Skip to content

Global — Banking

SWIFT Customer Security Programme (CSP) Assessment

Independent assessment against the SWIFT Customer Security Controls Framework, supporting the annual attestation every SWIFT user is required to submit.

The obligation

SWIFT requires every user of its messaging services to attest annually against the Customer Security Controls Framework, and that attestation must be supported by an independent assessment — either by a qualified internal function that is independent of the SWIFT operating environment, or by an external assessor. Self-attestation without independent assessment is no longer sufficient.

The framework is revised periodically and controls that were advisory in one version become mandatory in a later one. Confirm the version and control set applicable to your attestation cycle before scoping — we do this at the start of every engagement.

What we assess

The framework is built around three overarching objectives — secure your environment, know and limit access, and detect and respond — supported by a set of mandatory and advisory controls. Assessment covers the SWIFT-related infrastructure, the operators who use it, and the surrounding controls that protect it.

  • Definition of the SWIFT secure zone and its architecture type, which determines which controls apply.
  • Segregation of the SWIFT environment from the general enterprise network.
  • Operating system, application and database hardening within the secure zone.
  • Multi-factor authentication and privileged access management for operators and administrators.
  • Physical security over the SWIFT infrastructure.
  • Transaction integrity controls and detection of anomalous message flows.
  • Logging, monitoring and the ability to detect and respond to intrusion.
  • Security awareness for operators and incident response readiness.

Assessing the secure zone

External network Perimeter and exposed services Web, API & mobile OWASP-aligned, with manual logic testing Internal network Lateral movement and privilege escalation Cloud configuration Identity, exposure, storage and logging
Which controls apply depends on your architecture type — we confirm it before testing.

Architecture type matters

Which controls apply to you depends on your architecture type — whether you operate your own messaging interface, use a service bureau, or connect through a group hub. Getting the architecture classification wrong invalidates the assessment. We confirm and document it before testing begins.

How the engagement runs

  1. 1

    Version and architecture confirmation

    Confirm the applicable framework version and your architecture type, which together set the control set.

  2. 2

    Secure zone definition

    Document the boundary of the SWIFT environment and the components inside it.

  3. 3

    Control testing

    Test each applicable mandatory and advisory control with evidence.

  4. 4

    Gap identification

    Report non-compliant controls with the specific gap and closure requirement.

  5. 5

    Remediation support

    Advise on remediation approach ahead of the attestation deadline.

  6. 6

    Assessment report

    Issue the independent assessment report supporting your attestation submission.

What you receive

Documented architecture type classification and secure zone definition
Control-by-control assessment against the applicable CSCF version
Independent assessment report supporting the attestation
Gap register with remediation requirements and effort indication
Advice on compliance sequencing ahead of the submission deadline
Retest of remediated controls where time permits before attestation

Frequently asked questions

Early enough that identified gaps can be remediated before your attestation submission deadline. Leaving the assessment until the final weeks means discovering non-compliance with no time to fix it, which forces you either to attest as non-compliant or to submit late. Three to four months ahead of the deadline is a sensible target.

Yes, provided it is genuinely independent of the SWIFT operating environment and has the required competence. Many institutions use internal audit for this and engage an external assessor periodically for additional assurance. Confirm the current independence and competence expectations against SWIFT's published requirements for your attestation cycle.

Attesting honestly as non-compliant against specific controls, with a remediation plan, is a materially better position than attesting compliant without support. Non-compliance is visible to your counterparties through the KYC-SA platform and may affect correspondent relationships, but a false attestation is a considerably more serious problem.

Related services

Not sure this is the framework that binds you?

Six questions, ninety seconds, runs in your browser. It will tell you which frameworks apply and why.

Request a proposal
Top