Merchant Resources

Security

Merchant Levels: Defined

Acquirers are responsible for ensuring that all of their merchants protect Visa account information. Compliance with the Account Information Security (AIS) program is mandatory. Merchants must validate compliance at one of four merchant levels, depending on the volume of Visa transactions.

Acquirers are responsible for determining these levels for merchants. The transaction volume is based on the aggregate number of Visa transactions processed by a merchant. To confirm merchant level, please contact your Acquirer.

Merchant Level Description
1

Any merchant (regardless of acceptance channel) processing over 6,000,000 Visa transactions per year.

Any merchant that Visa, in its sole discretion, determines should meet the Level 1 Merchant requirements, to minimize risk to the Visa system.

2

Any merchant (regardless of acceptance channel) processing 1,000,000 to 6,000,000 Visa transactions per year.

3

Any merchant processing 20,000 to 1,000,000 Visa eCommerce transactions per year.

4

Any merchant processing fewer than 20,000 Visa eCommerce transactions per year, and all other merchants (regardless of acceptance channel) processing up to 1,000,000 Visa transactions per year.

Complying with the AIS Program

In addition to adhering to the 12 security requirements and sub-requirements of the Payment Card Industry's Data Security Standard (PCI-DSS), compliance validation is required for Level 1, Level 2 and Level 3 merchants. It is strongly recommended for Level 4 merchants as well.

Merchant Level Validation Action Validated by Due Date
1 On-site review QSA 9/30/2010
PCI Security Scans ASV
2 Annual PCI Questionnaire Acquirer 9/30/2011
PCI Security Scans ASV
3 Annual PCI Questionnaire Acquirer 12/31/2005
PCI Security Scans ASV
4** Annual PCI Questionnaire N/A
PCI Security Scans ASV
**Level 4 merchants must also comply with the PCI Data Security Standard. The method of compliance validation for this category is determined by a merchant's Acquirer.

Validation Procedures and Documentation

Merchant must demonstrate compliance by submitting the required documentation to its Acquirer. This documentation must be made available to Visa upon request. Compliance validation is performed at the merchant's expense.

Level 1 Merchant:

The Annual PCI Questionnaire and Annual On-Site PCI Data Security Assessment must be completed by Level 1 merchants according to the PCI DSS Security Assessment Procedures, and the results provided to the Acquirer. The PCI-DSS procedures are to be used as a template for the Report on Compliance. Although Acquirers are responsible for the security of Visa cardholder data wherever they are housed, the scope of AIS compliance validation for Level 1 merchants is focused on any system(s) or system component(s) related to authorization and settlement where Visa cardholder data are stored, processed or transmitted.

Every other year, Level 1 merchants (but not service providers) may choose to have their internal audit department perform their PCI-DSS review, provided:

  1. There are no major infrastructure changes to their credit card processing environment and no change in their compensating controls.
  2. The Acquirer approves this option.
  3. The very first review (validation of full compliance with the PCI-DSS) is performed by a QSA.
  4. PCI Security Assessment Procedures are followed and all observations and findings documented within the Audit form.
  5. The review is approved by a merchant’s senior officer.
  6. The merchant submits Items 4 and 5 to the Acquirer for review.
  7. PCI Security Scans are continued with an Approved Scanning Vendor.

If an internal audit is not used, a QSA must perform the validation.

Level 2 and 3 Merchants:

The Annual PCI Questionnaire and PCI Security Scans must be completed by Level 2 and 3 merchants. The Annual PCI Questionnaire must be submitted to the merchant's Acquirer. The Annual PCI Questionnaire must address any system(s) or system component(s) involved in processing, storing or transmitting Visa cardholder data.

Level 4 Merchants:

Level 4 merchants must also comply with the PCI Data Security Standard; however, the method of compliance validation for the merchant in this category is determined by the merchant's Acquirer.