Compliance and game theory

Game theory is a toolbox offering various analytical instruments that can be applied across a range of areas, for example in economics and law. In the simplest model, the “players” are a potential bank customer and a compliance officer. The game – onboarding, for example – is subject to particular rules. In the best-case scenario, the customer will be accepted and the compliance officer will not have any problems with them. In the worst-case scenario, the potential bank customer will be turned down, but the compliance officer will still experience problems.

In game theory, a disbursement feature defines success or failure. Customers can generate revenue for a bank – or fines. It’s not surprising that the compliance field has not yet employed game theory to any great extent. Compliance games feature complex interactions that are hardly on the same level as Parcheesi or the prisoner’s dilemma. However, it is to be hoped that game theory approaches will generate added value in compliance processes in future.

 

Data Protection Act

The Swiss Data Protection Act underwent a complete revision in 2020, and its new version took effect on September 1, 2023, along with the new Data Protection Ordinance (DPO). The revision itself is complete, but its practical application continues to evolve. The topic of AI is particularly relevant: On May 8, 2025, the FDPIC confirmed that the DPA is technology-neutral and applies directly to all AI applications. In practice, this means, among other things, that users must know whether they are interacting with AI (transparency requirement, Art. 19), and that a data protection impact assessment is mandatory in cases of high risk—such as profiling or facial recognition (Art. 22). The Federal Office of Justice (FOJ) is drafting a consultation document on AI regulation to be completed by the end of 2026. With this, Switzerland will implement the Council of Europe's AI Convention.

Eurospider Information Technology AG
Winterthurerstrasse 92
8006 Zürich