ValaisOS tool · runs in your browser

FTC Safeguards Rule path for state-registered advisers

Which parts of the FTC Safeguards Rule apply to my state-registered advisory firm, and what is still missing?

A state-registered investment adviser is a financial institution under the FTC Safeguards Rule (16 CFR part 314), not a covered institution under the SEC's Regulation S-P. The Safeguards Rule requires a written information security program with named elements in 16 CFR 314.4: a qualified individual, a risk assessment, specific safeguards including multi-factor authentication and encryption, testing, training, service-provider oversight, an incident response plan, an annual report, and notice to the FTC within 30 days of discovering a notification event involving 500 or more consumers. Firms holding information on fewer than 5,000 consumers are exempt from four of those elements under 16 CFR 314.6. This page sorts a firm's answers into in place, gap, and exempt, with the citation and the next action for each, and prints as a worksheet. Nothing you enter leaves your browser.

Key facts

  • An investment advisory company is a financial institution under the FTC Safeguards Rule (16 CFR 314.2(h)(2)(xii)), and the rule reaches the financial institutions over which the FTC has enforcement jurisdiction under the Gramm-Leach-Bliley Act (314.2(s)), which is where a state-registered adviser sits.
  • 16 CFR 314.4 lists the elements of the required information security program in paragraphs (a) through (j): qualified individual, risk assessment, safeguards, testing, training, service providers, evaluation, incident response plan, annual report, and FTC notification.
  • Multi-factor authentication is required for any individual accessing any information system unless the qualified individual approves an equivalent or stronger control in writing (314.4(c)(5)), and customer information must be encrypted in transit over external networks and at rest (314.4(c)(3)).
  • A firm maintaining customer information on fewer than 5,000 consumers is exempt from 314.4(b)(1), (d)(2), (h), and (i) under 16 CFR 314.6.
  • A notification event involving the information of at least 500 consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery (314.4(j)); discovery is the first day the event is known to any employee, officer, or agent other than the person committing it.

Answer for your firm

Fourteen questions. The worksheet sorts each element of 16 CFR 314.4 into in place, gap, or exempt as you answer. Everything happens in your browser; nothing is stored or sent.

Optional; appears on the printed worksheet.

1. How many consumers does the firm hold customer information about?

Count every individual whose nonpublic personal information the firm holds, including former clients and prospects who provided information, not only current households.

2. Has the firm designated a qualified individual to oversee the information security program?
3. Has the firm performed a risk assessment of its customer information and systems?
4. Are access controls in place that limit each user to the customer information they need?
5. Does the firm maintain an inventory of the data, devices, systems, and people that handle customer information?
6. Is customer information encrypted in transit over external networks and at rest?
7. Is multi-factor authentication required for every individual accessing any information system?
8. Does the firm have procedures to dispose of customer information no later than two years after its last use, unless retention is required?
9. Does the firm monitor and log the activity of authorized users to detect unauthorized access?
10. How does the firm test the effectiveness of its safeguards?
11. Do personnel receive security awareness training that reflects the firm's risks?
12. Are service providers that receive customer information required by contract to maintain safeguards, and assessed periodically?
13. Does the firm have a written incident response plan?
14. Does the qualified individual report in writing at least annually to the governing body or a senior officer?

What the worksheet does not decide

  • Whether the FTC rule or a state regulator's rule governs the firm. State-registered advisers answer to their state securities regulator, and many states have adopted their own cybersecurity requirements that sit alongside the federal rule.
  • Whether a particular control is adequate. The rule requires safeguards appropriate to the firm's size, complexity, and the sensitivity of the information; the worksheet records whether each element exists, not whether it is sufficient.
  • Notice to affected individuals after a breach. The Safeguards Rule's notification runs to the FTC; notice to clients comes from state breach-notification laws, which vary by state and by where each client lives.
  • Whether a vendor is a service provider. The service-provider inventory applies the definition, which the Safeguards Rule (16 CFR 314.2(r)) states in nearly the same words as Regulation S-P.

Questions

Does Regulation S-P apply to a state-registered adviser?

No. Regulation S-P's safeguards and breach-notification provisions apply to SEC-registered investment advisers, brokers, dealers, funding portals, and registered investment companies. An adviser registered only with a state is a financial institution under the FTC's jurisdiction and follows the FTC Safeguards Rule, 16 CFR part 314, plus its state's own rules.

What does the small-firm exemption cover?

Under 16 CFR 314.6, a financial institution that maintains customer information on fewer than 5,000 consumers is exempt from the written risk assessment (314.4(b)(1)), the continuous monitoring or annual penetration testing and semiannual vulnerability assessment requirement (314.4(d)(2)), the written incident response plan (314.4(h)), and the annual written report (314.4(i)). Every other element still applies, including multi-factor authentication, encryption, training, and service-provider oversight.

When must a state-registered adviser notify the FTC of a breach?

When a notification event, the unauthorized acquisition of unencrypted customer information, involves the information of at least 500 consumers, the firm must notify the FTC as soon as possible and no later than 30 days after discovery (16 CFR 314.4(j)). The notice is filed on the FTC's form. Notice to affected individuals comes from state breach laws, which the Safeguards Rule does not displace.

Does this page store my answers?

No. The answers are used only in your browser to sort the elements and build the worksheet. Nothing is transmitted, saved, or measured. Print the worksheet before leaving the page.

Primary sources

General information from ValaisOS LLC, not legal, compliance, tax, or investment advice. Confirm requirements for your firm with counsel. See Terms of Use.

ValaisOS is building a more enduring operating foundation for private-wealth professionals.

Request early access