Skip to main content
Assessor Designs Your Control, Then Validates It? That's Not CompliancePCI DSS Compliance
3 min readFor Payment Security Engineers

Assessor Designs Your Control, Then Validates It? That's Not Compliance

The Problem

An organization using PCI DSS v4.x opted for the customized approach for several requirements. They enlisted their Qualified Security Assessor (QSA) early on, seeking help to design custom controls. The assessor, aiming to assist, provided detailed guidance, suggested control architectures, and helped document the approach. When it was time for assessment, the same assessor validated the controls they had helped design.

The assessment report indicated compliance, but the principle of assessor independence was compromised. An assessor can't objectively evaluate controls they designed. The organization's compliance was flawed from the start.

How It Unfolded

Planning: The organization identified requirements suitable for a customized approach and consulted the QSA for control design guidance.

Design: The QSA gave specific recommendations, suggested architectures, and helped draft documentation. The organization implemented these suggestions.

Assessment: The same QSA conducted the assessment, validating the controls they helped create. The report showed compliance.

Aftermath: The organization assumed compliance, but the conflict of interest went unnoticed until a payment brand review or another assessor questioned the validation process.

Where It Went Wrong

The issue wasn't technical; it was procedural.

Role Confusion: The organization didn't separate control design (their job) from control validation (the assessor's job). Blurring these lines undermines assessment credibility.

Lack of Expertise: The organization lacked the expertise to design and implement customized controls independently. This indicated the customized approach wasn't suitable for them.

Missing Risk Management: Organizations ready for the customized approach have dedicated risk management functions to design and maintain controls without external help. This organization lacked that capability.

Dependent Documentation: The control documentation reflected the assessor's input, not the organization's independent analysis. It appeared complete but didn't show the entity's own design capability.

What PCI DSS v4.x Requires

Assessor Independence: The guidance mandates that assessors must be independent. An assessor involved in designing or implementing a control can't assess it. This is a fundamental requirement.

Entity Control Design: The entity must develop, implement, and maintain the control. You can't outsource this to your assessor. The customized approach requires your own design work.

Risk Maturity: The customized approach suits entities with strong risk management practices and the capacity to design, implement, and maintain controls. If you need your assessor to design your controls, you don't meet this standard.

Complete Documentation: Your documentation should clearly show how objectives are met and risks addressed. If an assessor can't validate your control from your documentation alone, it's incomplete. It should reflect your analysis and design rationale.

Action Steps for Your Team

Assess Your Risk Maturity: Before choosing the customized approach, evaluate if you can design and maintain controls independently. Ask: Do we have a dedicated risk management function? Can we design, document, and test controls without external help? If not, stick with the defined approach or compensating controls.

Set Assessor Boundaries: In your engagement letter, specify that the assessor won't provide design services for requirements they will assess. If you need design help, hire a separate consultant.

Build Internal Expertise: To use the customized approach, invest in developing internal risk and compliance expertise. Hire or train staff who understand PCI DSS objectives and your technical environment to create control designs.

Document Your Rationale: Your documentation should explain why you chose a control design, how it meets the objective, what risks you considered, and what alternatives you evaluated. This should be your narrative.

Use Assessors for Validation Only: Your QSA should evaluate if your control meets the objective, not dictate how to build it. The assessment should test your design, not validate their recommendations.

Consider Compensating Controls: If technical or business constraints prevent meeting a requirement, compensating controls might be more suitable than the customized approach. Both can coexist for the same requirement across different components.

Review Assessor Relationships: If your assessor has been providing design guidance for controls they assess, address this before your next assessment. Separate design and assessment functions or find a new assessor.

The customized approach offers flexibility for organizations with mature risk management capabilities, but it's not a shortcut. If you can't design the control independently, you're not ready for this approach.

PCI DSS official documentation

You Might Also Like