Ep. 5: Why is PCI compliance important? Savannah Keys of Aperia Compliance explains merchant risk and security
EPISODE GUESTS
Savannah Keys is Director of Strategic Partnerships at Aperia Compliance, an IXOPAY company. She specialises in building strategic fintech relationships and driving revenue growth across mid-market and enterprise organisations.
Savannah has worked in payments for around six years, with experience spanning middleware payment technology, enterprise sales, global sales leadership and merchant compliance. Her current focus is helping acquirers, ISOs, banks and other merchant aggregators give their customers clearer, more accessible ways to manage PCI compliance.
SHOW NOTES
Key Topics Discussed:
Why small merchants struggle to understand and complete PCI compliance
How PCI SAQs work for level-three and level-four merchants
The commercial tension around PCI non-compliance fees
Whether acquirers and ISOs are doing enough to educate merchants
Why PCI compliance does not guarantee protection from a data breach
How merchant risk management is becoming more personalised
The role of payment page monitoring, endpoint protection and breach insurance
Why payments technology can never be treated as “set it and forget it”
Episode Summary:
This episode gets into why PCI compliance is important, and why it can be particularly difficult for smaller merchants to manage. Savannah Keys, Director of Strategic Partnerships at Aperia Compliance, joins Justin Hanna at Money20/20 USA to discuss merchant education, non-compliance fees, security and the changing relationship between compliance and risk.
The conversation looks at a difficult commercial tension for acquirers and ISOs. Merchants need practical help to understand their responsibilities, but non-compliance fees can also represent a significant revenue stream for payment providers. Savannah explains why simply giving a merchant access to a compliance tool is rarely enough, particularly when that merchant has limited time, limited resources and little prior knowledge of PCI DSS.
PCI compliance matters because businesses accepting card payments need to demonstrate that they are handling payment data appropriately. For many smaller merchants, that means completing a PCI self-assessment questionnaire, commonly known as an SAQ. Failing to complete the process may lead to non-compliance fees from an acquirer or payment provider.
However, one point runs through the entire discussion: PCI compliance does not equal security. Completing an assessment can support good payment data practices, but it does not guarantee that a merchant will avoid a breach.
Why do small merchants struggle with PCI compliance?
Smaller level-three and level-four merchants often do not have dedicated compliance or security teams. They may be running a shop, restaurant or other small organisation where payments compliance is one task among many.
When the first meaningful communication they receive is a warning that they could be charged a non-compliance fee, the process can feel confusing and punitive. The forms may be unfamiliar, the language may be technical and the merchant may not know where to begin.
Savannah argues that education is therefore central to improving merchant compliance. A platform can make the process easier, but providers also need to explain what merchants are being asked to do, why it matters and what action they need to take.
What is a PCI SAQ?
A PCI SAQ is a self-assessment questionnaire used by eligible merchants to evaluate their compliance with relevant PCI DSS controls.
Aperia Compliance provides a white-labelled platform through which level-three and level-four merchants can complete these questionnaires. Acquirers, ISOs, banks and other organisations with merchant portfolios can offer the platform under their own brand.
The episode does not explore the different SAQ types or formal validation requirements. Its focus is on making the process more understandable and manageable for merchants that may otherwise fail to complete it.
Are non-compliance fees helping or hurting merchants?
The discussion is candid about the role of PCI non-compliance fees. Some acquirers and ISOs provide merchants with a tool, then charge a fee when the merchant does not use it. In some organisations, those charges can produce substantial revenue.
That creates a real tension. Payment providers want merchants to become compliant, but successful merchant education may reduce income generated through non-compliance fees. Savannah does not argue that every provider takes the same approach. Some partners actively work to raise compliance rates and offer additional tools covering areas such as website accessibility, privacy and payment page monitoring.
For acquirers and ISOs, the commercial question is whether compliance should be treated mainly as an enforcement mechanism or as part of a stronger merchant service proposition. Better support may reduce fee revenue in the short term, but it can also improve trust, retention and the overall quality of the merchant portfolio.
Does PCI compliance prevent data breaches?
No. A merchant can be PCI compliant and still experience a breach. Compliance provides a baseline, but merchants may need additional protection based on their business model, payment environment and risk profile. Savannah points to tools including endpoint protection, payment page script monitoring, data breach insurance and website compliance services.
This distinction matters because merchants can easily assume that completing an annual questionnaire means the job is finished. In practice, fraud methods, technology and payment risks continue to change. For payment providers, that creates an opportunity to move beyond a standardised annual process. Instead of offering every merchant the same package, they can assess individual risk and recommend relevant products or controls.
How are compliance and merchant risk coming together?
Aperia is exploring a model that connects merchant compliance with a broader view of risk. Savannah compares the idea to credit monitoring: a merchant could log in, see how its risk compares with others and receive recommendations based on how the business operates and processes payments.
A higher-risk merchant might be advised to complete its PCI assessment while also adopting data breach insurance, payment page monitoring or another security control. A lower-risk merchant may need a different combination.
This merchant-by-merchant approach could make compliance more useful for both providers and their customers.
Acquirers gain a clearer view of portfolio risk, while merchants receive guidance connected to their actual circumstances rather than a generic checklist.
Why compliance cannot be “set it and forget it”
Savannah’s nomination for The Shelf of Shame is the phrase “set it and forget it”. That approach does not fit payments. Fraud evolves, technology changes and new compliance obligations continue to appear. A tool that was correctly configured once may still need monitoring, reassessment and updates.
The same principle applies to merchant relationships. Giving somebody access to a portal does not guarantee that they understand the process, will complete it or remain secure afterwards. Providers need to keep educating merchants and reviewing how compliance services fit alongside wider risk controls.
What this episode answers
Why is PCI compliance important?
PCI compliance helps merchants assess how they handle payment card data and demonstrate that they meet relevant PCI DSS controls. It can also help them avoid contractual non-compliance fees. However, it should be treated as one part of a broader security and risk strategy.
Does PCI compliance prevent data breaches?
No. PCI compliance establishes a baseline but cannot guarantee that a merchant will not be breached. Additional controls may be needed, including endpoint protection, payment page monitoring and appropriate insurance.
Why do small merchants struggle with PCI compliance?
Many smaller merchants lack dedicated compliance resources and may not understand PCI terminology or the assessment process. Clear education, accessible tools and practical support can make completion more likely.
What is a PCI SAQ?
A PCI SAQ is a self-assessment questionnaire used by eligible merchants to evaluate their compliance with relevant PCI DSS requirements. The correct questionnaire depends on how the merchant accepts and processes card payments.
How can acquirers and ISOs support merchant compliance?
They can provide clearer education, simpler assessment tools and support based on the merchant’s specific risk profile. They can also help merchants understand which security and compliance-adjacent services may be relevant beyond the basic assessment.
The big takeaway: PCI compliance should be the starting point for merchant protection, not the end of the conversation. For acquirers, ISOs and payment providers, that means combining accessible compliance tools with better education and risk-based support. Get that right, and merchants are more likely to complete the process, understand their exposure and build stronger security practices. Get it wrong, and compliance becomes another confusing fee rather than a useful part of the merchant relationship.
MEET THE HOSTS

Co-Host and Co-Founder of The Payments Shed Podcast
Grant Evans
Grant Evans is a leading voice in the fintech industry and the creator of the widely followed ‘The Payments Shed Newsletter’. With more than 15 years experience shaping commercial strategy and driving partnership growth, he is recognised for turning complex topics such as embedded payments, BNPL, unified commerce, and open banking into clear, actionable insights that resonate with global audiences. Named a LinkedIn Top Voice in both 2024 and 2025, Grant has built a community of over 27,000 engaged professionals, merchants, and innovators who look to him for commentary on the trends redefining global commerce. A sought-after speaker and panelist, his thought leadership is regularly featured in financial services publications and at flagship industry events including Money 20/20, FTT Fintech and the Global RegTech Summit.

Co-Host and Co-Founder of The Payments Shed Podcast
Justin Hanna
Justin Hanna was recently named the #1 Head of Sales Top Voice by the National Sales Conference for good reason: he’s redefining what sales leadership looks like in the modern era. With deep B2B sales experience and a people-first approach, Justin earns trust through insight and practical strategy, not tired tactics. A respected voice in payments, he’s also built a 22,000-strong LinkedIn following by making complex topics relatable and actionable. His influence has been recognised widely: a LinkedIn Top Payment Systems Voice (2024), one of the top 30 voices shaping the future of payments, banking, and fintech (2025), and celebrated by the National Sales Conference as the #1 Head of Sales Top Voice. Known for challenging the status quo, Justin’s unfiltered take on leadership, culture, and growth resonates because it’s honest, and his ability to lead with both expertise and empathy has made him one of the most influential sales voices today.
EPISODE TRANSCRIPT
Episode 5 Transcript
Justin Hanna:
Welcome back to The Payments Shed Podcast. Today we have Savannah Keys, Director of Strategic Partnerships at Aperia Compliance.
Savannah, thank you so much for coming on the show. Tell us a bit more about yourself and Aperia Compliance.
Savannah Keys:
Savannah Keys with Aperia Compliance. I’ve been in the payments space for about six years. I came from more of a middleware payments technology background, but this past year I entered the payments compliance space.
Aperia Compliance is a PCI compliance platform for merchant aggregators. We work with acquirers, ISOs, banks and really anybody that has merchants under them.
We give them a white-labelled platform that their merchants can use to fill out their PCI SAQs. That is mainly for level-three and level-four merchants.
Justin Hanna:
Amazing. Compliance is scary. Compliance is tough. How should merchants really be looking at it?
Savannah Keys:
Compliance is interesting because a lot of merchants have no idea what it means.
When we think about small and medium-sized merchants, particularly level-three and level-four merchants doing PCI on their own, we are talking about small organisations and independent businesses.
They do not have the time or resources, and they simply do not know what to do.
If you are told, “Sit down and fill out this PCI audit, or you’re going to receive a big, scary non-compliance fee,” a lot of people do not know where to start.
Then you add the fact that every year there is another regulation or another thing on their list. It is really tricky, but that is where the creation of our platform started.
Justin Hanna:
Education is a big piece of it. As you mentioned, a lot of merchants do not understand PCI.
You are trying to educate them about something they have never heard of, while also telling them they might otherwise receive a fine. That can be quite scary, and they are not always sure how to react.
Do we think acquirers and ISOs are doing enough to educate their merchants?
Savannah Keys:
That is a great question. Some are and some are not.
Some take the route of saying, “I gave them a tool, they didn’t use it, so I’m going to charge them a non-compliance fee.”
That is where a lot of their revenue comes from. I am not saying that is good or bad. It is simply their viewpoint.
However, we do work with some organisations that really try to ensure all of their merchants are PCI compliant.
They are also rolling out additional tools that are compliance-adjacent. ADA web compliance and privacy are big areas. Payment page script monitoring is another example.
There are a lot of compliance-related or federally regulated areas that have emerged over the past couple of years. We are seeing partners who want to give these tools to their merchants.
They want to help merchants become compliant and avoid the fee, but also provide tools that support their business.
Justin Hanna:
You made a good point. It is a revenue stream for many acquirers, whether we like it or not.
In some cases, they are making millions from PCI non-compliance fees. It becomes a case of being careful what you wish for.
We want to help our customers, but there is also revenue that needs to be brought into the business.
Savannah Keys:
Absolutely. It is a difficult balance.
Justin Hanna:
When we talk about regulation, technology and fraud, everything is improving and changing every day.
What is Aperia Compliance doing to keep up with how quickly the industry is moving?
Savannah Keys:
One of our most recent projects is based on the fact that we will always be a compliance platform, but we are trying to shift how we look at compliance because that is where the industry is going.
With PCI compliance, there may not be credit card numbers in the future. That does not mean compliance will go away.
I think there will always be compliance around the payments side, but we are really looking at how we can bring risk and compliance together.
We are creating a future tool that you can think of a bit like credit monitoring.
When a merchant logs in, they will be able to see how they are performing and whether they are considered risky based on what their business does and how they process payments.
Their partner, acquirer or processor can then say, “Based on your risk, we suggest that you become PCI compliant. We also recommend data breach insurance, payment page script monitoring or website compliance.”
There are all these tools that we can help provide based on the individual merchant.
Justin Hanna:
So it is more specific to each merchant. Everyone’s needs are different.
Savannah Keys:
Yes.
Justin Hanna:
Incredible. What do you think the next 12 months will look like in compliance?
Savannah Keys:
I think the risk element will be really important.
There is a lot happening in the industry, and people are starting to talk about how a merchant becoming PCI compliant does not protect them from a breach.
Compliance does not mean that a merchant is safe.
I think we will see more people saying, “Yes, become PCI compliant, but also download this endpoint protection.”
They may also say, “Become PCI compliant, but take these additional steps to protect your business,” particularly for small merchants.
Justin Hanna:
You may think you are PCI compliant, but that does not mean you are not still exposed to a breach.
Savannah Keys:
Exactly. Compliance does not equal security.
Justin Hanna:
How has Money20/20 been for you so far?
Savannah Keys:
It has been great. I love Money20/20. I think it is my favourite show of the year.
I love the energy and the people. I think this is my fifth year attending, so I am starting to see people in the hallway and think, “I know you out of all these people.”
That is really cool. There are a lot of great vendors here, and I am learning a lot from everybody.
Justin Hanna:
Amazing. One last thing, Savannah: The Shelf of Shame.
What grinds your gears in payments that we can tell our listeners about?
Savannah Keys:
This one is interesting because I used to say this when I entered the payments space, and it really matched what I was doing at the time.
I hate it when vendors say, “Set it and forget it.”
That is especially true in payments because, as you said, the industry is changing daily.
Anything related to payments or technology cannot simply be set up and forgotten. You constantly have to stay on top of it.
Justin Hanna:
That is a good point. Sometimes we can blame salespeople for that. We simply move on to the next one.
Savannah, thank you so much for your time, and have a great event.
Savannah Keys:
Likewise. Thank you.
Join the podcast for a relaxed conversation where you can share your experience and perspective with people working across the payments industry.
Be a Guest on the Podcast
Sponsor the podcast and get your brand featured in front of the top players in the Payments and fintech industry.