|
FINMA Circular 2023/1 Operational Risks and ResilienceFINMA
|
Banks and other supervised institutions within the circular’s scope |
Operational-risk management, critical functions, resilience tolerances, business continuity, incident management, outsourcing and reporting. |
|
Source
|
|
FINMA Corporate Governance CircularsFINMA
|
Banks and insurers within the relevant circulars’ scope |
Board responsibilities, risk appetite, internal controls, compliance, internal audit independence and governance reporting. |
|
Source
|
|
Directive on Information Relating to Corporate GovernanceSER
|
Issuers subject to SIX listing rules |
Transparent governance disclosure, board and committee structures, control mechanisms, audit information and accountability. |
|
Source
|
|
Mandatory Cyber-Incident Notification for Critical InfrastructureNCSC
|
Critical-infrastructure operators within the national notification regime |
Critical-incident assessment, timely reporting, response coordination, service recovery and documented follow-up. |
|
Source
|
|
Federal Act on Data Protection, Article 24 Breach NotificationFDPIC
|
Controllers handling personal data within the FADP’s scope |
High-risk breach assessment, regulatory notification, data-subject communication, response documentation and corrective action. |
|
Source
|