# Payment-data AI input cases

Classify the synthetic payment patterns, then compare the intended handling with an actual authorised control observation.

Stripe’s published test number plus invented supporting values. No live cardholder, payment, PCI assessment or product test result is represented.

Source: https://aona.ai/resources/guides/pci-dss-cardholder-data-ai-prompts/
Sources checked: 2026-09-21

## Keep the distinction visible

### Test PAN pattern

4242 4242 4242 4242

Note: Stripe-published nonproduction card number.

### Test CVV pattern

123

Note: Invented verification value for the exercise.

### Reduced context

A generic payment question

Note: No payment credentials required.

| Input case | Data distinction | Action for this exercise |
| --- | --- | --- |
| 4242 4242 4242 4242; Ada Example; 12/34 | Published test PAN with invented associated fields, representing cardholder-data structure. | Check the proposed PAN policy on the selected input path; no observed result is asserted. |
| Test verification code 123, after a fictional purchase | Synthetic representation of sensitive authentication data. | Expected merchant policy: do not retain the code in an AI support record after authorisation. |
| Test verification code 123 without a PAN | A code’s category does not depend on a PAN being in the same text. | Check the scoped policy and context; do not treat the separated code as harmless by assumption. |
| Displayed card **** **** **** 4242 | A masked display does not establish the underlying transmitted value. | Inspect the actual payload and retained content in the authorised test. |
| “Explain a generic payment error.” | No account or authentication details are required. | Use as the reduced-context comparison case. |

## Review checklist

- [ ] Classify every payment field
  Separate PAN/cardholder data from CVV, track and PIN information; check attachments as well as the prompt.
- [ ] Remove unnecessary account data
  Use a generic error, invented example or approved reference when the task does not need payment credentials.
- [ ] Review the full service path
  Ask the responsible PCI owner about processing, retention, recipients and assessment scope before using real account data.

## Included example files

- pci-ai-payment-input-cases.md
- pci-ai-payment-input-cases.csv
- pci-synthetic-input-patterns.txt

## Source references

- PCI SSC: Payment security glossary: https://www.pcisecuritystandards.org/glossary/ (2026-09-21)
- PCI SSC: Can card verification codes be stored?: https://www.pcisecuritystandards.org/faq/articles/Frequently_Asked_Question/Can-card-verification-codes-values-be-stored-for-card-on-file-or-recurring-transactions/ (2026-09-21)
- Stripe: Test card numbers: https://docs.stripe.com/testing (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
