All resources
FTC SafeguardsGLBAChecklist

FTC Safeguards Rule checklist: the nine required elements

Official source: FTC Safeguards Rule (GLBA)

FTC Safeguards Rule's nine required elements mapped to the evidence examiners expect, with each control flagged auto vs. manual.

What FTC Safeguards requires

FTC Safeguards is assessed against 9 requirements across five areas: Program governance, Risk assessment, Technical safeguards, Monitoring & testing, Oversight. Each must be both designed and operating — auditors want evidence it worked throughout the period, not just that it existed on paper.

The control checklist

All nine required elements of the amended FTC Safeguards Rule. Use the table below as your working checklist — 9 line items. Controls marked Auto can be monitored continuously by SBCMSP; Manual controls need a documented process and human evidence.

ControlRequirementCoverage
§314.4 — the nine elements
(a)Designate a qualified individualManual
(b)Written risk assessmentManual
(c)Safeguards: access controls, inventory, encryption, MFA, disposal, change mgmt, monitoringAuto
(d)Regular testing: continuous monitoring or annual pen test + biannual vuln scansAuto
(e)Security awareness trainingManual
(f)Oversee service providersManual
(g)Evaluate & adjust the programManual
(h)Written incident response planManual
(i)Annual report to the boardManual

Evidence you must collect

For every control, an auditor expects evidence it operated throughout the review period. Common examples:

  • Access reviews with timestamps and approver
  • Change tickets linked to deployments
  • Encryption and configuration snapshots
  • Vendor / supplier risk assessments on file

Automating the checklist

Roughly two-thirds of FTC Safeguards controls can be monitored automatically. SBCMSP watches those continuously, collects timestamped evidence, and flags drift — so the audit becomes a review of a report you already have, not a month-long scramble.

Frequently asked questions

Who must comply with the FTC Safeguards Rule?
Non-banking financial institutions covered by the Gramm-Leach-Bliley Act — auto dealers, mortgage brokers, tax preparers, many fintechs — that handle customer financial information.

What are the required elements?
A written information security program with nine elements: a qualified individual, risk assessment, safeguards, monitoring and testing, staff training, service-provider oversight, program adjustment, an incident response plan, and periodic reporting to the board.

When did the updated Rule take effect?
Key provisions became enforceable on 9 June 2023, adding specific technical requirements such as encryption, MFA, and access controls.

Which controls can be automated?
Technical safeguards — encryption, MFA, access control, logging, and continuous monitoring — can be evidenced automatically. Governance, training, and service-provider oversight still need documented processes.

Turn this checklist into a live dashboard

SBCMSP tracks every FTC Safeguards control continuously across all your clients.