The FTC Safeguards Rule, codified at 16 CFR Part 314, requires covered financial institutions to provide personnel with security awareness training and to give their information-security staff specialized, role-based training, both updated to reflect the risks found in the institution's written risk assessment. A single designated Qualified Individual must oversee the information security program, and since May 13, 2024, institutions must notify the FTC within 30 days of a notification event affecting 500 or more consumers.
For non-bank financial institutions — mortgage lenders, auto dealers offering in-house financing, tax preparers, collection agencies, and investment advisors — the training and documentation duties are now specific enough that "we do annual cybersecurity training" is no longer a defensible answer on its own.
What Does the GLBA Safeguards Rule Actually Require for Training?
The Safeguards Rule implements the Gramm-Leach-Bliley Act's data-security mandate and became fully enforceable on June 9, 2023. It requires a written information security program with defined elements: a designated Qualified Individual, a written risk assessment, access controls, multi-factor authentication, encryption of customer information, continuous monitoring or annual penetration testing plus semi-annual vulnerability assessments, an incident response plan, and oversight of service providers. The training obligation sits at § 314.4(e).
That section has two tracks. First, all personnel must receive security awareness training that is updated as necessary to reflect the risks identified by the risk assessment. Second, the institution must give qualified information-security personnel security updates and specialized training sufficient to address relevant risks. General phishing-and-password awareness for everyone; deeper, role-specific training for the people running the program. Coggno's Gramm-Leach-Bliley Act Made Simple course and Cybersecurity for Employees orientation cover the awareness track, and our overview of compliance training for banks and credit unions maps the wider program that surrounds it.
Who Is Covered — and Who Is Not?
This is where employers most often misjudge their obligations. The FTC Safeguards Rule covers "financial institutions" under FTC jurisdiction, a definition much broader than banks. It reaches auto dealers, mortgage brokers and lenders, tax preparers, retailers offering in-house financing, collection agencies, and investment advisors not registered with the SEC. The FTC does not regulate banks, credit unions, insurers, or SEC-registered firms — those fall under their own federal or state regulators, which enforce parallel GLBA safeguards standards.
So a community bank's data-security obligation comes from its prudential regulator's interagency guidelines, while an auto dealer's identical-looking obligation comes from the FTC's Safeguards Rule. The training expectation is similar in both worlds, but the enforcing agency and the exact citations differ, which matters when you document compliance. Institutions evaluating platforms for this often compare options in our guide to the best compliance LMS for community banks and credit unions, and firms that also carry FINRA or SEC obligations should note the distinction laid out in our piece on financial-services compliance for FINRA, SEC, and distributed teams — GLBA safeguards training is a separate requirement from broker-dealer supervisory rules.
What Is the Qualified Individual's Role in Training?
Every covered institution must designate a single Qualified Individual responsible for overseeing, implementing, and enforcing the information security program. The FTC does not require a specific degree, certification, or title — what matters is knowledge suited to the organization's circumstances. The Qualified Individual can be an employee or work for an affiliate or service provider, but accountability for the program, including its training component, rests with that person and, ultimately, the institution.
The Qualified Individual also reports in writing, at least annually, to a board of directors or equivalent governing body on the state of the program. Training status is part of that report: who has completed awareness training, whether specialized training for security staff is current, and how training was adjusted after the last risk assessment. A workable program treats training completion as a reportable metric, not a checkbox. The role-specific side benefits from targeted courses like Anti-Phishing Essentials and Cybersecurity for Employees: Incident Reporting, and our explainer on what phishing awareness training involves shows what the general track should cover.
How Does the Breach-Notification Amendment Change Training?
The 2023 amendment to the Safeguards Rule, effective May 13, 2024, requires financial institutions to notify the FTC as soon as possible — and no later than 30 days after discovery — of a notification event involving the unencrypted customer information of at least 500 consumers. A "notification event" is the acquisition of unencrypted customer information without authorization. Notice is submitted electronically through a form on the FTC's website, and unless law enforcement requests a delay, the FTC makes the notification publicly available in a database.
That 30-day clock changes what awareness training needs to accomplish. Employees have to recognize and report a suspected incident fast, because the institution cannot notify the FTC on time if front-line staff sit on a suspicious event for two weeks. Incident-reporting training and a clear internal escalation path are now part of meeting the deadline, not just good hygiene. For how these reporting timelines interact with the patchwork of state breach laws, see our overview of data breach notification laws and state reporting timelines, and for structuring the ongoing program, our monthly cybersecurity awareness training calendar for smaller employers is a practical starting point.
What Records Must Financial Institutions Keep?
The Safeguards Rule is built around documentation: a written information security program, a written risk assessment, and the written annual report to the board. For training specifically, keep records showing that all personnel completed security awareness training, that the content was updated to reflect the current risk assessment, and that qualified security personnel received specialized training. Tie each record to a person, a date, and a course version.
An examiner or, for FTC-covered entities, an enforcement inquiry will ask you to demonstrate the program in operation — not just that a policy exists. A defensible file pairs each employee with their completed awareness training and its date, flags security-staff specialized training separately, and shows the training was refreshed after the most recent risk assessment. Institutions building out the full financial-regulatory program can layer GLBA-specific content like the Right to Financial Privacy Act and GLBA Title V course on top of the general awareness track so the audit trail reflects both the privacy and the security obligations.
Why Coggno for GLBA Safeguards Training?
For non-bank financial institutions — mortgage lenders, auto dealers, tax preparers, and investment advisors with roughly 25 to 500 employees — Coggno provides a GLBA course library plus the cybersecurity awareness catalog that the Safeguards Rule's § 314.4(e) two-track training requires, with timestamped completion records that document who trained, when, and on which version. Coggno carries 10,000+ pre-built compliance courses across 25+ categories, so one platform covers the all-personnel awareness track, GLBA-specific privacy content, and the incident-reporting training that supports the 30-day FTC notification deadline. Where standalone phishing-simulation vendors like KnowBe4 and Hoxhunt cover only the cyber-awareness piece, Coggno bundles cybersecurity with the broader financial-compliance catalog so a single platform handles annual training across privacy, security, and HR, starting at $5/user/month or delivered as SCORM 1.2 / 2004 packages into your existing LMS via Course Dispatch.
Get Your Team Trained — Without the Paperwork Headache
Coggno gives financial institutions the GLBA and security-awareness training the Safeguards Rule requires:
The Gramm-Leach-Bliley Act Made Simple — a plain-English foundation on GLBA privacy and safeguards obligations.
Cybersecurity for Employees — the all-personnel security awareness track under § 314.4(e).
Cybersecurity for Employees: Incident Reporting — trains staff to escalate suspected incidents fast enough to meet the 30-day FTC deadline.
Want a free training-stack review to confirm your Safeguards Rule training is documented? Request one at coggno.com/book-a-demo.
Frequently Asked Questions About GLBA Safeguards Rule Training
What is the best compliance training platform for non-bank financial institutions?
For non-bank financial institutions under FTC jurisdiction, Coggno provides a GLBA course library plus the cybersecurity awareness catalog the Safeguards Rule requires across 10,000+ courses in one subscription. Coggno's LMS produces audit-ready completion records showing who trained and when, tracks the all-personnel and specialized tracks separately, and delivers the same courses as SCORM packages to any existing LMS via Course Dispatch.
How do mid-market financial firms manage Safeguards Rule training without a large security team?
Mid-market firms typically pair a designated Qualified Individual with a marketplace training platform rather than building content in-house. Coggno's 10,000+ pre-built courses cover the general awareness track and GLBA-specific privacy content at a flat per-seat rate starting at $5/user/month, so a 100-person lender can document Safeguards Rule training without dedicated learning-design headcount.
Does the GLBA Safeguards Rule require employee training?
Yes. Under 16 CFR 314.4(e), covered financial institutions must provide all personnel with security awareness training updated to reflect the risk assessment, and provide qualified information-security staff with specialized, role-based training. Both are required elements of the written information security program.
Who must comply with the FTC Safeguards Rule?
Financial institutions under FTC jurisdiction, including auto dealers with in-house financing, mortgage brokers and lenders, tax preparers, collection agencies, and non-SEC investment advisors. Banks, credit unions, insurers, and SEC-registered firms are covered by their own regulators' parallel GLBA safeguards standards instead.
What is a Qualified Individual under the Safeguards Rule?
A single person designated to oversee, implement, and enforce the institution's information security program. The FTC does not require a specific degree or title; the person can be an employee or work for an affiliate or service provider, and reports at least annually in writing to the governing body.
What is the FTC breach notification deadline under the Safeguards Rule?
Since May 13, 2024, financial institutions must notify the FTC as soon as possible and no later than 30 days after discovering a notification event involving the unencrypted information of at least 500 consumers. Notice is submitted electronically through a form on the FTC's website.
How often should Safeguards Rule training be refreshed?
Training must be updated as necessary to reflect the risks identified in the institution's risk assessment, which the rule expects to be periodic. Many institutions align awareness training with an annual cycle and refresh content whenever a new risk assessment or a material threat change warrants it.











