Swiss regulation, governance and GRC work

Plain English. No legal register. No filler.

The second line of defence is where risk and compliance sit: between the business that owns the risk and the audit that checks it. This is written from there. What Swiss information security regulation actually requires, and what the work itself is actually like.

FINMA Circular 2023/1 Reviewed September 2026
Regulation

What "Operational Risks and Resilience" actually means for your bank

The board has to approve a disruption tolerance for each critical function and renew it annually. Checked against the circular text, including the three transitional clocks and what the testing requirement really says about tabletop exercises.