Financial sector · ISO 27001 as evidence base for FINMA & DORA

ISO 27001 as the implementation backbone and evidence base for FINMA and DORA

Supervisors and counterparties expect supervised institutions to run a certified or certification-ready information-security management system. An ISO 27001 ISMS gives you a single control framework that maps to large parts of the FINMA operational-resilience requirements and the DORA ICT-risk duties. Instead of running three frameworks in parallel, you operate one system and use it to demonstrate compliance to examiners and counterparties alike. SIDD builds the ISMS, maps the controls and prepares the certification through an accredited body.

one framework for FINMA + DORA DE · FR · EN certification by accredited body
ISO 27001 ISMS as evidence base for FINMA and DORA at financial institutions

For banks, insurers, securities firms, FinTechs, asset managers and their ICT providers

ISO 27001 / 27002 build & readiness
Control mapping ISO → FINMA · DORA
Operational resilience FINMA Circ. 2023/01
Internal audits certification readiness
CH · EU multilingual DE/FR/EN
Philipp Staiger

Responsible for this mandate

Philipp Staiger

M.Sc., MIT Sloan Fellow · Lead Auditor ISO 27001 (BSI)

Leads ISO 27001 and ISMS projects in healthcare from the scope workshop to stage-2 audit support, the interface to management, IT, data protection and the external certification body.

LinkedIn

Why an ISO 27001 ISMS becomes the backbone in the financial sector

Supervisors and counterparties require financial institutions to run a demonstrably governed information-security management system. ISO 27001 provides the recognised framework for this, and a maintained ISMS is at the same time the evidence base for FINMA and DORA.

Operational resilience and ICT risk management have moved in the financial sector from good practice to a supervisory duty. FINMA Circular 2023/01 on operational risks and resilience applies to FINMA-supervised institutions. For many Swiss houses DORA is added on top, the EU Digital Operational Resilience Act, which has applied in the EU since 17 January 2025. For Swiss institutions DORA usually applies indirectly, through EU branches and subsidiaries or through contracts with EU-regulated financial entities. Whether DORA applies directly or indirectly must be checked per institution.

These duties overlap strongly but are phrased in different texts. Anyone who implements FINMA resilience, DORA ICT risk and data protection separately builds duplicate structures and loses the overview in an audit. An ISO 27001 ISMS resolves this: you run one management system with one set of policies, controls and evidence, and map the same controls to the different regulatory requirements. That lowers the effort and makes the examination connectable.

The ISO 27001 certification itself is issued by an accredited certification body, not by SIDD. We advise and prepare the certification readiness, run internal audits and accompany you up to and through the external certification audit. For many institutions a certification-ready, cleanly mapped ISMS is already the decisive lever in the supervisory dialogue, even without a formal certificate.

  • A single control framework to ISO 27001 and ISO 27002 instead of separately maintained silos
  • Control mapping from ISO 27001 to FINMA resilience and DORA ICT-risk duties, documented audit-ready
  • Certification readiness through internal audits and management review, certificate by an accredited body
  • Policies, registers and measures maintained in one place as evidence base for supervisors and counterparties

What an ISO 27001 ISMS provides evidence for

Orientation, not legal advice. What actually applies depends on your licence, your size and your EU links. We verify scope and applicability case by case, and some timelines are still politically in motion.

RequirementHow ISO 27001 contributesTimingStatus
FINMA Circ. 2023/01 operational risks and resilienceICT, cyber and resilience controls from the ISMS cover large parts of the expected governance, risk steering and recoveryin forceFINMA-supervised institutions
DORA (EU)The ISMS ICT-risk framework, control set and evidence serve large parts of the DORA pillars on ICT risk and securityEU since 17 Jan 2025CH usually indirect, verify per institution
FINMA Circ. 2018/03 outsourcingThe ISMS supplier and third-party controls support the governance of material outsourcing and ICT providersin forcebanks & insurers
FINMA cyber-attack reporting dutyThe ISMS incident processes and detection controls support reporting within about 24 hours of detectionabout 24 hours after detectionFINMA supervisory practice, soft
nFADP (CH) & GDPR (EU)Controls on confidentiality, access and technical measures help carry the data-protection duties, complemented by the legal data-protection foundationin forcemandatory
EU AI Act (AI in the institution)The ISMS governance and control structures form the frame into which AI risk management and model governance fitstaggered 2025 to 2027, under revision (Digital Omnibus)verify case by case

How we build your ISMS and map it to FINMA and DORA

We turn ISO 27001 not into another framework alongside the supervisory duties, but into the shared backbone. One ISMS that covers the regulatory requirements instead of running in parallel to them.

We start with scoping: which business areas, systems and locations belong in the scope of the ISMS, aligned with your licence, your critical functions and your EU links. On this basis we build the ISMS to ISO 27001 and ISO 27002: information-security policy, roles and responsibilities, risk methodology, statement of applicability and the set of policies and controls. Where building blocks already exist, we adopt them and close only the gaps.

At the centre sit the gap assessment and the control mapping. We assess your maturity against ISO 27001 and place the ISO controls against the requirements of FINMA Circular 2023/01 on operational resilience and the DORA ICT-risk duties. The result is a mapping table that shows for each control which regulatory requirement it covers and where additional, sector-specific measures are needed, for example on critical functions, recovery objectives or the third-party register.

Before certification we run internal audits and a management review and close the findings identified. Then we accompany you through the external certification audit, which an accredited certification body carries out. The certificate is issued by that body, not by SIDD. Pentests and vulnerability scans, which evidence many controls technically, are carried out by our own technical team. Operational ongoing tasks such as 24/7 monitoring or managed incident response we coordinate with specialised partners when needed.

After certification the ISMS does not run by itself. On request we continue to operate it in an ongoing mandate: keep risks current, monitor controls, plan internal audits, prepare the management review and accompany the certification body's surveillance audits. Policies, the risk and control registers as well as measures and evidence we maintain in the Priverion Platform, so the evidence base for examiners and counterparties is current and exportable at any time.

Why SIDD for your ISO 27001 ISMS in the financial sector

An ISMS meant to hold up before FINMA and towards DORA counterparties needs legal classification and technical depth at once. We deliver exactly that combination from one partner.

Legal and security from one partner

The regulatory classification of FINMA resilience and DORA is led by doctorate-level lawyers, the ISMS and the technical controls by an in-house technical team under an ISO 27001 Lead Auditor. So the control mapping and the legal reading fit together.

One system for several duties

We build the ISMS so that it serves both the FINMA resilience and the DORA ICT-risk duties at once. Instead of maintaining three frameworks in parallel, you run one control system with an audit-ready mapping table.

Certification readiness cleanly separated

We advise, build and audit internally, the certificate is issued by an accredited certification body. This clear separation preserves the independence of the certification and is part of what supervisors and counterparties expect.

Technical evidence from an in-house team

Many ISMS controls only become credible through technical tests. Pentests and vulnerability scans are carried out by our own technical team. Operational ongoing tasks such as 24/7 monitoring or managed incident response we coordinate with specialised partners.

Audit-ready evidence in tooling

Policies, the risk and control registers, measures and audit evidence we maintain in the Priverion Platform. If the supervisor, internal audit or a counterparty asks, the evidence base is maintained and exportable.

Multilingual & independent

We advise in German, French and English, fitting institutions in Switzerland and with EU links. Because we do not sell an in-house SOC, our recommendations on controls and partners stay independent and focused on your audit-readiness.

Two routes to an audit-ready ISMS

ISMS operation / vCISO

on request retainer, on request

The ongoing operation of the ISMS after certification: someone who keeps risks current, monitors controls and guides you through the surveillance audits.

  • External ISMS lead or vCISO as a fixed point of contact for management and supervisors
  • Ongoing maintenance of the risk and control registers, measures and evidence in the Priverion Platform
  • Planning and running internal audits as well as preparing the management review
  • Accompaniment of the surveillance and recertification audits of the accredited certification body
  • Maintenance of the control mapping when FINMA or DORA requirements change

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your ISMS in the financial sector, concretely: LexCommand fills the Statement of Applicability and Annex A evidence with sourced content and mirrors each ISO 27001 control onto the matching FINMA and DORA requirements, so a certification basis also demonstrably carries the supervisory duties.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions

Do we strictly need an ISO 27001 certificate for FINMA and DORA?

Neither FINMA Circular 2023/01 nor DORA requires a formal ISO 27001 certificate. Both, however, expect a demonstrably governed ICT-risk and resilience management. ISO 27001 is the established way to build and evidence that. Many institutions start with a certification-ready, cleanly mapped ISMS and decide on the formal certificate later. Whether and when certification is worthwhile we clarify case by case.

Does an ISO 27001 ISMS fully cover the DORA requirements?

Not fully, but to a large extent. DORA's ICT-risk framework and security controls overlap strongly with ISO 27001. Certain DORA topics, however, need sector-specific additions, for example the register of ICT third parties, the classification and reporting of ICT incidents or advanced resilience testing. Our control mapping shows exactly what the ISMS covers and where additional measures are needed. Whether DORA applies to you directly or indirectly we check per institution.

Does SIDD issue the ISO 27001 certificate?

No. The certificate is issued by an accredited certification body, which must be independent of the consulting and build team. SIDD advises, builds the ISMS, runs internal audits and prepares you for the certification audit. This clear separation preserves the independence of the certification.

We already have some policies and controls, do we need to start over?

No. We begin with a gap assessment that captures your existing maturity against ISO 27001. Existing policies, risk registers and controls we adopt and close only the gaps in a targeted way. That saves effort and builds on what already holds.

Do you also take on the ongoing operation of the ISMS?

Yes. In the ISMS-operation retainer or as a vCISO we keep risks current, monitor the controls, plan the internal audits, prepare the management review and accompany you through the surveillance and recertification audits. Operational ongoing tasks such as 24/7 monitoring or managed incident response we coordinate with specialised partners, we do not run an in-house SOC.

Do you work in French and English?

Yes. We advise throughout in German, French and English and run ISMS documentation, mapping and audits in your house's language, relevant for institutions in German-speaking and French-speaking Switzerland and with international links.

Matching next steps

An ISO 27001 ISMS ties closely to ICT risk management and ongoing governance:

Ready to build an ISMS that carries FINMA and DORA at once?

We build your ISO 27001 ISMS up to certification readiness, map the controls to FINMA and DORA and continue to operate it on request. We verify scope and applicability case by case.