Full language-screen report
Fictional sample · no paymentWritten information security program · United States only
54 in-scope checks · 0 unresolved · 4 out of scope
Strong matches earn full credit; partial matches earn half credit. Unresolved and out-of-scope checks are excluded. This is a wording score, not a compliance grade.
Important: This report identifies potential policy and documentation gaps. It does not verify that controls are operating effectively and is not legal advice, certification, or a compliance determination.
FTC Safeguards Rule — WISP Readiness Draft
Version 0.1.0-draft.1 · DRAFT · 55 checks
- 16 CFR 314.4(d)(2)No matching language · critical
Covered information systems use effective continuous monitoring or the prescribed periodic testing path.
Federal Trade Commission · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 20.7%).
Suggested fix: Document the selected monitoring/testing approach, coverage, responsible parties, and follow-up.
- 16 CFR 314.4(j)(2)No matching language · critical
The notification clock uses the first imputed day of knowledge specified by the rule.
Federal Trade Commission · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 14.4%).
Suggested fix: Add the rule's discovery standard and immediate internal escalation requirement to the response procedure.
- 16 CFR 314.4(b)(1)(ii)No matching language · high
The written assessment defines criteria for confidentiality, integrity, availability, and control adequacy.
Federal Trade Commission · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 29.5%).
Suggested fix: Add CIA and control-adequacy assessment criteria to the written risk assessment.
- 16 CFR 314.4(d)(2)(ii)No matching language · high
Without effective continuous monitoring, vulnerability assessments occur at least every six months and upon material changes or circumstances.
Federal Trade Commission · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 27.5%).
Suggested fix: Require vulnerability assessments at least every six months and after each stated material trigger.
- 16 CFR 314.4(h)(3)No matching language · high
The plan assigns clear roles, duties, and decision authority.
Federal Trade Commission · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 24.5%).
Suggested fix: Create a response responsibility and decision-authority matrix.
- 16 CFR 314.4(j)(1)(i)No matching language · high
The notification process records institution name and contact information.
Federal Trade Commission · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 0.0%).
Suggested fix: Add institution name and contact information to the FTC notification checklist or template.
- 16 CFR 314.4(j)(1)(ii)No matching language · high
The notification process records types of information involved.
Federal Trade Commission · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 0.0%).
Suggested fix: Add types of information involved to the FTC notification checklist or template.
- 16 CFR 314.4(j)(1)(iii)No matching language · high
The notification process records event date or date range when determinable.
Federal Trade Commission · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 0.0%).
Suggested fix: Add event date or date range when determinable to the FTC notification checklist or template.
- 16 CFR 314.4(j)(1)(iv)No matching language · high
The notification process records number of consumers affected or potentially affected.
Federal Trade Commission · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 0.0%).
Suggested fix: Add number of consumers affected or potentially affected to the FTC notification checklist or template.
- 16 CFR 314.4(j)(1)(v)No matching language · high
The notification process records general description of the event.
Federal Trade Commission · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 0.0%).
Suggested fix: Add general description of the event to the FTC notification checklist or template.
- 16 CFR 314.4(j)(1)(vi)No matching language · high
The notification process records law-enforcement delay determination, contact method, and controlled extension handling.
Federal Trade Commission · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 0.0%).
Suggested fix: Add law-enforcement delay determination, contact method, and controlled extension handling to the FTC notification checklist or template.
- 16 CFR 314.3(a)Partial matching language · critical
The institution maintains an accessible written information security program scaled to its circumstances and covering the required elements.
Federal Trade Commission · official source
One or more required control concepts, scope details or contractual duties are missing from this passage; overlapping words alone cannot earn a strong label. Automated text screen found only a partial match (75.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Where a service provider performs the control, the provider's attestation and the contract clause reference are attached. The reviewer noted that the procedure in this WISP was followed as written and did not require an update this period.”
Suggested fix: Create or consolidate an approved written information security program, define its scope, and cross-reference every applicable § 314.4 element.
- 16 CFR 314.4(b)Partial matching language · critical
The program is risk-based, identifies foreseeable internal and external risks, and evaluates safeguard sufficiency.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (52.8% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“4. Risk assessment SOP Each January, the Security Lead documents reasonably foreseeable internal and external risks, assesses likelihood and impact, identifies controls, and records residual risk in the risk register.”
Suggested fix: Document the risk basis for the program, the relevant risk categories, and safeguard-sufficiency review.
- 16 CFR 314.4(c)(5)Partial matching language · critical
MFA protects every individual's access to information systems unless a written, equivalent-control exception is approved.
Federal Trade Commission · official source
One or more required control concepts, scope details or contractual duties are missing from this passage; overlapping words alone cannot earn a strong label. Automated text screen found only a partial match (65.2% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“• Evidence item 6: result carried forward to the annual written report to the Managing Partners. Reviewer notes MFA enrollment was confirmed for every account in scope, including administrator and service accounts with interactive access. The reviewer sampled five records from the period and traced each one to the supporting ticket or log entry without exception. Change tickets affecting this control were reviewed to confirm that the system owner approved the change before implementation.”
Suggested fix: Expand MFA coverage to all individuals and document any equivalent-control approval in writing.
- 16 CFR 314.4(g)Partial matching language · critical
The program is evaluated and adjusted after testing, risk assessment, material change, or other material circumstances.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (51.5% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“WISP evaluation and adjustment Control area WISP evaluation and adjustment Requirement reference 16 CFR 314.4(g) Scope for this record Business email tenant Control owner Security Lead Frequency Annually and after material change Review period 2026-07 Evidence required Redlined WISP and approval minutes Status Operating as designed - evidence on file Procedure performed For the review period 2026-07, the Security Lead performed the wisp evaluation and adjustment control for the business email tenant in accordance with the Cedar Hollow WISP.”
Suggested fix: Add event-driven program evaluation, change approval, versioning, and follow-through requirements.
- 16 CFR 314.4(h)Partial matching language · critical
A written plan supports prompt response and recovery for material customer-information security events.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (50.3% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Marketing website content that never receives customer information is out of scope but is still covered by change management. 2. Roles and responsibilities Role Responsibilities Security Lead (Qualified Individual) Owns the WISP, risk assessment, control testing, incident response coordination, vendor reviews, and the annual written report to the Managing Partners. Managing Partners Approve the WISP, risk exceptions, budget, and the annual report; receive escalations for material security events.”
Suggested fix: Create and approve a written incident response plan scoped to material customer-information events.
- 16 CFR 314.4(j)(1)-TIMINGPartial matching language · critical
For a qualifying notification event, the institution can notify the FTC as soon as possible and within 30 days of discovery. This is an event-triggered duty; document coverage demonstrates readiness but does not prove compliance in an actual event.
Federal Trade Commission · official source
One or more required control concepts, scope details or contractual duties are missing from this passage; overlapping words alone cannot earn a strong label. Automated text screen found only a partial match (75.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Legal counsel determines any applicable customer or regulator notice obligations, including whether an event involving unencrypted information of 500 or more consumers must be reported to the FTC no later than 30 days after discovery.”
Suggested fix: Add the threshold, discovery rule, owner, escalation, and 30-day FTC deadline to the response procedure.
- 16 CFR 314.3(b)(1)Partial matching language · high
The program expressly treats security and confidentiality of customer information as an objective.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (42.8% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“The program is designed to protect the security, confidentiality, and integrity of customer information, to protect against reasonably anticipated threats or hazards, and to protect against unauthorized access that could result in substantial harm or inconvenience to any customer.”
Suggested fix: Add security and confidentiality of customer information as an explicit program objective.
- 16 CFR 314.4(b)(1)(i)Partial matching language · high
The written risk assessment defines how risks and threats are evaluated and categorized.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (40.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“• Step 2 - Identify threats: phishing, credential theft, ransomware, lost devices, insider misuse, vendor compromise, misdirected mail, and physical theft. • Step 3 - Rate likelihood and impact from 1 (low) to 5 (high) using the matrix in 4.2. • Step 4 - Record existing controls and evaluate whether they sufficiently address each risk.”
Suggested fix: Add repeatable likelihood, impact, and categorization criteria to the written risk assessment.
- 16 CFR 314.4(b)(1)(iii)Partial matching language · high
The written assessment defines how risks are mitigated or formally accepted and fed into the program.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (37.2% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“• Step 5 - Record residual risk, the treatment decision (mitigate, accept, transfer, avoid), owner, and target date.”
Suggested fix: Define risk mitigation, acceptance authority, documentation, and program-update requirements.
- 16 CFR 314.4(c)(2)Partial matching language · high
The institution identifies and manages relevant assets according to business importance and risk.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (34.3% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Managing Partners approve any risk exception, with an owner and expiration date. 4.1 Procedure • Step 1 - Confirm the system and data inventory is current. • Step 2 - Identify threats: phishing, credential theft, ransomware, lost devices, insider misuse, vendor compromise, misdirected mail, and physical theft.”
Suggested fix: Document asset categories, ownership, inventory expectations, and risk-based prioritization.
- 16 CFR 314.4(c)(4)-EXTERNALPartial matching language · high
Covered externally developed applications receive security evaluation, assessment, or testing.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (47.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Marketing website content that never receives customer information is out of scope but is still covered by change management. 2. Roles and responsibilities Role Responsibilities Security Lead (Qualified Individual) Owns the WISP, risk assessment, control testing, incident response coordination, vendor reviews, and the annual written report to the Managing Partners.”
Suggested fix: Add risk-based security assessment and testing requirements for covered external applications.
- 16 CFR 314.4(d)(2)(i)Partial matching language · high
Without effective continuous monitoring, penetration testing occurs annually with risk-based scope.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (49.8% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Marketing website content that never receives customer information is out of scope but is still covered by change management. 2. Roles and responsibilities Role Responsibilities Security Lead (Qualified Individual) Owns the WISP, risk assessment, control testing, incident response coordination, vendor reviews, and the annual written report to the Managing Partners. Managing Partners Approve the WISP, risk exceptions, budget, and the annual report; receive escalations for material security events. Operations Manager Approves access requests based on job need; reports role changes within one business day; owns onboarding and offboarding checklists.”
Suggested fix: Set an annual risk-based penetration-testing requirement and remediation process.
- 16 CFR 314.4(e)(1)Partial matching language · high
Personnel receive security awareness training updated for identified risks.
Federal Trade Commission · official source
One or more required control concepts, scope details or contractual duties are missing from this passage; overlapping words alone cannot earn a strong label. Automated text screen found only a partial match (75.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Activity Frequency Owner Evidence Security awareness training At hire and annually Security Lead Training completion log Phishing simulation Quarterly Security Lead Campaign results and coaching notes Vulnerability scan Monthly IT Administrator Scan report and remediation tickets Penetration test Annually Independent tester Test report and retest letter Security staff updates Ongoing Security Lead Continuing education records 10.”
Suggested fix: Define and maintain risk-informed security awareness training for all relevant personnel.
- 16 CFR 314.4(e)(3)Partial matching language · high
Security personnel receive role-appropriate updates and training for relevant risks.
Federal Trade Commission · official source
One or more required control concepts, scope details or contractual duties are missing from this passage; overlapping words alone cannot earn a strong label. Automated text screen found only a partial match (66.7% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Activity Frequency Owner Evidence Security awareness training At hire and annually Security Lead Training completion log Phishing simulation Quarterly Security Lead Campaign results and coaching notes Vulnerability scan Monthly IT Administrator Scan report and remediation tickets Penetration test Annually Independent tester Test report and retest letter Security staff updates Ongoing Security Lead Continuing education records 10.”
Suggested fix: Establish continuing role-based training and security-update requirements for security personnel.
- 16 CFR 314.4(e)(4)Partial matching language · high
The institution verifies that key security personnel maintain current threat and countermeasure knowledge.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (51.4% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Procurement Performs service provider due diligence before contract signature and keeps contract security clauses current. All staff Complete training, follow this WISP, protect credentials, and report suspected incidents immediately. 3. Information and system inventory The Security Lead maintains an inventory of data, personnel, devices, systems, and facilities that store or process customer information. Each inventory entry records the system owner, data types, location, hosting model, encryption status, MFA status, backup status, and the date it was last verified.”
Suggested fix: Document continuing-knowledge activities and periodic verification for key security personnel.
- 16 CFR 314.4(h)(2)Partial matching language · high
The plan defines internal response processes.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (43.6% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Disposal evidence for this period includes the vendor certificate of destruction and the internal disposal log entry. Follow-up and escalation If this control fails or evidence is missing, the IT Administrator opens a remediation item within five business days, rates the gap using the scoring matrix in Section 4.2, and notifies the Security Lead. High or critical gaps affecting the managed it support provider (northpoint, fictional) are reported to the Managing Partners within 30 days, and any related security event is handled under the incident response SOP in Section 11.”
Suggested fix: Document detection, triage, containment, eradication, recovery, and lessons-learned processes.
- 16 CFR 314.4(h)(4)Partial matching language · high
The plan governs internal and external communications and sharing.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (33.7% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Access to the evidence folder is limited to the Security Lead, the Managing Partners, and the external assessor when engaged. No shared accounts were identified; named accounts were confirmed against the current staff roster provided by the Operations Manager.”
Suggested fix: Define stakeholders, approval, channels, timing, and protected information sharing.
- 16 CFR 314.4(h)(7)Partial matching language · high
The plan is evaluated and revised after security events when necessary.
Federal Trade Commission · official source
One or more required control concepts, scope details or contractual duties are missing from this passage; overlapping words alone cannot earn a strong label. Automated text screen found only a partial match (66.7% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Incident response plan Control area Incident response plan Requirement reference 16 CFR 314.4(h) Scope for this record Scanner and multifunction printers Control owner Security Lead Frequency Tested annually Review period 2026-02 Evidence required Plan, tabletop record, incident log Status Operating as designed - evidence on file Procedure performed For the review period 2026-02, the Security Lead performed the incident response plan control for the scanner and multifunction printers in accordance with the Cedar Hollow WISP.”
Suggested fix: Require a post-event review and controlled plan updates.
- 16 CFR 314.4(i)(1)Partial matching language · high
The written report covers overall program status and compliance with Part 314.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (45.2% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“14. Governance, annual report, and evidence The Security Lead gives the Managing Partners a written annual report covering risk assessment results, control testing, security events, vendor status, and recommended changes.”
Suggested fix: Add program-status and Part 314 compliance sections to the annual report template.
- 16 CFR 314.4(i)(2)Partial matching language · high
The written report addresses material program matters and recommendations for change.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (44.7% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“The Security Lead is designated as the Qualified Individual responsible for overseeing, implementing, and enforcing this information security program. The Security Lead maintains a system and data inventory and reviews this WISP every year and after material changes, such as a new office, a new tax software platform, a merger, or a security event. 1.1 Information in scope Information type Examples Formats Taxpayer identity data Names, SSNs, ITINs, dates of birth, identity document images Electronic, paper Tax return information Draft and filed returns, schedules, e-file acknowledgements Electronic, paper Financial account data Refund deposit account and routing numbers, payment records Electronic Client portal records Uploaded source documents, secure messages, signature records Electronic Engagement records Engagement letters, consent forms, preparer notes Electronic, paper 1.2 Systems and locations in scope • Main office and seasonal satellite office (fictional addresses on file with Operations).”
Suggested fix: Expand the annual report template to cover material risks, controls, providers, tests, events, responses, and recommendations.
- 16 CFR 314.4(a)Matching language found · critical
A specific Qualified Individual is designated with responsibility for oversight, implementation, and enforcement.
Federal Trade Commission · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“The Security Lead is designated as the Qualified Individual responsible for overseeing, implementing, and enforcing this information security program.”
- 16 CFR 314.4(c)(3)Matching language found · critical
Customer information is encrypted in transit over external networks and at rest, or documented compensating controls are approved by the Qualified Individual where encryption is infeasible.
Federal Trade Commission · official source
Automated text screen found a passage matching 57.9% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Customer information is encrypted at rest on managed laptops and servers and encrypted in transit with TLS. IT records encryption exceptions, applies compensating controls, and obtains written approval from the Security Lead before use.”
- 16 CFR 314.4(d)(1)Matching language found · critical
The institution regularly tests or monitors safeguard effectiveness, including attack detection.
Federal Trade Commission · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“8. Monitoring and logging IT monitors authorized user activity and detects unauthorized access, use of, or tampering with customer information. Logs from email, the client portal, the tax platform, endpoint protection, and the firewall are retained for at least one year. Alerts are reviewed each business day during tax season and at least weekly otherwise. 9. Training and testing SOP Employees complete security awareness training at hire and annually.”
- 16 CFR 314.3(b)(2)Matching language found · high
The program addresses anticipated threats and hazards affecting customer information.
Federal Trade Commission · official source
Automated text screen found a passage matching 71.6% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“The program is designed to protect the security, confidentiality, and integrity of customer information, to protect against reasonably anticipated threats or hazards, and to protect against unauthorized access that could result in substantial harm or inconvenience to any customer.”
- 16 CFR 314.3(b)(3)Matching language found · high
The program addresses unauthorized access or use that could harm customers.
Federal Trade Commission · official source
Automated text screen found a passage matching 83.2% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“The program is designed to protect the security, confidentiality, and integrity of customer information, to protect against reasonably anticipated threats or hazards, and to protect against unauthorized access that could result in substantial harm or inconvenience to any customer.”
- 16 CFR 314.4(b)(2)Matching language found · high
Risk assessment recurs periodically and reexamines risks and safeguard sufficiency.
Federal Trade Commission · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“4. Risk assessment SOP Each January, the Security Lead documents reasonably foreseeable internal and external risks, assesses likelihood and impact, identifies controls, and records residual risk in the risk register.”
- 16 CFR 314.4(c)(1)(i)Matching language found · high
Access controls authenticate users and limit access to authorized users.
Federal Trade Commission · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“5. Access control SOP Only named accounts may access customer information.”
- 16 CFR 314.4(c)(1)(ii)Matching language found · high
Authorized access follows need-to-know and least-privilege principles.
Federal Trade Commission · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“5. Access control SOP Only named accounts may access customer information. The Operations Manager approves access based on job need and least privilege.”
- 16 CFR 314.4(c)(6)(i)Matching language found · high
Secure disposal occurs within the specified period unless a documented rule exception applies.
Federal Trade Commission · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“When retention expires, paper containing customer information is cross-cut shredded by an approved vendor; electronic copies are securely erased or destroyed. Vendor destruction certificates are retained. Exceptions require a documented legal or business reason and a review date. Backups follow the approved deletion schedule. Customer information is disposed of no later than two years after the last date it was used to provide a product or service, unless retention is required by law or a legitimate business need documented in the retention schedule.”
- 16 CFR 314.4(c)(6)(ii)Matching language found · high
The institution periodically reviews retention policy to minimize unnecessary data.
Federal Trade Commission · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“• Evidence item 6: result carried forward to the annual written report to the Managing Partners. Reviewer notes Retention of this evidence follows the retention schedule in Appendix D, and the evidence is not subject to a legal hold.”
- 16 CFR 314.4(c)(7)Matching language found · high
Changes affecting relevant systems and customer information follow documented management procedures.
Federal Trade Commission · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“7. Change management and secure configuration Changes to systems that store or process customer information follow a documented change procedure: request, risk review, approval by the system owner, testing, implementation window, and post-change verification.”
- 16 CFR 314.4(c)(8)Matching language found · high
Authorized-user activity is monitored and logged to detect misuse or tampering involving customer information.
Federal Trade Commission · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“8. Monitoring and logging IT monitors authorized user activity and detects unauthorized access, use of, or tampering with customer information.”
- 16 CFR 314.4(e)(2)Matching language found · high
Sufficient qualified security personnel manage risk and perform or oversee the program.
Federal Trade Commission · official source
Automated text screen found a passage matching 58.8% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Vulnerability scans run monthly; a qualified independent tester performs an annual penetration test. The Security Lead tracks findings to closure and verifies fixes. Activity Frequency Owner Evidence Security awareness training At hire and annually Security Lead Training completion log Phishing simulation Quarterly Security Lead Campaign results and coaching notes Vulnerability scan Monthly IT Administrator Scan report and remediation tickets Penetration test Annually Independent tester Test report and retest letter Security staff updates Ongoing Security Lead Continuing education records 10. Vendor oversight SOP Before a service provider receives customer information, Procurement documents due diligence on its safeguards and incident response.”
- 16 CFR 314.4(f)(1)Matching language found · high
Service-provider selection and retention include reasonable safeguard due diligence.
Federal Trade Commission · official source
Automated text screen found a passage matching 61.1% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Records Manager Maintains the retention schedule, legal holds, disposal log, and vendor destruction certificates. Procurement Performs service provider due diligence before contract signature and keeps contract security clauses current.”
- 16 CFR 314.4(f)(2)Matching language found · high
Contracts require service providers to implement and maintain appropriate safeguards.
Federal Trade Commission · official source
Automated text screen found a passage matching 73.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Vendor oversight SOP Before a service provider receives customer information, Procurement documents due diligence on its safeguards and incident response. Contracts require appropriate security controls and prompt incident notice.”
- 16 CFR 314.4(f)(3)Matching language found · high
Service providers are periodically reassessed according to risk and safeguard adequacy.
Federal Trade Commission · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“The Security Lead reviews critical providers annually and records remediation for material gaps.”
- 16 CFR 314.4(h)(1)Matching language found · high
The plan states response and recovery goals.
Federal Trade Commission · official source
Automated text screen found a passage matching 62.3% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“Restore testing confirmed that backups covering this scope could be recovered within the target recovery time. The Operations Manager confirmed that role changes for staff in this scope were reported within one business day. The reviewer confirmed that the evidence matches the frequency stated in the WISP and that the owner signed the record. Follow-up and escalation If this control fails or evidence is missing, the IT Administrator opens a remediation item within five business days, rates the gap using the scoring matrix in Section 4.2, and notifies the Security Lead. High or critical gaps affecting the business email tenant are reported to the Managing Partners within 30 days, and any related security event is handled under the incident response SOP in Section 11.”
- 16 CFR 314.4(h)(5)Matching language found · high
The plan requires remediation of weaknesses identified during incidents.
Federal Trade Commission · official source
Automated text screen found a passage matching 75.3% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“The Managing Partners were informed of no material weaknesses for this control in the current period. Follow-up and escalation If this control fails or evidence is missing, the Security Lead opens a remediation item within five business days, rates the gap using the scoring matrix in Section 4.2, and notifies the Security Lead. High or critical gaps affecting the seasonal satellite office are reported to the Managing Partners within 30 days, and any related security event is handled under the incident response SOP in Section 11. Closure requires retest evidence.”
- 16 CFR 314.4(h)(6)Matching language found · high
The plan requires security-event and response documentation and reporting.
Federal Trade Commission · official source
Automated text screen found a passage matching 65.9% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“High or critical gaps affecting the paper file room are reported to the Managing Partners within 30 days, and any related security event is handled under the incident response SOP in Section 11. Closure requires retest evidence.”
- 16 CFR 314.4(i)Matching language found · high
The Qualified Individual reports in writing at least annually to the board, equivalent body, or responsible senior officer.
Federal Trade Commission · official source
Automated text screen found a passage matching 100.0% of this requirement's wording concepts or weighted terms. A document statement is not proof that a control operates.
“2. Roles and responsibilities Role Responsibilities Security Lead (Qualified Individual) Owns the WISP, risk assessment, control testing, incident response coordination, vendor reviews, and the annual written report to the Managing Partners.”
- 16 CFR 314.4(a)(1)Not in scope based on answers · high
Using an affiliate or service provider as Qualified Individual does not transfer the institution's responsibility.
Federal Trade Commission · official source
This subparagraph applies only when the Qualified Individual is supplied by an affiliate or service provider.
- 16 CFR 314.4(a)(2)Not in scope based on answers · high
A senior internal person directs and oversees an external Qualified Individual.
Federal Trade Commission · official source
This subparagraph applies only when the Qualified Individual is supplied by an affiliate or service provider.
- 16 CFR 314.4(a)(3)Not in scope based on answers · high
The external Qualified Individual's organization is required to maintain a protective information security program.
Federal Trade Commission · official source
This subparagraph applies only when the Qualified Individual is supplied by an affiliate or service provider.
- 16 CFR 314.4(c)(4)-IN-HOUSENot in scope based on answers · high
Covered in-house applications follow documented secure development practices.
Federal Trade Commission · official source
The institution does not develop in-house applications covered by this clause.
FTC Disposal Rule readiness
Version 0.1.0-draft.1 · DRAFT · 3 checks
- 16 CFR 682.3(b)(5)No matching language · high
An organization subject to the FTC Safeguards Rule integrates covered disposal controls into its written information security program. This paragraph is an illustrative measure.
Federal Trade Commission · official source
Automated text screen found no eligible passage matching at least 30% of this requirement's wording concepts or weighted terms (best match 28.4%).
Suggested fix: Cross-reference Part 682 disposal controls from the WISP and align ownership, testing, and service-provider controls.
- 16 CFR 682.3(a)Partial matching language · critical
The organization uses and monitors reasonable disposal measures for paper, electronic media, and transferred media containing consumer-report information.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (39.3% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“When retention expires, paper containing customer information is cross-cut shredded by an approved vendor; electronic copies are securely erased or destroyed.”
Suggested fix: Adopt a risk-based disposal policy and procedures that render covered information impracticable to read or reconstruct and monitor compliance.
- 16 CFR 682.3(b)(3)Partial matching language · high
When a disposal vendor is used, the organization performs due diligence, contracts for compliant disposal, and monitors performance. This paragraph is an illustrative safe practice, not an exclusive method.
Federal Trade Commission · official source
Coverage is below the strong-match threshold. Automated text screen found only a partial match (40.0% of wording concepts or weighted terms). Review the cited passage against the full requirement; weighted term overlap is not a measure of implementation.
“Records Manager Maintains the retention schedule, legal holds, disposal log, and vendor destruction certificates. Procurement Performs service provider due diligence before contract signature and keeps contract security clauses current.”
Suggested fix: Document vendor selection, contract controls, and monitoring for record-destruction providers.
Limitations
- Preview built on DRAFT rule packs that have not completed independent legal review.
- Produced by a deterministic keyword screen, not by AI and not by a human reviewer; it can miss evidence phrased differently and can match text that does not satisfy the requirement.
- Readiness screening only; not legal advice, an audit, or a certification of compliance.
- Items marked applicability unresolved depend on facts that have not been collected or confirmed yet.
Legal Notice & Disclaimer
This report is provided for informational and readiness-assessment purposes only. It is intended to help identify potential gaps, inconsistencies, or areas for improvement within policies, procedures, SOPs, manuals, and related documentation.
AuditReady does not provide legal advice, regulatory certification, audit opinions, or assurances that an organization is compliant with any law, regulation, standard, or contractual obligation. The presence or absence of a finding in this report does not establish compliance, non-compliance, operational effectiveness, or the adequacy of an organization’s actual practices.
AuditReady is not responsible for the implementation, operation, enforcement, interpretation, or failure to implement any policy, procedure, control, process, or recommendation. Responsibility for business operations, legal compliance, regulatory obligations, internal controls, and organizational decisions remains solely with the organization and its authorized personnel.
AuditReady and its operators disclaim liability, to the fullest extent permitted by applicable law, for any loss, damage, penalty, regulatory action, business interruption, claim, or other consequence arising from reliance on this report, the organization’s operations, or any action or inaction taken in response to the report.
Organizations should consult qualified legal, compliance, security, financial, or other professional advisers where appropriate before making decisions based on this report.