How to Choose a Dealership Compliance Vendor

Choose a dealership compliance vendor by testing four things: whether their own auditors come on site or the assessment is a questionnaire, which of the nine FTC Safeguards Rule elements they produce evidence for, whether their cybersecurity satisfies 16 CFR 314.4(d) through continuous monitoring, and whether you can export your audit and training history if you leave.

By Terry Dortch President, Automotive Risk Management Partners Last reviewed

What actually differentiates vendors in this market?

Nearly every dealership compliance vendor will show a dashboard, a course library, and a document repository. Those are table stakes and comparing them is mostly comparing screenshots. Four things genuinely differ between providers, and all four are answerable in a first call.

  1. Does anyone come to the store? Assessment-led providers send auditors. Software-led providers send a questionnaire. This determines whether your compliance record reflects reality.
  2. How much of the Safeguards Rule do they evidence? Many platforms cover training well and leave the other eight elements of 16 CFR 314.4 to the dealership.
  3. Do they satisfy 314.4(d)? Continuous monitoring or scheduled penetration testing — and if neither, you still owe it.
  4. Can you leave? Data portability determines whether year three is a renewal decision or a hostage negotiation.

How do you test coverage against the Safeguards Rule?

Take the nine elements and ask the vendor, element by element, whether they produce the evidence or assume you have it. The answers separate providers quickly.

ElementQuestion to ask
314.4(a) Qualified IndividualCan you serve as or support the Qualified Individual, and what does the overseeing employee still owe?
314.4(b) Risk assessmentDo you write the risk assessment, and is it store-specific or generic?
314.4(c) SafeguardsWhich of the eight controls do you assess, and which do you assume our IT provider handles?
314.4(d) TestingDoes your offering satisfy this through continuous monitoring, or do we still owe an annual penetration test?
314.4(e) TrainingIs training assigned by role, and do you track expiry as well as completion?
314.4(f) Service providersDo you collect vendor attestations, and what happens when a vendor ignores the request?
314.4(g) Evaluate and adjustHow is the program updated when our operations change?
314.4(h) Incident responseDo you supply a written plan specific to us, or a template?
314.4(i) Annual reportDo you produce the annual written report, and from what data?

A vendor answering "you would handle that" to five or more of these is a training platform. That may be all you need, but price it against what filling the other gaps costs.

What should you ask for before signing?

  • A redacted sample report from a real dealership, not a marketing mock-up. Findings volume and specificity tell you what the assessment is worth.
  • References at your size and structure. A single-rooftop reference tells a seven-store group nothing about group reporting.
  • The auditor's background. Who performs the on-site work, are they employed by the vendor or subcontracted, and what is their experience in retail automotive.
  • The remediation workflow. What happens between a finding and its closure, and who chases it.
  • Written confirmation of the 314.4(d) path. Get it in the contract, not in an email.
  • Export terms. Format, scope, and timeframe.

What are the warning signs?

  • A score that starts green. A real first assessment finds problems. A platform that shows a healthy score before anyone has visited is measuring form completion.
  • Compliance guaranteed. No vendor can guarantee this, and the contract will say so in the limitation of liability clause even where the sales deck does not.
  • Templates described as programs. A blank information security program template is not an information security program.
  • Training-only coverage sold as full compliance. Common, and the gap only appears when someone asks for the risk assessment.
  • No on-site component at any price. Physical findings are a real category of Safeguards and OSHA violation and cannot be found remotely.
  • Unclear data ownership. If the contract is silent on export, assume the answer is no.

How should the decision be scored?

Weight the criteria before seeing demos, because demos reward presentation. A workable weighting for most dealerships:

  • Regulatory coverage — highest weight. Gaps here become your liability.
  • Assessment quality — high. Determines whether the record is credible.
  • Remediation workflow — high. Findings without closure change nothing.
  • Reporting fit — medium to high for groups, lower for single stores.
  • Training library — medium. Widely available and rarely the differentiator.
  • Interface — low. The people using it daily are a small number of managers.

Where ARMP sits

ARMP is a single-vendor, assessment-led program: employed auditors perform the initial on-site compliance assessment and return through the year, findings are scored against defined violation libraries for OSHA, GLBA, and body shop, and remediation is tracked with escalation on overdue items. The written programs — information security program, OSHA manual, compliance management system, Red Flags — are generated and maintained rather than supplied as templates. The 314.4(d) requirement is met through continuous monitoring via the Ridgeback appliance rather than scheduled penetration testing.

That combination suits a dealership that wants one accountable party. A store with an established internal compliance officer and a strong existing IT provider may reasonably prefer to assemble specialists instead.

Related guides

Frequently asked questions

Single vendor or several specialists?

Both work; they fail differently. Several specialists usually give deeper coverage in each area and leave the dealership to reconcile findings, chase four renewal dates, and answer to four support desks. A single vendor gives one record and one accountable party, at the cost of accepting that one component may be less specialised than a best-of-breed alternative. The deciding question is normally whether the store has anyone whose actual job is coordinating compliance. If not, the reconciliation work does not happen and the single-vendor route wins by default.

How do I tell a real assessment from a questionnaire?

Ask who fills it in. If the answer is the general manager or the office manager, it is a questionnaire regardless of what it is called, and the resulting score reflects what staff believe rather than what is true. A real assessment has a named auditor on site, produces photographic evidence of findings, and generates items the store did not already know about. Ask to see a redacted example report before signing.

What contract terms matter most?

Data portability first: can you export audit history, training records, and certificates in a usable format if you leave, and how long do they keep your data afterwards. Then the on-site commitment, stated as a number of visits per year rather than as available on request. Then what happens when the vendor misses something, which is normally a limitation-of-liability clause worth reading closely. And the renewal and price escalation terms, since multi-year auto-renewal is common in this market.

How long does implementation take?

The initial assessment itself typically runs one to two days on site depending on store size. What follows takes longer: remediating findings, collecting vendor attestations, and getting training completed across departments. A realistic expectation for a single rooftop is a quarter to reach a stable state, not a week. Any vendor promising same-week compliance is selling a dashboard, not a program.

Should the same vendor handle compliance and cybersecurity?

There is a real argument for it under the Safeguards Rule, because 16 CFR 314.4(d) makes testing and monitoring a compliance requirement rather than a separate IT concern. When they are split, the compliance vendor cannot evidence the monitoring element and the IT vendor is not tracking it as a regulatory obligation, so it falls between them. If you do split them, make explicit in writing which party owns 314.4(d) evidence.