Skip to content

GLBA

GLBA Safeguards Rule Information Security Checklist

A Safeguards Rule checklist for written program, risk assessment, access controls, encryption, and qualified individual.

Estimated time
3–8 Months
Audience
US Financial Institutions and Fintechs under FTC/Banking Agencies
Last updated

Operational reference for GLBA Safeguards readiness. FTC and federal banking agencies enforce; this is not legal advice.

Progress0% Completed

Progress is saved in this browser only. Nothing is sent to a server.

Phase 1: Program

Phase 2: Controls

Phase 3: Test & Train

Phase 4: Evidence

FAQ

Who is a financial institution under GLBA?+

A defined term—banks, and many non-banks that provide financial products. Fintechs should confirm with counsel.

FTC vs banking agencies?+

Non-bank financial institutions often fall under the FTC Safeguards Rule; banks have parallel agency guidelines.

Does SOC 2 cover GLBA?+

SOC 2 evidence helps. GLBA has specific program and reporting elements.

Is MFA required?+

The FTC Safeguards Rule requires MFA for individuals accessing customer information, with limited exceptions.

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer