Compliance / By country / FINMA 2018/3

FINMA Circular 2018/3 (Outsourcing) and Microsoft 365

Swiss financial-sector outsourcing and access-control oversight. Siemserva by Senserva maps 197+ Microsoft 365 and Entra ID checks to the areas FINMA 2018/3 emphasizes, so a scan of your tenant doubles as evidence.

SwitzerlandFinancial sector197+ mapped checks

What FINMA 2018/3 is

FINMA Circular 2018/3 sets outsourcing and oversight expectations for Swiss banks and insurers, including access control over outsourced and cloud services. For firms running Microsoft 365, that means demonstrable control over identity, privileged access, and logging.

FINMA 2018/3 and Microsoft 365: common questions

Does FINMA 2018/3 apply to Microsoft 365?

FINMA Circular 2018/3 (Outsourcing) does not name Microsoft 365 specifically, but its identity, access-control, and logging requirements are met (or missed) in your Microsoft 365 and Entra ID configuration. That is where Siemserva checks provide the evidence.

How does Siemserva map to FINMA 2018/3?

Siemserva runs 197+ Microsoft 365 and Entra ID checks across the areas FINMA 2018/3 emphasizes, multi-factor authentication, Conditional Access, privileged access, and logging, ranks the gaps by Severity, and produces audit-ready evidence. It is evidence, not an official mapping or certification.

Is this an official FINMA 2018/3 certification?

No. Senserva is not an assessor and issues no certifications. It provides the configuration evidence, Severity ranking, and remediation that make an assessment defensible. Confirm requirements with your assessor or regulator.

More: the frameworks crosswalk, Microsoft 365 compliance by country, and the audit evidence guide.

Data notice: this page is informational and describes how Siemserva checks provide evidence relevant to the framework. It is not legal or compliance advice, not an official mapping, and not a certification. Confirm requirements with your assessor or regulator. All use is subject to the Senserva EULA.