
Why Many Fintechs Can’t Answer Their Auditor’s First Question
Key takeaway Answering “Where does the cardholder data live?” shouldn’t require a diagnostic action. Fintechs need to answer this cleanly to avoid overrunning their budget. A vendor’s PCI Attestation of Compliance (AoC) only covers PCI DSS Requirement 9; the others are the customer organization’s responsibility. Scope reduction is the simplest way to lower compliance costs. Fintechs that reduce the CDE through tokenization …








