Skip to main content
Merchant SupportAgent Login
AMP Payment Systems
Menu

Payment technology and security

Who is responsible for PCI compliance?

Direct answer

Every entity that stores, processes, transmits, or can affect the security of payment account data has responsibilities for its own environment. A merchant can outsource payment functions, but it cannot outsource accountability for selecting and monitoring providers, configuring systems safely, training staff, controlling access, and completing required validation. Exact obligations should be confirmed with the merchant’s acquirer.

Author
AMP Payment Systems
Review status
Primary sources checked; no named AMP subject-matter reviewer is claimed.
Published
Modified

Key facts

  • Responsibility is shared, not transferred wholesale.
  • Service providers must be managed and their scope understood.
  • The acquirer communicates merchant validation requirements.

Merchant responsibilities

Merchants should maintain data-flow and provider inventories, secure their networks and devices, manage users, patch systems, respond to incidents, and verify that outsourced controls cover the expected functions.

Provider responsibilities

Gateways, processors, hosting companies, managed service providers, and software vendors are responsible for applicable controls in their environments, but service boundaries must be documented.

When the answer changes

  • Responsibility changes with integrations and data flows.
  • Franchise, marketplace, and managed-POS models need explicit allocation.

Common mistakes

  • Assuming a compliant processor makes the merchant compliant.
  • Failing to remove former employee access.

What to verify

  1. Create a responsibility matrix.
  2. Review provider attestations, contracts, shared controls, and validation instructions.

Primary sources

Apply the answer to your business

AMP can help organize your payment, POS, or statement questions. Any recommendation, availability, pricing, or approval depends on the final written configuration and provider terms.

Contact AMP

Merchant processing options

Tell us how your business accepts payments

Secure request

Draft saved

Do not submit SSNs, full bank account numbers, passwords, or cardholder data. Information is used to respond to your request.