Most small financial services firms don't know they're covered by the same regulations as the big banks. Here's what that actually means for your firm.
TL;DR: Financial services firms carry the second-highest average data breach cost of any industry at $5.56 million per incident, yet most small firms drastically underestimate their regulatory exposure. The FTC Safeguards Rule, Regulation S-P, and GLBA collectively cover a much broader range of businesses than most owners realize, including tax preparers, mortgage brokers, investment advisors, and check cashers. The firms that get caught off guard aren't the ones that ignored compliance; they're the ones that didn't know they were covered.
Ask a small financial firm owner which federal regulations cover their business and you'll get one of two answers: a confident wrong one or an honest shrug. Someone asks about the FTC Safeguards Rule and gets a slightly confused look, because that's for banks, right? Big institutions. Not a two-person tax prep shop or a small mortgage brokerage.
Except it is. The Safeguards Rule covers tax prep shops. It covers mortgage brokers. It covers check cashers, credit counselors, and investment advisors who aren't registered with the SEC. If your business handles nonpublic personal financial information, you're almost certainly in it, and "I didn't know I was covered" is not a defense that tends to go well with regulators.
It's a little like finding out jaywalking laws apply on that empty street you've crossed a thousand times without a second thought. The rule was always there. You just never realized it applied to you in this situation until your friendly local police officer told you.
The regulatory environment covering financial services data security has tightened considerably in recent years, and the firms catching the most attention from regulators aren't always the large ones. Small firms often have weaker controls, less documentation, and less awareness of what they're required to do, which makes them both more vulnerable to breaches and more exposed when someone comes looking. According to IBM's 2025 Cost of a Data Breach Report, financial services firms face an average breach cost of $5.56 million, second only to healthcare. For a small firm, a fraction of that is existential.
Financial services compliance isn't a size threshold. It's a function of what your business does. This post covers what the major frameworks actually require and where small firms consistently fall short.
Most small financial services firms assume compliance is someone else's problem. Banks have compliance departments. Investment houses have legal teams. A two-person tax prep shop or a small mortgage brokerage? Surely that's different.
It isn't. The FTC Safeguards Rule under the Gramm-Leach-Bliley Act covers any business significantly engaged in financial activities, and the FTC reads that phrase broadly on purpose. Mortgage lenders, payday lenders, finance companies, mortgage brokers, account servicers, check cashers, wire transferors, collection agencies, credit counselors, and tax preparation firms are all explicitly named. Accounting firms fall under the same definition through the broader "significantly engaged in financial activities" standard, a point the IRS confirms in Publication 5708. Investment advisors are covered too, specifically those not required to register with the SEC, since SEC-registered advisors fall under Regulation S-P instead.
The SEC's Regulation S-P covers registered investment advisors, broker-dealers, and investment companies. The 2024 amendments added formal vendor oversight requirements: written policies, documented risk assessments, and periodic reviews for every service provider that accesses client data. FINRA rules apply to broker-dealers, with cybersecurity guidance that overlaps significantly with both frameworks.
The practical reality is that most small financial services firms are operating under at least two of these simultaneously, and the documentation requirements of each are specific enough that "we generally have good security" doesn't satisfy any of them.
The Safeguards Rule does include a limited exemption for financial institutions that maintain customer information on fewer than 5,000 consumers. If you fall below that threshold, certain provisions don't apply, including the annual penetration testing requirement and the written incident response plan. The core requirement to maintain a written information security program still applies, just with fewer mandatory elements. If you're close to that threshold or unsure which side you're on, it's worth confirming with a compliance professional rather than assuming either way.
The Safeguards Rule requires a written information security program. That program has to be specific to your business, appropriate to your size and complexity, and updated when things change. A generic template downloaded from the internet satisfies the "written" part and not much else, which is how a lot of small firms end up technically compliant on paper and genuinely exposed in practice.
The specifics matter because they're where the gaps show up. You need a designated qualified individual to oversee the program. Doesn't need a specific degree or title, but they do need real-world knowledge appropriate to your situation. If you outsource that role to a service provider, you still need a senior employee supervising them.
MFA is required for anyone accessing customer information on your system. Not optional, not recommended: required. Encryption is required for customer data at rest and in transit. Every service provider that touches customer data needs a written contract specifying your security expectations, and you're required to monitor their compliance with those expectations, not just sign the agreement and move on.
The breach notification piece is newer and worth paying attention to. As of May 2024, covered entities must report breaches involving 500 or more consumers' unencrypted information to the FTC within 30 days of discovery. Thirty days sounds like a lot until you're in the middle of an incident without a documented response plan, at which point it feels like nothing at all.
The qualified individual also has to report to your board or governing body at least annually, covering the state of the program, risk assessment results, test outcomes, and security incidents. For firms without a formal board, that report goes to a senior officer responsible for the security program. Most small firms have never done this. Most don't know it's required.
If the Safeguards Rule is the compliance framework most small financial firms have never heard of, Regulation S-P is the one most registered investment advisors have heard of but haven't fully read since the 2024 amendments rewrote the parts that matter most.
The SEC's updates to Reg S-P added a formal vendor oversight obligation that didn't exist before. Covered firms now need written policies and procedures for vendor risk management, documented risk assessments for every service provider that accesses client data, and periodic reviews of those assessments. Not a one-time checkbox. An ongoing program with documentation to prove it's actually happening.
The compliance deadlines already passed. Larger advisors with $1.5 billion or more in AUM were required to comply by December 2025. Smaller advisers had until June 2026. If your firm hasn't built out the vendor documentation this rule requires, you're not in a grace period. You're out of compliance.
The practical implication is that the informal vendor relationships that used to be fine aren't fine anymore. Your IT provider, your cloud storage platform, your email system if client information moves through it: each one that accesses client data needs a documented assessment. It doesn't have to be a lengthy report, but it has to exist, it has to be current, and it has to be something you could hand to an examiner without wincing.
The gaps that create the most exposure in small financial services firms aren't usually dramatic. They're the quiet ones that accumulated while everyone was busy running the business.
Shadow AI is increasingly the most common gap and the least addressed one. Research from Microsoft's 2024 Work Trend Index found that 78 percent of workers bring their own AI tools to work, usually without IT or compliance review. In a financial services environment, that means client data is regularly entering systems with unknown security postures, unknown data retention policies, and zero documentation. IBM's 2025 research found that shadow AI adds $670,000 to average breach costs. That's not a rounding error.
Vendor documentation is close behind. Most small firms have technology providers that access client data and either no written agreements, agreements that predate current requirements, or agreements that don't address security expectations in any meaningful way. Every one of those relationships is a regulatory gap, and "we've worked with them for years and nothing bad has happened" is not vendor oversight documentation.
Incident response planning is the third. Most small firms have a general sense of what they'd do if something went wrong. A general sense is not an incident response plan. The Safeguards Rule specifies exactly what the plan has to cover: goals, internal processes, roles and decision-making authority, communication procedures, remediation steps, and a post-incident review requirement. Most small firms have none of that written down, which means they're non-compliant independent of whether a breach ever occurs.
Access controls round out the list. Staff members with broader access to client data than their role actually requires. Former employees whose credentials were never disabled. These aren't exotic vulnerabilities. They're the kind of thing that shows up in almost every small firm assessment and almost never gets addressed proactively.
Here's the thing about compliance infrastructure for a small financial services firm: it doesn't require a dedicated compliance officer, a legal team, or a budget that would make a regional bank nervous. It requires documentation, consistency, and someone accountable for keeping it current. That's genuinely it.
The written information security program is the foundation. It has to be specific to your business, which means it describes how your firm actually operates, not how a hypothetical firm similar to yours might operate. Generic templates exist, and they're tempting, but they're not compliant. They're the appearance of compliance, which is a different and considerably more dangerous thing.
A current vendor inventory is the second piece. Every service provider that accesses client data, documented with what they can see, under what security controls, and when you last reviewed their practices. For firms covered by Regulation S-P, this isn't optional anymore. It's a documented regulatory requirement with deadlines that have already passed.
Employee training is the third, and it's probably the highest-return investment on this list. The most common source of security incidents in financial services isn't sophisticated hacking. It's employees doing things they shouldn't with client data, usually because nobody told them clearly what "shouldn't" looks like in practice. Regular training on approved tools, data handling expectations, and how to escalate concerns costs very little and closes a gap that pure technology investment can't.
For the broader compliance framework that ties all of this together, our previous piece, Compliance Isn't a Season. It's a System, covers what a continuous compliance program looks like and how CaaS makes it practical for businesses that can't staff a full compliance function internally. The short version is that building compliance into how your firm operates costs considerably less than reconstructing it after something forces the issue.
Most small financial services firms don't end up in regulatory trouble because they decided compliance wasn't important. They end up there because compliance drifted while everyone was focused on clients, growth, and the hundred other things that demand attention in a small firm. The frameworks updated. The vendor relationships changed. The documentation that used to be sufficient stopped being sufficient. And by the time it surfaced, the cost of catching up had grown considerably.
The firms that handle this well aren't the ones with the biggest compliance budgets. They're the ones that treat it as an ongoing function rather than a periodic project, which means the documentation stays current, the vendor assessments actually happen, and there's someone accountable for both rather than nobody accountable for either.
Succurri's compliance work with financial services firms across Arizona, Washington, and Montana isn't theoretical. The FTC Safeguards Rule, Regulation S-P, and GLBA requirements are the actual frameworks we help clients document, implement, and maintain. We know which gaps tend to appear in small firms because we see them regularly, and we know what it takes to close them before a regulator or a breach makes them impossible to ignore.
Compliance that's built into how your firm operates costs less and causes less pain than compliance that gets reconstructed after something forces the issue. Talk to a Succurri today and find out where your firm's compliance posture actually stands.
1. Does my small tax prep shop or accounting firm really have to comply with the FTC Safeguards Rule?
Almost certainly yes. The FTC explicitly names tax preparation firms in the Safeguards Rule's list of covered entities, and the IRS confirms in Publication 5708 that accounting professionals are considered financial institutions regardless of size. If your business handles nonpublic personal financial information, the safe assumption is that you're covered. Confirm with a compliance professional if you're unsure, but don't assume you're exempt based on size or because you don't think of yourself as a financial institution.
2. What's the difference between GLBA, the Safeguards Rule, and Regulation S-P?
GLBA is the foundational federal law. The Safeguards Rule is the FTC's implementing regulation under GLBA that specifies what a written information security program must include. Regulation S-P is the SEC's parallel framework for registered investment advisors, broker-dealers, and investment companies. Many small financial services firms are covered by more than one simultaneously, and the documentation requirements don't cancel each other out.
3. What happens if my firm has a breach and no documented incident response plan?
You face potential regulatory action on two fronts: the breach itself and the absence of required controls. The Safeguards Rule requires a written incident response plan as a specific element of your information security program. Not having one is a compliance violation independent of whether a breach occurred, which means the regulatory exposure starts before anyone's data is actually compromised.