Compliance guide

ALTA Best Practices 5.0: the IT checklist for title agencies

Version 5.0 of the ALTA Best Practices takes effect October 8, 2026. Here is what it asks of your technology, in plain English, with a checklist you can hand to whoever manages your IT.

Not legal advice. This guide summarizes the technology items in ALTA's published framework. Read the framework itself and talk to your underwriter or counsel about how it applies to your agency.

The short version

For IT purposes, two pillars matter. Pillar 3 asks you to write down how you protect client information and then actually do it. Pillar 2 asks you to have a tested procedure for wires, including how you verify instructions and what you do if a wire goes to a criminal.

Pillar 3: Information Security and Privacy Plans

The Pillar 3 practice reads: "Adopt and maintain a written information security plan ('WISP') and a written privacy plan to protect NPI as required by local, state, and federal law." NPI means non-public personal information, such as Social Security numbers, bank account details, and driver's license numbers.

The framework lists what the written plan should address. Here is each item with what it means in a small office:

What the framework calls forWhat that looks like in practice
Multi-factor authentication, if available, for systems containing NPITwo-step sign-in on every mailbox, your closing software, and file storage
A password plan aligned with NIST guidance (8 or more characters)A password manager, no shared logins, and blocking known-breached passwords
Timely software updatesAutomatic updates on every computer, with someone confirming they actually install
Physical securityLocked screens, locked file rooms, and a clean-desk habit for closing files
Network and cloud securityA managed firewall, separate guest Wi-Fi, and properly configured Microsoft 365 or Google Workspace
Acceptable-use guidelinesA one-page policy on personal devices, personal email, and where files may be stored
Encryption in transit and at rest, to the extent feasibleEncrypted email for NPI and disk encryption on every laptop
MonitoringSign-in alerts and mailbox auditing, reviewed by a person

Pillar 3 also calls for tested business-continuity and incident-response plans, and annual cybersecurity training that covers social engineering.

Pillar 2: the wire transfer rules

Wire controls are part of Pillar 2 (escrow trust accounting), not Pillar 3. Three items involve your IT:

  • A written wire procedure, tested annually. Outgoing wire instructions must be verified "independent of the initial communication," using multi-factor verification, and consumers should be warned about incoming-wire fraud.
  • Wire verification providers, to be used "if available, efficient, and economical."
  • A written wire fraud response procedure that incorporates the ALTA Rapid Response Plan and is reviewed annually. See our wire fraud response guide.

The framework is written at the level of plans and controls, not specific email settings. Locking your domain so email can't be forged from it is one practical way to protect the wire communications these rules are about. You can check your domain in seconds.

The IT checklist

  1. Two-step sign-in is on for every mailbox and every system that holds NPI.
  2. Your domain refuses forged email (DMARC set to reject), and someone reviews the reports.
  3. Every computer updates automatically and has an encrypted disk.
  4. NPI leaves the office only by encrypted email or a secure portal.
  5. Sign-in alerts and mailbox auditing are on, and someone looks at them.
  6. Accounts are removed the day someone leaves.
  7. Your written information security plan describes what you actually do.
  8. Your wire procedure and wire fraud response plan are written, and were tested in the last 12 months.
  9. Staff completed cybersecurity training in the last 12 months.
  10. You can produce documentation of all of the above when an assessor or underwriter asks.

Sources

Common questions

When does ALTA Best Practices 5.0 take effect?

ALTA lists Version 5.0 as approved by its Board on June 23, 2026 and effective October 8, 2026. It replaces Version 4.2.

Which pillar covers IT and information security?

Pillar 3, titled Information Security and Privacy Plans. It calls for a written information security plan (a WISP) and a written privacy plan to protect non-public personal information. Wire transfer controls sit in Pillar 2, which covers escrow trust accounting.

Is multi-factor authentication required under ALTA Best Practices?

The Pillar 3 written information security plan calls for multi-factor authentication, if available, on systems containing non-public personal information. Pillar 2 also calls for multi-factor verification when confirming outgoing wire instructions. In practice, every mailbox and every system holding client data should have it.

Does a small title agency really need a written information security plan?

Yes. Pillar 3 applies regardless of size, and the federal FTC Safeguards Rule separately requires a written information security program for settlement service providers. A short, accurate plan that matches what you actually do is far better than a long template nobody follows.