Scope and payment flows
Following cardholder data, connected systems and the services that can affect the security of the environment.
I assess how organisations protect payment environments, manage cardholder data and sustain PCI DSS controls in practice.
Card payments depend on more than one platform. People, applications, networks, processors, cloud services and third parties all shape the security of the transaction.
My work as a PCI Qualified Security Assessor focuses on how those parts fit together, where payment data travels and whether the controls expected by PCI DSS are properly designed and operating.
Following cardholder data, connected systems and the services that can affect the security of the environment.
Evidence-based assessment of applicable requirements, including documentation, interviews, observation and technical testing.
Understanding shared responsibility, contractual coverage and the controls that remain with the customer.
Building ownership and evidence into normal operations rather than treating compliance as an annual event.
Payment businesses in African markets operate across banks, mobile money, fintech infrastructure, merchants and international payment networks. The standard remains global. Its implementation must still make sense in the local operating environment.
That requires technical accuracy, clear evidence and a realistic understanding of how organisations here build and run payment systems.