Switzerland KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Switzerland.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Portable implementation guide
Get the PDF checklist
11 control areas · 38 implementation checks
Last reviewed: 9 October 2026 · Version 1.0
Download the checklistDirect answer
What does the Switzerland compliance checklist cover?
The Switzerland checklist translates primary KYC, KYB and AML rules into 11 control areas and 38 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- Primary AML law
- Anti-Money Laundering Act (AMLA; SR 955.0)
- FIU
- Money Laundering Reporting Office Switzerland (MROS)
- SAR trigger
- Report immediately when AMLA Article 9 conditions are met
- Records
- 10 years after relationship termination or transaction completion
- Beneficial ownership
- Identify and verify the natural person who ultimately owns or controls
- Transparency register
- Federal register operational from 1 October 2026; transition rules apply
- Privacy law
- Federal Act on Data Protection (FADP)
- FATF public lists
- Not listed at 19 June 2026
Implementation detail
Switzerland compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingClassify the activity, Swiss nexus and supervisory channel before launch.3 items+
Determine whether each activity is subject to AMLA.
- Implementation action
- Map services, custody, payments, exchange, lending, asset management, advisory activity and crypto-asset functions to the live AMLA perimeter, including the adviser provisions effective 1 October 2026.
- Evidence to retain
- Perimeter memo, service map and authority confirmation.
- Primary citation
- AMLA articles 2 and 2a; Anti-Money Laundering Ordinance
Select the correct supervisory route.
- Implementation action
- Document whether FINMA, a supervisory organisation or a FINMA-recognised self-regulatory organisation supervises each covered activity and obtain affiliation before operating.
- Evidence to retain
- Licence or affiliation record and scope analysis.
- Primary citation
- AMLA articles 12-18; FINMA AML supervision guidance
Obtain each activity-specific authorisation.
- Implementation action
- Classify banking, securities, insurance, collective investment, portfolio management, trusteeship, FinTech, payment, DLT and crypto services under the live financial-market laws.
- Evidence to retain
- Licence matrix, approvals and conditions.
- Primary citation
- Banking Act; FinIA; FinMIA; applicable FINMA authorisation rules
02Governance and risk assessmentControls must be risk-based, documented and effective.3 items+
Maintain an enterprise ML/TF/PF risk assessment.
- Implementation action
- Assess customers, geography, products, channels, transactions, intermediaries, technologies and sanctions exposure using current national and sector risk information.
- Evidence to retain
- Methodology, assessment, approval and updates.
- Primary citation
- AMLA articles 6 and 8; AMLO-FINMA
Maintain an adequate AML organisation.
- Implementation action
- Assign accountable management, compliance, training, monitoring, escalation, quality assurance and independent testing proportionate to the business.
- Evidence to retain
- Governance map, policies, training and test reports.
- Primary citation
- AMLA article 8; AMLO-FINMA
Apply group controls without weakening Swiss duties.
- Implementation action
- Govern permitted information sharing, overseas entities and higher-risk relationships while preserving Swiss secrecy, privacy and reporting restrictions.
- Evidence to retain
- Group standard, legal analysis and access controls.
- Primary citation
- AMLO-FINMA group-wide provisions; FADP
03Natural-person identificationVerify the contracting party, representatives and relevant asset ownership at the applicable trigger.4 items+
Verify the contracting party when establishing the relationship.
- Implementation action
- Use documents or permitted digital methods of evidentiary value and retain attributes, provenance and verification results.
- Evidence to retain
- Identity record, document check and verification result.
- Primary citation
- AMLA article 3; applicable FINMA/SRO identification rules
Apply current occasional-transaction thresholds by sector.
- Implementation action
- Maintain a dated matrix from the controlling ordinance or self-regulatory rule; do not treat one threshold as universal across cash, exchange, payment-token or other activity.
- Evidence to retain
- Threshold register, configuration and change tests.
- Primary citation
- AMLA article 3; AMLO; AMLO-FINMA and recognised self-regulation
Verify representatives and authority.
- Implementation action
- Identify the representative, authenticate authority and establish the represented contracting party before accepting instructions.
- Evidence to retain
- Representative KYC, mandate and validation.
- Primary citation
- AMLA article 3; applicable due-diligence rules
Escalate incomplete or doubtful identification.
- Implementation action
- Do not open or continue contrary to the applicable rules; clarify inconsistencies and assess reporting duties without tipping off.
- Evidence to retain
- Exception, restriction and SAR assessment.
- Primary citation
- AMLA articles 3, 6, 9 and 10a
04KYB, transparency register, and beneficial ownershipVerify legal existence, authority, ownership and ultimate control under both AML and entity-transparency rules.4 items+
Verify the legal entity and authorised persons.
- Implementation action
- Obtain current commercial-register, constitutional, purpose, director and signatory evidence and validate authority.
- Evidence to retain
- Zefix/cantonal extract, documents and discrepancy log.
- Primary citation
- AMLA article 3; Commercial Register Ordinance
Identify and verify the beneficial owner.
- Implementation action
- Obtain a written declaration where required, trace direct and indirect ownership and control, and apply the current natural-person fallback under the controlling rules.
- Evidence to retain
- Ownership chart, declaration, control rationale and verified identities.
- Primary citation
- AMLA article 4; applicable FINMA/SRO rules
Apply the federal transparency-register regime separately.
- Implementation action
- Determine the entity's registration duty, identify reportable beneficial owners, meet the applicable transition period and keep reported information current.
- Evidence to retain
- Scope memo, register filing, receipt and update log.
- Primary citation
- Act on the Transparency of Legal Persons and Identification of Beneficial Owners; implementing ordinance
Reconcile register and CDD differences.
- Implementation action
- Do not treat a register entry as a substitute for risk-based verification; investigate and report discrepancies through the prescribed route where the statutory duty applies.
- Evidence to retain
- Comparison, investigation and discrepancy report.
- Primary citation
- Transparency Act discrepancy-reporting provisions; AMLA article 4
05PEPs, EDD, and remote onboardingApply enhanced controls to PEPs and higher-risk relationships.3 items+
Identify foreign and domestic PEP exposure.
- Implementation action
- Screen customers, beneficial owners, family members and close associates and apply the approval, source-of-wealth, source-of-funds and monitoring measures required for the risk class.
- Evidence to retain
- Screening, classification, approval and corroboration.
- Primary citation
- AMLA articles 2a and 6; AMLO-FINMA
Clarify unusual and higher-risk activity.
- Implementation action
- Establish economic background and purpose, obtain additional evidence and document whether suspicion is present.
- Evidence to retain
- Trigger, clarification, conclusion and approval.
- Primary citation
- AMLA article 6
Control digital identification.
- Implementation action
- Use the FINMA video/online-identification practice and the version in force on the onboarding date; retain authentication, liveness, fraud and exception evidence.
- Evidence to retain
- Method assessment, session evidence and exceptions.
- Primary citation
- FINMA Circular 2016/7, including revision effective 1 November 2026
06Monitoring and suspicious reportingOngoing scrutiny supports immediate reporting to MROS.4 items+
Monitor and refresh on a risk basis.
- Implementation action
- Compare activity with purpose, expected behaviour, customer risk and source of assets and refresh CDD when events, material changes or doubts arise.
- Evidence to retain
- Scenarios, alerts, reviews and refresh history.
- Primary citation
- AMLA articles 6 and 7
Report when AMLA Article 9 conditions are met.
- Implementation action
- Submit a complete report to MROS immediately through the prescribed electronic channel; distinguish the statutory duty from the separate reporting right.
- Evidence to retain
- Trigger analysis, decision time, goAML submission and acknowledgement.
- Primary citation
- AMLA articles 9 and 23; MROSO
Apply transaction restrictions under the live rules.
- Implementation action
- Determine whether and when assets or transactions must be blocked or may be executed after a report, following MROS communications and the controlling AMLA provisions.
- Evidence to retain
- Legal basis, timestamps, restriction and release decision.
- Primary citation
- AMLA article 10 and MROSO
Prevent tipping off and protect report information.
- Implementation action
- Restrict access and communications and disclose only under a statutory permission.
- Evidence to retain
- Access logs, scripts, training and incidents.
- Primary citation
- AMLA article 10a
07Payments, wires, thresholds, and crypto-assetsSeparate identification thresholds, transfer information and activity-specific licensing.4 items+
Carry and screen required transfer information.
- Implementation action
- Apply current originator and beneficiary fields, missing-data procedures, sanctions checks and beneficiary/intermediary controls.
- Evidence to retain
- Field matrix, samples and repair queue.
- Primary citation
- AMLO-FINMA payment-transfer provisions; applicable SRO rules
Maintain a current threshold matrix.
- Implementation action
- Record identification, enhanced-diligence and cash-dealer triggers by activity, currency and rule version; do not present a sector threshold as universal.
- Evidence to retain
- Rule register, configuration and tests.
- Primary citation
- AMLA; AMLO; AMLO-FINMA
Classify payment and deposit-taking models before launch.
- Implementation action
- Map accounts, wallets, settlement, custody, agents and public deposits to AMLA, Banking Act, FinTech-licence and payment-system requirements.
- Evidence to retain
- Product memo, authorisation and control tests.
- Primary citation
- Banking Act article 1b; FinMIA; FINMA FinTech guidance
Apply AML and licensing rules to crypto services.
- Implementation action
- Classify exchange, transfer, custody, wallet, token and DLT-trading functions; join the required supervisory framework and implement travel-rule controls.
- Evidence to retain
- Classification, FINMA/SRO status and transfer tests.
- Primary citation
- AMLA; FinMIA; FINMA Guidance 02/2019 and 08/2023
08Targeted financial sanctionsUse current Swiss ordinances and the SECO sanctions database.3 items+
Screen current designations, ownership and control.
- Implementation action
- Screen relevant parties at onboarding, transactions and list updates against the SECO search database and applicable ordinance annexes.
- Evidence to retain
- List versions, screening logs and match decisions.
- Primary citation
- Embargo Act; programme-specific Federal Council ordinances
Implement freezes and reporting without delay where required.
- Implementation action
- Prevent prohibited dealing, make required declarations to SECO or the named authority and preserve the exact ordinance-specific timing and scope.
- Evidence to retain
- Ordinance, restriction timestamp and report receipt.
- Primary citation
- Applicable sanctions ordinance; SECO sanctions guidance
Use licences, exemptions and release only under written authority.
- Implementation action
- Apply the programme-specific procedure and preserve every condition and approval.
- Evidence to retain
- Legal analysis, permission and release record.
- Primary citation
- Embargo Act and applicable ordinance
09Records and regulator accessRetention triggers are record-specific.3 items+
Retain AML records for ten years.
- Implementation action
- Run the period from termination of the business relationship or completion of the transaction, as applicable, and preserve reconstructable evidence.
- Evidence to retain
- Schedule, trigger, samples and retrieval test.
- Primary citation
- AMLA article 7
Preserve SAR, CDD, monitoring and governance evidence.
- Implementation action
- Keep decisions, supporting material, acknowledgements, training, controls and audits subject to lawful holds and sector rules.
- Evidence to retain
- Case files, schedule and legal holds.
- Primary citation
- AMLA articles 7-9
Produce complete records to competent authorities.
- Implementation action
- Maintain controlled access and an auditable process for FINMA, supervisory bodies, MROS and other lawful requests.
- Evidence to retain
- Access matrix, production log and integrity checks.
- Primary citation
- AMLA and applicable supervisory law
10Privacy, biometrics, breaches, and transfersApply the Federal Act on Data Protection and sector secrecy together.4 items+
Map processing, transparency and data-subject rights.
- Implementation action
- Inventory personal data, purposes, processors, retention and disclosures; issue required information and support access, correction and other rights.
- Evidence to retain
- Data map, notices, contracts and rights log.
- Primary citation
- FADP articles 6, 8, 19 and 25
Assess high-risk and biometric processing.
- Implementation action
- Treat biometric data that uniquely identifies a person as sensitive, apply privacy by design and conduct a data-protection impact assessment where processing is likely high risk.
- Evidence to retain
- DPIA, controls, test results and approvals.
- Primary citation
- FADP articles 5, 7 and 22
Notify qualifying data-security breaches as soon as possible.
- Implementation action
- Assess likely high risk, notify the FDPIC as soon as possible and inform affected persons where necessary for their protection.
- Evidence to retain
- Incident chronology, risk assessment and notifications.
- Primary citation
- FADP article 24
Control cross-border disclosures.
- Implementation action
- Use an adequate destination or an Article 16 safeguard, meet FDPIC notification requirements where applicable, or document a narrow Article 17 exception.
- Evidence to retain
- Transfer map, mechanism, assessment and notices.
- Primary citation
- FADP articles 16-17; DPO
11Practical evidence packsEvidence must reconstruct decisions end to end.3 items+
Maintain an onboarding pack.
- Implementation action
- Bundle identity, authority, KYB, beneficial ownership, PEP, sanctions, purpose, risk, privacy and approvals.
- Evidence to retain
- Complete sample and retrieval result.
- Primary citation
- Operational control supporting AMLA articles 3-8
Maintain SAR and sanctions case packs.
- Implementation action
- Link activity, analysis, decision time, report, receipt, confidentiality, restrictions and communications.
- Evidence to retain
- Case pack, timeline and access record.
- Primary citation
- AMLA articles 9-10a; applicable sanctions ordinance
Maintain a launch and legal-change pack.
- Implementation action
- Record perimeter, licences, transparency-register transition, reporting, sanctions, privacy, vendors, current thresholds and tests.
- Evidence to retain
- Signed pack, source register and approvals.
- Primary citation
- Official sources listed below
Primary-source register
18 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Federal Anti-Money Laundering Act (AMLA; SR 955.0)Fedlex · Primary legislation - official consolidated text
- Federal Council brings new anti-money laundering rules into forceFederal Office of Justice · Official commencement notice
- Swiss Transparency RegisterFederal Office of Justice · Official registry guidance
- Combating money laundering in financial-market supervisionFINMA · Official supervisory guidance
- Money Laundering Reporting Office SwitzerlandFederal Office of Police · Official FIU guidance
- MROS entering and submitting reportsFederal Office of Police · Official filing guidance
- FINMA video and online identification revisionFINMA · Official supervisory circular notice
- FinTech financial services providersFINMA · Official perimeter and licensing guidance
- FinTech licenceFINMA · Official licensing guidance
- FINMA Guidance 02/2019 - payments on the blockchainFINMA · Official supervisory guidance
- Swiss sanctions portalState Secretariat for Economic Affairs · Official sanctions register and guidance
- Federal Act on Data ProtectionFedlex · Primary legislation - official consolidated text
- FDPIC data-breach guidanceFederal Data Protection and Information Commissioner · Official privacy guidance
- FDPIC cross-border transfer guidanceFederal Data Protection and Information Commissioner · Official privacy guidance
- FATF Switzerland country assessment pageFATF · Authoritative assessment
- FATF increased monitoring - 19 June 2026FATF · Authoritative current public-list status
- FATF call for action - 19 June 2026FATF · Authoritative current public-list status
- Using the Swiss cross and coat of armsSwiss Federal Institute of Intellectual Property · Official public-sign guidance
Direct answers
Switzerland KYC, KYB and AML questions
Who receives suspicious activity reports?+
MROS receives reports through the prescribed goAML route.
When must a report be filed?+
Immediately when the conditions in AMLA Article 9 are met; preserve the trigger analysis and decision time.
How long are AML records retained?+
Ten years after termination of the relationship or completion of the transaction, as applicable, under AMLA Article 7.
Is the transparency register live?+
Yes. It began operating on 1 October 2026; determine the applicable entity scope and transition period before fixing a filing date.
Is there one universal transaction threshold?+
No. Identification and enhanced-control thresholds depend on the activity and controlling FINMA, federal or self-regulatory rule.
Can onboarding be electronic?+
Yes where the applicable FINMA circular and supervisory rules permit the method; the revised Circular 2016/7 takes effect on 1 November 2026.
Are crypto-asset services regulated?+
Many exchange, transfer, custody, wallet and DLT activities are subject to AMLA and may also require FINMA authorisation or SRO affiliation.
When is a privacy breach notified?+
A breach likely to result in high risk must be notified to the FDPIC as soon as possible; affected persons are informed where necessary for their protection.
Is Switzerland on a FATF public list?+
No at 19 June 2026. Absence from a list is not a low-risk conclusion.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General information, not legal advice. Reviewed 9 October 2026. Confirm controlling German, French and Italian texts, transition periods under the new transparency regime, current FINMA/SRO rules, sector thresholds, MROS procedures, sanctions ordinances, registry practice, privacy guidance and licence conditions with the competent authority and qualified Swiss counsel.