If your organisation takes card payments from customers, you don't need a crash course in PCI DSS. You need a way to get most of your systems, staff and call centre out of scope for it altogether. Here's how enterprise billers do that.
PCI scope is a biller problem, not just a processor problem
Most PCI compliance content online is written for banks, acquirers and payment processors preparing for a QSA audit. If you're a utility, telco, financial services provider, government agency or health biller that simply takes payments from customers, that content solves the wrong problem for you.
Your goal isn't to become an expert in the 12 PCI DSS requirements. It's to remove as much of your organisation as possible from having to meet them in the first place.
What "PCI scope" actually means
Anything that touches cardholder data is "in scope" for PCI DSS: a customer service agent taking a card number over the phone, an IVR system, your website checkout, your CRM, your call recording platform. The more systems and people that touch card data, the more of the 12 requirements you need to implement, document and prove, every single year.
For an enterprise biller running a large contact centre across multiple channels (web, IVR, agent-assisted calls) on top of legacy billing systems, that scope adds up fast. It's also largely avoidable.
The real fix is descoping, not certifying
You can spend years writing policies, segmenting networks and training staff to satisfy PCI DSS across every system that touches card data. Or you can remove those systems and people from scope entirely by making sure card data never reaches them in the first place.
That's descoping, and for a biller, it's the more direct path. Descoping doesn't remove your responsibility to take payments securely. It removes the burden of proving compliance across every system and person that would otherwise be in scope.
How Glider takes PCI scope off your business
Glider hosts the payment experience across every channel, web, IVR, call centre and QR/pay-by-link, and connects to your existing payment gateway to process the transaction. Because that experience runs on Glider's PCI DSS Level 1 certified infrastructure, card data never has to touch your systems.
That has a direct effect on your compliance position:
- Card data never touches your servers, your CRM, your call recording platform or your network
- Your organisation is typically eligible for SAQ A, the shortest and lightest PCI self-assessment questionnaire, rather than a full onsite QSA audit or the more demanding SAQ D
- The same approach applies consistently across channels: web checkout, IVR, call centre and agent-assisted payments, and QR code or pay-by-link
Call centre and IVR payments, without the recording risk
Recording customer calls is standard practice, and a regulatory requirement in some industries. It's also directly at odds with PCI DSS, which requires that no card data be recorded or stored. Businesses have tried to solve this with pause-and-resume recording, audio masking, or keypad entry, but all three rely on a human or a system getting it right every single time.
With Glider Agent Assisted Payments, customers pay directly from their own phone during the call. Agents never see or hear the card details, and nothing sensitive is captured in the recording, so you can record the full call and stay out of scope.
Web and pay-by-link
The same principle applies online. When card capture happens on Glider's hosted, PCI DSS Level 1 infrastructure rather than embedded in your own site, your web checkout and payment link flows stay out of scope too.
What changes once you're descoped
| Before | After |
|---|---|
| Card data touches your servers, CRM and call recordings | Card data never reaches your systems |
| Full onsite QSA audit or SAQ D | Typically eligible for SAQ A |
| Every agent, system and network segment in scope | Agents, telephony and IT systems descoped |
| Manual call recording workarounds (pause/resume, masking) | Full call recording, nothing sensitive captured |
| Compliance managed channel by channel | One consistent approach across web, IVR, call centre and pay-by-link |
Built for the industries carrying the most exposure
Utilities, telcos, financial services providers, government agencies and health billers tend to carry the most PCI exposure of any merchant category: high call volumes, large contact centres, and customers who still want to pay by phone. That's exactly where descoping has the biggest impact.
- Utilities — high call volumes and legacy billing systems that were never built with card data in mind
- Financial services — collections and lending teams taking payments across multiple channels, often under extra regulatory scrutiny
- Government — rates, fines and licence payments taken across web, phone and in person
- Health — patient billing teams balancing payment flexibility with strict data handling requirements
- Telco billers managing high call centre volumes and recorded customer interactions face the same exposure
Common questions
Does using Glider automatically make us SAQ A eligible?
Your acquirer or QSA makes the final call, but hosting your card payment experience on a PCI DSS Level 1 provider that connects to your gateway, so card data never reaches your own systems, is exactly the scenario SAQ A was designed for. Most billers move to SAQ A once their web, IVR and call centre payments are routed through Glider.
Does this replace our existing payment gateway?
No. Glider is gateway-agnostic and connects into your existing tech stack rather than replacing it.
What about payments taken over the phone by an agent?
Agent Assisted Payments lets customers pay from their own phone mid-call. Agents never see or hear the card details, and nothing sensitive shows up in call recordings.
Will this reduce our annual PCI compliance cost?
Fewer systems and people in scope generally means fewer controls to implement, less to document, and a lighter annual assessment. The exact saving depends on your current setup, your acquirer, and how much of your business is currently in scope.
What channels does this cover?
Web checkout, IVR, call centre and agent-assisted payments, and QR code or pay-by-link.
See how much of your PCI scope you could remove
Glider is PCI DSS Level 1, SOC 2 Type II and ISO 27001 certified, so your card data is handled by infrastructure that's already built to the standard you're trying to get out from under.

