Free GLBA Compliance and FTC Safeguards Rule Checklist:
See If Your Business Is Compliant
- 9 quick questions
- Takes about 2 minutes
- No sign-up to see your result
Your top next moves
Answer 9 quick questions grounded in the FTC Safeguards Rule and get your risk level in about 2 minutes. The specific gaps to fix and a checklist you can hand to your team or IT provider.
No sign-up to see your result.
“Not sure” counts, because if you can’t confirm a control is in place, an FTC examiner can’t either.
What the FTC Safeguards Rule Actually Is (The Short Version)
The FTC Safeguards Rule is the federal regulation (16 CFR Part 314) that requires “financial institutions” under FTC jurisdiction to build and maintain a written information security program to protect their customers’ financial information. It’s the security piece of the Gramm-Leach-Bliley Act (GLBA). The Rule was significantly expanded in 2021, and the tougher requirements:
a named program owner, encryption, multi-factor authentication, written risk assessments, and more, took full effect in June 2023.
It applies whether you have two employees or two hundred.
The important thing most businesses miss: “financial institution” is far broader than banks. It covers a long list of non-bank businesses that handle customer financial information, including auto dealers, mortgage brokers and lenders, tax preparers, accountants and CPAs, payday and consumer lenders, finance companies, debt collectors, check cashers, wire transferors, investment advisers who aren’t registered with the SEC, and companies that bring in customers for these services. If your business collects financial information to provide a financial product or service, the Rule most likely applies to you.

The important thing most businesses miss: “financial institution” is far broader than banks.
It covers a long list of non-bank businesses that handle customer financial information, including auto dealers, mortgage brokers and lenders, tax preparers, accountants and CPAs, payday and consumer lenders, finance companies, debt collectors, check cashers, wire transferors, investment advisers who aren’t registered with the SEC, and companies that bring in customers for these services. If your business collects financial information to provide a financial product or service, the Rule most likely applies to you.
The checklist below is organized around the nine required elements of a compliant security program and matches the 9 questions in the tool above, so a “no” or “not sure” up top maps straight to a section here.
The FTC Safeguards Rule Checklist (16 CFR § 314.4)
Work through each area. Anything you can’t confirm is a gap, if you can’t prove it, an FTC examiner can’t either.
- 1. Designate a Qualified Individual to Run the Program:
✓ One specific person is named, in writing, to oversee and implement your information security program.
✓ That Qualified Individual can be an employee or an outside provider (such as your MSP or a virtual CISO), but it has to be a single accountable owner, not “everyone and no one.”
✓ If the role is outsourced, you keep a senior person responsible for overseeing that provider. - 2. Base the Program on a Written Risk Assessment:
✓ You have a written risk assessment, a document, not a hunch, that identifies reasonably foreseeable internal and external risks to customer financial information.
✓ It covers the confidentiality, integrity, and availability of that information and how each risk is being addressed
✓ It’s periodically reassessed as your systems, vendors, and business change - 3. Inventory Your Data and Enforce Access Controls
✓ You know everywhere customer financial information lives: every system, file share, application, and cloud service.
✓ Access is limited to the people who actually need it (least privilege), and access rights are reviewed periodically.
✓ The rule expects a current data inventory of what you collect, where it flows, and where it’s stored. - 4. Encrypt Customer Information, at Rest and in Transit
✓ Customer information is encrypted while stored (laptops, servers, drives, backups) and while sent over the internet (email, portals, file transfers)
✓ A stolen laptop, lost drive, or intercepted message stays unreadable
✓ Where encryption isn’t feasible, an equivalent control is approved in writing by the Qualified Individual - 5. Require Multi-Factor Authentication (MFA)
✓ MFA is enforced for any individual accessing systems that hold customer information, a second step (an app prompt or code) on top of the password.
✓ Stolen passwords are one of the most common ways attackers get in, which is why the Rule makes MFA (or an equally secure access control approved by the Qualified Individual) a hard requirement.
✓ This applies to email, remote access, and internal systems that touch customer data, not just remote logins. - 6. Dispose of Data Securely and Log System Activity:
✓ Customer information is securely disposed of no later than two years after the last time it was used to serve the customer, unless a legitimate business or legal reason requires keeping it.
✓ You maintain a documented data-retention and disposal schedule and periodically review what you’re holding.
✓ You log and monitor authorized users’ activity so you can detect unauthorized access to or misuse of customer information. - 7. Test your Safeguards Regularly
✓ You regularly test or monitor the effectiveness of your controls.
✓ If you don’t use continuous monitoring, the Rule expects annual penetration testing plus vulnerability assessments at least every six months (and after any material change).
✓ Weaknesses that testing surfaces are tracked through to remediation. - 8. Train your People:
✓ Staff receive security-awareness training so they can recognize phishing and other threats.
✓ Personnel responsible for security stay current on evolving risks and how to address them.
✓ Training is refreshed and reinforced on a recurring basis, not once at hire. - 9. Oversee Vendors, Plan for Incidents, and Report to Leadership:
✓ Service providers who touch customer information are selected for their ability to safeguard it and are held to security requirements by contract, with periodic assessment of their work.
✓ You have a written incident-response plan covering how you’ll respond to and recover from a security event affecting customer information.
✓ The Qualified Individual reports in writing, at least annually, to your board or a senior officer on the state of the program and any material risks.
How to read your gaps?
Most of the technical items above (MFA, encryption, audit logging, tested backups) live in your IT setup, not a policy binder, which is the half of HIPAA a managed IT partner operates for you.
- 0 – 2 “No/Not Sure” Answers
Strong Shape, confirm the pieces you’re unsure of and keep the written parts current.
- 03-6 “No/Not Sure” Answers
Real, findable gaps against the Safeguards Rule, exactly what an examiner or an attacker would find first.
- 7+ “No/Not Sure” Answers
Core required elements are missing, and you’re carrying meaningful exposure to both a breach and an enforcement action right now.
Most of the technical elements above, encryption, MFA, access controls, logging, testing, live in your IT setup, not a policy binder, which is the half of the Safeguards Rule a managed IT partner operates for you.
FTC Safeguards Rule Checklist FAQ
The FTC Safeguards Rule (16 CFR Part 314) is a federal regulation, part of the Gramm-Leach-Bliley Act, that requires “financial institutions” under FTC jurisdiction to maintain a written information security program protecting customer financial information. “Financial institution” is defined broadly, it’s not just banks. It covers auto dealers, mortgage brokers and lenders, tax preparers, accountants and CPAs, payday and consumer lenders, finance companies, debt collectors, check cashers, wire transferors, non-SEC-registered investment advisers, and businesses that refer customers to those services. If you handle customer financial information to provide a financial product or service, the Rule most likely applies to you.
A complete checklist maps to the nine required elements of § 314.4: designate a Qualified Individual to run the program, base it on a written risk assessment, inventory your data and enforce access controls, encrypt customer information at rest and in transit, require multi-factor authentication, securely dispose of data and log system activity, regularly test your safeguards, train your staff, and oversee your vendors while maintaining a written incident-response plan and reporting to leadership at least annually. The nine areas above group those elements to match the tool at the top of this page.
Any business “significantly engaged” in providing financial products or services to consumers. That deliberately sweeps in many businesses that don’t think of themselves as financial: car dealerships (through financing), mortgage brokers, tax-prep firms, accounting practices, collection agencies, consumer and payday lenders, finance companies, check cashers, wire transfer services, and companies that bring customers to any of these. A company doesn’t have to be a bank, it just has to handle customers’ financial information in the course of a financial service.
The Rule requires a written program built on these elements: a designated Qualified Individual to oversee it; a written risk assessment; safeguards to control identified risks, including access controls, a data inventory, encryption of customer information at rest and in transit, secure development practices, multi-factor authentication, secure disposal, change management, and logging of authorized user activity; regular testing of those safeguards; security-awareness training and qualified staff; oversight of service providers; a written plan to evaluate and adjust the program over time; a written incident-response plan; and an annual written report from the Qualified Individual to the board or a senior officer. The checklist above condenses these nine elements into workable areas that match the tool.
The FTC enforces the Safeguards Rule and can bring an enforcement action, which can lead to a consent order requiring years of independent security assessments, mandated program changes, and ongoing oversight, plus the legal and remediation costs that come with it. More common and more expensive in practice is the breach the Rule exists to prevent: recovery costs, notification and legal expenses, and lost customer trust. Because you can’t predict the timing of either, the practical answer is to close your gaps now and stay compliance-ready year-round.
Ready to close your gaps?
If your result flagged three or more gaps, most of them are technical work an IT partner handles day to day, a named Qualified Individual, a written risk assessment, encryption, MFA, access controls, logging, and testing.
LeadingIT has helped Chicagoland businesses lock down their systems and meet security requirements since 2010.
We’re not a regulator and we don’t certify or issue FTC compliance, we build and operate the written program, security controls, and ongoing monitoring the Safeguards Rule requires, and we can serve as your Qualified Individual.
Email yourself the full result from the tool above, book a free 30-minute gap review, or see how we deliver FTC Safeguards compliance as a managed service.