GLBA Safeguards Auditor
11 of 17 applicable Safeguards Rule elements have gaps; 4 are priority 1: 16 CFR 314.4(c)(3), (c)(5), (h) and (j).
Last performed 2025-05-24, 16 months before the 2026-09-24 review; 314.4(b) is due at least every 12 months (the risk assessment refresh setting), so the oldest date that passes is 2025-09-24. Priority: tier 2 weight 2 x gap weight 2 = 4 (3 to 5 is P2).
Method1Each element of 16 CFR 314.4 (a) through (j), including (d)(1), is tested against the questionnaire; missing elements are gaps.
2No, partial and yes-without-evidence answers are gaps; n/a is accepted only for (c)(4) secure development.
| Element | Title | Status |
|---|---|---|
| 16 CFR 314.4(b) | Written risk assessment | Gap |
| 16 CFR 314.4(c)(2) | Data and systems inventory | Gap |
| 16 CFR 314.4(c)(3) | Encryption in transit and at rest | Gap |
Safeguards control questionnaire answers
Element-by-element gap report and a remediation plan (Safeguards Rule gap report, Remediation plan (11 steps), Element results (CSV))
$3,000 / month, 30% to the referring partner
Read in memory for the session, never stored, never used to train a model.
Not financial, investment, banking or securities advice. Filings and screening results must be reviewed by a qualified compliance professional. Privacy and security findings are not legal advice or an audit opinion. Confirm them with privacy counsel or a qualified assessor.