Skip to content

Evidence request lists

GLBA

Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

GLBA: 2024-2025 Pipeline, Coordination and Cross-Mapping to Subordinate Substantive Rules

GLBA-2024-2025-Pipeline-Section-1033-AI
GLBA 2024-2025 Pipeline - SEC Reg S-P, CFPB Section 1033, NAIC AI Bulletin

GLBA 2024-2025 regulatory pipeline. (a) FTC SAFEGUARDS RULE 30-DAY FTC NOTIFICATION (16 CFR 314.5) - effective 2024-05-13 + applies to security events involving 500+ consumers + 30-day FTC notification + 60-day individual notification + clarifies coordination with state breach notification laws. (b) SEC REGULATION S-P AMENDMENTS - adopted 16 May 2024; effective 2025-12-03 (large institutions over USD 1.5B AUM) + 2026-06-03 (small institutions); new requirements: (1) written incident response program with policies + procedures + records; (2) customer + consumer notification within 30 days of substantial discovery of unauthorized access or use of sensitive customer information; (3) third-party service provider oversight + due diligence + monitoring; (4) extended record-keeping. (c) CFPB SECTION 1033 OPEN BANKING RULE - finalized October 2024 + effective phased 2026-2030; mandates personal-

Artefacts an auditor will ask for
  • Pipeline-tracking + implementation plan per rule
  • SEC Reg S-P readiness 2025-2026
  • Section 1033 readiness 2026-2030
  • NY DFS + NAIC AI compliance
Where this commonly fails
  • Pipeline not tracked
  • Reg S-P readiness gap
  • Section 1033 readiness absent
  • NY DFS + NAIC AI not addressed
GLBA-Coordination-FCRA-HIPAA-CCPA-Sectoral
GLBA Coordination with FCRA, ECOA, HIPAA, CCPA, State Privacy Laws and Sectoral Frameworks

GLBA coordination with related US privacy + financial frameworks. (a) FCRA (FAIR CREDIT REPORTING ACT, 15 USC 1681) - regulates consumer-reporting agencies + furnishers of information + users of consumer reports; coordinates with GLBA on information-sharing for credit-decision purposes; Red Flags Rule (16 CFR Part 681) and Disposal Rule (16 CFR Part 682) overlap with Safeguards. (b) ECOA (EQUAL CREDIT OPPORTUNITY ACT, 15 USC 1691) + Regulation B - prohibits credit-decision discrimination; ECOA NPI sharing coordinates with GLBA Section 6802. (c) HIPAA (HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT) Privacy + Security Rules - coordinates with GLBA for entities subject to both (e.g. health-insurance issuers + employee-benefit plans + insurance brokers handling health-related financial info); HIPAA generally provides higher floor than GLBA for protected health information; GLBA preserv

Artefacts an auditor will ask for
  • Cross-statute compliance program
  • State DP law GLBA-exemption scope analysis
  • Multi-state insurance + DP compliance
  • CFPB Section 1033 + UDAAP readiness
Where this commonly fails
  • Cross-statute coordination gaps
  • State DP law exemption misunderstood
  • Multi-state compliance fragmented
  • CFPB 1033 + UDAAP not addressed
GLBA-Crosswalk-Subordinate-Substantive-Rules
GLBA Crosswalk to FTC Safeguards Rule, FTC Privacy Rule, SEC Reg S-P, Interagency Guidelines, NAIC Model Law

GLBA crosswalk to subordinate substantive rules. Auditor evidence + substantive control content lives in the SUBORDINATE rules + this GLBA parent statute is a STATUTORY UMBRELLA reference. (a) FTC SAFEGUARDS RULE (16 CFR Part 314) - VERIFIED SEPARATELY 2026-05-28 with 11 section-aligned controls + 2225 incoming MAPS_TO; covers 9 Required Elements + 30-day FTC notification + Qualified Individual + risk assessment + access controls + encryption + MFA + monitoring + IR plan + board reporting. (b) FTC PRIVACY RULE (16 CFR Part 313) - tracked separately if present + implements Sections 6802 + 6803 disclosure + notice + opt-out + model privacy form. (c) SEC REGULATION S-P (17 CFR Part 248) - applies to broker-dealers + investment companies + investment advisers + transfer agents + 2024 major amendments effective 2025-12-03 (large) + 2026-06-03 (small) with 30-day individual notification + IR p

Artefacts an auditor will ask for
  • Subordinate-rule compliance evidence per institution type
  • NY DFS 23 NYCRR 500 evidence
  • NAIC #668 evidence
  • FCRA + ECOA + HIPAA coordination evidence
Where this commonly fails
  • Subordinate-rule compliance gaps
  • NY DFS evidence missing
  • NAIC evidence missing
  • Cross-statute coordination gaps
GLBA-Status-FTC-CFPB-SEC-NAIC-Enforcement
GLBA Status, Enforcement Activity, FTC + CFPB + SEC + NAIC Recent Actions

GLBA enforcement status. FTC enforcement actions (recent): (a) DRIZLY (2022) - alcohol delivery; security failures including no Information Security Program + no MFA + no audit + no vendor-management; consent order; (b) TaxSlayer (2017) - tax preparation; no Safeguards Rule + privacy notices issues; consent order; (c) Wyze Labs (2024) - smart devices; consumer fraud + security issues; (d) Equifax (2019 + ongoing) - credit-reporting agency; massive 2017 breach; settlements with FTC + CFPB + state AGs USD 575M+; (e) RingCentral + others. CFPB ENFORCEMENT: under Dodd-Frank Title X for non-bank financial institutions + UDAAP + Reg E + Reg P + including Section 1033 compliance once effective 2026-2030 phased; Section 1071 small-business lending data. SEC ENFORCEMENT: Regulation S-P enforcement actions (e.g. PIPL Securities + Cetera + JP Morgan + Voya + Morgan Stanley + others) + Item 1.05 For

Artefacts an auditor will ask for
  • Enforcement-history monitoring + lessons-learned
  • 36-hour banking notification procedure
  • NY DFS + NAIC enforcement readiness
  • Higher-Ed FSA audit response
Where this commonly fails
  • Enforcement-history not monitored
  • 36-hour banking notification gaps
  • NY DFS readiness gaps
  • FSA audit findings

GLBA: Operationalisation through FTC Safeguards Rule, FTC Privacy Rule, SEC Reg S-P

GLBA-Implementation-Roadmap-Examination
GLBA Implementation Roadmap, Examination Readiness, Roles and Tooling

GLBA implementation roadmap. ROLES: (a) GLBA OFFICER or CHIEF PRIVACY OFFICER (CPO) - strategic ownership + privacy notice + opt-out + Sec. 6802 + 6803 compliance; (b) QUALIFIED INDIVIDUAL (FTC Safeguards Rule 16 CFR 314.4(a)(1)) - designated information security program leader for non-bank financial institutions + reports to senior leadership + board; (c) CHIEF INFORMATION SECURITY OFFICER (CISO) - cyber-program ownership; (d) GENERAL COUNSEL + LEGAL - statutory + regulatory interpretation + breach response coordination; (e) COMPLIANCE OFFICER - examination readiness; (f) RISK COMMITTEE OF THE BOARD - 12-month risk assessment + annual report. EXAMINATION READINESS: regulators conduct GLBA-specific exams + identify deficiencies + issue MRBA (Matters Requiring Board Attention) + MRA (Matters Requiring Attention) + consent orders + monetary penalties. TOOLING: (a) information security plat

Artefacts an auditor will ask for
  • Role inventory + RACI
  • Examination response procedures
  • Tooling + metrics dashboard
  • Annual cycle documentation
Where this commonly fails
  • Roles undefined
  • Examination readiness gaps
  • Metrics not tracked
  • Annual cycle not documented
GLBA-Subordinate-Rules-Operationalisation
GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines

GLBA is a statutory umbrella whose substantive operational controls are issued by regulators via subordinate rules. (a) FTC SAFEGUARDS RULE (16 CFR Part 314) - the substantive cybersecurity rule for non-bank financial institutions; major 2021 revision + 2023 amendment with FTC 30-day notification requirement effective 2024-05-13 + the rule is VERIFIED SEPARATELY in this corpus (4-way consolidation completed 2026-05-28 with 2225 incoming MAPS_TO preserved); 9 Required Elements (Sec. 314.4(a)-(i)) including written program + Qualified Individual + risk assessment + access controls + encryption + secure development + MFA + monitoring + employee training + service provider oversight + IR plan + incident reporting + board reporting + continuous improvement. (b) FTC PRIVACY RULE (16 CFR Part 313) - implements GLBA Sections 6802 + 6803 privacy notice + opt-out for non-bank financial institution

Artefacts an auditor will ask for
  • Subordinate-rule compliance per institution type
  • SEC Reg S-P incident response (2025-2026 effective)
  • Interagency Guidelines program
  • NAIC Model Law compliance
Where this commonly fails
  • Subordinate-rule applicability misidentified
  • SEC Reg S-P 2024 amendments not adopted
  • NAIC Model Law not adopted
  • Interagency Guidelines program missing

GLBA: Rulemaking Authority - CFPB, SEC, CFTC, Federal Banking Agencies, FTC, NAIC

GLBA-Sec6804-6805-Rulemaking-Enforcement
GLBA Section 6804-6805 - Rulemaking Authority and Enforcement Mechanism

GLBA Sections 6804 and 6805 - rulemaking + enforcement. SECTION 6804 RULEMAKING (post Dodd-Frank): CFPB (Bureau of Consumer Financial Protection) + SEC (Securities and Exchange Commission) + CFTC (Commodity Futures Trading Commission) have authority to prescribe regulations as may be necessary to carry out the purposes of this subchapter with respect to financial institutions + other persons subject to their respective jurisdictions; CFPB does NOT have authority to prescribe regulations with respect to the safeguarding standards under Section 6801. SECTION 6805 ENFORCEMENT: this subchapter and the regulations prescribed thereunder shall be enforced by - (1) APPROPRIATE FEDERAL BANKING AGENCY under 12 USC 1818 for national banks (OCC) + state member banks (Federal Reserve) + state non-member banks (FDIC) + federal credit unions (NCUA) + savings associations (FDIC/OCC); (2) NCUA for federa

Artefacts an auditor will ask for
  • Regulatory mapping per institution type
  • Enforcement-history monitoring
  • Subordinate-rule compliance evidence
Where this commonly fails
  • Regulator confusion
  • Subordinate-rule misalignment
  • Enforcement-history not monitored

GLBA: Sectoral Application - Banking, Securities, Insurance, Non-Bank, Higher Education

GLBA-Sectoral-Higher-Ed-Insurance-Banking
GLBA Sectoral Application: Banking, Securities, Insurance, Non-Bank, Higher Education

GLBA sectoral application by institution type. BANKING (federal banking agencies enforcement): national banks (OCC) + state member banks (Federal Reserve) + state non-member banks (FDIC) + federal credit unions (NCUA) + savings associations (FDIC/OCC) - Interagency Guidelines Establishing Standards for Safeguarding Customer Information; subject to OCC + Federal Reserve + FDIC + NCUA examination programs + Federal Reserve SR Letters + OCC Bulletins + FDIC FILs. SECURITIES (SEC enforcement): broker-dealers + investment companies + investment advisers + transfer agents - SEC Regulation S-P (17 CFR Part 248) + 2024 amendments + Reg S-ID identity-theft red flags + Reg S-AM affiliate marketing; FINRA Rule 4530 + 2024-02-05 cybersecurity-disclosure rules. FUTURES (CFTC enforcement): futures commission merchants + commodity trading advisors + commodity pool operators - CFTC Reg 1.55 + 1.56 + 23.

Artefacts an auditor will ask for
  • Sectoral regulator engagement
  • Multi-state insurance compliance
  • CFPB Section 1033 readiness
  • Higher-Ed FSA Audit Guide compliance
Where this commonly fails
  • Sectoral applicability misunderstood
  • Multi-state insurance compliance gaps
  • CFPB 1033 not addressed
  • FSA Audit findings

GLBA: Statutory Scope, Definitions and Coverage of Financial Institutions

GLBA-Scope-FinancialInstitution-NPI-Defs
GLBA Scope, Financial Institution + Nonpublic Personal Information Definitions

GLBA scope + definitions (15 USC 6809 + 15 USC 6827). FINANCIAL INSTITUTION (Sec. 6809(3)): any institution engaged in financial activities described in section 4(k) of the Bank Holding Company Act of 1956 - includes banks + savings associations + credit unions + securities firms + broker-dealers + investment companies + investment advisers + insurance companies + insurance agencies + mortgage brokers + mortgage lenders + check-cashers + money-services businesses + consumer finance companies + collection agencies + tax preparers + non-bank lenders + entities engaged in financial data processing or transmission + any other entity engaged in financial activities. HIGHER EDUCATION institutions participating in Title IV (FSA - Federal Student Aid) are covered as financial institutions for FTC Safeguards Rule purposes. NONPUBLIC PERSONAL INFORMATION (NPI) (Sec. 6809(4)): personally identifiab

Artefacts an auditor will ask for
  • GLBA applicability assessment
  • NPI inventory + classification
  • Customer vs consumer determination
Where this commonly fails
  • GLBA scope misunderstood
  • NPI vs publicly-available unclear
  • Customer vs consumer conflated

GLBA: Subchapter I (15 USC 6801-6809) Privacy and Safeguarding Obligations

GLBA-Sec6801-PolicyDuty-SafeguardingStandard
GLBA Section 6801 - Privacy Obligation Policy and Safeguarding Standard

GLBA Section 6801 - Protection of nonpublic personal information. SUBSECTION (a) PRIVACY OBLIGATION POLICY: it is the policy of Congress that each financial institution has an AFFIRMATIVE AND CONTINUING OBLIGATION to respect the privacy of its customers + to protect the security and confidentiality of those customers nonpublic personal information. SUBSECTION (b) FINANCIAL INSTITUTIONS SAFEGUARDS: each agency or authority described in section 6805(a) - OTHER THAN the Bureau of Consumer Financial Protection (CFPB) - shall establish APPROPRIATE STANDARDS for the financial institutions subject to their jurisdiction relating to ADMINISTRATIVE, TECHNICAL, AND PHYSICAL SAFEGUARDS - (1) to insure the security + confidentiality of customer records + information; (2) to protect against any anticipated threats or hazards to the security or integrity of such records; (3) to protect against unauthor

Artefacts an auditor will ask for
  • Information security program (FTC Safeguards Rule)
  • Banking-agency safeguarding policies
  • Audit evidence per subordinate rule
Where this commonly fails
  • Safeguarding program absent
  • Subordinate-rule alignment gaps
  • Risk assessment not done
GLBA-Sec6802-6803-Disclosure-Notice-OptOut
GLBA Section 6802-6803 - Disclosure Limits, Privacy Notice and Opt-Out

GLBA Sections 6802 and 6803 - disclosure + notice + opt-out obligations. SECTION 6802 OBLIGATIONS WITH RESPECT TO DISCLOSURES: a financial institution may not disclose NPI to a NONAFFILIATED THIRD PARTY unless (a) the financial institution has provided the consumer a notice complying with Section 6803; (b) for non-marketing disclosures the institution clearly + conspicuously discloses + the consumer is given a REASONABLE OPPORTUNITY TO OPT OUT before the disclosure occurs + the consumer does not opt out. EXCEPTIONS include disclosures to service providers + joint marketing partners + as necessary to effect/administer/enforce a transaction + with consent + protect against fraud + comply with law + to regulators + and others (Sec. 6802(e)). RE-DISCLOSURE LIMITATIONS (Sec. 6802(c)): a nonaffiliated third party receiving NPI from a financial institution may not directly or indirectly disclos

Artefacts an auditor will ask for
  • Privacy notice templates
  • Opt-out mechanism + tracking
  • Service provider + JMA contracts with re-disclosure limits
  • Model privacy form (if used)
Where this commonly fails
  • Privacy notice missing or unclear
  • Opt-out not provided
  • Re-disclosure controls absent
  • Annual notice provided despite exemption

GLBA: Subchapter II (15 USC 6821-6827) Pretexting Prohibition and Criminal Penalties

GLBA-Sec6821-Pretexting-Prohibition-Criminal
GLBA Section 6821 + 6823 - Pretexting Prohibition and Criminal Penalties

GLBA Subchapter II - Fraudulent Access to Financial Information (Sections 6821-6827). SECTION 6821 PROHIBITION ON OBTAINING CUSTOMER INFORMATION BY FALSE PRETENSES (PRETEXTING): it shall be a violation of this subchapter for any person to obtain or attempt to obtain + or cause to be disclosed or attempt to cause to be disclosed + to any person + customer information of a financial institution relating to another person + by (1) making a FALSE FICTITIOUS OR FRAUDULENT STATEMENT OR REPRESENTATION to an officer + employee + or agent of a financial institution; (2) making a false statement or representation to a CUSTOMER of a financial institution; (3) providing a FORGED COUNTERFEIT LOST OR STOLEN OR FRAUDULENTLY OBTAINED OR FALSE document to an officer of a financial institution. Subsection (b) prohibits SOLICITATION of pretexting violations + and (c) prohibits OBTAINING SERVICES from anoth

Artefacts an auditor will ask for
  • Anti-pretexting program + verification procedures
  • Employee anti-pretexting training
  • Customer pretexting-awareness communications
  • Suspicious-activity escalation
Where this commonly fails
  • Pretexting training absent
  • Customer-verification weak
  • No suspicious-activity escalation
  • No customer awareness
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the GLBA framework page.