FINMA Guidance 08/2024, published on 18 December 2024, describes FINMA's observations from ongoing supervision on governance and risk management when supervised institutions use artificial intelligence. It states that Switzerland has no AI-specific legislation and that FINMA expects institutions to align governance, risk management and control systems with AI's impact on their risk profile under existing technology-neutral requirements. The guidance covers seven areas: governance, inventory and risk classification, data quality, tests and ongoing monitoring, documentation, explainability and independent review. For banks, the practical takeaway is to maintain a complete AI inventory with risk classification, defined responsibilities, tested and monitored applications and independent review of material ones.
OFFICIAL TEXT: finma.ch ↗ · FINAL · FINMA
| Document | FINMA Guidance 08/2024 — FINMA Guidance 08/2024: Governance and risk management when using artificial intelligence |
| Issued by | Swiss Financial Market Supervisory Authority (FINMA) |
| Type | Guidance |
| Status | Final |
| Published | Dec 18, 2024 |
| Applies to | Institutions supervised by FINMA that develop or use AI, including banks and securities firms, with the depth of governance scaled to the institution's size, complexity, structure and risk profile and to the materiality of its AI applications. Guidance, not a rule: it reports FINMA's supervisory observations and assessments. |
| Official source | finma.ch ↗ |
| Use cases | AI governance (general) · Model risk management · Third-party & vendor AI · Data & privacy · Generative & agentic AI |
What are the key points of FINMA Guidance 08/2024?
- Published 18 December 2024; 7 pages. Section 1 states there is no AI-specific legislation in Switzerland and that technology-neutral, principle-based governance and risk-management requirements cover AI risks.
- Section 1 materiality factors (footnote 2) include significance for compliance with financial market legislation, financial impact, legal and reputational risk, number and type of clients affected and consequences of errors; likelihood factors include complexity, data type, degree of autonomy, short calibration cycles and outsourcing.
- Section 2 names the main risks: operational risks (model risk — robustness, correctness, bias, explainability), IT and cyber risks, third-party dependency in a concentrated market, and legal and reputational risks, including unclear allocation of responsibility.
- Section 2.1 Governance: FINMA observed a focus on data protection rather than model risk, decentralised development and difficulty identifying AI in purchased applications; it assessed central inventories, accountabilities, testing requirements, documentation standards, training and, for outsourcing, additional tests, controls and contractual clauses.
- Section 2.2 Inventory and risk classification: FINMA saw AI defined too narrowly and incomplete inventories; it assessed whether a sufficiently broad AI definition (it cites the OECD approach) and risk classification are used, and states that AI is not a high-risk application per se.
- Sections 2.3 and 2.4: data quality requirements and controls (completeness, correctness, integrity, representativeness) and tests and ongoing monitoring (accuracy, robustness, stability, bias, data-drift detection, predefined thresholds, analysis of user overrides).
- Sections 2.5 to 2.7: documentation of purpose, data, model selection, performance, assumptions, limitations, testing, controls and fallback solutions for material applications; explainability where decisions must be justified to clients, investors, employees, supervisors or auditors; and independent review of the whole development process.
- Section 3 outlook: FINMA will refine its expectations in line with international developments and, where necessary, make them transparent in the market, seeking a technology-neutral, proportional approach across sectors.
What did FINMA Guidance 08/2024 change for banks?
The guidance converts FINMA's 2023–2024 on-site and supervisory-dialogue findings into published expectations for AI governance without new legislation. For Swiss banks it clarifies that AI is supervised through existing operational-risk, governance and outsourcing requirements, and it signals what examiners test: a complete inventory, a broad AI definition, central responsibilities, data-quality controls, drift monitoring, explainability and independent review.
What does FINMA Guidance 08/2024 require of banks using AI?
FINMA Guidance 08/2024 expects supervised institutions that use AI to identify, assess, manage and monitor the resulting risks within their existing governance and risk-management framework. FINMA's published observations and assessments cover seven areas: AI governance with central inventory and defined accountabilities, a broad AI definition and risk classification, data quality requirements and controls, tests and ongoing monitoring including data-drift detection, documentation of material applications, explainability sufficient to justify decisions, and independent review of the development process. The guidance is not a new rule, since Switzerland has no AI-specific legislation, but it shows what FINMA examines in supervision. It applies in proportion to the size, complexity and risk profile of the institution and the materiality of each AI application.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Section 1 — Technology-neutral governance and risk management | FINMA | Align governance, risk management and control systems with AI's impact on the risk profile, considering materiality and the probability that risks materialise. | Published 18 December 2024 |
| Section 2.1 — Governance | FINMA | Have AI governance with a central inventory and risk classification, defined responsibilities for development, implementation, monitoring and use, testing requirements, documentation standards and training; for outsourcing, additional tests, controls and contractual clauses. | Published 18 December 2024 |
| Section 2.2 — Inventory and risk classification | FINMA | Use a sufficiently broad definition of AI, keep inventories complete and classify applications by materiality and probability of risks. | Published 18 December 2024 |
| Section 2.3 — Data quality | FINMA | Define requirements in internal rules to ensure data is complete, correct and of integrity and that availability and access are secured. | Published 18 December 2024 |
| Section 2.4 — Tests and ongoing monitoring | FINMA | Schedule tests for data quality, accuracy, robustness, stability and where needed bias; define performance indicators and thresholds; monitor input-data changes and user overrides. | Published 18 December 2024 |
| Section 2.5 — Documentation | FINMA | For material applications, document purpose, data selection and preparation, model selection, performance measures, assumptions, limitations, testing, controls and fallback solutions. | Published 18 December 2024 |
| Section 2.6 — Explainability | FINMA | Where decisions must be justified to clients, employees, supervisors or auditors, understand the drivers and behaviour of the application well enough to assess plausibility and robustness. | Published 18 December 2024 |
| Section 2.7 — Independent review | FINMA | For material applications, separate development from independent review of the whole model development process by qualified personnel. | Published 18 December 2024 |
Section 2 is framed as observations and assessments rather than commands: 'FINMA observed' deficiencies at some institutions and 'assessed' whether others had measures in place. In practice it is the template FINMA uses in supervisory dialogue and inspections, which its earlier dossier says have included on-site inspections of institutions deploying AI extensively since the fourth quarter of 2023.
FINMA's 24 April 2025 survey of around 400 institutions found that about half use AI or have initial applications in development and that 91% of AI users also use generative AI, with dependence on BigTech providers growing — the same third-party risk the guidance flags.
The guidance cites international work, including the FSB's November 2024 report on the financial stability implications of AI, and the outlook says FINMA will refine expectations in line with international developments.
WHAT THIS MEANS IN PRACTICE
- Build and maintain a firm-wide AI inventory, including AI embedded in purchased software and generative AI used by staff.
- Classify each application by materiality and likelihood of risk, and scale testing, documentation and review accordingly.
- Set data-quality requirements and drift monitoring, and track cases where users override AI outputs.
- Document material applications end to end, including fallback solutions.
- Make sure someone independent of the developers reviews material models, and tighten contracts and controls for outsourced AI.
Does FINMA Guidance 08/2024 apply to banks?
Yes, to institutions supervised by FINMA, which include banks and securities firms. The depth of governance depends on the institution's size, complexity, structure and risk profile and on the materiality of its AI applications.
Is FINMA Guidance 08/2024 binding?
It is supervisory guidance describing FINMA's observations and the measures it assessed, not a new rule. It rests on binding technology-neutral governance, risk-management and operational-risk requirements; FINMA states there is no AI-specific legislation in Switzerland.
What does FINMA expect banks to do about AI inventories?
FINMA assessed whether institutions with many or significant AI applications keep a centrally managed inventory with risk classification and resulting measures, using a sufficiently broad definition of AI. It saw narrow definitions and incomplete inventories, particularly with decentralised use and generative AI.
How does FINMA Guidance 08/2024 compare with the EU AI Act?
The EU AI Act is binding law with risk categories; FINMA's guidance is technology-neutral and principle-based and says AI is not high-risk per se, with risk depending on complexity, adaptivity, autonomy, area of application and process integration. Swiss institutions that serve EU customers may be subject to both.
| Date | Document | Status |
|---|---|---|
| Sep 30, 2026 | SB 947 — Employment: Automated Decision Systems (No Robo Bosses Act) | Final |
| Sep 30, 2026 | Bailey: Frontier AI and the Question of Governance (Sep 2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey | Final |
| Sep 28, 2026 | AB 1609 — Customer Service Chatbots (Right to Human Customer Service Act) | Final |
| Sep 10, 2026 | Atkins remarks at Investor Advisory Committee (Sep 2026) — Remarks at the SEC Investor Advisory Committee Meeting on AI Technologies and the Public Markets Information Ecosystem | Final |
| Sep 2, 2026 | FCA multi-firm review: Frontier AI and cyber resilience (Sep 2026) — Frontier AI and Cyber Resilience | In force |
| Aug 31, 2026 | FSB Chair's letter to G20 (Aug 2026) — FSB Chair's letter to G20 Finance Ministers and Central Bank Governors: August 2026 — risks arising from frontier artificial intelligence models | Final |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning