§ Free resources·finserv compliance library

Financial Services Compliance Resource Library

GLBA, NYDFS Part 500, CCPA/CPRA, and NIST framework tools for banks, credit unions, insurance companies, broker-dealers, RIAs, and fintechs. Free downloads. No paywalls. Built by senior practitioners for the compliance and security officers who have to implement these frameworks under audit pressure.

Find the right resource for your entity type below. Every download goes directly to your work email.

§ Master framework maps·cross-framework control mapping

Master Framework Maps

Cross-framework control matrices that let you map GLBA, NIST, NYDFS, and CCPA obligations simultaneously. Start here if you answer to multiple frameworks.

14 pages For: All financial institution CISOs, CROs, CCOs

GLBA × NIST CSF 2.0 × NYDFS Part 500 × CCPA Master Control Matrix

A single cross-framework control matrix that maps GLBA Safeguards Rule, NIST CSF 2.0, NYDFS Part 500, and CCPA/CPRA requirements side by side — document once, satisfy four frameworks.

✓ Check your email for the download link.

Something went wrong. Please try again.

10 pages For: CROs, AI Governance Leads, Model Risk Officers

NIST AI RMF 1.0 × Financial Services Implementation Guide

Maps the NIST AI Risk Management Framework Govern/Map/Measure/Manage functions directly onto financial services model risk and AI governance obligations — practical, examiner-facing guidance.

✓ Check your email for the download link.

Something went wrong. Please try again.

§ By entity type·tailored to your charter and obligations

By Entity Type

Each financial institution type carries different charter obligations and regulatory expectations. Download the workbook built for your entity class.

10 pages For: Bank CISOs, BSA Officers, IT Directors

Banks & Credit Unions: GLBA ISP Template

A complete Information Security Program template for FDIC- and NCUA-supervised institutions, aligned to the GLBA Safeguards Rule final rule requirements for written ISPs.

✓ Check your email for the download link.

Something went wrong. Please try again.

9 pages For: Insurance CISOs, CCOs, Chief Actuaries

Insurance: GLBA + NYDFS Part 500 Compliance Guide

A compliance guide for insurance carriers and agencies navigating both the GLBA Safeguards Rule and NYDFS Part 500 cybersecurity regulation — including the overlap and the gaps between them.

✓ Check your email for the download link.

Something went wrong. Please try again.

9 pages For: BD CCOs, FINRA Principals, Legal Counsel

Broker-Dealers: GLBA + Reg S-P (2024) + FINRA Workbook

A compliance workbook covering the GLBA Safeguards Rule, the 2024 SEC Reg S-P amendments, and FINRA cybersecurity expectations for broker-dealer customer data protection programs.

✓ Check your email for the download link.

Something went wrong. Please try again.

10 pages For: RIA CCOs, Principals, Founder-CCOs

Investment Advisers: GLBA + Reg S-P + AI Exam Guide

A combined compliance guide for investment advisers covering GLBA obligations, the 2024 Reg S-P cybersecurity amendments, and SEC exam expectations for AI systems used in advisory functions.

✓ Check your email for the download link.

Something went wrong. Please try again.

9 pages For: Fintech CTOs, VP Compliance, General Counsel

Fintechs & Non-Bank FIs: GLBA Program Workbook

A GLBA compliance workbook for non-bank financial institutions and fintechs — covering which entities are covered, what a compliant ISP requires, and how to satisfy the Safeguards Rule without a legacy bank compliance team.

✓ Check your email for the download link.

Something went wrong. Please try again.

§ By entity type·senior-led AI governance engagements

AI governance service pages, by entity

The workbooks above are self-serve. When you are ready for a senior-led engagement, each financial-institution type has a dedicated AI governance page mapped to the regulators that examine it.

§ NYDFS deep dives·Part 500 and Part 23 compliance tools

NYDFS Deep Dives

New York Department of Financial Services Part 500 and Part 23 (BitLicense) compliance workbooks for NY-licensed entities navigating the most demanding state cybersecurity regime in the US.

13 pages For: NY-licensed entity CISOs, DFS Compliance Officers

NYDFS Part 500 Full Gap Assessment Workbook

The most complete Part 500 compliance workbook available: a section-by-section gap assessment covering all 23 NYCRR Part 500 requirements, mapped to evidence expectations for DFS examiners.

✓ Check your email for the download link.

Something went wrong. Please try again.

6 pages For: CISOs, CEOs signing the cert, Board Audit Committee

NYDFS Part 500 CISO Annual Report & Certification Template

A ready-to-use template for the NYDFS-required CISO annual report and board certification under 23 NYCRR Part 500.17 — covering the required attestation language and the supporting evidence structure.

✓ Check your email for the download link.

Something went wrong. Please try again.

7 pages For: Crypto Compliance Officers, BitLicense holders

NYDFS Part 23 (BitLicense) + Crypto Cybersecurity Workbook

A cybersecurity compliance workbook for BitLicense holders and virtual currency businesses, mapping NYDFS Part 23 cybersecurity requirements alongside Part 500 and the unique obligations of crypto-native financial entities.

✓ Check your email for the download link.

Something went wrong. Please try again.

§ Cross-framework tools·privacy and deadline tracking

Cross-Framework Tools

Tools that cut across regulatory frameworks: a GLBA/CCPA privacy navigator and a regulatory deadline tracker for the compliance calendar every CCO and GC needs.

6 pages For: Privacy Counsel, CDOs, CPOs

GLBA × CCPA/CPRA Financial Services Navigator

A side-by-side navigator for financial institutions subject to both GLBA and CCPA/CPRA — mapping the partial CCPA exemption, where it applies, where it does not, and what your privacy program must cover under both regimes.

✓ Check your email for the download link.

Something went wrong. Please try again.

5 pages For: CCOs, GCs, Board Risk Committees

Finserv Regulatory Deadline Tracker 2023–2026

Every material GLBA, NYDFS Part 500, CCPA/CPRA, Reg S-P, and related finserv cybersecurity and privacy deadline from 2023 through 2026 — with compliance status, effective dates, and transition guidance in one tracker.

✓ Check your email for the download link.

Something went wrong. Please try again.

Need help implementing these frameworks? A senior practitioner — not a junior analyst — scopes a fixed-fee readiness engagement on a 30-minute call. No pitch, just a clear picture of where you stand and what to fix first.

Schedule a complimentary scoping call →