SCRM Supplier Compliance & Risk Management

Home

FINMA circ. 2023/1 · transition periods ended 1 January 2026

Impact tolerance means deciding how long you can manage without it.

The circular requires institutions to identify critical functions, define how long an interruption is tolerable and know the resources they depend on – providers included.

The fully revised circular on operational risk and resilience has applied since 1 January 2024. Its transition periods have expired: inventory requirements from early 2025, operational resilience from early 2026. It addresses banks and, by analogy, securities firms; parallel requirements exist for insurers and asset managers.

Five building blocks interlock: operational risk management, ICT and cyber risk, outsourcing risk, critical data risk and operational resilience with impact tolerances. The supplier angle is not confined to the outsourcing part – a critical function described without its providers’ resources is not described at all.

Who is affected

  • Banks and securities firms under Swiss supervision.
  • Insurers and asset managers through their parallel circulars.
  • IT, data centre and processing providers to those institutions – through contracts and audit rights.
  • Intra-group providers whose failure hits a critical function.

What is required

Critical functions
Determine which functions are critical and name the processes and resources behind them.
Impact tolerance
Define for each critical function how long an interruption is bearable.
Inventory
Categorise and inventory operational risks consistently.
Outsourcing
Monitor outsourcing risks on a risk basis and periodically.
Critical data
Identify and protect critical data holdings, including those held at providers.
Accountability
The board approves risk tolerance; management implements.

How SCRM covers it

Provider mapped to function

Which provider underpins which critical function – the link without which no tolerance can be justified.

Recurring monitoring

Periodic assessments with a result and a date instead of ad-hoc review.

Data locations and audit rights

Checked fields with expiry, not a contract annex on a drive.

Report for the supervisory audit

An extract showing what was assessed and when – precisely what the audit firm asks for.

Frequently asked

How does this relate to the outsourcing circular?

They complement each other. The outsourcing circular governs how an arrangement is entered and steered; the resilience circular asks whether the supported function can withstand an interruption.

We are a provider to an institution. What arrives?

Data on availability, recovery times, subcontractors and data locations – plus audit rights for the institution, its audit firm and the supervisor.

How does it differ from DORA?

Related in substance, separate in law. Serving both areas is easiest with one register whose fields cover both regimes.

As of July 2026. The FINMA circulars in force govern. Not legal advice.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required