FINMA Compliance Documentation for Banks and Financial Institutions in Switzerland
FINMA supervises Switzerland's financial sector with rigorous documentation requirements. Here's what's required across AML, risk management, IT governance, and outsourcing — and how to review.
Switzerland's position as the world's leading wealth management centre — managing approximately CHF 7.9 trillion in cross-border assets — comes with regulatory expectations to match. FINMA supervises over 250 banks, 200 insurance companies, and thousands of other financial institutions with a supervisory approach that emphasises risk-based documentation and demonstrated compliance.
FINMA's regulatory framework operates through circulars that set detailed expectations for supervised institutions. Unlike some regulators that prescribe specific documentation formats, FINMA expects institutions to demonstrate compliance through documentation that is proportionate to their size, complexity, and risk profile. This principles-based approach creates flexibility but also uncertainty — institutions must determine what "adequate" documentation looks like for their specific circumstances.
FINMA Regulatory Framework
Key FINMA Circulars
| Circular | Subject | Documentation Focus |
|---|---|---|
| 2017/1 | Corporate governance — banks | Board and management documentation, risk governance |
| 2023/1 | Operational risks and resilience | IT governance, cyber risk, business continuity, outsourcing |
| 2016/7 | Video and online identification | Digital onboarding documentation |
| 2020/1 | Accounting — banks | Financial reporting documentation |
| 2013/3 | Auditing | Audit documentation requirements |
| 2011/2 | Capital buffer and capital planning | Capital adequacy documentation |
| 2019/2 | Interest rate risk — banks | Interest rate risk management documentation |
AML Documentation (AMLA and FINMA AMLO)
Switzerland's Anti-Money Laundering Act (AMLA) and FINMA's Anti-Money Laundering Ordinance (AMLO-FINMA) create extensive documentation requirements:
| Document | Requirement |
|---|---|
| AML organisational framework | Documented AML compliance structure, responsibilities, reporting lines |
| Risk assessment | Institutional ML/TF risk assessment covering customers, products, geographies, delivery channels |
| CDD policies and procedures | Customer identification, verification, beneficial ownership, business relationship purpose |
| Enhanced due diligence | EDD procedures for PEPs, high-risk countries, correspondent banking, complex structures |
| Transaction monitoring | Monitoring programme documentation, alert investigation procedures, escalation |
| Suspicious activity reporting | SAR procedures, MROS (Money Laundering Reporting Office Switzerland) filing records |
| Document retention | CDD and transaction records retained for 10 years after relationship ends |
| Training programme | AML/CFT training curriculum with attendance records |
| Internal audit of AML | Periodic independent review of AML programme effectiveness |
CDD Agreement (VSB): FINMA-supervised institutions must comply with the Agreement on the Swiss Banks' Code of Conduct with regard to the Exercise of Due Diligence (VSB). This creates specific documentation requirements for identifying the beneficial owner and the contracting partner.
Risk Management Documentation
| Document | FINMA Expectation |
|---|---|
| Risk management framework | Board-approved framework covering all material risks |
| Risk appetite statement | Quantitative and qualitative parameters for risk-taking |
| Credit risk policies | Lending criteria, counterparty limits, concentration management |
| Market risk policies | Trading limits, VaR methodology, stress testing |
| Liquidity risk policies | Liquidity management, contingency funding plan, LCR/NSFR |
| Operational risk framework | Risk identification, assessment, monitoring, mitigation |
| Capital planning | ICAAP documentation, capital contingency planning |
| Stress testing | Scenarios, methodology, results, management actions |
IT Governance and Operational Resilience (Circular 2023/1)
FINMA Circular 2023/1 significantly expanded IT and operational resilience documentation requirements:
| Document | Requirement |
|---|---|
| ICT strategy | Board-approved IT strategy aligned with business strategy |
| ICT governance | Roles, responsibilities, IT risk management framework |
| Cybersecurity framework | Comprehensive security documentation covering identification, protection, detection, response, recovery |
| ICT continuity management | Business continuity and disaster recovery for critical IT services |
| ICT change management | Change procedures, testing, approval documentation |
| ICT incident management | Incident response procedures, reporting obligations to FINMA |
| Cloud and outsourcing | Risk assessment, due diligence, contractual requirements, exit strategies |
| Data management | Data quality, data governance, data protection documentation |
| Third-party risk management | Assessment and monitoring of critical ICT service providers |
Outsourcing Documentation
FINMA Circular 2018/3 (and its integration into 2023/1) sets specific outsourcing documentation requirements:
| Document | Requirement |
|---|---|
| Outsourcing policy | Board-approved policy defining outsourcing governance |
| Risk assessment per arrangement | Pre-outsourcing risk assessment for each material arrangement |
| Due diligence records | Provider assessment documentation |
| Contractual documentation | Contracts meeting FINMA requirements (audit rights, data protection, BCP, exit) |
| Ongoing monitoring | Performance monitoring, SLA tracking, incident reporting |
| Exit strategy | Documented exit plan for each material outsourcing arrangement |
| FINMA notification | Notification for material outsourcing of significant functions |
| Sub-outsourcing documentation | Assessment and monitoring of sub-outsourcing by providers |
Common FINMA Audit Findings
Finding 1: AML Documentation Gaps
Beneficial ownership identification that doesn't meet VSB requirements, particularly for complex structures (trusts, foundations, nominee arrangements). CDD documentation that was adequate at onboarding but hasn't been updated during the relationship.
Finding 2: Operational Resilience Gaps (Post-Circular 2023/1)
Institutions that haven't updated their IT governance documentation to meet the expanded requirements of Circular 2023/1. Cybersecurity frameworks that don't cover all five NIST functions. Business continuity plans for critical IT services that haven't been tested.
Finding 3: Outsourcing Documentation Deficiencies
Material outsourcing arrangements — particularly cloud services — without adequate risk assessments, contractual protections, or documented exit strategies. FINMA notification requirements not met for significant outsourcing.
Finding 4: Risk Management Documentation Not Proportionate
Risk documentation that is either too generic (doesn't reflect the institution's specific risk profile) or too detailed for the institution's size and complexity (indicating template adoption without adaptation).
Finding 5: Insufficient Board Oversight Documentation
Board minutes that don't demonstrate meaningful discussion of risk issues. Risk reporting to the board that lacks the specificity for effective oversight.
Reviewing FINMA Compliance Documentation
AML Documentation Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| VSB compliance | 3 | Beneficial ownership identification meets VSB requirements |
| CDD completeness | 3 | All client files contain required identification, verification, and business purpose |
| Risk-based approach | 2 | AML programme proportionate to the institution's risk profile |
| Transaction monitoring | 2 | Monitoring documented, alerts investigated, effectiveness reviewed |
| Training and audit | 1 | Staff trained, independent AML audit conducted |
IT Governance Review Criteria (Circular 2023/1)
| Criterion | Weight | What to Check |
|---|---|---|
| Cybersecurity coverage | 3 | All five NIST functions addressed (identify, protect, detect, respond, recover) |
| ICT continuity | 3 | Critical IT services have documented and tested BCP/DR |
| Outsourcing compliance | 2 | All material IT outsourcing meets FINMA requirements |
| Incident management | 2 | Incident response procedures documented with FINMA reporting provisions |
| Data management | 1 | Data governance and data quality documentation current |
Frequently Asked Questions
How does FINMA's supervisory approach differ from EU regulators?
FINMA operates a principles-based, proportionate supervisory approach. Documentation expectations scale with the institution's size, complexity, and risk profile. Unlike the EU's more prescriptive approach, FINMA gives institutions flexibility in how they demonstrate compliance — but expects the chosen approach to be fully documented and evidenced.
What are the consequences of FINMA findings?
FINMA can impose corrective measures, appoint an investigating agent, restrict business activities, revoke licences, or initiate enforcement proceedings. For serious AML failures, criminal proceedings may follow. FINMA publishes enforcement actions — reputational consequences in the Swiss financial centre are severe.
Does documentation need to be in a specific language?
FINMA communicates in German, French, and Italian (Switzerland's three official languages). Documentation should generally be in the relevant official language of the institution's headquarters. For international institutions, FINMA may accept English documentation, but key regulatory submissions should be in an official language.
How has Circular 2023/1 changed documentation requirements?
Circular 2023/1 consolidated and significantly expanded IT and operational resilience requirements. Key additions include: comprehensive cybersecurity framework documentation, ICT continuity management for critical services, enhanced cloud and outsourcing provisions, and mandatory ICT incident reporting to FINMA. Institutions should conduct a gap analysis against the new circular.
Can AI review help with FINMA compliance documentation?
AI review can check documentation for completeness against FINMA circular requirements, verify currency of regulatory references, assess AML documentation for VSB compliance elements, and check consistency across related policies. Regulatory adequacy assessment requires qualified Swiss compliance professionals familiar with FINMA supervisory expectations.
Key Takeaways
- FINMA's principles-based approach requires proportionate documentation — not one-size-fits-all, but tailored to your institution's size, complexity, and risk profile.
- AML documentation under AMLA and VSB is the most scrutinised area — beneficial ownership identification and ongoing CDD updates are critical.
- Circular 2023/1 significantly expanded IT governance requirements — existing documentation likely has gaps in cybersecurity, ICT continuity, and cloud outsourcing.
- Outsourcing documentation must include risk assessments, contractual protections, and exit strategies for every material arrangement.
- Board documentation must demonstrate meaningful oversight — risk reporting should enable effective governance, not just inform.
- AI review checks completeness, currency, and consistency — regulatory adequacy requires qualified Swiss compliance professionals.
This article is for informational purposes only. FINMA regulatory requirements evolve through circulars, guidance, and supervisory practice. Consult a qualified compliance professional or legal adviser for guidance specific to your institution type and regulated activities in Switzerland.