I agree with your comments regarding PCI compliance, but this doesn't change anything relative to my original request.
If the client clicks the "ON" box, we are still responsible for PCI compliance whether the box was set on by default or by the client.