← Back to Compliance Insights

September 5, 2026  ·  Jonah Gobah

I Have an IT Company. Does That Mean I'm FTC Compliant?

Short answer: No. Having an IT company or managed service provider (MSP) does not mean your dealership is FTC Safeguards Rule compliant. An MSP typically handles technical infrastructure — network uptime, hardware, software patches — while Safeguards Rule compliance requires specific documentation your MSP usually doesn't produce: a designated Qualified Individual, a written risk assessment, employee training records, and a written incident response plan tied specifically to your dealership.

Why this misunderstanding is so common

It's an easy assumption to make. You're paying a company to "handle IT," security gets mentioned somewhere in that relationship, and it feels reasonable to conclude the compliance side is covered too. Most MSPs aren't trying to mislead anyone here — they're doing the job they were hired for, which is keeping systems running and reasonably secure. But "reasonably secure systems" and "documented FTC Safeguards Rule compliance" are different deliverables, and very few general-purpose MSPs produce the second one as part of a standard IT contract.

What an MSP typically does provide

  • Network monitoring and maintenance
  • Software updates and patching
  • Basic firewall and antivirus management
  • Help desk support for day-to-day issues
  • Sometimes, general security recommendations

All of that is genuinely useful. None of it, on its own, satisfies the Safeguards Rule.

What an MSP typically does NOT provide

  • A documented risk assessment specific to your dealership's customer data
  • A formally designated Qualified Individual (this needs to be a specific person, usually at your dealership, not a vendor)
  • Employee training records with completion proof, tied to Safeguards Rule requirements specifically
  • A written incident response plan that satisfies the rule's documentation requirements
  • Vendor oversight documentation covering your other vendors, not just themselves

What to actually ask your MSP

If you want a clear answer instead of an assumption, ask directly:

  1. "Do you provide a written risk assessment that satisfies the FTC Safeguards Rule, with a date?"
  2. "Can you name our Qualified Individual, and is that documented in writing?"
  3. "Do you maintain employee training records specifically tied to Safeguards Rule requirements?"
  4. "Do we have a written incident response plan, and have you reviewed it with us?"
  5. "If a lender asked for our compliance documentation tomorrow, could you produce it same-day?"

If the answer to any of these is unclear, vague, or "that's not really what we do," that's not a criticism of your MSP — it likely just means their contract was never scoped to cover this, and you have a real gap.

Closing the gap without replacing your MSP

You don't need to fire your IT company to fix this. Most dealers keep their MSP for infrastructure and add a dedicated compliance platform for the documentation side. Sterling Safeguard was built specifically to fill this gap — the risk assessment, Qualified Individual designation, training records, and incident response plan your MSP likely isn't producing.

Run the free FTC Safeguards Rule risk assessment →

FREE DOWNLOAD

FTC Safeguards Rule Readiness Checklist

The 9-point checklist every dealer needs. Delivered instantly to your inbox.

Sterling Safeguard

Ready to get your dealership FTC compliant?

Sterling Safeguard gives you everything you need — written security program, risk assessments, employee training, and the Verified™ seal — without hiring a consultant or a law firm.

Get Started →More Articles