Compliance — FTC Safeguards
FTC Safeguards Rule compliance services
The Rule’s definition of a financial institution is about what you do, not what your sign says. CPA and tax firms, financial advisors, mortgage brokers, insurance agencies, and auto dealers are covered — at any size — and the Rule prescribes nine specific program elements. We operate them.
Who is covered — and usually surprised
The Safeguards Rule reaches any business significantly engaged in financial activities for consumers, which sweeps in thousands of firms that have never thought of themselves as financial institutions: CPA and tax preparation firms, RIAs and financial advisors, mortgage brokers, insurance agencies, collection agencies, and auto dealerships arranging financing. There is no size threshold for coverage. A narrow carve-out relaxes a few written-documentation requirements for firms holding information on fewer than 5,000 consumers — the technical safeguards apply regardless.
In practice, the pressure rarely arrives as an FTC letter. It arrives as a custodian’s due-diligence request, a cyber-insurance application, or a client asking how their tax documents are protected. The firms that feel it first are exactly the ones with the least security staff — which for most covered firms means none. That is the gap this service closes; see also accounting and CPA firms.
The nine elements of 16 CFR 314.4
The Rule is unusually specific about what your program must contain. Here is each element, and how we run it.
1. Designate a Qualified Individual
One person accountable for the program — an employee or a service provider’s; we support or supply the function, detailed below.
2. Written risk assessment
An inventory of customer information, an assessment of threats to it, and periodic reassessment — produced and maintained by us, in writing.
3. Design and implement safeguards
The technical core: access controls, data inventory, encryption at rest and in transit, MFA, secure disposal, change management, and monitoring of user activity — the daily work of a managed IT and security practice.
4. Test and monitor
Continuous monitoring, or annual penetration testing plus vulnerability assessments every six months — we run the continuous option and document it.
5. Train your people
Security awareness training with completion records, because your staff handle the data the Rule protects.
6. Oversee service providers
Vendors that touch customer information selected for capability, bound by contract, and reassessed periodically.
7. Keep the program current
The program adjusted as your operations, systems, and test results change — a standing review, not a one-time project.
8. Written incident response plan
Roles, communications, remediation, and post-incident revision, written down and rehearsed before anything happens.
9. Annual report to your board
A written report from the Qualified Individual on program status, risk, and incidents — we draft it with the evidence attached.
Your Qualified Individual does not have to be a security expert
The Rule requires designating a Qualified Individual; it does not require hiring a CISO. The role can be filled by an employee or by a service provider — and when a provider fills it, you retain a senior employee to direct and oversee the work. In practice: your partner or operations lead holds the accountability, and we do the operating, the testing, the documentation, and the annual report they sign.
We prepare and operate safeguards; we are not a law firm or an auditor, and whether the Rule covers an edge case in your business is a question for counsel. Note for insurance agencies and some advisors licensed in New York: you likely sit under NYDFS Part 500 as well. The control sets overlap almost entirely, so we operate one program and evidence it for both — see the compliance hub.
Good fit if
CPA or tax firm with client portals and no security staff
Advisory firm or agency told by a custodian or carrier to formalize its program
Dealership holding finance and insurance data
You were named Qualified Individual and want operational backing
Your WISP is a template no one operates
Common questions
We are a three-partner CPA firm. Does the Rule really apply to us?
Coverage is activity-based with no size threshold — preparing returns and holding client financial data is enough. Firms with information on fewer than 5,000 consumers are excused from a few written-documentation elements, not from the safeguards themselves. For a genuine edge case, ask your counsel; we will build the program to whatever the answer is.
Who should we name as Qualified Individual?
Someone senior enough to be genuinely accountable — a partner or operations lead is typical. The Rule allows the expertise to come from a service provider, so the person you name does not need a security background; they need our reporting in front of them and the authority to act on it.
Is a WISP the same thing as Safeguards Rule compliance?
A WISP — a written information security program — is what the Rule effectively requires, but a document alone satisfies nothing. Ours is written from your actual environment and then operated: the testing, training, monitoring, and annual reporting the document promises.
What enforcement should we actually worry about?
FTC enforcement actions exist and the penalties are real, but the pressure most firms feel first is commercial: custodians, carriers, and clients asking for proof of the program. The same evidence answers all of them, which is why we build the program to be shown, not just held.
How long does it take to stand up the nine elements?
Firms with reasonable IT hygiene typically need a few months to close the gaps and formalize the program; firms starting from scratch need longer. The gap assessment gives you a real timeline before you commit to anything.
Nine elements, operated — not laminated.
A Safeguards gap assessment maps your current state against all nine elements. You keep the findings either way.