ALTA Best Practices 5.0: the IT checklist for title agencies
Version 5.0 of the ALTA Best Practices takes effect October 8, 2026. Here is what it asks of your technology, in plain English, with a checklist you can hand to whoever manages your IT.
The short version
For IT purposes, two pillars matter. Pillar 3 asks you to write down how you protect client information and then actually do it. Pillar 2 asks you to have a tested procedure for wires, including how you verify instructions and what you do if a wire goes to a criminal.
Pillar 3: Information Security and Privacy Plans
The Pillar 3 practice reads: "Adopt and maintain a written information security plan ('WISP') and a written privacy plan to protect NPI as required by local, state, and federal law." NPI means non-public personal information, such as Social Security numbers, bank account details, and driver's license numbers.
The framework lists what the written plan should address. Here is each item with what it means in a small office:
| What the framework calls for | What that looks like in practice |
|---|---|
| Multi-factor authentication, if available, for systems containing NPI | Two-step sign-in on every mailbox, your closing software, and file storage |
| A password plan aligned with NIST guidance (8 or more characters) | A password manager, no shared logins, and blocking known-breached passwords |
| Timely software updates | Automatic updates on every computer, with someone confirming they actually install |
| Physical security | Locked screens, locked file rooms, and a clean-desk habit for closing files |
| Network and cloud security | A managed firewall, separate guest Wi-Fi, and properly configured Microsoft 365 or Google Workspace |
| Acceptable-use guidelines | A one-page policy on personal devices, personal email, and where files may be stored |
| Encryption in transit and at rest, to the extent feasible | Encrypted email for NPI and disk encryption on every laptop |
| Monitoring | Sign-in alerts and mailbox auditing, reviewed by a person |
Pillar 3 also calls for tested business-continuity and incident-response plans, and annual cybersecurity training that covers social engineering.
Pillar 2: the wire transfer rules
Wire controls are part of Pillar 2 (escrow trust accounting), not Pillar 3. Three items involve your IT:
- A written wire procedure, tested annually. Outgoing wire instructions must be verified "independent of the initial communication," using multi-factor verification, and consumers should be warned about incoming-wire fraud.
- Wire verification providers, to be used "if available, efficient, and economical."
- A written wire fraud response procedure that incorporates the ALTA Rapid Response Plan and is reviewed annually. See our wire fraud response guide.
The framework is written at the level of plans and controls, not specific email settings. Locking your domain so email can't be forged from it is one practical way to protect the wire communications these rules are about. You can check your domain in seconds.
The IT checklist
- Two-step sign-in is on for every mailbox and every system that holds NPI.
- Your domain refuses forged email (DMARC set to reject), and someone reviews the reports.
- Every computer updates automatically and has an encrypted disk.
- NPI leaves the office only by encrypted email or a secure portal.
- Sign-in alerts and mailbox auditing are on, and someone looks at them.
- Accounts are removed the day someone leaves.
- Your written information security plan describes what you actually do.
- Your wire procedure and wire fraud response plan are written, and were tested in the last 12 months.
- Staff completed cybersecurity training in the last 12 months.
- You can produce documentation of all of the above when an assessor or underwriter asks.
Sources
- ALTA Best Practices (American Land Title Association), Version 5.0 framework
- ALTA Rapid Response Plan for Wire Fraud Incidents
Common questions
When does ALTA Best Practices 5.0 take effect?
ALTA lists Version 5.0 as approved by its Board on June 23, 2026 and effective October 8, 2026. It replaces Version 4.2.
Which pillar covers IT and information security?
Pillar 3, titled Information Security and Privacy Plans. It calls for a written information security plan (a WISP) and a written privacy plan to protect non-public personal information. Wire transfer controls sit in Pillar 2, which covers escrow trust accounting.
Is multi-factor authentication required under ALTA Best Practices?
The Pillar 3 written information security plan calls for multi-factor authentication, if available, on systems containing non-public personal information. Pillar 2 also calls for multi-factor verification when confirming outgoing wire instructions. In practice, every mailbox and every system holding client data should have it.
Does a small title agency really need a written information security plan?
Yes. Pillar 3 applies regardless of size, and the federal FTC Safeguards Rule separately requires a written information security program for settlement service providers. A short, accurate plan that matches what you actually do is far better than a long template nobody follows.