Free gap report
You are a covered financial institution under the FTC Safeguards Rule, and the FTC does not grade on size. If an incident happened today, could you produce the written program the Rule requires?
The regulation
The FTC Safeguards Rule (16 CFR Part 314), enacted under the Gramm-Leach-Bliley Act, requires financial institutions to develop, implement, and maintain a written information security program. The rule applies to tax preparers, CPA firms, insurance agencies, investment advisors, mortgage companies, and real estate settlement services companies, among others.
The written program must include a documented risk assessment, a Qualified Individual to oversee the program, specific technical and administrative safeguards, workforce training, service provider oversight, and an annual report to the governing body. The 2021 update to the rule significantly expanded these requirements and became effective in December 2022. What that named role has to do, subsection by subsection, is set out on the Qualified Individual page.
Without a documented risk assessment, you have no compliance baseline and no record of due diligence if an incident occurs. A written assessment is also a requirement of the rule itself, not just good practice.
Who it binds
| Office type | GLBA written security program | IRS WISP | Texas breach notification law | Enforced or audited by |
|---|---|---|---|---|
| CPA and tax firms | Applies | Applies | Applies | FTC · IRS PTIN attestation |
| Insurance agencies | Applies | Does not apply | Applies | State insurance regulator · carrier questionnaires |
| Title and settlement | Applies | Does not apply | Applies | FTC · ALTA Pillar 3 underwriter audits |
| Investment advisers | Applies | Does not apply | Applies | SEC Reg S-P or FTC, by registration · TSSB exams |
Enforced or audited by: FTC · IRS PTIN attestation
Enforced or audited by: State insurance regulator · carrier questionnaires
Enforced or audited by: FTC · ALTA Pillar 3 underwriter audits
Enforced or audited by: SEC Reg S-P or FTC, by registration · TSSB exams
The exposure
These are the real consequences the rule and your insurance create.
The free 14-Point Safeguards Gap Report shows exactly where you stand on each of these.
The FTC Safeguards Rule sets the requirements; these 14 points are how we check your office against them, plus the email, wire-fraud, and backup gaps that decide whether you survive an incident. The full rule, element by element, is in the Safeguards explorer.
Get the 14-point Safeguards checklist
A one-page PDF of the 14 points we review, mapped to the FTC Safeguards Rule.
The initial 14-Point Safeguards Gap Report is free, with written findings delivered to your inbox.
Get a free gap reportWritten by Hammad Arain, founder of Arain Systems. CCNA, CompTIA Security+, Microsoft AZ-104. Updated June 2026. Educational, not legal advice.
Non-bank financial offices that meet the Gramm-Leach-Bliley definition of a financial institution, which is broader than most owners expect.
On-site across the Houston metro. See the cities we cover.