Start free trial
Fintech

Walked into a PCI audit with the evidence already collected

Control responses, SOC 2 reports and pen tests were already in the vault when the assessor asked. Nobody spent the week chasing PDFs.


Tomas Ek

Head of Compliance, Ledgerline

Published

2 min read

Results at the 2026 assessment

Findings raised against third-party management controls
0
Evidence-gathering window ahead of the assessment
30 → 4 days
Of requested artefacts produced from the vault on the first ask
96%

Measured against Ledgerline's 2025 PCI DSS assessment, the last one run without a vault.

The month before every assessment

Ledgerline passed its assessments. It just paid for them twice: once in the assessment itself, and once in the four weeks beforehand, when four people stopped doing their jobs and went looking for documents.

The evidence existed. It was in a mail thread from fourteen months ago, or on a shared drive under a filename with somebody’s initials, or — often enough to matter — only in the memory of a person who had since moved teams. Every assessment started by rebuilding a picture that had been complete once already.

Collect once, at the review

Nothing about what Ledgerline collects changed. What changed is when, and where it lands.

Evidence is now attached to the vendor at the moment of the review, with its issue date, its expiry and the control it answers. When a SOC 2 report expires the review reopens on its own; when a sub-processor list changes, the vendor’s PCI scope flag is re-evaluated. By the time an assessor asks, the answer is a filter, not a search.

“The assessor asked for the pen test on our tokenisation vendor. It took about eleven seconds. Last year that question cost us two days.”

The 2026 assessment

  • Zero findings against third-party management, against three observations the year before.
  • The evidence-gathering window fell from thirty days to four, and three of those four were scheduling.
  • 96% of requested artefacts came out of the vault on the first ask. The remaining 4% were two vendors onboarded the month before the assessment.

What’s next

Ledgerline is mapping the same vault against DORA, which shares most of its evidence with PCI and almost none of its vocabulary. The mapping is the work; the documents are already there.


About Ledgerline

Ledgerline builds payment orchestration for European merchants. 310 people across Stockholm and London, PCI DSS Level 1 and SOC 2 Type II. Tomas Ek heads the compliance function and owns the third-party programme.

More customer stories

A locked shield rendered over a data centre, representing protected clinical records
Healthcare

−84% review time

38 days to 6, across 240 clinical vendors

A hospital group routed intake by data sensitivity instead of by whoever picked up the ticket. Two analysts clear the queue weekly.


Northwind Health

Glowing data pathways routing across a dense circuit landscape
Marketplace

3× volume, same team

1,200 sellers onboarded without adding a reviewer

Low-risk sellers clear an automated tier in minutes; only the top two tiers reach a human. The review team stayed at four people.


Kestrel Market

A framed SOC 2 Type II certificate standing on a desk
Healthcare

100% on-time renewals

Renewals stopped falling through the cracks

Certificate expiry and sub-processor changes reopen the review on their own, so nothing waits for an annual calendar reminder.


Aurea Bio