FTC Safeguards Rule emerging areas in 2024-2025. AI USE IN FINANCIAL INSTITUTIONS: FTC AI guidance + 2024 OMB M-22-09 ZTA + 2024 OMB M-24-08 AI Risk Management + Section 5 FTC Act unfair-and-deceptive enforcement against discriminatory AI + opaque scoring + biased credit decisions; financial institutions using AI for credit + underwriting + fraud detection + customer service must integrate AI risk into the 314.4(b) written risk assessment + 314.4(c) safeguard elements; the QUALIFIED INDIVIDUAL must ensure AI systems handling customer information are subject to: (a) data inventory + classification (314.4(c)(2)); (b) encryption (314.4(c)(3)); (c) MFA for AI system access (314.4(c)(5)); (d) monitoring + logging (314.4(c)(8)); (e) pen testing/vuln assessment of AI components (314.4(c)(9)). SBOM + SOFTWARE BILL OF MATERIALS: 2024 OMB M-22-18 + FTC guidance require SBOM for critical software used in financial institutions handling customer information; the Qualified Individual should track + assess SBOM-based supply-chain risks. SUPPLY-CHAIN DUE DILIGENCE: 2024-2025 FTC focus on 4th-party + 5th-party risks via service-provider oversight (314.4(d)) including cloud + AI + SaaS + outsourced functions; EO 14117 cross-border data restrictions on countries of concern + sectoral due-diligence applicable. CYBER INSURANCE: increasingly required by Boards + insurers + with coverage gaps + exclusions for AI-related claims. OPEN BANKING + CFPB 1033 (Personal Financial Data Rights Rule): 2024 final rule + may add data-sharing-related safeguards requirements + intersection with the FTC Safeguards Rule for non-bank consumer financial products.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.