A tailored course, built for your situation
Mastering GLBA for Senior KYC Practitioners in Global Financial Institutions
Build defensible, source-backed KYC frameworks that hold up to internal scrutiny and regulatory follow-up
The situation this course is for
KYC professionals are often expected to defend control designs without access to structured regulatory reasoning. When peers or auditors question threshold logic or data sourcing, responses default to 'policy says so', weakening credibility and inviting repeated review.
Who this is for
Senior KYC practitioner in a global financial institution, responsible for designing and defending control frameworks under U.S. and international regulations
Who this is not for
Entry-level compliance staff, IT auditors without KYC ownership, or professionals outside financial services
What you walk away with
- Articulate the regulatory 'why' behind KYC controls using GLBA-specific sections and enforcement history
- Respond confidently to cross-functional challenges with citations and real-world examples
- Structure control documentation to reflect defensible reasoning, not just procedural compliance
- Differentiate between GLBA requirements and internal policy layering
- Demonstrate alignment with U.S. regulatory expectations in global implementation contexts
The 12 modules (with all 144 chapters)
- Understanding the Gramm-Leach-Bliley Act in post-Dodd-Frank finance
- Key regulatory bodies enforcing GLBA: OCR, FDIC, Federal Reserve roles
- How GLBA interfaces with KYC and AML frameworks in U.S. and EBA jurisdictions
- Scope of 'nonpublic personal information' in digital banking environments
- GLBA vs. GDPR and CCPA: mapping overlapping and distinct data categories
- Historical evolution of GLBA since the current cycle and recent enforcement trends
- Consumer Financial Protection Bureau's role in privacy enforcement
- State-level variations in GLBA implementation and compliance expectations
- Interpreting 'financial institution' under GLBA in complex group structures
- GLBA's impact on third-party vendor management in KYC workflows
- Regulatory safe harbors and compliance presumptions under the Act
- How global banks operationalize GLBA outside U.S. legal jurisdictions
- Key elements of the Financial Privacy Rule under 16 CFR Part 313
- When and how to deliver initial and annual privacy notices
- Content requirements for effective privacy notices under GLBA
- Methods for delivering privacy notices across digital and paper channels
- Exceptions to privacy notice requirements in joint account scenarios
- Handling opt-out rights for marketing disclosures under the Rule
- Treatment of nonpublic personal information in account opening workflows
- Data sharing limitations between affiliated and unaffiliated entities
- Customer consent mechanisms compliant with GLBA standards
- Documentation needed to prove notice delivery and opt-out processing
- Enforcement cases involving failure to deliver required notices
- Best practices for privacy notice integration in onboarding systems
- Core obligations under the Safeguards Rule (16 CFR Part 314)
- Defining 'customer information' for safeguarding in KYC systems
- Risk assessment methodology specific to KYC data inventories
- Designating a qualified individual to oversee the safeguards program
- Implementing multi-factor authentication for systems with customer data
- Encryption standards for data at rest and in transit per GLBA guidance
- Vendor due diligence under the Safeguards Rule for KYC providers
- Incident response planning aligned with GLBA reporting expectations
- Secure disposal of customer information after account closure
- Periodic testing and evaluation of security controls
- Documentation of risk assessment and control effectiveness
- Lessons from FTC enforcement actions on inadequate safeguards
- Definition of pretexting under GLBA Section 501(b) and examples
- Common pretexting tactics targeting KYC and onboarding staff
- Employee training requirements to prevent unauthorized data access
- Procedures for verifying identity without enabling social engineering
- Call center scripts and customer verification protocols that reduce risk
- Logging and monitoring access to customer information systems
- Reporting suspicious access attempts under institution policy
- Role of dual controls in high-risk KYC data access scenarios
- Third-party service provider obligations under pretexting rules
- Case study: pretexting incident at a national bank and response
- Internal audits focused on pretexting prevention controls
- Balancing customer experience with security in verification flows
- FTC enforcement authority under GLBA and penalties applied
- Federal banking agency enforcement patterns in recent years
- State attorneys general actions under privacy provisions
- Notable cases: First American Financial, Fandango, DeVry University
- Common deficiencies cited in GLBA enforcement actions
- Expectations for 'reasonable' safeguards in multi-jurisdictional banks
- Regulatory coordination between CFPB, OCC, and state agencies
- Public disclosure requirements when breaches involve GLBA data
- How consent orders shape future supervisory expectations
- Lessons from resolved enforcement cases for KYC teams
- Documentation retention for compliance defense
- Preparing for GLBA-focused review cycles with internal audit
- Mapping account opening steps to GLBA data handling rules
- Designing privacy notice delivery into onboarding touchpoints
- Automating opt-out preference capture in digital KYC flows
- System requirements for customer information classification
- Access controls for KYC analysts handling nonpublic data
- Audit logging for access to sensitive KYC records
- Data minimization in customer information collection
- Vendor management interfaces in outsourced KYC
- System-to-system data sharing compliant with GLBA limits
- Exception handling for incomplete notice delivery
- Workflow rules for handling expired privacy preferences
- Testing KYC systems against GLBA compliance scenarios
- Defining 'service provider' under GLBA for KYC vendors
- Due diligence requirements before engaging third-party KYC providers
- Contractual obligations for GLBA compliance in vendor agreements
- Reviewing vendor security controls and audit reports
- Oversight of vendor incident response capabilities
- Monitoring vendor compliance with privacy notice obligations
- Vendor access to customer information: logging and review
- Penetration testing expectations for critical KYC vendors
- Managing subcontractor relationships under GLBA rules
- Vendor termination and data return protocols
- Documentation of vendor management activities for examiners
- Lessons from vendor-related enforcement actions under GLBA
- Applicability of GLBA to non-U.S. branches and subsidiaries
- Establishing U.S. nexus for data handling obligations
- Data localization strategies to meet GLBA and other regulations
- Transferring KYC data from EU to U.S. under GLBA and GDPR
- Role of model clauses and SCCs in GLBA-aligned transfers
- Managing differing opt-out expectations across jurisdictions
- Privacy notice translation and delivery standards
- Cross-border incident reporting aligned with GLBA expectations
- Centralized vs. decentralized KYC models under GLBA scrutiny
- Regulatory coordination with non-U.S. supervisors
- Documentation of global compliance strategy
- Case study: GLBA review of a pan-European onboarding rollout
- Audit scope expectations for GLBA's Financial Privacy Rule
- Audit scope for Safeguards Rule compliance
- Reviewing KYC process documentation for GLBA alignment
- Testing privacy notice delivery mechanisms
- Validating opt-out processing and preference tracking
- Auditing access logs for unauthorized customer data access
- Reviewing vendor management files for GLBA coverage
- Assessing risk assessment documentation completeness
- Evaluating incident response plans for GLBA relevance
- Audit sampling methods for KYC data handling
- Reporting findings to management with GLBA citations
- Using audit findings to improve defensibility of KYC controls
- Regulatory requirements for employee training under GLBA
- KYC-specific training content on privacy and safeguards
- Frequency and format of required training sessions
- Role-based training for onboarding, call center, and KYC analysts
- Content for managers overseeing GLBA-compliant processes
- Training on pretexting and social engineering awareness
- Vendor staff training expectations and verification
- Documenting training completion for examiners
- Evaluating training effectiveness through testing
- Updating training materials after enforcement actions
- Using real incidents as training case studies
- Digital badge systems for tracking compliance training
- Defining a 'breach' under GLBA and related regulations
- Notification obligations to customers after data exposure
- Reporting to regulators in GLBA-covered incidents
- Coordination between incident response and privacy teams
- Documentation needed for breach defense
- Safe harbor for encrypted data under GLBA guidance
- Assessing risk of harm to customers after exposure
- Customer notification content and delivery requirements
- Vendor breach notification obligations
- Post-incident audits and control enhancements
- Public statement alignment with GLBA expectations
- Lessons from breach responses in financial sector
- Structuring responses around GLBA statutory language
- Using enforcement actions as precedent in internal debates
- Mapping control decisions to Safeguards Rule requirements
- Articulating 'reasonable' safeguards in examiner discussions
- Differentiating policy choices from regulatory mandates
- Using risk assessments to justify control design
- Citing FTC guidance in vendor management decisions
- Responding to 'why not more stringent?' challenges
- Preparing for regulator follow-up with documentation
- Building internal credibility through precise reasoning
- Maintaining documentation to support long-term positions
- Refining talking points based on recent exam trends
How this maps to your situation
- GLBA relevance to KYC in global banks
- Privacy and data handling in onboarding
- Security controls for customer information
- Defending decisions under regulatory scrutiny
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 90 minutes per module, designed for completion over 4-6 weeks with weekend study.
How this compares to the alternatives
Generic compliance courses cover broad regulations without KYC specificity. This course focuses exclusively on GLBA as applied to KYC workflows in global banks, with real examples, defensible reasoning structures, and implementation tools not found in generalist training.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.