What is a Compliance Management System – and why is it relevant for companies in Switzerland?

Swiss companies must meet a wide range of legal, regulatory, contractual, and internal requirements. At the same time, customers, business partners, employees, and supervisory authorities expect responsible corporate governance and transparent decision-making. But how do companies ensure that these requirements are not only known but also systematically implemented in day-to-day business? A Compliance Management System (CMS) creates the structured framework to systematically implement requirements and manage compliance in a verifiable manner.

What is a Compliance Management System?

A CMS is a company's organizational framework for systematically identifying legal, regulatory, and contractual requirements as well as internal guidelines, ensuring their implementation, and identifying, assessing, and appropriately managing the risks of potential non-compliance at an early stage. An effective CMS does not aim to completely exclude every rule violation. Rather, it creates the conditions for systematically implementing requirements, identifying deviations early, and appropriately managing the associated risks.

Compliance thus becomes an integral part of corporate management – not as an isolated control function, but as a tool for managing risks and supporting well-founded decisions.

How does a Compliance Management System work?

An effective CMS follows a continuous process – from the identification of relevant requirements to ongoing monitoring and further development. The following illustration provides an overview of the essential process steps.

{%ALT_TEXT%}
Compliance Management System, graphic by Velaw in Zurich. Your specialist for compliance, risk, and legal in Zurich

1. Identify relevant requirements

The process begins with the systematic recording of all requirements relevant to the company.

This includes, in particular, legal and regulatory requirements, contractual obligations, and internal policies and directives. Depending on the industry and business model, different requirements may be relevant.

These requirements must not only be recorded once but must be reviewed regularly and updated in the event of changes.

 

2. Assign requirements to processes and responsibilities

A requirement can only be effectively implemented if it is clear which business processes are affected and who within the company bears responsibility for it.

The CMS creates a verifiable link between requirements, business processes, and responsibilities. This makes it transparent who is responsible for implementing individual requirements and how compliance is ensured.

 

3. Assess non-compliance risks

Not every requirement is of equal importance to a company. The impact of non-compliance can vary significantly.

Companies therefore assess the legal, financial, operational, or reputational consequences that may be associated with non-compliance.

Risk assessment creates transparency and helps companies deploy their resources in a risk-oriented manner and set priorities.

 

4. Define appropriate controls

Suitable controls are established based on the identified requirements and risks.

Controls should support compliance with requirements, make deviations recognizable at an early stage, and contribute to managing risks appropriately. Depending on the circumstances, preventive, detective, or corrective controls may be useful.

5. Perform controls

The defined controls must actually be carried out in day-to-day operations.

It is crucial that the responsible persons know what is to be checked, in what form the control takes place, and how to handle identified deviations.

6. Capture and document evidence

The execution and results of the controls must be documented in a verifiable manner.

Evidence documents whether and how a control was performed. It forms the proof for internal reviews, management reporting, and audits by internal or external audit bodies, supervisory authorities, and other stakeholders.

Verifiable documentation increases transparency and makes it possible to assess the effectiveness of the CMS.

7. Monitor effectiveness and report

A CMS does not end with the execution of individual controls.

The results must be evaluated, recurring deviations identified, and relevant developments presented transparently. This provides the Executive Board and Board of Directors with a sound basis for identifying the need for action and making appropriate decisions.

Where key performance indicators (KPIs) offer real added value, they can help to assess developments and deviations more objectively. However, many controls remain qualitative in nature. The key is to use KPIs where they provide meaningful support for management.

8. Continuously improve the system

Legal and regulatory requirements change. Business models, processes, and risks evolve. Findings from controls, internal reviews, incidents, or audits may also necessitate adjustments.

An effective CMS is therefore regularly reviewed and continuously developed.

A Compliance Management System is thus not a static set of rules, but an ongoing management and improvement process.

For which companies is a Compliance Management System relevant?

Compliance management is no longer only relevant for banks or insurance companies.

Industrial companies, healthcare organizations, energy suppliers, technology companies, service providers, and many other organizations face the challenge of complying with a wide variety of requirements and leading their organization responsibly.

The scope and design of a Compliance Management System differ depending on the industry, company size, business model, and risk profile. However, the basic principles remain the same.

A CMS should always be designed proportionately. A small or less complex company does not need the same structures as an international corporation or a highly regulated financial institution. The decisive factor is that the system fits the organization and its actual risks.

Compliance Management System for financial intermediaries

For financial intermediaries, an effective Compliance Management System is not just good practice, but a regulatory necessity.

Supervisory requirements – particularly from financial market supervision (FINMA), the Financial Institutions Act (FINIG), the Financial Services Act (FIDLEG), and the Anti-Money Laundering Act (AMLA) – require robust processes, clearly regulated responsibilities, and verifiable controls.

A CMS tailored to the specific licensing situation and risk profile helps financial intermediaries fulfill these requirements efficiently and in an audit-ready manner – from due diligence and reporting to providing proof to the supervisory authority.

What characterizes an effective Compliance Management System?

An effective Compliance Management System is characterized by verifiable processes, clearly regulated responsibilities, effective controls, and verifiably documented evidence. It takes the company's risks into account and creates transparency as to whether requirements are effectively implemented and complied with.

Conversely, a CMS is ineffective if it is essentially limited to guidelines, checklists, and the formal documentation of controls. The decisive factor is not just that requirements and controls exist, but that they are understood, applied, monitored, and further developed as needed in day-to-day business.

ISO 37301 – The international standard for Compliance Management Systems

These basic principles are also reflected in the international standard ISO 37301. It offers companies a recognized framework for the establishment, implementation, and continuous development of a Compliance Management System and is increasingly used as a reference by Swiss companies.

ISO 37301 replaced the former ISO 19600 in 2021 and defines the requirements for the structure, operation, and ongoing improvement of a Compliance Management System. It is certifiable and applicable across all industries.

However, the decisive factor is not the application of a specific standard, but that compliance is actually lived and continuously improved within the company.

Conclusion

A Compliance Management System is much more than an organizational duty.

It creates the conditions for systematically implementing regulatory and internal requirements, effectively managing risks, and verifiably proving compliance.

Correctly implemented, a CMS strengthens not only compliance but also governance, transparency, decision-making quality, and trust. It supports the Executive Board and Board of Directors in identifying risks early and making well-founded decisions.

For Swiss companies – and particularly for financial intermediaries – an effective Compliance Management System is thus a central component of responsible, transparent, and sustainable corporate governance.

Frequently Asked Questions about Compliance Management Systems (FAQ)

A Compliance Management System (CMS) is an organisation’s framework for systematically identifying statutory, regulatory and contractual requirements as well as internal policies, ensuring their implementation, and identifying, assessing and appropriately managing the risks of potential non-compliance at an early stage.

An effective CMS establishes clear responsibilities, supports the implementation of requirements in day-to-day operations, and enables the effectiveness of the measures taken to be monitored transparently and continuously improved.

A Compliance Management System (CMS) and an Internal Control System (ICS) pursue different, yet complementary objectives.

The CMS ensures that statutory, regulatory, contractual and internal requirements are systematically identified, implemented and monitored. It provides the organisational framework for effective compliance governance.

The ICS, by contrast, focuses on specific controls within business processes. It serves to reduce risks, prevent errors and ensure that defined processes function properly.

The Internal Control System is regularly a component of an effective Compliance Management System. While the CMS provides the organisational framework for managing compliance, the ICS comprises the specific controls within business processes. Both systems complement each other and together contribute to effective corporate governance.

ISO 37301 is the internationally recognised standard for Compliance Management Systems. It defines the requirements for establishing, operating and continuously improving a CMS, replaced the former ISO 19600 in 2021, and is certifiable.

It provides organisations with an established reference framework for embedding compliance systematically, risk-based and sustainably within their organisation.

Yes. Financial intermediaries are subject to specific supervisory requirements, in particular under financial market supervisory law, the Financial Institutions Act (FINIA), the Financial Services Act (FinSA) and the Anti-Money Laundering Act (AMLA).

A Compliance Management System tailored to the relevant licensing status and risk profile helps to implement these requirements efficiently, transparently and in an audit-ready manner, and to demonstrate compliance to supervisory authorities and audit firms.

Whether a Compliance Management System is built in-house or partially or fully outsourced depends on the organisation’s size, complexity and regulatory requirements.

While larger organisations often have their own compliance functions, many small and medium-sized enterprises as well as financial intermediaries opt to outsource or co-source individual compliance tasks. This gives them access to specialised expertise, established processes and modern digital solutions without having to build all resources internally.

velaw supports organisations in establishing, operating and continuously developing their Compliance Management System – from concept through to full compliance outsourcing:

Autor

Dirk Spiegel, Velaw Zurich

Dr. Iur. Dirk Spiegel, LL.M.

CEO, Founding Partner

Bio

Dirk is the founder of Velaw AG and has more than 20 years of experience in asset management, investment funds, and private market investments. He advises international and national asset managers, banks, funds, institutional investors, and other financial intermediaries on key legal, strategic, and transaction-related issues.

He specializes in the creation and structuring of investment products, the implementation of approval procedures and advice on sales and marketing activities in Switzerland and abroad.

He has extensive experience in corporate governance, compliance and risk management as well as in the development and implementation of internal regulations, anti-money laundering concepts and control mechanisms. Previously, he was Group General Counsel and Group Chief Compliance Officer of a global asset management company listed in Switzerland and gained professional experience in Europe, the USA and Asia.

More news

Without any obligation

We are here for you

Without any obligation

We are here for you

Experience VELA 2.0 Live

When quality, efficiency, and price align

Experience how vela 2.0 provides you with an effective Internal Control System that eases your daily workload and ensures audit compliance at all times.

We'll show you how – in just 30 minutes.

Thursday, June 25, 2026 | 4:00–4:30 PM
Free via Microsoft Teams

DAYS
HRS
MIN
SEC
The course has started!