Skip to content
DEEN
Book a call

Industry standard Statutory · Switzerland

FINMA Circular 2023/1 "Operational risks and resilience – banks".

Short answer

FINMA Circular 2023/1 sets out in detail, for Swiss banks under the Banking Act, how operational risks are to be managed - including ICT risk management, cyber risk management and business continuity management. It replaced the earlier Circular 2008/21. IMPORTANT: the title and content of this file come from secondary sources, not from a document examined in full text on finma.ch - the FINMA website could not be technically read in full text in this research. Before external use, the exact wording should be verified on finma.ch.

01 Triggers

When does FINMA Circular 2023/1 apply to you?

FINMA Circular 2023/1 may apply to you if one of these triggers applies. The Regulatory Check tests them against your details.

  • Industry: Financial services (Recommend individual review): If you are a bank or securities firm under the Swiss Banking Act, the FINMA circular on operational risks and resilience applies to you. For other financial institutions (insurers, asset managers), separate circulars exist that were not examined here.
  • Markets: Switzerland (applies if additionally: Industry: Financial services) (Recommend individual review): As a FINMA-supervised institution operating in Switzerland, this circular may be relevant to you.

Exceptions

  • Per a secondary source, the primary addressees are banks under the Banking Act (BankA); for insurers, analogous requirements are said, per the same source, to apply under a separate circular (Circular 2017/02). Both statements were not verified on finma.ch itself.
  • Smaller institutions benefit, per a secondary source, from a simplified application differentiated by supervisory category; the exact design was not examined.

02 Obligations

What does FINMA Circular 2023/1 require?

  • Establish an integrated operational risk management framework.
  • Own ICT risk management with an inventory of critical data and processes.
  • Cyber risk management with threat intelligence and monitoring.
  • Business continuity management (BCM) including cyber resilience.
  • Definition and management of critical functions and critical data ('Critical Data').

03 Evidence

What evidence is needed?

  • Documented operational risk framework.
  • ICT and cyber risk inventory.
  • BCM concept including cyber resilience measures.
  • Evidence of the management of critical functions towards FINMA as part of ongoing supervision.

04 Deadlines

Which deadlines apply?

  1. FINMA Circular 2023/1 entered into force per a secondary source (replacing Circular 2008/21); not verified on finma.ch itself.

Information as of: 24 September 2026. Past dates are grey, upcoming ones highlighted (as of when the page was built).

05 Penalties

What are the consequences of violations?

The circular itself contains no penalty provisions of its own - per FINMA's own description of its supervisory practice (Art. 7(1)(b) FINMASA), FINMA circulars set out in detail the application of financial market legislation and bind FINMA in its application of the law. Breaches of the obligations set out in it can be addressed through FINMA's general supervisory instruments (rulings, measures); the exact instruments were not examined article by article in this research.

06 Related

What is connected with it?

  • Digital Operational Resilience Act (Regulation (EU) 2022/2554): DORA obliges EU financial entities - banks, insurers, investment firms, payment service providers and others - to comply with uniform requirements for ICT risk management, incident reporting, resilience testing and the management of ICT third-party providers.

07 Open

What is still uncertain?

  • CANDIDATE STATUS: as with DORA, per the client's architecture decision this circular has not yet been adopted into the website; no 'Finance' industry page exists. Applicability to individual CH companies has not been conclusively clarified (ARCHITEKTUR-UND-CONTENT.md, item 13).
  • The exact title 'Operational risks and resilience – banks', the entry-into-force date (1 January 2024) and the substantive key points come from a single secondary source (a consultancy), not from the circular itself on finma.ch. The FINMA circular overview page (https://www.finma.ch/de/dokumentation/rundschreiben/) was reached and confirms the general system of circulars, but delivers the specific list of current circulars only via a dynamic programming interface not readable in this research.
  • The statement on an analogous circular for insurers (Circular 2017/02) was not verified.
  • Whether the wording given in the brief, 'Operating risks and resilience – banks', or the wording found here, 'Operational risks and resilience – banks', is the correct official title must be checked directly on finma.ch before publication.

08 Sources

Sources

Information as of: 24 September 2026.

A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.

FAQ Answers

Questions about FINMA Circular 2023/1.

Is this circular already part of the public regulatory check on sacosi.ch?

No. Per the client's architecture decision, it is a candidate: there is no separate 'Finance' industry on the website yet, and inclusion is an open decision (see ARCHITEKTUR-UND-CONTENT.md, item 13).

Why does the information come from secondary sources instead of directly from finma.ch?

The FINMA website loads its circular overview dynamically via JavaScript/AJAX; direct full-text access was not technically possible with the tools available in this research. Before any external publication of this file, the exact wording should be checked on finma.ch.

Does FINMA Circular 2023/1 apply to you?

The Regulatory Check gives an initial assessment. In a conversation, we clarify what really applies in your situation and in which order you address it.

Ivo Schönberner on a lakeside promenade in the morning light