Most organizations can answer those questions. Far fewer can prove their answers with evidence a regulator, an insurer, an investor, or a board would accept. PaperTrailProof exists to teach the difference, and to help you turn uncertainty into proof.
You cannot have a gap under a rule that does not apply to you. So the honest first step is not measuring your governance. It is finding out whether a regulator would consider you subject to these expectations at all. For a large share of organizations, the answer is yes, and no one has told them.
The FTC Safeguards Rule (16 CFR Part 314) applies to "financial institutions" under FTC jurisdiction, meaning any business significantly engaged in an activity that is financial in nature. That definition goes well beyond banks. The Rule itself lists thirteen kinds of covered businesses, from mortgage lenders and brokers to tax preparers, collection agencies, and wire transferors, and a fourteenth category, "finders," was added in 2021.
If your business is engaged in activities like those and you collect, process, or transmit customers' nonpublic personal financial information as part of them, the Rule likely reaches you, whether or not anyone has said so. Most organizations in scope have simply never been told they qualify.
See the full list of covered industries and where each one appears in the RuleThis is the part organizations discover last, usually at the worst possible moment. The Safeguards Rule does not simply ask you to be secure. It names specific things you must be able to produce, and it holds a single designated person accountable for them. Here is what the Rule expects, drawn straight from its own text.
Notice the pattern. In each row, the work is often happening. What is missing is the person accountable for capturing it as evidence, and the record that proves it existed before anyone asked. That is what a Qualified Individual is for. Not to do security, but to make governance provable. The Rule allows that person to be someone you designate from outside your organization.
See which of these gaps applies to youGovernance evidence is not produced for its own sake. It is produced because, sooner or later, someone with standing asks to see it, and by then it either exists or it does not. These are the four who ask.
Each of these developed separately, but they are converging on the same expectation. That an organization can demonstrate how cybersecurity was governed, not just assert it. The regulations do not create that idea. They confirm it. Select one to go deeper.
The Governance Proof Status starts with the only question that matters first. Does the Rule apply to you? From there it shows which of the three gaps, accountability, disclosure, or evidence, is most worth your attention. This is a decision, not a purchase: whether your organization decides to meet the FTC's expectation of a reasonable company's governance, with a predictable, documented outcome. No pitch. You will simply understand something you did not before.
Start your Governance Proof StatusI educate organizations on how to document cybersecurity decisions before, during, and after a material cybersecurity incident.
There are thousands of security professionals, GRC consultants, and auditors. Very few can take a regulatory expectation and explain it so that a general counsel, a CFO, a dealer principal, or a board member finally thinks, "that is why they require that." That translation is the work.
"We do not ask organizations to trust our conclusions. We teach them until they can reach those conclusions themselves."
Have a direct question? Get on my calendar