Global — Banking
SWIFT Customer Security Programme (CSP) Assessment
Independent assessment against the SWIFT Customer Security Controls Framework, supporting the annual attestation every SWIFT user is required to submit.
The obligation
SWIFT requires every user of its messaging services to attest annually against the Customer Security Controls Framework, and that attestation must be supported by an independent assessment — either by a qualified internal function that is independent of the SWIFT operating environment, or by an external assessor. Self-attestation without independent assessment is no longer sufficient.
The framework is revised periodically and controls that were advisory in one version become mandatory in a later one. Confirm the version and control set applicable to your attestation cycle before scoping — we do this at the start of every engagement.
What we assess
The framework is built around three overarching objectives — secure your environment, know and limit access, and detect and respond — supported by a set of mandatory and advisory controls. Assessment covers the SWIFT-related infrastructure, the operators who use it, and the surrounding controls that protect it.
- Definition of the SWIFT secure zone and its architecture type, which determines which controls apply.
- Segregation of the SWIFT environment from the general enterprise network.
- Operating system, application and database hardening within the secure zone.
- Multi-factor authentication and privileged access management for operators and administrators.
- Physical security over the SWIFT infrastructure.
- Transaction integrity controls and detection of anomalous message flows.
- Logging, monitoring and the ability to detect and respond to intrusion.
- Security awareness for operators and incident response readiness.
Assessing the secure zone
Architecture type matters
Which controls apply to you depends on your architecture type — whether you operate your own messaging interface, use a service bureau, or connect through a group hub. Getting the architecture classification wrong invalidates the assessment. We confirm and document it before testing begins.
How the engagement runs
-
1
Version and architecture confirmation
Confirm the applicable framework version and your architecture type, which together set the control set.
-
2
Secure zone definition
Document the boundary of the SWIFT environment and the components inside it.
-
3
Control testing
Test each applicable mandatory and advisory control with evidence.
-
4
Gap identification
Report non-compliant controls with the specific gap and closure requirement.
-
5
Remediation support
Advise on remediation approach ahead of the attestation deadline.
-
6
Assessment report
Issue the independent assessment report supporting your attestation submission.
What you receive
Frequently asked questions
Related services
Not sure this is the framework that binds you?
Six questions, ninety seconds, runs in your browser. It will tell you which frameworks apply and why.
Request a proposal