Share on LinkedInShare on LinkedIn

ARTICLE · 06 OCTOBER 2026

Switzerland's New AML Regime Is Live: Five Issues For FinTechs And Financial Platforms

On 1 October 2026, the revised Anti-Money Laundering Act and the new Transparency Act enter into force. For banks, the new federal register of beneficial owners is mainly an additional data source.

SwitzerlandTechnology

On 1 October 2026, the revised Anti-Money Laundering Act and the new Transparency Act enter into force. For banks, the new federal register of beneficial owners is mainly an additional data source. For FinTechs and digital financial platforms, it is something more demanding: a new interface in the KYC architecture, a new discrepancy-reporting duty that requires legal judgement at scale, and a fresh test of who is responsible for what in bank–FinTech partnerships.

Introduction

On 1 October 2026, the revised Anti-Money Laundering Act (AMLA) and the new Federal Act on the Transparency of Legal Entities and the Identification of Beneficial Owners (LETA) enter into force. Parliament adopted both acts on 26 September 2025; the Federal Council set the date of entry into force on 12 June 2026, together with the implementing ordinance. The reform establishes a central, non-public federal register of beneficial owners (the transparency register) and extends the AMLA to certain high-risk advisory activities, notably in connection with real estate transactions and the formation, structuring and management of companies. The timing is no coincidence: the new framework is intended to be in operation when the Financial Action Task Force (FATF) evaluates Switzerland in 2027–2028.

Much of the commentary so far has focused on the new reporting obligations of companies. For FinTechs and financial platforms subject to the AMLA, the more interesting questions lie elsewhere. The register changes the data landscape of customer due diligence, introduces a discrepancy-reporting mechanism for financial intermediaries, and raises practical questions about automation, data governance and the allocation of compliance responsibilities.

My central thesis is simple: the new regime will not be implemented in the compliance manual, but in the system architecture. This article considers five issues that FinTechs should have on their radar.

Key dates at a glance

1 October 2026: Revised AMLA and LETA enter into force; transition periods for existing legal entities begin to run.

31 December 2026 – 31 March 2027: Staggered deadlines for the initial registration of existing entities (starting with companies limited by shares subject to an ordinary audit and ending with all remaining and in-scope foreign entities).

One month: Deadline for newly incorporated entities and for reporting changes to beneficial ownership. Any commercial register filing made during the transition phase triggers the one-month deadline early.

1 April 2027: Discrepancy reporting by financial intermediaries becomes operational after the initial registration phase.

2027–2028: FATF mutual evaluation of Switzerland.

  1. A New Source of Beneficial Ownership Information – But Not a Safe Harbour

The transparency register contains information on the natural persons who ultimately control legal entities subject to LETA. It is maintained by the Federal Office of Justice; a control unit within the Federal Department of Finance checks whether the information is accurate, complete and up to date.

The scope is broad. It covers, among others, companies limited by shares (AG), limited liability companies (GmbH), cooperatives, SICAVs, SICAFs and limited partnerships for collective investment. Foreign legal entities with a sufficient connection to Switzerland are also caught, including entities with a registered Swiss branch, effective administration in Switzerland or Swiss real estate. Listed companies and qualifying subsidiaries are exempt. As a rule, a beneficial owner is a natural person who directly or indirectly holds at least 25% of the capital or voting rights, alone or in concert with third parties, or who otherwise controls the entity, including by contractual means.

The register is not public. Financial intermediaries subject to the AMLA may access it to the extent necessary to fulfil their due diligence obligations. Searches are entity-based: a financial intermediary can look up a legal entity, but cannot search the register by natural person. Every query is logged.

The most important point for practice, however, is what the register is not. During the parliamentary debate, a presumption that financial intermediaries may rely on the accuracy of the register was expressly not adopted. The register therefore has no reliance effect comparable to the commercial register. The financial intermediary remains fully responsible for identifying and verifying the beneficial owner under the AMLA; the register is an additional source of information and a control instrument, not a substitute for KYC.

For FinTechs, the question is therefore not whether to rely on the register, but how to integrate it into an existing due diligence process without creating a false sense of security.

  1. Digital KYC Meets the Transparency Register

For a traditional bank, consulting an additional register is primarily a process question. For a digital financial business, it is a technology question. FinTech models depend on fast, highly automated onboarding: customer data is captured electronically, identity is verified digitally and risk indicators trigger automated workflows.

The register has been designed with this environment in mind. Access is available through the federal EasyGov platform or via a dedicated API. According to the Federal Office of Justice, the API is aimed at medium-sized and large organisations with a high volume of queries, including financial intermediaries, and allows queries to be made directly from their own systems without a media break.

This opens an obvious opportunity: beneficial ownership information can be built directly into digital KYC workflows. It also raises implementation questions that should be answered before the first API call is made:

  • Trigger points: Is the register queried at onboarding only, at periodic reviews, or on event-driven triggers such as a change of signatories or unusual transaction patterns?
  • Comparison logic: Which data fields are compared, and how are name variants, transliterations and multi-layered ownership chains handled?
  • Storage and evidence: How are register extracts stored so that the firm can later demonstrate what it knew and when?
  • Data protection and security: Beneficial ownership data are personal data of a sensitive nature. Access rights, purpose limitation and retention must be defined; queries are logged by the authorities and access may be reviewed.

A fully automated comparison may work for simple corporate structures. Complex ownership and control arrangements will regularly require manual review. Access to more data does not automatically lead to better compliance; the value of the register depends entirely on how well it is embedded in the firm's KYC architecture.

  1. Discrepancies Matter – But Not Every Difference Is a Discrepancy

The most significant operational innovation for financial intermediaries is discrepancy reporting. Where a financial intermediary identifies a difference between the register and the information available to it, it must report that difference if it raises doubts about the accuracy, completeness or currency of the beneficial ownership information and remains unresolved after the customer has been informed and given an appropriate period to remedy it. The report must then be made within 30 days. Following the initial registration phase, the mechanism becomes operational from 1 April 2027 – which gives FinTechs a short but valuable window to build the process properly.

The decisive point is that a relevant discrepancy is a legal judgement, not a data mismatch. Three sources of false positives are foreseeable:

  • Different legal concepts of control. The beneficial owner under the AMLA and the beneficial owner under LETA are not always the same person. Rules for operating and domiciliary companies, fallback rules where no controlling person can be identified, and the treatment of intermediate entities in ownership chains may lead to different, yet correct, results. The banking industry raised precisely this concern in the consultation on the implementing ordinance.
  • Insignificant differences. Spelling variants, formatting differences or minor deviations that do not call into question the identity of the beneficial owner are not meant to trigger reports; the implementing ordinance provides for exceptions.
  • Outdated own data. A financial intermediary may not simply assume that its own file is correct and the register is wrong. Where necessary, it must first update its own customer information.

The resulting workflow is multi-stage:

comparison → identification of a relevant difference → clarification with the customer → remediation where possible → discrepancy report where required

This process cannot end with an automated red flag, nor should it end with an automated report. A sensible design separates detection from decision: the system identifies and routes potential discrepancies; a qualified compliance officer assesses materiality, evaluates the customer's response and decides whether to report. Firms need written rules on what constitutes a relevant difference, when the customer is contacted, how long the remedy period is, who decides, and how the 30-day deadline is monitored. Firms operating at scale should also expect that too many defensive reports are no better than too few: both indicate that the underlying process has not been properly calibrated.

  1. Bank–FinTech Partnerships: Who Does What?

The new framework is particularly relevant to business models in which the customer-facing FinTech is not the regulated entity providing the underlying financial service. A typical Banking-as-a-Service structure looks like this:

Bank → FinTech platform → customer

The FinTech controls the user interface and the onboarding journey; the bank holds the account, the assets or the licence. External KYC providers, cloud providers and other technology vendors add further layers. In such structures, the question is not whether AML obligations exist, but who performs each step:

  • Who collects and verifies beneficial ownership information?
  • Who queries the register, and under whose access credentials?
  • Who identifies discrepancies and assesses their relevance?
  • Who contacts the customer, and who evaluates the response?
  • Who ultimately decides on and files the discrepancy report?

Operational performance and legal responsibility must not be confused. A regulated institution may delegate tasks to a partner or technology provider, but it cannot delegate its regulatory responsibility; the requirements for outsourcing and for the delegation of due diligence tasks continue to apply. Where the FinTech is itself a financial intermediary, the allocation becomes even more delicate, because both parties may have their own obligations towards the same customer.

The introduction of the register is therefore a good reason to review cooperation agreements and operating procedures. They should address, in particular, access to customer and register data, responsibility for KYC updates, escalation and decision rights, deadlines, audit and information rights of the bank, instruction rights, and the documentation of each step. Otherwise, a process that appears seamless to the customer may conceal significant uncertainty about responsibility behind the interface.

  1. Supervision, Sanctions and Technology Governance

The discrepancy-reporting duty forms part of the financial intermediary's AML obligations. Its implementation will therefore be reviewed by the competent supervisors – FINMA, the supervisory organisations and the self-regulatory organisations – and by the regulatory audit firms. A missing, late or poorly documented process is primarily a supervisory issue, with the full range of consequences, from audit findings to enforcement proceedings or SRO sanctions. For FINMA-supervised institutions, the question of whether the process was properly designed and consistently applied may ultimately become relevant to the guarantee of irreproachable business conduct.

On the side of the reporting entities, LETA provides for a graduated enforcement system. The control unit may order corrections, a note may be entered in the register where the information is in doubt, and, in serious cases, membership and economic rights may be suspended. Intentional violations of the reporting or information duties are punishable by fines of up to CHF 500,000; failure to comply with an order of the control unit, by fines of up to CHF 100,000. For financial intermediaries, a note in the register relating to a customer is a risk indicator that should be reflected in the customer's risk profile.

The broader lesson is that AML compliance has become a question of technology governance. Reporting is digital, access runs through an API, and legal concepts such as control, beneficial ownership and a relevant discrepancy have to be translated into operational rules. Not all of these concepts lend themselves to a binary test. Implementation therefore requires four functions to work together:

  • Legal and compliance define what must be collected and when a difference requires investigation.
  • Product and engineering build register queries, comparison logic and escalation paths into onboarding and monitoring systems.
  • Data protection and information security govern access, storage, retention and logging.
  • Management ensures that responsibility for decisions and escalations is clearly allocated – and documented.

Automation increases speed and scalability. But it only works if the legal rules have been properly translated into the system, and if the system knows when to hand a decision back to a human.

Five Questions FinTechs Should Ask Now

  1. Do our KYC processes capture the beneficial ownership information required under the AMLA, and where does the transparency register fit into those processes?
  2. Should register access be integrated through the API, and at which points in onboarding and ongoing monitoring should a query be triggered?
  3. Do we have a defined, documented method for distinguishing a relevant discrepancy from an immaterial difference, a divergent legal concept of control or outdated information in our own records – with a clear escalation path to a human decision-maker?
  4. Where a bank, a FinTech and external KYC or technology providers are involved, is responsibility for each step clearly allocated in the contracts and in practice?
  5. Can our systems evidence the entire process – from the register query through customer clarification to any discrepancy report – in a form that will satisfy our auditor and supervisor?

A process that works when individual cases are reviewed manually may become difficult to operate once thousands of customers and automated workflows are involved. The window until April 2027 should be used accordingly.

Outlook

The revised AMLA and LETA take effect on 1 October 2026. For financial intermediaries and FinTechs, the transparency register is not merely a new corporate filing obligation. It creates a new source of beneficial ownership information, a new interface with existing KYC processes and a new mechanism for dealing with discrepancies between different data sets.

One point is easily overlooked: FinTechs organised as a Swiss AG or GmbH are themselves reporting entities under LETA. Before building register queries into their customer journeys, they should make sure that their own beneficial owners – often spread across several financing rounds, pooling arrangements and shareholders' agreements – are correctly identified and reported within the applicable deadline.

For technology-driven financial businesses, the conclusion is clear: AML compliance must be designed into the technology and operational architecture from the outset, rather than added afterwards. Firms that treat the new regime as an architecture question now will be better prepared – both for their auditors and for the FATF's scrutiny in 2027–2028.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See more popular content from