Who the FTC Rule Covers

The FTC Safeguards Rule applies to financial institutions — a category that includes investment advisers, financial planners, and other businesses that provide financial advisory services to consumers. If you hold, collect, or access nonpublic personal financial information about individual clients, the rule applies to your firm.

This includes:

SEC/FINRA vs. FTC — Not the Same Requirement

This is the most important thing for advisers to understand: SEC Regulation S-P and FINRA Rule 4370 address privacy notices and business continuity. They do not satisfy the FTC Safeguards Rule requirement for a Written Information Security Plan.

These are separate regulatory regimes with overlapping but distinct requirements. An adviser who is fully compliant with Regulation S-P may still be out of compliance with the FTC Safeguards Rule — because S-P doesn't require a written information security program in the same way the Safeguards Rule does.

⚠️ "My firm is SEC-registered and compliant with Reg S-P" is not a defense to an FTC Safeguards Rule enforcement action. These are independent requirements.

Why Small RIAs Are Most at Risk

Large broker-dealers and RIAs typically have compliance departments, chief compliance officers, and legal counsel who have addressed the FTC Safeguards Rule. Small RIAs — particularly those under $110M AUM supervised at the state level — often do not.

State-supervised RIAs tend to have fewer compliance resources, less regulatory infrastructure, and less awareness of FTC requirements specifically. The FTC has signaled increasing enforcement interest in small financial businesses precisely because this compliance gap is widespread.

💡 State-supervised RIAs have the same FTC Safeguards Rule obligations as SEC-supervised firms. The threshold for state vs. SEC supervision doesn't affect your FTC compliance requirements at all.

What Client Data Triggers the Requirement

For financial advisers, the trigger is almost everything in a standard client relationship:

If you've completed a financial plan for a single client, you almost certainly hold information that triggers the Safeguards Rule.

What Your WISP Needs to Address

For advisory firms, the FTC requires your Written Information Security Plan to address the specific systems and practices through which your firm handles client data. This typically includes:

Getting Compliant Without a Chief Compliance Officer

Most small RIAs and independent planners don't have a CCO on staff. The FTC doesn't require one. It requires a documented security program — and it can be prepared without legal counsel, without an IT firm, and without expensive compliance software.

What it does require is that the WISP accurately reflect your actual firm — your systems, your staff, your data handling practices. A generic template downloaded from the internet won't do that.

SafeguardsReady prepares custom WISPs for financial advisers and small RIAs in 48 hours, starting at $497. You complete a short questionnaire about your firm, and we build a document that covers your FTC Safeguards Rule obligations specifically — not boilerplate that could belong to any business.

Get Started

Need Help Organizing Your WISP Documentation?

  • Custom WISP built from your questionnaire responses
  • Word & PDF versions delivered in 48 hours
  • Loom video walkthrough of every section
  • Incident response plan included
  • No calls, no lawyers, no retainer
Get My WISP — $497 →

SafeguardsReady is not a law firm and does not provide legal advice. Documents are prepared based on publicly available FTC and IRS guidance. Consult a licensed attorney for advice specific to your compliance obligations.

SafeguardsReady is not a law firm and does not provide legal advice. Documents are prepared based on publicly available FTC and IRS guidance. Consult a licensed attorney for advice specific to your compliance obligations.