---
title: "BAU & Recurring Compliance"
description: "Run each client's standing PCI program between assessments — recurring activities, owners, a living register, and a portal where the client team executes."
version: "en"
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.kliper.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# BAU & Recurring Compliance

PCI DSS v4 expects compliance to run as **business as usual (BAU)** — daily log reviews, quarterly scans, annual training — not as a once-a-year scramble before the assessor arrives. Kliper models this as a standing program per client: the firm configures and reviews it, the client team executes it in the portal, and every completion leaves a record your next assessment can lean on.

## The BAU Tab

Open any client in the Engagement Hub — **BAU** is the first tab on the client page.

### Activating a Program

A client starts at day zero with no program. Click **Activate program** to seed **32 recurring activities taken straight from the standard's mandated frequencies** — each pre-mapped to its control and cadence:

| Cadence | Examples |
|---|---|
| Daily | Review security event logs (10.4.1), monitor alerting (12.10.5) |
| Weekly | Payment-page change detection (11.6.1), POI inspections (9.5.1.2.1) |
| Monthly | Critical patches (6.3.3), anti-malware review (5.3.2) |
| Quarterly | Internal scans (11.3.1), ASV scans (11.3.2), data purges (3.2.1) |
| Six-monthly | NSC ruleset review (1.2.7), access reviews (7.2.4) |
| Annual | Penetration test (11.4.1), awareness training (12.6.3), scope confirmation (12.5.2) |
| Per change | Network diagrams (1.2.3), change control (6.5.1) |

Add client-specific obligations with **Add activity**.

### Assigning Owners

Each activity carries an owner — the client-side person accountable for it. Click **Assign** on a row and enter their name, plus an optional **portal email**:

> **Note**
>
> The portal email is what connects an owner to the client portal: it scopes their **Mine** view and is where reminder emails go. A name without an email is a label; a name with an email is a working assignment.

### Three Lenses

- **Activities** — the heartbeat table, grouped by cadence. Overdue activities are pulled into a pinned section at the top and return to their cadence group once marked done. Statuses: On track / Due soon / Overdue / Not started.
- **Owners** — the same activities regrouped per person, with unowned activities pinned first.
- **Register** — the client's living risk list. Entries **open automatically when an activity crosses its due date** and **close themselves with a system note when it's marked done**. Manual entries (risks you add yourself) close manually — and closing or risk-accepting any entry requires a note, so the register stays auditable. Severity is always hand-picked, never computed.

### Marking Done

Click any activity to open its drawer: what PCI expects, the full occurrence history (who, when, note, evidence), and the **Mark done** form — date, optional note, optional evidence reference. Every completion is a record, not a checkbox.

## The Client Portal Side

The client team executes the program at **Recurring tasks** in the client portal:

- Tasks are bucketed by time — **Overdue** (pinned), **This week**, **Later** — because the doer thinks in "what do I owe this week," not in cadences.
- **Mine** shows the logged-in person's tasks (matched by their portal email); **All tasks** shows the whole program, with other people's tasks read-only and unassigned tasks actionable by anyone on the team.
- **Mark done** opens the same completion form — the record lands instantly in the firm-side view.

## Email Reminders

A daily job (07:00 UTC) emails each owner **one digest** listing their tasks that newly became due soon or overdue, with a button into the portal. Each task reminds once per state per cycle — no daily nagging — and the counter resets when the task is marked done.

> **Caution**
>
> Reminders reach only owners assigned with a portal email. The BAU tab banners flag unowned activities for exactly this reason.

Source: https://docs.kliper.dev/operations/bau-recurring-compliance/index.mdx
