← PCI DSS 4.0.1 · Req 12 — Policies and programmes

12.5.2 — PCI DSS scope documented and confirmed annually

high inventoryrecords

Requirement

PCI DSS scope is documented and confirmed at least once every 12 months and upon significant change — identifying all data flows, locations where account data is stored, processed and transmitted, connected systems, and segmentation controls — together with an inventory of in-scope system components.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
pci scopepci dss scopescope of the cdecde scopescope of the cardholder data environmentscopingscope is confirmedscope is documentedin-scope systemsin-scope system components
Required element 2 — any one of
confirmeddocumentedannual…every 12 monthsdata flowdata flowsinventorysignificant change
Supporting terms — specificity signals
12.5.112.5.2data-flow diagramsystem inventory

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
GDPR Art.30 Records of processing activities records inventory
GDPR Art.5(2) Accountability records
CCPA/CPRA Regs 7101 Records of consumer requests kept for 24 months records
SOC 2 CC2.1 Quality information for internal control records
ISO 27001 A.5.9 Inventory of information and other associated assets inventory
ISO 27001 A.5.31 Legal, statutory, regulatory and contractual requirements records
GLBA 314.4(c)(2) Inventory of data, personnel, devices and systems inventory
NIST CSF 2.0 ID.AM-01 Inventories of hardware are maintained inventory