Frameworks

GLBA Safeguards Rule

The FTC's security rule for anyone touching consumer financial data — broader than you think.

Book a demo

The Gramm-Leach-Bliley Safeguards Rule requires 'financial institutions' — a definition covering lenders, advisors, fintechs, even higher-ed financial aid offices — to run a documented information security program with named accountability, encryption, MFA, and vendor oversight.

The 2023-era rule is prescriptive

The updated rule names its expectations: a qualified individual accountable for the program, written risk assessment, encryption of customer information, MFA, secure disposal, continuous monitoring or annual pen testing, vendor oversight, and incident reporting to the FTC for breaches affecting 500+ consumers.

How Compriska helps

Compriska structures the written program: risk assessment feeding the register, each safeguard an owned control with evidence, vendors tracked with contractual security obligations, and reporting timelines managed in incident workflows.

Frequently asked questions

Is our fintech a 'financial institution' under GLBA?

If you're significantly engaged in financial activities — lending, advising, processing, servicing — very likely yes. The FTC's definition is intentionally broad; assume in-scope and verify with counsel.

Other frameworks

Automate GLBA with Compriska

See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.

Book a demo