GLBA & FFIEC: Security Compliance for US Financial Services
If your business touches US consumer financial data — as a bank, lender, broker, insurer, or the fintech serving one — two acronyms shape your security obligations: GLBA, the law, and FFIEC, the examiners’ playbook. Here’s what each actually requires, and how to build one control set that satisfies both.
GLBA in one paragraph
The Gramm-Leach-Bliley Act (1999) requires “financial institutions” — defined broadly enough to catch payday lenders, mortgage brokers, tax preparers, higher-education institutions handling federal loans, and many fintechs — to protect customers’ non-public personal information (NPI). Its teeth are in two rules: the Privacy Rule (notices and opt-outs for information sharing) and the Safeguards Rule (an information-security programme). The FTC’s 2023 amendments added a third obligation: breach notification to the FTC within 30 days for incidents affecting 500+ consumers.
What the Safeguards Rule requires
| Requirement | What examiners look for |
|---|---|
| Qualified Individual | A named person accountable for the security programme, reporting to the board (annually, in writing). |
| Written risk assessment | Documented, criteria-based, and refreshed — not a one-off spreadsheet. |
| Access controls & MFA | MFA for anyone accessing customer information systems; least-privilege reviews. |
| Encryption | NPI encrypted in transit and at rest — or a documented, approved compensating control. |
| Secure development | Security built into in-house apps handling NPI; vendor software assessed. |
| Monitoring & testing | Continuous monitoring, or annual penetration testing plus semi-annual vulnerability scans. |
| Vendor oversight | Service providers selected, contracted and periodically reassessed on security. |
| Incident response plan | A written plan covering roles, decision-making, remediation and post-incident review. |
Where FFIEC fits
The Federal Financial Institutions Examination Council doesn’t write law — it writes the examination handbooks federal banking regulators (OCC, FDIC, Federal Reserve, NCUA) use when they walk through your door. The FFIEC IT Handbook’s Information Security booklet reads like a control framework: governance, risk identification, layered defences, monitoring, and service-provider management. If you’re examined by a banking regulator, FFIEC guidance is your de facto standard, and the (now-sunset) CAT is being replaced in practice by mappings to NIST CSF 2.0 and CISA performance goals.
One control set, both regimes
GLBA’s Safeguards Rule and FFIEC’s booklets overlap heavily with ISO 27001 and NIST CSF. The efficient play is to run one control library mapped across all of them: your MFA control satisfies the Safeguards Rule, the FFIEC access-management expectations, and ISO Annex A simultaneously — with one piece of evidence. That’s the crosswalk approach we’ve covered before, applied to financial services.
Quick self-check
- Can you name your Qualified Individual — and produce their last written board report?
- Is your risk assessment written, criteria-based, and less than 12 months old?
- Does every path to customer data enforce MFA — including vendors and admins?
- Could you notify the FTC within 30 days of discovering a 500+ consumer incident?
- Do vendor contracts include security requirements, and are reassessments actually happening?
Miss two or more of those and you have your remediation roadmap — in the order an examiner would find them.
Map GLBA, FFIEC and 70+ frameworks from one control set
Cyber Horizon crosswalks your controls across GLBA, FFIEC guidance, NIST CSF and ISO 27001 — one register, one evidence trail, every regime covered.
Book a Demo