DFD — Card Authorisation (PCI DSS)
Level-2 decomposition of card capture, tokenisation, authorisation and settlement, with the PCI cardholder data environment drawn as a trust zone so the 9 flows that enter or leave CDE scope are enumerated.
Make it your own.
title "Take payment — decomposition of process 3"
level 2
entity Cardholder
entity "Card scheme"
entity "Acquiring bank"
entity "Fraud bureau"
process 3.1 "Capture checkout"
process 3.2 "Tokenise PAN"
process 3.3 "Score fraud risk"
process 3.4 "Authorise payment"
process 3.5 "Settle batch"
process 3.6 "Reconcile payout"
store D1 "Order book"
store D2 "Token vault"
store D3 "Auth log (PCI)"
store D4 "Settlement file"
boundary "Public internet" { Cardholder }
boundary "PCI cardholder data environment" { 3.2, 3.4, D2, D3 }
boundary "Scheme + banking network" { "Card scheme", "Acquiring bank" }
Cardholder -> 3.1 : "basket + card details"
3.1 -> D1 : "order (4 200/day)"
3.1 -> 3.2 : "PAN + expiry"
3.2 -> D2 : "token / PAN map"
D2 -> 3.4 : "detokenised PAN"
3.1 -> 3.3 : "device + basket signals"
"Fraud bureau" -> 3.3 : "velocity blocklist"
3.3 -> 3.4 : "risk score 0..100"
3.4 -> "Card scheme" : "ISO 8583 0100"
"Card scheme" -> 3.4 : "0110 approval code"
3.4 -> D3 : "auth result + RRN"
3.4 -> Cardholder : "receipt"
D1 -> 3.5 : "order totals"
D3 -> 3.5 : "captured auths"
3.5 -> D4 : "nightly batch file"
3.5 -> "Acquiring bank" : "settlement batch"
D4 -> 3.6 : "expected totals"
"Acquiring bank" -> 3.6 : "payout advice"
3.6 -> D1 : "reconciled flag"