Insights · Does the Rule Apply?

What Is a Financial Institution Under the FTC Safeguards Rule?

By A.V. Señero, Governance Evidence Translator™, FID Governance LLC · Published 8 September 2026 · About 10 minutes

A financial institution under the FTC Safeguards Rule is not limited to a bank, a credit union, or a company with the word financial in its name.

The Rule defines the term by what a business does. An organization may need a closer look if it is significantly engaged in activities that are financial in nature, or incidental to financial activities, and it handles customer information in connection with those activities.

Which is why the first question for leadership is not "Are we a bank?" It is: what financial activities do we perform, what consumer financial information do we handle, and can we show who is accountable for protecting it?

The short answer

Under 16 CFR §314.2(h), a financial institution is an institution whose business engages in an activity that is financial in nature or incidental to financial activities described in section 4(k) of the Bank Holding Company Act. This is an activity-based test. A business can be a financial institution under the Rule without being a bank, and can need to evaluate its activities even when its primary industry is automotive, tax, accounting, or real estate.

The final determination is fact-specific and may require qualified counsel. This article is an educational guide to the questions, activities, information flows, and evidence worth reviewing before assuming the Rule does, or does not, apply.

The definition

The legal definition in plain English

The regulatory language is technical. In plain terms it asks whether the business is meaningfully involved in activities that are financial in nature, or connected closely enough to those activities to be considered incidental.

"Significantly engaged" is doing real work in that sentence. The analysis is not necessarily triggered by every isolated or incidental contact with financial information. It asks what the organization does as part of its ordinary operations.

A useful starting point is whether the organization provides, arranges, brokers, facilitates, advises on, processes, or supports financial products, services, or transactions; whether it receives consumer applications, credit materials, borrower records, account data, or tax records in connection with those activities; whether it transfers information to lenders, financial platforms, tax software, credit providers, or payment processors; whether the activity is routine and meaningful to how the business operates; and who is responsible for assessing the risk and safeguarding the information involved.

The Rule does not read your marketing

A business can call itself a dealer, a broker, a processor, an accounting firm, or a service company and still need a serious activity review. The FTC's test looks at what you do, not at what you named yourself.

The stakes

Why the distinction matters

The Safeguards Rule is not a paperwork requirement. For covered institutions it requires a written information security program with administrative, technical, and physical safeguards appropriate to the organization's size and complexity, the nature and scope of its activities, and the sensitivity of the customer information it handles.

Which creates practical leadership questions. Who is designated to oversee the program? What written risk assessment identifies reasonably foreseeable internal and external risks? What safeguards are actually operating, as opposed to installed? Which service providers can reach customer information? What evidence exists of training, testing, vendor oversight, incident-response readiness, and program review? What has senior leadership actually received from the person responsible?

An organization can have good tools and still lack an evidence-backed program. It may run multi-factor authentication, secure cloud software, managed IT, and cyber insurance, and still be unable to show who owns the program, what risks were assessed, what vendors were reviewed, or what leadership was told and when.

Two different questions

"Do we have security tools?" and "Can we prove an accountable information security program is being governed and maintained?" are not the same question. Most organizations can answer the first one immediately and the second one not at all.

Triggers

Activities that should prompt a closer review

These examples do not create legal conclusions. They are practical triggers for a fact-specific review.

Arranging or facilitating consumer financing

A business may warrant further analysis if it helps customers apply for financing, transmits credit applications, works with lenders, leases vehicles, presents financing options, or otherwise plays a material role in a consumer finance process. An auto dealer may submit a buyer's credit application to third-party lenders without originating the loan itself. Its role in collecting, transmitting, storing, and supporting that process still deserves careful review.

The question to put to your teamWhen a customer applies for financing, can we map every person, system, vendor, lender portal, email inbox, and paper file that receives or accesses the information?

Mortgage brokerage and loan origination

Brokers, originators, processors, and related firms work directly with borrower financial records, tax documents, bank statements, income information, credit records, applications, lender portals, and technology vendors. The practical issue is rarely whether sensitive data exists. It is whether the organization can identify program ownership and demonstrate how borrower information is governed end to end.

The question to put to your teamWho can show leadership the written program, the risk assessment, the vendor oversight records, and the evidence of safeguards around borrower information?

Tax preparation and accounting

These firms receive taxpayer identification details, income records, bank information, payroll data, returns, business financials, and portal uploads. Coverage remains fact-specific. From a governance standpoint the firm should still understand where client financial information enters, where it lives, who can reach it, which providers support it, how it is protected, and how that work is documented.

The question to put to your teamCan we identify every platform, file location, employee role, outside provider, and process that accesses taxpayer or client financial information?

Other activities worth examining

Official sources and legal analyses commonly identify nonbank activities such as mortgage lending or brokering, finance company operations, payday lending, wire transfers, check cashing, debt collection, retail credit card activity, certain vehicle leasing, real estate settlement services, credit counseling, and certain tax preparation or accounting services as examples that may warrant analysis.

The point is not that every business in these categories is covered. It is that a conclusion reached from an industry label alone is not a conclusion at all.

Jurisdiction

Banks, insurers, and SEC-regulated firms

The FTC Safeguards Rule applies to financial institutions under FTC jurisdiction. Some financial institutions answer to other federal regulators, which can determine whether the FTC's version of the Safeguards Rule is the applicable federal framework at all.

This is a significant reason not to settle coverage from a single internet checklist. The organization has to consider what financial activities it performs, whether it is significantly engaged in them, whether those activities involve consumers and customer information, which regulator has jurisdiction, whether an exemption or another framework applies, and what its actual operational facts are.

If the answer is unclear, treat it as a legal and governance review question rather than a guess.

Worth saying plainlyThe first outcome of a responsible Safeguards review is usually clarity, not a predetermined answer that happens to match what someone is selling.
The evidence request

What leadership should investigate now

Once leadership concludes the business may be engaged in relevant financial activity, gather facts before buying technology, downloading a template, or assuming the IT provider resolved it.

Review areaWhat to investigateEvidence to locate
Business activityWhat financial or incidental financial activities do we perform?Service descriptions, workflows, financing agreements, customer journey maps
Customer informationWhat financial information do we receive, use, store, transmit, or dispose of?Intake forms, applications, data inventory, retention schedule
Information flowWhere does the information travel?Data flow map, system inventory, cloud storage inventory, portal list
AccountabilityWho owns the program?QI designation, job description, responsibility matrix
Written programWhat information security program exists?Current WISP, policy inventory, review dates
Risk managementWhat risks have been assessed and addressed?Written risk assessment, remediation plan, risk register
Service providersWhich vendors touch customer information?Vendor inventory, contracts, security reviews, due diligence records
Leadership oversightWhat does leadership know and approve?Reports, meeting minutes, approval records, action tracker

This does not replace legal review or a formal security assessment. It moves leadership from assumption to evidence, which is the only move that matters at this stage.

Corrections

Five common misconceptions

"We are not a bank."

You may well not be. But the definition is activity-based, so that fact alone does not resolve anything. What does the business actually do, and how does it handle customer financial information?

"We do not make loans ourselves."

Origination is not the only activity that can matter. Arranging financing, facilitating applications, or transmitting information to lenders may each require a closer look.

"Our IT provider handles cybersecurity."

They may do important technical work. That does not answer who has been designated to oversee the program, whether the risk assessment is current, whether vendors are overseen, or whether leadership receives reporting.

"We have a WISP, so we are finished."

A WISP is one component. Leadership should also be able to demonstrate ownership, risk assessment, safeguards, training, monitoring, vendor oversight, testing, adjustment, reporting, and retained evidence.

"We only have a small number of clients."

Size shapes the program and can lift specific written requirements. Under 16 CFR §314.6, organizations maintaining information on fewer than 5,000 consumers are exempt from four of them. It does not remove the need for a fact-based review, and it never touches service-provider oversight or the notification duty.

Questions

Frequently asked

Is every company that handles financial information a financial institution under the Rule?

No. Handling financial information is an important fact but does not by itself establish coverage. The definition turns on whether the organization is significantly engaged in financial activities or activities incidental to them, together with its jurisdictional circumstances.

Does an auto dealer qualify?

A dealer may require analysis where it arranges financing, handles credit applications, leases vehicles, transmits customer information to lenders, or engages in other relevant financial activities. The answer depends on actual operations and legal context.

Are mortgage brokers financial institutions under the Rule?

Brokers and similar businesses are often directly involved in consumer financial activity and routinely handle borrower financial information. They should conduct a fact-specific review of their obligations and the regulatory framework that applies to them.

Do tax and accounting firms need to think about this?

Yes. These firms handle highly sensitive financial information and may perform activities requiring closer analysis. Even before a coverage conclusion, they should map information flow, identify accountable owners, and review their governance evidence.

Is our managed service provider automatically the Qualified Individual?

Not automatically. A Qualified Individual may be an employee, an affiliate, or a service provider. Where the role sits outside the organization, 16 CFR §314.4(a)(2) contemplates that a senior member of your own personnel is designated to direct and oversee that person, and that responsibility for compliance remains with your organization.

Where to start

Find out where your evidence stands

Twenty-one questions, about six minutes, mapped to 16 CFR Part 314. It tells you as much about what you are exempt from as about what you owe.

Check where you stand How engagements work
A.V. Señero, Founder and Governance Evidence Translator of FID Governance LLC

A.V. Señero is Founder and Governance Evidence Translator™ of FID Governance LLC, the Sacramento firm behind PaperTrailProof™. He serves as a designated Qualified Individual under 16 CFR §314.4(a) and educates organizations that collect consumers' financial information on FTC Safeguards Rule accountability, WISP governance, and the evidence required to show an information security program is actually operating.

Leadership is the disciplined allocation of attention toward reducing uncertainty through evidence.

A.V. Señero · FID Governance LLC · Sacramento, California
linkedin.com/in/av-senero-papertrailproof · papertrailproof.com

Disclosure. FID Governance LLC receives compensation from the technology partner whose platform it places clients on. It takes no fee of any kind on independent testing under §314.4(d)(2). Full compensation disclosure.

Educational notice. This material is educational and describes governance methodology. It is not legal advice, does not establish an attorney-client relationship, does not determine whether the FTC Safeguards Rule applies to any particular organization, and does not guarantee regulatory or cybersecurity outcomes. Coverage depends on an organization's specific activities and facts. Consult qualified legal counsel for legal determinations.

Primary sources. 16 CFR Part 314 (Standards for Safeguarding Customer Information) · 16 CFR §314.2 (Definitions) · 12 U.S.C. §1843(k) · FTC staff business guidance for financial institutions.