Indicative quotes
SMI......SMI 5J...performanceSMI YTD...since JanuaryDay high......Day low......Volume SMI...sharesSMI......SMI 5J...performanceSMI YTD...since JanuaryDay high......Day low......Volume SMI...shares

Indicative quotes: SMI ..., change ..., SIX close on ... at 17:31 Zurich.

Independent Swiss market guides
Digital banks Switzerland: partner due-diligence checklist
Brokers

Digital banks Switzerland: partner due-diligence checklist

How banks, brokers and fintech providers can assess a digital financial partner before launching customer acquisition, onboarding or investment services.

Laurent Duplat
13 min read

Short answer: A digital bank should assess a technology, broker, lead or distribution partner through the full customer journey, not only through a product demonstration. The review should cover the legal entity, authorisation perimeter, customer money flow, KYC ownership, data processing, public claims, complaints, outsourcing and incident response. A partner that cannot explain these responsibilities clearly is not ready for scaled financial acquisition.

Digital banking partnerships can shorten product development and open new distribution channels. They can also create hidden dependencies. A bank may outsource identity checks, use a broker for investment execution, purchase qualified leads from a marketing company or connect a third-party savings interface to its customer journey. Each relationship changes how the bank must explain the service and monitor the customer experience.

This checklist is for digital banks, brokers, fintechs and professional partners working with Swiss or European customers. It is an operational review, not a legal opinion. The exact authorisation and outsourcing analysis depends on the entities, services and jurisdictions involved.

Start with the customer journey

Map what a customer sees from the first advertisement to the first transaction and the first complaint. The journey should show who owns each step.

Journey stagePartner questionsEvidence to request
DiscoveryWho writes and approves the claim?Approved copy and campaign record
ApplicationWho collects identity and customer data?Data-flow and onboarding responsibility map
ApprovalWho makes the customer decision?Decision rules and exception process
FundingWho receives and reconciles money?Payment and account-flow diagram
InvestingWho receives or executes an order?Execution, custody and product map
SupportWho answers questions and complaints?Service route and escalation matrix
IncidentWho communicates when the service fails?Incident contacts and customer templates

The table is deliberately simple. It makes a group identify the difference between a vendor that provides software and an entity that performs a regulated or customer-facing activity.

Legal entity and authorisation perimeter

The brand on an application screen may represent a group of companies. Before a partnership begins, identify which company contracts with the customer, which company receives money, which company holds or arranges custody and which company is responsible for the product explanation.

FINMA states that banks and securities firms, including certain branches and representative offices of foreign institutions, must be licensed for the relevant activities. Its authorisation overview and types of licensing should be included in the review file.

Do not treat an authorisation as a general endorsement of every group company. Record the name of the authorised entity, the activity and the public register source. If a partner is not the entity that holds the relevant authorisation, explain its role without creating a misleading impression.

Client money, custody and payments

The money-flow map should begin with the customer’s bank account and end with the account or custody location. Add payment providers, banks, brokers, custodians, clearing arrangements and technology vendors.

Ask:

  • Who receives the initial transfer?
  • Who can instruct a withdrawal?
  • Which entity reconciles balances?
  • Are securities held as custody assets or represented by another claim?
  • Which entity sends statements?
  • What happens if a provider becomes unavailable?
  • Does the customer understand the difference between cash and securities?

The public site should not use one broad promise such as “your assets are safe” when different assets, entities or protection rules apply. The Swiss custody protection guide provides the investor-facing explanation that partners can use as a content reference.

KYC and AML responsibility matrix

Outsourcing a KYC step does not necessarily outsource the bank’s responsibility for the customer relationship. The contract should state who collects evidence, who makes decisions, who handles exceptions, who updates the policy and who provides records for review.

Use a responsibility matrix with these roles:

  • product owner;
  • compliance owner;
  • data-protection owner;
  • technology owner;
  • vendor owner;
  • customer-support owner;
  • complaints owner;
  • incident owner.

Each role needs a named team, escalation address and backup. A partner review that only lists a vendor contact is incomplete.

The digital onboarding checklist explains how to separate identity, authority, ownership, relationship purpose and ongoing monitoring. Link to it from a partnership page so the reader can move from the strategic review to the operational control.

Product governance for investment features

Digital banks increasingly combine payments, savings, stocks, funds, structured products and trading features. A partner should not be approved for “investments” as one category. Each product needs a description, eligible customer, risk explanation, execution path, custody route and complaint owner.

For each product, write down:

  1. What is the customer buying?
  2. Which entity provides or executes it?
  3. What can the customer lose?
  4. How is the price or value determined?
  5. Is the customer receiving advice or execution-only access?
  6. Which documents are displayed before action?
  7. Which events trigger a review?

This prevents a payment partner from accidentally advertising a trading product as if it were a bank deposit or a broker from presenting a simulated trading result as an investment performance record.

Marketing and lead-partner controls

Acquisition partners often know how to generate attention but not how to explain regulated financial services. The bank should approve the language before it is published and monitor where that language appears.

Maintain a claims register containing:

  • the exact claim;
  • product and country scope;
  • responsible approver;
  • required qualifier;
  • source or evidence;
  • review date;
  • approved channels;
  • correction and removal process.

Do not allow a partner to add “safe,” “guaranteed,” “instant,” “regulated” or “protected” to a headline without the bank’s review. The partner should also know which customer questions require escalation rather than a marketing answer.

The insurer and insurance-distribution environment offers a useful parallel. FINMA explains that obligations relating to distribution affect insurers and intermediaries and that control expectations depend on the relationship. Read FINMA’s insurance distribution guidance.

Outsourcing, resilience and third parties

The partner review should list every critical service: identity, cloud, payments, market data, order management, customer messaging, records and analytics. For each one, identify the failure mode and recovery priority.

For financial entities in the European regulatory perimeter, DORA is a useful reference for ICT risk, incident reporting, testing and third-party arrangements. The EBA DORA overview explains the framework. A Swiss bank should verify its own scope rather than copy a generic EU conclusion.

Ask a provider:

  • How will it notify an incident?
  • Which subcontractors process customer data?
  • How is access controlled?
  • How quickly can records be exported?
  • How are changes approved?
  • What happens when the contract ends?
  • Can the service be replaced without losing the customer history?

If the answer is only “the platform is secure,” the review is not finished.

Complaints and customer support

Partners should be measured on the quality of the customer support route, not only the number of leads or completed applications. Define who receives a complaint, who acknowledges it, who can investigate it and who is allowed to promise a remedy.

Create categories for:

  • identity and access;
  • payment or withdrawal;
  • product understanding;
  • execution or price;
  • custody or statement;
  • marketing claim;
  • data request;
  • partner conduct;
  • technical incident.

Each category should have an owner and a feedback route to product and compliance. A recurring complaint about a comparison page is a content-control problem, not merely a customer-service problem.

Partner approval gates

A bank can use four gates before launch.

Gate one: model fit. The partner’s activity, customer and countries are understood.

Gate two: control fit. KYC, money flow, custody, product and complaints responsibilities are documented.

Gate three: communication fit. Public claims, disclosures, affiliate copy and translations are approved.

Gate four: operating fit. Incidents, vendor changes, records and exit plans are tested.

The gates should not be treated as a single signature. A partner may pass model fit and fail communication fit. That is useful information before a campaign goes live.

Questions for a quarterly partnership review

  1. Has the partner added a product or country?
  2. Has the contracting entity changed?
  3. Have complaint categories changed?
  4. Did a vendor, model or data path change?
  5. Were affiliates or translations reviewed?
  6. Were customer money and custody flows reconciled?
  7. Were incidents tested?
  8. Are public claims still accurate?
  9. Can the institution produce the partner’s decision record?
  10. Is the exit plan still realistic?

The purpose of the review is not to create paperwork for its own sake. It is to ensure that growth has not changed the service faster than governance can follow.

Frequently asked questions

What should a digital bank verify before using a broker partner?

It should verify the contracting entity, authorisation perimeter, execution route, custody model, customer eligibility, product documents, complaint process, technology dependencies and approved public claims.

Does a technology vendor become a bank partner automatically?

No. Its role depends on the service provided, access to customer data, operational control and contractual relationship. The vendor should be mapped separately from the entity providing the regulated financial service.

Who owns KYC when a bank uses a third-party provider?

The contract and operating model must define the roles. A provider may perform verification steps, while the institution remains responsible for its customer relationship and governance. The exact allocation requires a current legal and compliance review.

How should a bank evaluate financial lead generation?

Review consent, customer fit, campaign language, affiliate control, data transfer, complaints and the accuracy of the claims. A lead is not qualified merely because a form was completed.

Why should insurers care about digital-bank partnerships?

Digital financial journeys increasingly combine banking, investment and insurance decisions. The parties must identify who distributes the insurance, what information the customer receives and which entity handles the relationship.

Conclusion

The strongest digital-bank partnerships are built around a clear customer journey, a documented entity map and an honest division of responsibilities. Banks, brokers and fintechs can grow faster when they know who owns money, identity, product explanations, complaints and incidents. That clarity also makes a partner easier for insurers, technology providers and regulators to assess.

For related material, read the FinTech market-entry checklist, the digital onboarding checklist and the Swiss financial platforms pillar.