Advisory

Swift CSP Assessments

Independent Swift CSP assessments that support your yearly attestation, with clear results for each control that applies to you.

An independent check behind every attestation.

Every Swift user must attest each year to how well it meets the mandatory controls in the Customer Security Controls Framework (CSCF). Since 2021, that attestation must be backed by an independent assessment. Vectra performs that assessment, confirming your scope and architecture type, testing each control that applies and documenting the evidence you need to attest. Our team holds the specialist certifications this work needs, and we have run Swift CSP engagements in Australia and overseas.

Swift CSP Assessments

What the independent assessment covers.

Swift calls this a Community Standard Assessment. It is an assessment, not an audit, and it must be done before you attest.

The work checks that the controls you attest to are in place, for the architecture you run.

  • Scope and architecture type

    Confirm which components and data flows are in scope. Your architecture type decides which controls apply.

  • The current controls version

    Assess against the CSCF version that applies on your attestation date.

  • Mandatory and advisory controls

    Test every mandatory control that applies, and review the advisory ones so you can plan ahead.

  • Evidence you can stand behind

    Base each result on settings, records and interviews, not on controls that are only planned.

When you need more than an assessment.

Some users need a higher level of assurance for a regulator, a parent company or their own board. For them we run a Swift CSP audit, with a controls report under a recognised standard such as ISAE 3000.

From scope to attestation.

We plan the work around your attestation window, so there is time to fix gaps before you attest.

  1. Step 1: Plan

    Agree the timing, the CSCF version that applies on your attestation date and who will sign off.

  2. Step 2: Confirm scope

    Map your Swift components, operator PCs, connectors and back-office data flows, and confirm your architecture type.

  3. Step 3: Collect evidence

    Review settings, policies, records and logs, and interview the people who run your Swift environment.

  4. Step 4: Test controls

    Check each control that applies against the CSCF, and record whether it is in place and working.

  5. Step 5: Report

    Give you the results you need to complete your Security Attestation in the KYC-SA application.

  6. Step 6: Remediate

    Help you close gaps before you attest, and plan for changes in the next version of the controls.

Swift CSP services.

Readiness assessment

A detailed assessment of your Swift CSP controls ahead of the formal work, so you know where you stand before you attest.

Independent assessment

The independent assessment Swift requires to support your attestation, performed by assessors outside your organisation.

Swift CSP audit

We confirm your controls line up with the Swift CSP guidelines, with a controls report under a recognised standard such as ISAE 3000.

Scope and architecture review

A check of your Swift footprint and data flows, so you attest against the right architecture type and controls.

Technical testing

Penetration tests and vulnerability scans of the systems in your Swift environment.

Remediation support

Help to fix the gaps we find and to prepare for controls that change from year to year.

What you have at the end.

  • An independent assessment that supports your yearly attestation.

  • A clear result for each control that applies to your architecture type.

  • A ranked list of gaps, with the fixes needed.

  • Evidence you can show regulators, auditors and your board.

  • An early view of changes in the next version of the controls.

Swift CSP questions, answered.

Who has to attest?

Every Swift user must submit a Security Attestation in the KYC-SA application, confirming its compliance with the mandatory controls. Users must re-attest at least once a year, and new users attest before they go live on the Swift network.

Can our internal audit team run the assessment?

Swift allows the assessment to be internal or external. An internal team, such as internal audit, must be independent of the people who run the Swift controls. An external assessor can help where your team lacks the time, the independence or the specialist skills.

What does Swift expect of an external assessor?

External assessors need experience assessing against an industry standard, such as PCI DSS, ISO 27002 or the NIST Cybersecurity Framework. The lead assessor must hold at least one relevant professional certification.

Is an assessment the same as an audit?

No. Swift requires an assessment, which involves less time and cost than an audit. An audit gives a higher level of assurance and a formal controls report. We offer both.

Which version of the controls do we assess against?

The version that applies on your attestation date. Swift publishes a new version each year. A new version can add controls or make an advisory control mandatory, so we check what has changed before we start.

Start with a conversation.

Speak to us about your cyber governance and compliance requirements.