Guide

FINMA Circ. 2023/1 for non-lawyers

A plain-language breakdown of the operational risks and resilience circular.

FINMA replaced Circular 2008/21 with 2023/1 to align Switzerland with international standards (BCBS 239, DORA). Here's the essentials.

The 4 objectives

  • Manage operational risks
  • Ensure ICT and cyber resilience
  • Guarantee continuity of critical services
  • Oversee critical third parties

What an auditor will look for

  • Up-to-date register of critical services
  • Evidence of annual tests (BCP, cyber, DR)
  • Third-party dependency analysis
  • Periodic reporting to the board

Use this resource in BeeLink

Create your organization and import this template into your compliance workspace in one click.

Create an account