VQF and FINMA-authorised supervisory organisations (SOs) consistently identify the same deficiency patterns when auditing Swiss IAM KYC files. Understanding these patterns is the fastest way to identify and close gaps in your own compliance workflow before an audit does it for you. This guide documents the seven most frequently cited findings, explains the underlying compliance requirement, and provides practical remediation steps.
Finding 1 — Form A traces to a legal entity, not a natural person
What auditors find: The Form A in the client file names a legal entity — an AG, GmbH, or foreign equivalent — as the beneficial owner. The ownership chain was not followed through to natural persons.
Why it matters: AMLA Article 4 requires identification of the natural person(s) who ultimately own or control the client entity. A legal entity cannot be the final beneficial owner. The obligation is to trace the ownership chain through every intermediate entity until natural persons are reached, and to identify those individuals with their full name, date of birth, nationality, and domicile.
How to fix it: When a Form A is received naming a legal entity as beneficial owner, return it to the client with a request to complete the chain. For GmbH intermediate entities, use the Zefix quota holder list as a cross-check. For AG intermediate entities — where shareholder data is not public — request the relevant shareholder register extracts or corporate structure charts. Document each step in the tracing process.
Finding 2 — No plausibility check documented
What auditors find: A signed Form A exists in the file, but there is no record of any verification that the declaration is accurate. The file shows the form was received; it does not show that its contents were checked.
Why it matters: AMLA and AMLO-FINMA require not just that the beneficial owner be identified, but that the declaration be checked for plausibility. This is a separate, affirmative obligation that goes beyond form collection. It requires the IAM to use available information to assess whether the named beneficial owners are credible and consistent with what the register data shows.
How to fix it: Add a brief file note to every Form A documenting:
- What sources were consulted (Zefix extract date, quota holder list, corporate charts)
- What was found (consistent with declaration / discrepancies noted)
- How any discrepancies were resolved
For GmbH clients, the Zefix quota holder list provides a direct cross-check. For complex structures, a corporate chart from the client showing the full ownership chain to natural persons is appropriate.
Finding 3 — Zefix extract is outdated
What auditors find: The Handelsregisterauszug in the file dates from initial onboarding — sometimes several years prior — and has never been refreshed. The current file does not reflect the actual current state of the entity.
Why it matters: The Zefix extract documents the state of the entity at a specific date. Corporate structures change: directors are replaced, the registered address moves, the company purpose is amended. An extract that is years old provides no assurance that the entity is still what the file says it is. VQF and SO auditors specifically look for whether the extract has been refreshed at each periodic review.
How to fix it: Establish a process to re-pull the Zefix extract at every periodic review (minimum annually for high-risk, every three to five years for standard-risk). Record the retrieval date in the file. Also pull a fresh extract whenever a material SHAB event is detected for the entity. Do not rely on a retained PDF from onboarding as a current document.
Finding 4 — SHAB monitoring is absent or ad hoc
What auditors find: There is no systematic process for detecting SHAB publications about client entities between periodic reviews. Some IAMs rely on clients to self-report changes; others conduct manual spot checks with no consistent methodology or documentation.
Why it matters: AMLA and AMLO-FINMA require ongoing due diligence throughout the life of a client relationship — not just at onboarding and scheduled reviews. SHAB publications have legal effect from the date of publication. An IAM that fails to detect a material SHAB publication cannot claim ignorance of the change. The monitoring obligation is operational, not aspirational.
How to fix it: Implement UID-based SHAB monitoring for every Swiss corporate client. The UID (CHE-XXX.XXX.XXX) is the stable identifier for querying SHAB publications programmatically via LINDAS SPARQL or the Zefix REST API. Record the monitoring process in compliance documentation: who is responsible, how frequently checks are run, and what alert mechanism is in place. Commercial tools including Suiva provide portfolio-level SHAB monitoring with compliance-relevant alerts.
Finding 5 — Sanctions screening not re-run at periodic review
What auditors find: Sanctions and PEP screening was conducted at onboarding, but the file shows no evidence of re-screening at any subsequent periodic review. The screening record is a single entry from years ago.
Why it matters: Sanctions lists change continuously. Persons not on any list at onboarding may subsequently be designated. PEP status changes as officials take office or leave it. AMLO-FINMA requires screening to be current — a five-year-old screen result does not satisfy the current-state obligation for a client relationship that has continued for five years.
How to fix it: Build re-screening into the periodic review checklist as a mandatory step. Document the re-screening date, the lists checked, and the result. The documentation should show a clear audit trail: screening date, screening tool used, lists consulted, result (clear/match), and if a match — how it was resolved. For event-driven reviews triggered by SHAB events affecting natural persons in the file, re-run screening on the affected persons at the time of the event.
Finding 6 — High-risk relationship lacks management approval documentation
What auditors find: A PEP-connected relationship, a domiciliary company structure, or another elevated-risk client was onboarded without a record of senior management approval. The risk classification in the file may indicate high risk, but there is no approval sign-off from a named manager with a date.
Why it matters: AMLA Article 6 and AMLO-FINMA require that high-risk relationships receive senior management approval before onboarding commences. This is an affirmative approval — it cannot be inferred from the absence of an objection. The approval must be documented with the name of the approver and the date of approval. Without this, the file fails the enhanced due diligence requirement even if all other documentation is complete.
How to fix it: Add an approval step to the onboarding checklist for all relationships classified as high-risk. The approval record should include: the name and title of the approving manager, the date of approval, a brief statement of the risk factors considered, and the conditions (if any) attached to the approval. For existing high-risk relationships where the approval record is absent, retrospectively obtain and document a current approval as part of the next periodic review.
Finding 7 — Ten-year retention not systematically implemented
What auditors find: Files from terminated relationships are archived inconsistently — some are complete, some are partial, some cannot be located. There is no systematic process tied to the end date of each relationship, and no reliable way to confirm that all required documentation is retained for the full ten-year period.
Why it matters: AMLA Article 7 imposes a ten-year retention obligation from the end of the business relationship. The obligation covers all identification documents, beneficial ownership declarations (Form A and Form K), screening records, correspondence, and internal notes — not only signed forms. Failure to produce required documentation on regulatory request can constitute a compliance breach regardless of whether the underlying due diligence was conducted.
How to fix it: Implement a retention schedule tied to the relationship end date for each client file. Record the end date when a relationship is terminated. Set a systematic retention expiry review at ten years plus a short buffer. Ensure retention applies to all file components, not only the primary signed forms. For digital files, implement access controls to prevent premature deletion.
Summary: quick-fix checklist
| Finding | Quick fix |
|---|---|
| Form A names a legal entity | Return form; trace chain to natural persons |
| No plausibility check | Add file note: sources checked, findings, discrepancies |
| Outdated Zefix extract | Re-pull at every periodic review; record retrieval date |
| No SHAB monitoring | Implement UID-based monitoring; document the process |
| Screening not re-run | Add re-screening to periodic review checklist |
| No management approval for high-risk | Add approval step with name, title, date |
| Retention not systematic | Tie retention to relationship end date; track all file components |
Key terms
| Term | Definition |
|---|---|
| VQF | Leading SRO for Swiss IAMs — conducts AMLA compliance audits |
| SO | Supervisory Organisation — FINMA-authorised body conducting prudential supervision |
| Form A | Declaration of beneficial owner |
| Form K | Declaration of controlling person — used for domiciliary companies |
| AMLA Art. 4 | Beneficial ownership identification obligation |
| AMLA Art. 6 | Enhanced due diligence for elevated-risk relationships |
| AMLA Art. 7 | Ten-year record retention obligation |
| SHAB | Swiss Official Gazette of Commerce — legally binding publication of all register changes |
| UID | Unique company identifier (CHE-XXX.XXX.XXX) — used for SHAB monitoring |