Targets: 1,000 ideas in the database, 88% at Tier 1 or above.
| Metric | Now | Target | Gap |
|---|---|---|---|
| Total ideas | 331 | 1,000 | +669 |
| Tier 1+ verified | 134 (40.5%) | 880 (88%) | +746 |
| Tier 2 (evidenced) | 37 | 300 | +263 |
| Tier 3 (fully verified) | 0 | 60 | +60 |
Idea count is on pace (+79 this run). Verification is not. 197 rows have still never been through the kill-filters, and verification — not generation — is now the binding constraint. See R001 for why, and for the recommended change of approach.
Generated: 252 ideas across 18 industry branches, 14 per branch (manual taxonomy build).
Verified: 21 at Tier 2 — competitor pricing and a demand statistic sourced, but no CPC data, so nothing yet qualifies for Tier 3.
Killed: 1 — Ad Account Waste Audit (deliverable given away free as an agency lead-magnet).
Downgraded on evidence:
| Idea | Before | After | Why |
|---|---|---|---|
| Ad Account Waste Audit | 91.8 | 77.2 | Free PPC audits are the standard agency lead-magnet |
| Financial Aid Award Letter Comparison | 88.2 | 76.8 | Season is March–May; 7 months out |
| Technical SEO Audit | 88.0 | 77.2 | Same free-lead-magnet dynamic |
| Inspection Report → Repair Cost | 87.4 | 77.0 | RepairPricer owns the channel at $70–80 |
| Merchant Processing Fee Audit | 93.8 | 86.0 | Processors give free statement analysis |
| Marketing Agency Scope Audit | 88.8 | 81.6 | Rival agencies use it as a takeover wedge |
Upgraded on evidence: HIPAA Security Risk Analysis 81.0 → 84.8 (76% of 2025 OCR actions cited risk-analysis failures; new Security Rule finalising 2026).
Top 3 selected: Construction Plan Takeoff (96.6) · Grant Readiness Scoring (88.4) · HIPAA Security Risk Analysis (84.8).
Key lesson that became kill-filter #1: the single most common fatal flaw is that the deliverable is already given away free as a sales lead-magnet. Screen for this before spending any research budget.
Sources not yet mined: all of them. Start with the NAICS sweep and the Federal Register.
Headline: this was a demolition run, not a growth run. The five kill-filters, applied for the first time at volume, killed 9 of the previous top 20 — including 8 that died to filter #1 alone. The database is smaller in real terms than it looked a week ago.
| Before | After | |
|---|---|---|
| Rows | 252 | 331 (+79) |
| Tier 1+ | 21 (8.3%) | 134 (40.5%) |
| Tier 2 | 21 | 31 |
| Tier 3 | 0 | 0 |
| Killed (cumulative) | 1 | 51 |
Generated: 79 new rows. Seams mined: Federal Register final rules (13), enforcement actions — OSHA/FTC/DOL (21), NAICS 4-digit sweep (28), document-type × industry cross-product (17). 16 candidates were discarded pre-entry as near-duplicates of existing rows (collisions logged in sources-mined.md).
Screened: 20 clusters through the five kill-filters with real sources consulted. 113 rows promoted to Tier 1 or above. 197 rows remain at Tier 0 — the session's search budget ran out mid-screen. A further 6 kills were found by auditing existing Tier 2 rows against the tier standard (see below), with no new searches required.
Deep-verified to Tier 2: 16 rows. No row reached Tier 3: every Tier-3 candidate is missing the same thing — real CPC and search-volume data. That is a tooling gap, not a research gap, and it is why tier3_minimum_count: 60 has not moved off zero in two runs.
Filter 1 — deliverable is already a free lead-magnet (26 kills). Overwhelmingly the dominant failure mode, exactly as R000 predicted:
| Idea | Score at death | Who gives it away |
|---|---|---|
| Pitch Deck Investor-Lens Teardown | 84.2 | OpenVC, Futureproof, Slidebean, SeedBlink — free AI deck reviews; VCs review free for deal flow |
| SaaS Renewal Benchmark & Negotiation Brief | 84.0 | Vertice savings calculator, Tropic/Zylo free savings analyses (also duplicated an existing row) |
| Subscription & Recurring Charge Audit | 83.8 | Rocket Money and rivals — free, monetised on the negotiated saving |
| OSHA Written Program Gap Audit | 82.9 | Workers' comp carriers: free loss control, mock OSHA inspections, J.J. Keller written programs |
| Freight Invoice Overcharge Audit | 82.8 | Shipware, TCR, SSI, Lojistic — entire category is contingency-priced |
| Business Tax Return Missed-Deduction Review | 82.6 | H&R Block Second Look; CPA free second opinions |
| Freight & Utility Bill Audit | 82.2 | Same contingency model |
| Insurance Denial Appeal Builder | 82.0 | Patient Advocate Foundation, SHIP (federally funded, all 50 states), Counterforce Health (NIH-funded) |
| EB-1A / O-1 Evidence Strength Assessment | 81.9 | Free profile evaluations universal across the immigration bar |
| ADA / WCAG Remediation Report | 80.6 | AudioEye, accessiBe, Silktide, ADA Scanner — free scans are the category's standard bait |
| DOT / FMCSA Driver File Compliance Audit | 77.5 | CNS free DOT risk assessment; Motor Carrier HQ / J.J. Keller own the channel |
| Duplicate & Overpayment Recovery Audit | 74.4 | Contingency-priced |
Plus: Green Card Pathway, Data Map & Processing Inventory, Immigration Fee Comparison, N-400 Readiness, HazCom/SDS Audit, LOTO Procedure Audit, Respiratory Protection Audit, Fall Protection Plan, OSHA 300 Log Audit, DOT New Entrant Readiness, IRS CP2000 Response, State Sales Tax Audit Response, Lemon Law Case Strength, ADA Title II Conformance, Section 504 Digital Accessibility.
Filter 2 — licensed activity (8 kills). VA Disability Evidence Gap (38 U.S.C. 5901 restricts paid VA claim assistance to accredited agents/attorneys), Medicaid Spend-Down (UPL in most states), Workers' Comp Compensability (claim adjusting is licensed), Asylum Declaration, PERM Labor Certification, Consular Interview Prep, Prop 65 Safe Harbor Review (also needs lab testing the operator cannot do).
Filter 4 — incumbent owns the referral channel (contributing to 6 kills). IFTA/IRP Fuel Tax Defence, and reinforcing the DOT, OSHA, Rocket Money and immigration kills above.
Filter 5 — buyer unreachable by search intent (9 kills). CPPA Cybersecurity Audit Certification (enterprise-only until 2030), Section 1071 Lending Data Readiness (banks buy via core/LOS vendors), EPA Pesticide Applicator Records, MSHA Training Records, Security Guard Post Orders, Restaurant Health Inspection Plan, Practice Sale Diligence, Utility Rate Case Impact, EPA RMP.
Parked (1): FinCEN Investment Adviser AML Program Readiness — compliance deferred to Jan 2028. Wake-up date 2027-06-01.
Construction Plan Takeoff — 96.6 → 91.8 (still #1, whitespace cut 5 → 3). The R000 thesis was that existing AI takeoff tools are DIY software and the only done-for-you services are offshore. That is no longer true. Beam AI (Attentive.ai) now sells a done-for-you takeoff service: QA-reviewed, 24–72 hour turnaround, accuracy guaranteed within ±1%, 500,000+ takeoffs completed, ~$8,000+/yr per trade. A funded, US-based, accuracy-guaranteed incumbent now occupies the exact wedge. The idea survives because Beam prices as an annual per-trade subscription aimed at steady bidders, leaving the occasional bidder (59% of specialty trades are under $1M revenue) unserved on a per-report basis — but that is a much narrower claim than R000 made. Competitor pricing refreshed: Togal.AI $299/user/mo, Kreo Pro $175/user/mo (entry $35/mo), STACK from $249/user/mo, BuildingConnected Pro $5,000–15,000/yr.
Grant Readiness Scoring — 88.4, unchanged (#2), re-confirmed. Searching for pre-submission grant scoring surfaces software built for funders to score incoming applications (Submittable, Sopact, Submit.com), not tools that let an applicant pre-score their own draft against the published rubric. The R000 wedge holds. Published rubric weightings: impact 25–35%, feasibility 20–30%, budget 15–20%, innovation 10–20%.
HIPAA Security Risk Analysis — 84.8 → 81.8 (#11 of active), partial retraction. R000 upgraded this 81.0 → 84.8 on two facts. One still holds (76% of 2025 OCR actions cited risk-analysis failures). The other does not: the HIPAA Security Rule NPRM published 6 Jan 2025 has not been finalised — the May 2026 target slipped and no updated Security Rule is in force. The deadline catalyst is withdrawn; the standing 45 CFR 164.308(a)(1)(ii)(A) obligation and OCR's enforcement pattern remain. Half the R000 upgrade is taken back.
| Idea | Rank | Score | Why |
|---|---|---|---|
| Total Loss Valuation Dispute Packet | #7 → #83 | 84.7 → 73.1 | Appraisal clause routes this to licensed appraisers (risk → 4); market already served at $399 (DVCHECK, IASNW, SecondAppraisal, Total Loss Champions). AOV anchor collapses. |
| GDPR / CCPA Privacy Program Audit | #141 → #191 | 68.4 → 64.0 | OneTrust and Osano free assessment tools; the "CCPA compliance" SERP is saturated by free-scanner advertisers, so click quality is poor. |
| Royalty Statement Underpayment Audit | #21 → #50 | 81.9 → 77.1 | Follows the same contingency-pricing norm as freight/recovery audits. |
| Chargemaster Benchmark | #110 → #139 | 70.9 → 68.5 | PAF covers large medical debt burdens free. |
| Good-Faith-Estimate Fair Price Audit | #115 → #143 | 70.5 → 68.1 | Same. |
| SaaS Contract & Spend Audit | #10 → #34 | 84.4 → 79.8 | Free savings analyses from Vertice/Tropic/Zylo; they own the finance-team channel. |
| Medical Bill Audit & Overcharge Report | #30 → #42 | 80.8 → 78.4 | PAF free case management; survives only because nonprofit capacity is rationed. |
| Idea | Score | Tier | Why |
|---|---|---|---|
| FTC Safeguards Rule WISP Build & Gap Report | 87.3 | 2 | Straight into #4. Auto dealers, tax preparers and mortgage brokers are all covered non-bank financial institutions; the IRS requires a WISP for PTIN holders. MSPs give it away to win managed-services contracts — which is exactly why an independent document is the product. |
| Supplement & Health Claim Substantiation Dossier | 82.8 | 2 | Published price band of $1,500–$7,500 per claim set for file assembly; FTC penalty $53,088 per violation; ~700 marketers already on notice. Ad lawyers bill hourly and dislike document assembly. |
| Statement of Deficiencies Plan of Correction (ALF/SNF) | 78.0 | 2 | CMS requires an acceptable plan of correction within 10 calendar days of the CMS-2567. Consultants sell retainers to chains; independent single-site operators face the clock alone. |
| TSCA PFAS Reportability Determination | 77.5 | 2 | Submission window opens 31 Jan 2027 and reporting reaches back to 1 Jan 2011 — archival document reconstruction that fits neither a consultancy retainer nor a software subscription. |
| Hotel Franchise PIP Scope & Cost Challenge | 77.1 | 2 | PIPs run $2M–8M per property. Asset managers serve institutional owners; single-property owners get the letter and no advocate. |
The end-of-run integrity check compared every Tier 2 row against the Tier 2 evidence standard and found six rows whose own recorded notes were kill-filter findings, but which R000 left active at Tier 2 with high scores. R000 downgraded their scores instead of killing them. Corrected:
| Idea | Was | Now | The evidence R000 already had |
|---|---|---|---|
| Funder Match & Opportunity Report | 84.4, rank #8 active | 77.8, killed | "Instrumentl owns grant discovery at $179/mo with an aggregated funder database you cannot cheaply replicate. Discovery is the wrong wedge." (F4) |
| Cloud Bill Cost Optimization Report | 81.4 | 73.2, killed | "Buyer is mid-market with a procurement cycle. Cannot reliably close from cold paid ads inside 30 days." (F5) |
| Solar Proposal Comparison Report | 81.0 | 69.6, killed | "EnergySage and comparable marketplaces provide quote comparison free, monetized by lead-gen." (F1) |
| Solar PPA / Lease Contract Economics Review | 81.0 | 69.6, killed | "Free comparison layers already exist in the solar funnel." (F1) |
| QuickBooks Books-Health Diagnostic | 80.2 | 77.8, killed | "Bookkeeping and CAS firms give free diagnostic reviews to win the monthly engagement." (F1) |
| Technical SEO Audit from Crawl Data | 77.2 | 77.2, killed | "Ahrefs/Semrush/Screaming Frog give site audits away; agencies use them as the opener. No pricing power." (F1) |
This is a process failure worth naming: R000 treated kill-filter findings as score adjustments. A free lead-magnet is not a few points off the score, it is a dead business, and leaving these rows active put a killed idea at rank #8. Future runs must set status to killed whenever a filter fires, not merely downgrade. Tier 2 count falls 37 → 31 as a result; the killed rows correctly stay at Tier 1.
Schema hygiene note: 18 further Tier 2 rows inherited from R000 hold their competitor and demand evidence in the free-text notes column rather than the structured competitors / demand_stat / gap_reason columns. The evidence is real and the tier is justified, but it is not machine-checkable. Backfilling those columns is a cheap R002 task and would make this audit automatic.
Generation is not the problem. 79 new rows came out of the regulatory and enforcement seams at good quality, and the Federal Register / enforcement seams were the right priority: they produced the two strongest new entries (FTC Safeguards WISP, Supplement Substantiation) and a cluster of deadline-driven candidates with real forcing functions.
The problem is that filter #1 is killing ideas faster than generation replaces them at the top of the table. Nine of the previous top 20 are gone. The pattern is now unmistakable and worth stating as a rule: any deliverable whose value is legible to the buyer before purchase, in a category where someone downstream earns a larger fee, will be given away free. Recovery audits go contingency. Legal intake goes free-consultation. Compliance documents get bundled by the insurer or the MSP. Consumer-facing analysis gets funded by a nonprofit or a platform.
Two recommendations for R002:
On the targets. At this run's rate the 1,000-row target lands around week 9 (mid-October 2026), but the 88%-verified target does not land until roughly week 20 (late December 2026) — about two months later than the R000 projection. That slip is real and should not be papered over by tiering rows that were never screened.
Trigger: six of the 21 bench candidates (score ≥80, risk ≤3) had never been through any kill-filter. Screening them cost six searches. Testing them would have cost $900.
Result: 6 of 6 killed. A 100% kill rate against the ~38% predicted from R001.
| Idea | Score | Filter | What killed it |
|---|---|---|---|
| Security Questionnaire Auto-Response | 81.8 | F1 | Conveyor runs an always-free tier; paid market is $9.6k–19.8k/yr software |
| IEP / 504 Plan Review | 81.4 | F1 | Federally funded PTI centre in every state provides this free |
| Property Tax Appeal Packet | 81.3 | F1+F4 | Category is contingency-priced 25–45% of savings, free assessment standard |
| Bid / No-Bid Scoring Report | 80.6 | F1 | Bidara publishes a free no-signup 10-criteria scoring tool |
| Competitor Ad & Creative Teardown | 80.4 | F1 | AdTeardown.com gives it away; Meta Ad Library is the free public source |
| AIA / Subcontract Risk Review | 80.1 | F4 | Superlegal sells attorney-verified AI construction contract review; attorney flat fees average $287/subcontract |
Bench: 21 → 15, and all 15 are now Tier 1 or above. Verified coverage 40.5% → 42.3%.
A 100% kill rate at the top of the unscreened pile is not bad luck. The rubric systematically over-rates ideas that are about to die to filter #1.
Large demand, an obvious unmet need, and loud public complaints together carry 31% of the weight (dem 12 + und 12 + prf 7). Those are precisely the conditions that attract someone to give the deliverable away free as a lead magnet — big audience, legible pain, and a larger downstream fee worth chasing. So a high score on those three axes is partly a warning sign, not purely a positive, and the rubric currently cannot see that.
Consequence: never let an unscreened row sit in a ranking that anyone reads, and never spend money on a row that has not passed filter #1. Screening is cheap and catches what scoring cannot.
Open question for a future run: consider adding an explicit "who profits downstream from this buyer?" check at generation time. If a clear downstream fee-earner exists, expect the deliverable to already be free.
Mode: SCREENING-ONLY (Rule 0). Tier 0 was 191 of 331 rows = 57.7%, far over the 20% trigger. Nothing generated.
Second consecutive run with a 100% kill rate, and this time across the entire backlog rather than just its top. Seventeen clusters, each with at least one real source consulted. Verified coverage 0 -> 100% Tier 1+.
| Cluster | Rows | Killed | The source that did most of the work |
|---|---|---|---|
| Consumer life-admin | 13 | 13 | IdentityTheft.gov free FTC recovery plan, pre-filled letters, 30+ theft types |
| Insurance | 12 | 12 | CoverageCheck 100% free AI policy analyser; PlausTech, Newfront free CGA |
| Legal & litigation | 14 | 14 | Relevance AI and Justee free unlimited AI contract review |
| Real estate - residential | 11 | 11 | FairPriceCheck Closing Check audits a CD free in 60 seconds |
| Real estate - commercial | 13 | 13 | Broker-supplied OM/rent roll/T-12 free; PropRise free templates |
| Government & nonprofit | 13 | 13 | 300+ DoD-funded APEX Accelerators; ProPublica Nonprofit Explorer |
| Education & academia | 12 | 12 | U. Iowa "Grant Hawk" NIH reviewer simulation, free to faculty |
| Supply chain & trade | 12 | 12 | 46 CFR 541.6 makes non-compliant D&D invoices unpayable |
| IT & security | 11 | 11 | Stitchflow free Shadow IT Scanner on the Workspace Marketplace |
| HR & benefits | 11 | 11 | Jobscan free tier; HandbookHub free scored handbook review |
| Procurement & sales | 9 | 9 | Five separate free weighted RFP scoring matrices |
| Marketing | 9 | 9 | Semrush free checker, Ahrefs Webmaster Tools, Search Console |
| Finance & tax | 9 | 9 | ProjectionHub "Free SBA Expert Review" run by a former SBA director |
| Healthcare | 9 | 9 | SHIP free Medicare counselling in all 50 states; CoverMyMeds |
| Construction | 8 | 8 | City building departments publish free submittal checklists |
| Compliance & safety | 8 | 8 | Vanta includes SOC 2 gap analysis at no extra cost; FDA Q-Sub |
| Energy, ag & environment | 11 | 11 | Utilities give free on-site Level 1 commercial energy audits |
| Immigration | 6 | 6 | DOJ-accredited nonprofit representatives; UPL/notario exposure |
Roughly 60% of the kills name a specific free competitor. The remainder are category-rule kills against the downstream-fee-earner pattern, tagged as such in notes so a future run can revisit them if the rule is ever falsified.
The rule now has a third and much larger confirmation, and a sharper form:
Where a free provider is funded by something other than the buyer, no price floor exists.
Three funding structures did most of the killing, and none of them can be undercut:
The generation seams were not the problem. The product shape was. "Upload documents, get a report" is the exact shape that all three structures give away, because a report is cheap to produce and legible before purchase. Every remaining survivor wins on something other than the report: a licensing or channel barrier, a buyer too small for the incumbent's seat price, or a document nobody downstream is paid to produce.
While deep-verifying, six rows were found where a kill-filter had fired, been written into the notes, and the row was then merely score-downgraded and left active. That is the exact R000 error Rule 2 exists to prevent, and four of the six were sitting on the bench.
| Row | Score | Filter that had already fired, in the row's own notes |
|---|---|---|
| Merchant Processing Fee Audit | 86.0 | "every processor rep offers free statement analysis - the industry's main switching tactic" |
| Commercial Utility Tariff Optimization | 81.6 | "contingency consultants taking ~40% of savings with zero upfront cost" |
| Marketing Agency Scope & Value Audit | 81.6 | "the free-lead-magnet problem in disguise" |
| Surety Bond & Prequalification Review | 81.4 | "surety agents review free because they earn commission on placement" |
| SaaS Contract & Spend Audit | 79.8 | "Vertice, Tropic, Zylo, Spendhound run free savings analyses as lead magnets" |
| Inspection Report -> Repair Cost | 77.0 | "RepairPricer has locked the distribution channel via its partner program" |
All six killed. Medical Bill Audit and Royalty Statement Underpayment Audit were killed on the same basis, bringing the audit to eight.
The R000 note claimed "NOBODY scores your finished draft against the funder's rubric." That is falsified: DH Leonard Consulting gives away a Mock Review Toolkit containing an internal scoring tool and a rubric, as a lead magnet into $1,500-5,000 consulting. Underservice cut 5 -> 3.
It survives because the free scored reads found are all ecosystem-bound - universities for their own faculty, FAST programmes for SBIR applicants - and both of those buyer segments were killed this run as separate rows. What is left is a nonprofit chasing foundation or federal money with no university and no FAST programme behind it. That residual segment is now the entire thesis and it is unproven. It should be tested before money goes anywhere else.
TESTS.md contains no test rows, so no CPC exists; every Tier-2 row now carries cpc_data = UNAVAILABLE rather than a fabricated figure.Screening is now complete and cannot be run again - there is no backlog left. The next run must either generate or test, and generating more rows in the same product shape is not obviously worth doing given that 191 of 191 just died. The recommendation is to stop feeding the database and spend the Stage 1 money, which is also the only route to unblocking Tier 3.
Mode: GENERATE-AND-SCREEN, narrow. Operator-directed. Eight trades had been recommended to the operator as "not sexy" small businesses nobody is targeting with AI — HVAC, plumbing, electrical, roofing, landscaping, pest control, garage door, pool service. The run asked whether the database already held anything in them and whether it should. The full evaluation, including market sizing and taxonomy, is the first section of the new VERTICALS.md; this entry records only what changed in the database.
Only roofing was directly covered (Xactimate Scope & Supplement Review, 86.0, bench #4). HVAC, plumbing and electrical were covered indirectly through Plan Takeoff (#1) and Certified Payroll (#52). Landscaping and pest control shared one row, killed in R001 (EPA Pesticide Recordkeeping, 56.7, F5). Garage door and pool service had never appeared. Neither NAICS 238 nor NAICS 5617 had been mined.
Only two trades produced a candidate that fit the product shape — a document the buyer must produce per job and currently pays someone else to produce. Both were screened in the same run, and the existing roofing row was re-screened because its notes did not mention how the supplement category is priced.
| Row | Score | Result | Filter | The source that did the work |
|---|---|---|---|---|
| HVAC Manual J/S/D Load Calculation & Duct Design Report (new) | 64.1 | killed | F1 | LennoxPros: free ACCA-approved MJ8 report tool for dealers; CoolCalc free; ManualJs.com $79 |
| NEC 220 Load Calculation & Single-Line Diagram Permit Package (new) | 50.0 | killed | F1 + F4 | ChargeRight $12.99 done-for-you; Qmerit does it inside the ChargePoint installer workflow; GreenLancer plan sets $250–300 |
| Xactimate Scope & Supplement Review (existing, bench #4) | 86.0 | killed | F1 (contingency variant) + F2 | Supplement Experts / Claim Supplement Pro: 8–15% of recovery, zero upfront; FL, TX, OR UPPA statutes now cover anyone "assisting with a claim" |
Both new rows died the same way: the channel gives the document away. A manufacturer (Lennox), an installer network (Qmerit) or a regulator (the AHJ's own form) supplies the mandated document free to keep the contractor inside its channel. This is filter 1 operating at the level of an industry rather than a competitor, and it is the reason the seam is recorded closed rather than partial.
The row's R000 note said the licensing problem was solved by selling to the contractor rather than the homeowner. Two things falsify that:
The residual wedge — a flat-fee, no-carrier-contact scope audit at $199–399 outside FL/TX/OR — is recorded in gap_reason so the row can be revived if Stage 1 evidence ever contradicts this.
TEST-PLAYBOOK.md corrected in the hold list. Its Stage 1 test #4 write-up still describes Merchant Fee Audit and needs rewriting for CAM; the playbook is marked in progress on the site until that is done.VERTICALS.md is the first document written under that convention.TESTS.md.Same conclusion as R003, now with a fourth data point: a targeted sweep into a fresh seam with a well-fitted product shape produced a 100% kill rate. The database is not short of candidates; it is short of evidence that any candidate sells. The next run should spend Stage 1 money on the Takeoff test, not generate.
The playbook's Stage 1 test #2 carried its own gate: confirm the FTC is actually penalising small firms before spending a dollar. The Status page had been showing that check as the single next action since R003. It was run on 26 August.
| Question | Finding |
|---|---|
| FTC Safeguards Rule actions since the amended rule took effect (June 2023) | None. The FTC's data-security case list (Blackbaud, X-Mode, CafePress, Marriott and others) pleads Section 5 only. The last Safeguards Rule orders are pre-window: DealerBuilt 2019, Ascension 2020. |
| Any action against a small firm | Only indirectly: a $60,000 New York AG settlement with a CPA firm (Oct 2025) for an 18-month breach-notification delay — a state law, after a breach, not for lacking a WISP. |
| IRS enforcement of the PTIN WISP requirement | Form W-12 line 11 is a self-attestation checkbox. No verification, no upload, no stated penalty, no sanctioned preparer found. |
| Dealer audits or fines | None on any docket. Vendor claims of a 2023 "$3.2M dealer fine" trace to nothing. |
| Free producer of the document | IRS Publication 5708 — a 28-page WISP template written for small practices — plus TaxDome, COCPA and Protection Plus templates given away as lead magnets. |
FTC Safeguards WISP (87.3, #3 overall, Stage 1 test #2) — KILLED. Two independent grounds, either sufficient: filter 1 (the regulator supplies the mandated document free — the HIPAA SRA Tool pattern R003 killed on) and a falsified enforcement premise (the HIPAA deadline pattern R001 downgraded on). The actual buying triggers in this market — a breach, a cyber-insurance questionnaire, a lender's vendor form — are not what the row was priced on.
Knock-on changes.
rubric.json records ftc_enforcement_checked: true with the result.State after the addendum: database 335, active 69, killed 263, parked 3. Tier 2 unchanged at 38 — killed rows keep their evidence tier.