FINMA Circular 2018/3 · Editorial explanation

Outsourcing by Swiss Financial Institutions: FINMA Circular 2018/3

A current supervisory circular incorporating the amendment of 4 November 2020. It explains FINMA practice for its addressees and does not displace legislation, licensing conditions or the institution's own responsibility.

Key takeaways

Key takeaways

This material explains the official publication without reproducing it and is not an official translation or individual advice. Current legislation, cantonal practice and the facts must be checked before application.

01

Material outsourcing is determined by function and risk, not by the contract label or type of provider.

02

The institution maintains a current inventory, selects and monitors the provider and retains sufficient expertise to control the risk.

03

Responsibility to FINMA and clients is not transferred to the provider; auditors and FINMA need effective information and inspection rights.

04

The agreement must address services, security, subcontracting, control, audit, termination and return or deletion of data.

05

Foreign outsourcing requires advance review of information access, Swiss recovery and resolution, data protection and enforceability.

01

Scope and materiality

The circular applies to the addressees identified in its table, including banks, insurers and selected FinIA institutions. Outsourcing exists where an independent provider performs all or part of a function on an ongoing and autonomous basis that the institution would otherwise perform itself. For banks and relevant financial institutions, a function is material where compliance with financial-market-law objectives and requirements significantly depends on it; insurers also consider business-plan and core-function rules. Intragroup delegation is not automatically outside the regime.

02

Governance, oversight and contract

The institution records outsourced functions and providers, including material subcontractors, assigns internal responsibility and regularly assesses performance and risk. Selection requires review of the provider's professional, financial and staffing capacity and concentration scenarios. Responsibility for proper business conduct remains with the institution. The written agreement must enable instruction and control, impose security and incident duties, address material subcontracting, preserve audit rights and support an orderly termination and transfer of the service.

03

Audit, data and foreign providers

The institution, its regulatory auditor and FINMA must be able to obtain information and inspect the outsourced function without obstruction; contracts with providers and subcontractors must confer the necessary rights. Information security applies throughout the lifecycle, while client-data processing must align with banking secrecy and data-protection law. For foreign locations, the institution must demonstrate continued FINMA and auditor access, availability of information in Switzerland and compatibility with continuity, recovery and resolution requirements.

Fedlex · ESTV · FINMA

Official source

This material explains the official publication without reproducing it and is not an official translation or individual advice. Current legislation, cantonal practice and the facts must be checked before application.

Smart Global Capital

Need to apply a Swiss rule to a structure or transaction?

We review classification, federal and cantonal consequences and the banking perimeter, and prepare a documented position.

Discuss the legal position
WAWhatsAppTGTelegram