SWIFT CSP independent assessment for African banks

Since 2021, your annual SWIFT attestation has to be supported by an independent assessment, not a pure self-assessment. We act as an external independent assessor for the SWIFT Customer Security Programme: we test your in-scope controls by hand and hand back the evidence your attestation needs, ahead of the 31 December deadline. Led by an OSCP-credentialled practitioner with bank red-team experience.

Aligned to: SWIFT Customer Security Controls Framework | OSCP-credentialled practitioner | Annual attestation by 31 December | Evidence-led, attestation-ready reporting

What the assessment covers

01

CSP control scope

The Customer Security Controls Framework defines mandatory and advisory controls across your SWIFT-related environment and connectivity.

02

Independent assessment

Your attestation must be supported by an independent review: an independent internal function or an external independent assessor like us. We offer the external route.

03

The 31 December calendar

The attestation is annual and due by 31 December, with the submission window running roughly July to December.

04

Attestation-ready support

Control-by-control findings and evidence structured to map directly onto the attestation you file on the KYC-SA portal.

What the SWIFT CSP requires

The SWIFT Customer Security Programme (CSP) sets a baseline of security controls for every institution connected to the SWIFT network. Those controls live in the Customer Security Controls Framework, which groups mandatory and advisory controls across three objectives: secure your environment, know and limit access, and detect and respond. Every connected institution attests each year to which controls it meets, and the attestation is due by 31 December.

Rwanda's commercial banks are connected to the SWIFT network, so the programme applies to them, alongside other banks and financial institutions across Africa on the network. The submission window on the SWIFT KYC-SA portal runs roughly from July to December, which is why most institutions schedule their supporting assessment in the second half of the year, with time to close gaps before they attest.

Independent assessment: internal versus external

Since 2021, a pure self-assessment is no longer compliant. The attestation must be supported by an independent assessment of the in-scope controls. There are two valid routes, and external is not the only one:

We position ourselves as an external independent assessor, not as the only compliant path. Many institutions choose an external review to get an independent pair of eyes on the controls and to keep their own staff on operations. If you would rather assess internally, the programme allows it; we are simply the external option when you want one. Confirm your assessor-qualification expectations under SWIFT's Independent Assessment Framework with us at scoping; our strength is hands-on technical verification of the controls, and we will tell you plainly if your attestation route needs an audit-credentialled co-assessor.

What we deliver

We assess the in-scope controls against the Customer Security Controls Framework and test the technical controls by hand rather than by questionnaire, so the assessment reflects your live environment:

Why the testing credential matters here

An independent assessment is only as good as the person performing it. Our assessments are led by an OSCP-credentialled practitioner with red-team and penetration-testing experience inside a Tier-1 Nordic bank, a pan-African banking group, and a top-5 South African bank. That bank red-team background means the technical CSP controls are tested the way an attacker would probe them, not ticked off a form. If your environment also falls under Rwandan banking supervision, see our BNR-compliant penetration testing, and for the background on the programme, read our guide to SWIFT CSP compliance in Rwanda.

How an assessment runs

Scoping

We confirm your SWIFT architecture type and in-scope components, agree rules of engagement, and pin the assessment to the 31 December attestation deadline.

Assessment

Control-by-control review with hands-on testing of the technical controls, with clear communication and immediate escalation of anything critical.

Reporting

An attestation-ready report: control-by-control findings, gaps, and prioritised remediation, structured to map onto what you submit.

Retest & attest

Free retest on remediated controls, so you attest against controls you have closed, ahead of your 31 December deadline.

Frequently asked questions

Does SWIFT CSP require an independent assessment?
Since 2021, a pure self-assessment is no longer compliant. Your annual attestation must be supported by an independent assessment of the in-scope controls. That assessment can be carried out by a function inside your organisation that is independent of the people who run SWIFT, or by an external assessor like us. External is not the only path, but it is the one that puts an external independent reviewer in front of your controls without competing internal priorities.
When is the SWIFT CSP attestation due?
The attestation is annual and due by 31 December. The submission window on the SWIFT KYC-SA portal runs roughly from July to December, so most institutions schedule the supporting independent assessment in the second half of the year to leave time to remediate gaps before they attest.
Can the independent assessment be done internally?
Yes. SWIFT allows the independent assessment to be performed by an internal team that is independent of the people who operate your SWIFT infrastructure, or by an external assessor. We do not claim external is the only compliant route. Many institutions choose an external assessor to get an independent review and to keep their own staff focused on operations.
Who has to comply with the SWIFT CSP in Rwanda?
Any institution connected to the SWIFT network. Rwanda's commercial banks are connected to the SWIFT network, so the programme applies to them, alongside other African banks and financial institutions on the network. The controls and the annual attestation apply regardless of how you connect to SWIFT.
What do you deliver for a SWIFT CSP assessment?
We assess your in-scope controls against the Customer Security Controls Framework, test the technical controls by hand rather than by questionnaire, and hand back an assessment report with the evidence your attestation needs: control-by-control findings, gaps with prioritised remediation, and a retest after you fix them. The output is structured to map directly onto the attestation you file.
How much does a SWIFT CSP independent assessment cost?
Every engagement is scoped individually based on your architecture type, the number of in-scope components, and how deep the technical testing goes. Tell us your environment and the attestation deadline you are working to, and we reply within 24 hours, and a scoped proposal follows within 48 hours of the scoping call.

For the full scope of our manual testing across web, network, mobile, API, and cloud, see our penetration testing service, or read our guide to SWIFT CSP compliance in Rwanda.

Working to a 31 December attestation?

Tell us your SWIFT architecture and the date you are attesting toward. We reply within 24 hours, and a scoped proposal follows within 48 hours of the scoping call.

Chat on WhatsApp Chat with us