IntegrationsBlogBook a free AI assessment
Industry

Under 5,000 Clients? Four Safeguards Rule Duties You Do Not Have, and the Ones You Still Do

16 CFR 314.6 removes four Safeguards Rule duties for firms under 5,000 consumers. Which four, what survives, and how firms miscount the threshold.

By Mustafa Najoom»Oct 1, 2026»7 min read»safeguards rule 5000 consumers

The Safeguards Rule contains an exception for firms holding customer information on fewer than five thousand consumers, and it removes four specific obligations. All four are documents. Every control that actually protects the data survives, as does the duty to update your program when you deploy something new.

What does 314.6 actually say?

It is one sentence. 16 CFR 314.6 reads, in full: "Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers."

That is the whole exception. There is no application, no filing and no certification. If you are under the line, those four subsections simply do not apply to you, and a compliance vendor quoting you for all four is quoting you for work the rule does not ask of you.

Which four duties fall away?

The written risk assessment, the penetration testing and vulnerability assessment cadence, the written incident response plan, and the annual report. They are the four heaviest pieces of paperwork in 314.4, and every one of them is a document rather than a control.

  • 314.4(b)(1), the written risk assessment. You still have to think about risk, because the rest of the program is built on it. You do not have to produce the formal written assessment in the form the subsection prescribes.
  • 314.4(d)(2), the penetration testing and vulnerability assessment cadence. This is usually the single largest line item in a small firm's security budget.
  • 314.4(h), the written incident response plan.
  • 314.4(i), the annual report.

For a ten person practice that is a meaningful reduction, and it is worth confirming you qualify before you sign anything.

What does the exception not remove?

Every control that touches the data. Encryption, multi factor authentication and the service provider duties all sit in 314.4 outside the four exempted subsections, so they apply to a two partner firm exactly as they apply to a national one.

The encryption requirement is worth reading in its own words. 314.4(c)(3) requires you to "Protect by encryption all customer information held or transmitted by you both in transit over external networks and at rest", with "effective alternative compensating controls reviewed and approved by your Qualified Individual" where encryption is infeasible. Note that the compensating control route requires a named person to review and approve, which is a small firm's most commonly missed step because the Qualified Individual is often the person least likely to have read the vendor terms.

The right way to describe 314.6 to a partner: it is an exception about documents, not an exception about security.

Does the exception cover the duty to update your program?

No, and this is the one that catches firms adding AI tools. 314.4(g) requires the program to be adjusted for "any material changes to your operations or business arrangements", and (g) does not appear in the 314.6 list.

So a four person firm that starts routing client data through a model owes the same adjustment a four hundred person firm owes. What the exception spares you is the surrounding paperwork, the formal written risk assessment and the annual report. It does not spare you the update itself, and your WISP almost certainly does not mention AI yet. 314.4(c)(7), "Adopt procedures for change management", is also outside the exception, which means the small firm still needs a procedure for how a new tool gets approved before it touches client data.

How do you count to five thousand?

The text counts consumers, not clients, not engagements and not staff. That distinction is where firms get the answer wrong in their own favor.

A practice with 300 business clients can feel comfortably under the line and not be. If your engagements put you in contact with individual returns, W-2 data, K-1 recipients or beneficial owners, those are individuals whose customer information you maintain, and they are countable. The arithmetic runs on people, and a modest book of business entities can carry several thousand people inside it.

Treat that as a reading of the text rather than a settled answer, because the rule does not supply a counting method and reasonable advisers differ on the edges. The practical posture: if your own count lands anywhere near five thousand, plan as though you are over it. The exception is worth money only when you are clearly inside it, and a position you would struggle to defend is not worth the four documents it saves.

Is a model API a service provider at this size?

On the text, yes, and firm size has nothing to do with it. 314.2 defines a service provider as "any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a financial institution that is subject to this part."

"Processes" is listed separately from "maintains", which disposes of the argument that a vendor retaining nothing is not a service provider. Taking data in, computing on it and returning a result is processing whether or not a copy survives.

Say plainly that this is a reading of the definition and not a ruling. We are not aware of an FTC action or court decision applying 314.2 to a model API. The cost asymmetry is what should decide it for a small firm: the cautious reading costs you a diligence file, and the convenient reading costs you a finding if a regulator disagrees.

Does the 30 day notification clock apply to small firms?

Yes. 314.4(j) requires notification to the FTC within 30 days of discovery where the event involves at least 500 consumers, and (j) is not in the 314.6 list.

Hold the two numbers next to each other, because they are not the same number. You can sit comfortably below 5,000 consumers for the exception and still blow through 500 consumers on a single incident. A firm that read 314.6 as a general exemption from the rule will discover the difference at the worst possible moment, with a 30 day clock that started at discovery rather than at the point the picture became clear.

Is 314.6 an exception to Section 7216 as well?

No. 314.6 is an exception inside the FTC Safeguards Rule and it has no effect on the tax disclosure rules, which come from a different statute and a different agency.

On that regime, correct a common error while you are here: 26 CFR 301.7216-3(a)(1) provides that a preparer "may disclose or use tax return information as the taxpayer directs as long as the preparer obtains a written consent from the taxpayer as provided in this section". Section 7216 is not a prohibition that cannot be consented away, and guidance telling you otherwise has misread the regulation. The form and timing requirements for that consent live in the regulation text, including the rule at (b)(1) that there is no retroactive consent, so read the section and have counsel check it against the current version rather than relying on a template. We go through 7216 and AI tools in more detail, including what is still open.

What to do if you are near the line

Four steps, in order.

  • Count consumers, not clients, and write down the method you used and the date. A documented count you can defend is the asset here, not the number itself.
  • If you are clearly under, record which four subsections you are relying on 314.6 for. Do not throw away the documents you already have.
  • If you are anywhere near, build the program as though you are over. The incremental cost is lower than the cost of being wrong.
  • Either way, do the change management procedure and the vendor inventory, because neither is exempted and both are what an AI deployment lands on first.

Where Gaper fits

Gaper builds and deploys custom AI agents for accounting firms into your own cloud environment, which keeps the data path inside infrastructure you already describe in your security program instead of adding a new third party to it. We work as an implementation partner rather than a software vendor, so you own the agents and the configuration outright. General enquiries go to hello@gaper.io.

What this means for your firm

Count your consumers before you buy anything, because the four documents 314.6 removes are the expensive ones and plenty of small firms pay for them without needing to. Do not read the exception as permission to skip encryption, vendor diligence or the 30 day notification clock, none of which it touches. If you are adding an AI tool, 314.4(g) and the change management procedure apply at your size, so the update is owed now rather than at some future threshold.

Book a free AI assessment

Thirty minutes, no commitment. We map one workflow, make the build or buy call, and scope the smallest thing worth shipping.

Frequently asked questions

What does 314.6 actually say?
It is one sentence. 16 CFR 314.6 reads, in full: "Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers."
Which four duties fall away?
The written risk assessment, the penetration testing and vulnerability assessment cadence, the written incident response plan, and the annual report. They are the four heaviest pieces of paperwork in 314.4, and every one of them is a document rather than a control.
What does the exception not remove?
Every control that touches the data. Encryption, multi factor authentication and the service provider duties all sit in 314.4 outside the four exempted subsections, so they apply to a two partner firm exactly as they apply to a national one.
Does the exception cover the duty to update your program?
No, and this is the one that catches firms adding AI tools. 314.4(g) requires the program to be adjusted for "any material changes to your operations or business arrangements", and (g) does not appear in the 314.6 list.
How do you count to five thousand?
The text counts consumers, not clients, not engagements and not staff. That distinction is where firms get the answer wrong in their own favor.
Is a model API a service provider at this size?
On the text, yes, and firm size has nothing to do with it. 314.2 defines a service provider as "any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a financial institution that is subject to this part."
MN
Written by

Mustafa Najoom

Marketing & GTM, Gaper

Mustafa is a CPA turned B2B marketer focused on go-to-market strategy, working on growth at Gaper, the AI-native partner that builds and deploys production AI agents.

Ready to turn AI into execution?

Book a free assessment of one workflow. We map it, make an honest build versus buy call before any code, and if an off the shelf product covers the job we will tell you so.