Frameworks
FTC Safeguards and NY DFS, assessed in days
The US financial regulations reach a lot of companies that do not think of themselves as financial institutions — and the deadlines have already passed. We assess you against the rule that applies and hand back a gap report and a plan.
“Financial institution” is broader than it sounds
Under the Gramm-Leach-Bliley Act the term covers businesses significantly engaged in activities that are financial in nature — which takes in a great many firms that hold customer financial information without holding a banking licence.
Non-banking financial institutions
Lenders and mortgage brokers, motor dealers arranging finance, tax preparers, collection agencies, investment advisers, wire transfer and payment businesses. The label follows the activity, not the licence.
Fintech and service providers
If you process, store or transmit customer financial information on behalf of one of the above, the obligation reaches you through their service provider oversight — which is itself one of the rule’s required elements.
Anyone licensed in New York
A separate and stricter regime. If you hold a licence or registration under New York banking, insurance or financial services law, Part 500 applies directly and carries an annual filing.
Two rules, with different teeth
They overlap substantially in content and differ entirely in how compliance is proven. Assessing against one gets you most of the way to the other, which is the practical reason to do both at once.
- 01
The FTC Safeguards Rule
A written information security programme with nine required elements: a qualified individual to run it, a written risk assessment, access controls, an inventory of data and systems, encryption, secure development, multi-factor authentication, disposal procedures, change management, and monitoring of authorised users — plus testing, training, service provider oversight, an incident response plan, and an annual report to your board.
- 02
NY DFS Part 500
A cybersecurity programme and policy, a designated CISO, penetration testing and vulnerability assessment, audit trails, access privileges, risk assessment, training, encryption, and an incident response plan — with incident reporting to the superintendent on a 72-hour clock and an annual certification signed at senior level. The 2023 amendments added requirements that phased in through 2025.
- 03
FFIEC expectations
For firms examined by federal banking agencies, the interagency examination guidance sets what an examiner expects to see. We assess against the current expectations rather than against a retired self-assessment tool.
Four steps, and a few hours of your time
The point of a fixed-scope assessment is that it does not consume the team it is assessing.
- 01
Scoping call
About an hour. Which rule applies to you and why, what customer information you hold, and what you have already been asked to attest to.
- 02
Assessment
A structured questionnaire against the applicable rule, completed with the people who run the systems rather than sent to a mailbox.
- 03
Gap report and plan
A few business days. Findings element by element, a remediation plan with effort and priority, and a posture report management can act on.
- 04
Debrief
A working session on sequencing — and, where an annual certification is due, on what has to be true before somebody signs it.
We assess. You certify
The Safeguards Rule involves no filing and no certificate: you have to be able to prove compliance when asked. Part 500 does require an annual certification, and it is signed by your own senior officer — not by an adviser. We can tell you whether the evidence supports that signature; we cannot provide it.
We deliver the gap assessment and the remediation plan. The changes inside your systems are executed by your team or your provider, and hands-on remediation is scoped separately if you want it.
We are not your legal advisers. Whether a particular business activity brings you inside the definition of a financial institution is a question for counsel, and we will say so when you reach that line rather than guessing on your behalf.
An attestation due, and nobody sure it is true?
Tell us which rule you are being held to. We will tell you where you stand against it and what closing the gap involves.