Financial sector · ISO 27001 as evidence base for FINMA & DORA
ISO 27001 as the implementation backbone and evidence base for FINMA and DORA
Supervisors and counterparties expect supervised institutions to run a certified or certification-ready information-security management system. An ISO 27001 ISMS gives you a single control framework that maps to large parts of the FINMA operational-resilience requirements and the DORA ICT-risk duties. Instead of running three frameworks in parallel, you operate one system and use it to demonstrate compliance to examiners and counterparties alike. SIDD builds the ISMS, maps the controls and prepares the certification through an accredited body.
one framework for FINMA + DORADE · FR · ENcertification by accredited body
For banks, insurers, securities firms, FinTechs, asset managers and their ICT providers
ISO 27001 / 27002
build & readiness
Control mapping
ISO → FINMA · DORA
Operational resilience
FINMA Circ. 2023/01
Internal audits
certification readiness
CH · EU
multilingual DE/FR/EN
Responsible for this mandate
Philipp Staiger
M.Sc., MIT Sloan Fellow · Lead Auditor ISO 27001 (BSI)
Leads ISO 27001 and ISMS projects in healthcare from the scope workshop to stage-2 audit support, the interface to management, IT, data protection and the external certification body.
Why an ISO 27001 ISMS becomes the backbone in the financial sector
Supervisors and counterparties require financial institutions to run a demonstrably governed information-security management system. ISO 27001 provides the recognised framework for this, and a maintained ISMS is at the same time the evidence base for FINMA and DORA.
Operational resilience and ICT risk management have moved in the financial sector from good practice to a supervisory duty. FINMA Circular 2023/01 on operational risks and resilience applies to FINMA-supervised institutions. For many Swiss houses DORA is added on top, the EU Digital Operational Resilience Act, which has applied in the EU since 17 January 2025. For Swiss institutions DORA usually applies indirectly, through EU branches and subsidiaries or through contracts with EU-regulated financial entities. Whether DORA applies directly or indirectly must be checked per institution.
These duties overlap strongly but are phrased in different texts. Anyone who implements FINMA resilience, DORA ICT risk and data protection separately builds duplicate structures and loses the overview in an audit. An ISO 27001 ISMS resolves this: you run one management system with one set of policies, controls and evidence, and map the same controls to the different regulatory requirements. That lowers the effort and makes the examination connectable.
The ISO 27001 certification itself is issued by an accredited certification body, not by SIDD. We advise and prepare the certification readiness, run internal audits and accompany you up to and through the external certification audit. For many institutions a certification-ready, cleanly mapped ISMS is already the decisive lever in the supervisory dialogue, even without a formal certificate.
A single control framework to ISO 27001 and ISO 27002 instead of separately maintained silos
Control mapping from ISO 27001 to FINMA resilience and DORA ICT-risk duties, documented audit-ready
Certification readiness through internal audits and management review, certificate by an accredited body
Policies, registers and measures maintained in one place as evidence base for supervisors and counterparties
What an ISO 27001 ISMS provides evidence for
Orientation, not legal advice. What actually applies depends on your licence, your size and your EU links. We verify scope and applicability case by case, and some timelines are still politically in motion.
Requirement
How ISO 27001 contributes
Timing
Status
FINMA Circ. 2023/01 operational risks and resilience
ICT, cyber and resilience controls from the ISMS cover large parts of the expected governance, risk steering and recovery
in force
FINMA-supervised institutions
DORA (EU)
The ISMS ICT-risk framework, control set and evidence serve large parts of the DORA pillars on ICT risk and security
EU since 17 Jan 2025
CH usually indirect, verify per institution
FINMA Circ. 2018/03 outsourcing
The ISMS supplier and third-party controls support the governance of material outsourcing and ICT providers
in force
banks & insurers
FINMA cyber-attack reporting duty
The ISMS incident processes and detection controls support reporting within about 24 hours of detection
about 24 hours after detection
FINMA supervisory practice, soft
nFADP (CH) & GDPR (EU)
Controls on confidentiality, access and technical measures help carry the data-protection duties, complemented by the legal data-protection foundation
in force
mandatory
EU AI Act (AI in the institution)
The ISMS governance and control structures form the frame into which AI risk management and model governance fit
staggered 2025 to 2027, under revision (Digital Omnibus)
verify case by case
How we build your ISMS and map it to FINMA and DORA
We turn ISO 27001 not into another framework alongside the supervisory duties, but into the shared backbone. One ISMS that covers the regulatory requirements instead of running in parallel to them.
We start with scoping: which business areas, systems and locations belong in the scope of the ISMS, aligned with your licence, your critical functions and your EU links. On this basis we build the ISMS to ISO 27001 and ISO 27002: information-security policy, roles and responsibilities, risk methodology, statement of applicability and the set of policies and controls. Where building blocks already exist, we adopt them and close only the gaps.
At the centre sit the gap assessment and the control mapping. We assess your maturity against ISO 27001 and place the ISO controls against the requirements of FINMA Circular 2023/01 on operational resilience and the DORA ICT-risk duties. The result is a mapping table that shows for each control which regulatory requirement it covers and where additional, sector-specific measures are needed, for example on critical functions, recovery objectives or the third-party register.
Before certification we run internal audits and a management review and close the findings identified. Then we accompany you through the external certification audit, which an accredited certification body carries out. The certificate is issued by that body, not by SIDD. Pentests and vulnerability scans, which evidence many controls technically, are carried out by our own technical team. Operational ongoing tasks such as 24/7 monitoring or managed incident response we coordinate with specialised partners when needed.
After certification the ISMS does not run by itself. On request we continue to operate it in an ongoing mandate: keep risks current, monitor controls, plan internal audits, prepare the management review and accompany the certification body's surveillance audits. Policies, the risk and control registers as well as measures and evidence we maintain in the Priverion Platform, so the evidence base for examiners and counterparties is current and exportable at any time.
Why SIDD for your ISO 27001 ISMS in the financial sector
An ISMS meant to hold up before FINMA and towards DORA counterparties needs legal classification and technical depth at once. We deliver exactly that combination from one partner.
Legal and security from one partner
The regulatory classification of FINMA resilience and DORA is led by doctorate-level lawyers, the ISMS and the technical controls by an in-house technical team under an ISO 27001 Lead Auditor. So the control mapping and the legal reading fit together.
One system for several duties
We build the ISMS so that it serves both the FINMA resilience and the DORA ICT-risk duties at once. Instead of maintaining three frameworks in parallel, you run one control system with an audit-ready mapping table.
Certification readiness cleanly separated
We advise, build and audit internally, the certificate is issued by an accredited certification body. This clear separation preserves the independence of the certification and is part of what supervisors and counterparties expect.
Technical evidence from an in-house team
Many ISMS controls only become credible through technical tests. Pentests and vulnerability scans are carried out by our own technical team. Operational ongoing tasks such as 24/7 monitoring or managed incident response we coordinate with specialised partners.
Audit-ready evidence in tooling
Policies, the risk and control registers, measures and audit evidence we maintain in the Priverion Platform. If the supervisor, internal audit or a counterparty asks, the evidence base is maintained and exportable.
Multilingual & independent
We advise in German, French and English, fitting institutions in Switzerland and with EU links. Because we do not sell an in-house SOC, our recommendations on controls and partners stay independent and focused on your audit-readiness.
Two routes to an audit-ready ISMS
ISO 27001 readiness (financial sector)
Fixed fee
The one-off build of your ISMS up to certification readiness, mapped to FINMA and DORA and ready for the accredited certification body.
ISMS scoping and build to ISO 27001 and ISO 27002, aligned with your licence and critical functions
Gap assessment against ISO 27001 with a prioritised list of measures
Control mapping from ISO 27001 to FINMA Circ. 2023/01 and DORA ICT-risk duties as an audit-ready table
Internal audits, management review and accompaniment through the external certification audit
Policies, statement of applicability, risk and control registers maintained in the Priverion Platform
The ongoing operation of the ISMS after certification: someone who keeps risks current, monitors controls and guides you through the surveillance audits.
External ISMS lead or vCISO as a fixed point of contact for management and supervisors
Ongoing maintenance of the risk and control registers, measures and evidence in the Priverion Platform
Planning and running internal audits as well as preparing the management review
Accompaniment of the surveillance and recertification audits of the accredited certification body
Maintenance of the control mapping when FINMA or DORA requirements change
LexCMD
Our tool: LexCommand
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your ISMS in the financial sector, concretely: LexCommand fills the Statement of Applicability and Annex A evidence with sourced content and mirrors each ISO 27001 control onto the matching FINMA and DORA requirements, so a certification basis also demonstrably carries the supervisory duties.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions
Do we strictly need an ISO 27001 certificate for FINMA and DORA?
Neither FINMA Circular 2023/01 nor DORA requires a formal ISO 27001 certificate. Both, however, expect a demonstrably governed ICT-risk and resilience management. ISO 27001 is the established way to build and evidence that. Many institutions start with a certification-ready, cleanly mapped ISMS and decide on the formal certificate later. Whether and when certification is worthwhile we clarify case by case.
Does an ISO 27001 ISMS fully cover the DORA requirements?
Not fully, but to a large extent. DORA's ICT-risk framework and security controls overlap strongly with ISO 27001. Certain DORA topics, however, need sector-specific additions, for example the register of ICT third parties, the classification and reporting of ICT incidents or advanced resilience testing. Our control mapping shows exactly what the ISMS covers and where additional measures are needed. Whether DORA applies to you directly or indirectly we check per institution.
Does SIDD issue the ISO 27001 certificate?
No. The certificate is issued by an accredited certification body, which must be independent of the consulting and build team. SIDD advises, builds the ISMS, runs internal audits and prepares you for the certification audit. This clear separation preserves the independence of the certification.
We already have some policies and controls, do we need to start over?
No. We begin with a gap assessment that captures your existing maturity against ISO 27001. Existing policies, risk registers and controls we adopt and close only the gaps in a targeted way. That saves effort and builds on what already holds.
Do you also take on the ongoing operation of the ISMS?
Yes. In the ISMS-operation retainer or as a vCISO we keep risks current, monitor the controls, plan the internal audits, prepare the management review and accompany you through the surveillance and recertification audits. Operational ongoing tasks such as 24/7 monitoring or managed incident response we coordinate with specialised partners, we do not run an in-house SOC.
Do you work in French and English?
Yes. We advise throughout in German, French and English and run ISMS documentation, mapping and audits in your house's language, relevant for institutions in German-speaking and French-speaking Switzerland and with international links.
Matching next steps
An ISO 27001 ISMS ties closely to ICT risk management and ongoing governance:
Ready to build an ISMS that carries FINMA and DORA at once?
We build your ISO 27001 ISMS up to certification readiness, map the controls to FINMA and DORA and continue to operate it on request. We verify scope and applicability case by case.