Skip to content
Winslow Compliance Partners
Our position, stated first. Winslow is not a Qualified Security Assessor, so we do not assess, sign Reports on Compliance or certify anybody. We prepare you and also introduce independent QSA firms.

Insight

PCI DSS in banking: issuers, acquirers and the merchants they serve

PCI DSS in banking touches two roles at once. Banks protect card data they hold themselves, and as acquirers they make sure their merchants validate too.

  • Not a QSA, stated first
  • Introductions to independent QSAs
  • Written answers, no call
Pci dss in banking: map your roles, scope card data and oversee merchants

Where PCI DSS in banking applies

Banks that issue cards store and process account data. Therefore those environments fall under PCI DSS. Also, banks that acquire for merchants carry obligations under card brand rules.

So a single bank may need to manage both its own compliance and that of thousands of merchants.

Issuers and PCI DSS in banking

Issuing brings unusual data needs. For example, some sensitive authentication data may be stored by issuers when there is a documented business need and strong protection.

RoleTypical focus
IssuerCard production data, authorisation systems, sensitive data controls
AcquirerMerchant oversight and reporting to card brands
BothTheir own PCI DSS validation

PCI DSS in banking readiness check

Tick what is true for your institution.

Your result appears here as you tick, so you can see what is still open.

Acquirers and PCI DSS in banking

Acquirers decide how merchants validate. Also, they report compliance to card brands. As a result, merchants often meet PCI DSS first through their bank's requests.

  • Setting merchant validation requirements
  • Collecting questionnaires and attestations
  • Applying non-compliance fees under contract
  • Supporting merchants after a suspected breach

Common challenges

Legacy systems often hold card data in unexpected places. Therefore discovery matters. Also, many banks rely on processors, so third-party oversight is a large part of the work.

In addition, PCI DSS sits alongside banking regulation. So controls should map to both, to avoid duplicate evidence.

Where Winslow helps

We help banks scope card data, organise evidence and build merchant programmes. We are not a QSA. Gap analysis generally runs $8,000 to $40,000, with remediation on top. Standards are in the PCI SSC document library.

Also coordinate internal teams early. Because card programmes cross payments, technology and risk functions, ownership can blur. So a single accountable lead keeps evidence consistent. In addition, align assessment dates with other audit cycles, because shared evidence then serves several reviews at once.

PCI DSS in banking questions

Does PCI DSS in banking apply to small banks?

Yes, wherever the bank stores, processes or transmits account data.

Can issuers store sensitive data under PCI DSS in banking?

In limited cases, with a business need and strong protection.

Why do acquirers ask merchants about PCI DSS in banking terms?

Because card brands hold acquirers responsible for their merchants.

Does PCI DSS replace banking regulation?

No. It is a separate industry standard.

Related guides

Plan PCI DSS in banking with clear scope

Describe your card programmes. We reply in writing, usually within one business day.

Ask us anything