Skip to content

Evidence request lists

FTC GLBA Safeguards Rule (16 CFR Part 314)

Evidence request list. 11 controls, 11 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

FTC Safeguards Rule: 9 Safeguard Elements - Access, Encryption, MFA, Disposal, Change, Monitoring, Pen Test (314.4(c))

FTC-Safeguards-9-Elements
9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

16 CFR 314.4(c)(1-9) the 9 SPECIFIC SAFEGUARD ELEMENTS (added by 2021 amendments). (1) ACCESS CONTROLS - place access controls + limit access to authorized users + role-based + least-privilege + periodic review + revoke access promptly upon termination/role change; (2) DATA INVENTORY AND CLASSIFICATION - identify + manage data + personnel + devices + systems + facilities that enable the institution to achieve its purposes in accordance with their relative importance to business objectives + risk strategy; (3) ENCRYPTION of customer information held or transmitted by the institution both at REST and in TRANSIT over external networks - if encryption is infeasible + the Qualified Individual may approve compensating controls in writing; (4) SECURE DEVELOPMENT PRACTICES for in-house developed applications used to transmit + access + store customer information; (5) MULTI-FACTOR AUTHENTICATION

Artefacts an auditor will ask for
  • 9 elements implementation evidence
  • MFA enrollment + compensating controls
  • Encryption inventory + assessment
  • Pen test + vuln assessment reports
Where this commonly fails
  • Any of 9 elements partial or absent
  • MFA without coverage gap or compensating controls
  • Encryption inconsistent
  • Pen test + vuln assessment cadence missed

FTC Safeguards Rule: Comprehensive Information Security Program and Qualified Individual (314.3, 314.4(a))

FTC-Safeguards-Program-Qualified-Individual
Comprehensive Information Security Program + Qualified Individual (16 CFR 314.3, 314.4(a))

16 CFR 314.3 standards for safeguarding customer information + 314.4(a) Qualified Individual. STANDARD: financial institution must DEVELOP + IMPLEMENT + MAINTAIN a comprehensive WRITTEN INFORMATION SECURITY PROGRAM (WISP) containing administrative + technical + physical safeguards appropriate to its size + complexity + nature + scope of activities + the sensitivity of any customer information at issue. OBJECTIVES: (a) INSURE the security + confidentiality of customer information; (b) PROTECT against ANY ANTICIPATED THREATS or hazards to security or integrity; (c) PROTECT against UNAUTHORIZED ACCESS or use that could result in substantial harm or inconvenience. QUALIFIED INDIVIDUAL (314.4(a)): the institution MUST DESIGNATE a QUALIFIED INDIVIDUAL responsible for OVERSEEING + IMPLEMENTING + ENFORCING the information security program. The Qualified Individual may be in-house or third-party;

Artefacts an auditor will ask for
  • WISP document + version control
  • Qualified Individual appointment letter + qualifications
  • Annual Board report
Where this commonly fails
  • WISP missing or generic
  • Qualified Individual unqualified or under-resourced
  • Board reporting skipped

FTC Safeguards Rule: Effective Date, Small Institution Exemption and 2024-2025 Pipeline (314.5, 314.6, Coordination)

FTC-Safeguards-2024-2025-Status
2024-2025 Implementation Status, FTC Enforcement Actions and Anticipated Amendments

FTC Safeguards Rule 2024-2025 implementation status. EFFECTIVE DATES: full 2021 amendments effective 9 January 2022 + 13 January 2023 (delayed elements) + 13 May 2024 (FTC notification requirement). 2024-2025 FTC ENFORCEMENT ACTIONS (publicly published): multiple settlements + complaints against (a) MORTGAGE BROKERS for lack of WISP + Qualified Individual + MFA + encryption; (b) AUTO DEALERS for insufficient safeguards + service-provider oversight; (c) TAX PREPARERS for breach notification failures + cyber-incident response gaps; (d) CONSUMER REPORTING AGENCIES for systemic safeguards deficiencies; (e) INVESTMENT ADVISORS (where SEC + FTC dual-jurisdictional). PENALTIES range from civil penalties up to USD 50,000-100,000 per violation (FTC Act Section 5(m)) + injunctive relief + monetary refunds to affected consumers + COMPLIANCE MONITORING. ANTICIPATED 2025 AMENDMENTS (per FTC public ag

Artefacts an auditor will ask for
  • Effective-date compliance attestation
  • Enforcement-action tracking + lessons learned
  • 2025 amendment readiness plan
  • Industry benchmarking adoption
Where this commonly fails
  • Effective dates missed without remediation
  • FTC enforcement risk not assessed
  • 2025 amendment readiness gap
FTC-Safeguards-AI-SBOM-Pipeline
AI Use, SBOM, Supply Chain and 2024-2025 Emerging Areas

FTC Safeguards Rule emerging areas in 2024-2025. AI USE IN FINANCIAL INSTITUTIONS: FTC AI guidance + 2024 OMB M-22-09 ZTA + 2024 OMB M-24-08 AI Risk Management + Section 5 FTC Act unfair-and-deceptive enforcement against discriminatory AI + opaque scoring + biased credit decisions; financial institutions using AI for credit + underwriting + fraud detection + customer service must integrate AI risk into the 314.4(b) written risk assessment + 314.4(c) safeguard elements; the QUALIFIED INDIVIDUAL must ensure AI systems handling customer information are subject to: (a) data inventory + classification (314.4(c)(2)); (b) encryption (314.4(c)(3)); (c) MFA for AI system access (314.4(c)(5)); (d) monitoring + logging (314.4(c)(8)); (e) pen testing/vuln assessment of AI components (314.4(c)(9)). SBOM + SOFTWARE BILL OF MATERIALS: 2024 OMB M-22-18 + FTC guidance require SBOM for critical software u

Artefacts an auditor will ask for
  • AI risk assessment + safeguards
  • SBOM inventory + assessment
  • Cyber insurance review + AI coverage
  • CFPB 1033 compliance
Where this commonly fails
  • AI risk ignored in safeguards
  • SBOM not tracked
  • Cyber insurance coverage gaps
  • CFPB 1033 obligations missed
FTC-Safeguards-Coord-Banking-SEC-Higher-Ed
Coordination with Banking Agencies, SEC, Higher Education Safeguards and Insurance

FTC Safeguards Rule coordination with parallel regulators. BANKING AGENCIES (Interagency Guidelines per 12 CFR Parts 30 + 208 + 225 + 364 + 748): OCC + FRB + FDIC + NCUA issue equivalent safeguards regulations for federally-supervised banks + savings associations + credit unions; banks + credit unions are NOT subject to FTC Safeguards Rule (under banking regulator jurisdiction); the Interagency Guidelines are conceptually similar but apply different procedural specifics + supervisory expectations. SEC (17 CFR Part 248 Regulation S-P): SEC-registered investment advisors + broker-dealers + investment companies subject to SEC's Safeguards Rule under Regulation S-P (similar but with 2024 amendments adding incident notification + 30-day notification for affected individuals). CFPB: residual jurisdiction over certain non-bank financial institutions + may coordinate with FTC. STATE INSURANCE CO

Artefacts an auditor will ask for
  • Regulatory crosswalk + applicability
  • Parallel-regulator coordination + reporting
  • NAIC + state insurance compliance if applicable
Where this commonly fails
  • Wrong regulator applied
  • Parallel regulations gaps
  • NAIC + state insurance overlooked
FTC-Safeguards-Crosswalk-NIST-ISO-SOC
Crosswalk to NIST CSF 2.0, NIST SP 800-53, ISO 27001 and SOC 2

FTC Safeguards Rule crosswalk to comprehensive cybersecurity + privacy frameworks. NIST CSF 2.0 mapping: GOVERN (Qualified Individual + Board reporting + program governance) + IDENTIFY (314.4(b) risk assessment + 314.4(c)(2) data inventory) + PROTECT (314.4(c)(1) access controls + (3) encryption + (4) secure dev + (5) MFA + (6) disposal + (7) change mgmt) + DETECT (314.4(c)(8) monitoring + 314.4(g)(5) continuous monitoring or pen test/vuln assess) + RESPOND (314.4(h) written IRP) + RECOVER (314.4(h)(5) remediation). NIST SP 800-53 Rev 5: detailed control catalog + mapping at the AC + AT + AU + CA + CM + CP + IA + IR + MA + MP + PE + PL + PM + PS + PT + RA + SA + SC + SI + SR control families; FTC Safeguards generally aligns with Moderate baseline subset. ISO/IEC 27001:2022 + ISO/IEC 27701:2019: ISMS + PIMS structure provides framework for FTC Safeguards Rule program implementation. SOC 2

Artefacts an auditor will ask for
  • Crosswalk document
  • Compliance evidence per framework
  • SOC 2 report if applicable
Where this commonly fails
  • Crosswalk not maintained
  • Multi-framework alignment ad-hoc
  • SOC 2 report stale
FTC-Safeguards-EffectiveDate-Small-Institution
Effective Date, Small Institution Exemption and Sectoral Coordination (16 CFR 314.5, 314.6)

16 CFR 314.5 + 314.6. EFFECTIVE DATE (314.5): the FTC Safeguards Rule as amended in 2021 is in effect since 9 January 2022 + with January 2023 for elements requiring additional time (Qualified Individual + risk assessment + the 9 safeguard elements + continuous monitoring/pen test + incident response plan + Board reporting); the 2023 FTC NOTIFICATION REQUIREMENT (314.4(j)) became effective 13 May 2024. SMALL INSTITUTION EXEMPTION (314.6): financial institutions maintaining customer information concerning FEWER THAN 5,000 CONSUMERS qualify for SIMPLIFIED COMPLIANCE - they need not comply with all the detailed requirements but MUST: (a) DEVELOP + maintain a WRITTEN INFORMATION SECURITY PROGRAM addressing the standards of 314.3; (b) DESIGNATE A QUALIFIED INDIVIDUAL; (c) CONDUCT a WRITTEN RISK ASSESSMENT covering the 314.4(b) criteria; (d) DESIGN + IMPLEMENT SAFEGUARDS to control the risks i

Artefacts an auditor will ask for
  • Effective-date readiness
  • Consumer count tracking + simplification eligibility
  • Interagency + sectoral coordination evidence
Where this commonly fails
  • Effective dates missed
  • Small institution exemption misapplied
  • Interagency coordination skipped
  • Sectoral coordination ad-hoc

FTC Safeguards Rule: Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

FTC-Safeguards-Scope-Defs
Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

16 CFR 314.1 purpose + scope; 314.2 definitions. PURPOSE: to establish standards for safeguarding customer information held by financial institutions under FTC jurisdiction + implementing Title V of GLBA. SCOPE: applies to FINANCIAL INSTITUTIONS under FTC jurisdiction (i.e. not supervised by federal banking agencies). FINANCIAL INSTITUTION = any institution the business of which is engaging in financial activities described in 12 USC 1843(k); the 2021 amendments EXPANDED the definition to include FINDERS (entities that introduce buyers and sellers of financial products). EXAMPLES: consumer reporting agencies + finance companies + mortgage brokers + automobile dealers + payday lenders + tax preparation firms + non-bank lenders + collection agencies + investment advisors not registered with SEC + finders. CUSTOMER INFORMATION: nonpublic personal information about a consumer obtained in con

Artefacts an auditor will ask for
  • Financial-institution assessment + finder analysis
  • Customer information inventory
  • Small institution threshold tracking
Where this commonly fails
  • Scope misunderstood (e.g. assumed only banks)
  • Customer information definition too narrow
  • Small institution exemption misapplied

FTC Safeguards Rule: Service Provider Oversight and Program Evaluation (314.4(d-g))

FTC-Safeguards-ServiceProvider-Evaluation
Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

16 CFR 314.4(d-g). (d) SERVICE PROVIDER OVERSIGHT: (1) take reasonable steps to SELECT + RETAIN SERVICE PROVIDERS capable of maintaining safeguards for customer information; (2) require service providers by CONTRACT to implement + maintain such safeguards; (3) periodically ASSESS service providers based on the risk they present + the continued adequacy of their safeguards. (e) TESTING + MONITORING: (1) IMPLEMENT POLICIES + PROCEDURES to monitor effectiveness of safeguards on an ongoing basis; (2) TEST + monitor at intervals appropriate to the risks. (f) PERSONNEL TRAINING: (1) provide INFORMATION SECURITY TRAINING to personnel + based on risk-relevant roles + responsibilities; (2) verify that key personnel take steps to maintain CURRENT KNOWLEDGE of changing threats + countermeasures; (3) verify that information security personnel have qualifications + skills equal to the importance of t

Artefacts an auditor will ask for
  • Service provider list + DD records + contracts
  • Annual assessment records
  • Training program + records + qualifications
  • Program evaluation + adjustment log
Where this commonly fails
  • Service provider DD weak
  • Annual assessment skipped
  • Training program inconsistent
  • Program evaluation pro-forma

FTC Safeguards Rule: Written Incident Response Plan, Board Reporting and FTC Breach Notification (314.4(h-j))

FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification
Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))

16 CFR 314.4(h-j). (h) WRITTEN INCIDENT RESPONSE PLAN: prepare WRITTEN INCIDENT RESPONSE PLAN designed to promptly respond to + recover from any security event materially affecting confidentiality + integrity + availability of customer information; the IRP must address: (1) goals of plan; (2) internal processes for responding to security events; (3) clear roles + responsibilities + decision-making authority; (4) external + internal information sharing + communications; (5) requirements for remediation of identified weaknesses in systems + controls; (6) documentation + reporting; (7) evaluation + revision of plan after security event. (i) QUALIFIED INDIVIDUAL ANNUAL BOARD REPORTING: at least annually, the Qualified Individual must report in writing to the Board (or senior officer responsible) on (1) overall status of information security program + compliance; (2) material matters related

Artefacts an auditor will ask for
  • IRP document + tabletop tests
  • Annual Board report + minutes
  • FTC notification template + procedure
  • Documentation + records retention
Where this commonly fails
  • IRP missing or not tested
  • Annual Board report skipped
  • FTC notification delayed or undocumented
  • IRP not updated after events

FTC Safeguards Rule: Written Risk Assessment (314.4(b))

FTC-Safeguards-Risk-Assessment
Written Risk Assessment (16 CFR 314.4(b))

16 CFR 314.4(b) risk assessment. REQUIREMENT: financial institution must conduct a WRITTEN RISK ASSESSMENT to identify reasonably foreseeable internal + external risks to the security + confidentiality + integrity of customer information that could result in unauthorized disclosure + misuse + alteration + destruction + or other compromise. RISK ASSESSMENT CONTENTS (314.4(b)(1-4)): (1) CRITERIA for the evaluation + categorization of identified security risks or threats facing the institution; (2) CRITERIA for the assessment of confidentiality + integrity + availability of the institution information systems + customer information including the adequacy of existing controls in the context of identified risks or threats; (3) REQUIREMENTS that the safeguards (the 9 elements at 314.4(c) + 314.4(d-j)) be assessed in light of the risk assessment + adjusted accordingly. FREQUENCY: at least every

Artefacts an auditor will ask for
  • Written risk assessment document
  • Annual review + after-changes records
  • Risk register + heatmap
Where this commonly fails
  • Risk assessment not written
  • Annual review skipped
  • Criteria 314.4(b)(1-4) not addressed
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the FTC GLBA Safeguards Rule (16 CFR Part 314) framework page.