Storefront Location Manager

PCI Compliance

A storefront location manager is the person responsible for day-to-day operations of the storefront.

Responsibilities

1. Annual PCI Compliance

Storefront location managers are responsible for maintaining ongoing PCI DSS compliance ensuring all of this happens:

  • Completing the Annual PCI Merchant Survey
  • Completing required annual PCI and Cash Handling Training and ensuring all team members are trained.
  • Maintaining an accurate up-to-date payment device inventory in the department
  • Use only PCI-compliant service providers.
  • Maintain approved contracts.
  • Access Control Management:
    • Performing periodic user access reviews
    • Enforce the Principle of Least Privilege.
    • Remove user access immediately following role changes or termination.
    • Assign unique user accounts.
    • Maintain strong authentication and password practices.
  • Submitting required third-party PCI validation documentation (SAQ, AOC, or ROC)

2. Physical Security

  • Inspect payment terminals before each shift.
  • Secure payment devices when not in use.
  • Monitor devices for evidence of tampering or substitution.
  • Document all device inspections.

3. Cash Handling and Financial Controls

  • Perform beginning and ending cash counts, where applicable.
  • Complete daily three-way reconciliation of sales, deposits, and Banner.
  • Submit deposits and transmittals timely.
  • All refunds must be reviewed and approved by the supervisor prior to processing. No refunds may be issued without supervisory authorization.
  • All chargebacks should be documented, investigated, and escalated to the PCI Committee for review. A chargeback occurs when a cardholder disputes a payment card transaction with their issuing bank, resulting in the reversal of funds from the merchant while the transaction is reviewed and resolved. 
  • Retain all receipts, sales logs, and deposit records for at least five fiscal years in accordance with institutional record-retention requirements.