AI Governance & Readiness Dossier
This document establishes the baseline inventory, risk mappings, data flow controls, and deployment roadmap for AI adoption under Swiss regulatory frameworks.
Prepared For (Fictional)
Alps Asset Management SA
Regulated Independent Asset Manager · 18 staff
Review & Version
Version 1.0 (July 14, 2026)
Author: Enrico Bartolotti · Owner: Cytria Sàrl
Scope Notice
This dossier supports governance readiness and documents current exposure. It provides an evidence base for management decisions and identifies controls requiring implementation. It does not certify compliance and does not replace legal, regulatory, or professional advice.
1. Executive Summary
Alps Asset Management SA exhibits emergent, shadow AI usage across daily operations. Lacking formal guidelines, staff copy client records and investment summaries into unapproved public AI tools, exposing the firm to nLPD breaches and FINMA circular compliance gaps.
Remediation focuses on establishing a sovereign document-retrieval pipeline hosted in Switzerland, eliminating public leaks, and defining strict human-in-the-loop validation boundaries.
2. Organisation Profile
Entity: Alps Asset Management SA (Fictional)
Activity: Independent Wealth Management under FINMA supervision
Staff: 18 employees (3 Relationship Managers, 2 Compliance officers, 13 operations/investment staff)
Data sensitivity: High (client personal wealth data, tax reports, portfolio transactions).
3. Scope of Review
The audit covers all operational document processing workflows, staff desktop access points, client reporting preparation, and vendor APIs utilized by the wealth management staff as of Q3 2026.
4. Current AI-Use Inventory
| Tool Name | Estimated Users | Purpose | Approval Status |
|---|---|---|---|
| ChatGPT Free (Web) | 7 staff members | Summarizing market reports, drafting client emails | Unapproved (Shadow AI) |
| MS Copilot (Standard) | 4 staff members | Drafting meeting agendas and minutes | Conditionally tolerated |
5. Systems and Vendor Inventory
Primary software includes: CRM (hosted locally), Portfolio Management Tool (Swiss SaaS), and Microsoft 365 Tenant (EU-West). The connection of unverified external APIs poses direct data transit risks.
6. Data-Category Inventory
- Category A (PII): Client name, address, tax number, IBAN.
- Category B (Financial): Portfolio holdings, transaction histories, advisory preferences.
- Category C (Internal): Investment committee minutes, market research papers, compliance guidelines.
7. Data-Flow Map (Simulated Findings)
[Client Documents] → [RM Desktop] → [Public LLM Server API (US)] *Risk of Transit Leak*
[Sovereign Route Goal]: [Client Documents] → [Isolated Swiss VPC] → [Private Local Model (Swiss-Hosted)]
8. Confidentiality Considerations
Under the Swiss Data Protection Act (nLPD), processing client data on servers without absolute isolation guarantees constitutes an unauthorized transfer of personal data.
9. Professional-Responsibility Boundaries
Advisers remain personally and legally responsible for all client portfolio suitability assessments. AI must never generate or finalize investment recommendations autonomously.
10. AI-Use Risk Register
| Risk Description | Severity | Likelihood | Impact |
|---|---|---|---|
| PII sent to public US models | Critical | High | nLPD violation, reputational damage |
| AI hallucination in investment research | High | Medium | Incorrect RM advisory decisions |
11. Human-Oversight Register
All outputs generated by AI models must pass a four-eye verification step by a certified wealth manager before being published, logged in a CRM, or communicated to clients.
12. Vendor and Subprocessor Review
Currently, Microsoft 365 copilot subprocessors comply with EU sovereign boundaries. Public OpenAI APIs do not meet FINMA requirements for customer-data outsourcing.
13. Control-Gap Analysis
- No active firewall blocking of public AI API endpoints.
- Lack of employee training regarding data input guidelines.
- No secure internal alternative for basic text tasks.
14. Prioritised Remediation Plan
- Immediate: Block public AI tools at the corporate firewall and publish internal usage rules.
- Short-term: Implement a sovereign local sandbox using client-controlled infrastructure.
- Medium-term: Deploy the Relationship Manager Briefing helper workflow with full traceability.
15. Candidate First Workflows
Workflow: Relationship Manager briefing preparation.
Input: Selected internal investment committee papers (Category C).
Assisted output: Bulleted briefing memo.
Oversight: RM review and approval before meeting. No client names are included.
16. Recommended Deployment Posture
We recommend a **Swiss-Hosted Virtual Private Cloud (VPC)** deployment using isolated open-weights LLMs (such as Llama 3 or Qwen 2.5), ensuring no data transit outside Swiss borders.
17. Governance Roadmap
Establish the **AI Compliance Policy v1.0**, run staff training workshops, and perform annual security re-audits of sovereign models.
18. Management Decisions Required
- Approval of budget for firewalls and Swiss-hosted VPC infrastructure.
- Appointment of internal compliance officer for weekly logs review.
19. Limitations and Exclusions
This assessment is based on self-reported employee interviews and network snapshot inspections as of July 2026. It does not guarantee that all shadow AI usages have been identified.
20. Recommended Next Stage
Transition to the **AI Readiness & Governance Audit** to produce a complete customized version of this dossier for your organisation.
Request a Confidential Review
Discuss how an AI Governance and Readiness Audit applies to your organisation. We will map your exposure under Swiss regulations without needing access to your client files.