Skip to content

    How a Fintech Can Reduce PCI Scope

    Reducing PCI Scope

    The cost of maintaining PCI-DSS compliance can have a significant impact on the operating costs of any fintech. Whether the platform is trying to attain and remain at the highest point, or play by the rules at a lower transaction level, they must pay close attention, and dedicate significant resources to everything they do that includes customer personally identifiable information.

    A fintech that issues cards, moves remittances, or processes payments on behalf of a business doesn’t just inherit PCI scope, it multiplies it. Every partner, processor, and downstream API that touches raw card data pulls another system into scope.

    Fintechs and merchant platforms are always looking for ways to reduce their PCI scope and resource drain of PCI-DSS compliance efforts because every dollar not spent on compliance is available to be deployed to revenue-generating programs. With a third-party vault, PCI scope can be reduced by as much as 90%.

    What is PCI-DSS?

    PCI-DSS is the Payment Card Industry Data Security Standard and is a set of processes, requirements, and measurements that ensure fintechs properly secure their customers’ payment details. PCI-DSS was introduced in 2004 as online payments started to ramp up when both merchants and payment system operators recognized that data breaches, hacking, and other criminality would dampen a rapidly growing e-commerce industry: users who were afraid their cardholder data could be stolen and used without their permission were leery of paying for goods and services online.

    All fintech platforms seeking to accept payments via credit card are required to adhere to the PCI-DSS standard, which has four levels, based largely on volume.

    Since 2004, the standard has been updated repeatedly, most recently to PCI DSS version 4.0.1, which is now the only active version. As of March 2025, all 51 future-dated requirements introduced in version 4.0 became mandatory, meaning every 2026 assessment tests the full standard with no transition-period exceptions.

    As volumes grow, the complexity, resource requirements, and cost increase steadily at each phase. This cost is the primary reason fintechs seek to outsource PCI compliance. The smaller the proportion of their payment system that comes under PCI-DSS scope, the lower the drain on business economics.

    Return to Top

    Which payment systems fall under PCI-DSS scope? 

    Any part of a system that touches or provides access to consumer personally identifiable information falls under PCI-DSS's scope.

    The implications are significant, as this information may be made available to, for instance, customer service representatives, triggering a need to ensure a range of physical restrictions (locked doors with electronic tracking of entries and exits to the workspace, for instance) that can be onerous.

    By contrast, systems that do not provide access to cardholder data may be held to a lesser standard. If representatives do not, for instance, have access to meaningful cardholder data, their workspace may not need the same level of scrutiny; similarly, databases that do not hold any PII are unlikely to require the same level of security as those that do.

    This is exactly the calculation Ansa made as it built its payments platform. With a lean team and limited resources to allocate to compliance overhead, the company deliberately chose to keep cardholder data out of its systems entirely. As Ansa co-founder Sophia Goldberg put it, the team stays focused on what its merchants need.

    “Anything that we don't need to touch right now we don’t,” Goldberg said. “If there's a vendor and a partner we can trust, let's use them instead.”

    Return to Top

    How can a fintech reduce PCI scope? 

    There are a range of ways for fintechs to reduce PCI-DSS scope, including

    • Don’t store primary account numbers (PAN). These are the actual numbers stored on credit cards, which can be used to make purchases. One way to avoid storing these is using a full-service payment services provider (PSP), who will keep control of the numbers on your behalf.
    • Store PAN only in a hard-to-reach corner of your system, and keep it away from other systems and people who might otherwise need to be considered in scope.
    • Contract with a provider to collect and securely manage PII, providing you with a token to use for future transactions without limitation to a single PSP.

    A programmable payment vault eliminates the risk of a systems breach, as the information you store there is tokenized and cannot be returned to its original plain text form. It also allows the fintech to limit the information shared with employees and contractors, providing enough for quality customer service without exposing data unnecessarily.

    For instance, you can collect the PII in your vault and receive a token to use. You can then:

    • Programmatically instruct the vault to submit a transaction to your choice of PSP. You can switch between PSPs as you prefer, taking advantage of the best fee schedules, volume discounts, and specialty services, without the concern that you might lose control of your customer data (as would be the risk with committing to a single PSP.)
    • Allow your customer service team access to only the information you need them to have to service support requests—even obscure them entirely by, for instance, having them type the last four digits of a credit card number into the system as dictated by the customer and have the system decide whether the entry is correct—without revealing the numbers you have stored.
    • Direct the vault to deliver select information to any approved endpoint for a variety of reasons. Anything you store that should remain protected within your system to avoid it falling within PCI-DSS scope can be managed and redirected by your payments decisioning engine.

    Companies like Basis Theory have a shared responsibility matrix, which takes ownership of as much as 90% of the PCI compliance requirements. The remaining 10% is perfect for automation.

    Reducing your PCI scope isn’t just a compliance win, it opens the door to revenue lines like branded card issuing. Without the compliance burden, launch a program with a programmable payments vault as the foundation.

    Return to Top

    Stay Connected

    Receive the latest updates straight to your inbox