← SWIFT: banking support and project decisions
10 / 10 · 60 MIN

Workshop: change evidence and operational acceptance

Bind rehearsals to the candidate, review security scope, calculate rollback boundaries, and prepare operational handover with clear responsibilities.

Associate evidence with the candidate

A delivery package can contain many positive tests and still fail to demonstrate the proposed change. In the exercise, candidate dr-7 belongs to environment QUALIFICATION, footprint fp-2, and control set scope-3. The local gate compares those four attributes with the report and requires observed=true. Changing any attribute rejects the match. This conservative rule is invented to practise traceability; it is not a Swift-prescribed format. A merely scheduled rehearsal remains pending. Before the meeting, the PM should be able to identify the artifact actually executed, differences from the candidate, and evidence still to be produced.

Review architecture and responsibilities

A migration may remove local servers while creating new access paths or third-party dependencies. Prepare before-and-after diagrams, identify changing components, operators, and responsibilities, and request control-scope analysis. The public CSP page directs architecture identification and applicable-control mapping. The lab neither determines an institution’s architecture type nor implements a CSCF checklist. Obtaining the appropriate edition and product guidance requires separate work. The PM coordinates that information and records dependencies; a commercial contract or lower server count does not replace analysis. The resulting evidence should identify who owns each unresolved question and when the answer is needed.

Separate preparation and independent assessment

The implementation team can collect evidence and explain decisions while an eligible assessor performs independent assessment. Changing the title of the person who designed a control is insufficient. For reliance on a previous assessment, the public FAQ requires assessor agreement, no invalidating significant change, and coverage of new or changed controls; the same assessment cannot be relied on more than once. The exercise function represents only those prerequisites. A true result certifies no compliance and authorizes no attestation. The package should distinguish observed facts, proposed conclusions, and decisions belonging to the actual assessment process.

Calculate when to decide

The local case has closure at minute forty, twelve minutes for rollback, eight for reconciliation, and five reserve. The latest start fitting the window is fifteen. At minute sixteen, retaining those assumptions forecasts closure at forty-one. Changing a timestamp or silently omitting reconciliation recovers no time. The team should escalate the variance and present impact and options to the designated authority. These values are not Swift deadlines. The exercise rehearses a difficult out-of-hours conversation: distinguish technical feasibility, what fits the window, and what requires a new decision. Record the assumptions used so the next shift can reassess them.

Retain useful and proportionate evidence

The guide requests environment, version, time, correlation identifier, observed outcome, and open questions. A sanitized error can support diagnosis without exposing a token or password. A hash compares bytes with the reference used but does not prove that the rehearsal occurred in the claimed environment or that an independent person accepted it. Following local restore, reconcile effects already produced in other systems before deciding reprocessing. The recovery gate keeps owner acceptance as a separate condition. A green test informs the decision; it does not write approval on behalf of someone who has not given it.

Practise a usable handover

The workshop below lasts forty-five minutes and assigns APS, PM, and functional-owner roles. First examine mismatching version evidence and recovery conditions; then introduce delay at the rollback boundary. Prepare an English decision summary containing observation, impact, options, owner, and next update. During the final ten minutes, another person tries to locate artifacts and repeat diagnosis using only the package. Record difficulties and correct the runbook. If the learner performs every role alone, classify it as individual practice. Publishing this material demonstrates neither a conducted workshop, a shift’s competence, nor an institution’s operational acceptance.

DR original workshop / Oficina original DR: 45 minutes
Fictional maintenance only. No Swift traffic, real change or attestation.
Manutenção fictícia. Sem tráfego Swift, mudança real ou atestação.

0-10 min: Evidence / Evidência
Candidate: dr-7, QUALIFICATION, fp-2, scope-3.
Report: dr-6, QUALIFICATION, fp-1, scope-3, observed=true.
Identify build and footprint gaps; do not relabel the report.
Identificar diferenças de build e âmbito; não alterar os rótulos do relatório.

10-20 min: Recovery / Recuperação
Process up at minute 10; functional recovery forecast at minute 25.
Local functional target: minute 15. State the gap explicitly.
Processo ativo em 10; recuperação prevista em 25; alvo funcional 15.
Indicar explicitamente a lacuna face ao alvo.

20-35 min: Decision / Decisão
Deadline 40; rollback 12; reconciliation 8; reserve 5.
Latest rollback start = 15. At minute 16 forecast completion = 41.
Último início = 15. Ao minuto 16, fecho previsto = 41.
English note:
Observed: candidate evidence mismatch; rollback decision is late.
Impact: current recovery assumptions exceed the agreed window.
Decision needed: accountable owner to choose an authorized response.
Evidence needed: candidate-specific results and revised recovery forecast.
Next update: name a responsible role and specific time.

35-45 min: Handover / Passagem à operação
Another participant locates version, outcomes, runbook and escalation route.
Outro participante localiza versão, resultados, runbook e escalada.
Record usability failures and unresolved assumptions.
Registar falhas de utilização e pressupostos por resolver.
Solo practice is self-review, not independent acceptance.
Prática individual é autoavaliação, não aceitação independente.
Deliver expected/observed evidence without credentials or real customer data.
Entregar evidência esperada/observada sem credenciais ou dados reais de clientes.
IN PRACTICE

Case: dr-6 passed rehearsal, but dr-7 changes access. Identify the difference, assign impact assessment, and obtain applicable evidence before acceptance.

Common pitfalls

An old report with a new date; self-assessment called independent; hash treated as truth; rollback without reconciliation; attendance treated as autonomy.

Related topics: States, reconciliation, and recovery without duplication · Security scope and independent evidence · Continuity and operational handover

Take this idea with you

Accepting delivery requires applicable evidence, functional conditions, and identified authority; the workshop enables practice without awarding external compliance.

Create account

Reference: NIST SP 800-34 Rev. 1: Contingency Planning Guide · BigSavant Swift knowledge assessment2026.10; independent professional curriculum

SWIFT® is a registered trademark of S.W.I.F.T. SC. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by Swift. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.