Can I use a single set of compliance validation documents for multiple merchant entities?
You may use a single set of compliance validation documents (i.e. a single ROC or SAQ, and scan report) to cover all entities. Note, however, that you must specifically list all covered entities in the ROC or SAQ, and that if you use this consolidated documentation approach, a single non-compliant entity will prevent all entities from successfully validating compliance until that non-compliant entity becomes compliant.
Related Questions
- These levels determine the validation processes that a merchant must undertake in order to achieve and maintain compliance. Is there a distinction between the different types of service providers?
- Is a HEDIS Compliance Auditâ„¢ considered to be a validation of performance measures activity?
- Can I use a single set of compliance validation documents for multiple merchant entities?