Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Technology > PCI COMPLIANCE – WHY PCI DE-SCOPING SAVES YOU MONEY
    Technology

    PCI COMPLIANCE – WHY PCI DE-SCOPING SAVES YOU MONEY

    PCI COMPLIANCE – WHY PCI DE-SCOPING SAVES YOU MONEY

    Published by Gbaf News

    Posted on November 1, 2013

    Featured image for article about Technology

    By Rob Crutchington – Director at Encoded

    Every business or merchant that accepts payment via debit and credit cards has a contractual obligation with its acquiring bank (or acquirer) to be PCI DSS compliant.  The Payment Card Industry Data Security Standard (PCI DSS) was created by Visa®, MasterCard®, JBC®, Discover® and American Express® and is made up of 12 requirements designed to standardise controls surrounding card holder data and to help protect consumers and merchants against security breaches.

    Rob Crutchington

    Rob Crutchington

    To become PCI compliant the 12 requirements, consisting of 258 controls, must be implemented and the cost of this to a business can range from the tens of thousands to the tens of millions of pounds. To many, the costs involved can be prohibitive but there is money to be saved by undertaking a program of reducing the scope of the cardholder data environment (or de-scoping).

    What is de-scoping?
    To be PCI compliant organisations have to demonstrate that they have reached a level of security awareness and competence to a point where the risk of losing debit and credit card data is regarded as less than that of a non-PCI compliant organisation.  De-scoping is the process to reduce the number of requirements (tick-boxes) for PCI compliance.  This can be achieved by passing the responsibility of handling card data to a third party. As the merchant account agreement is between the merchant and the acquirer, the responsibility for PCI compliance cannot be entirely removed, however the amount of time and work required demonstrating compliance can be dramatically reduced.

    How to de-scope
    To begin the process of de-scoping it is essential to identify where in an organisation card data is handled.  This is usually in the contact centre or wherever card holder data is being processed.  There are many options available to organisations that regularly take card payments over the telephone.  For example working with an interactive payment solutions company such as Encoded allows organisations to offer either IVR (interactive voice response) or virtual terminal payment options.  Automated IVR payments reduce contact centre agent involvement and can be available 24x7x365 days of the year.  Virtual Terminal payments allow agents to take payment over the telephone by logging into a secure online virtual terminal interface to in-put card details directly or conferencing in the customer who uses their touchtone telephone to securely enter their card details themselves. Tokenisation is another way of keeping card data safe and out of scope of the PCI process. Tokenisation is the process of replacing card data with random numbers that, when used within a specific payment gateway, reference back to the actual card data without compromising its security.  Tokens can be used repeatedly by merchants where payments are regularly made.

    Why de-scoping saves money
    Taking areas of an organisation’s business out of the scope of PCI compliance minimises the cost and complexity associated with PCI DSS standards.  As mentioned before a PCI project can cost anything from £10k to several millions of pounds plus there is a requirement for quarterly network scans and an annual audit.  External Qualified Security Assessor (QSA) fees are typically £1000 per day which can rule out smaller merchants and can soon add up for larger organisations.  By working with a fully Level 1 PCI compliant interactive payment solutions supplier to de-scope, by removing customer card data from the process, means there is less for the QSA to audit.  Therefore, by de-scoping PCI compliance can be achieved in less time and with a much reduced price tag.

    Remember the buck stops with the merchant to ensure PCI compliance.  However, whether customer card data is handled within a contact centre, via web pages or a chip and pin terminal, PCI compliant payment companies such as Encoded, offer solutions to ensure compliance is achieved with minimum cost and maximum security.

    About Encoded
    Encoded is a leading provider of interactive voice response solutions and automated payment solutions. Encoded has invested in achieving the highest level of PCI DSS compliance.  It has a Level 1 Attestation of Compliance (AOC) which applies to organisations that store, process and/or transmit more than 300,000 Visa transactions per year it also appears on the Visa Europe Merchant Agents List http://www.visasmerchantslist.com

    All the company’s services are designed to fulfil three key objectives:

    • Reduce costs by automating business processes
    • Increase sales by offering new fulfilment channels
    • Improve customer service by maximising resource efficiency

    Encoded was established in 2001 to offer affordable, pay-as-you-go solutions to the growing payment handling requirements of small and large businesses. Today, the company’s software regularly supports 30 million customers and 10 million calls globally and automates £100 million of secure payments without operator intervention.
    For more information please visit www.encoded.co.uk

    By Rob Crutchington – Director at Encoded

    Every business or merchant that accepts payment via debit and credit cards has a contractual obligation with its acquiring bank (or acquirer) to be PCI DSS compliant.  The Payment Card Industry Data Security Standard (PCI DSS) was created by Visa®, MasterCard®, JBC®, Discover® and American Express® and is made up of 12 requirements designed to standardise controls surrounding card holder data and to help protect consumers and merchants against security breaches.

    Rob Crutchington

    Rob Crutchington

    To become PCI compliant the 12 requirements, consisting of 258 controls, must be implemented and the cost of this to a business can range from the tens of thousands to the tens of millions of pounds. To many, the costs involved can be prohibitive but there is money to be saved by undertaking a program of reducing the scope of the cardholder data environment (or de-scoping).

    What is de-scoping?
    To be PCI compliant organisations have to demonstrate that they have reached a level of security awareness and competence to a point where the risk of losing debit and credit card data is regarded as less than that of a non-PCI compliant organisation.  De-scoping is the process to reduce the number of requirements (tick-boxes) for PCI compliance.  This can be achieved by passing the responsibility of handling card data to a third party. As the merchant account agreement is between the merchant and the acquirer, the responsibility for PCI compliance cannot be entirely removed, however the amount of time and work required demonstrating compliance can be dramatically reduced.

    How to de-scope
    To begin the process of de-scoping it is essential to identify where in an organisation card data is handled.  This is usually in the contact centre or wherever card holder data is being processed.  There are many options available to organisations that regularly take card payments over the telephone.  For example working with an interactive payment solutions company such as Encoded allows organisations to offer either IVR (interactive voice response) or virtual terminal payment options.  Automated IVR payments reduce contact centre agent involvement and can be available 24x7x365 days of the year.  Virtual Terminal payments allow agents to take payment over the telephone by logging into a secure online virtual terminal interface to in-put card details directly or conferencing in the customer who uses their touchtone telephone to securely enter their card details themselves. Tokenisation is another way of keeping card data safe and out of scope of the PCI process. Tokenisation is the process of replacing card data with random numbers that, when used within a specific payment gateway, reference back to the actual card data without compromising its security.  Tokens can be used repeatedly by merchants where payments are regularly made.

    Why de-scoping saves money
    Taking areas of an organisation’s business out of the scope of PCI compliance minimises the cost and complexity associated with PCI DSS standards.  As mentioned before a PCI project can cost anything from £10k to several millions of pounds plus there is a requirement for quarterly network scans and an annual audit.  External Qualified Security Assessor (QSA) fees are typically £1000 per day which can rule out smaller merchants and can soon add up for larger organisations.  By working with a fully Level 1 PCI compliant interactive payment solutions supplier to de-scope, by removing customer card data from the process, means there is less for the QSA to audit.  Therefore, by de-scoping PCI compliance can be achieved in less time and with a much reduced price tag.

    Remember the buck stops with the merchant to ensure PCI compliance.  However, whether customer card data is handled within a contact centre, via web pages or a chip and pin terminal, PCI compliant payment companies such as Encoded, offer solutions to ensure compliance is achieved with minimum cost and maximum security.

    About Encoded
    Encoded is a leading provider of interactive voice response solutions and automated payment solutions. Encoded has invested in achieving the highest level of PCI DSS compliance.  It has a Level 1 Attestation of Compliance (AOC) which applies to organisations that store, process and/or transmit more than 300,000 Visa transactions per year it also appears on the Visa Europe Merchant Agents List http://www.visasmerchantslist.com

    All the company’s services are designed to fulfil three key objectives:

    • Reduce costs by automating business processes
    • Increase sales by offering new fulfilment channels
    • Improve customer service by maximising resource efficiency

    Encoded was established in 2001 to offer affordable, pay-as-you-go solutions to the growing payment handling requirements of small and large businesses. Today, the company’s software regularly supports 30 million customers and 10 million calls globally and automates £100 million of secure payments without operator intervention.
    For more information please visit www.encoded.co.uk

    Related Posts
    Treasury transformation must be built on accountability and trust
    Treasury transformation must be built on accountability and trust
    Financial services: a human-centric approach to managing risk
    Financial services: a human-centric approach to managing risk
    LakeFusion Secures Seed Funding to Advance AI-Native Master Data Management
    LakeFusion Secures Seed Funding to Advance AI-Native Master Data Management
    Clarity, Context, Confidence: Explainable AI and the New Era of Investor Trust
    Clarity, Context, Confidence: Explainable AI and the New Era of Investor Trust
    Data Intelligence Transforms the Future of Credit Risk Strategy
    Data Intelligence Transforms the Future of Credit Risk Strategy
    Architect of Integration Ushers in a New Era for AI in Regulated Industries
    Architect of Integration Ushers in a New Era for AI in Regulated Industries
    How One Technologist is Building Self-Healing AI Systems that Could Transform Financial Regulation
    How One Technologist is Building Self-Healing AI Systems that Could Transform Financial Regulation
    SBS is Doubling Down on SaaS to Power the Next Wave of Bank Modernization
    SBS is Doubling Down on SaaS to Power the Next Wave of Bank Modernization
    Trust Embedding: Integrating Governance into Next-Generation Data Platforms
    Trust Embedding: Integrating Governance into Next-Generation Data Platforms
    The Guardian of Connectivity: How Rohith Kumar Punithavel Is Redefining Trust in Private Networks
    The Guardian of Connectivity: How Rohith Kumar Punithavel Is Redefining Trust in Private Networks
    BNY Partners With HID and SwiftConnect to Provide Mobile Access to its Offices Around the Globe With Employee Badge in Apple Wallet
    BNY Partners With HID and SwiftConnect to Provide Mobile Access to its Offices Around the Globe With Employee Badge in Apple Wallet
    How Integral’s CTO Chidambaram Bhat is helping to solve  transfer pricing problems through cutting edge AI.
    How Integral’s CTO Chidambaram Bhat is helping to solve transfer pricing problems through cutting edge AI.

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Previous Technology PostBLACKLINE FINANCIAL CLOSE SUITE FOR SAP® SOLUTIONS BECOMES AN SAP-ENDORSED BUSINESS SOLUTION
    Next Technology PostTHE NEW KID ON THE BLOCK: WHY IS PAAS HERE TO STAY?

    More from Technology

    Explore more articles in the Technology category

    Why Physical Infrastructure Still Matters in a Digital Economy

    Why Physical Infrastructure Still Matters in a Digital Economy

    Why Compliance Has Become an Engineering Problem

    Why Compliance Has Become an Engineering Problem

    Can AI-Powered Security Prevent $4.2 Billion in Banking Fraud?

    Can AI-Powered Security Prevent $4.2 Billion in Banking Fraud?

    Reimagining Human-Technology Interaction: Sagar Kesarpu’s Mission to Humanize Automation

    Reimagining Human-Technology Interaction: Sagar Kesarpu’s Mission to Humanize Automation

    LeapXpert: How financial institutions can turn shadow messaging from a risk into an opportunity

    LeapXpert: How financial institutions can turn shadow messaging from a risk into an opportunity

    Intelligence in Motion: Building Predictive Systems for Global Operations

    Intelligence in Motion: Building Predictive Systems for Global Operations

    Predictive Analytics and Strategic Operations: Strengthening Supply Chain Resilience

    Predictive Analytics and Strategic Operations: Strengthening Supply Chain Resilience

    How Nclude.ai   turned broken portals into completed applications

    How Nclude.ai turned broken portals into completed applications

    The Silent Shift: Rethinking Services for a Digital World?

    The Silent Shift: Rethinking Services for a Digital World?

    Culture as Capital: How Woxa Corporation Is Redefining Fintech Sustainability

    Culture as Capital: How Woxa Corporation Is Redefining Fintech Sustainability

    Securing the Future: We're Fixing Cyber Resilience by Finally Making Compliance Cool

    Securing the Future: We're Fixing Cyber Resilience by Finally Making Compliance Cool

    Supply chain security risks now innumerable and unmanageable for majority of cybersecurity leaders, IO research reveals

    Supply chain security risks now innumerable and unmanageable for majority of cybersecurity leaders, IO research reveals

    View All Technology Posts