European supervisors warned this week that the region's banks and insurers remain heavily dependent on cloud and IT infrastructure based outside the European Union, and that artificial intelligence is making that dependency easier to exploit 1. Under the Digital Operational Resilience Act (DORA), the EU can already place the largest of these providers under direct supervisory oversight. Switzerland has no equivalent instrument: FINMA still asks each institution to manage the same concentrated dependency on its own. For Swiss boards, the question is no longer whether to worry about a cloud outage, but how to govern a risk that EU regulators have decided institutions cannot manage alone.
EU supervisors flag cloud concentration and AI-accelerated attacks
On 23 September 2026, the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authority (ESMA) — together the ESAs — published their Autumn 2026 joint risk update 1. It warns of an "ongoing strong reliance on non-EU ICT service providers and payment systems", noting that clearing, repurchase-agreement (repo) markets and credit ratings are "largely intermediated by non-EU entities" 1. Dependence on providers outside the European Economic Area exposes firms to other regulatory regimes and to geopolitical disruption, the ESAs say 1.
The update ties this concentration to two accelerating risks. It warns that "advanced AI systems could make cyberattacks more powerful and harder to contain, allowing malicious actors to identify and exploit vulnerabilities at unprecedented speed" 1 — exactly the kind of shock a concentrated dependency amplifies. It also flags that quantum computing "could also create major risks, through undermining cryptography systems widely used to secure communications, transactions, databases, and blockchains" 1, meaning the same concentrated infrastructure will also carry the sector's cryptographic migration.
Why direct oversight, not self-assessment, is the real shift
The ESAs' warning about concentration is not new; supervisors have flagged cloud dependency for years. What has changed is the governance model built to address it. In November 2025, the ESAs designated a first group of critical ICT third-party providers (CTPPs) under DORA and placed them under direct oversight: annual risk reviews, mandatory reporting and on-site inspections carried out by the ESAs themselves, not by the banks that use them 3. The designation criteria are systemic: a provider's potential impact if it failed, the concentration of financial institutions relying on it, and how easily its services could be substituted 3. For the first time, a small number of infrastructure providers, not thousands of individual financial firms, are the direct object of EU financial supervision.
Switzerland has no comparable mechanism. FINMA's Circular 2018/3 on outsourcing, in force since 2018, is principle-based and institution-level: each bank and insurer must assess the materiality of an outsourcing arrangement itself, retain audit rights, and give "appropriate allowance" for the higher risk of outsourcing activities outside Switzerland, particularly around restructuring and resolution 4. There is no register of systemically important providers, no threshold that triggers direct FINMA oversight of a provider itself, and no requirement that providers submit to on-site inspection by the regulator. The model assumes that if every institution manages its own third-party risk well, the system as a whole stays resilient.
FINMA's own supervisory practice suggests that assumption is under strain. Its 2024 review found "increased concentration at individual service providers supplying significant or even critical functions to numerous financial institutions", with one in five Swiss banks and insurers already outsourcing significant data or functions to public cloud providers, and warned that "an outage at one of these service providers, or an incident involving unauthorized access to sensitive data held by them, could have a very serious impact on the Swiss financial market" 2. That is a systemic-risk statement from the supervisor itself, made inside a framework that has no tool to act on the provider directly.
This is the gap the ESAs' update makes newly visible. The EU has decided that concentrated dependency on a handful of providers is a systemic risk requiring direct supervision of the provider, not only of the institutions that use it. Switzerland, exposed to a similarly small set of global cloud, clearing and payment infrastructure providers, still relies on each institution reaching its own judgment about the same underlying dependency, with no central view of how concentrated the Swiss financial sector's exposure actually is, and no direct channel for a regulator to test the resilience of the provider itself.
What it means for Switzerland
Swiss banks and insurers should not assume this is only a European problem. Many rely on the same global cloud, clearing and payment providers now under direct EU oversight, and institutions with EU operations or EU counterparties are already touched by DORA indirectly, through contracts, audits and reporting their EU-regulated units must satisfy. A purely domestic institution gets none of that visibility: no annual EU risk review of its provider, and no equivalent Swiss review to fall back on.
Two decisions follow. First, boards need a current, board-level map of which providers sit underneath multiple critical functions at once, not a compliance-team inventory buried in outsourcing files. FINMA's own findings show the exposure is already material and concentrated at a small number of providers 2. Second, institutions should use their commercial leverage now: asking the same hyperscale providers what oversight findings, audit rights and resilience commitments they extend to EU-regulated clients, and negotiating comparable terms, rather than waiting for Bern to build a Swiss designation regime that does not yet exist.
Beyond banking, the same logic applies wherever a Swiss organization depends on a small number of shared cloud or IT platforms for a function that would be hard to replace quickly. The EU's shift from institution-level to provider-level oversight is a governance signal worth watching well outside financial services, and well outside the EU.
Questions for leadership
- Do we have a current, board-level map of which cloud, payment and clearing providers underpin more than one critical function, updated at least annually?
- If one of our most-relied-on ICT providers had a multi-day outage tomorrow, what would fail first, and how would we report that to the board and to FINMA?
- Can we obtain, contractually, the same oversight evidence, audit rights or resilience commitments that our providers now give to EU-regulated clients under DORA?
- Should the Swiss financial sector, through FINMA or industry bodies, seek a designation-and-oversight mechanism of its own for systemically important ICT providers, rather than leave the assessment to each institution?
- How would an AI-accelerated attack on a shared, concentrated provider change our incident response and continuity plans, compared with an attack aimed at us alone?
Sources
- European Banking Authority, EIOPA and ESMA (the ESAs), “ESAs call for vigilance over external dependencies, cyber threats and private credit risks”, 23 September 2026. eiopa.europa.eu
- FINMA, “Cyber risks and outsourcing”, 8 April 2025. finma.ch
- European Banking Authority and EIOPA, “European Supervisory Authorities designate critical ICT third-party providers under the Digital Operational Resilience Act”, 18 November 2025. eiopa.europa.eu
- FINMA, “FINMA publishes outsourcing circular”, 5 December 2017. finma.ch