← Back to Compliance

Start with your entity type

Financial regulation depends on what kind of firm you are and where you are licensed or listed. Four regimes come up most often for non-bank firms. Banks and savings associations supervised by the OCC, Federal Reserve, or FDIC fall under the Interagency Guidelines Establishing Information Security Standards (12 CFR Part 30 App. B for national banks and federal savings associations; 12 CFR Part 208 App. D-2 for state member banks; 12 CFR Part 364 App. B for FDIC-supervised institutions). This page does not cover those guidelines. New York-licensed banks are also covered by NYDFS Part 500, and EU credit institutions by DORA. Each row below names who it covers and where the obligation comes from.

Which regulation applies?

Regulation Who it applies to Source of obligation
GLBA Safeguards Rule
16 CFR Part 314
Non-bank financial institutions under FTC jurisdiction. Examples in 16 CFR 314.1(b) include mortgage lenders and brokers, payday lenders, finance companies, check cashers, wire transferors, collection agencies, credit counselors and other financial advisers, tax preparation firms, non-federally insured credit unions, and investment advisers not required to register with the SEC. Investment advisers not required to register with the SEC are listed. SEC-registered advisers are not on that listFederal law (Gramm-Leach-Bliley Act, 15 U.S.C. 6801(b)), enforced by the FTC under 15 U.S.C. 6805(a)(7) for institutions not subject to another listed agency's jurisdiction
NYDFS Part 500
23 NYCRR 500
Entities that operate under a license, registration, charter, or similar authorization under New York's Banking, Insurance, or Financial Services LawNew York state regulation, enforced by the Department of Financial Services. Amended in 2023
DORA
Regulation (EU) 2022/2554
Financial entities in the EU listed in Article 2(1), including credit institutions, payment institutions, e-money institutions, investment firms, and insurance and reinsurance undertakings. Applies from 17 January 2025. ICT third-party providers designated as critical under Article 31 fall under a separate oversight frameworkEU regulation, directly applicable across member states
SOX Section 404
Sarbanes-Oxley Act
Issuers that file annual reports under Exchange Act section 13(a) or 15(d). Management assesses internal control over financial reporting each year. The auditor attestation in 404(b) does not apply to non-accelerated filers or emerging growth companiesFederal law (15 U.S.C. 7262(a); exclusions in 7262(b) and 7262(c)), enforced by the SEC. SEC Release 33-8810 (2007), Section II.B.1.d, says IT general controls "alone ordinarily do not adequately address financial reporting risks"

Quick check

Several of these can apply at once. A firm can be NYDFS-licensed and SEC-registered, for example. This page is a starting point, not legal advice. Confirm scope with counsel for your entity.

Vendors and cloud providers

DORA, NYDFS Part 500, and the GLBA Safeguards Rule each require oversight of third-party service providers that access or hold the firm's customer or nonpublic data (DORA Articles 28 to 30 for ICT third-party providers, 23 NYCRR 500.11, and 16 CFR 314.4(f)). The vendor tiering and due diligence guide covers that work.

Third-Party Risk Management →

Sources (Cornell LII mirrors of eCFR and USC where noted)