Scrutineer.ai

Scrutineer · By framework

GLBA compliance software for the FTC Safeguards Rule and GLBA requirements

GLBA does not have one rulebook. Which regulator writes your security rule decides whether MFA and annual penetration testing are mandatory or merely advisable.

Scrutineer maps your controls to the GLBA rule that actually applies to you, and keeps the proof dated, so an examiner sees a running programme instead of a binder.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with GLBA compliance software

The first question is which GLBA rule you are actually under

GLBA section 505(a) hands enforcement to whichever agency already supervises you, and those agencies wrote different rules. A mortgage broker is under the prescriptive FTC Safeguards Rule, with named MFA and penetration testing duties. A state member bank of the same size is under the interagency guidelines, which set risk-based objectives and name almost no specific controls. Scrutineer starts by pinning your entity type to the right rule text, because a checklist built from the wrong one is wasted work.

Most of what the Safeguards Rule asks for is ordinary control evidence

A qualified individual, a written risk assessment, access controls, encryption, MFA, change management, disposal, service provider oversight, an incident response plan and an annual report to the board. That is the same evidence base a SOC 2 or ISO 27001 programme already produces. Scrutineer maps your existing controls to 16 CFR 314.4 clause by clause so the work counts once and reports many times.

Evidence dated across the period, because an examiner asks how long it held

A screenshot proves a setting today. An examiner asks who had access last quarter, when the risk assessment was last refreshed, whether the leaver was removed and whether your penetration test actually happened inside the year. Scrutineer pulls that proof from your identity, cloud and ticketing systems on a schedule and timestamps it, so the record shows operation over time rather than a tidy afternoon.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Identifies which GLBA security rule governs you, and maps your controls to that rule text rather than a generic checklist
  • Maps your control set to 16 CFR 314.4 clause by clause, including the elements added in the 2021 amendments
  • Tracks the MFA requirement across every system holding customer information, and flags the ones still outside it
  • Holds the dated written risk assessment the Safeguards Rule requires in writing, with its review history
  • Keeps the annual penetration test and the semiannual vulnerability assessments on a calendar, with the reports attached
  • Runs the periodic access review that evidences limiting access to authorized users, with the joiner and leaver record behind it
  • Scores and monitors your service providers, which is the Safeguards Rule duty most often left as an unsigned contract clause
  • Assembles the annual written report to your board or governing body, from evidence rather than from memory
  • Runs the same evidence base against SOC 2, ISO 27001, NYDFS Part 500 and PCI DSS, so a financial institution files once
GLBA COMPLIANCE SOFTWARE readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Scope reference

Which GLBA security rule actually applies to you, and how the requirements differ

Almost every published GLBA checklist is written as though GLBA imposes one uniform set of security requirements. It does not. Section 505(a) of the Act assigns enforcement to whichever agency already supervises you, and those agencies wrote genuinely different rules. Multi-factor authentication and annual penetration testing are named obligations under the FTC rule and are absent from the banking guidelines. The breach notification clocks differ too. Find your row before you build a control list.

Your institution type Who writes and enforces your GLBA security rule Rule text Are specific controls named in the rule? Breach notification duty and clock
Non-bank financial institutions: mortgage lenders and brokers, auto dealers that extend or arrange credit, payday lenders, finance companies, account servicers, check cashers, wire transferors, collection agencies, credit counselors, tax preparation firms, non-federally insured credit unions, investment advisers not required to register with the SEC, and finders Federal Trade Commission Safeguards Rule, 16 CFR Part 314 Yes, and this is the most prescriptive of the GLBA rules. MFA, encryption in transit and at rest, annual penetration testing or continuous monitoring, semiannual vulnerability assessments, a named qualified individual, a written risk assessment and an annual report to the board. Compliance date for these provisions was June 9, 2023. Notify the FTC as soon as possible and no later than 30 days after discovery, where unencrypted customer information of at least 500 consumers was acquired without authorization. In force since May 13, 2024.
National banks, federal savings associations and federal branches Office of the Comptroller of the Currency Interagency Guidelines Establishing Information Security Standards, 12 CFR Part 30 Appendix B No. The guidelines set risk-based objectives and name almost no specific technology. There is no MFA mandate and no penetration testing mandate in the text. Customer notice under the 2005 interagency response programme guidance, on a reasonable-time standard rather than a fixed consumer count.
State non-member banks and state savings associations Federal Deposit Insurance Corporation 12 CFR Part 364 Appendix B No. Same interagency guidelines text, issued under the FDIC part. Same interagency response programme guidance.
State member banks, bank holding companies and their non-bank subsidiaries Federal Reserve Board 12 CFR Part 208 Appendix D-2 No. Same interagency guidelines text, issued under the Board parts. Same interagency response programme guidance.
Federally insured credit unions National Credit Union Administration 12 CFR Part 748 Appendix A, Guidelines for Safeguarding Member Information No. Risk-based guidelines rather than a named control list. Member notice under the NCUA response programme guidance at 12 CFR Part 748 Appendix B.
Broker-dealers, registered investment advisers, investment companies and transfer agents Securities and Exchange Commission Regulation S-P, 17 CFR Part 248 Partly. The 2024 amendments name a written incident response programme and service provider oversight, but do not prescribe specific technical controls the way the FTC rule does. Notify affected individuals as soon as practicable and no later than 30 days after becoming aware. Compliance from December 3, 2025 for larger entities and June 3, 2026 for smaller entities.
Title IV colleges, universities and their third-party servicers Department of Education, applying the FTC rule 16 CFR Part 314, incorporated through your Program Participation Agreement and the SAIG agreement Yes, identical to the FTC row. A university is held to the same rule text as a mortgage broker, which surprises most campus IT teams. Same as the FTC row. In addition, a compliance failure is written up as a finding in your annual Federal Single Audit and referred to the FTC and the Federal Student Aid Cybersecurity Team.
Insurers, insurance agencies and producers Your state insurance commissioner State law. In most states a version of the NAIC Insurance Data Security Model Law, model #668. New York insurers sit under NYDFS Part 500 instead. Varies by state. The model law names a written information security programme, a risk assessment and board oversight, and is closer to the FTC rule than to the banking guidelines. Varies by state. The model law text calls for notice to the commissioner within 72 hours of determining a cybersecurity event occurred.

Citations are to the current rule texts as at August 2026. Published sources disagree on how many jurisdictions have adopted the NAIC model law: the NAIC implementation map dated July 4, 2026 shows 28 adopting jurisdictions plus one pending, while several commentaries still cite 25, so confirm your own state directly with your commissioner. Enforcement assignment follows GLBA section 505(a) and turns on your charter and registrations rather than on what your business feels like, so an entity with more than one registration can sit under more than one row. Scrutineer prepares and maintains control evidence. It does not certify compliance, and no vendor or third party can.

Good questions

Questions about GLBA compliance software

GLBA compliance means meeting the obligations the Gramm-Leach-Bliley Act places on financial institutions handling nonpublic personal information. In practice it has three parts: the Privacy Rule, covering the notices you give consumers and their right to opt out of sharing with nonaffiliated third parties; the Safeguards Rule, covering the security programme protecting that data; and the pretexting provisions, which prohibit obtaining customer information under false pretenses. Most projects labelled GLBA compliance are really Safeguards Rule projects.
Any business significantly engaged in activities that are financial in nature, which reaches far beyond banks. Section 314.2(h) of the FTC rule lists thirteen examples including mortgage lenders and brokers, payday lenders, finance companies, account servicers, check cashers, wire transferors, collection agencies, credit counselors, tax preparation firms, non-federally insured credit unions and investment advisers not required to register with the SEC. The 2021 amendments added finders. Auto dealers that extend credit or arrange financing are covered too.
Under the FTC Safeguards Rule at 16 CFR 314.4 you must designate a qualified individual, perform and document a written risk assessment, and implement safeguards including access controls, an inventory of where customer data sits, encryption in transit and at rest, secure development practices, multi-factor authentication, secure disposal, change management and activity monitoring. You must then test them, train staff, oversee service providers, maintain a written incident response plan, and report to your board at least annually.
The Safeguards Rule is the FTC regulation at 16 CFR Part 314 that implements the security half of GLBA for financial institutions under FTC jurisdiction. It requires a written, comprehensive information security programme appropriate to your size and complexity. The rule was substantially amended in 2021 to add named technical controls, and the compliance date for those provisions was June 9, 2023.
Under the FTC Safeguards Rule, yes. Section 314.4(c)(5) requires MFA for any individual accessing any information system holding customer information, unless your qualified individual has approved in writing the use of reasonably equivalent or more secure controls. Under the interagency banking guidelines there is no equivalent named MFA mandate, although examiners will still expect strong authentication as a matter of sound practice. The difference is a good illustration of why the rule you are under matters.
The FTC Safeguards Rule requires either continuous monitoring of your information systems, or, if you do not have that, annual penetration testing plus vulnerability assessments at least every six months and whenever there is a material change. That is an either-or, and many firms miss it: the semiannual scanning obligation only bites if you are not doing continuous monitoring. The banking guidelines and Reg S-P do not name penetration testing as a requirement.
It depends on your regulator, and the clocks genuinely differ. Since May 13, 2024 the FTC Safeguards Rule requires notifying the FTC as soon as possible and no later than 30 days after discovering unauthorized acquisition of unencrypted customer information affecting at least 500 consumers. SEC Reg S-P requires notifying affected individuals within 30 days. The banking agencies work from the 2005 interagency response programme guidance, which uses a reasonable-time standard rather than a fixed count.
Nonpublic personal information is personally identifiable financial information a consumer gives you to obtain a financial product or service, information about a transaction between you and the consumer, or anything else you obtain in connection with providing that service. It also covers any list derived from that information. Publicly available information is excluded, but a list of your customers built from public sources is still covered because the fact of the relationship is not public.
The Privacy Rule governs disclosure: what you tell consumers about your information sharing practices and their right to opt out of sharing with nonaffiliated third parties. The Safeguards Rule governs security: the administrative, technical and physical controls protecting that data. They are separate rules with separate enforcement, and since Dodd-Frank they are largely written by separate agencies. A privacy notice on your website does nothing for Safeguards Rule compliance.
GLBA section 505(a) assigns enforcement to whichever agency already supervises you. The OCC, FDIC, Federal Reserve and NCUA supervise depository institutions, the SEC covers broker-dealers and registered advisers through Reg S-P, state insurance authorities cover insurers, and the FTC picks up everyone else. Dodd-Frank then moved most GLBA privacy rulemaking to the CFPB under Regulation P at 12 CFR Part 1016, while expressly leaving the section 501(b) security safeguards with the original agencies. The FTC also kept privacy rulemaking for motor vehicle dealers.
Yes, for institutions in the Title IV federal student aid programmes. Colleges and universities agree in their Program Participation Agreement to comply with the FTC Safeguards Rule at 16 CFR Part 314, and since June 9, 2023 that compliance is tested in the annual Federal Single Audit. A failure is written up as an audit finding and referred to the FTC and the Federal Student Aid Cybersecurity Team. Institutions are held to the same rule text as a mortgage broker.
No. No agency certifies, accredits or approves an organization or a product as GLBA compliant, and no third party can issue a certificate carrying regulatory weight. Compliance is a property of how your programme is designed and operated, assessed by your examiner or auditor. A vendor can honestly say its product supports GLBA control requirements. It cannot make you compliant on its own, and any certificate offered as proof is marketing.
The Safeguards Rule requires security awareness training for all personnel, plus enough training and updates for your security staff to address relevant risks. There is no prescribed curriculum, frequency or vendor. What an examiner samples is the record: who was assigned training, who completed it, when, and whether new joiners were covered. That is why training is a control evidence problem more than a content problem.
No. Scrutineer maps your controls to the GLBA rule that governs you and keeps the evidence behind them current, so you can see where you stand and answer an examiner quickly. The determination is made by your regulator, your examiner or your auditor, and the accountability for the programme stays with your qualified individual. We are explicit about that line rather than implying a purchase closes the obligation.

Keep reading

Guides that go deeper on GLBA and financial services controls

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification