FINMA Circular 2023/1 · Editorial explanation

Operational Risks and Resilience of Banks: FINMA Circular 2023/1

In force since 1 January 2024, the circular replaced FINMA Circular 2008/21. This is an editorial explanation of supervisory practice, not an official translation or a standalone source of obligations.

Key takeaways

Key takeaways

This material explains the official publication without reproducing it and is not an official translation or individual advice. Current legislation, cantonal practice and the facts must be checked before application.

01

The board approves the operational-risk framework and tolerance; executive management implements it and provides resources and controls.

02

Requirements are proportionate to size, complexity, structure and risk profile but cover ICT, cyber risk, critical data and continuity.

03

A bank identifies critical functions and disruption tolerances, runs scenario tests and remediates identified gaps.

04

Operational resilience is broader than disaster recovery: the institution must continue critical functions through severe but plausible disruption.

05

The circular replaced FINMA Circular 2008/21; the former document must not be presented as the current supervisory basis.

01

Governance and operational-risk framework

A bank establishes an integrated system to identify, assess, manage and monitor operational risks. The board defines the core framework and risk tolerance, receives comparable reporting and oversees material changes; executive management allocates responsibility, staff and budget. The framework includes independent control functions, systematic risk assessment, indicators and limits, internal events and external data, mitigation and escalation. Proportionality affects depth but does not remove the duty to understand material risks.

02

ICT, cyber risk and critical data

ICT governance covers strategy, architecture, change, operations, legacy systems, incidents and third-party dependencies. Cyber controls address threat and vulnerability identification, protection, detection, response and recovery; material attacks require timely internal escalation and supervisory notification under applicable rules. Critical data are identified by their importance to functions and clients, classified and protected against loss of confidentiality, integrity and availability, including where held by external providers.

03

Continuity and operational resilience

BCM requires business-impact analysis, continuity strategies, response and recovery plans, crisis management, communications and regular testing. For operational resilience, a bank identifies critical functions, maps people, processes, technology, data, premises and third parties, sets disruption tolerances and tests severe but plausible scenarios. Findings are documented and converted into remediation plans. By 2026 the circular's two-year resilience transition had expired, so the framework should be assessed as a current supervisory standard rather than a future programme.

Fedlex · ESTV · FINMA

Official source

This material explains the official publication without reproducing it and is not an official translation or individual advice. Current legislation, cantonal practice and the facts must be checked before application.

Smart Global Capital

Need to apply a Swiss rule to a structure or transaction?

We review classification, federal and cantonal consequences and the banking perimeter, and prepare a documented position.

Discuss the legal position
WAWhatsAppTGTelegram