GLBA Compliance Risk Assessment Questionnaire Form
Evaluate your institution’s privacy, security, and information handling controls for GLBA compliance.
How effective are your current privacy and security policies in protecting customer information?
*
Very Effective
Effective
Somewhat Effective
Needs Improvement
Not Effective
Please rate your institution’s procedures for handling customer information across the following areas.
*
Rows
Strong
Adequate
Needs Improvement
Not Implemented
Data Collection
1
2
3
4
Data Storage
5
6
7
8
Data Sharing
9
10
11
12
Data Disposal
13
14
15
16
How frequently does your institution review and update its privacy and security policies?
*
Annually
Every 2-3 Years
As Needed
Rarely
How would you rate your vendor management and oversight practices?
*
1
2
3
4
5
To what extent are third-party vendors required to comply with your privacy and security standards?
*
Fully Required
Partially Required
Not Required
Not Sure
How prepared is your institution to respond to a data breach or security incident?
*
Fully Prepared
Somewhat Prepared
Needs Improvement
Not Prepared
Please indicate the level of access controls in place for sensitive customer data.
*
Role-based and regularly reviewed
Role-based, not regularly reviewed
Limited controls
No controls
How are data retention and secure disposal policies implemented in your institution?
*
Strictly enforced and monitored
Implemented, but not monitored
Informal or ad-hoc
No formal policies
Please rate the effectiveness of employee training on privacy and security awareness.
*
1
2
3
4
5
Overall, how would you assess your institution’s current GLBA compliance risk?
*
Low Risk
1
2
3
4
High Risk
5
1 is Low Risk, 5 is High Risk
Submit Assessment
Should be Empty: