01
Protect data by role
Define the minimum data each participant needs, approved transfer paths, access boundaries, retention periods, monitoring, and incident ownership. Card-sensitive processes remain with appropriately controlled systems and providers.
02
Control both automation and exceptions
Automated decisions need versioned policies, reliable inputs, safe retry behavior, and observable failures. Manual decisions need limited authority, reason records, escalation, and periodic review.
03
Verify the external operating model
Provider diligence should confirm legal roles, program authority, network and issuer context, security responsibilities, service ownership, reporting, incident response, subcontractors, and exit provisions.