23/02/23
On 13 December 2022, the Swiss Financial Market Supervisory Authority FINMA published the fully revised circular on operational risks and resilience at banks (FINMA Circular 2023/1). With this circular, FINMA refines its supervisory practice regarding the management of operational risks, particularly in connection with information and communication technology, handling of critical data and cyber risks. In addition, the revision incorporates the requirements for operational resilience.
The circular will enter into force on 1 January 2024, where additional gradual transitional provisions for ensuring operational resilience apply over two years.
Chapter IV, letter D – ‘Critical data risk management’ of the FINMA Circular 2023/1 expands the previous focus on confidentiality of Client Identification Data (CID) to include the dimensions integrity and availability of critical data. Critical data is defined as data considered to be significant for the successful and sustainable provision of services or data required for regulatory purposes.
To ensure compliance with the requirements regarding critical data risk management of FINMA Circular 2023/1, organisations need to specifically address the following topics:
Please do not hesitate to contact us if you are interested in an exchange on how we can support you in becoming compliant with the FINMA Circular 2023/1 or require assistance for any other topic related to data management.
#social#