A financial institution under the FTC Safeguards Rule is not limited to a bank, a credit union, or a company with the word financial in its name.
The Rule defines the term by what a business does. An organization may need a closer look if it is significantly engaged in activities that are financial in nature, or incidental to financial activities, and it handles customer information in connection with those activities.
Which is why the first question for leadership is not "Are we a bank?" It is: what financial activities do we perform, what consumer financial information do we handle, and can we show who is accountable for protecting it?
Under 16 CFR §314.2(h), a financial institution is an institution whose business engages in an activity that is financial in nature or incidental to financial activities described in section 4(k) of the Bank Holding Company Act. This is an activity-based test. A business can be a financial institution under the Rule without being a bank, and can need to evaluate its activities even when its primary industry is automotive, tax, accounting, or real estate.
The final determination is fact-specific and may require qualified counsel. This article is an educational guide to the questions, activities, information flows, and evidence worth reviewing before assuming the Rule does, or does not, apply.
The regulatory language is technical. In plain terms it asks whether the business is meaningfully involved in activities that are financial in nature, or connected closely enough to those activities to be considered incidental.
"Significantly engaged" is doing real work in that sentence. The analysis is not necessarily triggered by every isolated or incidental contact with financial information. It asks what the organization does as part of its ordinary operations.
A useful starting point is whether the organization provides, arranges, brokers, facilitates, advises on, processes, or supports financial products, services, or transactions; whether it receives consumer applications, credit materials, borrower records, account data, or tax records in connection with those activities; whether it transfers information to lenders, financial platforms, tax software, credit providers, or payment processors; whether the activity is routine and meaningful to how the business operates; and who is responsible for assessing the risk and safeguarding the information involved.
A business can call itself a dealer, a broker, a processor, an accounting firm, or a service company and still need a serious activity review. The FTC's test looks at what you do, not at what you named yourself.
The Safeguards Rule is not a paperwork requirement. For covered institutions it requires a written information security program with administrative, technical, and physical safeguards appropriate to the organization's size and complexity, the nature and scope of its activities, and the sensitivity of the customer information it handles.
Which creates practical leadership questions. Who is designated to oversee the program? What written risk assessment identifies reasonably foreseeable internal and external risks? What safeguards are actually operating, as opposed to installed? Which service providers can reach customer information? What evidence exists of training, testing, vendor oversight, incident-response readiness, and program review? What has senior leadership actually received from the person responsible?
An organization can have good tools and still lack an evidence-backed program. It may run multi-factor authentication, secure cloud software, managed IT, and cyber insurance, and still be unable to show who owns the program, what risks were assessed, what vendors were reviewed, or what leadership was told and when.
"Do we have security tools?" and "Can we prove an accountable information security program is being governed and maintained?" are not the same question. Most organizations can answer the first one immediately and the second one not at all.
These examples do not create legal conclusions. They are practical triggers for a fact-specific review.
A business may warrant further analysis if it helps customers apply for financing, transmits credit applications, works with lenders, leases vehicles, presents financing options, or otherwise plays a material role in a consumer finance process. An auto dealer may submit a buyer's credit application to third-party lenders without originating the loan itself. Its role in collecting, transmitting, storing, and supporting that process still deserves careful review.
Brokers, originators, processors, and related firms work directly with borrower financial records, tax documents, bank statements, income information, credit records, applications, lender portals, and technology vendors. The practical issue is rarely whether sensitive data exists. It is whether the organization can identify program ownership and demonstrate how borrower information is governed end to end.
These firms receive taxpayer identification details, income records, bank information, payroll data, returns, business financials, and portal uploads. Coverage remains fact-specific. From a governance standpoint the firm should still understand where client financial information enters, where it lives, who can reach it, which providers support it, how it is protected, and how that work is documented.
Official sources and legal analyses commonly identify nonbank activities such as mortgage lending or brokering, finance company operations, payday lending, wire transfers, check cashing, debt collection, retail credit card activity, certain vehicle leasing, real estate settlement services, credit counseling, and certain tax preparation or accounting services as examples that may warrant analysis.
The point is not that every business in these categories is covered. It is that a conclusion reached from an industry label alone is not a conclusion at all.
The FTC Safeguards Rule applies to financial institutions under FTC jurisdiction. Some financial institutions answer to other federal regulators, which can determine whether the FTC's version of the Safeguards Rule is the applicable federal framework at all.
This is a significant reason not to settle coverage from a single internet checklist. The organization has to consider what financial activities it performs, whether it is significantly engaged in them, whether those activities involve consumers and customer information, which regulator has jurisdiction, whether an exemption or another framework applies, and what its actual operational facts are.
If the answer is unclear, treat it as a legal and governance review question rather than a guess.
Once leadership concludes the business may be engaged in relevant financial activity, gather facts before buying technology, downloading a template, or assuming the IT provider resolved it.
| Review area | What to investigate | Evidence to locate |
|---|---|---|
| Business activity | What financial or incidental financial activities do we perform? | Service descriptions, workflows, financing agreements, customer journey maps |
| Customer information | What financial information do we receive, use, store, transmit, or dispose of? | Intake forms, applications, data inventory, retention schedule |
| Information flow | Where does the information travel? | Data flow map, system inventory, cloud storage inventory, portal list |
| Accountability | Who owns the program? | QI designation, job description, responsibility matrix |
| Written program | What information security program exists? | Current WISP, policy inventory, review dates |
| Risk management | What risks have been assessed and addressed? | Written risk assessment, remediation plan, risk register |
| Service providers | Which vendors touch customer information? | Vendor inventory, contracts, security reviews, due diligence records |
| Leadership oversight | What does leadership know and approve? | Reports, meeting minutes, approval records, action tracker |
This does not replace legal review or a formal security assessment. It moves leadership from assumption to evidence, which is the only move that matters at this stage.
You may well not be. But the definition is activity-based, so that fact alone does not resolve anything. What does the business actually do, and how does it handle customer financial information?
Origination is not the only activity that can matter. Arranging financing, facilitating applications, or transmitting information to lenders may each require a closer look.
They may do important technical work. That does not answer who has been designated to oversee the program, whether the risk assessment is current, whether vendors are overseen, or whether leadership receives reporting.
A WISP is one component. Leadership should also be able to demonstrate ownership, risk assessment, safeguards, training, monitoring, vendor oversight, testing, adjustment, reporting, and retained evidence.
Size shapes the program and can lift specific written requirements. Under 16 CFR §314.6, organizations maintaining information on fewer than 5,000 consumers are exempt from four of them. It does not remove the need for a fact-based review, and it never touches service-provider oversight or the notification duty.
No. Handling financial information is an important fact but does not by itself establish coverage. The definition turns on whether the organization is significantly engaged in financial activities or activities incidental to them, together with its jurisdictional circumstances.
A dealer may require analysis where it arranges financing, handles credit applications, leases vehicles, transmits customer information to lenders, or engages in other relevant financial activities. The answer depends on actual operations and legal context.
Brokers and similar businesses are often directly involved in consumer financial activity and routinely handle borrower financial information. They should conduct a fact-specific review of their obligations and the regulatory framework that applies to them.
Yes. These firms handle highly sensitive financial information and may perform activities requiring closer analysis. Even before a coverage conclusion, they should map information flow, identify accountable owners, and review their governance evidence.
Not automatically. A Qualified Individual may be an employee, an affiliate, or a service provider. Where the role sits outside the organization, 16 CFR §314.4(a)(2) contemplates that a senior member of your own personnel is designated to direct and oversee that person, and that responsibility for compliance remains with your organization.
Twenty-one questions, about six minutes, mapped to 16 CFR Part 314. It tells you as much about what you are exempt from as about what you owe.
Check where you stand How engagements work
A.V. Señero is Founder and Governance Evidence Translator™ of FID Governance LLC, the Sacramento firm behind PaperTrailProof™. He serves as a designated Qualified Individual under 16 CFR §314.4(a) and educates organizations that collect consumers' financial information on FTC Safeguards Rule accountability, WISP governance, and the evidence required to show an information security program is actually operating.
Leadership is the disciplined allocation of attention toward reducing uncertainty through evidence.
Disclosure. FID Governance LLC receives compensation from the technology partner whose platform it places clients on. It takes no fee of any kind on independent testing under §314.4(d)(2). Full compensation disclosure.
Educational notice. This material is educational and describes governance methodology. It is not legal advice, does not establish an attorney-client relationship, does not determine whether the FTC Safeguards Rule applies to any particular organization, and does not guarantee regulatory or cybersecurity outcomes. Coverage depends on an organization's specific activities and facts. Consult qualified legal counsel for legal determinations.
Primary sources. 16 CFR Part 314 (Standards for Safeguarding Customer Information) · 16 CFR §314.2 (Definitions) · 12 U.S.C. §1843(k) · FTC staff business guidance for financial institutions.