Yes, if the firm is covered by the FTC Safeguards Rule as non-federally insured credit union, it needs a written security program for customer information. Citation: 16 CFR Part 314 and FTC Safeguards Rule business guidance.

Primary source: FTC Safeguards Rule business guidance

Does a non-federally insured credit union need a WISP?

Details

operates as a credit union that is not federally insured and maintains member financial information. Member data lives in core processing, online banking, loan files, card systems, ACH and wire systems, shared-branching tools, call-center notes, and vendor portals. The WISP should map third-party core and online banking providers with contract oversight. Many credit unions exceed 5,000 consumers through member and former-member records. A very small institution should still document the count because 16 CFR 314.6 is limited.

Primary source: FTC Safeguards Rule business guidance.

FAQ

Does a non-federally insured credit union need a WISP?

Yes, if the firm is covered by the FTC Safeguards Rule as non-federally insured credit union, it needs a written security program for customer information. Citation: 16 CFR Part 314 and FTC Safeguards Rule business guidance.

What is the data-flow issue for a non-federally insured credit union?

Member data lives in core processing, online banking, loan files, card systems, ACH and wire systems, shared-branching tools, call-center notes, and vendor portals. The WISP should map third-party core and online banking providers with contract oversight.

Is this legal advice?

No. It is source-cited educational content for a template product, not legal advice.

Policywright is a configurable template product, not a law firm and not legal advice. State breach deadlines and legal reliance should be reviewed with qualified counsel before launch or use.