5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

Switzerland

FINMA Guidance 08/2024 on artificial intelligence: what it is, which instruments actually bind, and what a supervised institution has to implement

On 18 December 2024 FINMA set out seven expectation areas for governance and risk management when using artificial intelligence, applied in proportion to materiality and risk — and the document is a supervisory communication, not a circular. In German it is an Aufsichtsmitteilung, in French a communication sur la surveillance, and in FINMA's own English simply FINMA Guidance 08/2024. English-language coverage calls it the FINMA AI circular with striking regularity; that is wrong, and it is noticed instantly by anyone who works in Swiss supervisory law. The mistake matters less for pedantry than for planning, because the binding requirements reach AI through two other instruments that most AI programmes never open.

Also available in Deutsch Français

How Barzel applies here Start free with BarzelVault

Standing, once: Switzerland is not in the European Union, so the GDPR and the EU AI Act are not the operative instruments for a domestic Swiss institution, and the German and French texts of FINMA's circulars and of federal statutes bind. This page is a working guide for a reader who works in neither language.

What kind of document is FINMA 08/2024?

FINMA Guidance 08/2024, Governance and risk management when using artificial intelligence, dated 18 December 2024. A supervisory communication conveys FINMA's observations and expectations. It is expressly not a circular and does not constitute binding regulation.

Its practical weight is nonetheless high: it describes what FINMA looks at during supervisory reviews, and gives concrete shape to requirements that already follow from binding instruments. FINMA's announcement names the risk categories in view — operational risks and in particular model risks (robustness, correctness, explainability, bias), data risks of security, quality and availability, IT and cyber risks, third-party dependencies, and legal and reputational risks.

Which instruments actually bind?

Three documents, three statuses
InstrumentStatusIn forceRelevance to AI
FINMA Guidance 08/2024 Supervisory communication of expectations 18.12.2024 The seven expectation areas
FINMA Circular 2023/1
Operational risks and resilience — banks
Binding 01.01.2024 ICT risk management, cyber risks, management of critical data, business continuity, operational resilience
FINMA Circular 2018/3
Outsourcing — banks and insurers
Binding 01.04.2018
(version applicable from 01.01.2021)
Every third-party AI solution

For most institutions Circular 2018/3 is the more consequential of the two, because AI is rarely built in house. It requires a materiality test; an inventory of outsourced functions including sub-contractors; a documented risk analysis before the contract is concluded; provider selection and ongoing monitoring; and unrestricted audit and access rights for the institution, its audit firm and FINMA — including where the provider is abroad, in which case those rights must be enforceable there. And it records that the outsourcing institution bears the same responsibility towards FINMA as if it performed the function itself.

How does supervision reach a group entity or a foreign vendor?

This is the part a group function outside Switzerland most often gets wrong, and it turns on a distinction FINMA does not blur. FINMA supervises the licensed Swiss institution. It does not supervise a foreign parent, a group technology function or a software vendor. But Circular 2018/3 reaches all three indirectly, and with force, because the obligation it imposes on the institution can be discharged only with their cooperation. Three practical consequences:

  • A group AI platform is an outsourcing. Where a Swiss subsidiary consumes a model service run by a group entity in London, Frankfurt or New York, that arrangement belongs in the outsourcing inventory with its sub-contractors, and needs a risk analysis dated before the contract. Intra-group provision does not remove it from the regime.
  • Audit rights have to be real where the provider sits. Unrestricted audit and access rights for the institution, its audit firm and FINMA are a contractual requirement whose enforceability abroad must be established, not assumed. A vendor whose standard terms cap audit at an annual questionnaire is not sellable into a supervised Swiss institution without amendment.
  • Responsibility does not move with the workload. The institution answers to FINMA as though it ran the model itself. Procuring an interface abroad changes only the place where that responsibility has to be demonstrated.

For a vendor, the conclusion is commercial rather than legal: the evidence a Swiss institution needs — model and configuration version per operation, data lineage, drift monitoring, audit access — is a procurement gate. FINMA also asks institutions to contact it at an early stage where AI is used in critical processes or to calculate regulatory parameters, which is a step a central AI function outside Switzerland will not know to prompt.

What are the seven expectation areas?

  1. Governance. Central oversight, clearly allocated responsibilities, consistent standards, competent staffing. Where the solution is outsourced, FINMA expects heightened diligence.
  2. Inventory and risk classification. A register of AI applications built on a broad definition of AI, with documented classification criteria. The broad definition is where most inventories stay incomplete: it also catches models not internally treated as AI — scoring rules, classifiers, decision trees embedded in processes for years.
  3. Data quality. Completeness, accuracy, integrity and bias assessment, particularly for historical and unstructured data.
  4. Testing and ongoing monitoring. Validation before deployment and continuously: accuracy, robustness, bias, data drift and exception handling. The continuous half is routinely reduced to a single acceptance sign-off.
  5. Documentation. Purpose, data selection and preparation, model choice, performance metrics, assumptions, limitations and fallback mechanisms.
  6. Explainability. The ability to explain and reproduce results to stakeholders and to supervisory authorities.
  7. Independent review. Separation of development from validation, qualified reviewers, across the whole lifecycle.

Where do agentic systems break expectation area 6?

Area 6 asks institutions to explain and reproduce. For a deterministic model that is tractable: same inputs, same code, same result.

For an agentic system it is not. The same input on the same model can produce a different result, and the model may have been replaced in the interim. Retracing the operation afterwards therefore yields a new decision rather than an explanation of the original one — an agent cannot be audited by repetition. Two requirements follow that go beyond ordinary logging:

  • Version capture. The model and configuration version at the moment of the operation, recorded with the operation itself, not reconstructed afterwards from a deployment log.
  • Input capture. The data the decision actually rested on. Not the entire context — the material that led to the action.

Area 7 — separating development from validation — carries a second reading for agent systems. The control that decides whether an action is permissible must not live in the same model that triggers the action. Otherwise the system validates itself, and anything that influences its context also influences the control. That is an architectural constraint, not a policy one: the threshold has to sit in a layer the agent passes through and cannot reconfigure, which also means it survives a change of model. See traceability for AI agents, approving AI actions before execution and the general treatment in AI governance.

Has FINMA classified AI as a principal risk?

No, and the correction is worth making because the opposite claim circulates widely. The FINMA Risk Monitor 2025 of 17 November 2025 names nine principal risks. The non-financial ones are money laundering, sanctions, outsourcing, cyberattacks and ICT risks. Artificial intelligence is not listed as a separate principal risk.

The actual list is more useful than the myth, because outsourcing and ICT risk are exactly the channels through which AI risk materialises in a supervised institution. Nearly half of reported cyber incidents involved third parties; FINMA calls for more robust controls over the outsourcing of critical functions and flags concentration risk. An AI programme that reports into an existing third-party risk framework is speaking the supervisor's language; a standalone AI workstream is not. The point is filed in the library's register of corrections.

What the survey shows about where institutions stand

From the FINMA survey published on 24 April 2025, covering around 400 institutions with data collected between the end of November 2024 and mid-January 2025: about half use AI or have applications in development, and a further quarter plan deployment within three years. 91 per cent of those already using AI use generative AI, and around half have a formalised AI strategy. The risks named are data quality, data protection, explainability, data security, accuracy and outsourcing. FINMA sums up its supervisory logic as same business, same risks, same rules — technology-neutral supervision.

How does this interact with Swiss data protection law?

The FINMA expectations sit alongside the data protection duties, not in place of them, and the two are enforced by different authorities on different theories.

Where an AI system takes a decision resting exclusively on automated processing that has legal consequences for a person or significantly affects them, Art. 21 of the revised Federal Act on Data Protection (revFADP; DSG / LPD), SR 235.1, imposes a duty to inform and gives a right to review by a natural person. For a lender the most frequent case is the refused application, because the contract exception in Art. 21 para. 3 lit. a applies only where the data subject's request is granted. The threshold for an impact assessment is judged separately under Art. 22. See automated decisions under Art. 21 and the impact assessment under Art. 22.

Two further points where English commentary regularly misstates Swiss law. FADP sanctions are criminal and fall on natural persons, up to CHF 250,000; the undertaking can be ordered to pay only in the alternative and only up to CHF 50,000 under Art. 64 para. 2. The FDPIC (EDÖB / PFPDT) does not levy fines — it issues rulings, and fines are pronounced by cantonal criminal prosecution authorities. And there is no 72-hour breach deadline in Swiss law: Art. 24 FADP requires notification to the FDPIC as soon as possible, and only above a high-risk threshold.

The 24-hour clock belongs to a different statute. Under Art. 74a et seq. of the Information Security Act (ISA; ISG / LSI), SR 128, in force since 1 April 2025, operators of critical infrastructure must report a cyberattack to the NCSC (BACS / OFCS) within 24 hours, with sanctions since 1 October 2025 up to CHF 100,000. That set of operators is narrower than the population FINMA supervises and narrower again than the population the FADP binds. One incident can start both clocks. See cyber incident reporting in Switzerland.

Does a Swiss institution also face the EU AI Act?

Only if it reaches the Union. There is no Swiss AI Act: on 12 February 2025 the Federal Council decided to ratify the Council of Europe Framework Convention on Artificial Intelligence and otherwise regulate sector by sector, expressly declining a horizontal statute on the EU model; a consultation draft was announced for the end of 2026 and none had opened as at 2 September 2026. A Swiss institution that places an AI system on the Union market, or whose system output is intended to be used in the Union, is nonetheless within Regulation (EU) 2024/1689, whose Article 2 applies irrespective of whether the provider is established in the Union or a third country. A purely domestic Swiss institution is not. That single question — does anything reach the EU — decides whether the AI programme runs one framework or two.

Implementation checklist

  1. Build the AI inventory on a broad definition, capturing models nobody internally calls AI.
  2. Document the classification criteria, not merely the classification result.
  3. Carry outsourced and intra-group AI into the outsourcing inventory under Circular 2018/3, sub-contractors included.
  4. Contract for unrestricted audit and access rights and evidence their enforceability abroad.
  5. Run ongoing data-drift monitoring rather than a single acceptance test.
  6. Capture model and configuration version with every operation — the precondition for explainability.
  7. Separate validation from development organisationally, and place the control outside the model it governs.
  8. Document fallback mechanisms and test them.
  9. Screen each application against Art. 21 FADP, with attention to outcomes that can be a refusal.
  10. Contact FINMA early where AI touches critical processes or regulatory parameters.

In practice

BarzelVault supplies what expectation areas 2, 6 and 7 require operationally: an inventory of actions with risk classification, capture of the model and policy version per operation, and a control that sits outside the agent and cannot be reconfigured by it. BarzelOps runs the cross-system workflow with durable state, approval checkpoints and tenant isolation.

How Barzel applies here

Frequently asked questions

Is FINMA 08/2024 binding?

Not as regulation. It is a supervisory communication — Aufsichtsmitteilung / communication sur la surveillance — and not a circular. The binding instruments are FINMA Circulars 2023/1 and 2018/3, both of which reach AI applications.

What are the seven expectation areas?

Governance; inventory and risk classification; data quality; testing and ongoing monitoring; documentation; explainability; independent review.

Has FINMA named AI a principal risk?

No. The Risk Monitor 2025 does not list it as a separate principal risk; the non-financial principal risks are money laundering, sanctions, outsourcing, cyberattacks and ICT risks.

What applies to third-party and intra-group AI?

Circular 2018/3: inventory including sub-contractors, documented risk analysis before contract conclusion, unrestricted audit rights enforceable where the provider sits — and unchanged responsibility towards FINMA.

Is there a Swiss AI Act?

No. The Federal Council adopted a sector-specific approach on 12 February 2025; a consultation draft was announced for the end of 2026, and none had opened as at 2 September 2026.

Where this leads

The seven expectation areas converge on one substantive requirement: it is not enough that a system works. Someone must establish, months later, what it relied on. Until the model version and the input data are captured with the operation, explainability is an intention and independent review a ticked box.

In practice

Permission before the action. Evidence after it.

The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.

FINMA Guidance 08/2024, published 18 December 2024

BarzelVault

The AI action firewall: decide what an agent may do before it does it.

  • Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
  • Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
  • Credential isolation, spend and action limits, and an emergency kill switch.

Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

BarzelOps

Governed workflow automation across the systems that run the business.

  • Durable, idempotent execution: a timeout is retried once, never filed twice.
  • Human approval checkpoints that pause the workflow and resume it.
  • Isolation per entity or client, signed evidence receipts and a portable manifest; HubSpot, Xero, Gmail, Google Drive and Slack.

Free tier: 100 calls a dayPaid plans from $19 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.


Related

Sources

  1. FINMA, FINMA Guidance 08/2024: Governance and risk management when using artificial intelligence, 18 December 2024.
  2. FINMA-Rundschreiben 2023/1, Operationelle Risiken und Resilienz — Banken (German text), in force since 1 January 2024.
  3. FINMA Circular 2018/3, Outsourcing — banks and insurers, version applicable from 1 January 2021. Cited without a link: only volatile archive URLs are available.
  4. FINMA, FINMA survey: artificial intelligence gaining traction at Swiss financial institutions, 24 April 2025.
  5. FINMA, Risk Monitor 2025, 17 November 2025.
  6. Federal Act on Data Protection (FADP; DSG / LPD), SR 235.1, Art. 21, 22 and 24 — binding German text; English translation, fedlex.admin.ch.
  7. Information Security Act (ISA; ISG / LSI), SR 128, Art. 74a et seq. — fedlex.admin.ch; NCSC, Reporting obligation for cyberattacks on critical infrastructures.
  8. Swiss Federal Council, media release of 12 February 2025 on the regulatory approach to artificial intelligence.
  9. Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence, Article 2.

This article is a working guide for English-speaking readers and does not constitute legal or supervisory advice. The binding texts are the German and French ones.