FINMA Operational Resilience & ICT Risk
Who needs it
Banks, securities firms and other entities expressly covered by the circular. Vendors should assess the service and customer contract; do not assume that every financial institution falls under this same circular.
Key requirements
An ICT risk management framework, business continuity and disaster recovery capability, a maintained outsourcing register, and significant-incident reporting to FINMA within a defined timeframe.
Cyber/privacy implications
Security controls must be demonstrable at the level of individual critical functions and third-party dependencies, not just at the organizational perimeter.
Assessment methodology
Gap assessment against Circular 2023/1, review of the outsourcing register and vendor agreements, and a review of business continuity and resilience test results.
Implementation phases
Assess
Map critical functions and outsourcing relationships against Circular 2023/1 scope.
Remediate
Close control gaps in ICT risk management, business continuity and vendor oversight.
Evidence
Maintain the outsourcing register and resilience test evidence in audit-ready form.
Evidence & documentation requirements
A current outsourcing register, vendor risk assessments, business continuity and disaster recovery test results, and an incident-reporting procedure with defined escalation timelines to FINMA.
Common mistakes
Assuming ISO 27001 certification alone satisfies Circular 2023/1; treating the outsourcing register as a one-time exercise rather than a maintained record; missing the incident-reporting timeframe because ownership of the obligation isn't clearly assigned internally.
Related standards
Expert review
FAQ
Request a Gap Assessment
See exactly where your operational resilience and outsourcing controls stand against FINMA Circular 2023/1.
Request a Gap Assessment →