Skip to content
RiskTemplates · The Daily Brief Sunday, July 26, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Data Privacy

FTC Safeguards Rule in 2026: The 9-Element Security Program Every Non-Bank Financial Institution Now Has to Prove It Has

If you're a mortgage broker, payday lender, tax preparer, money transmitter, or collection agency — not a bank, not an SEC-registered adviser — the FTC Safeguards Rule is your data security regulation. Here's what the 9-element information security program actually requires, plus the breach notification obligation that became enforceable in May 2024.

Table of Contents

TL;DR:

  • The FTC Safeguards Rule (16 CFR Part 314) applies to non-bank financial institutions — mortgage brokers, payday lenders, auto dealers, money transmitters, collection agencies, tax preparers, and others — not to banks, credit unions, or SEC-registered advisers.
  • A 9-element written information security program has been required since June 9, 2023. Most covered entities have a policy document. Far fewer have the annual penetration test, the semi-annual vulnerability assessment, the Qualified Individual’s written board report, or the breach notification process operationalized.
  • As of May 13, 2024, covered entities must notify the FTC within 30 days of a breach affecting 500 or more consumers. The FTC posts these reports publicly.
  • Civil penalties for violations reach $51,744 per violation per day. Criminal liability applies for willful violations.

“What privacy regulation applies to us?” is one of the most common questions compliance teams at non-bank fintechs get wrong — not because the answer is complicated, but because most of the regulatory noise is about rules that don’t apply to them.

If your firm is an SEC-registered investment adviser or broker-dealer, the SEC’s amended Regulation S-P is your breach notification rule. If you’re a bank or credit union, your primary federal banking regulator handles your GLBA obligations. But if you’re a mortgage company, a payday lender, a money transmitter, a tax preparation service, or a collection agency — and you don’t fit either of those buckets — the Federal Trade Commission’s Safeguards Rule is your data security regulator. And as of May 2024, it includes a breach notification obligation that publishes your incident report on the FTC’s website.

Who the FTC Safeguards Rule Actually Covers

The Safeguards Rule is issued under the Gramm-Leach-Bliley Act, which requires financial institutions to protect the security and confidentiality of customer nonpublic personal information. The FTC enforces GLBA for the categories of financial institutions that don’t fall under another federal regulator’s enforcement authority.

That population is larger than most teams realize. 16 CFR Part 314 covers:

  • Mortgage lenders and brokers
  • Non-bank auto lenders and dealers who arrange financing
  • Payday lenders and small-dollar credit providers
  • Check cashers
  • Money transmitters and payment companies
  • Collection agencies
  • Tax preparation services
  • Financial advisors and investment advisors not registered with the SEC
  • Non-federally insured credit unions
  • Real estate appraisers involved in mortgage transactions
  • Any company that acts as a “finder” to bring together buyers and sellers of financial products or services

Not covered by the FTC Safeguards Rule: banks and thrifts supervised by the OCC, Federal Reserve, or FDIC; federally insured credit unions supervised by the NCUA; SEC-registered broker-dealers; and SEC-registered investment advisers. Those entities have analogous obligations under their primary regulators.

If you’re a fintech that fits into one of the non-bank categories above — even if you partner with a sponsor bank — the FTC is your Safeguards Rule regulator. The bank partnership doesn’t transfer GLBA enforcement responsibility to the OCC or FDIC.

The 9 Elements of Section 314.4

The FTC’s 2021 amendments updated the Safeguards Rule from a general “comprehensive program” requirement to a specific 9-element framework. Full enforcement began June 9, 2023. Here’s what each element actually requires in practice:

1. Designate a Qualified Individual

You must designate a “Qualified Individual” (QI) to implement and supervise the information security program. This person can be an employee of your company, an affiliate employee, or a third-party service provider. The FTC’s guidance is explicit that no specific degree, certification, or title is required — what matters is real-world know-how suited to your circumstances.

The QI also has mandatory reporting obligations under Element 9. The designation needs to be formal and documented — not just whoever happens to handle IT.

2. Conduct a Written Risk Assessment

You must complete a written risk assessment that identifies foreseeable security risks to customer information, evaluates the effectiveness of current safeguards, and informs the safeguards you implement. The written requirement is non-negotiable — oral risk reviews don’t satisfy this element. The assessment must be updated periodically as your business, technology, and threat environment change.

This is the foundation the rest of the program builds on. If you have gaps in elements 3 through 8, the FTC traces them back here.

3. Design and Implement Safeguards

This is the technical core. Based on your risk assessment, you must implement safeguards that address at minimum:

  • Access controls: Limit who can access customer information, and apply the principle of least privilege
  • Data inventory: Know where all customer information is stored, transmitted, and processed
  • Encryption: Encrypt customer information at rest and in transit on open networks
  • Secure development: If you build applications in-house, apply secure development practices
  • Multi-factor authentication (MFA): Required for any employee accessing customer information systems — including internal network access to financial data
  • Data disposal: Dispose of customer information securely when you no longer need it
  • Change management: Document and review changes to systems that affect customer information security
  • Application security testing: Procedures for evaluating the security of internally developed and third-party applications

4. Monitor and Test Your Safeguards

This is where most programs have the biggest gap. The 2021 update specified concrete testing requirements:

  • Annual penetration testing by a qualified, sufficiently independent party
  • Vulnerability assessments at least every six months — or more frequently if your risk warrants it
  • Continuous monitoring for unauthorized access to customer information systems

The penetration test must be conducted by someone independent enough of IT management to provide objective results — either an internal team with appropriate separation from the systems being tested, or more commonly, an external firm. “We run internal scans regularly” does not satisfy the annual pen test requirement.

Annual penetration testing is one of the most commonly missing elements when the FTC investigates covered entities following a breach. If your last pen test was more than 12 months ago — or you’ve never had one — this is your highest-priority gap.

5. Provide Security Awareness Training

You must provide security awareness training to staff. The rule requires that training be current — a once-in-2019 security awareness video that hasn’t been updated doesn’t satisfy this element. Training must reflect the actual threats your institution faces, including phishing, social engineering, credential theft, and any threats specific to your business model.

6. Oversee Service Providers

Any service provider that accesses, maintains, processes, or otherwise handles customer information on your behalf must be subject to:

  • Due diligence: Assess the service provider’s security capabilities before onboarding
  • Written contractual protections: Require them to implement appropriate safeguards for customer information and allow you to monitor their compliance
  • Ongoing oversight: Monitor service providers’ security practices through the relationship, not just at onboarding

This means reviewing vendor contracts for security terms. A vendor whose security practices are unknown or undocumented is an unassessed risk — and an Element 6 gap if they touch customer data.

7. Keep the Program Current

Your information security program must be updated to reflect:

  • Results of monitoring and testing (Element 4)
  • Material changes to your operations, business arrangements, or systems
  • Changes in the threat environment
  • Any circumstances you know or reasonably believe may materially affect your program

Annual policy reviews alone don’t satisfy this element if your business has undergone material changes — new products, new systems, new vendors, acquisitions, or significant operational changes — that haven’t triggered a program update. The update must be contemporaneous with the material change, not saved for the next annual cycle.

8. Establish a Written Incident Response Plan

The program must include a written incident response plan that addresses:

  • Goals and criteria for the response program
  • Designated internal roles and decision-makers for incident response
  • Clear communication and information-sharing requirements, including with senior officers
  • Documentation and evidence-preservation procedures
  • Eradication and recovery steps
  • Post-incident evaluation and program improvement

The incident response plan is a standing program requirement — not something you build after an incident occurs. An examiner asking to see your incident response plan during an investigation is not the time to write it.

9. Qualified Individual Reports to Your Board

The Qualified Individual must report in writing to your board of directors — or, if there’s no board, to senior officers — at least annually. The report must cover:

  • The overall status of the information security program
  • Material matters relating to the program, including results of risk assessments, testing, and monitoring; any material changes to the program; and any security events

This takes information security reporting out of the informal briefing category and makes it a formal governance obligation. If your board has never received a written information security report, you haven’t satisfied Element 9 — regardless of how strong your technical controls are.

The Breach Notification Amendment: What Changed in May 2024

In October 2023, the FTC amended the Safeguards Rule to add mandatory FTC breach notification. The requirement became effective May 13, 2024.

What triggers it: A “notification event” means unauthorized acquisition of unencrypted customer information involving 500 or more consumers. The trigger is acquisition of the data without authorization — not confirmed customer harm, not a completed forensic investigation. If 500+ consumers’ unencrypted data was accessed without your authorization, you have a notification event.

Deadline: No later than 30 days after discovering the event. The clock starts on discovery, not investigation close.

How: Notification is submitted through the FTC’s online notification portal. You do not need to wait for a completed investigation to submit.

What the FTC does with it: The FTC posts breach notifications publicly on its website. Your firm’s name, the number of consumers affected, and the nature of the breach become publicly searchable — creating reputational exposure that runs parallel to the regulatory risk.

This is a fundamentally different trigger than state breach notification laws, which typically require notification to affected consumers. The FTC breach notification goes to the regulator, not to customers directly — though you likely have parallel state-law obligations to notify consumers. Your incident response plan needs to handle both clocks simultaneously.

The June 2025 FTC guidance addressing motor vehicle dealer compliance questions makes clear that FTC staff are actively receiving questions about the rule’s requirements — a sign that enforcement attention is active and that the agency views many covered entities as still working through compliance.

Non-bank financial institutions often see coverage for NYDFS Part 500 or SEC breach notification rules and assume they’re covered. The scope distinctions matter:

FTC Safeguards RuleAmended Reg S-PNYDFS Part 500
Who it coversNon-bank FIs: mortgage brokers, payday lenders, money transmitters, tax preparers, collection agencies, etc.SEC-registered investment advisers, broker-dealers, investment companies, transfer agentsCovered entities licensed by NYDFS (NY-licensed financial services businesses)
RegulatorFTCSECNYDFS
Security program requiredYes — 9-element WISP under 16 CFR Part 314Yes — written incident response programYes — comprehensive cybersecurity program
Breach notification deadline30 days to FTC (500+ consumers)30 days to customers72 hours to NYDFS (if material)
Annual penetration testRequiredNot specifiedRequired
MFARequired for customer data system accessNot specifiedRequired for specific access types

The GLBA Regulation P privacy notice requirements apply to many of the same non-bank financial institutions covered by the Safeguards Rule. But Regulation P covers annual privacy notices and opt-out rights — not information security programs. Both requirements apply independently. Being current on your Regulation P annual notice filing does not mean you’ve met Safeguards Rule obligations.

For fintechs working through state-level privacy requirements, including the ongoing GLBA safe harbor erosion under new state privacy laws, the Safeguards Rule is a federal floor that state cybersecurity requirements can and do layer on top of.

What the Common Gaps Look Like

When the FTC investigates a covered entity following a breach, the most consistent gaps found are:

  1. No annual penetration test: Either no testing at all, internal-only testing that doesn’t satisfy the independence requirement, or testing conducted more than 12 months ago
  2. No written incident response plan: Oral procedures and institutional knowledge don’t satisfy the written requirement
  3. No Qualified Individual board report: Security discussions happen but no written, board-directed report exists
  4. Service provider agreements without security terms: Vendors accessing customer data under contracts that contain no security requirements, audit rights, or breach notification obligations
  5. Stale risk assessment: A written risk assessment from 2022 that hasn’t been updated to reflect current products, systems, and vendors
  6. No operationalized breach notification process: No documented internal escalation path from event discovery to FTC notification within 30 days

So What?

If you’re a covered non-bank financial institution — mortgage broker, payday lender, money transmitter, collection agency, tax preparer — and you don’t have a written, 9-element information security program, you’re not in compliance with a rule that has been fully enforceable since June 2023 and has active breach notification requirements since May 2024.

Civil penalties at $51,744 per violation per day are one exposure. Public breach notification disclosures are another. FTC consent orders — which require independent security assessments and multi-year monitoring — create ongoing operational burden that goes well beyond the cost of building the program before an investigation opens.

The most efficient path forward: build the 9-element program once, document it, assign the Qualified Individual, get the annual pen test scheduled, and operationalize the 30-day FTC notification clock before you need it.

The Data Privacy Compliance Kit includes a written information security program template mapped to all 9 elements of the FTC Safeguards Rule, a written incident response plan with the FTC notification workflow built in, and service provider security agreement language you can add to vendor contracts. It’s designed for non-bank financial institutions that need a defensible program without starting from a blank document.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What non-bank financial institutions are covered by the FTC Safeguards Rule?
The FTC Safeguards Rule (16 CFR Part 314) covers non-banking financial institutions that are not subject to another federal regulator's GLBA enforcement authority. That includes mortgage lenders and brokers, auto dealers who arrange financing, payday lenders, collection agencies, tax preparation services, check cashers, money transmitters, financial advisors not registered with the SEC, credit counselors, non-federally insured credit unions, and real estate appraisers involved in mortgage transactions. Banks, NCUA-supervised credit unions, SEC-registered broker-dealers, and SEC-registered investment advisers have separate obligations under their primary regulators — the FTC Safeguards Rule does not apply to them.
What are the 9 elements of the FTC Safeguards Rule information security program?
Section 314.4 of the Safeguards Rule identifies nine elements: (1) designate a Qualified Individual to implement and supervise the program; (2) conduct a written risk assessment; (3) design and implement safeguards to control identified risks, including access controls, encryption, multi-factor authentication, and secure development practices; (4) regularly monitor and test the effectiveness of safeguards — including annual penetration testing and semi-annual vulnerability assessments; (5) provide security awareness training to staff; (6) oversee service providers through due diligence and contractual protections; (7) keep the program current as your business and technology change; (8) establish a written incident response plan; and (9) require the Qualified Individual to report in writing to your board or senior officers at least annually.
What is the FTC Safeguards Rule breach notification requirement?
As of May 13, 2024, covered non-bank financial institutions must notify the FTC no later than 30 days after discovering a 'notification event' — defined as unauthorized acquisition of unencrypted customer information involving 500 or more consumers. Notification is submitted through the FTC's online portal. The FTC posts these notices publicly on its website, creating reputational exposure on top of regulatory risk. The trigger is unauthorized acquisition of the data, not confirmed customer harm — the clock starts when you discover the event, not when an investigation concludes.
Who qualifies as a 'Qualified Individual' under the FTC Safeguards Rule?
The Safeguards Rule does not require a specific degree, certification, or title for the Qualified Individual. The FTC's guidance says what matters is 'real-world know-how suited to your circumstances.' The Qualified Individual can be an employee of your company, an affiliate employee, or a third-party service provider. For most small and mid-size non-bank financial institutions, this will be a senior IT, security, or compliance professional — not necessarily a CISO — who has practical experience designing and managing information security programs.
What civil penalties apply to FTC Safeguards Rule violations?
The FTC can seek civil penalties of up to $51,744 per violation per day (adjusted annually for inflation) under Section 5(m)(1)(A) of the FTC Act for violations of the Safeguards Rule. The FTC can also require corrective actions, independent security audits, and multi-year monitoring through consent orders. Willful GLBA violations separately carry criminal penalties including fines up to $100,000 per violation for institutions and up to $10,000 per violation for individual officers and directors, plus up to five years imprisonment.
Does the FTC Safeguards Rule require penetration testing and MFA?
Yes to both. The monitoring and testing element (element 4) requires annual penetration testing by a qualified, sufficiently independent party and vulnerability assessments at least every six months. The safeguards element (element 3) requires multi-factor authentication for any employee accessing customer information systems, including internal network access to financial data. These are among the most frequently cited gaps when the FTC investigates covered entities following a breach. A general 'we test periodically' statement does not satisfy the annual pen test requirement.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.