New governance requirements for SMEs in Switzerland: everything boards of directors must implement in 2026

In 2026, Swiss SME governance will face stricter regulatory frameworks, growing digitalization, new risk management (cyber, compliance, AI), and increased expectations for transparency. This article details the new responsibilities of Swiss boards of directors, rising obligations (transparency, compliance, risk prevention), digital tools to facilitate management, and provides pragmatic implementation advice tailored to SME realities.

By Ark Fiduciaire

Published on 08/25/2026

Reading time: 13min (2580 words)

tresoreriefinancecashbudgetpaiementpme

Are you on the board of directors of a Swiss SME (or its main shareholder) and feel that "governance" is becoming a topic that goes beyond the annual meeting minutes? You're right. In 2026, you won't be expected to operate like a listed multinational. But you will be expected to maintain basic discipline, traceability, and, above all, defensibility if a problem arises.

The key point: the board of directors (BoD) is not just for show. It is the responsible body. And when things go wrong (fraud, cyberattack, conflict of interest, missing cash, AML control, shareholder dispute), the question isn't "who made the mistake?" but "what did the BoD put in place to prevent it?" (source: Board of Directors: obligations, responsibilities and risks (admin.ch, CO)).

New governance priorities (2026): overview

In practice, Geneva SMEs don't change governance because they've read a guide. They change when an event shakes them:

  • a public client requests anti-corruption guarantees,
  • a bank demands a cleaner compliance file,
  • an investor wants to understand "who decides what",
  • an internal or external audit points out a gap,
  • a cyber incident blocks invoicing for 10 days.

In 2026, the most common priorities for the BoD are very concrete:

  1. Structured risk management (not a forgotten spreadsheet in a folder)

  2. Decision traceability: who decided, on what basis, with which documents

  3. Transparency: beneficial owners, conflicts of interest, sensitive financial flows

  4. Compliance: AML according to activity, sanctions, export, data, taxation, VAT (8.1%, 2.6%, 3.8% depending on the case)

  5. Digital management: indicators, document access, validation, archiving

What changes is not just the rule, but the expectation. "We didn't know" is less forgivable.

What authorities, banks, and partners really look at

Many SMEs think they're "in order" because accounts are closed and taxes paid. Good. But the questions coming in 2026 are on another level:

  • Do you have a risk map and follow-up?
  • Who approves payments and from what threshold?
  • How do you manage conflicts of interest (director also supplier, relative employed, etc.)?
  • Where are the minutes and supporting documents for sensitive decisions?
  • Who has access to bank accounts and tools?

Result? "Light" governance remains possible, but it must be solid.

Field observation (Geneva): the trigger often comes at year-end

Every year, many SMEs discover a governance problem at year-end. Why? Because that's when tough questions are asked: provisions, doubtful receivables, shareholder loans, remuneration, expense reports, transactions with relatives.

If the BoD hasn't framed these issues in advance, you end up patching things after the fact. Bad timing, bad posture.

The increased role of the board in risk management and compliance

Swiss law is clear: the BoD has non-transferable and inalienable duties. You can delegate execution, not responsibility (source: Board of Directors: obligations, responsibilities and risks (admin.ch, CO)).

In 2026, the BoD must be able to prove it has:

  • defined the organization,
  • implemented suitable internal controls,
  • supervised management,
  • managed major risks,
  • ensured compliance on relevant topics.

"We're a small structure": yes, but that doesn't protect you

The classic trap: confusing size with complexity. An SME with 12 people can have:

  • international payments,
  • sensitive data,
  • an ERP,
  • subcontractors,
  • a director who signs alone,
  • tight margins.

This mix can explode faster than a 200-person company with procedures.

The 6 risks the BoD must address in writing

No need for a novel. One page is enough. But it must be written, dated, discussed.

  1. Liquidity risk (client delays, seasonality, dependence on 2 major accounts)
  2. Tax and VAT risk (wrong rate, wrong service location, deduction errors)
  3. Cyber risk (phishing, ransomware, bank access)
  4. HR risk (dependence on a key person, conflicts, salary compliance)
  5. Contractual risk (penalty clauses, termination, liability)
  6. Reputation/integrity risk (gifts, commissions, intermediaries)

Table 1 — Example of a "SME version" risk register

RiskProbabilityImpactAlert indicatorMeasure decided by BoDResponsibleReview
Liquidity (client delays)MediumHighDSO > 55 daysClient credit limit + reminders D+7/D+21Finance managementMonthly
VAT (wrong treatment)LowHighRecurring correctionsQuarterly VAT review + check rates 8.1% / 2.6% / 3.8%Fiduciary / CFOQuarterly
Cyber (phishing)HighHighAttempts on mailboxesDouble payment validation + MFA + trainingIT / ManagementQuarterly
Conflicts of interestMediumMediumLinked suppliersAnnual declaration + recusal minutesBoD presidentAnnual
Key person dependenceMediumHighUncovered absenceContinuity plan + process documentationManagementSemiannual

This table must be updated. Otherwise, it's useless.

Transparency, AML prevention, and anti-corruption: key regulatory developments

Transparency is no longer a "bank-only" issue. SMEs are affected too, especially if they deal with:

  • financial intermediation,
  • third-party fund management,
  • offshore structures,
  • international trade,
  • exposed sectors (construction, trading, high-commission services).

AML: are you affected… without knowing it?

AML targets specific activities. Many managers think "we're not a bank, so it doesn't matter." Beware, that's a classic trap.

If your model involves receiving, holding, transferring assets for third parties, or acting as an intermediary in payments, AML applies (source: Anti-Money Laundering (AML, admin.ch, company obligations)).

The BoD must at least:

  • identify if the activity falls under AML,
  • document the analysis,
  • decide on measures (process, training, controls).

Anti-corruption: the issue comes via contracts

In 2026, it may not be the authority calling you. It's your client:

  • "Do you have a gifts policy?"
  • "Do you pay commissions to intermediaries?"
  • "Who approves representation expenses?"

If you answer "we operate on trust," you lose tenders.

Conflicts of interest: the BoD must stop ignoring them

In an SME, it's common:

  • the director also owns a supplier,
  • a relative is employed,
  • a shareholder invoices consulting,
  • a director has a mandate at a competitor.

It's not automatically illegal. But if it's not declared and managed, it becomes toxic.

Good practice: annual declaration of interests + recusal minutes when a topic affects a director.

Table 2 — Transparency and compliance documents to keep ready

TopicConcrete documentWho keeps it updatedWhen BoD reviews it
Beneficial owners/shareholdingInternal shareholder register + org chartManagement / fiduciaryAnnual + on change
Conflicts of interestSigned interest declaration by each directorBoD secretaryAnnual
Anti-corruptionGifts/commissions policy + thresholds + validationManagementAnnual
AML (if applicable)AML analysis + KYC proceduresCompliance / fiduciaryAnnual
PaymentsDouble signature rule + delegationsManagementSemiannual
ArchivingArchiving rules for minutes/contracts/invoicesManagementAnnual

BoD's role in VAT and taxation: not micro-management, but safeguards

The BoD isn't asked to recalculate every VAT return. It's asked to ensure the system avoids gross errors.

Two points often arise in Geneva:

  • wrong rate applied (8.1% vs 2.6% vs 3.8%),
  • wrong treatment of cross-border services (service location, proof, invoicing).

The BoD must require:

  • a simple rate validation procedure,
  • periodic control (quarterly is realistic),
  • a clear contact (internal or fiduciary).

Digitalization and management: tools, automation, and efficiency for SME boards

Digitalization isn't "buying software." It's about reducing blind spots.

In 2026, an effective BoD has three things:

  1. reliable, regular figures
  2. accessible documents (minutes, contracts, delegations)
  3. a validation circuit (who approves what, and how it's proven)

Tools that really change a BoD's life

  • Monthly dashboard (1 page): revenue, gross margin, cash, DSO, social/tax debts, order book.
  • Document management: a single space, access rights, versioning.
  • Payment workflow: double validation, thresholds, approval log.
  • Electronic signature for minutes and circular decisions.
  • Access log on critical tools (bank, ERP, CRM).

You can keep it simple. But it must be robust.

Ark Fiduciaire

Need help with this topic?

Our experts are available for personalised guidance. First consultation free, no commitment.

Automation: what to automate first (and what to avoid)

Automate first what causes repeated errors:

  • client reminders,
  • bank reconciliations,
  • indicator extraction,
  • expense validation,
  • IBAN control when changing bank details.

Avoid automating a faulty process. Otherwise, you automate chaos.

Field anecdote: IBAN change fraud

Case seen in Geneva: a supplier "changes IBAN." Well-imitated email, correct logo, credible tone. Accounting updates. Payment of CHF 48,600. Money lost.

Tracing back, the BoD discovers there was:

  • no phone call procedure,
  • no double validation,
  • no threshold,
  • no approval log.

The BoD didn't click "pay." But it left the system without safeguards.

Step by step: upgrade your governance in 30 days (without paralyzing the company)

Want a practical plan? Here it is. We often do this with SMEs between 10 and 80 people.

Week 1 — Clarify who decides what

  1. List sensitive decisions: key hires, investments, credits, leases, disputes, variable remuneration, shareholder loans.
  2. Set thresholds: for example, any commitment > CHF 25,000 goes to the BoD.
  3. Write a simple delegation of authority (1–2 pages).

Week 2 — Set up minimum internal control

  1. Double payment validation (or double bank signature).
  2. "IBAN change" procedure: call a known number.
  3. Separation of duties: the person creating the supplier doesn't validate the payment.

Week 3 — Install monthly management

  1. Define 8 to 12 indicators.
  2. Set a calendar: reporting on the 10th, BoD meeting on the 15th.
  3. Standardize the format: same structure, same definitions.

Week 4 — Document compliance and transparency

  1. Directors' interest declaration.
  2. Gifts/commissions policy (even brief).
  3. AML analysis if your activity involves third-party flows.
  4. Central filing of minutes, contracts, decisions.

After 30 days, you're not "perfect." You're defensible.

Practical case (Geneva): when light governance is expensive

Geneva SME, 18 employees, B2B services, turnover CHF 3.2 million. BoD: 2 directors (shareholders) + 1 external director.

Problem: no clear rules on commitments and payments.

  • A project manager signs a 12-month subcontract: CHF 9,800/month.
  • No BoD validation minutes.
  • The end client terminates after 3 months (unfavorable termination clause).
  • The SME remains committed to the subcontractor for at least 6 months.

Financial impact:

  • Remaining subcontractor cost: 6 × CHF 9,800 = CHF 58,800
  • Legal fees (negotiation + review): CHF 7,500
  • Internal time (management + finance) estimated: CHF 6,000

Total: CHF 72,300.

Analysis shows the problem isn't "the project manager is bad." The problem is the BoD didn't have:

  • commitment threshold,
  • validated contract template,
  • review of critical clauses,
  • reporting on off-balance commitments.

In our opinion, this is the kind of loss avoidable with simple, written governance.

3 costly mistakes for LLCs and PLCs (and how to fix them)

Mistake 1 — Nonexistent or unusable minutes

The minutes "we discussed, everyone agrees" won't save you.

Correction: Short but precise minutes:

  • decision,
  • amount,
  • documents seen,
  • vote,
  • recusal if conflict.

Mistake 2 — Confusing management and BoD

In many SMEs, the BoD is also management. It happens. But roles must still be distinguished.

Correction: written delegation + BoD meeting with agenda and documents. Even if you're just two at the table.

Mistake 3 — "We'll see when it happens" on cyber and fraud

When it happens, you're in panic mode. And you pay.

Correction:

  • MFA on tools,
  • double payment validation,
  • tested backups,
  • incident procedure (who calls whom, in what order).

The BoD and Swiss best practices: what I recommend for SMEs

You don't need to invent your own doctrine. Swiss best practices exist and are adaptable for SMEs (source: Swiss Code of Best Practice for Corporate Governance (Economiesuisse); source: Corporate Governance (SECO); source: Corporate Governance (official SME site)).

What I often recommend:

  • 1 BoD meeting per quarter (minimum) + a longer "budget/strategy" session.
  • A meeting pack sent 3 days before: reporting, cash, risks, legal points.
  • A list of decisions reserved for the BoD (investments, loans, disputes, variable remuneration, transactions with relatives).
  • An external director when there's growth, financing, or complexity (international, regulated, multi-site).

A good external director doesn't just "look good." They ask the questions no one dares to ask.

Checklist 1 — Documents your BoD must have on hand (2026 version)

  • Updated statutes + commercial register extract
  • Organizational regulations / delegation of authority (even brief)
  • List of authorized signatures (banks, contracts)
  • Payment procedure (thresholds, double validation)
  • Risk register + date of last review
  • Standard monthly reporting (KPI + cash)
  • BoD meeting minutes + signed circular decisions
  • Directors' interest declaration
  • Gifts/commissions policy + validation
  • VAT file: internal rules on rates 8.1% / 2.6% / 3.8% + controls
  • Continuity plan (at least cyber + key person)

Checklist 2 — How to strengthen your SME's governance (concrete actions 2026)

  • Set 5 quantified thresholds (commitment, payment, investment, discount, hiring)
  • Implement a monthly dashboard (1 page) and maintain it for 12 months
  • Create a risk map (10 lines) and review it 4 times a year
  • Formalize conflict of interest management (declaration + recusal)
  • Secure payments (double validation + IBAN change procedure)
  • Centralize BoD documents (one place, access rights)
  • Test your backups and cyber plan (at least 1 exercise)
  • Quarterly VAT review if you have mixed or international cases
  • Clarify if you're affected by AML and document the answer
  • Plan BoD agenda over 12 months (fixed dates, less improvisation)

Digitalization: minimum security standards (otherwise you're playing with fire)

We can discuss tools for hours. But there's a non-negotiable foundation:

  • MFA enabled on email, bank, ERP, storage tools
  • access management (who has what, and removal when someone leaves)
  • offline or immutable backups + restoration test
  • logging sensitive actions (payments, supplier changes)
  • phishing training (short but regular)

The BoD doesn't need to be technical. It must demand proof: reports, tests, dates.

FAQ

What is the legal role of the board of directors of an SME in Switzerland?

The BoD has non-transferable duties: organization, supervision, suitable internal control, major risk management, and oversight of management. You can delegate operations, not responsibility (source: Board of Directors: obligations, responsibilities and risks (admin.ch, CO)).

What new transparency obligations affect SMEs?

It depends on your activity and partners. In practice, transparency requests often come from banks, public clients, investors, and major contractors: beneficial owners, conflicts of interest, anti-corruption policies, payment traceability.

What concrete tools facilitate SME governance?

A standard monthly dashboard, a single document space (minutes, contracts, delegations), a payment validation workflow, and electronic signature for decisions. If you can't prove a decision, it's as if it doesn't exist.

Is a third-party expert (fiduciary, lawyer, external director) necessary?

Not always. But as soon as you have growth, financing, international, or an exposed sector (third-party flows, commissions, public contracts), an external perspective saves time and avoids blind spots. In our opinion, a useful external director is well worth their cost if they prevent a single major mistake.

What mistakes to avoid in 2026 when "strengthening governance"?

Two classics: writing unrealistic procedures no one applies, and buying a tool without clarifying responsibilities. Start with thresholds, validations, monthly reporting, and the risk register.

How do I know if my company is affected by AML?

Ask simply: do you receive, hold, or transfer assets for third parties, or act as a payment intermediary? If yes, you must analyze AML applicability and document the answer (source: Anti-Money Laundering (AML, admin.ch, company obligations)).


References

Opting-out of audit in Switzerland (2026): legal requirements, risks and checklist for SME managers

A practical guide for boards, directors of AG/GmbH and administrative managers: understand opting-out from limited audit, check legal requirements, identify risks for banking/shareholding access, and prepare the required documentation (minutes, declarations, documents to keep, filing with the commercial register), with a concrete checklist adapted to French-speaking Switzerland.

Control and optimization of supplier invoices for SMEs and freelancers in French-speaking Switzerland: common mistakes, practical tips, and effective processes (2026)

Discover how to efficiently structure the control and recording of supplier invoices, avoid common omissions, anticipate VAT recovery pitfalls, and implement a clear and automatable procedure adapted to SMEs and freelancers in 2026.

Let's talk

Get in touch

Our experts can help you understand the details and implications for your business. Get personalised advice tailored to your situation.