Skip to content
TB
TeamBenchResources

FINMA Compliance Documentation for Banks and Financial Institutions in Switzerland

FINMA supervises Switzerland's financial sector with rigorous documentation requirements. Here's what's required across AML, risk management, IT governance, and outsourcing — and how to review.

TeamBench· Content Quality PlatformFebruary 9, 20268 min read

Switzerland's position as the world's leading wealth management centre — managing approximately CHF 7.9 trillion in cross-border assets — comes with regulatory expectations to match. FINMA supervises over 250 banks, 200 insurance companies, and thousands of other financial institutions with a supervisory approach that emphasises risk-based documentation and demonstrated compliance.

FINMA's regulatory framework operates through circulars that set detailed expectations for supervised institutions. Unlike some regulators that prescribe specific documentation formats, FINMA expects institutions to demonstrate compliance through documentation that is proportionate to their size, complexity, and risk profile. This principles-based approach creates flexibility but also uncertainty — institutions must determine what "adequate" documentation looks like for their specific circumstances.

FINMA Regulatory Framework

Key FINMA Circulars

CircularSubjectDocumentation Focus
2017/1Corporate governance — banksBoard and management documentation, risk governance
2023/1Operational risks and resilienceIT governance, cyber risk, business continuity, outsourcing
2016/7Video and online identificationDigital onboarding documentation
2020/1Accounting — banksFinancial reporting documentation
2013/3AuditingAudit documentation requirements
2011/2Capital buffer and capital planningCapital adequacy documentation
2019/2Interest rate risk — banksInterest rate risk management documentation

AML Documentation (AMLA and FINMA AMLO)

Switzerland's Anti-Money Laundering Act (AMLA) and FINMA's Anti-Money Laundering Ordinance (AMLO-FINMA) create extensive documentation requirements:

DocumentRequirement
AML organisational frameworkDocumented AML compliance structure, responsibilities, reporting lines
Risk assessmentInstitutional ML/TF risk assessment covering customers, products, geographies, delivery channels
CDD policies and proceduresCustomer identification, verification, beneficial ownership, business relationship purpose
Enhanced due diligenceEDD procedures for PEPs, high-risk countries, correspondent banking, complex structures
Transaction monitoringMonitoring programme documentation, alert investigation procedures, escalation
Suspicious activity reportingSAR procedures, MROS (Money Laundering Reporting Office Switzerland) filing records
Document retentionCDD and transaction records retained for 10 years after relationship ends
Training programmeAML/CFT training curriculum with attendance records
Internal audit of AMLPeriodic independent review of AML programme effectiveness

CDD Agreement (VSB): FINMA-supervised institutions must comply with the Agreement on the Swiss Banks' Code of Conduct with regard to the Exercise of Due Diligence (VSB). This creates specific documentation requirements for identifying the beneficial owner and the contracting partner.

Risk Management Documentation

DocumentFINMA Expectation
Risk management frameworkBoard-approved framework covering all material risks
Risk appetite statementQuantitative and qualitative parameters for risk-taking
Credit risk policiesLending criteria, counterparty limits, concentration management
Market risk policiesTrading limits, VaR methodology, stress testing
Liquidity risk policiesLiquidity management, contingency funding plan, LCR/NSFR
Operational risk frameworkRisk identification, assessment, monitoring, mitigation
Capital planningICAAP documentation, capital contingency planning
Stress testingScenarios, methodology, results, management actions

IT Governance and Operational Resilience (Circular 2023/1)

FINMA Circular 2023/1 significantly expanded IT and operational resilience documentation requirements:

DocumentRequirement
ICT strategyBoard-approved IT strategy aligned with business strategy
ICT governanceRoles, responsibilities, IT risk management framework
Cybersecurity frameworkComprehensive security documentation covering identification, protection, detection, response, recovery
ICT continuity managementBusiness continuity and disaster recovery for critical IT services
ICT change managementChange procedures, testing, approval documentation
ICT incident managementIncident response procedures, reporting obligations to FINMA
Cloud and outsourcingRisk assessment, due diligence, contractual requirements, exit strategies
Data managementData quality, data governance, data protection documentation
Third-party risk managementAssessment and monitoring of critical ICT service providers

Outsourcing Documentation

FINMA Circular 2018/3 (and its integration into 2023/1) sets specific outsourcing documentation requirements:

DocumentRequirement
Outsourcing policyBoard-approved policy defining outsourcing governance
Risk assessment per arrangementPre-outsourcing risk assessment for each material arrangement
Due diligence recordsProvider assessment documentation
Contractual documentationContracts meeting FINMA requirements (audit rights, data protection, BCP, exit)
Ongoing monitoringPerformance monitoring, SLA tracking, incident reporting
Exit strategyDocumented exit plan for each material outsourcing arrangement
FINMA notificationNotification for material outsourcing of significant functions
Sub-outsourcing documentationAssessment and monitoring of sub-outsourcing by providers

Common FINMA Audit Findings

Finding 1: AML Documentation Gaps

Beneficial ownership identification that doesn't meet VSB requirements, particularly for complex structures (trusts, foundations, nominee arrangements). CDD documentation that was adequate at onboarding but hasn't been updated during the relationship.

Finding 2: Operational Resilience Gaps (Post-Circular 2023/1)

Institutions that haven't updated their IT governance documentation to meet the expanded requirements of Circular 2023/1. Cybersecurity frameworks that don't cover all five NIST functions. Business continuity plans for critical IT services that haven't been tested.

Finding 3: Outsourcing Documentation Deficiencies

Material outsourcing arrangements — particularly cloud services — without adequate risk assessments, contractual protections, or documented exit strategies. FINMA notification requirements not met for significant outsourcing.

Finding 4: Risk Management Documentation Not Proportionate

Risk documentation that is either too generic (doesn't reflect the institution's specific risk profile) or too detailed for the institution's size and complexity (indicating template adoption without adaptation).

Finding 5: Insufficient Board Oversight Documentation

Board minutes that don't demonstrate meaningful discussion of risk issues. Risk reporting to the board that lacks the specificity for effective oversight.

Reviewing FINMA Compliance Documentation

AML Documentation Review Criteria

CriterionWeightWhat to Check
VSB compliance3Beneficial ownership identification meets VSB requirements
CDD completeness3All client files contain required identification, verification, and business purpose
Risk-based approach2AML programme proportionate to the institution's risk profile
Transaction monitoring2Monitoring documented, alerts investigated, effectiveness reviewed
Training and audit1Staff trained, independent AML audit conducted

IT Governance Review Criteria (Circular 2023/1)

CriterionWeightWhat to Check
Cybersecurity coverage3All five NIST functions addressed (identify, protect, detect, respond, recover)
ICT continuity3Critical IT services have documented and tested BCP/DR
Outsourcing compliance2All material IT outsourcing meets FINMA requirements
Incident management2Incident response procedures documented with FINMA reporting provisions
Data management1Data governance and data quality documentation current

Frequently Asked Questions

How does FINMA's supervisory approach differ from EU regulators?

FINMA operates a principles-based, proportionate supervisory approach. Documentation expectations scale with the institution's size, complexity, and risk profile. Unlike the EU's more prescriptive approach, FINMA gives institutions flexibility in how they demonstrate compliance — but expects the chosen approach to be fully documented and evidenced.

What are the consequences of FINMA findings?

FINMA can impose corrective measures, appoint an investigating agent, restrict business activities, revoke licences, or initiate enforcement proceedings. For serious AML failures, criminal proceedings may follow. FINMA publishes enforcement actions — reputational consequences in the Swiss financial centre are severe.

Does documentation need to be in a specific language?

FINMA communicates in German, French, and Italian (Switzerland's three official languages). Documentation should generally be in the relevant official language of the institution's headquarters. For international institutions, FINMA may accept English documentation, but key regulatory submissions should be in an official language.

How has Circular 2023/1 changed documentation requirements?

Circular 2023/1 consolidated and significantly expanded IT and operational resilience requirements. Key additions include: comprehensive cybersecurity framework documentation, ICT continuity management for critical services, enhanced cloud and outsourcing provisions, and mandatory ICT incident reporting to FINMA. Institutions should conduct a gap analysis against the new circular.

Can AI review help with FINMA compliance documentation?

AI review can check documentation for completeness against FINMA circular requirements, verify currency of regulatory references, assess AML documentation for VSB compliance elements, and check consistency across related policies. Regulatory adequacy assessment requires qualified Swiss compliance professionals familiar with FINMA supervisory expectations.

Key Takeaways

  • FINMA's principles-based approach requires proportionate documentation — not one-size-fits-all, but tailored to your institution's size, complexity, and risk profile.
  • AML documentation under AMLA and VSB is the most scrutinised area — beneficial ownership identification and ongoing CDD updates are critical.
  • Circular 2023/1 significantly expanded IT governance requirements — existing documentation likely has gaps in cybersecurity, ICT continuity, and cloud outsourcing.
  • Outsourcing documentation must include risk assessments, contractual protections, and exit strategies for every material arrangement.
  • Board documentation must demonstrate meaningful oversight — risk reporting should enable effective governance, not just inform.
  • AI review checks completeness, currency, and consistency — regulatory adequacy requires qualified Swiss compliance professionals.

This article is for informational purposes only. FINMA regulatory requirements evolve through circulars, guidance, and supervisory practice. Consult a qualified compliance professional or legal adviser for guidance specific to your institution type and regulated activities in Switzerland.

finma-complianceswiss-bankingfinma-circularsamla-switzerlandswiss-financial-regulationfinma-audit

Need consistent content quality across your team?

TeamBench lets you create custom AI reviewers that score content against your specific criteria. Submit content, get instant scored feedback, and improve with one click.

  • Create custom AI reviewers for your brand
  • Score content against your specific criteria
  • Instant feedback, one-click improvement
  • Free to start — no credit card required