Hybrid Cloud in Practice: Compliance and Sovereignty

Hybrid Cloud
Cloud
In the Swiss financial and insurance industry, the specific way the cloud is used determines whether innovation can scale or gets bogged down in audit overhead, fears of losing control, and dependencies. A closer look shows that compliance and sovereignty are not the brake, but rather the mechanism that makes public-cloud innovation usable in a regulated environment in the first place.

Compliance and sovereignty as the unifying bracket 

Part 1 of this blog series described the dilemma: growth and digitalization demand speed, while the regulatory framework demands demonstrability. Part 2 showed how security becomes an operating principle. Part 3 introduced FinOps as a governance model for costs. 

Part 4 now closes the loop: compliance and sovereignty are the unifying bracket that bindingly brings together security, costs, operating model, and governance—making cloud use “bank-ready” in the first place. 

Compliance in the cloud: what supervisors and audits require 

Many requirements sound technical, but at their core they are governance questions: 

  • Who remains responsible? 
  • Who is allowed to audit what? 
  • How do we ensure control and business continuity? 

Two points in particular are central and often underestimated in cloud discussions: 

  1. Audit and access rights: FINMA, the audit firm, and the institution must be able to verify the service provider’s compliance with supervisory requirements, with access and audit rights at any time, without hindrance. 
  2. Sub-service providers and an orderly exit: cloud is rarely “one provider.” FINMA therefore requires that institutions be informed early about the engagement or change of material subcontractors—and that they have the option to terminate an outsourcing arrangement in an orderly manner.

In addition: the cloud must also fit into the resilience logic. With Circular 2023/1 on operational risks and resilience, FINMA emphasizes, among other things, topics such as critical processes, BCM, and the handling of critical data. And finally, data protection in the cloud plays a dual role—both as a legal framework and as an expectation of transparency. The fully revised data protection law has been in force since September 1, 2023. 

Sovereignty: what it’s really about 

  • “Sovereignty” is often reduced to data location in Switzerland. That is important, but not sufficient. For decision-makers, sovereignty ultimately is the sum of four control capabilities: 
    Legal controllability: which legal jurisdictions can affect data and processes (keyword: foreign lawful access, i.e., government access based on foreign laws)? The Swiss Bankers Association (SBA) explicitly lists this topic as a focus in the updated cloud guideline. 
  • Contractual controllability: do I have genuine audit, information, and cooperation rights—even with sub-service providers—and a practical exit option?
  • Technical controllability: who controls keys and identities? How is data exfiltration limited? How are logs/evidence generated? 
  • Operational controllability: can operations be continued during disruptions, including access to the necessary information in Switzerland? This is explicitly addressed in the outsourcing context. 

“Hybrid” is particularly strong 

The hybrid cloud is an architectural principle and a control and governance model in one. It allows workloads to be placed according to risk, regulation, and business value while simultaneously leveraging innovation via public cloud services. 
In practical terms, this means: 

  • Sensitive, heavily regulated workloads run in a community/private environment operated in Switzerland, with clear operating and evidencing mechanisms. 
  • Innovation and scaling building blocks can be used in public cloud services—but embedded in a unified governance, security, and monitoring regime. 

So: a community cloud operated in Switzerland for banks and insurers, plus public cloud services explicitly built on automation, monitoring, and governance and security requirements. This way, compliance is not merely documented after the fact, but generated directly in operations. Governance becomes a strategic leadership task in the hybrid, highly regulated IT world. 

The checklist for management 

The difference between “using the cloud” and “mastering the cloud” lies in management. Public-cloud hyperscalers provide powerful platforms. However, they are built globally, operated globally, and do not automatically address the Swiss specifics of supervision, audit, and data requirements. 
A provider therefore must assume responsibility for operational capability and demonstrability. If you want to raise this topic pragmatically with the executive management, five questions are enough to start: 

  1. Can we enforce audit and access rights at any time along the entire value chain (including subcontractors)? 
  2. Is our exit realistically planned—technically, organizationally, and contractually—or only “theoretically possible”? 
  3. Where are our most critical data and processes located, and do location, key/identity control, and BCM fit with that?
  4. Do we have a clear approach to foreign lawful access and government procedures, including transparency and cooperation with providers?
  5. Do we generate compliance evidence “by build,” i.e., continuously, or only shortly before the audit? 

Conclusion: compliance and sovereignty as an innovation booster 

Anyone who successfully uses the cloud in a regulated environment treats compliance and sovereignty as a design principle. FINMA outsourcing requirements, resilience expectations, and data protection set the framework. In practice, particularly critical: governance, data processing, authorities/procedures, and audit. 

Hybrid cloud is a particularly effective approach for this: it combines Swiss operating and control logic with the innovative power of modern cloud services—provided it is managed, integrated, and implemented in a governance-capable way. 

Author

Torsten Böttjer

Head of Cloud Services

LinkedIn
Foto Torsten Böttjer

Contact