Short answer: An audit-ready dealership needs seven specific documents: a written risk assessment (dated within the last 12 months), a Written Information Security Program (WISP), a designated Qualified Individual with documentation of that designation, employee training records with dates and completion proof, a vendor list with evidence of security vetting, a written incident response plan, and an annual report to leadership. If you're missing any of these, that's a specific, fixable gap — not a vague compliance problem.
Why "we're compliant" isn't a document
A lot of dealership owners describe their compliance status in general terms — "we take security seriously," "our IT handles that." None of that is a document, and none of it is what an examiner, lender, or auditor is actually asking for. Compliance under the Safeguards Rule is evidenced by specific paperwork, dated and current. Here's exactly what that paperwork is.
The 7 documents, explained
1. A written risk assessment. This identifies where customer financial data lives across your systems and what threatens it. It needs a date, and that date needs to be recent — a risk assessment from three DMS providers ago doesn't reflect your dealership today.
2. A Written Information Security Program (WISP). The master document describing your dealership's specific security program — not a generic template, a document that actually matches what you're doing.
3. Qualified Individual designation. A specific name and title, documented, showing who's formally responsible for the program. "Management" isn't a name.
4. Employee training records. Not a statement that training happens — dates, content covered, and proof each relevant employee actually completed it.
5. Vendor list with security evidence. Every vendor that touches customer financial data — your DMS, F&I platform, marketing tools, IT provider — needs to be documented, along with evidence you've vetted their security practices.
6. Written incident response plan. A specific, dated plan for what happens if data is breached — not something you'd figure out in the moment.
7. Annual report to leadership. Even a single-owner dealership needs a documented, periodic review of where the program stands.
The gap between having these and having them ready
Some dealers have pieces of this scattered across old emails, a filing cabinet, and someone's memory of a training session six months ago. Technically, elements of the program might exist. Practically, if a lender asked for all seven documents tomorrow, most dealers in that position couldn't produce them same-day — and "we have it somewhere" doesn't satisfy an actual audit.
Getting all seven into one place
The dealers who handle audits and lender reviews smoothly are the ones who can produce this list on request, not the ones scrambling to reconstruct it. Sterling Safeguard generates and maintains all seven of these documents in one dashboard, tied to your actual risk assessment, so "prove it" becomes a five-minute request instead of a fire drill.