16 CFR §314.4

Nine program elements, plus one thing that is not an element.

You will see this described as "the ten elements" in a lot of vendor material. That framing quietly misses something worth understanding, and the distinction matters the first time anything goes wrong.

The program

The nine elements at §314.4(a) through (i)

These are the components of the information security program itself. Each one has a record behind it, or it does not exist in any way you could demonstrate. The question worth carrying into your own organization is not whether you do these things. It is who holds the record that shows you do.

§314.4(a)

Designate a Qualified Individual

Someone must be named, in writing, to oversee and enforce the program. That person can be an employee, an affiliate, or a service provider. If the role sits outside your organization, you must still designate a senior member of your own personnel to direct and oversee them, and the responsibility for compliance stays with you. That last clause is the one most organizations cannot produce a record for.

§314.4(b)

Conduct a written risk assessment

A documented assessment of reasonably foreseeable internal and external risks to customer information, with criteria for evaluating those risks and for assessing the safeguards you put against them. Written is the operative word.

§314.4(c)

Design and implement safeguards

The technical and physical controls: access controls, an inventory of where data lives, encryption in transit and at rest, secure development, multi-factor authentication, secure disposal, change management, and logging of authorized user activity.

§314.4(d)

Test and monitor those safeguards

Regular testing or monitoring of the effectiveness of the controls. Where you do not have continuous monitoring in place, this means annual penetration testing plus vulnerability assessments at least twice a year.

§314.4(e)

Train your people

Security awareness training for personnel, with qualified staff for security work and steps to keep them current on changing threats. Completion records are the evidence here.

§314.4(f)

Oversee your service providers

Select providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess them based on the risk they present. This one is never exempt at any size, and it is where dealer-facing FTC staff guidance has focused most recently.

§314.4(g)

Keep the program current

Evaluate and adjust the program in light of testing results, material changes to your operations, or anything else with a material bearing on it. A program written once and never revisited is the failure pattern the FTC keeps describing.

§314.4(h)

Establish a written incident response plan

A documented plan for responding to a security event affecting customer information: goals, internal processes, roles and responsibilities, communications, remediation, documentation and reporting, and a post-event review.

§314.4(i)

Report to your board or senior officer

At least annually, the Qualified Individual reports in writing on the overall status of the program, compliance, and material matters: risk assessment, risk management decisions, service provider arrangements, testing results, security events and management's response, and recommendations for change.

Not a tenth element

§314.4(j) is an event-triggered reporting duty, not a program component. Covered financial institutions must notify the FTC as soon as possible, and no later than 30 days after discovery, of a notification event involving the unauthorized acquisition of unencrypted customer information of at least 500 consumers.

Two things follow from that. The §314.6 exceptions never touch it, so it applies at every size. And discovery is treated as the date the event became known to any employee, officer, or agent other than whoever caused it, which means the clock can already be running before leadership hears anything. That is why the useful question is not whether you have a plan, but who is named in writing as the person who decides whether the clock has started.

The exception

Four of the nine lift below 5,000 consumers

Under 16 CFR §314.6, an organization maintaining information on fewer than 5,000 consumers is exempt from four written requirements: the written risk assessment at (b)(1), the penetration testing and vulnerability assessment regime at (d)(2), the written incident response plan at (h), and the annual written report at (i).

Everything else still applies. Service-provider oversight at (f) is never exempt. Neither is the notification duty at (j).

This is the part that tends to surprise people, and it is the reason we tell organizations what they are exempt from before we tell them anything else. A meaningful number of businesses are sitting in the exempt class and buying as though they are not.

Where to start

Which of these can you actually produce?

Twenty questions, about six minutes. It tells you as much about what you can skip as about what you need.

Check where you stand How engagements work