← All examplesFictional sample document

Cedar Hollow Tax Services

Tax firm WISP · 40 PDF pages. Generated using the current draft checks and the same report renderer as the scan flow.

Download the source policy (.pdf)
Applicability answers for this fictional scenario

These are explicit sample assumptions, not a legal determination for a real organization.

Consumer information held for business purpose
Yes
Consumers represented in maintained customer information
6000
Develops covered applications in house
No
Effective continuous monitoring
No
FTC jurisdiction
Yes
Qualified Individual arrangement
INTERNAL
Subject to FTC Safeguards Rule
Yes
Uses covered externally developed applications
Yes

Fictional example · Same report layout and download format as generated reports.

AuditReadySample report

Full language-screen report

Fictional sample · no payment

Written information security program · United States only

57%
Document wording coverage

54 in-scope checks · 0 unresolved · 4 out of scope

20 Strong22 Partial12 Not found

Strong matches earn full credit; partial matches earn half credit. Unresolved and out-of-scope checks are excluded. This is a wording score, not a compliance grade.

Important: This report identifies potential policy and documentation gaps. It does not verify that controls are operating effectively and is not legal advice, certification, or a compliance determination.

FTC Safeguards Rule — WISP Readiness Draft

Version 0.1.0-draft.1 · DRAFT · 55 checks

  1. 16 CFR 314.4(d)(2)No matching language · critical

    Covered information systems use effective continuous monitoring or the prescribed periodic testing path.

    Federal Trade Commission · official source

    Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 20.7%).

    Suggested fix: Document the selected monitoring/testing approach, coverage, responsible parties, and follow-up.

  2. 16 CFR 314.4(j)(2)No matching language · critical

    The notification clock uses the first imputed day of knowledge specified by the rule.

    Federal Trade Commission · official source

    Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 14.4%).

    Suggested fix: Add the rule's discovery standard and immediate internal escalation requirement to the response procedure.

  3. 16 CFR 314.4(b)(1)(ii)No matching language · high

    The written assessment defines criteria for confidentiality, integrity, availability, and control adequacy.

    Federal Trade Commission · official source

    Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 29.5%).

    Suggested fix: Add CIA and control-adequacy assessment criteria to the written risk assessment.

  4. 16 CFR 314.4(d)(2)(ii)No matching language · high

    Without effective continuous monitoring, vulnerability assessments occur at least every six months and upon material changes or circumstances.

    Federal Trade Commission · official source

    Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 27.5%).

    Suggested fix: Require vulnerability assessments at least every six months and after each stated material trigger.

  5. 16 CFR 314.4(h)(3)No matching language · high

    The plan assigns clear roles, duties, and decision authority.

    Federal Trade Commission · official source

    Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 24.5%).

    Suggested fix: Create a response responsibility and decision-authority matrix.

  6. 16 CFR 314.4(j)(1)(i)No matching language · high

    The notification process records institution name and contact information.

    Federal Trade Commission · official source

    Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 0.0%).

    Suggested fix: Add institution name and contact information to the FTC notification checklist or template.

  7. 16 CFR 314.4(j)(1)(ii)No matching language · high

    The notification process records types of information involved.

    Federal Trade Commission · official source

    Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 0.0%).

    Suggested fix: Add types of information involved to the FTC notification checklist or template.

  8. 16 CFR 314.4(j)(1)(iii)No matching language · high

    The notification process records event date or date range when determinable.

    Federal Trade Commission · official source

    Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 0.0%).

    Suggested fix: Add event date or date range when determinable to the FTC notification checklist or template.

  9. 16 CFR 314.4(j)(1)(iv)No matching language · high

    The notification process records number of consumers affected or potentially affected.

    Federal Trade Commission · official source

    Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 0.0%).

    Suggested fix: Add number of consumers affected or potentially affected to the FTC notification checklist or template.

  10. 16 CFR 314.4(j)(1)(v)No matching language · high

    The notification process records general description of the event.

    Federal Trade Commission · official source

    Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 0.0%).

    Suggested fix: Add general description of the event to the FTC notification checklist or template.

  11. 16 CFR 314.4(j)(1)(vi)No matching language · high

    The notification process records law-enforcement delay determination, contact method, and controlled extension handling.

    Federal Trade Commission · official source

    Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 0.0%).

    Suggested fix: Add law-enforcement delay determination, contact method, and controlled extension handling to the FTC notification checklist or template.

  12. 16 CFR 314.3(a)Partial matching language · critical

    The institution maintains an accessible written information security program scaled to its circumstances and covering the required elements.

    Federal Trade Commission · official source

    One or more required control concepts, scope details or contractual duties are missing from this passage; overlapping words alone cannot earn a strong label. Automated text screen found only a partial match (75.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “Where a service provider performs the control, the provider's attestation and the contract clause reference are attached. The reviewer noted that the procedure in this WISP was followed as written and did not require an update this period.”
    tax-preparer-cpa.pdf · page 9

    Suggested fix: Create or consolidate an approved written information security program, define its scope, and cross-reference every applicable § 314.4 element.

  13. 16 CFR 314.4(b)Partial matching language · critical

    The program is risk-based, identifies foreseeable internal and external risks, and evaluates safeguard sufficiency.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (52.8% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “4. Risk assessment SOP Each January, the Security Lead documents reasonably foreseeable internal and external risks, assesses likelihood and impact, identifies controls, and records residual risk in the risk register.”
    tax-preparer-cpa.pdf · page 4

    Suggested fix: Document the risk basis for the program, the relevant risk categories, and safeguard-sufficiency review.

  14. 16 CFR 314.4(c)(5)Partial matching language · critical

    MFA protects every individual's access to information systems unless a written, equivalent-control exception is approved.

    Federal Trade Commission · official source

    One or more required control concepts, scope details or contractual duties are missing from this passage; overlapping words alone cannot earn a strong label. Automated text screen found only a partial match (65.2% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “• Evidence item 6: result carried forward to the annual written report to the Managing Partners. Reviewer notes MFA enrollment was confirmed for every account in scope, including administrator and service accounts with interactive access. The reviewer sampled five records from the period and traced each one to the supporting ticket or log entry without exception. Change tickets affecting this control were reviewed to confirm that the system owner approved the change before implementation.”
    tax-preparer-cpa.pdf · page 17

    Suggested fix: Expand MFA coverage to all individuals and document any equivalent-control approval in writing.

  15. 16 CFR 314.4(g)Partial matching language · critical

    The program is evaluated and adjusted after testing, risk assessment, material change, or other material circumstances.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (51.5% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “WISP evaluation and adjustment Control area WISP evaluation and adjustment Requirement reference 16 CFR 314.4(g) Scope for this record Business email tenant Control owner Security Lead Frequency Annually and after material change Review period 2026-07 Evidence required Redlined WISP and approval minutes Status Operating as designed - evidence on file Procedure performed For the review period 2026-07, the Security Lead performed the wisp evaluation and adjustment control for the business email tenant in accordance with the Cedar Hollow WISP.”
    tax-preparer-cpa.pdf · page 24

    Suggested fix: Add event-driven program evaluation, change approval, versioning, and follow-through requirements.

  16. 16 CFR 314.4(h)Partial matching language · critical

    A written plan supports prompt response and recovery for material customer-information security events.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (50.3% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “Marketing website content that never receives customer information is out of scope but is still covered by change management. 2. Roles and responsibilities Role Responsibilities Security Lead (Qualified Individual) Owns the WISP, risk assessment, control testing, incident response coordination, vendor reviews, and the annual written report to the Managing Partners. Managing Partners Approve the WISP, risk exceptions, budget, and the annual report; receive escalations for material security events.”
    tax-preparer-cpa.pdf · page 3

    Suggested fix: Create and approve a written incident response plan scoped to material customer-information events.

  17. 16 CFR 314.4(j)(1)-TIMINGPartial matching language · critical

    For a qualifying notification event, the institution can notify the FTC as soon as possible and within 30 days of discovery. This is an event-triggered duty; document coverage demonstrates readiness but does not prove compliance in an actual event.

    Federal Trade Commission · official source

    One or more required control concepts, scope details or contractual duties are missing from this passage; overlapping words alone cannot earn a strong label. Automated text screen found only a partial match (75.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “Legal counsel determines any applicable customer or regulator notice obligations, including whether an event involving unencrypted information of 500 or more consumers must be reported to the FTC no later than 30 days after discovery.”
    tax-preparer-cpa.pdf · page 5

    Suggested fix: Add the threshold, discovery rule, owner, escalation, and 30-day FTC deadline to the response procedure.

  18. 16 CFR 314.3(b)(1)Partial matching language · high

    The program expressly treats security and confidentiality of customer information as an objective.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (42.8% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “The program is designed to protect the security, confidentiality, and integrity of customer information, to protect against reasonably anticipated threats or hazards, and to protect against unauthorized access that could result in substantial harm or inconvenience to any customer.”
    tax-preparer-cpa.pdf · page 2

    Suggested fix: Add security and confidentiality of customer information as an explicit program objective.

  19. 16 CFR 314.4(b)(1)(i)Partial matching language · high

    The written risk assessment defines how risks and threats are evaluated and categorized.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (40.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “• Step 2 - Identify threats: phishing, credential theft, ransomware, lost devices, insider misuse, vendor compromise, misdirected mail, and physical theft. • Step 3 - Rate likelihood and impact from 1 (low) to 5 (high) using the matrix in 4.2. • Step 4 - Record existing controls and evaluate whether they sufficiently address each risk.”
    tax-preparer-cpa.pdf · page 4

    Suggested fix: Add repeatable likelihood, impact, and categorization criteria to the written risk assessment.

  20. 16 CFR 314.4(b)(1)(iii)Partial matching language · high

    The written assessment defines how risks are mitigated or formally accepted and fed into the program.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (37.2% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “• Step 5 - Record residual risk, the treatment decision (mitigate, accept, transfer, avoid), owner, and target date.”
    tax-preparer-cpa.pdf · page 4

    Suggested fix: Define risk mitigation, acceptance authority, documentation, and program-update requirements.

  21. 16 CFR 314.4(c)(2)Partial matching language · high

    The institution identifies and manages relevant assets according to business importance and risk.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (34.3% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “Managing Partners approve any risk exception, with an owner and expiration date. 4.1 Procedure • Step 1 - Confirm the system and data inventory is current. • Step 2 - Identify threats: phishing, credential theft, ransomware, lost devices, insider misuse, vendor compromise, misdirected mail, and physical theft.”
    tax-preparer-cpa.pdf · page 4

    Suggested fix: Document asset categories, ownership, inventory expectations, and risk-based prioritization.

  22. 16 CFR 314.4(c)(4)-EXTERNALPartial matching language · high

    Covered externally developed applications receive security evaluation, assessment, or testing.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (47.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “Marketing website content that never receives customer information is out of scope but is still covered by change management. 2. Roles and responsibilities Role Responsibilities Security Lead (Qualified Individual) Owns the WISP, risk assessment, control testing, incident response coordination, vendor reviews, and the annual written report to the Managing Partners.”
    tax-preparer-cpa.pdf · page 3

    Suggested fix: Add risk-based security assessment and testing requirements for covered external applications.

  23. 16 CFR 314.4(d)(2)(i)Partial matching language · high

    Without effective continuous monitoring, penetration testing occurs annually with risk-based scope.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (49.8% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “Marketing website content that never receives customer information is out of scope but is still covered by change management. 2. Roles and responsibilities Role Responsibilities Security Lead (Qualified Individual) Owns the WISP, risk assessment, control testing, incident response coordination, vendor reviews, and the annual written report to the Managing Partners. Managing Partners Approve the WISP, risk exceptions, budget, and the annual report; receive escalations for material security events. Operations Manager Approves access requests based on job need; reports role changes within one business day; owns onboarding and offboarding checklists.”
    tax-preparer-cpa.pdf · page 3

    Suggested fix: Set an annual risk-based penetration-testing requirement and remediation process.

  24. 16 CFR 314.4(e)(1)Partial matching language · high

    Personnel receive security awareness training updated for identified risks.

    Federal Trade Commission · official source

    One or more required control concepts, scope details or contractual duties are missing from this passage; overlapping words alone cannot earn a strong label. Automated text screen found only a partial match (75.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “Activity Frequency Owner Evidence Security awareness training At hire and annually Security Lead Training completion log Phishing simulation Quarterly Security Lead Campaign results and coaching notes Vulnerability scan Monthly IT Administrator Scan report and remediation tickets Penetration test Annually Independent tester Test report and retest letter Security staff updates Ongoing Security Lead Continuing education records 10.”
    tax-preparer-cpa.pdf · page 5

    Suggested fix: Define and maintain risk-informed security awareness training for all relevant personnel.

  25. 16 CFR 314.4(e)(3)Partial matching language · high

    Security personnel receive role-appropriate updates and training for relevant risks.

    Federal Trade Commission · official source

    One or more required control concepts, scope details or contractual duties are missing from this passage; overlapping words alone cannot earn a strong label. Automated text screen found only a partial match (66.7% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “Activity Frequency Owner Evidence Security awareness training At hire and annually Security Lead Training completion log Phishing simulation Quarterly Security Lead Campaign results and coaching notes Vulnerability scan Monthly IT Administrator Scan report and remediation tickets Penetration test Annually Independent tester Test report and retest letter Security staff updates Ongoing Security Lead Continuing education records 10.”
    tax-preparer-cpa.pdf · page 5

    Suggested fix: Establish continuing role-based training and security-update requirements for security personnel.

  26. 16 CFR 314.4(e)(4)Partial matching language · high

    The institution verifies that key security personnel maintain current threat and countermeasure knowledge.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (51.4% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “Procurement Performs service provider due diligence before contract signature and keeps contract security clauses current. All staff Complete training, follow this WISP, protect credentials, and report suspected incidents immediately. 3. Information and system inventory The Security Lead maintains an inventory of data, personnel, devices, systems, and facilities that store or process customer information. Each inventory entry records the system owner, data types, location, hosting model, encryption status, MFA status, backup status, and the date it was last verified.”
    tax-preparer-cpa.pdf · page 3

    Suggested fix: Document continuing-knowledge activities and periodic verification for key security personnel.

  27. 16 CFR 314.4(h)(2)Partial matching language · high

    The plan defines internal response processes.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (43.6% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “Disposal evidence for this period includes the vendor certificate of destruction and the internal disposal log entry. Follow-up and escalation If this control fails or evidence is missing, the IT Administrator opens a remediation item within five business days, rates the gap using the scoring matrix in Section 4.2, and notifies the Security Lead. High or critical gaps affecting the managed it support provider (northpoint, fictional) are reported to the Managing Partners within 30 days, and any related security event is handled under the incident response SOP in Section 11.”
    tax-preparer-cpa.pdf · page 28

    Suggested fix: Document detection, triage, containment, eradication, recovery, and lessons-learned processes.

  28. 16 CFR 314.4(h)(4)Partial matching language · high

    The plan governs internal and external communications and sharing.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (33.7% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “Access to the evidence folder is limited to the Security Lead, the Managing Partners, and the external assessor when engaged. No shared accounts were identified; named accounts were confirmed against the current staff roster provided by the Operations Manager.”
    tax-preparer-cpa.pdf · page 9

    Suggested fix: Define stakeholders, approval, channels, timing, and protected information sharing.

  29. 16 CFR 314.4(h)(7)Partial matching language · high

    The plan is evaluated and revised after security events when necessary.

    Federal Trade Commission · official source

    One or more required control concepts, scope details or contractual duties are missing from this passage; overlapping words alone cannot earn a strong label. Automated text screen found only a partial match (66.7% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “Incident response plan Control area Incident response plan Requirement reference 16 CFR 314.4(h) Scope for this record Scanner and multifunction printers Control owner Security Lead Frequency Tested annually Review period 2026-02 Evidence required Plan, tabletop record, incident log Status Operating as designed - evidence on file Procedure performed For the review period 2026-02, the Security Lead performed the incident response plan control for the scanner and multifunction printers in accordance with the Cedar Hollow WISP.”
    tax-preparer-cpa.pdf · page 25

    Suggested fix: Require a post-event review and controlled plan updates.

  30. 16 CFR 314.4(i)(1)Partial matching language · high

    The written report covers overall program status and compliance with Part 314.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (45.2% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “14. Governance, annual report, and evidence The Security Lead gives the Managing Partners a written annual report covering risk assessment results, control testing, security events, vendor status, and recommended changes.”
    tax-preparer-cpa.pdf · page 6

    Suggested fix: Add program-status and Part 314 compliance sections to the annual report template.

  31. 16 CFR 314.4(i)(2)Partial matching language · high

    The written report addresses material program matters and recommendations for change.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (44.7% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “The Security Lead is designated as the Qualified Individual responsible for overseeing, implementing, and enforcing this information security program. The Security Lead maintains a system and data inventory and reviews this WISP every year and after material changes, such as a new office, a new tax software platform, a merger, or a security event. 1.1 Information in scope Information type Examples Formats Taxpayer identity data Names, SSNs, ITINs, dates of birth, identity document images Electronic, paper Tax return information Draft and filed returns, schedules, e-file acknowledgements Electronic, paper Financial account data Refund deposit account and routing numbers, payment records Electronic Client portal records Uploaded source documents, secure messages, signature records Electronic Engagement records Engagement letters, consent forms, preparer notes Electronic, paper 1.2 Systems and locations in scope • Main office and seasonal satellite office (fictional addresses on file with Operations).”
    tax-preparer-cpa.pdf · page 3

    Suggested fix: Expand the annual report template to cover material risks, controls, providers, tests, events, responses, and recommendations.

  32. 16 CFR 314.4(a)Matching language found · critical

    A specific Qualified Individual is designated with responsibility for oversight, implementation, and enforcement.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “The Security Lead is designated as the Qualified Individual responsible for overseeing, implementing, and enforcing this information security program.”
    tax-preparer-cpa.pdf · page 3
  33. 16 CFR 314.4(c)(3)Matching language found · critical

    Customer information is encrypted in transit over external networks and at rest, or documented compensating controls are approved by the Qualified Individual where encryption is infeasible.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 57.9% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “Customer information is encrypted at rest on managed laptops and servers and encrypted in transit with TLS. IT records encryption exceptions, applies compensating controls, and obtains written approval from the Security Lead before use.”
    tax-preparer-cpa.pdf · page 4
  34. 16 CFR 314.4(d)(1)Matching language found · critical

    The institution regularly tests or monitors safeguard effectiveness, including attack detection.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “8. Monitoring and logging IT monitors authorized user activity and detects unauthorized access, use of, or tampering with customer information. Logs from email, the client portal, the tax platform, endpoint protection, and the firewall are retained for at least one year. Alerts are reviewed each business day during tax season and at least weekly otherwise. 9. Training and testing SOP Employees complete security awareness training at hire and annually.”
    tax-preparer-cpa.pdf · page 5
  35. 16 CFR 314.3(b)(2)Matching language found · high

    The program addresses anticipated threats and hazards affecting customer information.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 71.6% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “The program is designed to protect the security, confidentiality, and integrity of customer information, to protect against reasonably anticipated threats or hazards, and to protect against unauthorized access that could result in substantial harm or inconvenience to any customer.”
    tax-preparer-cpa.pdf · page 2
  36. 16 CFR 314.3(b)(3)Matching language found · high

    The program addresses unauthorized access or use that could harm customers.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 83.2% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “The program is designed to protect the security, confidentiality, and integrity of customer information, to protect against reasonably anticipated threats or hazards, and to protect against unauthorized access that could result in substantial harm or inconvenience to any customer.”
    tax-preparer-cpa.pdf · page 2
  37. 16 CFR 314.4(b)(2)Matching language found · high

    Risk assessment recurs periodically and reexamines risks and safeguard sufficiency.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “4. Risk assessment SOP Each January, the Security Lead documents reasonably foreseeable internal and external risks, assesses likelihood and impact, identifies controls, and records residual risk in the risk register.”
    tax-preparer-cpa.pdf · page 4
  38. 16 CFR 314.4(c)(1)(i)Matching language found · high

    Access controls authenticate users and limit access to authorized users.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “5. Access control SOP Only named accounts may access customer information.”
    tax-preparer-cpa.pdf · page 4
  39. 16 CFR 314.4(c)(1)(ii)Matching language found · high

    Authorized access follows need-to-know and least-privilege principles.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “5. Access control SOP Only named accounts may access customer information. The Operations Manager approves access based on job need and least privilege.”
    tax-preparer-cpa.pdf · page 4
  40. 16 CFR 314.4(c)(6)(i)Matching language found · high

    Secure disposal occurs within the specified period unless a documented rule exception applies.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “When retention expires, paper containing customer information is cross-cut shredded by an approved vendor; electronic copies are securely erased or destroyed. Vendor destruction certificates are retained. Exceptions require a documented legal or business reason and a review date. Backups follow the approved deletion schedule. Customer information is disposed of no later than two years after the last date it was used to provide a product or service, unless retention is required by law or a legitimate business need documented in the retention schedule.”
    tax-preparer-cpa.pdf · page 5
  41. 16 CFR 314.4(c)(6)(ii)Matching language found · high

    The institution periodically reviews retention policy to minimize unnecessary data.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “• Evidence item 6: result carried forward to the annual written report to the Managing Partners. Reviewer notes Retention of this evidence follows the retention schedule in Appendix D, and the evidence is not subject to a legal hold.”
    tax-preparer-cpa.pdf · page 21
  42. 16 CFR 314.4(c)(7)Matching language found · high

    Changes affecting relevant systems and customer information follow documented management procedures.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “7. Change management and secure configuration Changes to systems that store or process customer information follow a documented change procedure: request, risk review, approval by the system owner, testing, implementation window, and post-change verification.”
    tax-preparer-cpa.pdf · page 4
  43. 16 CFR 314.4(c)(8)Matching language found · high

    Authorized-user activity is monitored and logged to detect misuse or tampering involving customer information.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “8. Monitoring and logging IT monitors authorized user activity and detects unauthorized access, use of, or tampering with customer information.”
    tax-preparer-cpa.pdf · page 5
  44. 16 CFR 314.4(e)(2)Matching language found · high

    Sufficient qualified security personnel manage risk and perform or oversee the program.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 58.8% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “Vulnerability scans run monthly; a qualified independent tester performs an annual penetration test. The Security Lead tracks findings to closure and verifies fixes. Activity Frequency Owner Evidence Security awareness training At hire and annually Security Lead Training completion log Phishing simulation Quarterly Security Lead Campaign results and coaching notes Vulnerability scan Monthly IT Administrator Scan report and remediation tickets Penetration test Annually Independent tester Test report and retest letter Security staff updates Ongoing Security Lead Continuing education records 10. Vendor oversight SOP Before a service provider receives customer information, Procurement documents due diligence on its safeguards and incident response.”
    tax-preparer-cpa.pdf · page 5
  45. 16 CFR 314.4(f)(1)Matching language found · high

    Service-provider selection and retention include reasonable safeguard due diligence.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 61.1% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “Records Manager Maintains the retention schedule, legal holds, disposal log, and vendor destruction certificates. Procurement Performs service provider due diligence before contract signature and keeps contract security clauses current.”
    tax-preparer-cpa.pdf · page 3
  46. 16 CFR 314.4(f)(2)Matching language found · high

    Contracts require service providers to implement and maintain appropriate safeguards.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 73.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “Vendor oversight SOP Before a service provider receives customer information, Procurement documents due diligence on its safeguards and incident response. Contracts require appropriate security controls and prompt incident notice.”
    tax-preparer-cpa.pdf · page 5
  47. 16 CFR 314.4(f)(3)Matching language found · high

    Service providers are periodically reassessed according to risk and safeguard adequacy.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “The Security Lead reviews critical providers annually and records remediation for material gaps.”
    tax-preparer-cpa.pdf · page 5
  48. 16 CFR 314.4(h)(1)Matching language found · high

    The plan states response and recovery goals.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 62.3% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “Restore testing confirmed that backups covering this scope could be recovered within the target recovery time. The Operations Manager confirmed that role changes for staff in this scope were reported within one business day. The reviewer confirmed that the evidence matches the frequency stated in the WISP and that the owner signed the record. Follow-up and escalation If this control fails or evidence is missing, the IT Administrator opens a remediation item within five business days, rates the gap using the scoring matrix in Section 4.2, and notifies the Security Lead. High or critical gaps affecting the business email tenant are reported to the Managing Partners within 30 days, and any related security event is handled under the incident response SOP in Section 11.”
    tax-preparer-cpa.pdf · page 36
  49. 16 CFR 314.4(h)(5)Matching language found · high

    The plan requires remediation of weaknesses identified during incidents.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 75.3% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “The Managing Partners were informed of no material weaknesses for this control in the current period. Follow-up and escalation If this control fails or evidence is missing, the Security Lead opens a remediation item within five business days, rates the gap using the scoring matrix in Section 4.2, and notifies the Security Lead. High or critical gaps affecting the seasonal satellite office are reported to the Managing Partners within 30 days, and any related security event is handled under the incident response SOP in Section 11. Closure requires retest evidence.”
    tax-preparer-cpa.pdf · page 10
  50. 16 CFR 314.4(h)(6)Matching language found · high

    The plan requires security-event and response documentation and reporting.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 65.9% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “High or critical gaps affecting the paper file room are reported to the Managing Partners within 30 days, and any related security event is handled under the incident response SOP in Section 11. Closure requires retest evidence.”
    tax-preparer-cpa.pdf · page 20
  51. 16 CFR 314.4(i)Matching language found · high

    The Qualified Individual reports in writing at least annually to the board, equivalent body, or responsible senior officer.

    Federal Trade Commission · official source

    Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.

    “2. Roles and responsibilities Role Responsibilities Security Lead (Qualified Individual) Owns the WISP, risk assessment, control testing, incident response coordination, vendor reviews, and the annual written report to the Managing Partners.”
    tax-preparer-cpa.pdf · page 3
  52. 16 CFR 314.4(a)(1)Not in scope based on answers · high

    Using an affiliate or service provider as Qualified Individual does not transfer the institution's responsibility.

    Federal Trade Commission · official source

    This subparagraph applies only when the Qualified Individual is supplied by an affiliate or service provider.

  53. 16 CFR 314.4(a)(2)Not in scope based on answers · high

    A senior internal person directs and oversees an external Qualified Individual.

    Federal Trade Commission · official source

    This subparagraph applies only when the Qualified Individual is supplied by an affiliate or service provider.

  54. 16 CFR 314.4(a)(3)Not in scope based on answers · high

    The external Qualified Individual's organization is required to maintain a protective information security program.

    Federal Trade Commission · official source

    This subparagraph applies only when the Qualified Individual is supplied by an affiliate or service provider.

  55. 16 CFR 314.4(c)(4)-IN-HOUSENot in scope based on answers · high

    Covered in-house applications follow documented secure development practices.

    Federal Trade Commission · official source

    The institution does not develop in-house applications covered by this clause.

FTC Disposal Rule readiness

Version 0.1.0-draft.1 · DRAFT · 3 checks

  1. 16 CFR 682.3(b)(5)No matching language · high

    An organization subject to the FTC Safeguards Rule integrates covered disposal controls into its written information security program. This paragraph is an illustrative measure.

    Federal Trade Commission · official source

    Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 28.4%).

    Suggested fix: Cross-reference Part 682 disposal controls from the WISP and align ownership, testing, and service-provider controls.

  2. 16 CFR 682.3(a)Partial matching language · critical

    The organization uses and monitors reasonable disposal measures for paper, electronic media, and transferred media containing consumer-report information.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (39.3% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “When retention expires, paper containing customer information is cross-cut shredded by an approved vendor; electronic copies are securely erased or destroyed.”
    tax-preparer-cpa.pdf · page 5

    Suggested fix: Adopt a risk-based disposal policy and procedures that render covered information impracticable to read or reconstruct and monitor compliance.

  3. 16 CFR 682.3(b)(3)Partial matching language · high

    When a disposal vendor is used, the organization performs due diligence, contracts for compliant disposal, and monitors performance. This paragraph is an illustrative safe practice, not an exclusive method.

    Federal Trade Commission · official source

    Coverage is below the strong-match threshold. Automated text screen found only a partial match (40.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.

    “Records Manager Maintains the retention schedule, legal holds, disposal log, and vendor destruction certificates. Procurement Performs service provider due diligence before contract signature and keeps contract security clauses current.”
    tax-preparer-cpa.pdf · page 3

    Suggested fix: Document vendor selection, contract controls, and monitoring for record-destruction providers.

Limitations

  • Preview built on DRAFT rule packs that have not completed independent legal review.
  • Produced by a deterministic keyword screen, not by AI and not by a human reviewer; it can miss evidence phrased differently and can match text that does not satisfy the requirement.
  • Readiness screening only; not legal advice, an audit, or a certification of compliance.
  • Items marked applicability unresolved depend on facts that have not been collected or confirmed yet.
Quote fictional-tax-firm-quote · Report fictional-tax-firm-report
Check your own policy