A tailored course, built for your situation
Mastering GLBA for Financial Services Compliance Practitioners
A structured path to rigorous, defensible compliance grounded in real-world enforcement outcomes.
Who this is for
AVP-level compliance and risk professionals in global financial institutions managing GLBA, data privacy, and regulatory response frameworks.
Who this is not for
Junior analysts, external auditors, or professionals outside financial services where GLBA does not apply.
What you walk away with
- Trace every GLBA requirement to its originating statute, FTC guidance, or enforcement case
- Respond to peer challenges with specific examples from real regulatory actions
- Build control narratives that stand up to internal and external audit scrutiny
- Reference exact sections of the Gramm-Leach-Bliley Act and implementing rules in documentation
- Use precedent-based reasoning to justify control design, not just policy alignment
The 12 modules (with all 144 chapters)
- The the current cycle Financial Services Modernization Act
- Repeal of Glass-Steagall Act provisions
- Creation of financial holding companies
- Consumer privacy expectations post-merger
- FRB and OCC joint statements on data use
- Early FTC enforcement posture
- State-level privacy overlaps
- Data segmentation in multi-line institutions
- Inter-agency coordination models
- Privacy Notice rule foundations
- Safeguards Rule precursor frameworks
- Initial GLBA examination protocols
- Scope of covered financial institutions
- Designation of internal responsibility
- Risk assessment documentation standards
- Employee training requirements
- Access controls for customer data
- Encryption standards for data at rest
- Encryption in transit protocols
- Multi-factor authentication mandates
- Incident response planning
- Vendor oversight obligations
- Periodic testing frequency
- Change management integration
- Initial privacy notice timing
- Annual notice delivery methods
- Content requirements for clarity
- Opt-out rights for consumers
- Exceptions to opt-out rules
- Joint marketing disclosures
- Third-party sharing statements
- Online notice presentation
- Multilingual notice obligations
- Customer service handling of requests
- Record retention for notices
- Safe harbor provisions
- the current cycle Interagency Guidelines overview
- the current cycle Safeguards Rule updates
- FTC v. LifeLock precedent
- OCC enforcement against regional banks
- FRB supervision findings
- FDIC consent order patterns
- Penalties for noncompliance
- Consumer harm threshold
- Data breach reporting triggers
- Third-party vendor failures
- Reputational damage cases
- Corrective action timelines
- Lending data handling practices
- Wealth management client profiles
- Payment processing logs
- IT asset inventory standards
- Cloud data storage obligations
- Call center recording policies
- Email retention settings
- Mobile app data collection
- KYC process alignment
- Anti-money laundering overlaps
- Cross-border data flows
- Data localization requirements
- Identifying customer information systems
- Categorizing data sensitivity
- Threat modeling approach
- Vulnerability scoring system
- Likelihood-impact matrix
- Control gap analysis
- Remediation prioritization
- Third-party risk inclusion
- Cloud provider risk factors
- Insider threat considerations
- Physical security review
- Documentation standards
- Vendor identification process
- Pre-contract due diligence
- Data processing agreements
- Subcontractor oversight
- Audit rights clauses
- Cybersecurity questionnaires
- Penetration testing requirements
- Incident reporting SLAs
- Termination for noncompliance
- Ongoing monitoring frequency
- Vendor risk tiering
- Contract renewal checks
- Breach definition under GLBA
- 72-hour reporting expectations
- Regulator notification process
- Customer notification letters
- Credit monitoring obligations
- Media statement preparation
- Law enforcement coordination
- Internal escalation paths
- Legal counsel engagement
- Post-mortem documentation
- Regulatory follow-up
- Corrective action planning
- Annual training requirement
- Role-based curriculum design
- Phishing simulation integration
- Data handling policies
- Physical access rules
- Remote work considerations
- Mobile device policies
- Social engineering defenses
- Reporting suspicious activity
- Disciplinary actions
- Training record keeping
- Acknowledgment signatures
- OCC examination scope
- FRB review protocols
- FTC investigation triggers
- Document organization standards
- Control testing walkthroughs
- Interview preparation
- Evidence retention periods
- Prior finding resolution
- Cross-agency coordination
- Examiner communication norms
- Corrective action responses
- Follow-up inspection prep
- EU-US data transfer mechanisms
- Standard Contractual Clauses
- UK data adequacy status
- APAC privacy law overlaps
- Data localization laws
- Encryption for transit
- Data residency mapping
- Vendor subprocessing
- Internal data routing logs
- Customer consent requirements
- Regulator inquiry responses
- Multi-jurisdictional alignment
- Control ownership documentation
- Succession planning for compliance
- Knowledge transfer protocols
- Standard operating procedures
- Automated control monitoring
- Centralized repository design
- Version control for policies
- Cross-functional alignment
- Executive briefing templates
- Board-level summary formats
- Regulatory change tracking
- Continuous improvement process
How this maps to your situation
- Preparing for regulatory examination
- Responding to internal audit findings
- Designing controls for new product launch
- Managing third-party risk in cloud migration
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 12 hours of focused reading and implementation planning, designed for integration into current compliance cycles.
How this compares to the alternatives
Unlike generic compliance overviews, this course delivers verifiable sources, real enforcement precedents, and control templates tied directly to GLBA requirements, enabling immediate application in audits and peer reviews.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.