Why Physical Compliance Audits Matter as Much as Cybersecurity

Terry Dortch President, Automotive Risk Management Partners

Key takeaways

  • The FTC Safeguards Rule has required safeguarding of customer information since 2003 as part of the Gramm-Leach-Bliley Act, with a newer amendment adding clarity specifically to the cybersecurity requirements.
  • Physical compliance risks in sales, F&I, and body shop processes occur daily and can cause real financial harm, yet dealers are largely ignoring them while focused on cyber security.
  • A dealership can face FTC scrutiny and disparate impact issues even without intentional wrongdoing, simply from ongoing errors in daily processes.
  • Dealers can be caught and penalized by state attorneys general, state banking associations, or the FTC for physical compliance failures, not just cyber breaches.
  • Dealerships should ensure vendors address all compliance issues comprehensively rather than focusing narrowly on one area like cyber security while neglecting others.

Summary

Dealership compliance is often reduced to whatever regulation is making headlines, and right now that means the cyber security amendment to the FTC's Safeguards Rule, in place since 2003 under the Gramm-Leach-Bliley Act, with the updated compliance deadline in June. That amendment brought welcome clarity to the cyber requirements, but it has pulled attention away from the physical, day-to-day compliance risks that actually generate the most trouble for dealers: errors in the sales process, F&I, OSHA issues in the shop or body shop, and patterns that can look like disparate impact even when unintentional.

Overreliance on cyber readiness while ignoring these physical processes leaves stores exposed to state attorneys general, state banking associations, and the FTC, agencies that pursue exactly these kinds of everyday operational failures. Regular, independent audits of sales, F&I, and service processes matter as much as any cyber safeguard. Dealers should press any compliance vendor, ARMP included, to confirm they are covering the full range of physical and cyber risk rather than addressing one issue while leaving other gaps unaddressed, which only creates a false sense of security.

Transcript

Dealers focused on cyber security amendment

Hello, my name is Terry Dortch with Automotive Risk Management Partners. I'm here today to talk to you a little bit about priorities. You know, last week I ran, uh, I ran down in the southern states, down in Louisiana, Alabama, Georgia. This week I was running around northern Illinois talking to dealers, and everybody's hot point or hot button right now is the whole cyber security part of the Safeguards Rule.

History of the Safeguards Rule and cyber clarity

One of the things that I really want to talk about is that, you know, the Safeguards Rule's been around since 2003. It started, it came out as a whole piece of the Gramm-Leach-Bliley Act, and everything was about safeguarding customer information. There's been a cyber piece in that forever. There was not as much clarity, obviously, as there is with this amendment that's coming out that's due in June. So this amendment, what it's done is it's added clarity to the whole cyber aspect of the Safeguards Rule.

Physical compliance risks being overlooked

You know, we shouldn't ignore that cyber piece at all. We need to pay attention to it, but I think, I think we're missing the boat here. We're not paying attention, and the more I talk to dealers, it's we're completely ignoring the physical aspects of the compliance piece. There's so many other things that could happen in a dealership that can cause you problems financially, cost you money, you know, real money, as well as indirectly affecting the revenue streams of your businesses. And those things mostly are physical. They're not going to be the cyber part of it, or the whole data being stolen from your DMS system, let's say.

The real problem that you're going to find is you're going to find in the physical aspects, that it's going to be errors made either in your sales process, your F&I process, which is part of your sales process obviously, in the back in the shop, the OSHA, if you have a body shop, something in the body shop. Those are the things that are ongoing daily, and those are the things that we're not paying attention to now because all of the attention is being poignant, or focused, on that cyber aspect. You really need to step back a minute and take a look at the overall picture of everything.

Real-world case of FTC scrutiny in Illinois

This whole, and the reason I bring this up, we have a store here in Illinois, in the northern part of Illinois, that the FTC's in their store right now. There's going to be some issues, there's going to be some complications for that dealer, and I feel bad for them. They probably really didn't do anything wrong, but they're going to get in trouble for it because it's almost inevitable as a dealership to not have some sort of disparate impact occurring, or it appeared to be occurring.

Need to audit all compliance areas, not just cyber

And my whole point in all of this is, if you're not having someone come in and audit these processes on a daily basis, that to me is as much, if not more, important right now than the cyber aspect. And I can't stress this enough, I'm not telling you to ignore the cyber part of it. That's an issue that needs to be addressed, just like all of it. But don't focus all of your attention over here and forget about here, which really is the point that we need to focus on.

This is over here's where we're going to get caught by a state AG, we're going to get caught by a state banking association, we're going to get caught by the FTC. There's so many different aspects that control the physical part of your dealership and that are involved in it. That's the part that we need to address as much as the cyber aspects, and it's just because this is the hot button right now. And I get it, and trust me, we can handle all of it for you, but I really think, whether it's us or anybody else that you're talking to out there, make sure that they're not just taking care and plugging one hole in a dike that has a bunch of them, right? We want to make sure that we plug all the holes that we can out there.

Past heavy fines and advice on vendor selection

You know, again, back in Illinois, two, three years ago, we had a major automotive group here that got fined heavy, heavy. I want to say it was to the tune of somewhere around 10 million dollars. You can fact check me on it, I don't remember exactly what it was, but it was large money. My point in all of this is that there's a lot to compliance. Please take the time, talk to your vendors, whoever you're talking to, and make sure that they're addressing all of these issues and not little bits and pieces of it, and then giving you a false sense of security in the process.

If you guys have any questions about this, you want to discuss it, please feel free to give me a call anytime. You want numbers, here on the screen, our website's out there. You can go to the website, you can contact us via email, however you'd like to. Thanks a lot, talk to you later.

Questions this video answers

Should our dealership focus mainly on cyber security compliance right now?

No, while cyber security under the Safeguards Rule amendment is important, dealers are ignoring physical compliance risks in sales, F&I, and body shop processes that occur daily and can cause real financial harm and regulatory trouble.

What kind of compliance issues can get a dealership in trouble besides data breaches?

Errors in the sales process, F&I process, and body shop operations (including OSHA issues) are ongoing daily risks. These physical compliance failures can lead to action from a state AG, state banking association, or the FTC.

How do we know if our compliance vendor is covering everything we need?

Make sure your vendor is auditing all compliance processes daily rather than just plugging one hole, such as cyber security, while leaving other physical compliance gaps unaddressed and giving you a false sense of security.

Can a dealership get in trouble with the FTC even if it did not intentionally do anything wrong?

Yes, it is almost inevitable for a dealership to have some disparate impact occur or appear to occur in its processes, which can lead to FTC involvement even when the dealer did not intentionally violate any rule.

Covered in this video

  • FTC Safeguards Rule
  • Gramm-Leach-Bliley Act
  • OSHA
  • disparate impact
  • vendor due diligence