Cardholders Commercial Merchants Value Of Visa Media Center
How Account Information Security Works
Introduction   |   What is AIS   |   AIS benefits   |   How AIS works   |   How to get started   |   Downloads and resources   |   In case of compromise
What does the AIS program involve?
How do I know if I meet the PCIDSS standards?
Do I have to complete all the validation tasks?
How often do the validation tasks need to be completed?
What acknowledgement of validation to PCIDSS standards will be received?
What if I choose not to be involved in the AIS program?
What does the AIS program involve?
The AIS program is a requirement if you participate in the Visa payment system. Your acquiring bank will be responsible for ensuring that you meet Visa’s PCIDSS standards, and will be able to guide you through the AIS validation process.
How do I know if I meet the PCIDSS standards?
To check whether you organization meets the PCIDSS standards, you complete the following validation tasks (depending on the average monthly Visa volume you proess or cardholder data you handle): 

Do I have to complete all the validation tasks?
  
Service Providers
 

 
 
Merchants
 

 


* includes all transactions, regardless of the type / channel
 
  Back to top
How often do the validation tasks need to be completed?
All entities that process Visa transactions should ensure they complete the AIS validation tasks on an annual basis. It is expected that your organization already regularly reviews and tests security procedures. Validation to the PCIDSS standards should be part of this process. 
 
 
Required documentation:
 
Members are required to submit the following documentation:
 
For entities that are not fully compliant at the time of validation, the following documents are required to be submitted in addition to the Certificate of Compliance:
 
 
Once remediation tasks have been completed, a final Certificate of Compliance must be submitted indicating full compliance.
 
 Certificate of Compliance (Service Provider)
 
 Certificate of Compliance (Merchant)
What acknowledgement of validation to PCIDSS standards will be received?
Your acquiring bank will inform you about the validation tasks you are required to complete and the validation deadline.  Your acquiring bank will inform Visa of your compliance status via the Certificate of Compliance. 
 
Being PCIDSS compliant gives you a competitive edge and a channel to demonstrate a high level of security to your customers and other industry and regulatory bodies.
What if I choose not to be involved in the AIS program?
Visa can enforce the AIS program using financial penalties on all acquirers and may require that specific actions be taken to protect account and transaction Information.
 
Should a compromise occur and your organization has not taken the appropriate steps to ensure that account information was protected, your acquiring bank may be financially penalized.
  Back to top
Print this page   |
Tell a friend   |
Get a card
Home  |   About Visa  |   Careers  |   Sitemap  |   Legal  |   Privacy Policy  |   Hyperlink Guidelines  |   Global Sites  |   Asia Pacific Sites