- GLBA Safeguards Rule: What It Requires and How to Comply
- What Is the GLBA Safeguards Rule?
- Safeguards Rule Requirements: The 9 Elements
- GLBA Safeguards Rule Updates
- How to Simplify GLBA Safeguards Rule Compliance
- Key Takeaways
-
GLBA Safeguards Rule FAQs
- What Is the GLBA Safeguards Rule?
- Who Does the GLBA Safeguards Rule Apply To?
- What Are the 9 Elements of the Safeguards Rule?
- What Changed in the 2023 Safeguards Rule Update?
- Does the Safeguards Rule Require Encryption?
- Is There a Small Business Exemption for the Safeguards Rule?
- What Happens If an Institution Violates the Safeguards Rule?
GLBA Safeguards Rule: What It Requires and How to Comply
The GLBA Safeguards Rule is the most operationally demanding component of the Gramm-Leach-Bliley Act. The Federal Trade Commission’s (FTC) 2021 update, effective June 9, 2023, significantly expanded what it requires.
Organizations classified as “financial institutions” under GLBA include banks, mortgage brokers, auto dealers, and universities that process student financial aid. The GLBA Safeguards Rule requires covered financial institutions to develop, implement, and maintain a comprehensive information security program with 9 specific elements.
This guide covers what the Safeguards Rule is, the required elements of an information security program, updates and what they changed, and how to implement each requirement. For a step-by-step compliance process across all three rules, see the GLBA compliance guide.
Free download: Map every Safeguards Rule requirement (§314.3–314.4) to NIST 800-53, NIST 800-171, NIST CSF 2.0, CIS Controls v8, and the Secure Controls Framework with the GLBA Safeguards Rule Requirements Crosswalk.
What Is the GLBA Safeguards Rule?
The GLBA Safeguards Rule — formally titled the Standards for Safeguarding Customer Information and codified at 16 CFR Part 314 — is a Federal Trade Commission (FTC) regulation that requires non-bank financial institutions to implement and maintain a comprehensive written Information Security Program (ISP) to protect the confidentiality and security of customer information.
The GLBA Safeguards Rule (16 CFR Part 314) is a Federal Trade Commission regulation requiring financial institutions to develop, implement, and maintain a comprehensive information security program. Updated in 2021 and effective June 2023, the rule specifies 9 required elements including risk assessments, encryption, multi-factor authentication, and incident response planning.
Issued in 2003 as a flexible, principles-based standard, the original rule gave organizations broad latitude in designing their security programs. But that changed dramatically with the FTC’s December 2021 amendments.
The updated Safeguards Rule took effect on June 9, 2023. It specifies nine required elements that every ISP must contain, including prescriptive requirements for encryption, multi-factor authentication (MFA), penetration testing, and incident response planning.
The requirements apply to all “financial institutions” under FTC jurisdiction. That includes:
- Mortgage brokers
- Auto dealers
- Payday lenders
- Tax preparation firms
- Collection agencies
- Colleges and universities that process Title IV student financial aid
Traditional banks and credit unions are subject to parallel requirements from their respective federal banking regulators (OCC, FDIC, Federal Reserve, NCUA) rather than the FTC.
Colleges and universities answer to a second regulator on top of the FTC. Any institution that participates in Title IV federal student aid agrees in its Program Participation Agreement to follow the Safeguards Rule, so the Department of Education and its office of Federal Student Aid enforce the same 16 CFR Part 314 requirements as a condition of keeping Title IV eligibility, as Federal Student Aid guidance explains.
Safeguards Rule Requirements: The 9 Elements
The GLBA Safeguards Rule requires financial institutions to implement nine specific elements within their information security program, each designed to address a core aspect of customer data protection.
| Element | Regulatory Reference | Key Requirement |
|---|---|---|
| Qualified Individual | 16 CFR 314.4(a) | Appoint one person to oversee ISP |
| Risk Assessment | 16 CFR 314.4(b) | Written assessment of foreseeable threats |
| Implement Safeguards | 16 CFR 314.4(c) | Access controls, encryption, MFA, secure disposal |
| Monitor and Test | 16 CFR 314.4(d) | Annual pen test, semi-annual vuln assessment |
| Train Staff | 16 CFR 314.4(e) | Security awareness for all personnel |
| Service Providers | 16 CFR 314.4(f) | Contractual safeguards, ongoing monitoring |
| Keep ISP Current | 16 CFR 314.4(g) | Update based on testing, threats, operations |
| Incident Response | 16 CFR 314.4(h) | Written plan with notification procedures |
| Board Reporting | 16 CFR 314.4(i) | Annual report from qualified individual |
To see how each element maps to established control frameworks, use the GLBA Safeguards Rule Requirements Crosswalk, which aligns §314.3–314.4 with NIST 800-53, NIST 800-171, NIST CSF 2.0, CIS Controls v8, and the SCF.
1. Designate a Qualified Individual
Every financial institution must appoint one person to oversee and implement the information security program. This “qualified individual” can be an internal employee (such as a CISO or IT director) or an outsourced service provider. They do not need a specific certification, but they must have sufficient knowledge and experience to manage the program effectively.
2. Conduct a Risk Assessment
The ISP must be built on a written risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information. The assessment must evaluate the sufficiency of existing safeguards to control those risks. Results must be documented and must drive the design and implementation of the entire security program.
Risk assessments must be periodically updated as the organization’s operations, threats, or business environment change. For a step-by-step process, see the GLBA risk assessment guide.
3. Implement Safeguards
Based on risk assessment findings, the institution must deploy safeguards to control identified risks. The updated rule specifies several required controls:
- Access controls: Restrict access to customer information based on business need and least-privilege principles
- Data inventory: Identify and classify all systems and data stores containing customer information
- Encryption: Encrypt customer information both in transit over external networks and at rest
- Secure development practices: Evaluate and implement secure coding practices for in-house applications
- Multi-factor authentication (MFA): Require MFA for any individual accessing customer information systems
- Secure data disposal: Implement procedures for the secure disposal of customer information no later than two years after last use
For a detailed breakdown of each technical requirement, see our GLBA cybersecurity requirements guide.
4. Monitor and Test
Effectiveness of safeguards must be regularly verified through testing. The updated rule requires:
- Annual penetration testing: Simulate real-world attacks against systems containing customer information
- Semi-annual vulnerability assessments: Identify and evaluate security weaknesses in systems and networks
- Continuous monitoring alternative: Organizations may implement continuous monitoring procedures in place of annual penetration testing and semi-annual vulnerability assessments
5. Train Staff
All personnel with access to customer information must receive security awareness training. Training must address recognition and prevention of social engineering attacks, cover the organization’s specific ISP policies and procedures, be updated to reflect emerging threats, and include specialized training for the qualified individual responsible for the ISP.
6. Manage Service Providers
Financial institutions must take reasonable steps to select and retain service providers capable of maintaining appropriate safeguards. Requirements include contractually requiring service providers to implement safeguards, periodically assessing providers based on the risk they present, and monitoring compliance on an ongoing basis.
7. Keep the ISP Current
The information security program must be a living document. Institutions must evaluate and adjust the ISP based on results of testing and monitoring activities, changes to operations or business arrangements, new or emerging threats, and any circumstances the qualified individual identifies as having a material impact.
8. Create an Incident Response Plan
The updated rule requires a written incident response plan that specifies how the institution will respond to security events affecting customer information. The plan must address roles and responsibilities, internal and external communication procedures, remediation steps, documentation requirements, and post-incident analysis.
The October 2023 breach notification amendment added a specific requirement, effective May 13, 2024: institutions must notify the FTC within 30 days of discovering a breach affecting 500 or more consumers. For complete breach notification timelines, see the GLBA data breach notification requirements guide.
9. Report to the Board
The qualified individual must report to the board of directors, governing body, or equivalent senior authority at least annually. The report must cover the overall status of the ISP, compliance with the Safeguards Rule, material matters related to the program, and recommendations for changes.
GLBA Safeguards Rule Updates
The FTC’s December 2021 amendments to the Safeguards Rule, which took effect on June 9, 2023, transformed GLBA’s security requirements from a flexible, principles-based standard into the prescriptive cybersecurity mandate it is today.
Before the update (2003-2023): The original Safeguards Rule required a written ISP but gave organizations broad discretion in designing their programs. There were no specific technology requirements.
After the update (effective June 2023): The amended rule specifies exactly what an ISP must include.
| Requirement | Before (2003) | After (2023) |
|---|---|---|
| Qualified individual | Not required | Required; must report to board annually |
| Risk assessment | Required (flexible format) | Required; must be written, must drive ISP design |
| Encryption | Not specified | Required; in transit and at rest |
| Multi-factor authentication | Not specified | Required; for all access to customer information |
| Penetration testing | Not specified | Required; annual |
| Vulnerability assessments | Not specified | Required; semi-annual |
| Incident response plan | Not specified | Required; written plan with notification procedures |
| Board reporting | Not specified | Required; at least annually |
Small business exception: Organizations that maintain customer information for fewer than 5,000 consumers are exempt from several prescriptive requirements, including the written risk assessment, incident response plan, and annual board reporting requirements. However, these organizations must still maintain an ISP with appropriate safeguards.
How to Simplify GLBA Safeguards Rule Compliance
Implementing the 9 elements across a distributed organization takes coordination between IT, compliance, and business units. Isora GRC is the GRC Assessment Platform™ that gives security teams one shared workspace to run assessments, track live risks, and publish audit-ready reports.
- **Assessment Management:** Organize Safeguards Rule assessments by compliance goal to manage complex campaigns across departments, campuses, and business units, with live completion tracking in one dashboard.
- **Questionnaires & Surveys:** Distribute prebuilt GLBA questionnaires so department heads and unit owners can add responses, upload evidence, and flag gaps, reducing the time teams spend collecting and reviewing assessment data.
- **Reports & Scorecards:** Generate compliance scorecards for the qualified individual’s annual board report and track control status across all 9 elements, freeing the team for more strategic work.
Unlike enterprise GRC suites, Isora focuses on information security risk and compliance, so assessments, inventories, risk registers, and reporting fit how security practitioners actually work.
See how Isora GRC simplifies GLBA Safeguards Rule compliance →
Key Takeaways
The GLBA Safeguards Rule requires every covered financial institution to build and maintain a written information security program across nine elements, from designating a qualified individual to encrypting customer data, requiring multi-factor authentication, and testing controls on a set schedule.
- The FTC’s 2021 amendments, effective June 9, 2023, turned what was once a flexible standard into a prescriptive mandate.
- The October 2023 breach-notification amendment went further, adding a 30-day reporting deadline for incidents affecting 500 or more consumers.
Compliance depends on documented risk assessments, ongoing monitoring and testing, and clear accountability that runs from the qualified individual up to the board. Even though institutions that maintain information on fewer than 5,000 consumers get relief from a few provisions, every covered institution still needs a working program that holds up to FTC review.
For a complete overview of the Gramm-Leach-Bliley Act and its three rules, see our What Is GLBA complete guide.
See the GRC Assessment Platform™ in action →
GLBA Safeguards Rule FAQs
What Is the GLBA Safeguards Rule?
The GLBA Safeguards Rule (16 CFR Part 314) is a Federal Trade Commission regulation that requires financial institutions to develop, implement, and maintain a comprehensive information security program to protect customer information. Updated in 2021 and effective June 2023, it specifies 9 required elements including risk assessments, encryption, MFA, and incident response planning.
Who Does the GLBA Safeguards Rule Apply To?
The Safeguards Rule applies to all “financial institutions” under FTC jurisdiction — including non-bank entities such as mortgage brokers, auto dealers, payday lenders, tax preparers, and colleges and universities that process student financial aid.
What Are the 9 Elements of the Safeguards Rule?
The 9 elements are: (1) designate a qualified individual, (2) conduct risk assessments, (3) implement safeguards, (4) monitor and test safeguards, (5) train staff, (6) manage service providers, (7) keep the ISP current, (8) create an incident response plan, and (9) report to the board of directors.
What Changed in the 2023 Safeguards Rule Update?
The FTC’s 2021 amendments (effective June 2023) added specific prescriptive requirements to the previously flexible, principles-based rule. Key changes include mandatory encryption for data in transit and at rest, multi-factor authentication, annual penetration testing, semi-annual vulnerability assessments, written incident response plans, and annual board reporting.
Does the Safeguards Rule Require Encryption?
Yes. The updated Safeguards Rule requires financial institutions to encrypt all customer information both in transit over external networks and at rest.
Is There a Small Business Exemption for the Safeguards Rule?
Yes. Organizations maintaining customer information for fewer than 5,000 consumers are exempt from several prescriptive requirements: the written risk assessment, incident response plan, and annual board reporting. However, they must still maintain an information security program with appropriate safeguards.
What Happens If an Institution Violates the Safeguards Rule?
Safeguards Rule violations can lead to FTC enforcement actions such as consent orders, injunctions, and mandatory compliance programs. The rule carries no civil penalty of its own, so the FTC pursues monetary penalties under the FTC Act, which reach up to $53,088 per violation as of January 17, 2025 and rise with annual inflation adjustments. The FTC can also name the individual officers and directors responsible for a program in its orders.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.