Insights · Does the Rule Apply?

Does the FTC Safeguards Rule Apply to Your Business? The Activity Test Explained

By A.V. Señero, Governance Evidence Translator™, FID Governance LLC · Published 8 September 2026 · About 9 minutes

Many business leaders begin with the wrong question. They ask "Are we a bank?" and, satisfied with the answer, stop.

The better question is whether the organization is significantly engaged in activities that are financial in nature, or incidental to financial activities, and whether it handles customer information in connection with those activities.

A business does not have to call itself a bank, a lender, or a financial institution for the FTC Safeguards Rule to become relevant. The Rule reaches certain financial institutions under the FTC's jurisdiction, and that term turns on the activities a business performs, not the label it uses. The analysis is fact-specific, and a legal determination belongs to qualified counsel. What follows is meant to help leadership understand which questions are worth investigating first.

The short answer

If your organization provides or arranges financial products or services, handles consumers' financial information in connection with those activities, and falls under FTC jurisdiction, the Safeguards Rule may apply. Start with a review of your activities and information flows rather than resting on the assumption that you are not a bank.

The premise

Why the activity test matters

The Safeguards Rule requires covered financial institutions to develop, implement, and maintain an information security program designed to protect customer information. FTC guidance describes that program as including administrative, technical, and physical safeguards, overseen by a designated Qualified Individual.

For an owner or executive, the first issue is not whether the company has cybersecurity software, an MSP, or a written policy. It is whether the organization's actual activities create the need for a more formal analysis in the first place.

That matters because an organization may:

Read that list again and notice what the last item is doing. The first four are about technology and information. The fifth is not. What most organizations discover is a governance problem wearing a technology problem's clothes.

The definition

What "financial institution" actually means

Under 16 CFR §314.2(h), a financial institution is an institution whose business is engaging in an activity that is financial in nature, or incidental to such financial activities. The definition draws on the activities described in section 4(k) of the Bank Holding Company Act.

This is why a business should not rely on its category label. A company may not describe itself as a financial institution and still perform activities that warrant a closer look: arranging financing, receiving financial applications, supporting consumer lending processes, facilitating financial transactions, or handling consumer financial information in connection with covered activities.

FTC guidance offers examples including mortgage brokers, payday lenders, finance companies, account servicers, and businesses engaged in financing-related activities. The examples are illustrations of activities, not a roster of industries. That distinction is the entire point, and it is the one most commonly lost in secondhand summaries.

See the worked coverage examples from the regulation itself →

The method

The five-question practical test

Before anyone buys anything, leadership should be able to answer these five in plain language.

1. What does the organization actually do?

Does it provide, arrange, facilitate, advise on, broker, process, or support financial products, services, or transactions? Not what the sign says. What the work is.

2. What consumer information does it handle?

Does it receive, collect, store, transmit, access, use, or dispose of consumer financial information, identifiers, applications, tax records, account details, or credit documents?

3. Why is the information being handled?

Is it being used in connection with financial activity: a consumer financial product or service, financing, credit, lending, tax preparation, or another potentially relevant activity?

4. How does information move?

Through email, cloud storage, portals, lender systems, tax software, dealership systems, paper files, laptops, phones, or outsourced vendors? One record can exist in six places, each with different people able to reach it.

5. Who owns the process?

Is there a designated individual responsible for the information security program, the evidence, the risk review, vendor oversight, and leadership reporting? This is the question that most often has no answer, and it is the one that matters most.

In practice

Three common business situations

These are educational illustrations, not legal conclusions. Whether the Rule applies depends on the actual services, activities, information, and jurisdictional facts of a specific organization.

Auto dealers

A dealership may collect credit applications, driver's license information, proof of income, insurance details, bank information, and financing documentation. It may transmit that information to lenders, work through a dealer management system, and maintain records with third-party technology platforms.

The relevant question is not limited to whether the dealership originates loans. Leadership should examine whether the dealership arranges financing, facilitates credit applications, handles customer financial information, and maintains a program reflecting those risks.

The question to put to your teamIf our dealership submits a credit application to a lender today, who owns the safeguards around that information from intake through lender submission, system storage, vendor access, and secure disposal?

Mortgage brokers and originators

Brokers, originators, and processors work routinely with borrower financial information: income documents, credit records, bank statements, tax returns, lender portals, and third-party technology providers.

Because the work is closely connected to consumer financial activity, the useful starting point is usually not whether sensitive information exists. It plainly does. The question is whether leadership can demonstrate accountable governance around it.

The question to put to your teamWho can show how borrower information is protected across intake, processing, lender submission, shared systems, email, vendors, and leadership oversight?

Tax preparation and accounting firms

Tax preparers and accounting firms receive highly sensitive information: income documents, tax records, account numbers, payroll data, identity information, business financials, and documents uploaded to preparation software or client portals.

Coverage still requires fact-specific analysis. Regardless of where that lands, these firms should be able to map where sensitive information enters, who can reach it, which vendors process it, what safeguards exist, and what evidence shows those safeguards are managed.

The question to put to your teamCan our firm show where taxpayer and client financial information enters, where it is stored, who accesses it, which vendors touch it, and how leadership knows the safeguards are working?
The requirement

What covered organizations are expected to have

If the Rule applies, the organization must develop, implement, and maintain a written information security program with administrative, technical, and physical safeguards appropriate to its size and complexity, the nature and scope of its activities, and the sensitivity of the customer information it handles.

Section 314.4 sets out nine program elements at (a) through (i). You will frequently see this described as ten. That framing folds in §314.4(j), which is not a program element at all but an event-triggered duty to notify the FTC. The distinction is not pedantry: the §314.6 exceptions lift four of the nine for organizations under 5,000 consumers and never touch (j), so counting it as a tenth element hides the fact that it reaches you at any size.

This does not mean every business needs the same technology or the same volume of paperwork. It means a covered organization needs a program scaled to its operations, and evidence that the program exists and is being maintained.

All nine elements, and what record proves each one →

The distinction

A WISP alone is not proof

A written program matters. But a document by itself does not demonstrate that anything is operating.

Leadership should be able to identify who owns the program, when the risk assessment was last updated, which safeguards address the organization's significant risks, how training is assigned and documented, which vendors can reach customer information and how they are overseen, what testing and incident-response evidence exists, and what the Qualified Individual has reported to senior leadership.

Policy is not the same as governance

A policy says what should happen. Governance evidence shows what did happen, who was accountable, and when leadership last looked. The gap between those two is where most organizations actually live, and it is invisible until somebody asks.

At PaperTrailProof we use Governance Proof Status to describe whether an organization can locate clear, current, accountable evidence for the components of its program.

What to do

A practical next step

Do not start by buying a generic WISP template, and do not assume an IT provider has settled the governance question. Start with a structured review of five areas: coverage (what financial activities the business performs), accountability (who owns the program), program (what policies, assessments, and procedures exist), evidence (what records show the program operates), and decision (whether to run it internally, use oversight support, or engage managed governance).

The Governance Proof Status is built to organize that first conversation. It does not provide legal advice or a coverage determination. It helps an organization see which activities, information flows, ownership questions, and evidence areas need review next. It also tells you what you may be exempt from, which is frequently more than people expect.

Questions

Frequently asked

Does the FTC Safeguards Rule apply only to banks?

No. The definition does not depend on whether a business calls itself a bank. It turns on whether the business is significantly engaged in financial activities or activities incidental to them, along with other jurisdictional facts. Evaluate actual activities, and seek counsel for a legal determination.

Does collecting financial information automatically mean the Rule applies?

Not necessarily. Handling sensitive financial information is a real risk and governance issue, but coverage requires an activity-based, fact-specific analysis of how the organization's services, financial activities, customer relationships, and information practices sit within the Rule and FTC jurisdiction.

Can our IT provider handle this for us?

An IT provider may operate important technical safeguards. The organization still needs clear program ownership, a risk assessment, service-provider oversight, evidence, and leadership reporting. A Qualified Individual can be an employee, an affiliate, or a service provider. If the role sits outside the organization, a senior member of your own personnel must still be designated to direct and oversee that person, and responsibility for compliance stays with you.

What is the first document we should locate?

The written information security program, the written risk assessment, the name and documented scope of the Qualified Individual, and any recent governance report given to senior leadership. If those cannot be found quickly, that is itself the finding.

Where to start

Find out where your evidence stands

Twenty-one questions, about six minutes, mapped to 16 CFR Part 314. It tells you as much about what you are exempt from as about what you owe.

Check where you stand How engagements work
A.V. Señero, Founder and Governance Evidence Translator of FID Governance LLC

A.V. Señero is Founder and Governance Evidence Translator™ of FID Governance LLC, the Sacramento firm behind PaperTrailProof™. He serves as a designated Qualified Individual under 16 CFR §314.4(a) and educates organizations that collect consumers' financial information on FTC Safeguards Rule accountability, WISP governance, and the evidence required to show an information security program is actually operating.

Leadership is the disciplined allocation of attention toward reducing uncertainty through evidence.

A.V. Señero · FID Governance LLC · Sacramento, California
linkedin.com/in/av-senero-papertrailproof · papertrailproof.com

Disclosure. FID Governance LLC receives compensation from the technology partner whose platform it places clients on. It takes no fee of any kind on independent testing under §314.4(d)(2). Full compensation disclosure.

Educational notice. This material is educational and describes governance methodology. It is not legal advice, does not establish an attorney-client relationship, does not determine whether the FTC Safeguards Rule applies to any particular organization, and does not guarantee regulatory or cybersecurity outcomes. Coverage depends on an organization's specific activities and facts. Consult qualified legal counsel for legal determinations.

Primary sources. 16 CFR Part 314 (Standards for Safeguarding Customer Information) · 16 CFR §314.2 (Definitions) · 12 U.S.C. §1843(k) · FTC staff business guidance for financial institutions.