Introducing Bland Speech v3, the most realistic voice model.

Back to blog

13 PCI Compliance Violations and Their Consequences

Built for regulated industries, this guide on PCI compliance violations helps enterprise teams avoid costly penalties with self-hosted architecture.

Ethan ClouserUpdated August 10, 202624 min read

Passing your annual PCI assessment does not mean your cardholder data environment is secure. Here is what actually triggers a violation, how fast penalties compound, and where the phone channel quietly blows your scope.

Most enterprise buyers in regulated industries think: "We've passed our annual PCI assessment, so our cardholder data environment is secure, including our phone channel." That confidence is often well-earned. It is also, frequently, out of date before the ink dries.

The reason is scope. PCI DSS violations are not limited to breaches caused by bad actors. A violation is any failure to meet the 12 Payment Card Industry Data Security Standard (PCI DSS) requirements designed to protect cardholder data.

Enterprise compliance desk with passed PCI certificate beside an expanding cardholder data environment boundary

All 12 must be satisfied simultaneously; falling short on even one is a violation, regardless of whether a breach has occurred. The Cardholder Data Environment (CDE) is defined by what touches cardholder data, not by what your last assessment documented. Adding a new integration, a cloud-hosted vendor, or a third-party phone channel without reassessing scope silently expands the CDE.

Consider what happens when a compliance team adds a cloud-hosted voice AI to a payment call flow mid-year. If the vendor routes call audio through shared infrastructure outside the organization's environment, the CDE has expanded in a way no checkbox exercise will catch. The prohibition against retaining sensitive authentication data after authorization is absolute: no encryption exception, no business-necessity carve-out. If a system captures spoken card numbers during a call and retains that audio or transcript after authorization is complete, the violation is not a gray area; it is absolute, and no compensating control overrides it.

Key takeaways#

  • PCI DSS violations aren't limited to breaches caused by bad actors. Scope failures, misconfigured log files, and unmapped third-party pipelines trigger the same penalties as a direct intrusion.
  • Fines are the smallest line item. The real cost of a violation lands simultaneously: card-brand assessments, forensic investigation fees, mandatory re-audits, and civil litigation, none of which appear in the fine-range slide your board approved.
  • Target, British Airways, and TJX each failed on PCI DSS requirements that already existed and were already named. The standard wasn't the gap; execution was.
  • QSA assessments keep surfacing violations in voice channels where live payment audio moves through third-party infrastructure that was never added to the cardholder data environment scope.
  • Signing a BAA with a cloud voice vendor transfers liability on paper; it does nothing to change where call audio actually travels or whose infrastructure processes it.
  • The only architectural move that removes third-party voice risk from your CDE is eliminating the third party entirely. Bland's self-hosted infrastructure runs the full voice stack on its own GPU hardware, co-located for network speed, with a CDE boundary your QSA can actually inspect.

The Financial Penalties for PCI Non-Compliance — and How Fast They Escalate#

The common assumption is that passing an annual PCI assessment means the cardholder data environment is secure, including the phone channel. The fine range gets cited in board decks. It gets used to justify firewall budgets and annual QSA fees.

What rarely gets cited is everything else that hits simultaneously the moment a violation surfaces, because the monthly penalty is almost never the largest invoice a non-compliant organization receives. One dimension that compounds exposure quietly: organizations that process payments or handle sensitive member data over the phone often underestimate how broadly PCI scope can reach. A flat network architecture, common in small and mid-market operations, means a single non-compliant device, such as a laptop used for phone-based payment intake, can pull the entire network into scope.

Escalating PCI non-compliance fines shown as rising bars beside stacked invoice folders and a cracked calculator

What looked like an SAQ A engagement becomes an SAQ-D SP engagement, and compliance costs scale accordingly before a single fine is issued.

The $5,000 to $100,000 Fine Range — What the Tiers Actually Mean#

Compliance practitioners report that small businesses hosting client sites face unexpectedly broad PCI scope, so compliance costs can escalate well beyond what they initially anticipated — for example, needing SAQ-D SP instead of the simpler SAQ A.

PCI DSS non-compliance fines range from $5,000 to $100,000 per month, assessed by card brands such as Visa and Mastercard and passed through acquiring banks to merchants, according to a 2026 review. The tier you land in depends on violation severity, transaction volume, and your compliance history. A first-time gap in a lower-risk environment typically starts at the lower end. Repeat violations or failures protecting high-volume cardholder data environments push toward the ceiling fast.

Escalation Mechanics — How Monthly Fines Tier Upward Over Time#

Fines compound monthly and escalate in tier the longer non-compliance persists. A merchant fined at the lower end of the monthly range while remediating an encryption gap accumulates substantial penalties over the months-long remediation window before a single forensic invoice arrives. Stay non-compliant longer, and the monthly figure steps upward into a higher tier.

The escalation is not linear; it accelerates. This is precisely where the phone channel creates hidden risk. High-volume phone operations — outbound sales, open-enrollment outreach, inbound intake — generate the most touchpoints with sensitive data, and they are frequently staffed by human agents working under capacity pressure.

When agents are overwhelmed, shortcuts emerge: calls handled on unscoped devices, data entered into systems outside the assessed environment, transfers managed through workarounds. Every one of those shortcuts is a potential scope expansion event. American Way Health, for example, faced exactly this dynamic: every open-enrollment period brought an avalanche of inbound leads their human agents simply could not reach fast enough; leads went cold within minutes, and the pressure to move quickly created the conditions where process discipline breaks down.

Recruiting teams face the same ceiling, spending hours on repetitive screening calls, meaning the team couldn't maintain consistent process controls across every interaction simply because human bandwidth was the hard limit on volume. Removing human agents from the highest-repetition, highest-volume call legs is one structural way to reduce that scope exposure. Bland.ai's AI phone calling, available on plans from Start through Enterprise, handles outbound and inbound call flows continuously, without the bandwidth ceiling that forces human agents into shortcuts.

On higher-tier plans, concurrent calls can run simultaneously with a high-uptime SLA, real-time transcription included in the per-minute rate, and no separate token charges, meaning the call environment is consistent and auditable at volume, not variable based on which agent happened to pick up. American Way Health captured this directly: "Bland allowed us to scale our outreach during open enrollment without hiring a ton of new agents. The AI handles the first touch, qualifies the lead, and transfers them over to our team, it's been a game changer."

Consistent, logged, AI-handled first-touch calls are a materially different compliance surface than a pool of human agents working at capacity under deadline pressure.

The Costs That Dwarf the Fine#

Forensic investigation fees, elevated transaction processing rates, and emergency remediation sprints routinely exceed the fine itself, often by a wide margin. What most teams report after a confirmed breach is forensic investigation costs running into the hundreds of thousands of dollars. Acquiring banks also impose elevated processing rates on non-compliant merchants, a recurring surcharge that compounds across every transaction for the duration of non-compliance.

Emergency remediation adds engineering hours, third-party assessors, and infrastructure changes that rarely come cheap. The real number is not any single line item. A mid-market organization managing a months-long remediation cycle can realistically face substantial combined costs across fines, forensic fees, elevated processing surcharges, and emergency engineering expenses before a single legal settlement is negotiated, a figure that dwarfs the annual cost of proactive compliance infrastructure.

Bland.ai's dedicated infrastructure tier includes compliance documentation available under NDA, on-prem and VPC deployment options, data residency controls, and a forward-deployed engineering team, structural controls that address the phone-channel scope problem before the QSA arrives, not after.

Real-World PCI Breach Consequences — What Target, British Airways, and TJX Actually Paid#

Three of the most expensive data breaches in payment history share one uncomfortable fact: every control that failed had a corresponding PCI DSS requirement that already existed. These weren't gaps in the standard. They were gaps in execution.

And the financial consequences that followed weren't unpredictable; they were the direct, documented cost of leaving named requirements unmitigated. One of the sharpest challenges compliance practitioners face is that no single reliable "cost per record" figure exists for PCI breaches. The TJX, British Airways, and Target cases each landed at radically different per-record costs depending on card-reissuance exposure, litigation posture, and regulatory jurisdiction.

That ambiguity makes it genuinely difficult to benchmark risk internally, and it is exactly the kind of monitoring gap that real-time visibility tools are designed to close.

TJX and TJMaxx — The $256M Blueprint for What Unencrypted Cardholder Data Actually Costs#

TJX Companies exposed tens of millions of customer accounts between 2005 and 2006 through an unencrypted wireless network segment at a single store location. The initial Visa settlement was only the opening payment. Card reissuance fees, litigation costs, and remediation expenses pushed total financial exposure to hundreds of millions of dollars.

The root cause mapped directly to PCI DSS Requirement 4: failure to encrypt cardholder data in transit across public networks. The unencrypted wireless segment wasn't an unknown risk; it was an unmitigated one. A detailed breakdown of how those costs compounded is documented in the Target breach post-mortem analysis, which illustrates how per-record costs diverge sharply once litigation and remediation are separated from the headline fine.

For organizations running high call volumes across voice channels today, the same execution gap surfaces differently: customer calls that carry sensitive payment context move through agent interactions at scale, and no one is watching the full picture in real time. Bland.ai's Enterprise plan includes real-time sentiment analysis across all customer calls to identify trends and surface anomalies as they happen, giving compliance and operations teams the visibility layer that post-breach reviews consistently show was absent. That capability ships on dedicated infrastructure, with compliance documentation available under NDA and a forward-deployed engineering team that delivers a working first agent within 30 days.

1. Bland.ai — Best for Regulated Industries Needing PCI-Safe Voice AI Infrastructure#

For enterprises handling payment data over phone channels, PCI compliance violations often originate in voice infrastructure — recorded card numbers, unencrypted call data, third-party API exposure. Bland.ai's self-hosted architecture eliminates the shared-infrastructure risk that triggers PCI scope creep. It's the right pick for financial services, healthcare, and high-volume commerce teams that can't afford a TJX-style breach traced back to a vendor. Tradeoff: self-hosted deployment demands internal DevOps maturity.

2. TJX / TJMaxx — The $256M Blueprint for What Unencrypted Cardholder Data Actually Costs#

TJX's 2005–2006 breach, 94 million card records exposed through unencrypted wireless networks, became the defining PCI compliance violation case study. Total costs exceeded $256 million including a $40.9 million Visa settlement, card reissuance fees, and litigation. For security and compliance teams benchmarking breach risk, TJX illustrates how a single unencrypted data segment can cascade into enterprise-ending liability. Limitation: the regulatory landscape has tightened significantly since 2007, making modern penalties even steeper.

3. British Airways — The £20M GDPR-PCI Overlap Penalty That Redefined Multi-Regulator Exposure#

In 2018, a Magecart script injection on British Airways' payment page compromised hundreds of thousands of customers. The UK Information Commissioner's Office initially proposed a substantially larger penalty; the final fine was reduced to £20 million, partly due to COVID-19's economic impact. The breach mapped to PCI DSS Requirement 6, which governs secure systems and software development, specifically the failure to detect unauthorized script modifications on a payment-processing page.

What makes this case instructive is the dual-regulator exposure: the same technical failure triggered both GDPR enforcement and PCI DSS violations simultaneously, compounding reputational damage alongside the financial penalty. The Target breach analysis at Cloudskope surfaces a parallel pattern: when a single control point fails, the cost attribution across regulators rarely lands where risk models predicted. Most enterprises assume a vendor contract closes their compliance exposure on a third-party channel.

The British Airways case demonstrates the opposite: contractual data-handling clauses do not rewrite the technical fact of where data traveled, and regulators assess the data flow, not the paperwork. For teams managing voice as a customer channel at scale, that same logic applies. Bland.ai's Enterprise plan offers data residency controls, on-prem and VPC deployment options, JWT signatures, BAA availability, and SSO, precisely because the technical fact of where voice data flows is what a regulator will examine, not the vendor agreement attached to it.

For organizations not yet at enterprise scale, higher-tier plans provide a structured foundation with high-uptime guarantees, version controls, and expanded knowledge base capacity to build documented, repeatable call handling before compliance exposure grows with call volume.

13 PCI Compliance Violations and Their Consequences — The Full List#

QSA assessments keep turning up violations in places no one mapped. Not in the obvious spots, like an unencrypted database sitting on a public-facing server, but in log files that have been quietly capturing full card numbers for months, in third-party pipelines that were never added to the cardholder data environment scope, and in voice channels where live payment audio routes through shared cloud infrastructure that nobody thought to inventory. The most common PCI DSS violations are almost never the ones organizations expect.

The most common types of PCI DSS violations fall into predictable categories: improper data storage, weak access controls, missing encryption, skipped scans, and unmanaged third-party pipelines. Each one maps to a specific PCI DSS requirement, and each one carries a fine exposure of $5,000 to $100,000 per month until the gap is closed. What follows is the full list, with the decision-relevant detail that compliance and security teams actually need.

Third-Party and Agentic Pipeline Failures#

This is the violation most organizations discover last, and it carries the same fine exposure as every other item on this list. Requirement 12.8 mandates that organizations maintain a list of all service providers with access to cardholder data, confirm their compliance status annually, and document their responsibilities. Requirement 12.8 places the documentation and annual confirmation burden on the merchant, not the vendor.

The failure mode that standard breach narratives miss is the agentic pipeline: a contact center deploying a generic cloud-based voice AI for payment calls inadvertently routes live card number audio through a third-party cloud, triggering Requirement 12.8 and Requirement 4 violations simultaneously. No BAA or contractual SLA closes this gap, because the data is already leaving the environment before any contractual protection applies. Most teams handle this by requesting compliance documentation from their voice AI vendor and treating the BAA as sufficient coverage.

The hidden cost is that the data has already left the perimeter; the contract only governs what happens after. Platforms built on self-hosted voice infrastructure eliminate this exposure at the architecture level: when the full voice stack runs on dedicated, customer-controlled GPUs with no third-party cloud routing, the CDE scope expansion from the phone channel never occurs in the first place. A clean annual PCI assessment is a liability timestamp, not a security guarantee.

The fine clock starts the moment the environment drifts from its assessed state, and in practice, that drift begins the day after the QSA leaves. Knowing which of the 13 violations your organization is most exposed to is only half the equation. The harder question is which controls actually close each gap without creating new compliance debt.

The next section maps a specific, actionable control to every violation on this list, starting with the one that standard frameworks still don't have a clean answer for: the phone channel.

PCI Compliance Violations Quick-Reference — All 13 Violations, Requirements, and Controls

Violation

PCI DSS Requirement

Primary Control

1

Storing prohibited cardholder data (CVV/CVC/PINs)

Req. 3.2/3.3

Eliminate post-auth storage; enforce purge at processor level

2

Plaintext storage of PANs

Req. 3.4

Tokenization at point of capture

3

Default or weak system passwords

Req. that same figure

Automated provisioning checklist; credential rotation policy

4

Unencrypted cardholder data in transit

Req. 4.1

Enforce TLS 1.2+ on all paths including voice channels

5

Missing or overdue vulnerability scans

Req. 11

Quarterly ASV scans; annual pen test calendar integration

6

Inadequate patch management

Req. 6.3

Patch SLA ≤30 days; include third-party and legacy systems

7

Audit log failures

Req. 10

Centralized SIEM; 12-month retention, 3-month hot availability

8

Weak or absent access controls

Req. 7

Least-privilege RBAC reviewed quarterly

9

Missing multi-factor authentication

Req. 8.3

MFA on all remote and non-console admin access (v4.0 scope)

10

Absent or inadequate network segmentation

Req. 1

Firewall allow-lists; segmentation validated by pen test

11

No formal security policy

Req. 12

Documented, published, annually reviewed policy

12

Inadequate physical security controls

Req. 9

Physical access controls for all CDE locations and media

13

Third-party and agentic pipeline failures

Req. 12.8 + Req. 4

Self-hosted or fully auditable vendor infrastructure; annual TPSP compliance confirmation

1. Storing Prohibited Cardholder Data — The Most Cited PCI Compliance Violation#

CVV/CVC codes, full magnetic stripe data, and PINs cannot be stored after authorization under any circumstances, regardless of encryption status. This is one of the most heavily penalized storage violations because it is absolute: there is no compensating control that makes post-authorization CVV storage acceptable. A retailer keeping CVV codes in an order management database "for customer convenience" is in direct violation of Requirement 3.2, and the fine clock starts the moment a QSA or forensic investigator finds it.

2. Weak or Default Passwords on Payment Systems — A Gateway Violation#

Using vendor-supplied default credentials or deploying weak passwords on point-of-sale terminals, routers, and payment applications is a foundational PCI compliance violation. It directly violates Requirement 8 and is a leading entry point in card-data breaches. Merchants with distributed retail locations face the greatest exposure. The tradeoff is operational: enforcing strong credential policies across hundreds of endpoints requires centralized identity management most SMBs lack.

3. Failure to Maintain a Firewall Configuration — Network Perimeter Violations#

PCI DSS Requirement 1 mandates documented, tested firewall rules protecting the cardholder data environment. Auditors routinely find overly permissive rules, undocumented rule sets, and firewalls that haven't been reviewed in over a year. This violation is common in organizations that grew quickly through acquisition. The real limitation: firewall rule reviews require cross-team coordination between network, security, and compliance functions that rarely share a single workflow.

4. Unencrypted Transmission of Cardholder Data Across Open Networks#

Transmitting PANs over HTTP, unencrypted FTP, or legacy protocols like Telnet violates PCI DSS Requirement 4 and exposes organizations to fines ranging from $5,000 to $100,000 per month. E-commerce platforms and payment integrators are most vulnerable. Consequences escalate sharply after a confirmed breach. The tradeoff: migrating legacy integrations to TLS 1.2+ often requires renegotiating contracts with third-party processors and rebuilding older API connections.

5. Lack of Regular Security Testing — Vulnerability Scan Failures#

PCI DSS Requirements 11.3 and 11.4 mandate quarterly external vulnerability scans by an Approved Scanning Vendor and annual penetration testing. Organizations that skip or delay these tests, often citing cost or resource constraints, face immediate non-compliance findings during QSA assessments. The consequence is loss of compliant status and potential card brand fines. The tradeoff: penetration testing engagements are expensive and require remediation windows that interrupt release cycles.

6. Insufficient Access Controls — Violating the Least-Privilege Principle#

Granting employees broader access to cardholder data than their job function requires violates PCI DSS Requirement 7. This is especially prevalent in fast-scaling fintech companies where access provisioning outpaces policy enforcement. Auditors flag shared admin accounts and orphaned user credentials as critical findings. The key limitation: implementing role-based access control retroactively in monolithic systems is technically complex and often requires significant re-architecture.

7. Failure to Track and Monitor All Access to Network Resources — Log Management Violations#

PCI DSS Requirement 10 mandates comprehensive logging of all access to cardholder data and network resources, with log retention for at least 12 months. Organizations frequently fail audit on incomplete log coverage, missing timestamps, or logs that aren't reviewed daily. Payment processors and large retailers face the steepest fines for this violation. The tradeoff: centralized SIEM solutions that satisfy Requirement 10 carry significant licensing and operational overhead.

8. Unpatched Systems and Software in the Cardholder Data Environment#

Running operating systems or payment applications with known, unpatched vulnerabilities violates PCI DSS Requirement 6 and is a direct precursor to breaches like the Target and Home Depot incidents. Organizations with large, heterogeneous endpoint estates struggle most. Card brands treat unpatched critical CVEs as a severe compliance failure. The real tradeoff: patch deployment in payment environments requires extensive regression testing to avoid breaking certified payment applications.

9. No Formal Security Policy — Documentation and Governance Violations#

Requirement 12 mandates a documented, published, and annually reviewed information security policy that addresses all PCI DSS requirements. The absence of this policy is a standalone violation, but its downstream effect is larger: without a formal policy, every other control in the organization lacks a governance anchor. QSAs treat the policy as the foundation. If it is missing or outdated, every other finding carries additional weight.

10. Third-Party Vendor Non-Compliance — Supply Chain PCI Violations#

Several of the largest PCI compliance breaches in history, including Target's 2013 breach, originated through non-compliant third-party vendors with access to the cardholder data environment. PCI DSS Requirement 12.8 mandates managing and monitoring all service providers. Organizations that fail to obtain annual compliance attestations from vendors face shared liability. The tradeoff: enforcing vendor compliance requires contractual leverage and ongoing monitoring programs that add procurement complexity.

11. Improper Segmentation of the Cardholder Data Environment — Scope Creep Violations#

Failing to properly isolate the cardholder data environment from the rest of the corporate network dramatically expands PCI scope and increases breach risk. QSAs frequently find flat network architectures where payment systems share segments with general business systems. This violation inflates compliance costs and fine exposure simultaneously. The core tradeoff: proper network segmentation through VLANs, firewalls, and microsegmentation requires significant infrastructure investment and ongoing validation.

12. Failure to Protect Physical Access to Cardholder Data — Physical Security Violations#

PCI DSS Requirement 9 mandates physical access controls for all systems storing or processing cardholder data, including badge access logs, visitor management, and protection of POS terminals from tampering or skimming. Retail environments and hospitality businesses are most frequently cited. Physical security violations are often overlooked during internal reviews focused on digital controls. The limitation: retrofitting physical access controls in older retail locations requires capital expenditure and operational disruption.

13. Inadequate Employee Security Awareness Training — Human Factor Violations#

PCI DSS Requirement 12.6 mandates formal security awareness training for all personnel with access to cardholder data, delivered at hire and annually thereafter. Auditors consistently find organizations with no documented training program or training records that can't be produced during assessments. Phishing and social engineering remain the leading human-factor breach vectors in payment environments. The tradeoff: building a training program that satisfies QSA evidence requirements demands dedicated HR and compliance coordination.

How to Avoid PCI Compliance Violations — Controls That Address All 13#

Preventing PCI violations is not a documentation problem. It is a control design problem, and the difference matters enormously when a breach investigator is tracing cardholder data through infrastructure your QSA never reviewed. A mistake payment and operations teams frequently make is assuming that using a PCI-compliant gateway automatically makes their entire payment environment compliant; it does not.

Gaps remain wherever cardholder data flows through systems, voice channels, or integrations that were never brought into scope, and those gaps are exactly where violations originate. The controls below address each of the 13 violations directly, but read them with one structural truth in mind: layered controls reduce risk on channels you can observe, and they cannot eliminate scope expansion on channels where data flows through infrastructure you do not own.

Shield hub connecting 13 PCI compliance controls including tokenization, firewalls, and self-hosted voice AI

Tokenization — Replace Cardholder Data With Non-Sensitive Tokens to Shrink CDE Scope#

Tokenization is the most effective way to prevent prohibited-data storage and plaintext-PAN violations simultaneously. By replacing the primary account number (PAN) with a non-sensitive token at the point of capture, downstream systems, logs, and databases never touch real cardholder data. Systems that only ever see tokens fall outside PCI scope entirely: fewer systems to audit, fewer controls to maintain, and a smaller blast radius if any single component is compromised.

For teams handling high call volumes through AI voice agents, this principle extends to the voice channel itself. Bland.ai's Enterprise plan includes compliance documentation available under NDA, dedicated infrastructure, and on-premises or VPC deployment options, architectural choices that let regulated teams eliminate dependence on third parties for data privacy and control, keeping tokenization logic inside an environment your QSA can actually review rather than delegating it to shared infrastructure you cannot fully inspect.

Minimize What You Store — Build a Data-Retention Policy With Defined Purge Schedules#

Plaintext-storage and retention violations both trace back to data that outlived its purpose sitting in a database, a log file, or a backup tape someone forgot to rotate. Define retention windows by data category, automate deletion, and document the schedule in a policy your QSA can verify. If you cannot state exactly where every PAN lives and when it will be destroyed, your retention policy is aspirational, not operational. Bland.ai's Enterprise plan includes data residency controls, which means regulated organizations can specify where call data is stored and processed, a prerequisite for building a defensible retention policy that covers the voice channel, not just the database tier.

Enforce TLS 1.2+ on Every Network Path That Carries Cardholder Data, Including Voice Channels#

Every network path that carries cardholder data must enforce TLS 1.2 or higher, with expired or self-signed certificates treated as a blocking issue. The voice channel deserves specific attention: call audio containing spoken card numbers is cardholder data in transit, and if that audio traverses a public network segment without enforced encryption, you have a Requirement 4 violation regardless of what your call recording policy says. This is where the intersection of AI voice and compliance gets operationally complex.

Bland.ai is most beneficial when a business already uses platforms like Amazon Connect or a CRM and needs the AI agent to operate within that existing stack, meaning encrypted call paths that Amazon Connect already enforces can be preserved rather than bypassed by bolting on a separate, unaudited voice layer. Bland.ai's Amazon Connect integration lets AI agents handle inbound and outbound call flows inside the existing encrypted infrastructure, so encryption controls do not need to be renegotiated or re-documented from scratch.

Network Segmentation — Isolate the CDE From General Business Networks to Contain Breach Blast Radius#

The Verizon 2026 Data Breach Investigations Report (DBIR) identifies network segmentation failures as a primary enabler of lateral movement. Segment the cardholder data environment from general business networks using firewalls with explicit allow-list rules, and validate that segmentation with penetration testing, not just configuration review. A segmented CDE does not prevent every breach; it contains the damage to a defined perimeter you can actually defend. For organizations running AI-assisted phone operations at scale, the segmentation question extends to where AI agent infrastructure lives. Bland.ai's Enterprise plan includes a dedicated orchestration server and on-premises or VPC deployment, options that allow the AI voice layer to be placed inside a segmented CDE rather than routing regulated call audio through shared cloud infrastructure outside your network perimeter.

Harden Access Controls — Apply Least-Privilege and Unique User IDs#

Requirement 7 and Requirement 8 together demand that access to cardholder data is granted only to individuals whose role explicitly requires it, and that every individual authenticates with a unique user ID. Shared credentials, a single login used by a whole team, make forensic attribution impossible after a breach and are treated as a standalone violation. Implement role-based access controls (RBAC) that are reviewed quarterly and revoked immediately upon role change or termination.

Pair least-privilege enforcement with MFA on every remote and non-console administrative path, and audit the access log against the current org chart at least once per quarter. If your RBAC model was designed before your last re-org, it is likely already out of compliance. Bland.ai's Enterprise plan includes SSO, JWT signatures, and guardrails, controls that give regulated teams the identity and access primitives needed to enforce unique user IDs and least-privilege access across the AI voice layer, not just across traditional application tiers.

The Verizon 2026 Data Breach Investigations Report (DBIR) and the PCI Security Standards Council's own analysis of that report both underscore that credential abuse remains a leading breach vector, making SSO enforcement and JWT-signed API authentication on AI agent infrastructure a control gap that QSAs are increasingly scrutinizing. For organizations that handle complex, regulated calls that generic AI cannot support, having these access controls native to the AI platform, rather than grafted on afterward, is the difference between a defensible architecture and a compensating control that may not satisfy your QSA.

Eliminate PCI Scope Creep on the Phone Channel With Self-Hosted Voice Infrastructure#

Signing a BAA with a cloud voice vendor feels like closing the compliance loop on your phone channel. It is not. The contract transfers liability on paper; it does nothing to change where your call audio actually travels.

Voice call path splitting between risky shared cloud and secure self-hosted server infrastructure

Why Third-Party Voice AI Platforms Silently Expand Your Cardholder Data Environment#

PCI DSS takes a broad view of scope: any system component that stores, processes, or transmits cardholder data is in-scope for the CDE by definition (SecurityScorecard). The moment a caller reads a card number and that audio traverses a third-party platform's shared cloud infrastructure, that platform is part of your CDE, whether your QSA scoped it or not. Contractual data-handling clauses do not change the data flow; they document who is blamed after the fact.

This is not a theoretical risk for operations running high-volume, high-stakes phone calls. When your AI agents are handling inbound payment inquiries and outbound follow-ups continuously, 24/7, at the call volumes that justify AI investment in the first place, spoken card numbers are crossing that shared infrastructure on every qualifying interaction. The compliance exposure scales with the very call volume that makes the AI economically attractive.

The Audit Problem — Why QSAs Cannot Fully Scope Shared-Cloud Voice Infrastructure#

QSAs can only assess what they can inspect. On a shared, multi-tenant cloud voice platform, your assessor cannot verify network segmentation, sub-processor access controls, or whether call transcripts touch infrastructure outside your environment (SecurityScorecard). Third-party integrations are consistently among the most common sources of scope-expansion findings in PCI audits (Davis Wright Tremaine).

Scope creep found late means remediation costs, extended assessment timelines, and a CDE boundary that is harder to defend the next cycle. Teams that rely on platforms like Amazon Connect and layer AI voice on top, without controlling where that AI infrastructure runs, face the same inspection problem. An Amazon Connect integration that routes audio through a shared-cloud AI layer adds the AI vendor's infrastructure to audit scope, regardless of how the integration is documented.

Self-Hosted Architecture as a Structural Control, Not a Compensating Control#

Most compliance teams handle the phone channel by layering a BAA, encryption policy, and vendor questionnaire on top of a shared-cloud voice AI platform. Each of those is a documentation control. None of them changes the underlying data flow: call audio containing spoken card numbers still traverses the vendor's infrastructure, which means the vendor's infrastructure is in your CDE whether or not your QSA has scoped it (SecurityScorecard).

A self-hosted architecture is not a compensating control applied on top of an existing risk; it eliminates the scope expansion at the infrastructure level. Bland.ai's self-hosted (on-prem / VPC) deployment option, available on the Enterprise plan, is purpose-built for exactly this boundary problem. When the full voice stack runs on dedicated, customer-controlled infrastructure, with no third-party cloud routing, live payment audio never leaves the customer's environment, and the CDE boundary remains exactly where the last QSA drew it.

The Enterprise plan also makes compliance documentation available under NDA, giving your QSA the inspection surface that a shared-cloud vendor simply cannot provide. Bland.ai's forward-deployed engineering team operates on a defined rapid deployment framework, scoping, building, and gray/red/green-team testing before go-live, so dedicated infrastructure does not mean a multi-quarter procurement delay. The result is an architecture that lets you automate high-volume, high-stakes phone calls and deliver consistent customer experiences at scale, without expanding the CDE every time a caller reads a card number.

Next steps#

If your compliance team passed its last PCI assessment and still routes payment calls through a shared-cloud voice platform, the path forward starts with recognizing that the assessment certified the scope you declared, not the scope that actually exists. Start with our voice AI.

A clean annual assessment is a liability timestamp, not a security guarantee, which means the fine clock starts ticking the moment your environment drifts from its assessed state. And as the third-party pipeline analysis in this post shows, vendor infrastructure the merchant never fully controlled is a recurring source of payment card breaches. Together, those two facts point to one structural conclusion: documentation controls (BAAs, vendor questionnaires, SOC 2 reports) cannot close a gap that lives at the infrastructure layer, and the phone channel is where that gap is widest.

Start with voice AI built on self-hosted, customer-controlled infrastructure. From there, your QSA gets an auditable CDE boundary around live payment call audio, compliance documentation available under NDA, and on-prem or VPC deployment options that keep spoken card numbers inside an environment you actually own.

Frequently Asked Questions#

What actually counts as a PCI DSS violation?#

Any failure to meet even one of the 12 PCI DSS requirements is a violation; a breach doesn't have to occur. All 12 requirements must be satisfied simultaneously, so a single gap, like retaining spoken card numbers in a call recording after authorization or using a default system password, is a violation the moment it exists.

Who issues PCI DSS fines and how much can they reach?#

Fines are assessed by card brands such as Visa and Mastercard and passed through acquiring banks to merchants. They range from $5,000 to $100,000 per month, with the tier depending on violation severity, transaction volume, and compliance history, and they compound monthly, escalating to higher tiers the longer non-compliance persists.

Are the monthly fines really the biggest cost when a violation is found?#

No. Forensic investigation fees, elevated transaction processing rates, and emergency remediation costs routinely exceed the fine itself, often by a wide margin. A mid-market organization working through a months-long remediation cycle can face substantial combined costs across all of these line items before a single legal settlement is negotiated.

Can I store CVV codes if I encrypt them?#

No. CVV/CVC codes, full magnetic stripe data, and PINs cannot be stored after authorization under any circumstances, regardless of encryption status. There is no compensating control that makes post-authorization CVV storage acceptable under PCI DSS Requirement 3.2.

Does adding a new phone channel or cloud vendor affect my PCI scope even if I've already passed my annual assessment?#

Yes. The Cardholder Data Environment is defined by what touches cardholder data, not by what your last assessment documented. Adding a cloud-hosted vendor or a third-party phone channel without reassessing scope silently expands the CDE, meaning your passing assessment can be out of date before the ink dries.

See Bland on your actual call volume.

10 to 15 minutes with the team that ships your first agent. We come prepared with answers, not a pitch deck.

Book a call
Written byEthan ClouserContributor