GLBA Compliance Checklist: The 9 FTC Safeguards Rule Elements Your Program Must Cover

If you are searching for a complete GLBA compliance checklist, you need to look directly at the nine required elements outlined in the federal code. The Gramm-Leach-Bliley Act (GLBA) is a 1999 US federal law. It requires financial institutions to explain how they share and protect their customers’ nonpublic personal information. For non-bank businesses, the data-security piece is implemented by the FTC Safeguards Rule (16 CFR Part 314).
This rule requires non-bank financial institutions under FTC jurisdiction to develop, implement, and maintain a written information security program. The program must be comprehensive and designed to protect customer information. If you run a business that handles consumer financial data, a vague security policy is no longer enough. You need concrete, documented controls.
Key Compliance Dates at a Glance
Three dates define the current rule:
| Date | What happened | Why it matters to you |
|---|---|---|
| 2021 | The FTC amended the Safeguards Rule | The amendment added the key prescriptive provisions this checklist covers |
| June 9, 2023 | The key prescriptive provisions became mandatory | All nine elements below are now required |
| May 13, 2024 | The breach-notification requirement took effect | Report security events involving unencrypted information of 500 or more consumers to the FTC within 30 days of discovery |
Who Must Comply with the FTC Safeguards Rule?
The rule covers non-bank financial institutions as the FTC defines them, which surprises many business owners. If your business is significantly engaged in providing financial products or services to consumers, assume you are covered until proven otherwise. That includes:
- Auto dealers that arrange financing or leasing
- Mortgage brokers
- Non-bank lenders
- Payday and consumer lenders
- Finance companies
- Tax preparation firms
- Accountants and CPA firms
- Debt collectors
- Check cashers
- Wire transferors
- Investment advisers not required to register with the SEC
- Real estate settlement services
- Colleges or universities participating in federal student aid (for that aid data)
FTC Safeguards Rule financial institutions are a broad category. If you fit into any of these buckets, you must follow the nine elements to protect the nonpublic personal information you collect.
The Three Primary Pillars of GLBA
Before reviewing the technical checklist, understand the full scope of Gramm-Leach-Bliley Act requirements.
| Pillar | What it governs | What you must do |
|---|---|---|
| GLBA Financial Privacy Rule | Privacy notices and data sharing | Provide notices explaining how you collect, share, and protect customer data; honor opt-out rights before sharing with unaffiliated third parties |
| GLBA Safeguards Rule | Data security | Put the actual technical and administrative controls in place to keep the data safe; the nine prescriptive elements live here |
| GLBA pretexting provisions | Social engineering defenses | Prevent unauthorized individuals from obtaining customer information under false pretenses |
Pretexting is essentially social engineering. A scammer might call your front desk pretending to be a customer to reset a password.
The 9 Elements of an FTC Safeguards Rule Program
Section 314.4 of the rule requires nine specific elements. Your written information security program (WISP) is the core deliverable. It describes how your business protects customer information, it must be built on a written risk assessment, and it covers all the requirements below. If you need help creating yours, review the WISP build guide.
The checklist at a glance; detail on each element follows.
- Designate a Qualified Individual: one named person implements and supervises the program.
- Base the program on a written risk assessment: identify threats, map where customer data lives.
- Implement specific technical safeguards: access controls, encryption, multi-factor authentication, secure disposal, and logging.
- Regularly test the safeguards: continuous monitoring, or penetration testing plus vulnerability assessments.
- Train staff on security awareness: ongoing, updated for new threats.
- Oversee service providers: by contract and periodic assessment.
- Keep the program current: update it as the business changes.
- Maintain a written incident response plan: roles, containment, recovery, FTC breach reporting.
- Report to the board annually: a written status report from the Qualified Individual.
1. Designate a Qualified Individual
You must designate a single Qualified Individual to implement and supervise the information security program. It can be an employee, or a person at an affiliate or service provider. Many covered small businesses designate a role supported by their managed IT provider. However, the business itself always retains legal responsibility for compliance.
2. Base the Program on a Written Risk Assessment
You cannot protect data if you do not know where it lives or what threatens it. You must base your program on a formal GLBA risk assessment. The process follows four sequential steps:
| Step | Action | What it means |
|---|---|---|
| 1 | Identify threats | Catalog every threat to your nonpublic personal information |
| 2 | Build an asset inventory | Map all systems that store, process, or transmit customer data |
| 3 | Evaluate risks | Assess the likelihood and impact of each threat against those systems |
| 4 | Document mitigations | Write down exactly how you will address each identified risk |
Each step depends on the one before it. You cannot evaluate risks you have not inventoried, and you cannot document mitigations for risks you have not assessed.
3. Implement Specific Technical Safeguards
This element contains the bulk of the technical work. You must implement specific safeguards to control the risks you identified:
- Access controls so employees only see the data they need to do their jobs.
- A data inventory mapping exactly which laptops, servers, and cloud applications hold sensitive files.
- Encryption of customer information at rest and in transit, specifically required by the amended rule.
- Multi-factor authentication for any individual accessing any information system that holds customer information, unless the Qualified Individual approves in writing a reasonably equivalent control. This is the multi-factor authentication financial institutions need to secure their systems.
- Secure development practices for any software you build in-house.
- Secure disposal of customer information no longer needed: properly shred physical documents and wipe hard drives before recycling them.
- Change management procedures for your systems.
- Monitoring and logging of authorized user activity so you can track who accesses what data and when.
4. Regularly Test the Safeguards
The safeguards you put in place must be tested regularly to ensure they work. The rule gives you a choice on how to accomplish this.
Option A: Continuous monitoring. Deploy tools that detect changes in vulnerabilities in real time. For most modern businesses, this is the most practical path. A capable IT partner can set up and manage the monitoring infrastructure.
Option B: Scheduled testing. If you do not run continuous monitoring, you must meet two requirements. First, have a penetration test performed at least once a year. Penetration testing simulates a cyberattack to find weaknesses. Second, run vulnerability assessments at least every six months. Vulnerability scanning looks for known software flaws across your systems.
The continuous monitoring path tends to be less expensive and more thorough over time than scheduling separate pen tests and scans.
5. Train Staff on Security Awareness
Your technology is only as secure as the people using it. Employees need to know how to spot phishing emails, how to handle nonpublic personal information securely, and how to report suspicious activity. This training must be ongoing and updated to reflect new threats.
6. Oversee Service Providers
You cannot outsource your compliance. Vendor management GLBA rules require you to oversee your service providers by contract and assessment. If you hire a third-party software vendor or an outsourced billing company, you must ensure they have adequate security controls in place. You must write security expectations into their contracts and periodically assess their compliance.
7. Keep the Program Current
A security policy you never update is a security policy that fails an audit. If you open a new office, switch to a new cloud software platform, or start offering a new financial product, your risk profile changes. Your Qualified Individual must update the risk assessment and the written information security program to reflect these operational changes.
8. Maintain a Written Incident Response Plan
You must maintain a written incident response plan that dictates exactly what your team will do if a security event occurs. This plan needs to outline roles, responsibilities, and the steps for containment and recovery. A breach-notification requirement was added recently, and it comes with a hard deadline.
Effective May 13, 2024, financial institutions must report to the FTC within 30 days of discovery any security event involving the unencrypted information of 500 or more consumers.
Your incident response plan must account for this strict reporting timeline to ensure you do not miss the legal window.
9. Report to the Board Annually
Finally, the Qualified Individual must report in writing to your board of directors or senior leadership at least annually. This report must detail the overall status of the information security program for financial institutions and any material matters related to it, which keeps leadership informed and accountable.
What Your IT Partner Operates vs. What You Own
Achieving GLBA compliance for small businesses can feel overwhelming, especially when reading through the dense federal code. You do not have to build and manage every technical control yourself, but you must understand the division of responsibilities. A capable managed IT provider handles the technical implementation, while compliance remains a business function you own.
| What your IT partner operates | What you own |
|---|---|
| Deploys encryption protocols and rolls out multi-factor authentication | Enforcing employee security policies |
| Sets up and manages continuous monitoring tools | Ensuring your privacy notices are accurate |
| Coordinates required penetration testing | Overseeing non-technical vendors and service providers |
| Configures logging systems and monitors authorized user activity | Legal liability for FTC enforcement actions |
| Helps draft the technical portions of your incident response plan | Holding the business risk: no vendor absorbs it for you |
| Can serve as or support the Qualified Individual role | Retaining legal responsibility for the program regardless |
LeadingIT does not certify FTC compliance, because no such certification exists. Compliance is an ongoing operational state, not a one-time stamp of approval.
Unlike PCI DSS, the Safeguards Rule is enforced directly by the federal government. The FTC can investigate, bring enforcement actions, impose consent orders with years of oversight obligations, and seek civil penalties. GLBA penalties for non-compliance are severe. Your IT partner helps you become and stay compliant, but compliance is ultimately your responsibility.
Your 9-Element Self-Audit Scorecard
Work through this table honestly. Every “No” is a gap in your written information security program.
| # | Element | In place? | What “yes” looks like |
|---|---|---|---|
| 1 | Qualified Individual | Yes / No | One named person responsible for the program |
| 2 | Written risk assessment | Yes / No | Threats identified, customer data systems mapped |
| 3 | Technical safeguards | Yes / No | Access controls, encryption, MFA |
| 4 | Regular testing | Yes / No | Continuous monitoring, or annual penetration test plus six-month assessments |
| 5 | Security awareness training | Yes / No | Ongoing, updated for new threats |
| 6 | Service provider oversight | Yes / No | Security expectations in contracts, assessed periodically |
| 7 | Program kept current | Yes / No | Updated as the business changes |
| 8 | Written incident response plan | Yes / No | Roles, containment, recovery, the 30-day FTC window |
| 9 | Annual board report | Yes / No | Written report from the Qualified Individual |
See Where You Stand
Take our free 2-minute Safeguards Rule self-check to answer 8 plain-English questions, discover your risk level, and identify the gaps you need to fix with no sign-up required to see your result. free 2-minute Safeguards Rule risk check
Related Guides
- What Is the Gramm-Leach-Bliley Act (GLBA)? Plain English
- How to Write a WISP for the FTC Safeguards Rule
- GLBA Compliance: Who it Covers and What it Requires
- What Is the FTC Safeguards Rule? Who it Covers, What Changed
Frequently Asked Questions
What is the GLBA compliance?
GLBA compliance refers to following the requirements of the Gramm-Leach-Bliley Act of 1999. For non-bank businesses, this primarily means adhering to the FTC Safeguards Rule and the Privacy Rule. It requires you to protect consumer financial data and explain exactly how you share it.
What are the three key rules of GLBA?
The law is built on three main pillars. The Financial Privacy Rule governs how you disclose data sharing to consumers. The Safeguards Rule dictates the technical security controls you must implement. The pretexting provisions require measures to stop social engineering attacks.
Who needs to comply with GLBA?
The law covers financial institutions, which includes many non-bank businesses. Auto dealers that arrange financing, CPA firms, mortgage brokers, and debt collectors are all covered. If your business is significantly engaged in providing financial products or services, you must comply.
What is a GLBA compliance checklist?
A true checklist for this law maps directly to the nine required elements of the FTC Safeguards Rule. It covers designating a Qualified Individual, conducting a risk assessment, and implementing technical controls like encryption. It also includes testing, training, vendor oversight, and incident response planning.
What are examples of GLBA violations?
Failing to implement multi-factor authentication for systems holding customer data is a direct violation. Other examples include skipping your risk assessment or failing to oversee the security practices of your third-party vendors. The FTC can investigate these failures and impose severe penalties.
Secure Your Financial Data
LeadingIT is a Chicagoland managed it and cybersecurity provider that helps you become and stay compliant with federal regulations. We have helped Illinois businesses since 2010, serving roughly 200 organizations and 2,500+ users from our offices in Woodstock and Manteno. If you need help implementing the technical safeguards required by the FTC, explore LeadingIT’s FTC Safeguards compliance services, contact us directly, or book a call at 815-788-6041.
