Skip to content

Blog

Cloud and FINMA: what your provider must put in the contract

Circulars 2018/3 and 2023/1: clauses to demand from a cloud provider. Practical for Swiss financial institutions. Not legal advice. Hikube does not certify your FINMA file.

Hidora article published 21 August 2026. Figures, prices and comparisons are as of that date.

What Circulars 2018/3 and 2023/1 actually require of your cloud contract, and why the location of the servers is not enough.

FINMA Circular 2023/1 on operational risk has been in force since 1 January 2024. It adds to Circular 2018/3 on outsourcing, which remains the reference text for any move to the cloud. What both texts establish unambiguously: a Swiss financial institution entrusting an essential function to a cloud provider remains solely answerable to FINMA, exactly as if it ran that infrastructure itself.

A provider can have servers in Switzerland, hold an ISO 27001 certification and offer a 99.99% SLA, and still fail FINMA requirements if the appropriate contractual clauses are missing from the contract. This guide details the two applicable texts, the five non-negotiable clauses, and the three misconceptions that expose the most institutions to a compliance risk.

Are you concerned by the FINMA circulars on cloud?

Quick qualification:

  • Status: Are you a bank, a securities dealer, an insurer or a FinIA company with its seat in Switzerland?
  • Nature of the function: Does the function entrusted to the provider significantly condition compliance with financial market legislation?
  • Examples concerned: core banking hosting, customer data storage, authentication infrastructure, critical compute environments.

If the first two criteria are met: Circulars 2018/3 and 2023/1 apply in full, whatever the size of the institution.

Circulars 2018/3 and 2023/1, the two texts framing your financial cloud

FINMA Circular 2018/3 "Outsourcing" came into force on 1 April 2018. It applies to banks, securities dealers, insurers and FinIA companies with their seat in Switzerland, and to the Swiss branches of foreign institutions. Its purpose is precise: to frame the conditions under which an institution may outsource an essential function to a third party, by defining the organisational and contractual requirements that outsourcing must respect.

Circular 2023/1 completed that framework by introducing an updated approach to operational risk management, with particular attention to information and communication technology, cyber risk and the notion of critical data. It has applied since 1 January 2024 and dovetails directly with 2018/3: the two texts work together as soon as the outsourced function is qualified as essential.

A point frequently overlooked, FINMA requires no prior approval for the use of public cloud. The institution is free to choose its provider, including among international hyperscalers, provided the contractual and organisational requirements are met.

What it changes concretely for your organisation

The first impact is non-delegable responsibility. Whatever the provider's service level, the outsourcing institution answers to FINMA for the outsourced function exactly as if it performed it itself. There is no transfer of regulatory responsibility to the provider, even when the provider is contractually at fault.

The second impact concerns the structure of the contract. Any outsourcing of an essential function must rest on a written agreement containing specific clauses defined by Circular 2018/3. A standard cloud contract, even signed with a recognised market player, does not automatically satisfy those requirements. It is for the institution to verify, clause by clause, that the contract proposed by its provider complies.

The third impact concerns the right of audit. FINMA and the institution's external auditor must be able to exercise a complete, permanent and unrestricted right of examination over the provider, including at its subcontractors. That right has to be explicitly provided for in the contract. Without that clause, the institution cannot demonstrate its compliance during an inspection.

The five contractual clauses FINMA requires in your cloud contract

These five clauses follow directly from Circular 2018/3 and were reaffirmed in the SBA Cloud Guidelines published in November 2025 by the Swiss Bankers Association. They are non-negotiable for any outsourcing qualified as essential.

1. Written description of the outsourced function. The contract must explicitly designate the parties and describe precisely the function entrusted to the provider. A generic description such as "cloud hosting services" is not enough.

2. Permanent and unrestricted right of audit. The institution, its external auditor and FINMA must hold a contractual right of complete examination over the outsourced function, including at the provider's subcontractors. That right must be exercisable without delay or restriction, in Switzerland or abroad if the data is processed there.

3. Control of subcontractors. Any use of a subcontractor by the provider must be subject to the institution's prior agreement. The contract must provide that the institution be informed early enough of any change of essential subcontractor and that it may terminate the contract if it refuses that change.

4. Contractualised security requirements. The security measures applying to the data processed by the provider must be defined in the contract: protection of critical data, encryption in transit and at rest, access control, logging. Those requirements must match the institution's risk profile.

5. Documented exit plan. The contract must guarantee data portability in open formats, provide a reasonable notice period for termination, and ensure the continuity of the outsourced function should the provider fail or become insolvent.

FINMA criterionUS provider (CH servers)Sovereign Swiss provider
Written description of the functionPossible depending on the contractIncluded by default
Permanent FINMA right of auditLimited, US jurisdiction appliesGuaranteed contractually
Control of subcontractorsOpaque chain, international subcontractorsDocumented chain, infrastructure in Switzerland
Security requirementsTo be negotiated, standard contract insufficientISO 27001 and nFADP contractualised
Exit planOften limited, proprietary formatsOpen formats, contractualised notice
Applicable jurisdictionUS CLOUD Act (extraterritorial law)Swiss law only

* Sources: FINMA Circular 2018/3, SBA Cloud Guidelines November 2025 (Swiss Bankers Association)

This table illustrates a point many institutions discover at audit time, FINMA compliance is not verified on the provider's datasheet but in the signed contract. To go deeper into migrating to a sovereign Swiss cloud, our complete guide covers the transition steps and the contractual points to watch.

Three misconceptions about FINMA compliance and the cloud

Misconception 1: "FINMA has to approve our choice of cloud provider"

What the regulation actually says: No prior FINMA approval is required for using public cloud, including with international players. Circular 2018/3 rests on a principles-based approach: it is for the institution to make sure the conditions are met, not for FINMA to validate each choice. Particular cases may justify informing FINMA in advance, but they remain exceptional.

Misconception 2: "Our provider is ISO 27001 certified, so we are FINMA compliant"

What the regulation actually says: ISO 27001 certification attests to an information security management system. It is necessary but insufficient for FINMA requirements. Circulars 2018/3 and 2023/1 impose specific contractual clauses that go beyond what ISO 27001 covers: the FINMA right of audit, control of subcontractors, the exit plan, and qualification of the applicable jurisdiction. An ISO 27001 certified provider that does not guarantee the FINMA right of audit contractually is not compliant.

Misconception 3: "Only large banks are concerned by these requirements"

What the regulation actually says: Circular 2018/3 applies to every institution under FINMA supervision that outsources an essential function, with no size threshold. A ten-person wealth manager hosting its customer CRM on an American cloud without the required contractual clauses is in non-compliance just as a large bank would be. Proportionality applies to how the measures are implemented, not to the obligation to adopt them.

Frequently asked questions

Can a Swiss financial institution use AWS or Azure?

Yes. FINMA permits the use of public cloud without prior approval, including with American providers. The institution remains solely responsible for compliance with Circulars 2018/3 and 2023/1. That means obtaining contractually the rights of audit, the control of subcontractors, the protection of critical data and an adequate exit plan. Those clauses must appear in the signed contract, not in non-binding annexed documentation.

Is having the servers in Switzerland enough for FINMA compliance?

No. FINMA assesses the jurisdiction applying to the provider's parent company, not only the physical location of the servers. An American provider whose datacenters are in Switzerland remains subject to the US CLOUD Act, which can let American authorities access the hosted data. That situation can conflict directly with the requirements of Swiss banking secrecy and with the exclusive right of audit FINMA must be able to exercise.

Which clauses must a FINMA-compliant cloud contract contain?

The contract must include five non-negotiable elements under Circular 2018/3: the written description of the outsourced function, the permanent right of audit for the institution, its external auditor and FINMA, the institution's mandatory prior agreement for any use of a subcontractor, the security requirements applying to critical data, and an exit plan guaranteeing data portability in usable formats.

In short, three key points

FINMA compliance rests on the contract, not on location

The five clauses imposed by Circular 2018/3 are non-negotiable with any provider. A provider with servers in Zurich and a standard contract is not compliant. A provider with servers in Dublin and a contract including the five clauses can be. The compliance audit starts by reading the contract, not by checking the datacenter's address.

Responsibility stays with the institution, even under total outsourcing

Circular 2018/3 is explicit: the institution answers to FINMA as if it performed the outsourced functions itself. Choosing a provider that eases the exercise of the right of audit, documents its subcontracting chain and operates under Swiss jurisdiction is not a preference, it is an operational condition. Financial institutions wanting to go deeper will find complementary perspective in our article on why sovereign cloud is indispensable for Swiss companies.

Public cloud is permitted, provided the contract complies from signature

There is no obligation to use a private cloud or a Swiss provider to meet FINMA requirements. What counts is that the five contractual clauses are present in the initial contract. Renegotiating them after a critical infrastructure has gone live is technically possible but operationally risky. The contractual check has to precede the choice of provider, not follow it.

Your cloud infrastructure has to meet FINMA requirements. The Hikube team supplies the items an outsourcing file calls for, operator, sites, certificates, audit clauses, and helps you match them against Circulars 2018/3 and 2023/1. The file itself stays yours: Hikube is neither your auditor nor your counsel. The evidence is on security and compliance, the qualification path on Finance & FINMA. Talk to our team.

Ready to run on 100% Swiss infrastructure?

14-day trial, no credit card. GPUs included.