SWIFT CSP

SWIFT CSP Remote / Onsite Assessment Service

What is SWIFT Customer Security Program?

The SWIFT Customer Security Programme (CSP) is a mandatory initiative that helps financial institutions protect their SWIFT footprint against cyber threats with the primary objective of implementing practices to safeguard against, detect, and share information pertaining to financial service cybercrime.  

SWIFT manages the Customer Security Control Framework (CSCF), which establishes the mandatory and advisory security requirements that all SWIFT users and Bank Identifier Code (BIC) holders must adhere to. In addition, all applicable entities are required to submit Security Attestations through the SWIFT KYC Security Attestation (KYC-SA) Application to demonstrate compliance with the CSCF.

The SWIFT CSP includes an assessor certification framework for external assessment providers. Under this framework, individual assessors may obtain certification by successfully meeting the applicable certification requirements and examinations established by SWIFT.

AGES provides independent SWIFT CSP assessment services through assessors who have attained the relevant SWIFT CSP Assessor Certification. (SWIFT Site)

Certified assessors are required to demonstrate competency against defined assessment criteria, which are periodically updated to reflect changes to the SWIFT CSP, SWIFT services and products, industry practices, and the evolving cybersecurity landscape.

When a SWIFT user engages an assessment provider with a SWIFT CSP Certified Assessor to perform an independent assessment, this capability may be identified within the SWIFT KYC Security Attestation (KYC-SA) application in accordance with SWIFT’s published processes. (SWIFT Site)

Introduction of Independent Assessment Framework (IAF)

The SWIFT IAF requires eligible financial institutions to undergo an annual independent assessment of their compliance with the SWIFT Customer Security Controls Framework (CSCF) before submitting their Security Attestation.

Assessments must be conducted by an independent internal function or a qualified external assessment provider, with supporting evidence retained for 5 years.

The IAF evaluates compliance across the three pillars of the SWIFT CSP:

  • Secure Your Environment
  • Know and Limit Access
  • Detect and Respond

Compliance may be demonstrated through:

  • Community Standard Assessment
  • SWIFT Mandated Assessment

The assessment results submitted through the SWIFT KYC Security Attestation (KYC-SA) application.

The core principle of the IAF is to ensure that SWIFT CSP assessments are conducted independently by qualified assessors who possess professional certifications.

    Risk-Based Approach Assessments

    AGES provides independent SWIFT CSP assessment services using a risk-based, customer-focused methodology designed to evaluate compliance with the SWIFT CSCF. Rather than relying solely on a checklist approach, each assessment is tailored to the organisation’s SWIFT environment, security controls, and operational risks, enabling a more effective and practical evaluation.

    Drawing on the experience of conducting over 3,000 security assessments across multiple assurance programmes, AGES applies proven practices to help organisations prepare for and complete their independent SWIFT CSP assessments.

      AGES SWIFT CSP Assessment Services

      AGES provides independent SWIFT CSP assessment services, delivered either remotely or onsite to meet client requirements.

      The assessment encompasses:

      • Assessment scoping
      • Review of mandatory and advisory security controls
      • Sampling of technical controls
      • Identification of non-conformities
      • Practical recommendations and technical guidance to support compliance

      Assessments are conducted by experienced AGES assessors with relevant industry expertise and applicable SWIFT CSP Assessor Certifications.

      Leveraging experience from more than 500 remote assessments, AGES applies a structured remote assessment methodology designed to effectively evaluate compliance while providing flexibility for organisations across different locations.

      To preserve assessor independence, remediation and independent assessment engagements for the same client are delivered by separate teams, in line with the SWIFT IAF.