IT outsourcing and private AI for banks and insurers under FINMA Circular 2018/3

Open-source and source-available apps and private AI for banks, asset managers and insurers, operated under a contract written for FINMA Circular 2018/3 and, for EU entities, DORA.

Talk to our teamBook a 30-minute briefing

Framework
Contract written for FINMA Circular 2018/3 and DORA
Audit rights
For you, your audit firm and the supervisor
Data location
Your premises or Switzerland, named per app
Operator
Pilae SA, a Swiss company with no US parent

Outsourcing your supervisor can inspect

When a bank or insurer hands an important function to a provider, the supervisor expects the same control as if it ran in-house. We build the operation, the records and the contract around that expectation.

Audit and inspection rights

You, your external audit firm and FINMA can inspect how we operate your apps, with the records to back it.

Client data in Switzerland

Client-identifying data stays on your premises or on dedicated machines in Zurich. The location is named per app in the contract.

Private AI, inside the perimeter

Analysts and advisers use open models on your hardware. No client document or prompt goes to a public AI service.

Every change approved and recorded

The Pilae Agent plans each change and waits for approval. Plan, approver, commands and result go to an audit log you can export to your SIEM.

Backups you can prove

Daily encrypted backups offsite in the country you choose, and a restore test every month recorded in the console.

An exit plan on file

A documented exit with open export formats and a handover to another operator or back in-house, tested on request.

Outsourcing under FINMA Circular 2018/3

FINMA Circular 2018/3 sets what banks, securities firms and insurers must do when they outsource a significant function. The institution stays responsible. It keeps an inventory of what it outsources, chooses and supervises the provider carefully, and secures the right for itself, its audit firm and FINMA to inspect. We write our contract to that list. The FINMA page goes through the circular point by point, and the shared responsibility page shows who does what.

Banking secrecy and client data

Article 47 of the Banking Act protects client information held by banks and by the people they engage. Most institutions keep client-identifying data in Switzerland or on their own premises. We run your apps on your premises or on dedicated machines in Switzerland. Pilae SA is a Swiss company with no US parent, and the jurisdiction page explains which laws can reach your data.

DORA for EU entities

The EU Digital Operational Resilience Act has applied to banks, insurers, investment firms and other financial entities in the EU since 17 January 2025. It sets required clauses for ICT third-party contracts, asks for a register of information and expects exit strategies that have been tested. The NIS2 and DORA page covers what we supply for each.

Private AI for advisers and analysts

Private bankers, underwriters and analysts want AI for research, drafting and summaries, on documents that must not leave the institution. We run private AI with open models on your hardware and Open WebUI as the interface, behind your own identity provider.

Talk to us

Contact us to start due diligence, or email hello@pilae.com with your questionnaire.

How we onboard a financial institution

  1. Due diligence pack

    We send our security documentation, sub-processor list, data processing agreement and draft outsourcing clauses to your risk and compliance teams.

  2. Materiality and placement

    You classify each function. Together we decide what runs on your premises, what runs in Switzerland and what stays air-gapped.

  3. Contract and exit plan

    Audit rights, sub-outsourcing rules, data location, incident reporting and exit are written into the agreement before any data moves.

  4. Fixed-price onboarding

    We install the apps, connect Keycloak or Entra ID and migrate data, with each step recorded for your outsourcing inventory.

  5. Managed operations

    Changes run in agreed windows after your approval. Monitoring alerts reach Pilae engineers around the clock.

What your contract includes

Audit rights
Access to records, premises and staff for you, your audit firm and FINMA, and for EU entities your competent authority.
Sub-outsourcing
Sub-processors disclosed in the signed data processing agreement. Changes notified in advance, with a right to object.
Data location
Named per app: your premises, Switzerland, or an EU region you choose.
Incident reporting
Notice of security incidents affecting your services within the time your contract sets, with the detail your own reporting needs.
Availability
99.9% monthly availability commitment with service credits, in every plan. RPO and RTO stated per app.
Exit
A full export of data and configuration in open formats, and help moving to another operator or back in-house.

The apps behind it

Questions

Does outsourcing to Pilae meet FINMA Circular 2018/3?

The circular places the responsibility on your institution: you keep an inventory, select and supervise the provider, and secure audit and inspection rights. Pilae supplies what that requires on our side: a written agreement with audit rights for you, your audit firm and FINMA, sub-processors disclosed in the signed agreement, a data location per app and a documented exit. Whether a function is significant under the circular is your classification.

Is Pilae FINMA-approved?

FINMA does not approve or certify outsourcing providers. It supervises the institutions that outsource. Our role is to give your institution the contractual rights and the records the circular expects from a provider.

How do you handle banking secrecy and client-identifying data?

Banking secrecy under Article 47 of the Banking Act binds your institution and the agents it uses. Client-identifying data stays on your premises or on dedicated machines in Switzerland, Pilae staff are bound by confidentiality obligations, and every administrative access is recorded. Your legal team decides which data may leave your premises at all.

We are an EU financial entity. Does Pilae support DORA?

DORA has applied since 17 January 2025 and requires specific clauses in contracts with ICT third-party providers, a register of information and tested exit strategies. Our contract carries those clauses, including service locations, audit access, incident assistance and termination rights, and we supply the details your register needs.

Is Pilae certified to ISO 27001 or SOC 2?

No. Pilae is built to ISO 27001 controls, and Pilae Cloud is hosted in ISO 27001-certified datacentres. Pilae SA does not hold an ISO 27001 certificate or a SOC 2 report of its own. We answer your security questionnaire in full and support your on-site audit.

Can AI be used on client documents?

Yes, when the model runs inside your perimeter. Open WebUI or LibreChat runs on your machines with open models hosted there, so client documents and prompts do not leave. The optional connection to an external model stays off unless you enable it.

Related

Send us your due diligence questionnaire.

We answer it in full, then walk your risk and compliance teams through the outsourcing clauses and the exit plan.