General Requirement
OM-6.1.1
Retail banks must maintain up to date Payment Card Industry Data Security Standards (PCI-DSS) certification. The initial certification must be obtained by 30th April 2017. Failure to comply with this requirement will trigger a supervisory response, which may include formal enforcement measures, as set out in Module EN (Enforcement).
Amended: October 2016
Amended: April 2016
Amended: January 2011
October 07OM-6.1.1.A
In order to maintain up to date PCI-DSS certification, retail banks will be periodically audited by PCI authorised companies for compliance.
Licensees are asked to make certified copies of such documents available if requested by the CBB.Added: April 2016