Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Qualified Individual explained

Qualified Individual: The Complete WISP and Safeguards Rule Guide

The Qualified Individual is the first element of the FTC Safeguards Rule and the person a written information security plan is built around: 16 CFR 314.4(a) requires every covered financial institution to designate a qualified individual responsible for overseeing and implementing its information security program and enforcing it — and the Rule’s own capitalised term for that person is what the industry has adopted. The role can be filled by an employee, an affiliate or a service provider, but if it is outsourced the institution keeps responsibility for compliance, must designate a senior member of its own personnel to direct and oversee that person, and must require the provider to maintain a program that protects the institution. Under 314.4(i) the individual reports in writing, at least annually, to the board or equivalent — or, where none exists, to a senior officer — on the program’s status and compliance and on the material matters the Rule lists. The exemption in 314.6 for institutions with fewer than five thousand consumers removes the written annual report, not the role. This guide sets out what the Rule requires of the role, what “qualified” means when the Rule does not define it, the three ways to fill the role and the strings attached to outsourcing, the annual report’s content, what the role looks like in a small tax or accounting practice, and the errors examiners find.

The Qualified Individual under 16 CFR 314.4(a)
Designated to oversee, implement and enforce the information security program · employee, affiliate or service provider · if outsourced: institution retains responsibility, designates a senior overseer, contractually requires the provider’s own program · reports in writing at least annually to the board or a senior officer (314.4(i)) · report exempt below 5,000 consumers (314.6); the role is not.

What 16 CFR 314.4(a) requires

Requirement Rule text (condensed) What it means
Designate Designate a qualified individual responsible for overseeing and implementing your information security program and enforcing it One named person with three verbs: oversee, implement, enforce
Who may hold it May be employed by you, an affiliate, or a service provider An owner, a manager, a group IT lead or a contracted virtual CISO all qualify — subject to the outsourcing conditions
If a service provider or affiliate is used — (1) Retain responsibility for compliance with this part Outsourcing the role does not outsource the obligation
(2) Designate a senior member of your personnel responsible for direction and oversight of the Qualified Individual A named internal owner who directs the outsourced QI
(3) Require the service provider or affiliate to maintain an information security program that protects you in accordance with this part A contractual obligation on the provider

The Rule does not define “qualified”; the FTC’s guidance describes the individual as someone with the knowledge and experience to run the program, scaled to the institution’s size and complexity — a certified security professional for a lender with a million records, a trained owner or office manager for a three-person tax practice. Our guide to who the FTC Safeguards Rule applies to covers which institutions must designate one.

What the Qualified Individual is responsible for

Rule element The individual’s part
314.4(b) Risk assessment Owns the written risk assessment — criteria, evaluation of confidentiality, integrity and availability, mitigation or acceptance decisions — and its periodic update
314.4(c) Safeguards Implements and oversees the safeguards: access controls, data inventory, encryption, secure development, MFA, disposal, change management, activity monitoring
314.4(d) Testing Ensures regular testing — continuous monitoring, or annual penetration testing and six-monthly vulnerability assessments
314.4(e) Training Ensures security awareness training and that security personnel are qualified and kept current
314.4(f) Service providers Oversees selection, contractual requirements and periodic assessment of service providers
314.4(g) Adjusting the program Evaluates and adjusts the program in light of testing, changes in operations and circumstances
314.4(h) Incident response plan Owns the written incident response plan and its execution
314.4(i) Annual report Writes and presents the report to the board or senior officer
314.4(j) FTC notification Runs the notification-event determination and the FTC notice within 30 days for events affecting 500 or more consumers

Our guide to the written information security plan covers the ten elements the individual signs off.

Three ways to fill the Qualified Individual role

Model Who Conditions Fits
Internal employee An owner, partner, office manager, IT manager or CISO Competence appropriate to the program; authority to enforce; time Any size; the default for practices where the owner runs everything
Affiliate A group or parent company’s security function The three 314.4(a)(1)–(3) conditions: retained responsibility, an internal senior overseer, the affiliate’s own program Subsidiaries of larger financial groups
Service provider A managed security provider or virtual CISO The same three conditions, in the contract; the provider’s program covers the institution Small and mid-size institutions without security staff

Outsourcing is common and lawful; the error is outsourcing without the overseer. The senior member of personnel in 314.4(a)(2) is the person the FTC will ask what the provider did — and who must be able to answer.

The annual report under 314.4(i)

The individual reports in writing, regularly and at least annually, to the board of directors or equivalent governing body — or, where none exists, to a senior officer responsible for the program. The report covers the overall status of the program and compliance with the Rule, and material matters: risk assessment, risk management and control decisions, service provider arrangements, results of testing, security events or violations and management’s responses, and recommendations for changes. Under 314.6 the annual report requirement in 314.4(i) — like the written risk assessment in (b)(1), the testing specifics in (d)(2) and the written incident response plan in (h) — does not apply to institutions with customer information on fewer than five thousand consumers. The designation of the Qualified Individual in (a) is not exempt.

The role in a small practice

The IRS states that federal law requires tax and accounting professionals to create and maintain a written information security plan, and a sole practitioner is the Qualified Individual by default. The role is then a set of habits rather than a job: an annual walk through the risk assessment, the safeguards checklist, the vendor list and the training log; a decision recorded when something changes; and the notification-event procedure ready before it is needed. Our guides to the FTC Safeguards Rule for tax preparers and the WISP for sole practitioners cover what a small practice keeps and what it may leave out.

Errors examiners find

  • No designation in writing. Everyone knows who “does security”; nothing names the person.
  • A title without authority. A designated person who cannot approve spend, enforce policy or stop a practice is not overseeing, implementing and enforcing.
  • Outsourced without an overseer. A provider named as QI with no senior member of personnel directing it and no contractual program requirement.
  • Annual report never written. Above five thousand consumers, a program with no written report to the board fails 314.4(i) on the face of the file.
  • Qualification unevidenced. No record of the training, certification or experience that makes the individual qualified for the program’s size.
  • The role held by the breacher’s only reviewer. In a one-person practice, the incident procedure should still say who else is told, because 314.4(j) deems discovery when any employee, officer or agent other than the person who committed the breach knows.

Frequently asked questions

What is the Qualified Individual under the FTC Safeguards Rule?
The person 16 CFR 314.4(a) requires every covered financial institution to designate as responsible for overseeing, implementing and enforcing its information security program. The Rule capitalises the term; the person may be an employee, an affiliate or a service provider.

Does the Qualified Individual have to be an employee?
No. An affiliate or service provider may fill the role, but the institution retains responsibility for compliance, must designate a senior member of its own personnel to direct and oversee that person, and must require the provider to maintain an information security program that protects the institution.

What qualifications are required?
The Rule does not specify any. ‘Qualified’ is read as knowledge and experience appropriate to the size and complexity of the program — from a trained owner in a small practice to a certified security professional in a large lender — and the file should evidence it.

Does a small practice need a Qualified Individual?
Yes. The 314.6 exemption for fewer than five thousand consumers removes the written annual report, the written risk assessment, the specific testing requirements and the written incident response plan — not the designation in 314.4(a).

What must the annual report contain?
Under 314.4(i): the overall status of the program and compliance with the Rule, and material matters — risk assessment, risk management and control decisions, service provider arrangements, testing results, security events or violations and management’s responses, and recommendations for changes — in writing, at least annually, to the board or a senior officer.

Where this leaves you

Designate the individual in writing, with the authority to oversee, implement and enforce and with the qualification evidenced for the program’s size; if the role is outsourced, name the senior overseer and put the provider’s program in the contract; write the annual report where 314.4(i) applies and keep the habit where it does not — because the Rule’s ten elements all run through one named person, and the first question an examiner asks is who that is.

References

More on WISP and the Safeguards Rule

The Qualified Individual designation letter, the role description and qualification record, the service-provider oversight clause, the annual report template and the ten-element WISP are in the WISP Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.