Feature Data Privacy
The FTC Safeguards Rule's 9 Requirements Have Been Enforceable for Three Years. Here's What Non-Bank Financial Institutions Are Still Getting Wrong.
The FTC Safeguards Rule's 9 information security requirements became fully enforceable in June 2023, and breach notification requirements kicked in May 2024. Enforcement is now active across mortgage brokers, auto dealers, personal finance apps, and tax preparers. Here's what the 9 elements actually require and what FTC examiners are finding.
Table of Contents
TL;DR
- The FTC Safeguards Rule’s 9 information security requirements became fully enforceable June 9, 2023. A breach notification requirement — 500+ customers, report to the FTC within 30 days — took effect May 13, 2024. FTC enforcement has been active in FY2025 with multiple actions.
- The Rule covers non-bank financial institutions broadly: mortgage brokers, auto dealers that arrange financing, payday lenders, personal finance apps, tax preparers, investment advisors not registered with the SEC. If your company handles customer financial information and you’re not a bank, you’re almost certainly covered.
- The most common gaps: no qualified individual designated by name to the board, no written risk assessment, MFA deployed selectively rather than comprehensively, and service provider agreements with no security requirements.
- Penalties reach $51,744 per violation per day. Consent orders impose 20-year monitoring. The FTC has stated company size will not be a factor in enforcement decisions.
There’s a version of GLBA Safeguards compliance that many non-bank financial institutions have: a security policy that IT wrote in 2021, a SOC 2 report from a SaaS vendor that someone filed, and a vague awareness that “we need to protect customer data.” The requirements changed significantly in 2023. And then there’s a breach notification requirement that kicked in May 2024 that most non-bank financial institutions still haven’t fully operationalized.
The FTC’s Safeguards Rule — implementing the Gramm-Leach-Bliley Act’s requirement for a written information security program — has been around since 2003. But the 2023 overhaul added specific, technical requirements that go substantially beyond the original rule’s principles-based approach. And the FTC’s breach notification amendment, effective May 2024, added an entirely new reporting obligation. FTC Chairman Andrew Ferguson has publicly signaled an active enforcement period in H2 2026. So this is a good time to run the actual requirements against your program.
Who This Covers — The List Is Longer Than You Think
The Safeguards Rule applies to non-bank financial institutions — any company that is “significantly engaged” in financial activities and falls under FTC jurisdiction. That definition is broad:
- Mortgage brokers and servicers
- Motor vehicle dealers that arrange or facilitate financing or leasing (even if they don’t do the lending themselves)
- Payday lenders, installment lenders, and personal finance apps
- Tax preparers and accounting firms with financial planning services
- Investment advisors not registered with the SEC (typically those with under $100M AUM)
- Financial planners and wealth management firms that don’t fall under SEC or FINRA jurisdiction
- Check cashers and money transmission businesses in some circumstances
- Student loan servicers
- Companies providing credit report monitoring, financial literacy tools, or similar consumer financial services
Banks, credit unions, and their holding companies are excluded — they have their own regulators and separate GLBA compliance frameworks. But most fintechs, most auto dealerships that offer financing, most mortgage shops, and most tax preparation businesses are squarely covered by FTC jurisdiction.
The Congressional GLBA overhaul discussions from earlier this year would change some of these dynamics — but those are prospective legislative changes. The existing Safeguards Rule is current law, currently being enforced.
The 9 Required Elements — What They Actually Mean
The amended rule, codified at 16 CFR Part 314, requires a written information security program containing nine specific elements. Not nine general principles — nine elements with specific operational requirements behind each.
1. Designate a Qualified Individual
You must designate — in writing — a qualified individual responsible for implementing and supervising your information security program. This person’s identity and the program’s status must be reported to your board of directors or equivalent governing body at least annually.
“Qualified individual” means someone with the knowledge and experience to manage an information security program. It can be an employee or an outside contractor, but if it’s a contractor, the institution retains responsibility. What it cannot be is “the IT team generally” or “whoever deals with security stuff.” A name must be attached to this responsibility, and that person must brief the board.
2. Written Risk Assessment
You must conduct and document a written risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information. The assessment must also evaluate the sufficiency of existing safeguards.
This is not a policy document. It’s an assessment — something that evaluates your specific systems, processes, and data, identifies where risks exist, and documents the evaluation. The risk assessment must be updated when there are material changes to your operations or business arrangements.
The original 2003 Rule also required a risk assessment. Enforcement keeps finding institutions without one.
3. Access Controls
Implement and periodically review access controls — including technical and, where appropriate, physical controls — to manage access to customer information. This means controlling who can access what, with appropriate restrictions based on need.
Access controls include: user authentication for system access, role-based access limitations, controls on physical access to servers and storage where customer information lives, and a process for promptly removing access when employees leave or change roles.
4. Multi-Factor Authentication
The 2023 amendments added an explicit MFA requirement. You must implement multi-factor authentication for any individual accessing any information system within your organization that contains customer information — unless you document why an equivalent compensating control provides a reasonable level of security.
The exception is narrow. The MFA requirement is the baseline. If you’ve deployed MFA for remote access but not for internal systems, or for administrative accounts but not standard user accounts, you have a compliance gap.
5. Encryption
Customer information must be encrypted both in transit over external networks and at rest. This applies to all customer information, not just particularly sensitive fields. There’s a similar compensating control exception — but again, it’s a documented exception to a default requirement, not an option.
6. Monitoring and Testing
You must continuously monitor and test your safeguards to ensure they remain effective. At a minimum, this means annual penetration testing and vulnerability assessments (or more frequently if risk assessment indicates). It also means monitoring your systems for unauthorized access or activity.
This requirement exists because safeguards that worked when implemented don’t necessarily remain effective as systems, threats, and business operations evolve. The monitoring and testing obligation keeps the program current.
7. Employee Training
Covered institutions must implement a security awareness training program and keep staff updated on reasonably foreseeable internal and external risks. Training must be periodic — not a one-time onboarding event — and updated as threats evolve.
8. Service Provider Oversight
Any service provider who handles customer information on your behalf must be required by contract to implement appropriate safeguards for that information. You must also oversee service providers’ compliance with those requirements — which means your contracts need security requirements and your oversight needs to include periodic review of whether those requirements are being met.
This is where most non-bank financial institutions have their biggest gap. Cloud agreements, SaaS contracts, and payment processor agreements frequently lack specific security requirements or audit rights. The Rule requires them — in the contract, not just in a verbal assurance.
9. Written Incident Response Plan
You must develop, implement, and maintain a written incident response plan that addresses the goals of the plan, internal processes for responding to security events, roles and responsibilities, external communications and information-sharing, steps to remediate vulnerabilities, documentation, and procedures for revising the plan post-incident.
An incident response plan is not the same as an incident notification policy. The plan must address what you do when an incident occurs — before you know whether it triggers notification obligations. The notification requirements under Section 314.4(j) sit on top of this plan.
The Breach Notification Requirement — What It Specifically Requires
Section 314.4(j) took effect May 13, 2024. It requires covered institutions to notify the FTC no later than 30 days after discovering a “notification event.”
A notification event is the unauthorized acquisition of unencrypted customer information involving at least 500 consumers. “Unauthorized acquisition” includes both external breaches and unauthorized access by employees or contractors.
The notification goes to the FTC through its secure online portal. It’s separate from state breach notification laws — you may need to notify the FTC, affected consumers, and one or more state regulators from a single event, each with different timelines.
What the rule doesn’t specify is industry practice on what to do during the 30 days before the FTC notification deadline. The incident response plan required under Element 9 should drive that — forensic investigation, scope determination, affected-record count, legal review, and preparation of the FTC notification. If your incident response plan doesn’t account for this sequence, update it.
For AnnieMac Home Mortgage, which disclosed in August 2024 that a breach exposed names and Social Security numbers of over 171,000 customers, the event was a concrete example of what triggers FTC reporting under the new rule. If you exceed 500 consumers, the 30-day clock starts when you discover it.
What FTC Enforcement Is Finding
FTC enforcement in FY2025 brought multiple Safeguards Rule actions. The patterns across enforcement actions and the FTC’s public statements point to consistent violations:
No qualified individual. Companies without a formally designated security lead — or where the designation exists on paper but the person isn’t actually running a program — are the first thing enforcement finds.
Selective MFA. MFA deployed for remote access but not for internal systems, or for IT staff but not business users, or for new systems but not legacy systems. The Rule requires comprehensive MFA, not a reasonable MFA program. The distinction matters.
No vendor security requirements. Cloud and SaaS agreements with no security language, no right to audit, and no documented oversight cadence. Service provider oversight under the Rule requires contracts with requirements in them.
Written risk assessment missing. Despite this requirement existing since 2003, enforcement keeps finding companies without a documented, current risk assessment. “We did an assessment mentally” doesn’t satisfy 16 CFR 314.
No written incident response plan. Or a plan that describes notification timelines but doesn’t address the operational response to an incident — investigation, containment, evidence preservation, stakeholder communication.
The FTC has publicly stated that company size will not be a factor in enforcement decisions. Civil penalties reach $51,744 per violation per day. Consent orders routinely include 20-year monitoring requirements — which means the FTC can audit your security program for two decades.
So What? The Compliance Audit Checklist
Run your program against these questions. Any “no” is a compliance gap:
| Requirement | Key Question | Common Gap |
|---|---|---|
| Qualified Individual | Is a specific person designated by name, with board-level accountability? | Vague “IT team” designation |
| Risk Assessment | Is there a documented, current risk assessment with named risks and control adequacy evaluations? | Absent or from 2021 |
| Access Controls | Are access permissions reviewed periodically and removed promptly when roles change? | Legacy accounts, no review cycle |
| MFA | Is MFA deployed for all users accessing systems with customer information? | External access only |
| Encryption | Is customer information encrypted in transit and at rest, across all systems? | Legacy systems excluded |
| Monitoring/Testing | Is annual penetration testing documented, with findings tracked to remediation? | No pen test, or no remediation tracking |
| Training | Is security awareness training conducted periodically, with attendance documented? | One-time onboarding only |
| Service Provider Oversight | Do contracts with vendors handling customer information include security requirements? | No security language in agreements |
| Incident Response Plan | Does a written IR plan address all required elements, including the FTC notification sequence? | Generic IR policy, no FTC notification procedure |
If your incident response program needs a structured update to incorporate the FTC reporting obligation and the board notification requirements in the incident response context, the Incident Response & Breach Notification Kit includes templates that cover the FTC Safeguards breach notification sequence alongside state notification obligations.
And if the broader gap is your written information security program — the foundational document that ties all 9 elements together — the Data Privacy Compliance Kit includes an information security program framework, vendor security assessment questionnaires, and a breach notification decision flowchart calibrated for non-bank financial institutions.
The Practitioner Reality
The FTC Safeguards Rule isn’t new. The enforcement intent isn’t new. What is new is that Chairman Ferguson has publicly telegraphed H2 2026 as an active enforcement period — which, combined with the breach notification data the FTC is now collecting, gives the agency both the signal and the mandate to act.
Non-bank financial institutions that have treated the Safeguards Rule as background compliance have about one quarter to close the gaps before enforcement actions from the H2 surge start landing. The gaps aren’t hard to close — but they need to be documented, not just patched informally.
Start with the qualified individual, the written risk assessment, and the incident response plan. Those are the gaps enforcement is finding most reliably. Then work through MFA, service provider contracts, and monitoring. Get the program on paper, documented, and briefed to your board.
The 30-day breach notification clock doesn’t wait for your IR plan to be ready.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Who does the FTC Safeguards Rule cover?
What is the FTC Safeguards Rule breach notification requirement?
What are the 9 required elements of the FTC Safeguards Rule information security program?
What are the penalties for violating the FTC Safeguards Rule?
What are the most common FTC Safeguards Rule compliance gaps?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Data Privacy Compliance Kit
Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.
◆ Keep reading
Related posts.
Data Privacy
FTC Chairman Ferguson Says a Privacy Enforcement Surge Is Coming in H2 2026. Here's What Financial Services Companies Need in Place.
FTC Chairman Andrew Ferguson publicly warned that reporters covering the FTC will 'have a hard time keeping up' with the number of privacy enforcement cases coming in the second half of 2026. The Kochava settlement and new Section 5 standalone data-security cases telegraph exactly what's in the crosshairs. Here's what financial services companies need to have documented before the cases start landing.
Sep 9, 2026
Data Privacy
CalPrivacy Has Issued Eight Data Broker Fines and Is Still Going. What the September 2026 Enforcement Advisory Means for Your Fintech.
California's Privacy Protection Agency issued Enforcement Advisory 2026-01 on September 3, making clear that inaccurate data broker registration is a live $200-per-day penalty risk. Two August 2026 settlements and eight prior enforcement actions signal that CalPrivacy is done with warnings. Here's what fintech compliance teams need to know.
Sep 7, 2026
Data Privacy
PADFAA Is Real Enforcement Now: What Fintech Data Companies Need to Know Before the FTC Files Its First Case
The Protecting Americans' Data from Foreign Adversaries Act prohibits data brokers from selling sensitive consumer data — including financial records — to entities in China, Russia, Iran, North Korea, Cuba, and Venezuela. The FTC sent 13 warning letters in February 2026. Here's what counts as a data broker, what data is covered, and what your compliance program needs before enforcement begins.
Sep 5, 2026