Your so mis informed about what Security Metrics actually does,. Security Metrics doesn't come up with the vulnerabilities that companies need to be flagged for its determined by PCI (Payment Card Industry).
Some members are more upto date as to PCI-DSS than people in your organisation. If you know who should and who should not have it then its your job to inform the bank they have it wrong - oh but then you would not get any money for that