GRCCopilot
Sign In
U.S. Federal Trade Commission (FTC)

FTC Safeguards Rule Assessment

FTC's updated financial data security rule — requires written security programs with specific technical controls for non-bank financial institutions

Start Assessment Create Free Account
12
Controls
36
Questions
Active
Status
May 2029
Expires

About this Framework

The FTC Safeguards Rule (amended 2021, effective June 2023) requires non-bank financial institutions regulated by the FTC to implement a written information security program with specific technical requirements. The updated rule mandates designation of a qualified information security individual, formal risk assessments, specific safeguards (access controls, MFA, encryption, annual penetration testing, biannual vulnerability scanning, incident response plan) and annual reporting to the board. Institutions with 5,000+ customer records must notify the FTC of qualifying security events within 30 days.

Key Control Domains

Written Information Security Program (WISP)
Qualified Individual Designation (QI)
Risk Assessment Process
Access Controls & Least Privilege
Encryption In Transit and At Rest
Multi-Factor Authentication (MFA)
Penetration Testing (Annual)
Vulnerability Scanning (Biannual)
Incident Response Plan
Service Provider Oversight
Board of Directors Reporting

Who Needs This?

  • Mortgage companies and brokers regulated by the FTC
  • Payday and student loan lenders
  • Auto dealers offering consumer financing
  • Accountants and tax preparation services
  • Investment advisors not subject to SEC Regulation S-P

Compliance Benefits

  • FTC regulatory compliance and civil penalty avoidance
  • Structured programme for protecting customer financial data
  • Specific technical requirements reduce implementation ambiguity
  • 30-day incident notification requirement provides regulatory clarity

Official Reference

FTC Safeguards Rule Guidance
https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act/safeguards-rule

Assessment Details

Issuer / AuthorityU.S. Federal Trade Commission (FTC)
FrameworkFTC Safeguards Rule Assessment
Controls12
Questions36
StatusActive
Assessment Start25 May 2026
Assessment Expires25 May 2029

Share this Assessment

Share this permanent link with your team, clients or auditors.

https://grcopilot.app/frameworks/ftc-safeguards-rule-assessment

Sign in to begin this assessment

Create a free GRC Copilot account to access this and 50+ other security and compliance frameworks.