The year runs on schedule
A recurring schedule starts the annual review on the same date each year and the check-in six months later. A missed scan shows up as an overdue task, not a gap found when the board report is due.
The FTCThe FTC’s Safeguards Rule is not a one-off project. It requiresrsquo;s Safeguards Rule requires a written information security programme that is tested and adjusted, with a Qualified Individual reporting on it at least once a year. This free GLBA Safeguards Rule checklist is built for the non-bank financial institutions the FTC oversees, from mortgage brokers and finance companies to tax preparers and auto dealers that finance or lease. It walks the Qualified Individual through every element of 16 CFR 314.4 once a year, with a six-monthly check-in for vulnerability assessments. It hides the tasks the small-institution exemption removes and shows the FTC notification steps only when they are needed. Every task has an owner and every year leaves a record you can hand to an examiner.
The Gramm-Leach-Bliley Act requires financial institutions to protect the security and confidentiality of customer information, but it leaves the detail to each regulator. The FTC’s version is the Standards for Safeguarding Customer Information, 16 CFR Part 314, usually called the Safeguards Rule. It covers financial institutions that no other federal regulator or state insurance authority oversees under the Act. Auto dealers that finance vehicles for consumers, or lease them for longer than 90 days, are covered too. Colleges in the federal student aid programmes agree to comply in their Program Participation Agreement, and the Department of Education checks it in their annual compliance audits.
The FTC rewrote the rule in December 2021. Most of the new elements took effect on 9 June 2023, after a six-month extension, and the duty to notify the FTC of certain breaches followed on 13 May 2024.
Rule: 16 CFR Part 314.
Who: the rule’s examples include mortgage lenders and brokers, payday lenders, finance companies, check cashers, collection agencies, tax preparers and investment advisers not required to register with the SEC.
Distinctive features: a Qualified Individual, specific MFA and encryption requirements, a board report and FTC notice of larger breaches within 30 days.
Banks: the Interagency Guidelines Establishing Information Security Standards, e.g. 12 CFR Part 30, Appendix B.
Federally insured credit unions: the NCUA’s guidelines, 12 CFR Part 748, Appendix A.
Broker-dealers, funds, SEC-registered advisers: Regulation S-P, amended in 2024, with compliance dates of 3 December 2025 for larger entities and 3 June 2026 for smaller ones.
Insurers: state insurance law.
What it covers: privacy notices and consumers’ right to opt out of certain sharing.
Where it lives: Regulation P, 12 CFR Part 1016, or the FTC’s Privacy Rule, 16 CFR Part 313, for motor vehicle dealers.
Why it matters: a clean safeguards review says nothing about your privacy notices.
Seven phases take the annual programme review from scoping to the Qualified Individual’s sign-off. Tasks the small-institution exemption removes hide when you record fewer than 5,000 consumers, and Phase 6 appears only when a notification event occurred.
Owned by the Qualified Individual or the compliance lead. The answers here decide which later tasks appear.
Every institution must base its programme on a risk assessment. The written-assessment task shows only at 5,000 consumers or more.
Re-run at the six-month check-in. The penetration test and scan tasks show only at 5,000 consumers or more.
Shown only when Phase 5 records a notification event. The 30-day clock runs from discovery, not from the review.
The report and board tasks show at 5,000 consumers or more. The sign-off is assigned to the Qualified Individual by name.
Section 314.4 lists ten elements, (a) to (j), and 314.6 exempts institutions with fewer than 5,000 consumers from four of them. The table maps each requirement to its citation, the evidence an examiner would expect and the phase that produces it. Your obligations depend on your firm and your regulator, so treat the table as a starting point, not legal advice.
| Requirement | 16 CFR citation | What evidences it | Under 5,000 consumers | Phase |
|---|---|---|---|---|
| Written information security programme | 314.3(a) | Current programme document, version history | Applies | Phases 1, 7 |
| Qualified Individual, with oversight if outsourced | 314.4(a) | Designation record; senior overseer named | Applies | Phase 1 |
| Risk assessment, periodically repeated | 314.4(b), (b)(2) | Updated risks and safeguard sufficiency | Applies | Phase 2 |
| Written risk assessment with set criteria | 314.4(b)(1) | Rating, CIA and mitigate-or-accept criteria | Exempt | Phase 2 |
| Access controls and MFA | 314.4(c)(1), (c)(5) | Access review; MFA coverage; written approval of any alternative | Applies | Phase 3 |
| Inventory, disposal and retention | 314.4(c)(2), (c)(6) | Asset inventory; disposal log; retention policy review | Applies | Phase 3 |
| Encryption in transit and at rest | 314.4(c)(3) | Encryption status; approved compensating controls | Applies | Phase 3 |
| Secure development, change management, logging | 314.4(c)(4), (c)(7), (c)(8) | Change records; app security testing; log review | Applies | Phase 3 |
| Test or monitor key controls | 314.4(d)(1) | Control testing and intrusion detection records | Applies | Phase 4 |
| Continuous monitoring, or annual pen test and six-monthly vulnerability assessments | 314.4(d)(2) | Monitoring evidence, or test and scan reports | Exempt | Phase 4 |
| Training and security staffing | 314.4(e) | Completion records; staff training and updates | Applies | Phase 5 |
| Service provider oversight | 314.4(f) | Contracts; periodic risk-based assessments | Applies | Phase 5 |
| Written incident response plan | 314.4(h) | Plan covering the seven required areas; test record | Exempt | Phases 5, 6 |
| Evaluate and adjust the programme | 314.4(g) | Documented changes and reasons | Applies | Phase 7 |
| Written report to the board, at least annually | 314.4(i) | Report; date presented; minutes | Exempt | Phase 7 |
| Notify the FTC of a notification event affecting 500+ consumers | 314.4(j) | Discovery date; FTC submission within 30 days | Applies | Phase 6 |
The rhythm follows the rule. Run the full checklist once a year, then run Phase 4 again six months later for the next vulnerability assessment, with the other phases marked not applicable. Banks, credit unions and SEC-registered firms answer to different standards, but the shape of the review carries over.
A recurring schedule starts the annual review on the same date each year and the check-in six months later. A missed scan shows up as an overdue task, not a gap found when the board report is due.
The rule lets the Qualified Individual approve alternatives to MFA and encryption. Those approvals sit on the task they relate to, with who, when and why. The annual sign-off and the board’s receipt of the report are approval steps assigned to named people.
Conditional logic hides the four exempt elements for a firm under 5,000 consumers and shows the FTC notification phase only when there was an event. Test reports, scans and board minutes attach to their tasks, and each year exports as one record.
CheckFlow is a checklist and workflow tool. It is not a vulnerability scanner, a SIEM or a GRC suite, it does not file the FTC notice for you, and it does not replace legal advice. It runs the review, approvals and evidence trail around those tools. See CheckFlow’s compliance checklist software and CheckFlow for financial services for the other recurring reviews regulated firms run.
For Phase 5, the SOC Report Review Checklist gives you a repeatable way to read a vendor’s SOC 2 report, and CheckFlow for SOC 2 helps if you face SOC 2 audits yourself. EU financial entities, under a different regime entirely, can start from the DORA ICT Risk Management Checklist.
Financial institutions that no other GLBA regulator oversees, such as mortgage lenders and brokers, payday lenders, finance companies, collection agencies, tax preparers, non-federally insured credit unions and auto dealers that finance or lease vehicles for consumers. Colleges in the federal student aid programmes commit to it in their Program Participation Agreement. The rule covers all customer information you hold, including information about other institutions’ customers that was passed to you.
Under 16 CFR 314.6, an institution that maintains customer information on fewer than 5,000 consumers is exempt from four elements: the written risk assessment in 314.4(b)(1), the penetration testing and vulnerability assessments in (d)(2), the written incident response plan in (h) and the annual report to the board in (i). Everything else still applies, including the Qualified Individual, MFA, encryption and the duty to notify the FTC.
Unless you have effective continuous monitoring, 16 CFR 314.4(d)(2) requires annual penetration testing scoped from your risk assessment, and vulnerability assessments at least every six months and after material changes to your operations or business arrangements. Institutions under the 5,000-consumer threshold are exempt from this element, but must still test or monitor their key controls.
Since 13 May 2024, 16 CFR 314.4(j) requires notice when a notification event involves the information of at least 500 consumers. A notification event is the unauthorised acquisition of unencrypted customer information; unauthorised access is presumed to be acquisition unless you have reliable evidence otherwise. Notify the FTC as soon as possible, and no later than 30 days after discovery, on its online form. The FTC warns that reports may be made public. State breach laws may require separate notices.
The FTC’s guidance says the role needs no particular degree or title, only real-world expertise suited to your circumstances. The Qualified Individual can be an employee or work for an affiliate or service provider. If you outsource the role, you keep responsibility for compliance, must designate a senior member of staff to oversee them, and must require the provider to maintain a programme that protects you.
No. Banks follow the Interagency Guidelines Establishing Information Security Standards, and federally insured credit unions follow the NCUA’s equivalent. SEC-registered broker-dealers, investment companies and investment advisers follow Regulation S-P, whose 2024 amendments added incident response and customer notification requirements. Insurers follow state insurance law. The elements overlap, so this checklist adapts, but citations and some requirements differ.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.