Compliance

Compliance (regulatory compliance) means conforming to comply with relevant laws and regulations. Together with KYC Spider in Zug Eurospider has in-depth compliance know-how.

Names of persons are used to distinguish individuals. In today’s digitized world, the spelling of names matters, since computers compare name strings character by character, unless sophisticated name matching is used. In compliance, very often Arabic names are mentioned. A thorough look at the naming problem, however, has already started here.

A common question concerns the frequency of checks of the customer base. Art. 9 (duty to report) of the Anti-Money Laundering Act (AMLA) is relevant to this question: a financial intermediary must immediately file a report with the Money Laundering Reporting Office Switzerland (MROS) as defined. It is evident that immediate reporting is difficult if the customer base is checked infrequently.

Qualitative methods produce information only on the particular cases studied, and any more general conclusions are just hypotheses. Quantitative methods aim at the systematic empirical investigation of observable phenomena. In compliance, quantitative methods are usually adopted to periodically check the customer base. The results are hypotheses for certain risks that can be verified by qualitative methods for the particular cases.

The Financial Action Task Force (FATF) recommendations and the Anti-Money Laundering Act (AMLA) require a risk-based approach. In the following, we discuss some basic aspects of risk-based approaches.

 Compliance requires name matching: for instance, to match customers against sanctions and PEP lists. Unfortunately, the name of a single person can be spelled in many different ways. Hence, a decision has to be made whether matches of only very similar names should be verified,or matches of less similar names. In the former case, we may miss relevant matches and in the latter, we may get too many matches.

Data Protection Act

The Swiss Data Protection Act underwent a complete revision in 2020, and its new version took effect on September 1, 2023, along with the new Data Protection Ordinance (DPO). The revision itself is complete, but its practical application continues to evolve. The topic of AI is particularly relevant: On May 8, 2025, the FDPIC confirmed that the DPA is technology-neutral and applies directly to all AI applications. In practice, this means, among other things, that users must know whether they are interacting with AI (transparency requirement, Art. 19), and that a data protection impact assessment is mandatory in cases of high risk—such as profiling or facial recognition (Art. 22). The Federal Office of Justice (FOJ) is drafting a consultation document on AI regulation to be completed by the end of 2026. With this, Switzerland will implement the Council of Europe's AI Convention.

Eurospider Information Technology AG
Winterthurerstrasse 92
8006 Zürich

 

Cookies make it easier for us to provide you with our services. With the usage of our services you permit us to use cookies.
More information Ok Decline