In This Article
If your firm completes tax returns for pay, closes real estate transactions, arranges car financing, collects debts, or advises clients on investments, federal law places you in a category you probably never use for yourself: financial institution. The FTC Safeguards Rule (16 CFR Part 314) applies the Gramm-Leach-Bliley Act's data security requirements to exactly these businesses, and it defines "financial institution" far more broadly than the way people use the phrase in conversation.
Coverage comes with homework. A covered business must run a written information security program with a named accountable person, specific technical controls such as multifactor authentication and encryption, staff training, vendor oversight, and an incident response plan. Since May 2024 it also carries a reporting duty: notify the FTC within 30 days of discovering a breach that involves the unencrypted information of 500 or more consumers.
Here is the useful part. Access Business Technologies has served financial institutions since 1999 and manages Microsoft 365 for them today. Our mortgage company clients sit under this exact rule. The security baseline we deploy for them is formally mapped to the rule's own subsections. The same baseline, at the same published price, works for a tax office or a title agency, because the price list does not ask what industry you are in.
The Label You Did Not Choose
The Gramm-Leach-Bliley Act ties "financial institution" to activities that are financial in nature, not to charters or vaults. Banks and federally insured credit unions answer to their own federal regulators for data security. Everyone else engaged in financial activities, from a two-partner CPA practice to a regional auto group, answers to the Federal Trade Commission under the Safeguards Rule.
The rule is not shy about naming names. Its definitions section works through examples, and two of them cover businesses that rarely think of themselves as regulated entities:
"An accountant or other tax preparation service that is in the business of completing income tax returns is a financial institution." ... "An entity that provides real estate settlement services is a financial institution."
The same examples section reaches automobile dealerships that lease vehicles on a nonoperating basis for longer than 90 days, investment advisory companies, credit counselors, and businesses that act as finders bringing buyers and sellers together. The FTC's own compliance guidance adds payday lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, collection agencies, tax preparation firms, non-federally insured credit unions, and investment advisers that are not required to register with the SEC.
Why Your Bank Has Never Mentioned This Rule
Banks and federally insured credit unions carry Gramm-Leach-Bliley security obligations through their prudential regulators, so the FTC's version never comes up in their world. The Safeguards Rule is GLBA's arm for everyone else. That split is why a mortgage lender, a CPA firm, and a title agency share a rulebook with each other, not with the bank down the street, even though the required protections look nearly identical.
Who Is Covered? The List Is Longer Than You Think
The test is whether your business engages in activities that are financial in nature, or incidental to them, as defined under the Bank Holding Company Act. In practice, that sweeps in most of the professional services economy that touches money on its way somewhere else.
| If your business... | Then under the Safeguards Rule... | Where it says so |
|---|---|---|
| Completes income tax returns for pay | You are a financial institution, by the rule's own example | 16 CFR 314.2(h) |
| Provides real estate settlement or escrow services | You are a financial institution, by the rule's own example | 16 CFR 314.2(h) |
| Extends credit, arranges financing, or leases vehicles long term | Financing is a financial activity; the rule's examples include a dealership leasing on a nonoperating basis over 90 days | 16 CFR 314.2(h) |
| Advises on investments without SEC registration | You appear on the FTC's list of covered businesses | FTC Safeguards Rule guidance |
| Collects debts, cashes checks, wires money, or counsels on credit | You appear on the FTC's list of covered businesses | FTC Safeguards Rule guidance |
| Brings together buyers and sellers as a finder | You are a financial institution, by the rule's own example | 16 CFR 314.2(h) |
Tax professionals get the message from two directions at once. Beyond the FTC, the IRS and its Security Summit partners remind preparers every filing season that federal law requires them to maintain a Written Information Security Plan, and IRS Publication 4557 points the requirement straight back at the Safeguards Rule. If you prepare returns for pay, this is already your obligation, whether or not anyone has said the words "financial institution" to you.
Insurance agencies live one street over: they are regulated by state insurance departments rather than the FTC, and a growing number of states have enacted insurance data security laws based on the NAIC's model. The obligations rhyme with the Safeguards Rule: a written information security program, investigation of cybersecurity events, and notification to the state insurance commissioner.
What the Safeguards Rule Actually Requires
Section 314.4 spells out nine elements of a compliant information security program. Most of them resolve to controls that already exist inside Microsoft 365, waiting to be configured for regulated data rather than left on general-business defaults. We walked through the full mapping for mortgage lenders in our guide to the FTC Safeguards Rule and Microsoft 365; the short version applies to every covered business.
| The rule requires | The Microsoft 365 control that answers it |
|---|---|
| A designated Qualified Individual accountable for the program | A named owner. The rule allows this person to work for a service provider while your firm keeps accountability |
| A written risk assessment | The assessment itself, informed by tenant data such as Microsoft Secure Score |
| Access controls, encryption, and multifactor authentication | Microsoft Entra ID Conditional Access policies; Microsoft Purview encryption and sensitivity labels; MFA enforced for every account |
| Regular monitoring and testing | Microsoft Defender alerting, Secure Score tracking, and configuration drift monitoring |
| Security awareness training | Phishing simulation and training built on Microsoft Attack Simulation Training |
| Service provider oversight | Vendor review discipline, including of your IT provider |
| A program you keep current | Baseline comparison against a maintained policy set, not a one-time setup |
| A written incident response plan | A plan wired to the tenant's actual alerting paths |
| Annual reporting to the board or a senior officer | Reporting built from tenant evidence rather than assembled by hand |
Two footnotes matter for small firms. First, the rule offers a partial exemption to institutions maintaining customer information on fewer than 5,000 consumers, but it only waives four items (the written risk assessment, continuous monitoring or annual penetration testing, the written incident response plan, and the annual report). Encryption, MFA, access controls, and training still apply. Second, the encryption detail has teeth: the 30-day FTC breach notice applies to unencrypted customer information, and the rule treats data as unencrypted if the key was taken too, which makes properly configured encryption and key protection the difference between an incident and a reportable event. Our walkthrough of Microsoft 365 encryption for financial institutions covers exactly which layers count.
Find out where your firm stands against the rule that already covers it
A free security assessment from the team that runs Microsoft 365 for 750+ financial institutions. You get the gaps, in plain English, mapped to the Safeguards Rule.
What Bank-Grade Security Looks Like in Practice
"Bank-grade" gets thrown around as a marketing adjective. We mean something specific by it: the M365 Guardian baseline we deploy for the banks, credit unions, and mortgage companies we manage Microsoft 365 for. It is not a product you install. It is the configuration and monitoring layer wrapped around a tenant from day one.
- An 80-policy Microsoft 365 security baseline across 11 categories, deployed to every client from day one
- 11 Conditional Access policies enforcing MFA, risk-based access, device compliance, geo-blocking, and legacy authentication blocking
- 62 of the 80 baseline policies formally mapped to Safeguards Rule subsections in 16 CFR 314.4, with coverage across 169 Microsoft Secure Score controls
- Data loss prevention that detects Social Security numbers, bank account numbers, credit card numbers, and ITINs across Exchange, SharePoint, OneDrive, and Teams, and automatically encrypts matching outbound email
- Zero-tolerance response: on any risk detection, ABT's automation immediately revokes every active session and token, on top of Microsoft's Continuous Access Evaluation and risk-based Conditional Access
- Guardian Security Insights, refreshed nightly and reviewed with you on a scheduled cadence, so drift gets caught instead of accumulating
Notice what that mapping means for a covered business outside banking. The compliance layer is keyed to 16 CFR 314.4, which is the FTC Safeguards Rule itself. When a CPA firm or a title agency asks us to line their tenant up against "their" regulation, we are not adapting a bank framework to fit. Their rule is the rule the baseline already speaks.
There is one more overlap worth naming: AI. Staff at covered firms are already pasting client information into personal AI tools, and none of those tools answer to your security program. Bringing AI inside the tenant with Microsoft 365 Copilot, where Conditional Access, data loss prevention, and Microsoft Purview audit logging apply, turns an unmanaged risk into a governed productivity gain. That governance work is the same work banks are doing right now, and it is part of the same baseline.
The rule does not grade on a curve. A twelve-person tax office and a two-billion-dollar mortgage lender read the same nine elements.
The Same Platform Banks Run, at the Same Published Price
Here is the part that surprises people. Security pricing usually assumes an enterprise buyer: call us, we will size you up. ABT publishes its prices, and the list is the same for every customer we serve. There is no bank tier and no small-business tier on the M365 Guardian page. The hardened-tenant foundation, including Guardian Security Insights, is included with Microsoft licensing through ABT. The managed response tiers are published per-user prices with 50-user minimums, identical whether your logo is a bank charter or a shingle.
Microsoft licensing itself is billed at Microsoft's price for your organization type. What we bring is the part that usually gets gated behind enterprise sales conversations: the baseline, the mapping to your rule, and the monitoring, at the price on the page. If it is good enough for 750 financial institutions, and priced for them, there is no reason a covered firm one tenth their size should get less.
Where to Start Without Hiring a Security Team
The Safeguards Rule assumes a program, not a heroic individual. The rule even acknowledges that the Qualified Individual can work for a service provider, as long as your firm keeps accountability and a senior employee provides oversight. That is the realistic shape of compliance for a covered business with no security staff: keep ownership, delegate operation.
The practical sequence is the one our financial institution clients run. Assess the tenant against the baseline. Close the gaps that matter first: MFA everywhere, legacy authentication off, encryption on regulated data, access trimmed to who actually needs it. Then keep it that way with monitoring and a review cadence, so the program stays current instead of decaying back to defaults.
None of this requires you to become an IT company. It requires the same thing the rule has always required: someone accountable, a real program behind them, and controls that are actually on. If a regulator, a client, or an insurance carrier asks tomorrow, the answer is a report, not a scramble.
Your industry finally gets the bank treatment. Take it.
Talk to the largest Tier-1 Microsoft Cloud Solution Provider primarily dedicated to financial services. We will map your tenant against the Safeguards Rule and show you exactly what covered means, for free.
Frequently Asked Questions
Engaging in activities that are financial in nature, or incidental to financial activities, as defined under the Bank Holding Company Act. The rule's examples in 16 CFR 314.2(h) include tax preparation services, real estate settlement providers, certain automobile dealership leasing, investment advisory companies, credit counselors, and finders. A banking charter is not part of the test.
Yes, if the firm is in the business of completing income tax returns. That example appears in the rule text itself, and the FTC's guidance lists tax preparation firms among covered businesses. The IRS reinforces it: paid tax professionals are required to maintain a Written Information Security Plan, and IRS Publication 4557 ties that duty to the Safeguards Rule.
Dealership activities around money are what trigger coverage. Extending credit and arranging financing are financial activities, and the rule's own examples include an automobile dealership that leases vehicles on a nonoperating basis for longer than 90 days. A dealership that only sells for cash with no financing role would look different, but that describes very few dealerships.
Only a partial one. Institutions that maintain customer information on fewer than 5,000 consumers are exempt from four requirements: the written risk assessment, continuous monitoring or annual penetration testing, the written incident response plan, and the annual report to the board. Encryption, multifactor authentication, access controls, and training still apply, and many small firms hold records on more consumers than they expect.
Since May 2024, a covered financial institution must notify the FTC as soon as possible, and no later than 30 days after discovery, of a breach involving the unencrypted information of at least 500 consumers. Reports are filed through the FTC's online form and can be made public. Because the duty attaches to unencrypted information, and data counts as unencrypted if the key was compromised, properly configured encryption and key protection can be the difference between an internal incident and a reportable event.
Yes, because the platform is the same and so is the price list. ABT publishes one set of prices for its M365 Guardian services: the hardened-tenant foundation with Guardian Security Insights is included with Microsoft licensing through ABT, and the managed response tiers are published per-user prices with 50-user minimums that do not vary by industry. Microsoft licensing is billed at Microsoft's price for your organization type.