Registration for Britannic's Annual Summit is now open!

Register Now!

*Updated 16 September 2026*

PCI DSS compliance can fail in places organisations do not immediately associate with the payment system.

A recorded telephone call can capture card details. A new third-party integration can change the payment-data flow. An e-commerce script can introduce another attack route. A contact centre migration can move sensitive information into systems that were previously outside PCI scope.

This matters because PCI DSS v4.0.1 is now the active standard, and requirements that were previously future-dated became effective on 31 March 2025.

Payment fraud also remains significant. UK Finance reported on 15 June 2026 that criminals stole £1.28 billion through payment fraud during 2025, an increase of 4%. Remote purchase fraud alone accounted for £423.5 million, with 3.2 million cases recorded.

The important lesson is that PCI DSS cannot be treated as a payment gateway problem.

Organisations need to understand everywhere payment data can travel, who or what can access it and what changes could expose it again.

What Is PCI DSS Designed To Protect?

PCI DSS is designed to protect payment account data across organisations that store, process or transmit it, as well as systems that can affect the security of the cardholder data environment.

The current PCI DSS v4.0.1 framework includes controls covering areas such as:

PCI DSS v4 introduced greater flexibility around how organisations meet security objectives, alongside concepts such as targeted risk analysis.

Compliance is therefore about understanding the complete payment environment, not simply confirming that a payment provider holds the correct certification.

Where Does PCI DSS Compliance Commonly Break Down?

The biggest problems often appear at the boundaries between systems.

Card Data Enters More Systems Than Expected

A telephone payment could potentially expose card information to:

  • An agent
  • A call recording
  • A desktop
  • A contact centre
  • A CRM system
  • Voice infrastructure
  • A payment gateway
  • Third-party applications

Every additional system or person exposed to payment information can increase complexity.

The strongest approach is therefore to prevent card data entering unnecessary systems in the first place.

Call Recordings Capture Sensitive Payment Data

Call recording creates a particular risk when customers read payment information aloud.

PCI SSC clarified again in June 2025 that sensitive authentication data such as card verification codes cannot be retained in digital audio recordings after authorisation.

Where technology exists to prevent that information being recorded, PCI SSC states that it should be used.

That makes the architecture of telephone payments important.

Secure DTMF payment technology allows customers to enter card information using their telephone keypad while preventing the agent and voice recording from receiving the sensitive card details.

Britannic's NetPCI capability provides PCI-compliant telephone payments at the network layer, helping organisations take payments while reducing unnecessary exposure to card information.

Why Are E-Commerce Scripts A PCI DSS Risk?

Payment-page security has received greater attention under PCI DSS v4.x.

PCI SSC published specific guidance in March 2025 covering Requirements 6.4.3 and 11.6.1, which address the risks created by payment-page scripts and unauthorised changes.

The guidance reflects the growth of e-skimming attacks, where malicious or compromised scripts can capture card information while customers are completing online payments.

Organisations therefore need visibility of:

  • Which scripts run on payment pages
  • Whether those scripts are authorised
  • Whether their integrity is checked
  • How unexpected changes are detected
  • Which third parties can affect the payment environment

This illustrates why PCI compliance needs to extend beyond the systems directly processing the transaction.

Can System Changes Increase PCI DSS Scope?

Yes.

Something that was outside the cardholder data environment yesterday can become relevant after a technology change.

PCI SSC identifies significant changes as potentially including:

  • New hardware or software
  • Major platform upgrades
  • Changes to account data flows
  • Changes to PCI DSS scope
  • Infrastructure changes
  • Changes to third-party providers

These changes can require organisations to reassess security controls and PCI DSS scope.

This is particularly relevant when organisations migrate contact centres, introduce cloud communications, change payment providers or integrate new CRM applications.

Compliance needs to follow the architecture as it changes.

Britannic's Payment Security Pressure Test

Britannic recommends reviewing payment environments through five questions.

Area Pressure-Test Question 
Data Where can card information enter, travel or be stored?
People Who can see, hear or access payment information?
Recording Could sensitive authentication data enter voice recordings or other records?
Change
Has new technology altered the payment-data flow or PCI scope?
Dependencies  Which suppliers, scripts, integrations and services can affect payment security?

If the answer to any of these questions is unclear, the environment deserves further investigation.

The aim is to expose hidden dependencies before they become compliance or security problems.

How Can Telephone Payments Be Made More Secure?

For organisations taking payments over the telephone, removing sensitive card information from the agent environment can significantly simplify the risk model.

Britannic's secure payment proposition uses DTMF masking so customers can enter payment details through their telephone keypad without the agent seeing or hearing the information.

This also allows the wider customer conversation to continue to be recorded without sensitive payment credentials entering the audio recording.

The Institution of Engineering and Technology provides a practical example.

Britannic helped The IET replace physical PDQ payments with SIP telephony and a cloud-based secure payment solution. Agents could remain connected to customers while card information was captured securely through DTMF.

The project saved The IET 30 hours per month while allowing agents to take payments from different locations.

This demonstrates that stronger payment security does not necessarily require a more complicated customer or agent experience.

Does Outsourcing Payments Remove PCI DSS Risk?

Not entirely.

Third-party payment providers can significantly reduce the number of systems an organisation needs to operate within the PCI environment.

However, organisations still need to understand:

  • Which provider performs each activity
  • Which PCI DSS responsibilities remain with the organisation
  • Whether integrations have been implemented correctly
  • Whether providers maintain appropriate compliance status
  • What happens when suppliers or services change

PCI SSC specifically advises organisations to work with their acquirer, payment brand or other compliance-accepting entity to understand their validation and reporting obligations.

Reducing PCI scope should therefore make responsibilities smaller and clearer, not invisible.

PCI DSS Payment Security Checklist

Organisations should regularly confirm:

  • Where payment data enters the business
  • Which systems can access cardholder data
  • Whether employees can see or hear card details
  • Whether call recordings can capture sensitive authentication data
  • Whether DTMF or another secure payment method could remove that exposure
  • Which applications integrate with payment processes
  • Which scripts operate on payment pages
  • How unauthorised payment-page changes are detected
  • Which third parties can affect payment security
  • Whether MFA and access controls are appropriate
  • Whether users only have the permissions they need
  • How payment systems are monitored
  • Whether vulnerabilities are being managed
  • Whether significant technology changes trigger PCI review
  • Whether PCI scope is still accurate
  • Who owns PCI DSS compliance internally
  • Whether compliance evidence can be produced when required

PCI DSS should be reviewed as technology changes, not simply when the next assessment becomes due.

Payment Security Should Be Designed Around Less Exposure

Strong PCI DSS compliance does not begin by securing every system around card data.

It begins by asking whether those systems need access to the data at all.

Removing payment information from agents, recordings and unnecessary communications systems can reduce both exposure and operational complexity.

The remaining environment can then be secured, monitored and governed appropriately.

Britannic provides secure card payment, voice recording and compliance capabilities alongside NetX, contact centre and communications integration to help organisations reduce unnecessary payment-data exposure while maintaining a straightforward customer journey.

Organisations reviewing telephone payments, call recording or PCI DSS scope can book a complimentary meeting with Britannic to map their current payment journey and identify where sensitive data exposure could be reduced.