Back to blog
US & Americas

The GLBA Safeguards Rule: who it covers is broader than you think

The FTC's Safeguards Rule reaches well beyond banks — into lenders, brokers, advisers, tax preparers and many businesses that never considered themselves financial institutions. What it requires, and the elements with hard specifics.
GRC Copilot Team
The GLBA Safeguards Rule: who it covers is broader than you think

The most common GLBA compliance failure is not a weak control — it is not realising the rule applies. The FTC's definition of a financial institution captures a wide range of businesses that provide financial products or services, and many of them have never thought of themselves that way.

Who it covers

Beyond obvious lenders and brokers, the rule has been applied to mortgage brokers, tax preparation firms, collection agencies, investment advisers not registered with the SEC, motor vehicle dealers arranging financing, career counsellors serving the financial industry, and businesses that provide credit or transfer funds as part of their service.

If your business touches consumer financial information as part of providing a financial product or service, check the definition properly rather than assuming. Smaller entities get a partial exemption from some elements based on the number of consumers whose information they hold — partial, not total.

What it requires

  • A written information security programme, appropriate to your size and complexity.
  • A designated qualified individual responsible for overseeing and enforcing it. This may be a third party, but accountability remains with you and requires senior oversight of that arrangement.
  • A written risk assessment, with criteria for evaluating and categorising risks — not an informal exercise.
  • Access controls limiting access to customer information to those who need it, reviewed periodically.
  • An inventory of data, personnel, devices and systems.
  • Encryption of customer information in transit and at rest — with compensating controls permitted only where encryption is infeasible, approved by the qualified individual.
  • Secure development practices for applications handling customer information.
  • Multi-factor authentication for anyone accessing information systems holding customer information. The wording is broad; scope it carefully.
  • Secure disposal of customer information, generally within two years of last use unless retention is justified.
  • Change management procedures.
  • Monitoring and logging of authorised user activity, to detect unauthorised access.

Evidence the programme, not just the policy

GRC Copilot tracks the controls, risk assessment and evidence a written information security programme depends on.

Testing, training and oversight

  • Continuous monitoring, or annual penetration testing plus vulnerability assessments at least twice yearly and after material changes. Note the "or" — continuous monitoring substitutes for the testing cadence.
  • Security awareness training, with more specialised training for security personnel.
  • Service provider oversight — selection based on their ability to safeguard, contractual requirements, and periodic reassessment.
  • Written incident response plan covering goals, processes, roles, communications, remediation and post-incident revision.
  • Annual written report from the qualified individual to the board or equivalent governing body, covering programme status, risk assessment results and recommendations.
The annual report to the board is the accountability hinge, in the same way certification is under NYDFS Part 500. It forces the programme's real state in front of people who can fund it — which is usually its most useful effect.

Incident notification

The rule includes an obligation to notify the FTC of certain security events affecting a threshold number of consumers, within a defined period of discovery. Build the determination process in advance — as with every short-clock obligation, the constraint is reaching a decision quickly, not filing the form.

How it relates to other frameworks

Organisations running ISO 27001 or aligned to the NIST CSF will find most of the substance covered. The gaps are structural rather than technical: the named qualified individual, the written risk assessment with defined criteria, the annual board report, the specific disposal timeline, and the encryption-infeasibility approval mechanism. Map, do not rebuild.

Frequently asked questions

We are not a bank — does it apply?

Possibly. The definition covers businesses significantly engaged in providing financial products or services. Check it against your actual activities.

Can the qualified individual be outsourced?

Yes, with a senior member of your organisation directing and overseeing that person, and you retain responsibility.

Is MFA required for everyone?

For individuals accessing information systems holding customer information. Scope the boundary carefully rather than assuming it is only remote access.

What if encryption is not feasible?

Compensating controls may be used, reviewed and approved in writing by the qualified individual. That approval is the evidence.

Key takeaways

  • Scope is far broader than banks — check the definition against your activities.
  • The qualified individual and annual board report are the accountability mechanism.
  • MFA and encryption carry specific wording; scope them deliberately.
  • An existing ISO or CSF programme covers the substance; the gaps are structural.
#glba #safeguards-rule #ftc #financial-institutions #qualified-individual #non-banks