NewsSEALSQ takes a majority stake in Wecan Group — a CHF 5M investment to accelerate our AI Compliance Co-Pilot.
Wecan
Back to blog
Regulation11 min read· September 10, 2026

FinSA and FinIA for Swiss Asset Managers: Two Regimes, One Client File

FinIA decides who may manage third-party assets. FinSA decides how you must behave towards the client. They impose different duties on the same file, and the place firms get caught is the seam between them — where client segmentation, suitability evidence and AML risk classification are mistaken for one another.

by Wecan

Most Swiss asset managers now hold their FINMA authorisation, have a supervisory organisation, and have lived through at least one audit cycle. The licensing scramble is over. What remains is subtler and, on the evidence of supervisory samples, less well handled: two separate bodies of law impose two separate sets of duties on the same client file, and the two are routinely conflated.

The Financial Institutions Act (FinIA, LEFin) governs who may operate — authorisation, organisation, supervision. The Financial Services Act (FinSA, LSFin) governs how you must behave towards the client — segmentation, information, suitability, documentation. Anti-money-laundering law sits on top of both, with its own logic again. This article maps the three onto one file and marks the seams where firms get caught.

1. Two acts, two purposes

The distinction is easy to state and easy to forget under pressure.

FinIA is about the firm. Anyone managing third-party assets professionally in Switzerland needs FINMA authorisation and must affiliate with an approved supervisory organisation that conducts ongoing supervision, alongside an audit mandate. A little over 1,500 portfolio managers are now authorised. FinIA asks whether you are organised well enough to be trusted with the mandate at all: adequate resourcing, fit-and-proper management, risk management and internal control appropriate to your size, and a compliance function that actually functions.

FinSA is about the client relationship. It applies to the provision of financial services regardless of authorisation status, and it asks a different question: given this particular client, was this particular service appropriate, were they told what they needed to know, and can you show it?

The practical consequence is that satisfying one says nothing about the other. A firm can be impeccably organised under FinIA and still fail a FinSA sample because its suitability evidence lives in a relationship manager's memory. The audit will test both, from different angles, and often in the same visit.

2. FinIA in practice: what supervision actually samples

Under the old self-regulatory regime, a small firm could run due diligence on shared drives and reconstruct its reasoning if anyone asked. Ongoing supervision changed the question. It is no longer whether you reached a defensible conclusion, but whether you can demonstrate the process that produced it — consistently, across every file, on request.

That word consistently is where firms lose points. A supervisory organisation samples files. It is not looking for one excellent dossier; it is looking for whether two officers handling two comparable clients produced comparable work. Where each relationship manager keeps their own structure, their own naming, their own idea of what is worth writing down, the sample reveals variance — and variance is the finding, even when every individual file would have been defensible on its own.

The second recurring finding is the absence of a trail. A decision that exists but cannot be dated, attributed and justified is, for supervisory purposes, close to a decision that was never taken.

3. FinSA in practice: five duties that produce evidence

FinSA is often summarised as a conduct regime, which undersells how much documentation it generates. Five duties matter operationally.

Client segmentation. Every client must be classified — private, professional, or institutional — with the possibility of opting out of, or into, the higher protection. The classification determines which duties apply to that relationship, so it is the hinge on which everything else turns. It must be documented, communicated, and revisited when circumstances change.

Information duties. Clients must be told, before the service is provided, who you are, what service you offer, what risks it carries, what it costs, and how you handle conflicts of interest and third-party compensation. The obligation is not satisfied by a clause buried in a mandate signed years ago.

Appropriateness and suitability. For portfolio management and investment advice covering the whole portfolio, you must assess suitability — the client's financial situation, investment objectives, knowledge and experience, judged against the portfolio as a whole. For advice on individual transactions, appropriateness. For execution-only, neither, provided the boundary is genuinely respected. Firms drift across that boundary far more easily than they think, particularly when a relationship manager answers a question informally.

Documentation and accountability. You must record the service agreed and the information gathered, and be able to render account to the client on request. This is the duty that most often reveals itself as a gap only when a client — or their lawyer — asks.

Ombudsman affiliation. Financial service providers must affiliate with a recognised ombudsman body and inform clients of that possibility.

One nuance worth stating, because it causes recurring confusion: the client advisor register was designed for advisors of providers that are not prudentially supervised. Obtaining FinIA authorisation changes your position on that question — which is a good example of the two acts interacting rather than stacking. Confirm your own situation with your supervisory organisation rather than inferring it from a general statement, including this one.

4. The seam: three classifications that are not the same thing

Here is the mistake that produces findings, and it is almost always the same one. A client file carries at least three distinct classifications, and they answer different questions:

Classification Under which regime The question it answers
Private / professional / institutional FinSA How much protection does this client receive?
Suitability profile — objectives, knowledge, capacity FinSA Is this service right for this client?
AML risk rating — low, increased, high AMLA How much due diligence and monitoring does this relationship need?

A professional client can be a high AML risk. A private client with a conservative profile can be low risk. An experienced investor who understands derivatives perfectly may sit in a jurisdiction that mandates enhanced due diligence. The categories are orthogonal, and treating any one as a proxy for another produces exactly the finding a sample is designed to catch.

The operational failure mode is subtler than a wrong label. It is that the three classifications live in three places — the segmentation letter in one folder, the suitability questionnaire in a spreadsheet, the risk rating in the AML tool — and drift apart. A client is reclassified for FinSA purposes after a change in circumstances; the AML profile is not revisited; the periodic review cadence keeps running on the old rating. Nothing was decided wrongly. The file simply stopped telling one coherent story, and that is what an examiner reads.

5. The AML layer, and what changes on 1 October 2026

On top of both regimes sits anti-money-laundering law, which holds asset managers to the same substantive standard as any other financial intermediary: identify the client, establish the beneficial owner, build a risk profile, screen against sanctions and PEP lists, monitor on an ongoing basis, and conduct periodic reviews at a cadence set by risk.

That layer changes materially this autumn. From 1 October 2026, the Federal Act on the Transparency of Legal Entities and a revised AMLA introduce a federal beneficial-ownership register, tighten the obligation to identify the natural person who ultimately controls a legal entity regardless of intervening layers, and lower the thresholds at which beneficial ownership must be captured. We have covered that reform and its readiness checklist in detail in Swiss AML in 2026; this article does not repeat it.

What is worth saying here is how it interacts with the two acts above. Lowered thresholds mean more identified persons per corporate file. More identified persons mean more screening, more documentation, and more objects whose changes have to be monitored. For a firm whose FinSA and FinIA evidence is already spread across folders, that increase in volume is what turns a manageable inconsistency into an unmanageable one.

6. What this means for a firm with one compliance officer, or none

The obligations described above do not scale down to fit the team. A firm managing CHF 300–800 million across 150–300 relationships may have a single dedicated compliance officer, or none at all, with the managing partner absorbing the role alongside client work.

For that firm, the binding constraint is rarely knowledge of the rules. It is evidence production: being able to show, on a Tuesday afternoon, that the segmentation was communicated, the suitability assessment was made before the service, the AML risk rating was reviewed at the right cadence, and the same standard was applied to the file opened last month and the one opened three years ago.

There is no rule requiring software, and it would be self-serving to pretend otherwise. Below roughly 150 relationships, disciplined manual processes or an outsourced compliance mandate can meet the standard. Above that, the per-file cost of manual work and the difficulty of proving consistency across officers usually make tooling the cheaper option — not because the rules demand it, but because arithmetic does.

7. A practical readiness check

Six questions. If any answer is uncomfortable, that is where to look first.

  • Can you produce, for any client, the segmentation decision with its date and the person who made it?
  • Is the suitability assessment demonstrably prior to the service, or only contemporaneous with the file?
  • When a client's circumstances change, does one update propagate to the FinSA classification, the suitability profile and the AML risk rating — or only to whichever one someone remembered?
  • Would two officers handling comparable clients produce comparable files?
  • Can you render account to a client, or an examiner, without reconstructing anything from memory?
  • After 1 October 2026, do you know which of your corporate files will require additional beneficial owners to be identified?

8. Frequently asked questions

What is the difference between FinSA and FinIA?

FinIA (LEFin) governs the firm: who may manage third-party assets professionally, under what authorisation, with what organisation and under whose ongoing supervision. FinSA (LSFin) governs the client relationship: how clients must be segmented, informed, assessed for suitability, and documented. Complying with one says nothing about the other, and an audit will typically test both.

Does FinSA apply to us if we already hold a FinIA authorisation?

Yes. The two acts address different questions and apply in parallel. Authorisation under FinIA does affect specific points of interaction — the client advisor register being the most commonly cited — but it does not displace the conduct duties. Confirm your own position with your supervisory organisation rather than reasoning from a general rule.

Is a client's FinSA segmentation the same as their AML risk rating?

No, and treating one as a proxy for the other is a recurring source of findings. Segmentation answers how much protection the client receives under FinSA. The AML risk rating answers how much due diligence and monitoring the relationship requires. A professional client can be high risk; a private client can be low risk. They are set independently and must be maintained independently.

What do supervisory organisations actually sample?

Files, not policies. The recurring findings are variance between officers handling comparable clients, and decisions that exist but cannot be dated, attributed or justified. A single excellent dossier does not answer the question a sample is asking, which is whether your process produces consistent work across the whole book.

What changes for asset managers on 1 October 2026?

The Federal Act on the Transparency of Legal Entities and a revised AMLA introduce a federal beneficial-ownership register, tighten identification of the ultimate controlling natural person across intervening layers, and lower the capture thresholds. Practically, expect more identified persons per corporate file, and therefore more screening and more monitoring. The detailed readiness guidance is in our article on Swiss AML in 2026.

Do we need software to comply?

No rule requires it. Below roughly 150 client relationships, disciplined manual processes or an outsourced compliance mandate can meet the standard. Above that threshold, the per-file cost of manual work and the difficulty of demonstrating consistency across officers usually make tooling the cheaper route. The decision is one of arithmetic and evidence, not of regulatory obligation.

9. Where Wecan fits

Wecan Comply was built with Swiss asset managers and their custodian banks rather than for them, which shaped one design decision that matters here: the client file is a single object carrying its FinSA segmentation, its suitability evidence, its AML risk rating and its supporting documents together, with every change dated, attributed and justified. Updating one classification prompts review of the others rather than leaving them to drift apart in separate folders.

What it does not do is decide your classifications for you, or make a small book worth automating. If you are below the threshold where the arithmetic works, we will say so.

See Wecan in action. In 30 minutes.

A live walkthrough on real KYC scenarios — no slides, no commitment. Just see if it fits your context.