FTC Safeguards Rule Checklist for Small Financial Businesses

Customer data can sit in a loan platform, email inbox, shared drive, and vendor portal before anyone maps it. A practical FTC Safeguards Rule checklist gives a small financial business a way to assign ownership, close control gaps, and preserve evidence.

The rule applies to many non-bank financial institutions under FTC jurisdiction. Compliance requires more than antivirus software. You need a written security program, a qualified individual, documented risk decisions, tested safeguards, vendor oversight, and a response plan. Start by confirming scope, then turn each requirement into an owner, task, and record.

Confirm whether the FTC Safeguards Rule applies

The FTC Safeguards Rule is part of 16 CFR Part 314. It implements information security requirements under the Gramm-Leach-Bliley Act, often called GLBA, for covered financial institutions within the FTC's jurisdiction.

Identify your regulatory category

The rule can cover businesses that are significantly engaged in financial activities but aren't banks. Examples may include mortgage brokers, payday lenders, finance companies, tax preparers, collection agencies, auto dealers that extend credit, and some investment advisers.

Coverage depends on the business's activities, ownership structure, and regulators. A company supervised under GLBA by the SEC, a banking regulator, or another authorized regulator may fall outside the FTC's Safeguards Rule enforcement authority. That doesn't remove every privacy or security obligation.

Ask the owner, compliance lead, and qualified legal adviser to document the decision. Keep a short applicability memo that names the business activities, regulators, affiliates, and reasons for the conclusion. Review it when the company adds a product, acquires another business, or changes how it handles customer data.

Define customer information

The rule covers customer information in paper, electronic, or other forms. It includes records containing nonpublic personal information about a customer that the business or its affiliates handle or maintain.

Your inventory may include loan applications, tax returns, account numbers, Social Security numbers, income records, identity documents, payment details, customer emails, call recordings, and reports stored by vendors. Employee information isn't automatically customer information, but it can still require protection under other laws and policies.

Have IT and compliance create a data map showing:

  • What information the business collects
  • Which systems store or transmit it
  • Which employees and vendors can access it
  • Where paper records are kept
  • How long each record is retained
  • How the business securely disposes of it

For working purposes, use P0 for legal, access, or incident gaps that need immediate attention. Use P1 for high-risk control improvements, and P2 for routine maturity work.

Build an FTC Safeguards Rule checklist around the core controls

A small business can maintain a practical program without creating a policy library nobody follows. The written program should describe real safeguards, responsible people, review dates, and exceptions.

Appoint a Qualified Individual

The business must designate a Qualified Individual to oversee, implement, and enforce its information security program. This person needs enough authority, knowledge, and access to manage the program. The role may sit with an internal leader or an appropriately qualified outside professional, depending on the company's structure.

The Qualified Individual should maintain a written risk assessment that considers the company's size, complexity, activities, and the sensitivity of customer information. The assessment should identify reasonably foreseeable internal and external risks, evaluate current safeguards, and record decisions about additional controls.

The business owner or governing body should approve the program. Evidence can include the appointment record, approved policy, risk assessment, risk register, annual review date, and documented exceptions. A risk assessment that says "low risk" without supporting facts won't help much during an examination or incident review.

Apply access controls, MFA, and encryption

Access controls authenticate users and limit customer information to people who need it for approved business purposes. Each employee should have a unique account. Shared administrator passwords make investigations harder and weaken accountability.

Multifactor authentication is a required safeguard for individuals who access customer information, unless the Qualified Individual approves an equivalent alternative in writing. MFA combines a password with another factor, such as an authenticator app, hardware key, or biometric check.

Encryption is also required for customer information held on systems and transmitted over external networks. Encryption changes readable data into protected text that requires a key to restore. If a required form of encryption is infeasible, the Qualified Individual must approve a reasonable alternative in writing.

Priority Action Primary owner Suggested evidence
P0 Name the Qualified Individual Owner or governing body Signed appointment and role description
P0 Complete the written risk assessment Qualified Individual Risk assessment and risk register
P0 Require MFA and unique accounts IT or managed IT provider Identity reports and MFA settings
P1 Encrypt stored and transmitted data IT and Qualified Individual System configuration records
P1 Review vendors handling customer data Compliance and IT Vendor inventory and contracts
P2 Test, train, report, and improve Qualified Individual Test reports, training records, annual report

Keep written approvals for exceptions. An informal decision made during a phone call is difficult to prove later.

Protect customer information through its full lifecycle

Security starts before data enters a system and continues through deletion. The Safeguards Rule addresses several points in that lifecycle.

Inventory, retain, and dispose of records

The business should maintain an accurate inventory of customer information and the systems where it resides. Include cloud applications, local computers, servers, removable media, backups, paper files, and vendor platforms.

A written retention schedule should state how long each type of customer information is kept. The schedule should account for legal, regulatory, tax, litigation, and legitimate business needs. When the retention period ends, securely dispose of the information unless a documented hold applies.

Secure disposal can include cross-cut shredding, certified destruction, cryptographic erasure, and verified deletion from systems that no longer need the data. Deleting a shortcut or removing a file from one computer doesn't prove that all copies are gone.

Compliance or records management should own the schedule. IT should document technical deletion. Evidence may include a data inventory, retention policy, deletion logs, shred certificates, vendor destruction records, and legal hold notices.

Secure applications, changes, and recovery

Businesses that develop software must use secure development practices. They also need procedures for evaluating, assessing, and testing applications developed by outside parties. A small company that doesn't write code still needs a sensible process for reviewing new platforms that will handle customer information.

Change management records should show what changed, who approved it, when it occurred, and how the business tested the result. Changes to firewalls, identity systems, cloud permissions, backup jobs, and line-of-business applications deserve particular attention.

The program also needs safeguards against destruction, loss, or damage caused by environmental hazards and technology failures. The rule doesn't prescribe one backup product or require a particular backup architecture. However, tested backups, off-site copies, recovery procedures, and power protection are practical ways to address this requirement.

A documented backup and disaster recovery services plan can help a small business show how it will recover customer information after hardware failure, ransomware, fire, water damage, or a major cloud outage. Evidence should include backup reports, failed-job alerts, restore tests, recovery priorities, and records showing that someone reviewed the results.

Test controls, train people, and prepare for incidents

Policies cannot show whether a safeguard works. Testing and employee behavior provide that evidence.

Monitor systems and test key safeguards

The program must include activity monitoring and regular testing of key controls, systems, and procedures. Monitoring looks for unusual activity, attacks, intrusions, failed logins, malware, unauthorized changes, and other signs of trouble.

The rule describes continuous monitoring or periodic penetration testing and vulnerability assessments as testing methods. Its requirements include vulnerability assessments every six months and after material changes, while annual penetration testing applies to the periodic testing path. Confirm the testing approach with the Qualified Individual and qualified compliance counsel.

A vulnerability assessment searches systems for known weaknesses. A penetration test uses controlled techniques to determine whether those weaknesses can lead to unauthorized access. Neither replaces routine patching or alert review.

A small business may use internal staff, a managed IT provider, or a qualified security firm. 24/7 network monitoring services can help collect alerts and identify device, patching, antivirus, and network problems before they become larger incidents.

Keep scan reports, penetration test results, alert review records, remediation tickets, exception approvals, and retest results. A report that lists a serious weakness without a follow-up ticket leaves an obvious gap.

Train employees and maintain an incident response plan

Personnel training is a required part of the information security program. Training should cover phishing, password and MFA use, customer data handling, clean-desk practices, secure remote access, device loss, reporting procedures, and vendor communication rules.

New hires need training before they receive access to customer information. Existing employees need periodic refreshers and additional training after major incidents or policy changes. Keep attendance records, test results, training content, and completion reports.

The business must also maintain a written incident response plan. It should name the response leader, IT contact, owner, legal adviser, insurance contact, communications lead, and backup decision-maker. It should explain how the team will contain an incident, preserve evidence, assess affected information, restore systems, and decide whether notification duties apply.

Test the plan with a short tabletop exercise at least annually. Record what participants decided, where they lacked information, and who owns each correction.

Control service providers and cloud systems

A business remains responsible for customer information handled by affiliates and service providers. Outsourcing a system doesn't outsource the duty to select capable providers or oversee their safeguards.

Review vendors before and after signing

Create a vendor inventory for every provider that can access customer information. Include cloud storage, loan origination software, payroll platforms, email, backup providers, managed IT companies, shredding services, document processors, payment systems, and outside call centers.

Before signing, review the provider's security practices, incident history, access controls, encryption, backup process, employee training, and subcontractors. The rule requires service-provider oversight and contractual requirements for appropriate safeguards.

Contracts should address data protection, permitted use, access controls, breach notification, cooperation with investigations, secure return or destruction, audit information, and subcontractor responsibilities. A SOC 2 report, security questionnaire, or cyber insurance certificate can support the review, but none proves automatic compliance.

Assign compliance to maintain the vendor register and IT to verify technical details. Review high-risk providers at a defined interval and after a material service, ownership, or security change. Keep contracts, questionnaires, reports, review notes, risk ratings, and remediation records.

Configure cloud identities and business applications

Cloud services need the same attention as local servers. A Microsoft 365 subscription doesn't automatically satisfy the Safeguards Rule. Administrators still need to configure MFA, privileged roles, audit logging, mailbox protections, device access, retention, and secure sharing.

Review guest users and inactive accounts at regular intervals. Restrict global administrator access, require approval for sensitive changes, and record investigations of suspicious sign-ins. Confirm whether the provider's backup and retention features meet your recovery and legal needs.

For help with Microsoft 365 setup and security, keep the service configuration, access review, policy settings, and provider agreement with the rest of the security evidence.

Respond to a notification event within the required time

The breach-notification amendment took effect in May 2024. It created a specific FTC notification duty for covered financial institutions.

Understand the 500-consumer threshold

A covered institution must notify the FTC as soon as possible, and no later than 30 days after discovering a notification event involving the unauthorized acquisition of unencrypted customer information affecting at least 500 consumers.

The threshold is 500 consumers, not 500 records. One customer may have several records, while one compromised file may contain information about many people. Unauthorized access to unencrypted customer information is generally presumed to involve unauthorized acquisition unless reliable evidence shows otherwise.

Information may be treated as unencrypted if an unauthorized person accessed the encryption key. The Qualified Individual should involve legal counsel quickly because facts may change as the investigation develops.

The FTC notice is submitted electronically. It generally includes the institution's name and contact information, the types of information involved, the date or date range, the number of consumers affected, a general description of the event, and certain law-enforcement information when applicable.

Preserve evidence and coordinate the response

Your incident playbook should treat the 30-day period as a firm outside deadline, not as a target for starting the investigation. Use these steps:

  1. Contain the affected account, device, application, or connection without destroying evidence.
  2. Open an incident record with the discovery time, people involved, systems affected, and actions taken.
  3. Preserve logs, email, endpoint images, vendor notices, access records, and relevant business documents.
  4. Determine what information was exposed, whether it was encrypted, and how many consumers may be affected.
  5. Notify the owner, Qualified Individual, legal counsel, insurer, and required partners under the response plan.
  6. File the FTC notice when the rule's threshold applies, then address separate state, contractual, or sector-specific duties.
  7. Document corrective actions, test the fixes, and update the risk assessment.

Other breach laws may require consumer, state, law enforcement, or contractual notices. The FTC filing doesn't replace those duties.

Report to the governing body and keep the program current

The Qualified Individual must provide a written report to the board of directors or governing body at least annually. For a small company, the governing body may be the owners or an appointed management committee.

Make the annual report useful

A strong report connects security work to business decisions. It should summarize the current risk assessment, major safeguards, testing results, incidents, vendor concerns, unresolved exceptions, training status, planned changes, and resources needed.

The report doesn't need to repeat every help desk ticket. It should give decision-makers enough information to approve priorities and understand the remaining risk. Include the reporting date, author, recipients, meeting date, decisions, and follow-up owners.

Store the signed report with meeting minutes and the supporting evidence. If the business has no formal board, document who received the report and how management approved the next steps.

Update the program after changes

The information security program must be evaluated and adjusted when circumstances change. Triggers include a new office, new product, acquisition, cloud migration, major vendor, incident, test finding, or change in the type of customer information collected.

Maintain an action register with the issue, risk rating, owner, deadline, status, and closure evidence. Written exceptions should state why the control isn't in place, what temporary safeguard applies, who approved it, and when the exception expires.

A policy file without operating records provides little proof. Keep evidence in a controlled location with restricted access, version history, backup protection, and a clear retention period.

Turn the checklist into a 90-day action plan

A small financial business can make useful progress by setting a short sequence of work instead of waiting for a perfect program.

First 30 days

Confirm whether the FTC rule applies and document the conclusion. Name the Qualified Individual, identify every system that handles customer information, review administrator accounts, and require MFA wherever the rule applies.

During the same period, approve an incident response plan and create a list of people to contact. Ask key vendors for current security and breach-notification information. Treat unknown systems, shared accounts, and missing logs as P0 findings.

Days 31 through 60

Complete the written risk assessment and information security program. Document encryption, retention, disposal, access reviews, secure changes, backup protection, and vendor oversight.

Then review the highest-risk applications and cloud services. Remove unnecessary access, close inactive accounts, test backup restoration, and schedule vulnerability assessments. Train employees on the approved procedures and keep completion records.

Days 61 through 90

Run a tabletop incident exercise and review monitoring alerts. Complete the required testing path, assign remediation work, and retest serious findings. Verify that vendors meet contract requirements and that system changes have approval records.

Finally, prepare the Qualified Individual's written report for the governing body. Use the report to approve deadlines, budget, and owners for remaining gaps. Revisit the checklist after any material business or technology change.

Conclusion

The FTC Safeguards Rule becomes manageable when every requirement has a named owner, a working safeguard, and evidence that someone reviewed it. Small financial businesses should start with scope, customer information, MFA, encryption, vendor oversight, incident response, and tested recovery.

A completed FTC Safeguards Rule checklist supports better IT decisions, but it doesn't replace legal or regulatory advice. Confirm your coverage with qualified counsel, keep the written program current, and make security records part of normal business operations.

ASK AN IT PRO