Skip to content
← Back to Services
Illustrative sample. Fictional organisation and simulated findings.
Deliverable Reference

AI Governance & Readiness Dossier

This document establishes the baseline inventory, risk mappings, data flow controls, and deployment roadmap for AI adoption under Swiss regulatory frameworks.

Prepared For (Fictional)

Alps Asset Management SA

Regulated Independent Asset Manager · 18 staff

Review & Version

Version 1.0 (July 14, 2026)

Author: Enrico Bartolotti · Owner: Cytria Sàrl

Scope Notice

This dossier supports governance readiness and documents current exposure. It provides an evidence base for management decisions and identifies controls requiring implementation. It does not certify compliance and does not replace legal, regulatory, or professional advice.

1. Executive Summary

Alps Asset Management SA exhibits emergent, shadow AI usage across daily operations. Lacking formal guidelines, staff copy client records and investment summaries into unapproved public AI tools, exposing the firm to nLPD breaches and FINMA circular compliance gaps.

Remediation focuses on establishing a sovereign document-retrieval pipeline hosted in Switzerland, eliminating public leaks, and defining strict human-in-the-loop validation boundaries.

2. Organisation Profile

Entity: Alps Asset Management SA (Fictional)
Activity: Independent Wealth Management under FINMA supervision
Staff: 18 employees (3 Relationship Managers, 2 Compliance officers, 13 operations/investment staff)
Data sensitivity: High (client personal wealth data, tax reports, portfolio transactions).

3. Scope of Review

The audit covers all operational document processing workflows, staff desktop access points, client reporting preparation, and vendor APIs utilized by the wealth management staff as of Q3 2026.

4. Current AI-Use Inventory

Tool NameEstimated UsersPurposeApproval Status
ChatGPT Free (Web)7 staff membersSummarizing market reports, drafting client emailsUnapproved (Shadow AI)
MS Copilot (Standard)4 staff membersDrafting meeting agendas and minutesConditionally tolerated

5. Systems and Vendor Inventory

Primary software includes: CRM (hosted locally), Portfolio Management Tool (Swiss SaaS), and Microsoft 365 Tenant (EU-West). The connection of unverified external APIs poses direct data transit risks.

6. Data-Category Inventory

  • Category A (PII): Client name, address, tax number, IBAN.
  • Category B (Financial): Portfolio holdings, transaction histories, advisory preferences.
  • Category C (Internal): Investment committee minutes, market research papers, compliance guidelines.

7. Data-Flow Map (Simulated Findings)

[Client Documents] → [RM Desktop] → [Public LLM Server API (US)] *Risk of Transit Leak*

[Sovereign Route Goal]: [Client Documents] → [Isolated Swiss VPC] → [Private Local Model (Swiss-Hosted)]

8. Confidentiality Considerations

Under the Swiss Data Protection Act (nLPD), processing client data on servers without absolute isolation guarantees constitutes an unauthorized transfer of personal data.

9. Professional-Responsibility Boundaries

Advisers remain personally and legally responsible for all client portfolio suitability assessments. AI must never generate or finalize investment recommendations autonomously.

10. AI-Use Risk Register

Risk DescriptionSeverityLikelihoodImpact
PII sent to public US modelsCriticalHighnLPD violation, reputational damage
AI hallucination in investment researchHighMediumIncorrect RM advisory decisions

11. Human-Oversight Register

All outputs generated by AI models must pass a four-eye verification step by a certified wealth manager before being published, logged in a CRM, or communicated to clients.

12. Vendor and Subprocessor Review

Currently, Microsoft 365 copilot subprocessors comply with EU sovereign boundaries. Public OpenAI APIs do not meet FINMA requirements for customer-data outsourcing.

13. Control-Gap Analysis

  • No active firewall blocking of public AI API endpoints.
  • Lack of employee training regarding data input guidelines.
  • No secure internal alternative for basic text tasks.

14. Prioritised Remediation Plan

  1. Immediate: Block public AI tools at the corporate firewall and publish internal usage rules.
  2. Short-term: Implement a sovereign local sandbox using client-controlled infrastructure.
  3. Medium-term: Deploy the Relationship Manager Briefing helper workflow with full traceability.

15. Candidate First Workflows

Workflow: Relationship Manager briefing preparation.

Input: Selected internal investment committee papers (Category C).
Assisted output: Bulleted briefing memo.
Oversight: RM review and approval before meeting. No client names are included.

16. Recommended Deployment Posture

We recommend a **Swiss-Hosted Virtual Private Cloud (VPC)** deployment using isolated open-weights LLMs (such as Llama 3 or Qwen 2.5), ensuring no data transit outside Swiss borders.

17. Governance Roadmap

Establish the **AI Compliance Policy v1.0**, run staff training workshops, and perform annual security re-audits of sovereign models.

18. Management Decisions Required

  • Approval of budget for firewalls and Swiss-hosted VPC infrastructure.
  • Appointment of internal compliance officer for weekly logs review.

19. Limitations and Exclusions

This assessment is based on self-reported employee interviews and network snapshot inspections as of July 2026. It does not guarantee that all shadow AI usages have been identified.

20. Recommended Next Stage

Transition to the **AI Readiness & Governance Audit** to produce a complete customized version of this dossier for your organisation.

Request a Confidential Review

Discuss how an AI Governance and Readiness Audit applies to your organisation. We will map your exposure under Swiss regulations without needing access to your client files.

Illustrative sample · Fictional organisation and simulated findings