{
  "tool_id": "art-486-cscf-control-applicability",
  "tool_version": "1.0.0",
  "display_name": "CSCF Control Applicability & Coverage",
  "mcp_name": "check_cscf_control_applicability",
  "mandate_type": "compliance_mandate",
  "wave": 66,
  "gpu": false,
  "url": "https://ainumbers.co/chaingraph/art-486-cscf-control-applicability.html",
  "description": "Scores a Swift member's declared architecture type and component inventory against a policy-supplied Swift Customer Security Controls Framework (CSCF) control matrix -- the published control number, tier (mandatory/advisory), applicable-architecture-type list, and evidence column, never a hand-transcribed list. Returns the applicable mandatory/advisory control set, coverage percentages, a gap list keyed by the published control number, an evidence index mapped to the matrix's supporting-evidence column, and an explicit not-applicable set with a stated reason per exclusion so an omission can never read as a pass. Not a Swift-endorsed tool and not a KYC-SA submission; consumes the firm's own declared architecture and its own copy of the published matrix.",
  "input_schema_ref": "chaingraph/art-486-cscf-control-applicability.html#manifest",
  "consumes": [],
  "feeds": [],
  "status": "live",
  "conformance_fixtures": true,
  "compute_capability": "server",
  "compute_images": [{"system":"sha256-source","image_id":"sha256:e61f7e68aeceece5e32ce4f26e110cac1da3e8f1a8d79d74304674e7de0c8484","valid_from":"2026-07-10"},{"system":"risc0","image_id":"sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6","valid_from":"2026-06-28"}],
  "export_capability": [
    "json"
  ],
  "compute_proof_ready": "ready",
  "compute_proof": {
    "type": "ZkVmReceipt",
    "system": "risc0",
    "receiptFormat": "groth16-bn254",
    "imageId": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
    "seal": "K1PTp1dvRePes2HN2O60no2UPb/drHvlU0T7EWtEGBwNDUE3prHJvtuylxO6TFVomXhe7uftBNL/UQPfeFiChQzJ5uD+lB0V5BoeVu88lnsIRYasLXBfXrjMpVGytZJlIg7WbCGG/ocoVuvDqyMTht4hB6AMwnQ2m9LFjU4IQ8UO+fBrAIZtZNuoHePpIOKB5Rtnn6YaXT8ZAgZwxUyDySK4ofu5l8sxFF+J53IkTHdByJtwFqHt+UNpeb/ddjyAEGnj0xDnJZ2UNI/owq68ApIESfKrCbCobuLlbLWcoYgHh1fMB/fCwpoNbunEcHCbY4B2vYSYDbfEZL/vOhMx1g==",
    "journal": {
      "chaingraph_version": "0.4.0",
      "kernel_digest": "sha256:e61f7e68aeceece5e32ce4f26e110cac1da3e8f1a8d79d74304674e7de0c8484",
      "output": {
        "advisory_coverage_pct": 0,
        "applicable_advisory_count": 2,
        "applicable_mandatory_count": 4,
        "architecture_type": "A1",
        "component_inventory": [
          "swift_alliance_access",
          "hsm",
          "jump_server"
        ],
        "cscf_version": "2026",
        "evidence_index": {
          "1.1": {
            "evidence_provided": true,
            "evidence_ref": "SWIFT.io evidence",
            "tier": "mandatory"
          },
          "1.2": {
            "evidence_provided": true,
            "evidence_ref": "Network diagram",
            "tier": "mandatory"
          },
          "2.1": {
            "evidence_provided": false,
            "evidence_ref": "Access control list",
            "tier": "mandatory"
          },
          "2.4A": {
            "evidence_provided": false,
            "evidence_ref": "Logging config export",
            "tier": "advisory"
          },
          "5.1": {
            "evidence_provided": true,
            "evidence_ref": "HSM audit report",
            "tier": "mandatory"
          },
          "7.2": {
            "evidence_provided": false,
            "evidence_ref": "Pen-test report",
            "tier": "advisory"
          }
        },
        "gap_list": [
          {
            "control_number": "2.1",
            "evidence_ref": "Access control list",
            "tier": "mandatory"
          },
          {
            "control_number": "2.4A",
            "evidence_ref": "Logging config export",
            "tier": "advisory"
          }
        ],
        "mandatory_coverage_pct": 75,
        "not_applicable_set": {
          "7.2": "No externally exposed pen-test surface for this architecture"
        },
        "overall_status": "gaps_present"
      }
    }
  }
}
