Home/Questions/Third parties and vendors/Outsourced card processing
Third parties and vendors

Does the Applicant fully outsource payment card processing?

A yes here removes a whole category of exposure from your submission. It is worth confirming that it is actually true.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether card data never enters your environment: no storage, no processing, no transmission through your systems. Full outsourcing means the customer's card details go directly to the processor, typically through a hosted page or an embedded field that your systems never see.

Why it is underwritten

Card data attracts a distinct set of liabilities: card brand assessments, forensic investigation requirements, and account data compromise procedures that operate independently of general breach law. Removing card data from your environment removes all of it.

Where the answer lives in Microsoft 365, Entra ID, and Azure

This is a question about your payment architecture, so it is attested. The technical check is where card data actually flows.

PlatformWhere the setting livesWhat has to be true
Payment architectureHow card details reach the processorHosted page or direct-to-processor field, with no card data traversing your servers. Attested
Web applicationScripts running on the payment pageThird-party scripts on the payment page can capture card data even with a hosted field, which is the skimming attack pattern
Business processesPhone orders, email, and customer serviceWhether staff ever handle card details manually, which pulls those systems back into scope
Microsoft 365Content discovery for card-shaped data in mail and collaborationCard numbers arriving by mail, which happens whether or not you invited it
Compliance documentsThe self-assessment questionnaire type applicable to your flowThe questionnaire matches the architecture, which is how the outsourcing claim is evidenced
Customers send card numbers by email

Regardless of your architecture, some customers will email or read out card details. Those messages sit in mailboxes, inside your scope, indefinitely. A data loss prevention rule that blocks and deletes them is the practical control, and it is what makes a full outsourcing answer actually true.

What a defensible yes requires

  • Card data reaches the processor without traversing your systems.
  • Scripts on the payment page are controlled, since a compromised script defeats a hosted field.
  • Manual channels are addressed, including phone and email.
  • A rule detects and removes card data that arrives in mail or collaboration.
  • The questionnaire type on file matches the architecture you describe.

How this answer goes wrong

The web flow is fully outsourced and the customer service team takes card details over the phone into a notes field, or a scanned form with card details sits in a shared mailbox. Either brings systems back into scope that the compliance position excluded.

Frequently asked

Does an embedded payment field count as outsourced?

Generally yes, when the field is served by the processor and the data never touches your servers. The page still needs script control, because skimming attacks target the page rather than the field.

What about stored cards for recurring billing?

Tokenisation at the processor keeps you out of scope. Storing the actual number, even encrypted, does not.

Do we still need a questionnaire?

Yes, a shorter one. Full outsourcing reduces scope substantially and does not eliminate the obligation entirely.

How do we handle card details arriving by email?

Block and delete automatically, and tell customers not to send them. Manual handling of these messages leaves them in the mailbox and in scope.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture