A focused course, tailored for you
The Senior IT Compliance Manager Evidence Operating System
A working operating system for the merchant-acquirer IT compliance lead who runs PCI DSS v4.0.1, SOC 1, SOC 2, and the acquired-entity rollups in one calendar.
The evidence-tracker pivot has more controls than weeks left before the assessor walkthrough, and every customised approach now needs its own targeted risk analysis on file.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
The Senior IT Compliance Manager inside a global merchant acquirer sits between three pressures that do not line up. The first is PCI DSS v4.0.1, where the customised-approach option, targeted risk analyses, expanded multi-factor scope, and continuous evidence model have moved the assessor conversation away from screenshots into actual control-by-control proof. The second is the SOC 1 and SOC 2 calendar, where the service-organisation report is the artefact card-brand acquirers, ISO partners, and large merchant clients ask for, and where any control-language drift between SOC and PCI shows up as a finding. The third is acquired-entity integration. Each acquisition lands with its own ticketing platform, its own access-review cadence, its own evidence-collection habit, and a clock that says the assessor needs it inside the AOC by the next cycle. Doing all three out of three different spreadsheets does not scale. The job is one shared control mapping, one evidence schema, one set of templates the team actually uses, and a defensible position when the assessor opens up the customised-approach pages.
What you walk away with
- A single shared control mapping across PCI DSS v4.0.1, SOC 1, SOC 2, ISO 27001, and the card-brand AML asks, with one evidence object serving all of them.
- A working customised-approach register and targeted risk analysis library, structured the way a QSA expects to see it during the on-site walkthrough.
- A reusable acquired-entity compliance-integration plan that gets a new portfolio inside the AOC by the next assessment cycle without doubling the sample selection.
- A defensible evidence rhythm covering CDE access reviews, change advisory board sampling, segmentation validation, and key-management oversight, every quarter, on a written calendar.
- A board-readable IT compliance status page that translates assessor findings, customised-approach risk acceptance, and acquired-entity gaps into one risk-rated artefact.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- 12 modules of text-based course content in the Art of Service learning environment.
- Downloadable templates: CDE asset inventory, customised-approach register, targeted risk analysis template, segmentation validation pack, key-management evidence pack, acquired-entity onboarding plan, shared SOC and PCI control-mapping table, board status pack.
- Worked examples drawn from merchant-acquirer, ISO, and payments-platform IT compliance teams.
- The hand-built implementation playbook produced for your specific stack and assessor cycle, delivered alongside course access.
What you will have in hand by Day 1, Week 1, Month 1
Day 0: Course access provisioned in the Art of Service learning environment.
Day 0: Hand-built implementation playbook for the Senior IT Compliance Manager stack delivered alongside course access.
Weeks 1-2: Modules 1-3 run, the scoping reset and customised-approach register stand up.
Weeks 3-5: Modules 4-7 run, the four v4.0.1 control areas land in the evidence schema.
Weeks 6-7: Modules 8-9 run, SOC and PCI align and the acquired-entity plan is built.
Weeks 8-10: Modules 10-12 run, the continuous evidence rhythm and the board status pack go live.
Before and after
PCI, SOC 1, SOC 2, and the card-brand AML asks live in four different spreadsheets, each assessor walkthrough costs a month of evidence chasing, the customised-approach pages get written the week before the on-site, and every acquired portfolio lands as a six-month problem.
One control mapping, one evidence schema, one customised-approach register kept current month-on-month, one acquired-entity onboarding template that gets a portfolio inside the AOC by the next cycle, and a board-readable status pack the committee chair opens the discussion with.
What happens if you do not address this
Without the operating system, the next PCI DSS v4.0.1 walkthrough lands with the targeted risk analyses and customised-approach pages written under deadline, the SOC report drifts from PCI on language the merchant clients can read, and the next acquired portfolio stays outside the AOC for two cycles. None of those failures are visible until the assessor surfaces them, by which point the remediation window is gone.
Who it is for
Built for the Senior IT Compliance Manager (or Manager, IT Compliance / IT Risk and Compliance Manager) inside a card-payments, merchant-acquiring, ISO, or payments-platform business who personally owns the PCI DSS v4.0.1 assessor relationship, signs off the SOC 1 and SOC 2 control narratives, runs the acquired-entity compliance-onboarding plan, and chairs the internal evidence-review meeting that decides what goes to the external auditor.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Roughly two to three hours per module across about ten weeks. The templates are usable from week one. The full evidence operating system runs alongside the day job rather than in place of it.
Why $199 is the right number
The Big4 advisory equivalent is a six-figure engagement that ends in slides rather than a working register. The QSA can score the assessment but cannot supply the templates. The major GRC platforms supply the workflow shell but not the customised-approach pattern, the targeted risk analysis library, or the acquired-entity onboarding plan. This course is the working operating system for the role, paid once, with the implementation playbook hand-built for your stack.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.