The payments disclosure set, and who asks for what
Payments companies field requests from several directions at once, and each direction wants a different slice. Sponsor banks and acquirers want the outsourcing pack: SOC 2, BCP and DR evidence, cyber insurance, information security and vendor management policies, AML/KYC and sanctions screening summaries. Schemes and larger merchants concentrate on card-data scope: the PCI DSS Attestation of Compliance, a ROC summary or SAQ as applicable, network segmentation evidence and the current penetration test. Partner PSPs and platforms usually sit between the two and want the DPA, subprocessor list and a security overview they can attach to their own review.
Mapping documents to audiences up front is what makes a portal useful rather than another folder. Public layer: certificate, DPA, subprocessor list, security overview, redacted pen test summary. NDA layer: AOC and ROC content, full pen test report, regulator correspondence, detailed BCP test results.