Training · Fintech & financial services
Privacy & Security Training for Payment Processors & PayFacs
Our training teaches the people who actually touch cardholder and merchant data how to handle it: support agents reading PANs during disputes, onboarding analysts reviewing beneficial-owner files, and settlement staff approving payouts. PCI DSS names security-awareness training as a control, and insider-access incidents at payments companies have shown what happens when staff with broad lookup rights are never taught the boundary. Processors typically book this ahead of a PCI assessment cycle, after a sponsor's due-diligence questionnaire asks how training is tracked, or following a scare involving an employee's access.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What training must cover for staff who touch payment data
A generic security-awareness module misses the roles where a payments company's real exposure sits. Four groups need purpose-built content.
Support staff with PAN visibility
Agents who see full or partial card numbers during dispute and support calls need explicit rules on what may be read aloud, typed into a ticket, or repeated back to a caller claiming to be the cardholder.
Onboarding and underwriting analysts
Staff reviewing beneficial-owner IDs, void cheques and banking details at sub-merchant intake need training on handling, storage and the red flags of a fabricated applicant.
Engineers with production data access
Developers who can query transaction or KYB tables in production need clear rules on least-privilege access, logging expectations and why a debugging shortcut into live cardholder data is a PCI finding waiting to happen.
Settlement and finance staff
The people who approve payout runs and banking-detail changes are the direct target of business email compromise, so their training centres on verification-by-callback and recognizing pressure tactics.
Regulatory map
Why training is a named control, not a nice-to-have
PCI DSS names it directly, and several other obligations quietly assume a trained workforce sits behind the paper.
PCI DSS security-awareness training
The standard requires a formal security-awareness program for personnel, with training at hire and at least annually for anyone with access to the CDE, a control your QSA checks records for.
RPAR competency underneath the framework
The Retail Payment Activities Regulations expect controls to be tested and reviewed, which is difficult to demonstrate if the people executing those controls were never trained on them.
PIPEDA safeguards extending to your workforce
Appropriate protection for cardholder and merchant-owner data includes staff competence: employees handling that information are themselves part of the safeguard, or a gap in it.
Law 25 governance presumes informed staff
Quebec's regime assumes an organization where people understand the privacy rules they operate under, relevant the moment your onboarding or support teams handle Quebec merchant or cardholder files.
What goes wrong
What untrained staff let through
The incidents below are less about missing technology and more about a person nobody had told where the line sat.
Insiders mining internal lookup tools
In September 2020, employees on Shopify's support team abused their standing access to internal tooling and pulled transaction histories for close to 200 merchants, without ever needing to breach a single external defence.
A support agent talked past a social-engineering script
A caller impersonating a merchant or cardholder can extract far more over a support line than any technical control blocks, if the agent has never rehearsed a verification script that holds under pressure.
A payout approved on a spoofed instruction
Settlement staff facing an urgent, plausible request to change banking details are the last control before a business-email-compromise attempt becomes stolen funds, which is why their training centres on slowing down, not speed.
A synthetic sub-merchant approved at intake
Onboarding analysts who have never been shown the patterns behind fabricated beneficial-owner documents can wave a fraudulent applicant straight into your merchant base.
Our training for payment processors & payfacs
What our training covers for a PSP
Tailored modules, compliance fundamentals and flexible delivery, built around the roles that actually handle cardholder and merchant data.

Role-tracked modules
Distinct content for PAN-handling support staff, onboarding and KYB analysts, engineers with production access, and settlement and finance teams, rather than one session for everyone.
PCI-aligned security awareness
Curriculum built to satisfy PCI's training requirement for anyone with CDE access, covering data handling, incident reporting and the annual refresh cycle.
Insider-risk and access discipline
A module addressing why broad lookup rights need justification and logging, and how to raise a concern about a colleague's access without waiting for an incident to prove the point.
Fraud and social-engineering scenarios
Practical drills built from payments workflows: a support call, a payout-change request, a synthetic onboarding applicant, run as decision exercises rather than lectures.
Evidence pack for QSA and sponsor reviewers
Completion records, curriculum summaries and refresh dates packaged so a QSA interview or a sponsor's due-diligence schedule gets a clean, current answer.
How the engagement runs
Rolling training out across a PSP's teams
We start from your org chart, because the content that matters differs sharply between a support floor and a settlement desk.
Step 1
Tune the content
We adapt modules to your systems, your acquirer and sponsor names, and your actual onboarding and support workflows, not a generic financial-services template.
Step 2
Deliver by role
Cohorts run live where discussion helps, especially for the fraud scenarios, and on-demand where support and operations shifts make live sessions impractical.
Step 3
Capture the record
Completions, dates and roles are logged into an evidence pack from the first session, because untracked training answers nobody's questionnaire.
Step 4
Refresh on a schedule
Annual refreshers plus updates triggered by a new sponsor, a new product line, or any incident that shows a gap in what staff were taught.
What it costs
What training costs depend on at a PSP
Pricing tracks headcount, how many role tracks you need, whether live sessions are required for fraud-scenario drills, and how much customization your onboarding and support workflows call for. A ten-person gateway team is a different project from a 150-person PayFac with a support floor, an underwriting team and a settlement desk.
Training seats are included in both retainer plans: ten seats with Minimum Viable Privacy, $5,499 CAD per year, and twenty-five with the Virtual Privacy Office, from $2,200 CAD per month, which is often the more economical route for growing processors. For a standalone program, tell us headcount and roles and we will quote it flat.
Payment Processors & PayFacs: Training questions, answered
Yes. Anyone with access to the cardholder data environment, which includes support agents who see full or partial PANs during dispute handling, falls under PCI DSS's security-awareness training requirement, delivered at hire and at least annually. We build the module around your actual support workflow, what may be read aloud on a call, what belongs in a ticket, how to verify a caller, and keep completion records in the format your QSA expects to review.
It targets the specific failure that incident revealed: staff with legitimate lookup access using it beyond what their role required. Training covers what access is actually justified for a given job, how to raise a concern about unusual internal activity, and why broad, unlogged lookup rights are a finding rather than a convenience. Paired with your own access reviews, the module gives staff the vocabulary to recognize and report the pattern before it becomes a repeat of that incident.
Yes, their exposure is completely different. Onboarding and underwriting analysts need training on beneficial-owner document review, KYB red flags and safe handling of banking details collected at intake. Engineers need training on least-privilege access to production data, why a query against live cardholder or KYB tables should never be a debugging shortcut, and how their access decisions show up in a PCI or RPAR review. Running one generic module for both groups tends to under-serve each.
At least annually for anyone with CDE access, and again after any role change that expands what a person can see or touch. We also recommend a short refresh after a relevant incident, whether at your own company or a widely reported one in the sector, because a fresh example lands better than an abstract reminder. Refresh records are kept alongside the original completion data so your evidence trail reads as continuous rather than patchy.
Usually, yes, provided the records are specific. A B-10-style due-diligence schedule typically asks whether staff receive periodic security-awareness training and how completion is tracked. We package attendance records, module summaries and refresh dates into a document you can attach directly, which tends to close that line of the questionnaire faster than a paragraph of assurances written on the spot.
Yes, because they are the specific target of payout-redirection fraud. Their module focuses on verifying banking-detail changes by callback to a known number, recognizing urgency and authority pressure in a spoofed request, and knowing exactly who else must sign off before a settlement instruction changes. This is deliberately narrower and more scenario-driven than the general awareness content, because the decision they face under pressure is very specific.
More for payment processors & payfacs
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.