Financial services · FINMA resilience & DORA scope

FINMA 2023/01 and DORA, from supervisory duty to audit-ready evidence

With FINMA Circular 2023/01, operational resilience is a supervisory duty for supervised institutions. In parallel, DORA reaches in from the EU, for Swiss institutions usually indirectly via EU branches or contracts with EU-regulated counterparties. We clarify what applies directly and what applies indirectly, close the gaps and keep the evidence so it withstands a review.

legal + security + AI from one partner DE · FR · EN independent, no in-house SOC business
FINMA 2023/01 and DORA compliance for Swiss financial services

For banks, insurers, securities firms, FinTechs and their critical IT providers

FINMA 2023/01 operational resilience
DORA direct or indirect
Gap assessment audit-ready
Critical functions mapping & BCM
CH · EU multilingual DE/FR/EN
Dr. Dominic Staiger

Responsible for this mandate

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

LinkedIn

Operational resilience has become a supervisory duty

FINMA Circular 2023/01 on operational risks and resilience applies to supervised institutions, and DORA reaches in from the EU on top. What actually applies, and to what depth, we verify per institution case by case.

FINMA Circular 2023/01 on operational risks and resilience at banks covers FINMA-supervised institutions, in practice banks, insurers, securities firms and supervised FinTechs. It is in force. At its core the supervisor expects you to know your critical functions, to set a defensible tolerance for their disruption and to show that you can keep these functions running, or restore them, within that tolerance even under stress. Operational resilience is therefore not a peripheral IT topic but a duty at executive and board level.

From the EU, DORA is added, the Regulation on digital operational resilience for the financial sector. It applies in the EU since 17 January 2025 and rests on five pillars: ICT risk management, handling and reporting of ICT-related incidents, testing of digital operational resilience up to threat-led penetration testing, management of ICT third-party risk, and information sharing on cyber threats. For Swiss institutions DORA usually does not apply directly. It takes effect indirectly, for example where you have a branch or subsidiary in the EU, or where you act as an ICT provider to EU-regulated financial entities and their DORA duties flow back to you through contracts.

Whether DORA affects you directly or indirectly cannot be answered in the abstract. It depends on your group structure, your EU touchpoints and your contracts. We verify this delineation per institution case by case before we talk about measures. That way you build only what is actually required and can justify it to reviewers.

  • Identify critical functions and set a defensible tolerance for their disruption, documented and owned by the board
  • Business continuity management and ICT continuity that keep the critical functions within tolerance
  • ICT and cyber risk management with clear roles, protective measures and monitoring
  • Where DORA applies, cover the five pillars: ICT risk management, incident reporting, resilience testing, ICT third-party management and information sharing
  • Determine the scope of DORA, direct versus indirect, per institution and verify case by case

How we make FINMA and DORA audit-ready

We start with the question that drives everything: are you in scope of DORA at all, and if so directly or indirectly? On that basis we build a gap assessment, a mapping of critical functions and a roadmap, with the evidence maintained in the Priverion Platform.

First we run an applicability assessment. We review your group structure, your EU branches and subsidiaries, your contracts with EU-regulated financial entities and your role as a possible ICT provider. From this it follows whether DORA affects you directly or indirectly and which duties reach you through contracts. We record this classification with reasons so you can evidence it to the supervisor and to counterparties.

Then comes the FINMA/DORA gap assessment. We measure your current state against the expectations of Circular 2023/01 and, where applicable, against the five DORA pillars. The result is a prioritised gap list with a rating, not a raw finding. In parallel we map your critical and important functions onto the supporting processes, systems and ICT third parties, because without that mapping a disruption tolerance can neither be set nor evidenced.

On that basis we set up the governance and the documentation. We clarify roles and responsibilities across the executive board, the board of directors and the specialist functions, write out the resilience and ICT risk policies and ensure that decisions, tolerances and tests are documented. We maintain registers, records and measures in the Priverion Platform so the evidence sits maintained and exportable in one place rather than scattered across spreadsheets.

Finally you receive a prioritised roadmap with clear ownership and realistic timelines. Operational building blocks such as 24/7 monitoring, managed incident response or advanced threat-led red teaming we do not run ourselves. Where such building blocks are required, we coordinate them with specialised partners, while legal, governance, readiness as well as pentests and vulnerability scans sit with us.

Why SIDD for FINMA and DORA

Resilience in the financial sector combines supervisory law, ICT security and increasingly AI in one dossier. We cover exactly that combination from one partner, independent and multilingual.

Legal, security and AI from one partner

The supervisory interpretation of FINMA 2023/01 and DORA is led by doctorate-level lawyers, the ICT risk and the testing by an in-house technical team under an ISO 27001 Lead Auditor. So the legal classification and the technical measures carry the same logic.

Audit-ready evidence in tooling

We maintain the register of critical functions, ICT third parties, measures and decisions in the Priverion Platform. If the supervisor or internal audit asks, the evidence is ready, maintained and exportable, instead of scattered across spreadsheets.

Fixed-fee entry

You start with a fixed-fee FINMA/DORA Applicability & Gap Assessment with a board-ready report and a prioritised roadmap. Then you decide on an ongoing advisory mandate, without committing in advance.

We know our limits

We are a legally led governance, compliance, readiness and testing partner. We coordinate 24/7 monitoring, managed incident response and advanced red teaming with specialised partners. Pentests and vulnerability scans we run ourselves. That keeps our advice independent.

AI governance depth

If you use AI in credit, fraud detection or client processes, we classify the obligations from the EU AI Act and the FINMA expectations for your models. With three dedicated AI services we tie resilience and AI governance into one dossier.

Multilingual & independent

We advise in German, French and English, fitting institutions in German-speaking Switzerland, French-speaking Switzerland and with EU exposure. Because we do not sell an in-house SOC, our recommendations stay independent and focused on your audit-readiness.

Two routes to audit-ready resilience

Regulatory Advisory

on request retainer, on request

The ongoing operation: someone who maintains the resilience governance, keeps the registers current and supports you through reviews and regulatory change.

  • Ongoing maintenance of the resilience and ICT risk governance and documentation
  • Updating of the registers of critical functions and ICT third parties in the Priverion Platform
  • Support in FINMA reviews, internal audit and counterparty requests
  • Monitoring of regulatory developments at FINMA and DORA, with case-by-case classification
  • Point of contact for the executive board and board of directors in DE, FR or EN

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your FINMA/DORA assessment, concretely: LexCommand maps your critical functions to the exact duties in FINMA Circular 2023/01 and the five DORA pillars, with a source for each requirement, and makes the direct and indirect applicability for your institution traceable and evidenced.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions

Does DORA apply to us at all as a Swiss institution?

For Swiss institutions DORA usually does not apply directly. It can reach you indirectly, for example through a branch or subsidiary in the EU or through contracts with EU-regulated financial entities whose DORA duties flow back to you. Whether there is a direct or indirect link in your case depends on group structure and contracts. We verify this per institution case by case and record the classification with reasons.

By when do we need to have this in place?

FINMA Circular 2023/01 is in force and applies to supervised institutions. DORA applies in the EU since 17 January 2025. Which concrete timelines are decisive for you depends on your scope and your contracts and can shift with supervisory practice. We anchor the deadlines that apply to you in the mandate and verify them case by case.

Is DORA mandatory in Switzerland?

DORA is EU law and is not in force as such in Switzerland. For Swiss institutions it usually becomes binding indirectly, through EU branches, EU subsidiaries or contractual duties towards EU-regulated financial entities. Binding and in force, by contrast, is FINMA Circular 2023/01 on operational resilience for supervised institutions. We clearly separate what you must meet from Swiss supervisory law and what from EU exposure.

How does this relate to ISO 27001?

An ISO 27001 ISMS delivers a large part of the ICT and cyber foundations that FINMA and DORA expect, such as risk management, measures and monitoring. But it does not cover everything. Resilience-specific topics such as critical functions, disruption tolerances, resilience testing and ICT third-party management go beyond it. We use an existing ISMS as a foundation and add the supervisory requirements instead of building parallel structures. The ISO certificate itself is issued by an accredited certification body, we consult and prepare.

Do you work in French and English?

Yes. We advise throughout in German, French and English and produce the documentation in the language you need, relevant for institutions in German-speaking Switzerland, French-speaking Switzerland and with EU exposure. Reports for the executive board and the board of directors we deliver in your body's working language.

Matching next steps

FINMA and DORA tie closely to ICT risk management, the management of your ICT third parties and the reporting of major incidents:

Ready to make FINMA and DORA audit-ready?

We clarify your DORA scope, measure the gaps against FINMA 2023/01 and deliver a prioritised roadmap with a board-ready report, with the evidence held in the Priverion Platform.