Swift Attestation Services

Practical support for Swift CSP & CSCF v2026 compliance

Advisory consultant lecturing at a conference

Clear scope, structured evidence and independent assessment support — helping you achieve Swift attestation with confidence and reduce delivery risk.

Swift's Customer Security Programme (CSP) requires organisations to implement the controls set out in the Customer Security Controls Framework (CSCF), complete an independent assessment where required and submit an annual security attestation via KYC Security Attestation (KYCSA).  For many organisations, particularly those operating across outsourced, hosted or group service models, the challenge is not only meeting the controls — but clearly demonstrating compliance through robust, well-organised evidence.  We support organisations with a practical, evidence-led approach to CSP — helping you confirm scope, prepare for CSCF v2026 changes and deliver a smooth, credible attestation process.

Understanding Swift CSP compliance

Three foundations shape every attestation cycle — who needs to comply, how independent assessment works and what happens when requirements are not met.

Who needs to comply?

CSP applies to all Swift users, including institutions with a Business Identifier Code (BIC) used solely to receive messages.

All users must submit an annual attestation via KYCSA between July and December, with new users required to attest before going live.

Independent assessment requirements

Most organisations must support their attestation with an independent assessment to confirm compliance with mandatory CSCF controls. This may be delivered by an appropriately independent internal function or an external provider.

Organisations with receive-only BICs may be eligible for self-attestation, provided all applicable mandatory controls are met.

Consequences of non-compliance

Failure to meet CSP requirements can lead to increased scrutiny and reputational risk. Swift may report organisations that:

  • Do not submit a valid attestation
  • Are not compliant with mandatory controls
  • Have not completed the required independent assessment
  • Rely on non-compliant service providers
  • Do not complete mandated external assessments where required

Non-compliance may also be made visible to regulators and counterparties.

What's changing in CSCF v2026?

CSCF v2026 reflects evolving threats and operating models. For many organisations, three areas are particularly important:

Mandatory Control 2.4 — Back Office Data Flow Security

Control 2.4 becomes mandatory, increasing focus on securing and evidencing data flows between the Swift environment and connected back-office systems, including APIs, middleware, managed integrations and file transfers.

Expanded scope — customer-client connectors

Customer-client connectors are now in scope, potentially widening the systems, teams and processes involved in the assessment.

Stronger third-party conformance requirements

Swift has introduced additional conformance requirements for messaging and connectivity providers. Organisations must ensure appropriate assurance is available where third parties are used.

New international finance centre hub and offices

The challenge for international and outsourced models

Many organisations — particularly in international finance centres such as Jersey, Guernsey and the Isle of Man — operate Swift environments across outsourced, hosted or group-shared service models.

In these environments, the key challenge is demonstrating:

  • Clear scope and architecture
  • Defined control ownership
  • Complete and consistent evidence
  • Effective oversight of third-party and group dependencies

While delivery may sit with service providers or group functions, accountability remains with the organisation.

How we support you

We provide end-to-end support across the CSP lifecycle, with a focus on clarity, efficiency and assurance.

Our services include:

  • Scope & architecture confirmation
    Defining the in-scope Swift environment, connectivity model, integration points and key dependencies.

  • Independent assessment support

    Supporting the planning and execution of assessments aligned to Swift expectations.


  • Supplier & group evidence management

    Structuring third-party evidence requests and demonstrating effective oversight.


  • Evidence readiness & gap assessment
    Mapping controls to evidence owners, assessing sufficiency and identifying practical remediation priorities.


  • KYCSA attestation readiness
    Preparing evidence, management reporting and submission support.



Why BDO?

Specialist CSP capability
We support Swift CSP assessments in line with Swift's Certified Assessors framework.

Global Centre of Excellence
Our CSP work is supported by a global Centre of Excellence, ensuring consistency, alignment and quality assurance.

Evidence-led delivery
We take a structured, practical approach to evidence, helping ensure submissions are robust, clear and efficient.

Experience across complex models
We work with organisations operating across outsourced, hosted and group service environments — helping bring clarity to ownership, evidence and oversight.

FAQs

Contact our dedicated Management Consulting team for more information


If you are preparing for CSCF v2026 or your next Swift attestation, we can help you reduce risk, improve efficiency and strengthen assurance.

photo of Allam Zia

Allam Zia

Head of Management Consulting
View bio
Arthur Mainja

Arthur Mainja

Principal Consultant
View bio