
- 01CSCF was created in response to the 2016 Bangladesh Bank heist. Every SWIFT participant must self-attest annually; independent assessment is becoming the norm and is mandatory for the highest-risk participants.
- 02Architecture types A1–B drive applicability. A1 (full SWIFT footprint owned by the participant) carries the full control set; B (no SWIFT footprint, all access through a service bureau) carries the smallest. Get the architecture type right and the rest of the program follows.
- 03Highest-impact controls: restricted SWIFT environment with segregated networks and jump hosts, OS-level privileged account control, MFA on operator interfaces, vulnerability scanning of all SWIFT-related infrastructure, and 12-month-minimum logging.
- 04Independent assessment validates actual implementation, not attestation language. Self-attestation without engineering evidence is the path to a credibility problem with counterparties — and counterparties can see your attestation.
The SWIFT Customer Security Controls Framework (CSCF) was created in response to the 2016 Bangladesh Bank heist and has hardened the global financial messaging environment. Every SWIFT participant must self-attest annually, with independent assessment becoming the norm.
The architecture types and the controls they trigger
Architecture types A1 through B drive the applicability of mandatory controls. Architecture A1 (full SWIFT footprint owned by the participant) carries the full control set; B (no SWIFT footprint, all access through a service bureau) carries the smallest. Get the architecture type right and the rest of the program is straightforward.
Controls with the most operational impact
- 01Restricted SWIFT environment (segregated networks, jump hosts)
- 02Operating system privileged account control
- 03Multi-factor authentication on operator interfaces
- 04Vulnerability scanning of all SWIFT-related infrastructure
- 05Logging and monitoring with 12-month retention minimum
Independent assessment is the new floor
SWIFT now expects independent assessment for the highest-risk participants. Plan for it: the assessor will validate the actual implementation, not just the attestation language. Self-attestation without underlying engineering evidence is the path to a credibility problem with counterparties.


