Blog / US compliance
US compliance
FTC Safeguards Rule: The CPA, the Car Dealer and the Tax Preparer Are All Financial Institutions Now
The FTC Safeguards Rule covers CPAs, dealers with in-house financing and tax preparers. What a WISP is, who the qualified individual is, and the 30-day notice.
The wrong customer gets the right file
The office manager of a family used-car dealership in Tulsa has been there nineteen years. Fourteen employees, in-house financing for about a third of the cars, a filing cabinet of credit applications with Social Security numbers and pay stubs, and the same dealer management system since 2016.
On a Friday she emails a customer his finance paperwork. Autocomplete picks the wrong Michael. The other Michael, who bought a truck in March, replies twenty minutes later: "I think this went to the wrong person. There's someone's Social in here."
She apologizes, asks him to delete it, and he says he will. She believes him. It is a small town. Then she wonders, for the first time, whether she is supposed to tell anyone.
The following Monday the dealership's floor-plan lender sends its annual compliance questionnaire. Question four asks for the name of the dealership's qualified individual under the FTC Safeguards Rule. Question five asks for a copy of the written information security program. She has never heard the first phrase. She takes the second one to the owner, who has run the dealership since his father retired, and he asks the reasonable question: since when is a car lot a financial institution?
Since before the dealership bought its first computer, as it turns out, and with teeth since June 2023. Nobody told them, because nobody sells compliance to a used-car lot. They sell it to banks.
What the heck does this mean
The Safeguards Rule is a Federal Trade Commission regulation under the Gramm-Leach-Bliley Act that requires non-bank "financial institutions" to protect customer information. Banks have their own regulators. Everyone else who handles money on behalf of consumers gets the FTC.
A financial institution, in the rule's sense, is any business significantly engaged in financial activities: dealers who arrange or provide financing, tax preparers, CPAs, mortgage brokers, payday lenders, collection agencies, and a long list of others who would never describe themselves that way.
A WISP is a written information security program, the document the rule requires. It says what customer information you hold, who protects it, how, and what happens when something goes wrong. The IRS requires the same document from every tax professional, whatever the size of the practice.
The qualified individual is the named person who runs the program. The name is the point: the rule wants one person who cannot say "I thought IT had it", and the owner's name works fine.
The 30-day notice is the newest piece. Since May 2024, a breach affecting 500 or more consumers must be reported to the FTC within 30 days of discovery. The wrong-Michael email is one consumer; write it down anyway, and fix the pattern.
The numbers that matter
The Safeguards Rule has been enforceable since 9 June 2023, and the amendment requiring notice to the FTC within 30 days of a breach affecting 500 or more consumers took effect in May 2024, per the Federal Trade Commission's 2023 and 2024 rulemakings. The grace period has been over for three years.
IRS Publication 4557 requires every tax professional to maintain a written information security program regardless of size, per the IRS's guidance as it stands for the 2026 filing season. The sole preparer working from a spare bedroom is covered, and so is the 40-person CPA firm.
Business email compromise accounted for roughly $3 billion in reported losses in 2025, according to the FBI IC3 2025 Annual Report. A dealership that emails credit applications and wires lender payoffs is the exact target that number describes.
What to do this week
- Name the qualified individual in writing, and if the technical work is outsourced, name the inside person who supervises it. One sentence on letterhead, signed by the owner, dated. The lender's question four is now answered. (CIS 6 Access Control Management)
- Find the customer information. Credit applications in the DMS, scanned IDs on the shared drive, pay stubs in email attachments, the filing cabinet, the finance manager's phone. List every place, and how long each item has sat there. (CIS 3 Data Protection)
- Put MFA on the DMS, email and every lender portal, and end the shared "finance" login today. The rule requires MFA for anyone accessing customer information, and the attacker who steals one password is counting on the shared one. (CIS 6 Access Control Management)
- Stop sending credit applications by email. Use the lender's portal, or an encrypted link, and turn on full-disk encryption on every laptop that leaves the building. The wrong Michael cannot open a link that was never sent to him. (CIS 3 Data Protection)
- List every vendor that touches customer information: the DMS provider, lender portals, the CPA, the shredding company, the IT firm. Get each one's security commitment in writing, and note who at the dealership reviewed it. (CIS 15 Service Provider Management)
- Write the WISP from what you found: eight pages, not eighty, with the incident steps included and the 30-day FTC notice on a named person's checklist. Then train everyone for twenty minutes on the wrong-Michael scenario. (CIS 17 Incident Response Management)
Where AccuSights fits
We write WISPs for businesses that did not know they needed one, in language a dealership or a tax office recognizes. Our assessment finds where the customer information actually is and what the rule requires for each place, and our team implements the controls at a reasonable rate: MFA, encryption, data loss prevention that stops the wrong-Michael email before it sends, scanning, and protection of the machines that hold the files. Take the three-minute Cyber Hygiene Test, then spend 15 minutes with an engineer who can also act as your qualified individual's technical backstop.
Questions people ask
Who is a qualified individual under the Safeguards Rule? The one named person responsible for running your information security program. The rule lets that person be an employee, an affiliate or an outside firm, but if you outsource it you still have to name someone inside the business who supervises the outsider and owns the result. For a 14-person dealership that is often the general manager or the office manager, backed by an IT or security partner who does the technical work.
Does the rule apply to businesses with under 5,000 customers? Yes. The rule applies to every non-bank financial institution regardless of size. Businesses that hold information on fewer than 5,000 consumers are relieved of a few of the written-document requirements, not of the safeguards themselves: the qualified individual, access controls, MFA, encryption, training and vendor oversight still apply, and so does the 30-day notice to the FTC for a breach of 500 or more consumers.
What is the penalty for non-compliance? The FTC does not publish a fee schedule the way a card brand does. Its tool is an enforcement order, which can bind a business to years of outside assessments and public reporting, and a public complaint that customers, lenders and licensing boards read. The sharper penalty for a dealer, CPA or tax preparer is the lender or the IRS asking for the WISP and the qualified individual's name, and getting silence.
You became a financial institution the day you took the first credit application. The rule has just been waiting for you to notice.
Controls this post maps to
CIS Controls v8.1. These are the same controls our assessment scores and the console watches.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
The WISP a CPA Firm Can Write in a Week, Before the January Rush Starts
A CPA WISP for tax season: what the FTC Safeguards Rule and IRS Publication 4557 expect, the Security Six, and the PTIN attestation you already signed.
US complianceThe 2027 Cybersecurity Calendar for US Small Business: The Dates That Are Real, and the One Everybody Is Guessing About
A US cybersecurity regulatory calendar for 2027: the confirmed dates from January to December, which ones apply to a 40-person company, and what to do first.
US complianceNine Terminals, Five Stores, One Holiday Peak: PCI DSS 4.0.1 for Atlanta Retail
PCI DSS for multi-location retail in Atlanta: what 4.0.1 asks of nine terminals across five stores, and the six checks to finish before the holiday peak.
