Skip to main content
AdvisoryBy Rutvi VaderaAugust 28, 202610 min read

The GLBA Qualified Individual: Who Qualifies and Can You Outsource It?

The GLBA Qualified Individual: Who Qualifies and Can You Outsource It?

The direct answer: under the FTC Safeguards Rule, every covered financial institution must designate a single Qualified Individual to oversee and implement its information security program, and that person must report in writing to the board or governing body at least annually. There is no certification requirement. The FTC judges qualification by whether the program works, not by credentials. You can assign the role internally or bring in an outside provider such as a vCISO service, and many smaller institutions do. What you cannot do is outsource the responsibility. When a service provider serves as your Qualified Individual, your institution retains full compliance responsibility and must supervise that provider. The designation, and the obligation behind it, always stay with you.

Status verified August 27, 2026. This page is updated when the regulatory status changes.

This page answers the designation question specifically. For the full rule, including the nine required elements of a written information security program, see our GLBA Safeguards Rule compliance guide. For what the FTC is actually penalizing this year, see the 2026 Safeguards enforcement breakdown.

What the rule actually requires

The revised Safeguards Rule has been fully mandatory since June 9, 2023. Among its requirements, three define the Qualified Individual role. First, the designation itself: one named person, singular, who oversees and implements the information security program. Second, ongoing oversight: the Qualified Individual is the accountable point for the risk assessment, the safeguards, the testing, and the incident response planning that the rule requires. Third, governance: a written report to the board or an equivalent governing body at least once a year.

The rule applies to non-bank financial institutions, which is a far wider net than most executives assume: auto dealers that arrange financing, mortgage brokers, payday and title lenders, tax preparers, collection agencies, investment advisers not registered with the SEC, fintechs without bank charters, and higher-ed institutions under GLBA. The FTC's own Safeguards Rule FAQ for auto dealers is the clearest agency statement of how the designation works in practice, and its June 2025 updated guidance restates the expectations for the full covered population.

Who qualifies: no certification, judged by outcomes

The rule sets no credential bar. No CISSP, no degree, no minimum years of experience. "Qualified" is measured against the size and complexity of your institution and the sensitivity of the customer information you hold. A ten-location dealership group and a two-partner tax practice can both satisfy the rule with very different people in the seat.

That flexibility cuts both ways. Because there is no credential test, the FTC evaluates qualification by what the program produces: a current written risk assessment, safeguards that map to it, testing that actually happened, and a board report that reflects reality. A Qualified Individual who cannot produce those artifacts is not qualified in the only sense that matters at exam time. Conversely, a controller with no security background who runs a disciplined program, with the right support behind them, meets the standard. The rule cares about the program, not the resume.

Can you outsource it? Yes, with three strings attached

The Safeguards Rule explicitly permits the Qualified Individual to be an employee, an affiliate, or a service provider. This is how most smaller institutions close the gap, because an auto dealer, a consumer lender, or a tax practice generally cannot hire a full-time security executive, and the rule was written knowing that. Outsourced and fractional arrangements, including vCISO services, are a legitimate and common way to staff the role.

Three conditions attach the moment you use a provider. Your institution retains full compliance responsibility for the Safeguards Rule. You must supervise the provider. And you must designate a senior member of your own personnel to direct and oversee that provider, which means the buck still stops with a named employee on your payroll, not with the firm you hired. Neither condition is fine print. They are the structure of the rule: the FTC regulates you, not your vendor, and a designation letter naming an outside firm does not move the obligation an inch. Commentary aimed at the broader covered population, such as this analysis of the updated rule for all non-bank financial institutions, makes the same point: outsourcing the work is allowed, outsourcing the accountability is not.

You can outsource You cannot outsource
The day-to-day work of the role: running the risk assessment, drafting the program, coordinating testing, preparing the board reportCompliance responsibility for the Safeguards Rule
Security expertise your institution does not employThe duty to supervise whoever performs the role
The Qualified Individual seat itself, to a service provider, if you choose to structure it that wayThe decisions: accepting risk, approving the program, acting on recommendations
Program operations: monitoring, vendor reviews, awareness training deliveryAnswering to the FTC when the program fails

Our own position at Z Cyber is deliberately conservative on this. The Qualified Individual designation and the responsibility behind it always remain with the client. A Z Cyber advisor leads and runs the program work that supports your Qualified Individual: the risk assessment, the written program, the testing cadence, the board report draft. The advisor recommends; your institution decides, approves, and owns the risk. We do not hold the designation, because the rule never lets the obligation leave your building, and pretending otherwise serves the vendor, not you.

Just got named your institution's Qualified Individual?

A Z Cyber advisor can walk you through the current state of your program and lead the work your designation depends on.

Talk to an Advisor →

The annual board report

The written report to the board, at least annually, is the most concrete recurring duty of the role and the artifact an examiner will ask for first. It should cover the overall status of the information security program and your institution's compliance with the rule, the results of the written risk assessment, testing and monitoring outcomes, security events during the period and how management responded, and recommended changes to the program. If your institution has no board, the report goes to a senior officer responsible for the program. Treat it as a dated record, not a formality: a report that says the same thing every year, or that skips the risk assessment results, reads as evidence that the program is nominal.

The first 90 days for the accidental Qualified Individual

Most Qualified Individuals at mid-market institutions did not apply for the job. A controller, an IT manager, or a general manager got named because the rule demanded a name. If that is you, the sequence below turns a designation on paper into a defensible program.

Days 1 to 30: find out what exists. Locate the written risk assessment, or confirm there is not one, because everything else in the rule hangs off it. Inventory the current state of the program against the nine required elements in our Safeguards Rule guide. Identify who actually operates each control today: who manages access, who holds the MFA configuration, which vendors touch customer information. Do not fix anything yet. You cannot prioritize what you have not mapped.

Days 31 to 60: close the loudest gaps. Enforcement attention concentrates on the controls that are binary and visible: MFA on access to customer information systems, encryption of customer data, a written incident response plan, and vendor oversight. If the risk assessment does not exist, commission it now, whether internally or with outside support. This is also the window to decide honestly whether you can run this program alongside your actual job, or whether you need a provider behind you.

Days 61 to 90: establish the rhythm. Draft your first board report using the contents above, even if the honest version is uncomfortable. A report that says "here is where we are, here are the gaps, here is the plan" is exactly what the rule contemplates. Set the recurring cadence: when the risk assessment gets refreshed, when testing happens, when the next report is due. A program with a calendar survives. A program that depended on a 90-day burst does not.

Why the designation gap is expensive in 2026

Enforcement against non-bank financial institutions escalated through 2026, and an unfilled or nominal designation is the first thing an investigator can see. We cover the enforcement record, who is covered, and the penalty exposure in the FTC Safeguards Rule in 2026. The point for this page is narrower: every one of those obligations runs through the Qualified Individual, so a designation that exists only on paper is where the program fails first.

Staffing the role: your options

You have three workable structures. Name an internal person and resource them properly, which works when someone senior has the bandwidth and the institution can buy them expert support. Contract a fractional or vCISO arrangement to hold the expertise while an internal officer supervises. Or pair an internal Qualified Individual with a standing advisory team that runs the program work under them, which is the model behind our Executive Security Advisor service: a named advisor leads the risk assessment, the program build, the testing cadence, and the board report preparation, while your institution keeps the designation, makes the decisions, and owns the risk. Whichever structure you choose, the rule's logic is constant. Someone qualified must run the program, the board must hear about it every year, and the responsibility never leaves your institution.

What to watch next

Three things. FTC enforcement against non-bank financial institutions has been escalating through 2026, and the March warning letters to auto dealerships signal where attention is going. Your next annual board report is a fixed obligation, so calendar it rather than discovering it late. And if you use a service provider, the designation of the senior employee who directs that provider should be revisited whenever that person changes roles, because the rule attaches the duty to a person and not to a job title. This page is updated when the rule or its enforcement posture changes.

Frequently Asked Questions

Who qualifies as a GLBA Qualified Individual?

The FTC Safeguards Rule does not require any certification, degree, or title. A Qualified Individual is anyone with the knowledge and experience to oversee and implement your information security program, judged against the size and complexity of your institution. In practice the FTC evaluates qualification by outcomes: whether the risk assessment exists, whether the required safeguards are in place, and whether the board receives the annual written report. A controller or general manager can hold the role if the program actually runs.

Can we outsource the GLBA Qualified Individual role?

Yes. The Safeguards Rule allows the Qualified Individual to be an employee, an affiliate, or an outside service provider such as a vCISO or MSSP. Two conditions attach when you use a provider: your institution retains full compliance responsibility, and you must supervise the provider. Outsourcing buys expertise and execution capacity. It does not transfer the legal obligation. If the program fails, the FTC looks at your institution, not your vendor.

What must the Qualified Individual's annual board report include?

The Qualified Individual must report in writing to the board or an equivalent governing body at least once a year. The report should cover the overall status of the information security program, the results of the written risk assessment, testing and monitoring outcomes, security events and how management responded, and recommended changes to the program. If your institution has no board, the report goes to a senior officer responsible for the program.

Does the Qualified Individual need a CISSP or other certification?

No. The Safeguards Rule imposes no certification requirement on the Qualified Individual. The FTC deliberately left qualification flexible so that a small lender or dealership is not forced to hire a credentialed security executive it cannot afford. The tradeoff is that competence is judged by the state of the program itself. A certification does not satisfy the rule, and the absence of one does not violate it.

What happens if we never designated a Qualified Individual?

You have a visible compliance gap in a rule that has been fully mandatory since June 9, 2023. The designation is one of the first things an FTC inquiry asks about because it is binary: either a named person oversees the program or no one does. Enforcement pressure on non-bank financial institutions is rising, with 97 warning letters sent to auto dealerships in March 2026 and civil penalty exposure cited at up to $51,744 per violation per day. Naming a Qualified Individual is the fastest gap to close.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.