A monetary authority in Luxembourg City, within the Grand Duchy of Luxembourg, is preparing its 2026 independent attestation under the SWIFT Customer Security Programme (CSP). The SWIFT CSP Assessor will review one BIC with an A1 architecture against the mandatory controls in the SWIFT Customer Security Control Framework v2026, combining payment systems auditing, cyber security, and formal risk assessments.
The mission
The organisation's payment-system responsibilities sit within Luxembourg's financial infrastructure, where the attestation provides an independent view of the controls protecting SWIFT-related activity. The independent SWIFT CSP assessment is limited to one BIC and mandatory controls in CSCF v2026, based on architecture type A1. Results will be prepared for publication through the SWIFT KYC portal using the framework's required evidence and reporting approach.
You will define the evidence request, conduct interviews and control testing, review technical and procedural evidence, and record conclusions against each applicable control. The assignment is expected to take approximately 15 to 20 days, beginning no earlier than September 2026, with reporting completed by the end of November 2026. The assessment report and assessment completion form must be delivered in English, using the template provided by SWIFT.
Your responsibilities
- Plan the independent assessment scope for one BIC and A1 architecture, aligning the work with mandatory CSCF v2026 controls.
- Examine payment-system security measures, policies, procedures, and supporting evidence to determine control compliance.
- Perform risk assessments and security assessments, testing whether control implementation meets SWIFT requirements.
- Identify and document compliance gaps, observations, and evidence limitations in a traceable working file.
- Produce the assessment report and assessment completion form in English, following the current SWIFT templates.
- Prepare the final attestation results for publication on the SWIFT KYC portal by the agreed reporting deadline.
Your profile
Essential skills
- Demonstrates medior-level experience in IT auditing of payment systems or comparable regulated technology environments.
- Applies SWIFT CSP requirements and understands the control objectives in the SWIFT Customer Security Control Framework, including mandatory controls.
- Conducts structured risk assessments and security assessments, reviewing evidence and challenging control design and operation.
- Assesses security controls in a SWIFT-connected environment with an impartial and evidence-based approach.
- Works independently, maintains an assessor position, and communicates findings clearly with technical and non-technical stakeholders.
- Writes precise assessment reports and completion forms in English, with findings supported by clear evidence.
Languages
- English, C1 or equivalent professional written proficiency, for assessment reports, completion forms, and stakeholder communication.