PCI Compliance Audit Scope Assessment Questionnaire
Use this questionnaire to define the PCI audit scope, identify card data flows, list in-scope systems and third parties, and capture readiness details for the assessment.
Scope Overview
Business or Project Name
*
Respondent Role or Department
*
Current Assessment Phase
*
Initial Scoping
Annual Review
Post-Change Review
Other
Description of Payment Card Environment
*
PCI Environment and Data Handling
Environment type(s) in scope
*
Web app
Mobile app
Call center
In-person POS
E-commerce backend
Internal admin system
Hosted service
Cloud infrastructure
Other
Is cardholder data stored, processed, or transmitted in scope?
*
Yes
No
Cardholder data flow and protection points
*
Rows
Enters scope
Processed
Stored
Encrypted or tokenized
Web app
1
2
3
4
Mobile app
5
6
7
8
Call center
9
10
11
12
In-person POS
13
14
15
16
E-commerce backend
17
18
19
20
Internal admin system
21
22
23
24
Hosted service
25
26
27
28
Cloud infrastructure
29
30
31
32
Other
33
34
35
36
Systems, Third Parties, and Controls
Systems/components in scope
*
Number of locations or business units in scope
*
Current control maturity / audit readiness
*
Low readiness
1
2
3
4
5
6
7
8
9
High readiness
10
1 is Low readiness, 10 is High readiness
Notable recent changes, exceptions, or scope-expanding events
Submit Assessment
Should be Empty: