Guide
FINMA Circ. 2023/1 for non-lawyers
A plain-language breakdown of the operational risks and resilience circular.
FINMA replaced Circular 2008/21 with 2023/1 to align Switzerland with international standards (BCBS 239, DORA). Here's the essentials.
The 4 objectives
- Manage operational risks
- Ensure ICT and cyber resilience
- Guarantee continuity of critical services
- Oversee critical third parties
What an auditor will look for
- Up-to-date register of critical services
- Evidence of annual tests (BCP, cyber, DR)
- Third-party dependency analysis
- Periodic reporting to the board
Use this resource in BeeLink
Create your organization and import this template into your compliance workspace in one click.
Create an accountIn the same category
Getting started with ISO 27001 in 30 days
A concrete, week-by-week plan to lay the foundations of an ISO 27001:2022-compliant ISMS.
nFADP: what really changes
The 12 structural changes between the old FADP (1992) and the new Act (2023).
DORA: mapping your ICT third parties
The register to produce, criticality criteria, and contractual requirements.