← GLBA · Safeguards Rule (16 CFR 314)

314.4(i) — Annual written report to the board

high board-oversightpolicy-governance

Requirement

The Qualified Individual reports in writing, regularly and at least annually, to the board of directors or equivalent governing body — or to a senior officer if there is no board — on the overall status of the program and compliance with the Safeguards Rule, and on material matters such as risk assessment, risk management decisions, service provider arrangements, testing results, security events and recommended changes.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
boardboard of directorsgoverning bodysenior officersenior leadershipexecutive team
Required element 2 — any one of
reportreportsreportedreporting
Required element 3 — any one of
annual…at least annuallyin writingwrittenyearlyquarterly
Supporting terms — specificity signals
314.4(i)qualified individualstatus of the program

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
SOC 2 CC1.2 Board independence and oversight board-oversight policy-governance
NIST CSF 2.0 GV.RM-05 Communication of cybersecurity risk policy-governance board-oversight
GDPR Art.5(2) Accountability policy-governance
GDPR Art.24 Responsibility of the controller policy-governance
GDPR Art.31 Cooperation with the supervisory authority policy-governance
SOC 2 CC1.1 Commitment to integrity and ethical values policy-governance
SOC 2 CC1.3 Organisational structure and reporting lines policy-governance
SOC 2 CC2.2 Internal communication of responsibilities policy-governance