PCI DSS v4 expects compliance to run as business as usual (BAU) — daily log reviews, quarterly scans, annual training — not as a once-a-year scramble before the assessor arrives. Kliper models this as a standing program per client: the firm configures and reviews it, the client team executes it in the portal, and every completion leaves a record your next assessment can lean on.
The BAU Tab
Open any client in the Engagement Hub — BAU is the first tab on the client page.
Activating a Program
A client starts at day zero with no program. Click Activate program to seed 32 recurring activities taken straight from the standard’s mandated frequencies — each pre-mapped to its control and cadence:
| Cadence | Examples |
|---|---|
| Daily | Review security event logs (10.4.1), monitor alerting (12.10.5) |
| Weekly | Payment-page change detection (11.6.1), POI inspections (9.5.1.2.1) |
| Monthly | Critical patches (6.3.3), anti-malware review (5.3.2) |
| Quarterly | Internal scans (11.3.1), ASV scans (11.3.2), data purges (3.2.1) |
| Six-monthly | NSC ruleset review (1.2.7), access reviews (7.2.4) |
| Annual | Penetration test (11.4.1), awareness training (12.6.3), scope confirmation (12.5.2) |
| Per change | Network diagrams (1.2.3), change control (6.5.1) |
Add client-specific obligations with Add activity.
Assigning Owners
Each activity carries an owner — the client-side person accountable for it. Click Assign on a row and enter their name, plus an optional portal email:
Three Lenses
- Activities — the heartbeat table, grouped by cadence. Overdue activities are pulled into a pinned section at the top and return to their cadence group once marked done. Statuses: On track / Due soon / Overdue / Not started.
- Owners — the same activities regrouped per person, with unowned activities pinned first.
- Register — the client’s living risk list. Entries open automatically when an activity crosses its due date and close themselves with a system note when it’s marked done. Manual entries (risks you add yourself) close manually — and closing or risk-accepting any entry requires a note, so the register stays auditable. Severity is always hand-picked, never computed.
Marking Done
Click any activity to open its drawer: what PCI expects, the full occurrence history (who, when, note, evidence), and the Mark done form — date, optional note, optional evidence reference. Every completion is a record, not a checkbox.
The Client Portal Side
The client team executes the program at Recurring tasks in the client portal:
- Tasks are bucketed by time — Overdue (pinned), This week, Later — because the doer thinks in “what do I owe this week,” not in cadences.
- Mine shows the logged-in person’s tasks (matched by their portal email); All tasks shows the whole program, with other people’s tasks read-only and unassigned tasks actionable by anyone on the team.
- Mark done opens the same completion form — the record lands instantly in the firm-side view.
Email Reminders
A daily job (07:00 UTC) emails each owner one digest listing their tasks that newly became due soon or overdue, with a button into the portal. Each task reminds once per state per cycle — no daily nagging — and the counter resets when the task is marked done.