On 18 December 2024, the Swiss Financial Market Supervisory Authority (FINMA) published Guidance 08/2024 on governance and risk management when using artificial intelligence. Switzerland has no AI-specific financial market statute; FINMA relies on the existing technology-neutral, principles-based requirements for effective governance and risk management.
The guidance is addressed to supervised institutions. For other sectors it is not a binding standard — but a useful orientation framework when banks, insurers, or asset managers procure or deploy AI.
Core message
Institutions that use AI should actively consider the impact on their risk profile and align governance, risk management, and control systems accordingly. The benchmark is the institution's size, complexity, structure, and risk profile, as well as the materiality of applications and the likelihood that risks materialise.
Observed risk areas
According to FINMA, risks arise mainly in:
- operational risks, in particular model risks (robustness, correctness, bias, explainability);
- IT and cyber risks;
- growing dependence on third parties (hardware, models, cloud) in a concentrated market;
- legal and reputational risks;
- unclear allocation of responsibilities in decentralised development and hard-to-explain systems.
What FINMA examines in supervision (selection)
Governance
Central steering, clear responsibilities for development, implementation, monitoring, and use, testing requirements, documentation standards, training. For outsourcing: additional tests, controls, contractual arrangements on responsibility and liability, and assessment of third-party capabilities.
Inventory and risk classification
A sufficiently broad definition of AI, a complete inventory, and consistent criteria for applications that need particular attention because of materiality. FINMA has critically observed definitions that are too narrow in order to capture «only the big risks».
Data quality
Requirements and controls for completeness, correctness, and integrity of data; securing availability and access. For purchased solutions, limited influence on training data is often a known risk.
Testing and ongoing monitoring
Tests of accuracy, robustness, stability, and where relevant bias; predefined performance indicators; detection of data drift; analysis of cases where outputs were manually corrected or ignored; fallback considerations.
Documentation and explainability
For material applications: purpose, data selection, model choice, performance measures, assumptions, limits, tests, controls, and fallback. Results must be traceable and plausibility-checkable for critical decisions.
Independent review
For material applications: an objective, informed, and unbiased opinion on adequacy and reliability — separate from development.
Practical takeaways for procurement
Even if you are not yourself FINMA-supervised, FINMA clients typically ask:
- Is there an AI inventory with risk class?
- Who is owner for model, data, and operations?
- Which tests and monitoring thresholds are documented?
- How is third-party risk (cloud LLM, API) covered contractually and operationally?
- Can decisions be explained to customers, audit, and supervisors?
Disclaimer
This page is informational and not legal or supervisory advice. Binding are the FINMA guidance and the financial market rules applicable to your institution.