Safeguards Rule proof,
before anyone asks for it.
Thirteen of the requirements for non-bank financial institutions. The platform evidences six — and we name the other seven.
Request an initial conversationThirteen of the requirements in 16 CFR 314.4 — what this page walks through, one by one.
30days
To notify the FTC — as soon as possible, and no later than 30 days from the day the event is discovered. In effect since May 13, 2024.
500
Consumers affected — the threshold that triggers § 314.4(j).
5,000
Where § 314.6 draws a line: below it, parts of four requirements fall away — the written risk assessment, the testing schedule, the incident response plan, and the annual report. On which side of that line a business falls is for the FTC and for counsel to say.
Six of thirteen. Not all thirteen.
Most vendors answer this with a column of checkmarks. Here is the actual split.
6/13
carried by the platform. The rest is named, not hidden.
Qualified Individual
§ 314.4(a)
Risk assessment
§ 314.4(b)
Access controls
§ 314.4(c)(1)
Inventory
§ 314.4(c)(2)
Encryption
§ 314.4(c)(3)
Multi-factor authentication
§ 314.4(c)(5)
Monitoring and testing
§ 314.4(d)
Training
§ 314.4(e)
Service providers
§ 314.4(f)
Evaluate and adjust
§ 314.4(g)
Incident response plan
§ 314.4(h)
Report to the board
§ 314.4(i)
FTC notification
§ 314.4(j)
Platform — six requirements Mahoney Control continuously measures and evidences.
Service — three that no software can satisfy: a named individual, encryption in your environment, and training. How they get covered is part of that conversation.
Indirect — two the platform sees through a composite signal, not control by control. Not claimed — the annual report to the board and the periodic evaluation of the program. For the report the platform holds much of the substance; for the evaluation we make no claim. Neither is presented as satisfied.
§ 314.4(b) · (c)(2) · (d) · (f)
The evidence writes itself
-
Scored, not estimated
A structured assessment produces a result and a risk index.
-
Current between reviews
The inventory is fed by the stack you already run.
-
Signals become evidence
Endpoint detection, log management, and patch status — each with an audit trail.
What you end up holding
Printable on the day it is asked for
-
Status, source, date
Carried per control, as far as the platform can evaluate it — not a folder assembled the week before a review.
-
Vendors and where they sit
Each one recorded with its data processing agreement.
-
Where the assessment stops
The platform records whether an agreement exists. Assessing its adequacy remains legal work.
How thirteen of the requirements in 16 CFR 314.4 divide in practice — what Mahoney Control measures, what Mahoney IT delivers as a service, and what neither claims. Measuring a requirement is not the same as satisfying it; whether a program meets the Rule is for an examiner and for counsel to say.
The transition
One requirement starts a clock.
Twelve of the thirteen are ongoing duties. The thirteenth is different: it begins on a single day, and that day is often recognized only after the fact.
Thirty days, counted from discovery
-
The incident happens
Nobody has to notice it yet. The event itself does not start anything.
- The clock starts here
Anyone at the business knows
An employee, officer, or agent — anyone other than the person who committed it. From this point on, the business is deemed to know.
-
Management is told
Often days later. The clock does not restart here — it has been running since the step before.
-
By day 30 — notice to the FTC
Counted from discovery, not from the day the report reached a desk — where the event meets the threshold in the Rule.
Thirty days sounds generous until the clock starts on a day nobody logged, and the count depends on an inventory nobody kept. Mahoney Control records both as they happen. The deadline is the regulation’s, not a service commitment of ours.
Bring the day you’d have to account for
A platform can hold the evidence.
It cannot decide whether the Rule reaches you.
Where we start, and where we stop
Mahoney IT
What you can evidence under the Rule.
Six frameworks ship with the platform: ISO 27001, NIS 2, SOC 2 Type II, NIST CSF, HIPAA and GDPR. The Safeguards Rule is not one of them — it is carried as your own rule set, loaded and scored the same way. Selecting a framework does not make anyone compliant — the product says so on the screen where you select one.
See it against your own controlsYour counsel and the FTC
Who the Rule covers in the first place.
The Rule reaches non-bank financial institutions. Whether your business is one of them is a question for your counsel and the FTC — a vendor who answers it is guessing about your business and handing you a legal conclusion at the same time.
Read the FTC’s own guidanceMahoney Control maps client controls against these frameworks. That mapping is not a certification of Mahoney IT or of any client. Certification is issued by independent auditors against their own criteria. Mahoney IT Group Germany holds ISO 9001:2015, certified by DEKRA — a quality management certification, which says nothing about the requirements described on this page.
Questions that decide the engagement
Does Mahoney Control make your business compliant with the FTC Safeguards Rule?
No, and no software does. Compliance is an outcome an examiner or auditor confirms. Mahoney Control keeps the controls, signals, and documents that a review asks to see, scored against your rule set and exportable at any point. The requirements the platform does not cover — a named Qualified Individual, encryption inside the client environment, and training — are not product features. How they get covered is part of the initial conversation.
Is the Safeguards Rule one of the frameworks built into the platform?
No. The platform ships with six recognized frameworks: ISO 27001, NIS 2, SOC 2 Type II, NIST CSF, HIPAA, and GDPR. The Safeguards Rule is carried as your own rule set — the platform loads your written program, extracts its rules, and scores them like the built-in ones. Mapping controls against a framework is not a certification of Mahoney IT or of any client; certification is issued by independent auditors against their own criteria.
Does the platform check whether multi-factor authentication is switched on?
Not as a single reading. Where Microsoft 365 is connected, Mahoney Control reads the tenant’s overall Microsoft Secure Score, which reflects sign-in security among other factors. Confirming multi-factor authentication coverage under 16 CFR 314.4(c)(5) is a review activity carried out by people, and Mahoney IT states it that way rather than presenting a composite score as proof.
Do you have to replace your existing tools?
No. Mahoney Control reads the stack that is already in place and turns its signals into evidence. Where a control is missing entirely, that shows up as a gap rather than as a purchase order.
Bring the requirement you’re least able to evidence
Not a demo — a walk through thirteen of the requirements, checked against what your organization can produce today.
Your inquiry could not be sent
This page describes requirements under 16 CFR Part 314 and how Mahoney Control helps produce the evidence behind them. It is not legal advice and does not establish whether any particular business is subject to the Rule. Regulatory citations reflect the text in force on August 19, 2026.