PCXProgram controls

Design controls around the full program lifecycle

Controls should follow data and decisions from Shopify intake through eligibility, provider coordination, customer communication, support, reporting, change, and closure.

01

Protect data by role

Define the minimum data each participant needs, approved transfer paths, access boundaries, retention periods, monitoring, and incident ownership. Card-sensitive processes remain with appropriately controlled systems and providers.

02

Control both automation and exceptions

Automated decisions need versioned policies, reliable inputs, safe retry behavior, and observable failures. Manual decisions need limited authority, reason records, escalation, and periodic review.

03

Verify the external operating model

Provider diligence should confirm legal roles, program authority, network and issuer context, security responsibilities, service ownership, reporting, incident response, subcontractors, and exit provisions.