Swiss AI Resource
← Back to home

FINMA expectations for AI governance

Last verified:

The German version is canonical; translations may differ.

This translation is an LLM draft and has not yet been human-reviewed.

What FINMA Guidance 08/2024 expects from supervised institutions on governance and risk management when using artificial intelligence.

On 18 December 2024, the Swiss Financial Market Supervisory Authority (FINMA) published Guidance 08/2024 on governance and risk management when using artificial intelligence. Switzerland has no AI-specific financial market statute; FINMA relies on the existing technology-neutral, principles-based requirements for effective governance and risk management.

The guidance is addressed to supervised institutions. For other sectors it is not a binding standard — but a useful orientation framework when banks, insurers, or asset managers procure or deploy AI.

Core message

Institutions that use AI should actively consider the impact on their risk profile and align governance, risk management, and control systems accordingly. The benchmark is the institution's size, complexity, structure, and risk profile, as well as the materiality of applications and the likelihood that risks materialise.

Observed risk areas

According to FINMA, risks arise mainly in:

  • operational risks, in particular model risks (robustness, correctness, bias, explainability);
  • IT and cyber risks;
  • growing dependence on third parties (hardware, models, cloud) in a concentrated market;
  • legal and reputational risks;
  • unclear allocation of responsibilities in decentralised development and hard-to-explain systems.

What FINMA examines in supervision (selection)

Governance

Central steering, clear responsibilities for development, implementation, monitoring, and use, testing requirements, documentation standards, training. For outsourcing: additional tests, controls, contractual arrangements on responsibility and liability, and assessment of third-party capabilities.

Inventory and risk classification

A sufficiently broad definition of AI, a complete inventory, and consistent criteria for applications that need particular attention because of materiality. FINMA has critically observed definitions that are too narrow in order to capture «only the big risks».

Data quality

Requirements and controls for completeness, correctness, and integrity of data; securing availability and access. For purchased solutions, limited influence on training data is often a known risk.

Testing and ongoing monitoring

Tests of accuracy, robustness, stability, and where relevant bias; predefined performance indicators; detection of data drift; analysis of cases where outputs were manually corrected or ignored; fallback considerations.

Documentation and explainability

For material applications: purpose, data selection, model choice, performance measures, assumptions, limits, tests, controls, and fallback. Results must be traceable and plausibility-checkable for critical decisions.

Independent review

For material applications: an objective, informed, and unbiased opinion on adequacy and reliability — separate from development.

Practical takeaways for procurement

Even if you are not yourself FINMA-supervised, FINMA clients typically ask:

  1. Is there an AI inventory with risk class?
  2. Who is owner for model, data, and operations?
  3. Which tests and monitoring thresholds are documented?
  4. How is third-party risk (cloud LLM, API) covered contractually and operationally?
  5. Can decisions be explained to customers, audit, and supervisors?

Disclaimer

This page is informational and not legal or supervisory advice. Binding are the FINMA guidance and the financial market rules applicable to your institution.

Sources

Last verified:

This page is for information only and is not legal advice. For specific projects, consult qualified professionals.