Switzerland - AI Governance Guidelines (08/2024)

FINMA Guidance 08/2024: Governance and risk management when using artificial intelligence

Switzerland

RAI-CH-NA-FG0GRXX-2024
Effective: December 18, 2024
In Force(In Force)
GuidelineGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

FINMA Guidance 08/2024 (published 18 December 2024) provides supervisory observations and expectations for supervised financial institutions in Switzerland on governance and risk management when using artificial intelligence (AI). It emphasises a technology‑neutral, risk‑based approach covering governance, inventories and risk classification, data quality, testing and monitoring, documentation, explainability and independent review.

Overview

FINMA Guidance 08/2024, published on 18 December 2024, consolidates supervisory observations on the use of artificial intelligence (AI) by supervised financial institutions in Switzerland and sets out FINMA’s expectations for governance and risk management. The Guidance is technology‑neutral and principle‑based: it does not introduce an AI‑specific statute but explains how existing prudential, operational and supervisory requirements apply where institutions use AI. FINMA highlights operational and model risks (robustness, correctness, explainability and bias), data quality and availability issues, IT/cyber vulnerabilities, third‑party concentration risks, and legal/reputational exposures. The document aims to help institutions identify, assess, monitor and manage AI risks proportionately to the materiality, complexity and autonomy of AI applications. The Guidance also points supervised entities to international work on AI risk management, notably by the Financial Stability Board and the OECD, and encourages early engagement with FINMA for critical AI uses. For the full text see FINMA Guidance 08/2024 (PDF) and the press announcement at FINMA news (18 Dec 2024).

Definitions

FINMA emphasises a broad, practical definition of AI: rather than limiting the term to recent generative models, supervised institutions should adopt an inclusive definition that captures any modelled system that infers from inputs to generate outputs (predictions, recommendations, decisions or content) influencing processes or persons. The Guidance refers to the OECD’s updated definition of an AI system and explanatory memorandum to inform identification and inventory efforts. Institutions should document what they consider an AI application, the data types used (structured/unstructured), the model family (statistical, machine learning, deep learning, LLMs), the system’s degree of autonomy and adaptivity, and whether outputs affect regulatory compliance, financial outcomes, or client interests. This inclusive approach reduces the risk that legacy or traditional models with similar vulnerabilities are excluded from oversight (see the OECD memorandum at OECD explanatory memorandum).

Governance and Institutional Framework

FINMA observed decentralised AI development and scattered responsibilities across many supervised institutions. To remedy this, it expects institutions with many or significant AI applications to implement central AI governance (a central function or committee) accountable to senior management and the board. This governance should set policies, standards and minimum controls, define roles and responsibilities across the model lifecycle (development, validation, deployment, monitoring and decommissioning), require training and skill sets for staff, and maintain a centrally managed inventory of AI applications with risk classification. Where outsourcing or vendor‑provided AI is used, governance must include due diligence requirements, contractual clauses clarifying responsibilities and liability, performance and security SLAs, and contingency plans. FINMA’s governance expectation aligns with its broader supervisory principles (same business, same risks, same rules) and supports proportional, auditable control frameworks; see FINMA’s news release at FINMA news (18 Dec 2024) for the supervisory context.

Key Focus Areas

FINMA identifies seven core risk and control areas where institutions must concentrate efforts: 1) Inventory & risk classification: Maintain a comprehensive register of AI applications and classify each by materiality and risk (considering financial impact, regulatory relevance, client impact, autonomy, complexity and data sensitivity). Institutions should ensure the inventory includes in‑house and third‑party solutions and is kept current. 2) Data quality & governance: Define and enforce data quality standards (completeness, correctness, integrity, representativeness, timeliness), perform provenance checks and secure data availability and access. Institutions must be alert to historical biases, unrepresentative samples, and manipulated or low‑quality unstructured data inputs. 3) Testing & monitoring: Implement pre‑deployment testing (backtesting, out‑of‑sample tests, sensitivity analyses, adversarial testing, benchmarking against simpler models), define performance metrics and thresholds, and set up continuous monitoring for concept and data drift. Monitoring should track instances where outputs are overridden to inform model limitations. 4) Documentation: For material AI systems, require recipient‑oriented documentation that covers purpose, data selection/preparation, model architecture and rationale, assumptions, performance measures, limitations, validation results, fallback solutions and lifecycle governance. 5) Explainability: Ensure that material decisions—especially those affecting clients, investors or regulatory compliance—are explainable to relevant stakeholders, with methods that reveal drivers and behaviour under different conditions to allow plausibility and robustness assessments. 6) Independent review: Where applications are material, conduct objective, independent reviews of the development and governance processes by qualified persons; ensure review findings are taken seriously in model decisions. 7) Third‑party risk & outsourcing: Conduct due diligence on vendors, verify their data and model practices, include contractual clauses for transparency, audit rights and contingency measures, and assess concentration risks in provider markets. These focus areas echo international concerns set out by bodies such as the FSB; see the FSB’s assessment at FSB report (Nov 2024).

Implementation Framework

FINMA expects supervised institutions to implement proportionate controls according to size, complexity and application materiality. Practical measures include establishing an AI policy and governance charter; creating and maintaining an AI inventory; defining identification and classification criteria; embedding data‑quality gates in pipelines; developing test plans and acceptance criteria; operationalising alerts for drift and performance degradation; maintaining centralised documentation and model cards for material systems; scheduling independent reviews; and ensuring escalation procedures to senior management for incidents or material changes. Where institutions rely on vendor solutions or cloud providers, they should map dependencies, require transparency on data and model provenance, apply contractual protections (audit rights, termination rights, service continuity clauses) and maintain fallback/manual processes. FINMA emphasises that these measures should be risk‑based and scalable: a small, low‑impact rule‑based application need not face the same controls as an autonomous, market‑facing model that influences capital calculations or client decisions. FINMA also encourages institutions to contact the authority early when planning critical AI uses (for example, to calculate regulatory parameters) so that supervisory expectations and potential scrutiny can be discussed in advance; see FINMA.

Monitoring and Evaluation

Monitoring should combine continuous technical checks (performance metrics, data drift detection, adversarial resilience) with governance oversight (periodic reviews, reporting to committees, audits). FINMA expects institutions to define KPIs and thresholds, to document remedial actions when thresholds are breached, and to evidence periodic reassessments of materiality and classification. Monitoring also includes analysing overrides and exceptions as signals of model weakness and maintaining logs and traceability to enable audits and post‑incident analysis. For material models, independent validators should perform periodic re‑validation and stress testing; institutions should retain validation artefacts and evidence that independent reviews influenced deployment decisions. FINMA’s supervisory practice will continue to evolve in light of international work and market developments (for instance the FSB’s and OECD’s outputs referenced above).

Penalties, Liability, and Appeals

FINMA Guidance 08/2024 itself does not create new criminal offences or administrative fines but explains how existing prudential obligations apply in the AI context. If a supervised institution fails to meet statutory or prudential duties (for example on operational risk, prudential organisation, outsourcing or disclosure), FINMA already has enforcement powers under Swiss supervisory law and may apply measures ranging from requirements to remediate, public statements, orders to improve governance, restrictions on business activities, or formal enforcement proceedings. Liability in civil law (for harm to clients) remains governed by Swiss private law; contractual and indemnity provisions for vendor relationships are important mitigants. FINMA highlights the compliance risk that arises when poorly governed AI is used for decisions affecting clients or regulatory reporting; institutions should ensure appeal and escalation processes internally and preserve evidence of controls and independent reviews to support appeals or legal defence. FINMA’s enforcement approach and powers are summarised at FINMA enforcement information and the broader legal framework is on FINMA’s documentation pages.

Relationship to Other Instruments

FINMA positions Guidance 08/2024 within a network of international and domestic instruments. It references international standards (FSB reports, OECD definition work) and reiterates that existing Swiss supervisory and prudential laws (technology‑neutral) apply to AI. The Guidance complements other FINMA communications and sectoral rules (e.g., outsourcing/third‑party risk guidance, operational risk requirements) and should be read together with those instruments. Where new Swiss AI legislation emerges (federal approaches or sectoral laws), FINMA will adapt its expectations accordingly. The Guidance also aligns with the OECD’s and other standard‑setters’ recommendation that institutions adopt risk‑based, proportionate governance and that supervisors enhance monitoring and capability-building; see the OECD explanatory memorandum at OECD and the FSB report at FSB.

International Alignment

FINMA explicitly cites and aligns its supervisory expectations with international work: it notes the FSB’s identification of systemic and operational vulnerabilities and references the OECD’s definitional approach, encouraging consistency with internationally recognised best practice. FINMA intends to adopt a technology‑neutral, proportionate and standardised supervisory stance across sectors, mindful of international standards and cross‑border implications, including third‑party and cloud provider concentration risks. This alignment supports cross‑jurisdictional cooperation among supervisors and mutual learning; FINMA also signals it will refine expectations in response to both domestic legislative developments and international guidance.

Implementation Timeline

MilestoneRecommended/Observed TimingNotes
Publication of Guidance18 December 2024FINMA published Guidance 08/2024 (press release and PDF).
Initial Institutional Gap Analysis0–6 months after publicationInstitutions should complete an inventory and gap analysis proportional to materiality.
Establish Central Governance & Inventory3–12 monthsCreate central AI governance, risk classification and documentation standards.
Implement Testing & Monitoring Regime6–18 monthsAdopt validation tests, KPIs, drift monitoring and independent review processes for material systems.
Vendor Due Diligence & Contracting3–12 monthsReview supplier arrangements, SLAs, audit rights and concentration risk plans.
Ongoing Supervision & RefinementOngoingFINMA will continue supervisory dialogue and refine expectations in light of international developments.

Compliance Checklist

RequirementYes/NoEvidence
Central AI governance function established[ ]Governance charter, committee minutes
Comprehensive AI inventory with risk classification[ ]Inventory register, classification criteria
Data quality policies and controls[ ]Data governance policy, data lineage reports
Pre‑deployment testing & validation[ ]Test plans, backtesting results
Continuous monitoring & drift detection[ ]Monitoring dashboards, incident logs
Documentation for material applications[ ]Model cards, user manuals, validation reports
Independent review for material systems[ ]Independent review reports, remediation logs
Vendor due diligence & contractual safeguards[ ]Vendor risk assessments, contract clauses

Sources and References

SourceType
FINMA Guidance 08/2024: Governance and risk management when using artificial intelligence (PDF)Primary Source
FINMA press release (18 Dec 2024)Primary Source
FSB: The Financial Stability Implications of Artificial Intelligence (Nov 2024)Secondary/Context
OECD: Explanatory Memorandum on the Updated OECD Definition of an AI System (Mar 2024)Secondary/Context
Plain English

FINMA Guidance 08/2024 clarifies how existing rules for governance and risk management apply to artificial intelligence (AI) for all supervised financial institutions in Switzerland. This guidance, effective December 18, 2024, sets out the Swiss financial regulator's expectations for managing AI risks, emphasizing a technology-neutral, risk-based approach.

The guidance applies to all financial institutions under FINMA's supervision, particularly those using numerous or significant AI applications. FINMA expects these institutions to establish robust frameworks to identify, assess, monitor, and manage AI risks. Key obligations include: - Implementing central AI governance, such as a dedicated function or committee, accountable to senior management and the board. This body should set policies and define roles across the AI lifecycle. - Maintaining a comprehensive inventory of all AI applications, both in-house and from third parties, classifying each by its materiality and risk level. - Ensuring high data quality, including checks for completeness, correctness, and representativeness, and being vigilant about historical biases or manipulated data. - Conducting thorough pre-deployment testing and continuous monitoring of AI systems to detect performance degradation or "drift" over time. - Ensuring that decisions made by material AI systems are explainable to relevant stakeholders, especially those affecting clients or regulatory compliance.

While the guidance itself doesn't introduce new penalties, FINMA will use its existing enforcement powers if institutions fail to meet their prudential duties, now explicitly extended to AI use. This could range from remediation orders to business restrictions or formal proceedings. A practical pitfall for institutions is FINMA's broad definition of AI: it's not limited to modern generative models but includes any system that infers from inputs to generate outputs influencing processes or people, meaning even older, simpler models might be in scope. Institutions are expected to implement these controls proportionately, with a phased approach over the next 3 to 18 months.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 15 marked complete

Plain-English obligations under Switzerland - AI Governance Guidelines (08/2024). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalGovernance and Institutional FrameworkDec 18, 2025

    Applies to: Supervised financial institutions with many or significant AI applications.

    implement central AI governance (a central function or committee) accountable to senior management and the board.
  2. #2CriticalKey Focus Areas - Inventory & risk classificationDec 18, 2025

    Applies to: Supervised financial institutions.

    Maintain a comprehensive register of AI applications and classify each by materiality and risk... ensure the inventory includes in‑house and third‑party solutions and is kept current.
  3. #3CriticalGovernance and Institutional FrameworkDec 18, 2025

    Applies to: Institutions using outsourced or vendor-provided AI.

    governance must include due diligence requirements, contractual clauses clarifying responsibilities and liability, performance and security SLAs, and contingency plans.
  4. #4CriticalKey Focus Areas - Data quality & governanceBefore deployment

    Applies to: Supervised financial institutions.

    Define and enforce data quality standards (completeness, correctness, integrity, representativeness, timeliness), perform provenance checks and secure data availability and access.
  5. #5CriticalKey Focus Areas - Testing & monitoringJun 18, 2026

    Applies to: Supervised financial institutions.

    Implement pre‑deployment testing... define performance metrics and thresholds, and set up continuous monitoring for concept and data drift.
  6. #6CriticalKey Focus Areas - DocumentationBefore deployment

    Applies to: Institutions using material AI systems.

    For material AI systems, require recipient‑oriented documentation that covers purpose, data selection/preparation, model architecture and rationale...
  7. #7CriticalKey Focus Areas - ExplainabilityBefore deployment

    Applies to: Institutions using material AI systems.

    Ensure that material decisions—especially those affecting clients, investors or regulatory compliance—are explainable to relevant stakeholders...
  8. #8CriticalKey Focus Areas - Independent reviewBefore deployment

    Applies to: Institutions using material AI systems.

    Where applications are material, conduct objective, independent reviews of the development and governance processes by qualified persons...
  9. #9CriticalMonitoring and EvaluationOngoing

    Applies to: Institutions using material AI systems.

    For material models, independent validators should perform periodic re‑validation and stress testing...
  10. #10ImportantGovernance and Institutional FrameworkDec 18, 2025

    Applies to: Institutions with central AI governance.

    This governance should set policies, standards and minimum controls, define roles and responsibilities across the model lifecycle...
  11. #11ImportantGovernance and Institutional FrameworkDec 18, 2025

    Applies to: Supervised financial institutions.

    require training and skill sets for staff
  12. #12ImportantDefinitionsDec 18, 2025

    Applies to: Supervised financial institutions.

    Institutions should document what they consider an AI application, the data types used... the system’s degree of autonomy and adaptivity...
  13. #13ImportantImplementation FrameworkBefore deployment

    Applies to: Supervised financial institutions.

    ensuring escalation procedures to senior management for incidents or material changes.
  14. #14ImportantMonitoring and EvaluationBefore deployment

    Applies to: Supervised financial institutions.

    FINMA expects institutions to define KPIs and thresholds, to document remedial actions when thresholds are breached...
  15. #15ImportantMonitoring and EvaluationOngoing

    Applies to: Supervised financial institutions.

    maintaining logs and traceability to enable audits and post‑incident analysis.

© Regulations.AI — created on 13-Jun-2026