Draft policy scan · US scope

Auto dealers that finance or lease

Get a locked quote and a free policy wording pre-scan for the checks listed below. Your answers confirm the organization's scope.

Draft policy wording checks: free pre-scan and optional paid early-access report. Findings need review. Public uploads must contain no patient data or other restricted information.

Draft checks you can use today

Draft policy checks

FTC Safeguards + Disposal

58 checks · +$0.25 per page

Organizations within the confirmed FTC Safeguards scope. Disposal checks are included; their consumer-report and jurisdiction facts are assessed separately.

US scope only. Applicability answers may exclude checks or leave them unresolved.

Draft policy checks

FTC Red Flags

13 checks · +$0.25 per page

Organizations within the FTC enforcement scope that meet the creditor/financial-institution and covered-account conditions.

US scope only. Applicability answers may exclude checks or leave them unresolved.

The $1.00 base rate applies per page. Disposal checks are included with Safeguards at no additional charge.

Documents to review

  • WISPDraft wording checks available
  • Information security programDraft wording checks available
  • Incident response planDraft wording checks available
  • Risk assessmentDraft wording checks available
  • Retention disposal policyDraft wording checks available
  • Identity theft prevention programDraft wording checks available

Scope questions

Industry alone does not establish legal applicability. Confirm location, activities, role, data and relevant thresholds.

  • Card issuer

    Whether the organization issues debit or credit cards within § 681.2.

  • Consumer information held for business purpose

    Whether the organization maintains or possesses consumer information, as defined in § 682.1, for a business purpose.

  • Consumers represented in maintained customer information

    Number of consumers whose customer information the institution maintains; used only for the limited 16 CFR 314.6 exceptions.

  • Covered accounts

    Whether the organization offers or maintains one or more covered accounts after the required risk assessment.

  • Covered-account service providers

    Whether service-provider arrangements involve covered-account activity.

  • Develops covered applications in house

    Whether the institution develops applications used to transmit, access, or store customer information.

  • Effective continuous monitoring

    Whether effective continuous monitoring or equivalent ongoing detection covers information-system vulnerability changes.

  • FTC FCRA enforcement

    Whether the organization is a financial institution or creditor subject to FTC administrative enforcement under the cited FCRA provision. Human legal confirmation is required.

  • FTC jurisdiction

    Whether the organization is a person over which the FTC has jurisdiction. This legal conclusion requires human confirmation.

  • Qualified Individual arrangement

    One of INTERNAL, AFFILIATE, or SERVICE_PROVIDER.

  • Subject to FTC Safeguards Rule

    Whether Part 314 applies to the organization.

  • Uses covered externally developed applications

    Whether externally developed applications transmit, access, or store customer information.

Unknown answers stay unresolved. Document detection does not answer these questions for you.

A fictional example to explore

These sample policies contain intentional gaps. Use them to try the quote and pre-scan flow; they are not adopted policies or complete compliance templates.

PDF pages are counted exactly. DOCX and TXT use the disclosed word-count estimate, so the same policy can have different billable page counts.

Regulations and frameworks to explore

These are research candidates for this profile. Confirm the exact organization and activity before concluding that a rule applies.

Draft policy checks available

FTC Safeguards Rule

16 CFR Part 314

Organizations within the confirmed FTC Safeguards scope. Disposal checks are included; their consumer-report and jurisdiction facts are assessed separately.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Whether the organization maintains or possesses consumer information, as defined in § 682.1, for a business purpose.
  • Number of consumers whose customer information the institution maintains; used only for the limited 16 CFR 314.6 exceptions.
  • Whether the institution develops applications used to transmit, access, or store customer information.
  • Whether effective continuous monitoring or equivalent ongoing detection covers information-system vulnerability changes.
  • Whether the organization is a person over which the FTC has jurisdiction. This legal conclusion requires human confirmation.
  • One of INTERNAL, AFFILIATE, or SERVICE_PROVIDER.
  • Whether Part 314 applies to the organization.
  • Whether externally developed applications transmit, access, or store customer information.
Draft policy checks available

FTC Identity Theft Red Flags Rule

16 CFR Part 681

Organizations within the FTC enforcement scope that meet the creditor/financial-institution and covered-account conditions.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Whether the organization issues debit or credit cards within § 681.2.
  • Whether the organization offers or maintains one or more covered accounts after the required risk assessment.
  • Whether service-provider arrangements involve covered-account activity.
  • Whether the organization is a financial institution or creditor subject to FTC administrative enforcement under the cited FCRA provision. Human legal confirmation is required.
Research only

NIST Cybersecurity Framework 2.0

NIST CSWP 29

Voluntary cybersecurity risk-management framework for organizations of any size or sector. Customer contracts may request alignment; it is not a law or a certification. Map the selected profile and desired outcomes; do not score optional framework alignment as a legal violation.

Jurisdictions: GLOBAL

Research applicability questions
  • Has your organization or a customer selected a NIST CSF profile or outcomes to evaluate?
  • Does a customer contract, regulator or internal policy require a particular CSF profile or outcome set?