The Qualified Individual is the first element of the FTC Safeguards Rule and the person a written information security plan is built around: 16 CFR 314.4(a) requires every covered financial institution to designate a qualified individual responsible for overseeing and implementing its information security program and enforcing it — and the Rule’s own capitalised term for that person is what the industry has adopted. The role can be filled by an employee, an affiliate or a service provider, but if it is outsourced the institution keeps responsibility for compliance, must designate a senior member of its own personnel to direct and oversee that person, and must require the provider to maintain a program that protects the institution. Under 314.4(i) the individual reports in writing, at least annually, to the board or equivalent — or, where none exists, to a senior officer — on the program’s status and compliance and on the material matters the Rule lists. The exemption in 314.6 for institutions with fewer than five thousand consumers removes the written annual report, not the role. This guide sets out what the Rule requires of the role, what “qualified” means when the Rule does not define it, the three ways to fill the role and the strings attached to outsourcing, the annual report’s content, what the role looks like in a small tax or accounting practice, and the errors examiners find.

What 16 CFR 314.4(a) requires
| Requirement | Rule text (condensed) | What it means |
|---|---|---|
| Designate | Designate a qualified individual responsible for overseeing and implementing your information security program and enforcing it | One named person with three verbs: oversee, implement, enforce |
| Who may hold it | May be employed by you, an affiliate, or a service provider | An owner, a manager, a group IT lead or a contracted virtual CISO all qualify — subject to the outsourcing conditions |
| If a service provider or affiliate is used — (1) | Retain responsibility for compliance with this part | Outsourcing the role does not outsource the obligation |
| (2) | Designate a senior member of your personnel responsible for direction and oversight of the Qualified Individual | A named internal owner who directs the outsourced QI |
| (3) | Require the service provider or affiliate to maintain an information security program that protects you in accordance with this part | A contractual obligation on the provider |
The Rule does not define “qualified”; the FTC’s guidance describes the individual as someone with the knowledge and experience to run the program, scaled to the institution’s size and complexity — a certified security professional for a lender with a million records, a trained owner or office manager for a three-person tax practice. Our guide to who the FTC Safeguards Rule applies to covers which institutions must designate one.
What the Qualified Individual is responsible for
| Rule element | The individual’s part |
|---|---|
| 314.4(b) Risk assessment | Owns the written risk assessment — criteria, evaluation of confidentiality, integrity and availability, mitigation or acceptance decisions — and its periodic update |
| 314.4(c) Safeguards | Implements and oversees the safeguards: access controls, data inventory, encryption, secure development, MFA, disposal, change management, activity monitoring |
| 314.4(d) Testing | Ensures regular testing — continuous monitoring, or annual penetration testing and six-monthly vulnerability assessments |
| 314.4(e) Training | Ensures security awareness training and that security personnel are qualified and kept current |
| 314.4(f) Service providers | Oversees selection, contractual requirements and periodic assessment of service providers |
| 314.4(g) Adjusting the program | Evaluates and adjusts the program in light of testing, changes in operations and circumstances |
| 314.4(h) Incident response plan | Owns the written incident response plan and its execution |
| 314.4(i) Annual report | Writes and presents the report to the board or senior officer |
| 314.4(j) FTC notification | Runs the notification-event determination and the FTC notice within 30 days for events affecting 500 or more consumers |
Our guide to the written information security plan covers the ten elements the individual signs off.
Three ways to fill the Qualified Individual role
| Model | Who | Conditions | Fits |
|---|---|---|---|
| Internal employee | An owner, partner, office manager, IT manager or CISO | Competence appropriate to the program; authority to enforce; time | Any size; the default for practices where the owner runs everything |
| Affiliate | A group or parent company’s security function | The three 314.4(a)(1)–(3) conditions: retained responsibility, an internal senior overseer, the affiliate’s own program | Subsidiaries of larger financial groups |
| Service provider | A managed security provider or virtual CISO | The same three conditions, in the contract; the provider’s program covers the institution | Small and mid-size institutions without security staff |
Outsourcing is common and lawful; the error is outsourcing without the overseer. The senior member of personnel in 314.4(a)(2) is the person the FTC will ask what the provider did — and who must be able to answer.
The annual report under 314.4(i)
The individual reports in writing, regularly and at least annually, to the board of directors or equivalent governing body — or, where none exists, to a senior officer responsible for the program. The report covers the overall status of the program and compliance with the Rule, and material matters: risk assessment, risk management and control decisions, service provider arrangements, results of testing, security events or violations and management’s responses, and recommendations for changes. Under 314.6 the annual report requirement in 314.4(i) — like the written risk assessment in (b)(1), the testing specifics in (d)(2) and the written incident response plan in (h) — does not apply to institutions with customer information on fewer than five thousand consumers. The designation of the Qualified Individual in (a) is not exempt.
The role in a small practice
The IRS states that federal law requires tax and accounting professionals to create and maintain a written information security plan, and a sole practitioner is the Qualified Individual by default. The role is then a set of habits rather than a job: an annual walk through the risk assessment, the safeguards checklist, the vendor list and the training log; a decision recorded when something changes; and the notification-event procedure ready before it is needed. Our guides to the FTC Safeguards Rule for tax preparers and the WISP for sole practitioners cover what a small practice keeps and what it may leave out.
Errors examiners find
- No designation in writing. Everyone knows who “does security”; nothing names the person.
- A title without authority. A designated person who cannot approve spend, enforce policy or stop a practice is not overseeing, implementing and enforcing.
- Outsourced without an overseer. A provider named as QI with no senior member of personnel directing it and no contractual program requirement.
- Annual report never written. Above five thousand consumers, a program with no written report to the board fails 314.4(i) on the face of the file.
- Qualification unevidenced. No record of the training, certification or experience that makes the individual qualified for the program’s size.
- The role held by the breacher’s only reviewer. In a one-person practice, the incident procedure should still say who else is told, because 314.4(j) deems discovery when any employee, officer or agent other than the person who committed the breach knows.
Frequently asked questions
What is the Qualified Individual under the FTC Safeguards Rule?
The person 16 CFR 314.4(a) requires every covered financial institution to designate as responsible for overseeing, implementing and enforcing its information security program. The Rule capitalises the term; the person may be an employee, an affiliate or a service provider.
Does the Qualified Individual have to be an employee?
No. An affiliate or service provider may fill the role, but the institution retains responsibility for compliance, must designate a senior member of its own personnel to direct and oversee that person, and must require the provider to maintain an information security program that protects the institution.
What qualifications are required?
The Rule does not specify any. ‘Qualified’ is read as knowledge and experience appropriate to the size and complexity of the program — from a trained owner in a small practice to a certified security professional in a large lender — and the file should evidence it.
Does a small practice need a Qualified Individual?
Yes. The 314.6 exemption for fewer than five thousand consumers removes the written annual report, the written risk assessment, the specific testing requirements and the written incident response plan — not the designation in 314.4(a).
What must the annual report contain?
Under 314.4(i): the overall status of the program and compliance with the Rule, and material matters — risk assessment, risk management and control decisions, service provider arrangements, testing results, security events or violations and management’s responses, and recommendations for changes — in writing, at least annually, to the board or a senior officer.
Where this leaves you
Designate the individual in writing, with the authority to oversee, implement and enforce and with the qualification evidenced for the program’s size; if the role is outsourced, name the senior overseer and put the provider’s program in the contract; write the annual report where 314.4(i) applies and keep the habit where it does not — because the Rule’s ten elements all run through one named person, and the first question an examiner asks is who that is.
References
- 16 CFR Part 314 — Standards for Safeguarding Customer Information (eCFR) — Sections 314.4(a), 314.4(i) and 314.6.
- FTC — Safeguards Rule — The FTC’s Gramm-Leach-Bliley Act business guidance.
More on WISP and the Safeguards Rule
- The Qualified Individual — you are here
- The written information security plan: 10 elements
- Who the FTC Safeguards Rule applies to
- The FTC Safeguards Rule for tax preparers
- WISP for sole practitioners
- FTC Safeguards Rule breach notification
The Qualified Individual designation letter, the role description and qualification record, the service-provider oversight clause, the annual report template and the ten-element WISP are in the WISP Toolkit, or start with the free templates.