How ARMP's Hands-On Consulting Model Differs from Other Compliance Vendors
Key takeaways
- ARMP audits dealerships a minimum of four times a year, and up to six depending on operation size, employee count, and body shop presence.
- ARMP automates third-party vendor vetting by sending agreements to vendors and following up every 30 days until a response is received, to help meet FTC vendor vetting requirements.
- ARMP offers a North American exclusive hardware-based cybersecurity device that the speaker says cannot be hacked unless physically removed.
- Clients who sign with ARMP become named as additional insured on an E&O policy covering their contracted services.
- ARMP provides a dashboard with over a hundred online courses, phishing campaign tools, and stored manuals, tailored to each dealership.
Summary
Compliance vendors vary widely in what they actually deliver, and this video lays out what a full-service program should include: hands-on consulting with in-person audits (a minimum of four times a year, more for larger stores or those with a body shop), cyber security work ranging from pen testing and vulnerability scans to full remediation, and automated third-party service provider vetting that follows up every 30 days to help satisfy FTC due-diligence expectations around vendor oversight. It also covers a dashboard housing over a hundred online staff courses, including OFAC certification and Title VII harassment and discrimination training in English and Spanish, plus built-in phishing campaign tools with reporting.
For a dealership, the practical takeaway is that compliance, cyber security, and staff training don't have to be handled by separate vendors billed separately. Terry Dortch describes ARMP's approach as consultative rather than transactional, working directly with a dealership's management team to build a program suited to its size and risk profile, and notes that a proprietary hardware-based cyber security tool is offered on an exclusive basis in North America. He also points out that signing on activates an E&O policy naming the dealership as additional insured, and that the full package is offered at a flat monthly rate rather than per-service pricing common elsewhere in the industry.
Transcript
Introduction to ARMP's differentiators
Hi, I'm Terry Dortch, Automotive Risk Management Partners. I'm here today to talk to you about the differences between us and every other compliance company out there today. So as I go through this, I'm going to give you some bullet points on things that differentiate us.
Consulting approach and audit frequency
One of the biggest things is we truly are a consulting company. So we're going to come in and we're going to sit down with your dealership, and we're going to work with your management team in order to come up with the best practices for how to deal with the compliance issues that exist in the dealership today. So we're going to come in and we're going to audit you four times a year minimum, depending on the size of your operation, the number of employees, whether you have a body shop or not. It could be, we could be there six times a year. It depends, it depends on how everything kind of flows and how it all works its way through. But we're there to do all the auditing, we're going to do that. There's really nobody else out there is going to do it the way that we do, as far as coming in and having that personal attention to it.
Cybersecurity services and hardware device
The other thing is that we're going to handle all your cyber security piece. So your cyber security, we can do anything that you want, from simple pen testing, vulnerability scans, to a full-blown remediation program. The other thing too, you got to realize, is that we do have the North American exclusive rights to the cyber security piece here that will basically lock your system down from being hacked. There's no way it can be hacked. It's hardware, it's not software, so you can't hack this box. The only way to hack your system, if you were to do business with us and employ this in your system, would be to remove it. That's the only way you're going to hack it. We're the only ones with this, so this is something that really all of you need to take a look at. Nobody else is going to have that.
Automated third-party vendor vetting
The other thing that we're going to do, besides the cyber security piece of all of this, is we're going to handle all your third-party service providers. We automate that whole process for you, that process is automated, so that all you need to do is provide us with a list of your vendors, an email, a contact name, and an email address. We'll take it from there, and then what we do is we follow up, we send them out a third-party service provider agreement, and then they get it back to us. If they don't get it back to us, we're going to follow up with that every 30 days until we get some sort of response. And really what we're trying to do is just show that we're doing our due diligence and we're being proactive and trying to conform with the FTC rules that require vetting of your third-party vendors.
Online training courses and dashboard
So the other thing that we're going to do too is we're going to provide you with over a hundred different online courses for your staff. That could range anything from an OFAC certification course down to your title seven, you know, harassment discrimination courses, all of that, both in English and Spanish, in our dashboard. Those are all provided to you as well.
On top of all of that, we have a dashboard that basically is designed specifically for your dealership, so it's tailor made to each customer that we have. And when I say that, we have phishing campaigns proprietary to ours, we've developed it, it's our program. We're going to set it up, we're going to do the phishing for you through our dashboard. It'll have all the statistics there for you. In addition to that, that's where all your courses will reside, all your manuals will reside, basically everything in our dashboard. It's a very, very simple, easy to maneuver through process. It's a perfect animal for what you want to do as far as compliance.
E&O insurance and pricing
And to top it all off, on top of all of that, once you sign a contract with us, you then activate our E&O policy, where you become named as additional insured on an E&O policy to cover you against anything that you contract with us for. There's no other compliance company out there that does that. We do that, we're going to protect you.
And here's the best part, we're going to do all of it for $9.95 a month. You've got compliance companies out there charging you $800, $900 to run pen tests and vulnerability scans. Ours are unlimited. We can set it up to run a vulnerability scan on a monthly basis if you want. Our pen tests, we don't just run one a year, we can run two, three, four if we need to. We can do whatever we need to do, because again, we're hands-on. We're a compliance company, and because of that, we're actually going to work with your management team to design the best possible compliance program that works and fits within your environment. And we're going to do it at a reasonable cost, $9.95 a month, that's it.
So give us a call, number's on the screen, website's here, send us an email if you want, whatever you want to do. Thanks, talk to you later.
Questions this video answers
How often does ARMP audit our dealership for compliance?
ARMP audits your dealership a minimum of four times a year, though it could be up to six times a year depending on the size of your operation, the number of employees, and whether you have a body shop.
How does ARMP handle vetting our third-party vendors?
ARMP automates the process. You provide a vendor list with contact names and emails, and they send out a third-party service provider agreement, following up every 30 days until they get a response, to help conform with FTC rules requiring vendor vetting.
What does ARMP's cybersecurity service include?
ARMP handles the full cybersecurity piece, from simple pen testing and vulnerability scans to full remediation programs, and offers a North American exclusive hardware device that locks your system down so it cannot be hacked unless physically removed.
Are we covered by insurance if something goes wrong with ARMP's compliance program?
Once you sign a contract with ARMP, you become named as an additional insured on their E&O policy, covering you against anything you contract with them for, which the speaker says no other compliance company offers.
Read more on this
-
FTC Safeguards Rule Compliance for Car Dealerships
Car dealerships that arrange financing or leases are "financial institutions" under the Gramm-Leach-Bliley Act, so the FTC Safeguards Rule (16 CFR Part 314) app...
-
How to Choose a Dealership Compliance Vendor
Choose a dealership compliance vendor by testing four things: whether their own auditors come on site or the assessment is a questionnaire, which of the nine FT...
Covered in this video
- FTC third-party vendor vetting requirements
- penetration testing and vulnerability scans
- E&O insurance coverage
- compliance dashboard and online training courses