← Back to Compliance Insights

September 5, 2026  ·  Jonah Gobah

How Often Should a Dealership Perform an FTC Risk Assessment?

Short answer: At minimum, once a year. But the FTC Safeguards Rule doesn't just want an annual calendar reminder — it expects your risk assessment to reflect your current systems, which means specific events (a new DMS, a new F&I vendor, a breach or near-miss, significant staff changes) should trigger an update regardless of when your last annual review happened.

Why "once a year" is the floor, not the whole answer

The rule requires periodic reassessment, and most guidance points to annual as the baseline expectation. But treating this as a once-a-year checkbox misses the actual intent behind the requirement. A risk assessment is supposed to reflect where your customer data lives and what threatens it — and both of those things change continuously, not on a calendar schedule.

If your dealership switched DMS providers in March but your risk assessment is dated from the previous December, that document no longer accurately describes your actual risk. Technically you did your "annual" assessment. Practically, it's already out of date.

Specific events that should trigger a fresh assessment

A new DMS, F&I platform, or major software change. These systems are where most customer financial data lives. Changing one changes your risk profile immediately, not next year.

Adding or changing vendors with data access. A new marketing platform, a new payment processor, a new IT provider — each one is a new potential point of exposure that your existing assessment doesn't account for.

A security incident or near-miss. Even one that didn't result in an actual breach. If something almost went wrong, that's specific evidence your current safeguards have a gap worth reassessing.

Significant staff turnover, especially in roles with data access. New employees need training and access provisioning; departing employees need access revoked. A risk assessment that doesn't reflect current staff isn't reflecting current risk.

Expansion to a new location or additional rooftop. New physical location, new local systems, new local risk factors.

Why dealers tend to let this slide

An annual risk assessment often gets treated as a once-and-done task completed under some deadline pressure — maybe when a lender asked, maybe when an examiner was scheduled — and then not revisited until the next similar prompt. The gap in between is exactly where most dealers' documented risk assessment stops matching their actual operations.

Making this easier to keep current

The reason risk assessments tend to go stale is that redoing one from scratch — especially with an outside consultant — is time-consuming and expensive enough that dealers put it off. A software-based assessment removes that friction, since it can be re-run whenever something changes rather than requiring a new full engagement each time.

Run the free FTC Safeguards Rule risk assessment →

FREE DOWNLOAD

FTC Safeguards Rule Readiness Checklist

The 9-point checklist every dealer needs. Delivered instantly to your inbox.

Sterling Safeguard

Ready to get your dealership FTC compliant?

Sterling Safeguard gives you everything you need — written security program, risk assessments, employee training, and the Verified™ seal — without hiring a consultant or a law firm.

Get Started →More Articles