Skip to content
Alert Banner Text Goes Here Alert Banner Text Goes Here Alert Banner Text Goes Here Alert Banner Text Goes Here
Get in Touch

How Your Organisations Can Comply

Swift users can complete an independent assessment in two ways. 

  • Internal assessment—carried out by your company’s second or third line of defence, such as your internal compliance, risk, or audit departments. 
  • External assessment—via an independent, external organisation with cybersecurity assessment experience and individual assessors with relevant security industry certification. 

Keep Up-to-Date with Your Responsibilities

All Swift users, including corporates, banks, and financial institutions, must attest annually to this framework. Non-compliant customers can be reported to their local regulator and attestation compliance statuses can be visible to other Swift counterparties, which may be used when assessing new vendors.

Swift customers are responsible for reviewing their infrastructure, meeting control standards, and completing their due diligence when selecting and contracting cyber security service providers.

Benefits of Partnering with Bottomline

Our solutions can help in the following areas:

Clarity and Transparency

Up-to-date information on the latest Swift CSP framework controls and what action you need to take, every step of the way.

No Need to Wish for Hindsight

A full understanding of your compliance status each year, ahead of the attestation to help you take any remediation required.

Experts on Hand

A dedicated Account Manager or Cyber Security specialist to comply with the Swift CSP and reap additional benefits for peace of mind.

Bottomline Technologies
TESTIMONIALS

What Our Customers Say

We have used Bottomline and AJC to meet this year’s new CSP Independent Assessment deadline and the service has been very efficient. It has given us peace of mind that the CSP attestation deadline is met and that our payment infrastructure is safe, secure, and compliant.

Japanese Financial Institutions face an ever-increasing Anti-Money Laundering (AML) and Counter Financing of Terrorism (CFT) compliance burden. We, therefore, wanted to partner with an established transaction monitoring solution provider as Japanese institutions tend to favour established solutions that are proven to detect and prevent risk.

Lion Global Investors turned to trusted partner Bottomline for support as other options were looking very costly. Our existing relationship assured us that the project would run smoothly, and we would remain compliant. The service has been efficient, and we are very happy with the guidance and professionalism provided by Bottomline.

Bottomline’s Swift CSP Independent Assessment gave us reassurance that we would meet all advisory and mandatory controls and provided us with a deeper understanding of the framework. As the programme continues to evolve, we will continue to partner with Bottomline to ensure GLAS remains compliant and our Swift environment is secure now and in the future.

Prev
Next

FAQs

Everything you need to know about Swift CSP.
What are the consequences of non-compliance?

Swift can inform other members within the community and have the right to report any non-conformities to that member's local authorities. This could have detrimental effects on an organisation, potentially jeopardising daily business operations, reputational damage, and trust.

How long does remedial action take prior to the independent assessment taking place?

Resolution periods typically range from weeks to months. During the CSP pre-attestation review, we will identify any instances of non-conformance and provide you with a task list detailing any necessary remediation works required before conducting the actual independent assessment. Our Swift-certified auditors will be on hand to provide guidance and ensure you have the necessary measures in place to fully comply with the Swift CSP.

Can Bottomline provide a template of what the pre-attestation review outputs look like?

The pre-attestation review will allow our Swift-certified auditors to review and discuss your organisation’s current compliance status before the actual independent assessment is performed. The auditors will then recommend enhancements and possible remediation works. We will outline the outputs of this in both a summary presentation and a detailed task list containing the relevant details. We are happy to share an example of the reports with you.

Can Bottomline help with CSP attestation next year as well as this year?

Yes, we do recommend multi-year contracts and most customers have this. However, clients that have signed for just one year will need to extend their agreement to support next year’s control framework too.

What are the common failure areas?

The most common areas of non-compliance tend to relate to poor policy and documentation which is often overlooked. Organisations have documentation in place but it is not adequately maintained or doesn’t contain the specifics to meet the CSP requirements. Similarly, we often see organisations failing to adhere to the controls that focus on vulnerability scanning and penetration testing.

Does my ISO Certificate mean that I can certify as compliant?

Whilst the ISO certificate and audit ensures that the organisation has appropriate information security governance, it does not cover the specifics related to the Swift CSP. As a consequence, a review of the Swift-specific components are required.

Get In Touch

Speak to one of our experts today.