• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Articles » What to look for in a PCI DSS-compliant call center

What to look for in a PCI DSS-compliant call center

  • PCI DSS 4.0.1 is fully enforced as of April 2025, with stricter requirements around call recording, agent authentication, and cardholder data access that older compliance frameworks did not cover.
  • PCI compliance in a call center is not a certification to be shown once. It requires active controls: call recording architecture, role-based access, staff training, and regular audits against the current standard.
  • The most common compliance failure is not malicious: it is pause-and-resume call recording, which is no longer acceptable under PCI DSS 4.0.1 for calls where cardholder data is verbally transmitted.
  • SixEleven is a PCI DSS-certified BPO in the Philippines with 15+ years of experience, operating customer support, chat, email, and back-office services with HIPAA compliance and ISO 9001 certification alongside PCI controls.

Businesses that need a call center to handle payments, process card-related inquiries, or access any cardholder data during customer interactions are not choosing between compliant and non-compliant vendors on features. They are managing regulatory exposure on every transaction that touches their outsourced channel.

PCI DSS compliance in a call center is an operational architecture, not a checkbox. The right question when evaluating a vendor is not “are you PCI compliant?” (every vendor will say yes).

The right question is what specific controls are in place, when they were last audited, and what the attestation of compliance actually covers.

This guide explains what PCI DSS compliance really means for a call center: the controls that matter, the audit details worth checking, and the questions to ask before any vendor handles cardholder data.

What PCI DSS actually requires in a call center environment

PCI DSS (Payment Card Industry Data Security Standard) applies to any environment where cardholder data is stored, processed, or transmitted. In a call center, that includes agents who take verbal card numbers, systems that route or log those calls, and any screen or record that displays cardholder data during an interaction.

PCI DSS applies to cardholder data environments

The current version, PCI DSS 4.0.1, introduced specific requirements that have elevated what “compliant” means in a call center context.

Get 3 free quotes 4,000+ BPO SUPPLIERS

Balto’s breakdown of PCI DSS call center compliance identifies seven core control categories for compliant call centers:

  1. Restricted physical and logical access to cardholder data environments
  2. Call recording architecture that prevents capture of sensitive authentication data
  3. Agent authentication via MFA
  4. Real-time monitoring and logging
  5. Staff training and awareness programs
  6. Regular vulnerability assessments
  7. Annual third-party audits against the full PCI DSS control set

Under PCI DSS 4.0.1, pause-and-resume call recording (where the recording stops when an agent requests card data and resumes after) is no longer sufficient for calls where cardholder data is verbally transmitted.

Compliant call centers must use systems that either never record those portions or use audio redaction technology to remove card data from recordings entirely.

Pro Tip: Ask any prospective call center vendor to describe specifically how they handle call recordings during payment capture. If they describe pause-and-resume as their primary control, they may be operating under an older interpretation of PCI DSS that the 4.0.1 update addressed. Ask for their most recent Attestation of Compliance and confirm what call recording architecture is listed within scope.

The controls that separate compliant call centers from those that claim to be

Compliance claims are common. Documentation is less common. When evaluating a call center vendor for PCI compliance, the following controls should be verifiable through documentation, not vendor assurance.

Call recording and audio architecture

Compliant call centers handling verbal card data either do not record those portions at all or use certified audio redaction technology to scrub sensitive authentication data from recordings before storage.

Pause-and-resume, agent-controlled recording pauses, and manual annotation of what was or wasn’t recorded are not sufficient controls under the current standard. Ask for documentation of the call recording architecture specifically as it relates to PCI scope.

Get the complete toolkit, free

Role-based access and MFA

Cardholder data environments must be access-controlled to only the agents and systems with a documented business need. That access must be authenticated via MFA for all non-console administrative access and for all access to cardholder data remotely.

In a call center, this includes screen-level data masking for agents who handle payment inquiries but do not need to see full card numbers to resolve the call.

Staff training and awareness programs

PCI DSS requires annual security awareness training for all personnel with access to cardholder data. For a call center, this includes agents, supervisors, and quality assurance staff. Ask vendors for their training documentation and frequency of retraining.

PCI DSS training should cover all cardholder data access

High-turnover environments with inconsistent training compliance are a structural compliance gap regardless of the technical controls in place.

Pro Tip: Request the call center’s most recent Attestation of Compliance (AoC) document. This is the formal output of a PCI audit and lists the specific controls and systems assessed. If a vendor can provide a current AoC but cannot explain what is in it, that is a signal about the depth of their compliance program versus their documentation.

What annual audits and penetration testing require

Merchant levels under PCI DSS determine what annual audit requirements apply.

Call center BPOs processing above certain transaction volumes or serving clients in higher merchant tiers will be required to undergo annual third-party Qualified Security Assessor (QSA) audits and quarterly network scans. Lower-tier operations may self-assess, but the controls required are the same.

Penetration testing against the cardholder data environment is required annually and after significant infrastructure changes. When evaluating call center vendors, ask when their most recent penetration test occurred, who conducted it, and what remediation actions followed.

A vendor that has not completed penetration testing within the past 12 months is operating outside of the standard’s requirements regardless of certification claims.

For a broader overview of compliance across call center and BPO operations, see how PCI DSS, HIPAA, and ISO standards intersect in practice.

The documents below are the minimum a buyer should request from any call center vendor claiming PCI DSS compliance, before contracting begins.

StandardDocument to RequestWhat It Confirms
PCI DSSAttestation of Compliance (AoC)Certified systems and environments; QSA identity; assessment date
PCI DSSMost recent penetration test reportActive audit cadence; remediation completed within 12 months
PCI DSSCall recording architecture documentationCompliance with 4.0.1 (audio redaction or non-capture, not pause-and-resume)
HIPAABusiness Associate Agreement templatePHI handling obligations and breach notification procedures
ISO 9001Current certificate with validity periodQuality management system scope and audit continuity

How SixEleven operates PCI-compliant call center services

SixEleven is a PCI DSS-certified BPO based in General Santos City and Cebu, Philippines, with over 15 years of experience running customer support, chat, email, and back-office services for international clients.

SixEleven holds PCI DSS certification alongside HIPAA compliance, ISO 9001 certification, and NPC Certificate of Registration, providing a documented multi-standard compliance posture for clients in regulated industries.

  • PCI DSS certified: current certification with documented controls covering call recording architecture, role-based access, agent authentication, and audit cadence
  • HIPAA compliant: structured data handling for healthcare-adjacent clients requiring dual compliance across payment and health data environments
  • ISO 9001 certified: quality management system certification that governs process consistency and service delivery standards across all client programs
  • NPC Certificate of Registration: registered with the Philippine National Privacy Commission for compliant personal data handling under Philippine law
  • Customer support, chat, email, and back office: service focus on CX and back-office operations
  • 15+ years of operation: established Philippines-based BPO with documented audit history and compliance program continuity across client relationships

Looking for PCI DSS and HIPAA-compliant offshore support? Get in touch with SixEleven.

Key takeaways

  • PCI DSS 4.0.1 is fully enforced as of April 2025 and raised specific requirements for call recording architecture, agent authentication, and cardholder data access in call center environments.
  • Pause-and-resume call recording is no longer an acceptable control under the current standard. Ask any vendor to document their call recording architecture before contracting.
  • An Attestation of Compliance, current penetration test results, and documented staff training records are the three verification documents that distinguish genuine compliance from compliance claims.
  • SixEleven provides PCI DSS-certified customer support, chat, email, and back-office services in the Philippines with HIPAA compliance, ISO 9001, and NPC registration as part of a documented multi-standard compliance posture.

Frequently Asked Questions

Is pause-and-resume call recording still acceptable under PCI DSS 4.0.1?

No. Under PCI DSS 4.0.1, fully enforced from April 2025, pause-and-resume is not considered a sufficient control for calls where cardholder data is verbally transmitted. Compliant call centers must use systems that either prevent recording of those portions entirely or use certified audio redaction to remove sensitive authentication data from any stored recordings.

What is an Attestation of Compliance, and should I request one from my call center vendor?

An Attestation of Compliance (AoC) is the formal document produced following a PCI DSS audit, confirming that the assessed systems met the standard’s requirements at the time of the audit. Yes, you should request it, and verify the date of the most recent assessment, the name of the Qualified Security Assessor who conducted it, and whether your call center’s specific systems and cardholder data environment are within the listed scope.

Can a call center be HIPAA compliant and PCI DSS certified at the same time?

Yes, and for clients in healthcare-adjacent industries (medical billing, insurance, healthcare payments), dual compliance is often necessary. The two frameworks have different but complementary requirements. PCI DSS governs cardholder data; HIPAA governs protected health information. A call center operating in both environments needs separate documented controls and training programs for each standard, not a single merged approach.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image