FINMA circulars on outsourcing and operational risk
You may outsource. The responsibility stays with you.
FINMA requires supervised institutions to inventory material outsourcing, document provider selection and monitor providers continuously – sub-outsourcing included.
The supervisor has treated outsourcing as a distinct risk for years. The relevant sources are the outsourcing circular for banks and insurers and the requirements on operational risk and resilience. The thread is the same: material functions may be outsourced, the institution’s responsibility remains.
For providers that is the flip side. Serving an institution means granting access and audit rights to the institution, its audit firm and the supervisor, disclosing sub-outsourcing and supporting contingency planning. A provider who cannot contract for that drops out of procurement.
Who is affected
- Banks, securities firms and insurers under Swiss supervision.
- Their IT, data centre and processing providers, including abroad.
- Intra-group providers – group-internal outsourcing is still outsourcing.
- Liechtenstein institutions facing comparable requirements from their supervisor.
What is required
- Materiality
- Assess and document which outsourcing concerns material functions.
- Inventory
- Maintain a current register of all material outsourcing.
- Selection
- Select and instruct providers carefully and document their suitability.
- Sub-outsourcing
- Know and govern sub-outsourcing, not merely permit it.
- Audit rights
- Secure access and audit rights for the institution, its audit firm and the supervisor.
- Exit
- Plan termination and repatriation before they are needed.
How SCRM covers it
Inventory-ready structure
Arrangement, supported function, materiality and location as fields rather than prose.
Sub-outsourcing
The chain behind the provider as part of the record.
Contract attributes
Audit rights, notice periods and data locations checked and with expiry.
Monitoring on a cycle
Recurring assessments with a result, not with good intentions.
Frequently asked
Is intra-group outsourcing still outsourcing?
As a rule yes. Requirements can be applied proportionately but do not disappear because the provider belongs to the same group.
We are a provider, not supervised. Does it concern us?
Not as an addressee of supervision, very much as a counterparty. The requirements arrive as clauses – audit rights, notification duties, disclosure of subcontractors.
How does this relate to DORA?
Related in substance, separate in law. Serving both areas is easiest with one register covering the fields of both regimes.
As of July 2026. The FINMA circulars in force govern; verify before relying on this. Not legal advice.