Conveyancers & escrowUnited States

US title industry: ALTA Best Practices 5.0 adds a vendor pillar

The American Land Title Association published version 5.0 of its Best Practices on 8 October 2026. Vendor management is now the seventh pillar, and complaints move to settlement.

· 10 min read

Kooky
Written by
Kooky

Builder of Shaka, the payment router that pays every agent their commission on closing date.

About Kooky and Shaka →

The American Land Title Association (ALTA), the trade body of US title insurers, title agents and settlement companies, published version 5.0 of its Best Practices on 8 October 2026. In its announcement of the same day, the association said the revision overhauls the vendor management requirements and strengthens the guidance on cybersecurity, information security and regulatory compliance.

The framework document itself, 21 pages long, states on its cover that it is effective from 8 October 2026 and its version history records that the ALTA Board approved it on 23 June 2026. Its most visible change is structural. Vendor management, until now the subject of a separate guidance document, becomes a pillar of its own, the seventh. The subject that used to occupy that place, consumer complaints, moves into the settlement pillar.

For the companies that close US home sales, the Best Practices are the title industry's own answer to a question regulators expect banks to ask of every outside firm that touches a borrower's money or data: how is it run, and who checked?

7pillars, the last now vendor management
21pages in the version 5.0 framework
24 monthsassessment interval ALTA suggests

ALTA Best Practices framework, version 5.0, effective 8 October 2026, and ALTA's Best Practices questions and answers.

What version 5.0 changes

ALTA's release notes for version 5.0 describe the changes against version 4.2, the edition in force since August 2025. Five stand out.

The first is the format. The guidelines, previously bullet points, are now written as an outline, so that each requirement has a reference of its own.

The second concerns Pillar 1, on licences. A company must now document that it complies with ALTA's Policy Forms Licence, the association's licence for the use of its copyrighted policy forms, and attach the proof to its certification package. The framework adds that a compliance certificate is available from ALTA, and asks a company to confirm its listing in the ALTA Registry where its type of entity is supported.

Related readConveyancers in Victoria: licence fees, insurance, audits and penalties

The third is in Pillar 3, on information security. The release notes list new requirements for planning and implementing the written information security plan, known in the trade as a WISP, and new elements under a heading on preparedness and training for threats. Multi-factor authentication becomes a defined term, used in Pillars 2 and 3. The framework describes it as verification by at least two kinds of factor: something a person knows, something a person has, or something a person is.

The fourth is the move of complaint handling into Pillar 4, on settlement. The same pillar now clarifies that a company is responsible for vetting the outside firms that monitor and verify third-party signing professionals, and that the choice of a remote notarisation platform may mean weighing the requirements of two places, where the notary sits and where the property lies.

The fifth is the new Pillar 7. The release notes say it builds on the vendor management guidance ALTA produced in 2025, and that "vendor" is now a defined term, intended to help a company decide when an evaluation is needed.

What the vendor pillar asks

The definition is broad. Under the framework, a vendor is an entity that sells or provides goods, services or resources to the company, with or without a contract and with or without payment. The text names third-party providers of specialised services or outsourced operations. It also names artificial intelligence agents, chatbots and virtual assistants, including where the company does no more than share data with the provider, and social media platforms used for business operations, advertising or data processing.

Related readSettlement agents in Western Australia: licences, fees and safeguards

The pillar's purpose statement sets the principle: using a vendor may be a sound business decision, but it does not relieve the company of its duty to avoid harm to consumers and other parties. The framework then sets out two procedures, one for selecting a vendor and one for reviewing it afterwards. The selection procedure itself falls into an evaluation and a vetting scaled to exposure, which gives the three stages below.

The vendor pillar in three stages
  1. Evaluate at selectionEstablish whether the vendor will reach non-public personal information or funds the company holds, and what risks follow.
  2. Vet according to exposureConfirm the vendor can meet its legal and financial duties and trains its staff. Write enforceable compliance terms into the contract.
  3. Review periodicallyCheck that the vendor still meets those expectations. The framework sets no fixed interval.

One part of the vetting stage looks past the vendor to its own suppliers. A company is asked to assess sub-vendor risk: whether the vendor applies equivalent security controls to the firms it relies on, whether it will notify the company of a breach at one of them, and whether it accepts liability for their acts to the same extent as for its own services.

The pillar does not sort vendors into tiers, and it gives no timetable for reviews. It says only that the depth of the checks depends on how much personal information, money or other information the vendor could affect. Vendor duties also sit in other pillars. Pillar 2 says wire transfer verification providers should be vetted under Pillar 7. Pillar 3 asks that vendors and third-party systems, software tools, AI processes and connected devices among them, be chosen so that their security fits the company's WISP. Pillar 4 covers third-party signing professionals.

A companion document, the guidance on vetting a vendor, was republished the same day for members and subscribers. According to the release notes, it now suggests that a company consider being named as an additional insured on a vendor's insurance, and check whether its own cover extends to what the vendor does.

Related readWho holds the money in a California home sale? Escrow holders explained

The seven pillars as version 5.0 names them

The names below are those printed in the version 5.0 framework. The right-hand column gives one requirement from each pillar as an illustration; none of the pillars is limited to it.

ALTA Best Practices, version 5.0Pillar names as printed in the framework
PillarNameOne requirement it contains
1LicensesProof of the Policy Forms Licence in the certification package.
2Funds and Escrow Trust AccountsReconciliation at least daily, and a three-way reconciliation at least monthly.
3Information Security and Privacy PlansA written information security plan and a written privacy plan.
4SettlementDocuments sent for recording within two business days.
5Title Insurance PoliciesPolicies delivered within 30 days and reported to the insurer within 45.
6Insurance and Fidelity CoverageCover limits and exclusions reviewed with a broker at least once a year.
7Vendor ManagementVendors evaluated at selection and reviewed periodically.

ALTA Best Practices framework, version 5.0. The two-day, 30-day and 45-day periods run from settlement or from another date set in the text.

Pillar 2's three-way reconciliation compares the trial balance, the book balance and the reconciled bank balance, and is to be carried out by staff with no authority to sign or disburse.

Where the Best Practices came from

ALTA announced the Best Practices on 16 October 2012. Its announcement that day explained the reason: regulators had made clear that they expect banks to oversee their third-party service providers, and lenders were becoming more selective about the firms they worked with. The framework was meant to show lenders and consumers the safeguards the industry already applied.

Michelle Korsmo, then ALTA's chief executive, said in that announcement: "The title insurance industry has always been serious about protecting consumers and combating criminal behavior."

The regulatory pressure has a text. The Consumer Financial Protection Bureau's Compliance Bulletin 2016-02, released on 31 October 2016 as a reissue of its Bulletin 2012-03 on service providers, lists five steps it expects of supervised banks and non-banks: thorough due diligence on a provider, a review of its policies, controls and training materials, contracts that carry compliance standards and enforceable consequences, ongoing monitoring, and prompt action on any problem found. The bulletin adds that legal responsibility may lie with the supervised company as well as with its provider.

The original 2012 list already had seven headings: licensing, escrow and trust accounts, privacy and information security, settlement procedures, title policy production, insurance, and consumer complaints. The version history printed in the new framework shows how often the text has been reworked since version 1.0, which the Board approved on 20 December 2012: versions 2.0 in 2013, 2.5 in 2016, 3.0 in 2019, 4.0 in 2023, 4.1 in 2024 and 4.2 in 2025.

Related readSelling or buying Dubai property through a power of attorney

Version 4.0 was the last large rewrite. ALTA's announcement of 24 January 2023 listed, among other changes, daily reconciliation, verification of outgoing wires with multi-factor authentication, and the term WISP. Version 4.1, published on 17 September 2024, aligned password rules with federal standards guidance and added due diligence for closings that involve no title insurance policy. Version 4.2, announced on 19 August 2025, added identity verification duties to the settlement pillar, including staff training on impersonation of buyers, borrowers and sellers.

Set side by side, the two texts follow a similar order. Pillar 7 asks a title company for due diligence on a vendor, enforceable contract terms and periodic review; the federal bulletin asks supervised lenders for due diligence, contractual expectations and ongoing monitoring of their own service providers.

How compliance is assessed, and by whom

The framework's mission statement says the practices are voluntary. The practical pressure comes from the other side of the table: ALTA's page on demonstrating compliance says that, depending on a lender's vendor management policies, a company may be asked to engage a third-party certification specialist, whose report supports the company's own assessment.

Worth knowing

ALTA does not certify anyone

The association states that it performs no Best Practices assessments, issues no certifications and reviews no reports. Evidence of an assessment goes to the lender or the title insurer that asks for it, not to ALTA.

The route is therefore a self-assessment, in which a company reviews and tests its own policies and procedures against the standards, with or without an outside report on top. ALTA publishes assessment procedures and report templates for both cases, and notes that accountants may refer to technical guidance from their own professional institute for these engagements. It keeps no list of preferred assessment firms, and advises companies to consult their lender partners before engaging a certification specialist.

Related readWho handles the legal transfer of a property in Dubai?

On timing, ALTA suggests an assessment every 24 months, while noting that each lender or title insurer may set a shorter or longer cycle, and that a company may find it worthwhile to address the changes of a new revision before its 24 months are up.

What comes next

The Best Practices Assessment Procedures were updated to version 5.0 and published on 8 October 2026 alongside the framework, for members and subscribers. The release notes say the update was made to align the procedures with the new text.

Neither the framework nor the release notes sets a transition period. The cover gives 8 October 2026 as the effective date, and ALTA's Best Practices pages, including its questions and answers and its assessment pages, give no date from which assessments must use version 5.0. The internal and third-party report templates listed there still carry the version 4.0 label. In 2023, by contrast, ALTA published version 4.0 on 23 January with an effective date four months later, 23 May, and said assessments performed after that date should use the new framework. How quickly version 5.0 reaches a given title agent will depend, as before, on what its lenders and its title insurers ask for.

The version reached its final form after a public consultation. ALTA announced the comment period on 14 July 2026; it ran until 31 July. The proposals listed in that announcement, the outline format, the definition of vendor, the licence guidance in Pillar 1, the move of complaints and the standalone seventh pillar, all appear in the published framework. In the same announcement, ALTA said a Best Practices Bootcamp would be offered through the Land Title Institute later in 2026. It gave no date.

Kooky, from Shaka

Kooky edits Agents Estate and builds Shaka, the payment router he made for real estate professionals. One payment comes in, and every agent, agency and party in the deal receives their signed share on closing date.