Regulatory Mapping · PCI DSS v4.0

PCI DSS Compliance Mapping

Payment Card Industry Data Security Standard v4.0. Live evidence mapping for AI systems operating in cardholder data environments.

PCI DSS scope: Applies to all entities that store, process, or transmit cardholder data. AI systems integrated into payment flows, fraud detection, or customer service for financial transactions must demonstrate continuous monitoring (Req.10), access controls (Req.8), and cryptographic integrity (Req.4). TrustLayers provides the continuous audit logs required under Requirement 10 and the evidence chain required for QSA assessments.
Req.1-2 — Network Security
Install and maintain network security controls for AI cardholder data environments
Req.3 — Protect Stored Data
Protect stored account data — AI systems must not retain sensitive authentication data
Req.4 — Encryption in Transit
Protect cardholder data with strong cryptography during transmission
Req.6 — Secure Systems
Develop and maintain secure systems and software — includes AI models
Req.8 — Access Control
Identify users and authenticate access to system components
Req.10 — Logging & Monitoring
Log and monitor all access to system components and cardholder data
Req.11 — Security Testing
Test security of systems and networks regularly
Req.12 — Security Policy
Support information security with organisational policies and programs
Agent Category Events Error rate Violations Sensitive Drift Encrypted Overrides PCI Criteria Assessment
TransparencyAgent
-ransparency-gent-297b…
Governance 1,156 0% 0 0 0 20% 0
6/7
PCI READY
ClaraAI-Assistant
-lara-ssistant-a8ad…
Support 200 0% 0 0 0 3% 0
6/7
PCI READY
HumanOversightAgent
-uman-versight-gent-01…
Governance 58 0% 0 0 0 0% 0
6/7
PCI READY
ComplianceAlignment
-ompliance-lignment-08…
Governance 30 0% 0 0 0 0% 0
6/7
PCI READY
AuditabilityAgent
-uditability-gent-aa78…
Governance 7 0% 0 0 0 0% 0
6/7
PCI READY
ClaraAI-Voice
-lara-oice-7b52…
Support 6 0% 0 0 0 0% 0
6/7
PCI READY
ClaraAI-Emergency
-lara-mergency-326e…
Support 4 0% 0 4 0 0% 0
5/7
PARTIAL
ClaraAI-Tracking
-lara-racking-c8c2…
Support 1 0% 0 0 0 0% 0
6/7
PCI READY
DataGovernanceAgent
gov-datagovernance-005…
Governance 1 0% 0 0 0 0% 0
6/7
PCI READY
SecurityAgent
gov-security-008…
Governance 1 0% 0 0 0 0% 0
6/7
PCI READY
DocumentationAgent
gov-documentation-011…
Governance 1 0% 0 0 0 0% 0
6/7
PCI READY
Generated 09/09/2026 11:24 · TrustLayers.eu · PCI DSS v4.0 · trustlayer@danidanwin.eu