Back to Field Notes
Compliance & Regulation/Field Note

SWIFT CSCF — The Controls Banks Cannot Skip

CSCF is small, focused, and serious. Compliance is annual, attested, and visible to your counterparties.

Author

Hiroshi Tanaka

OT Security Lead

Published

January 19, 2026

Read

9 min

Share
AI-generated illustration of a power plant facility
AI-generated illustration of a power plant facility
Key Takeaways
  • 01CSCF was created in response to the 2016 Bangladesh Bank heist. Every SWIFT participant must self-attest annually; independent assessment is becoming the norm and is mandatory for the highest-risk participants.
  • 02Architecture types A1–B drive applicability. A1 (full SWIFT footprint owned by the participant) carries the full control set; B (no SWIFT footprint, all access through a service bureau) carries the smallest. Get the architecture type right and the rest of the program follows.
  • 03Highest-impact controls: restricted SWIFT environment with segregated networks and jump hosts, OS-level privileged account control, MFA on operator interfaces, vulnerability scanning of all SWIFT-related infrastructure, and 12-month-minimum logging.
  • 04Independent assessment validates actual implementation, not attestation language. Self-attestation without engineering evidence is the path to a credibility problem with counterparties — and counterparties can see your attestation.

The SWIFT Customer Security Controls Framework (CSCF) was created in response to the 2016 Bangladesh Bank heist and has hardened the global financial messaging environment. Every SWIFT participant must self-attest annually, with independent assessment becoming the norm.

The architecture types and the controls they trigger

Architecture types A1 through B drive the applicability of mandatory controls. Architecture A1 (full SWIFT footprint owned by the participant) carries the full control set; B (no SWIFT footprint, all access through a service bureau) carries the smallest. Get the architecture type right and the rest of the program is straightforward.

Controls with the most operational impact

  • 01Restricted SWIFT environment (segregated networks, jump hosts)
  • 02Operating system privileged account control
  • 03Multi-factor authentication on operator interfaces
  • 04Vulnerability scanning of all SWIFT-related infrastructure
  • 05Logging and monitoring with 12-month retention minimum

Independent assessment is the new floor

SWIFT now expects independent assessment for the highest-risk participants. Plan for it: the assessor will validate the actual implementation, not just the attestation language. Self-attestation without underlying engineering evidence is the path to a credibility problem with counterparties.

#SWIFT#Banking#Payments

/WRITTEN_BY

Hiroshi Tanaka

OT Security Lead · Alexa Cybersecurity