Specimen report

What lands in your file.

This is a complete assessment result, exactly as a plan sponsor receives it — the headline score, every domain, every answer, and the provider’s own written evidence. Read it before you buy anything.

Specimen — not a real assessment

Northwind Recordkeeping LLC” is a fictitious service provider created to illustrate the deliverable. No real provider is described, rated or implied. The scoring is real: every figure below was produced by the same deterministic engine that scores live assessments, from the answers shown.

Northwind Recordkeeping LLC

Recordkeeper · assessed for Ironbridge Retirement Group· submitted 2026-05-14

Rubric v1.0

86.3%

Adequate

Controls are broadly in place with noteworthy shortfalls in one or more domains — none of them automatic fails.

Do this: Retain, but put the specific gaps in writing to the provider with a remediation date, and re-check at the next cycle.

No automatic-fail control was missed.

Where to look first

The three weakest domains, which is what a remediation letter should cover.

Domain 6

Cloud & Sub-Processor Security

60%

3 of 5 controls in place

Domain 11

Strong Technical Controls

67%

4 of 6 controls in place

Domain 4

Security Roles & Responsibilities

80%

4 of 5 controls in place

Every domain

  • 1Cybersecurity ProgramHigh100%6/6
  • 2Annual Risk AssessmentsHigh83%5/6
  • 3Annual Third-Party Audit of ControlsHigh100%5/5
  • 4Security Roles & ResponsibilitiesMedium80%4/5
  • 5Access ControlsHigh100%6/6
  • 6Cloud & Sub-Processor SecurityHigh60%3/5
  • 7Cybersecurity Awareness TrainingMedium80%4/5
  • 8Secure System Development LifecycleMediumN/A
  • 9Business Resiliency (BCP / DR / IR)High80%4/5
  • 10EncryptionHigh100%5/5
  • 11Strong Technical ControlsHigh67%4/6
  • 12Response to Past IncidentsMedium100%2/2

Domain 8 is N/A: this provider writes no software in-house, the one exclusion the methodology permits. N/A answers leave the denominator rather than scoring zero.

The 9 controls not in place

Each with the provider’s own written explanation. This is the part that turns a score into a remediation conversation.

Domain 2 · Q2.3

Does the assessment specifically consider risks to participant PII and plan assets?

Last full risk assessment was 2024-11. The 2025 cycle slipped; scheduled for Q3 2026.

Domain 4 · Q4.4

Do you perform background screening on personnel with access to plan data?

Roles are documented in the ISP but have not been independently reviewed since 2023.

Domain 6 · Q6.3

Do contracts impose security and breach-notification obligations on them?

We collect SOC 2 reports at onboarding but do not re-review them on a set cadence.

Domain 6 · Q6.4

Are sub-processors monitored or reassessed periodically?

Four of our eleven sub-processors have no documented right-to-audit clause.

Domain 7 · Q7.3

Do you conduct phishing simulations?

Annual training is delivered via KnowBe4; we do not currently retain per-employee completion records beyond the current year.

Domain 9 · Q9.3

Are the plans tested at least annually?

Backups run nightly and are monitored, but a full restoration has not been exercised since 2024.

Domain 11 · Q11.3

Do you operate a patch-management program with defined SLAs?

Findings are tracked in Jira. There is no formal remediation SLA by severity.

Domain 11 · Q11.5

Do you centrally log and monitor security events (e.g., SIEM)?

Internal vulnerability scanning is monthly. No independent penetration test has been commissioned.

Domain 12 · Q12.1

Have you experienced any security incident or breach affecting plan or participant data in the last 36 months?

Who they are (Section A)

What is your role with the plan(s), and which plan types are involved? (e.g., plan administrator / fund office, recordkeeper, TPA, actuary, custodian, payroll, investment manager; pension, health & welfare, annuity, training)
Recordkeeper and TPA for defined-contribution plans; also provide participant call-centre services.
Do you create, receive, store, or transmit participant PII (name, SSN, date of birth, financial account data)?
Yes
Approximately how many participants' records do you handle for the plan?
About 84,000 participant records across 210 plans.
Do you store or process Protected Health Information (for health & welfare plans)?
No
Can you initiate, approve, or process distributions, loans, or fund transfers?
Yes
Do you have access to plan bank accounts or the ability to move plan assets?
Yes
Where is plan data hosted? (on-premises, cloud, or hybrid — name providers)
Hybrid — core recordkeeping on-premises in our Columbus data centre, participant portal and reporting in AWS (us-east-2).
Do you rely on sub-processors or fourth parties that can access plan data?
Yes
Do you provide a participant-facing portal, website, or mobile application?
Yes
Have you had a security incident affecting plan or participant data in the last 36 months?
No

All 64 answers

The complete record. On the free tier a sponsor sees the score and the per-domain percentages; the answer-level detail below is what the paid tiers add.

QControlAnswer
1.1Do you maintain a formal, written information security program or policy?Yes
1.2Is the program approved by senior management or the board of directors?Yes
1.3Is it reviewed and updated at least annually?Yes
1.4Is the program aligned to a recognized framework (NIST CSF, ISO 27001, NIST 800-53, or CIS)?Yes
1.5Does it explicitly cover all systems that store or process plan and participant data?Yes
1.6Are policies communicated to and formally acknowledged by personnel?Yes
2.1Do you conduct a formal cybersecurity risk assessment at least annually?Yes
2.2Is the risk-assessment methodology documented?Yes
2.3Does the assessment specifically consider risks to participant PII and plan assets?No
2.4Are findings rated by severity or likelihood/impact?Yes
2.5Are findings tracked to remediation with assigned owners and due dates?Yes
2.6Is the most recent assessment available for independent review?Yes
3.1Do you undergo an independent third-party security audit at least annually (e.g., SOC 2 Type II, ISO 27001)?Yes
3.2Does the audit scope cover the systems and services used to serve this plan?Yes
3.3Is a current report or bridge/gap letter available?Yes
3.4Were exceptions or findings remediated and re-tested?Yes
3.5Do you perform independent penetration testing at least annually?Yes
4.1Have you designated a security leader (CISO or equivalent) with clear authority?Yes
4.2Are information-security roles and responsibilities formally documented?Yes
4.3Does the security function report to senior management or the board?Yes
4.4Do you perform background screening on personnel with access to plan data?No
4.5Are confidentiality and acceptable-use agreements signed by such personnel?Yes
5.1Is multi-factor authentication enforced for all remote and administrative access?Yes
5.2Is access granted on a least-privilege, role-based basis?Yes
5.3Are user access rights reviewed at least quarterly?Yes
5.4Is access revoked within a defined SLA upon termination or role change?Yes
5.5Are unique credentials required, with no shared or generic accounts?Yes
5.6Is privileged access separately managed and monitored?Yes
6.1Do you maintain an inventory of sub-processors and fourth parties with access to plan data?Yes
6.2Are sub-processors security-assessed before onboarding?Yes
6.3Do contracts impose security and breach-notification obligations on them?No
6.4Are sub-processors monitored or reassessed periodically?No
6.5Are cloud environments configured to a recognized benchmark (e.g., CIS) and reviewed?Yes
7.1Is security-awareness training required for all personnel at least annually?Yes
7.2Does training cover phishing, social engineering, and identity theft?Yes
7.3Do you conduct phishing simulations?No
7.4Is enhanced or role-based training provided to privileged users?Yes
7.5Is completion tracked and enforced?Yes
8.1Do you follow a documented secure development lifecycle for software that handles plan data?N/A
8.2Are security reviews or code analysis (SAST/DAST) part of the process?N/A
8.3Are applications penetration tested at least annually?N/A
8.4Do you operate a vulnerability-management program with remediation SLAs by severity?N/A
8.5Are development, test, and production environments separated, with no live participant data in test?N/A
9.1Do you maintain documented business-continuity and disaster-recovery plans?Yes
9.2Are recovery objectives (RTO/RPO) defined for systems handling plan data?Yes
9.3Are the plans tested at least annually?No
9.4Do you maintain an incident-response plan with defined roles and escalation paths?Yes
9.5Are backups performed, tested, and protected with offline or immutable copies?Yes
10.1Is sensitive and participant data encrypted at rest using a strong standard (e.g., AES-256)?Yes
10.2Is data encrypted in transit (TLS 1.2 or higher)?Yes
10.3Does encryption extend to backups and portable or removable media?Yes
10.4Are encryption standards documented?Yes
10.5Are encryption keys securely managed (rotation, separation of duties)?Yes
11.1Do you deploy and maintain network protections (firewalls, IDS/IPS)?Yes
11.2Do you use endpoint protection or EDR on systems that access plan data?Yes
11.3Do you operate a patch-management program with defined SLAs?No
11.4Is the environment segmented to isolate systems holding participant data?Yes
11.5Do you centrally log and monitor security events (e.g., SIEM)?No
11.6Are systems hardened to a documented configuration baseline?Yes
12.1Have you experienced any security incident or breach affecting plan or participant data in the last 36 months?No
12.2If so, were affected plans, participants, and regulators notified per legal requirements?N/A
12.3Was a documented root-cause analysis performed?N/A
12.4Was remediation completed and independently verified?N/A
12.5Do your contracts specify breach-notification timelines to the plan?Yes

Want this for your own providers?

Send a provider a link. They answer once, with no account. The result lands on your dashboard, scored against the published rubric.

Start an assessment