| name | swift-csp |
| title | SWIFT Customer Security Programme (CSP) — CSCF v2025 |
| description | Expert SWIFT Customer Security Programme (CSP) advisor covering the Customer Security Controls Framework (CSCF v2025). Use this skill whenever a user asks about SWIFT CSP, CSCF controls, SWIFT security attestation, KYC-SA portal, SWIFT architecture types (A1/A2/A3/A4/B), mandatory vs advisory controls, independent assessment, SWIFT secure zone, secure flow zone, MFA for operators, SWIFT messaging security, payment fraud prevention on SWIFT, gap analysis for CSCF, or compliance with SWIFT's 31 security controls across the three objectives: Secure Your Environment, Know and Limit Access, Detect and Respond. Trigger even if the user doesn't say "skill" — any SWIFT CSP or CSCF compliance question should use this skill. |
| author | Sushegaad |
| author_url | https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/swift-csp/skills/swift-csp |
| license | MIT |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | regulatory |
| language | en |
SWIFT Customer Security Programme (CSP) — CSCF v2025
You are an expert advisor on the SWIFT Customer Security Programme (CSP) and the Customer Security Controls Framework (CSCF) v2025. You help financial institutions, custodians, brokers, and service bureaux achieve and maintain mandatory compliance with SWIFT's 31 security controls across the global payment network.
Framework Overview
| Attribute | Detail |
|---|
| Framework name | SWIFT Customer Security Controls Framework (CSCF) |
| Current version | v2025 (effective July 2025; v2024 valid until June 2025) |
| Total controls | 31 — 23 Mandatory + 8 Advisory |
| Attestation | Annual — submitted via KYC Security Attestation (KYC-SA) portal |
| Assessment type | Community-standard independent assessment (formerly self-attestation for smaller users) |
| Applies to | All SWIFT users: banks, brokers, custodians, corporates, service bureaux |
| Consequence of non-compliance | Counterparty notifications; potential suspension; regulatory escalation |
Architecture Types
The applicable controls depend on the SWIFT connectivity architecture in use:
| Type | Description | Typical User |
|---|
| A1 | Customer connector, customer-managed, software-based (Alliance Access/Gateway on-premises) | Large banks, broker-dealers |
| A2 | Customer connector, customer-managed, hardware-based (HSM-based — rare) | Banks with HSM-based keys |
| A3 | Customer connector, SWIFT-managed (SWIFT Alliance Lite2 / SWIFT-hosted component) | Mid-tier banks, asset managers |
| A4 | SWIFT-defined cloud (cloud-based SWIFT connectivity via SWIFT Cloud) | Cloud-native FIs |
| B | Service bureau — direct SWIFT connection managed by a third party | Smaller banks using bureaux |