Swift's CSP Assessment
Due for your Swift attestation? Independent assessment is mandatory, and what you're assessed against depends on your architecture type.
0
0 +
0 +
What is the Swift Customer Security Programme?
The Customer Security Programme (CSP) is Swift's mandatory security initiative for institutions connected to the Swift network. At its centre is the Customer Security Controls Framework (CSCF), which sets the mandatory and advisory controls a Swift user has to implement across its Swift infrastructure.
Each year, users attest to their level of compliance against the applicable controls through the KYC-SA application, providing remediation dates for any control not yet met. The effectiveness of those controls has to be validated through an independent assessment.
Who needs a Swift CSP assessment?
Every institution connected to the Swift network falls under the CSP, including banks, credit unions, payment processors and corporate treasuries. Which controls apply depends on your architecture type, from A1 through A4 and B, which reflects how much of the Swift infrastructure you own and operate yourself.
Independent assessment can be carried out internally, by a risk, compliance or internal audit function with sufficient separation from the teams running your Swift environment, or externally by an independent assessor. Where that separation is difficult to demonstrate, or the capacity isn't there, an external assessment is the practical route.
Steps to validate your Swift compliance posture
SWIFT CSP Readiness
The readiness review identifies your architecture type, determines which CSCF controls apply to your operating environment, surfaces any gaps, and sets out practical remediation steps to address them before the formal assessment begins.
SWIFT CSP Independent Assessment
The independent assessment verifies that mandatory controls are implemented against CSCF requirements across your policies, processes and business practices, recording each as satisfied, partially satisfied or not satisfied. Through stakeholder meetings, documentation reviews, site visits and operational reviews, you come away with the documentation to support your attestation.
Remediation plan
When gaps surface, we work alongside your team to close them and hold the control level across your environment through to the next attestation cycle.
Speak to an expert
Attestation runs on an annual cycle, so the useful question is how much runway sits between now and your submission date. Talk to an advisor about where your controls stand and what the assessment will need.
Dublin: +353 01 293 4027
London: +44 20 3397 3414
Sofia: +359 2 491 0110
Cape Town: +27 08 606 25673
Johannesburg: +27 08 606 25673

