Automotive Risk Management

Automotive risk management is the practice of identifying, measuring and reducing the risks a dealership carries across four areas at once: customer data under the FTC Safeguards Rule, workplace safety under OSHA, environmental handling under EPA rules, and consumer finance in the F&I office. Compliance covers the part of that a regulation happens to name.

By Terry Dortch President, Automotive Risk Management Partners Last reviewed

What is automotive risk management?

Automotive risk management is the work of finding out what could cost a dealership money, deciding which of those things to act on, and keeping a record that the decision was made. Some of that work is required by regulation. A lot of it is not.

The regulated part is easier to describe because somebody else has written it down. A franchised or independent dealership that arranges financing is a "financial institution" under the Gramm-Leach-Bliley Act, which brings it under the FTC Safeguards Rule. It runs a workplace, which brings it under OSHA. It handles waste oil, refrigerant and paint, which brings it under EPA rules. It writes consumer credit contracts, which brings the F&I office under the federal lending statutes.

The unregulated part is where dealerships are usually least prepared, because nothing forces the conversation. No rule requires a store to know how long it could keep selling with the DMS offline, or what happens when the one person who understands the deal jacket process leaves.

What risks does a dealership actually carry?

Written out, the list is longer than most stores expect.

CategoryWhat it looks like at a storeRegulated?
Customer informationCredit applications, driver licence scans and deal jackets held in a DMS, a scan-to-folder share, and a filing cabinet. Exposure runs from ransomware to an unattended desk.16 CFR 314
Workplace safetyLifts, compressed air, solvents, paint booths, blocked exits, lockout/tagout on service equipment, and the injury log.29 CFR 1910, 1904
EnvironmentalUsed oil and antifreeze storage, hazardous waste determination, body shop coating rules, refrigerant handling, and stormwater where it applies.EPA, varies by state
Consumer financeDisclosure accuracy, adverse action notices, credit report handling and Red Flags, lease disclosure, OFAC screening, and cash reporting on Form 8300.TILA, ECOA, FCRA, Reg M
EmploymentTraining assignment and expiry by role, harassment training where the state requires it, and classification of pay plans.Varies by state
Business continuityHow long the store can sell, service and deliver with the DMS, the phones or the building unavailable.No
ReputationWhat a breach notification, a citation or a lawsuit does to a store whose market is measured in a handful of zip codes.No
Key personKnowledge held by one controller, one fixed ops director or one F&I manager and written down nowhere.No

The bottom three rows are the ones that get skipped. They have no citation, no inspector and no deadline, which is exactly why they survive every compliance review a store passes.

How is risk management different from compliance?

Compliance answers a question somebody else asked. Risk management asks the question.

A compliance program takes a published standard and demonstrates that the store meets it. That is valuable and frequently mandatory, and it has a defined edge: the standard stops where its author stopped. The FTC wrote a rule about customer information, so the Safeguards Rule says nothing about whether the store can trade with its DMS down. OSHA wrote rules about worker safety, so they say nothing about the controller who has never taken two consecutive weeks off.

Risk management starts from what the dealership has to lose and works back. In practice that means the regulated obligations are a floor rather than a program. A store that treats the two as identical has outsourced its risk appetite to whichever agency last published a rule.

This distinction has a buying consequence. Most products sold to dealerships are compliance products: they track the named obligations and report against them. They are worth having. They will not tell a general manager that the store has one paint booth, one painter, and no plan.

What does an automotive risk assessment involve?

The Safeguards Rule makes a written risk assessment mandatory. 16 CFR 314.4(b) requires the dealership to identify reasonably foreseeable internal and external threats to customer information, to set criteria for evaluating those threats, and to write down how it will address them. A verbal understanding does not satisfy it.

An assessment worth the time it takes covers more than the rule requires:

  • The building. Exit routes, eyewash and shower testing, secondary containment, chemical labelling, lift inspection records, electrical panel access, and where deal jackets physically sit overnight.
  • The network. What is exposed to the internet, who has administrative access, whether multi-factor authentication is actually enforced rather than available, and what the monitoring would catch.
  • The deal files. A sample pulled and checked against disclosure, adverse action, and Red Flags requirements, which is what an F&I audit does.
  • The back lot and body shop. Waste determination, accumulation start dates, used oil labelling, and the coating rules covered in the EPA guide.
  • The people. Which roles require which training, when each expires, and who is currently out of date.
  • The vendors. Every third party holding dealership or customer data, and whether each one can produce a security attestation.

The output is a list of findings, each with a named owner and a date. A number on its own tells the general manager that something is wrong without telling them what to do on Monday.

Who is accountable for it?

The Safeguards Rule settles part of this by requiring a single named Qualified Individual responsible for the information security program, reporting to the board or ownership at least annually under 16 CFR 314.4(i). Responsibility for everything else is set by custom rather than by rule, and usually lands like this: OSHA and EPA with fixed operations, F&I with the finance director, employment with the controller or an outside HR firm.

That division is workable. The failure mode is that those four people report separately, so nobody is holding the whole picture, and a risk that sits between two of them belongs to neither. The service drive camera that also covers the F&I desk is a safety fixture to one of them and a customer information problem to the other.

A dealership group adds a second problem on top. Each rooftop can be individually diligent while ownership has no way to compare them, which is the subject of the group compliance guide.

What does risk management software actually do?

It keeps the evidence. Every obligation a dealership carries is eventually examined by somebody who was not there: a lender asking for an attestation, a manufacturer running a franchise review, an insurer at renewal, an inspector, or an attorney after an incident. All of them ask a version of the same question, which is show me the record.

So the useful test of any feature is what it leaves behind. Training reported as "94% complete" is a status. A dated per-employee record showing course, score, completion and expiry is evidence. A dashboard that is green today is a status. An archived report history showing what the network looked like each month for two years is evidence.

What software cannot do is walk the building. The findings that generate citations are physical and nobody self-reports them, because no general manager answers "no" when asked whether exit routes are clear. The blocked exit is behind the tyre rack and it is found by walking to it. A questionnaire measures what a store believes about itself, which is worth knowing and is a different thing from its actual condition. Comparing platforms on this point matters more than comparing feature lists.

How often should a dealership reassess?

Parts of the cadence are set for you. The Safeguards Rule requires either continuous monitoring or annual penetration testing with vulnerability assessments every six months, and an annual written report to ownership. OSHA injury records run continuously, with the summary posted from February to April. Training expires on its own schedule by role and by state.

Outside those fixed points, reassess when something material changes rather than on the anniversary. A new DMS changes where customer information lives. An acquired rooftop arrives with somebody else's history. A change of Qualified Individual moves accountability. A breach or an inspection has already told you the assessment was wrong.

Where does this usually go wrong?

Four patterns account for most of it.

  • The green dashboard nobody earned. A store self-assesses, answers from memory on a busy day, and gets a score that reflects its beliefs rather than its building.
  • Four programs that never meet. Safeguards, OSHA, EPA and F&I each managed competently in isolation, with no one holding the combined view and no shared record.
  • Documents that exist but cannot be produced. The information security program written once, saved somewhere, and not exportable on the day a lender asks for it.
  • Unregulated risk left unexamined. Continuity, reputation and key person exposure carry no citation, so they never reach an agenda.

The common thread is that each one survives a compliance review. That is what separates automotive risk management from compliance: the review was never the point, and passing it was never the same as being safe.

Frequently asked questions

What is automotive risk management?

It is the practice of finding, measuring and reducing the exposures a dealership carries as a business. Four of those exposures are regulated: customer information under the FTC Safeguards Rule, workplace safety under OSHA, waste and emissions under EPA rules, and consumer finance in the F&I office. Others are not regulated at all, including business interruption, reputational damage after a breach, and dependence on one person who holds knowledge nobody else has.

Is automotive risk management the same as compliance?

Compliance is a subset of it. Compliance asks whether the store meets a standard somebody else wrote. Risk management asks what could cost the dealership money and what to do about it, which includes everything the regulations cover and a good deal they do not. A store can be compliant with every rule that applies and still be carrying an uninsured single point of failure.

What should an automotive risk assessment cover?

A written assessment under 16 CFR 314.4(b) has to identify threats to customer information and set criteria for evaluating them. A useful one goes further: the physical condition of the shop, the state of the network and who can reach it, deal file accuracy in F&I, waste handling and storage in the body shop, training currency by role, and the vendors holding dealership or customer data. The output is a list of findings with owners and dates, not a score.

Who is responsible for risk management at a dealership?

The Safeguards Rule requires one named Qualified Individual accountable for the information security program, and that person reports to ownership at least annually under 16 CFR 314.4(i). OSHA and EPA obligations usually sit with a fixed operations or service director. F&I sits with the finance director. The common failure is that these four people never compare notes, so nobody holds the whole picture.

How often should a dealership reassess its risk?

The Safeguards Rule requires continuous monitoring, or annual penetration testing with vulnerability assessments every six months. OSHA injury records are maintained continuously and posted each February. Beyond the required cadence, reassess whenever something material changes: a new DMS, a new rooftop, a change of Qualified Individual, a breach, or an inspection.

What does automotive risk management software do?

It holds findings, remediation, training records, vendor attestations and monitoring results in one place so the evidence exists when somebody asks for it. What it cannot do is see the shop floor. Blocked exits, unlabelled containers, an open deal jacket and an unsecured server closet are physical findings, so software that only collects self-reported answers records what staff believe rather than what is there.