Guide

12 questions compliance will ask

Use this before an exam, vendor review, or board update. Infrastructure answers are not a substitute for legal or CCO review — they are the questions you should be able to answer clearly.

Hosting & ownership

  1. Who hosts the public WordPress site, and under what legal entity?
  2. Where do files and the database live (region / provider), and who has root or panel access?
  3. Is there a named internal owner for the WordPress stack on the firm’s vendor list?

Access & change control

  1. Who has wp-admin access today, and is 2FA / least privilege enforced?
  2. Are vendor or marketing logins shared, or uniquely attributed?
  3. How are core, plugin, and theme updates tested and approved before production?

Resilience & evidence

  1. Are offsite backups scheduled, and when was the last restore drill?
  2. What is the malware / integrity monitoring path, and who responds same day?
  3. Can you produce change history or posture summaries for the last 12 months?

Content, forms & exit

  1. When did compliance last review claims, testimonials, and third-party scripts?
  2. How are contact forms and any PII-adjacent submissions retained and encrypted in transit?
  3. Could the firm exit the host in under 30 days with full site, database, and DNS control?

Want a scored version of this conversation? Take the Advisor Web Risk Scorecard — twelve themes mapped to security, compliance, performance, and vendor risk.

Score your siteStart a conversation

← All resources