REGULATIONS AND FRAMEWORKS
PCI DSS
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Payments · Industry standard
How to use and verify
- Open Audit Evidence in the organization account. In the regulatory program tab, select the reference and record applicability and obligations defined by your organization.
- Attach evidence references and submit obligations for review by another administrator. Preserve the rationale and follow revisions.
- Export the complete dossier and check the records, period and file integrity. Internal review does not replace regulatory assessment.
What the evidence demonstrates
Records show declared content, its owners and revisions. Technical artifacts depend on available integrations, data and period. Export integrity does not confirm that a declaration is true.
Responsibilities and official source
Your organization determines applicability, validates information, carries out measures and obtains the necessary external opinions and assessments. Internal review or risk acceptance does not constitute certification or turn a control into compliance.
Consult official source — PCI DSS