An appraiser stores workfiles in a cloud service. What obligation does the Ethics Rule impose?
Correct Answer
A) That confidential information remains protected
Why this is correct: The Ethics Rule's confidentiality requirement is not tied to the physical location of files. The core duty is to protect client information from unauthorized access. Using a cloud service is permissible, but the appraiser must take reasonable steps to ensure the service provides adequate security for the confidential data, as stated in the original explanation. Why the other choices are wrong: The rule does not require the provider be located in the same state. It does not mandate that the client approve the specific provider in writing. It also does not require retaining paper duplicates alongside electronic files; workfiles can be stored electronically. Exam tip: Remember, the duty of confidentiality is about protecting the information itself, not the medium or location where it is stored.
Why This Is the Correct Answer
That confidential information remains protected is the obligation the Ethics Rule imposes, and it is technology-neutral by design, applying identically to a filing cabinet, a laptop, and a cloud account. The appraiser cannot delegate the duty to the vendor by pointing at a service agreement, so the reasonable-steps standard covers choosing a provider with appropriate security, using strong and unique authentication, limiting who has access, and understanding whether the provider's default settings expose links publicly. It also extends to devices, since a synced folder on an unlocked phone is the same exposure as an unlocked cabinet. None of this prohibits cloud storage, which is now ordinary practice; it conditions how it is done.
Why the Other Options Are Wrong
Option B: That the provider be located in the same state
Nothing in the ETHICS RULE addresses where a service provider is located, and geography is not a proxy for security. Some data residency requirements exist in other bodies of law for particular kinds of information, which is a separate matter the appraiser should be aware of under the obligation to comply with applicable privacy laws. Inventing a same-state rule misstates the Ethics Rule.
Option C: That the client approve the provider in writing
Client approval of a specific storage vendor is not required, and the confidentiality duty runs to the client without needing the client's participation in how it is discharged. The client does authorize disclosure of confidential information in the sense of permitting particular recipients, but that is a different act from approving infrastructure. The option confuses authorization to disclose with approval of the storage arrangement.
Option D: That paper duplicates be retained alongside them
Paper duplicates are not required by any part of USPAP, and keeping a second copy on paper would multiply the confidentiality exposure rather than reduce it. The RECORD KEEPING RULE is medium-neutral and the ETHICS RULE is concerned with protection rather than format. This option carries a paper requirement into a rule that has none.
The Duty Travels With the Data
Confidentiality attaches to the information, not to the cabinet. Move the data to a server, a laptop, or a cloud, and the duty rides along. You may hire a vendor; you may not hire out the obligation.
How to use: On any question about where or how files are kept, answer with protection of confidential information and reject options about location, client approval, or paper. Then think through the practical safeguards, which are access control, authentication, encryption, and device security. Remember that disclosure limits are a separate list worth memorizing.
Exam Tip
Ethics Rule questions about storage are confidentiality questions. The duty is technology-neutral and cannot be transferred to a vendor.
Common Mistakes to Avoid
- -Treating a vendor's security marketing as satisfying the appraiser's own duty to take reasonable steps
- -Leaving default public sharing enabled on folders containing client files
- -Confusing the categories permitted to receive confidential information, such as state regulators and peer review committees, with general permission to share
Concept Deep Dive
Analysis
This item moves from the RECORD KEEPING RULE to the ETHICS RULE, since the question asks specifically what the Ethics Rule imposes on cloud storage. The Confidentiality section of the ETHICS RULE requires the appraiser to protect the confidential nature of the appraiser-client relationship, to act in good faith with regard to the legitimate interests of the client in the use of confidential information and assignment results, and to be aware of and comply with confidentiality and privacy laws that apply. It also limits disclosure of confidential information and assignment results to the client, to persons the client specifically authorizes, to state appraiser regulatory agencies, to third parties as authorized by due process of law, and to a duly authorized professional peer review committee. Storing files with a third-party provider does not change any of that; it simply means the appraiser has placed confidential material in someone else's custody and must take reasonable steps to see that it remains protected. Practically that means attention to access controls, credentials, encryption, provider terms, and who else in a firm or household can reach the account.
Background Knowledge
You need to know the Confidentiality section of the ETHICS RULE, including the duty to protect confidential information, the good faith obligation regarding the client's legitimate interests, and the limited categories to whom confidential information and assignment results may be disclosed. You should know that the rule also requires awareness of and compliance with applicable confidentiality and privacy laws and regulations. You also need to know that the duty is technology-neutral and cannot be delegated to a vendor, so reasonable safeguards over access, credentials, and devices are the appraiser's responsibility.
Real-World Application
A sole practitioner moves her workfiles to a cloud service, enables multifactor authentication, turns off default public link sharing, and confirms that only she and her assistant have access. When a lender's processor asks her to drop a prior client's report into a shared folder for reference, she declines, explaining that assignment results and confidential information from another assignment cannot be disclosed without that client's authorization.
More Emerging Methods Questions
How does an alternative inspection method affect the appraiser's disclosure obligations?
A collector's photographs show a condition the appraiser believes needs specialist assessment. What is the appropriate step?
What responsibility does an appraiser retain for an error originating in a third-party database?
Under current USPAP guidance, what is the output of an automated valuation model before an appraiser analyzes it?
Which assignment type still requires the appraiser to develop an opinion of value?
A model returns an estimate far from the appraiser's own conclusion. What is the appropriate response?
What does it mean that a tool cannot comply with USPAP?
An appraiser is asked to review an assignment where an AVM supplied the value. What does the review examine?
Why is the date a data extract was pulled worth recording in the workfile?
A desktop appraisal is best described as an assignment completed how?
People Also Study
Real Estate Market
13.6% of exam
Property Description
11.8% of exam
Land or Site Valuation
4.5% of exam
Sales Comparison Approach
16.4% of exam
Cost Approach
13.6% of exam
