Skip to content

Evidence request lists

US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule

Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Applicability to Title IV Institutions

HE-1
Financial institution status of higher education

Institutions participating in Title IV federal student aid programmes are financial institutions under GLBA.

Artefacts an auditor will ask for
  • Written information security program (WISP) per 16 CFR 314
  • Service provider oversight register and contractual safeguards
  • Qualified Individual designation letter
  • Risk assessment covering student financial information
Where this commonly fails
  • Risk assessment not refreshed within required cadence
  • Service provider monitoring limited to onboarding
  • Incident response plan does not address FSA notification
  • No formal Qualified Individual or unclear authority
HE-2
Student financial information as customer information

Student financial aid records and information constitute customer information under the Safeguards Rule.

Artefacts an auditor will ask for
  • Written information security program (WISP) per 16 CFR 314
  • Board or equivalent governing body reporting records
  • Encryption and MFA implementation evidence
  • Qualified Individual designation letter
Where this commonly fails
  • MFA not enforced for all access to customer information
  • Service provider monitoring limited to onboarding
  • Risk assessment not refreshed within required cadence
  • No formal Qualified Individual or unclear authority
HE-3
FSA compliance requirements

Federal Student Aid requires institutions to comply with the amended Safeguards Rule as programme participation condition.

Artefacts an auditor will ask for
  • Qualified Individual designation letter
  • Service provider oversight register and contractual safeguards
  • Risk assessment covering student financial information
  • Encryption and MFA implementation evidence
Where this commonly fails
  • Incident response plan does not address FSA notification
  • MFA not enforced for all access to customer information
  • No formal Qualified Individual or unclear authority
  • Risk assessment not refreshed within required cadence
HE-4
Institutional governance integration

Information security programme must be integrated with the institution's overall governance structure.

Artefacts an auditor will ask for
  • Encryption and MFA implementation evidence
  • Board or equivalent governing body reporting records
  • Qualified Individual designation letter
  • Written information security program (WISP) per 16 CFR 314
Where this commonly fails
  • No formal Qualified Individual or unclear authority
  • MFA not enforced for all access to customer information
  • Service provider monitoring limited to onboarding
  • Incident response plan does not address FSA notification

GLBA Higher Education: Title IV and Privacy Notices

GLBA-HE-DoE-PPA
Title IV Program Participation Agreement Compliance

Institutions participating in Title IV federal student aid programs must comply with GLBA Safeguards Rule as a condition of the Program Participation Agreement with the Department of Education, and must self assess and remediate findings reported by independent auditors.

Artefacts an auditor will ask for
  • Most recent A 133 or single audit report addressing GLBA
  • Self assessment of Safeguards Rule controls
  • Remediation evidence for audit findings
  • Communications with FSA cybersecurity team
Where this commonly fails
  • Single audit covers financial aid administration but not Safeguards Rule
  • No self assessment refresh after 2023 rule update
  • Audit findings open beyond one year
GLBA-HE-Privacy-Notice
Privacy Notices and Opt Out

Although higher education institutions are deemed compliant with the GLBA Privacy Rule when they comply with FERPA, institutions must still ensure privacy notice and opt out practices align with FTC expectations where they perform financial activities beyond student financial aid administration.

Artefacts an auditor will ask for
  • FERPA notification of rights
  • Privacy notices for any non Title IV financial services such as employee credit unions or banking partnerships
  • Opt out mechanisms where applicable
Where this commonly fails
  • Reliance on FERPA without evaluating non Title IV financial activities
  • No privacy notices for institution operated lending or banking arrangements

GLBA Safeguards 314.3 to 314.4(b): Programme and Risk Assessment

GLBA-HE-314.3
Information Security Program

Develop, implement, and maintain a comprehensive written information security program that contains administrative, technical, and physical safeguards appropriate to the size and complexity of the institution and the nature and scope of activities involving customer information.

Artefacts an auditor will ask for
  • Written information security program (WISP) document
  • Board or executive approval minutes
  • Annual review evidence
  • Scope of customer information covered
Where this commonly fails
  • WISP exists only as policy fragments rather than a single program document
  • No evidence of periodic review and update
  • Scope excludes financial aid systems or third party servicers
GLBA-HE-314.4(a)
Qualified Individual

Designate a qualified individual responsible for overseeing, implementing, and enforcing the institution's information security program. The qualified individual may be employed by the institution, an affiliate, or a service provider.

Artefacts an auditor will ask for
  • Written designation of Qualified Individual
  • Position description with cybersecurity responsibilities
  • Reporting line documentation
  • Qualifications and credentials evidence
Where this commonly fails
  • No formal written designation
  • Qualified Individual lacks authority over IT or financial aid systems
  • Responsibilities split across roles with no single accountable owner
GLBA-HE-314.4(b)
Risk Assessment

Conduct a written risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information, and assesses the sufficiency of safeguards in place to control those risks. Update periodically.

Artefacts an auditor will ask for
  • Written risk assessment with criteria for evaluating risks
  • Asset inventory covering customer information systems
  • Threat and vulnerability analysis
  • Risk treatment register
  • Periodic update evidence
Where this commonly fails
  • Risk assessment is qualitative without defined criteria
  • Financial aid SaaS and student information systems excluded from scope
  • No reassessment after material changes

GLBA Safeguards 314.4(c): Technical and Physical Safeguards

GLBA-HE-314.4(c)(1)
Access Controls

Implement and periodically review access controls including technical and physical controls to authenticate and permit access only to authorized users and limit authorized users access to customer information that they need to perform their duties.

Artefacts an auditor will ask for
  • Access control policy
  • Role based access matrix for student information systems
  • Periodic access review records
  • Joiner mover leaver evidence
  • Privileged access logs
Where this commonly fails
  • Shared accounts in financial aid offices
  • No periodic recertification of access
  • Bursar or registrar staff have access beyond their duties
GLBA-HE-314.4(c)(2)
Data Inventory and Classification

Identify and manage the data, personnel, devices, systems, and facilities that enable the institution to achieve business purposes in accordance with their relative importance to business objectives and the institution's risk strategy.

Artefacts an auditor will ask for
  • Inventory of systems processing customer information
  • Data flow diagrams showing student financial data
  • Data classification standard
  • Record of authoritative sources for FAFSA data
Where this commonly fails
  • Inventory limited to enterprise IT and excludes departmental systems
  • No mapping of customer information across cloud services
  • Shadow IT in admissions or advancement offices
GLBA-HE-314.4(c)(3)
Encryption of Customer Information

Encrypt all customer information held or transmitted by the institution both in transit over external networks and at rest. Where encryption is infeasible, compensating controls reviewed and approved by the Qualified Individual must be used.

Artefacts an auditor will ask for
  • Encryption standard and key management policy
  • Configuration evidence for TLS on external interfaces
  • Disk and database encryption evidence
  • Approved exception register signed by Qualified Individual
Where this commonly fails
  • Legacy financial aid systems transmit data unencrypted internally
  • No evidence of encryption at rest in backup tapes
  • Exceptions undocumented or unapproved
GLBA-HE-314.4(c)(4)
Secure Development Practices

Adopt secure development practices for in house developed applications utilized for transmitting, accessing, or storing customer information, and procedures for evaluating, assessing, or testing the security of externally developed applications utilized to access customer information.

Artefacts an auditor will ask for
  • Secure coding standards
  • Code review and SAST DAST evidence
  • Vendor security assessments for student information systems
  • Penetration test reports for student portals
Where this commonly fails
  • No SAST or DAST run on internally developed portals
  • Procured SaaS not assessed for security before integration
  • Departmental web apps outside central SDLC
GLBA-HE-314.4(c)(5)
Multi-Factor Authentication

Implement multi factor authentication for any individual accessing any information system. The Qualified Individual may approve in writing the use of reasonably equivalent or more secure access controls.

Artefacts an auditor will ask for
  • MFA enrollment reports
  • Configuration of identity provider
  • Coverage report for student information system and ERP
  • Written approvals for any equivalent controls
Where this commonly fails
  • MFA enforced only for VPN and not for SaaS
  • Service accounts excluded with no compensating control
  • Adjunct faculty accounts not enrolled
GLBA-HE-314.4(c)(6)
Secure Disposal

Develop, implement, and maintain procedures for the secure disposal of customer information in any format no later than two years after the last date the information is used in connection with the provision of a product or service to the customer, unless retention is required for legitimate business purposes or by law.

Artefacts an auditor will ask for
  • Retention schedule with categories for customer information
  • Certificate of destruction for media and paper
  • Automated purge job evidence
  • Legal hold exceptions
Where this commonly fails
  • No retention schedule for financial aid records beyond regulatory minimums
  • Decommissioned servers wiped without certificate
  • Departmental backups retained indefinitely
GLBA-HE-314.4(c)(7)
Change Management

Adopt procedures for change management. Changes to information systems that store, process, or transmit customer information must be tracked, evaluated for security impact, tested, and approved.

Artefacts an auditor will ask for
  • Change management policy
  • Change advisory board minutes
  • Sample change tickets with security review
  • Emergency change records
Where this commonly fails
  • No security impact assessment in change tickets
  • Shadow changes outside formal process
  • No segregation of duties between developer and deployer
GLBA-HE-314.4(c)(8)
Logging and Monitoring of Authorized Users

Implement policies, procedures, and controls designed to monitor and log the activity of authorized users and detect unauthorized access or use of, or tampering with, customer information by such users.

Artefacts an auditor will ask for
  • Logging standard
  • SIEM use cases for customer information access
  • Sample alerts and triage records
  • Privileged user session monitoring evidence
Where this commonly fails
  • No logging on financial aid database queries
  • Logs retained less than 90 days
  • No correlation between SIS and identity provider events

GLBA Safeguards 314.4(d) to (i): Testing, Training and Oversight

GLBA-HE-314.4(d)
Testing and Monitoring of Safeguards

Regularly test or otherwise monitor the effectiveness of the safeguards key controls, systems, and procedures. Testing must include continuous monitoring or, in its absence, annual penetration testing and biannual vulnerability assessments.

Artefacts an auditor will ask for
  • Annual penetration test report
  • Biannual vulnerability scan reports
  • Continuous monitoring tooling configuration
  • Remediation tracking
Where this commonly fails
  • Vulnerability scans run but not reviewed
  • Penetration test scope excludes student portals
  • No retest of remediated findings
GLBA-HE-314.4(e)
Security Awareness Training

Implement policies and procedures to ensure personnel are able to enact the information security program by providing security awareness training that is updated as necessary to reflect risks identified by the risk assessment, and utilize qualified information security personnel.

Artefacts an auditor will ask for
  • Annual training records with completion rates
  • Role based training for financial aid staff
  • Phishing simulation results
  • Personnel qualifications for security team
Where this commonly fails
  • Training completion below 95 percent for student facing staff
  • Generic content without higher ed scenarios
  • No verification of training currency for contractors
GLBA-HE-314.4(f)
Service Provider Oversight

Oversee service providers by taking reasonable steps to select and retain service providers capable of maintaining appropriate safeguards, requiring providers by contract to implement and maintain such safeguards, and periodically assessing service providers based on the risk they present.

Artefacts an auditor will ask for
  • Vendor inventory and tiering
  • Security clauses in service provider contracts
  • Annual reassessment evidence
  • SOC 2 or equivalent reports for material providers
Where this commonly fails
  • Loan servicers, FAFSA processors, or LMS vendors not assessed
  • No reassessment after initial onboarding
  • Contracts predate Safeguards Rule update without amendment
GLBA-HE-314.4(g)
Program Evaluation and Adjustment

Evaluate and adjust the information security program in light of the results of the testing and monitoring, any material changes to operations or business arrangements, the results of risk assessments, or any other circumstances that may have a material impact on the program.

Artefacts an auditor will ask for
  • Program change log
  • Lessons learned from incidents
  • Adjustments following merger or acquisition
  • Trigger events register
Where this commonly fails
  • No formal trigger criteria for re evaluation
  • Adjustments not documented
  • Program unchanged across multiple risk assessments
GLBA-HE-314.4(h)
Incident Response Plan

Establish a written incident response plan designed to promptly respond to and recover from any security event materially affecting the confidentiality, integrity, or availability of customer information in the institution's control.

Artefacts an auditor will ask for
  • Written incident response plan
  • Plan covers goals, internal processes, roles, communications, remediation, documentation, and post incident review
  • Tabletop exercise records
  • Sample incident records
Where this commonly fails
  • IR plan exists but is not customer information specific
  • No post incident review documented
  • Tabletop exercises do not involve financial aid leadership
GLBA-HE-314.4(i)
Annual Report to Board

Require the Qualified Individual to report in writing, at least annually, to the board of directors, equivalent governing body, or senior officer responsible for the information security program. The report addresses overall program status, risk assessment, risk management decisions, service provider arrangements, testing results, security events, and recommendations.

Artefacts an auditor will ask for
  • Annual written report to board or senior officer
  • Board or committee meeting minutes acknowledging report
  • Distribution list and review records
Where this commonly fails
  • Verbal updates only, no written report
  • Report omits required topics such as testing results or service provider arrangements
  • No evidence of board acknowledgement

GLBA Safeguards 314.5: Security Event Notification

GLBA-HE-314.5
Notification of Security Event

Notify the FTC as soon as possible, and no later than 30 days after discovery, of any notification event involving unauthorized acquisition of unencrypted customer information of 500 or more consumers.

Artefacts an auditor will ask for
  • Notification procedure
  • Determination memo for notification threshold
  • FTC notification submission record
  • Coordination with Department of Education and state regulators
Where this commonly fails
  • No procedure for the 30 day FTC notification timeline
  • Threshold determination not documented
  • No coordination playbook with DoE PPA contacts

Governance

USGLBAHIGHER-1
Qualified Individual and Risk Assessment

Per FTC Safeguards Rule 16 CFR Part 314 + GLBA: Qualified Individual designation + Written risk assessment + Board engagement + applicable to higher education through Title IV.

Artefacts an auditor will ask for
  • GLBA Higher Ed evidence for USGLBAHIGHER-1
Where this commonly fails
  • QI + risk + MFA partial

Incident

USGLBAHIGHER-4
Incident Response and Notification

Per 16 CFR 314: incident response + notification to FTC + maintain written IR plan.

Artefacts an auditor will ask for
  • GLBA Higher Ed evidence for USGLBAHIGHER-4
Where this commonly fails
  • QI + risk + MFA partial

Monitoring

USGLBAHIGHER-3
Continuous Monitoring, Testing, Vendor Oversight

Per 314.4(d) + (f): continuous monitoring and testing + service provider oversight + program evaluation and adjustment.

Artefacts an auditor will ask for
  • GLBA Higher Ed evidence for USGLBAHIGHER-3
Where this commonly fails
  • QI + risk + MFA partial

Technical

USGLBAHIGHER-2
Access Controls, Encryption, MFA, Inventory

Per 16 CFR 314.4(c): access controls + encryption + MFA + asset inventory + secure SDLC + change management.

Artefacts an auditor will ask for
  • GLBA Higher Ed evidence for USGLBAHIGHER-2
Where this commonly fails
  • QI + risk + MFA partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule framework page.