Most business owners who fall under the FTC Safeguards Rule do not think of themselves as financial institutions. That is the whole problem with it.
The rule applies to businesses "significantly engaged" in providing financial products or services to consumers, and the Federal Trade Commission reads that more broadly than the phrase suggests. Tax preparers and accounting firms. Auto dealers arranging financing. Mortgage brokers and lenders. Collection agencies. Real estate appraisers. Businesses that offer their own payment plans. Career counselors serving people in finance. Wire transfer services.
If your business touches consumers' financial information as part of what it does, the rule is worth reading rather than assuming it is about someone else.
The core obligation is a written information security program appropriate to your size and complexity. Not a policy binder bought off the shelf, and not an assurance that your IT provider handles security. A written program, tied to your actual systems and actual data.
Within it, the rule is specific about several things:
There is also a breach notification requirement: certain security events affecting consumer information have to be reported to the FTC.
Three reasons, in our experience.
The name. "Financial institution" sounds like it means a bank. A four-person CPA practice does not read that phrase and think of itself.
The written part. Plenty of businesses genuinely have decent security, including MFA, managed endpoints and backups, and no document that says so. The rule requires the program, not just the controls. Doing the right things without documenting them does not satisfy it.
The assumption that IT covers it. We handle a great deal of what the rule asks about technically. But the risk assessment reflects your business processes, the disposal schedule reflects your retention decisions, and the annual report goes to your governing body. A provider cannot own those, and any provider who tells you they can has not read it carefully.
We want to be direct about this line, because it is where a lot of businesses end up with a false sense of coverage.
We implement and operate technical controls: multi-factor authentication, encryption, access control, logging and monitoring, patching, secure configuration, backup and recovery. We can produce evidence that those controls exist and are working, which is usually the hardest part of an assessment to assemble.
The compliance obligation itself stays with you. The written program is your document. The qualified individual is your appointment. The decision about what is an acceptable risk is a business decision rather than a technical one. We support that work and we do not pretend to absorb it.
If you think the rule might apply and you have nothing written:
If you want the technical side assessed against what the rule asks for, meaning what is in place, what is missing, and what the evidence looks like, book a discovery call.
We are not attorneys and this is not legal advice. Whether the Safeguards Rule applies to your business is a question for your counsel. What we can tell you is whether your systems would stand up if the answer is yes.