A tailored course, built for your situation
Deeper command of the GLBA compliance framework
A 199 course tailored for Jelle to master the structure, controls, and expectations that define GLBA implementation in financial services
Who this is for
Financial services compliance advisor with exposure to GLBA-related governance and client data policies, operating at the intersection of regulation and implementation
Who this is not for
Entry-level analysts or professionals outside financial services compliance, or those focused solely on marketing or sales under GLBA
What you walk away with
- Complete understanding of GLBA’s three rule pillars: Financial Privacy, Safeguards, and Pretexting
- Ability to map GLBA requirements directly to internal controls and data handling workflows
- Confidence to explain GLBA’s application across business lines and to external partners
- Access to tested documentation templates and control mapping examples
- Clear framework for updating policies in line with examiner expectations
The 12 modules (with all 144 chapters)
- Origins of GLBA
- Core legislative goals
- Who GLBA applies to
- Key definitions explained
- Recent regulatory emphasis
- Regulator expectations today
- Interaction with other laws
- Common misinterpretations
- Scope boundaries
- Exemptions and exclusions
- Enforcement history
- Case study: recent findings
- Notice content requirements
- Timing of disclosure
- Delivery methods
- Joint marketing exceptions
- Opt-out mechanisms
- Record retention
- Third-party sharing rules
- Client categories
- Privacy notice updates
- Internal tracking systems
- Audit evidence needed
- Common gaps in implementation
- Scope of covered information
- Designated employee requirement
- Risk assessment steps
- Security controls by category
- Access controls policy
- Encryption expectations
- Multi-factor adoption
- Vendor management process
- Incident response plan
- Testing frequency
- Reporting lines
- Documentation standards
- Definition of pretexting
- Common attack vectors
- Employee training content
- Verification protocols
- Call center safeguards
- Email authentication
- Record access controls
- Fraud detection systems
- Response to suspected pretexting
- Reporting obligations
- Regulatory guidance sources
- Case example: breach investigation
- What is nonpublic information
- PII vs NPI distinction
- Data inventory methods
- Storage classification
- Transmission rules
- Disposal standards
- Access logging
- Departmental responsibilities
- Client data lifecycle
- Cloud data handling
- Third-party flows
- Audit trail requirements
- Vendor identification
- Due diligence steps
- Contractual clauses needed
- Ongoing monitoring
- Audit rights negotiation
- Subcontractor oversight
- Risk tiering approach
- Compliance checklists
- Vendor incident response
- Exit protocols
- Performance metrics
- Documentation retention
- Control objectives by rule
- Control design examples
- Ownership assignment
- Testing frequency
- Evidence collection
- Remediation tracking
- Control rationalization
- Automation opportunities
- Reporting to leadership
- Audit preparation
- Internal vs external testing
- Continuous monitoring
- Risk assessment templates
- Policy version control
- Training sign-offs
- Meeting minutes content
- Incident log structure
- Vendor review records
- Testing result retention
- Executive sign-off
- Document hierarchy
- Retrieval systems
- Review cycles
- Archiving rules
- Mapping to ISO 27001
- SOC 2 control overlap
- NIST CSF alignment
- Internal audit coordination
- Single control, multiple use
- Cross-framework reporting
- Efficiency gains
- Holistic risk view
- Unified policy language
- Training integration
- Assessment bundling
- Leadership reporting
- Audience segmentation
- Training frequency
- Content formats
- Pretexting simulations
- Role-specific modules
- Testing understanding
- Refresher cycles
- Leadership messaging
- Third-party training
- Recordkeeping
- Effectiveness metrics
- Improvement feedback
- Common examiner questions
- Evidence packets
- Interview readiness
- Control walkthroughs
- Gap identification
- Response planning
- Coordination across teams
- Documentation walkthrough
- Executive briefing
- Post-review follow-up
- Lessons learned
- Continuous improvement
- Tracking regulatory updates
- Supervisory priorities
- Emerging threats
- Technology shifts
- Client data expansion
- Cross-border considerations
- Policy review cycles
- Stakeholder updates
- Budget alignment
- Metrics evolution
- Leadership communication
- Long-term roadmap
How this maps to your situation
- When initiating a GLBA review
- Before an audit cycle begins
- After a vendor incident
- During policy renewal planning
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3-4 hours per module, with self-paced access to all materials.
How this compares to the alternatives
Public courses often focus on generic privacy laws. This course is tailored specifically to GLBA and financial services implementation, with deep operational detail not found in broad compliance overviews.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.