The rule requires a written information security program and, unless exempt, specific written risk-assessment, testing, incident-response, and reporting records. Citation: 16 CFR 314.4 and 314.6.
Primary source: FTC Safeguards Rule business guidance
What documents does the Safeguards Rule actually require for a non-federally insured credit union?
Details
Policywright splits the operating record into a WISP, incident response plan, acceptable use policy, and access control policy. For a non-federally insured credit union, those documents should map to Member data lives in core processing, online banking, loan files, card systems, ACH and wire systems, shared-branching tools, call-center notes, and vendor portals. The WISP should map third-party core and online banking providers with contract oversight.
Primary source: FTC Safeguards Rule business guidance.
FAQ
What documents does the Safeguards Rule actually require for a non-federally insured credit union?
The rule requires a written information security program and, unless exempt, specific written risk-assessment, testing, incident-response, and reporting records. Citation: 16 CFR 314.4 and 314.6.
What is the data-flow issue for a non-federally insured credit union?
Member data lives in core processing, online banking, loan files, card systems, ACH and wire systems, shared-branching tools, call-center notes, and vendor portals. The WISP should map third-party core and online banking providers with contract oversight.
Is this legal advice?
No. It is source-cited educational content for a template product, not legal advice.