# FINMA Circular 2023/1 "Operational risks and resilience – banks"

> FINMA Circular 2023/1 sets out in detail, for Swiss banks under the Banking Act, how operational risks are to be managed - including ICT risk management, cyber risk management and business continuity management. It replaced the earlier Circular 2008/21. IMPORTANT: the title and content of this file come from secondary sources, not from a document examined in full text on finma.ch - the FINMA website could not be technically read in full text in this research. Before external use, the exact wording should be verified on finma.ch.

- Type: Industry standard, Statutory
- Scope: Switzerland
- As of: 24 September 2026
- Page: https://sacosi.ch/en/norms/finma_rundschreiben
- Regulatory Check: https://sacosi.ch/en/regulation#normencheck

## When does FINMA Circular 2023/1 apply to you?

- Industry: Financial services (Recommend individual review): If you are a bank or securities firm under the Swiss Banking Act, the FINMA circular on operational risks and resilience applies to you. For other financial institutions (insurers, asset managers), separate circulars exist that were not examined here.
- Markets: Switzerland (applies if additionally: Industry: Financial services) (Recommend individual review): As a FINMA-supervised institution operating in Switzerland, this circular may be relevant to you.

## Exceptions

- Per a secondary source, the primary addressees are banks under the Banking Act (BankA); for insurers, analogous requirements are said, per the same source, to apply under a separate circular (Circular 2017/02). Both statements were not verified on finma.ch itself.
- Smaller institutions benefit, per a secondary source, from a simplified application differentiated by supervisory category; the exact design was not examined.

## Obligations

- Establish an integrated operational risk management framework.
- Own ICT risk management with an inventory of critical data and processes.
- Cyber risk management with threat intelligence and monitoring.
- Business continuity management (BCM) including cyber resilience.
- Definition and management of critical functions and critical data ('Critical Data').

## Evidence

- Documented operational risk framework.
- ICT and cyber risk inventory.
- BCM concept including cyber resilience measures.
- Evidence of the management of critical functions towards FINMA as part of ongoing supervision.

## Deadlines

- 1 January 2024: FINMA Circular 2023/1 entered into force per a secondary source (replacing Circular 2008/21); not verified on finma.ch itself.

## Penalties

The circular itself contains no penalty provisions of its own - per FINMA's own description of its supervisory practice (Art. 7(1)(b) FINMASA), FINMA circulars set out in detail the application of financial market legislation and bind FINMA in its application of the law. Breaches of the obligations set out in it can be addressed through FINMA's general supervisory instruments (rulings, measures); the exact instruments were not examined article by article in this research.

## Frequently asked questions

**Is this circular already part of the public regulatory check on sacosi.ch?**
No. Per the client's architecture decision, it is a candidate: there is no separate 'Finance' industry on the website yet, and inclusion is an open decision (see ARCHITEKTUR-UND-CONTENT.md, item 13).

**Why does the information come from secondary sources instead of directly from finma.ch?**
The FINMA website loads its circular overview dynamically via JavaScript/AJAX; direct full-text access was not technically possible with the tools available in this research. Before any external publication of this file, the exact wording should be checked on finma.ch.

## Open points of the research

- CANDIDATE STATUS: as with DORA, per the client's architecture decision this circular has not yet been adopted into the website; no 'Finance' industry page exists. Applicability to individual CH companies has not been conclusively clarified (ARCHITEKTUR-UND-CONTENT.md, item 13).
- The exact title 'Operational risks and resilience – banks', the entry-into-force date (1 January 2024) and the substantive key points come from a single secondary source (a consultancy), not from the circular itself on finma.ch. The FINMA circular overview page (https://www.finma.ch/de/dokumentation/rundschreiben/) was reached and confirms the general system of circulars, but delivers the specific list of current circulars only via a dynamic programming interface not readable in this research.
- The statement on an analogous circular for insurers (Circular 2017/02) was not verified.
- Whether the wording given in the brief, 'Operating risks and resilience – banks', or the wording found here, 'Operational risks and resilience – banks', is the correct official title must be checked directly on finma.ch before publication.

## Sources

- [FINMA & DORA 2026, Resilienz für Finanzinstitute (nennt FINMA-RS 2023/1 Titel, Adressaten und Kerninhalte)](https://www.sidd.swiss/einblicke/finma-dora-leitfaden/), SIDD Swiss (Beratungsunternehmen, Sekundärquelle), retrieved 24 September 2026
- [Rundschreiben – Aufsichtspraxis der FINMA (Übersichtsseite, Rundschreiben-Systematik)](https://www.finma.ch/de/dokumentation/rundschreiben/), Eidgenössische Finanzmarktaufsicht (FINMA), retrieved 24 September 2026

---
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
Source: SACOSI, Situational Awareness Consulting by Ivo Schönberner (https://sacosi.ch).
