Diff: FAQ #1451

Can PFIs provide reports to their clients before sending the report to the affected payment brands?

Earlier Version
Later Version
Removed
Added
No. It is not acceptable for reports (draft or final) to be issued to clients, acquirers, issuers, or other parties for review/amendment before being sent to payment brands and/or acquirers. PCI Forensic Investigators (PFIs) are obliged under the terms of the PFI Program Guide to provide Preliminary Incident Response Reports and Final PFI Reports to their client, each affected payment brand, and their client?sclient's affected acquirer(s). The reports must be sent to all parties (clients, affected payment brands and all affected acquirer(s) identified in Appendix C of the Final PFI Report) at the same time.
Appendix A of the PFI Program Guide describes the provisions PFI Companies must include in their contracts to support the report delivery requirements. Appendix C: Impacted Entities should be broken out into separate lists for each acquirer
(if the clientmore than one acquirer is involved), with a merchant). complete "master list" provided to each affected payment brand. 
The judgements, conclusions, and findings in PFI reports must be sent to all parties (client, affected payment brand and acquirer (if required)) at the same time. Itbased solely on the factual evidence obtained during the investigation and reflect the independent judgement, findings, and conclusion of the PFI company. If an amendment is not acceptablerequired to a Final PFI Report post-issue, for reports (draftexample to correct a factual error or final) toomission, the amendment must be issued to clients, acquirers, issuers or other parties for review/amendment before being sent to payment brands and/or acquirers. Appendix Aclearly evidenced in the Table of the PFI Program Guide describes the provisions PFI Companies must includeChanges in their contracts to support thethe revised report delivery requirements. Appendix C: Impacted Entities should be broken out into separate lists for each acquirer (if more than one acquirer is involved), with a complete ?master list? provided to each affected payment brand.

The judgements, conclusions and findings in PFI reports must be based solely on the factual evidence obtained during the investigation and reflect the independent judgement, findings and conclusion of the PFI company. If an amendment is required to a Final PFI Report post-issue, for example to correct a factual error or omission, the amendment must be clearly evidenced in the Table of Changes in the revised
and the report and the report version number incremented appropriately.

Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.