Requirements and features in compliance processes

The Anti-Money Laundering Act (AMLA) defines conditions without specifying how or with what tools these are to be achieved. These conditions are known as requirements. One example is Article 6 of the AMLA, which requires financial intermediaries to clarify the background and aims of politically exposed persons (PEP). In order to do so, they may carry out research online, question the client and/or compare their client base with a commercial PEP list. This comparison with a PEP list is a feature of a compliance solution. It is important to distinguish between requirements and features when it comes to digitalizing processes.

Process digitalization usually constitutes a complex restructuring project. Put simply, the individual steps are as follows: (1) Use of known, often familiar and trusted features. (2) The identification of the requirements that a particular feature is intended to fulfil demands a significant increase in abstraction, which does not always succeed at the first attempt. (3) A critical assessment of each requirement clarifies whether it is still up to date or whether it can be replaced by an alternative requirement. Examples of this are the expansion of the PEP concept through national PEP (in force since 2016) and the possibility of identifying clients online or using video.

Once the requirement has made clear what needs to be achieved, various options must be identified regarding how and in what order this can be done. As a rule, various optimality criteria such as cost, resources, risks, etc. come into play here. Once the new process has been defined, it is necessary to implement it. This requires suitable change management, as comprehensive, cross-divisional changes involving wide-ranging content often arise.

Data Protection Act

The Swiss Data Protection Act underwent a complete revision in 2020, and its new version took effect on September 1, 2023, along with the new Data Protection Ordinance (DPO). The revision itself is complete, but its practical application continues to evolve. The topic of AI is particularly relevant: On May 8, 2025, the FDPIC confirmed that the DPA is technology-neutral and applies directly to all AI applications. In practice, this means, among other things, that users must know whether they are interacting with AI (transparency requirement, Art. 19), and that a data protection impact assessment is mandatory in cases of high risk—such as profiling or facial recognition (Art. 22). The Federal Office of Justice (FOJ) is drafting a consultation document on AI regulation to be completed by the end of 2026. With this, Switzerland will implement the Council of Europe's AI Convention.

Eurospider Information Technology AG
Winterthurerstrasse 92
8006 Zürich

 

Cookies make it easier for us to provide you with our services. With the usage of our services you permit us to use cookies.
More information Ok Decline