Start with your entity type
Financial regulation depends on what kind of firm you are and where you are licensed or listed. Four regimes come up most often for non-bank firms. Banks and savings associations supervised by the OCC, Federal Reserve, or FDIC fall under the Interagency Guidelines Establishing Information Security Standards (12 CFR Part 30 App. B for national banks and federal savings associations; 12 CFR Part 208 App. D-2 for state member banks; 12 CFR Part 364 App. B for FDIC-supervised institutions). This page does not cover those guidelines. New York-licensed banks are also covered by NYDFS Part 500, and EU credit institutions by DORA. Each row below names who it covers and where the obligation comes from.
Which regulation applies?
| Regulation | Who it applies to | Source of obligation |
|---|---|---|
| GLBA Safeguards Rule 16 CFR Part 314 | Non-bank financial institutions under FTC jurisdiction. Examples in 16 CFR 314.1(b) include mortgage lenders and brokers, payday lenders, finance companies, check cashers, wire transferors, collection agencies, credit counselors and other financial advisers, tax preparation firms, non-federally insured credit unions, and investment advisers not required to register with the SEC. Investment advisers not required to register with the SEC are listed. SEC-registered advisers are not on that list | Federal law (Gramm-Leach-Bliley Act, 15 U.S.C. 6801(b)), enforced by the FTC under 15 U.S.C. 6805(a)(7) for institutions not subject to another listed agency's jurisdiction |
| NYDFS Part 500 23 NYCRR 500 | Entities that operate under a license, registration, charter, or similar authorization under New York's Banking, Insurance, or Financial Services Law | New York state regulation, enforced by the Department of Financial Services. Amended in 2023 |
| DORA Regulation (EU) 2022/2554 | Financial entities in the EU listed in Article 2(1), including credit institutions, payment institutions, e-money institutions, investment firms, and insurance and reinsurance undertakings. Applies from 17 January 2025. ICT third-party providers designated as critical under Article 31 fall under a separate oversight framework | EU regulation, directly applicable across member states |
| SOX Section 404 Sarbanes-Oxley Act | Issuers that file annual reports under Exchange Act section 13(a) or 15(d). Management assesses internal control over financial reporting each year. The auditor attestation in 404(b) does not apply to non-accelerated filers or emerging growth companies | Federal law (15 U.S.C. 7262(a); exclusions in 7262(b) and 7262(c)), enforced by the SEC. SEC Release 33-8810 (2007), Section II.B.1.d, says IT general controls "alone ordinarily do not adequately address financial reporting risks" |
Quick check
- Required to file annual reports with the SEC under Exchange Act section 13(a) or 15(d)? SOX 404(a) applies to your internal control over financial reporting.
- Licensed by New York's financial regulator? Part 500 applies to your cybersecurity program.
- One of the financial entities listed in DORA Article 2, such as a credit institution, payment institution, investment firm, or insurer? DORA applies to your ICT risk management and third-party oversight.
- A non-bank mortgage broker, check casher, or tax preparer? The GLBA Safeguards Rule applies to customer information.
Several of these can apply at once. A firm can be NYDFS-licensed and SEC-registered, for example. This page is a starting point, not legal advice. Confirm scope with counsel for your entity.
Vendors and cloud providers
DORA, NYDFS Part 500, and the GLBA Safeguards Rule each require oversight of third-party service providers that access or hold the firm's customer or nonpublic data (DORA Articles 28 to 30 for ICT third-party providers, 23 NYCRR 500.11, and 16 CFR 314.4(f)). The vendor tiering and due diligence guide covers that work.
Third-Party Risk Management →Sources (Cornell LII mirrors of eCFR and USC where noted)
- 16 CFR Part 314, FTC Safeguards Rule (eCFR)
- 16 CFR 314.1, scope and listed financial institutions (Cornell LII)
- 16 CFR 314.2, definitions and examples (Cornell LII)
- 15 U.S.C. 6805, GLBA enforcement (Cornell LII)
- 12 CFR Part 30, Appendix B, Interagency Guidelines, OCC (Cornell LII)
- 12 CFR Part 208, Appendix D-2, Federal Reserve (Cornell LII)
- 12 CFR Part 364, Appendix B, FDIC (Cornell LII)
- 23 NYCRR Part 500, NYDFS cybersecurity regulation (Cornell LII)
- Regulation (EU) 2022/2554, DORA (EUR-Lex)
- 15 U.S.C. 7262, SOX Section 404 (Cornell LII)
- SEC Release 33-8810 (2007), management guidance on internal control over financial reporting