified Individual first, because every other item needs an owner. Inventory where customer information lives, including with vendors, since the risk assessment is meaningless without it. Run the risk assessment against that inventory. Implement the eight safeguards in 314.4(c), treating MFA and encryption as non-negotiable because both also reduce your breach notification exposure. Stand up the testing cadence, the training, and the vendor due diligence file. Write the incident response plan and the board reporting rhythm if you are over the threshold. Then set a review date, because element (g) requires the program to change as your business does.
How the Safeguards Rule overlaps other regimes
Almost none of this work is single-purpose. The access controls, encryption, MFA, asset inventory, vendor due diligence and incident response plan that 314.4 requires are the same controls tested under the NYDFS cybersecurity regulation if you also hold a New York license, and the same ones a SOC 2 auditor samples under the common criteria. The evidence differs in who reads it, not in what it is.
That overlap is worth engineering deliberately. Mapping one control set to every regime you answer to, and pointing each at the same dated evidence, is what makes the second and third obligation cheap rather than a second full program. The mechanics of doing that well are covered in our guide to the user access review process and in how to conduct a cybersecurity risk assessment, both of which produce artifacts the Safeguards Rule, NYDFS and SOC 2 all accept.
If you want the control mapping and evidence collection handled continuously rather than rebuilt each year, that is what security compliance software is for. Scrutineer maps your controls once and keeps the proof current; your own Qualified Individual still owns the program and signs for it.
See Scrutineer scrutinize your posture
Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.