Does the Applicant fully outsource payment card processing?
A yes here removes a whole category of exposure from your submission. It is worth confirming that it is actually true.
What the carrier is actually asking
The carrier is asking whether card data never enters your environment: no storage, no processing, no transmission through your systems. Full outsourcing means the customer's card details go directly to the processor, typically through a hosted page or an embedded field that your systems never see.
Why it is underwritten
Card data attracts a distinct set of liabilities: card brand assessments, forensic investigation requirements, and account data compromise procedures that operate independently of general breach law. Removing card data from your environment removes all of it.
Where the answer lives in Microsoft 365, Entra ID, and Azure
This is a question about your payment architecture, so it is attested. The technical check is where card data actually flows.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Payment architecture | How card details reach the processor | Hosted page or direct-to-processor field, with no card data traversing your servers. Attested |
| Web application | Scripts running on the payment page | Third-party scripts on the payment page can capture card data even with a hosted field, which is the skimming attack pattern |
| Business processes | Phone orders, email, and customer service | Whether staff ever handle card details manually, which pulls those systems back into scope |
| Microsoft 365 | Content discovery for card-shaped data in mail and collaboration | Card numbers arriving by mail, which happens whether or not you invited it |
| Compliance documents | The self-assessment questionnaire type applicable to your flow | The questionnaire matches the architecture, which is how the outsourcing claim is evidenced |
Regardless of your architecture, some customers will email or read out card details. Those messages sit in mailboxes, inside your scope, indefinitely. A data loss prevention rule that blocks and deletes them is the practical control, and it is what makes a full outsourcing answer actually true.
What a defensible yes requires
- Card data reaches the processor without traversing your systems.
- Scripts on the payment page are controlled, since a compromised script defeats a hosted field.
- Manual channels are addressed, including phone and email.
- A rule detects and removes card data that arrives in mail or collaboration.
- The questionnaire type on file matches the architecture you describe.
How this answer goes wrong
The web flow is fully outsourced and the customer service team takes card details over the phone into a notes field, or a scanned form with card details sits in a shared mailbox. Either brings systems back into scope that the compliance position excluded.
Frequently asked
Does an embedded payment field count as outsourced?
Generally yes, when the field is served by the processor and the data never touches your servers. The page still needs script control, because skimming attacks target the page rather than the field.
What about stored cards for recurring billing?
Tokenisation at the processor keeps you out of scope. Storing the actual number, even encrypted, does not.
Do we still need a questionnaire?
Yes, a shorter one. Full outsourcing reduces scope substantially and does not eliminate the obligation entirely.
How do we handle card details arriving by email?
Block and delete automatically, and tell customers not to send them. Manual handling of these messages leaves them in the mailbox and in scope.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture