US Federal Law United States

GLBA Vendor Management: Service Provider Oversight Under 314

Service provider oversight under the Safeguards Rule: selection diligence, mandatory contract terms, tiered periodic reassessment, and the fourth-party problem.

Regulation

GLBA Safeguards Rule, 16 CFR 314.4(f); Privacy Rule service-provider exception conditions (12 CFR 1016.13); interagency third-party risk guidance as reference

Max Penalty

Vendor oversight failures are per-element Safeguards violations with per-violation penalties; a vendor's breach of your customer data is your 30-day FTC notification and your name in the public database

Enforcing Authority

Federal Trade Commission (FTC); CFPB for Regulation P conditions

Official Source

www.ftc.gov

Executive Summary

  • 16 CFR 314.4(f) imposes three duties: select service providers capable of maintaining appropriate safeguards, require those safeguards by contract, and periodically assess providers based on the risk they present.
  • The Privacy Rule adds a parallel condition: sharing NPI with service providers without opt-out requires contracts limiting use and disclosure to the engagement's purposes.
  • A vendor's breach of your customer information is legally your breach: the FTC's 30-day notification names the institution, not the vendor, so vendor risk is notification risk.
  • Oversight must be risk-tiered: diligence depth and reassessment frequency proportionate to data access, with full-population inventory reconciled against actual data flows.
  • The fourth-party chain (your vendor's vendors) is the modern failure mode, MOVEit-style supply-chain incidents reached institutions through subcontractors they had never assessed.

Vendor management under GLBA has a clarifying asymmetry: you can delegate the work, never the liability. The processor holds the data, the cloud host runs the systems, the subcontractor moves the files, and when any of them fails, the FTC’s public breach database prints your name, on your 30-day clock, under your Safeguards obligations. The rule’s three verbs, select, contract, reassess, are the whole discipline, but the craft lives in proportionality (tier the effort to the data) and in pre-positioning (the breach-notice clock and the contact path negotiated before anyone needs them). And since MOVEit, every serious program asks the fourth-party question: not just ‘is our vendor secure?’ but ‘what does our vendor run, and who runs theirs?‘

Rule16 CFR 314.4(f): select, contract, reassess
Privacy Rule tie1016.13: purpose-limited use, by contract
Contract floorSafeguards + breach notice (24-72h) + flow-down + deletion
ReassessmentRisk-tiered annual/biennial + event-driven
Hard truthVendor’s breach = your notification, your name

Running the program

Inventory against data flows, not invoices. The vendor list must reconcile with the risk assessment’s data map; the unlisted tool receiving NPI is the standing gap.

Negotiate the clock hardest. Vendor breach notice at 24-72 hours protects your 30-day FTC notification window; ‘promptly’ protects nobody.

Tier ruthlessly. Deep diligence on data-holding vendors, light touch elsewhere; uniform effort produces uniform shallowness.

Ask the fourth-party question. Subprocessor disclosure, flow-down, and concentration analysis; the FTC’s security expectations treat vendor oversight as a first-class control, and privacy notices must match the sharing reality.

Third-party scripts on your site are vendors too, often unvetted ones: inventory them with a free scan.

Frequently Asked Questions

What does 'select service providers capable of maintaining appropriate safeguards' require?

Documented pre-contract diligence proportionate to what the provider will touch. For providers holding or processing customer information: security questionnaires (SIG or equivalent), independent attestations (SOC 2 Type II being the market standard, read for scope and exceptions, not just existence), penetration-test summaries, breach history, financial viability, and subcontractor disclosure. For peripheral vendors: a lighter screen confirming no covered data exposure. Two disciplines make it real: the diligence must precede signature (retroactive questionnaires prove the violation, not compliance), and the file must be kept, in an FTC inquiry following a vendor incident, the selection record is what separates 'our vendor failed' from 'we failed to select adequately.' Capability gaps found in diligence are handled by compensating contract terms, scope reduction, or walking away, each a documented decision.

What terms must, and should, the contract contain?

Must (to satisfy 314.4(f)(2) and the Privacy Rule's 1016.13 condition): the provider implements and maintains appropriate safeguards for customer information, and uses/discloses NPI only for the engagement's purposes. Should, per market practice and examiner expectation: specific security commitments (encryption, MFA, access limits) rather than 'industry standard' vagueness; breach and security-incident notice to you on a defined clock, 24 to 72 hours, not 'promptly', since your own FTC 30-day clock runs on discovery; audit or attestation rights (annual SOC 2 delivery plus questionnaire rights); subcontractor disclosure and flow-down of equivalent obligations; data location, return, and certified deletion at termination; cooperation duties in your incident response and regulatory inquiries; and liability allocation with breach-cost coverage or cyber-insurance requirements. Renegotiation reality: paper the must-haves at renewal for legacy vendors; a dated remediation plan for contract gaps reads far better than an unexamined vendor file.

How should periodic reassessment be tiered?

By the risk the provider presents, the rule's own words. Tier 1 (holds or processes customer information at scale: core processors, cloud hosts, servicers): annual reassessment, fresh SOC 2 review, questionnaire refresh, incident-history check, and performance-against-contract review. Tier 2 (limited or incidental covered-data access: niche SaaS, support tools): questionnaire refresh every one to two years, attestation where obtainable. Tier 3 (no covered-data access): inventory confirmation that the classification still holds, because scope creep is how tier 3 becomes tier 1 silently (the marketing platform that starts ingesting account data). Event-driven reassessment overrides the calendar: the provider's own breach, a material service change, acquisition, or adverse audit findings each trigger immediate review. Feed results into the risk assessment and the Qualified Individual's annual board report, vendor risk is a named topic in 314.4(i)'s report requirements.

What is the fourth-party problem, and what can we actually do about it?

Your obligations run to customer information wherever it flows, but your contract reaches only your counterparty, and your counterparty has vendors too. The MOVEit campaign (2023) made the pattern canonical: institutions were breached through file-transfer software operated by their vendors or their vendors' vendors, entities the institution had never assessed, triggering the institution's own notification duties. Realistic controls: contractual subcontractor disclosure with approval or objection rights for material subprocessors; flow-down clauses obligating equivalent safeguards down the chain; concentration analysis (which single fourth parties, cloud regions, or software components underlie multiple vendors); exit and contingency planning for critical chains; and, increasingly, software-supply-chain questions in diligence (what file-transfer, remote-access, and identity tooling does the vendor run?). You cannot audit the whole chain; you can know its shape, name its concentrations, and pre-position your response for the day one link fails.

Who does what when a vendor has an incident?

Pre-position the choreography, because the clocks are yours. The vendor's contractual duty: rapid notice (your negotiated 24-to-72-hour clock), facts (systems, data elements, individuals affected, containment status), cooperation, and preservation of evidence. Your duties: assess whether customer information was involved (this determines if the FTC's 30-day notification for 500+ consumers applies, and it names you); run state breach-law analysis on individual notice; document the timeline from your discovery, which begins on the vendor's notice, not the vendor's internal detection; and manage the vendor relationship decision (remediation plan, scope reduction, or termination per contract). Common failures: vendor notice clauses that never defined 'incident' (leading to late or lawyered notices), no contact-path testing (notices sent to a departed employee's inbox), and institutions waiting for the vendor's 'final report' while their own 30-day clock expired. Tabletop the vendor-breach scenario annually with your two or three most critical providers named in the script.

Regulatory Crosswalk

Interagency Third-Party Risk Management Guidance (2023)SOC 2NYDFS Part 500.11SIG questionnaires

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.