FINMA Operational Resilience & ICT Risk
Who needs it
Swiss-regulated banks, securities firms, insurers and financial market infrastructures, plus any vendor or service provider they outsource critical functions to, regardless of the vendor's own location.
Key requirements
An ICT risk management framework, business continuity and disaster recovery capability, a maintained outsourcing register, and significant-incident reporting to FINMA within a defined timeframe.
Cyber/privacy implications
Security controls must be demonstrable at the level of individual critical functions and third-party dependencies, not just at the organizational perimeter.
Assessment methodology
Gap assessment against Circular 2023/1, review of the outsourcing register and vendor agreements, and a review of business continuity and resilience test results.
Implementation phases
Assess
Map critical functions and outsourcing relationships against Circular 2023/1 scope.
Remediate
Close control gaps in ICT risk management, business continuity and vendor oversight.
Evidence
Maintain the outsourcing register and resilience test evidence in audit-ready form.
Evidence & documentation requirements
A current outsourcing register, vendor risk assessments, business continuity and disaster recovery test results, and an incident-reporting procedure with defined escalation timelines to FINMA.
Common mistakes
Assuming ISO 27001 certification alone satisfies Circular 2023/1; treating the outsourcing register as a one-time exercise rather than a maintained record; missing the incident-reporting timeframe because ownership of the obligation isn't clearly assigned internally.
Related standards
Expert review
FAQ
Request a Gap Assessment
See exactly where your operational resilience and outsourcing controls stand against FINMA Circular 2023/1.
Request a Gap Assessment →