Phone us
As another SWIFT Customer Security Programme (CSP) season draws to a close, AJC reflects on a dynamic and successful year supporting clients worldwide.

With a high volume of audits completed and continued investment in certified expertise, AJC has further strengthened its position as a trusted partner in SWIFT compliance. In this article, we look back at the highlights of the 2025 season and what lies ahead as organisations prepare for changes to the SWIFT CSCF standard in 2026.

Global Delivery at Scale

During the 2025 CSP season, AJC’s dedicated SWIFT auditors supported circa 130 organisations, covering approximately 160 BIC codes across North America, Europe, Asia and Australasia. This breadth of activity reflects both the confidence clients place in AJC and our continued commitment to delivering consistent, high-quality audits at scale.

Our global reach enables us to support organisations operating across multiple jurisdictions, while maintaining a rigorous and standardised approach to SWIFT CSP compliance.

Robust Governance Through Lead Auditor Oversight

Following changes introduced by SWIFT to the CSP audit process, organisations listed on the SWIFT directory are required to maintain a minimum of two certified Lead Auditors. Lead Auditors play a critical role in ensuring audits meet SWIFT’s requirements and that attestations are completed accurately and consistently.

AJC continues to exceed this requirement, with three fully certified Lead Auditors in place throughout the 2025 season. In practice, Lead Auditors provide an additional layer of assurance by reviewing the work of each auditor, carrying out detailed quality control and completeness checks on audit evidence, findings and outcomes before results are reported to clients.

Looking ahead, AJC has plans to certify two additional Lead Auditors during 2026. This investment reflects both the scale of our CSP work and our commitment to maintaining resilience, quality and capacity as requirements evolve.

Strong Strategic Partnerships 

In addition to delivering against CSP compliance requirements, AJC continued to strengthen its strategic partnership with Bottomline during the 2025 season. The extension of this collaboration reinforces a long-standing relationship focused on supporting clients with robust, reliable solutions aligned to SWIFT security and compliance expectations.

Staying Ahead of the 2026 CSCF Updates

SWIFT has confirmed that further updates to the Customer Security Controls Framework (CSCF) will come into effect for the 2026 attestation cycle. AJC is already reviewing these changes in detail and assessing their practical implications for organisations subject to CSP requirements.

By taking a proactive approach, we ensure our clients are kept informed well in advance and can plan confidently for any adjustments required to controls, evidence or governance processes.

Supporting Clients Into the Next Attestation Cycle

The 2026 SWIFT CSP season is expected to be another busy and evolving cycle. With established global delivery, certified Lead Auditor oversight and a strong track record across hundreds of audits, AJC is well placed to support both existing and new clients through the next phase of SWIFT compliance.

Our performance throughout 2025 reflects AJC’s continued focus on quality, expertise and client confidence. As organisations prepare for the 2026 CSCF changes, we remain committed to providing clear guidance, robust assurance and dependable support at every stage of the SWIFT CSP journey

To learn more about AJC’s SWIFT services and how we can help your organisation navigate the SWIFT CSP attestation process, visit our website or contact us today on 020 7101 4861 or info@ajollyconsulting.co.uk

In case you missed it...

Login Credentials Exposed
149 Million Login Credentials Exposed

January 2026 has shaped up to be a month that reinforces the importance of taking time to ensure personal and...

Read More
operational resilience data
Operational Resilience Without Real Data Is...

Operational resilience has become a central theme in UK risk and regulatory conversations. Boards, regulators and risk teams speak of...

Read More
instagram cyber risk
Instagram Password Reset Emails, GDPR and...

In January 2026, Instagram users worldwide reported receiving unexpected password reset emails from what appeared to be Instagram’s official security...

Read More

Get in touch

    By submitting this form you are consenting that your data be handled in accordance with our Privacy Notice and we will be in touch regarding your enquiry.