The dealership must designate a qualified individual to implement and supervise the information security program, and that person must report to the board at least annually. An MSP can help execute controls, but it does not replace internal accountability. Clear ownership matters because regulators expect the dealership to demonstrate oversight, not just outsourced activity.
Who owns FTC Safeguard Rule compliance at a dealership?
Accountability sits with the dealership, not the MSP. The rule expects the business to designate a qualified individual to run and supervise the information security program, and that person must report at least annually to the board or equivalent governing body. Outsourcing can support execution, but it cannot replace internal ownership, oversight, or proof of governance.
What accountability looks like in practice
The practical test is whether someone inside the dealership can answer for the program, evidence its operation, and escalate issues to leadership. That owner does not need to do every control manually, but they do need authority over the program, visibility into control performance, and the ability to direct remediation when gaps appear.
A dealership can assign day-to-day work to an MSP, internal IT team, or security consultant, but the accountable party must still be able to demonstrate that controls are selected, monitored, and adjusted as conditions change. Regulators care about governance, not just task completion.
If the dealership cannot show who approved the security program, who reviewed exceptions, and who received reporting, then accountability is already too diffuse. The designation must be operational, not just a name on a document.
Why MSP support does not equal compliance ownership
An MSP can be a control operator, but it is rarely the control owner. That distinction matters because an external provider may configure tools, rotate credentials, or monitor alerts, yet the dealership still owns risk acceptance, policy decisions, vendor oversight, and board-level reporting.
This separation also matters when controls fail. If a breach, missing review, or misconfiguration occurs, the dealership cannot credibly say the MSP was responsible for compliance in the legal or regulatory sense. The firm that is regulated must retain oversight of the program and its outcomes.
For that reason, contracts should make MSP duties explicit, including what they manage, what they escalate, and what evidence they supply. The dealership should be able to reconstruct accountability even if the provider changes.
What the board should expect from the security owner
The board does not need to run the program, but it should receive an annual report that is specific enough to show the program is real. That report should summarize major risks, control changes, incidents, exceptions, and remediation progress in language that leadership can act on.
Internal accountability works best when the owner has clear authority to challenge weak controls and to prioritize fixes over convenience. A qualified individual who lacks budget influence, escalation paths, or access to leadership is accountable in theory only.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RR-01 — Risk Management Roles, Responsibilities, and Authorities | The rule hinges on clear internal accountability for security oversight. |
| Recommendation — Assign and document security roles, responsibilities, and authorities for the dealership program. | ||
| NIST SP 800-53 Rev 5 | PM-1 — Information Security Program Plan | The question is about who owns and supervises the security program. |
| Recommendation — Designate a responsible owner and maintain an approved security program plan. | ||
| ISO/IEC 27001:2022 | A.5.2 — Information security roles and responsibilities | The dealership must assign responsibility for the security program and oversight. |
| Recommendation — Define and communicate security responsibilities, including who is accountable for compliance. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Compliance ownership depends on oversight of who can do what and who reviews it. |
| Recommendation — Ensure one accountable owner oversees access decisions, reviews, and exceptions. | ||
Practitioner Guidance
What to verify: Confirm that one named individual is responsible for the information security program, that their remit covers oversight as well as execution, and that they can evidence board reporting. If an MSP performs key tasks, verify the dealership still receives status, exceptions, and incident escalation in a form leadership can review.
Common mistake: Treating the MSP contract as a substitute for internal governance. Outsourced controls can reduce workload, but they do not remove the dealership’s duty to own the program, approve risk decisions, and show accountability to regulators.
Decision rule: If a control failure, audit question, or incident cannot be answered by a dealership employee who owns the program, the accountability model is too weak. The dealership should tighten ownership before relying on additional tooling or more provider activity.
Practitioner takeaway: Compliance succeeds when the dealership can prove there is a real internal owner with authority, reporting, and oversight, not merely an external team performing security tasks.
Related resources from NHI Mgmt Group
- How should MSPs help dealership clients prepare for FTC Safeguard Rule compliance?
- Who should be accountable for FTC Safeguards Rule compliance when the security program is outsourced?
- How should security teams govern non-human identities for compliance?
- How should security teams govern non-human identities for SOC 2 compliance?