Your title company is a financial institution. The rule says so in one sentence.
Most title, escrow, and settlement agencies have never read the sentence that puts them inside the FTC Safeguards Rule. It is not an interpretation and it is not a stretch. It is an example printed in the regulation itself, and a second sentence a few paragraphs earlier decides whose information you are holding.
- The rule names real estate settlement services directly, at 16 CFR 314.2(h)(2)(x)
- The buyer at your closing table is your customer under the rule, which makes their file customer information
- Nine elements, one written program, and a 30 day clock that starts at discovery
Is a title company a financial institution under the FTC Safeguards Rule?
Yes. The rule does not leave this to be argued. Among the thirteen worked examples the FTC prints in its own definition section, one of them is you.
An entity that provides real estate settlement services is a financial institution because providing real estate settlement services is a financial activity listed in 12 CFR 225.28(b)(2)(viii) and referenced in section 4(k)(4)(F) of the Bank Holding Company Act, 12 U.S.C. 1843(k)(4)(F). 16 CFR 314.2(h)(2)(x)
The word financial institution is doing unfamiliar work here. In conversation it means a bank. In the Gramm-Leach-Bliley Act, which the Safeguards Rule implements, it means any business significantly engaged in an activity that is financial in nature, and Congress delegated the list of those activities to banking regulation written for bank holding companies. Real estate settlement is on that list. So is appraisal, at 16 CFR 314.2(h)(2)(iii), which means the appraiser on the file is covered on the same basis you are.
There is no revenue threshold in the definition, no employee count, and no carve out for agencies that consider themselves too small to be regulated. A two person escrow office and a national underwriter are financial institutions on identical grounds. Size changes four obligations later in the rule, which we get to below, and it changes nothing about whether the rule applies.
Whose information are you actually holding?
The identity sentence gets quoted often enough. The one that decides your exposure sits a few paragraphs earlier and almost never gets quoted at all. The rule defines when a consumer has a continuing relationship with you, and lists the ways that relationship forms:
A consumer has a continuing relationship with you if the consumer ... Obtains real estate settlement services from you. 16 CFR 314.2(e)(2)(i)(K)
Follow the chain, because each link is a definition rather than an inference. A consumer with a continuing relationship is a customer under 16 CFR 314.2(c). Any record containing nonpublic personal information about a customer is customer information under 16 CFR 314.2(d), and the definition explicitly covers records held in paper, electronic, or other form, including records handled on your behalf by someone else.
Put the two sentences together and the picture is unambiguous. The rule says you are a financial institution, and it says the people at your closing table are your customers, which pulls the whole of 16 CFR 314.4 down onto the files you already hold. Neither half requires anyone's interpretation. Both are printed in the regulation.
What most agencies believe, and what the regulation says
Every row on the right is a direct reading of the cited paragraph. None of it is ABT's opinion about best practice.
| The common assumption | What it gets wrong | What the rule actually says |
|---|---|---|
| "We are a title agency, not a financial institution." | Uses the conversational meaning of the phrase | Real estate settlement services are named as an example of a financial institution. 16 CFR 314.2(h)(2)(x) |
| "The lender is the regulated party. We just handle the closing." | Assumes the customer relationship belongs to whoever originated the loan | A consumer who obtains settlement services from you has a continuing relationship with you, which makes them your customer. 16 CFR 314.2(e)(2)(i)(K) and (c) |
| "We are under the threshold, so we are exempt." | Reads a partial exception as a full exemption | Below five thousand consumers, exactly four paragraphs stop applying. The rest, including the written program itself, still binds. 16 CFR 314.6 |
| "Our policies are documented across a few systems and manuals." | Treats scattered documentation as a program | A comprehensive program, written in one or more readily accessible parts. 16 CFR 314.3(a) |
| "We use Microsoft 365, so encryption is handled." | Confuses a licence with a configuration | Encrypt customer information in transit over external networks and at rest, or document compensating controls approved in writing by your Qualified Individual. 16 CFR 314.4(c)(3) |
| "We turned on multifactor authentication for the office staff." | Scopes the requirement to employees and to email | Multifactor authentication for any individual accessing any information system, unless equivalent or stronger controls are approved in writing. 16 CFR 314.4(c)(5) |
| "Our IT provider handles security, so it is on them." | Assumes outsourcing transfers accountability | Your Qualified Individual may work for a service provider, but you retain responsibility for compliance and must name a senior person of your own to oversee them. 16 CFR 314.4(a)(1) and (2) |
| "If something happened, we would deal with it then." | Ignores that the clock starts before anyone escalates | Notice to the FTC within 30 days of discovery at 500 consumers, and an event counts as discovered the first day it is known to any employee or agent. 16 CFR 314.4(j) |
Read the cited paragraphs yourself. Every one is public at the eCFR, and the sources for this page are listed at the bottom.
The nine elements, and where Microsoft 365 carries the weight
Section 314.4 sets out nine elements your information security program must include. Two of them are where Microsoft 365 does the work. The other seven are organizational or documentary, and no product satisfies them, which is worth knowing before anyone sells you a compliance package.
Designate a Qualified Individual
One named person accountable for overseeing, implementing, and enforcing the program. Organizational. The rule permits this person to work for a service provider, with conditions covered below.
Base the program on a risk assessment
Identify foreseeable internal and external risks to customer information and judge whether existing safeguards control them. Organizational, though what your tenant reports is the raw material.
Access controls, encryption, and multifactor authentication
The technical core, and the largest element in the rule. Access controls that authenticate authorized users and limit them to what their duties require, encryption of customer information in transit over external networks and at rest, multifactor authentication for any individual accessing any information system, secure disposal, change management, and logging. Microsoft Entra ID and Microsoft Purview are where most of this is configured and evidenced.
Test and monitor the safeguards
The second technical element. Regularly test or monitor the effectiveness of key controls, including detection of attempted intrusions. Either continuous monitoring, or annual penetration testing plus vulnerability assessments at least every six months. Microsoft Defender and audit logging carry the monitoring half.
Train your people
Security awareness training updated to reflect the risks your assessment identified, plus qualified security personnel and current knowledge of changing threats. Organizational, and the element most directly aimed at the fraud pattern that targets closings.
Oversee your service providers
Select providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically reassess them against the risk they present. Organizational, and it is where your production system, your document vendor, and your IT provider all land.
Evaluate and adjust the program
Revise the program in light of testing results, material changes to your operations, and anything else you know may have a material impact on it. Organizational, though what your tenant reports is what should trigger it. Settings drift and offices reorganize, and the program is expected to notice.
Keep a written incident response plan
Goals, internal response processes, defined roles and decision authority, internal and external communications, remediation requirements, documentation, and post-incident revision. Seven specified areas, and this is one of the four paragraphs the small agency exception lifts.
Report to your governing body
The Qualified Individual reports in writing, at least annually, on program status and material matters. Where there is no board, the report goes to a senior officer. Also lifted by the small agency exception.
Two of the technical requirements deserve a closer read than they usually get. The encryption paragraph covers customer information at rest, not only in transit, and if you decide encryption is infeasible anywhere the rule wants compensating controls reviewed and approved in writing by your Qualified Individual. The multifactor paragraph says any individual accessing any information system. Not employees only, not email only. Both are the kind of sentence that reads as boilerplate until someone reads it against your actual configuration.
There is also a disposal requirement that catches title and escrow work squarely. Customer information must be securely disposed of no later than two years after the last date it was used in connection with providing a service, unless it is needed for business operations, required to be retained by law or regulation, or targeted disposal is not reasonably feasible given how the information is kept. Closing files are retained under state law and underwriter agreements, so the exception usually applies. What the rule then expects is that you periodically review your retention policy to minimize unnecessary retention, which is a different obligation from keeping everything forever by default.
We handle fewer than 5,000 consumers. Does the rule still apply?
Yes, it still applies. This is the single most common misreading, and it is understandable, because a threshold that sounds like an exemption is written as a list of four paragraph numbers.
Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers. 16 CFR 314.6
Four paragraphs. Here is what each one is, and then what is conspicuously not on the list.
Now the part that matters more. The exception reaches into 314.4 only. It never touches 16 CFR 314.3, so the comprehensive written information security program is required of a two person escrow office exactly as it is of a national underwriter. It does not lift encryption, multifactor authentication, access controls, secure disposal, logging, training, service provider oversight, or the duty to notify the FTC. Roughly speaking, four documentation obligations lift and every safeguard stays.
One more detail decides whether you are under the threshold at all, and it is easy to get wrong. The test counts consumers whose information you maintain, not files you closed this year. Prior years count for as long as you still hold the records, which for a title agency operating under state retention requirements is usually a long time. Agencies that assume they are comfortably under five thousand are often counting annual volume rather than the archive.
Thirty days, five hundred consumers, and the word that starts the clock
Since 13 May 2024, covered financial institutions have owed the FTC notice of qualifying breaches. The requirement is short and the two conditions inside it carry all the weight.
Upon discovery of a notification event ... if the notification event involves the information of at least 500 consumers, you must notify the Federal Trade Commission as soon as possible, and no later than 30 days after discovery of the event. 16 CFR 314.4(j)(1)
The notice goes in electronically through a form on the FTC website and asks for the types of information involved, the date or date range where determinable, the number of consumers affected, and a general description of what happened. Law enforcement can request a delay of up to 30 days, extendable by up to 60 more in writing, where public disclosure would impede an investigation.
The trap is in the definition of discovery, which the rule supplies rather than leaving to common sense:
A notification event shall be treated as discovered as of the first day on which such event is known to you. You shall be deemed to have knowledge of a notification event if such event is known to any person, other than the person committing the breach, who is your employee, officer, or other agent. 16 CFR 314.4(j)(2)
Be precise about what is being discovered, because it is not any odd occurrence. The thing discovered has to be a notification event, which the rule defines as unauthorized acquisition of unencrypted customer information, and the 30 day duty attaches only where at least 500 consumers are involved. Plenty of alarming Tuesdays never become notification events at all.
What the definition does change is whose knowledge counts, and that is the part worth planning around. If a closing coordinator sees the mailbox activity that later turns out to be the acquisition, and says nothing for two weeks, the firm is deemed to have known from the day she saw it. Discovery is not the day it reached the owner, and it is not the day a forensic engagement confirmed the numbers. In practice you will be reconstructing that date afterwards, from logs, under time pressure, to a regulator.
That is why detection capability and the 30 day clock are the same problem wearing different clothes. An agency that cannot see unusual mailbox activity does not get a slower clock. It gets a clock that may already be running, measured from a date it will have to reconstruct afterwards. The same logic applies to the word unencrypted in the definition of a notification event: encryption changes the exposure of an incident before one happens, not after.
State breach notification statutes, underwriter agreements, and your insurer impose separate duties on their own timetables, and several of them are shorter. Confirm your specific obligations with counsel rather than with a vendor.
The fraud that targets closings is an email problem before it is a wire problem
Before quoting any statistic here, one clarification is owed, because the obvious number is the wrong one. The FBI's Internet Crime Complaint Center publishes a crime category called Real Estate, and its own appendix defines it as "Loss of funds from a real estate investment or fraud involving rental or timeshare property." That category is not closing wire fraud. Diverted closing funds are counted under business email compromise, so that is the number that speaks to this audience.
In the 2025 IC3 annual report, the FBI recorded 1,008,597 complaints and $20.877 billion in reported losses, a 26 percent increase over 2024. On the composition, the report is direct: "Investment-related fraud was once again the largest component of these losses, followed by business email compromises and tech support scams." Second by loss, out of every category the FBI tracks.
Individuals closing on a home received an email impersonating their legitimate attorneys. A wire for more than $449,000 was submitted at their bank and sent to the recipient bank. After the fraud was discovered, the buyers reported it to their bank and their attorneys made separate attempts to reach the recipient bank, with no result.
Only when the IC3 complaint reached the FBI's Recovery Asset Team, which initiated the Financial Fraud Kill Chain to request a freeze, did the recipient bank confirm the full amount was still in the account and on hold.
Three things in that account are worth sitting with. The impersonated party was the professional the buyers trusted most in the transaction. The victims and their own attorneys could not recover the funds through ordinary channels. And recovery happened only because a federal process reached the receiving bank while the money was still sitting there.
The kill chain works when it is fast. Across 2025 the FBI initiated 3,900 of these actions against $1,163,919,846 in attempted theft and froze $679,013,183, a 58 percent success rate. The bureau's own guidance leads with the reason: "If you discover a fraudulent transfer, time is of the essence."
Notice what that implies about the control that matters. Wire verification callbacks are necessary and every serious agency has them. But the fraud does not begin at the wire. It begins in a mailbox, days or weeks earlier, where someone is reading the thread and waiting for the closing date. The controls that reach that stage are the ones the Safeguards Rule already requires you to have: multifactor authentication on every information system, logging that would show a mailbox rule nobody created, and the ability to notice an unusual sign in while the file is still open.
ALTA has been pointing at a written plan for years
None of this should feel foreign. The American Land Title Association maintains the ALTA Best Practices 4.0 Framework, organized across seven pillars, along with an assessment readiness guide, policy and procedure templates, and vendor vetting guidance. Underwriters and lenders have been asking agencies about it for years.
ALTA also publishes WISP Guidance and FAQ, currently at version 09-17-2024. A written information security plan is the same artifact 16 CFR 314.3(a) requires when it calls for a comprehensive program written in one or more readily accessible parts. Your trade association and the federal regulator are asking for the same document.
Which reframes the work in front of you. For a great many agencies this is not a program built from nothing. It is a Best Practices posture that already exists on paper, checked honestly against what the tenant is actually doing, with the gaps closed and the whole thing written down where someone can find it. The uncomfortable part is rarely the writing. It is discovering that a control the plan claims has not been switched on for two years.
We already work under this rule, on the other side of your closings
Access Business Technologies manages Microsoft 365 for more than 750 financial institutions, and hosts their Azure environments. Banks, credit unions, and mortgage companies. The lenders on your files.
That adjacency is the entire reason this page exists, and it is worth being precise about why it matters. ABT's Microsoft 365 security baseline runs 80 policies across 11 categories, deployed from day one, including 11 Conditional Access policies. 62 of those 80 policies are formally mapped to Gramm-Leach-Bliley Safeguards Rule subsections at 16 CFR 314.4, and the baseline covers 169 Microsoft Secure Score controls.
16 CFR 314.4 is the paragraph this whole page has been quoting. It is the same rule. Not a bank framework adapted for title work, and not a compliance overlay invented for a new market. The mapping already speaks your regulation because ABT's mortgage clients have lived under it for years.
A free security assessment of your Microsoft 365 tenant
Our engineers read the tenant and report what is actually there, with each finding tied to the element of the rule it belongs to.
- Multifactor authentication coverage, by user and by system, against 16 CFR 314.4(c)(5)
- Encryption posture for information in transit and at rest, against 314.4(c)(3)
- Access controls and whether staff can reach files their duties do not require, against 314.4(c)(1)
- Audit logging and retention, the evidence any incident response depends on, against 314.4(c)(8)
- Where closing files have actually ended up, including the copies in mailboxes and shared drives
- A plain reading of what your written plan can honestly claim today
The assessment is a technical review of your Microsoft 365 configuration. It is not legal advice and not a determination of regulatory compliance. Whether your firm is covered, and whether your program satisfies the rule, are questions for your counsel.
If the review turns up work worth doing, one thing is worth knowing before you ask. ABT publishes a single price list and it has no industry dimension anywhere in it. A title agency sees the same numbers a community bank sees, because there is only one set of numbers. That is a fact about the catalog rather than a discount or a match. Guardian Foundation, a hardened tenant with Guardian Security Insights, is included at no additional charge with Microsoft licensing through ABT, and the managed tiers above it, along with their per user rates and published minimums, are listed openly on the M365 Guardian page.
ABT also operates M365 Guardian, its managed security service for credit unions, banks, and mortgage companies.
There is no obligation attached to the assessment, and plenty of agencies take the report to their existing provider. That is a fine outcome. The report is more useful than the sales conversation.
Where the facts on this page come from
Every regulatory quotation was read from the current text of the regulation, and every statistic from the primary report, on 28 August 2026.
- 16 CFR Part 314, the FTC Safeguards Rule, current text via the Electronic Code of Federal Regulations. Sections quoted: 314.2(c), 314.2(d), 314.2(e)(2)(i)(K), 314.2(h)(2)(iii), 314.2(h)(2)(x), 314.2(k), 314.3(a), 314.4(a) through (j), and 314.6. ecfr.gov
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report. Source of the 2025 complaint and loss totals, the statement that business email compromise was the second largest loss component, the Financial Fraud Kill Chain figures, the August 2025 closing case, and the definition of the Real Estate crime category. ic3.gov
- American Land Title Association, Best Practices 4.0 Framework and WISP Guidance and FAQ (version 09-17-2024). alta.org
- Microsoft product documentation for the capabilities named on this page: Microsoft Entra ID, Microsoft Purview, Microsoft Defender, and Microsoft Intune. learn.microsoft.com
Nothing on this page is legal advice. Whether a particular business is covered by the FTC Safeguards Rule, and whether its program satisfies the rule, are determinations for its own counsel.
More on the rule and the fraud
You Might Be Running a Financial Institution. The FTC Thinks So.
The thirteen worked examples in the rule, and the businesses that find themselves inside a definition written for banks.
Email Security: Stop Wire Fraud and Business Email Compromise
How the attack actually runs, from the first mailbox to the diverted payment, and the controls that interrupt it.
The FTC Safeguards Rule and Microsoft 365 for Mortgage Lenders
The same rule, read from the lender's side of the closing. Useful context for the counterparties on your files.
Title and escrow questions, answered from the rule text
Find out what your tenant
can honestly claim.
Tell us roughly how many people are in the agency and how many consumers' information you still hold, counting prior years. Our engineers will read the tenant and come back with what is switched on, what is not, and which element of the rule each finding belongs to.

