GLBA Safeguards Rule Checklist Template

Writing the information security programme was the 2023 project. The harder part is showing, every year since, the risk assessment update, the six-monthly scans and the written report to the board that the FTC rule expects.

The FTCThe FTC’s Safeguards Rule is not a one-off project. It requiresrsquo;s Safeguards Rule requires a written information security programme that is tested and adjusted, with a Qualified Individual reporting on it at least once a year. This free GLBA Safeguards Rule checklist is built for the non-bank financial institutions the FTC oversees, from mortgage brokers and finance companies to tax preparers and auto dealers that finance or lease. It walks the Qualified Individual through every element of 16 CFR 314.4 once a year, with a six-monthly check-in for vulnerability assessments. It hides the tasks the small-institution exemption removes and shows the FTC notification steps only when they are needed. Every task has an owner and every year leaves a record you can hand to an examiner.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: September 2026

One Law, Several Rulebooks: Which Safeguards Standard Is Yours?

The Gramm-Leach-Bliley Act requires financial institutions to protect the security and confidentiality of customer information, but it leaves the detail to each regulator. The FTC’s version is the Standards for Safeguarding Customer Information, 16 CFR Part 314, usually called the Safeguards Rule. It covers financial institutions that no other federal regulator or state insurance authority oversees under the Act. Auto dealers that finance vehicles for consumers, or lease them for longer than 90 days, are covered too. Colleges in the federal student aid programmes agree to comply in their Program Participation Agreement, and the Department of Education checks it in their annual compliance audits.

The FTC rewrote the rule in December 2021. Most of the new elements took effect on 9 June 2023, after a six-month extension, and the duty to notify the FTC of certain breaches followed on 13 May 2024.

FTC Safeguards Rule

Non-bank financial institutions

Rule: 16 CFR Part 314.

Who: the rule’s examples include mortgage lenders and brokers, payday lenders, finance companies, check cashers, collection agencies, tax preparers and investment advisers not required to register with the SEC.

Distinctive features: a Qualified Individual, specific MFA and encryption requirements, a board report and FTC notice of larger breaches within 30 days.

Other GLBA safeguards standards

Banks, credit unions, SEC registrants, insurers

Banks: the Interagency Guidelines Establishing Information Security Standards, e.g. 12 CFR Part 30, Appendix B.

Federally insured credit unions: the NCUA’s guidelines, 12 CFR Part 748, Appendix A.

Broker-dealers, funds, SEC-registered advisers: Regulation S-P, amended in 2024, with compliance dates of 3 December 2025 for larger entities and 3 June 2026 for smaller ones.

Insurers: state insurance law.

Out of scope here

The GLBA Privacy Rule

What it covers: privacy notices and consumers’ right to opt out of certain sharing.

Where it lives: Regulation P, 12 CFR Part 1016, or the FTC’s Privacy Rule, 16 CFR Part 313, for motor vehicle dealers.

Why it matters: a clean safeguards review says nothing about your privacy notices.

What the GLBA Safeguards Rule Checklist Covers

Seven phases take the annual programme review from scoping to the Qualified Individual’s sign-off. Tasks the small-institution exemption removes hide when you record fewer than 5,000 consumers, and Phase 6 appears only when a notification event occurred.

Phase 1

Phase 1: Scope the Review & Confirm the Qualified Individual

Owned by the Qualified Individual or the compliance lead. The answers here decide which later tasks appear.

  • Confirm the institution falls under the FTC Safeguards Rule — not the bank guidelines, Regulation S-P or state insurance law
  • Count the consumers whose customer information you maintain — fewer than 5,000 brings the 314.6 exemption
  • Confirm the Qualified Individual designation — if outsourced, name the senior person who oversees them
  • Name who receives the annual report — the board or equivalent body, or else the responsible senior officer
  • Carry forward open actions — from last year’s report and the six-monthly check-in
Phase 2

Phase 2: Risk Assessment

Every institution must base its programme on a risk assessment. The written-assessment task shows only at 5,000 consumers or more.

  • Reassess reasonably foreseeable internal and external risks to customer information — new systems, products, vendors and threats
  • Reassess whether existing safeguards are sufficient for each risk — each gap gets an owner and a date
  • Update the written risk assessment — criteria for rating risks, assessing confidentiality, integrity and availability, and mitigating or accepting each risk
  • Record risk acceptance decisions — who accepted each residual risk, and why
Phase 3

Phase 3: Safeguards Review

  • Review access controls — users reach only the customer information their role needs
  • Refresh the inventory of data, personnel, devices, systems and facilities — ranked by business importance
  • Confirm encryption of customer information in transit over external networks and at rest — exceptions need Qualified Individual-approved compensating controls
  • Check multi-factor authentication covers anyone accessing any information system — alternatives need written approval
  • Review secure development and change management — in-house code, external applications and change approvals
  • Test the disposal procedure — disposal within two years of last use unless an exception applies; retention policy reviewed
  • Confirm logging and monitoring of authorised user activity — tampering and unauthorised use are detected
Phase 4 — Also Six-Monthly

Phase 4: Testing & Monitoring

Re-run at the six-month check-in. The penetration test and scan tasks show only at 5,000 consumers or more.

  • Record how key controls are tested or monitored — including intrusion detection
  • Confirm the approach for information systems — continuous monitoring, or annual penetration testing plus vulnerability assessments
  • Attach this year’s penetration test — scoped from the risk assessment
  • Attach the vulnerability assessments — at least six-monthly, and after material business changes
  • Track findings to remediation — owner, due date and retest evidence
Phase 5

Phase 5: People, Service Providers & Incidents

  • Confirm security awareness training is complete — content updated for current risks
  • Confirm information security staffing — qualified people, kept current on threats
  • Assess service providers by risk — contract safeguards and current evidence, such as SOC 2 reports
  • Review and test the written incident response plan — roles, decision authority, communications and remediation
  • Review the security event log for the period — record whether any event was a notification event
Phase 6 — If an Event Occurred

Phase 6: FTC Notification Event

Shown only when Phase 5 records a notification event. The 30-day clock runs from discovery, not from the review.

  • Confirm the event meets the notification event definition — unauthorised acquisition of unencrypted customer information
  • Record the discovery date — the first day any employee, officer or agent other than the perpetrator knew of it
  • Count the consumers affected — 500 or more means the FTC must be notified
  • Submit the FTC notice on the online form — no later than 30 days after discovery; keep the confirmation
  • Check other notice obligations — state breach laws and contracts run on their own timelines
  • Evaluate and revise the incident response plan after the event — lessons logged as actions
Phase 7

Phase 7: Evaluate, Report & Sign Off

The report and board tasks show at 5,000 consumers or more. The sign-off is assigned to the Qualified Individual by name.

  • Evaluate and adjust the programme — for test results, risk changes, security events and business changes
  • Write the Qualified Individual’s report to the board — overall status, compliance with the rule and material matters
  • Board or senior officer receives the report — date presented, questions raised and decisions
  • Qualified Individual signs off the annual review — every action has an owner and a due date
  • Schedule the six-monthly vulnerability assessment check-in — before the review closes

Safeguards Rule Requirements Map

Section 314.4 lists ten elements, (a) to (j), and 314.6 exempts institutions with fewer than 5,000 consumers from four of them. The table maps each requirement to its citation, the evidence an examiner would expect and the phase that produces it. Your obligations depend on your firm and your regulator, so treat the table as a starting point, not legal advice.

Requirement 16 CFR citation What evidences it Under 5,000 consumers Phase
Written information security programme314.3(a)Current programme document, version historyAppliesPhases 1, 7
Qualified Individual, with oversight if outsourced314.4(a)Designation record; senior overseer namedAppliesPhase 1
Risk assessment, periodically repeated314.4(b), (b)(2)Updated risks and safeguard sufficiencyAppliesPhase 2
Written risk assessment with set criteria314.4(b)(1)Rating, CIA and mitigate-or-accept criteriaExemptPhase 2
Access controls and MFA314.4(c)(1), (c)(5)Access review; MFA coverage; written approval of any alternativeAppliesPhase 3
Inventory, disposal and retention314.4(c)(2), (c)(6)Asset inventory; disposal log; retention policy reviewAppliesPhase 3
Encryption in transit and at rest314.4(c)(3)Encryption status; approved compensating controlsAppliesPhase 3
Secure development, change management, logging314.4(c)(4), (c)(7), (c)(8)Change records; app security testing; log reviewAppliesPhase 3
Test or monitor key controls314.4(d)(1)Control testing and intrusion detection recordsAppliesPhase 4
Continuous monitoring, or annual pen test and six-monthly vulnerability assessments314.4(d)(2)Monitoring evidence, or test and scan reportsExemptPhase 4
Training and security staffing314.4(e)Completion records; staff training and updatesAppliesPhase 5
Service provider oversight314.4(f)Contracts; periodic risk-based assessmentsAppliesPhase 5
Written incident response plan314.4(h)Plan covering the seven required areas; test recordExemptPhases 5, 6
Evaluate and adjust the programme314.4(g)Documented changes and reasonsAppliesPhase 7
Written report to the board, at least annually314.4(i)Report; date presented; minutesExemptPhase 7
Notify the FTC of a notification event affecting 500+ consumers314.4(j)Discovery date; FTC submission within 30 daysAppliesPhase 6

The rhythm follows the rule. Run the full checklist once a year, then run Phase 4 again six months later for the next vulnerability assessment, with the other phases marked not applicable. Banks, credit unions and SEC-registered firms answer to different standards, but the shape of the review carries over.

Why Run Your Safeguards Rule Review in CheckFlow?

1

The year runs on schedule

A recurring schedule starts the annual review on the same date each year and the check-in six months later. A missed scan shows up as an overdue task, not a gap found when the board report is due.

2

Exceptions carry a name and a date

The rule lets the Qualified Individual approve alternatives to MFA and encryption. Those approvals sit on the task they relate to, with who, when and why. The annual sign-off and the board’s receipt of the report are approval steps assigned to named people.

3

The checklist fits the firm

Conditional logic hides the four exempt elements for a firm under 5,000 consumers and shows the FTC notification phase only when there was an event. Test reports, scans and board minutes attach to their tasks, and each year exports as one record.

CheckFlow is a checklist and workflow tool. It is not a vulnerability scanner, a SIEM or a GRC suite, it does not file the FTC notice for you, and it does not replace legal advice. It runs the review, approvals and evidence trail around those tools. See CheckFlow’s compliance checklist software and CheckFlow for financial services for the other recurring reviews regulated firms run.

For Phase 5, the SOC Report Review Checklist gives you a repeatable way to read a vendor’s SOC 2 report, and CheckFlow for SOC 2 helps if you face SOC 2 audits yourself. EU financial entities, under a different regime entirely, can start from the DORA ICT Risk Management Checklist.

Frequently Asked Questions

Who has to comply with the FTC Safeguards Rule?

+

Financial institutions that no other GLBA regulator oversees, such as mortgage lenders and brokers, payday lenders, finance companies, collection agencies, tax preparers, non-federally insured credit unions and auto dealers that finance or lease vehicles for consumers. Colleges in the federal student aid programmes commit to it in their Program Participation Agreement. The rule covers all customer information you hold, including information about other institutions’ customers that was passed to you.

What does the Safeguards Rule exemption for small businesses cover?

+

Under 16 CFR 314.6, an institution that maintains customer information on fewer than 5,000 consumers is exempt from four elements: the written risk assessment in 314.4(b)(1), the penetration testing and vulnerability assessments in (d)(2), the written incident response plan in (h) and the annual report to the board in (i). Everything else still applies, including the Qualified Individual, MFA, encryption and the duty to notify the FTC.

How often does the Safeguards Rule require penetration testing?

+

Unless you have effective continuous monitoring, 16 CFR 314.4(d)(2) requires annual penetration testing scoped from your risk assessment, and vulnerability assessments at least every six months and after material changes to your operations or business arrangements. Institutions under the 5,000-consumer threshold are exempt from this element, but must still test or monitor their key controls.

When do you have to report a data breach to the FTC?

+

Since 13 May 2024, 16 CFR 314.4(j) requires notice when a notification event involves the information of at least 500 consumers. A notification event is the unauthorised acquisition of unencrypted customer information; unauthorised access is presumed to be acquisition unless you have reliable evidence otherwise. Notify the FTC as soon as possible, and no later than 30 days after discovery, on its online form. The FTC warns that reports may be made public. State breach laws may require separate notices.

Who can be the Qualified Individual?

+

The FTC’s guidance says the role needs no particular degree or title, only real-world expertise suited to your circumstances. The Qualified Individual can be an employee or work for an affiliate or service provider. If you outsource the role, you keep responsibility for compliance, must designate a senior member of staff to oversee them, and must require the provider to maintain a programme that protects you.

Does the FTC Safeguards Rule apply to banks and broker-dealers?

+

No. Banks follow the Interagency Guidelines Establishing Information Security Standards, and federally insured credit unions follow the NCUA’s equivalent. SEC-registered broker-dealers, investment companies and investment advisers follow Regulation S-P, whose 2024 amendments added incident response and customer notification requirements. Insurers follow state insurance law. The elements overlap, so this checklist adapts, but citations and some requirements differ.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

One Signed Safeguards Review a Year, Scans Checked Every Six Months

Free trial — no credit card required.