Compliance · Switzerland
Swiss Financial Market Supervisory Authority
Circular 2023/1, operational risks and resilience
FINMA Operational Resilience & ICT Risk
Plain-English definition
FINMA is the Swiss financial regulator. FINMA Circular 2023/1 sets out how Swiss-regulated banks, securities firms, insurers and financial market infrastructures must manage operational risk, including ICT and cyber risk, business continuity, and oversight of outsourced service providers. If you serve a Swiss-regulated financial institution, including as a vendor, these obligations apply to your relationship with them.
Applies to Swiss-regulated financial institutions directly, and flows down contractually to their vendors and service providers, including those outside Switzerland.
Who needs it
Swiss-regulated banks, securities firms, insurers and financial market infrastructures, plus any vendor or service provider they outsource critical functions to, regardless of the vendor's own location.
Key requirements
An ICT risk management framework, business continuity and disaster recovery capability, a maintained outsourcing register, and significant-incident reporting to FINMA within a defined timeframe.
Cyber/privacy implications
Security controls must be demonstrable at the level of individual critical functions and third-party dependencies, not just at the organizational perimeter.
Assessment methodology
Gap assessment against Circular 2023/1, review of the outsourcing register and vendor agreements, and a review of business continuity and resilience test results.
Implementation phases
01
Assess
Map critical functions and outsourcing relationships against Circular 2023/1 scope.
02
Remediate
Close control gaps in ICT risk management, business continuity and vendor oversight.
03
Evidence
Maintain the outsourcing register and resilience test evidence in audit-ready form.
Evidence & documentation requirements
A current outsourcing register, vendor risk assessments, business continuity and disaster recovery test results, and an incident-reporting procedure with defined escalation timelines to FINMA.
Common mistakes
Assuming ISO 27001 certification alone satisfies Circular 2023/1; treating the outsourcing register as a one-time exercise rather than a maintained record; missing the incident-reporting timeframe because ownership of the obligation isn't clearly assigned internally.
Expert review
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA
FAQ
Does this apply to us if we're not based in Switzerland?
Yes, if you provide outsourced services to a Swiss-regulated financial institution. The obligation is contractual, flowing down from the regulated institution to its vendors, wherever those vendors are based.
How is this different from DORA?
DORA is the EU's comparable operational-resilience regulation for financial entities. The intent is similar, but the regulator, jurisdiction and specific requirements differ, so compliance with one does not automatically satisfy the other.
Request a Gap Assessment
See exactly where your operational resilience and outsourcing controls stand against FINMA Circular 2023/1.
Request a Gap Assessment →