FINMA

FINMA Circ. 2023/1: what banks really need to prove

BeeLink Team·Aug 27, 2026 10 min

FINMA Circular 2023/1 "Operational risks and resilience — banks" replaces Circular 2008/21 and raises the bar on ICT risk management, cyber resilience, and business continuity.

The 4 pillars to document

  • Mapping of critical services and their dependencies (people, data, IT, third parties)
  • ICT risk management: identification, assessment, treatment, monitoring
  • Cyber resilience: detection, response, recovery, regular testing
  • Operational continuity: BIA, tested plans, impact tolerance thresholds

Typical evidence expected

  • Dated and version-controlled register of critical services
  • Minutes of quarterly risk committee meetings
  • Penetration test and continuity test reports
  • List of critical third parties + annual assessments
  • Incident register with root cause analysis

BeeLink automatically structures this evidence in the FINMA module and generates an Auditor Pack in one click, ready to send to your auditor.

Ready to structure your compliance?

BeeLink centralizes your frameworks, questionnaires, policies and audit evidence in a single interface.

Try for free