Auditing of institutions under FinIA and CISA

FINMA uses regulatory auditors to extend its reach when supervising the following licence holders.
  • Managers of collective assets
  • Fund management companies
  • SICAVs and SICAFs
  • Limited partnerships for collective investment
  • Custodian banks
  • Representatives of foreign collective investment schemes

Risk analysis and audit strategy

Within six months after a licence holder’s financial year ends, audit firms submit an assessment of the institution’s risk situation as well as the derived audit strategy to FINMA electronically using a standardised form. The risk analysis covers all audit fields with a view to determining net risk from a combination of the different risk factors and in accordance with the business activities.

A standard audit strategy is generally applied for supervised institutions in FINMA Supervisory Category 5. Here, the frequency and depth of the audit to be performed are determined by the net risk exposure in the respective audit fields. For supervised institutions in FINMA Supervisory Category 4, FINMA can exercise greater influence on the audit fields to be assessed by defining the audit strategy individually in a dialogue with the audit firm.

Supervised institutions in FINMA supervisory category 5 with no heightened risk situation and without any significant weaknesses in their internal control system can apply for the audit frequency to be reduced. If the application is approved by FINMA, the audit firm will then only carry out regulatory on-site audits every two years. In years when no audit is carried out, no risk analysis or audit strategy is drawn up either.


Once an audit firm has completed a regulatory audit of a licence holder, it communicates the findings and recommendations to FINMA in the form of a standardised report. The report also contains information about the conduct of the audit, a declaration of independence on the part of the audit firm, and further information in accordance with FINMA guidelines.

Audit mandataries

In exceptional circumstances, FINMA can appoint an audit mandatary. Potential candidates for this role are approved audit firms and independent third parties with relevant experience and specialist knowledge.


2013/03 FINMA-Rundschreiben "Prüfwesen" (06.12.2012)

Prüfwesen (gültig bis 31.12.2023)

Updated: 04.11.2020 Size: 1.05  MB
Add to personal download list
2013/03 FINMA-Rundschreiben "Prüfwesen" (06.12.2012)

Prüfwesen (gültig ab 1.1.2024)

Updated: 07.12.2022 Size: 0.45  MB
Add to personal download list

Annexes to Auditing Circular

Anhang 7: Standardprüfstrategie SICAV

Updated: 01.01.2022 Size: 0.01  MB
  • Language(s):
  • DE
  • FR
Add to personal download list
Anhang 15: Risikoanalyse FINIG/KAG

Updated: 01.01.2022 Size: 0.03  MB
  • Language(s):
  • DE
  • FR
Add to personal download list

Guidelines for Auditing Circular

Audit points
Conduct rules FinSA (Suitability)

Updated: 04.05.2023 Size: 0.14  MB
Add to personal download list

 Regulatory Audit Report

Audits for institutions seeking authorisation

Choice of the audit firm

The notification regarding the selection of an audit firm is made via the FINMA Survey and Application Platform (EHP). If your institution does not have access to the EHP, the form below can be used.