Compliance · Switzerland
Swiss Financial Market Supervisory Authority Circular 2023/1, operational risks and resilience

FINMA Operational Resilience & ICT Risk

Plain-English definition

FINMA is the Swiss financial regulator. FINMA Circular 2023/1 sets out how Swiss-regulated banks, securities firms, insurers and financial market infrastructures must manage operational risk, including ICT and cyber risk, business continuity, and oversight of outsourced service providers. If you serve a Swiss-regulated financial institution, including as a vendor, these obligations apply to your relationship with them.

Applies to Swiss-regulated financial institutions directly, and flows down contractually to their vendors and service providers, including those outside Switzerland.

Who needs it

Swiss-regulated banks, securities firms, insurers and financial market infrastructures, plus any vendor or service provider they outsource critical functions to, regardless of the vendor's own location.

Key requirements

An ICT risk management framework, business continuity and disaster recovery capability, a maintained outsourcing register, and significant-incident reporting to FINMA within a defined timeframe.

Cyber/privacy implications

Security controls must be demonstrable at the level of individual critical functions and third-party dependencies, not just at the organizational perimeter.

Assessment methodology

Gap assessment against Circular 2023/1, review of the outsourcing register and vendor agreements, and a review of business continuity and resilience test results.

Implementation phases

01
Assess

Map critical functions and outsourcing relationships against Circular 2023/1 scope.

02
Remediate

Close control gaps in ICT risk management, business continuity and vendor oversight.

03
Evidence

Maintain the outsourcing register and resilience test evidence in audit-ready form.

Evidence & documentation requirements

A current outsourcing register, vendor risk assessments, business continuity and disaster recovery test results, and an incident-reporting procedure with defined escalation timelines to FINMA.

Common mistakes

Assuming ISO 27001 certification alone satisfies Circular 2023/1; treating the outsourcing register as a one-time exercise rather than a maintained record; missing the incident-reporting timeframe because ownership of the obligation isn't clearly assigned internally.

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

Does this apply to us if we're not based in Switzerland?
Yes, if you provide outsourced services to a Swiss-regulated financial institution. The obligation is contractual, flowing down from the regulated institution to its vendors, wherever those vendors are based.
How is this different from DORA?
DORA is the EU's comparable operational-resilience regulation for financial entities. The intent is similar, but the regulator, jurisdiction and specific requirements differ, so compliance with one does not automatically satisfy the other.

Request a Gap Assessment

See exactly where your operational resilience and outsourcing controls stand against FINMA Circular 2023/1.

Request a Gap Assessment →