GLBA
Evidence request list. 12 controls, 12 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
GLBA: 2024-2025 Pipeline, Coordination and Cross-Mapping to Subordinate Substantive Rules
GLBA 2024-2025 regulatory pipeline. (a) FTC SAFEGUARDS RULE 30-DAY FTC NOTIFICATION (16 CFR 314.5) - effective 2024-05-13 + applies to security events involving 500+ consumers + 30-day FTC notification + 60-day individual notification + clarifies coordination with state breach notification laws. (b) SEC REGULATION S-P AMENDMENTS - adopted 16 May 2024; effective 2025-12-03 (large institutions over USD 1.5B AUM) + 2026-06-03 (small institutions); new requirements: (1) written incident response program with policies + procedures + records; (2) customer + consumer notification within 30 days of substantial discovery of unauthorized access or use of sensitive customer information; (3) third-party service provider oversight + due diligence + monitoring; (4) extended record-keeping. (c) CFPB SECTION 1033 OPEN BANKING RULE - finalized October 2024 + effective phased 2026-2030; mandates personal-
- Pipeline-tracking + implementation plan per rule
- SEC Reg S-P readiness 2025-2026
- Section 1033 readiness 2026-2030
- NY DFS + NAIC AI compliance
- Pipeline not tracked
- Reg S-P readiness gap
- Section 1033 readiness absent
- NY DFS + NAIC AI not addressed
GLBA coordination with related US privacy + financial frameworks. (a) FCRA (FAIR CREDIT REPORTING ACT, 15 USC 1681) - regulates consumer-reporting agencies + furnishers of information + users of consumer reports; coordinates with GLBA on information-sharing for credit-decision purposes; Red Flags Rule (16 CFR Part 681) and Disposal Rule (16 CFR Part 682) overlap with Safeguards. (b) ECOA (EQUAL CREDIT OPPORTUNITY ACT, 15 USC 1691) + Regulation B - prohibits credit-decision discrimination; ECOA NPI sharing coordinates with GLBA Section 6802. (c) HIPAA (HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT) Privacy + Security Rules - coordinates with GLBA for entities subject to both (e.g. health-insurance issuers + employee-benefit plans + insurance brokers handling health-related financial info); HIPAA generally provides higher floor than GLBA for protected health information; GLBA preserv
- Cross-statute compliance program
- State DP law GLBA-exemption scope analysis
- Multi-state insurance + DP compliance
- CFPB Section 1033 + UDAAP readiness
- Cross-statute coordination gaps
- State DP law exemption misunderstood
- Multi-state compliance fragmented
- CFPB 1033 + UDAAP not addressed
GLBA crosswalk to subordinate substantive rules. Auditor evidence + substantive control content lives in the SUBORDINATE rules + this GLBA parent statute is a STATUTORY UMBRELLA reference. (a) FTC SAFEGUARDS RULE (16 CFR Part 314) - VERIFIED SEPARATELY 2026-05-28 with 11 section-aligned controls + 2225 incoming MAPS_TO; covers 9 Required Elements + 30-day FTC notification + Qualified Individual + risk assessment + access controls + encryption + MFA + monitoring + IR plan + board reporting. (b) FTC PRIVACY RULE (16 CFR Part 313) - tracked separately if present + implements Sections 6802 + 6803 disclosure + notice + opt-out + model privacy form. (c) SEC REGULATION S-P (17 CFR Part 248) - applies to broker-dealers + investment companies + investment advisers + transfer agents + 2024 major amendments effective 2025-12-03 (large) + 2026-06-03 (small) with 30-day individual notification + IR p
- Subordinate-rule compliance evidence per institution type
- NY DFS 23 NYCRR 500 evidence
- NAIC #668 evidence
- FCRA + ECOA + HIPAA coordination evidence
- Subordinate-rule compliance gaps
- NY DFS evidence missing
- NAIC evidence missing
- Cross-statute coordination gaps
GLBA enforcement status. FTC enforcement actions (recent): (a) DRIZLY (2022) - alcohol delivery; security failures including no Information Security Program + no MFA + no audit + no vendor-management; consent order; (b) TaxSlayer (2017) - tax preparation; no Safeguards Rule + privacy notices issues; consent order; (c) Wyze Labs (2024) - smart devices; consumer fraud + security issues; (d) Equifax (2019 + ongoing) - credit-reporting agency; massive 2017 breach; settlements with FTC + CFPB + state AGs USD 575M+; (e) RingCentral + others. CFPB ENFORCEMENT: under Dodd-Frank Title X for non-bank financial institutions + UDAAP + Reg E + Reg P + including Section 1033 compliance once effective 2026-2030 phased; Section 1071 small-business lending data. SEC ENFORCEMENT: Regulation S-P enforcement actions (e.g. PIPL Securities + Cetera + JP Morgan + Voya + Morgan Stanley + others) + Item 1.05 For
- Enforcement-history monitoring + lessons-learned
- 36-hour banking notification procedure
- NY DFS + NAIC enforcement readiness
- Higher-Ed FSA audit response
- Enforcement-history not monitored
- 36-hour banking notification gaps
- NY DFS readiness gaps
- FSA audit findings
GLBA: Operationalisation through FTC Safeguards Rule, FTC Privacy Rule, SEC Reg S-P
GLBA implementation roadmap. ROLES: (a) GLBA OFFICER or CHIEF PRIVACY OFFICER (CPO) - strategic ownership + privacy notice + opt-out + Sec. 6802 + 6803 compliance; (b) QUALIFIED INDIVIDUAL (FTC Safeguards Rule 16 CFR 314.4(a)(1)) - designated information security program leader for non-bank financial institutions + reports to senior leadership + board; (c) CHIEF INFORMATION SECURITY OFFICER (CISO) - cyber-program ownership; (d) GENERAL COUNSEL + LEGAL - statutory + regulatory interpretation + breach response coordination; (e) COMPLIANCE OFFICER - examination readiness; (f) RISK COMMITTEE OF THE BOARD - 12-month risk assessment + annual report. EXAMINATION READINESS: regulators conduct GLBA-specific exams + identify deficiencies + issue MRBA (Matters Requiring Board Attention) + MRA (Matters Requiring Attention) + consent orders + monetary penalties. TOOLING: (a) information security plat
- Role inventory + RACI
- Examination response procedures
- Tooling + metrics dashboard
- Annual cycle documentation
- Roles undefined
- Examination readiness gaps
- Metrics not tracked
- Annual cycle not documented
GLBA is a statutory umbrella whose substantive operational controls are issued by regulators via subordinate rules. (a) FTC SAFEGUARDS RULE (16 CFR Part 314) - the substantive cybersecurity rule for non-bank financial institutions; major 2021 revision + 2023 amendment with FTC 30-day notification requirement effective 2024-05-13 + the rule is VERIFIED SEPARATELY in this corpus (4-way consolidation completed 2026-05-28 with 2225 incoming MAPS_TO preserved); 9 Required Elements (Sec. 314.4(a)-(i)) including written program + Qualified Individual + risk assessment + access controls + encryption + secure development + MFA + monitoring + employee training + service provider oversight + IR plan + incident reporting + board reporting + continuous improvement. (b) FTC PRIVACY RULE (16 CFR Part 313) - implements GLBA Sections 6802 + 6803 privacy notice + opt-out for non-bank financial institution
- Subordinate-rule compliance per institution type
- SEC Reg S-P incident response (2025-2026 effective)
- Interagency Guidelines program
- NAIC Model Law compliance
- Subordinate-rule applicability misidentified
- SEC Reg S-P 2024 amendments not adopted
- NAIC Model Law not adopted
- Interagency Guidelines program missing
GLBA: Rulemaking Authority - CFPB, SEC, CFTC, Federal Banking Agencies, FTC, NAIC
GLBA Sections 6804 and 6805 - rulemaking + enforcement. SECTION 6804 RULEMAKING (post Dodd-Frank): CFPB (Bureau of Consumer Financial Protection) + SEC (Securities and Exchange Commission) + CFTC (Commodity Futures Trading Commission) have authority to prescribe regulations as may be necessary to carry out the purposes of this subchapter with respect to financial institutions + other persons subject to their respective jurisdictions; CFPB does NOT have authority to prescribe regulations with respect to the safeguarding standards under Section 6801. SECTION 6805 ENFORCEMENT: this subchapter and the regulations prescribed thereunder shall be enforced by - (1) APPROPRIATE FEDERAL BANKING AGENCY under 12 USC 1818 for national banks (OCC) + state member banks (Federal Reserve) + state non-member banks (FDIC) + federal credit unions (NCUA) + savings associations (FDIC/OCC); (2) NCUA for federa
- Regulatory mapping per institution type
- Enforcement-history monitoring
- Subordinate-rule compliance evidence
- Regulator confusion
- Subordinate-rule misalignment
- Enforcement-history not monitored
GLBA: Sectoral Application - Banking, Securities, Insurance, Non-Bank, Higher Education
GLBA sectoral application by institution type. BANKING (federal banking agencies enforcement): national banks (OCC) + state member banks (Federal Reserve) + state non-member banks (FDIC) + federal credit unions (NCUA) + savings associations (FDIC/OCC) - Interagency Guidelines Establishing Standards for Safeguarding Customer Information; subject to OCC + Federal Reserve + FDIC + NCUA examination programs + Federal Reserve SR Letters + OCC Bulletins + FDIC FILs. SECURITIES (SEC enforcement): broker-dealers + investment companies + investment advisers + transfer agents - SEC Regulation S-P (17 CFR Part 248) + 2024 amendments + Reg S-ID identity-theft red flags + Reg S-AM affiliate marketing; FINRA Rule 4530 + 2024-02-05 cybersecurity-disclosure rules. FUTURES (CFTC enforcement): futures commission merchants + commodity trading advisors + commodity pool operators - CFTC Reg 1.55 + 1.56 + 23.
- Sectoral regulator engagement
- Multi-state insurance compliance
- CFPB Section 1033 readiness
- Higher-Ed FSA Audit Guide compliance
- Sectoral applicability misunderstood
- Multi-state insurance compliance gaps
- CFPB 1033 not addressed
- FSA Audit findings
GLBA: Statutory Scope, Definitions and Coverage of Financial Institutions
GLBA scope + definitions (15 USC 6809 + 15 USC 6827). FINANCIAL INSTITUTION (Sec. 6809(3)): any institution engaged in financial activities described in section 4(k) of the Bank Holding Company Act of 1956 - includes banks + savings associations + credit unions + securities firms + broker-dealers + investment companies + investment advisers + insurance companies + insurance agencies + mortgage brokers + mortgage lenders + check-cashers + money-services businesses + consumer finance companies + collection agencies + tax preparers + non-bank lenders + entities engaged in financial data processing or transmission + any other entity engaged in financial activities. HIGHER EDUCATION institutions participating in Title IV (FSA - Federal Student Aid) are covered as financial institutions for FTC Safeguards Rule purposes. NONPUBLIC PERSONAL INFORMATION (NPI) (Sec. 6809(4)): personally identifiab
- GLBA applicability assessment
- NPI inventory + classification
- Customer vs consumer determination
- GLBA scope misunderstood
- NPI vs publicly-available unclear
- Customer vs consumer conflated
GLBA: Subchapter I (15 USC 6801-6809) Privacy and Safeguarding Obligations
GLBA Section 6801 - Protection of nonpublic personal information. SUBSECTION (a) PRIVACY OBLIGATION POLICY: it is the policy of Congress that each financial institution has an AFFIRMATIVE AND CONTINUING OBLIGATION to respect the privacy of its customers + to protect the security and confidentiality of those customers nonpublic personal information. SUBSECTION (b) FINANCIAL INSTITUTIONS SAFEGUARDS: each agency or authority described in section 6805(a) - OTHER THAN the Bureau of Consumer Financial Protection (CFPB) - shall establish APPROPRIATE STANDARDS for the financial institutions subject to their jurisdiction relating to ADMINISTRATIVE, TECHNICAL, AND PHYSICAL SAFEGUARDS - (1) to insure the security + confidentiality of customer records + information; (2) to protect against any anticipated threats or hazards to the security or integrity of such records; (3) to protect against unauthor
- Information security program (FTC Safeguards Rule)
- Banking-agency safeguarding policies
- Audit evidence per subordinate rule
- Safeguarding program absent
- Subordinate-rule alignment gaps
- Risk assessment not done
GLBA Sections 6802 and 6803 - disclosure + notice + opt-out obligations. SECTION 6802 OBLIGATIONS WITH RESPECT TO DISCLOSURES: a financial institution may not disclose NPI to a NONAFFILIATED THIRD PARTY unless (a) the financial institution has provided the consumer a notice complying with Section 6803; (b) for non-marketing disclosures the institution clearly + conspicuously discloses + the consumer is given a REASONABLE OPPORTUNITY TO OPT OUT before the disclosure occurs + the consumer does not opt out. EXCEPTIONS include disclosures to service providers + joint marketing partners + as necessary to effect/administer/enforce a transaction + with consent + protect against fraud + comply with law + to regulators + and others (Sec. 6802(e)). RE-DISCLOSURE LIMITATIONS (Sec. 6802(c)): a nonaffiliated third party receiving NPI from a financial institution may not directly or indirectly disclos
- Privacy notice templates
- Opt-out mechanism + tracking
- Service provider + JMA contracts with re-disclosure limits
- Model privacy form (if used)
- Privacy notice missing or unclear
- Opt-out not provided
- Re-disclosure controls absent
- Annual notice provided despite exemption
GLBA: Subchapter II (15 USC 6821-6827) Pretexting Prohibition and Criminal Penalties
GLBA Subchapter II - Fraudulent Access to Financial Information (Sections 6821-6827). SECTION 6821 PROHIBITION ON OBTAINING CUSTOMER INFORMATION BY FALSE PRETENSES (PRETEXTING): it shall be a violation of this subchapter for any person to obtain or attempt to obtain + or cause to be disclosed or attempt to cause to be disclosed + to any person + customer information of a financial institution relating to another person + by (1) making a FALSE FICTITIOUS OR FRAUDULENT STATEMENT OR REPRESENTATION to an officer + employee + or agent of a financial institution; (2) making a false statement or representation to a CUSTOMER of a financial institution; (3) providing a FORGED COUNTERFEIT LOST OR STOLEN OR FRAUDULENTLY OBTAINED OR FALSE document to an officer of a financial institution. Subsection (b) prohibits SOLICITATION of pretexting violations + and (c) prohibits OBTAINING SERVICES from anoth
- Anti-pretexting program + verification procedures
- Employee anti-pretexting training
- Customer pretexting-awareness communications
- Suspicious-activity escalation
- Pretexting training absent
- Customer-verification weak
- No suspicious-activity escalation
- No customer awareness
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the GLBA framework page.