Skip to content

15 September 2026 | 6 min

FINMA on Outsourcing: Why Externalisation Reduces Effort, but Not Responsibility

At the Small Banks Symposium on 7 September 2026, FINMA made an important point clear: proportionality does not mean that material risks can be taken less seriously. Especially when it comes to cyber risks, outsourcing, cloud providers and artificial intelligence, responsibility remains with the supervised institution.

Smaller banks can benefit significantly from sourcing technology or services externally. They do not need to build the same internal structures as large institutions. But they still need to know and effectively manage their material risks. This is exactly where outsourcing becomes a GRC topic.

FINMA emphasises that smaller institutions can benefit from proportionate supervision. At the same time, outsourcing may reduce internal effort, but it does not reduce responsibility for risk management, controls and evidence.

Cyber risks, cloud dependencies, concentration risks and the use of AI are particularly in focus. External providers can make processes more efficient, but they also create new dependencies.

For financial institutions, this means that outsourcing must not only be regulated contractually. It needs to be managed as an ongoing governance process. This includes risk analysis, responsibilities, controls, vendor oversight, exit planning and audit-ready evidence.

Proportionality Does Not Remove Responsibility

Proportionality is important for smaller banks and financial institutions. Requirements should be implemented in a way that reflects size, complexity, business model and risk profile. This is reasonable, because smaller institutions do not have the same resources as large banks.

However, FINMA makes clear that proportionality does not mean that key risks can be ignored or weakly managed. For topics such as money laundering, sanctions, cyber risks or outsourcing, the size of the institution can only be a limited argument for reduced expectations.

The decisive point is responsibility. A financial institution can outsource an IT service, a cloud platform, an operational function or a security capability. But responsibility towards customers, supervisors and management remains internal.

Why Outsourcing Is Becoming More Critical in Finance

Outsourcing has long been part of everyday operations in financial institutions. IT operations, cloud infrastructure, payment processes, core banking systems, data analytics, cybersecurity, customer communication and compliance-related services are increasingly provided by external vendors.

This creates clear benefits. Institutions can access specialist expertise, reduce costs, gain scalability and adopt modern technologies faster. Smaller banks in particular benefit because they do not need to build complex capabilities fully in-house.

At the same time, new risks emerge. When important processes are handled by external providers, dependencies arise. When many institutions use the same cloud or technology providers, concentration risks increase. When vendors provide AI systems, data platforms or security services, oversight becomes more complex.

Outsourcing is therefore not merely a procurement or IT topic. It is a governance topic.

Cloud and Technology Providers: Efficiency Meets Concentration Risk

The increasing use of cloud and technology providers is a double-edged issue for financial institutions. On the one hand, it enables modern, secure and scalable infrastructure. On the other hand, it can create strong dependencies on a small number of large providers.

For GRC leaders, the key task is to make these dependencies visible. Which critical processes run with which provider? Which data is processed? Which subcontractors are involved? Which outage or security risks exist? How quickly could the institution react if a provider failed or suffered a serious security incident?

FINMA’s perspective is clear: smaller institutions may use pragmatic solutions. But they must know and effectively manage their material risks. This requires structured third-party risk management.

AI Changes Both Sides of the Risk

FINMA’s reference to artificial intelligence is particularly interesting. AI can support financial institutions, for example in process automation, fraud detection, customer service, risk analysis or cybersecurity. At the same time, AI can make attacks easier to automate and scale.

This changes both the opportunity side and the threat landscape. An institution may use AI functionality from an external provider without fully understanding the underlying models, data flows or security mechanisms. At the same time, attackers can use AI to make phishing, social engineering, malware or fraud attempts more professional.

For outsourcing, this means that vendor assessments will increasingly need to consider AI governance, data processing, model risks, security controls and transparency. This is especially important where AI is used in critical processes or customer-relevant decisions.

What a Good Outsourcing Framework Needs to Do

An effective outsourcing framework does not start with the contract. It starts with the question of which processes are critical and which risks arise from outsourcing them. Providers then need to be assessed, controls defined and responsibilities clarified.

Ongoing monitoring is equally important. A provider that is acceptable today may have a different risk profile tomorrow because of new subcontractors, changed services, security incidents or regulatory expectations. Outsourcing risks are dynamic.

Financial institutions should therefore not only maintain a list of vendors. They need a central view of criticality, contracts, controls, risk acceptances, findings, actions, dependencies and exit scenarios.

Conclusion: Outsourcing Needs Internal Control

FINMA makes clear that outsourcing can be useful and efficient for smaller banks. But it does not transfer responsibility to the service provider. Cyber risks, cloud dependencies, concentration risks and AI use must be understood and managed internally.

For GRC leaders, the message is clear: outsourcing requires transparency. Which providers are critical? Which risks exist? Which controls are in place? Which evidence is available? And how quickly can the institution react if a provider fails or suffers a security incident?

Zazoon supports financial institutions in centrally managing outsourcing, vendor risk, cyber risks, controls and evidence. This turns outsourcing from a blind spot into a controlled component of modern governance.

FAQ

What did FINMA say about outsourcing?

FINMA emphasises that smaller institutions can outsource technology and services, but responsibility for appropriate risk management remains with the supervised institution.

Why is outsourcing a GRC topic?

Outsourcing connects vendor risk, cybersecurity, operational resilience, compliance, internal controls, audit and management responsibility. It is not only about contracts, but about ongoing oversight.

Which risks are most relevant?

Cyber risks, cloud dependencies, concentration risks, subcontractors, data risks, outage risks and new risks from AI use are particularly relevant.

What does proportionality mean?

Proportionality means that requirements can be implemented in a way that reflects size, complexity and risk profile. It does not mean that material risks can be taken less seriously.

What should financial institutions review now?

Institutions should review their critical service providers, cloud dependencies, subcontractors, controls, exit scenarios, risk acceptances and evidence in a structured way.

How does Zazoon help?

Zazoon helps connect service providers, risks, controls, responsibilities, assessments, findings and evidence in one central GRC system. This makes outsourcing manageable, traceable and audit-ready.

Related posts