Swiss independent asset managers (IAMs) licensed under FinIA are subject to AMLA due diligence obligations supervised by a FINMA-authorised supervisory organisation (SO) and, where applicable, a self-regulatory organisation (SRO) such as VQF. A compliant KYC workflow for a Swiss corporate client covers six stages: pre-onboarding risk assessment, entity verification via the Handelsregister, beneficial ownership identification (Form A/K), sanctions and PEP screening, risk classification and file assembly, and ongoing monitoring via SHAB. Each stage must be documented and retained for ten years under AMLA Article 7.
Who this guide is for
This guide is written for IAMs licensed by FINMA under FinIA and supervised by a FINMA-authorised SO — typically AOOS, OAR, or similar — with AMLA obligations monitored by an SRO, most commonly VQF.
It covers the KYC workflow for Swiss corporate clients — the scenario where the Handelsregister, Zefix, and SHAB are directly relevant. The underlying obligations apply equally to non-Swiss corporate clients and natural person clients, but the specific verification tools differ.
The regulatory framework
Since 1 January 2020, Swiss IAMs operate under a dual regulatory framework.
FinIA governs the IAM's licence, prudential supervision, organisational requirements, and conduct obligations. FINMA grants the licence; a FINMA-authorised SO carries out ongoing prudential supervision.
AMLA governs the IAM's due diligence obligations toward clients — identity verification, beneficial ownership identification, ongoing monitoring, and suspicious activity reporting. For most IAMs, AMLA supervision is carried out by the SO in conjunction with SRO membership, or through a standalone SRO such as VQF.
These two supervisory streams run in parallel. The same client file must satisfy both.
Stage 1 — Pre-onboarding risk assessment
Before committing resources to a full KYC review, a compliant IAM performs a preliminary assessment of whether the prospective client relationship is one the firm can and should accept.
What this stage covers:
- Business purpose check: Is the proposed mandate within the IAM's licensed scope and investment policy?
- Preliminary sanctions check: Does the entity name or any named director appear on Swiss (SECO), EU, UN, or US (OFAC) sanctions lists? A positive match at this stage is a hard stop — no further onboarding until resolved.
- Jurisdiction review: Is the entity registered in a FATF-listed jurisdiction, a Swiss country-risk-flagged country, or an offshore centre that typically presents complex ownership structures?
- Source of funds plausibility: Does the anticipated mandate size and source of funds make sense given what is known about the client at this stage?
- Conflict of interest check: Internal check against existing client relationships.
Output: A documented pre-screening decision — proceed, proceed with enhanced diligence, or decline — recorded in the client file before any onboarding forms are issued.
This stage is often skipped or underdocumented. VQF and SO auditors look for it specifically because it demonstrates that the IAM is applying a risk-based approach from the outset, not merely completing forms after the fact.
Stage 2 — Entity verification via the Handelsregister (AMLA Art. 3)
The Handelsregister is the primary source for satisfying AMLA Article 3 — verification of the contracting party's identity. For a Swiss corporate client, this means confirming that the legal entity is what it claims to be.
Step 2a — Zefix lookup by company name or UID
Search the entity on zefix.admin.ch. Confirm:
- The company is active (not gelöscht, not in liquidation)
- The legal form matches what the client has represented
- The registered address is consistent with the client's representations
- The UID number — record this; it is your stable identifier for all subsequent queries
If the company cannot be found on Zefix, it is either not registered in Switzerland, uses a different registered name, or has been deleted. Any of these outcomes requires clarification before proceeding.
Step 2b — Download and review the Handelsregisterauszug
From the Zefix profile, download the current register extract. Review and document:
- Company purpose (Zweck): Is the stated business purpose consistent with the proposed mandate?
- Authorised signatories: Who can legally bind the company, and is the person you are dealing with listed? Is their authority individual (Einzelunterschrift) or collective (Kollektivunterschrift)?
- Directors and board members: Names, nationalities, and domiciles of all Verwaltungsrat members. Note any non-Swiss nationalities or addresses in high-risk jurisdictions for follow-up in Stage 3.
- Mutation history: Review the SHAB publication log linked from the Zefix profile. Are there recent director changes, address changes, or purpose amendments that require explanation?
Step 2c — Verify signatory authority
If the person instructing the IAM is listed as an authorised signatory with individual authority, document this. If their authority is collective, the file must record that dual-signature requirements apply to mandate instructions. If the person is not listed in the register at all, a power of attorney or board resolution authorising their actions is required.
Output: Zefix PDF extract filed with date of retrieval, SHAB review documented, signatory authority confirmed, and any anomalies noted for follow-up.
Stage 3 — Beneficial ownership identification (AMLA Art. 4)
AMLA Article 4 requires identification of the natural person(s) who ultimately own or control the client entity. This is the most substantive and most frequently deficient stage in IAM KYC files.
Step 3a — Determine the applicable form
- Form A (Declaration of beneficial owner): required when the contracting party is a legal entity and a natural person controls it through shareholding or equivalent means.
- Form K (Declaration of controlling person): required when the entity is a domiciliary company (letterbox entity with no operational substance) and control is exercised through means other than direct shareholding.
Step 3b — Obtain the completed form
Issue Form A or Form K to the client and require completion before the mandate commences. The form must name every natural person with a beneficial ownership interest above 25% of capital or voting rights, directly or indirectly. A Form A that names another legal entity — rather than a natural person — as the beneficial owner is non-compliant. The ownership chain must be traced through every intermediate entity until natural persons are identified.
Step 3c — Verify plausibility
Obtaining a signed Form A is necessary but not sufficient. AMLA and AMLO-FINMA require that the declaration be checked for plausibility:
- Cross-reference named beneficial owners against the Handelsregister data (directors, quota holders for GmbHs)
- For complex multi-level structures, request corporate charts or shareholder registers for intermediate entities
- Note any discrepancies between the Form A declaration and the register data — these require resolution, not silent filing
Output: Signed Form A and/or Form K on file, plausibility check documented, ownership chain traced to natural persons, any discrepancies resolved and recorded.
Stage 4 — Sanctions, PEP, and adverse media screening (AMLA Art. 6)
AMLA Article 6 requires enhanced diligence for elevated-risk relationships. Sanctions and PEP screening must be run against the contracting party, all directors and board members, all identified beneficial owners, and any other natural persons with significant authority over the relationship.
Sanctions screening covers Swiss SECO lists, UN consolidated sanctions lists, EU sanctions lists, and US OFAC lists.
PEP screening identifies current or former senior public officials, their immediate family members, and close associates. A PEP identification is a trigger for enhanced due diligence — additional source-of-wealth documentation, senior management approval before onboarding, and more frequent periodic reviews.
Adverse media screening reviews publicly available information for red flags: criminal proceedings, regulatory sanctions, negative press coverage linked to financial crime. For Swiss corporate clients, a SHAB review covering the full mutation history is part of this check — prior bankruptcy proceedings, frequent director turnover, or suspicious address history are detectable through SHAB.
Output: Screening results documented for each person and entity checked, date and source of screening recorded, positive matches escalated and resolved with documented rationale.
Stage 5 — Risk classification and file assembly
With entity verification, beneficial ownership, and screening complete, the IAM classifies the relationship by risk level and assembles the complete onboarding file.
| Risk factor present | Implication |
|---|---|
| PEP identified | High risk — enhanced due diligence, SO/senior approval required |
| Domiciliary company structure | High risk — Form K required, enhanced source of funds |
| FATF grey/black list jurisdiction | High risk — enhanced due diligence |
| Complex multi-layer ownership | Elevated risk — full ownership chart required |
| Fiduciary registered address | Elevated risk — substance verification |
| Standard Swiss operating company | Standard risk — standard due diligence |
The complete onboarding file for a standard Swiss corporate client includes:
- Pre-screening decision record (Stage 1)
- Zefix extract with retrieval date and SHAB review note (Stage 2)
- Signatory authority confirmation (Stage 2)
- Signed Form A and/or Form K (Stage 3)
- Plausibility check documentation (Stage 3)
- Sanctions, PEP, and adverse media screening results (Stage 4)
- Risk classification with rationale (Stage 5)
- Management approval record for high-risk relationships (Stage 5)
- Signed mandate agreement and investment policy statement
Retention: The complete file must be retained for ten years after the end of the business relationship under AMLA Article 7.
Stage 6 — Ongoing monitoring and periodic review
KYC is not a one-time onboarding event. AMLA and AMLO-FINMA require ongoing due diligence throughout the life of the relationship.
Continuous SHAB monitoring is the operational mechanism for detecting corporate changes between periodic reviews. For each Swiss corporate client, the IAM should monitor SHAB publications by UID — looking specifically for:
- Director or signatory changes (may require Form A update and fresh screening on new persons)
- Address changes (potential fiduciary address flag)
- Purpose changes (material change in business scope)
- Entry into liquidation or bankruptcy (immediate risk escalation)
- Mergers or structural changes (may require re-KYC)
Periodic file review supplements SHAB monitoring with a full review at regular intervals — at minimum annually for high-risk relationships, and at least every three to five years for standard-risk relationships. The periodic review refreshes the Zefix extract, re-runs sanctions and PEP screening, and assesses whether the risk classification remains appropriate.
Event-driven re-KYC is triggered by material SHAB changes, client requests to change mandate scope, a sanctions designation affecting any person in the file, or suspicious transactions.
Key terms
| Term | Definition |
|---|---|
| FinIA | Financial Institutions Act — requires IAMs to hold a FINMA licence since 1 January 2020 |
| AMLA | Anti-Money Laundering Act — governs IAM due diligence obligations |
| SO | Supervisory Organisation — FINMA-authorised body conducting prudential supervision |
| VQF | Verein zur Qualitätssicherung von Finanzdienstleistungen — leading SRO for IAMs |
| Form A | Declaration of beneficial owner |
| Form K | Declaration of controlling person — used for domiciliary companies |
| SHAB | Swiss Official Gazette of Commerce — legally binding publication of all register changes |
| PEP | Politically Exposed Person — triggers enhanced due diligence |
| Zefix | Federal portal for searching Swiss commercial register data |