GLBA internal audit

The FTC Safeguards Rule at 16 CFR 314.4(d) requires financial institutions to test their key controls regularly. We run that test as an independent internal audit and report what an examiner would find.
Talk to an auditor
Definition

What is a GLBA internal audit?

A GLBA internal audit is an independent test of a financial institution's information security program against the safeguards the Gramm-Leach-Bliley Act requires. The FTC Safeguards Rule at 16 CFR 314.4(d) requires regular testing or monitoring of key controls, and the banking agencies' Interagency Guidelines expect testing by independent staff or qualified outside parties. BD Emerson tests every element of your program against the rule text: the qualified individual, the written risk assessment, access controls, encryption, multi-factor authentication, monitoring, incident response, service provider oversight, and the annual report to the board. We report exceptions with evidence keyed to rule cites, so you see what an examiner would find before an examiner does. We deliver this as a standalone engagement or within our broader internal audit services.

Services

What does a GLBA internal audit cover?

Governance and reporting
Risk assessment
Access and inventory
Technical safeguards
Monitoring and testing
Incident response and vendors

Governance and the qualified individual

We verify a qualified individual is designated and directing the program under 314.4(a), and that the annual written report to the board required by 314.4(i) was delivered and reflects what the evidence shows. If the report says the program is healthy and the logs disagree, that is a finding.

Risk assessment against 314.4(b)

The rule requires a written risk assessment with specific contents: the criteria used to evaluate and categorize risk, the criteria for assessing the adequacy of your safeguards, and how identified risks will be mitigated or accepted. We test the document against those requirements and confirm the program follows it.

Access controls and data inventory

We test who can reach customer information, whether access reviews run on the cadence your program commits to, and whether the data and system inventory matches where customer information actually lives. Unreviewed access and uninventoried systems are the two most common exceptions we write.

Encryption, MFA, retention, and disposal

We test encryption of customer information at rest and in transit, or the compensating controls your qualified individual approved in writing. We also test multi-factor authentication on every system holding customer information, secure development practices, change management, and disposal within the rule's two-year expectation.

Monitoring, logging, and testing cadence

Rule 314.4(d)(2) offers a choice: continuous monitoring, or an annual penetration test plus vulnerability assessments every six months. We verify which path you chose, whether it ran on schedule, and whether logging of authorized user activity would catch misuse of customer information.

Incident response and service providers

We test the written incident response plan against 314.4(h), including whether it operationalizes notification to the FTC within 30 days for security events involving 500 or more consumers. We also test how service providers holding customer information were selected, contracted, and monitored under 314.4(f).

Our approach

Our approach to GLBA testing

01

We test against the rule text

Every procedure maps to a cite in 16 CFR 314.4 or the Interagency Guidelines. Findings quote the requirement, state what we observed, and reference the evidence, so there is no debate about whether something is actually required.

02

Independence is structural

The audit team does not build safeguards programs, does not sell remediation, and does not audit work BD Emerson consultants performed. That separation is what makes the report usable in front of an examiner.

03

Evidence decides every finding

We test what the systems that retain that history actually show: access reviews, logs, training records, vendor contracts, and test results. Interviews explain the evidence. They do not replace it.

04

You remediate, we verify

We report exceptions with evidence. We do not correct them. When you close a finding, we verify the corrective action resolved it, which is audit work and stays inside the independence line.

contact us

Schedule a GLBA internal audit

Tell us your institution type, who examines you, and when the annual board report is due. An auditor will come back with scope, timeline, and cost.

Our Advantage

Why BD Emerson for GLBA audits

Audit is a separate practice

Our audit practice operates independently of BD Emerson's consulting and technology practices. The team that tests your program has no stake in what the fixes cost or who performs them.

Built for the examiner's lens

We test the way examiners under the FFIEC handbooks probe a program and the way FTC orders read: rule text first, then evidence, then severity ranked by consumer data exposure. The report reads like the finding letter you are trying to avoid.

Reports the board can use

Each engagement ends with findings keyed to rule cites, workpapers with evidence references, and a summary the qualified individual can attach to the annual written report to the board under 314.4(i).

How We Work

How we run a GLBA internal audit

The audit runs in ten steps, from scoping to board report support. Each step produces workpapers you keep, and every exception comes with the evidence behind it. Most institutions run the full cycle annually, then again after material changes such as new products, acquisitions, or new service providers holding customer information.
Reviews

What our customers say

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.
FAQ

Frequently asked questions

Who does GLBA apply to?

What does the Safeguards Rule require an audit to cover?

Does GLBA require a penetration test?

How is this different from an FTC action or a bank examination?

What does a GLBA internal audit cost?

How does the audit feed the annual board report?

Blog

Related Articles

Insights on strategy, transactions, technology, security, and compliance from BD Emerson's practitioners