The customised approach under PCI DSS v4.0.1 was introduced to provide organisations with greater flexibility. Instead of forcing modern payment environments into rigid prescriptive controls, PCI DSS now allows organisations to implement alternative controls – provided they can prove those controls achieve the same security objective.
On paper, that sounds straightforward.
In practice, it is exposing a major operational gap across APAC.
Throughout 2025 and into 2026, QSA assessments across the region have revealed a recurring pattern: organisations are capable of implementing controls, but many are failing to consistently demonstrate that those controls remain effective over time.
The Question That Stops the Room
During a PCI DSS v4.0.1 assessment of a mid-sized Philippine payment service provider in early 2026, a QSA team asked a single question:
“Can you show us evidence that this control has continuously achieved its intended security objective over the past twelve months?”
The organisation had already implemented a customised web application security control under Requirement 6.4. The architecture was well designed. Documentation was detailed. Exception handling looked mature.
But the organisation struggled to produce sustained operational evidence.
This is becoming a defining characteristic of PCI DSS v4.0.1 assessments across APAC.
The issue is rarely technical incompetence.
The real challenge is that many organisations still treat compliance as a documentation exercise rather than an operational assurance discipline.
From Prescriptive Compliance to Continuous Assurance
Historically, PCI DSS operated as a prescriptive framework.
Security teams implemented clearly defined controls, produced screenshots or configuration evidence, and passed assessments through relatively straightforward validation activities.
The customised approach changes that model entirely.
Under PCI DSS v4.0.1, organisations are now responsible for:
- Defining the alternative control
- Explaining how the control satisfies the intended security objective
- Performing targeted risk analysis
- Maintaining ongoing evidence of effectiveness
- Demonstrating operational assurance to QSAs continuously over time
This introduces a significantly heavier evidentiary burden on the assessed entity.
For modern cloud-native environments, API ecosystems, tokenised payment systems, and containerised infrastructure, the customised approach offers necessary flexibility.
But flexibility without operational maturity creates exposure.
Why APAC Organisations Are Failing Validation
QSA assessments throughout APAC are uncovering several recurring failure patterns.
1. The Implementation Assurance Gap
Many organisations can implement controls successfully.
What they cannot yet do consistently is generate continuous operational evidence that those controls remain effective over time.
Security teams frequently produce point-in-time evidence for controls that require continuous validation.
2. Retrospective Risk Analysis
Requirement 12.3 mandates targeted risk analysis for customised approach controls.
However, many organisations still create these documents shortly before assessments rather than maintaining them as living operational artefacts.
A compliance justification document created weeks before an audit does not carry the same credibility as a continuously maintained risk management process.
3. Third-Party Visibility Blind Spots
APAC payment ecosystems often rely on complex third-party chains involving:
- Payment aggregators
- Cloud providers
- Tokenisation platforms
- Sub-merchants
- Managed infrastructure providers
An organisation may maintain strong internal controls while lacking visibility into outsourced payment processing dependencies.
When oversight fails at these boundaries, customised approach validation often collapses.
The Five Most Common QSA Findings in 2026
Assessment teams across APAC are now converging around a highly recognisable set of recurring findings.
1. Security Process Validation Gaps
API security validation has emerged as a major weakness.
Many organisations maintain incomplete API inventories, meaning security controls are operating against inaccurate asset scopes.
This creates immediate assessment problems under Requirement 6.
2. Logging and Monitoring Deficiencies
Hybrid cloud environments continue to generate visibility gaps.
QSAs are repeatedly identifying:
- Inconsistent cloud logging
- Missing telemetry between cloud and on-premises environments
- Weak detection engineering maturity
- Poor evidence retention processes
These issues commonly surface under Requirement 10.
3. Governance and Risk Management Failures
Security controls frequently evolve faster than governance documentation.
Common findings include:
- Policies not updated for customised controls
- Risk registers disconnected from operational decisions
- Weak board-level oversight of payment security controls
These governance failures are increasingly surfacing under Requirement 12.
4. Compensating Control Misuse
Many organisations incorrectly treat compensating controls and customised approach controls as interchangeable.
QSAs are increasingly challenging permanent workaround models that were originally built under legacy compensating control methodologies.
5. Evidence Collection Failures
Perhaps the most common issue is evidence fragmentation.
Security evidence often exists across ticketing systems, SIEMs, cloud consoles, and change management tools, but organisations lack structured processes to continuously collect and retain assessment-ready evidence.
As a result, assessment periods become reactive reconstruction exercises.
Why SAQ-D Is No Longer Sufficient
One of the most dangerous misconceptions emerging across APAC is the belief that SAQ-D remains sufficient for customised approach environments.
It does not.
SAQ-D was designed for prescriptive validation models.
It does not require organisations to:
- Demonstrate how controls achieve security objectives
- Maintain targeted risk analysis documentation
- Provide analytical validation evidence
- Prove continuous assurance outcomes
Under PCI DSS v4.0.1, customised approach environments require formal Report on Compliance (ROC) assessments performed by QSAs or qualified Internal Security Assessors.
Organisations claiming customised approach status while relying solely on SAQ-D are creating compliance blind spots that may remain invisible until regulatory scrutiny or network enforcement occurs.
Regional Regulatory Exposure Across APAC
PCI DSS failures are no longer isolated payment compliance problems.
Across APAC, they increasingly trigger broader regulatory consequences.
Philippines – BSP Circular 1140
BSP Circular 1140 establishes technology risk management obligations for supervised financial institutions and payment operators.
Where PCI DSS customised controls fail, the same weaknesses often constitute broader technology risk governance failures under BSP supervision.
Regulatory tolerance for compliance gaps is rapidly decreasing.
Malaysia – PDPA and Bank Negara
In Malaysia, PCI DSS failures can directly intersect with PDPA obligations around security safeguards and breach notification.
Organisations managing PCI DSS and privacy obligations separately are creating operational blind spots where a single security failure can trigger multiple regulatory consequences simultaneously.
Singapore – MAS TRM and the Payment Services Act
Singapore’s regulatory environment expects a significantly higher level of operational maturity.
A common failure pattern emerging during assessments is overconfidence in the quality of documentation without the corresponding operational security maturity to back it up.
Internal audit readiness does not always equal operational assurance readiness.
The Cross-Border Boundary Problem
Cross-border payment ecosystems are creating another major focus area for QSAs.
QSAs are increasingly scrutinising:
- Jurisdictional boundaries
- Shared processing environments
- Cross-border data movement
- Third-party processing chains
- Responsibility transfer points
These boundary conditions are becoming some of the highest-risk zones for regulatory exposure.
A single control failure can now cascade across multiple jurisdictions simultaneously, multiplying notification obligations and enforcement exposure.
What Mature Organisations Are Doing Differently
The organisations that successfully pass customised approach assessments share several operational characteristics.
Version-Controlled Risk Analysis
Targeted risk analysis documentation is maintained continuously with revision history, ownership tracking, and operational updates.
These are living governance artefacts — not documents created before assessments.
Automated Evidence Collection
Mature organisations integrate compliance evidence directly into operational tooling.
When QSAs request twelve months of evidence, the response is a structured export — not a manual search across disconnected systems.
Governance Integration
Risk committees formally review customised control decisions.
Changes to control architecture trigger parallel updates to compliance documentation, risk analysis, and governance processes.
Pre-Assessment Internal Assurance Testing
Successful organisations validate their customised controls internally before formal QSA assessments begin.
The assessment becomes confirmation of operational maturity rather than discovery of hidden gaps.
Operational Resilience Is the Real Objective
The customised approach is exposing a deeper reality across APAC payment ecosystems.
Most organisations struggling with PCI DSS v4.0.1 are not fundamentally insecure.
They often have capable security teams and strong technical intent.
What many have not yet built is assurance infrastructure:
- Continuous evidence management
- Operational governance
- Structured risk reasoning
- Compliance-integrated security operations
- Evidence-driven security culture
Implementing a control is an engineering task.
Continuously proving its effectiveness is an operational discipline.
That is the real shift PCI DSS v4.0.1 is forcing across APAC in 2026.
Final Thoughts
The organisations succeeding with the customised approach are not treating compliance as a yearly assessment.
They are treating it as a continuous operational capability.
As regulatory expectations across APAC continue to tighten — particularly across the Philippines, Malaysia, and Singapore — the gap between perceived compliance maturity and demonstrable assurance maturity will become increasingly visible.
PCI DSS v4.0.1 is no longer asking organisations whether controls exist.
It is asking whether organisations can continuously prove those controls work.
And for many across APAC, that remains the hardest question in the room.

