TL;DR
- FINMA’s Guidance 08/2024, published December 18, 2024, sets out supervisory expectations (not a binding circular) for how Swiss financial institutions should govern AI risk.
- It rests on four themes: governance and accountability, robustness and reliability, explainability and transparency, and non-discrimination.
- FINMA has told supervised entities directly that most of them are still building the governance structures this guidance assumes they already have.
- Third-party AI dependencies do not reduce your liability. FINMA holds the regulated institution accountable even when the model, cloud, or vendor sits outside its walls.
- The guidance leans on existing law (the Banking Act, FinIA, Circular 2023/1 on operational risk) rather than creating new AI-specific rules, which means your existing risk framework is the starting point, not a blank page.
- Roughly half of surveyed Swiss financial institutions already use AI in daily operations, and another quarter plan to within three years, so this is not a hypothetical compliance exercise.
Ask a chief risk officer at a Zurich private bank what changed on December 18, 2024, and most will tell you: nothing new was invented, but everything old got a lot more specific.
That’s the uncomfortable truth about FINMA’s AI guidance. It didn’t write a new rulebook. It took the rulebook Swiss financial institutions already live under, held it up against the machine learning models, chatbots, and generative AI tools already running in production, and said: these apply too.
If your model risk framework, outsourcing controls, and board-level accountability structures were built for spreadsheets and credit scoring engines, they now have to stretch to cover large language models making decisions your compliance team may not fully be able to explain.
That’s a harder problem than it sounds. And FINMA has already told the industry, in writing, that most institutions aren’t there yet.
This breakdown works through FINMA Guidance 08/2024 section by section: what it actually says, what counts as a firm expectation versus a recommendation, and what each requirement means operationally for a team running AI in production today.
What Exactly Is FINMA Guidance 08/2024?
FINMA Guidance 08/2024 is a supervisory guidance note on governance and risk management when using artificial intelligence, published by the Swiss Financial Market Supervisory Authority on December 18, 2024.
On 18 December 2024, the Swiss Financial Market Supervisory Authority (FINMA) published Guidance Note 08/2024 on governance and risk management when using artificial intelligence (AI).
It’s worth pausing on the word “guidance” before going any further, because it does real legal work here.
Unlike a circular (Rundschreiben) or a supervisory notice (Aufsichtsmitteilung), a guidance note carries less formal weight under Swiss administrative law. One legal analysis of the document put it plainly:
Although the term “supervisory expectations” chosen by FINMA itself may suggest a formal character, the guidelines do not originate from a supervisory guidance or a circular and are therefore less binding, and institutions can thus also deal with the issue differently.
That does not mean you can ignore it. FINMA regularly issues these notes to signal what it’s already looking for in examinations, and:
FINMA regularly publishes guidance notes to inform market participants of its observations from ongoing supervision activities, drawing attention to the risks associated with the use of AI in the financial services industry.
The document is built on legal hooks that are very much binding: FINMA’s interpretive authority under the Financial Market Supervision Act and the proper-organization provisions of the Banking Act and the Financial Institutions Act. The guidance tells you how FINMA will interpret those existing, hard-law obligations when AI is involved.
The risks it names are specific and recur throughout the document:
These include operational risks, in particular model risks such as lack of robustness, correctness, explainability or bias, data-related risks such as data security, data quality, data availability, IT and cyber risks, increasing third-party dependencies as well as legal and reputational risks.

Why FINMA Is Watching This Closely Right Now
FINMA didn’t publish this guidance in a vacuum. It surveyed the market first, and the numbers explain the urgency.
Between late November 2024 and mid-January 2025, FINMA ran a market-wide check on AI adoption:
The Swiss Financial Market Supervisory Authority FINMA conducted a survey of around 400 Swiss financial institutions on their use of artificial intelligence, surveying licensed banks and securities firms, insurance companies and intermediaries, fund management companies, managers of collective assets and financial market infrastructures.
The results confirmed what examiners were already seeing in the field:
Around 50% of the institutions surveyed use AI or have initial applications in development, and a further 25% intend to use it in the next three years.
Broken down by sector:
Of the 187 authorised institutions using AI, 75 insurance companies and insurance intermediaries fall into the “Insurance” category, 100 banks and securities firms into the “Banks” category, and 12 fund management companies, managers of collective assets and financial market infrastructures into the “Other institutions” category.
That adoption curve is exactly why the guidance exists. FINMA is applying its stated supervisory philosophy of “same business, same risks, same rules” to a technology moving faster than most institutions’ control frameworks. And its own examiners already found a gap:
In the course of its supervisory activities, FINMA has observed that most financial institutions are still in the early stages of development and that the corresponding governance and risk management structures are still being established.
If you’re reading this inside a risk or compliance function right now, that sentence is directed at you specifically, not the industry in the abstract. FINMA has already looked at institutions like yours and found the governance layer thinner than the technology deployment.
The Four Pillars: What FINMA Actually Expects
FINMA’s supervisory expectations organize around four recurring themes, confirmed consistently across legal analysis of the guidance: governance and responsibility, robustness and reliability, transparency and explainability, and non-discrimination. Each one maps to a different failure mode FINMA has watched play out during examinations.
Governance and Responsibility: Who Owns This When It Breaks?
Accountability cannot sit with the model. This is the clearest, least negotiable expectation in the entire document. Legal commentary on the guidance’s underlying principles is unambiguous:
Clear roles and responsibilities as well as risk management processes must be defined and implemented, responsibility for decisions cannot be delegated to AI or third parties, and all parties involved must have sufficient expertise in the field of AI.
Practically, this means three things have to exist before a material AI application goes live: a named owner at a level senior enough to answer for it, a documented risk management process specific to that application, and demonstrable AI literacy among the people signing off on it. FINMA also expects institutions to know what they’re running in the first place:
Institutions should maintain comprehensive inventories of AI applications, clearly define roles and responsibilities, and ensure staff are adequately trained.
Boards that treat AI oversight as a slide in an annual IT update are misreading the assignment. This is proper-organization territory under the Banking Act and FinIA, the same legal foundation that governs credit risk committees and internal audit charters. Institutions building out this ownership layer are increasingly turning to purpose-built tooling for it, since Lyzr for Heads of AI is designed around exactly this problem: giving a single senior owner visibility into every AI application’s risk posture without chasing spreadsheets across departments.
Robustness and Reliability: Prove It, Don’t Assume It
An AI system earns the right to run unsupervised only once its reliability can be demonstrated, not assumed. FINMA’s expectation here is that outputs are sufficiently accurate, robust, and reliable, and that both the underlying data and the model’s results get critically examined rather than taken at face value.
FINMA’s examiners look for specific, testable behaviors:
FINMA assesses whether reporting entities provide for regular checks on the accuracy, robustness and stability of the AI system or model, tests that help ensure the application is not biased, and expects performance indicators to be used to assess the extent to which the system achieves the objectives set.
Institutions are also expected to watch how their models degrade over time as production data drifts from training data, and to:
Ensure that changes in input data do not affect the AI model underlying the application, analyse cases where results have been ignored or modified by users as these situations may indicate a weakness in the system, and monitor AI applications throughout their use.
That last point deserves attention. If your analysts routinely override an AI-generated credit recommendation, FINMA doesn’t want that pattern buried in a log file. It wants it treated as a signal worth investigating.
Transparency and Explainability: The Line Between “It Works” and “I Can Explain Why”
An AI output only satisfies FINMA’s explainability expectation if someone can explain it to the person who actually needs the explanation. The threshold moves with the audience and the stakes. FINMA’s principle is that explainability and transparency:
Must be ensured depending on the recipient, relevance and process integration.
A loan applicant, a compliance auditor, and a FINMA examiner all need different depths of explanation, but all three need something better than “the model decided.”
This is where FINMA’s field observations get pointed:
If AI systems and models are to be critically evaluated, results need to be explainable and understood by staff, but FINMA found that results were often not understood or explained and could not be critically assessed, which poses a problem for ensuring robustness and accuracy.
Institutions are increasingly under pressure not just from clients but from their own auditors, and generative AI outputs often lack explainability because:
Users generally do not know the underlying logic or mechanisms behind AI-generated answers, creating challenges when institutions need to explain outcomes to third parties such as clients, auditors, or FINMA itself.
Retrieval-Augmented Generation, or RAG, the technique of grounding a large language model’s answers in a curated, verifiable knowledge base instead of its raw training data, is one of the few practical answers to this problem. It gives you a traceable link between an output and the source document that produced it, which is close to what an examiner is actually asking for when they ask “why did the model say this.”
Non-Discrimination: Bias Is a Model Risk, Not a PR Risk
FINMA treats bias as an operational risk, not a reputational afterthought. The expectation is that institutions avoid unjustifiable unequal treatment in AI outcomes, tested proactively before deployment and monitored continuously after. FINMA’s press materials list bias in the same breath as robustness and correctness:
These include operational risks, in particular model risks such as lack of robustness, correctness, explainability or bias, data-related risks such as data security, data quality, data availability, IT and cyber risks, increasing third-party dependencies as well as legal and reputational risks.
That framing matters. A biased credit model isn’t just an ethics problem to route to your DEI committee. Under this guidance, it’s a model risk finding that belongs in the same escalation path as a broken fraud detection algorithm.
Data Quality: The Requirement Everyone Underrates
FINMA has said, more or less directly, that data quality matters more than which model you pick. One legal summary of the guidance’s emphasis is direct on this point:
In FINMA’s view, data quality is often more important than model selection.
That’s a notable statement from a regulator, because it reframes the compliance conversation. Institutions spend enormous energy vetting which large language model to license, and comparatively little auditing the pipelines that feed it.
Historical financial data carries its own trap here:
The fact that reliance on historical data may be dangerous due to hidden biases is an issue well-known in econometrics and financial analysis.
A model trained on ten years of mortgage approval data will happily reproduce every bias baked into those ten years of human underwriting decisions, just faster and at scale.
Interestingly, FINMA’s own field research suggests institutions have this half-solved already:
Data protection remains a concern, particularly as users may input confidential information into tools not designed for secure handling of such data, but FINMA observes that supervised institutions are generally well aware of data protection risks and may even overemphasize them compared to other risks.
Translation: compliance teams have spent years worrying about data leakage into consumer chatbots. They haven’t spent nearly as much time worrying about whether the training data itself is fit for purpose.
Third-Party Dependencies: You Cannot Outsource Accountability
This is the part of the guidance that catches procurement teams off guard. If you license a model from a cloud provider, buy a fintech platform with embedded AI, or plug into a third-party API, FINMA’s position is that the risk stays with you, not your vendor.
The guidance flags this dependency explicitly as a growing structural risk:
There is a growing dependence on third-party suppliers, especially for AI models and cloud services, added to the difficulty of assigning clear responsibilities in the event of errors in the AI system or model.
One legal review noted the market concentration angle specifically:
Such risks are further heightened by a growing dependence on third parties such as providers of hardware solutions, models or cloud services in an increasingly concentrated market.
This connects directly to FINMA’s existing outsourcing framework:
FINMA’s AI guidance is closely related to Circular 2023/1 on operational risks and resilience, which covers many ICT-related risks, and both the new AI guidance and the circular on operational risks are based on FINMA’s authority to issue interpretative guidance under the Financial Markets Supervisory Act and the provisions on proper organisation contained in the Banking Act and Financial Institutions Act.
Circular 2023/1, in force since January 1, 2024, already requires institutions to manage ICT risk and critical data risk with rigor. AI vendors now fall squarely inside that perimeter. FINMA’s older Circular 2018/3 on outsourcing adds selection, instruction, and monitoring obligations for any service provider, AI or otherwise.
What this means in practice: your vendor contracts need audit rights, performance data access, and enough visibility into the model’s behavior that you can produce an explanation when FINMA asks for one. If your AI vendor can’t tell you why their model made a specific decision, you have a problem that legal language in a contract will not fully solve.
This is precisely the gap a centralized orchestration layer is built to close, one that governs in-house and third-party agents under the same audit and monitoring standard rather than treating vendor AI as a black box sitting outside your control perimeter.
Cybersecurity: A New Attack Surface on an Old Framework
FINMA doesn’t treat AI-specific cyber risk as separate from its existing operational resilience regime. It expects it folded into the same controls already required under Circular 2023/1, which governs ICT risk, critical data, and business continuity for banks. That circular already requires:
Significant adjustments in information and communication technology risk management and critical data risk management, along with new requirements for ensuring operational resilience.
AI systems introduce attack surfaces that circular didn’t originally anticipate in detail: data poisoning during training, adversarial inputs designed to trick a model into misclassifying a transaction, and model theft through repeated querying. FINMA’s guidance folds these into the existing IT and cyber risk category rather than inventing a parallel regime, which is consistent with its technology-neutral approach across the whole document.
What’s a Firm Expectation vs. What’s a Recommendation
This distinction matters more than most compliance summaries acknowledge, and it changes how much resource pressure you apply to each item.
Firm expectations, grounded in existing binding law that the guidance interprets
- Clear governance structure with named, senior-level accountability for AI applications
- Risk identification, assessment, management, and monitoring processes specific to AI, built into your existing internal control system
- Data quality controls appropriate to the risk of the application
- Explainability proportionate to the recipient and the materiality of the decision
- Third-party AI risk brought inside your existing outsourcing and operational resilience frameworks
Softer recommendations, where the guidance signals direction without binding force
- FINMA’s suggestion that institutions
contact FINMA in good time if they are planning to use AI in critical processes or to calculate regulatory parameters
is framed as a recommendation, not a mandatory notification requirement. - Alignment with the EU AI Act or broader international standards is presented as forward-looking guidance rather than a current obligation for purely domestic Swiss operations. FINMA’s own outlook section suggests institutions should not only comply with the guidelines but also consider international standards, such as those set by the EU AI Act.
- Independent, third-party reviews of AI systems are described as advisable in appropriate cases rather than mandated across the board. Where appropriate, independent reviews should be commissioned to ensure transparency and accountability.
The gap between these two categories is where a lot of Swiss institutions are currently over-investing in the wrong places, chasing EU AI Act parity before their own board-level AI inventory even exists.
What This Actually Means for Teams Running AI in Production
None of this reads as abstract to a team that has already shipped an AI feature into a regulated workflow. It reads as a checklist against work already underway.
If you’re running a generative AI assistant for client queries, an underwriting model, or a fraud detection pipeline, the practical shift is this: you now need an inventory entry for it, a named accountable owner, documented testing and monitoring evidence, and an explanation you could hand a client or an examiner without embarrassment. That’s not a one-time compliance sprint. It’s an operating discipline that has to survive every model update, every retraining cycle, and every new vendor integration.
Teams building these underwriting, fraud, and client-service applications directly are increasingly standardizing on platforms purpose-built for banking use cases, where Banking Agents come with the audit trail, risk classification, and monitoring hooks FINMA’s examiners are trained to ask for, rather than bolting compliance on after the model is already live.
The institutions that will struggle most are the ones treating this as a documentation exercise to complete once and file away. FINMA’s own language, that most institutions are still in early-stage development of these structures, suggests the gap is operational maturity, not paperwork. Governance frameworks like Lyzr for Compliance Teams exist precisely because manually maintaining an audit trail, a risk classification, and an explainability record across dozens of production agents becomes unmanageable past a certain scale, and unmanageable is exactly the state FINMA’s examiners are trained to find.
Frequently Asked Questions
Is FINMA Guidance 08/2024 legally binding?
Not in the same way a circular or ordinance is. Legal analysis of the document notes that although the term “supervisory expectations” chosen by FINMA itself may suggest a formal character, the guidelines do not originate from a supervisory guidance or a circular and are therefore less binding, and institutions can thus also deal with the issue differently. That said, it interprets binding proper-organization requirements under the Banking Act and Financial Institutions Act, and FINMA examiners will use it as their reference point during supervision.
What is FINMA’s risk-based approach to AI?
FINMA scales its scrutiny to the materiality of the AI application rather than applying uniform rules to every use case. The core question examiners ask is what happens if the system fails:
What happens if the AI makes a material error or grossly malfunctions, how many customers would be affected and how, what would be the financial impact, and what impact would this have on compliance with legal requirements.
Low-stakes internal tools get lighter scrutiny than client-facing credit or investment decisions.
How does FINMA’s AI guidance compare to the EU AI Act?
FINMA’s approach is principle-based and Switzerland-specific, while the EU AI Act is a prescriptive, rules-based regulation with binding penalties:
The EU AI Act establishes a comprehensive, risk-based framework applying across sectors, detailed and prescriptive with a focus on sector-wide governance and transparency, while FINMA’s Guidance offers a principle-based, flexible approach tailored to the unique risks of the Swiss financial sector, focusing specifically on banks, investment fund managers and insurers.
Swiss institutions with EU clients or EU-facing operations may still need to track the AI Act separately due to its extraterritorial reach.
Does FINMA require an AI inventory?
FINMA expects supervised institutions to know what AI they’re running, in enough detail to answer for it. Legal guidance on implementation confirms that institutions should maintain comprehensive inventories of AI applications, clearly define roles and responsibilities, and ensure staff are adequately trained. An inventory without a documented risk classification behind each entry does not satisfy this expectation on its own.
Who is responsible when a third-party AI model causes a loss?
The regulated institution remains accountable, not the vendor. FINMA’s guidance treats third-party dependency as a risk that must be actively managed rather than one that transfers with the contract, tying it directly to the existing outsourcing and operational resilience circulars that already govern vendor relationships at Swiss banks and insurers.
Does FINMA’s AI guidance apply to insurers as well as banks?
Yes. The survey underlying the guidance covered the full range of supervised entities, and the results confirm meaningful AI adoption across sectors: of the 187 authorised institutions using AI, 75 insurance companies and insurance intermediaries fall into the “Insurance” category, 100 banks and securities firms into the “Banks” category, and 12 fund management companies, managers of collective assets and financial market infrastructures into the “Other institutions” category. The guidance’s language is deliberately technology-neutral and entity-neutral rather than bank-specific.
Where This Leaves You
FINMA didn’t write this guidance to slow anyone down. It wrote it because it already found the gap between AI ambition and AI governance during its own examinations, and it’s telling the market exactly where that gap sits before it becomes an enforcement finding.
The real test isn’t whether you can produce a policy document that references governance, robustness, explainability, and non-discrimination. It’s whether you can pull up, on demand, the risk classification, the owner, the monitoring history, and the explanation for any AI application currently touching a client decision. If that request would send your team scrambling across spreadsheets and Slack threads, the guidance has already told you what your next audit finding looks like.
Start there: pick your single highest-risk AI application in production today, and try to answer FINMA’s four questions about it, on paper, this week. What you can’t answer cleanly is your actual compliance roadmap for 2026.
__PROGRESS__:Quality check: Found “robust” – flagged by the anti-AI-slop checklist.Book A Demo: Click Here
Join our Slack: Click Here
Link to our GitHub: Click Here


