Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Who should be accountable for FTC Safeguard Rule…
Governance, Ownership & Risk

Who should be accountable for FTC Safeguard Rule compliance at a dealership?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

The dealership must designate a qualified individual to implement and supervise the information security program, and that person must report to the board at least annually. An MSP can help execute controls, but it does not replace internal accountability. Clear ownership matters because regulators expect the dealership to demonstrate oversight, not just outsourced activity.

Who owns FTC Safeguard Rule compliance at a dealership?

Accountability sits with the dealership, not the MSP. The rule expects the business to designate a qualified individual to run and supervise the information security program, and that person must report at least annually to the board or equivalent governing body. Outsourcing can support execution, but it cannot replace internal ownership, oversight, or proof of governance.

What accountability looks like in practice

The practical test is whether someone inside the dealership can answer for the program, evidence its operation, and escalate issues to leadership. That owner does not need to do every control manually, but they do need authority over the program, visibility into control performance, and the ability to direct remediation when gaps appear.

A dealership can assign day-to-day work to an MSP, internal IT team, or security consultant, but the accountable party must still be able to demonstrate that controls are selected, monitored, and adjusted as conditions change. Regulators care about governance, not just task completion.

If the dealership cannot show who approved the security program, who reviewed exceptions, and who received reporting, then accountability is already too diffuse. The designation must be operational, not just a name on a document.

Why MSP support does not equal compliance ownership

An MSP can be a control operator, but it is rarely the control owner. That distinction matters because an external provider may configure tools, rotate credentials, or monitor alerts, yet the dealership still owns risk acceptance, policy decisions, vendor oversight, and board-level reporting.

This separation also matters when controls fail. If a breach, missing review, or misconfiguration occurs, the dealership cannot credibly say the MSP was responsible for compliance in the legal or regulatory sense. The firm that is regulated must retain oversight of the program and its outcomes.

For that reason, contracts should make MSP duties explicit, including what they manage, what they escalate, and what evidence they supply. The dealership should be able to reconstruct accountability even if the provider changes.

What the board should expect from the security owner

The board does not need to run the program, but it should receive an annual report that is specific enough to show the program is real. That report should summarize major risks, control changes, incidents, exceptions, and remediation progress in language that leadership can act on.

Internal accountability works best when the owner has clear authority to challenge weak controls and to prioritize fixes over convenience. A qualified individual who lacks budget influence, escalation paths, or access to leadership is accountable in theory only.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RR-01 — Risk Management Roles, Responsibilities, and AuthoritiesThe rule hinges on clear internal accountability for security oversight.
Recommendation — Assign and document security roles, responsibilities, and authorities for the dealership program.
NIST SP 800-53 Rev 5PM-1 — Information Security Program PlanThe question is about who owns and supervises the security program.
Recommendation — Designate a responsible owner and maintain an approved security program plan.
ISO/IEC 27001:2022A.5.2 — Information security roles and responsibilitiesThe dealership must assign responsibility for the security program and oversight.
Recommendation — Define and communicate security responsibilities, including who is accountable for compliance.
CIS Controls v8CIS-6 — Access Control ManagementCompliance ownership depends on oversight of who can do what and who reviews it.
Recommendation — Ensure one accountable owner oversees access decisions, reviews, and exceptions.

Practitioner Guidance

What to verify: Confirm that one named individual is responsible for the information security program, that their remit covers oversight as well as execution, and that they can evidence board reporting. If an MSP performs key tasks, verify the dealership still receives status, exceptions, and incident escalation in a form leadership can review.

Common mistake: Treating the MSP contract as a substitute for internal governance. Outsourced controls can reduce workload, but they do not remove the dealership’s duty to own the program, approve risk decisions, and show accountability to regulators.

Decision rule: If a control failure, audit question, or incident cannot be answered by a dealership employee who owns the program, the accountability model is too weak. The dealership should tighten ownership before relying on additional tooling or more provider activity.

Practitioner takeaway: Compliance succeeds when the dealership can prove there is a real internal owner with authority, reporting, and oversight, not merely an external team performing security tasks.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org