2022-12-07
The Swiss Financial Market Supervisory Authority issued Circular 2023/1 to establish supervisory requirements for operational risk management and resilience for banks, securities dealers, and financial groups. The document mandates comprehensive governance structures, including board-approved risk tolerances, robust ICT and cyber risk controls, and defined business continuity plans to protect critical functions. It further requires institutions to define disruption tolerance levels for critical services and report significant ICT incidents and cyber attacks to FINMA within strict timeframes.