Skip to main content

Retail & telecommunications

Sustained compliance of a point-of-sale estate

Verify that systems already certified as compliant have stayed so through version upgrades, migrations and changes of supplier.

  • Sustained compliance
  • Multi-site estate
  • Archiving
  • Periodic review
Checkout points aligned in a retail space, evoking a multi-site point-of-sale estate

Context

Several organisations running point-of-sale systems across multi-site estates, already covered by vendor attestations of compliance. In the meantime the software had gone through version upgrades, local configurations had accumulated, suppliers had changed, and flows towards the ERP had been added.

The challenge

An attestation covers one precise version of a piece of software, at one moment. It says nothing about the estate as it runs three years later. The point was to measure the drift between what was attested and what is operated, then install a periodic review so that the drift does not build up again.

What AXENEO did

The work we carried out

  1. 01

    Diagnosis of the estate

    • Consistency check between the versions deployed and the versions attested
    • Analysis of the customisations and of their bearing on the requirements
    • Review of the exchange flows with the ERP and the other applications
    • Assessment of the archiving policy and of the restore procedures
  2. 02

    Gaps and remediation

    • Gap analysis with criticality rating
    • Remediation plans gap by gap, with owners and deadlines
    • Formalisation of the operating procedures that were missing
  3. 03

    Audit preparation

    • Assembly of the supporting documents expected
    • Preparation of the teams for questions from the authorities or the auditor
    • A periodic compliance review put in place

Results

What the set-up changed

Results are described qualitatively. We do not publish figures we would not be able to document.

  • A picture of the estate as it really is, version by version, set against the attestations held.

  • The drifts identified and rated: version upgrades never re-attested, local configurations, flows added downstream of recording.

  • An archiving policy verified across the regulatory retention period, with the restore procedure tested.

  • A periodic compliance review written into the operating calendar, distinct from the vendor's attestation.

Contact

A comparable situation?

We can walk you through the approach taken, the difficulties met along the way, and what we would do differently.