Governance Evidence, Explained
01
What did you know?Who, in writing, is responsible for overseeing your cybersecurity program? That is the accountability question.
02
What did you do?What decisions were made, and what process carried them out before, during, and after an incident? That is the disclosure question.
03
When can you prove it?If someone asked tomorrow, what evidence could you produce, and how quickly? That is the evidence question.

Most organizations can answer those questions. Far fewer can prove their answers with evidence a regulator, an insurer, an investor, or a board would accept. PaperTrailProof exists to teach the difference, and to help you turn uncertainty into proof.

Before proof, one prior question. Are you even covered?

You cannot have a gap under a rule that does not apply to you. So the honest first step is not measuring your governance. It is finding out whether a regulator would consider you subject to these expectations at all. For a large share of organizations, the answer is yes, and no one has told them.

The FTC's "financial institution" reaches further than most people think

The FTC Safeguards Rule (16 CFR Part 314) applies to "financial institutions" under FTC jurisdiction, meaning any business significantly engaged in an activity that is financial in nature. That definition goes well beyond banks. The Rule itself lists thirteen kinds of covered businesses, from mortgage lenders and brokers to tax preparers, collection agencies, and wire transferors, and a fourteenth category, "finders," was added in 2021.

If your business is engaged in activities like those and you collect, process, or transmit customers' nonpublic personal financial information as part of them, the Rule likely reaches you, whether or not anyone has said so. Most organizations in scope have simply never been told they qualify.

See the full list of covered industries and where each one appears in the Rule

If the Rule reaches you, it expects one person to own it.

This is the part organizations discover last, usually at the worst possible moment. The Safeguards Rule does not simply ask you to be secure. It names specific things you must be able to produce, and it holds a single designated person accountable for them. Here is what the Rule expects, drawn straight from its own text.

What the Rule requires
Where it says so
The gap most organizations have
A single Qualified Individual designated to oversee, implement, and enforce the program
16 CFR 314.4(a)
Someone handles security, but no document names them or defines their authority
A written risk assessment
16 CFR 314.4(b)
Risks are understood informally, but nothing is written down or kept current
Written oversight of service providers
16 CFR 314.4(f)
Vendors touch customer data, but no records show they were vetted or required to safeguard it
A written report from the Qualified Individual to the board or a senior officer
16 CFR 314.4(i)
Updates happen verbally, so leadership has no record of what it was told or when

Notice the pattern. In each row, the work is often happening. What is missing is the person accountable for capturing it as evidence, and the record that proves it existed before anyone asked. That is what a Qualified Individual is for. Not to do security, but to make governance provable. The Rule allows that person to be someone you designate from outside your organization.

See which of these gaps applies to you

The question is not if you will be asked. It is who asks first.

Governance evidence is not produced for its own sake. It is produced because, sooner or later, someone with standing asks to see it, and by then it either exists or it does not. These are the four who ask.

A regulator
The FTC, the SEC, or a state authority opens an inquiry and asks how cybersecurity was governed. Not whether you meant well, but what you can show.
A cyber-insurer
At renewal or at claim time, the carrier asks for evidence the controls you attested to were actually in place and operating.
An investor or acquirer
Diligence asks for your governance record. Gaps become price reductions, escrow holdbacks, or dropped deals.
Your own board
Directors ask what system existed to surface cyber risk to them, because their personal oversight duty now depends on the answer.

Three bodies of law. One idea underneath them.

Each of these developed separately, but they are converging on the same expectation. That an organization can demonstrate how cybersecurity was governed, not just assert it. The regulations do not create that idea. They confirm it. Select one to go deeper.

Consumer protection

FTC Safeguards

16 CFR Part 314
A covered business must designate a Qualified Individual, assess its risks in writing, and be able to produce evidence of its safeguards on request.
Confirms the idea that accountability must be assigned and provable.
See who is covered →
Market integrity

SEC Item 106

Reg S-K, and Item 1.05 of Form 8-K
A public company must describe how it governs cyber risk and disclose material incidents, backed by evidence of the process behind the disclosure.
Confirms the idea that what you disclose must be backed by what you can show.
Deep-dive coming soon
Board oversight

Caremark

Delaware duty of oversight
Directors can face personal liability where no functioning system existed to surface a mission-critical risk, and evidence is how a board shows the system worked.
Confirms the idea that oversight is judged on whether a system existed and operated.
Deep-dive coming soon
The question
The gap it reveals
What proof establishes
Who was responsible?
Accountability Gap
What the organization knew
What process was implemented?
Disclosure Gap
What the organization did
Could you prove it?
Evidence Gap
When the organization did it

See where you stand, in about five minutes.

The Governance Proof Status starts with the only question that matters first. Does the Rule apply to you? From there it shows which of the three gaps, accountability, disclosure, or evidence, is most worth your attention. This is a decision, not a purchase: whether your organization decides to meet the FTC's expectation of a reasonable company's governance, with a predictable, documented outcome. No pitch. You will simply understand something you did not before.

Start your Governance Proof Status
Free, about five minutes, and you will leave knowing more than when you arrived.
A.V. Senero, Governance Evidence Translator
A.V. SENERO
Governance Evidence Translator

I educate organizations on how to document cybersecurity decisions before, during, and after a material cybersecurity incident.

There are thousands of security professionals, GRC consultants, and auditors. Very few can take a regulatory expectation and explain it so that a general counsel, a CFO, a dealer principal, or a board member finally thinks, "that is why they require that." That translation is the work.

"We do not ask organizations to trust our conclusions. We teach them until they can reach those conclusions themselves."

Have a direct question? Get on my calendar