1. Home
  2. Services
  3. SWIFT CSCF assessment

SWIFT CSCF assessments for banks in the GCC and India.

I've run the full SWIFT Customer Security Programme lifecycle for eight financial institutions, from architecture scoping and control interviews to validation and attestation support.

SWIFT CSCF engagements
8
Countries
4
Attestation cycle
Annual

What I do

Independent assessment, done properly.

Architecture type and scope

Confirm your architecture type (A1 to A4, or B) and define the secure zone, connected components and operator PCs, so the right controls are assessed.

Independent assessment

Assessment of every mandatory control and the advisory controls you choose to attest to, backed by interviews, evidence review and testing.

Gap analysis and remediation

A clear view of non-compliant controls before the attestation window, with a prioritised plan your infrastructure and security teams can act on.

Attestation support

An assessment report and evidence mapping that support your annual attestation in SWIFT's KYC Security Attestation application.

CSCF version changes

SWIFT updates the framework every year. I help you plan for controls that are changing or moving from advisory to mandatory.

Standardised methodology

A repeatable review and validation approach, so year-on-year assessments are consistent and quicker to complete.

How an assessment runs

From kick-off to attestation.

  1. Kick-off and architecture review

    Confirm the architecture type, in-scope components and the CSCF version you are attesting against.

  2. Control walkthroughs

    Interview the owners of each control and understand how it operates in practice, not just on paper.

  3. Evidence validation

    Review configurations, logs and records, and test controls where evidence alone is not enough.

  4. Report and remediation

    Document compliance status per control and agree fixes for any gaps before attestation.

  5. Attestation

    Support your team in submitting an accurate attestation in the KYC-SA application.

Where

SWIFT CSCF work across four countries.

  • United Arab Emirates4
  • Oman2
  • Bahrain1
  • India1

Number of SWIFT CSCF client engagements per country. Client names stay confidential.

FAQ

SWIFT CSP questions I hear most.

Is an independent assessment mandatory for SWIFT CSCF?

Yes. SWIFT requires your attestation to be supported by an independent assessment. It can be carried out by an independent internal function, such as internal audit, or by an external assessor.

When is the SWIFT attestation deadline?

Users attest every year against the current CSCF version. The window opens in July and closes on 31 December. Starting the assessment early leaves time to fix gaps before you attest.

How do I know my architecture type?

It depends on which SWIFT components you host yourself and which a provider hosts for you, for example whether you run your own messaging and communication interfaces or connect through a service bureau or a cloud connector. The type determines which controls apply, so it is the first thing to confirm.

What happens if we are not compliant?

Your attestation status can be shared with your counterparties through the KYC-SA application, and SWIFT can report users who fail to attest or who are non-compliant to their supervisors. An honest attestation with a remediation plan is far better than a late or inaccurate one.

Next step

Preparing for this year's attestation?

Tell me your architecture type and your timeline. I'll tell you honestly what the assessment involves.