Monday to Friday, 8am to 6pm CT832-907-5594
ServicesQualified Individual

Qualified Individual

Your Qualified Individual, supported.

The FTC Safeguards Rule makes your firm name one person to oversee your security program. We do not take that role, and we do not take your accountability. We build the written program behind it, run the controls it depends on, and hand your Qualified Individual the documents and evidence the rule asks them to produce.

This page is written for the Houston offices the FTC Rule reaches: CPA and tax firms, Texas state-registered investment advisers, and the settlement-services side of title work.

The regulation

What the Safeguards Rule requires a Qualified Individual to do

The Qualified Individual oversees, implements, and enforces your information security program (16 CFR 314.4(a)). It is one named person, not a committee, and the designation belongs to your firm.

What that person owns is the list below. Each line is its own requirement in 16 CFR Part 314, with its own subsection.

Risk assessment
A written risk assessment identifying the internal and external risks to the security, confidentiality, and integrity of customer information (16 CFR 314.4(b)(1)).
Access controls
Access controls that limit each person to the data their role needs, on the principle of least privilege (16 CFR 314.4(c)(1)).
Inventory
An inventory of the data, personnel, devices, systems, and facilities that hold or reach customer information (16 CFR 314.4(c)(2)).
Encryption
Encryption of customer information at rest and in transit (16 CFR 314.4(c)(3)).
Secure development
Secure development practices for applications used to transmit, access, or store customer information (16 CFR 314.4(c)(4)).
Multi-factor authentication
Multi-factor authentication for anyone reaching an information system that holds customer information (16 CFR 314.4(c)(5)).
Secure disposal
Secure disposal of customer information once it is no longer needed (16 CFR 314.4(c)(6)).
Change management
Change management procedures, so a change to a system is reviewed rather than improvised (16 CFR 314.4(c)(7)).
Monitoring and logging
Monitoring and logging of authorized user activity, and detection of unauthorized access to customer information (16 CFR 314.4(c)(8)).
Testing
Either continuous monitoring (16 CFR 314.4(d)(1)), or annual penetration testing plus vulnerability assessments at least every six months (16 CFR 314.4(d)(2)). One or the other, not neither.
Training
Security awareness training for personnel (16 CFR 314.4(e)).
Service providers
Selection and oversight of the service providers that touch customer information, with the safeguards written into the contract (16 CFR 314.4(f)).
Program evaluation
Evaluation and adjustment of the program as your systems, staffing, and threats change (16 CFR 314.4(g)).
Incident response plan
A written incident response plan (16 CFR 314.4(h)).
Annual report
An annual written report from the Qualified Individual to the board or equivalent governing body, or to a senior officer if there is none (16 CFR 314.4(i)).
FTC notification
Notice to the FTC within 30 days of discovering a notification event involving 500 or more consumers (16 CFR 314.4(j), effective May 13, 2024 per 16 CFR 314.5).

Civil penalties under the rule are more than $53,000 per violation, adjusted annually (16 CFR 1.98).

The full rule, element by element, is in the Safeguards explorer. For a quick read on where your office stands, take the Safeguards quiz. The written findings version is the FTC Safeguards gap assessment.

Due diligence

The five questions to ask any provider

Ask these five, in this order. Each one maps to a document or a control you can be asked to produce, so a vague answer is the answer.

Do you provide or maintain a Written Information Security Program?

Yes. Tier 2 Comply includes a written security program (WISP) for FTC Safeguards, kept current, and we update it as your systems and vendors change. The written risk assessment behind it is a separate requirement at 16 CFR 314.4(b)(1), and it sits in the same tier. You hold the document.

Will you act as or support the Qualified Individual required by the FTC?

We support your Qualified Individual. We do not act as it, and we do not take on the legal accountability that stays with your firm. The rule requires your firm to designate one person to oversee the program (16 CFR 314.4(a)), and Tier 2 Comply includes virtual CISO advisory and the annual report to ownership, which is the report at 16 CFR 314.4(i). Your firm remains responsible for compliance.

Do you perform documented annual risk assessments?

Yes. Tier 2 Comply includes a written risk assessment (Safeguards or HIPAA), refreshed on a schedule we set with you in writing. The written risk assessment is required at 16 CFR 314.4(b)(1), and the program itself has to be evaluated and adjusted as things change (16 CFR 314.4(g)). We keep the dated versions, so you can show when each one was done and what moved.

Do you supply evidence for cyber insurance and regulatory audits?

Yes. Tier 2 Comply includes cyber-insurance readiness with an evidence pack, and audit support. The pack holds what an underwriter or an examiner asks for: the written program, the risk assessment, security awareness training and phishing-test records, vulnerability scanning with fixes tracked, and access reviews with sign-off you can show an auditor. We supply the evidence. We do not certify you.

Are MFA, endpoint detection, encryption, email security, and backup included in your managed service?

Yes. All five are in Tier 1 Manage, and every tier above it includes them. MFA with least-privilege roles and conditional access covers 16 CFR 314.4(c)(5) and 16 CFR 314.4(c)(1), disk and file encryption is enforced for 16 CFR 314.4(c)(3), and email security (SPF, DKIM, DMARC) with phishing filtering runs on your domain. Endpoint protection (EDR) is always-on tool-based monitoring, and encrypted offsite backup comes with tested recovery.

Every line above is a plan item, not a promise made for this page. Each tier includes unlimited in-scope support. Work outside your plan is quoted separately.

Does this apply to a small firm

Yes. A firm that maintains customer information on fewer than 5,000 consumers is exempt from exactly four provisions and no more: the written risk assessment (16 CFR 314.4(b)(1)), the penetration testing and vulnerability assessment cadence (16 CFR 314.4(d)(2)), the written incident response plan (16 CFR 314.4(h)), and the annual report (16 CFR 314.4(i)). Everything else still applies, including the Qualified Individual (16 CFR 314.4(a)), multi-factor authentication (16 CFR 314.4(c)(5)), encryption (16 CFR 314.4(c)(3)), access controls (16 CFR 314.4(c)(1)), secure disposal (16 CFR 314.4(c)(6)), security awareness training (16 CFR 314.4(e)), service provider oversight (16 CFR 314.4(f)), and the FTC breach notification (16 CFR 314.4(j)). The exemption is at 16 CFR 314.6.

Waived under 5,000 consumers (16 CFR 314.6)Still required at any size
Written risk assessment (16 CFR 314.4(b)(1))Qualified Individual (16 CFR 314.4(a))
Penetration testing and vulnerability assessment cadence (16 CFR 314.4(d)(2))Multi-factor authentication (16 CFR 314.4(c)(5)) and encryption (16 CFR 314.4(c)(3))
Written incident response plan (16 CFR 314.4(h))Access controls (16 CFR 314.4(c)(1)) and secure disposal (16 CFR 314.4(c)(6))
Annual report to the governing body (16 CFR 314.4(i))Training (16 CFR 314.4(e)), service provider oversight (16 CFR 314.4(f)), and FTC breach notification (16 CFR 314.4(j))

Source: 16 CFR 314.6 and 16 CFR 314.4.

Works with the software your firm already runs

Nothing here asks you to change your tax software. We secure the machines, the Microsoft 365 tenant, the network, and the backups those applications depend on. Below is the software commonly run in small firms.

Tax preparation

  • Intuit Lacerte, ProSeries, and ProConnect Tax
  • Drake Tax
  • Thomson Reuters UltraTax CS
  • Wolters Kluwer CCH Axcess Tax and ProSystem fx
  • ATX
  • TaxWise

Books

  • QuickBooks Online
  • QuickBooks Desktop

Portals and workflow

  • TaxDome
  • Canopy
  • SmartVault
  • ShareFile

Product names are listed for compatibility only. Arain Systems is not affiliated with these vendors and makes no claim about their relative merits.

What it costs

The program sits in Tier 2 Comply, from $103 per user per month. That is the tier holding the written security program, the written risk assessment, the evidence pack, the access reviews, and audit support.

Tier 3 Accelerate, from $124 per user per month, adds the AI layer on top: an AI-use policy and governance with staff guardrails, vetted approved AI tools, and flagging when staff paste client data into AI tools. The technical controls the rule names live a tier below, in Tier 1 Manage, and carry upward.

Each tier includes unlimited in-scope support. Work outside your plan is quoted separately. The full ladder and the per-user calculator are on the plans page.

If your firm is regulated somewhere else

The Qualified Individual is a creature of the FTC Rule, so not every financial office has one. Here is who answers to whom.

Insurance agencies
In Texas the Department of Insurance regulates the business of insurance under the GLBA enforcement allocation at 15 U.S.C. 6805(a)(6), and the GLBA safeguarding duty applies. There is no federal Qualified Individual role for the business of insurance. See the insurance agency page.
SEC-registered advisers
An adviser registered with the SEC follows SEC Regulation S-P, 17 CFR 248.30, amended in 2024 and in force for all registrants as of June 2026. A Texas state-registered adviser, below the SEC threshold and registered with the Texas State Securities Board, falls under FTC Part 314 instead. See the adviser page.
Title and settlement
Settlement and closing services fall under FTC Part 314, since real estate settlement services is a listed covered activity. Title insurance agency activity answers to the state insurance regulator, TDI in Texas, under the same GLBA allocation. Most Texas title offices do both, so the written program is still the job. See the title and settlement page.
Medical practices
A physician practice answers to HHS OCR under the HIPAA Security Rule, not the FTC. The equivalent role is the designated security official at 45 CFR 164.308(a)(2), and the risk analysis at 45 CFR 164.308(a)(1)(ii)(A). See the HIPAA security official page and the healthcare practice page.

Service area

Arain Systems serves the Houston metro, including Houston, Katy, Sugar Land, Pearland, Cypress, The Woodlands, Spring, Bellaire, Richmond, Missouri City. Support is remote across the metro, on-site when the office calls for it.

Local pages cover Houston, Katy, and Sugar Land. The full list is on the service areas page.

Scope note

Arain Systems provides a gap assessment and a remediation plan. This is not a certification or a guarantee of compliance. Content here is educational, not legal advice.

Start with the free gap report

We check your office against the Safeguards elements above, then send written findings and a prioritized fix list your Qualified Individual can work from.

Get a free gap report

Written by Hammad Arain, founder of Arain Systems. CCNA, CompTIA Security+, Microsoft AZ-104. Updated June 2026. Educational, not legal advice.