GLBA Safeguards readiness for financial services firms
GLBA's reach is wider than its name suggests. The FTC's amended Safeguards Rule pulls in a long tail of non-bank financial institutions, mortgage brokers and lenders, auto dealers arranging financing, payday and installment lenders, collection agencies, tax preparers, investment advisers not registered with the SEC, and even finders bringing together buyers and sellers, and since the 2023 amendments it also requires reporting certain security events affecting 500 or more consumers to the FTC within 30 days. Banks answer to their prudential regulators under the Interagency Guidelines instead, but the substance converges: a written information security program with specific, named elements, and accountability that reaches leadership.
What distinguishes the amended Safeguards Rule from older Gramm-Leach-Bliley practice is prescriptiveness. A designated qualified individual must own the program and report to the board or a senior officer at least annually. The rule then names its required controls: risk assessment in writing, access controls, inventory of data and systems, encryption of customer information at rest and in transit, multi-factor authentication, secure development practices, change management, monitoring or annual penetration testing plus vulnerability assessments, service provider oversight, and an incident response plan. Readiness is therefore unusually concrete: each named element either exists with evidence or it does not, and enforcement actions have followed exactly that checklist.
Key considerations for financial services teams
Confirm whether and how you are covered. 'Financial institution' under the FTC rule turns on activities, not charters; businesses that never considered themselves financial (dealerships, tax practices, collection firms) are covered, while banks follow parallel interagency guidance through their examiners.
The qualified individual is an accountability mechanism, not a title. The rule expects a named person with real authority, a written program they own, and at least annual written reporting to the board covering program status, risk assessment, and security events; missing governance is itself a violation.
Encryption and MFA are effectively non-negotiable. The rule requires encryption of customer information in transit and at rest, and MFA for any individual accessing information systems, with narrowly available compensating-control write-ups approved by the qualified individual; legacy systems that cannot comply need documented, approved alternatives.
Service provider oversight must be a lifecycle, not a clause. Selecting providers capable of maintaining safeguards, contractually requiring them, and periodically reassessing them are all explicit rule elements; a BAA-style contract signature without ongoing assessment fails the third prong.
The FTC breach-reporting clock is short. Notification events involving unencrypted customer information of 500 or more consumers must be reported to the FTC within 30 days of discovery; your incident response plan needs that determination and filing path built in, alongside state breach-notification obligations.
This work is part of our Cyber Governance practice
A security program you can demonstrate, not just describe.
Explore Cyber GovernanceFrequently asked questions
We are not a bank. Why does GLBA apply to us?
Because coverage follows financial activities as defined by the rule, not banking charters. Arranging loans, extending credit, collecting debts, preparing tax returns, or providing financial advisory services can each make you a financial institution under the FTC Safeguards Rule. The determination is worth documenting formally either way, since it defines your obligations.
How does the Safeguards Rule interact with state privacy and security laws?
GLBA-regulated data is typically exempted from state comprehensive privacy laws, but the exemptions are usually data-level, not entity-level: information outside GLBA's scope at the same company can still be covered by state law. Security-wise, states like New York layer additional requirements (NYDFS Part 500) on licensed entities; the programs should be built once and mapped to each.
What does 'continuous monitoring or annual penetration testing' actually require?
The rule offers a choice: implement continuous monitoring capable of detecting changes that create vulnerabilities, or conduct annual penetration testing plus vulnerability assessments at least every six months (and after material changes). Most smaller institutions choose the testing path; either way, results must feed documented remediation.
See where your GLBA program stands today.
Start with a structured readiness review scoped to your organization, or run a self-serve risk assessment to get an initial read.
RiskSensai content is informational only. It is not an audit opinion, assurance, or legal or accounting advice.
Related readiness guides
SOC 2 for Financial Services
In financial services, SOC 2 usually arrives through the vendor door: banks, broker-dealers, and insurers are themselves regulated on third-party risk, so they push examination-grade expectations down to every fintech, data provider, and outsourced service they touch.
ISO 27001 for Financial Services
ISO 27001 certification carries particular weight in financial services because it attests to a management system, not just a snapshot of controls.
EU AI Act for Financial Services
Financial services sits squarely in the EU AI Act's crosshairs: creditworthiness assessment for natural persons and risk assessment and pricing in life and health insurance are explicitly designated high-risk uses, and AI used in employment decisions, common across the industry, is high-risk as well.
NIST AI RMF for Financial Services
Financial services has governed models for decades: SR 11-7 made model risk management a supervisory expectation, with inventories, independent validation, and documentation as table stakes.
