Executive Summary
A global fintech payment processor operating regulated entities in the UAE and India was running two disconnected PCI DSS efforts — separate assessors, duplicated evidence, and conflicting interpretations of shared controls. This engagement consolidated both entities under a single CEMEA assessment model delivered from CyberSigma’s Dubai and India teams.
Client Overview
The client is a global fintech payment processor serving banks and merchants across CEMEA, with processing entities in the UAE and India sharing a common technology platform. The regulatory drivers were annual PCI DSS validation for both entities plus UAE central-bank licensing expectations; scope covered the shared processing platform, both regional datacentres, and entity-specific payment channels.
- Industry: Fintech / Payment Processing (global, multi-entity)
- Region: UAE + India (CEMEA)
- Regulatory driver: Annual PCI DSS validation per entity; UAE licensing expectations
- Timeline: One assessment cycle to unify; ~10 weeks of prep versus months previously
- CyberSigma team: Lead QSA (Dubai), lead QSA (India), shared-controls consultant, evidence manager
Challenge
Two entities on one platform were being assessed as if they were unrelated companies. Shared controls were evidenced twice, assessed twice, and sometimes judged differently — audit preparation consumed months of engineering time every year.
- Duplicate evidence collection for controls operated once on the shared platform
- Inconsistent control interpretations between previous assessors in each country
- Audit-prep effort measured in months per entity, hitting the same platform teams twice
- Cross-border evidence handling requirements between UAE and India entities
- Assessment calendars that collided with product release freezes
Objectives
- Unify both entities under one assessment methodology and one QSA relationship
- Build a shared-controls matrix so platform controls are evidenced once and inherited
- Cut audit-preparation time from months to weeks
- Keep entity-level RoCs aligned with each regulator’s expectations
- Establish a single annual assessment calendar across CEMEA
Our Approach
1. Entity & Platform Scoping
We mapped which controls were operated centrally on the shared platform versus locally per entity, producing a responsibility matrix that both entities and the assessment could rely on.
2. Unified Evidence Model
A shared evidence library was built with one artefact per platform control, tagged for inheritance by each entity, with entity-specific evidence limited to genuinely local controls.
3. Harmonised Control Interpretation
Conflicting historical interpretations (key management, MFA boundaries, scan cadence) were resolved into a single documented position applied consistently across both RoCs.
4. Coordinated Dual-Entity Assessment
Dubai- and India-based assessment teams ran interviews and testing in one coordinated window, sharing platform-control results so the same engineers were not interviewed twice.
5. Sustain & Annual Calendar
A rolling evidence-refresh calendar replaced the annual scramble, spreading collection across quarters and keeping both entities continuously assessment-ready.
Solution
- Shared-controls responsibility matrix separating platform controls from entity-local controls
- Single evidence library with inheritance tagging across both entities
- Harmonised control interpretations documented once and applied to both RoCs
- Coordinated dual-entity QSA assessment executed in one window from Dubai and India
- Rolling quarterly evidence-refresh calendar for continuous readiness
Results
- Audit-preparation time cut from months to roughly 10 weeks across both entities
- Platform controls evidenced once instead of twice, removing duplicate engineering effort
- Both entity RoCs completed in a single coordinated assessment window
- Consistent control interpretations eliminated cross-entity findings disputes
- Annual assessment now runs on a predictable CEMEA-wide calendar
Timelines and outcomes reflect the documented engagement record for this client; results vary with scope and readiness.
What We Delivered
- Scope definition and network/data-flow diagrams for the cardholder data environment
- Gap assessment against PCI DSS v4.0.1 with risk-ranked remediation plan
- Evidence pack per requirement (configurations, records, sampled artefacts)
- Formal validation deliverable — Report on Compliance or Self-Assessment Questionnaire with Attestation of Compliance
- Quarterly ASV scan coordination and remediation verification
The standard artefact set for this engagement type; per-client environment and architecture details are shared under NDA during procurement, not published.
Lessons Learned
- Scope decided the budget: every environment that touched cardholder data unnecessarily was cost — segmentation work done early paid for itself before the assessment started.
- v4.0.1’s future-dated controls (MFA for all CDE access, payment-page script controls) were the schedule risk; treating them as day-one requirements removed the crunch.
- Evidence produced continuously beat evidence assembled before the audit — the requests that stall assessments are always for artefacts nobody collected at the time.
Talk to the team that ran this engagement
This was a real Multi-Entity PCI DSS QSA Assessment (CEMEA) engagement. If you are preparing for the same, speak to a specialist who has delivered it — not a sales rep. We will give you a clear read on your scope, gaps and the fastest path, and reply within four business hours.
Explore PCI DSS QSA assessment · more case studies
Liked the case study? Share on:


