A tailored course, built for your situation
Sources and specific examples on hand when peers push back
A 12-module course to master GLBA compliance with defensible reasoning and real-world implementation clarity
Who this is for
Senior technical compliance leader in a regulated financial institution
Who this is not for
Entry-level analysts, auditors looking for checklist training, or teams seeking automated tooling solutions
What you walk away with
- Articulate GLBA control rationale using cited regulatory text and examiner feedback patterns
- Reference documented implementations when challenged on scope or design
- Respond to peer challenges with specific examples from peer institutions
- Build internal training materials with source-backed explanations
- Strengthen cross-functional influence by leading with evidence, not opinion
The 12 modules (with all 144 chapters)
- What GLBA regulates
- Three titles of GLBA
- Purpose of Title V
- Scope of financial institutions
- Consumer vs customer defined
- Privacy Rule foundation
- Safeguards Rule foundation
- Pretexting Rule foundation
- FTC enforcement role
- OCC and Federal Reserve roles
- State regulator overlap
- Recent regulatory updates
- Initial privacy notice timing
- Annual notice delivery methods
- Content requirements for notices
- Exceptions to notice rule
- Opt-out rights explanation
- Joint marketing exceptions
- Affiliate sharing policy
- Consumer right to opt out
- Exempt institutions
- Regulation P citations
- FTC guidance documents
- OCC Bulletin references
- Designated individual requirement
- Risk assessment expectations
- Employee training frequency
- Service provider oversight
- Incident response planning
- Multi-factor authentication use
- Encryption of stored data
- Access controls policy
- Data inventory necessity
- Penetration testing cadence
- Third-party risk assessments
- Physical security inclusion
- Definition of pretexting
- Vishing attack patterns
- Call center safeguards
- Customer authentication steps
- KYC integration points
- Employee impersonation risks
- Caller ID spoofing
- Account takeover indicators
- Verification protocol design
- Dual control for changes
- Session timeout policies
- Logging verification attempts
- Data categorization framework
- Customer information inventory
- Threat modeling approach
- Internal threat scenarios
- External threat sources
- Likelihood impact matrix
- Risk register structure
- Third-party risk inputs
- Legacy system exposure
- Cloud migration factors
- Remote workforce impact
- Regulatory examination trends
- Due diligence checklist
- Contractual requirements
- SLA compliance tracking
- Right-to-audit clauses
- Subprocessor management
- Cybersecurity questionnaires
- Vendor risk scoring
- Onsite assessment planning
- Continuous monitoring
- Breach notification terms
- Termination triggers
- Model contract language
- Breach definition under GLBA
- Notification triggers
- Internal escalation paths
- Customer notice timing
- Regulator reporting process
- Forensic data collection
- Legal counsel engagement
- Public relations coordination
- Remediation tracking
- Post-mortem documentation
- Regulator communication
- Past enforcement examples
- Training content requirements
- Phishing simulation design
- Role-based modules
- Senior management inclusion
- Tracking completion
- Knowledge retention testing
- New hire onboarding
- Language accessibility
- Refresher frequency
- Audit trail documentation
- Third-party delivery
- Training effectiveness metrics
- Data encryption standards
- Access control tiers
- Role-based permissions
- Privileged account management
- Network segmentation
- Firewall rule management
- Endpoint protection
- Data loss prevention
- Backup encryption
- Secure disposal methods
- Facility access logs
- Visitor sign-in systems
- FFIEC IT Handbook references
- OCC examination process
- Document retention policy
- Response timeline expectations
- Common deficiency patterns
- Regulator interview prep
- Evidence organization
- Control mapping format
- Gap remediation tracking
- Follow-up response drafting
- Internal audit coordination
- Third-party assessment use
- NIST CSF mapping
- SOC 2 control overlap
- FFIEC IT Handbook
- OCC Bulletins
- State privacy law alignment
- CCPA interaction points
- HIPAA distinctions
- Gramm-Leach-Bliley Act
- FDICIA connection
- Basel III context
- ISO 27001 alignment
- COBIT 5 integration
- Decision documentation template
- Regulatory citation method
- Examiner feedback analysis
- Peer institution benchmarking
- Legal opinion integration
- Risk tolerance statements
- Control design trade-offs
- Cost benefit justification
- Future-proofing designs
- Cross-functional alignment
- Version control for policies
- Leadership sign-off trail
How this maps to your situation
- When peers question your control scope
- Before regulator interviews
- During vendor contract negotiations
- When designing new customer data flows
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3 hours per module, designed for completion in 12 weeks with flexible pacing
How this compares to the alternatives
Unlike generic compliance courses, this program focuses exclusively on GLBA with defensible implementation logic, real regulatory citations, and examples from financial institutions of comparable size and complexity.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.