Wealth-platform decisions are often presented as technology modernisation. In practice, the platform can reshape onboarding, client records, portfolio activity, controls, reporting, fees, communications, and daily operations. The institution needs to know what it is delegating, what it must retain, and how the combined model will remain governable.

Start with the service and regulatory perimeter

“Wealth platform” can describe very different arrangements: software supplied to an internal operation, hosted infrastructure, managed services, business-process outsourcing, or a broader provider model spanning several regulated and supporting functions. The applicable requirements depend on the institution, jurisdiction, activity, and materiality.

FINMA Circular 2018/3 applies to the institutions identified in its scope, including banks, securities firms, and insurers, rather than to every wealth or asset manager in the same way. It takes a principle-based, technology-neutral approach and requires institutions within scope to address outsourced material functions through governance, inventory, selection, contracts, security, audit, and continuity arrangements.12

Map the operating capability before the supplier solution

Define the end-to-end capabilities the future model must support: prospect and client records, onboarding, due diligence, restrictions, mandate and suitability evidence where applicable, portfolio and order activity, pricing and valuations, corporate actions, fees, statements, communications, complaints, controls, and management information.

For each capability, identify the accountable business owner, system of record, critical data, controls, upstream and downstream dependencies, service expectations, and fallback. This prevents a supplier taxonomy from replacing the institution’s own operating model.

Decide what expertise and authority must remain inside

Outsourcing should not leave the institution unable to understand, challenge, or change the service. The FCA’s SYSC 8 rules state that an in-scope firm outsourcing a critical or important operational function remains responsible for its obligations and must retain the expertise and resources needed to supervise the function and manage its risks.4

The retained organisation therefore needs more than contract management. It needs decision rights, service knowledge, data access, control ownership, financial oversight, change capability, and enough operational depth to respond when the supplier’s standard process does not fit a client or regulatory need.

Preserve one authoritative client and transaction record

A platform migration can distribute records across customer relationship management, onboarding, portfolio, custody, payment, document, and reporting systems. Agree which source is authoritative for each critical field and event, how records are reconciled, and how corrections propagate.

Data ownership should cover definitions, lineage, quality thresholds, access, retention, deletion, legal hold, export, and evidence. Reports should be traceable to source transactions and decision records. A visually complete client view is not sufficient if the institution cannot reproduce why a value, restriction, fee, or communication was produced.

Evaluate the provider chain and concentration

The contracting provider may rely on cloud infrastructure, market-data services, communications platforms, specialist processors, and subcontracted operations. The institution should understand which dependencies are material, where services and data are located, how subcontractors can change, and where several capabilities depend on the same provider or technology.

The EBA’s outsourcing guidelines require a register of outsourcing arrangements and address criticality, due diligence, contractual rights, sub-outsourcing, access and audit, security, monitoring, and exit.3 For financial entities within DORA’s scope, ICT third-party risk must also be managed as part of the entity’s ICT risk framework, with enhanced requirements for services supporting critical or important functions.5

Translate oversight into evidence and decisions

Service levels should measure client and operational outcomes. Availability alone says little about overdue onboarding cases, unreconciled positions, inaccurate valuations, failed reports, unresolved restrictions, incorrect fees, or aged complaints.

Define a focused oversight set: service and control indicators, incidents, reconciliation breaks, data-quality exceptions, overdue cases, client impact, supplier changes, audit findings, remediation, capacity, and continuity readiness. Each threshold should lead to a named decision or escalation rather than a dashboard observation.

Design change governance before migration

Provider platforms evolve through standard releases, regulatory changes, shared product roadmaps, and client-specific configuration. Establish who can request and approve change, how impact is assessed, what is tested, which evidence is retained, and how conflicting client or market requirements are resolved.

Migration itself should be governed as a sequence of data, process, control, people, client, and financial decisions. Reconciliation, parallel operation, cutover, rollback, communications, and hypercare need defined entry and exit criteria. Technical transfer without operational acceptance is not a completed migration.

Make exit capability proportionate and usable

Exit planning should identify the data, documents, configuration, interfaces, licences, knowledge, people, and transition support required to move the service or restore an internal capability. It should cover scheduled transition and adverse conditions such as provider failure, material breach, or an unacceptable concentration risk.

The FCA requires continuity and quality to be maintained on termination by transferring the function to another provider or performing it internally, where the relevant rules apply.4FINMA’s circular similarly requires institutions within scope to preserve inspectability and account for continuity, including the added risks of outsourcing abroad.1

A decision record for the target model

Before approving the arrangement, leadership should be able to see:

  • the capabilities, functions, and entities in scope;
  • the regulatory and criticality assessments;
  • the retained organisation and decision rights;
  • the client, transaction, data, and evidence model;
  • the provider, subcontractor, and concentration map;
  • the service, control, audit, and escalation framework;
  • the migration, change, and operational-acceptance criteria; and
  • the continuity, exit, and transition capability.

A strong platform decision does more than select capable technology. It creates an operating structure in which the institution can still explain, control, and change the service delivered to its clients.

Primary sources

References

  1. Swiss Financial Market Supervisory Authority (FINMA), Circular 2018/3, Outsourcing – banks and insurers, 21 September 2017, last amended 31 October 2019. Official source. Accessed 21 May 2026.
  2. Swiss Financial Market Supervisory Authority (FINMA), FINMA publishes outsourcing circular, 5 December 2017. Official source. Accessed 21 May 2026.
  3. European Banking Authority, Guidelines on outsourcing arrangements, EBA/GL/2019/02, 25 February 2019. Official source. Accessed 21 May 2026.
  4. Financial Conduct Authority, Handbook, SYSC 8, Outsourcing, current edition at the date of publication, especially SYSC 8.1. Official source. Accessed 21 May 2026.
  5. European Parliament and Council, Regulation (EU) 2022/2554 of 14 December 2022 on digital operational resilience for the financial sector, especially Articles 28–30. Official source. Accessed 21 May 2026.