Don’t do SECURITY. Do business SECURELY.

First SWIFT Customer Security Attestation deadline

SWIFT users must attest compliance with the Customer Security Controls Framework mandatory controls for the first time.

Today is the deadline for all SWIFT users to submit their first self-attestation against the SWIFT Customer Security Controls Framework, introduced under the Customer Security Programme (CSP) following high-profile attacks on SWIFT users.

Key points

  • The framework sets mandatory and advisory security controls for the local SWIFT environment.
  • Controls cover environment segregation, privileged access, patching, anomaly detection and incident response.
  • Attestations are submitted through the KYC Security Attestation application.
  • Counterparties can view attestation status to inform their risk decisions.
  • Non-attesting users may be reported to their supervisors.

UK banks, corporates and service bureaux connected to SWIFT must now maintain an annual attestation cycle. Expect counterparties to request attestation details, and plan for the framework to evolve each year.

Source: Customer Security Programme security attestation (Swift)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights