Most Swiss asset managers now hold their FINMA authorisation, have a supervisory organisation, and have lived through at least one audit cycle. The licensing scramble is over. What remains is subtler and, on the evidence of supervisory samples, less well handled: two separate bodies of law impose two separate sets of duties on the same client file, and the two are routinely conflated.
The Financial Institutions Act (FinIA, LEFin) governs who may operate — authorisation, organisation, supervision. The Financial Services Act (FinSA, LSFin) governs how you must behave towards the client — segmentation, information, suitability, documentation. Anti-money-laundering law sits on top of both, with its own logic again. This article maps the three onto one file and marks the seams where firms get caught.
1. Two acts, two purposes
The distinction is easy to state and easy to forget under pressure.
FinIA is about the firm. Anyone managing third-party assets professionally in Switzerland needs FINMA authorisation and must affiliate with an approved supervisory organisation that conducts ongoing supervision, alongside an audit mandate. A little over 1,500 portfolio managers are now authorised. FinIA asks whether you are organised well enough to be trusted with the mandate at all: adequate resourcing, fit-and-proper management, risk management and internal control appropriate to your size, and a compliance function that actually functions.
FinSA is about the client relationship. It applies to the provision of financial services regardless of authorisation status, and it asks a different question: given this particular client, was this particular service appropriate, were they told what they needed to know, and can you show it?
The practical consequence is that satisfying one says nothing about the other. A firm can be impeccably organised under FinIA and still fail a FinSA sample because its suitability evidence lives in a relationship manager's memory. The audit will test both, from different angles, and often in the same visit.
2. FinIA in practice: what supervision actually samples
Under the old self-regulatory regime, a small firm could run due diligence on shared drives and reconstruct its reasoning if anyone asked. Ongoing supervision changed the question. It is no longer whether you reached a defensible conclusion, but whether you can demonstrate the process that produced it — consistently, across every file, on request.
That word consistently is where firms lose points. A supervisory organisation samples files. It is not looking for one excellent dossier; it is looking for whether two officers handling two comparable clients produced comparable work. Where each relationship manager keeps their own structure, their own naming, their own idea of what is worth writing down, the sample reveals variance — and variance is the finding, even when every individual file would have been defensible on its own.
The second recurring finding is the absence of a trail. A decision that exists but cannot be dated, attributed and justified is, for supervisory purposes, close to a decision that was never taken.
3. FinSA in practice: five duties that produce evidence
FinSA is often summarised as a conduct regime, which undersells how much documentation it generates. Five duties matter operationally.
Client segmentation. Every client must be classified — private, professional, or institutional — with the possibility of opting out of, or into, the higher protection. The classification determines which duties apply to that relationship, so it is the hinge on which everything else turns. It must be documented, communicated, and revisited when circumstances change.
Information duties. Clients must be told, before the service is provided, who you are, what service you offer, what risks it carries, what it costs, and how you handle conflicts of interest and third-party compensation. The obligation is not satisfied by a clause buried in a mandate signed years ago.
Appropriateness and suitability. For portfolio management and investment advice covering the whole portfolio, you must assess suitability — the client's financial situation, investment objectives, knowledge and experience, judged against the portfolio as a whole. For advice on individual transactions, appropriateness. For execution-only, neither, provided the boundary is genuinely respected. Firms drift across that boundary far more easily than they think, particularly when a relationship manager answers a question informally.
Documentation and accountability. You must record the service agreed and the information gathered, and be able to render account to the client on request. This is the duty that most often reveals itself as a gap only when a client — or their lawyer — asks.
Ombudsman affiliation. Financial service providers must affiliate with a recognised ombudsman body and inform clients of that possibility.
One nuance worth stating, because it causes recurring confusion: the client advisor register was designed for advisors of providers that are not prudentially supervised. Obtaining FinIA authorisation changes your position on that question — which is a good example of the two acts interacting rather than stacking. Confirm your own situation with your supervisory organisation rather than inferring it from a general statement, including this one.
4. The seam: three classifications that are not the same thing
Here is the mistake that produces findings, and it is almost always the same one. A client file carries at least three distinct classifications, and they answer different questions:
| Classification | Under which regime | The question it answers |
|---|---|---|
| Private / professional / institutional | FinSA | How much protection does this client receive? |
| Suitability profile — objectives, knowledge, capacity | FinSA | Is this service right for this client? |
| AML risk rating — low, increased, high | AMLA | How much due diligence and monitoring does this relationship need? |
A professional client can be a high AML risk. A private client with a conservative profile can be low risk. An experienced investor who understands derivatives perfectly may sit in a jurisdiction that mandates enhanced due diligence. The categories are orthogonal, and treating any one as a proxy for another produces exactly the finding a sample is designed to catch.
The operational failure mode is subtler than a wrong label. It is that the three classifications live in three places — the segmentation letter in one folder, the suitability questionnaire in a spreadsheet, the risk rating in the AML tool — and drift apart. A client is reclassified for FinSA purposes after a change in circumstances; the AML profile is not revisited; the periodic review cadence keeps running on the old rating. Nothing was decided wrongly. The file simply stopped telling one coherent story, and that is what an examiner reads.
