Choosing compliance software as a Swiss external asset manager comes down to identifying which shape of problem you actually have. If your bottleneck is due-diligence data and screening, you need a data toolbox. If it is inconsistent, undocumented processes, you need workflow orchestration. If it is documenting the same end client separately for every custodian bank you work with, you need a shared record — and no amount of internal automation will fix it, because the duplication happens between institutions, not inside yours.
Most selection exercises fail because they compare feature lists before naming the problem. This guide is written for the compliance officer or managing partner of a FINMA-authorised portfolio manager, and gives you a way to diagnose before you shortlist. We disclose our position: Wecan builds one of these platforms. We say where it fits and where it does not.
1. What the FinIA regime changed for tooling
Since the Financial Institutions Act (FinIA/LEFin) came into force, anyone managing third-party assets professionally in Switzerland needs FINMA authorisation and must affiliate with a FINMA-approved supervisory organisation that carries out ongoing supervision, alongside an audit mandate. The authorisation wave is essentially complete: a little over 1,500 portfolio managers are now authorised and supervised.
That transition changed what compliance tooling has to deliver. Under the previous regime, a small firm could run due diligence on shared drives and spreadsheets and reconstruct the reasoning if anyone asked. Under ongoing supervision, the question is no longer whether you reached a defensible conclusion but whether you can demonstrate the process that produced it — consistently, across every file, on request, to a supervisory organisation and an auditor who will sample your work.
That is a documentation and repeatability requirement before it is a technology requirement. It is also why "we have a folder structure and a checklist" stopped being an answer.
2. The three shapes of the problem
Swiss compliance software for asset managers clusters into three families. They are not competitors in the ordinary sense — they address different failures, and firms often need more than one.
| Your symptom | The shape of the problem | What you are actually buying |
|---|---|---|
| Screening is slow, false positives swamp you, registry data is manual | Data and screening | Access to due-diligence data sources, sanctions/PEP/adverse-media coverage, registry lookups — a toolbox you call when you need it |
| Every officer does onboarding slightly differently; you cannot prove consistency to your supervisory organisation | Process | A configurable workflow engine that encodes your risk-based approach into steps, with an audit trail — orchestration across whichever data vendors you use |
| The same end client is documented three or four times, once per custodian bank, and each bank asks again at its own review cycle | Multi-bank duplication | A shared, permissioned record that one maintained file serves every banking relationship from |
The Swiss market has recognisable examples of each. KYC Spider positions itself as a modular due-diligence toolbox with Swiss-hosted infrastructure. Atfinity positions itself around orchestration — configuring processes so multiple vendors work together rather than against each other. Wecan Comply is built around the shared record between an asset manager and its custodian banks, and connects to existing screening providers rather than replacing them.
Diagnose honestly. If your real problem is the third one and you buy a solution to the first, you will automate your side of a duplication you are still performing four times.
3. Selection criteria that differ from a bank's
Most published buyer's guides are written for banks. An authorised portfolio manager carries a comparable obligation with a fraction of the resources, which changes what "good" means.
| Criterion | What good looks like for an EAM | Why it differs from a bank |
|---|---|---|
| Operable by one or two people | A compliance officer wearing three hats can run the full cycle without a specialist administrator | A bank has a dedicated KYC team; you do not. A platform needing a full-time administrator is a hidden headcount cost |
| Custodian-bank compatibility | Output the banks you actually work with will accept, ideally without rekeying | A bank is the endpoint. You are in the middle, and your output has to satisfy several endpoints at once |
| Evidence export for your supervisory organisation | One-click, timestamped file history you can hand to an auditor or your SO | Banks have internal audit functions and established reporting; your evidence has to travel outside the firm |
| Swiss or EEA data residency | Explicit hosting location, documented, contractually fixed | Client confidentiality expectations in Swiss wealth management are stricter than generic GDPR compliance |
| Cost per file, not enterprise licence | Pricing that scales down to a few hundred clients without a floor priced for a bank | Enterprise licensing models make the per-client economics unworkable below a certain size |
| Weeks to deploy, not quarters | Configured and live within a quarter, without a systems-integration programme | You have no project office to run a twelve-month implementation |
Score a shortlist on these six before looking at any feature demo. A platform that wins on features and loses on the first and fifth criterion will not survive contact with your operating reality.
4. Swiss hosting and data residency
For a Swiss asset manager this is rarely a preference and often a client commitment. Ask three questions and require documented answers: where is the data physically stored, where is it processed (which can differ, particularly for AI features), and who else can access it under which legal regime.
Vendors serving this market usually address it explicitly — Swiss-hosted infrastructure is a common and reasonable answer, as is Swiss-or-EEA hosting for firms with cross-border books. What matters is that the answer is contractual rather than reassuring, and that it covers processing as well as storage.
5. What LETA changes from 1 October 2026
The Transparency Act on Legal Entities (LETA/LTPM, TJPG in German, LTPG in Italian) enters into force on 1 October 2026, establishing a federal beneficial-ownership register and reinforced duties to establish and maintain ownership information. We cover the substance in our guide to Swiss AML in 2026.
The selection consequence is narrower than the regulatory one. LETA rewards maintained ownership data over verified-once ownership data, because the obligation is continuous. Ask any vendor on your shortlist a single concrete question: when a client's beneficial ownership changes, what happens without anyone remembering to look? If the honest answer is "it surfaces at the next periodic review", the platform is built on the assumption the regime is moving away from. This is the same shift we describe in perpetual KYC.
6. Build, buy, or outsource
Asset managers have a third option banks rarely consider seriously.
Build is almost never right at this scale. The cost is not the initial build, it is maintaining screening-source integrations and regulatory change across a shifting landscape with no dedicated engineering team.
Outsource to a compliance consultant is a legitimate and common Swiss answer, particularly below roughly 150 client relationships. You buy judgement along with capacity. The limit is that outsourcing the work does not transfer the obligation, and you will still need a defensible record of how each decision was reached.
Buy is right when file volume makes per-file manual cost the dominant expense, when several custodian banks multiply the same work, or when your supervisory organisation has asked for evidence of consistency you cannot currently produce.
Those three are combinable: many firms buy the platform and retain a consultant for judgement on complex files.
7. Red flags in a demo
- The demo shows a clean individual client. Ask for a complex corporate structure with a trust in the chain, end to end, nothing done outside the system.
- Screening is demonstrated on a name with no false positives. Ask for a common name and watch the triage.
- Nobody can say where the data is processed, only where it is stored.
- The audit trail is described but not shown. Ask to export one file's full history as an auditor would receive it.
- Pricing requires a call to answer whether it works at your client count.
- The AI features cannot show their reasoning. In a supervised function, a recommendation you cannot explain to your SO is a liability, not an efficiency — which is the distinction we draw in what an AML copilot actually does.
8. Frequently asked questions
Do Swiss external asset managers need KYC software?
There is no rule requiring software. FinIA requires authorisation, ongoing supervision by an approved supervisory organisation, and demonstrably consistent processes. Firms below roughly 150 client relationships can meet that with disciplined manual processes or an outsourced compliance mandate; above that, per-file manual cost and the difficulty of proving consistency across officers usually make tooling the cheaper option.
What is the difference between KYC software and compliance orchestration?
KYC software generally means access to due-diligence data and verification checks. Orchestration means configuring the process that decides which checks run, in what order, and what happens to the result. A firm can hold excellent data sources and still fail a supervisory review because its process was undocumented and applied inconsistently.
Can one platform serve several custodian banks?
Yes, and this is the specific gap that generic KYC tools leave open for asset managers. The relevant question is not whether a platform can export a file, but whether the banks you work with accept the output without rekeying it. Ask which of your custodians are already connected before you assume compatibility.
How long does implementation take for a small firm?
Expect four to twelve weeks for a firm with a few hundred client relationships, most of it spent agreeing your risk-based methodology and migrating existing files rather than on technical configuration. Any quote materially longer than that is describing a bank-scale programme.
Does LETA require new software from 1 October 2026?
No. It raises the standard for establishing and maintaining beneficial-ownership information. Firms already maintaining ownership data continuously will find it a documentation exercise; firms verifying ownership once at onboarding and revisiting it at periodic review will find the gap structural rather than administrative.
9. How Wecan fits — and when it does not
Wecan Comply is built for the third shape of the problem. An external asset manager maintains one authoritative due-diligence record per end client and shares it, with explicit and revocable permission, with each custodian bank that needs it. Update once, and the change propagates to every connected bank rather than surfacing separately at each bank's next review. It connects to existing screening providers — World-Check, LexisNexis, ComplyAdvantage, Sumsub, KYC Spider, Polixis — so adopting it does not mean abandoning data sources you already trust, and it is hosted in Switzerland or Luxembourg.
Where it is not the right answer: if you work with a single custodian bank and your problem is screening quality rather than duplication, a data toolbox will serve you better and cost less. If your processes are undocumented and inconsistent across officers, fix that first — a shared record propagates whatever discipline you put into it, including the absence of any.
For the regulatory background rather than the selection question, see our KYC and AML playbook for external asset managers.
