OpenChainGraph Suite · ART-486 · Swift CSP / CSCF

CSCF Control Applicability & Coverage

Scores a declared architecture type and component inventory against a policy-supplied Swift Customer Security Controls Framework control matrix — the published control number, tier, applicable-architecture-type list, and evidence column, never a hand-transcribed list. Returns the applicable mandatory/advisory control set, coverage percentages, a gap list keyed by the published control number, an evidence index mapped to the matrix's evidence column, and an explicit not-applicable set with a stated reason per exclusion so an omission can never read as a pass. Step 1 of the Customer Security Controls Attestation Cycle, where an outstanding mandatory-control gap puts the cycle on a §27 hold gate.

CSCF v2026 Coverage Gap List
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
⚠ Not a Swift endorsement, not an assessor accreditation, and not a KYC-SA submission. The control matrix is a policy input you supply — your own copy of the published CSCF matrix — never embedded kernel source; CSCF versions change annually.
Declared Architecture
Control Matrix (policy-supplied — your copy of the published CSCF matrix)
Demo fixture loaded on page open — a synthetic, structurally-representative sample, not Swift's published text.
Coverage
ControlTierStatusEvidence Ref
Execution Hash (SHA-256)

Ask your agent

Copy this paragraph into Claude, OpenClaw, or any MCP-aware agent to run this exact tool, with this sample, and verify the artifact.

Run the AINumbers MCP tool `check_cscf_control_applicability`. Task: Score a Swift member's declared architecture type and component inventory against a policy-supplied Swift Customer Security Controls Framework (CSCF) control matrix -- the published control number, tier (mandatory/advisory), applicable-architecture-type list, and evidence column, never a hand-transcribed list.
Call it with arguments: {"policy_parameters":{"architecture_type":"A1","cscf_version":"2026","component_inventory":["swift_alliance_access","hsm","jump_server"],"control_matrix":[{"control_number":"1.1","tier":"mandatory","applicable_architecture_types":["A1","A2","A3","A4"],"evidence_ref":"SWIFT.io evidence"},{"control_number":"1.2","tier":"mandatory","applicable_architecture_types":["ALL"],"evidence_ref":"Network diagram"},{"control_number":"2.1","tier":"mandatory","applicable_architecture_types":["A1","A2"],"evidence_ref":"Access control list"},{"control_number":"2.4A","tier":"advisory","applicable_architecture_types":["A1","A2","A3"],"evidence_ref":"Logging config export"},{"control_number":"5.1","tier":"mandatory","applicable_architecture_types":["A1","B","C"],"evidence_ref":"HSM audit report"},{"control_number":"7.2","tier":"advisory","applicable_architecture_types":["ALL"],"evidence_ref":"Pen-test report"}],"implementation_status":{"1.1":{"implemented":true,"evidence_provided":true},"1.2":{"implemented":true,"evidence_provided":true},"2.1":{"implemented":false,"evidence_provided":false},"5.1":{"implemented":true,"evidence_provided":true},"7.2":{"not_applicable":true,"na_reason":"No externally exposed pen-test surface for this architecture"}}}}
Verify before trusting: call `verify_execution_hash` on mcp.ainumbers.co (https://mcp.ainumbers.co/mcp) with the parameter `claimed_hash` set to the returned `execution_hash`, passing the full artifact the run returned (the object containing `policy_parameters` + `output_payload` + `execution_hash`; equivalently `policy_parameters` + `output_payload` with `claimed_hash`), not the bare hash string.
Return the ledger link https://ledger.ainumbers.co/ so a human can re-verify without contacting us.
PII rule: All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Open the tool with the sample prefilled: https://ainumbers.co/chaingraph/art-486-cscf-control-applicability.html#p=v1.H4sIAAAAAAAA_wHIBDf7eyJhcmNoaXRlY3R1cmVfdHlwZSI6IkExIiwiY3NjZl92ZXJzaW9uIjoiMjAyNiIsImNvbXBvbmVudF9pbnZlbnRvcnkiOlsic3dpZnRfYWxsaWFuY2VfYWNjZXNzIiwiaHNtIiwianVtcF9zZXJ2ZXIiXSwiY29udHJvbF9tYXRyaXgiOlt7ImNvbnRyb2xfbnVtYmVyIjoiMS4xIiwidGllciI6Im1hbmRhdG9yeSIsImFwcGxpY2FibGVfYXJjaGl0ZWN0dXJlX3R5cGVzIjpbIkExIiwiQTIiLCJBMyIsIkE0Il0sImV2aWRlbmNlX3JlZiI6IlNXSUZULmlvIGV2aWRlbmNlIn0seyJjb250cm9sX251bWJlciI6IjEuMiIsInRpZXIiOiJtYW5kYXRvcnkiLCJhcHBsaWNhYmxlX2FyY2hpdGVjdHVyZV90eXBlcyI6WyJBTEwiXSwiZXZpZGVuY2VfcmVmIjoiTmV0d29yayBkaWFncmFtIn0seyJjb250cm9sX251bWJlciI6IjIuMSIsInRpZXIiOiJtYW5kYXRvcnkiLCJhcHBsaWNhYmxlX2FyY2hpdGVjdHVyZV90eXBlcyI6WyJBMSIsIkEyIl0sImV2aWRlbmNlX3JlZiI6IkFjY2VzcyBjb250cm9sIGxpc3QifSx7ImNvbnRyb2xfbnVtYmVyIjoiMi40QSIsInRpZXIiOiJhZHZpc29yeSIsImFwcGxpY2FibGVfYXJjaGl0ZWN0dXJlX3R5cGVzIjpbIkExIiwiQTIiLCJBMyJdLCJldmlkZW5jZV9yZWYiOiJMb2dnaW5nIGNvbmZpZyBleHBvcnQifSx7ImNvbnRyb2xfbnVtYmVyIjoiNS4xIiwidGllciI6Im1hbmRhdG9yeSIsImFwcGxpY2FibGVfYXJjaGl0ZWN0dXJlX3R5cGVzIjpbIkExIiwiQiIsIkMiXSwiZXZpZGVuY2VfcmVmIjoiSFNNIGF1ZGl0IHJlcG9ydCJ9LHsiY29udHJvbF9udW1iZXIiOiI3LjIiLCJ0aWVyIjoiYWR2aXNvcnkiLCJhcHBsaWNhYmxlX2FyY2hpdGVjdHVyZV90eXBlcyI6WyJBTEwiXSwiZXZpZGVuY2VfcmVmIjoiUGVuLXRlc3QgcmVwb3J0In1dLCJpbXBsZW1lbnRhdGlvbl9zdGF0dXMiOnsiMS4xIjp7ImltcGxlbWVudGVkIjp0cnVlLCJldmlkZW5jZV9wcm92aWRlZCI6dHJ1ZX0sIjEuMiI6eyJpbXBsZW1lbnRlZCI6dHJ1ZSwiZXZpZGVuY2VfcHJvdmlkZWQiOnRydWV9LCIyLjEiOnsiaW1wbGVtZW50ZWQiOmZhbHNlLCJldmlkZW5jZV9wcm92aWRlZCI6ZmFsc2V9LCI1LjEiOnsiaW1wbGVtZW50ZWQiOnRydWUsImV2aWRlbmNlX3Byb3ZpZGVkIjp0cnVlfSwiNy4yIjp7Im5vdF9hcHBsaWNhYmxlIjp0cnVlLCJuYV9yZWFzb24iOiJObyBleHRlcm5hbGx5IGV4cG9zZWQgcGVuLXRlc3Qgc3VyZmFjZSBmb3IgdGhpcyBhcmNoaXRlY3R1cmUifX19j0PLdcgEAAA