Yes. A self-assessment is only credible when the organisation can show that access to cardholder data is current, limited, and reviewed with clear ownership. Identity governance supplies the evidence trail behind that claim, so access reviews and remediation records are part of the compliance control set, not optional extras.
How PCI DSS self-assessments become an access-control evidence exercise
A self-assessment is only defensible if the organisation can prove who can reach cardholder data, why they can reach it, and whether that access is still justified. That means the assessment is not just a questionnaire, it is an evidence pull from identity, access, and review processes. If the access story is weak, the self-assessment is weak, even if the technical answers look complete.
For payment environments, the control question is less “do we have a policy?” and more “can we show current entitlements, business ownership, and review outcomes for every relevant account?” That is why PCI DSS v4.0 matters here: access restriction and account-use expectations push organisations toward evidence-backed access governance, not paper compliance.
identity governance gives the assessor something verifiable: access approvals, recertification results, removal records, and ownership assignments. Without those artefacts, a self-assessment can confirm intent but not control operation.
Why identity governance is part of the compliance control set
PCI DSS self-assessments are credible only when the organisation can demonstrate that access is current, limited, and reviewed. In practice, that depends on identity governance processes such as access certification, role ownership, entitlement scoping, and remediation tracking. If those processes are outside the compliance workflow, the organisation usually ends up answering the questionnaire from memory instead of evidence.
This is especially important where access changes frequently or where multiple teams share responsibility for cardholder data systems. A self-assessment can quickly become stale if there is no closed loop between access review findings and actual entitlement removal. For that reason, Access Reviews and Certification Guide is a useful companion for turning review activity into audit-ready proof.
Good governance also means distinguishing between standing access and exceptional access. If a user, admin, or service account has broad or persistent access without a current business need, the self-assessment should not treat that as a documentation issue. It is a control failure that needs remediation before the response is signed off.
What auditors and assessors actually need to see
The strongest self-assessments show a direct chain from access requirement to approval to review to remediation. Practitioners should expect to produce the owner of the data or system, the list of accounts in scope, the entitlements attached to those accounts, the date of the last review, and evidence that exceptions were removed or formally accepted.
That chain is easier to maintain when the organisation runs identity governance as a recurring operational process rather than as an annual project. The most useful evidence usually comes from the same system of record that manages provisioning, review campaigns, and role changes. IAM and IGA Basics is relevant because it frames that operating model clearly: authenticate, authorise, review, and remove what is no longer justified.
Self-assessments also benefit from clear exception handling. If a business owner accepted a risk temporarily, that exception should have scope, expiry, and compensating control evidence. Otherwise the assessment is describing a permanent control gap as if it were a temporary deviation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while PCI DSS v4.0 and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| PCI DSS v4.0 | 7.1 — Restrict Access by Business Need to Know | Self-assessments depend on proving least-privilege access to cardholder data. |
| 7.2 — Access Control Systems | Current access evidence must reflect controlled entitlement assignment and enforcement. | |
| 8.6 — Use of Application and System Accounts | Account governance is central when assessing non-human or shared accounts with access. | |
| Recommendation — Document and enforce business-need access restrictions for all in-scope accounts. Use access control systems to define and enforce who can reach cardholder data. Inventory, restrict, and review system and application accounts that can access the CDE. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The question hinges on governed, evidenced access decisions over sensitive data systems. |
| A.5.18 — Access rights | Self-assessment credibility depends on current access rights being reviewed and removed when obsolete. | |
| Recommendation — Apply formal access control rules and keep them evidence-ready for review. Review, approve, and revoke access rights on a defined cadence. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | PCI self-assessment credibility requires showing access is limited to business need. |
| IA-5 — Authenticator Management | Account and credential governance supports proving access is controlled and current. | |
| AU-6 — Audit Record Review, Analysis, and Reporting | Review findings and remediation evidence are part of the assurance trail for self-assessment. | |
| Recommendation — Limit entitlements to the minimum needed and remove excess access promptly. Manage authenticators and related lifecycle evidence for in-scope accounts. Review audit evidence regularly and retain records that show issues were addressed. | ||
| CIS Controls v8 | 5 — Account Management | Account ownership, review, and removal are the operational backbone of access evidence. |
| 6 — Access Control Management | The answer centers on governing who can access cardholder data and proving it. | |
| Recommendation — Maintain account inventories, review access, and remove stale or unnecessary accounts. Enforce least privilege and document access approvals, reviews, and exceptions. | ||
Practitioner Guidance
What to prioritise: Start with the accounts that can reach cardholder data, then separate human, privileged, and non-human access. The first question is not whether the questionnaire is complete, but whether every in-scope account has an owner, a current business need, and a review record that can survive challenge.
What to verify: Verify that remediation is closed loop. If an access review found excessive access, the evidence should show the entitlement was removed or reduced, not merely flagged. A self-assessment that cannot produce closure evidence is exposing a control design weakness, not a missing report.
What good looks like: The assessor can trace each material access path to an approver, a reviewer, and a dated outcome. The organisation can show that reviews are recurring, exceptions are time-bound, and stale or overbroad access is removed before the control relies on user memory.
Practitioner takeaway: Treat the self-assessment as proof of control operation, not a paperwork exercise. If you cannot evidence who had access, why they had it, and what changed after review, you do not yet have a credible PCI DSS self-assessment.
Related resources from NHI Mgmt Group
- What breaks when organisations treat identity compliance as a one-time legal exercise instead of an ongoing governance function?
- How should organisations treat PCI DSS 4.0 as part of an ongoing compliance programme rather than a one-time certification exercise?
- Why is it important to integrate identity and data governance?
- When should organisations treat an NHI as a high-priority risk?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org