The written security program the FTC expects a “financial institution” to have
Mortgage brokers, insurance agencies and lenders sit squarely inside the FTC Safeguards Rule’s definition of a financial institution — most have never been told. What the Rule asks for, and how to produce the written program without a security team.
Usually a carrier renewal asking for a written information security program, an E&O policy tightening its questions, or a larger underwriting partner asking how client financial data is protected.
What the engine actually produced for one real business of this kind — including the gaps, which it states with a remediation clause rather than leaving out.
What tends to be true of firms like yours.
The Rule’s definition is broader than “bank”
The FTC’s definition of a financial institution covers businesses significantly engaged in financial activities — which routinely includes mortgage brokers, insurance agents and brokers, and consumer lenders, not just depository banks. Most firms this size find out by accident, which is exactly the gap this segment exists for.
It asks for more than a document
A written program, yes — but also a named Qualified Individual responsible for it, access controls, encryption, multi-factor authentication for anyone reaching customer information, secure disposal, service-provider oversight, and staff training. Your documents name each of these and who owns it, so you can see what is still outstanding.
Size changes what applies
A firm holding information on fewer than 5,000 consumers is relieved of several elements — the written risk assessment, penetration testing, the written incident response plan, and the annual report — but not of the Rule itself. Firms get this wrong in both directions, and it is worth five minutes to establish which side you are on.
There is a 30-day federal clock
A security event involving the unencrypted customer information of 500 or more consumers has to be reported to the FTC within 30 days of discovery. That is shorter than most state deadlines and runs independently of them, so it goes in your incident response plan explicitly.
Whether the Safeguards Rule applies to your firm is a legal determination for you and your counsel. Coverwright produces the documentation the Rule asks a covered firm to hold; holding it is not the same as being compliant with the Rule, and your documents say so.