ALTA Best Practices Pillar 3: A WISP Guide for Title Agencies
ALTA Best Practices Pillar 3 covers one thing: protecting non-public personal information, or NPI. It requires a Written Information Security Plan, known as a WISP. The American Land Title Association, or ALTA, created and maintains ALTA Best Practices, a voluntary framework for title companies. It is not a federal law. Lenders require it by contract, not by government mandate.
If a lender partner is asking you to prove ALTA Best Practices compliance, this guide explains what that actually means. We’ll cover the seven-pillar framework briefly, then focus the rest of the page on Pillar 3, the one most lenders and assessors scrutinize hardest: protecting client data through a written security plan.
The Seven Pillars at a Glance
ALTA Best Practices organizes a title or settlement company’s operations into seven areas. Each pillar covers a different risk category, from how you’re licensed to how you handle complaints.
| Pillar | Focus Area |
|---|---|
| 1 | Licensing |
| 2 | Escrow and trust accounting |
| 3 | Protecting NPI (WISP and written privacy plan) |
| 4 | Settlement processes |
| 5 | Policy production |
| 6 | Insurance coverage (E&O, fidelity, and surety) |
| 7 | Consumer complaints |
This guide focuses on Pillar 3 for the rest of the page. It carries the most technical requirements of the seven pillars. It’s also the pillar an independent assessor or a lender’s own compliance team tends to dig into hardest, because it’s the one tied directly to data breaches and fraud losses.
Why Your Lender Is the One Enforcing This
ALTA Best Practices isn’t a law. No government agency audits your title company against it. So why does your lender’s compliance team keep asking you to prove it?
The answer traces back to a 2012 regulatory bulletin. The CFPB’s Bulletin 2012-03 put mortgage lenders on notice. It said lenders are responsible for managing the risk of their service providers. Title and settlement agents count as service providers under that bulletin.
In practice, that regulatory pressure flows downhill to you:
- Lenders have to vet every vendor, including the title company, who touches a loan file.
- A data breach or a fraud loss at your company creates real liability for the lender who referred the business to you.
- Major lenders, including Wells Fargo, require their approved title and closing partners to demonstrate ALTA Best Practices adherence. That’s typically verified through an independent third-party certification, not a lender’s own audit.
That’s why your lender’s onboarding checklist mentions ALTA Best Practices at all. They’re managing their own regulatory exposure, not yours. Your WISP, and the rest of your Pillar 3 documentation, is how you answer that request without a scramble every time a new lender relationship comes up.
What Pillar 3 Requires: The WISP and Written Privacy Plan
Pillar 3 requires two things: a Written Information Security Plan and a written privacy plan. Together, they document how you protect non-public personal information under applicable law.

A WISP isn’t a single file you sign once and file away. It’s a set of policies that work together to define how your company actually operates day to day. Common components of a WISP include:
- Acceptable Use Policy: rules for how employees use company systems, email, and client data.
- Vendor Management Policy: how you vet the security practices of contractors, software vendors, and other third parties who touch your systems or your clients’ NPI.
- Disaster Recovery Plan: how you keep operating, and keep client data protected, if a system goes down or an incident hits.
ALTA knows this structure trips people up.
Pillar 3 doesn’t ask for a single generic security policy. It asks for a WISP and a written privacy plan, working together, that actually match how your company handles NPI.
The written privacy plan is a related but distinct piece. Where the WISP covers how you secure systems and vet vendors, the privacy plan covers how you collect, use, and disclose NPI in the first place, and who in your company is accountable for that. An assessor reviewing you for Pillar 3 wants to see both: the technical and operational security plan, and the privacy plan that governs the data itself. Missing either one is a common reason title agencies fail their first Best Practices assessment.
The Technical Controls Pillar 3 Actually Expects
A WISP isn’t just paperwork. Pillar 3 names specific technical controls an assessor checks for directly. If any of these are missing, the paperwork won’t save you.

- Multi-factor authentication (MFA). Every system touching NPI needs a second verification step beyond a password. See our guide to how MFA works if you’re still rolling this out. – Documented password management. You need a written policy, not just a good habit. The old standard leaned on periodic password expiration. The new one requires a forced reset when a “triggering event” happens, like a known or suspected compromise. Our password policy guide breaks down what that looks like in practice. – Patched and updated software. Outdated software with known vulnerabilities is one of the easiest ways in for an attacker. Pillar 3 expects a documented patching cadence, not ad hoc updates. – Vendor and third-party vetting. Every contractor, consultant, or third-party system touching your data needs review. Their security policies have to line up with your own WISP.
ALTA’s 2024 revision requires a password reset triggered by a suspected compromise, not just a periodic expiration schedule, aligning Pillar 3 with current NIST digital-identity guidance.
What a WISP Looks Like in Practice for a Title Agency
A WISP is a set of connected policies, not one document. Here’s how the pieces typically break down for a title or settlement company.
| Policy | What It Covers | Who Typically Owns It |
|---|---|---|
| Acceptable Use Policy | Rules for employee use of company systems, email, and client data | Office manager or HR, with IT sign-off |
| Vendor Management Policy | Vetting security practices of contractors, software vendors, and other third parties | Compliance officer or principal |
| Disaster Recovery Plan | Keeping operations running and data protected during an outage or incident | IT/MSP partner |
| Access Control Policy | Who can reach which systems and NPI, and how that access is reviewed | IT/MSP partner |
| Incident Response Plan | Steps to take the moment a breach or suspected breach is identified | Compliance officer, executed with IT |
| Employee Training Policy | How and how often staff are trained on phishing, fraud, and data handling | Office manager or compliance officer |
No single person owns the whole WISP. That’s by design. Security is spread across roles the same way the risk is.
Common Gaps LeadingIT Sees in Title Agency Environments
Most title agencies don’t fail Pillar 3 because they ignored it. They fail because the pieces never got connected.
- MFA is enabled on email but not on the title production software itself.
- A password policy exists on paper but nobody enforces the reset-on-compromise trigger.
- Vendor contracts were signed years ago, before anyone asked the vendor about their own security practices.
- Patching happens “when someone notices,” not on a documented schedule.
- The WISP references a disaster recovery plan that was never actually written down.
Each gap on its own looks small. An assessor reviewing the whole picture sees a WISP that exists in name only. This is the part of Pillar 3 that’s genuinely technical work, not just documentation. It’s also the part LeadingIT was built to handle. See our managed IT services for title and settlement companies for the full picture. LeadingIT doesn’t issue the ALTA Best Practices certification itself. That’s an independent third-party assessment. LeadingIT builds and maintains the technical controls a title agency needs to pass one.
How This Connects to Fraud Prevention
Pillar 3’s vendor and access controls aren’t just a compliance checkbox. They’re also your first defense against the fraud schemes actually hitting title companies right now.
Seller impersonation fraud (SIF) is one of the sharpest examples. A criminal poses as the true property owner, often using stolen identity documents, to sell or borrow against a property and steal the closing proceeds. ALTA’s own guidance flags vacant lots and mortgage-free properties as the highest-risk targets, since there’s no lender or occupant present to catch it early.
The numbers show how common this has become:
| Finding | What It Measures |
|---|---|
| Only about 8% of attempted wire fraud schemes succeeded | Where training and verification procedures were in place |
Business email compromise (BEC) drives most of this. It’s the technique behind the fraudulent wiring instructions and impersonation emails that target closings. Nationally, BEC alone has driven billions in reported losses across all industries. ALTA’s own Information Security Committee publishes two tools built specifically for this: an Outgoing Wire Preparation Checklist that requires verifying wiring instructions through an independently sourced phone number, never one supplied in the email itself, and a Rapid Response Plan so staff have a pre-built action plan the moment fraud is suspected.
This is why Pillar 3 and fraud prevention aren’t two separate projects. The same vendor vetting, access controls, and staff training that satisfy your WISP also close the door BEC-driven wire fraud walks through. For the full breakdown of how seller impersonation fraud works and what to watch for, see our seller impersonation fraud guide for title companies.
See Where You Stand
You don’t have to guess where your WISP has gaps. Answer a few plain-English questions about your MFA, password management, and vendor controls, and get your readiness level plus the specific gaps to close before your next lender assessment. No sign-up required to see your result.
Take the free 2-minute ALTA Best Practices Pillar 3 risk-check
Related Guides
- Seller Impersonation Fraud: What Title Companies Need to Know
- ALTA Best Practices Pillar 3 Assessment: What to Expect
- How to Write a WISP: A Step-by-Step Template for Small Businesses
- Vendor Management for Title Agencies: Meeting Lender Requirements
Frequently Asked Questions
A WISP, or Written Information Security Plan, is a set of policies that together define how a company protects non-public personal information. It typically includes an acceptable use policy, a vendor management policy, and a disaster recovery plan, among others. It is not one single document but a coordinated set of written rules covering how systems, vendors, and data are handled.
No. ALTA Best Practices is a voluntary industry framework created by the American Land Title Association, not a federal or state law. Title companies adopt it because mortgage lenders require it contractually, largely due to regulatory pressure on lenders to manage the risk of their service-provider relationships.
There is no single government body that certifies ALTA Best Practices compliance. Compliance is typically demonstrated to lenders through an independent third-party assessment against the seven pillars, rather than through a government audit. ALTA itself maintains the framework but does not act as the certifying body for individual title companies.
There is no government fine for noncompliance since ALTA Best Practices is not a law. The real consequence is business risk: losing lender-approved-vendor status, facing errors and omissions liability if a WISP gap contributes to a breach or fraud loss, and reputational damage in a referral-driven business. Lenders can and do stop referring business to title companies that can’t demonstrate compliance.
Ready to Close Your Pillar 3 Gaps?
Building a WISP that actually holds up to a lender’s assessor takes real technical work, not just a policy template. LeadingIT builds and maintains the MFA, password management, patching, and vendor documentation your title agency needs for Pillar 3, backed by our managed IT services for title and settlement companies. Book a call to talk through where your agency stands, or contact us with questions.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
