Skip to content
← Dossiers

Regulatory analysis · Switzerland

Supervised by whom

August 2026·CH
FATFFINMASROsVASPsSupervisionSwitzerland

Regulatory analysis · Switzerland

FATF's standard on virtual assets says that VASPs must be supervised by "a competent authority (not a SRB)". Switzerland supervises its crypto businesses through self-regulatory organisations — around 200 were SRO-affiliated as at mid-2024, on the Federal Council's own figure — and is rated Largely Compliant on that Recommendation.

Below: how that was reconciled, what actually differs between the two supervisory channels, and why the question is about to be resolved by a route that never names it.

The rule

Interpretive Note to Recommendation 15, paragraph 5, in the material part:

"VASPs should be supervised or monitored by a competent authority (not a SRB), which should conduct risk-based supervision or monitoring."

FATF restated it plainly in the executive summary of its 2021 virtual-assets guidance: "only competent authorities, and not self-regulatory bodies, can act as VASP supervisory or monitoring bodies."

The exclusion is unqualified. Compare Recommendation 28(b), which governs non-casino designated non-financial businesses and professions and says the opposite: monitoring "may be performed by (a) a supervisor or (b) by an appropriate self-regulatory body (SRB), provided that such a body can ensure that its members comply with their obligations". R.28(b) is permissive as to institutional form and conditions the permission on outcome. INR.15 §5 is prohibitive as to form and conditions nothing.

A sourcing note. That wording was checked against the current consolidated text on 24 August 2026, in The FATF Recommendations, updated June 2026, at the Interpretive Note to Recommendation 15. It is still paragraph 5, and it still reads "(not a SRB)". The February 2025 revision of INR.15 did not disturb either. The sentence as it now stands: "VASPs should be supervised or monitored by a competent authority (not a SRB), which should conduct risk-based supervision or monitoring."

The Swiss position

A financial intermediary in the Swiss parabanking sector must affiliate to a FINMA-recognised self-regulatory organisation. There are eleven, on FINMA's own list as at 23 August 2026. That list is a register: name and seat, nothing else attached.

Whether VASPs sit in that population is not a matter of inference. FINMA's Geschäftsbericht 2025 states it directly:

"Die SRO sind gemäss Geldwäschereigesetz für die Überwachung von berufsmässig tätigen Finanzintermediären zuständig – etwa Geldwechsler, Money Transmitters oder andere Zahlungsdienstleister, Virtual Asset Service Providers, Organe bei Sitzgesellschaften, Kredit- und Leasinggeber oder Investmentgesellschaften"

And FINMA's authorisation pages put the corollary in English: Art. 2(3) intermediaries "are supervised by the SROs where they are affiliated, and not by FINMA."

So: FATF says not a self-regulatory body. Switzerland uses self-regulatory organisations. And Switzerland is rated Largely Compliant.

How the two were reconciled

The reconciliation happened once, in a single passage, in FATF's 3rd Enhanced Follow-up Report on Switzerland of January 2020 — the first assessment after INR.15 was adopted. It is worth reading in full, because the whole matter turns on it:

"In the 2016 MER, Switzerland was considered to be technically compliant with criterion 26.1, indicating that, in the context of Recommendation 26, Swiss OAR fulfil the FATF definition of 'supervisor', because they have the necessary powers. Therefore, in line with the applicable requirements of Recommendations 26 and 27, VASPs are supervised by financial supervisors which are either the FINMA or the Swiss OAR."

Three features of that reasoning are matters of the text rather than of argument.

The premise is a 2016 finding, made three years before INR.15 existed. Criterion 26.1 asks whether a body is a supervisor. INR.15 §5 asks whether it is an SRB. These are different questions with different definitions, and the second was not available to be asked in 2016.

FATF's own paraphrase drops the parenthesis. Two paragraphs earlier in the same report, summarising the new requirements it was about to assess, FATF renders §5 as "requirements for countries to apply adequate risk-based AML/CFT supervision (including sanctions) to VASPs and that such supervision should be conducted by a competent authority". The words "(not a SRB)" are absent. It then reasons to the conclusion that the SROs qualify.

The deficiencies FATF did record are about something else. Switzerland's Largely Compliant rating on the revised R.15 was qualified on three grounds: the occasional-transaction thresholds under the FINMA Anti-Money Laundering Ordinance (AMLO-FINMA, SR 955.033.0), the disproportionality of FINMA's sanctions, and international co-operation. The institutional form of the supervisor is not among them.

The definitions do not settle it either

There is a real question underneath, and FATF's own glossary makes it genuinely arguable rather than obviously wrong.

An SRB is defined as "a body that represents a profession (e.g. lawyers, notaries, other independent legal professionals or accountants), and which is made up of members from the profession, has a role in regulating the persons that are qualified to enter and who practise in the profession, and also performs certain supervisory or monitoring type functions."

The last limb every Swiss SRO plainly satisfies. The first three are the arguable ones. Most Swiss SROs are open-membership AML compliance associations admitting heterogeneous parabanking businesses — money changers, money transmitters, VASPs, trustees of domiciliary companies, lessors, investment companies — rather than bodies representing a profession and controlling entry to it. Two of the eleven are profession-based on their face: the SRO of the Swiss Bar Association and Swiss Notaries Association, and SRO-Treuhand Suisse.

Meanwhile Supervisors is defined to include "non-public bodies (which could include certain types of SRBs)", provided they "be empowered by law to exercise the functions they perform, and be supervised by a competent authority in relation to such functions". Swiss SROs satisfy both conditions: Art. 7(3) of the Financial Market Supervision Act of 22 June 2007 (FINMASA) lets FINMA recognise and enforce self-regulation as a minimum standard, and Arts. 12, 18 and 24 of the Anti-Money Laundering Act of 10 October 1997 (AMLA) give FINMA recognition, withdrawal of recognition and approval of an SRO's regulations.

So the standard contains both a definition that most Swiss SROs arguably escape and a definition that expressly accommodates them — and a prohibition that turns on which applies.

No one has ever put the question. Not FATF, in the 2016 evaluation, the 2020 follow-up, the 2023 follow-up or the June 2025 Targeted Update. Not the Federal Council, FINMA or the State Secretariat for International Financial Matters, in anything traced. The 2023 follow-up report — Switzerland's most recent FATF assessment — contains no mention of virtual assets, VASPs or cryptocurrency at all.

What actually differs

Set the institutional argument aside and compare the toolkits.

FINMA's enforcement instruments against a directly supervised institution sit in Arts. 31–37 FINMASA: restoration of compliance and the power to require security; declaratory ruling and substituted performance at the defaulter's cost; an industry ban on an individual for up to five years; publication of the ruling naming the person; disgorgement of profit, including avoided losses, with an estimation power and a seven-year prescription; appointment of an investigating agent who may act in place of the firm's own organs; withdrawal of the authorisation.

An SRO's powers come from its own Reglement, which FINMA approves under Art. 18(1)(c) AMLA but does not write. Art. 25(3) AMLA requires the Reglement to provide "angemessene Sanktionen" and to set the conditions for affiliation and exclusion. The statute names no specific sanction other than exclusion.

PowerFINMA over a licenseeSRO over a member
Enforceable administrative ruling (Verfügung)YesNo
Disgorgement of profitArt. 35 FINMASANo
Industry ban on an individualArt. 33, up to five yearsNo
Publication naming the personArt. 34No
Investigating agent inside the firmArt. 36No
Order security for client assetsArt. 31No
Terminal remedyWithdrawal of authorisation, Art. 37Exclusion

The Federal Supreme Court settled the character of SRO sanctions in BGE 143 II 162: an SRO discharges a public-law task "ungeachtet der privatrechtlichen Natur ihrer Organisation und des privatrechtlichen Charakters der von ihnen ausgesprochenen Sanktionen" — notwithstanding the private-law nature of its organisation and of the sanctions it pronounces. SRO sanctions are contractual. They are not administrative acts, and they do not travel the administrative-law review channel that governs FINMA decisions.

Exclusion approaches the effect of a licence withdrawal, because affiliation is mandatory under Art. 14(1) AMLA and the old direct-subordination alternative has been repealed. But Art. 14(2) gives a firm that still meets the conditions an entitlement to affiliate elsewhere. What follows an exclusion in practice — whether FINMA opens proceedings, whether re-affiliation is common — is not established from any primary source located.

And the audit chain

For a directly supervised institution the chain runs firm → state-licensed audit firm → FINMA. The auditor holds a regulatory-audit licence from the Federal Audit Oversight Authority under Art. 9a of the Audit Oversight Act of 16 December 2005 (AOA, SR 221.302). Art. 27 FINMASA makes the auditor's escalation duty statutory and owed to FINMA — immediately, on serious breaches. Art. 28a(2) lets FINMA require a change of audit firm; Art. 24a lets FINMA install its own auditor at the firm's cost. The Federal Council sets the content and form of the audit.

For an SRO member the chain runs firm → SRO-licensed auditor → SRO. Art. 24a(1) AMLA is explicit: "The self-regulatory organisation shall grant the audit firms and lead auditors the necessary licence and supervise their activity." The audit cycle is whatever the Reglement says; the Act prescribes none. FINMA approves the Reglement and supervises the SRO, but the licensing of the auditor, the cycle, the content and the escalation route all sit inside a document FINMA did not write.

What is not published

Three negatives, each material, each verified as an absence rather than a search failure.

Nobody publishes how many financial intermediaries are under SRO supervision. FINMA maintains a public directory under Art. 18a AMLA, but it is a search interface and gives no total. No figure appears in the 2025 annual report.

The crypto subset is published, but in an unlikely place. Not by FINMA, and not in any statistical release. It appears in the regulatory-impact section of the explanatory report accompanying the FinIA consultation — Erläuternder Bericht zur Änderung des Finanzinstitutsgesetzes, published by the Federal Council on 22 October 2025, at Ziff. 5.4.2 (Krypto-Institute), p. 102:

"Mitte 2024 waren rund 200 Virtual Asset Service Provider (VASP) einer Selbstregulierungsorganisation angeschlossen, wobei etwa 115 aktiv waren."

Around 200 SRO-affiliated VASPs as at mid-2024, of which roughly 115 were active.

Three dates sit behind that sentence and are easily run together. The data are as at mid-2024. The document carrying them was published on 22 October 2025. This practice read it on 23 August 2026, in the German original. So the figure is more than two years old at the time of writing, and the Federal Council states no methodology, collection basis or underlying source for it. It is the best published figure there is, which is a different thing from a reliable one.

For the wider national picture — all intermediaries with VASP activity, not the SRO-affiliated subset — the interdepartmental risk assessment of January 2024 records a rise "von unter zehn im Jahr 2018 auf über 204 per Ende 2022", and that at least 180 of them had filed no report to MROS. Those data are as at 31 December 2022.

Nobody publishes what SRO supervision produces. Art. 27(2) AMLA requires an SRO to notify FINMA immediately of every exclusion, with reasons, and of the opening of any sanction proceedings that could end in exclusion. Art. 27(3) requires an annual report plus "eine Aufstellung über die in der Berichtsperiode ergangenen Sanktionsentscheide" — a schedule of every sanction decision in the period. FINMA therefore receives, every year, a complete account of SRO enforcement. None of it is published in aggregate. The output of the system supervising Switzerland's virtual-asset sector is invisible from outside it.

For the practitioner

"Regulated in Switzerland" does not identify the supervisor. The first question about any Swiss crypto counterparty is which channel it sits in: FINMA-authorised, or affiliated to one of the eleven SROs. The FINMA directory under Art. 18a AMLA answers it. The two channels carry materially different enforcement exposure, different audit chains and different review routes, and nothing in a firm's own description of itself will tell you which applies.

A favourable FATF rating is a technical-compliance rating. Switzerland's Largely Compliant on R.15 was reached in 2020 on the reasoning set out above. Effectiveness is measured separately, under Immediate Outcome 3, where Switzerland has stood at Moderate since December 2016 — never re-assessed, because the follow-up process re-rates technical compliance only. Anyone citing Switzerland's ratings should be clear which of the two they mean.

The date matters more than usual here. Switzerland moved to regular monitoring in October 2023. FATF's own assessment calendar gives its fifth-round evaluation an on-site period from June 2027 and plenary discussion in February 2028, against the 2022 Methodology. The Swiss State Secretariat for International Financial Matters says instead that the review falls in 2026–27; the two do not reconcile, and the FATF calendar is the better source for its own timetable. Either way, that evaluation is the first occasion on which the SRO/VASP question could be put squarely — and by then it may have been overtaken.

The question may be answered by being removed

The amendment to the Federal Act on Financial Institutions of 15 June 2018 (FinIA/FINIG) consulted on between 22 October 2025 and 6 February 2026 would create a crypto-institution licence and, in the same movement, insert payment institutions and crypto institutions into Art. 2(2) AMLA — moving them out of Art. 2(3), and so out of SRO supervision under Art. 12(c) and into FINMA supervision under Art. 12(a).

That is the whole mechanism. It is a reclassification of the intermediary, not a reform of the SRO regime.

The Federal Council does say plainly what it means for the firms concerned, in the same paragraph as the VASP figure: "Für die Mehrheit der Unternehmen, die heute bereits dem GwG unterstellte Tätigkeiten mit kryptobasierten Vermögenswerten ausüben und hierfür einer Selbstregulierungsorganisation angeschlossen sind, bedeutet dies einen Wechsel der Aufsicht zur FINMA." For the majority of firms currently SRO-affiliated for their crypto activity, this means a change of supervisor to FINMA. What it does not say is why the institutional form of the supervisor should change at all.

Two things about it are worth noticing. The transition keeps SRO affiliation as the bridge: draft Art. 74b(2) lets a firm continue trading until FINMA decides, "sofern sie einer Selbstregulierungsorganisation nach dem GwG angeschlossen sind und durch diese in Bezug auf die Einhaltung der entsprechenden Pflichten beaufsichtigt werden" — affiliated to an SRO and supervised by it as to compliance. And the explanatory report, which devotes a page of its comparative section to FATF Recommendation 15 and asserts at Ziff. 2.4.1 that the proposals "stehen im Einklang mit den Empfehlungen der FATF", never reaches INR.15 §5. Across its 111 pages there is no occurrence of Interpretativnote, of INR.15, or of any rendering of "not a SRB", and no discussion anywhere of who may supervise a VASP. It reaches the last sentence of §5 — licence withdrawal, restriction, suspension — and stops one clause short of the supervision sentence. INR.15 is not cited as the driver in any public document traced.

So Switzerland may be about to resolve a tension it has never acknowledged, for reasons it has not given, and the resolution would take effect no earlier than 2028 — the year of its next FATF plenary.

Key takeaways

  • INR.15 §5 requires VASP supervision by "a competent authority (not a SRB)". R.28(b) permits SRB supervision for non-casino DNFBPs. The exclusion for VASPs is unqualified.
  • FINMA states in its 2025 annual report that SROs supervise VASPs, and that Art. 2(3) intermediaries are not supervised by FINMA.
  • FATF reconciled the two in one passage of its 2020 follow-up report, by applying a 2016 finding on the R.26 definition of "supervisor" and paraphrasing INR.15 §5 without the words "(not a SRB)".
  • No FATF or Swiss document traced has ever asked whether Swiss AMLA SROs are SRBs within INR.15. The 2023 follow-up report does not mention virtual assets at all.
  • An SRO has exclusion and contractual sanctions. It has no disgorgement, no individual ban, no publication power, no investigating agent, and cannot issue an enforceable ruling.
  • Switzerland publishes no count of SRO-affiliated intermediaries, no crypto subset, and no aggregate of SRO sanctions or exclusions — though FINMA receives a schedule of every one annually.

Sources

FATF

Swiss law

FINMA

Swiss federal


Research and analysis, not legal advice · this piece describes the supervisory architecture and does not rate, rank or compare individual self-regulatory organisations · positions stated as at 23 August 2026 · check the SR texts in force.

Working on a matter this touches?

Start a conversation