Skip to content

BAU & Recurring Compliance

Run each client's standing PCI program between assessments — recurring activities, owners, a living register, and a portal where the client team executes.

Updated View as Markdown

PCI DSS v4 expects compliance to run as business as usual (BAU) — daily log reviews, quarterly scans, annual training — not as a once-a-year scramble before the assessor arrives. Kliper models this as a standing program per client: the firm configures and reviews it, the client team executes it in the portal, and every completion leaves a record your next assessment can lean on.

The BAU Tab

Open any client in the Engagement Hub — BAU is the first tab on the client page.

Activating a Program

A client starts at day zero with no program. Click Activate program to seed 32 recurring activities taken straight from the standard’s mandated frequencies — each pre-mapped to its control and cadence:

Cadence Examples
Daily Review security event logs (10.4.1), monitor alerting (12.10.5)
Weekly Payment-page change detection (11.6.1), POI inspections (9.5.1.2.1)
Monthly Critical patches (6.3.3), anti-malware review (5.3.2)
Quarterly Internal scans (11.3.1), ASV scans (11.3.2), data purges (3.2.1)
Six-monthly NSC ruleset review (1.2.7), access reviews (7.2.4)
Annual Penetration test (11.4.1), awareness training (12.6.3), scope confirmation (12.5.2)
Per change Network diagrams (1.2.3), change control (6.5.1)

Add client-specific obligations with Add activity.

Assigning Owners

Each activity carries an owner — the client-side person accountable for it. Click Assign on a row and enter their name, plus an optional portal email:

Three Lenses

  • Activities — the heartbeat table, grouped by cadence. Overdue activities are pulled into a pinned section at the top and return to their cadence group once marked done. Statuses: On track / Due soon / Overdue / Not started.
  • Owners — the same activities regrouped per person, with unowned activities pinned first.
  • Register — the client’s living risk list. Entries open automatically when an activity crosses its due date and close themselves with a system note when it’s marked done. Manual entries (risks you add yourself) close manually — and closing or risk-accepting any entry requires a note, so the register stays auditable. Severity is always hand-picked, never computed.

Marking Done

Click any activity to open its drawer: what PCI expects, the full occurrence history (who, when, note, evidence), and the Mark done form — date, optional note, optional evidence reference. Every completion is a record, not a checkbox.

The Client Portal Side

The client team executes the program at Recurring tasks in the client portal:

  • Tasks are bucketed by time — Overdue (pinned), This week, Later — because the doer thinks in “what do I owe this week,” not in cadences.
  • Mine shows the logged-in person’s tasks (matched by their portal email); All tasks shows the whole program, with other people’s tasks read-only and unassigned tasks actionable by anyone on the team.
  • Mark done opens the same completion form — the record lands instantly in the firm-side view.

Email Reminders

A daily job (07:00 UTC) emails each owner one digest listing their tasks that newly became due soon or overdue, with a button into the portal. Each task reminds once per state per cycle — no daily nagging — and the counter resets when the task is marked done.

Was this helpful?

Report an issue with this page
Navigation

Type to search…

↑↓ navigate↵ selectEsc close