PCI DSS 12.4.1 (service providers): Responsibility is established by executive management for the protection of cardholder data
PCI DSS v4.0.1 control 12.4.1: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.4.
Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.4
Additional requirement for service providers only: Responsibility is established by executive management for the protection of cardholder data and a PCI DSS compliance program to include:
- Overall accountability for maintaining PCI DSS compliance.
- Defining a charter for a PCI DSS compliance program and communication to executive management.
Summary
Service providers: executive management owns PCI DSS compliance, in writing, with a charter.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 12.4.1 | Additional testing procedure for service provider assessments only: Examine documentation to verify that executive management has established responsibility for the protection of cardholder data and a PCI DSS compliance program in accordance with all elements specified in this requirement. |
Service providers only, and it is the accountability counterpart to 12.1.4. Where that control assigns information security to an executive, this assigns PCI DSS compliance specifically, and it has two elements: overall accountability for maintaining PCI DSS compliance, and defining a charter for a PCI DSS compliance program and communication to executive management. The charter is the part entities do not have. It is what turns compliance from an annual assessment project into a programme with scope, objectives and reporting, and the requirement asks that it be communicated to executive management rather than merely written. The distinction from 12.1.4 matters practically: an organisation can have a capable CISO accountable for security and nobody accountable for the compliance programme, which is how an assessment becomes a scramble.
What to prepare
- Documentation showing executive management established the responsibility.
- The named executive holding overall accountability for PCI DSS compliance.
- The programme charter.
- Evidence it was communicated to executive management.
How to implement it
1. Write the charter, since it is the missing element. Scope, objectives, who does what, and how progress is reported is enough, and it is what makes the programme continuous.
2. Name the accountable executive explicitly, and check whether it should be the same person as 12.1.4 or a different one. Either is defensible; leaving it implied is not.
3. Communicate it upward and record that. Communication to executive management is a named element, so minutes or a distribution record is the artefact.
4. Review it when the business changes. A charter written for a smaller organisation stops describing what happens.
Where this commonly fails
- Accountability assumed to follow from 12.1.4, when this control is separate and service-provider specific.
- A compliance programme with no charter, so it exists as an annual project.
- A charter written and never communicated to executive management.
- A merchant applying this, when it is a service provider requirement.
Related controls
Others in section 12.4:
| Control | What it requires |
|---|---|
| 12.4.2 | Service providers: Reviews are performed at least once every three months to confirm that personnel are performing… |
| 12.4.2.1 | Service providers: Reviews conducted in accordance with Requirement 12.4.2 are documented… |
← 12.3.4 · All controls · 12.4.2 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.