FINMA 2023/1 and DORA: what each requires, and where a Swiss institution has to satisfy both
FINMA Circular 2023/1 sets Swiss expectations for operational risk and resilience, including critical function identification, tolerance for disruption and third-party risk. DORA is EU law and does not apply to a Swiss institution directly. It does apply where that institution operates through an EU-authorised entity, or where an EU financial counterparty pushes DORA-equivalent obligations down through a contract, which is the case in practice for most Swiss groups with EU reach. If your critical function register and your DORA-facing register would name different functions as critical, that mismatch is the actual finding.
Published · Updated
Maximilian Bazzi, Founder and CEOWhat FINMA Circular 2023/1 actually asks for
FINMA 2023/1 (Operational risks and resilience, banks) sets out expectations for identifying critical functions, defining tolerance levels for disruption, and demonstrating the ability to recover them within that tolerance. It also covers third-party risk management where a critical function depends on an outsourced provider. It is principles-based: FINMA sets the outcome and leaves the institution to design the control environment that gets there, which is different in character from a prescriptive EU regulation.
What DORA adds, and where it actually reaches a Swiss institution
DORA (the Digital Operational Resilience Act) is EU law covering ICT risk management, incident reporting, digital operational resilience testing and oversight of critical third-party ICT providers, with binding technical standards under it. It does not apply to a purely Swiss-domiciled entity by itself. It reaches a Swiss group in two common ways: through an EU-regulated subsidiary or branch that is itself in scope, and through contract, where an EU bank or insurer that is in scope requires its suppliers, including a Swiss counterparty, to demonstrate DORA-aligned controls as a condition of doing business.
Where the two regimes actually overlap
Both regimes converge on the same underlying questions: what are your critical functions, what is your tolerance for disruption to each, can you demonstrate recovery within that tolerance, and can you show equivalent discipline over the third parties those functions depend on. A control library built to answer those questions once, then mapped separately to FINMA 2023/1's supervisory expectations and DORA's specific technical requirements, avoids running two parallel programmes that ask the same internal stakeholders for the same evidence twice.
Where teams commonly run into difficulty
The common failure is treating FINMA 2023/1 and DORA as two separate compliance projects, often owned by different teams, each building its own critical function register and its own third-party risk process. The duplicated effort is the visible cost. The less visible cost is inconsistency: two registers that answer "what is critical" differently undermine both regulators' confidence in either answer.
How Bazzi Consulting helps
We build one control library and one critical function register that satisfies FINMA 2023/1's principles-based expectations and maps cleanly to DORA's specific requirements where they reach your organisation, so the underlying work is done once. See risk and resilience advisory for how this is scoped.