- - What FINMA expects from supervised institutions
- - What is possible and sensible today
- - What AI is not permitted to do in wealth management
- - Internal AI Policy: what must be documented in writing
- - The most common pitfalls during implementation
- - Implementing AI securely, with the right partner
- - Frequently asked questions (FAQ)
AI offers real benefits in wealth management, for example in summarising meetings, searching internal knowledge databases and creating documents using Microsoft Copilot. However, not everything is permitted: FINMA Supervisory Circular 08/2024 requires all supervised institutions to maintain an AI inventory that includes risk classification, clear lines of responsibility, data quality, traceability and explainability of decisions.
Entering customer data into public AI services, autonomous decision-making in regulated activities and a lack of traceability are strictly prohibited. A written internal AI policy is mandatory; the absence of such a policy is regarded as a governance gap. Furthermore, Copilot should only be activated once the authorisation framework has been finalised.
Enthusiasm for artificial intelligence has also arrived in the financial industry. «Can't we do this with AI?» is a question we hear today in almost every conversation with asset managers, whether in connection with meeting minutes, market reports or the management of client files.
The short answer: yes, a great deal is possible. But not everything is simply permitted. And FINMA is looking closely: in December 2024, it set out clear expectations with FINMA Guidance 08/2024 «Governance and risk management when using artificial intelligence», applicable to all supervised institutions, and therefore also to independent asset managers.
This article gives you a practical overview of sensible use cases, outlines the regulatory guardrails and names the most common pitfalls during implementation.
What FINMA expects from supervised institutions
FINMA Guidance 08/2024 states that there is currently no AI-specific legislation in Switzerland. However, the existing, technology-neutral requirements for governance and risk management also apply to the use of AI. FINMA expects supervised institutions that use AI to have:
-
An AI inventory with risk classification of all applications used
-
Clear responsibilities for development, implementation, monitoring and use
-
Requirements for data quality (completeness, correctness, integrity)
-
Regular testing and ongoing monitoring of AI outputs
-
Traceable documentation of the applications
-
Ensuring the explainability of decisions that must be justified to clients, supervisory authorities or the audit firm
-
An independent review of material AI applications
FINMA emphasises the principle of proportionality: requirements are based on the materiality of the applications used and the institution's risk profile. Not every AI application requires the same level of effort, but an inventory and risk categorisation are expected of all institutions.

What is possible and sensible with AI today
Microsoft Copilot for Microsoft 365 is the AI tool that makes the most sense for most asset managers, since it is directly integrated into the existing M365 environment.
Meeting minutes and summaries: Copilot can automatically summarise Teams meetings: who discussed what, which measures were agreed, which next steps were defined. This saves time and improves the quality of documentation. Important: if client conversations are recorded with AI, the client must have been informed about this; the duty to inform arises from the revised FADP.
Search across internal knowledge bases: Copilot can search SharePoint, OneNote and emails and answer questions about internally stored information. This function requires that access permissions are correctly configured; an incorrectly configured access concept can lead to unwanted information flows.
Document creation: Drafts for investment proposals, market commentaries or internal reports can be created faster with AI support. AI-generated content must be reviewed in a traceable manner and approved by responsible persons, particularly when it is used towards clients or authorities.
What AI is not permitted to do in Wealth Management
Entering client data into external AI services: This concerns primarily public AI tools such as ChatGPT or other web-based services. Entering sensitive client data, such as client names, portfolio information or other personal data, into such services can violate the FADP, professional secrecy, internal policies or contractual obligations. The data leaves the controlled corporate environment.
Autonomous decisions in regulated activities: AI can support but cannot replace regulated activities. Investment decisions, suitability assessments and advisory services within the meaning of FinSA must be the responsibility of authorised persons.
Lack of traceability: FINMA Guidance 08/2024 explicitly states that decisions must be explainable and traceable. «The AI recommended it» is not a sufficient justification.
Internal AI policy: what needs to be set out in writing
Regardless of which AI tools are used, asset managers need an internal policy that regulates at least the following:
-
Which AI tools are permitted and which are prohibited?
-
Which data may be entered into which tools?
-
Who is responsible for AI-generated content?
-
How are AI outputs reviewed and approved?
-
How are employees trained?
FINMA Guidance 08/2024 shows that FINMA looks at exactly these points during audits. The absence of an AI policy or an AI inventory is considered a governance gap.
The most common stumbling blocks in AI implementation
-
Activating Copilot without an access concept: Copilot works with existing access rights. Anyone activating Copilot before the access concept has been cleaned up risks unwanted information flows.
-
Lack of user training: Employees need a clear introduction: what can the tool do, what are its limits, what is prohibited?
-
Excessive expectations: AI accelerates and supports, it does not replace professional expertise or regulated decisions.
-
No review process: Any AI-generated content that goes outward or ends up in client files must be reviewed and approved by a human.
Download tip: ICT checklist for asset managers
Developed from practical experience with FINMA-regulated asset managers and family offices: Our checklist provides a concise summary of the key ICT requirements and helps identify gaps in governance, security, and documentation.
Implementing AI Securely, with the Right Partner
At Dinotronic, we support asset managers through the entire process: from analysing the existing environment, through configuring Microsoft Copilot and developing an internal AI policy including an AI inventory, to training employees. As a Microsoft partner with ISO 27001:2022 certification and over 30 years of experience in managed services for financial service providers, we know the regulatory requirements from practical experience.
Implementing AI tools securely means: regulatorily sound, traceably documented and with real benefit for your daily work. IT. But for sure.
Do you have questions about the secure implementation of AI in your company? We are happy to advise you.
