Skip to main content
Image coming soon

CMP6660 Mastering GLBA for Financial Services Compliance Practitioners

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering GLBA for Financial Services Compliance Practitioners

A structured path to owning critical compliance deliverables in regulated financial environments

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
M&A and regulator-facing reviews routed directly to your desk

The situation this course is for

In complex financial institutions, critical compliance artefacts like GLBA Safeguards Reports, data flow inventories, and third-party risk assessments often get caught in cross-team loops. When ownership isn't clear, rework delays submissions, weakens audit posture, and pushes final sign-off to senior sponsors. Practitioners who can close the loop on these artefacts become the default escalation point, not the bottleneck.

Who this is for

Compliance and risk practitioners in global financial institutions managing cross-border data, regulatory reporting, and control frameworks; focused on GLBA, data privacy, and audit readiness.

Who this is not for

Entry-level analysts learning basics, consultants selling frameworks, or practitioners outside regulated financial services.

What you walk away with

  • Own the final version of GLBA-mapped control documentation
  • Become the internal reference for cross-functional teams on data safeguards
  • Reduce rework in M&A integration packs by applying consistent GLBA templates
  • Receive direct handoffs from senior compliance leads on regulator-facing deliverables
  • Produce audit-ready narratives that require no rewrites under inspection cycles

The 12 modules (with all 144 chapters)

Module 1. Understanding GLBA's Core Structure
Break down the Gramm-Leach-Bliley Act into its three key titles: Financial Privacy, Safeguards, and Pretexting. Identify how each applies to customer information handling in multinational banking operations.
12 chapters in this module
  1. Overview of GLBA legislative intent and scope
  2. Key definitions: nonpublic personal information
  3. Historical context: post-GLBA financial consolidation
  4. Regulatory bodies enforcing GLBA: FTC and CFPB
  5. How GLBA intersects with international data laws
  6. Differences between GLBA and GDPR in data handling
  7. Sector-specific exemptions and limitations
  8. Timeline of major GLBA enforcement actions
  9. Consumer rights under the Privacy Rule
  10. Disclosure requirements for customer notices
  11. Role of senior management in GLBA compliance
  12. Common misconceptions about GLBA applicability
Module 2. The Financial Privacy Rule Explained
Detail the requirements for handling nonpublic personal information, including disclosure obligations, opt-out rights, and exceptions for affiliated sharing.
12 chapters in this module
  1. Scope of the Financial Privacy Rule
  2. Types of institutions subject to the rule
  3. Definition of nonpublic personal information
  4. When and how to provide privacy notices
  5. Annual disclosure timing and format
  6. Opt-out rights for consumers
  7. Exceptions to opt-out requirements
  8. Affiliated vs. unaffiliated third parties
  9. Data sharing between bank subsidiaries
  10. Electronic notice delivery standards
  11. Record retention for disclosure compliance
  12. Internal audit checks for notice accuracy
Module 3. Safeguards Rule Framework
Build a compliant information security program tailored to financial institutions, covering risk assessment, vendor oversight, and incident response planning.
12 chapters in this module
  1. Mandatory components of a safeguards program
  2. Designating a dedicated security lead
  3. Conducting thorough risk assessments
  4. Developing and testing security policies
  5. Employee training on data protection
  6. Monitoring systems for unauthorized access
  7. Implementing access controls by role
  8. Encrypting sensitive data at rest and in transit
  9. Vendor due diligence and oversight
  10. Incident response and breach notification
  11. Regular testing and monitoring cycles
  12. Adjusting safeguards based on findings
Module 4. Pretexting and Social Engineering
Recognize and prevent tactics used to obtain customer information through false pretenses, including phishing, impersonation, and database queries.
12 chapters in this module
  1. Definition and examples of pretexting
  2. Common social engineering techniques
  3. Protecting against phone-based pretexting
  4. Email spoofing and phishing detection
  5. Verifying identity before data release
  6. Training staff to recognize red flags
  7. Logging and reporting suspicious requests
  8. Third-party access control policies
  9. Call center verification protocols
  10. Multi-factor authentication for access
  11. Auditing access attempts and logs
  12. Updating defenses based on new tactics
Module 5. Data Inventory and Mapping
Conduct a comprehensive inventory of customer information across systems, locations, and processing activities to support Safeguards compliance.
12 chapters in this module
  1. Identifying all data collection points
  2. Classifying data by sensitivity level
  3. Documenting storage locations and formats
  4. Tracking data flows within the organization
  5. Mapping data sharing with third parties
  6. Using data flow diagrams effectively
  7. Updating inventories after system changes
  8. Assigning ownership to data categories
  9. Integrating inventory with risk assessments
  10. Automating data discovery processes
  11. Validating inventory completeness
  12. Reporting gaps to compliance leads
Module 6. Risk Assessment Execution
Perform a thorough, documented risk assessment focused on customer information security across people, processes, and technology.
12 chapters in this module
  1. Planning the risk assessment scope
  2. Engaging cross-functional stakeholders
  3. Identifying internal and external threats
  4. Evaluating existing security controls
  5. Prioritizing risks by likelihood and impact
  6. Documenting findings and recommendations
  7. Linking risks to control objectives
  8. Using standardized assessment frameworks
  9. Incorporating third-party risk data
  10. Reviewing assessments with legal teams
  11. Setting timelines for mitigation
  12. Tracking progress on remediation
Module 7. Security Program Development
Design and document an organization-wide information security program aligned with GLBA’s Safeguards Rule requirements.
12 chapters in this module
  1. Establishing program governance structure
  2. Defining roles and responsibilities
  3. Developing security policies and standards
  4. Creating incident response playbooks
  5. Setting up monitoring and alerting
  6. Integrating with change management
  7. Documenting program updates
  8. Aligning with enterprise risk framework
  9. Securing leadership approval
  10. Training teams on program elements
  11. Conducting annual reviews
  12. Measuring program effectiveness
Module 8. Vendor Oversight and Due Diligence
Ensure third-party service providers comply with GLBA by conducting thorough due diligence and ongoing monitoring.
12 chapters in this module
  1. Identifying vendors with data access
  2. Performing initial risk assessments
  3. Reviewing vendor security certifications
  4. Requiring written safeguards agreements
  5. Conducting on-site audits when needed
  6. Monitoring vendor compliance status
  7. Tracking contract renewal dates
  8. Evaluating vendor incident history
  9. Managing offboarding securely
  10. Updating due diligence for scope changes
  11. Centralizing vendor documentation
  12. Reporting vendor risks to compliance
Module 9. Incident Response and Reporting
Establish clear procedures for detecting, containing, assessing, and reporting data incidents involving customer information.
12 chapters in this module
  1. Defining what constitutes a reportable event
  2. Activating the incident response team
  3. Containing the breach quickly
  4. Assessing scope and data types affected
  5. Notifying internal stakeholders
  6. Engaging legal and compliance leads
  7. Preserving forensic evidence
  8. Reporting to regulators per policy
  9. Communicating with affected customers
  10. Conducting post-incident reviews
  11. Updating controls based on findings
  12. Maintaining incident logs
Module 10. Employee Training and Awareness
Deliver effective, role-specific training that ensures staff understand their responsibilities under GLBA.
12 chapters in this module
  1. Designing training for different roles
  2. Covering privacy and safeguards topics
  3. Including pretexting awareness
  4. Using real-world scenarios
  5. Delivering annual refresher content
  6. Tracking completion rates
  7. Testing knowledge retention
  8. Providing on-demand resources
  9. Incorporating new hire training
  10. Updating materials based on incidents
  11. Reporting training metrics
  12. Auditing training effectiveness
Module 11. Testing and Monitoring
Implement regular testing of security controls and continuous monitoring to verify the effectiveness of the safeguards program.
12 chapters in this module
  1. Scheduling annual penetration tests
  2. Conducting vulnerability scans
  3. Reviewing access logs regularly
  4. Performing social engineering tests
  5. Auditing policy compliance
  6. Evaluating control performance
  7. Using automated monitoring tools
  8. Reporting findings to management
  9. Integrating test results into risk register
  10. Prioritizing follow-up actions
  11. Documenting testing cycles
  12. Aligning with audit requirements
Module 12. Program Evaluation and Improvement
Establish a feedback loop for continuous improvement of the GLBA compliance program through management reviews and audits.
12 chapters in this module
  1. Scheduling annual program reviews
  2. Engaging senior management
  3. Incorporating audit findings
  4. Reviewing incident reports
  5. Assessing changes in business operations
  6. Updating policies based on changes
  7. Benchmarking against peer institutions
  8. Evaluating new regulatory guidance
  9. Prioritizing enhancements
  10. Documenting decisions and actions
  11. Reporting improvements to governance bodies
  12. Ensuring long-term sustainability

How this maps to your situation

  • GLBA compliance in global banking
  • Cross-border data governance
  • Regulatory submission ownership
  • M&A integration compliance

Before vs. after

Before
Waiting for senior leads to assign ownership of GLBA-related submissions, relying on legacy templates, reacting to audit findings.
After
Receiving direct handoffs on regulator-facing deliverables, leading M&A integration packs, producing audit-ready reports without rework.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 5 hours of focused learning, designed to be completed in short sessions over one week.

If nothing changes
Continuing to operate without clear ownership of GLBA deliverables means missed opportunities to lead high-visibility compliance work, slower recognition from senior management, and dependency on others for career progression.

How this compares to the alternatives

Public GLBA summaries lack actionable steps. Generic compliance courses don't address financial services nuances. Internal training often skips ownership mechanics. This course delivers exact templates and workflows used in top-tier banks to close the loop on real submissions.

Frequently asked

Is this course focused on U.S. compliance only?
While GLBA is U.S.-based, its requirements affect any global bank handling U.S. customer data. The course includes guidance on cross-border data handling relevant to institutions like the firm.
How is the course structured?
12 modules, each containing 2 chapters (144 chapters total).
Will I receive templates I can use immediately?
Yes. Every module includes downloadable, customizable templates , including a GLBA Safeguards Report draft, vendor due diligence checklist, and incident response flowchart.
$199 one-time. Approximately 5 hours of focused learning, designed to be completed in short sessions over one week..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours