Does your organization collect or use consumers’ financial information to provide or arrange financial products or services? If you answered yes, or if you are not sure, there are governance expectations that may already apply to you. Most organizations inside the definition have never been told they are in it.
You can probably answer those three questions right now. What is harder is proving your answers with evidence a regulator, an insurer, an investor, or your own board would accept. That difference is the whole subject of this site, and we teach it before we ask you for anything.
You cannot have a gap under a rule that does not apply to you. So the honest first step is not measuring your governance. It is finding out whether the Rule reaches your organization at all. For a large share of organizations the answer is yes, and no one has told them.
Does your organization collect, receive, store, transmit, or use consumers’ financial information in connection with providing or arranging financial products or services?
Notice what that question does not ask. It does not ask whether you are a bank. It does not ask whether you lend your own money. Under the Gramm-Leach-Bliley framework the Safeguards Rule sits in, a financial institution is any business significantly engaged in activities that are financial in nature, or in activities incidental to them. The FTC has stated that businesses which finance, or facilitate the financing of, purchases for consumers are financial institutions for purposes of the Rule, because lending money is a financial activity. Leasing personal property on a non-operating basis for longer than 90 days is treated the same way.
So you can send every credit application to an outside lender, hold no paper of your own, never call yourself a lender, and still sit inside the definition. And the obligation does not end at the sale. Information you gathered to arrange that financing stays customer information for as long as you keep it, even after the paper is sold.
16 CFR 314.2(h), definition of financial institution. Coverage turns on your own facts. Nothing here determines it for you.
See which activities bring an organization inside the definitionThis is the part organizations discover last, usually at the worst possible moment. The Safeguards Rule does not simply ask you to be secure. It names specific things you must be able to produce, and it holds a single designated person accountable for them. Section 314.4 sets out nine program elements at (a) through (i), plus a separate notification requirement at (j). You will see it described as ten. That framing is common, and it quietly costs you something. Here are five of the nine, drawn straight from the text.
Why the distinction is worth two sentences of your time: the nine are components of a program you build and maintain. Section 314.4(j) is not a component of anything. It is an event-triggered duty to notify the FTC, and the §314.6 exceptions that lift four of the nine for smaller organizations never touch it. Counting it as a tenth element hides the fact that it applies to you at every size, and that its clock starts on discovery rather than on a decision anyone makes. The full nine, and what record proves each one →
Notice the pattern. In every row, the work is probably already happening at your organization. What is missing is the person accountable for capturing it as evidence, and the record that proves it existed before anyone asked. That is what a Qualified Individual is for. Not to do your security, but to make your governance provable. The Rule allows you to designate that person from outside your organization.
See which of these gaps applies to youGovernance evidence is not produced for its own sake. It is produced because, sooner or later, someone with standing asks to see it, and by then it either exists or it does not. These are the four who ask.
Each of these developed separately, but they are converging on the same expectation. That an organization can demonstrate how cybersecurity was governed, not just assert it. The regulations do not create that idea. They confirm it. Select one to go deeper.
Here is exactly what happens when you click. You get one question first, the same one you read above, so you find out whether the Rule reaches you before you answer anything else. If it does not, you will be told so plainly and sent on your way. If it does, you walk through 21 questions mapped to 16 CFR Part 314. Each one asks what a regulator, an insurer, or an investor would ask, which is not what you have installed but what you could produce.
At the end you get your status out of 100, the three things you are already doing well, and the single next proof worth your attention. Nothing is sold to you on that screen. You will simply understand something about your own organization that you did not understand before.
Start your Governance Proof StatusI educate organizations that collect and protect consumers’ financial information on how to document cybersecurity decisions before, during, and after a material cybersecurity incident.
There are thousands of security professionals, GRC consultants, and auditors. Very few can take a regulatory expectation and explain it so that a general counsel, a CFO, an owner, or a board member finally thinks, "that is why they require that." That translation is the work, and it is all I do.
"We do not ask organizations to trust our conclusions. We educate them until they can reach those conclusions themselves."
Have a direct question? Get on my calendar