Certificate of Compliance


Assessed Entity:National Commercial Bank Jamaica ltd ( NCB)

Contact Name: Mr. Septimus C. Blake & Mr. Howard D. Gordon

Job Title: Chief Operating Officer & Senior General Manager, Group Operations & Technology Division

Email: BlakeSC@jncb.com &

Certificate Number:PAL-PCIDSS3.2-JM-2017-001

Date Certified: 30-Sept-2017

Valid Till:29-Sept-2018

Version: 3.2 (PCI-DSS 3.2)

Scope: IT Systems, Networks, Core Applications, People and Processes which is used to support Acquiring and issuing services ,within the scope specified in the Attestation Of Compliance (AOC) and Report On Compliance (ROC).

Registered Address: 32 Trafalgar Rd, Kingston 10, Jamaica W.I

QSA Company:Paladion Networks Private Limited.

QSA Name:Mr. Saju Thomas Paul

Certificate Terms & Conditions

1. This certificate doesn’t guarantee the client’s ability to ensure confidentiality, integrity and/or availability of card holder data. Paladion doesn’t accept any financial and or legal liability on the client’s and/or any third party’s part due to breach of security controls at the Client’s premise and subsequent loss of card holder data.

2. Our opinion on compliance and subsequent issuing of this certificate is based on the documentations and other information made available to us and data collected through physical inspection of the systems, network and applications within the specified scope. Rejection of any conclusions on the client’s ability to securely receive, process, transmit, store and/or destroy Card Holder Information in soft and/or hard form in the future, is subject to the risk that the validity of such conclusions may be altered because of lapses in maintenance of the CI-DSS compliance, changes to people, infrastructure, systems, network and application.