Qualified Individual
The FTC Safeguards Rule makes your firm name one person to oversee your security program. We do not take that role, and we do not take your accountability. We build the written program behind it, run the controls it depends on, and hand your Qualified Individual the documents and evidence the rule asks them to produce.
This page is written for the Houston offices the FTC Rule reaches: CPA and tax firms, Texas state-registered investment advisers, and the settlement-services side of title work.
The regulation
The Qualified Individual oversees, implements, and enforces your information security program (16 CFR 314.4(a)). It is one named person, not a committee, and the designation belongs to your firm.
What that person owns is the list below. Each line is its own requirement in 16 CFR Part 314, with its own subsection.
Civil penalties under the rule are more than $53,000 per violation, adjusted annually (16 CFR 1.98).
The full rule, element by element, is in the Safeguards explorer. For a quick read on where your office stands, take the Safeguards quiz. The written findings version is the FTC Safeguards gap assessment.
Due diligence
Ask these five, in this order. Each one maps to a document or a control you can be asked to produce, so a vague answer is the answer.
Yes. Tier 2 Comply includes a written security program (WISP) for FTC Safeguards, kept current, and we update it as your systems and vendors change. The written risk assessment behind it is a separate requirement at 16 CFR 314.4(b)(1), and it sits in the same tier. You hold the document.
We support your Qualified Individual. We do not act as it, and we do not take on the legal accountability that stays with your firm. The rule requires your firm to designate one person to oversee the program (16 CFR 314.4(a)), and Tier 2 Comply includes virtual CISO advisory and the annual report to ownership, which is the report at 16 CFR 314.4(i). Your firm remains responsible for compliance.
Yes. Tier 2 Comply includes a written risk assessment (Safeguards or HIPAA), refreshed on a schedule we set with you in writing. The written risk assessment is required at 16 CFR 314.4(b)(1), and the program itself has to be evaluated and adjusted as things change (16 CFR 314.4(g)). We keep the dated versions, so you can show when each one was done and what moved.
Yes. Tier 2 Comply includes cyber-insurance readiness with an evidence pack, and audit support. The pack holds what an underwriter or an examiner asks for: the written program, the risk assessment, security awareness training and phishing-test records, vulnerability scanning with fixes tracked, and access reviews with sign-off you can show an auditor. We supply the evidence. We do not certify you.
Yes. All five are in Tier 1 Manage, and every tier above it includes them. MFA with least-privilege roles and conditional access covers 16 CFR 314.4(c)(5) and 16 CFR 314.4(c)(1), disk and file encryption is enforced for 16 CFR 314.4(c)(3), and email security (SPF, DKIM, DMARC) with phishing filtering runs on your domain. Endpoint protection (EDR) is always-on tool-based monitoring, and encrypted offsite backup comes with tested recovery.
Every line above is a plan item, not a promise made for this page. Each tier includes unlimited in-scope support. Work outside your plan is quoted separately.
Yes. A firm that maintains customer information on fewer than 5,000 consumers is exempt from exactly four provisions and no more: the written risk assessment (16 CFR 314.4(b)(1)), the penetration testing and vulnerability assessment cadence (16 CFR 314.4(d)(2)), the written incident response plan (16 CFR 314.4(h)), and the annual report (16 CFR 314.4(i)). Everything else still applies, including the Qualified Individual (16 CFR 314.4(a)), multi-factor authentication (16 CFR 314.4(c)(5)), encryption (16 CFR 314.4(c)(3)), access controls (16 CFR 314.4(c)(1)), secure disposal (16 CFR 314.4(c)(6)), security awareness training (16 CFR 314.4(e)), service provider oversight (16 CFR 314.4(f)), and the FTC breach notification (16 CFR 314.4(j)). The exemption is at 16 CFR 314.6.
| Waived under 5,000 consumers (16 CFR 314.6) | Still required at any size |
|---|---|
| Written risk assessment (16 CFR 314.4(b)(1)) | Qualified Individual (16 CFR 314.4(a)) |
| Penetration testing and vulnerability assessment cadence (16 CFR 314.4(d)(2)) | Multi-factor authentication (16 CFR 314.4(c)(5)) and encryption (16 CFR 314.4(c)(3)) |
| Written incident response plan (16 CFR 314.4(h)) | Access controls (16 CFR 314.4(c)(1)) and secure disposal (16 CFR 314.4(c)(6)) |
| Annual report to the governing body (16 CFR 314.4(i)) | Training (16 CFR 314.4(e)), service provider oversight (16 CFR 314.4(f)), and FTC breach notification (16 CFR 314.4(j)) |
Source: 16 CFR 314.6 and 16 CFR 314.4.
Nothing here asks you to change your tax software. We secure the machines, the Microsoft 365 tenant, the network, and the backups those applications depend on. Below is the software commonly run in small firms.
Product names are listed for compatibility only. Arain Systems is not affiliated with these vendors and makes no claim about their relative merits.
The program sits in Tier 2 Comply, from $103 per user per month. That is the tier holding the written security program, the written risk assessment, the evidence pack, the access reviews, and audit support.
Tier 3 Accelerate, from $124 per user per month, adds the AI layer on top: an AI-use policy and governance with staff guardrails, vetted approved AI tools, and flagging when staff paste client data into AI tools. The technical controls the rule names live a tier below, in Tier 1 Manage, and carry upward.
Each tier includes unlimited in-scope support. Work outside your plan is quoted separately. The full ladder and the per-user calculator are on the plans page.
The Qualified Individual is a creature of the FTC Rule, so not every financial office has one. Here is who answers to whom.
Arain Systems serves the Houston metro, including Houston, Katy, Sugar Land, Pearland, Cypress, The Woodlands, Spring, Bellaire, Richmond, Missouri City. Support is remote across the metro, on-site when the office calls for it.
Local pages cover Houston, Katy, and Sugar Land. The full list is on the service areas page.
Arain Systems provides a gap assessment and a remediation plan. This is not a certification or a guarantee of compliance. Content here is educational, not legal advice.
We check your office against the Safeguards elements above, then send written findings and a prioritized fix list your Qualified Individual can work from.
Get a free gap reportWritten by Hammad Arain, founder of Arain Systems. CCNA, CompTIA Security+, Microsoft AZ-104. Updated June 2026. Educational, not legal advice.