News

Why your vendor's cyber incident is still your compliance problem in Switzerland

By
BizAge Interview Team
By

Swiss organisations increasingly find that outsourcing an activity does not outsource the accountability that comes with it. Two separate regulatory regimes make this explicit, and together they leave very little room for a "our supplier handled it" defence.

The two frameworks that make third party risk unavoidable

Financial institutions and data controllers face this from different directions, but the underlying message is the same.

FINMA's outsourcing expectations

FINMA's Circular 2023/1 on operational risks and resilience requires supervised institutions to assess, monitor and document the risk presented by third party relationships on an ongoing basis, not just at onboarding. Institutions remain accountable for outsourced functions, including data and cloud arrangements, and FINMA explicitly states that fulfilment of requirements outsourced to third parties, particularly around systems and information security, remains the supervised entity's own responsibility.

The revised FADP's processor rules

Separately, the revFADP holds data controllers responsible for ensuring that their processors handle personal data lawfully. If a vendor mishandles data or suffers a breach, the controlling organisation remains accountable for the resulting harm, and cross border data transfers to a vendor processing data outside Switzerland must meet equivalent protection standards.

What FINMA is actually seeing in the data

FINMA's own reporting shows this is not a theoretical concern. The regulator observed a sharp increase in reports of cyber attacks via supply chains and third parties in 2025, and its Risk Monitor noted that some risks in the supply chain are insufficiently identified and managed, including at third parties not formally classified as significant outsourcing providers.

Concentration risk is a specific supervisory focus

FINMA maintains an inventory of significant outsourcings specifically to identify concentration on a narrow group of service providers, since an incident at a single widely used provider can affect several regulated institutions simultaneously. This is a structural risk that individual vendor questionnaires, completed once at onboarding, do not capture on their own.

Why onboarding checks alone are not enough

Most organisations onboard a vendor with a questionnaire and then move on. Supervisors and the FDPIC are increasingly focused on what happens after signing, specifically how an organisation monitors concentration risk on an ongoing basis, and whether critical suppliers continue to meet the resilience and data protection standard they were assessed against initially.

What proportionate third party risk management actually covers

A defensible approach generally includes a small number of specific practices, applied consistently rather than as a one-off exercise.

  • Documented risk assessment and monitoring of third party relationships, not just at onboarding but on a recurring basis
  • A clear inventory of critical outsourcing arrangements, with visibility into concentration risk across the supplier base
  • Contractually secured guarantees on data access, data export and any sub-provider chains, rather than relying on blanket references to standard contractual clauses alone
  • A well founded rationale for where critical data is actually processed, including consideration of foreign legal access regimes affecting cloud providers

The regulatory direction of travel

Third-party and supply chain risk management Switzerland organisations put in place today is increasingly being measured against international standards, including how closely it maps to frameworks like ISO 27001 and ISO 27005 for information security in supplier relationships. Organisations building a defensible programme now, ahead of an incident forcing the issue, are in a considerably stronger position than those treating vendor risk as a questionnaire completed once and filed away.

Cloud arrangements bring a specific set of questions

Where critical data sits with a cloud provider, particularly a large international hyperscaler, Swiss regulators expect more than a general assurance that the provider is reputable. FINMA specifically expects a well founded rationale for the chosen processing location and contractually secured guarantees covering data access, data export and any sub-provider chains, since blanket references to standard contractual clauses on their own do not satisfy this expectation. An institution processing critical data in a jurisdiction where foreign law could compel access, the US CLOUD Act being a frequently cited example, needs to have addressed that specific risk directly rather than assuming a general data protection agreement covers it.

Insider risk sits inside the third-party conversation too

FINMA's recent supervisory focus has extended third party risk thinking beyond external vendors to include personnel supplied by those vendors. Insider threats are now treated as a distinct, formally recognised risk category, with an explicit emphasis on deliberate malicious acts rather than simple error, and the scope extends to third party personnel working within an organisation's systems, not only its own direct employees.

Where DORA becomes relevant even for purely Swiss organisations

Organisations without any EU presence sometimes assume the EU's Digital Operational Resilience Act is entirely outside their concern. That is not always accurate. A Swiss ICT provider supplying an EU regulated financial entity can be pulled into DORA's requirements indirectly, since EU regulated customers are contractually required to impose DORA compliant terms on their own vendors. Swiss providers with material EU customer relationships should assess this exposure directly rather than assuming Swiss domicile provides a complete exemption.

‍

Written by
BizAge Interview Team
September 30, 2026
Written by
September 30, 2026