Skip to main content
Image coming soon

The Senior IT Compliance Manager Evidence Operating System

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Senior IT Compliance Manager Evidence Operating System

A working operating system for the merchant-acquirer IT compliance lead who runs PCI DSS v4.0.1, SOC 1, SOC 2, and the acquired-entity rollups in one calendar.

The evidence-tracker pivot has more controls than weeks left before the assessor walkthrough, and every customised approach now needs its own targeted risk analysis on file.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

The Senior IT Compliance Manager inside a global merchant acquirer sits between three pressures that do not line up. The first is PCI DSS v4.0.1, where the customised-approach option, targeted risk analyses, expanded multi-factor scope, and continuous evidence model have moved the assessor conversation away from screenshots into actual control-by-control proof. The second is the SOC 1 and SOC 2 calendar, where the service-organisation report is the artefact card-brand acquirers, ISO partners, and large merchant clients ask for, and where any control-language drift between SOC and PCI shows up as a finding. The third is acquired-entity integration. Each acquisition lands with its own ticketing platform, its own access-review cadence, its own evidence-collection habit, and a clock that says the assessor needs it inside the AOC by the next cycle. Doing all three out of three different spreadsheets does not scale. The job is one shared control mapping, one evidence schema, one set of templates the team actually uses, and a defensible position when the assessor opens up the customised-approach pages.

What you walk away with

  • A single shared control mapping across PCI DSS v4.0.1, SOC 1, SOC 2, ISO 27001, and the card-brand AML asks, with one evidence object serving all of them.
  • A working customised-approach register and targeted risk analysis library, structured the way a QSA expects to see it during the on-site walkthrough.
  • A reusable acquired-entity compliance-integration plan that gets a new portfolio inside the AOC by the next assessment cycle without doubling the sample selection.
  • A defensible evidence rhythm covering CDE access reviews, change advisory board sampling, segmentation validation, and key-management oversight, every quarter, on a written calendar.
  • A board-readable IT compliance status page that translates assessor findings, customised-approach risk acceptance, and acquired-entity gaps into one risk-rated artefact.

The 12 modules

Module 1. The merchant-acquirer scoping reset
Rebuild the CDE inventory and the connected-systems inventory the way PCI DSS v4.0.1 expects to see it, with the acquired-portfolio assets and the ISO host platforms explicitly in or out, with the rationale documented. Walks through how to separate the cardholder data environment from the supporting-system environment, where the AOC asks for both, and how to scope the SOC 1 and SOC 2 boundary against the same diagram so the two reports do not contradict each other.
Module 2. The customised approach register
Stand up the customised-approach register the QSA wants to see. Walks through which v4.0.1 requirements actually need a customised-approach object, how to write the objective and the controls the same way the assessor reads them, how to attach the targeted risk analysis to each one, and how the customised-approach pages get reviewed by senior management on a cadence that holds up at the on-site walkthrough.
Module 3. Targeted risk analysis templates
Build the targeted risk analysis library required by PCI DSS v4.0.1 for both the customised-approach option and the periodicity-defined controls. Walks through the threat-asset inventory, the likelihood scoring grid acquirers actually use, the mitigation linkage to the customised-approach controls, and the annual review cadence that keeps the TRA pages current. Outputs a register that the assessor can sample without back-and-forth.
Module 4. Multi-factor and access governance at the CDE
Operationalise the expanded multi-factor scope under v4.0.1 across all access to the cardholder data environment, including non-console administrative access, third-party access, and access from acquired-portfolio platforms. Walks through the access-review evidence schema, the privileged-access timer cadence, the joiner-mover-leaver workflow integration with the HR system, and how to evidence each one with a single artefact rather than three.
Module 5. Change advisory board evidence
Connect the CAB process to the v4.0.1 change-management requirements so every relevant deployment carries the documented authorisation, the impact assessment on cardholder data, and the post-implementation review. Walks through the ticket-template fields the assessor samples, the segregation-of-duties evidence the QSA expects between developer, approver, and deployer, and how to handle emergency changes without breaking the sample.
Module 6. Segmentation validation that the QSA accepts
Run the annual segmentation validation the way it gets accepted on-site. Walks through the test methodology, the artefacts the QSA wants to see (firewall ruleset extracts, network-flow logs, segmentation penetration test scope and result), and how to keep the result current between annual cycles when the network changes. Outputs a segmentation evidence pack the next assessor walks into and signs.
Module 7. Key management and cryptographic inventory
Build the cryptographic-asset inventory and the key-management evidence pack covering point-of-interaction devices, the HSM estate, the application-layer encryption boundaries, and the acquired-portfolio key custodians. Walks through the dual-control evidence, the annual key rotation calendar, the post-quantum readiness statement the bigger ISO partners are now asking for, and how to align the inventory with the SOC 2 confidentiality criteria.
Module 8. SOC 1 and SOC 2 alignment with PCI
Lay out the shared control narrative so SOC 1, SOC 2 type II, and PCI DSS v4.0.1 are evidenced from one library rather than three. Walks through the description-of-the-system writing pattern, the common-control mapping table, the complementary user entity controls language that satisfies merchant clients, the auditor sample-coordination memo, and how to time the SOC report so it lands before the next PCI walkthrough.
Module 9. Acquired-entity compliance integration
Build the acquired-portfolio onboarding plan that gets a new entity inside the assessment-of-compliance boundary by the next cycle. Walks through the day-one gap assessment template, the 90-day remediation calendar, the evidence-tooling consolidation plan, the personnel-training transfer, and the assessor notification path. Covers how to handle the case where the acquired entity was on a different QSA the prior cycle.
Module 10. Continuous evidence and the assessor on-site
Move from quarterly screenshots to the continuous evidence rhythm v4.0.1 expects. Walks through the daily, weekly, monthly, and quarterly evidence cadences, the automated extract jobs that feed the evidence library, the QA pattern that catches stale evidence before the assessor does, and the on-site walkthrough script the team uses so every assessor question has a pre-staged answer.
Module 11. Card-brand AML, sanctions, and merchant due-diligence intersections
Connect the card-brand acquirer AML and merchant due-diligence requirements (Visa GMCP, Mastercard BRAM, the merchant-monitoring expectations from the issuing banks) to the IT compliance evidence stack. Walks through the merchant-monitoring data-flow diagram, the sanctions-screening evidence pack, the high-risk merchant review calendar, and the IT control linkage so the AML and the PCI evidence libraries do not duplicate.
Module 12. The board-readable IT compliance status pack
Translate the assessor findings, the customised-approach risk acceptances, the acquired-entity remediation status, and the SOC report results into one risk-rated, board-readable status pack. Walks through the page template, the risk-rating rubric, the trend chart that shows control-effectiveness over the last four quarters, and the talking points the committee chair actually opens the discussion with. Outputs the pack and the script.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Modules 1-3 hand you the scoping reset, the customised-approach register, and the targeted risk analysis library, which is what the next QSA walkthrough opens with.
Modules 4-7 cover the four control areas where v4.0.1 has moved the bar (access, change, segmentation, key management) with the evidence schema the assessor accepts.
Modules 8-9 align SOC 1, SOC 2, and PCI into one library and give you the acquired-entity onboarding plan you can run on the next portfolio inside the cycle.
Modules 10-12 are the operating cadence: continuous evidence, the AML and merchant-due-diligence intersection, and the board-readable status pack that closes the year.

What you get with this course

  • 12 modules of text-based course content in the Art of Service learning environment.
  • Downloadable templates: CDE asset inventory, customised-approach register, targeted risk analysis template, segmentation validation pack, key-management evidence pack, acquired-entity onboarding plan, shared SOC and PCI control-mapping table, board status pack.
  • Worked examples drawn from merchant-acquirer, ISO, and payments-platform IT compliance teams.
  • The hand-built implementation playbook produced for your specific stack and assessor cycle, delivered alongside course access.

What you will have in hand by Day 1, Week 1, Month 1

Day 0: Course access provisioned in the Art of Service learning environment.

Day 0: Hand-built implementation playbook for the Senior IT Compliance Manager stack delivered alongside course access.

Weeks 1-2: Modules 1-3 run, the scoping reset and customised-approach register stand up.

Weeks 3-5: Modules 4-7 run, the four v4.0.1 control areas land in the evidence schema.

Weeks 6-7: Modules 8-9 run, SOC and PCI align and the acquired-entity plan is built.

Weeks 8-10: Modules 10-12 run, the continuous evidence rhythm and the board status pack go live.

Before and after

Before

PCI, SOC 1, SOC 2, and the card-brand AML asks live in four different spreadsheets, each assessor walkthrough costs a month of evidence chasing, the customised-approach pages get written the week before the on-site, and every acquired portfolio lands as a six-month problem.

After

One control mapping, one evidence schema, one customised-approach register kept current month-on-month, one acquired-entity onboarding template that gets a portfolio inside the AOC by the next cycle, and a board-readable status pack the committee chair opens the discussion with.

What happens if you do not address this

Without the operating system, the next PCI DSS v4.0.1 walkthrough lands with the targeted risk analyses and customised-approach pages written under deadline, the SOC report drifts from PCI on language the merchant clients can read, and the next acquired portfolio stays outside the AOC for two cycles. None of those failures are visible until the assessor surfaces them, by which point the remediation window is gone.

Who it is for

Built for the Senior IT Compliance Manager (or Manager, IT Compliance / IT Risk and Compliance Manager) inside a card-payments, merchant-acquiring, ISO, or payments-platform business who personally owns the PCI DSS v4.0.1 assessor relationship, signs off the SOC 1 and SOC 2 control narratives, runs the acquired-entity compliance-onboarding plan, and chairs the internal evidence-review meeting that decides what goes to the external auditor.

Who this is NOT for. Not for first-line application engineers who only contribute evidence. Not for CISOs who do not personally close out assessor questions. Not for organisations that have never been through a PCI ROC, where the foundational scoping and CDE inventory work happens before this course is useful.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Roughly two to three hours per module across about ten weeks. The templates are usable from week one. The full evidence operating system runs alongside the day job rather than in place of it.

Why $199 is the right number

The Big4 advisory equivalent is a six-figure engagement that ends in slides rather than a working register. The QSA can score the assessment but cannot supply the templates. The major GRC platforms supply the workflow shell but not the customised-approach pattern, the targeted risk analysis library, or the acquired-entity onboarding plan. This course is the working operating system for the role, paid once, with the implementation playbook hand-built for your stack.

FAQ

Does it cover the v4.0.1 changes specifically or is it still on v4.0?
v4.0.1, including the customised-approach option, targeted risk analysis requirements, expanded multi-factor scope, and the continuous evidence model. The templates are written against v4.0.1.
Is this useful if we are already through one v4.0 assessment cycle?
Yes. The bigger value once the first cycle is complete is the SOC and PCI alignment, the acquired-entity onboarding plan, and the continuous evidence rhythm that prevents the next cycle from being another deadline sprint.
How tailored is the implementation playbook?
Hand-built for the stack and cycle described at purchase. Merchant-acquirer with an ISO portfolio and recent acquisitions gets different templates than a payments-platform business with a single legal entity.
Does it cover the card-brand AML and merchant-monitoring side?
Module 11 covers the IT compliance intersection with the card-brand AML, sanctions screening, and merchant-monitoring evidence. It is positioned next to PCI rather than as a separate AML programme course.
Refund?
30-day money-back if the course is not useful for the role.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.