Skip to Content

Swift RMA


Control which counterparties can send you messages

Without control over who can send you authenticated messages, your institution is open to unwanted, fraudulent, or unauthorised traffic across thousands of BICs. RMA lets you define, per counterparty and per message type, exactly what you will accept.


Talk to Swift Expert!
What it is.

Control Counterparty Access

The Relationship Management Application (RMA) records and enforces pre-agreed bilateral authorisations that control which messages you send to and receive from each counterparty.

Why it matters.

Protect Every SWIFT Exchange

RMA is mandatory for FIN and FINplus. It filters traffic centrally, reducing fraud and unwanted messages, and enforces authorisations regardless of local settings.

How it helps.

Manage RMA Centrally

You manage relationships from the RMA Portal, apply changes in bulk, and keep local interfaces in sync through distribution files.

Overview



Authorisations are one-directional. Granting an authorisation lets a counterparty send to you, which is your authorisation to receive. For two-way traffic, each party grants the other. RMA applies only to messages that require authentication, such as MT 103. Unauthenticated messages, such as MT 999, need no authorisation.

You manage authorisations centrally through the RMA Portal, a web application that supports grant, modify, revoke, reciprocate, search, templates, and four-eyes control through role-based access. Bulk actions cover grant, revoke, refuse, add, remove, and replace, each with two-operator control. Central Portal changes take effect within 15 minutes of acknowledgement.


Capability
What it does

Business profiles

Group message and request types across FIN and FINplus for a business flow, so you authorise a whole flow consistently rather than message by message.

Distribution files

Export authorisations as XML to synchronise local RMA applications, manually or automated through FileAct.

RMA Query APIs

Read-only checks of relationship status before sending, to avoid rejected messages. They cannot create or update authorisations.

Processing timelines are set. Received authorisations must be processed within six business days, an equivalent authorisation returned within six business days where required, and revocations processed within one business day.




Benefits



 Lower fraud exposure

Accept authenticated messages only from counterparties you have authorised, closing off unwanted traffic.


 Central enforcement

Central authorisations are always enforced, regardless of local interface settings.


 Management at scale

Bulk actions, templates, and business profiles handle large relationship sets without message-by-message work.


 Synchronised interfaces

Distribution files keep local RMA applications aligned with your central records..

FAQs


Yes, for FIN and FINplus, but only for messages that require authentication. Unauthenticated messages such as MT 999 need no authorisation. For InterAct and FileAct, the service administrator decides.

Authorisations are one-directional. Granting one lets a counterparty send to you. For two-way traffic, each party must grant the other.

Central Portal changes are effective within 15 minutes of acknowledgement. Revocations must be processed within one business day and received authorisations within six business days.

The RMA Query APIs are read-only. You can check relationship status and details, but must use the RMA Portal to create or update authorisations.

Export distribution files from the Portal, manually or automated through FileAct, and import them into your local RMA applications.


Contact us

Have a question? We're here to help with your SWIFT journey.