RXDecision brief
Scope security and compliance review to the proposed program
Security and compliance evidence should match the services, systems, data, entities, and regions involved in the proposed Shopify reward card program.
In this brief01 What this choice changes02 Questions for the Shopify program team03 Evidence to collect
01
What this choice changes
A certification label is only one input. Review the data flow, access model, subprocessors, incident responsibilities, retention, customer communications, issuer oversight, program terms, and the boundaries of every report or attestation.
02
Questions for the Shopify program team
Resolve these questions against the actual offer, customer journey, and operating model before comparing providers.
- What Shopify and recipient data enters each system?
- Which entities store, transmit, or decide with that data?
- What evidence covers the services in scope?
- How are incidents, access changes, and vendor risks handled?
03
Evidence to collect
Ask for evidence that can be reviewed by commercial, operations, support, security, and legal stakeholders.
- Current data-flow and architecture diagrams
- Scoped independent assurance evidence
- Incident and vulnerability processes
- Subprocessor and retention inventory