FTC Safeguards Rule Training Requirements in 2026

FTC Safeguards Rule training is required, but is an annual course enough? Find out who needs training, what to cover, and what records help.

Manager discussing customer information security with employees during workplace training

Covered financial institutions must give their personnel security awareness training and update it as needed to reflect risks found in their risk assessments. They must also provide suitable security training and updates to information security personnel and check that key staff stay current. The FTC Safeguards Rule does not set one annual course, a minimum number of training hours, or an FTC-issued certificate for every employee. Your training must help people carry out your business’s information security program. Read the training provision in 16 CFR § 314.4(e). 

If you manage training at a dealership, tax firm, mortgage business, or another covered company, the practical question is, what should each person be able to do after the training? Start with the rule, then match the lessons to the customer information and risks in your workplace.

What Does the FTC Actually Require for Training?

Infographic explaining security awareness training for personnel and additional training for information security staff under FTC Safeguards Rule section 314.4(e)

The Safeguards Rule’s training provision has four parts. In plain English, a covered institution must:

  1. Train personnel in security awareness. Update that training as needed to reflect risks identified by the institution’s risk assessment.

  2. Use qualified information security personnel. These people may work for the institution, an affiliate, or a service provider. There must be enough qualified people to manage the risks and carry out or oversee the security program.

  3. Give information security personnel suitable training and updates. Their learning must address the risks relevant to their work.

  4. Check that key security personnel keep their knowledge current. They need to stay informed about changing threats and ways to counter them. 

The rule requires training that fits the risks. In practice, an employer might assign awareness lessons to its 

staff, add technical training for the security team, and revisit both when its risks change. That is an implementation example, not a separate federal checklist. The FTC’s business guide also recommends regular refreshers and specialized training for people responsible for the program. 

Training is one part of the broader FTC Safeguards Rule requirements. Your access controls, vendor oversight, and other applicable safeguards still matter.

Which Businesses and Workers Need Training?

The rule applies to financial institutions under the FTC’s jurisdiction, a category wider than everyday use of the term “financial institution.” Coverage depends on what a business does and which regulator oversees it. The FTC lists examples including mortgage brokers, tax preparation firms, collection agencies, and certain financial advisors. Its auto dealer guidance explains why most dealers that arrange consumer financing or lease cars are covered. A business should check its activities before assuming it is in or out.

Customer information can include a paper or electronic record containing nonpublic personal information about a customer that the institution, an affiliate, or someone acting on its behalf handles or keeps. For example, a covered dealership’s customer financing records need protection. Staff who collect, enter, print, email, store, or dispose of such records need to know the practices their jobs require. The FTC explains what counts as customer information in its dealer guidance.

The wording of § 314.4(e) says “your personnel” for awareness training. It separately calls for appropriate training and updates for information security personnel. So do not assume a general course is all your qualified individual or IT staff needs. The FTC says the Qualified Individual can be an employee or work for an affiliate or service provider; the institution remains responsible for its program.

What if your business is small? A covered institution that maintains customer information concerning fewer than 5,000 consumers has an exception from certain specified provisions. Training under § 314.4(e) is not one of them. The threshold refers to consumers whose information the institution maintains, not the number of employees Check the exact exception in § 314.6. 

What Should FTC Safeguards Rule Training Cover?

The rule does not give every business the same lesson plan. Build your topics around your staff’s work, your written security program, and the risks you have identified. A useful awareness program might teach employees to:

  • Spot suspicious requests. Practice what to do with a message asking for a customer file, a password, or an unexpected payment change. If your team uses Outlook, our guide to reporting a phishing email in Outlook answers a useful next question.

  • Handle customer information safely. Show the approved way to receive, share, store, print, and dispose of the records used in their jobs.

  • Use the access tools your company provides. Teach staff to protect accounts, follow access limits, and use multi-factor authentication (MFA) where it applies. The rule includes access controls and MFA requirements, but a short lesson does not implement those controls for the company.

  • Report a possible problem quickly. Give staff a named contact or clear reporting route for a lost device, wrongly sent file, suspicious login, or suspected disclosure. Teach them what details to pass along without asking them to decide whether the event is legally reportable.

  • Follow the company’s own procedures. A tax preparer, dealership employee, and security administrator may all need different examples, even if they share the same basic awareness course.

These are practical training topics, not a syllabus prescribed word for word by the FTC. They connect daily behavior to the rule’s safeguards and incident-response provisions. For some security events involving at least 500 consumers’ unencrypted information, the institution may have an FTC notification duty. Employees need to know how to alert the right internal team; they do not need to make that legal determination on their own. 

Need a starting point for staff awareness? US Compliance Institute’s FTC Safeguards Rule Awareness Training covers customer information, phishing and social engineering, access controls, incident reporting, and related employee duties. Use it alongside your own policies, reporting contacts, and any additional role-specific security training. The course does not, by itself, make an institution compliant.

Employee checking a suspicious email with a supervisor in a financial services office

How Often Should Employees Take the Training?

The FTC Safeguards Rule does not say “once a year” for awareness training. It says training must be updated as necessary to reflect risks found through the risk assessment. The FTC’s guidance recommends scheduling regular refreshers. That advice is useful, but it is different from a fixed annual deadline in the regulation. 

Here is an example schedule, not a federal schedule: Introduce the basics when someone starts a role, run periodic refreshers, and update lessons when your risk review finds a new problem or the workplace changes. A new customer portal, a rise in phishing attempts, or a change in who can access records may call for a targeted lesson. Security staff may also need updates on the threats and controls they manage.

Ask one practical question after each session: Can this person apply the lesson to the work they do here? A repeated mistake or a missed reporting step may tell you more about the need for a refresher than the date on a calendar.

How Can You Show That Training Happened?

Keep records that let you understand what each person received and whether it helped. For example, record the employee’s role, the assigned course or lesson and its version, the completion date, any knowledge check or acknowledgment, and any follow-up coaching. Keep the materials and your reason for updating them when risks change.

This is a recommended way to manage and show your training program. Section 314.4(e) does not prescribe this particular record format or state that a completion certificate alone proves compliance. A certificate may show that someone completed a course. It cannot show, by itself, that the course matched the institution’s risks, that the person knows the local reporting process, or that other required safeguards are in place. Review the actual training provision here. 

How to Build a Training Plan for Your Team

Five-step practical plan for assigning, checking, and updating FTC Safeguards Rule employee training

  1. Confirm whether the rule covers your business. Check your activities and regulator. Do not decide from the business name alone.

  2. Identify jobs and risks. Note where customer information moves and which employees can handle it. Use the institution’s risk findings to choose examples people will recognize.

  3. Assign the right learning. Give personnel security awareness training. Plan additional training and updates for information security personnel and check how key people keep current.

  4. Teach what happens at your workplace. Point to the actual reporting contact, approved file-sharing method, access process, and response steps. Let staff practice a realistic decision.

  5. Check and update. Track participation, ask a short question or run a scenario, fix gaps, and revise lessons when risks change.

For example, a covered auto dealer might teach sales staff how to handle financing records and flag a suspicious request for a customer’s documents. Its IT or security staff may need deeper instruction on the access systems and threats they manage. A new file-sharing tool would prompt the dealer to review both the procedure and the relevant training. That is a sample plan, not an FTC-approved dealership template. The FTC’s dealer-specific guidance can help the business check the underlying obligations.

Can an Online Course Meet the Training Requirement?

An online course can support the awareness part of a training program. Section 314.4(e) does not require classroom delivery or designate an approved course provider. Whether a particular course helps meet the institution’s obligation depends on its content, the jobs assigned to it, and how the institution connects it to its own risks and procedures. This conclusion follows from the rule’s wording; it is not an FTC endorsement of online courses. 

Before choosing a course, ask: Does it cover customer information and common employee risks? Is it understandable to the staff taking it? Can you track completion and check understanding? What extra training do security staff need? How will employees learn your reporting contact and policies?

US Compliance Institute’s FTC Safeguards Rule Awareness Training is listed as an 80-minute, self-paced beginner course with five modules, knowledge checks, and a certificate of completion. Those features can give staff a common starting point. Your institution must still decide how the course fits its program and what local or specialist training to add. 

Put the Training Into Practice

Start with the people who handle customer information: identify their tasks, give them clear security awareness training, and show them exactly how to report a concern. Then check the needs of your security staff and update lessons when risks change.

If your team needs a shared introduction, FTC Safeguards Rule Awareness Training can help staff learn the basics. Make it part of the security program your business actually uses.

Frequently Asked Questions

01 Is FTC Safeguards Rule Training Required Annually? +

No fixed annual training interval appears in § 314.4(e). Covered institutions must update personnel awareness training as needed to reflect risks identified by the risk assessment. FTC guidance recommends regular refreshers. An annual session can be part of a plan, but it should not replace updates when risks call for them. Read the provision and FTC guidance. 

02 Do Small Covered Businesses Need Training? +

Yes. The exception for an institution maintaining information concerning fewer than 5,000 consumers does not remove the training provision. First confirm that the business is covered; then apply the provisions that remain in force. The exception lists exactly which provisions do not apply. 

03 Does the Qualified Individual Need a Particular Certificate? +

The FTC does not specify a particular degree, title, or certificate for the qualified individual. The person needs suitable know-how for the institution’s circumstances, while key security personnel must take steps to stay current on changing threats and countermeasures. The FTC explains the role in its business guide.

04 Is Online FTC Safeguards Rule Training Allowed? +

The training provision does not prescribe a delivery format. Online lessons may be useful if they fit the relevant risks and roles. Pair them with instruction on your company’s systems, policies, and reporting process. This is an inference from the regulation, not a separate FTC approval of any platform.

05 Does a Completion Certificate Prove Compliance? +

No. It can help show that one person completed one course. The institution must also maintain its applicable written security program and ensure its personnel can carry it out. A certificate cannot stand in for the rest of that work. The FTC describes the wider program here.

Precision Compliance Training Built for Your Business.
We’re constantly expanding our U.S. compliance courses to fit your exact needs. Whether that’s state-specific mandates, niche industry standards, or scalable training for your workforce. Reach out today to build your custom plan.
Request Custom Training
Ready to Write Your Success Story?
Join thousands of students who have already transformed their careers. Start your learning journey today and become our next success story.