Here's a question every independent auto dealer should be able to answer: if someone asked you tomorrow to prove that your dealership is complying with the FTC Safeguards Rule, could you do it? Not explain it. Not say "our IT company handles cybersecurity," or "we have a WISP somewhere," or "our employees completed training." Prove it.
- Could you pull up the risk assessment?
- Could you show the current Written Information Security Program?
- Could you demonstrate who is responsible for the program?
- Could you produce employee training records?
- Could you show how vendors are being evaluated?
- Could you demonstrate that security testing has been performed?
- Could you show what happened when a security issue was identified and how it was remediated?
- Could you demonstrate that your program has been reviewed and updated? For many dealerships, those questions are harder to answer than they should be. That's exactly why compliance evidence matters.
Compliance is more than having the right documents
The FTC Safeguards Rule requires covered automobile dealers to develop, implement, and maintain a comprehensive written information security program designed to protect customer information, appropriate to the dealership's size, complexity, activities, and the sensitivity of the information it handles. Notice the words: develop, implement, maintain. The FTC isn't simply asking whether a dealership has a document called "WISP." A dealership needs an actual security program, needs to put that program into practice, and needs to keep maintaining it as the business and its risks change. That's where evidence comes in.
Imagine someone asked you these questions
Let's say you're sitting in your office and someone asks:
"Show me your current risk assessment." You have one. But when was it completed? Who completed it? What risks did it identify, what safeguards were evaluated, which gaps were found, and what happened to those gaps? If you can't answer those questions, simply having a risk assessment document may not tell the whole story. "Show me your employee training records." You say "we train our employees every year." That's good. Now: who completed the training, and when? What training did they receive? Were new employees trained, and what about employees who changed roles — can you produce the records? Doing something and being able to demonstrate that you did it are two different things. "Show me your vendor assessments." You probably have dozens of vendors — your DMS, CRM, IT provider, cloud services, payment processors, marketing companies, document services, and other technology providers. Do you know which ones have access to customer information? Have they been evaluated, when, and what did the evaluation find? What contractual safeguards are in place? The FTC's guidance specifically addresses oversight of service providers and expects covered institutions to take reasonable steps in selecting and retaining providers, require appropriate safeguards through contracts, and periodically assess providers based on the risk they present.
This is where compliance evidence becomes important
Think of compliance evidence as the paper trail — or digital trail — that shows your program is actually operating. For an auto dealership, that evidence might include risk assessments, WISP versions, security policies, employee training records and certificates, vendor assessments and contracts, access reviews, vulnerability assessments, penetration testing reports, security monitoring records, incident and remediation records, backup testing records, management reports, compliance reviews, meeting records, and approval records. The exact evidence a dealership needs will depend on its circumstances and compliance program. But the principle is simple: don't just say you did it. Keep evidence that shows you did it.
Your WISP is only as good as its implementation
Let's take a common example. Your WISP says: "Employees will receive security awareness training." That's a policy statement. Now imagine your dealership has 20 employees. You trained 18 of them. Two never completed the training. Six months later, nobody remembers who the two employees were. The WISP still says employees receive training — but your records tell a different story. This is why a good compliance program needs more than policies. It needs execution and documentation. The FTC's Safeguards Rule specifically addresses security awareness training, monitoring and testing, vendor oversight, incident response, risk assessments, and keeping the information security program current. Each of those activities can generate evidence, and that evidence shouldn't disappear into someone's inbox.
What about your risk assessment?
A risk assessment shouldn't be treated as a document you create once a year just to satisfy a requirement. It should help management understand the dealership's actual risk. For example:
- Risk identified: Former employees may retain access to dealership systems.
- Current safeguard: User accounts are disabled when HR submits a termination request.
- Gap: No formal access review is performed.
- Remediation: Implement quarterly access reviews — owned by the IT Manager, due September 30, status completed, evidenced by the access review report. Now you have something useful. You aren't simply saying "we manage employee access." You can show how you manage it, who owns it, what was identified, and what was done about it. That's a much stronger compliance posture.
What happens when you find a problem?
This is another area where documentation matters. Say your dealership performs a security assessment and discovers that several employee accounts aren't protected by MFA. Finding the problem is good. Fixing it is better. Documenting the process is better still.
- Finding: MFA not enabled for certain accounts.
- Risk: Increased risk of unauthorized access.
- Action: MFA enabled by IT — identified August 5, remediated August 8, verified with a follow-up review. Now you have a record of continuous improvement. That's what a living compliance program looks like.
The "we have it somewhere" problem
There's another problem dealerships often face: the evidence exists, it's just scattered everywhere. The risk assessment is on someone's laptop. The WISP is in a shared folder. Training certificates are in email. Vendor contracts are in accounting. The penetration test is with the MSP. The incident report is in a Word document. The management report is in someone's inbox. Technically, you may have everything. Practically, you don't have a compliance system. And when someone needs the complete picture, somebody has to spend hours hunting for documents. That's not a good way to manage compliance.
Your compliance program should tell a story
A strong compliance program should let someone look at your records and understand the story: you identified your risks, evaluated your safeguards, identified gaps, assigned responsibility, took corrective action, tested your controls, documented the results, updated the program — and management reviewed it. That's much more meaningful than a folder full of disconnected documents.
The annual report is part of that story
The FTC's Safeguards Rule requires the designated Qualified Individual to report in writing at least annually to the board of directors or other governing body regarding the overall status of the information security program and material matters related to it. For an independent dealership, that governing body may be the dealer principal, ownership group, or another appropriate governing authority. That report should give leadership visibility into what risks were identified, what testing was performed, what incidents occurred, what vendors create significant risk, what remediation work was completed, and what still needs attention. You can't produce a meaningful annual report if you don't have a reliable record of what happened throughout the year.
A simple test: the 30-minute challenge
Here's something worth trying. Set a timer for 30 minutes, then ask whoever's responsible for compliance to gather the current WISP, the current risk assessment, employee training records, the vendor list and assessments, security testing records, the incident response plan, recent remediation records, compliance activity history, and the most recent management report. Don't give them a week. Don't let them reconstruct everything from memory. Just see what happens. If they can quickly produce everything, that's a very good sign. If they spend most of the 30 minutes searching through emails and shared folders, you've learned something important — your dealership may have a documentation problem, and documentation problems are much easier to fix when you discover them before you need the documents.
Where Sterling Safeguard fits
This is one of the central problems Sterling Safeguard was designed to solve. Compliance shouldn't depend on one employee remembering where everything is stored, an Excel spreadsheet nobody updates, or the dealer principal chasing five different people every time management wants to know where the dealership stands. Risk Assessment. The Risk Assessment Engine helps your dealership identify risks, evaluate safeguards, document gaps, and track remediation. Living WISP. The Living WISP Generator helps create a dealership-specific Written Information Security Program that can be updated as your dealership changes. Evidence Vault. One organized place for policies, assessments, training records, vendor documentation, testing reports, and other compliance evidence. Vendor Management. Track vendors, their risk levels, contracts, renewal dates, and access to customer information. Employee Training. Keep training records and certificates organized so you don't have to reconstruct them later. Compliance Calendar. Keep recurring compliance activities visible and on schedule. Audit Timeline. A chronological record of important compliance actions — because sometimes the question isn't just "what did you do?" It's "when did you do it?" FTC Audit Readiness Score™. A straightforward way for dealership leadership to understand the current state of its compliance program and identify areas that need attention. The goal isn't more paperwork — it's visibility.
Compliance shouldn't depend on memory
Imagine being asked "when was the last time your dealership reviewed its vendors?" You shouldn't have to remember — the system should tell you. Same for "when was your last risk assessment," "which employees completed training," "what compliance issues were identified last quarter," and "what did we do to correct them." The evidence should be there. That's the difference between managing compliance and simply having compliance documents.
So, can you prove your dealership is compliant?
That's the question. Not "do we have a WISP," not "do we have an IT company," not "do we have cybersecurity software." But: can we demonstrate that our information security program is actually operating? Can you show your risk assessment, your safeguards, your training, your vendor oversight, your testing, your remediation, your incident response process, your management reporting, and how the program has changed over time? If the answer is yes, you're in a much stronger position. If the answer is "I'm not sure," that's not necessarily a crisis — but it is a reason to start organizing your program now.
Don't wait until someone asks
The worst time to discover that your compliance evidence is scattered is when someone is asking for it. Build the record while you're doing the work: document the assessment, save the training record, record the vendor review, track the remediation, keep the testing results, update the WISP, and record important compliance activities. Then, when someone asks "can you prove it?" — you don't have to start searching. You can simply show them. Not sure where your dealership stands today? A risk assessment isn't the same as a complete compliance program, and it doesn't replace legal or professional advice — but it's a practical first step toward understanding your dealership's risks and building a stronger, more organized program. Know your risks. Close your gaps. Keep your evidence. Stay ready. Sterling Safeguard — FTC Safeguards Rule Compliance Built for Independent Auto Dealerships. Take the free FTC risk assessment here. This publication is provided for educational and informational purposes only and does not constitute legal advice. The FTC Safeguards Rule may apply differently depending on a dealership's specific activities and circumstances. Dealerships should consult qualified legal or compliance professionals regarding their specific obligations.