Cardholder Data PAN Masking Desktop Audit
Cardholder Data PAN Masking Desktop Audit
Inspection template for verifying that an agent desktop application masks Primary Account Numbers (PANs) after entry and displays only the permitted digits based on user role and access level.
Audit Setup and Scope
- Application name, environment, and user role documented
- Audit scope includes PAN entry and post-entry display behavior
- Test account has role-based display permissions defined
PAN Entry and Masking Behavior
- PAN is masked immediately after entry is completed
- Only permitted digits remain visible after masking
- Full PAN is not visible in the application field, pop-up, or summary view
Role-Based Display Controls
- Displayed PAN digits match the role's permitted view
- Unauthorized roles cannot reveal additional PAN digits
- Role-based masking behavior is consistent across screens and workflows
Evidence, Logs, and Exception Handling
- Screenshot or photo evidence captured showing masked PAN
- Audit notes identify any masking defects or non-conformance
- Any exception to masking policy is documented and approved
Closeout and Corrective Actions
- Overall audit result
- Corrective action owner and due date documented
Ask AI
Template Studio