PCI DSS 12.4.2.1 (service providers): Reviews conducted in accordance with Requirement 12.4.2 are documented
PCI DSS v4.0.1 control 12.4.2.1: the requirement in full, the 1 testing procedure an assessor uses to verify it, and the related controls in section 12.4.
Requirement 12: Support Information Security with Organizational Policies and Programs › Section 12.4
Additional requirement for service providers only: Reviews conducted in accordance with Requirement 12.4.2 are documented to include:
- Results of the reviews.
- Documented remediation actions taken for any tasks that were found to not be performed at Requirement 12.4.2.
- Review and sign-off of results by personnel assigned responsibility for the PCI DSS compliance program.
Summary
Service providers: write down what the quarterly reviews found, what was fixed, and get it signed off.
What the assessor will examine
These are the testing procedures the standard defines for this control. They tell you what evidence to have ready.
| Procedure | |
|---|---|
| 12.4.2.1 | Additional testing procedure for service provider assessments only: Examine documentation from the reviews conducted in accordance with PCI DSS Requirement 12.4.2 to verify the documentation includes all elements specified in this requirement. |
The documentation half of 12.4.2, and three elements: results of the reviews, documented remediation actions for any tasks found not to be performed, and review and sign-off by personnel assigned responsibility for the PCI DSS compliance program. That last one connects directly to 12.4.1: the sign-off belongs to whoever holds the programme accountability that control establishes, so an entity without a named programme owner cannot satisfy this element. The middle element is where the control has teeth. A quarterly review that finds a task was not performed and produces no remediation record has been performed and not acted on, which is the same shape as 10.4.3 for log anomalies and 1.2.7 for firewall rules.
What to prepare
- Documented results for each quarterly review.
- Remediation records for anything found not performed.
- Sign-off by the compliance programme owner, dated.
- The link to whoever holds the 12.4.1 accountability.
How to implement it
1. Record findings even when everything passed. "All five tasks evidenced for the quarter" is the result, and a review with no artefact looks identical to no review.
2. Track remediation to closure. The element is remediation actions taken, so an action raised and not completed leaves it partly met.
3. Route sign-off to the programme owner, not to the team that performed the review.
4. Use one template per quarter covering results, remediation and sign-off, so all three elements are captured together.
Where this commonly fails
- Reviews performed with results held informally and nothing documented.
- Findings recorded and remediation left implicit.
- Sign-off by the reviewer rather than by the compliance programme owner.
- No named programme owner, so the third element has nobody to satisfy it.
Related controls
This control refers to 12.4.2.
Others in section 12.4:
| Control | What it requires |
|---|---|
| 12.4.1 | Service providers: Responsibility is established by executive management for the protection of cardholder data… |
| 12.4.2 | Service providers: Reviews are performed at least once every three months to confirm that personnel are performing… |
← 12.4.2 · All controls · 12.5.1 →
Source
The requirement text and testing procedures above are reproduced from PCI DSS v4.0.1 (June 2024), ©2006-2024 PCI Security Standards Council, LLC. All rights reserved. The commentary is our own.
The official standard is authoritative and also contains the Customized Approach Objective, applicability notes and guidance for this control. Download it from the PCI Security Standards Council document library. PCI DSS is a registered standard of the PCI Security Standards Council, LLC, which does not endorse this site. Nothing here is a substitute for advice from a Qualified Security Assessor.