Insight
PCI DSS in banking: issuers, acquirers and the merchants they serve
PCI DSS in banking touches two roles at once. Banks protect card data they hold themselves, and as acquirers they make sure their merchants validate too.
- Not a QSA, stated first
- Introductions to independent QSAs
- Written answers, no call
Where PCI DSS in banking applies
Banks that issue cards store and process account data. Therefore those environments fall under PCI DSS. Also, banks that acquire for merchants carry obligations under card brand rules.
So a single bank may need to manage both its own compliance and that of thousands of merchants.
Issuers and PCI DSS in banking
Issuing brings unusual data needs. For example, some sensitive authentication data may be stored by issuers when there is a documented business need and strong protection.
| Role | Typical focus |
|---|---|
| Issuer | Card production data, authorisation systems, sensitive data controls |
| Acquirer | Merchant oversight and reporting to card brands |
| Both | Their own PCI DSS validation |
PCI DSS in banking readiness check
Tick what is true for your institution.
Your result appears here as you tick, so you can see what is still open.
Acquirers and PCI DSS in banking
Acquirers decide how merchants validate. Also, they report compliance to card brands. As a result, merchants often meet PCI DSS first through their bank's requests.
- Setting merchant validation requirements
- Collecting questionnaires and attestations
- Applying non-compliance fees under contract
- Supporting merchants after a suspected breach
Common challenges
Legacy systems often hold card data in unexpected places. Therefore discovery matters. Also, many banks rely on processors, so third-party oversight is a large part of the work.
In addition, PCI DSS sits alongside banking regulation. So controls should map to both, to avoid duplicate evidence.
Where Winslow helps
We help banks scope card data, organise evidence and build merchant programmes. We are not a QSA. Gap analysis generally runs $8,000 to $40,000, with remediation on top. Standards are in the PCI SSC document library.
Also coordinate internal teams early. Because card programmes cross payments, technology and risk functions, ownership can blur. So a single accountable lead keeps evidence consistent. In addition, align assessment dates with other audit cycles, because shared evidence then serves several reviews at once.
PCI DSS in banking questions
Does PCI DSS in banking apply to small banks?
Yes, wherever the bank stores, processes or transmits account data.
Can issuers store sensitive data under PCI DSS in banking?
In limited cases, with a business need and strong protection.
Why do acquirers ask merchants about PCI DSS in banking terms?
Because card brands hold acquirers responsible for their merchants.
Does PCI DSS replace banking regulation?
No. It is a separate industry standard.
Related guides
Plan PCI DSS in banking with clear scope
Describe your card programmes. We reply in writing, usually within one business day.
Ask us anything