Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Training · Fintech & financial services

Privacy & Security Training for Payment Processors & PayFacs

Our training teaches the people who actually touch cardholder and merchant data how to handle it: support agents reading PANs during disputes, onboarding analysts reviewing beneficial-owner files, and settlement staff approving payouts. PCI DSS names security-awareness training as a control, and insider-access incidents at payments companies have shown what happens when staff with broad lookup rights are never taught the boundary. Processors typically book this ahead of a PCI assessment cycle, after a sponsor's due-diligence questionnaire asks how training is tracked, or following a scare involving an employee's access.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What training must cover for staff who touch payment data

A generic security-awareness module misses the roles where a payments company's real exposure sits. Four groups need purpose-built content.

Support staff with PAN visibility

Agents who see full or partial card numbers during dispute and support calls need explicit rules on what may be read aloud, typed into a ticket, or repeated back to a caller claiming to be the cardholder.

Onboarding and underwriting analysts

Staff reviewing beneficial-owner IDs, void cheques and banking details at sub-merchant intake need training on handling, storage and the red flags of a fabricated applicant.

Engineers with production data access

Developers who can query transaction or KYB tables in production need clear rules on least-privilege access, logging expectations and why a debugging shortcut into live cardholder data is a PCI finding waiting to happen.

Settlement and finance staff

The people who approve payout runs and banking-detail changes are the direct target of business email compromise, so their training centres on verification-by-callback and recognizing pressure tactics.

Regulatory map

Why training is a named control, not a nice-to-have

PCI DSS names it directly, and several other obligations quietly assume a trained workforce sits behind the paper.

PCI DSS security-awareness training

The standard requires a formal security-awareness program for personnel, with training at hire and at least annually for anyone with access to the CDE, a control your QSA checks records for.

Primary source →

RPAR competency underneath the framework

The Retail Payment Activities Regulations expect controls to be tested and reviewed, which is difficult to demonstrate if the people executing those controls were never trained on them.

Primary source →

PIPEDA safeguards extending to your workforce

Appropriate protection for cardholder and merchant-owner data includes staff competence: employees handling that information are themselves part of the safeguard, or a gap in it.

Read our guide →

Law 25 governance presumes informed staff

Quebec's regime assumes an organization where people understand the privacy rules they operate under, relevant the moment your onboarding or support teams handle Quebec merchant or cardholder files.

Primary source →

What goes wrong

What untrained staff let through

The incidents below are less about missing technology and more about a person nobody had told where the line sat.

  • Insiders mining internal lookup tools

    In September 2020, employees on Shopify's support team abused their standing access to internal tooling and pulled transaction histories for close to 200 merchants, without ever needing to breach a single external defence.

    Source →

  • A support agent talked past a social-engineering script

    A caller impersonating a merchant or cardholder can extract far more over a support line than any technical control blocks, if the agent has never rehearsed a verification script that holds under pressure.

  • A payout approved on a spoofed instruction

    Settlement staff facing an urgent, plausible request to change banking details are the last control before a business-email-compromise attempt becomes stolen funds, which is why their training centres on slowing down, not speed.

  • A synthetic sub-merchant approved at intake

    Onboarding analysts who have never been shown the patterns behind fabricated beneficial-owner documents can wave a fraudulent applicant straight into your merchant base.

Our training for payment processors & payfacs

What our training covers for a PSP

Tailored modules, compliance fundamentals and flexible delivery, built around the roles that actually handle cardholder and merchant data.

Skilled team of developers using modern technologies for testing application online showing to leader, multiracial young crew of students concentrated on working process watching v
  1. Role-tracked modules

    Distinct content for PAN-handling support staff, onboarding and KYB analysts, engineers with production access, and settlement and finance teams, rather than one session for everyone.

  2. PCI-aligned security awareness

    Curriculum built to satisfy PCI's training requirement for anyone with CDE access, covering data handling, incident reporting and the annual refresh cycle.

  3. Insider-risk and access discipline

    A module addressing why broad lookup rights need justification and logging, and how to raise a concern about a colleague's access without waiting for an incident to prove the point.

  4. Fraud and social-engineering scenarios

    Practical drills built from payments workflows: a support call, a payout-change request, a synthetic onboarding applicant, run as decision exercises rather than lectures.

  5. Evidence pack for QSA and sponsor reviewers

    Completion records, curriculum summaries and refresh dates packaged so a QSA interview or a sponsor's due-diligence schedule gets a clean, current answer.

How the engagement runs

Rolling training out across a PSP's teams

We start from your org chart, because the content that matters differs sharply between a support floor and a settlement desk.

  1. Step 1

    Tune the content

    We adapt modules to your systems, your acquirer and sponsor names, and your actual onboarding and support workflows, not a generic financial-services template.

  2. Step 2

    Deliver by role

    Cohorts run live where discussion helps, especially for the fraud scenarios, and on-demand where support and operations shifts make live sessions impractical.

  3. Step 3

    Capture the record

    Completions, dates and roles are logged into an evidence pack from the first session, because untracked training answers nobody's questionnaire.

  4. Step 4

    Refresh on a schedule

    Annual refreshers plus updates triggered by a new sponsor, a new product line, or any incident that shows a gap in what staff were taught.

What it costs

What training costs depend on at a PSP

Pricing tracks headcount, how many role tracks you need, whether live sessions are required for fraud-scenario drills, and how much customization your onboarding and support workflows call for. A ten-person gateway team is a different project from a 150-person PayFac with a support floor, an underwriting team and a settlement desk.

Training seats are included in both retainer plans: ten seats with Minimum Viable Privacy, $5,499 CAD per year, and twenty-five with the Virtual Privacy Office, from $2,200 CAD per month, which is often the more economical route for growing processors. For a standalone program, tell us headcount and roles and we will quote it flat.

Payment Processors & PayFacs: Training questions, answered

Yes. Anyone with access to the cardholder data environment, which includes support agents who see full or partial PANs during dispute handling, falls under PCI DSS's security-awareness training requirement, delivered at hire and at least annually. We build the module around your actual support workflow, what may be read aloud on a call, what belongs in a ticket, how to verify a caller, and keep completion records in the format your QSA expects to review.

It targets the specific failure that incident revealed: staff with legitimate lookup access using it beyond what their role required. Training covers what access is actually justified for a given job, how to raise a concern about unusual internal activity, and why broad, unlogged lookup rights are a finding rather than a convenience. Paired with your own access reviews, the module gives staff the vocabulary to recognize and report the pattern before it becomes a repeat of that incident.

Yes, their exposure is completely different. Onboarding and underwriting analysts need training on beneficial-owner document review, KYB red flags and safe handling of banking details collected at intake. Engineers need training on least-privilege access to production data, why a query against live cardholder or KYB tables should never be a debugging shortcut, and how their access decisions show up in a PCI or RPAR review. Running one generic module for both groups tends to under-serve each.

At least annually for anyone with CDE access, and again after any role change that expands what a person can see or touch. We also recommend a short refresh after a relevant incident, whether at your own company or a widely reported one in the sector, because a fresh example lands better than an abstract reminder. Refresh records are kept alongside the original completion data so your evidence trail reads as continuous rather than patchy.

Usually, yes, provided the records are specific. A B-10-style due-diligence schedule typically asks whether staff receive periodic security-awareness training and how completion is tracked. We package attendance records, module summaries and refresh dates into a document you can attach directly, which tends to close that line of the questionnaire faster than a paragraph of assurances written on the spot.

Yes, because they are the specific target of payout-redirection fraud. Their module focuses on verifying banking-detail changes by callback to a known number, recognizing urgency and authority pressure in a spoofed request, and knowing exactly who else must sign off before a settlement instruction changes. This is deliberately narrower and more scenario-driven than the general awareness content, because the decision they face under pressure is very specific.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.