Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Skip to main content

FINMA ISAE 3000 Type 2 Report

Overview

Amazon Web Services (AWS) has completed the FINMA ISAE 3000 Type 2 Report. The International Standard on Assurance Engagements (ISAE) 3000 is a standard which is applied for audits of internal controls, sustainability, and compliance with laws and regulations, and completion of the ISAE 3000 Type 2 Report verifies that AWS’s control environment is appropriately designed and implemented to align with certain Swiss Financial Market Supervisory Authority (FINMA) requirements applicable to regulated financial services customers. AWS’s alignment with FINMA requirements demonstrates our continuous commitment to meeting the heightened expectations for cloud service providers set by Swiss financial services regulators and customers.

The FINMA ISAE 3000 Type 2 Report, conducted by an independent third party audit firm, provides Swiss financial industry customers with the assurance that AWS’s control environment is appropriately designed and implemented to address key operational risks and risks related to outsourcing and business continuity management. Additionally, the report provides customers with important guidance on complementary user entity controls (CUECs), which they should consider implementing as part of AWS’s Shared Responsibility Model to help them comply with FINMA’s control objectives. The report covers the three core FINMA circulars that are applicable to Swiss financial services institutions in the context of outsourcing arrangements to the cloud. These FINMA circulars are intended to assist regulated financial institutions in understanding approaches to due diligence, third party management, and key technical and organizational controls that should be implemented in cloud outsourcing arrangements, particularly for material workloads. The scope covers the requirements of the following FINMA circulars:

  • 2023/01 “Operational risks and resilience – banks (07.12.2022)
  • 2018/03 FINMA Circular “Outsourcing – banks and insurers” (31.10.2019)
  • Business Continuity Management (BCM) minimum standards proposed by the Swiss Insurance Association (01.06.2015)
Missing alt text value

Page topics