Swiss regulation, governance and GRC work

Plain English. No legal register. No filler.

The second line of defence is where risk and compliance sit: between the business that owns the risk and the audit that checks it. This is written from there. What Swiss information security regulation actually requires, and what the work itself is actually like.

FINMA Circular 2023/1 Reviewed September 2026
Regulation

What "Operational Risks and Resilience" actually means for your bank

FINMA expects boards to define, in advance, exactly how much disruption each critical function can tolerate — and to prove it under a realistic scenario, not a tabletop walkthrough.