Short answer: Any vendor that can access, store, process, or transmit your customers' nonpublic financial information needs to be included in your FTC Safeguards Rule vendor assessment. For most independent dealerships, that list includes your DMS provider, your F&I platform, your marketing and CRM tools, your IT/MSP provider, your payment processor, and any third-party lender integration — a longer list than most dealers initially assume.
Why the vendor list matters as much as your own systems
The Safeguards Rule doesn't stop at your own dealership's walls. If a vendor you use has weak security and that vendor holds or touches your customers' financial data, that's your exposure too — not just theirs. The rule specifically requires dealers to assess vendor risk and contractually require vendors to maintain adequate safeguards, which means "we use a reputable company" isn't sufficient on its own. You need documented evidence of vetting.
The core vendor categories to include
Your DMS (Dealer Management System). This is usually the biggest concentration of customer data in your operation — deal records, financing details, personal information. If you haven't reviewed your DMS provider's security practices directly, this is the first place to start.
Your F&I (Finance & Insurance) platform. Credit applications, income information, financing terms — this is exactly the kind of nonpublic financial data the rule is built around protecting.
Marketing and CRM tools. Easy to overlook because they don't feel "financial," but if your CRM stores customer contact information alongside deal or financing status, it's in scope.
Your IT provider or MSP. They often have broad access across your systems by nature of their role, which makes their own security practices directly relevant to yours.
Payment processors. Any platform handling payments, deposits, or financial transactions on your customers' behalf.
Third-party lenders and financing integrations. If your dealership routes applications to outside lenders electronically, that data transfer point is part of your risk surface too.
What "included in the assessment" actually means
For each vendor on this list, you need more than just a name on a spreadsheet. The rule expects:
- Documentation of what data the vendor can access
- Evidence you've evaluated their security practices (a security questionnaire, SOC 2 report, or similar)
- Contract language requiring them to maintain adequate safeguards
- A process for re-evaluating the relationship if something changes
Why dealers often underestimate this list
Most independent dealers can name their DMS and F&I provider without thinking twice. Fewer immediately think to include their marketing platform, payment processor, or IT provider — but an examiner or auditor reviewing your vendor assessment will expect all of them accounted for, not just the obvious two.
Building this out without missing anyone
The safest way to build a complete vendor list is to walk through every system that touches a customer record, rather than relying on memory. Sterling Safeguard's risk assessment includes a guided vendor inventory step designed to surface the ones dealers commonly forget, not just the obvious ones.