Skip to main content
FTC Safeguards Rule — Compliance Audit

If an FTC auditor knocked on your door tomorrow — could you produce the documentation?

The FTC Safeguards Rule isn’t theoretical risk. Violations carry civil penalties up to $50,120 per violation per day. The rule has nine required elements. Most dealerships are missing at least three. LouieAuto tracks all nine — with audit-ready documentation.

See the compliance dashboard →

Are You Covered?

The FTC Safeguards Rule isn’t a checkbox exercise. Each element requires documented evidence — written policies, access logs, encryption verification. Here is what the rule requires, and what LouieAuto provides for each.

Safeguard & Requirement
What LouieAuto Provides
Documentation
Status
1 of 9
Qualified Individual
Designate a specific person responsible for the information security program — by name, with documented appointment.
LouieAuto logs who holds this role per dealer, with appointment date and acknowledgment timestamp.
Written designation + date in compliance dashboard
Covered
2 of 9
Risk Assessment
Conduct a written risk assessment identifying threats to customer information and how they are addressed.
Annual risk assessment template, pre-populated with dealer-specific data categories and threat inventory.
Signed, dated risk assessment document
Covered
3 of 9
Access Controls
Limit who can access customer data, based on the principle of least privilege. Document who has access and why.
RBAC (role-based access control) enforced system-wide. Every user’s access level is logged with role assignment date.
Full access log: user, role, date granted, last access
Covered
4 of 9
Encryption
Encrypt customer information at rest and in transit. Be able to demonstrate that encryption is active — not just claimed.
AES-256 encryption at rest (LUKS-mounted data volume). TLS in transit. Encryption status is verifiable in the audit log — readable by an auditor, not just a developer.
Encryption status log + LUKS mount verification
Covered
5 of 9
Multi-Factor Authentication
Require MFA for anyone who accesses customer records. No exceptions. Document implementation.
SMS one-time-code MFA enforced for all users with a phone on file. Every enrollment and verification is logged.
MFA enforcement log + user enrollment records
Covered
6 of 9
Security Monitoring
Monitor for unauthorized access attempts. Investigate security events. Document your monitoring program.
Every login, failed attempt, and data export is logged automatically. An on-demand Integrity Monitor scans that log for after-hours access and suspicious approval patterns, with an AI-written summary.
Access event log + on-demand integrity scan history
Covered
7 of 9
Annual Penetration Testing
Conduct or commission a penetration test of your systems at least annually. Document results and remediation.
LouieAuto provides the documentation slot and remediation tracking. The pen test itself must be scheduled with an external third-party firm. LouieAuto documents the results.
Pen test documentation slot — external test required
Action Required
8 of 9
Vendor Oversight
Assess your service providers’ security practices. Require them to maintain appropriate safeguards. Document this in writing.
Vendor review checklist and documentation of each third-party with customer data access. Most dealers have zero documentation on this element.
Dealer must execute vendor agreements — templates included.
Vendor security review log with agreement tracking
Template Provided
9 of 9
Incident Response Plan
Have a written plan for responding to security incidents. The plan must include notification workflows and be updated regularly.
Incident response template, pre-populated with dealer-specific contacts and escalation paths. Includes notification workflows and annual review prompts.
Written IRP + notification workflow documentation
Covered
The gap most dealers don’t know they have

The FTC doesn’t care that your legacy DMS representative told you the system was compliant. The dealer is responsible for compliance — not the vendor. When the auditor arrives, they ask the dealer principal for documentation. “My DMS handles it” is not an acceptable answer. Vendors can be compliant on their end and still leave your dealership exposed if you cannot produce documentation of your own program.

The Seven-Day Documentation Request

FTC investigations typically begin with a documentation request. Here is the sequence — and the timeline by which each item must be produced.

Day 1
Auditor requests your written information security program — the document naming your qualified individual, your risk assessment, and your overall safeguards strategy.
Day 2
Request for complete list of all third-party vendors with access to customer information — plus written security agreements with each. This is where most dealers go blank.
Day 3
MFA implementation evidence requested. Access control logs for the past 12 months. User list with role assignments and access grant dates. Who accessed customer records, when, and from where.
Day 5
Encryption verification for data at rest and data in transit. Not “we use a secure system” — specific technical documentation of what is encrypted, with what standard, and how it is verified.
Day 7
Written incident response plan. Security incident log for the past 24 months. Annual penetration test documentation with remediation records.
Result
Civil penalties can begin accruing from Day 1 for any missing documentation. The FTC does not offer a grace period for dealers who “didn’t know” what was required.
$50,120
Max daily penalty per violation
Per violation, per day — not per incident. Multiple missing elements compound.
9
Required elements by law
Most dealers are covered on 5–6 and exposed on 3–4. The gaps are specific and documentable.
No grace
Enforcement is active
The FTC increased dealer enforcement activity after the 2023 Safeguards Rule amendments went into effect.

Audit-Ready Documentation — Built Into the Platform

Not a separate compliance module you buy separately. Not a checklist you print and sign manually. Every element is tracked inside the platform, exportable for an auditor, and updated in real time as your data changes.

  • FTC Safeguards gap tracker with current status per element — red/amber/green at a glance
  • AES-256 encryption at rest (LUKS-mounted data volume) — active on every installation
  • SMS one-time-code MFA enforced for all users with a phone on file — every enrollment and verification logged
  • RBAC — every role, every access level, every change logged with timestamp and user identity
  • Real-time audit log: who accessed what, when, from which IP, with what role
  • Incident response plan template, pre-populated with your store’s contacts and notification workflows
  • Vendor review checklist with documentation slots for each third-party with customer data access
  • Annual risk assessment template with auto-population from your current data categories
  • Encryption verification documentation — written for an auditor, not for a developer
  • Annual penetration test must be scheduled with an external firm — LouieAuto documents the results, but cannot conduct the test itself
The question to ask your current DMS vendor

“Can you produce audit-ready documentation for all nine FTC required safeguards?”

If they say yes, ask them to email it to you today. If they pause — you have your answer.