About this Framework
The FTC Safeguards Rule (amended 2021, effective June 2023) requires non-bank financial institutions regulated by the FTC to implement a written information security program with specific technical requirements. The updated rule mandates designation of a qualified information security individual, formal risk assessments, specific safeguards (access controls, MFA, encryption, annual penetration testing, biannual vulnerability scanning, incident response plan) and annual reporting to the board. Institutions with 5,000+ customer records must notify the FTC of qualifying security events within 30 days.
Key Control Domains
Who Needs This?
- Mortgage companies and brokers regulated by the FTC
- Payday and student loan lenders
- Auto dealers offering consumer financing
- Accountants and tax preparation services
- Investment advisors not subject to SEC Regulation S-P
Compliance Benefits
- FTC regulatory compliance and civil penalty avoidance
- Structured programme for protecting customer financial data
- Specific technical requirements reduce implementation ambiguity
- 30-day incident notification requirement provides regulatory clarity
Official Reference
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/ftc-safeguards-rule-assessment