Loading...

Run: Cardholder Data PAN Masking Desktop Audit

Audit an agent desktop for PAN masking, role-based visibility, and evidence of no full card data exposure. Use it to verify PCI DSS display controls before a...

Fill this out, get a PDF emailed to you. No account required. Want to run it with your team and track results? Sign up free →

Inspection Scope and Environment

Record the application name, workstation ID, environment (production/UAT), and date/time of inspection.
Select the role used for the audit to verify role-based PAN display permissions.
Confirm that test PAN data used for the inspection is authorized and does not expose real cardholder data unnecessarily.
Confirm the audit is focused on PAN masking and permitted digit display behavior rather than unrelated application functions.
Verify against PCI DSS PAN display expectations: Primary Account Numbers must be masked when displayed, with only the permitted digits visible based on business need and role.

PAN Entry and Masking Behavior

After the card number is entered, the application displays a masked value instead of the full PAN.
Confirm the display shows only the allowed digits for the role, such as last four digits or another approved limit.
Record the observed masking format, such as ************1234, and compare it to the approved masking rule.
Verify the full card number is not visible in entry fields, confirmation panels, pop-ups, or summary views.

Role-Based Display Controls

Confirm the application applies the correct PAN display rule for the selected role.
If the role has elevated access, verify the visible digits still remain within approved business and PCI limits.
Confirm the user cannot expand, unmask, copy, or otherwise reveal additional PAN digits without approved authorization.
Document any approved exception, temporary access, or compensating control related to PAN visibility.

Evidence, Logging, and Data Exposure Checks

Verify that application logs, audit events, and transaction history do not display the full PAN.
Confirm that screen capture tools, remote assistance sessions, and shared views do not expose unmasked card numbers.
Attach a screenshot or photo showing the masked PAN display and the role context used for the test.
Document any non-conformance, including affected screen, role, observed exposure, and required remediation.

Get your results

Enter your email — we'll send you a PDF of your filled-out template, plus the occasional MangoScoop newsletter (templates, workflow tips, product updates). Unsubscribe anytime — link is in every email.

Generated with MangoApps Templates — browse 250+ free