Who the FTC Safeguards Rule Covers

The FTC Safeguards Rule (16 CFR Part 314) applies to any business that qualifies as a "financial institution" under the Gramm-Leach-Bliley Act. Mortgage brokers — including independent brokers and small non-bank lenders — are explicitly listed as financial institutions under this definition.

That means if you originate, broker, or assist with mortgage loans and collect consumer financial information in the process, the FTC Safeguards Rule applies to your business. Full stop.

⚠️ The FTC Safeguards Rule has no employee-count minimum. A solo mortgage broker operating from a home office is subject to the same requirements as a 50-person lending firm.

What Data Triggers the Requirement

The rule is triggered when your business collects or holds "nonpublic personal information" from consumers. For mortgage brokers, this includes virtually everything in a standard loan application:

If a loan application touches your desk — even one you didn't close — the data in that application puts you under the Safeguards Rule.

What Your WISP Must Include

The FTC requires mortgage brokers to develop, implement, and maintain a written information security program. At minimum, your WISP must address:

💡 Many brokers already do most of these things informally. The problem is they haven't written them down. The FTC requires documented proof, not perfection.

Bank Lenders vs. Independent Brokers — A Common Misunderstanding

One of the most common compliance mistakes mortgage brokers make is assuming they're covered by the bank or lender they work with. This is wrong in almost every case.

Banks regulated by the OCC, Federal Reserve, or FDIC have their own information security examination requirements — but those rules cover the bank, not the independent broker. When you originate loans as an independent broker, you are your own financial institution under the FTC's definition. Your compliance is your responsibility.

The lender you submit loans to may have their own WISP. That document does not protect you.

Penalties for Non-Compliance

The FTC can impose civil penalties of up to $50,120 per violation. Because each missing safeguard may be treated as a separate violation, a single enforcement action can result in penalties that far exceed six figures.

There's a second risk that's often overlooked: cyber insurance. If your business suffers a data breach and you don't have a documented WISP, your cyber insurance carrier may deny your claim. Several insurers have added WISP documentation as a condition of coverage — meaning an undocumented security program could leave you exposed to both FTC fines and uninsured breach costs simultaneously.

⚠️ A data breach at a mortgage brokerage is particularly costly — loan files contain the most comprehensive picture of a consumer's financial life, making the data extremely valuable to identity thieves.

How to Get Compliant

Getting compliant doesn't require hiring a lawyer or a cybersecurity firm. The FTC requires a documented security program, not a perfect one. For most independent brokers and small lending offices, a properly customized WISP covers the full requirement.

The fastest path to compliance:

  1. Complete a short intake questionnaire about your business, systems, and data practices
  2. Receive a custom WISP document built around your actual setup — not a generic template
  3. Review, sign, and file your WISP
  4. Schedule an annual review to keep it current

SafeguardsReady delivers a custom WISP for mortgage brokers and small lenders in 48 hours, starting at $497. No calls, no retainer, no legal fees required.

Get Started

Need Help Organizing Your WISP Documentation?

  • Custom WISP built from your questionnaire responses
  • Word & PDF versions delivered in 48 hours
  • Loom video walkthrough of every section
  • Incident response plan included
  • No calls, no lawyers, no retainer
Get My WISP — $497 →

SafeguardsReady is not a law firm and does not provide legal advice. Documents are prepared based on publicly available FTC and IRS guidance. Consult a licensed attorney for advice specific to your compliance obligations.

SafeguardsReady is not a law firm and does not provide legal advice. Documents are prepared based on publicly available FTC and IRS guidance. Consult a licensed attorney for advice specific to your compliance obligations.