GRC International Group PLC announced that its IT Governance business is now providing Payment Card Industry (PCI) Qualified Security Assessor (QSA) services in the USA. The business has been authorised to operate in the US and now appears on the PCI Security Standards Council (PCI SSC) website. PCI SSC is a global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments worldwide.

All businesses that accept payment cards are vulnerable to hackers trying to steal financial information and commit identity fraud. The Payment Card Industry Data Security Standard (PCI DSS) introduced by the PCI SSC, exists to ensure that businesses process credit and debit card payments effectively to protect cardholder data. IT Governance's new PCI QSA licence means that the business can now extend its Qualified Security Adviser services to the US.

It can undertake security audits on organizations that process payment cards and certify that they are compliant with the PCI DSS. This investment is one of a number that are accelerating the growth of the Group's US business, one of GRC's medium-term strategic priorities.