About this Framework
The SWIFT Customer Security Programme (CSP) defines mandatory security controls (16 mandatory, 17 advisory) that all SWIFT users must attest to annually through the Customer Security Controls Framework (CSCF). Following the 2016 Bangladesh Bank heist ($81M stolen via fraudulent SWIFT messages), the CSP was established to secure SWIFT infrastructure and detect fraudulent transactions. Independent third-party assessment is now required for all mandatory controls, with attestation results visible to correspondent banks.
Key Control Domains
Restrict Internet Access
Separate Critical Systems
Reduce Attack Surface
Prevent Credential Compromise
Manage Identities & Access Privileges
Detect Anomalous Activity
Share Information & Prepare to Respond
Manage Vulnerabilities
Implement Physical Security
Who Needs This?
- Banks and financial institutions on the SWIFT network
- Correspondent banks and clearing institutions
- Financial market infrastructures (exchanges, CSDs, CCPs)
- Service bureaus connecting clients to the SWIFT network
Compliance Benefits
- Mandatory SWIFT network participation compliance
- Reduces financial fraud via compromised SWIFT credentials
- Annual attestation evidences security posture to correspondent banks
- Framework for systematic financial messaging security assurance
Official Reference
SWIFT Customer Security Programme
https://www.swift.com/myswift/customer-security-programme-csp
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/swift-customer-security-programme-csp