Regulatory Framework

Built for
DACH Regulation

Our solutions are designed to meet the requirements of FINMA, BaFin and FMA. From data protection and AI governance to supervisory outsourcing expectations.

Get in touch
Our Approach

A tool that audits compliance must itself meet the standards it applies. Our systems are designed to satisfy the requirements that all three DACH supervisory authorities place on ICT service providers, outsourcing partners, and supervisory-adjacent tools.

01

Direct Obligations

Data protection, AI regulation and disclosure duties that apply directly to BlackAI as a Swiss AI service provider.

02

Supervisory Requirements

Controls, contract clauses and evidence requirements that FINMA, BaFin and FMA expect from supervised institutions and their ICT providers.

03

Authority Collaboration

Methodological reproducibility, traceability and reporting standards for direct collaboration with supervisory authorities.

Supervisory Authorities

Three jurisdictions. One integrated approach.

CH

Switzerland

FINMA
  • FINMA Circular 2018/3 Outsourcing
  • FINMA Circular 2023/1 Operational Risks
  • FIDLEG / FinSA
  • FinIA
  • Revised FADP / DSG
  • Data Protection Ordinance
DE

Germany

BaFin
  • MaRisk
  • BAIT / DORA Transition
  • Cloud Outsourcing Circular
  • WpHG
  • MiFID II Implementation
  • BDSG / TDDDG / DDG
AT

Austria

FMA
  • WAG 2018
  • FMA IT Risk Supervision
  • FMA Circulars on Organisational Requirements
  • FMA Circulars on Marketing Information
  • Austrian DSG
  • ECG
Layer A

Direct Legal Obligations

Frameworks that apply directly to BlackAI as a Swiss AI service provider with a DACH customer perimeter.

01

DACH Data Protection

GDPR / BDSG / TDDDG / DSG / FADP
  • Controller/processor role definitions
  • Processing inventory and legal basis
  • Data protection impact assessments
  • Cross-border data transfers
  • Data subject rights and deletion concepts
02

EU AI Act

Regulation (EU) 2024/1689
  • Operator role classification
  • AI literacy for staff
  • Transparency obligations
  • Technical documentation and logs
  • Third-party model governance
03

Disclosure Duties

DDG / ECG / OR / UWG
  • Provider identification
  • No unverifiable claims
  • Clear distinction: scan vs. legal opinion
  • Transparent methodology description
  • Limitations and false-positive risk
04

Corporate Law

Swiss Company Law
  • Commercial register obligations
  • Board accountability
  • Accounting and record-keeping
  • Contractual liability and confidentiality
  • Internal AI governance
05

National Privacy Overlays

BDSG / TDDDG / DSG (AT)
  • National GDPR supplements
  • Art. 28 processor clauses
  • Transfer mechanisms
  • DPIA triggers and security measures
  • Training/prompt logging with personal data
06

Marketing Law

UWG (CH/DE/AT)
  • No misleading compliance claims
  • No unsubstantiated ISO conformity
  • Clear AI disclosure
  • Transparent service limitations
  • Competition law diligence
Layer B

Conditional Obligations

Frameworks that become binding depending on customer relationships, delivery model, or market developments. Our architecture is prepared.

DORA

Reg. (EU) 2022/2554

ICT third-party obligations, register support, incident cooperation, exit strategy, resilience testing

NIS2

Dir. (EU) 2022/2555

Supply-chain security, incident handling, NIS2-grade control maturity as procurement requirement

Cyber Resilience Act

Reg. (EU) 2024/2847

Relevant for software distribution. Architecture and packaging determine scope

Public Procurement

EU / CH Procurement Law

Subcontractor disclosure, integrity declarations, auditability, accessibility

Accessibility

EN 301 549 / WCAG

For authority portals and reports: accessibility becomes a procurement condition

eIDAS

Reg. (EU) No 910/2014

Relevant for electronic signatures, seals, or timestamps in evidence packages

Data Act

Reg. (EU) 2023/2854

Relevant for data processing services, switching obligations, or connected-product models

Cross-Border Transfers

GDPR Ch. V / FADP

Hosting, subprocessors, model providers, logging, support access, and backups

Layer C

Supervisory Customer Requirements

Regulations that primarily bind our customers. Since our solutions support their compliance, we must map them completely.

01

FINMA Ecosystem

  • Vendor due-diligence pack for Swiss regulated customers
  • Outsourcing support per FINMA Circular 2018/3
  • Audit trail and reproducibility for every finding
  • Explainable methodology and versioned rule catalogues
  • Evidence segregation and confidentiality controls
02

BaFin Ecosystem

  • MaRisk-compliant outsourcing questionnaires
  • Risk and security annexes
  • Controlled change management
  • Logging and resilience evidence
  • Report language for regulated governance
03

FMA Ecosystem

  • DORA implementation requirements
  • ICT third-party oversight
  • Austrian legal content in rule catalogue
  • Versioned and maintained AT content
  • Evidence readiness for supervised AT customers
04

Financial Conduct Rulebooks

  • MiFID II / WpHG / WAG 2018 / FIDLEG
  • Jurisdiction-specific legal taxonomy
  • Every rule mapped to legal source and version date
  • Distinction: legal requirement vs. heuristic vs. AI inference
  • Bilingual consistency checks
Layer D

Standards and Management Systems

Our technical architecture and operating processes are aligned to the following international standards.

Core Standards

ISO/IEC 42001

AI Governance

AI management system. Structure for AI policy, lifecycle controls, and evidence. Anchor standard for organisational AI governance.

ISO/IEC 27001

Information Security

Information security management. Default enterprise security credential and regulated procurement baseline.

ISO/IEC 27701

Privacy Management

Privacy extension to ISO 27001. Structured operating model for privacy and data protection.

ISO/IEC 23894

AI Risk Management

Bridge between management-system governance and practical AI risk assessment.

Additional Standards

AI-Specific

ISO/IEC 22989 — Concepts and terminology
ISO/IEC 23053 — Framework for AI systems using ML
ISO/IEC 38507 — Governance implications of AI
ISO/IEC TR 24028 — Trustworthiness in AI
ISO/IEC 5259-1/4/5 — Data quality and governance

Security / Privacy / Cloud

ISO/IEC 27017 — Cloud security controls
ISO/IEC 27018 — PII protection in public cloud
ISO/IEC 29100 — Privacy framework
ISO 31700-1 — Privacy by design
BSI C5 — Cloud security catalogue (DE)
Layer E

Technical Good-Practice Frameworks

Engineering frameworks that guide our technical implementation.

01

NIST AI RMF

AI risk decomposition, trustworthiness attributes, mapping into engineering and governance controls

02

NIST SSDF

Secure SDLC, vulnerability prevention, supplier-assurance language, procurement evidence

03

EN 301 549 / WCAG

Accessibility for authority portals and reports. Foundation of good product engineering

04

Soft-Law Frameworks

OECD AI Principles, UNESCO AI Ethics, Council of Europe AI Convention. Increasingly in procurement language

Control Architecture

Common denominator across all three authorities

Requirements that BaFin, FMA and FINMA equally place on ICT service providers and supervisory-adjacent tools. Our architecture addresses them systematically.

01

Governance

  • Named control owners
  • Documented policies
  • Escalation paths
  • Controlled rule catalogue changes
  • AI governance and human oversight
02

Security and Resilience

  • Access control and IAM
  • Logging and monitoring
  • Vulnerability management
  • Incident response
  • Backup, recovery and BC/DR
03

Outsourcing and Supplier Governance

  • Subcontractor inventory
  • Model provider inventory
  • Contractual flow-down controls
  • Right-to-audit support
  • Exit support and concentration risk
04

Evidence and Auditability

  • Reproducible scans
  • Timestamped evidence
  • Versioned rule catalogues
  • Source traceability
  • Model/version traceability
05

Legal Defensibility

  • Every finding tied to a rule source
  • Every heuristic marked as heuristic
  • Every AI inference marked as inference
  • No hidden automation
  • Clear human-oversight boundaries
06

Authority-Grade Quality

  • Explainable methodology
  • False-positive discipline
  • False-negative discipline
  • Multilingual consistency
  • Evidence chain preserved
Implementation Priorities

Our regulatory architecture

01

Legal Spine

  • FADP / DSG
  • GDPR / BDSG
  • EU AI Act
  • DACH disclosure duties
02

Customer Spine

  • FINMA supervisory framework
  • BaFin supervisory framework
  • FMA supervisory framework
  • DORA-ready supplier posture
03

Assurance Spine

  • ISO/IEC 42001
  • ISO/IEC 27001
  • ISO/IEC 27701
  • ISO/IEC 23894
04

Engineering Spine

  • NIST AI RMF
  • NIST SSDF
  • EN 301 549 / WCAG
  • Reproducibility and evidence

Questions about our regulatory framework?

We are happy to discuss how our solutions address the regulatory requirements of your jurisdiction. Confidential and without obligation.

Get in touch