Governance Evidence, Explained

The FTC does not regulate industries. It regulates activities.

Does your organization collect or use consumers’ financial information to provide or arrange financial products or services? If you answered yes, or if you are not sure, there are governance expectations that may already apply to you. Most organizations inside the definition have never been told they are in it.

01
What did you know?Who, in writing, is responsible for overseeing your cybersecurity program? That is the accountability question.
02
What did you do?What decisions were made, and what process carried them out before, during, and after an incident? That is the disclosure question.
03
When can you prove it?If someone asked tomorrow, what evidence could you produce, and how quickly? That is the evidence question.

You can probably answer those three questions right now. What is harder is proving your answers with evidence a regulator, an insurer, an investor, or your own board would accept. That difference is the whole subject of this site, and we teach it before we ask you for anything.

A.V. Señero, Founder and Governance Evidence Translator of FID Governance LLC and designated Qualified Individual under 16 CFR 314.4(a)
A.V. SEÑEROGovernance Evidence Translator™
FID Governance LLC

Before proof, one prior question. Does this reach you?

You cannot have a gap under a rule that does not apply to you. So the honest first step is not measuring your governance. It is finding out whether the Rule reaches your organization at all. For a large share of organizations the answer is yes, and no one has told them.

Here is the question that decides it

Does your organization collect, receive, store, transmit, or use consumers’ financial information in connection with providing or arranging financial products or services?

Notice what that question does not ask. It does not ask whether you are a bank. It does not ask whether you lend your own money. Under the Gramm-Leach-Bliley framework the Safeguards Rule sits in, a financial institution is any business significantly engaged in activities that are financial in nature, or in activities incidental to them. The FTC has stated that businesses which finance, or facilitate the financing of, purchases for consumers are financial institutions for purposes of the Rule, because lending money is a financial activity. Leasing personal property on a non-operating basis for longer than 90 days is treated the same way.

So you can send every credit application to an outside lender, hold no paper of your own, never call yourself a lender, and still sit inside the definition. And the obligation does not end at the sale. Information you gathered to arrange that financing stays customer information for as long as you keep it, even after the paper is sold.

16 CFR 314.2(h), definition of financial institution. Coverage turns on your own facts. Nothing here determines it for you.

See which activities bring an organization inside the definition

If the Rule reaches you, it expects one person to own it.

This is the part organizations discover last, usually at the worst possible moment. The Safeguards Rule does not simply ask you to be secure. It names specific things you must be able to produce, and it holds a single designated person accountable for them. Section 314.4 sets out nine program elements at (a) through (i), plus a separate notification requirement at (j). You will see it described as ten. That framing is common, and it quietly costs you something. Here are five of the nine, drawn straight from the text.

Why the distinction is worth two sentences of your time: the nine are components of a program you build and maintain. Section 314.4(j) is not a component of anything. It is an event-triggered duty to notify the FTC, and the §314.6 exceptions that lift four of the nine for smaller organizations never touch it. Counting it as a tenth element hides the fact that it applies to you at every size, and that its clock starts on discovery rather than on a decision anyone makes. The full nine, and what record proves each one →

What the Rule requires
Where it says so
The gap most organizations have
A single Qualified Individual designated to oversee, implement, and enforce the program
16 CFR 314.4(a)
Someone handles security, but no document names them or defines their authority
A written risk assessment
16 CFR 314.4(b)
Risks are understood informally, but nothing is written down or kept current
Written oversight of service providers
16 CFR 314.4(f)
Vendors touch customer data, but no records show they were vetted or required to safeguard it
The program evaluated and adjusted when testing results or your operations change
16 CFR 314.4(g)
The program does get updated, but nothing records what prompted the change
A written report from the Qualified Individual to the board or a senior officer
16 CFR 314.4(i)
Updates happen verbally, so leadership has no record of what it was told or when

Notice the pattern. In every row, the work is probably already happening at your organization. What is missing is the person accountable for capturing it as evidence, and the record that proves it existed before anyone asked. That is what a Qualified Individual is for. Not to do your security, but to make your governance provable. The Rule allows you to designate that person from outside your organization.

See which of these gaps applies to you

The question is not if you will be asked. It is who asks first.

Governance evidence is not produced for its own sake. It is produced because, sooner or later, someone with standing asks to see it, and by then it either exists or it does not. These are the four who ask.

A regulator
The FTC, the SEC, or a state authority opens an inquiry and asks how cybersecurity was governed. Not whether you meant well, but what you can show.
A cyber-insurer
At renewal or at claim time, the carrier asks for evidence the controls you attested to were actually in place and operating.
An investor or acquirer
Diligence asks for your governance record. Gaps become price reductions, escrow holdbacks, or dropped deals.
Your own board
Directors ask what system existed to surface cyber risk to them, because their personal oversight duty now depends on the answer.

Three bodies of law. One idea underneath them.

Each of these developed separately, but they are converging on the same expectation. That an organization can demonstrate how cybersecurity was governed, not just assert it. The regulations do not create that idea. They confirm it. Select one to go deeper.

Consumer protection

FTC Safeguards

16 CFR Part 314
A covered business must designate a Qualified Individual, assess its risks in writing, and be able to produce evidence of its safeguards on request.
Confirms the idea that accountability must be assigned and provable.
See who is covered →
Market integrity

SEC Item 106

Reg S-K, and Item 1.05 of Form 8-K
A public company must describe how it governs cyber risk and disclose material incidents, backed by evidence of the process behind the disclosure.
Confirms the idea that what you disclose must be backed by what you can show.
Deep-dive coming soon
Board oversight

Caremark

Delaware duty of oversight
Directors can face personal liability where no functioning system existed to surface a mission-critical risk, and evidence is how a board shows the system worked.
Confirms the idea that oversight is judged on whether a system existed and operated.
Deep-dive coming soon
The question
The gap it reveals
What proof establishes
Who was responsible?
Accountability Gap
What the organization knew
What process was implemented?
Disclosure Gap
What the organization did
Could you prove it?
Evidence Gap
When the organization did it

See where you stand, in about five minutes.

Here is exactly what happens when you click. You get one question first, the same one you read above, so you find out whether the Rule reaches you before you answer anything else. If it does not, you will be told so plainly and sent on your way. If it does, you walk through 21 questions mapped to 16 CFR Part 314. Each one asks what a regulator, an insurer, or an investor would ask, which is not what you have installed but what you could produce.

At the end you get your status out of 100, the three things you are already doing well, and the single next proof worth your attention. Nothing is sold to you on that screen. You will simply understand something about your own organization that you did not understand before.

Start your Governance Proof Status
Free, about five minutes, and no obligation attached to anything you find.
A.V. Señero, Governance Evidence Translator
A.V. SEÑERO
Governance Evidence Translator

I educate organizations that collect and protect consumers’ financial information on how to document cybersecurity decisions before, during, and after a material cybersecurity incident.

There are thousands of security professionals, GRC consultants, and auditors. Very few can take a regulatory expectation and explain it so that a general counsel, a CFO, an owner, or a board member finally thinks, "that is why they require that." That translation is the work, and it is all I do.

"We do not ask organizations to trust our conclusions. We educate them until they can reach those conclusions themselves."

Have a direct question? Get on my calendar