If an FTC auditor knocked on your door tomorrow — could you produce the documentation?
The FTC Safeguards Rule isn’t theoretical risk. Violations carry civil penalties up to $50,120 per violation per day. The rule has nine required elements. Most dealerships are missing at least three. LouieAuto tracks all nine — with audit-ready documentation.
See the compliance dashboard →Are You Covered?
The FTC Safeguards Rule isn’t a checkbox exercise. Each element requires documented evidence — written policies, access logs, encryption verification. Here is what the rule requires, and what LouieAuto provides for each.
Dealer must execute vendor agreements — templates included.
The FTC doesn’t care that your legacy DMS representative told you the system was compliant. The dealer is responsible for compliance — not the vendor. When the auditor arrives, they ask the dealer principal for documentation. “My DMS handles it” is not an acceptable answer. Vendors can be compliant on their end and still leave your dealership exposed if you cannot produce documentation of your own program.
The Seven-Day Documentation Request
FTC investigations typically begin with a documentation request. Here is the sequence — and the timeline by which each item must be produced.
Audit-Ready Documentation — Built Into the Platform
Not a separate compliance module you buy separately. Not a checklist you print and sign manually. Every element is tracked inside the platform, exportable for an auditor, and updated in real time as your data changes.
- FTC Safeguards gap tracker with current status per element — red/amber/green at a glance
- AES-256 encryption at rest (LUKS-mounted data volume) — active on every installation
- SMS one-time-code MFA enforced for all users with a phone on file — every enrollment and verification logged
- RBAC — every role, every access level, every change logged with timestamp and user identity
- Real-time audit log: who accessed what, when, from which IP, with what role
- Incident response plan template, pre-populated with your store’s contacts and notification workflows
- Vendor review checklist with documentation slots for each third-party with customer data access
- Annual risk assessment template with auto-population from your current data categories
- Encryption verification documentation — written for an auditor, not for a developer
- Annual penetration test must be scheduled with an external firm — LouieAuto documents the results, but cannot conduct the test itself
“Can you produce audit-ready documentation for all nine FTC required safeguards?”
If they say yes, ask them to email it to you today. If they pause — you have your answer.