FINMA outsourcing requirements for self-hosted apps

Pilae maps its service to FINMA Circular 2018/3 and writes the controls into your contract: inventory, due diligence, audit and information rights, subcontracting, data location and exit.

Talk to our teamRequest the security pack

Framework
FINMA Circular 2018/3 Outsourcing
Data location
Your premises or dedicated machines in Zurich
Audit rights
For you, your audit firm and FINMA
Operator
Pilae SA, Lausanne, under Swiss law

The controls of Circular 2018/3, mapped to the Pilae service

The circular leaves responsibility with your institution and asks you to select, instruct and monitor your provider. These are the parts of that work Pilae delivers in writing.

Inventory of outsourced functions

A list of every app and function we operate for you, with its location, its sub-processors and its data, ready for your outsourcing inventory.

Due diligence pack

Company facts, security controls, sub-processors, continuity and exit, with the evidence behind each. Delivered before you sign.

Audit and information rights

Your contract grants you, your audit firm and FINMA the rights of information, inspection and audit the circular requires, over the records and systems that hold your data.

Subcontracting under control

Each subcontractor is named with its role and location. A change is notified in advance, and the same duties pass down the chain.

Data location in Switzerland

Your premises or dedicated machines in Zurich, with backups in Switzerland. Stored client data does not leave the country without your written agreement.

Continuity and exit

Daily encrypted backups, monthly restore tests and an exit plan with your data in open formats, so the function can come back in-house or move on.

FINMA Circular 2018/3 and what it asks of a provider

FINMA Circular 2018/3 sets the rules for banks, securities firms and insurers that outsource significant functions. The institution stays responsible. It must keep an inventory of what it outsources, choose its provider with care, instruct and monitor it, and be able to bring the function back or move it on.

None of that can be done without the provider’s cooperation. Pilae writes that cooperation into the contract, control by control, so your compliance team maps our terms onto the circular instead of negotiating them one at a time. Our financial services page covers the wider picture for your sector.

Audit and information rights for you, your audit firm and FINMA

The circular requires that you, your audit firm and FINMA can inspect and audit an outsourced function. Your contract grants those rights. The console shows every app, machine, deployment, backup and restore test. The audit log records every access, approval and change made by the Pilae Agent or by a named engineer, and exports to your SIEM.

Data location, confidentiality and subcontracting

Stored client data can stay entirely in Switzerland. Run on your own premises, including air-gapped sites, or on dedicated machines in Zurich in Pilae Cloud. Backups are encrypted before they leave the machine and stored in Switzerland. Data residency describes how each location is named in your contract. Security lists the controls, built to ISO 27001.

Every subcontractor appears in our data processing agreement with its role and location. A change is notified in advance with a right to object, and each subcontractor is bound by the same duties.

An exit plan you can test

The circular expects you to be able to end an outsourcing arrangement without disrupting your business. Every app Pilae operates is open source or source-available, and every export is in open formats. Our exit plan service documents how each function comes back in-house, and we test it by restoring an export into an environment you control.

For a proposal, see pricing or talk to us.

How we prepare your outsourcing file

  1. Classify the functions

    With your team we list each app and decide whether its function is significant under the circular.

  2. Deliver the due diligence pack

    Controls, sub-processors, locations, continuity and exit, with evidence your risk and compliance teams can check.

  3. Write the contract

    Audit and information rights, subcontracting rules, data location, service levels, security duties and termination, in one written agreement.

  4. Set up monitoring

    Console access, audit log exports and periodic reports, so you can supervise the service as the circular expects.

  5. Test the exit

    We restore an app from its export into an environment you control, so the exit plan is proven rather than assumed.

What your contract includes

Audit rights
Rights of information, inspection and audit for you, your audit firm and FINMA, as the circular requires.
Data location
Every machine and backup target named in the contract, in Switzerland unless you agree otherwise in writing.
Subcontracting
Sub-processors disclosed to you in the DPA, changes notified in advance with a right to object, and our duties passed on to each one.
Security and confidentiality
Controls built to ISO 27001, named access, encryption in transit and at rest, and an audit log retained for the contract.
Service levels
99.9% monthly availability with service credits. Around-the-clock incident response on the Enterprise plan.
Exit
Your data and configuration returned in open formats, with support during the transition, then deleted with written confirmation.

The apps behind it

Questions

Is Pilae FINMA-approved?

FINMA does not approve outsourcing providers. Under Circular 2018/3 your institution stays responsible for what it outsources and must select, instruct and monitor the provider. Pilae gives you the contract terms, documentation and access that let you do so.

Can FINMA and our audit firm audit Pilae?

Yes. Your contract grants you, your audit firm and FINMA rights of information, inspection and audit over the service, including its records and the environments that hold your data.

Can client data stay in Switzerland?

Yes. Run on your own premises or on dedicated machines in Zurich, with backups in Switzerland. Every location is named in your contract, and nothing moves without your written agreement.

Which subcontractors are involved?

The DPA you sign discloses each one with its role and location. Hosting and backups run in ISO 27001-certified datacentres in Switzerland, and optional AI features are used only if you enable them. On your premises, your application data stays on your servers.

What happens when we end the contract?

We export your data and configuration in open formats and support the transition to your own team or another provider. We then delete your data from machines and backups and confirm it in writing.

Does the circular apply to our institution?

Circular 2018/3 is addressed to banks, securities firms and insurance companies supervised by FINMA, and other supervised institutions often use it as their reference. Your compliance team decides whether it applies and whether a given function is significant. We supply the facts those decisions need.

Related

Send us your outsourcing questionnaire.

An engineer answers it control by control and sends the draft contract terms for your legal team.