First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation, Data & AI Microsoft partner since 2006 1,100+ organizations under management

FTC Safeguards Rule Checklist and a WISP Outline for Microsoft 365 Tenants

2026-09-20·IT PartnerNewComplianceSecurityMicrosoft 365

If your business arranges financing, prepares tax returns, brokers mortgages or collects debts, the FTC Safeguards Rule most likely reaches you, and since its 2023 amendments it names the safeguards instead of asking for "reasonable" ones. Below, each element is mapped to Microsoft 365 controls and evidence, followed by a WISP outline. It is an engineering reading of the public rule text, not legal advice.

Who the rule reaches and what it asks for

The Safeguards Rule (16 CFR Part 314, under GLBA) applies to the non-bank businesses the FTC calls financial institutions: auto dealers that arrange financing, mortgage brokers and lenders, finance companies, tax-preparation and accounting firms, collection agencies, credit counselors, investment advisers not registered with the SEC and, per the FTC's guidance at the time of writing, some higher-education institutions. Coverage is your counsel's call; our FTC Safeguards Rule (GLBA) Readiness Assessment records that position as its first deliverable.

The amended rule has been in force since June 2023 and, as we read 314.4, asks for nine things: a designated Qualified Individual who owns the program; a written risk assessment; eight named safeguards (mapped in the next section); testing (continuous monitoring, or annual penetration testing with semiannual vulnerability assessments); staff training; service-provider oversight; a program kept current; a written incident response plan; and an annual written report to the board or a senior officer. A tenth duty took effect on May 13, 2024: when unencrypted customer information on 500 or more consumers is acquired without authorization, the FTC is notified as soon as possible and no later than 30 days after discovery.

Under 314.6, an institution holding information on fewer than 5,000 consumers is relieved of the written risk assessment, the penetration-testing cadence, the written incident response plan and the annual board report, but not of MFA, encryption or the other safeguards. The FTC's June 2025 FAQs for auto dealers add that a platform your manufacturer requires you to use is still your service provider to oversee.

The eight safeguards, mapped to Microsoft 365

Microsoft 365 Business Premium carries Entra ID P1 for Conditional Access, Intune and Defender for Business. Defaults are tuned for collaboration, not for 314.4(c), so each safeguard needs a setting turned on and an export filed.

  1. Access controls. Conditional Access requiring MFA and blocking legacy authentication (the baseline policies), least-privilege admin roles, tightened sharing settings. Evidence: policy export, role list, sharing settings. Conditional Access Policy Implementation ($2,950 per project) builds the set.
  2. Data and systems inventory. Purview data classification for the sensitive information types the rule protects (Social Security, bank account, card and driver's license numbers), plus a list of the non-Microsoft systems holding customer information. Evidence: classification results and the systems list.
  3. Encryption in transit and at rest. Microsoft's service-side encryption and TLS, BitLocker enforced through Intune compliance, Purview Message Encryption for outbound client documents. Evidence: the Intune encryption report and the encrypted-email rules.
  4. Secure development practices. Applies if you build applications; otherwise a documented "not applicable" plus governance of Power Platform makers.
  5. MFA for anyone accessing any information system. Conditional Access for every identity, including administrators, shared mailboxes and service accounts, with legacy authentication off. Non-Microsoft systems are listed with their MFA status, with the Qualified Individual's written exception where a vendor cannot. Enable MFA for All Users ($700 per project) closes the tenant side.
  6. Secure disposal. Purview retention and deletion policies; Intune retire and wipe records for devices. Evidence: retention policies and disposition records.
  7. Change management. A written change process and Entra audit log entries for Conditional Access and role changes. Evidence: change records and audit exports.
  8. Logging and monitoring of user activity. Purview audit on with a recorded retention period, Entra logs, Defender alerts routed to a person. Longer retention needs Sentinel or an add-on; what you could prove after a breach explains the licensing dependencies.

The organizational elements and their evidence

These are documents with names and dates; no setting produces them.

  • Qualified Individual. A written designation. A provider's employee may hold the role only under the conditions in the FAQ below.
  • Written risk assessment. Criteria, the risks considered, a date and a review cadence; the tenant findings feed it.
  • Testing. The Qualified Individual chooses continuous monitoring or annual penetration testing with semiannual vulnerability assessments. Continuous monitoring is often the practical path; Defender XDR Incident Readiness and Automated Response ($3,500 per project) documents coverage and automation.
  • Training. Dated records per person. Managed Security Awareness Training and Phishing Simulation delivers quarterly reports; it needs Defender for Office 365 Plan 2 or E5 for enrolled users.
  • Service-provider oversight. A vendor register with contract security language, evidence held and a reassessment cadence. Microsoft's side is documented from its published Product Terms and audit reports.
  • Incident response plan and FTC notification. Roles, decision points, the 500-consumer and 30-day trigger, and the contents of the notice (see the FAQ).
  • Annual board report. The program's status and the material matters 314.4(i) expects, dated.

A vCISO can carry the program cadence without taking the designation; what a vCISO is covers when that fits.

The WISP outline

The WISP is the document the program lives in. The Microsoft 365 findings go in section 4; the coverage position and the notification wording are marked for counsel.

  1. Purpose, scope and coverage position: the financial-institution determination, the consumer-count band and the 314.6 position, the systems holding customer information.
  2. Qualified Individual: name, authority, reporting line; the oversight arrangement if a provider's employee.
  3. Risk assessment: method, criteria, risks identified, date, review cadence.
  4. Safeguards: one subsection per 314.4(c) safeguard, each naming the control, the setting and workload, the owner and the evidence location.
  5. Testing and monitoring: the chosen path, cadence and reports.
  6. Training: who, what, when, records.
  7. Service-provider oversight: the register, contract requirements, evidence, reassessment cadence.
  8. Program maintenance: what triggers a review and how often.
  9. Incident response plan: roles, decision points, the FTC notification procedure, the post-incident review.
  10. Board reporting: contents and date of the annual report.
  11. Physical safeguards: paper files, office access, media destruction, as headings to complete.
  12. Appendices: evidence index, vendor register, exception log, document control.

The IRS separately expects paid tax preparers to keep a written information security plan and points at the same rule, so one document does double duty. HIPAA on Microsoft 365 applies the same evidence logic for a different regulator.

Licensing: what you have and what needs more

Business Premium covers Conditional Access, Intune, Defender for Business and the Purview basics. Longer audit retention, Privileged Identity Management and access reviews depend on higher plans or add-ons; a control your licensing does not carry is a licensing gap, not a configuration failure. The Microsoft 365 Plan Optimizer prices the identity, Defender and Purview tiers against an all-in E5. Microsoft's subscription and any metered charges are yours.

Frequently asked questions

Does being on Microsoft 365 make us compliant?

No. It gives you most of the technical safeguards, but whether they are switched on, cover everyone and are evidenced is the question, and the organizational elements are yours.

We hold information on fewer than 5,000 consumers. What still applies?

The Qualified Individual, a risk assessment on which the program is based, all eight safeguards including MFA and encryption, training, service-provider oversight and the FTC notification duty. Applicants and former customers count, and counsel confirms the band.

Is there an FTC Safeguards certification?

No. The FTC recognizes no certifying body and issues no certificate; what exists is a documented program with evidence behind it.

Can our IT provider be the Qualified Individual?

Under conditions: you retain responsibility, a senior member of your staff directs and oversees that person, and the provider maintains its own program. Virtual CISO support for the person you designate is the shape we offer.

What must the FTC notice contain, and when?

As soon as possible and within 30 days of discovering a notification event: who you are, the types of information, the date or range if known, the number of consumers and a general description. Whether an event qualifies is counsel's decision.

Sources

  • IT Partner: content/services/ITPWW450CONOT - FTC Safeguards Rule (GLBA) Readiness Assessment.json; the rule's elements, dates and thresholds are reused from this page (an engineering reading as of September 2026, not legal advice)
  • IT Partner service pages under content/services: ITPWW400IMPOT, ITPWW240SECOT, ITPWW320MSPRC, ITPWW520SECOT, ITPWW305IMPOT
  • IT Partner subscription page: content/subscriptions/CFQ7TTC0LCHC__Commercial.json (Microsoft 365 Business Premium)
  • IT Partner blog posts linked above; src/app/tools/plan-optimizer/page.tsx
  • The higher-education note is hedged to the FTC's guidance and was not verified from this environment; confirm any date or threshold against the FTC's current text before relying on it.
Rule element (16 CFR 314.4) Microsoft 365 control Evidence to file Done
(a) Qualified Individual Not a setting Written designation [ ]
(b) Written risk assessment Tenant findings as input Dated assessment [ ]
(c)(1) Access controls Conditional Access, least-privilege roles, sharing settings Policy export; role list; sharing settings [ ]
(c)(2) Data and systems inventory Purview classification; systems list Classification results; systems register [ ]
(c)(3) Encryption Service-side encryption and TLS; BitLocker via Intune; Message Encryption Encryption report; mail rules [ ]
(c)(4) Secure development Power Platform governance, or not applicable Written determination [ ]
(c)(5) MFA for all access Conditional Access for every identity; legacy authentication off Registration report; policy export; vendor MFA list [ ]
(c)(6) Secure disposal Purview retention and deletion; Intune retire and wipe Retention policies; disposition records [ ]
(c)(7) Change management Change process; Entra audit log Change records; audit exports [ ]
(c)(8) Logging and monitoring Purview audit with retention; Defender alerts Audit settings; alert routing [ ]
(d) Testing Continuous monitoring or annual pen test plus semiannual assessments Documented choice; reports [ ]
(e) Training Awareness training and phishing simulation Per-person records; quarterly report [ ]
(f) Service providers Vendor register Contracts, evidence, reassessment dates [ ]
(g) Program kept current Review triggers Program change log [ ]
(h) Incident response plan Written plan with FTC procedure Plan; exercise record [ ]
(i) Board report Annual written report Dated report [ ]
(j) FTC notification 500 consumers, 30 days Procedure; decision log [ ]

Key takeaways

  • The amended rule names nine program elements plus the May 13, 2024 notification duty; the 5,000-consumer relief never removes MFA, encryption or the other safeguards.
  • Business Premium carries the technical safeguards; the work is switching them on for everyone and filing the evidence.
  • MFA under 314.4(c)(5) reaches every information system, including the DMS and lender portals; non-Microsoft systems go in the register with their status and any written exception.
  • The organizational elements are documents no platform produces for you.
  • The WISP is one document with twelve sections, and tax preparers can reuse it for the IRS expectation.

The FTC Safeguards Rule (GLBA) Readiness Assessment is a fixed-price, three-week engagement ($3,950 for one Microsoft 365 tenant and one program) that records the coverage position with counsel's input, maps the eight safeguards to your tenant with the evidence exported, and hands you the gap report, roadmap, WISP outline, vendor checklist, notification procedure and board-report template. For IT Partner clients the Microsoft 365 Security Assessment is available at no charge first. We are Microsoft 365 engineers, not a law firm, and nothing certifies compliance.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.