Answers to the questions practitioners most commonly ask about Layering.
Is layering a defined term within PCI DSS or the payment security standards?
No. Layering is not a control or defined term in PCI DSS, PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, or PCI 3DS. Within the broader financial-crime domain, layering has an established meaning as a stage of money laundering, but that concept is governed by anti-money-laundering frameworks and regulations rather than by the PCI standards. Readers should not expect to find layering as a numbered PCI DSS requirement, and any AML use of the term should be confirmed against current authoritative AML guidance rather than PCI documentation.
Does 'layering' here mean the same thing as 'defense in depth' or layered security controls?
Not necessarily, and the two should not be conflated. In an information-security context, practitioners sometimes speak informally of layering security controls, which overlaps with the concept of defense in depth. In the financial-crime context, layering refers instead to a stage of the money-laundering process. Because the same word carries different meanings in different domains, an entry that uses it should state which sense is intended and avoid presenting the security-architecture sense and the AML sense as interchangeable.
How does the concept relate to fraud and transaction monitoring programs in a payments environment?
Payment processors and merchant risk teams that operate transaction-monitoring or suspicious-activity programs may encounter layering as part of AML typologies rather than PCI scope. Detection of such patterns typically relies on behavioral analytics and rules that carry inherent false-positive and false-negative trade-offs. Any monitoring obligation, its scope, and its limitations are defined by the applicable AML regulatory framework for the entity and region, not by the PCI standards, so implementation should be aligned to that governing authority.
Where should a compliance officer look to confirm the authoritative definition and obligations?
For the AML sense of the term, confirm the definition and any obligations against current authoritative sources appropriate to your jurisdiction, such as FATF guidance and the relevant national financial-intelligence or regulatory authority. For anything relating to cardholder data protection, consult the current published PCI DSS and the applicable PCI standard directly, since requirement numbering and wording differ between versions. Do not rely on a fixed requirement number or a single secondary summary.
If our program spans both PCI DSS and AML obligations, how should the term be handled to avoid scope confusion?
Keep the two frameworks and their controls documented separately, and label which regime governs each requirement. Cardholder data protection controls fall under PCI DSS and the related PCI standards, while transaction-based financial-crime controls fall under the applicable AML regime. When a policy or glossary references layering, specify the intended domain so that engineers, fraud analysts, and auditors do not misattribute an AML concept to a PCI requirement or vice versa.
What are the known limitations of controls associated with detecting this activity?
Detection controls associated with financial-crime monitoring are intended to help identify suspicious patterns but do not prevent or guarantee elimination of illicit activity. They involve tuning trade-offs, where tighter thresholds increase false positives and looser thresholds increase false negatives. The precise effectiveness, thresholds, and reporting duties depend on the governing AML framework, the institution's risk profile, and the region, and exact performance figures depend on source, period, and methodology.