Scrutineer · By framework
GLBA compliance software for the FTC Safeguards Rule and GLBA requirements
GLBA does not have one rulebook. Which regulator writes your security rule decides whether MFA and annual penetration testing are mandatory or merely advisable.
Scrutineer maps your controls to the GLBA rule that actually applies to you, and keeps the proof dated, so an examiner sees a running programme instead of a binder.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with GLBA compliance software
The first question is which GLBA rule you are actually under
GLBA section 505(a) hands enforcement to whichever agency already supervises you, and those agencies wrote different rules. A mortgage broker is under the prescriptive FTC Safeguards Rule, with named MFA and penetration testing duties. A state member bank of the same size is under the interagency guidelines, which set risk-based objectives and name almost no specific controls. Scrutineer starts by pinning your entity type to the right rule text, because a checklist built from the wrong one is wasted work.
Most of what the Safeguards Rule asks for is ordinary control evidence
A qualified individual, a written risk assessment, access controls, encryption, MFA, change management, disposal, service provider oversight, an incident response plan and an annual report to the board. That is the same evidence base a SOC 2 or ISO 27001 programme already produces. Scrutineer maps your existing controls to 16 CFR 314.4 clause by clause so the work counts once and reports many times.
Evidence dated across the period, because an examiner asks how long it held
A screenshot proves a setting today. An examiner asks who had access last quarter, when the risk assessment was last refreshed, whether the leaver was removed and whether your penetration test actually happened inside the year. Scrutineer pulls that proof from your identity, cloud and ticketing systems on a schedule and timestamps it, so the record shows operation over time rather than a tidy afternoon.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Identifies which GLBA security rule governs you, and maps your controls to that rule text rather than a generic checklist
- Maps your control set to 16 CFR 314.4 clause by clause, including the elements added in the 2021 amendments
- Tracks the MFA requirement across every system holding customer information, and flags the ones still outside it
- Holds the dated written risk assessment the Safeguards Rule requires in writing, with its review history
- Keeps the annual penetration test and the semiannual vulnerability assessments on a calendar, with the reports attached
- Runs the periodic access review that evidences limiting access to authorized users, with the joiner and leaver record behind it
- Scores and monitors your service providers, which is the Safeguards Rule duty most often left as an unsigned contract clause
- Assembles the annual written report to your board or governing body, from evidence rather than from memory
- Runs the same evidence base against SOC 2, ISO 27001, NYDFS Part 500 and PCI DSS, so a financial institution files once
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Scope reference
Which GLBA security rule actually applies to you, and how the requirements differ
Almost every published GLBA checklist is written as though GLBA imposes one uniform set of security requirements. It does not. Section 505(a) of the Act assigns enforcement to whichever agency already supervises you, and those agencies wrote genuinely different rules. Multi-factor authentication and annual penetration testing are named obligations under the FTC rule and are absent from the banking guidelines. The breach notification clocks differ too. Find your row before you build a control list.
| Your institution type | Who writes and enforces your GLBA security rule | Rule text | Are specific controls named in the rule? | Breach notification duty and clock |
|---|---|---|---|---|
| Non-bank financial institutions: mortgage lenders and brokers, auto dealers that extend or arrange credit, payday lenders, finance companies, account servicers, check cashers, wire transferors, collection agencies, credit counselors, tax preparation firms, non-federally insured credit unions, investment advisers not required to register with the SEC, and finders | Federal Trade Commission | Safeguards Rule, 16 CFR Part 314 | Yes, and this is the most prescriptive of the GLBA rules. MFA, encryption in transit and at rest, annual penetration testing or continuous monitoring, semiannual vulnerability assessments, a named qualified individual, a written risk assessment and an annual report to the board. Compliance date for these provisions was June 9, 2023. | Notify the FTC as soon as possible and no later than 30 days after discovery, where unencrypted customer information of at least 500 consumers was acquired without authorization. In force since May 13, 2024. |
| National banks, federal savings associations and federal branches | Office of the Comptroller of the Currency | Interagency Guidelines Establishing Information Security Standards, 12 CFR Part 30 Appendix B | No. The guidelines set risk-based objectives and name almost no specific technology. There is no MFA mandate and no penetration testing mandate in the text. | Customer notice under the 2005 interagency response programme guidance, on a reasonable-time standard rather than a fixed consumer count. |
| State non-member banks and state savings associations | Federal Deposit Insurance Corporation | 12 CFR Part 364 Appendix B | No. Same interagency guidelines text, issued under the FDIC part. | Same interagency response programme guidance. |
| State member banks, bank holding companies and their non-bank subsidiaries | Federal Reserve Board | 12 CFR Part 208 Appendix D-2 | No. Same interagency guidelines text, issued under the Board parts. | Same interagency response programme guidance. |
| Federally insured credit unions | National Credit Union Administration | 12 CFR Part 748 Appendix A, Guidelines for Safeguarding Member Information | No. Risk-based guidelines rather than a named control list. | Member notice under the NCUA response programme guidance at 12 CFR Part 748 Appendix B. |
| Broker-dealers, registered investment advisers, investment companies and transfer agents | Securities and Exchange Commission | Regulation S-P, 17 CFR Part 248 | Partly. The 2024 amendments name a written incident response programme and service provider oversight, but do not prescribe specific technical controls the way the FTC rule does. | Notify affected individuals as soon as practicable and no later than 30 days after becoming aware. Compliance from December 3, 2025 for larger entities and June 3, 2026 for smaller entities. |
| Title IV colleges, universities and their third-party servicers | Department of Education, applying the FTC rule | 16 CFR Part 314, incorporated through your Program Participation Agreement and the SAIG agreement | Yes, identical to the FTC row. A university is held to the same rule text as a mortgage broker, which surprises most campus IT teams. | Same as the FTC row. In addition, a compliance failure is written up as a finding in your annual Federal Single Audit and referred to the FTC and the Federal Student Aid Cybersecurity Team. |
| Insurers, insurance agencies and producers | Your state insurance commissioner | State law. In most states a version of the NAIC Insurance Data Security Model Law, model #668. New York insurers sit under NYDFS Part 500 instead. | Varies by state. The model law names a written information security programme, a risk assessment and board oversight, and is closer to the FTC rule than to the banking guidelines. | Varies by state. The model law text calls for notice to the commissioner within 72 hours of determining a cybersecurity event occurred. |
Citations are to the current rule texts as at August 2026. Published sources disagree on how many jurisdictions have adopted the NAIC model law: the NAIC implementation map dated July 4, 2026 shows 28 adopting jurisdictions plus one pending, while several commentaries still cite 25, so confirm your own state directly with your commissioner. Enforcement assignment follows GLBA section 505(a) and turns on your charter and registrations rather than on what your business feels like, so an entity with more than one registration can sit under more than one row. Scrutineer prepares and maintains control evidence. It does not certify compliance, and no vendor or third party can.
Good questions
Questions about GLBA compliance software
Keep reading
Guides that go deeper on GLBA and financial services controls
What is GLBA compliance and who must comply
The thirteen categories of business the FTC treats as financial institutions, and the three-question test for whether you are covered.
Read the guideThe FTC Safeguards Rule explained
What the nine required elements of 16 CFR 314.4 ask for in practice, and where teams usually fall short.
Read the guideIT general controls explained
Access, change management, program development and operations, and the evidence sampled in each.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification