Pillar guide

FTC Safeguards Rule explained for small firms

The FTC Safeguards Rule (16 CFR Part 314), issued under the Gramm-Leach-Bliley Act, requires financial institutions — a category that expressly includes tax preparers — to build and maintain a written program that protects customer information. The rule is not vague about what that means: it lists nine elements, sets a breach-notification deadline, and defines who gets a lighter version. This page walks through each in plain English, with the citation for every claim.

Key facts

  • Coverage is based on what you do, not what you call yourself — handling client financial data brings you in (16 CFR 314.1, 314.2).
  • The program is built on nine elements in 16 CFR 314.4, from a designated security lead to vendor oversight and incident response.
  • Breach notification is firm-size-blind: 16 CFR 314.4(j) requires FTC notice within 30 days of an event affecting 500+ consumers.

Key takeaways

  • Coverage is based on what you do, not what you call yourself — handling client financial data brings you in (16 CFR 314.1, 314.2).
  • The program is built on nine elements in 16 CFR 314.4, from a designated security lead to vendor oversight and incident response.
  • Breach notification is firm-size-blind: 16 CFR 314.4(j) requires FTC notice within 30 days of an event affecting 500+ consumers.
  • The under-5,000-consumer exemption (16 CFR 314.6) lightens four written obligations — it does not remove the program.

Who has to follow the Safeguards Rule?

The rule applies to covered financial institutions that handle customer information. IRS guidance treats paid tax preparers as subject to written data-security plan expectations.

Coverage is functional, not just based on whether the firm calls itself a bank. If the firm handles financial products or services for consumers, it should evaluate coverage carefully.

For tax practices, bookkeeping firms, enrolled agents, and small accounting offices, the safer operating assumption is that a written data-security program is required.

What are the nine Safeguards Rule elements?

16 CFR 314.4 requires nine things: (a) designate a Qualified Individual; (b) base the program on a written risk assessment; (c) implement safeguards including access controls and MFA (c)(1),(c)(5), a data inventory (c)(2), encryption (c)(3), secure app vetting (c)(4), secure disposal (c)(6), change management (c)(7), and logging/monitoring (c)(8); (d) regularly test or monitor those safeguards; (e) train staff; (f) oversee service providers by contract; (g) evaluate and adjust the program; and (h) maintain a written incident response plan.

The rule is not satisfied by a document alone. The WISP should describe how the firm actually configures access, protects systems, disposes of information, trains personnel, and reviews vendors — each tied to the subsection it comes from.

A good plan also documents unfinished work. Remediation language (with an owner and target date) is more credible than an unsupported claim that every control is already perfect.

What are the breach-notification and small-firm rules?

Since May 13, 2024, 16 CFR 314.4(j) requires a covered firm to notify the FTC as soon as possible, and no later than 30 days after discovering a security event involving the unencrypted information of 500 or more consumers. Separately, 16 CFR 314.6 exempts firms that maintain information on fewer than 5,000 consumers from four written obligations — the prescribed written risk-assessment contents (314.4(b)(1)), the penetration-testing/vulnerability cadence (314.4(d)(2)), the written incident response plan (314.4(h)), and the annual written report to a governing body (314.4(i)).

The breach-notification duty applies at every firm size; the fewer-than-5,000 exemption does not reach it.

The exemption lightens paperwork, not the underlying duty: an exempt firm is still a covered financial institution that must maintain a written security program and reasonable safeguards.

How does Policywright map the rule to documents?

Policywright maps the Safeguards Rule into four maintainable documents: the WISP, Incident Response Plan, Acceptable Use Policy, and Access Control Policy.

Splitting operational rules into companion policies makes the packet easier to use. Staff can read acceptable-use rules, managers can review access controls, and owners can maintain the WISP as the top-level program.

Each packet includes primary-source citations and proof-of-implementation prompts so the firm can collect evidence over time.

The nine-element Safeguards Rule checklist
RequirementWhat a small firm should documentPrimary reference
Designate a Qualified IndividualOne accountable person for the security program and its annual review16 CFR 314.4(a)
Written risk assessmentSystems, client data, threats, safeguards, and residual gaps (written contents required at 5,000+ consumers)16 CFR 314.4(b), (b)(1)
Access controls & MFALeast-privilege access and multi-factor authentication on systems holding customer information16 CFR 314.4(c)(1), (c)(5)
Data inventoryInventory of the customer information held and where it lives16 CFR 314.4(c)(2)
EncryptionEncryption in transit and at rest, or approved compensating controls16 CFR 314.4(c)(3)
Secure disposalDispose of customer information no longer needed (generally within two years)16 CFR 314.4(c)(6)
Change management & loggingManage system changes and log/monitor access to customer information16 CFR 314.4(c)(7), (c)(8)
Testing & monitoringContinuous monitoring, or annual penetration test + semiannual vulnerability assessment at 5,000+ consumers16 CFR 314.4(d)
Security-awareness trainingRecurring staff training and qualified security personnel16 CFR 314.4(e)
Service-provider oversightSelect, contract with, and periodically assess vendors handling customer information16 CFR 314.4(f)
Evaluate & adjustUpdate the program as risks, systems, and operations change16 CFR 314.4(g)
Written incident response planWritten escalation, containment, notice, and recovery steps16 CFR 314.4(h)
FTC breach notificationNotify the FTC within 30 days of a breach of unencrypted information of 500+ consumers (since May 13, 2024)16 CFR 314.4(j)

FAQ

Is this legal advice?

No. Policywright is a configurable template product, not a law firm and not legal advice. A qualified lawyer should review state-law reliance or breach-notification decisions.

Does a small firm still need a written plan?

Yes. The Safeguards Rule requires a written information security program for covered financial institutions, and IRS guidance tells paid tax preparers to maintain a written data security plan.

What if a control is not in place yet?

A serious WISP should not pretend. It should identify the gap, assign an owner, set a target date, and preserve a dated remediation record.

Does the small-business exemption remove the WISP requirement?

No. It reduces specific obligations for firms below the consumer-information threshold, but covered firms still need a written security program.

Is cyber insurance the same thing as compliance?

No. Insurance applications often ask about the same controls, but insurance is not a substitute for maintaining a written program.

Sources

Turn the rule into a working policy packet.

Policywright converts your answers into source-cited documents and checklists.

See pricing
Policywright is a configurable template product, not a law firm and not legal advice. State breach deadlines and legal reliance should be reviewed with qualified counsel before launch or use.