The FTC Safeguards Rule (16 CFR Part 314) requires a written information-security program with specific, named elements — and the FTC enforces it. Score your firm against the nine required components.
"Financial institution" is defined broadly — it's not just banks. It includes accountants and tax-preparation firms, financial advisors and RIAs, mortgage brokers and lenders, auto dealers, wire transferors, collection agencies, and payday/installment lenders, among others. If your firm handles customers' financial information, assume it applies until an attorney tells you otherwise.
The written spine of the program — the parts the FTC and your insurer ask to see first.
The eight controls the rule requires you to design and implement §314.4(c).
Prove the controls actually work §314.4(d).
Your staff and your vendors are in scope too §314.4(e),(f).
"We're not a bank, so this doesn't apply." The definition is broad — most accounting, tax, advisory, lending, and dealer businesses are covered. And "our IT company handles security." The rule requires a named Qualified Individual, a written risk assessment, and an annual written report to leadership — governance documents an IT vendor doesn't produce. The FTC (and your cyber-insurer) ask for those first.
I build FTC Safeguards programs for small financial, accounting, and advisory firms — the written risk assessment, the safeguards, the incident response plan, and the governance documents — and I can serve as your Qualified Individual on retainer. Enterprise-grade rigor, small-firm price.
Book a free 15-minute call: [email protected] · trentcyber.com
Reflects the FTC Safeguards Rule, 16 CFR Part 314 §314.4. Firms maintaining information on fewer than 5,000 consumers are exempt from some elements (written risk assessment, penetration testing, incident response plan, annual report) — confirm your status with counsel. Not legal advice; verify current requirements before relying.
This checklist is an educational self-assessment provided by Trent Cyber Advisory, a technical security and compliance advisory practice. It is not legal advice; whether the Rule applies and how it applies to your firm are determinations for the firm and its counsel. © 2026 Trent Cyber Advisory.