Skip to main content
Image coming soon

CMP6772 Mastering GLBA for Financial Services Compliance Practitioners

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Mastering GLBA for Financial Services Compliance Practitioners

A structured path to rigorous, defensible compliance grounded in real-world enforcement outcomes.

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

AVP-level compliance and risk professionals in global financial institutions managing GLBA, data privacy, and regulatory response frameworks.

Who this is not for

Junior analysts, external auditors, or professionals outside financial services where GLBA does not apply.

What you walk away with

  • Trace every GLBA requirement to its originating statute, FTC guidance, or enforcement case
  • Respond to peer challenges with specific examples from real regulatory actions
  • Build control narratives that stand up to internal and external audit scrutiny
  • Reference exact sections of the Gramm-Leach-Bliley Act and implementing rules in documentation
  • Use precedent-based reasoning to justify control design, not just policy alignment

The 12 modules (with all 144 chapters)

Module 1. Origins of GLBA and the Financial Modernization Context
Understand the legislative intent behind the Gramm-Leach-Bliley Act, including the repeal of Glass-Steagall and the creation of financial conglomerates. Explore how data handling expectations emerged from systemic risk reforms.
12 chapters in this module
  1. The the current cycle Financial Services Modernization Act
  2. Repeal of Glass-Steagall Act provisions
  3. Creation of financial holding companies
  4. Consumer privacy expectations post-merger
  5. FRB and OCC joint statements on data use
  6. Early FTC enforcement posture
  7. State-level privacy overlaps
  8. Data segmentation in multi-line institutions
  9. Inter-agency coordination models
  10. Privacy Notice rule foundations
  11. Safeguards Rule precursor frameworks
  12. Initial GLBA examination protocols
Module 2. FTC Safeguards Rule: Structure and Scope
Break down the FTC’s Safeguards Rule into actionable control domains. Learn how each requirement maps to technical, administrative, and physical safeguards.
12 chapters in this module
  1. Scope of covered financial institutions
  2. Designation of internal responsibility
  3. Risk assessment documentation standards
  4. Employee training requirements
  5. Access controls for customer data
  6. Encryption standards for data at rest
  7. Encryption in transit protocols
  8. Multi-factor authentication mandates
  9. Incident response planning
  10. Vendor oversight obligations
  11. Periodic testing frequency
  12. Change management integration
Module 3. Privacy Rule: Notice and Choice Requirements
Master the requirements for initial and annual privacy notices. Learn how to structure opt-out mechanisms and handle joint marketing disclosures.
12 chapters in this module
  1. Initial privacy notice timing
  2. Annual notice delivery methods
  3. Content requirements for clarity
  4. Opt-out rights for consumers
  5. Exceptions to opt-out rules
  6. Joint marketing disclosures
  7. Third-party sharing statements
  8. Online notice presentation
  9. Multilingual notice obligations
  10. Customer service handling of requests
  11. Record retention for notices
  12. Safe harbor provisions
Module 4. Interagency Guidelines and Enforcement Trends
Review joint guidance from the FRB, OCC, and FDIC. Analyze enforcement actions and consent orders to identify high-risk control gaps.
12 chapters in this module
  1. the current cycle Interagency Guidelines overview
  2. the current cycle Safeguards Rule updates
  3. FTC v. LifeLock precedent
  4. OCC enforcement against regional banks
  5. FRB supervision findings
  6. FDIC consent order patterns
  7. Penalties for noncompliance
  8. Consumer harm threshold
  9. Data breach reporting triggers
  10. Third-party vendor failures
  11. Reputational damage cases
  12. Corrective action timelines
Module 5. Control Mapping Across Business Units
Map GLBA requirements to specific functions: lending, wealth management, payments, and IT. Identify ownership and accountability.
12 chapters in this module
  1. Lending data handling practices
  2. Wealth management client profiles
  3. Payment processing logs
  4. IT asset inventory standards
  5. Cloud data storage obligations
  6. Call center recording policies
  7. Email retention settings
  8. Mobile app data collection
  9. KYC process alignment
  10. Anti-money laundering overlaps
  11. Cross-border data flows
  12. Data localization requirements
Module 6. Risk Assessment Methodology for GLBA
Build a defensible risk assessment process specific to GLBA. Use standardized templates and scoring frameworks.
12 chapters in this module
  1. Identifying customer information systems
  2. Categorizing data sensitivity
  3. Threat modeling approach
  4. Vulnerability scoring system
  5. Likelihood-impact matrix
  6. Control gap analysis
  7. Remediation prioritization
  8. Third-party risk inclusion
  9. Cloud provider risk factors
  10. Insider threat considerations
  11. Physical security review
  12. Documentation standards
Module 7. Vendor Management and Third-Party Risk
Ensure compliance with vendor oversight requirements. Develop due diligence and monitoring processes.
12 chapters in this module
  1. Vendor identification process
  2. Pre-contract due diligence
  3. Data processing agreements
  4. Subcontractor oversight
  5. Audit rights clauses
  6. Cybersecurity questionnaires
  7. Penetration testing requirements
  8. Incident reporting SLAs
  9. Termination for noncompliance
  10. Ongoing monitoring frequency
  11. Vendor risk tiering
  12. Contract renewal checks
Module 8. Incident Response and Breach Notification
Align incident response plans with GLBA requirements. Understand when and how to notify regulators and customers.
12 chapters in this module
  1. Breach definition under GLBA
  2. 72-hour reporting expectations
  3. Regulator notification process
  4. Customer notification letters
  5. Credit monitoring obligations
  6. Media statement preparation
  7. Law enforcement coordination
  8. Internal escalation paths
  9. Legal counsel engagement
  10. Post-mortem documentation
  11. Regulatory follow-up
  12. Corrective action planning
Module 9. Training and Employee Accountability
Develop effective employee training programs. Ensure staff understand their role in protecting customer data.
12 chapters in this module
  1. Annual training requirement
  2. Role-based curriculum design
  3. Phishing simulation integration
  4. Data handling policies
  5. Physical access rules
  6. Remote work considerations
  7. Mobile device policies
  8. Social engineering defenses
  9. Reporting suspicious activity
  10. Disciplinary actions
  11. Training record keeping
  12. Acknowledgment signatures
Module 10. Audit Preparation and Examination Readiness
Prepare for routine and surprise examinations. Know what examiners look for and how to present evidence effectively.
12 chapters in this module
  1. OCC examination scope
  2. FRB review protocols
  3. FTC investigation triggers
  4. Document organization standards
  5. Control testing walkthroughs
  6. Interview preparation
  7. Evidence retention periods
  8. Prior finding resolution
  9. Cross-agency coordination
  10. Examiner communication norms
  11. Corrective action responses
  12. Follow-up inspection prep
Module 11. International Data Transfer Compliance
Address cross-border data flows under GLBA and complementary frameworks like GDPR.
12 chapters in this module
  1. EU-US data transfer mechanisms
  2. Standard Contractual Clauses
  3. UK data adequacy status
  4. APAC privacy law overlaps
  5. Data localization laws
  6. Encryption for transit
  7. Data residency mapping
  8. Vendor subprocessing
  9. Internal data routing logs
  10. Customer consent requirements
  11. Regulator inquiry responses
  12. Multi-jurisdictional alignment
Module 12. Sustaining Compliance Across Leadership Changes
Create self-documenting, transferable compliance frameworks that survive personnel shifts.
12 chapters in this module
  1. Control ownership documentation
  2. Succession planning for compliance
  3. Knowledge transfer protocols
  4. Standard operating procedures
  5. Automated control monitoring
  6. Centralized repository design
  7. Version control for policies
  8. Cross-functional alignment
  9. Executive briefing templates
  10. Board-level summary formats
  11. Regulatory change tracking
  12. Continuous improvement process

How this maps to your situation

  • Preparing for regulatory examination
  • Responding to internal audit findings
  • Designing controls for new product launch
  • Managing third-party risk in cloud migration

Before vs. after

Before
Compliance decisions are reactive, based on general understanding and policy summaries.
After
Every control decision is backed by statute, precedent, and documented rationale accessible to peers and examiners.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 12 hours of focused reading and implementation planning, designed for integration into current compliance cycles.

If nothing changes
Without structured depth in GLBA compliance, practitioners risk appearing reactive during audits, unable to defend design choices when challenged by leadership or regulators.

How this compares to the alternatives

Unlike generic compliance overviews, this course delivers verifiable sources, real enforcement precedents, and control templates tied directly to GLBA requirements, enabling immediate application in audits and peer reviews.

Frequently asked

Is this course relevant to non-US financial institutions?
Yes, any institution handling data of US consumers falls under GLBA jurisdiction. The course includes guidance on international application.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Are real enforcement cases included?
Yes, every major FTC and interagency enforcement action since the current cycle is analyzed for control lessons.
$199 one-time. Approximately 12 hours of focused reading and implementation planning, designed for integration into current compliance cycles..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours