Limit the card number to ten characters

Error BR-51 EN 16931

In accordance with card payments security standards an invoice should never include a full card primary account number (BT-87). At the moment PCI Security Standards Council has defined that the first 6 digits and last 4 digits are the maximum number of digits to be shown.

Mandatory rule: As long as it is violated, the invoice is invalid and will be rejected by validators.
What is wrong

The normalized value of ID contains more than ten characters. An invoice must not contain a full card number; under the stated security guidance, no more than ten digits should be shown.

What the rule means

The limit protects the card number by preventing the full primary account number from appearing on the invoice.

Affected fields BT-87
Please limit the card identifier to no more than ten characters

The card identifier in the invoice is longer than ten characters. Shorten the identifier so that the invoice does not contain a full card number.

What to do
  1. Locate the card identifier in ApplicableTradeSettlementFinancialCard/ID.
  2. Limit its normalized value to no more than ten characters.
  3. Generate the invoice again and validate it again.
What it looks like
✗ Triggers the message
<ram:ApplicableTradeSettlementFinancialCard>
  <ram:ID>123456789012</ram:ID>
</ram:ApplicableTradeSettlementFinancialCard>
✓ Correct
<ram:ApplicableTradeSettlementFinancialCard>
  <ram:ID>1234567890</ram:ID>
</ram:ApplicableTradeSettlementFinancialCard>
Technical details

The test applies normalize-space to ID and checks that the resulting string length is no greater than ten.

Where the rule applies

The rule applies to the card identifier ID within ApplicableTradeSettlementFinancialCard.

Context (rule/@context)
//ram:ApplicableTradeSettlementFinancialCard
Test expression (assert/@test)
string-length(normalize-space(ram:ID)) <= 10