Operational Risks and Resilience: FINMA Circular 2023/01 in Practice
What FINMA Circular 2023/01 governs
The FINMA Circular 2023/01 'Operational Risks and Resilience - Banks' has been in force since 1 January 2024. It consolidates the previously separate circulars on operational risk and on business continuity into a single rulebook and extends it with the concept of operational resilience.
The scope covers banks under the Banking Act and, analogously, securities firms. For insurers, parallel requirements apply under FINMA Circular 2017/2 and under the supervisory regime of the Insurance Supervision Ordinance; asset managers are addressed via FINMA Circular 2023/2. The Circular provides for a two-year transition period for certain resilience requirements, whose full implementation is therefore expected by 1 January 2026.
In substance, the Circular requires five interlocking building blocks: management of operational risk in the narrow sense, ICT and cyber risks, outsourcing risks, risks affecting critical data, and operational resilience with Impact Tolerances.
Definitions: risk, continuity, resilience
Three terms must be kept distinct, because they imply different control logics:
- Operational risk is the risk of loss resulting from inadequate or failed internal processes, people, systems or external events (analogous to the Basel definition).
- Business continuity (BCM, Business Continuity Management) denotes the ability to continue or restore business operations within tolerable recovery times in a crisis.
- Operational resilience is the ability to maintain critical functions even under significant disruption - including cyber incidents, third-party failures and natural events. It is broader than BCM because, beyond 'recovery', it focuses on 'remaining operational'.
The supervisory authority expects institutions to identify critical functions, map their dependencies, and define Impact Tolerances - that is, the maximum damage or maximum interruption duration that can be accepted before the stability of the institution or of the financial centre must be considered at risk.
Critical functions and Impact Tolerances
At the heart of the Circular is the concept of critical functions. A function is critical where its interruption can cause material harm to customers, other market participants or the financial centre. Examples include payment processing, securities settlement, credit administration, core data management and market-data provision.
For every critical function, Impact Tolerances must be defined - derived from worst-case scenarios and calibrated with quantitative thresholds (RTO, RPO, maximum customer impact, maximum tolerable liquidity outflow). The tolerances must be approved by the board of directors and must be consistent with the business-continuity plans, IT disaster recovery and third-party contracts.
The supervisory authority expects the Impact Tolerances to be tested regularly - not only in technical recovery tests, but in scenario-based exercises combining cyber incidents, third-party failures and pandemic-style personnel shortages.
ICT and cyber risks in the Circular
The Circular explicitly accentuates ICT and cyber risks. Expected are documented ICT risk management, an up-to-date IT asset inventory, effective vulnerability management, a rehearsed crisis organisation, and tests appropriate to the threat landscape.
For the notification of serious cyber incidents, the duty under Art. 29 para. 2 FINMASA applies, specified in FINMA supervisory notice 05/2020 and reinforced by FINMA supervisory notice 03/2024. Since 1 January 2024, the notification duty to BACS under Art. 74a et seq. ISG also applies to operators of critical infrastructure. Both reporting paths must be reflected in the institution's notification concept.
Methodologically, institutions draw on established standards: ISO/IEC 27001:2022 for the management system, ISO/IEC 27005 for risk analyses, NIST CSF for structuring functions, and the CIS Controls for prioritised hardening. TIBER-EU and the DORA TLPT (Threat-Led Penetration Testing) logic (Articles 26-27 DORA) provide the framework for threat-led penetration testing.
Outsourcing and third parties
The governance of outsourcing remains central. In parallel to Circular 2023/01, FINMA Circular 2018/3 'Outsourcing - Banks and Insurers' applies. Both require a complete inventory of material outsourcing arrangements, a risk-based prior assessment, minimum contractual content (audit, information and termination rights), and continuous oversight.
Particular attention is given to concentration risks with cloud providers and shared market service providers, the sub-processor chain, and practical substitutability. Within operational resilience, exit strategies are to be tested and calibrated against consistent Impact Tolerances.
Provider-related evidence - C5 attestation (BSI), ISO/IEC 27001:2022, ISO/IEC 27017/27018, SOC 2 Type II - is consolidated in the supplier file. Methodological guidance on the C5 attestation in the Swiss context is available in the SIDD article on the C5 attestation.
Interface with DORA
For Swiss institutions with EU exposure, Regulation (EU) 2022/2554 (DORA) is relevant; it has been applicable since 17 January 2025. DORA overlaps thematically with FINMA Circular 2023/01, but is more prescriptive in several respects - in particular for incident reporting with harmonised thresholds, for the third-party regime including oversight of critical ICT third-party providers, and for TLPT (Threat-Led Penetration Testing) for systemically relevant institutions.
FINMA is pursuing a pragmatic convergence: organisations operating in DORA-compliant fashion implicitly meet the expectations of the Circular in many points. Those operating purely under the Swiss regime increasingly adopt the DORA vocabulary - Impact Tolerances, threat-led testing, sub-processor visibility - because it is seen as a contemporary benchmark.
A detailed comparison of the two rulebooks is available in the German-language FINMA/DORA pillar at /einblicke/finma-dora-leitfaden/.
Implementation steps and typical pitfalls
A proven implementation grid summarises the requirements in five steps:
- Inventory: capture critical functions, supporting business processes, IT assets, data flows and third parties without gaps.
- Impact Tolerances: define per critical function and have them approved by the board of directors.
- Control architecture: allocate preventive, detective and reactive controls on a risk basis and document their effectiveness.
- Tests: combine recovery, cyber scenarios, third-party failure and crisis communications in scenario-based exercises; schedule threat-led penetration testing for systemically relevant functions.
- Governance and reporting: clear responsibilities, defined escalation paths, regular reporting to the board of directors and FINMA.
Typical pitfalls include incomplete third-party inventories, Impact Tolerances without a traceable derivation, technical recovery tests with no crisis-communications exercise, and lack of consistency between BCM, IT DR and supplier contracts.
How SIDD supports you
SIDD supports Swiss banks and securities firms in implementing FINMA Circular 2023/01. We structure inventories, derive Impact Tolerances, sharpen control architectures, and translate the results into audit-ready evidence for internal audit and supervision.
Our services include building an ISMS to ISO/IEC 27001:2022 as a methodological framework, providing a fractional CISO for ongoing governance, and delivering penetration testing and vulnerability scans for technical verification. A methodological framing of both approaches is provided in our article on pentest vs. vulnerability scan.
Certifications are issued through CIS Cert (Quality Austria Group, ISO/IEC 17021-accredited). Get in touch if you are looking for a structured stocktake on operational resilience.
