A leadership checklist

After an FTC Safeguards conversation: ten things worth investigating.

If we spoke recently, this is what I would look into before spending a dollar on anything. None of these ask what you have installed. Every one asks what record exists, who owns it, and when someone last looked at it.

You do not need me to work through this list. Several organizations have run it internally and found they were in better shape than they thought. A few found the opposite. Both outcomes are useful, and both are cheaper to learn on a Tuesday than during an incident.

The ten

What leadership should be able to answer

Read each question out loud to whoever would know. The useful signal is not whether the answer is yes. It is how long it takes and how many people it takes.

01

Coverage

16 CFR §314.2(h)
The question to ask

Which of our activities, if any, bring us inside the definition of a financial institution, and who wrote that determination down?

The Rule reaches organizations that are significantly engaged in financial activities. It does not reach industries. Arranging financing counts even if you hold no paper of your own, and leasing on a non-operating basis beyond 90 days is treated the same way. The record that matters is a dated written determination, not an assumption in someone's head.

02

Consumer information

16 CFR §314.2(d)
The question to ask

Where does customer financial information exist across this organization, and who maintains the list?

Customer information is broader than the database. It lives in email, attachments, paper files, credit applications, DMS records, phones, cloud storage, and vendor systems. One record can exist in six places with different people able to reach it.

03

Ownership

16 CFR §314.4(a)(1) and (a)(2)
The question to ask

Who holds the document naming the senior person on our side responsible for directing and overseeing whoever runs our information security program?

A Qualified Individual can be an employee, an affiliate, or a service provider. If the role sits outside the organization, you must still designate a senior member of your own personnel to direct and oversee them, and the responsibility for compliance stays with you. This is the single question most organizations cannot answer with a document.

04

Written program

16 CFR §314.3
The question to ask

Is there a current written information security program, and when was it last reviewed by someone with authority?

The program has to be written, and it has to be appropriate to the size and complexity of the organization. A file that exists but has not been opened in three years is evidence of a different problem than having no file at all.

05

Risk assessment

16 CFR §314.4(b)
The question to ask

What written risk assessment are our current safeguards actually based on, and who signed off on it?

The assessment must be written, must identify reasonably foreseeable internal and external risks, and must state the criteria used to evaluate them. Safeguards are supposed to flow from it. Organizations under 5,000 consumers are exempt from the written form of this one.

06

Controls

16 CFR §314.4(c) and (d)
The question to ask

Which safeguards can we demonstrate are operating right now, as opposed to installed?

Access controls, encryption in transit and at rest, multi-factor authentication, secure disposal, change management, and logging of authorized user activity. Then testing that they work. A dashboard shows what is true today. It cannot show what was true on the day something mattered.

07

Service providers

16 CFR §314.4(f)
The question to ask

If our technology provider stopped answering the phone tomorrow, who on our payroll holds the record of what they were required to protect?

You must select providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess them based on the risk they present. FTC staff guidance issued to dealers in June 2025 focused specifically on obligations around third-party vendors and OEMs. This one is never exempt at any size.

08

Training and incident response

16 CFR §314.4(e), (h) and (j)
The question to ask

If an employee discovered this morning that customer records had been reached, who is named in writing as the person who decides whether the reporting clock has started?

Training records with completion dates, a written incident response plan, and evidence it has been exercised. Then the piece almost nobody has: §314.4(j) requires notifying the FTC within 30 days of discovering a notification event affecting at least 500 consumers, and discovery means the date any employee or agent knew, not the date leadership was told.

09

Leadership reporting

16 CFR §314.4(i)
The question to ask

What has the Qualified Individual actually reported in writing to our board or senior officer, and when?

At least annually, in writing, covering overall program status, compliance, risk assessment results, service provider arrangements, testing results, security events and management's response, and recommendations for change. Verbal updates leave leadership with no record of what it was told or when.

10

Evidence location

All of the above
The question to ask

For each of the nine, who owns the artifact, where does it live, and when was it last reviewed?

This is the one that turns the other nine into something usable. Ownership, location, and review date for every record. An organization that can answer this in an afternoon is in a fundamentally different position from one that needs three weeks and four people.

Before you buy anything

What the answers tell you

If leadership can quickly name the owner, the evidence location, the review date, and the decision record for all ten, you are in better shape than most organizations I meet, and you should keep doing exactly what you are doing.

If it cannot, that gap is worth understanding before a policy purchase, a platform subscription, or a consultant. Buying tools to solve a documentation problem is how organizations end up owning things they cannot explain and still cannot produce.

Worth knowing either wayThe Governance Proof Status writes this down and dates it. It tells you as much about what you are exempt from as about what you owe, and organizations under 5,000 consumers are frequently exempt from more than they expect.

Twenty questions, about six minutes, mapped to 16 CFR Part 314. Nothing is sold to you on the results screen. The nine program elements in full →

Where to start

Find out where your evidence stands

Twenty questions, about six minutes. You will know more when you finish than when you started.

Check where you stand How engagements work