Compliance
Advanced
50 minPlan an Internal Audit
Pro
Scope, resource, schedule, and risk-based test plan for an annual internal audit cycle.
Company brief
WovenCart
Retail · Global
Description
D2C apparel brand with 400 employees, peak-season traffic concentrated in November-December.
Analyst task
Quantify the PCI scope question for the next QSA and write the internal page that walks finance through what is and is not in PCI scope at WovenCart.
Systems
- Shopify Plus
- AWS (ECS, RDS)
- Marketing CDP
- Warehouse management system
Regulatory exposure
- PCI DSS
- CCPA / state privacy laws
- GDPR for EU customers
Top risks
- Peak-season DDoS
- Cardholder data leakage via marketing tooling
- Phishing of finance team during peak
- Open-source dependency compromise
Audit concerns
- PCI scope clarity (Shopify handling vs in-scope systems)
- Marketing CDP data flow documentation
Write your answer
Pro
Loading lab…