What the payment-security guidance says
The PCI Security Standards Council’s small-business terminal guidance recommends maintaining a device list and photographs, looking for unfamiliar attachments, altered cables or damaged seals, and recording who checked each terminal and when. It also advises allowing repairs only by authorized personnel whose visit is expected, and contacting the terminal supplier or merchant bank promptly when something looks suspicious. This is established guidance, not an announcement of a new October deadline.
Make the reference useful at the counter
For a practical store procedure, give each checkout location an unambiguous name. A note saying “front register checked” is difficult to interpret if the store has moved equipment between counters. Record the device identifier alongside its assigned location, and keep authorized replacement or service records with the reference.
Decide who updates that record after a legitimate equipment change. Otherwise, a careful employee may compare today’s approved installation with an obsolete picture and receive conflicting instructions. Keep the reference accessible to the staff responsible for the check without including customer card details or login credentials.
Practice the handoff before a busy shift
Consider this illustrative exercise: an employee notices a cable that differs from the reference, while a visitor says they have come to replace the terminal. The employee should be able to identify the manager responsible for verification and locate the supplier’s established contact details. A badge or an unexpected caller’s phone number should not be the entire verification process.
Write down who can take a questioned device out of service, arrange an approved alternative checkout method and authorize its return. Staff should not improvise repairs or attempt to investigate a suspected skimmer themselves. Preserve the observation and follow the supplier’s incident instructions. The same need for a clear handoff applies when the store’s internet connection fails.
Keep the checklist in proportion
A completed inspection record does not establish PCI DSS compliance or prove that a device is secure. The Council’s compliance-validation FAQ directs merchants to their acquirer or payment brand for the applicable reporting requirements. Confirm the required inspection process and frequency for the actual payment environment. Use the store procedure to make that process workable, then review whether staff can carry it out and resolve exceptions.