Our solutions are designed to meet the requirements of FINMA, BaFin and FMA. From data protection and AI governance to supervisory outsourcing expectations.
Get in touchA tool that audits compliance must itself meet the standards it applies. Our systems are designed to satisfy the requirements that all three DACH supervisory authorities place on ICT service providers, outsourcing partners, and supervisory-adjacent tools.
Data protection, AI regulation and disclosure duties that apply directly to BlackAI as a Swiss AI service provider.
Controls, contract clauses and evidence requirements that FINMA, BaFin and FMA expect from supervised institutions and their ICT providers.
Methodological reproducibility, traceability and reporting standards for direct collaboration with supervisory authorities.
Frameworks that apply directly to BlackAI as a Swiss AI service provider with a DACH customer perimeter.
Frameworks that become binding depending on customer relationships, delivery model, or market developments. Our architecture is prepared.
ICT third-party obligations, register support, incident cooperation, exit strategy, resilience testing
Supply-chain security, incident handling, NIS2-grade control maturity as procurement requirement
Relevant for software distribution. Architecture and packaging determine scope
Subcontractor disclosure, integrity declarations, auditability, accessibility
For authority portals and reports: accessibility becomes a procurement condition
Relevant for electronic signatures, seals, or timestamps in evidence packages
Relevant for data processing services, switching obligations, or connected-product models
Hosting, subprocessors, model providers, logging, support access, and backups
Regulations that primarily bind our customers. Since our solutions support their compliance, we must map them completely.
Our technical architecture and operating processes are aligned to the following international standards.
AI management system. Structure for AI policy, lifecycle controls, and evidence. Anchor standard for organisational AI governance.
Information security management. Default enterprise security credential and regulated procurement baseline.
Privacy extension to ISO 27001. Structured operating model for privacy and data protection.
Bridge between management-system governance and practical AI risk assessment.
Engineering frameworks that guide our technical implementation.
AI risk decomposition, trustworthiness attributes, mapping into engineering and governance controls
Secure SDLC, vulnerability prevention, supplier-assurance language, procurement evidence
Accessibility for authority portals and reports. Foundation of good product engineering
OECD AI Principles, UNESCO AI Ethics, Council of Europe AI Convention. Increasingly in procurement language
Requirements that BaFin, FMA and FINMA equally place on ICT service providers and supervisory-adjacent tools. Our architecture addresses them systematically.
We are happy to discuss how our solutions address the regulatory requirements of your jurisdiction. Confidential and without obligation.
Get in touch