AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

FTC Safeguards Rule: The CPA, the Car Dealer and the Tax Preparer Are All Financial Institutions Now

The FTC Safeguards Rule covers CPAs, dealers with in-house financing and tax preparers. What a WISP is, who the qualified individual is, and the 30-day notice.

Sam KhanSam Khan The Cyber ExpertFounder and CEOSeptember 2, 2026 · 6 min read

The wrong customer gets the right file

The office manager of a family used-car dealership in Tulsa has been there nineteen years. Fourteen employees, in-house financing for about a third of the cars, a filing cabinet of credit applications with Social Security numbers and pay stubs, and the same dealer management system since 2016.

On a Friday she emails a customer his finance paperwork. Autocomplete picks the wrong Michael. The other Michael, who bought a truck in March, replies twenty minutes later: "I think this went to the wrong person. There's someone's Social in here."

She apologizes, asks him to delete it, and he says he will. She believes him. It is a small town. Then she wonders, for the first time, whether she is supposed to tell anyone.

The following Monday the dealership's floor-plan lender sends its annual compliance questionnaire. Question four asks for the name of the dealership's qualified individual under the FTC Safeguards Rule. Question five asks for a copy of the written information security program. She has never heard the first phrase. She takes the second one to the owner, who has run the dealership since his father retired, and he asks the reasonable question: since when is a car lot a financial institution?

Since before the dealership bought its first computer, as it turns out, and with teeth since June 2023. Nobody told them, because nobody sells compliance to a used-car lot. They sell it to banks.

What the heck does this mean

The Safeguards Rule is a Federal Trade Commission regulation under the Gramm-Leach-Bliley Act that requires non-bank "financial institutions" to protect customer information. Banks have their own regulators. Everyone else who handles money on behalf of consumers gets the FTC.

A financial institution, in the rule's sense, is any business significantly engaged in financial activities: dealers who arrange or provide financing, tax preparers, CPAs, mortgage brokers, payday lenders, collection agencies, and a long list of others who would never describe themselves that way.

A WISP is a written information security program, the document the rule requires. It says what customer information you hold, who protects it, how, and what happens when something goes wrong. The IRS requires the same document from every tax professional, whatever the size of the practice.

The qualified individual is the named person who runs the program. The name is the point: the rule wants one person who cannot say "I thought IT had it", and the owner's name works fine.

The 30-day notice is the newest piece. Since May 2024, a breach affecting 500 or more consumers must be reported to the FTC within 30 days of discovery. The wrong-Michael email is one consumer; write it down anyway, and fix the pattern.

The numbers that matter

The Safeguards Rule has been enforceable since 9 June 2023, and the amendment requiring notice to the FTC within 30 days of a breach affecting 500 or more consumers took effect in May 2024, per the Federal Trade Commission's 2023 and 2024 rulemakings. The grace period has been over for three years.

IRS Publication 4557 requires every tax professional to maintain a written information security program regardless of size, per the IRS's guidance as it stands for the 2026 filing season. The sole preparer working from a spare bedroom is covered, and so is the 40-person CPA firm.

Business email compromise accounted for roughly $3 billion in reported losses in 2025, according to the FBI IC3 2025 Annual Report. A dealership that emails credit applications and wires lender payoffs is the exact target that number describes.

What to do this week

  1. Name the qualified individual in writing, and if the technical work is outsourced, name the inside person who supervises it. One sentence on letterhead, signed by the owner, dated. The lender's question four is now answered. (CIS 6 Access Control Management)
  2. Find the customer information. Credit applications in the DMS, scanned IDs on the shared drive, pay stubs in email attachments, the filing cabinet, the finance manager's phone. List every place, and how long each item has sat there. (CIS 3 Data Protection)
  3. Put MFA on the DMS, email and every lender portal, and end the shared "finance" login today. The rule requires MFA for anyone accessing customer information, and the attacker who steals one password is counting on the shared one. (CIS 6 Access Control Management)
  4. Stop sending credit applications by email. Use the lender's portal, or an encrypted link, and turn on full-disk encryption on every laptop that leaves the building. The wrong Michael cannot open a link that was never sent to him. (CIS 3 Data Protection)
  5. List every vendor that touches customer information: the DMS provider, lender portals, the CPA, the shredding company, the IT firm. Get each one's security commitment in writing, and note who at the dealership reviewed it. (CIS 15 Service Provider Management)
  6. Write the WISP from what you found: eight pages, not eighty, with the incident steps included and the 30-day FTC notice on a named person's checklist. Then train everyone for twenty minutes on the wrong-Michael scenario. (CIS 17 Incident Response Management)

Where AccuSights fits

We write WISPs for businesses that did not know they needed one, in language a dealership or a tax office recognizes. Our assessment finds where the customer information actually is and what the rule requires for each place, and our team implements the controls at a reasonable rate: MFA, encryption, data loss prevention that stops the wrong-Michael email before it sends, scanning, and protection of the machines that hold the files. Take the three-minute Cyber Hygiene Test, then spend 15 minutes with an engineer who can also act as your qualified individual's technical backstop.

Questions people ask

Who is a qualified individual under the Safeguards Rule? The one named person responsible for running your information security program. The rule lets that person be an employee, an affiliate or an outside firm, but if you outsource it you still have to name someone inside the business who supervises the outsider and owns the result. For a 14-person dealership that is often the general manager or the office manager, backed by an IT or security partner who does the technical work.

Does the rule apply to businesses with under 5,000 customers? Yes. The rule applies to every non-bank financial institution regardless of size. Businesses that hold information on fewer than 5,000 consumers are relieved of a few of the written-document requirements, not of the safeguards themselves: the qualified individual, access controls, MFA, encryption, training and vendor oversight still apply, and so does the 30-day notice to the FTC for a breach of 500 or more consumers.

What is the penalty for non-compliance? The FTC does not publish a fee schedule the way a card brand does. Its tool is an enforcement order, which can bind a business to years of outside assessments and public reporting, and a public complaint that customers, lenders and licensing boards read. The sharper penalty for a dealer, CPA or tax preparer is the lender or the IRS asking for the WISP and the qualified individual's name, and getting silence.

You became a financial institution the day you took the first credit application. The rule has just been waiting for you to notice.

Controls this post maps to

CIS 6 Access Control ManagementCIS 3 Data ProtectionCIS 15 Service Provider Management

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.