Suisse KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Suisse.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Guide d’implémentation portable
Obtenir la checklist PDF
11 domaines de contrôle · 38 contrôles d’implémentation
Dernière revue: 9 October 2026 · Version 1.0
Télécharger la checklistRéponse directe
Que couvre la checklist de conformité pour Suisse ?
La checklist pour Suisse traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 38 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- Primary AML law
- Anti-Money Laundering Act (AMLA; SR 955.0)
- FIU
- Money Laundering Reporting Office Switzerland (MROS)
- SAR trigger
- Report immediately when AMLA Article 9 conditions are met
- Records
- 10 years after relationship termination or transaction completion
- Beneficial ownership
- Identify and verify the natural person who ultimately owns or controls
- Transparency register
- Federal register operational from 1 October 2026; transition rules apply
- Privacy law
- Federal Act on Data Protection (FADP)
- FATF public lists
- Not listed at 19 June 2026
Détail d’implémentation
Exigences et actions de conformité pour Suisse
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingClassify the activity, Swiss nexus and supervisory channel before launch.3 éléments+
Determine whether each activity is subject to AMLA.
- Action d’implémentation
- Map services, custody, payments, exchange, lending, asset management, advisory activity and crypto-asset functions to the live AMLA perimeter, including the adviser provisions effective 1 October 2026.
- Preuves à conserver
- Perimeter memo, service map and authority confirmation.
- Source primaire
- AMLA articles 2 and 2a; Anti-Money Laundering Ordinance
Select the correct supervisory route.
- Action d’implémentation
- Document whether FINMA, a supervisory organisation or a FINMA-recognised self-regulatory organisation supervises each covered activity and obtain affiliation before operating.
- Preuves à conserver
- Licence or affiliation record and scope analysis.
- Source primaire
- AMLA articles 12-18; FINMA AML supervision guidance
Obtain each activity-specific authorisation.
- Action d’implémentation
- Classify banking, securities, insurance, collective investment, portfolio management, trusteeship, FinTech, payment, DLT and crypto services under the live financial-market laws.
- Preuves à conserver
- Licence matrix, approvals and conditions.
- Source primaire
- Banking Act; FinIA; FinMIA; applicable FINMA authorisation rules
02Governance and risk assessmentControls must be risk-based, documented and effective.3 éléments+
Maintain an enterprise ML/TF/PF risk assessment.
- Action d’implémentation
- Assess customers, geography, products, channels, transactions, intermediaries, technologies and sanctions exposure using current national and sector risk information.
- Preuves à conserver
- Methodology, assessment, approval and updates.
- Source primaire
- AMLA articles 6 and 8; AMLO-FINMA
Maintain an adequate AML organisation.
- Action d’implémentation
- Assign accountable management, compliance, training, monitoring, escalation, quality assurance and independent testing proportionate to the business.
- Preuves à conserver
- Governance map, policies, training and test reports.
- Source primaire
- AMLA article 8; AMLO-FINMA
Apply group controls without weakening Swiss duties.
- Action d’implémentation
- Govern permitted information sharing, overseas entities and higher-risk relationships while preserving Swiss secrecy, privacy and reporting restrictions.
- Preuves à conserver
- Group standard, legal analysis and access controls.
- Source primaire
- AMLO-FINMA group-wide provisions; FADP
03Natural-person identificationVerify the contracting party, representatives and relevant asset ownership at the applicable trigger.4 éléments+
Verify the contracting party when establishing the relationship.
- Action d’implémentation
- Use documents or permitted digital methods of evidentiary value and retain attributes, provenance and verification results.
- Preuves à conserver
- Identity record, document check and verification result.
- Source primaire
- AMLA article 3; applicable FINMA/SRO identification rules
Apply current occasional-transaction thresholds by sector.
- Action d’implémentation
- Maintain a dated matrix from the controlling ordinance or self-regulatory rule; do not treat one threshold as universal across cash, exchange, payment-token or other activity.
- Preuves à conserver
- Threshold register, configuration and change tests.
- Source primaire
- AMLA article 3; AMLO; AMLO-FINMA and recognised self-regulation
Verify representatives and authority.
- Action d’implémentation
- Identify the representative, authenticate authority and establish the represented contracting party before accepting instructions.
- Preuves à conserver
- Representative KYC, mandate and validation.
- Source primaire
- AMLA article 3; applicable due-diligence rules
Escalate incomplete or doubtful identification.
- Action d’implémentation
- Do not open or continue contrary to the applicable rules; clarify inconsistencies and assess reporting duties without tipping off.
- Preuves à conserver
- Exception, restriction and SAR assessment.
- Source primaire
- AMLA articles 3, 6, 9 and 10a
04KYB, transparency register, and beneficial ownershipVerify legal existence, authority, ownership and ultimate control under both AML and entity-transparency rules.4 éléments+
Verify the legal entity and authorised persons.
- Action d’implémentation
- Obtain current commercial-register, constitutional, purpose, director and signatory evidence and validate authority.
- Preuves à conserver
- Zefix/cantonal extract, documents and discrepancy log.
- Source primaire
- AMLA article 3; Commercial Register Ordinance
Identify and verify the beneficial owner.
- Action d’implémentation
- Obtain a written declaration where required, trace direct and indirect ownership and control, and apply the current natural-person fallback under the controlling rules.
- Preuves à conserver
- Ownership chart, declaration, control rationale and verified identities.
- Source primaire
- AMLA article 4; applicable FINMA/SRO rules
Apply the federal transparency-register regime separately.
- Action d’implémentation
- Determine the entity's registration duty, identify reportable beneficial owners, meet the applicable transition period and keep reported information current.
- Preuves à conserver
- Scope memo, register filing, receipt and update log.
- Source primaire
- Act on the Transparency of Legal Persons and Identification of Beneficial Owners; implementing ordinance
Reconcile register and CDD differences.
- Action d’implémentation
- Do not treat a register entry as a substitute for risk-based verification; investigate and report discrepancies through the prescribed route where the statutory duty applies.
- Preuves à conserver
- Comparison, investigation and discrepancy report.
- Source primaire
- Transparency Act discrepancy-reporting provisions; AMLA article 4
05PEPs, EDD, and remote onboardingApply enhanced controls to PEPs and higher-risk relationships.3 éléments+
Identify foreign and domestic PEP exposure.
- Action d’implémentation
- Screen customers, beneficial owners, family members and close associates and apply the approval, source-of-wealth, source-of-funds and monitoring measures required for the risk class.
- Preuves à conserver
- Screening, classification, approval and corroboration.
- Source primaire
- AMLA articles 2a and 6; AMLO-FINMA
Clarify unusual and higher-risk activity.
- Action d’implémentation
- Establish economic background and purpose, obtain additional evidence and document whether suspicion is present.
- Preuves à conserver
- Trigger, clarification, conclusion and approval.
- Source primaire
- AMLA article 6
Control digital identification.
- Action d’implémentation
- Use the FINMA video/online-identification practice and the version in force on the onboarding date; retain authentication, liveness, fraud and exception evidence.
- Preuves à conserver
- Method assessment, session evidence and exceptions.
- Source primaire
- FINMA Circular 2016/7, including revision effective 1 November 2026
06Monitoring and suspicious reportingOngoing scrutiny supports immediate reporting to MROS.4 éléments+
Monitor and refresh on a risk basis.
- Action d’implémentation
- Compare activity with purpose, expected behaviour, customer risk and source of assets and refresh CDD when events, material changes or doubts arise.
- Preuves à conserver
- Scenarios, alerts, reviews and refresh history.
- Source primaire
- AMLA articles 6 and 7
Report when AMLA Article 9 conditions are met.
- Action d’implémentation
- Submit a complete report to MROS immediately through the prescribed electronic channel; distinguish the statutory duty from the separate reporting right.
- Preuves à conserver
- Trigger analysis, decision time, goAML submission and acknowledgement.
- Source primaire
- AMLA articles 9 and 23; MROSO
Apply transaction restrictions under the live rules.
- Action d’implémentation
- Determine whether and when assets or transactions must be blocked or may be executed after a report, following MROS communications and the controlling AMLA provisions.
- Preuves à conserver
- Legal basis, timestamps, restriction and release decision.
- Source primaire
- AMLA article 10 and MROSO
Prevent tipping off and protect report information.
- Action d’implémentation
- Restrict access and communications and disclose only under a statutory permission.
- Preuves à conserver
- Access logs, scripts, training and incidents.
- Source primaire
- AMLA article 10a
07Payments, wires, thresholds, and crypto-assetsSeparate identification thresholds, transfer information and activity-specific licensing.4 éléments+
Carry and screen required transfer information.
- Action d’implémentation
- Apply current originator and beneficiary fields, missing-data procedures, sanctions checks and beneficiary/intermediary controls.
- Preuves à conserver
- Field matrix, samples and repair queue.
- Source primaire
- AMLO-FINMA payment-transfer provisions; applicable SRO rules
Maintain a current threshold matrix.
- Action d’implémentation
- Record identification, enhanced-diligence and cash-dealer triggers by activity, currency and rule version; do not present a sector threshold as universal.
- Preuves à conserver
- Rule register, configuration and tests.
- Source primaire
- AMLA; AMLO; AMLO-FINMA
Classify payment and deposit-taking models before launch.
- Action d’implémentation
- Map accounts, wallets, settlement, custody, agents and public deposits to AMLA, Banking Act, FinTech-licence and payment-system requirements.
- Preuves à conserver
- Product memo, authorisation and control tests.
- Source primaire
- Banking Act article 1b; FinMIA; FINMA FinTech guidance
Apply AML and licensing rules to crypto services.
- Action d’implémentation
- Classify exchange, transfer, custody, wallet, token and DLT-trading functions; join the required supervisory framework and implement travel-rule controls.
- Preuves à conserver
- Classification, FINMA/SRO status and transfer tests.
- Source primaire
- AMLA; FinMIA; FINMA Guidance 02/2019 and 08/2023
08Targeted financial sanctionsUse current Swiss ordinances and the SECO sanctions database.3 éléments+
Screen current designations, ownership and control.
- Action d’implémentation
- Screen relevant parties at onboarding, transactions and list updates against the SECO search database and applicable ordinance annexes.
- Preuves à conserver
- List versions, screening logs and match decisions.
- Source primaire
- Embargo Act; programme-specific Federal Council ordinances
Implement freezes and reporting without delay where required.
- Action d’implémentation
- Prevent prohibited dealing, make required declarations to SECO or the named authority and preserve the exact ordinance-specific timing and scope.
- Preuves à conserver
- Ordinance, restriction timestamp and report receipt.
- Source primaire
- Applicable sanctions ordinance; SECO sanctions guidance
Use licences, exemptions and release only under written authority.
- Action d’implémentation
- Apply the programme-specific procedure and preserve every condition and approval.
- Preuves à conserver
- Legal analysis, permission and release record.
- Source primaire
- Embargo Act and applicable ordinance
09Records and regulator accessRetention triggers are record-specific.3 éléments+
Retain AML records for ten years.
- Action d’implémentation
- Run the period from termination of the business relationship or completion of the transaction, as applicable, and preserve reconstructable evidence.
- Preuves à conserver
- Schedule, trigger, samples and retrieval test.
- Source primaire
- AMLA article 7
Preserve SAR, CDD, monitoring and governance evidence.
- Action d’implémentation
- Keep decisions, supporting material, acknowledgements, training, controls and audits subject to lawful holds and sector rules.
- Preuves à conserver
- Case files, schedule and legal holds.
- Source primaire
- AMLA articles 7-9
Produce complete records to competent authorities.
- Action d’implémentation
- Maintain controlled access and an auditable process for FINMA, supervisory bodies, MROS and other lawful requests.
- Preuves à conserver
- Access matrix, production log and integrity checks.
- Source primaire
- AMLA and applicable supervisory law
10Privacy, biometrics, breaches, and transfersApply the Federal Act on Data Protection and sector secrecy together.4 éléments+
Map processing, transparency and data-subject rights.
- Action d’implémentation
- Inventory personal data, purposes, processors, retention and disclosures; issue required information and support access, correction and other rights.
- Preuves à conserver
- Data map, notices, contracts and rights log.
- Source primaire
- FADP articles 6, 8, 19 and 25
Assess high-risk and biometric processing.
- Action d’implémentation
- Treat biometric data that uniquely identifies a person as sensitive, apply privacy by design and conduct a data-protection impact assessment where processing is likely high risk.
- Preuves à conserver
- DPIA, controls, test results and approvals.
- Source primaire
- FADP articles 5, 7 and 22
Notify qualifying data-security breaches as soon as possible.
- Action d’implémentation
- Assess likely high risk, notify the FDPIC as soon as possible and inform affected persons where necessary for their protection.
- Preuves à conserver
- Incident chronology, risk assessment and notifications.
- Source primaire
- FADP article 24
Control cross-border disclosures.
- Action d’implémentation
- Use an adequate destination or an Article 16 safeguard, meet FDPIC notification requirements where applicable, or document a narrow Article 17 exception.
- Preuves à conserver
- Transfer map, mechanism, assessment and notices.
- Source primaire
- FADP articles 16-17; DPO
11Practical evidence packsEvidence must reconstruct decisions end to end.3 éléments+
Maintain an onboarding pack.
- Action d’implémentation
- Bundle identity, authority, KYB, beneficial ownership, PEP, sanctions, purpose, risk, privacy and approvals.
- Preuves à conserver
- Complete sample and retrieval result.
- Source primaire
- Operational control supporting AMLA articles 3-8
Maintain SAR and sanctions case packs.
- Action d’implémentation
- Link activity, analysis, decision time, report, receipt, confidentiality, restrictions and communications.
- Preuves à conserver
- Case pack, timeline and access record.
- Source primaire
- AMLA articles 9-10a; applicable sanctions ordinance
Maintain a launch and legal-change pack.
- Action d’implémentation
- Record perimeter, licences, transparency-register transition, reporting, sanctions, privacy, vendors, current thresholds and tests.
- Preuves à conserver
- Signed pack, source register and approvals.
- Source primaire
- Official sources listed below
Registre des sources primaires
18 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Federal Anti-Money Laundering Act (AMLA; SR 955.0)Fedlex · Primary legislation - official consolidated text
- Federal Council brings new anti-money laundering rules into forceFederal Office of Justice · Official commencement notice
- Swiss Transparency RegisterFederal Office of Justice · Official registry guidance
- Combating money laundering in financial-market supervisionFINMA · Official supervisory guidance
- Money Laundering Reporting Office SwitzerlandFederal Office of Police · Official FIU guidance
- MROS entering and submitting reportsFederal Office of Police · Official filing guidance
- FINMA video and online identification revisionFINMA · Official supervisory circular notice
- FinTech financial services providersFINMA · Official perimeter and licensing guidance
- FinTech licenceFINMA · Official licensing guidance
- FINMA Guidance 02/2019 - payments on the blockchainFINMA · Official supervisory guidance
- Swiss sanctions portalState Secretariat for Economic Affairs · Official sanctions register and guidance
- Federal Act on Data ProtectionFedlex · Primary legislation - official consolidated text
- FDPIC data-breach guidanceFederal Data Protection and Information Commissioner · Official privacy guidance
- FDPIC cross-border transfer guidanceFederal Data Protection and Information Commissioner · Official privacy guidance
- FATF Switzerland country assessment pageFATF · Authoritative assessment
- FATF increased monitoring - 19 June 2026FATF · Authoritative current public-list status
- FATF call for action - 19 June 2026FATF · Authoritative current public-list status
- Using the Swiss cross and coat of armsSwiss Federal Institute of Intellectual Property · Official public-sign guidance
Réponses directes
Questions KYC, KYB et AML pour Suisse
Who receives suspicious activity reports?+
MROS receives reports through the prescribed goAML route.
When must a report be filed?+
Immediately when the conditions in AMLA Article 9 are met; preserve the trigger analysis and decision time.
How long are AML records retained?+
Ten years after termination of the relationship or completion of the transaction, as applicable, under AMLA Article 7.
Is the transparency register live?+
Yes. It began operating on 1 October 2026; determine the applicable entity scope and transition period before fixing a filing date.
Is there one universal transaction threshold?+
No. Identification and enhanced-control thresholds depend on the activity and controlling FINMA, federal or self-regulatory rule.
Can onboarding be electronic?+
Yes where the applicable FINMA circular and supervisory rules permit the method; the revised Circular 2016/7 takes effect on 1 November 2026.
Are crypto-asset services regulated?+
Many exchange, transfer, custody, wallet and DLT activities are subject to AMLA and may also require FINMA authorisation or SRO affiliation.
When is a privacy breach notified?+
A breach likely to result in high risk must be notified to the FDPIC as soon as possible; affected persons are informed where necessary for their protection.
Is Switzerland on a FATF public list?+
No at 19 June 2026. Absence from a list is not a low-risk conclusion.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General information, not legal advice. Reviewed 9 October 2026. Confirm controlling German, French and Italian texts, transition periods under the new transparency regime, current FINMA/SRO rules, sector thresholds, MROS procedures, sanctions ordinances, registry practice, privacy guidance and licence conditions with the competent authority and qualified Swiss counsel.