Who the FTC Rule Covers
The FTC Safeguards Rule applies to financial institutions — a category that includes investment advisers, financial planners, and other businesses that provide financial advisory services to consumers. If you hold, collect, or access nonpublic personal financial information about individual clients, the rule applies to your firm.
This includes:
- Registered Investment Advisers (RIAs) at both the SEC and state level
- Fee-only financial planners
- Insurance agents who sell investment or financial products
- Hybrid advisers (registered reps who also provide advisory services)
- Family offices that manage individual client wealth
SEC/FINRA vs. FTC — Not the Same Requirement
This is the most important thing for advisers to understand: SEC Regulation S-P and FINRA Rule 4370 address privacy notices and business continuity. They do not satisfy the FTC Safeguards Rule requirement for a Written Information Security Plan.
These are separate regulatory regimes with overlapping but distinct requirements. An adviser who is fully compliant with Regulation S-P may still be out of compliance with the FTC Safeguards Rule — because S-P doesn't require a written information security program in the same way the Safeguards Rule does.
⚠️ "My firm is SEC-registered and compliant with Reg S-P" is not a defense to an FTC Safeguards Rule enforcement action. These are independent requirements.
Why Small RIAs Are Most at Risk
Large broker-dealers and RIAs typically have compliance departments, chief compliance officers, and legal counsel who have addressed the FTC Safeguards Rule. Small RIAs — particularly those under $110M AUM supervised at the state level — often do not.
State-supervised RIAs tend to have fewer compliance resources, less regulatory infrastructure, and less awareness of FTC requirements specifically. The FTC has signaled increasing enforcement interest in small financial businesses precisely because this compliance gap is widespread.
💡 State-supervised RIAs have the same FTC Safeguards Rule obligations as SEC-supervised firms. The threshold for state vs. SEC supervision doesn't affect your FTC compliance requirements at all.
What Client Data Triggers the Requirement
For financial advisers, the trigger is almost everything in a standard client relationship:
- Net worth and income information gathered in discovery or onboarding
- Account statements, holdings, and transaction history
- Social Security numbers collected for account opening or tax reporting
- Tax returns and W-2s reviewed for planning purposes
- Estate documents, trust structures, and beneficiary information
- Insurance policy details
If you've completed a financial plan for a single client, you almost certainly hold information that triggers the Safeguards Rule.
What Your WISP Needs to Address
For advisory firms, the FTC requires your Written Information Security Plan to address the specific systems and practices through which your firm handles client data. This typically includes:
- CRM and portfolio management software — who has access, how credentials are managed, and what data is stored
- Custodian portals — Schwab, Fidelity, TD Ameritrade and similar platforms that hold client data on your behalf
- Document storage — how financial plans, account statements, and client records are stored and protected
- Third-party service providers — compliance consultants, technology vendors, and others who access client data
- Remote work protocols — if staff access client data from home or mobile devices, your WISP must address this
- Incident response — your plan for responding to a data breach, including client notification
Getting Compliant Without a Chief Compliance Officer
Most small RIAs and independent planners don't have a CCO on staff. The FTC doesn't require one. It requires a documented security program — and it can be prepared without legal counsel, without an IT firm, and without expensive compliance software.
What it does require is that the WISP accurately reflect your actual firm — your systems, your staff, your data handling practices. A generic template downloaded from the internet won't do that.
SafeguardsReady prepares custom WISPs for financial advisers and small RIAs in 48 hours, starting at $497. You complete a short questionnaire about your firm, and we build a document that covers your FTC Safeguards Rule obligations specifically — not boilerplate that could belong to any business.
Need Help Organizing Your WISP Documentation?
- Custom WISP built from your questionnaire responses
- Word & PDF versions delivered in 48 hours
- Loom video walkthrough of every section
- Incident response plan included
- No calls, no lawyers, no retainer
SafeguardsReady is not a law firm and does not provide legal advice. Documents are prepared based on publicly available FTC and IRS guidance. Consult a licensed attorney for advice specific to your compliance obligations.
SafeguardsReady is not a law firm and does not provide legal advice. Documents are prepared based on publicly available FTC and IRS guidance. Consult a licensed attorney for advice specific to your compliance obligations.