← Back to Compliance Insights

August 11, 2026  ·  Jonah Gobah

The Auto Dealer's FTC Safeguards Rule Compliance Checklist

For many auto dealers, FTC compliance is one of those things that sits somewhere between the IT department, the finance office, the dealer principal, and the person who "usually handles compliance."

That can become a problem.

The FTC Safeguards Rule doesn't simply ask whether your dealership has antivirus software or whether your IT provider has security controls in place. Covered automobile dealers are expected to develop, implement, and maintain a comprehensive written information security program designed to protect customer information. And that means you should be able to demonstrate what you are doing — not just say that you are doing it.

The good news is that compliance doesn't have to be overwhelming. A good place to start is with a simple checklist.

Use the checklist below as a starting point for evaluating your dealership. A "Yes" answer is a good sign. A "No" or "Not Sure" answer identifies an area that deserves attention.

1. Determine whether the Safeguards Rule applies to your dealership

  • ☐ Does your dealership arrange financing for customers?
  • ☐ Does your dealership provide or facilitate financing?
  • ☐ Does your dealership lease automobiles for more than 90 days?
  • ☐ Does your dealership collect financial information from consumers as part of financing or leasing?

If your dealership engages in these activities, the FTC's Safeguards Rule may apply. The FTC specifically states that most automobile dealers that finance or lease automobiles are covered financial institutions under the Rule.

Why this matters: You don't have to call yourself a bank to have responsibilities under the Safeguards Rule. Your activities can determine whether the Rule applies.

2. Know what customer information you have

You can't protect information you don't know you have. Start by identifying the information your dealership collects, processes, stores, or shares.

  • ☐ Customer names and addresses
  • ☐ Social Security numbers
  • ☐ Driver's license information
  • ☐ Income and employment information
  • ☐ Credit applications
  • ☐ Financial account information
  • ☐ Financing and leasing records
  • ☐ Other nonpublic personal information
  • ☐ Paper records containing customer information
  • ☐ Electronic records containing customer information

The FTC specifically identifies financing and leasing applications, financial information, and certain customer lists as examples of information covered by the Safeguards Rule.

Ask yourself: if someone asked me to identify every location where our customers' sensitive information is stored, could I do it? If the answer is "I'm not sure," that's a risk worth addressing.

3. Know where the information lives

Customer information rarely lives in one place. It may be spread across your DMS, CRM, F&I systems, email, Microsoft 365 or Google Workspace, shared drives, cloud applications, employee computers, laptops, mobile devices, paper files, backup systems, and third-party systems.

  • ☐ We have identified the systems containing customer information.
  • ☐ We know who owns each system.
  • ☐ We know who has access.
  • ☐ We understand how information moves between systems.
  • ☐ We know which vendors have access to customer information.

The Safeguards Rule applies not only to systems containing customer information but also to information systems connected to systems containing that information, subject to the Rule's requirements.

4. Assign responsibility for information security

Someone needs to own the program.

  • ☐ We have designated a qualified individual to oversee our information security program.
  • ☐ The person's responsibilities are clearly defined.
  • ☐ Management understands who is responsible for the program.
  • ☐ The qualified individual has sufficient authority and resources to perform the role.

The FTC's Rule requires covered financial institutions to designate a qualified individual to oversee and implement the information security program. That person can be an employee, an affiliate, or an appropriate service provider.

This is important because "our IT company handles security" isn't necessarily the same thing as having a clearly defined compliance responsibility.

5. Complete a written risk assessment

This is one of the foundations of the program.

  • ☐ We have completed a written risk assessment.
  • ☐ The assessment identifies internal risks.
  • ☐ The assessment identifies external risks.
  • ☐ We have evaluated our existing safeguards.
  • ☐ We have documented identified gaps.
  • ☐ We have documented how identified risks will be addressed.
  • ☐ The risk assessment is reviewed periodically.

The FTC says the written information security program should be based on a risk assessment that identifies reasonably foreseeable internal and external risks to customer information and evaluates the safeguards used to control those risks.

A risk assessment shouldn't be a document created once and forgotten. Your dealership changes. Your technology changes. Your employees change. Your vendors change. Your risks change. Your assessment should keep up.

6. Have a written information security program

  • ☐ We have a written Information Security Program/WISP.
  • ☐ The program reflects our actual dealership environment.
  • ☐ The program addresses administrative safeguards.
  • ☐ The program addresses technical safeguards.
  • ☐ The program addresses physical safeguards.
  • ☐ The program is reviewed and updated when circumstances change.

The FTC requires the information security program to be appropriate to the dealership's size and complexity, the nature and scope of its activities, and the sensitivity of the information involved. In other words, your WISP should not simply be a generic document downloaded from the internet. It should describe your dealership.

7. Control access to customer information

Not everyone in the dealership needs access to everything.

  • ☐ We maintain user accounts for employees.
  • ☐ Employees only receive the access they need to perform their jobs.
  • ☐ Administrative privileges are restricted.
  • ☐ Access is reviewed periodically.
  • ☐ Former employees have their access removed promptly.
  • ☐ Employees who change roles have their access adjusted.
  • ☐ Shared accounts are limited or eliminated where appropriate.

Access controls are specifically identified by the FTC as one of the safeguards covered financial institutions should implement to control identified risks.

A simple question to ask is: if an employee left the dealership today, could we prove that their access was removed?

8. Implement multifactor authentication

  • ☐ MFA is enabled for appropriate systems.
  • ☐ MFA is used by employees who access information systems containing customer information.
  • ☐ Privileged accounts receive appropriate protection.
  • ☐ MFA exceptions are documented and addressed.

The Safeguards Rule specifically addresses multifactor authentication for individuals accessing information systems containing customer information, subject to the Rule's requirements. MFA is not a complete cybersecurity strategy. But it is an important layer of protection.

9. Protect customer information with encryption

  • ☐ Customer information is encrypted where required.
  • ☐ Information is protected while being transmitted.
  • ☐ Information stored on appropriate systems is protected.
  • ☐ Encryption practices are documented.

The FTC identifies encryption of customer information at rest and in transit among the safeguards addressed by the Safeguards Rule. The goal isn't to check a box that says "encryption." The goal is to understand where sensitive information travels and how it is protected along the way.

10. Monitor and test your security controls

Security controls should not simply exist. They should be tested.

  • ☐ We monitor our information systems.
  • ☐ We review relevant security activity and logs.
  • ☐ We conduct vulnerability assessments as required.
  • ☐ We conduct penetration testing when required.
  • ☐ Findings are documented.
  • ☐ Identified weaknesses are remediated.

The FTC's guidance addresses continuous monitoring and, where continuous monitoring isn't used, vulnerability assessments at least every six months and penetration testing at least annually.

This is where documentation becomes extremely important. If a test identifies a vulnerability, don't just fix it and move on. Document what was found, what was done, who handled it, when it was resolved, and what evidence supports the resolution.

11. Train your employees

Your employees are part of your security program.

  • ☐ Employees receive security awareness training.
  • ☐ Training is appropriate to their responsibilities.
  • ☐ New employees receive training.
  • ☐ Training is repeated as appropriate.
  • ☐ Training completion is documented.
  • ☐ Certificates or other evidence are retained.
  • ☐ Employees with specialized security responsibilities receive appropriate training.

The FTC specifically includes security awareness training as part of the safeguards covered institutions should implement. And remember: training without records is difficult to demonstrate. If you train 25 employees, you should be able to show that those 25 employees actually completed the training.

12. Review your vendors

Your dealership probably depends on a long list of outside companies — your DMS provider, CRM provider, MSP, cloud provider, payment processor, marketing provider, IT security provider, document management provider, and other technology vendors may have some level of access to your systems or customer information.

  • ☐ We maintain a list of vendors.
  • ☐ We know which vendors have access to customer information.
  • ☐ Vendor risk is assessed.
  • ☐ Appropriate security requirements are included in contracts.
  • ☐ Vendor security is reviewed periodically based on risk.
  • ☐ Vendor contracts are tracked.
  • ☐ Contract renewal dates are monitored.

The FTC expects covered financial institutions to take reasonable steps when selecting and retaining service providers, including requiring appropriate safeguards through contractual arrangements and periodically assessing providers based on the risk they present. Your dealership may have excellent security controls. But if a vendor with access to your customer information has weak controls, that relationship can still create risk.

13. Have an incident response plan

Hope is not an incident response strategy.

  • ☐ We have a written incident response plan.
  • ☐ We know who is responsible for responding to an incident.
  • ☐ We have defined escalation procedures.
  • ☐ We have documented communication procedures.
  • ☐ We have procedures for containing and recovering from an incident.
  • ☐ We document security incidents.
  • ☐ We know when legal or regulatory notification may be required.

The Safeguards Rule requires covered institutions to have a written incident response plan addressing how they will respond to and recover from security events affecting customer information. The FTC also has breach notification requirements for certain security incidents involving customer information, which took effect in May 2024. This is not something you want to figure out after the breach happens.

14. Protect physical records

Cybersecurity isn't only about computers.

  • ☐ Paper customer records are secured.
  • ☐ File cabinets containing sensitive information are appropriately protected.
  • ☐ Access to physical records is restricted.
  • ☐ Sensitive documents are securely destroyed when no longer needed.
  • ☐ Employees understand how to handle physical customer information.

The FTC specifically notes physical safeguards, including securing file cabinets containing paper records with customer information. That old filing cabinet in the finance office is part of your security program too.

15. Keep the program current

This may be one of the most overlooked parts of compliance.

  • ☐ We periodically review our information security program.
  • ☐ We update the program when our business changes.
  • ☐ We update it when technology changes.
  • ☐ We address findings from security testing.
  • ☐ We update our risk assessment.
  • ☐ We review changes in vendors and systems.
  • ☐ We document important changes.

The FTC expects covered institutions to keep their information security programs current and make adjustments based on monitoring, testing, risk assessments, vulnerabilities, and material changes to the business. Compliance should not be a once-a-year event. It should be an ongoing process.

16. Document everything

This is where many dealerships can improve. Ask yourself: if someone asked us to prove that we are doing these things, could we?

  • ☐ Risk assessment
  • ☐ WISP
  • ☐ Employee training records
  • ☐ Vendor assessments
  • ☐ Vendor contracts
  • ☐ Security testing reports
  • ☐ Vulnerability assessments
  • ☐ Penetration testing reports
  • ☐ Incident response plan
  • ☐ Incident records
  • ☐ Access reviews
  • ☐ Security policies
  • ☐ Evidence of remediation
  • ☐ Annual management reporting

Documentation turns your compliance program from a collection of intentions into something you can actually demonstrate. The FTC's Safeguards Rule also requires the qualified individual to report in writing at least annually to the board of directors or other governing body regarding the overall status of the information security program and material matters related to it.

So, how did your dealership score?

Here's a simple way to look at your results.

🟢 Green — you're in good shape. Most of your answers are "Yes," and you have documentation to support them. Keep monitoring, testing, documenting, and improving.

🟡 Yellow — some work is needed. You have a program, but several areas are incomplete, outdated, or poorly documented. This is where many dealerships probably find themselves.

🔴 Red — significant gaps exist. You answered "No" or "Not Sure" to many of the questions. You may not have a complete written program, risk assessment, vendor oversight process, training records, or documented evidence. Don't panic. But don't ignore it either. The first step is understanding exactly where the gaps are.

The biggest mistake: confusing technology with compliance

A dealership can have Microsoft 365, MFA, antivirus, firewalls, EDR, backup systems, a managed IT provider, and cyber insurance — and still have significant gaps in its FTC compliance program.

Why? Because the Safeguards Rule is not simply asking "do you have cybersecurity technology?" It is asking whether you have a comprehensive information security program designed to protect customer information and whether you are actually maintaining that program. Technology is part of the answer. It isn't the entire answer.

Where Sterling Safeguard comes in

This is the reason we built Sterling Safeguard. Independent dealerships shouldn't have to manage FTC compliance through a collection of spreadsheets, Word documents, email reminders, shared folders, and disconnected systems. Sterling Safeguard brings the major pieces of an FTC compliance program together in one platform.

Assess — Use the FTC Risk Assessment Engine to identify risks, evaluate safeguards, identify gaps, and establish a measurable compliance posture.

Build — Create and maintain your dealership's Written Information Security Program (WISP).

Organize — Keep policies, assessments, training records, vendor documents, reports, and other compliance evidence in the Evidence Vault.

Manage — Track vendors, employee training, compliance activities, important deadlines, and remediation tasks.

Respond — Maintain your Incident Response Center so your dealership has a documented process when something goes wrong.

Demonstrate — Use the Audit Timeline, compliance records, and FTC Audit Readiness Score™ to understand how prepared your dealership is and demonstrate the work that has been completed.

The goal is simple: make FTC compliance easier to manage and easier to demonstrate.

Your dealership doesn't have to be perfect. It needs to be prepared.

If you went through this checklist and discovered a few "No" answers, that's okay. The purpose of a checklist isn't to make you feel like you've failed. It's to show you where you need to focus.

Start with the basics. Know what customer information you have. Understand where it lives. Identify who has access. Complete your risk assessment. Build your WISP. Train your employees. Review your vendors. Test your safeguards. Prepare for incidents. And document what you do. Then keep the program alive.

Because FTC compliance isn't something you finish once. It's something you manage.

Is your dealership FTC audit ready?

Sterling Safeguard helps independent auto dealerships organize, manage, and demonstrate their FTC Safeguards Rule compliance program from one platform.

Know your risks. Close your gaps. Protect your customers. Demonstrate your compliance.

This publication is provided for educational and informational purposes only and does not constitute legal advice. The FTC's Safeguards Rule and related requirements may vary based on a dealership's activities and circumstances. Dealerships should consult qualified legal or compliance professionals regarding their specific obligations.

FREE DOWNLOAD

FTC Safeguards Rule Readiness Checklist

The 9-point checklist every dealer needs. Delivered instantly to your inbox.

Sterling Safeguard

Ready to get your dealership FTC compliant?

Sterling Safeguard gives you everything you need — written security program, risk assessments, employee training, and the Verified™ seal — without hiring a consultant or a law firm.

Get Started →More Articles