The most common GLBA compliance failure is not a weak control — it is not realising the rule applies. The FTC's definition of a financial institution captures a wide range of businesses that provide financial products or services, and many of them have never thought of themselves that way.
Who it covers
Beyond obvious lenders and brokers, the rule has been applied to mortgage brokers, tax preparation firms, collection agencies, investment advisers not registered with the SEC, motor vehicle dealers arranging financing, career counsellors serving the financial industry, and businesses that provide credit or transfer funds as part of their service.
If your business touches consumer financial information as part of providing a financial product or service, check the definition properly rather than assuming. Smaller entities get a partial exemption from some elements based on the number of consumers whose information they hold — partial, not total.
What it requires
- A written information security programme, appropriate to your size and complexity.
- A designated qualified individual responsible for overseeing and enforcing it. This may be a third party, but accountability remains with you and requires senior oversight of that arrangement.
- A written risk assessment, with criteria for evaluating and categorising risks — not an informal exercise.
- Access controls limiting access to customer information to those who need it, reviewed periodically.
- An inventory of data, personnel, devices and systems.
- Encryption of customer information in transit and at rest — with compensating controls permitted only where encryption is infeasible, approved by the qualified individual.
- Secure development practices for applications handling customer information.
- Multi-factor authentication for anyone accessing information systems holding customer information. The wording is broad; scope it carefully.
- Secure disposal of customer information, generally within two years of last use unless retention is justified.
- Change management procedures.
- Monitoring and logging of authorised user activity, to detect unauthorised access.
Evidence the programme, not just the policy
GRC Copilot tracks the controls, risk assessment and evidence a written information security programme depends on.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Testing, training and oversight
- Continuous monitoring, or annual penetration testing plus vulnerability assessments at least twice yearly and after material changes. Note the "or" — continuous monitoring substitutes for the testing cadence.
- Security awareness training, with more specialised training for security personnel.
- Service provider oversight — selection based on their ability to safeguard, contractual requirements, and periodic reassessment.
- Written incident response plan covering goals, processes, roles, communications, remediation and post-incident revision.
- Annual written report from the qualified individual to the board or equivalent governing body, covering programme status, risk assessment results and recommendations.
The annual report to the board is the accountability hinge, in the same way certification is under NYDFS Part 500. It forces the programme's real state in front of people who can fund it — which is usually its most useful effect.
Incident notification
The rule includes an obligation to notify the FTC of certain security events affecting a threshold number of consumers, within a defined period of discovery. Build the determination process in advance — as with every short-clock obligation, the constraint is reaching a decision quickly, not filing the form.
How it relates to other frameworks
Organisations running ISO 27001 or aligned to the NIST CSF will find most of the substance covered. The gaps are structural rather than technical: the named qualified individual, the written risk assessment with defined criteria, the annual board report, the specific disposal timeline, and the encryption-infeasibility approval mechanism. Map, do not rebuild.
Frequently asked questions
We are not a bank — does it apply?
Possibly. The definition covers businesses significantly engaged in providing financial products or services. Check it against your actual activities.
Can the qualified individual be outsourced?
Yes, with a senior member of your organisation directing and overseeing that person, and you retain responsibility.
Is MFA required for everyone?
For individuals accessing information systems holding customer information. Scope the boundary carefully rather than assuming it is only remote access.
What if encryption is not feasible?
Compensating controls may be used, reviewed and approved in writing by the qualified individual. That approval is the evidence.
Key takeaways
- Scope is far broader than banks — check the definition against your activities.
- The qualified individual and annual board report are the accountability mechanism.
- MFA and encryption carry specific wording; scope them deliberately.
- An existing ISO or CSF programme covers the substance; the gaps are structural.