No spam - just the latest insights!
Join over 30,000 industry professionals who subscribe for free
Subscribe for free!
We'll never share your information or send you spam
Dr Christian Schönfeld is counsel at Prager Dreifuss and a member of the corporate and M&A practice group. He focuses on the law of banking and capital markets and the regulatory issues associated with financial market law. Within these areas he has particular experience in collective investment schemes law and in the areas of Fintech and crypto assets (ICOs, tokenization etc.). Furthermore, he works in the areas of corporate and commercial law including mergers and acquisitions. He also advises on data protection matters and is a member of Prager Dreifuss’ Startup Desk.
Prior to joining Prager Dreifuss as a lawyer, he worked as a research assistant at the University of St. Gallen where he also earned his doctorate with a thesis on collective investment schemes in distress. He is a regular speaker at conferences and publishes on the topics he specialises in.
Switzerland encourages innovative business models and aims to keep regulatory requirements at a sensible level and to reduce unnecessary regulatory obstacles. However, the goal to encourage innovation may be at odds with the regulatory aims of protecting investors and ensuring transparency and the proper functioning of the financial markets. Therefore, the constant technological progress also requires the constant re-evaluation of existing regulatory answers to strike a balance between enabling innovation without jeopardising the other goals of financial market regulation.
Following last year’s overview of the general Swiss Fintech framework, this essay shall provide an overview of recent trends in the Fintech area and how Switzerland addresses the issues connected therewith.
Swiss financial market regulation adheres to the principle of technology neutrality, i.e. “same business, same risks, same rules”. This means that the same rules shall apply to equivalent activities irrespective of the underlying technology unless such technology results in a different risk structure which, in turn, warrants a different regulatory treatment. In other words, Switzerland regulates business models instead of technologies.
So far, Switzerland has refrained from enacting a separate, comprehensive Fintech statute. Consequently, the statutes which regulate the financial industry apply also in the context of Fintech, namely the following:
The Banking Act (BA) provides the rules for the provision of banking services, i.e. in particular lending services and accepting deposits from the public on a professional basis.
The Financial Institutions Act (FinIA) regulates dealing in securities. Securities firms require a license by the Swiss Financial Market Supervisory Authority FINMA (FINMA) if they operate on a commercial basis. In addition, FinIA also contains rules pertaining to further financial market participants, e.g. asset managers.
The Financial Services Act (FinSA) regulates the provision of financial services to clients and includes various obligations to be complied with by financial service providers. Furthermore, it regulates the obligation to prepare and publish prospectuses in certain cases.
The Collective Investment Schemes Act (CISA) regulates the formation of collective investment schemes.
The Financial Markets Infrastructure Act (FMIA) regulates financial market infrastructures such as stock exchanges.
The Anti-Money-Laundering Act (AMLA) regulates the obligations of so-called financial intermediaries (including regulated entities such as banks as well as persons who on a professional basis accept or hold on deposit assets belonging to others or who assist in the investment or transfer of such assets) in combating money laundering. Namely, this includes the duty to perform KYC checks, to notify the competent authorities in case of suspected money laundering and to affiliate with a self-regulatory organisation.
The aforementioned statutes are supplemented by lower-level regulation as well as circulars and guidelines published by FINMA on its practice.
The legal basis for FINMA is provided by the Financial Market Supervision Act (FINMASA).
3.1. From Open Banking and Open Finance to Decentralised Finance
3.1.1. Open Banking and Open Finance
Open Banking describes a business model which is based on the standardised and secure exchange of transaction data between banks and trusted third-party service providers, namely Fintech companies. Open Finance can be viewed as an extension of the concept of Open Banking in that it is not limited to the exchange of transactional data but also includes further information, e.g. on available assets.
Despite the growth in popularity of such business models, the Swiss legislator, so far, refrains from specifically regulating them. Notably, there is no obligation of banks to provide open interfaces to service providers. Instead, Open Finance models are governed by existing regulation. Particularly, FINMA has published a circular on outsourcing by banks and other financial institutions that regulates regulatory outsourcing, i.e. cases in which a company mandates service providers with performing all or part of functions that are significant to the company’s business activities independently and on an ongoing basis. Significant functions are functions that have a material effect on compliance with the goals and regulations of financial market legislation. However, often Open Finance services will not qualify as such a regulatory outsourcing because they occur on the client’s initiative instead of the bank’s initiative.
Furthermore, the services provided by a service provider may qualify as financial services and trigger obligations under FinSA. The bank has to inform its client about the risks of providing information to the service provider. Compliance with anti-money laundering rules is a further topic: The outsourcing bank falls under the scope of AMLA due to it being a regulated entity. To what extent AMLA also applies to service providers depends on the circumstances, e.g. whether they may dispose of the client’s assets.
3.1.2. Decentralised Finance
Decentralised Finance (“DeFi”) refers to openly accessible financial services linked to open-access distributed ledger platforms. DeFi applications do not rely on traditional financial intermediaries like banks but function on a peer-to-peer basis with so-called smart contracts, i.e. programs that automatically execute the terms of a contract. Consequently, there are no longer individually identifiable or controlling operators.
So far, Switzerland regulated the distributed ledger technology only to a limited extend. In 2021, the so-called DLT Act came into force. Among else, it opened certain regulatory concepts for business models based on crypto assets and it created a new category of licensed financial market infrastructures, the DLT trading facility which enjoys more freedom than traditional trading facilities like stock exchanges regarding who may be granted access and what services may be offered. Beyond that Switzerland has not enacted comprehensive legislation in this area. In line with the principle of technology neutrality, FINMA applies existing financial market regulation when assessing DeFi enquiries. If a DeFi project offers the same services and/or creates the same risks as a service provided by traditional financial intermediaries the same rules also apply including licensing requirements if a DeFi project – economically – pursues an activity which requires a license.
In principle, this approach is straightforward. Nonetheless, the peer-to-peer structure of DeFi projects raises new questions:
DeFi projects rely on a layered technical infrastructure, consisting, among else, of settlement, asset, protocol or application layers. On each layer different parties may participate which may remain unidentified. Furthermore, due to the peer-to-peer concept there is no party controlling the system. Rather, the system and the DeFi application on it run automatically. Meanwhile, financial market regulation relies on identifiable parties to attribute (licensing and other) obligations and responsibilities to. Additional complexity stems from the fact that independent parties may be active on different layers which only together trigger the regulatory consequences (traditionally, somewhat similar issues are addressed by considering parties acting in concert as a group and by applying regulation to the group). Mostly, the scope of financial market regulation follows the principle of territoriality. This makes it difficult to apply regulation to DeFi applications due to their international decentralisation. For these reasons, complying with regulation may often be difficult for DeFi initiatives. Also, it remains to be seen whether traditional enforcement mechanisms will prove to be sufficient, particularly in view of limiting the availability of unlicensed DeFi applications to protect investors.
The automatic execution of smart contracts also raises civil law questions. With the code being the law and due to the lack of a controlling operator it will be difficult, for instance, to enforce a court decision requiring a cancellation of a transaction. The pseudonymous nature of distributed ledger platforms further complicates enforcement of claims as a claimant may struggle to find out who his counterparty is.
Besides that, this pseudonymity also raises questions with respect to compliance with anti-money laundering rules, namely KYC obligations. While there are technological attempts to ensure compliance with KYC obligations (e.g. so-called zero-knowledge Know-your-customer technologies, zkKYC) they likely do not satisfy the requirements of AMLA.
3.2. Use of Artificial Intelligence in Financial Services
3.2.1. Background
Recently, artificial intelligence (“AI”) received substantial public attention (particularly, in connection with OpenAI’s ChatGPT platform).
However, this rise of AI has not only been met with enthusiasm but also with some scepticism as its use also raises various (legal and other) questions, not least whether new legislation is needed to address issues associated with the use of AI solutions.
These general remarks also apply in the context of financial markets and Fintech solutions. Here, AI has been used for a while already, for instance for AI assisted decision making, e.g. in assessing the risk of default when granting loans or choosing investment options when providing investment advice. Also, chatbots are used to interact with clients and AI solutions help monitoring and identifying suspicious transactions in view of AML obligations.
Switzerland has no dedicated AI legislation yet. However, this is likely to change as already members of the Swiss government have publicly stated that regulation is needed.
Due to this lack of specific legislation, Swiss law relies on existing law to deal with the legal challenges of AI.
3.2.2. Regulatory Issues
Generally speaking, AI solutions may be used in the financial sector provided they comply with the existing regulatory requirements. The principle of technology neutrality also applies here. FINMA will assess the use of AI solutions in view of the aims of financial market regulations, particularly the protection of customers/investors and financial market stability. For instance, when employing roboadvisors to provide financial services the requirements of FinSA must be complied with same way as when humans provide such services. Particularly, one must also consider the (likely) limited knowledge of clients regarding the general functioning of such roboadvisors. Beyond this general principle, the exact details remain open at this point.
3.2.3. Further issues
The use of AI solutions also raises further issues, not least data protection concerns. A fundamental requirement of data protection law is informing the data subject about the processing of his/her personal data. Adequate, clear and comprehensive information is particularly important considering the consequences the processing, e.g. in connection with investment advice or loan approvals, may have for the data subject (consequences may range from financial repercussions, e.g. when denying a loan, to potential criminal law proceedings, e.g. in the context of transaction monitoring). Furthermore, in such cases the processing of personal data in this context may qualify as so-called profiling. In addition, automated decision making by AI solutions triggers obligations in addition to enhanced information requirements, e.g. the duty to provide the data subject with the opportunity to request the decision made by the AI to be reassessed by a human. Also, prior to using such solutions a data protection impact assessment may need to be performed and additional measures to reduce the potential risks for the data subjects must be implemented.
The processing of personal data must be proportionate. Furthermore, personal data may only be collected for a specific purpose that the data subject can recognise and, subsequently, personal data may only be further processed in a manner that is compatible with this purpose. Besides the aforementioned requirement to inform the data subjects this may also limit the further use of existing collections of data. Whether the processing of already available personal data for a new purpose can be justified (e.g. based on an overriding interest) requires a careful assessment in each case.
Finally, AI solutions regularly rely on services by, and require the transfer of personal data to, third party providers. In this context it is necessary to ensure that no professional secrecy requirements, e.g. banking secrecy rules, are violated. Also, where such transfers occur across borders additional requirements for international transfers of personal data apply. This may cause challenges where service providers operate from jurisdictions which – from a Swiss viewpoint – do not offer a similar level of data protection, namely the US.
Swiss financial market regulation follows the principle of technology neutrality and, consequently, regulates specific technologies only to a limited extent. Therefore, Swiss law largely relies on the existing statutes and regulation also when dealing with new developments such as Open Banking, Open Finance, DeFi but also the use of AI solutions.
This allows Switzerland to foster innovative business models within the rapidly evolving area of Fintech. At the same time Switzerland ensures not jeopardising the protection of investors and the functioning of the market. In combination, this increases the attractiveness of Switzerland as a hub for Fintech businesses.
However, refraining from adapting existing law also leads to the challenge of dealing with new issues under statutes which were enacted without consideration for such new problems. It remains to be seen what solutions will be found to these now problems. In any case, the current lack of clear and tested solutions and the potential consequences of violations of applicable laws make it highly advisable to seek expert legal advice in advance.