Specimen report
What lands in your file.
This is a complete assessment result, exactly as a plan sponsor receives it — the headline score, every domain, every answer, and the provider’s own written evidence. Read it before you buy anything.
Specimen — not a real assessment
“Northwind Recordkeeping LLC” is a fictitious service provider created to illustrate the deliverable. No real provider is described, rated or implied. The scoring is real: every figure below was produced by the same deterministic engine that scores live assessments, from the answers shown.
Northwind Recordkeeping LLC
Recordkeeper · assessed for Ironbridge Retirement Group· submitted 2026-05-14
Rubric v1.0
86.3%
AdequateControls are broadly in place with noteworthy shortfalls in one or more domains — none of them automatic fails.
Do this: Retain, but put the specific gaps in writing to the provider with a remediation date, and re-check at the next cycle.
No automatic-fail control was missed.
Where to look first
The three weakest domains, which is what a remediation letter should cover.
Domain 6
Cloud & Sub-Processor Security
60%
3 of 5 controls in place
Domain 11
Strong Technical Controls
67%
4 of 6 controls in place
Domain 4
Security Roles & Responsibilities
80%
4 of 5 controls in place
Every domain
- 1Cybersecurity ProgramHigh100%6/6
- 2Annual Risk AssessmentsHigh83%5/6
- 3Annual Third-Party Audit of ControlsHigh100%5/5
- 4Security Roles & ResponsibilitiesMedium80%4/5
- 5Access ControlsHigh100%6/6
- 6Cloud & Sub-Processor SecurityHigh60%3/5
- 7Cybersecurity Awareness TrainingMedium80%4/5
- 8Secure System Development LifecycleMediumN/A
- 9Business Resiliency (BCP / DR / IR)High80%4/5
- 10EncryptionHigh100%5/5
- 11Strong Technical ControlsHigh67%4/6
- 12Response to Past IncidentsMedium100%2/2
Domain 8 is N/A: this provider writes no software in-house, the one exclusion the methodology permits. N/A answers leave the denominator rather than scoring zero.
The 9 controls not in place
Each with the provider’s own written explanation. This is the part that turns a score into a remediation conversation.
Domain 2 · Q2.3
Does the assessment specifically consider risks to participant PII and plan assets?
“Last full risk assessment was 2024-11. The 2025 cycle slipped; scheduled for Q3 2026.”
Domain 4 · Q4.4
Do you perform background screening on personnel with access to plan data?
“Roles are documented in the ISP but have not been independently reviewed since 2023.”
Domain 6 · Q6.3
Do contracts impose security and breach-notification obligations on them?
“We collect SOC 2 reports at onboarding but do not re-review them on a set cadence.”
Domain 6 · Q6.4
Are sub-processors monitored or reassessed periodically?
“Four of our eleven sub-processors have no documented right-to-audit clause.”
Domain 7 · Q7.3
Do you conduct phishing simulations?
“Annual training is delivered via KnowBe4; we do not currently retain per-employee completion records beyond the current year.”
Domain 9 · Q9.3
Are the plans tested at least annually?
“Backups run nightly and are monitored, but a full restoration has not been exercised since 2024.”
Domain 11 · Q11.3
Do you operate a patch-management program with defined SLAs?
“Findings are tracked in Jira. There is no formal remediation SLA by severity.”
Domain 11 · Q11.5
Do you centrally log and monitor security events (e.g., SIEM)?
“Internal vulnerability scanning is monthly. No independent penetration test has been commissioned.”
Domain 12 · Q12.1
Have you experienced any security incident or breach affecting plan or participant data in the last 36 months?
Who they are (Section A)
- What is your role with the plan(s), and which plan types are involved? (e.g., plan administrator / fund office, recordkeeper, TPA, actuary, custodian, payroll, investment manager; pension, health & welfare, annuity, training)
- Recordkeeper and TPA for defined-contribution plans; also provide participant call-centre services.
- Do you create, receive, store, or transmit participant PII (name, SSN, date of birth, financial account data)?
- Yes
- Approximately how many participants' records do you handle for the plan?
- About 84,000 participant records across 210 plans.
- Do you store or process Protected Health Information (for health & welfare plans)?
- No
- Can you initiate, approve, or process distributions, loans, or fund transfers?
- Yes
- Do you have access to plan bank accounts or the ability to move plan assets?
- Yes
- Where is plan data hosted? (on-premises, cloud, or hybrid — name providers)
- Hybrid — core recordkeeping on-premises in our Columbus data centre, participant portal and reporting in AWS (us-east-2).
- Do you rely on sub-processors or fourth parties that can access plan data?
- Yes
- Do you provide a participant-facing portal, website, or mobile application?
- Yes
- Have you had a security incident affecting plan or participant data in the last 36 months?
- No
All 64 answers
The complete record. On the free tier a sponsor sees the score and the per-domain percentages; the answer-level detail below is what the paid tiers add.
| Q | Control | Answer |
|---|---|---|
| 1.1 | Do you maintain a formal, written information security program or policy? | Yes |
| 1.2 | Is the program approved by senior management or the board of directors? | Yes |
| 1.3 | Is it reviewed and updated at least annually? | Yes |
| 1.4 | Is the program aligned to a recognized framework (NIST CSF, ISO 27001, NIST 800-53, or CIS)? | Yes |
| 1.5 | Does it explicitly cover all systems that store or process plan and participant data? | Yes |
| 1.6 | Are policies communicated to and formally acknowledged by personnel? | Yes |
| 2.1 | Do you conduct a formal cybersecurity risk assessment at least annually? | Yes |
| 2.2 | Is the risk-assessment methodology documented? | Yes |
| 2.3 | Does the assessment specifically consider risks to participant PII and plan assets? | No |
| 2.4 | Are findings rated by severity or likelihood/impact? | Yes |
| 2.5 | Are findings tracked to remediation with assigned owners and due dates? | Yes |
| 2.6 | Is the most recent assessment available for independent review? | Yes |
| 3.1 | Do you undergo an independent third-party security audit at least annually (e.g., SOC 2 Type II, ISO 27001)? | Yes |
| 3.2 | Does the audit scope cover the systems and services used to serve this plan? | Yes |
| 3.3 | Is a current report or bridge/gap letter available? | Yes |
| 3.4 | Were exceptions or findings remediated and re-tested? | Yes |
| 3.5 | Do you perform independent penetration testing at least annually? | Yes |
| 4.1 | Have you designated a security leader (CISO or equivalent) with clear authority? | Yes |
| 4.2 | Are information-security roles and responsibilities formally documented? | Yes |
| 4.3 | Does the security function report to senior management or the board? | Yes |
| 4.4 | Do you perform background screening on personnel with access to plan data? | No |
| 4.5 | Are confidentiality and acceptable-use agreements signed by such personnel? | Yes |
| 5.1 | Is multi-factor authentication enforced for all remote and administrative access? | Yes |
| 5.2 | Is access granted on a least-privilege, role-based basis? | Yes |
| 5.3 | Are user access rights reviewed at least quarterly? | Yes |
| 5.4 | Is access revoked within a defined SLA upon termination or role change? | Yes |
| 5.5 | Are unique credentials required, with no shared or generic accounts? | Yes |
| 5.6 | Is privileged access separately managed and monitored? | Yes |
| 6.1 | Do you maintain an inventory of sub-processors and fourth parties with access to plan data? | Yes |
| 6.2 | Are sub-processors security-assessed before onboarding? | Yes |
| 6.3 | Do contracts impose security and breach-notification obligations on them? | No |
| 6.4 | Are sub-processors monitored or reassessed periodically? | No |
| 6.5 | Are cloud environments configured to a recognized benchmark (e.g., CIS) and reviewed? | Yes |
| 7.1 | Is security-awareness training required for all personnel at least annually? | Yes |
| 7.2 | Does training cover phishing, social engineering, and identity theft? | Yes |
| 7.3 | Do you conduct phishing simulations? | No |
| 7.4 | Is enhanced or role-based training provided to privileged users? | Yes |
| 7.5 | Is completion tracked and enforced? | Yes |
| 8.1 | Do you follow a documented secure development lifecycle for software that handles plan data? | N/A |
| 8.2 | Are security reviews or code analysis (SAST/DAST) part of the process? | N/A |
| 8.3 | Are applications penetration tested at least annually? | N/A |
| 8.4 | Do you operate a vulnerability-management program with remediation SLAs by severity? | N/A |
| 8.5 | Are development, test, and production environments separated, with no live participant data in test? | N/A |
| 9.1 | Do you maintain documented business-continuity and disaster-recovery plans? | Yes |
| 9.2 | Are recovery objectives (RTO/RPO) defined for systems handling plan data? | Yes |
| 9.3 | Are the plans tested at least annually? | No |
| 9.4 | Do you maintain an incident-response plan with defined roles and escalation paths? | Yes |
| 9.5 | Are backups performed, tested, and protected with offline or immutable copies? | Yes |
| 10.1 | Is sensitive and participant data encrypted at rest using a strong standard (e.g., AES-256)? | Yes |
| 10.2 | Is data encrypted in transit (TLS 1.2 or higher)? | Yes |
| 10.3 | Does encryption extend to backups and portable or removable media? | Yes |
| 10.4 | Are encryption standards documented? | Yes |
| 10.5 | Are encryption keys securely managed (rotation, separation of duties)? | Yes |
| 11.1 | Do you deploy and maintain network protections (firewalls, IDS/IPS)? | Yes |
| 11.2 | Do you use endpoint protection or EDR on systems that access plan data? | Yes |
| 11.3 | Do you operate a patch-management program with defined SLAs? | No |
| 11.4 | Is the environment segmented to isolate systems holding participant data? | Yes |
| 11.5 | Do you centrally log and monitor security events (e.g., SIEM)? | No |
| 11.6 | Are systems hardened to a documented configuration baseline? | Yes |
| 12.1 | Have you experienced any security incident or breach affecting plan or participant data in the last 36 months? | No |
| 12.2 | If so, were affected plans, participants, and regulators notified per legal requirements? | N/A |
| 12.3 | Was a documented root-cause analysis performed? | N/A |
| 12.4 | Was remediation completed and independently verified? | N/A |
| 12.5 | Do your contracts specify breach-notification timelines to the plan? | Yes |
Want this for your own providers?
Send a provider a link. They answer once, with no account. The result lands on your dashboard, scored against the published rubric.
Start an assessment