01
FINMA money laundering risk analysis: key points
- On 4 June 2026, FINMA issued Guidance 04/2026, clarifying and tightening its expectations for money laundering risk analysis under Article 25(2) AMLO-FINMA.
- For the first time, the requirements expressly also apply to institutions under FinIA: securities firms, fund management companies, managers of collective assets, asset managers and trustees.
- The most frequent deficiencies are unclear risk tolerance, overly permissive exception-to-policy processes, missing or unsuitable key risk indicators and a lack of transparent reconciliation between net risk and risk tolerance.
- Institutions with gaps risk supervisory findings at their next audit. Existing risk analyses should now be revised.
02
What is new in FINMA Guidance 04/2026?
FINMA had already outlined minimum standards for money laundering risk analysis in Guidance 05/2023. Since then, it has re-examined some of the banks reviewed at that time and analysed numerous additional banks and institutions under FinIA. The result is that progress is visible, but substantial gaps remain at both banks and FinIA institutions.
Guidance 04/2026 is therefore not a change of direction but a clarification expressed in considerably stronger terms. For practically every criticism raised in 2023, it provides concrete examples of what FINMA considers inadequate in practice and what it expects instead. A separate new chapter also regulates its application to institutions under FinIA, referring to Article 9(2) FinIA, Article 8 AMLA and Articles 23 et seq. AMLO-FINMA.
03
Why is a “soft” risk tolerance no longer sufficient?
FINMA requires institutions consciously to exclude certain countries, client segments, products or services, rather than merely describing risk-mitigation measures. A statement such as “foreign politically exposed persons are accepted only with executive management approval” is not sufficient to define risk tolerance; it is a control measure, not a limit.
Simply excluding cases that must be avoided in any event, such as North Korea, Iran, drug trafficking and human trafficking, is also insufficient. FINMA expects institution-specific exclusions related to the business model, such as no complex structures, no crypto business or no trade finance, depending on what is appropriate for the institution. Risk tolerance as a whole must also be documented and classified as low, medium or high.
04
How strict may an exception-to-policy process be?
An exception-to-policy process is permissible, but FINMA identified institutions that effectively undermined their defined risk tolerance by approving a very large number of exceptions. This is not permitted: the process must not enable permanent or systematic breaches of risk limits. An institution that consciously wishes to carry higher risk must have the risk tolerance itself formally amended by the supreme governing body rather than accumulating individual exceptions.
Institutions must record exception-to-policy cases centrally and monitor them both quantitatively, including number, volume and development, and qualitatively, including reasons, risk profiles and effectiveness of measures. They must also report them regularly to the supreme governing body. FINMA expressly highlighted positively institutions that have no exception-to-policy process at all and adhere strictly to their tolerance.
05
Which key risk indicators does FINMA expect?
A central criticism is that many institutions equate key risk indicators with existing risk limits instead of defining targeted metrics for material risks. According to FINMA, two design flaws occur particularly frequently. The first is using relative indicators compared with the previous year, which leads to a gradual expansion of risk tolerance that is never formally approved. The second is combining different criticality levels in one indicator, such as clients from low-, medium- and high-risk countries in a single ratio.
According to FINMA, meaningful indicators for inherent risks include the number and assets under management of client relationships involving politically exposed persons, the number of approved exceptions to policy and exposure to high-risk countries outside target markets. Several metrics should be combined to obtain a meaningful picture, typically the number of client relationships and assets under management.
06
What must be correct when inherent risk, control risk and net risk are assessed?
FINMA requires all legally specified risk categories — client segments, registered office or residence, products and services — to be assessed completely and individually, including criteria presenting medium or low inherent risk. Combining different criticality levels in one group, such as retail, affluent and high-net-worth clients in one category, is not permitted because it obscures the actual risk.
FINMA also criticises systematically low classifications. Complex structures, relationships with politically exposed persons and crypto services were in some cases assessed as medium rather than correctly as high. In addition, very high inherent risks can never be reduced below high through control measures, a point that FINMA says not all institutions understand. Risk-mitigation measures must consistently be reflected in control risk, not in the assessment of inherent risk.
07
What does the failure to reconcile risk with risk tolerance mean in practice?
Many institutions calculate net risk for each individual risk criterion but do not aggregate it into an overall net risk and compare that result with the defined risk tolerance. Without this comparison, it remains unclear whether the institution as a whole operates within its own limits. If the tolerance is exceeded, risk-mitigation measures are mandatory; retrospective approval under the exception-to-policy process is not the appropriate instrument for a breach of limits.
08
Do the requirements also apply to smaller asset managers and trustees?
Yes, but proportionately. The same legal foundations apply to institutions under FinIA, including Article 9(2) FinIA, Article 8 AMLA and Articles 23 et seq. AMLO-FINMA. The level of detail and design of the risk analysis depend on the nature, scale, complexity and risk content of the relevant business. An institution without increased risks does not necessarily have to break country or sector risks down to individual-country level. Only very small financial intermediaries, with no more than five full-time positions or less than CHF 2 million in gross income and no increased risks, are exempt from the risk-analysis requirement; even then, FINMA may require a full risk analysis in an individual case.
09
Frequently asked questions
Does our existing risk analysis now need to be completely rewritten? Not necessarily from the ground up, but most existing analyses have at least one of the gaps identified. A structured review against FINMA’s criteria is the right first step.
Is it enough simply to count our exception-to-policy cases in future? No. FINMA requires central recording, quantitative and qualitative analysis and regular reporting to the supreme governing body; counting alone is not enough.
What happens if we do not meet the requirements at the next audit? With two pieces of guidance in three years, FINMA has clearly signalled that it actively reviews risk analyses. Deficiencies may lead to supervisory findings and requirements.
Does this also affect pure asset managers with no politically exposed persons or crypto business? Yes, but with a reduced level of detail. Even a low-risk business model requires a documented and transparent risk analysis; only the degree of granularity may be lower.
When should we act? Immediately. FINMA conducts ongoing reviews, and revising the risk analysis, risk-tolerance definition and key risk indicators takes time for internal coordination and approval by the supreme governing body.
Primary sources