AI Governance for Swiss Financial Operators

From untracked tooling to certified control.

The Problem

Artificial intelligence is already operating inside Swiss financial firms. Portfolio screening, research synthesis, client drafting, reconciliation — AI tools now touch functions that carry regulatory consequences.

The Federal Financial Market Supervisory Authority FINMA documented this reality in its 2025 survey of approximately 400 supervised institutions: roughly half already deploy AI, a further quarter is designing deployment, and generative AI dominates the use cases. Yet only half of the deploying institutions maintain a formal AI strategy, and existing governance frameworks were built around data protection — not AI. FINMA Guidance 08/2024 closed the methodological gap by setting explicit expectations: inventory of AI deployments, risk classification, data quality control, testing and monitoring, documentation, explainability, independent review.

The consequence is a structural gap between expectation and evidence. Deployments accumulate without inventory. Risk classifications remain informal. Oversight is documented nowhere an auditor can reach.

The Swiss regulatory framework for AI is under active development. What is already settled is the supervisory principle: same business, same risks, same rules.

The Stakeholders

The gap does not distribute evenly. It concentrates where supervision is thinnest and proof is hardest to produce.

Single family offices operate outside direct FINMA supervision — their regulatory confrontation is not with the regulator but with correspondent banks and counterparties that demand demonstrable governance. Multi family offices managing third-party assets are licensed portfolio managers under the Financial Institutions Act and supervised through a supervisory organization; for them the gap narrows, but the evidentiary burden toward counterparties is identical. Asset managers answer to FINMA licensing and outsourcing rules, where AI-supported processes already fall within supervised functions. Fiduciaries operate under the supervision of recognized supervisory organizations — SO-FIT and the member organizations of OAR — where AI adoption has outrun internal control structures faster than anywhere else in the sector.

The common denominator: every one of these operators must produce evidence of AI governance to a party entitled to demand it. Few can.

The Thesis

AI usage does not need to be stopped. It needs to be governed within the operator's existing compliance architecture.

ISO 37301 provides the certified perimeter. Its clauses absorb AI as a subject of compliance management: clause 4.6 subjects AI deployments to formal risk assessment; clause 8.2 embeds operational controls around them; clauses 9.1.4 and 9.1.5 impose reporting and record-keeping on compliance performance; clause 5.3.2 places oversight with the compliance function; clause 7.2 extends competence requirements to the personnel operating the tools. Deployed AI enters the management system the same way any other outsourced or technology-dependent process does: named, assessed, controlled.

This is not a parallel framework. It is the operator's existing compliance system extended to cover what has already entered the firm.

The Output

The engagement produces three verifiable artifacts:

The AI Registry

A complete inventory of AI deployments across the operator's functions, aligned with the inventory and risk classification expectations set out in FINMA Guidance 08/2024.

The Clause Mapping Matrix

Each deployment traced to the ISO 37301 clauses that govern it, producing a defensible correspondence between what the firm runs and what the certificate covers.

The Certification-Ready Audit Pack

Documentation assembled for the accredited certifier's audit, so AI usage is presented as evidence of control rather than exposure.

The organization certifies ISO 37301 with AI within the scope — a position held by no Swiss financial operator today, and a differentiating probative profile toward correspondent banks, counterparties and supervisory organizations alike.

Read The Framework →