NewsChecking whether your organization follows the FTC Safeguards Rule requires more than confirming that a cybersecurity policy exists.
Covered financial institutions must develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards designed to protect customer information. The program must also reflect the organization's size and complexity, activities, and the sensitivity of the information it handles.
This FTC Safeguards Rule Compliance Checklist gives financial institutions a practical way to review major areas of their program from risk assessment and multi-factor authentication to personnel training, service-provider oversight, and incident response.
It is a review tool, not an FTC-approved audit or a guarantee of compliance. For regulatory context, see the Federal Trade Commission's FTC Safeguards Rule guidance for businesses.
For a broader explanation of scope, covered financial institutions, exemptions, and core obligations, see our FTC Safeguards Rule Requirements: Compliance Guide
How to Use This FTC Safeguards Rule Compliance Checklist
A useful compliance review should go beyond asking whether a policy or control exists. For each item below, consider four questions:
-
Implementation: Is the control, process, or policy actually in place?
-
Ownership: Is someone clearly responsible for it?
-
Evidence: Can the organization demonstrate how it has been implemented?
-
Review: Is it reevaluated when risks, systems, operations, or regulatory requirements change?
Responsibility may be shared across compliance, information security, IT, management, HR, training, procurement, and other functions. The appropriate structure will depend on the organization.
If your team needs broader context on how regulatory duties connect with security controls, USCI's guide to cybersecurity compliance provides additional background without replacing the Safeguards Rule's specific requirements.
FTC Safeguards Rule Compliance Checklist

1. Designate a Qualified Individual
The first question is straightforward: Who is responsible for overseeing the information security program?
Review whether your organization can check each of these boxes:
-
A Qualified Individual has been designated to oversee and implement the information security program.
-
The individual's responsibilities are clearly documented.
-
If the Qualified Individual works for an affiliate or service provider, a senior member of your personnel oversees that individual.
-
The organization retains responsibility for complying with the Rule.
The Qualified Individual does not have to hold a specific title or degree. The Rule allows the person to be employed by the financial institution, an affiliate, or a service provider, subject to the conditions in 16 CFR § 314.4(a).
2. Maintain a Written Risk Assessment
A Safeguards Rule program should be built around the risks the organization actually faces.
Check whether:
-
The organization has a written risk assessment.
-
It identifies reasonably foreseeable internal and external risks to customer information.
-
Existing safeguards are evaluated against those risks.
-
Criteria for evaluating and categorizing security risks are documented.
-
The organization documents how identified risks will be mitigated or accepted.
-
Additional risk assessments are performed periodically as circumstances change.
The FTC requirements for risk assessments require more than a one-time inventory of threats. The assessment must also evaluate the adequacy of existing safeguards and be revisited periodically.
For teams developing broader risk-review methods, a risk assessment matrix can help explain how risks may be evaluated and prioritized. That resource is general risk-management guidance; the Safeguards Rule itself remains the controlling federal requirement here.
3. Review Access, Data, Encryption, MFA, and Other Safeguards
Once risks have been identified, the organization must design and implement safeguards to control them.
Use the following questions as a focused review.
Access controls
-
Are users authenticated before accessing customer information?
-
Is access limited to information users need for their duties?
-
Are access permissions periodically reviewed?
Data, systems, and assets
-
Has the organization identified relevant data, personnel, devices, systems, and facilities?
-
Does the organization know where customer information is stored, transmitted, and processed?
Encryption
-
Is customer information encrypted both at rest and in transit over external networks?
-
If encryption is infeasible, are effective alternative compensating controls reviewed and approved by the Qualified Individual?
Application security
-
Are secure development practices used for in-house applications that handle customer information?
-
Are externally developed applications evaluated, assessed, or tested for security?
Multi-factor authentication
-
Is multi-factor authentication used for individuals accessing information systems?
-
If an alternative access control is used, has the Qualified Individual approved in writing that it is reasonably equivalent or more secure?
Retention and disposal
-
Does the organization have procedures for securely disposing of customer information when the Rule requires it?
-
Is the data-retention policy periodically reviewed to reduce unnecessary retention?
Change management and logging
-
Are changes to information systems managed through established procedures?
-
Are authorized-user activities monitored and logged?
-
Are controls designed to detect unauthorized access, use, or tampering?
These requirements are addressed in the required safeguards under 16 CFR § 314.4(c).
4. Test and Monitor the Effectiveness of Safeguards
Security controls cannot simply be implemented and then left unchecked.
Review whether:
-
Key controls, systems, and procedures are regularly tested or monitored.
-
The organization has effective continuous monitoring where appropriate.
-
If effective continuous monitoring or another ongoing vulnerability-detection system is not used, the organization addresses the applicable penetration-testing requirements.
-
Vulnerability assessments are performed at the required intervals and when relevant changes or circumstances arise.
One detail is important here. The Rule does not simply say that every covered organization must perform one penetration test every year regardless of its monitoring program.
Under the FTC testing and monitoring requirements, information-system monitoring and testing must include continuous monitoring or periodic penetration testing and vulnerability assessments. Absent effective continuous monitoring or comparable ongoing detection, the Rule calls for annual penetration testing and vulnerability assessments at least every six months, as well as assessments in certain additional circumstances.
5. Provide Security Awareness Training to Personnel
Technology alone does not satisfy the Rule. Personnel must be able to carry out the information security program.

Check whether:
-
Personnel receive security awareness training.
-
Awareness training is updated as necessary to reflect risks identified through the risk assessment.
-
Qualified information security personnel are available to manage relevant risks and oversee the program.
-
Information security personnel receive training and security updates appropriate to relevant risks.
-
Key security personnel maintain current knowledge of changing threats and countermeasures.
-
Training participation or completion is appropriately documented.
The security awareness training requirements in § 314.4(e) distinguish general security awareness for personnel from the more specialized security training and updates needed by information security personnel.
Organizations reviewing this part of their program may use USCI's FTC Safeguards Rule Awareness Training to support personnel awareness efforts. Learners receive a certificate of completion after completing the course; the course itself should not be treated as proof that an organization satisfies every Safeguards Rule requirement.
Related risks such as phishing and manipulation of employees are also covered in USCI's educational guide to social engineering in cybersecurity.
6. Oversee Service Providers
Outsourcing a service does not eliminate the need to protect customer information handled by that provider.
Check whether:
-
Reasonable steps are taken to select and retain service providers capable of maintaining appropriate safeguards.
-
Contracts require relevant service providers to implement and maintain safeguards.
-
Service providers are periodically assessed based on the risks they present.
-
Vendor reviews and significant findings are documented.
The FTC service provider requirements expressly address provider selection, contractual safeguards, and ongoing assessment.
Organizations that rely heavily on external data sources or vendors may also find it useful to review how third-party data enters and moves through their operations.
7. Evaluate and Update the Information Security Program
A written security program should change when the organization's risks change.
Ask:
-
Are testing and monitoring results used to adjust the program?
-
Are material changes in business operations or arrangements considered?
-
Do updated risk assessments lead to appropriate program changes?
-
Are other circumstances that may materially affect information security taken into account?
The Rule's requirements for evaluating and adjusting the security program make this an ongoing process rather than a one-time compliance exercise.
8. Maintain a Written Incident Response Plan
Financial institutions subject to the relevant requirement should have a written plan for responding to and recovering from security events that materially affect customer information.
Check whether the plan addresses:
-
The goals of the incident response process.
-
Internal procedures for responding to a security event.
-
Clear roles, responsibilities, and decision-making authority.
-
Internal and external communications.
-
Remediation of identified weaknesses.
-
Documentation and reporting of security events and response activities.
-
Evaluation and revision of the plan after a security event.
These elements come directly from the incident response requirements under § 314.4(h).
A strong incident response plan should also fit within the organization's broader approach to data privacy compliance, particularly where personal information may be affected by an incident.
9. Complete Required Governance Reporting
The Qualified Individual's responsibilities extend beyond day-to-day program management.
Review whether:
-
The Qualified Individual reports in writing to the board of directors or equivalent governing body.
-
If no board or equivalent governing body exists, the report goes to the appropriate senior officer.
-
Reporting occurs regularly and at least annually.
-
The report addresses the overall status of the information security program and compliance with the Rule.
-
Material matters such as risk assessments, controls, service-provider arrangements, testing results, security events, and recommended program changes are addressed where relevant.
See the annual reporting requirement for the Qualified Individual for the regulatory language.
10. Prepare for FTC Breach Notification Requirements
Incident response and regulatory notification are related, but they are not the same task.
Check whether:
-
Suspected notification events are escalated promptly.
-
The organization can determine which information was involved and how many consumers were affected or potentially affected.
-
Responsibility for evaluating FTC notification obligations is clearly assigned.
-
The response process accounts for the federal notification deadline.
-
Applicable state and other federal notification requirements are evaluated separately.
Under FTC notification requirements in 16 CFR § 314.4(j), a covered financial institution must notify the FTC as soon as possible and no later than 30 days after discovery of a notification event involving the unauthorized acquisition of unencrypted customer information affecting at least 500 consumers. .
The Rule contains specific definitions and conditions for determining what constitutes a notification event and when it is treated as discovered. Organizations should evaluate the actual regulatory language rather than relying only on the numerical threshold.

Does the Fewer-Than-5,000-Consumers Exemption Remove All Safeguards Rule Requirements?
No. The fewer-than-5,000-consumers provision should not be treated as a blanket exemption from the Safeguards Rule.
According to the FTC's guidance on who is covered by the Safeguards Rule, financial institutions that maintain customer information concerning fewer than 5,000 consumers are exempt from certain provisions of the Rule.
That distinction matters. An organization below the threshold should not simply assume that the Safeguards Rule no longer applies.
Instead, determine which provisions apply to the organization and document the basis for that conclusion. Questions about the scope of an exemption or how it applies to a particular business may also warrant advice from qualified legal or compliance counsel.
Federal FTC Requirements and State Data Security Laws

The FTC Safeguards Rule is a federal requirement. Completing a federal Safeguards Rule review does not automatically address every state privacy, cybersecurity, data-security, or breach-notification obligation that may apply.
State laws can impose separate requirements based on factors such as where affected individuals live, the type of information involved, and the organization's activities.
This is particularly important after a security incident. An event that triggers or does not trigger the FTC's notification provision may still require a separate state-law analysis.
For that reason, organizations operating across multiple states should treat state requirements as a separate layer of the compliance review rather than assuming the federal checklist resolves them.
Keep the Checklist Current
FTC Safeguards Rule compliance is not a one-time checkbox exercise.
Risk assessments change. Systems are replaced. Employees change roles. New service providers gain access to information. Security threats evolve. A practical review process should account for those changes and document how identified gaps are addressed.
For broader workforce education, USCI's guide to information security compliance training explains how employee training fits into a wider security program.
And when personnel awareness is one of the areas identified for improvement, FTC Safeguards Rule Awareness Training can support that effort. USCI learners receive a certificate of completion; training should be used as one component of the organization's broader information security program, not as a substitute for the other safeguards the Rule requires.