Draft policy scan · US scope

Mortgage lenders and servicers

Get a locked quote and a free policy wording pre-scan for the checks listed below. Your answers confirm the organization's scope.

Draft policy wording checks: free pre-scan and optional paid early-access report. Findings need review. Public uploads must contain no patient data or other restricted information.

Draft checks you can use today

Draft policy checks

FTC Safeguards + Disposal

58 checks · +$0.25 per page

Organizations within the confirmed FTC Safeguards scope. Disposal checks are included; their consumer-report and jurisdiction facts are assessed separately.

US scope only. Applicability answers may exclude checks or leave them unresolved.

Draft policy checks

FTC Red Flags

13 checks · +$0.25 per page

Organizations within the FTC enforcement scope that meet the creditor/financial-institution and covered-account conditions.

US scope only. Applicability answers may exclude checks or leave them unresolved.

The $1.00 base rate applies per page. Disposal checks are included with Safeguards at no additional charge.

Documents to review

  • WISPDraft wording checks available
  • Information security programDraft wording checks available
  • Incident response planDraft wording checks available
  • Risk assessmentDraft wording checks available
  • Retention disposal policyDraft wording checks available
  • Identity theft prevention programDraft wording checks available
  • Servicing policyResearch document type
  • Complaint procedureResearch document type

Scope questions

Industry alone does not establish legal applicability. Confirm location, activities, role, data and relevant thresholds.

  • Card issuer

    Whether the organization issues debit or credit cards within § 681.2.

  • Consumer information held for business purpose

    Whether the organization maintains or possesses consumer information, as defined in § 682.1, for a business purpose.

  • Consumers represented in maintained customer information

    Number of consumers whose customer information the institution maintains; used only for the limited 16 CFR 314.6 exceptions.

  • Covered accounts

    Whether the organization offers or maintains one or more covered accounts after the required risk assessment.

  • Covered-account service providers

    Whether service-provider arrangements involve covered-account activity.

  • Develops covered applications in house

    Whether the institution develops applications used to transmit, access, or store customer information.

  • Effective continuous monitoring

    Whether effective continuous monitoring or equivalent ongoing detection covers information-system vulnerability changes.

  • FTC FCRA enforcement

    Whether the organization is a financial institution or creditor subject to FTC administrative enforcement under the cited FCRA provision. Human legal confirmation is required.

  • FTC jurisdiction

    Whether the organization is a person over which the FTC has jurisdiction. This legal conclusion requires human confirmation.

  • Qualified Individual arrangement

    One of INTERNAL, AFFILIATE, or SERVICE_PROVIDER.

  • Subject to FTC Safeguards Rule

    Whether Part 314 applies to the organization.

  • Uses covered externally developed applications

    Whether externally developed applications transmit, access, or store customer information.

Unknown answers stay unresolved. Document detection does not answer these questions for you.

A fictional example to explore

These sample policies contain intentional gaps. Use them to try the quote and pre-scan flow; they are not adopted policies or complete compliance templates.

PDF pages are counted exactly. DOCX and TXT use the disclosed word-count estimate, so the same policy can have different billable page counts.

Regulations and frameworks to explore

These are research candidates for this profile. Confirm the exact organization and activity before concluding that a rule applies.

Draft policy checks available

FTC Safeguards Rule

16 CFR Part 314

Organizations within the confirmed FTC Safeguards scope. Disposal checks are included; their consumer-report and jurisdiction facts are assessed separately.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Whether the organization maintains or possesses consumer information, as defined in § 682.1, for a business purpose.
  • Number of consumers whose customer information the institution maintains; used only for the limited 16 CFR 314.6 exceptions.
  • Whether the institution develops applications used to transmit, access, or store customer information.
  • Whether effective continuous monitoring or equivalent ongoing detection covers information-system vulnerability changes.
  • Whether the organization is a person over which the FTC has jurisdiction. This legal conclusion requires human confirmation.
  • One of INTERNAL, AFFILIATE, or SERVICE_PROVIDER.
  • Whether Part 314 applies to the organization.
  • Whether externally developed applications transmit, access, or store customer information.
Draft policy checks available

FTC Identity Theft Red Flags Rule

16 CFR Part 681

Organizations within the FTC enforcement scope that meet the creditor/financial-institution and covered-account conditions.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Whether the organization issues debit or credit cards within § 681.2.
  • Whether the organization offers or maintains one or more covered accounts after the required risk assessment.
  • Whether service-provider arrangements involve covered-account activity.
  • Whether the organization is a financial institution or creditor subject to FTC administrative enforcement under the cited FCRA provision. Human legal confirmation is required.
Research only

Regulation X servicing policies and procedures

12 CFR 1024.38

For mortgage servicing within Regulation X Subpart C. Section 1024.30 excludes specified loans and servicers from sections 1024.38–1024.41, including qualifying small servicers subject to the stated exceptions. Confirm the mortgage type and actual servicing role; a small-servicer exemption does not remove every servicing obligation.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Do you service mortgage loans within section 1024.31 rather than only originate or broker them?
  • Do the section 1024.30 loan, small-servicer or other exemptions apply, and which obligations remain?
Research only

Regulation S-P and financial privacy

17 CFR Part 248 · 16 CFR Part 313 · 12 CFR Part 1016

The SEC Regulation S-P regime applies to defined SEC-covered institutions; FTC Part 313 and CFPB Regulation P are separate privacy regimes. The 2024 S-P safeguards and incident-response amendments had phased compliance dates in December 2025 and June 2026. Confirm institution category, covered customer information and the correct regulator before selecting requirements.

Jurisdictions: US-FEDERAL

Research applicability questions
  • Is this an SEC-covered broker-dealer, investment company, registered adviser or covered transfer agent?
  • Which SEC, FTC or CFPB privacy regime governs the institution and consumer relationship?
  • Which 2024 S-P amendment provisions apply to your institution’s category and size?
Research only

NIST Cybersecurity Framework 2.0

NIST CSWP 29

Voluntary cybersecurity risk-management framework for organizations of any size or sector. Customer contracts may request alignment; it is not a law or a certification. Map the selected profile and desired outcomes; do not score optional framework alignment as a legal violation.

Jurisdictions: GLOBAL

Research applicability questions
  • Has your organization or a customer selected a NIST CSF profile or outcomes to evaluate?
  • Does a customer contract, regulator or internal policy require a particular CSF profile or outcome set?