Role:
UX/UI Designer
Platform:
Web Application (SaaS)
Team Size:
3 SMs, 2 POs, 4 BAs
Overview
A B2B compliance platform redesign for Aperia, the leading BI/SaaS provider for finance, banking, and payments. The PCI Compliance Center helps merchants complete PCI-DSS certification, gives Aperia's internal team tools to manage that process at scale, and supports Approved Scanning Vendors (ASV) on the technical side — three distinct user groups on one platform.
Context & Problem
The legacy system was a dense, form-heavy admin portal with no design system: merchant records, compliance status (SAQ version, SAQ status, ASV compliance status, scan schedules) were all packed into unlabeled grids and long detail pages with no visual hierarchy.

This created friction for two different audiences at once:
The Approach
Worked within a cross-functional team of 3 SMs, 2 POs, and 4 BAs. Rather than redesigning each of the three sites in isolation, the process started by auditing the existing system end to end, then established a shared layout and accessibility pattern library before designing the three user-facing experiences on top of it — so Merchant, Admin, and ASV interfaces would stay visually and behaviorally consistent as the platform grew.
User Research & Analysis
Merchant
Aperia Admin (AS)
ASV
Goal
Get PCI compliant with minimal confusion
Keep the merchant portfolio compliant at scale
Run and report vulnerability scans
Old pain point
Didn't know which SAQ type applied to them; long, ungrouped form
Manually tracked and followed up with non-compliant merchants; couldn't adjust questionnaires without dev help
No structured workflow surfaced in the legacy system
Core need
A guided path from "who am I" to "I'm compliant"
Tools to configure questionnaires and run outreach without engineering
A clear scan-and-report flow tied to merchant compliance status



Design Solutions
Instead of asking merchants to already know their SAQ type, the flow asks a few plain questions about how they process cardholder data and determines the right questionnaire for them. From there, the questionnaire itself is broken into 12 clearly labeled sections with live progress tracking, tooltips on ambiguous requirements, bulk "answer all" actions for straightforward sections, and an explanation prompt when a merchant flags something as not yet compliant.


A dedicated step for merchants to register scan targets (IPs/domains), launch ASV scans, track each target's status, and move through review and attestation before final sign-off — turning a previously informal, email-driven step into a tracked in-product flow.



On the Aperia side, admins can build and publish new questionnaires directly — adding sections and questions, mapping them to product codes — without engineering involvement. A campaign tool lets the team schedule automated letter, call, and email reminders to non-compliant merchants, with live tracking of how much of the portfolio has been reached.


Results & Feedback
Note: I left Aperia some time ago and no longer have access to confirm exact figures — these are the directional outcomes the team observed at the time, not verified metrics.
The team reported that merchants completed compliance faster with the guided questionnaire flow, and that support call volume dropped as merchants found it easier to work through the questionnaire on their own rather than calling in for help understanding it.