Financial services sector · compliance & operational resilience

Operational resilience for financial services, from FINMA to DORA

Operational resilience and ICT/cyber governance have become a supervisory duty for financial institutions. FINMA Circular 2023/01 demands resilient operations, DORA reaches in from the EU, and the cyber-reporting duty runs in hours when it counts. SIDD makes these duties audit-ready, with legal, security and AI depth from one partner, multilingual and independent.

legal + security + AI from one partner DE · FR · EN independent, no in-house SOC business
Security and compliance for financial services

For banks, insurers, securities firms, FinTechs, asset managers and their critical IT providers

Legally led Dr. iur. · CIPP/E
ISO 27001 / ISMS consulting & readiness
DORA & FINMA Circ. 2023/01 · ICT risk
Pentest & resilience tests evidence for the regulator
CH · EU multilingual DE/FR/EN
Philipp Staiger

Responsible for this mandate

Philipp Staiger

M.Sc., MIT Sloan Fellow · Lead Auditor ISO 27001 (BSI)

Leads ISO 27001 and ISMS projects in healthcare from the scope workshop to stage-2 audit support, the interface to management, IT, data protection and the external certification body.

LinkedIn

Operational resilience has become a supervisory duty

What was long treated as an operational matter is now subject to supervision. FINMA and DORA demand demonstrable operational resilience and managed ICT and cyber governance.

With FINMA Circular 2023/01 on operational risks and resilience the regulator made clear that institutions must keep their critical functions running even through severe disruption. In parallel, DORA reaches in from the EU: whoever has EU branches or subsidiaries, or contracts with EU-regulated financial entities, may be caught indirectly. Whether DORA applies directly or indirectly must be checked per institution.

More than a fine is at stake. An interrupted core function, an unmanaged cyber incident or a failed IT provider hits customers, reputation and licence at once. The regulator expects risks, measures and tests to be documented and presentable when reviewed. Audit-readiness is therefore not a by-product but the goal.

These duties cannot be solved from a single discipline. They combine law, technical security and increasingly AI governance. That is exactly the combination we cover from one partner, and we maintain the evidence so it stands up to the regulator.

  • Protection and recovery of critical functions under FINMA Circular 2023/01
  • ICT risk management and cyber governance, domestically and towards DORA
  • Management of third parties and critical IT providers under FINMA Circular 2018/03
  • Reporting of serious cyber incidents within a short deadline, backed by prepared processes
  • Resilience tests up to scenario-based and threat-led testing

The finance compliance map at a glance

Orientation, not legal advice. What actually applies depends on your licence, your business model and your EU ties. We verify scope and deadlines case by case, and some timelines are still politically in motion.

RegulationWhat it means for financial institutionsTimingStatus
FINMA Circ. 2023/01 (operational risks & resilience)Identification of critical functions, tolerance levels, business continuity and recovery, documented and audit-readyin forceFINMA-supervised institutions
DORA (EU)ICT risk management, incident reporting, resilience testing and a third-party register, for Swiss institutions usually indirect via EU tiesapplies in the EU since 17 January 2025direct EU / indirect CH, verify case by case
FINMA Circ. 2018/03 (outsourcing, banks & insurers)Properly govern the outsourcing of material functions, manage providers, secure audit and instruction rightsin forcemandatory
ISO 27001 / 27002A certified ISMS as recognised evidence of ICT and information security towards the regulator, auditors and counterpartiesmarket-drivenmarket standard / evidence
FINMA cyber-reporting dutyReporting of serious cyber incidents to FINMA, in practice within around 24 hours of detectionaround 24 hours after detectionsupervisory practice, verify case by case
EU AI Act (AI in finance)Governance, transparency and possibly high-risk obligations, for example in creditworthiness assessment or insurance risk scoringstaggered 2025 to 2027, under revision (Digital Omnibus)verify case by case
nFADP & GDPRProtection of customer and employee data, records, measures and notification routes, domestically and towards the EUin forcemandatory

Our focus areas for financial services

Dive into the topic your next review is currently focused on:

Why SIDD for financial services

Operational resilience combines law, technical security and AI in a single supervisory duty. We cover exactly that combination from one partner.

Legal, security and AI from one partner

Regulation and contracts are led by doctorate-level lawyers with CIPP/E, the ISMS, pentests and resilience tests by an in-house technical team under an ISO 27001 Lead Auditor. So legal and technical evidence fits together before the regulator.

Independent, no in-house SOC

We are a legally led governance, compliance, readiness and testing partner. We coordinate 24/7 monitoring, managed incident response and advanced threat-led testing with specialised partners. That keeps our recommendations independent.

Multilingual DE/FR/EN

We advise throughout in German, French and English, fitting institutions in German-speaking Switzerland, French-speaking Switzerland and with EU ties. We deliver supervisory documents, contracts and tests in the language of your stakeholders.

Audit-ready evidence in the platform

We maintain risks, registers, measures and tests in the Swiss Priverion Platform. If the regulator, an auditor or a counterparty asks, the evidence is ready, maintained and exportable.

Fixed-fee entry

You start with a fixed-fee resilience baseline assessment with a board-ready report and a prioritised roadmap, then decide on an ongoing mandate.

FINMA and DORA depth

We know the interplay of FINMA Circular 2023/01, outsourcing under 2018/03, the cyber-reporting duty and DORA, and we determine what applies to your institution directly or indirectly instead of applying templates.

Experience with regulated organisations

For an established Swiss manufacturer (Pilatus Aircraft) we took on the role of external data protection officer and mapped data protection in the Swiss Priverion Platform: records, measures and evidence maintained in one place. This approach transfers directly to regulated, audit-facing institutions where risks, registers and tests must be presentable at any time.

We do not claim specific bank or FINMA mandates. What we contribute is a proven method: translate regulatory duties into a clear framework, maintain the evidence in an audit-ready place and keep it current repeatably. That is exactly what financial institutions need to not only assert operational resilience but evidence it.

  • External mandate as a fixed point of contact for a regulated organisation
  • Records, measures and evidence maintained in the Priverion Platform
  • An approach that transfers to audit-facing financial institutions

From baseline assessment to resilience

Baseline assessment & gap analysis

A fixed-fee assessment of your posture against FINMA Circular 2023/01, outsourcing, the cyber-reporting duty and the DORA ties relevant to you, with a prioritised roadmap and a board-ready report.

Build the framework & evidence

ICT risk framework, ISMS readiness, the outsourcing and third-party register, plus the technical and organisational measures, depending on what your reviews demand.

Tests, reporting routes & governance

Vulnerability scan, pentest and resilience tests, prepared cyber-reporting routes to FINMA, plus managed ICT and cyber governance, advanced testing coordinated with partners.

Make it repeatable in the Priverion Platform

Risks, registers, measures and test results stay current in the Priverion Platform so every further review is served fast and audit-ready.

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your FINMA and DORA readiness, concretely: LexCommand backs every resilience requirement with the exact provision in FINMA Circular 2023/01 and the DORA articles, and maps overlapping duties across FINMA, DORA, ISO 27001 and the revised FADP in one crosswalk, so your roadmap rests on retrievable sources rather than judgement calls.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions

Does DORA apply to us as a Swiss institution?

DORA applies in the EU since 17 January 2025. For Swiss institutions it usually applies indirectly, for example via EU branches or subsidiaries or via contracts with EU-regulated financial entities that pass down DORA duties. Whether DORA applies to you directly or indirectly we verify case by case and align your framework accordingly.

Do we need ISO 27001?

ISO 27001 is not mandatory for every institution, but it is a market standard and recognised evidence of ICT and information security towards the regulator, auditors and counterparties. A certification-ready ISMS evidences many FINMA and DORA requirements at once. We advise and prepare the readiness; the certificate is issued by an accredited certification body, not by SIDD.

Are you a managed-SOC provider?

No. We are a legally led governance, compliance, readiness and testing partner. We run pentests and vulnerability scans ourselves. We coordinate 24/7 monitoring, managed incident response and advanced threat-led testing with specialised partners, which keeps our advice independent.

We are a small asset manager, is it worth it?

Especially then. The duties on operational resilience and ICT risk also apply to smaller licensed institutions, only the resources are tighter. We size the effort to your scale and risk profile, start with what a review addresses first and build the rest step by step.

Do you handle the FINMA report in a real incident?

We set up the notification process and templates in advance and support you in a real case with the cyber report to FINMA within the short deadline. However, we do not run a 24/7 SOC or managed incident response. Ongoing detection and response is handled by your internal functions or specialised partners, with whom we coordinate.

Do you work in French and English?

Yes. We advise throughout in German, French and English and produce supervisory documents, contracts and test reports in the language of your stakeholders, relevant for institutions in German-speaking Switzerland, French-speaking Switzerland and with EU ties.

Ready for audit-ready operational resilience?

We assess your posture against FINMA Circular 2023/01, outsourcing, the cyber-reporting duty and the DORA ties relevant to you, with a board-ready report and a prioritised roadmap. Go deeper in the FINMA/DORA guide.