Skip to main content
Image coming soon

GEN6136 Mastering GLBA for Senior KYC Practitioners in Global Financial Institutions

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering GLBA for Senior KYC Practitioners in Global Financial Institutions

Build defensible, source-backed KYC frameworks that hold up to internal scrutiny and regulatory follow-up

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Frequent internal challenges to KYC control decisions due to lack of regulatory grounding

The situation this course is for

KYC professionals are often expected to defend control designs without access to structured regulatory reasoning. When peers or auditors question threshold logic or data sourcing, responses default to 'policy says so', weakening credibility and inviting repeated review.

Who this is for

Senior KYC practitioner in a global financial institution, responsible for designing and defending control frameworks under U.S. and international regulations

Who this is not for

Entry-level compliance staff, IT auditors without KYC ownership, or professionals outside financial services

What you walk away with

  • Articulate the regulatory 'why' behind KYC controls using GLBA-specific sections and enforcement history
  • Respond confidently to cross-functional challenges with citations and real-world examples
  • Structure control documentation to reflect defensible reasoning, not just procedural compliance
  • Differentiate between GLBA requirements and internal policy layering
  • Demonstrate alignment with U.S. regulatory expectations in global implementation contexts

The 12 modules (with all 144 chapters)

Module 1. GLBA Overview and Relevance to Modern KYC
Establish foundational understanding of GLBA's structure, key titles, and applicability to customer identification and data handling in banking contexts.
12 chapters in this module
  1. Understanding the Gramm-Leach-Bliley Act in post-Dodd-Frank finance
  2. Key regulatory bodies enforcing GLBA: OCR, FDIC, Federal Reserve roles
  3. How GLBA interfaces with KYC and AML frameworks in U.S. and EBA jurisdictions
  4. Scope of 'nonpublic personal information' in digital banking environments
  5. GLBA vs. GDPR and CCPA: mapping overlapping and distinct data categories
  6. Historical evolution of GLBA since the current cycle and recent enforcement trends
  7. Consumer Financial Protection Bureau's role in privacy enforcement
  8. State-level variations in GLBA implementation and compliance expectations
  9. Interpreting 'financial institution' under GLBA in complex group structures
  10. GLBA's impact on third-party vendor management in KYC workflows
  11. Regulatory safe harbors and compliance presumptions under the Act
  12. How global banks operationalize GLBA outside U.S. legal jurisdictions
Module 2. The Financial Privacy Rule and Customer Data Handling
Break down the Financial Privacy Rule’s requirements and operational expectations for data collection, use, and disclosure.
12 chapters in this module
  1. Key elements of the Financial Privacy Rule under 16 CFR Part 313
  2. When and how to deliver initial and annual privacy notices
  3. Content requirements for effective privacy notices under GLBA
  4. Methods for delivering privacy notices across digital and paper channels
  5. Exceptions to privacy notice requirements in joint account scenarios
  6. Handling opt-out rights for marketing disclosures under the Rule
  7. Treatment of nonpublic personal information in account opening workflows
  8. Data sharing limitations between affiliated and unaffiliated entities
  9. Customer consent mechanisms compliant with GLBA standards
  10. Documentation needed to prove notice delivery and opt-out processing
  11. Enforcement cases involving failure to deliver required notices
  12. Best practices for privacy notice integration in onboarding systems
Module 3. Safeguards Rule: Building a Risk-Based Security Program
Map KYC data flows to Safeguards Rule requirements and build defensible security controls.
12 chapters in this module
  1. Core obligations under the Safeguards Rule (16 CFR Part 314)
  2. Defining 'customer information' for safeguarding in KYC systems
  3. Risk assessment methodology specific to KYC data inventories
  4. Designating a qualified individual to oversee the safeguards program
  5. Implementing multi-factor authentication for systems with customer data
  6. Encryption standards for data at rest and in transit per GLBA guidance
  7. Vendor due diligence under the Safeguards Rule for KYC providers
  8. Incident response planning aligned with GLBA reporting expectations
  9. Secure disposal of customer information after account closure
  10. Periodic testing and evaluation of security controls
  11. Documentation of risk assessment and control effectiveness
  12. Lessons from FTC enforcement actions on inadequate safeguards
Module 4. Pretexting and Social Engineering Protections
Understand and defend against pretexting risks in KYC verification workflows.
12 chapters in this module
  1. Definition of pretexting under GLBA Section 501(b) and examples
  2. Common pretexting tactics targeting KYC and onboarding staff
  3. Employee training requirements to prevent unauthorized data access
  4. Procedures for verifying identity without enabling social engineering
  5. Call center scripts and customer verification protocols that reduce risk
  6. Logging and monitoring access to customer information systems
  7. Reporting suspicious access attempts under institution policy
  8. Role of dual controls in high-risk KYC data access scenarios
  9. Third-party service provider obligations under pretexting rules
  10. Case study: pretexting incident at a national bank and response
  11. Internal audits focused on pretexting prevention controls
  12. Balancing customer experience with security in verification flows
Module 5. GLBA Enforcement and Regulatory Expectations
Study past enforcement actions to anticipate reviewer scrutiny.
12 chapters in this module
  1. FTC enforcement authority under GLBA and penalties applied
  2. Federal banking agency enforcement patterns in recent years
  3. State attorneys general actions under privacy provisions
  4. Notable cases: First American Financial, Fandango, DeVry University
  5. Common deficiencies cited in GLBA enforcement actions
  6. Expectations for 'reasonable' safeguards in multi-jurisdictional banks
  7. Regulatory coordination between CFPB, OCC, and state agencies
  8. Public disclosure requirements when breaches involve GLBA data
  9. How consent orders shape future supervisory expectations
  10. Lessons from resolved enforcement cases for KYC teams
  11. Documentation retention for compliance defense
  12. Preparing for GLBA-focused review cycles with internal audit
Module 6. KYC Workflow Design with GLBA Compliance by Design
Embed GLBA requirements into KYC process architecture and tooling.
12 chapters in this module
  1. Mapping account opening steps to GLBA data handling rules
  2. Designing privacy notice delivery into onboarding touchpoints
  3. Automating opt-out preference capture in digital KYC flows
  4. System requirements for customer information classification
  5. Access controls for KYC analysts handling nonpublic data
  6. Audit logging for access to sensitive KYC records
  7. Data minimization in customer information collection
  8. Vendor management interfaces in outsourced KYC
  9. System-to-system data sharing compliant with GLBA limits
  10. Exception handling for incomplete notice delivery
  11. Workflow rules for handling expired privacy preferences
  12. Testing KYC systems against GLBA compliance scenarios
Module 7. Third-Party Vendor Management under GLBA
Ensure external partners meet GLBA obligations in KYC delivery.
12 chapters in this module
  1. Defining 'service provider' under GLBA for KYC vendors
  2. Due diligence requirements before engaging third-party KYC providers
  3. Contractual obligations for GLBA compliance in vendor agreements
  4. Reviewing vendor security controls and audit reports
  5. Oversight of vendor incident response capabilities
  6. Monitoring vendor compliance with privacy notice obligations
  7. Vendor access to customer information: logging and review
  8. Penetration testing expectations for critical KYC vendors
  9. Managing subcontractor relationships under GLBA rules
  10. Vendor termination and data return protocols
  11. Documentation of vendor management activities for examiners
  12. Lessons from vendor-related enforcement actions under GLBA
Module 8. GLBA and Cross-Border KYC Operations
Operationalize GLBA in global institutions with data flows across regions.
12 chapters in this module
  1. Applicability of GLBA to non-U.S. branches and subsidiaries
  2. Establishing U.S. nexus for data handling obligations
  3. Data localization strategies to meet GLBA and other regulations
  4. Transferring KYC data from EU to U.S. under GLBA and GDPR
  5. Role of model clauses and SCCs in GLBA-aligned transfers
  6. Managing differing opt-out expectations across jurisdictions
  7. Privacy notice translation and delivery standards
  8. Cross-border incident reporting aligned with GLBA expectations
  9. Centralized vs. decentralized KYC models under GLBA scrutiny
  10. Regulatory coordination with non-U.S. supervisors
  11. Documentation of global compliance strategy
  12. Case study: GLBA review of a pan-European onboarding rollout
Module 9. Internal Audit and GLBA Readiness
Prepare for audit cycles with defensible, source-backed documentation.
12 chapters in this module
  1. Audit scope expectations for GLBA's Financial Privacy Rule
  2. Audit scope for Safeguards Rule compliance
  3. Reviewing KYC process documentation for GLBA alignment
  4. Testing privacy notice delivery mechanisms
  5. Validating opt-out processing and preference tracking
  6. Auditing access logs for unauthorized customer data access
  7. Reviewing vendor management files for GLBA coverage
  8. Assessing risk assessment documentation completeness
  9. Evaluating incident response plans for GLBA relevance
  10. Audit sampling methods for KYC data handling
  11. Reporting findings to management with GLBA citations
  12. Using audit findings to improve defensibility of KYC controls
Module 10. Training and Awareness for KYC Teams
Develop role-specific training to prevent GLBA violations.
12 chapters in this module
  1. Regulatory requirements for employee training under GLBA
  2. KYC-specific training content on privacy and safeguards
  3. Frequency and format of required training sessions
  4. Role-based training for onboarding, call center, and KYC analysts
  5. Content for managers overseeing GLBA-compliant processes
  6. Training on pretexting and social engineering awareness
  7. Vendor staff training expectations and verification
  8. Documenting training completion for examiners
  9. Evaluating training effectiveness through testing
  10. Updating training materials after enforcement actions
  11. Using real incidents as training case studies
  12. Digital badge systems for tracking compliance training
Module 11. Incident Response and Breach Reporting under GLBA
Align incident management with GLBA’s expectations.
12 chapters in this module
  1. Defining a 'breach' under GLBA and related regulations
  2. Notification obligations to customers after data exposure
  3. Reporting to regulators in GLBA-covered incidents
  4. Coordination between incident response and privacy teams
  5. Documentation needed for breach defense
  6. Safe harbor for encrypted data under GLBA guidance
  7. Assessing risk of harm to customers after exposure
  8. Customer notification content and delivery requirements
  9. Vendor breach notification obligations
  10. Post-incident audits and control enhancements
  11. Public statement alignment with GLBA expectations
  12. Lessons from breach responses in financial sector
Module 12. Defending KYC Decisions in Regulatory and Peer Reviews
Use GLBA to build source-backed, articulate responses to challenges.
12 chapters in this module
  1. Structuring responses around GLBA statutory language
  2. Using enforcement actions as precedent in internal debates
  3. Mapping control decisions to Safeguards Rule requirements
  4. Articulating 'reasonable' safeguards in examiner discussions
  5. Differentiating policy choices from regulatory mandates
  6. Using risk assessments to justify control design
  7. Citing FTC guidance in vendor management decisions
  8. Responding to 'why not more stringent?' challenges
  9. Preparing for regulator follow-up with documentation
  10. Building internal credibility through precise reasoning
  11. Maintaining documentation to support long-term positions
  12. Refining talking points based on recent exam trends

How this maps to your situation

  • GLBA relevance to KYC in global banks
  • Privacy and data handling in onboarding
  • Security controls for customer information
  • Defending decisions under regulatory scrutiny

Before vs. after

Before
Defending KYC control decisions based on internal policy without regulatory grounding
After
Confidently articulating the GLBA basis for thresholds, data use, and escalation paths with specific citations and examples

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 90 minutes per module, designed for completion over 4-6 weeks with weekend study.

If nothing changes
Without structured regulatory grounding, KYC decisions may be perceived as arbitrary, leading to repeated review cycles, erosion of internal credibility, and higher risk of non-conformance findings during exams.

How this compares to the alternatives

Generic compliance courses cover broad regulations without KYC specificity. This course focuses exclusively on GLBA as applied to KYC workflows in global banks, with real examples, defensible reasoning structures, and implementation tools not found in generalist training.

Frequently asked

How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Is this relevant if I'm outside the U.S.?
Yes. GLBA applies to U.S.-connected operations of global banks. the firm's U.S. presence makes GLBA a key reference standard for KYC design and defense.
Do I need legal training to benefit?
No. The course translates GLBA into operational decisions without requiring legal expertise.
$199 one-time. Approximately 90 minutes per module, designed for completion over 4-6 weeks with weekend study..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours