Skip to content
← Back to Services
Illustrative sample. Fictional organisation and simulated findings.
Deliverable Reference

AI Governance & Readiness Dossier

This document establishes the baseline inventory, risk mappings, data flow controls, and deployment roadmap for AI adoption under Swiss regulatory frameworks.

Prepared For (Fictional)

Alps Asset Management SA

Regulated Independent Asset Manager · 18 staff

Review & Version

Version 1.0 (July 14, 2026)

Author: Enrico Bartolotti · Owner: Cytria Sàrl

Scope Notice

This dossier supports governance readiness and documents current exposure. It provides an evidence base for management decisions and identifies controls requiring implementation. It does not certify compliance and does not replace legal, regulatory, or professional advice.

1. Executive Summary

Alps Asset Management SA exhibits emergent, shadow AI usage across daily operations. Lacking formal guidelines, staff copy client records and investment summaries into unapproved public AI tools, exposing the firm to nLPD breaches and FINMA circular compliance gaps.

Remediation focuses on establishing a sovereign document-retrieval pipeline hosted in Switzerland, eliminating public leaks, and defining strict human-in-the-loop validation boundaries.

2. Organisation Profile

Entity: Alps Asset Management SA (Fictional)
Activity: Independent Wealth Management under FINMA supervision
Staff: 18 employees (3 Relationship Managers, 2 Compliance officers, 13 operations/investment staff)
Data sensitivity: High (client personal wealth data, tax reports, portfolio transactions).

3. Scope of Review

The audit covers all operational document processing workflows, staff desktop access points, client reporting preparation, and vendor APIs utilized by the wealth management staff as of Q3 2026.

4. Current AI-Use Inventory

Tool NameEstimated UsersPurposeApproval Status
ChatGPT Free (Web)7 staff membersSummarizing market reports, drafting client emailsUnapproved (Shadow AI)
MS Copilot (Standard)4 staff membersDrafting meeting agendas and minutesConditionally tolerated

5. Systems and Vendor Inventory

Primary software includes: CRM (hosted locally), Portfolio Management Tool (Swiss SaaS), and Microsoft 365 Tenant (EU-West). The connection of unverified external APIs poses direct data transit risks.

6. Data-Category Inventory

  • Category A (PII): Client name, address, tax number, IBAN.
  • Category B (Financial): Portfolio holdings, transaction histories, advisory preferences.
  • Category C (Internal): Investment committee minutes, market research papers, compliance guidelines.

7. Data-Flow Map (Simulated Findings)

[Client Documents] → [RM Desktop] → [Public LLM Server API (US)] *Risk of Transit Leak*

[Sovereign Route Goal]: [Client Documents] → [Isolated Swiss VPC] → [Private Local Model (Swiss-Hosted)]

8. Confidentiality Considerations

Under the Swiss Data Protection Act (FADP), cross-border personal data transfers require an adequate level of data protection or appropriate safeguards and risk assessment.

9. Professional-Responsibility Boundaries

Advisers remain personally and legally responsible for all client portfolio suitability assessments. AI must never generate or finalize investment recommendations autonomously.

10. AI-Use Risk Register

Risk DescriptionSeverityLikelihoodImpact
PII sent to public US modelsCriticalHighFADP violation, reputational damage
AI hallucination in investment researchHighMediumIncorrect RM advisory decisions
Assessment note: In this illustrative scenario, “FADP violation” reflects the configuration assessed, including the absence of appropriate safeguards for the identified transfer. It does not mean that using a foreign or public AI service is inherently unlawful under the FADP.

11. Human-Oversight Register

External client communications, portfolio recommendations, and regulatory filings require explicit human review and sign-off before dispatch or recording. Routine internal drafts follow workflow-specific validation rules.

12. Vendor and Subprocessor Review

Vendor and subprocessor relationships must be assessed against applicable data-protection and FINMA outsourcing guidance. Commercial cloud APIs require specific contractual safeguards, data-location controls, and risk assessments before processing client-identifying data.

13. Control-Gap Analysis

  • No active firewall blocking of public AI API endpoints.
  • Lack of employee training regarding data input guidelines.
  • No secure internal alternative for basic text tasks.

14. Prioritised Remediation Plan

  1. Immediate: Block public AI tools at the corporate firewall and publish internal usage rules.
  2. Short-term: Implement a sovereign local sandbox using client-controlled infrastructure.
  3. Medium-term: Deploy the Relationship Manager Briefing helper workflow with full traceability.

15. Candidate First Workflows

Workflow: Relationship Manager briefing preparation.

Input: Selected internal investment committee papers (Category C).
Assisted output: Bulleted briefing memo.
Oversight: RM review and approval before meeting. No client names are included.

16. Recommended Deployment Posture

We recommend a **Swiss-Hosted Virtual Private Cloud (VPC)** deployment using isolated open-weights LLMs (such as Llama 3 or Qwen 2.5), ensuring no data transit outside Swiss borders.

17. Governance Roadmap

Establish the **AI Compliance Policy v1.0**, run staff training workshops, and perform annual security re-audits of sovereign models.

18. Management Decisions Required

  • Approval of budget for firewalls and Swiss-hosted VPC infrastructure.
  • Appointment of internal compliance officer for weekly logs review.

19. Limitations and Exclusions

This assessment is based on self-reported employee interviews and network snapshot inspections as of July 2026. It does not guarantee that all shadow AI usages have been identified.

20. Recommended Next Stage

Transition to the **AI Readiness & Governance Audit** to produce a complete customized version of this dossier for your organisation.

Request a Confidential Review

Discuss how an AI Governance and Readiness Audit applies to your organisation. We will map your exposure under Swiss regulations without needing access to your client files.

Illustrative sample · Fictional organisation and simulated findings