What Dealership Compliance Vendors Often Leave Out of Their Coverage

Terry Dortch President, Automotive Risk Management Partners

Key takeaways

  • Some compliance vendors only provide pieces of a larger compliance puzzle, such as a pen test and vulnerability scan, and call that cyber security.
  • The FTC Safeguards Rule requires more than a pen test and vulnerability scan; it also requires taking precautions and measures to protect data.
  • Auditing a dealership only once a year is not sufficient given the fluid, transient nature of dealership operations and personnel.
  • Many compliance vendor contracts include a hold harmless clause stating the vendor is not responsible if something goes wrong.
  • Automotive Risk Management Partners does not use a hold harmless clause, carries an E&O policy that names dealers as additional insured, and will pay the deductible on that policy if needed.

Summary

Many compliance vendors in the auto industry oversell narrow services as complete protection. Some claim a pen test and vulnerability scan satisfy cyber security obligations, or that a once-a-year compliance audit is sufficient. Given how frequently dealership staff, processes, and risks change, an annual audit alone cannot keep pace. The FTC Safeguards Rule does require testing like pen tests and vulnerability scans, but it also requires ongoing measures to safeguard data, meaning a scan-and-done approach leaves real gaps. Worse, many of these vendor contracts include hold-harmless clauses that shift liability back onto the dealer if something goes wrong.

For a dealership principal, GM, or F&I director, the practical takeaway is to scrutinize what a compliance vendor actually delivers versus what they claim. Terry Dortch notes that Automotive Risk Management Partners does not use a hold-harmless clause; instead it carries an E&O policy that names dealers as additional insured, removing the need to pursue separate legal action, and the company covers the deductible if a claim arises. Dealers should look past buzzwords like "cyber security" and confirm their provider offers continuous monitoring and will stand behind its work, rather than paying for partial protection with no accountability.

Transcript

Fake news about compliance vendor coverage

Hello, my name's Terry Dortch. I'm with Automotive Risk Management Partners. I'm here today to talk to you about fake news. Yep, fake news. A lot of you have been fed fake news by the compliance companies out there in the auto industry, okay? A lot of these companies are professing to provide you with security, they're professing to be the company to solve your compliance needs. Really what they're doing is they're giving you pieces and parts of an overly large puzzle.

Piecemeal cyber security and infrequent audits

And what I say about that is, you know, you've got one company out here that's probably going to try to provide you, or they'll tell you they're providing you, with your cyber security. And that cyber security, in your mind or in theirs, is being fed to you and said as long as you have a pen test and a vulnerability scan, you're good to go. Well, you know what, there's a whole lot more to cyber security than that. And other companies are going to be talking to you and they're going to tell you that it's okay to do an audit of your dealership once a year. It can't be, with the fluid nature of our business and the way that people move and go and the transient behaviors that occur, there's no way in the world that auditing once a year is going to be able to solve your compliance needs.

Vendor hold harmless clauses leave dealers exposed

What a lot of these companies are doing is they're coming out and they're professing to provide you with a solution where you feel protected, and in reality they're not, they're not protecting you. They're giving you little bits and pieces of an overall puzzle, and what they're doing is they're providing you with half of the solution, or even less, of the solution that's needed in order to solve your compliance needs. And what's worse is all of these companies, all of them, have some sort of a hold harmless in their contract that basically says, you know what, if something happens, we're not responsible.

ARMP's E&O policy and deductible protection

The bottom line here is that you need a compliance company that's going to stand behind you. You need a compliance company that's there to protect the dealer and then isn't afraid to walk away, or to be able to provide their dealers with sufficient protection. So at Automotive Risk Management Partners, we don't have a hold harmless. As a matter of fact, we take it a step further, we carry an E&O policy that our dealers can be named as additional insured on, which protects them. Why is that important? For a lot of reasons. You know, a lot of legal minds out there would say, well, we don't really need that because we could just sue you as the compliance company if there was any kind of infraction or any kind of action brought against the dealership. Well, if you're named as a named insured on our policy, you don't have to go through that because you're already going to be protected. So that eliminates that step, or that legal maneuvering that has to occur. In addition to that, we take it even another step further, and we're going to pay the deductible for you, for that insurance policy, if it ever gets to that point.

What the FTC Safeguards Rule actually requires

The bottom line here is you need a compliance company that's willing to stand up and say, you know what, our program and our solutions are correct, they're fluid, they're enough to be able to protect our dealers, and if they don't, we're going to tell you that we're going to stand behind them. That's the compliance company that you need. Be careful about listening to all the various nuances, or the latest greatest new keyword, buzzword, that they throw out there. You know, everybody talks cyber security, cyber security. It's a pretty in-depth animal, it's not something you can solve by running a pen test and some vulnerability scans. Does the FTC Safeguards Rule require that? Absolutely. But it also goes a step further and states that you have to take precautions and measures to protect that data.

Choosing a compliance company that stands behind you

So the bottom line here is what I'm trying to tell you is make sure that when you're talking to your compliance company that they're actually providing you a service that's worthwhile. Why would you pay $800 a month for something that gives half the solution? Trust me, give us a call, we'll solve your problems and we'll do it for less money. So the bottom line here is, if you really want a good compliance company, someone that's going to have your back, and someone that's going to do more than a single audit every year, then you need to give us a call. Numbers on the screen, website's here. Thanks, take care.

Questions this video answers

Is a pen test and vulnerability scan enough to satisfy the FTC Safeguards Rule?

No. The FTC Safeguards Rule does require a pen test and vulnerability scan, but it also requires taking additional precautions and measures to protect data, so relying on just those two items provides only part of the needed solution.

Why is it a problem that compliance vendors only audit once a year?

Because dealership operations are fluid, with people and processes constantly moving and changing, auditing only once a year cannot adequately address a dealership's ongoing compliance needs.

What happens if something goes wrong under a typical compliance vendor's contract?

Most compliance companies include a hold harmless clause in their contracts stating they are not responsible if something happens, leaving the dealership exposed rather than protected.

How does Automotive Risk Management Partners handle liability differently from other vendors?

ARMP does not use a hold harmless clause. Instead it carries an E&O policy that names dealers as additional insured, which protects them without needing to sue ARMP, and ARMP will also pay the insurance deductible if it is ever needed.

Covered in this video

  • FTC Safeguards Rule
  • cyber security vendor practices
  • hold harmless clauses
  • E&O insurance for dealerships
  • compliance vendor auditing frequency