What "Operational Risks and Resilience" actually means for your bank
If a critical function at your bank goes down, including because a third party failed rather than you, FINMA expects the board to have already approved how much disruption that specific function can tolerate, and expects you to have tested that you can hold that line under a severe but plausible scenario. Working it out during the incident is not an answer.
Whether it applies to you at all
The addressee table on page one is the fastest answer to that question, and it is the part almost everyone skips. Five boxes are ticked: banks, financial groups and conglomerates, persons under Article 1b BA, and investment firms in both proprietary and non-proprietary trading. Insurers, portfolio managers, trustees, fund management companies and custodian banks are not addressees of this circular.
Margin no. 2 states it in law. The circular applies to banks under Article 1a BA, persons under Article 1b BA, securities dealers under Article 2 para. 1 let. e and Article 41 FinIA, and financial groups and financial conglomerates under Article 3c BA and Article 49 FinIA. All of them are called "institutions" throughout the text. The circular entered into force on 1 January 2024 and replaced Circular 2008/21.
Proportionality is a list, not a principle
Margin no. 19 says the requirements are implemented case by case according to size, complexity, structure and risk profile. It also contains the half that never gets quoted: FINMA can tighten the rules in individual cases as well as relax them. Margin no. 27 goes further and reserves the right to impose more stringent requirements on specific topics during ongoing supervision.
Beyond that, the relief is enumerated rather than general. Banks and securities firms in FINMA categories 4 and 5 are exempt from margin nos. 33–38, 41–46, 48, 51, 57, 73, 74, 76–78, 80, 87, 92, 93, 96, 103, 104 and 110–112. Institutions under Articles 47a–47e CAO, persons under Article 1b BA and investment firms in non-proprietary trading are additionally exempt from 72, 75, 79 and 105–109. If you are relying on proportionality, you should be able to point at those numbers rather than at the concept.
What it actually covers
Chapter IV on operational risk management runs from margin no. 22 to 112 and has six parts, not the three most summaries describe: overarching operational risk management (22–46), ICT risk management (47–60), cyber risk management (61–70), critical data risk management (71–82), business continuity management (83–96), and management of risks from cross-border service business (97–100). Chapter V covers operational resilience (101–111) and Chapter VI adds continuation of critical services for systemically important banks (112).
The cross-border chapter is the one people are surprised to find here. Exposure to foreign tax, criminal and anti-money-laundering law, including through foreign-based subsidiaries and branches serving Swiss clients, is treated as an operational risk under this circular rather than as a purely legal matter.
Critical data is defined more broadly than most institutions assume. Margin no. 7 covers data crucial for the successful and sustainable provision of the institution's services or for regulatory purposes, and states that confidentiality, integrity and availability can each independently make data critical. Availability alone is enough. That is a wider net than a confidentiality-driven classification scheme tends to catch.
The part with real teeth
Margin no. 17 defines the tolerance for disruption as the extent, for example the duration or the expected damage, of disruption to a critical function that the institution is willing to accept under severe but plausible scenarios. One must be defined for each critical function. That is a different object from the risk tolerance for operational risk the board approves annually under margin no. 23, and the two are routinely confused.
Margin no. 101 requires the board to approve the critical functions and their tolerances. Margin no. 103 requires that approval to be renewed at least annually, so it is not a one-time sign-off. Margin no. 107 requires an inventory of critical functions, reviewed at least annually, containing the tolerances and the dependencies between critical processes and the resources needed to deliver them. Margin no. 54 is stricter still for the underlying ICT asset inventory, which is expected to be available in real time.
The timing, which most summaries get wrong
Margin no. 113 sets out three different clocks, not one two-year runway. Identification of critical functions, definition of tolerances, the approvals under margin nos. 101 and 103 and the initial reporting under margin no. 105 were expected from entry into force, with no transitional period granted. A one-year transitional period applied to margin nos. 106–109 and to the first tests under margin no. 110. A two-year period applied to ensuring operational resilience under margin no. 102 and to the requirements in margin nos. 104 and 111.
All three windows have now passed. An institution that treated this as a single two-year programme was on time for the last group and late for the first, which is a different conversation with an examiner than being on schedule.
What the testing requirement actually says
There is a widespread claim that tabletop exercises no longer satisfy the circular. That is not what it says. Margin no. 91 explicitly lists tabletop exercises among the acceptable means of testing, and margin no. 70 names them again for cyber exercises. The bar is not the format.
The bar is the scenario. Margin no. 94 requires tests to encompass various severe but plausible scenarios and to take account of recovery dependencies, including those involving third parties. Margin no. 110 goes further and requires scenarios that differ from short, limited interruptions: longer duration, in the order of several months, and a lack of basic resources. Footnote 27 gives the examples, and they are worth reading in full, because they include a pandemic, a power shortage, prolonged downtime from the insolvency of a key service provider, and a foreign government prohibiting its cloud providers from serving Swiss firms. Margin no. 92 requires the most important BCP and DRP measures and the crisis organisation to be tested at least once a year.
So a tabletop run against a severe, long-duration, third-party scenario meets the requirement. A live failover test against a two-hour outage does not, however impressive it looks in the report.
Have you formally identified which services meet the margin no. 14 definition of a critical function, rather than informally agreed which ones matter?
For each critical function, has the board approved a tolerance for disruption expressed as an extent, such as duration or expected damage, rather than a general risk appetite statement?
Was that approval renewed within the last twelve months, as margin no. 103 requires?
Does your critical-function inventory under margin no. 107 actually contain the dependencies between critical processes and the resources delivering them, or only a list of function names?
Do your test scenarios include long duration and a lack of basic resources, as margin no. 110 requires, or only short outages?
Does your critical-data classification treat availability and integrity as independent triggers, and include data held for regulatory purposes rather than only client data?
Is your outsourcing risk management under Circular 2018/3 coordinated with this framework, as margin no. 104 expressly requires, or are the two still separate exercises?
If you are relying on proportionality relief, can you name the margin numbers you are exempt from under margin nos. 20 and 21?
Three reporting triggers, not one
The circular contains three separate duties to report to FINMA, and institutions often build a process for only one. Margin no. 60 requires ICT incidents regarded as a significant disruption to critical processes and material for supervision to be reported without delay. Margin no. 81 requires the same for incidents substantially impairing the confidentiality, integrity or availability of critical data. Margin no. 68 sets the cyber timetable: an initial assessment and preliminary notification to the responsible body at FINMA within 24 hours, the full report through the EHP platform within 72 hours, and a conclusive root cause analysis once the case is closed.
Those are the duties inside this circular. They are not the only reporting clocks a Swiss institution runs, and the interaction between them is a subject of its own.
Where this trips people up
Common misreading
Treating this as an IT circular that the security or infrastructure team owns end to end. It deliberately is not. FINMA placed the tolerance decision at board level and requires annual re-approval, which puts accountability with governance rather than architecture. The second common mistake is assuming an existing risk appetite statement already satisfies this. It does not. The risk tolerance for operational risk under margin no. 23 is institution-wide and approved annually. The tolerance for disruption under margin no. 17 is a separate object, defined per critical function, expressed as an extent, and approved on its own.
If you are not sure whether your current business continuity documentation would hold up to an examiner asking for this level of specificity, that gap is usually smaller to close than it looks. The hard part is almost always naming the critical functions honestly, not the testing itself.
Checked against FINMA Circular 2023/1 "Operational risks and resilience – banks", dated 7 December 2022, in force 1 January 2024. Margin numbers refer to that text. The German, French and Italian versions are authoritative; the English translation is not.