The Financial Action Task Force (FATF) recommendations and the Anti-Money Laundering Act (AMLA) require a risk-based approach. In the following, we discuss some basic aspects of risk-based approaches.

 

A risk-based approach is an approach that takes risk into account. Risk is related to the impact of possible events and their probability. From a simplified point of view, risk can be defined as:

Risk Based Approach3

Assessment of risks allows resources to be allocated in the most efficient way such that the greatest risks receive the highest attention. It is crucial to distinguish between necessary and sufficient risk factors.

If a necessary risk is low, the overall risk is also. For instance, in avalanche risk, the steepness of the slope to be traversed and the danger lever of the avalanche bulletin are necessary risk factors. Traversing a horizontal plane is safe, even when the danger level of the avalanche bulletin is high.

Examples of necessary risk factors

Risk Based Approach

In contrast to necessary factors, a sufficient risk factor implies a risk independent of other factors. For instance, a ski tour should be cancelled if extreme weather conditions are expected independent of the avalanche risk. Similary, a cancellation is advisable in the case of a high avalanche risk, even when weather conditions are excellent. In this example, weather conditions and avalanche risk are sufficient risk factors.

Examples of sufficient risk factors

Risk Based Approach2

Data Protection Act

The Swiss Data Protection Act underwent a complete revision in 2020, and its new version took effect on September 1, 2023, along with the new Data Protection Ordinance (DPO). The revision itself is complete, but its practical application continues to evolve. The topic of AI is particularly relevant: On May 8, 2025, the FDPIC confirmed that the DPA is technology-neutral and applies directly to all AI applications. In practice, this means, among other things, that users must know whether they are interacting with AI (transparency requirement, Art. 19), and that a data protection impact assessment is mandatory in cases of high risk—such as profiling or facial recognition (Art. 22). The Federal Office of Justice (FOJ) is drafting a consultation document on AI regulation to be completed by the end of 2026. With this, Switzerland will implement the Council of Europe's AI Convention.

Eurospider Information Technology AG
Winterthurerstrasse 92
8006 Zürich

 

Cookies make it easier for us to provide you with our services. With the usage of our services you permit us to use cookies.
More information Ok Decline