In recent months, one observation has consistently come up in discussions with security, treasury, and IT teams: the SWIFT CSP is no longer just a compliance exercise. It has become a moment of truth, where regulatory constraints, architectural complexity, and organizations’ actual ability to secure their critical data flows all come into sharp focus.
It is against this backdrop that Oaklen and Utsit announce the certification of three new CSP auditors: Caroline Miltgen, Sami Oughella, and Shoma Okuwa. This expansion is a direct response to market developments.
Since 2016, SWIFT’s Customer Security Program has provided a framework for cybersecurity requirements across the entire financial community. Each year, organizations must demonstrate compliance with the Customer Security Controls Framework (CSCF). But in practice, the nature of the issue has changed. Architectures have become more complex, data flows have become more critical, and requirements have become more specific. As a result, there is growing demand for independent CSP assessments—not only to validate compliance, but also to provide a clear picture of an organization’s security posture.
“Our clients have been eagerly awaiting this expansion of our capabilities,” explains Olivier Ringard, Partner at Utsit. “The certification of Caroline Miltgen, Sami Oughella, and Shoma Okuwa now enables us to handle a higher volume of requests while maintaining the expected high standards.”
Behind the CSP, there is not a single reality, but a multitude of configurations: corporate entities processing international payments, TMS vendors integrating Swift connectivity, and banking institutions with hybrid architectures. Added to this are the various connection models—A1, A2, A3, A4, or B—which directly determine the applicable controls. In this context, the challenge is not simply to increase audit capacity, but to maintain a tailored approach capable of adapting the assessment to the technical and operational reality of each organization.
One of the most common points of friction from the customer’s perspective remains the same: the CSP is often perceived as a significant burden that ties up substantial resources. But when used properly, it can become a valuable management tool: structuring one’s security approach, prioritizing truly critical risks, and avoiding unnecessary effort. “We understand the compliance issues, as well as the operational constraints and technical challenges our clients face,” continues Olivier Ringard. “Our goal is precisely to transform this obligation into an opportunity for continuous improvement.”
With three additional certified auditors, Oaklen and Utsit are strengthening their ability to support corporations, Treasury Management System vendors, and banking institutions, regardless of their architecture. In practical terms, this translates to greater availability, an improved ability to handle requests, and structured support—from the assessment phase through the preparation of the attestation in the KYC Security Attestation tool.
Under the CSP program, communication regarding certifications is strictly defined. The Oaklen and Utsit teams include Swift-certified assessors (Swift Certified Assessors) in the area of Customer Security Program Assessment, in accordance with the requirements of the Swift Partner Program—a designation that attests to the assessors’ qualifications, without implying any liability on the part of Swift for the engagements carried out.
Beyond the announcement itself, this strengthening signals something broader: payment security is no longer a peripheral issue. It has become a prerequisite for implementation, and in this context, the quality of the assessment—its rigor, its independence, and its understanding of the architectures—becomes almost as strategic as the controls themselves.


















.png)



.png)



.png)





































