Architecture type and scope
Confirm your architecture type (A1 to A4, or B) and define the secure zone, connected components and operator PCs, so the right controls are assessed.
I've run the full SWIFT Customer Security Programme lifecycle for eight financial institutions, from architecture scoping and control interviews to validation and attestation support.
What I do
Confirm your architecture type (A1 to A4, or B) and define the secure zone, connected components and operator PCs, so the right controls are assessed.
Assessment of every mandatory control and the advisory controls you choose to attest to, backed by interviews, evidence review and testing.
A clear view of non-compliant controls before the attestation window, with a prioritised plan your infrastructure and security teams can act on.
An assessment report and evidence mapping that support your annual attestation in SWIFT's KYC Security Attestation application.
SWIFT updates the framework every year. I help you plan for controls that are changing or moving from advisory to mandatory.
A repeatable review and validation approach, so year-on-year assessments are consistent and quicker to complete.
How an assessment runs
Confirm the architecture type, in-scope components and the CSCF version you are attesting against.
Interview the owners of each control and understand how it operates in practice, not just on paper.
Review configurations, logs and records, and test controls where evidence alone is not enough.
Document compliance status per control and agree fixes for any gaps before attestation.
Support your team in submitting an accurate attestation in the KYC-SA application.
Where
Number of SWIFT CSCF client engagements per country. Client names stay confidential.
FAQ
Yes. SWIFT requires your attestation to be supported by an independent assessment. It can be carried out by an independent internal function, such as internal audit, or by an external assessor.
Users attest every year against the current CSCF version. The window opens in July and closes on 31 December. Starting the assessment early leaves time to fix gaps before you attest.
It depends on which SWIFT components you host yourself and which a provider hosts for you, for example whether you run your own messaging and communication interfaces or connect through a service bureau or a cloud connector. The type determines which controls apply, so it is the first thing to confirm.
Your attestation status can be shared with your counterparties through the KYC-SA application, and SWIFT can report users who fail to attest or who are non-compliant to their supervisors. An honest attestation with a remediation plan is far better than a late or inaccurate one.
Next step
Tell me your architecture type and your timeline. I'll tell you honestly what the assessment involves.