Managing PCI Scope Without Losing Control
PCI compliance costs fintechs and platforms far more than the audit fee. Any fintech that is accepting credit cards has a duty to protect their customers’ personally identifiable information (PII), and PCI DSS is the standard that governs how.
While nobody could credibly argue that having a carefully-crafted, broadly-agreed upon standard is a bad thing for security and customer protections, the weight of maintaining PCI compliance can be a drag on any company’s growth.
Thankfully, there are approaches that can reduce the cost and automate portions of PCI compliance, delivering the same critical benefits to consumers while acting as the foundation for company growth and profitability.
What is PCI compliance?
The PCI-DSS standard is a framework supported by all the major credit card companies to ensure that consumer information is properly protected. PCI compliance governs processes that include collection, storage, processing, and transmission of all PII. As online business has expanded and accelerated, so too has the PCI-DSS standard.
In a nutshell, PCI-DSS dictates the boundaries of what a business can do with credit card data, how it must be stored, and handled. This can be ensuring all online interactions are SSL-protected, to providing clear audit reports of which individuals have seen the details, to ensuring physical locations where data is stored are properly secured. As transaction volumes increase, so do the PCI requirements, including, eventually, having a third-party auditor examine and confirm self-reported PCI compliance policies, procedures, and operations.
Do I have to be PCI compliant to process credit cards?
Technically you can process credit cards without having PCI compliance in order, but that’s risky!
Not only do the card networks levy non-compliance fees, they also charge higher fees, and are more likely to close merchant accounts leaving them unable to take card payments from consumers.
Equally importantly, failing to achieve PCI compliance can imply that the business’s payment systems are insecure, representing a tempting target for hackers and data thieves. And for a fintech, a breach doesn't just cost money. It's the fastest way to lose the trust of the banks, processors, and customers the whole business depends on.
So the honest answer is: you can process cards without being PCI compliant, but every fintech serious about scale treats compliance as table stakes, not an optional cost center to defer.
Is managing PCI compliance expensive?
Yes, and the cost curve is steep.
Achieving and maintaining PCI compliance is initially relatively easy and low-cost, and ultimately expensive and onerous. PCI-DSS includes four levels:
- Level 4: Less than 20,000 transactions annually. Largely managed by providing a self-assessment and arranging quarterly scans by an approved scanning vendor (ASV) to test for obvious vulnerabilities.
- Level 3: Between 20,000 and one million transactions annually, and all e-commerce merchants. Similar to Level 4, this is largely self-reported.
- Level 2: Between one and six million transactions annually. Now things get a bit more complicated - merchants here must include a Report of Compliance (ROC), though they can do the compliance check themselves
- Level 1: Over six million transactions annually. Now things accelerate rapidly, because the Report of Compliance now needs to be provided by a Qualified Security Assessor (QSA), which is an external auditor.
For a fintech operating at Level 1 volume, PCI can be intrusive, time-consuming and expensive. Annual compliance costs can run upward of $200,000, without internal engineering and security time spent preparing for an audit or assessment.
One of the key ways that a fintech company will reduce the cost of PCI compliance is to pass customer data management off to a downstream provider, often their payment services provider (PSP).
Most of the full-service PSPs offer a tokenization service, in which the PSP maintains control of the actual data and provides an unencrypted token to the merchant. This, in turn, reduces the PCI scope of the systems, as protectable data never enters their processes. However, when accepting the services of a PSP, the fintech will effectively cede control of the customer data. If the fintech should choose to switch PSPs, or want to add another, they are highly unlikely to be able to access the underlying customer information.
This will mean requiring every customer with stored information to reenter it for subsequent transactions (future purchase, subscription payments, etc.) Given the benefits of tokenization, but the disadvantages of using a PSP-provided service, many fintech companies are turning to a programmable token vault.
A programmable token vault can enable a multi-processor strategy, allowing a fintech company to submit transactions to a functionally infinite number of downstream providers, while retaining control of their own data.
How does PCI Compliance impact a multi-processor setup?
Any business almost universally wants, and needs, to implement a multi-processor payments strategy in order to protect and grow their revenue. At its core, the number one concern is business continuity: a merchant with only a single PSP runs the risk that that provider may suffer downtime, effectively eliminating the merchant’s ability to do business
Increasingly importantly, merchants are seeking to:
- Manage processing fees by directing transactions to lower-cost PSPs.
- Deliver transactions to specialized or geographically-dispersed PSP partners, to increase their transaction close rate.
- Create leverage in their PSP relationships by not committing entirely to a single provider.
- Ensure ownership of customer data that can be transmitted to their provider of choice.
While it’s entirely possible to run a multi-processor system by holding customer card information in their own systems, payment leaders are discovering that safeguarding that amount of PII is expensive and risky. The use of a third party tokenization provider solves both problems: keeping PCI compliance costs low, while ensuring access to any PSP partner.