Safeguards Rule roles

Who is the 'qualified individual' under the FTC Safeguards Rule?

The single named person responsible for overseeing, implementing and enforcing the dealership's information security program. The role can be held by an employee or supplied by a service provider, but accountability stays with the dealership and the person must be identified rather than implied. This is issue-spotting information and not legal advice.

Direct answerSeptember 1, 2026 reviewedNeutral evaluation
01

It is a named role, not a committee

The requirement is a designated individual. Where an outside provider supplies the function, the dealership still needs a named person responsible for direction and oversight of that provider.

02

Reporting obligation

The role includes reporting to the governing body on the program's status, risks and incidents. Build that reporting into an existing management cadence rather than treating it as an annual document.

03

Vendor oversight sits here

Selecting service providers capable of safeguarding information, requiring safeguards contractually and monitoring them belongs to this role — which is why the person should see software purchases before they are signed.

04

Document the decisions

Risk assessments, testing results and remediation decisions are the evidence that a program exists in practice. Keep them where they can be produced.

Decision checklist

What to verify

Open procurement templates →

Name one individual, even if a provider supplies the function

Build the reporting obligation into an existing cadence

Route software purchases through this role before signature

Keep risk assessments and testing results producible

Related market maps

Continue the research

People also research

Related dealership technology questions