Switzerland · Financial institutions

Quantum securityand AI governancefor financial institutions

Two deadlines are running: by mid-2027 FINMA expects supervised institutions to have a PQC roadmap approved by executive management. For AI applications it expects an inventory, a risk classification and, for material applications, an independent review separate from development. I record the current state, deliver the basis for your decision and implement the first components, on your infrastructure, with data handling under Swiss law.

Fields

  • 01

    Artificial intelligence

    Models · Data · Governance

  • 02

    Blockchain & identity

    Contracts · Proofs · Integration

  • 03

    Quantum security

    PQC · Keys · Migration

Next step: taking stock

ML-KEM/Kyber/ML-DSA/Dilithium/Retrieval-Augmented Generation/Fine-Tuning/Solidity/Zero-Knowledge/Verifiable Credentials/Hardware Security Module/Multi-Party Computation/NIST PQC/ISO/IEC 27001/Open Source/

Context

Why now

The supervisor has set the timeframe. Anyone who waits loses the freedom to choose the order and the budget.

  1. 01

    FINMA counted in July 2026. In supervisory notice 05/2026 it states: of 60 banks, insurers, asset managers and financial market infrastructures surveyed, 72 percent had neither planned nor implemented measures for quantum security, and only 8 percent had a concrete roadmap. FINMA recommends a roadmap approved by executive management by mid-2027 at the latest. Institutions already planning expect four to five years until critical systems are quantum-safe.

  2. 02

    Retention beats quantum timing. In Switzerland, business records and vouchers must be kept for ten years, and AML documentation likewise. Data stored encrypted today therefore has to stay secret longer than an attacker has to wait for a quantum computer. FINMA names this risk explicitly: harvest now, decrypt later.

  3. 03

    On AI, the supervisor does not ask about the model but about governance. FINMA Guidance 08/2024 expects an inventory of AI applications, a consistent risk classification, testing and ongoing monitoring, documentation, explainability and, for material applications, an independent review separate from development. About half of the institutions surveyed by FINMA already use AI, on average five applications in operation and nine in development.

Services

Two deadlines, one approach: assess first, then build.

01

AI governance that stands up to a review

FINMA Guidance 08/2024 expects an inventory of all AI applications, a consistent risk classification, testing and ongoing monitoring, documentation and explainability. Material applications additionally require an independent review, separate from development. That is where I start: taking stock, assessing, and for the applications with obligations a review procedure an audit firm can follow.

  • AI inventory and risk classification
  • Model and data quality, stability, bias
  • Explainability towards clients and the supervisor
  • Independent review separate from development
  • Assistants and automation on your own data
More on AI governance

What you are left with

  • 01An inventory that stands up to a review
  • 02A review report with findings and measures, not just an opinion
  • 03Clear rules on who sees which data and who signs off results

02

Quantum security: roadmap by mid-2027

In supervisory notice 05/2026 FINMA expects a strategy approved by executive management with milestones and target dates, a cryptographic inventory across all systems (in-house, outsourced and purchased), a risk analysis focused on data requiring long-term protection, and cryptographic agility as a requirement for new systems and procurement. I deliver the findings, the roadmap and the first implemented components.

  • Cryptographic inventory across all ICT systems, including outsourced ones
  • Risk analysis including harvest now, decrypt later
  • Roadmap with milestones for executive management
  • Hybrid operation and migration to ML-KEM (FIPS 203) and ML-DSA (FIPS 204)
  • Falcon-1024 (FN-DSA, NIST draft for FIPS 206), native on Algorand
  • Cryptographic agility as a requirement for procurement and contracts
More on post-quantum migration

What you are left with

  • 01A roadmap with target dates that executive management can approve
  • 02An inventory that stays current instead of a snapshot
  • 03Evidence for your audit firm on what is already quantum-safe

03

Digital assets and distributed ledgers

Distributed ledgers belong in the cryptographic inventory; FINMA explicitly counts new technologies such as distributed ledger technology. Where claims, registers or payments run over a chain, you need key management, an audit trail and human sign-off instead of automatic execution. And an honest answer to the question of whether a database would have done the same job.

  • Clarifying whether a distributed ledger solves the problem
  • Contracts for claims, registers and payment flows
  • Key management and approval processes
  • Review of attack surface before go-live
  • Integration with existing systems

What you are left with

  • 01A concept that cleanly separates business logic, rights and liability
  • 02Contracts and proofs that can be reviewed before go-live
  • 03An integration that does not replace your accounting or ERP

Approach

Four stages, no surprises.

Each stage ends with a result you can see and pass on. The scope is agreed before the first line of code.

  1. 01

    Listening & review

    A conversation with the people who will work with it later, plus a look at existing systems, data and contracts.

  2. 02

    Assessment & roadmap

    An honest view: what is worth doing, what is not, what is risky. Written as a basis for management decisions.

  3. 03

    Delivery in stages

    Short stages, each ending with something that runs. Open standards, documented code, ownership stays with you.

  4. 04

    Operation & handover

    Operating instructions, training for your team and one clear contact for the first months, or full handover.

About me

In finance since 1999, 27 years. Structuring, regulation and technology, most recently almost exclusively the question of how to bring both sides together.

For my own companies, a quantum-safe financial platform, a tokenisation platform, an insurance platform and a payment platform are being built: concept, requirements and the basis for decisions, with implementation by the development team of Fidentus Core in Sofia.

What I advise on, I build myself. A cryptographic inventory for an institution is the same work I did for my own platform, only with your supervisor, your deadlines and your systems. I know both sides: the requirement in the supervisory document and the effort it takes to deliver.

The consulting work runs through an independent Swiss sole proprietorship. It is not part of the Fidentus Group; the group operates through its own companies that are legally independent per country and partly supervised.

  • 01

    In finance since 1999

  • 02

    27 years of structuring, regulation and technology

  • 03

    Own platforms: quantum security, tokenisation, insurance, payments

Audience

Who this is for

The work is aimed at institutions and at the firms that supply them.

  1. 01

    Institutions

    Private banks, regional and cantonal banks, foreign banks domiciled in Switzerland. Asset managers and family offices with FINMA authorisation. Insurers and reinsurers. Fund management companies and managers of collective investment schemes. Payment service providers and financial market infrastructures.

  2. 02

    Suppliers and audit firms

    Software houses, core banking providers and IT service providers supplying institutions. FINMA requires institutions to assess the PQC maturity of their service providers and to anchor contractual clauses and exit strategies. A supplier unable to answer these questions becomes a risk in the supplier assessment. 60 percent of the institutions surveyed are already in contact with their software suppliers for this reason. Added to this are audit and review firms checking compliance with supervisory expectations.

  3. 03

    Set-up

    Assessment, review and project management are delivered by me from Thalwil. For implementation, the development team of Fidentus Core in Sofia, the technology company of the Fidentus Group, is available. The contractual relationship and your contact person remain in Switzerland. Where data is processed is agreed in writing before a project starts and, on request, limited to infrastructure in Switzerland or the EEA.

    Robert Zovko is an independent sole proprietorship and not part of the Fidentus Group. The Fidentus Group operates through separate companies that are legally independent per country and partly supervised. Technology company: fidentus.tech

Principles

What you can count on.

No framework agreement, no consulting team explaining itself: you talk to the person who also builds.

  • I

    Swiss data handling

    Storage, contracts and instruction rights under Swiss law. Where your data sits is stated in the concept, not in the small print.

  • II

    Open standards instead of lock-in

    I work with tools you can move away from: open formats, documented interfaces and source code that stays with you.

  • III

    Plain language for the board

    Technology that can be explained to a committee. Every recommendation comes with its benefit, its risk and its cost.

  • IV

    What I do not do

    No public bodies and no public tender procedures. No trading in cryptocurrencies, no token issuance, no asset management. Payment and insurance services are not offered; the platforms of my own companies are not part of the consulting offering. No legal, tax or investment advice. That calls for the relevant professional.

Insights

Insights

A short summary of what institutions need to know about quantum security and AI governance, with the deadlines and the sources.

Post-quantum migration under FINMA 05/2026

What belongs in a PQC roadmap: a cryptographic inventory across all systems, risk analysis, cryptographic agility and supplier assessment. With the deadlines from the supervisory notice.

To post-quantum migration

AI governance under FINMA 08/2024

AI inventory, risk classification, testing and the independent review separate from development: what the supervisor expects of AI applications.

To AI governance

Maturity check in five minutes

Twelve questions on quantum security and AI governance based on FINMA's expectations. Result immediately, with no data stored.

To the maturity check

Answers

Frequently asked questions

Yes. The starting point is deliberately small: first the cryptographic inventory, then the order of work, then delivery in stages. Each stage ends with something you can put into operation or present to your audit firm. You do not need a dedicated project team for it.

Contact

Listening comes first.

In a first conversation we clarify your situation, your goal and the risks. You get an honest assessment and find out whether I am the right fit.

What is it about

Your details are used solely to answer your request.