Draft · internal validation

FTC Safeguards Rule

16 CFR Part 314 · Federal Trade Commission

Checks a written information security program against the administrative, technical and physical safeguard requirements in 16 CFR Part 314.

This pack is a draft.Every requirement traces to official text, but it has not had independent compliance or legal review. You can get a quote and aggregate policy pre-scan today; cited reports open after review.
Requirements55atomic checksCRITICAL11severityHIGH44severityWith official link55/55eCFR section URLRule effectiveMay 13, 2024current textPack version0.1.0-draft.1authored Sep 26, 2026

Requirements

Showing 8 of 55 · official summaries
16 CFR 314.3(a)

The institution maintains an accessible written information security program scaled to its circumstances and covering the required elements.

CRITICALeCFR
16 CFR 314.3(b)(1)

The program expressly treats security and confidentiality of customer information as an objective.

HIGHeCFR
16 CFR 314.3(b)(2)

The program addresses anticipated threats and hazards affecting customer information.

HIGHeCFR
16 CFR 314.4(a)

A specific Qualified Individual is designated with responsibility for oversight, implementation, and enforcement.

CRITICALeCFR
16 CFR 314.4(a)(1)

Using an affiliate or service provider as Qualified Individual does not transfer the institution's responsibility.

HIGHeCFR
16 CFR 314.4(a)(3)

The external Qualified Individual's organization is required to maintain a protective information security program.

HIGHeCFR
All 55 requirements are versioned in the draft pack. Full evidence and remediation guidance remain inside the product.