Guide
12 questions compliance will ask
Use this before an exam, vendor review, or board update. Infrastructure answers are not a substitute for legal or CCO review — they are the questions you should be able to answer clearly.
Hosting & ownership
- Who hosts the public WordPress site, and under what legal entity?
- Where do files and the database live (region / provider), and who has root or panel access?
- Is there a named internal owner for the WordPress stack on the firm’s vendor list?
Access & change control
- Who has wp-admin access today, and is 2FA / least privilege enforced?
- Are vendor or marketing logins shared, or uniquely attributed?
- How are core, plugin, and theme updates tested and approved before production?
Resilience & evidence
- Are offsite backups scheduled, and when was the last restore drill?
- What is the malware / integrity monitoring path, and who responds same day?
- Can you produce change history or posture summaries for the last 12 months?
Content, forms & exit
- When did compliance last review claims, testimonials, and third-party scripts?
- How are contact forms and any PII-adjacent submissions retained and encrypted in transit?
- Could the firm exit the host in under 30 days with full site, database, and DNS control?
Want a scored version of this conversation? Take the Advisor Web Risk Scorecard — twelve themes mapped to security, compliance, performance, and vendor risk.