Are you on the board of directors of a Swiss SME (or its main shareholder) and feel that "governance" is becoming a topic that goes beyond the annual meeting minutes? You're right. In 2026, you won't be expected to operate like a listed multinational. But you will be expected to maintain basic discipline, traceability, and, above all, defensibility if a problem arises.
The key point: the board of directors (BoD) is not just for show. It is the responsible body. And when things go wrong (fraud, cyberattack, conflict of interest, missing cash, AML control, shareholder dispute), the question isn't "who made the mistake?" but "what did the BoD put in place to prevent it?" (source: Board of Directors: obligations, responsibilities and risks (admin.ch, CO)).
New governance priorities (2026): overview
In practice, Geneva SMEs don't change governance because they've read a guide. They change when an event shakes them:
- a public client requests anti-corruption guarantees,
- a bank demands a cleaner compliance file,
- an investor wants to understand "who decides what",
- an internal or external audit points out a gap,
- a cyber incident blocks invoicing for 10 days.
In 2026, the most common priorities for the BoD are very concrete:
-
Structured risk management (not a forgotten spreadsheet in a folder)
-
Decision traceability: who decided, on what basis, with which documents
-
Transparency: beneficial owners, conflicts of interest, sensitive financial flows
-
Compliance: AML according to activity, sanctions, export, data, taxation, VAT (8.1%, 2.6%, 3.8% depending on the case)
-
Digital management: indicators, document access, validation, archiving
What changes is not just the rule, but the expectation. "We didn't know" is less forgivable.
What authorities, banks, and partners really look at
Many SMEs think they're "in order" because accounts are closed and taxes paid. Good. But the questions coming in 2026 are on another level:
- Do you have a risk map and follow-up?
- Who approves payments and from what threshold?
- How do you manage conflicts of interest (director also supplier, relative employed, etc.)?
- Where are the minutes and supporting documents for sensitive decisions?
- Who has access to bank accounts and tools?
Result? "Light" governance remains possible, but it must be solid.
Field observation (Geneva): the trigger often comes at year-end
Every year, many SMEs discover a governance problem at year-end. Why? Because that's when tough questions are asked: provisions, doubtful receivables, shareholder loans, remuneration, expense reports, transactions with relatives.
If the BoD hasn't framed these issues in advance, you end up patching things after the fact. Bad timing, bad posture.
The increased role of the board in risk management and compliance
Swiss law is clear: the BoD has non-transferable and inalienable duties. You can delegate execution, not responsibility (source: Board of Directors: obligations, responsibilities and risks (admin.ch, CO)).
In 2026, the BoD must be able to prove it has:
- defined the organization,
- implemented suitable internal controls,
- supervised management,
- managed major risks,
- ensured compliance on relevant topics.
"We're a small structure": yes, but that doesn't protect you
The classic trap: confusing size with complexity. An SME with 12 people can have:
- international payments,
- sensitive data,
- an ERP,
- subcontractors,
- a director who signs alone,
- tight margins.
This mix can explode faster than a 200-person company with procedures.
The 6 risks the BoD must address in writing
No need for a novel. One page is enough. But it must be written, dated, discussed.
- Liquidity risk (client delays, seasonality, dependence on 2 major accounts)
- Tax and VAT risk (wrong rate, wrong service location, deduction errors)
- Cyber risk (phishing, ransomware, bank access)
- HR risk (dependence on a key person, conflicts, salary compliance)
- Contractual risk (penalty clauses, termination, liability)
- Reputation/integrity risk (gifts, commissions, intermediaries)
Table 1 — Example of a "SME version" risk register
| Risk | Probability | Impact | Alert indicator | Measure decided by BoD | Responsible | Review |
|---|---|---|---|---|---|---|
| Liquidity (client delays) | Medium | High | DSO > 55 days | Client credit limit + reminders D+7/D+21 | Finance management | Monthly |
| VAT (wrong treatment) | Low | High | Recurring corrections | Quarterly VAT review + check rates 8.1% / 2.6% / 3.8% | Fiduciary / CFO | Quarterly |
| Cyber (phishing) | High | High | Attempts on mailboxes | Double payment validation + MFA + training | IT / Management | Quarterly |
| Conflicts of interest | Medium | Medium | Linked suppliers | Annual declaration + recusal minutes | BoD president | Annual |
| Key person dependence | Medium | High | Uncovered absence | Continuity plan + process documentation | Management | Semiannual |
This table must be updated. Otherwise, it's useless.
Transparency, AML prevention, and anti-corruption: key regulatory developments
Transparency is no longer a "bank-only" issue. SMEs are affected too, especially if they deal with:
- financial intermediation,
- third-party fund management,
- offshore structures,
- international trade,
- exposed sectors (construction, trading, high-commission services).
AML: are you affected… without knowing it?
AML targets specific activities. Many managers think "we're not a bank, so it doesn't matter." Beware, that's a classic trap.
If your model involves receiving, holding, transferring assets for third parties, or acting as an intermediary in payments, AML applies (source: Anti-Money Laundering (AML, admin.ch, company obligations)).
The BoD must at least:
- identify if the activity falls under AML,
- document the analysis,
- decide on measures (process, training, controls).
Anti-corruption: the issue comes via contracts
In 2026, it may not be the authority calling you. It's your client:
- "Do you have a gifts policy?"
- "Do you pay commissions to intermediaries?"
- "Who approves representation expenses?"
If you answer "we operate on trust," you lose tenders.
Conflicts of interest: the BoD must stop ignoring them
In an SME, it's common:
- the director also owns a supplier,
- a relative is employed,
- a shareholder invoices consulting,
- a director has a mandate at a competitor.
It's not automatically illegal. But if it's not declared and managed, it becomes toxic.
Good practice: annual declaration of interests + recusal minutes when a topic affects a director.
Table 2 — Transparency and compliance documents to keep ready
| Topic | Concrete document | Who keeps it updated | When BoD reviews it |
|---|---|---|---|
| Beneficial owners/shareholding | Internal shareholder register + org chart | Management / fiduciary | Annual + on change |
| Conflicts of interest | Signed interest declaration by each director | BoD secretary | Annual |
| Anti-corruption | Gifts/commissions policy + thresholds + validation | Management | Annual |
| AML (if applicable) | AML analysis + KYC procedures | Compliance / fiduciary | Annual |
| Payments | Double signature rule + delegations | Management | Semiannual |
| Archiving | Archiving rules for minutes/contracts/invoices | Management | Annual |
BoD's role in VAT and taxation: not micro-management, but safeguards
The BoD isn't asked to recalculate every VAT return. It's asked to ensure the system avoids gross errors.
Two points often arise in Geneva:
- wrong rate applied (8.1% vs 2.6% vs 3.8%),
- wrong treatment of cross-border services (service location, proof, invoicing).
The BoD must require:
- a simple rate validation procedure,
- periodic control (quarterly is realistic),
- a clear contact (internal or fiduciary).
Digitalization and management: tools, automation, and efficiency for SME boards
Digitalization isn't "buying software." It's about reducing blind spots.
In 2026, an effective BoD has three things:
- reliable, regular figures
- accessible documents (minutes, contracts, delegations)
- a validation circuit (who approves what, and how it's proven)
Tools that really change a BoD's life
- Monthly dashboard (1 page): revenue, gross margin, cash, DSO, social/tax debts, order book.
- Document management: a single space, access rights, versioning.
- Payment workflow: double validation, thresholds, approval log.
- Electronic signature for minutes and circular decisions.
- Access log on critical tools (bank, ERP, CRM).
You can keep it simple. But it must be robust.
Ark Fiduciaire
Need help with this topic?
Our experts are available for personalised guidance. First consultation free, no commitment.
Automation: what to automate first (and what to avoid)
Automate first what causes repeated errors:
- client reminders,
- bank reconciliations,
- indicator extraction,
- expense validation,
- IBAN control when changing bank details.
Avoid automating a faulty process. Otherwise, you automate chaos.
Field anecdote: IBAN change fraud
Case seen in Geneva: a supplier "changes IBAN." Well-imitated email, correct logo, credible tone. Accounting updates. Payment of CHF 48,600. Money lost.
Tracing back, the BoD discovers there was:
- no phone call procedure,
- no double validation,
- no threshold,
- no approval log.
The BoD didn't click "pay." But it left the system without safeguards.
Step by step: upgrade your governance in 30 days (without paralyzing the company)
Want a practical plan? Here it is. We often do this with SMEs between 10 and 80 people.
Week 1 — Clarify who decides what
- List sensitive decisions: key hires, investments, credits, leases, disputes, variable remuneration, shareholder loans.
- Set thresholds: for example, any commitment > CHF 25,000 goes to the BoD.
- Write a simple delegation of authority (1–2 pages).
Week 2 — Set up minimum internal control
- Double payment validation (or double bank signature).
- "IBAN change" procedure: call a known number.
- Separation of duties: the person creating the supplier doesn't validate the payment.
Week 3 — Install monthly management
- Define 8 to 12 indicators.
- Set a calendar: reporting on the 10th, BoD meeting on the 15th.
- Standardize the format: same structure, same definitions.
Week 4 — Document compliance and transparency
- Directors' interest declaration.
- Gifts/commissions policy (even brief).
- AML analysis if your activity involves third-party flows.
- Central filing of minutes, contracts, decisions.
After 30 days, you're not "perfect." You're defensible.
Practical case (Geneva): when light governance is expensive
Geneva SME, 18 employees, B2B services, turnover CHF 3.2 million. BoD: 2 directors (shareholders) + 1 external director.
Problem: no clear rules on commitments and payments.
- A project manager signs a 12-month subcontract: CHF 9,800/month.
- No BoD validation minutes.
- The end client terminates after 3 months (unfavorable termination clause).
- The SME remains committed to the subcontractor for at least 6 months.
Financial impact:
- Remaining subcontractor cost: 6 × CHF 9,800 = CHF 58,800
- Legal fees (negotiation + review): CHF 7,500
- Internal time (management + finance) estimated: CHF 6,000
Total: CHF 72,300.
Analysis shows the problem isn't "the project manager is bad." The problem is the BoD didn't have:
- commitment threshold,
- validated contract template,
- review of critical clauses,
- reporting on off-balance commitments.
In our opinion, this is the kind of loss avoidable with simple, written governance.
3 costly mistakes for LLCs and PLCs (and how to fix them)
Mistake 1 — Nonexistent or unusable minutes
The minutes "we discussed, everyone agrees" won't save you.
Correction: Short but precise minutes:
- decision,
- amount,
- documents seen,
- vote,
- recusal if conflict.
Mistake 2 — Confusing management and BoD
In many SMEs, the BoD is also management. It happens. But roles must still be distinguished.
Correction: written delegation + BoD meeting with agenda and documents. Even if you're just two at the table.
Mistake 3 — "We'll see when it happens" on cyber and fraud
When it happens, you're in panic mode. And you pay.
Correction:
- MFA on tools,
- double payment validation,
- tested backups,
- incident procedure (who calls whom, in what order).
The BoD and Swiss best practices: what I recommend for SMEs
You don't need to invent your own doctrine. Swiss best practices exist and are adaptable for SMEs (source: Swiss Code of Best Practice for Corporate Governance (Economiesuisse); source: Corporate Governance (SECO); source: Corporate Governance (official SME site)).
What I often recommend:
- 1 BoD meeting per quarter (minimum) + a longer "budget/strategy" session.
- A meeting pack sent 3 days before: reporting, cash, risks, legal points.
- A list of decisions reserved for the BoD (investments, loans, disputes, variable remuneration, transactions with relatives).
- An external director when there's growth, financing, or complexity (international, regulated, multi-site).
A good external director doesn't just "look good." They ask the questions no one dares to ask.
Checklist 1 — Documents your BoD must have on hand (2026 version)
- Updated statutes + commercial register extract
- Organizational regulations / delegation of authority (even brief)
- List of authorized signatures (banks, contracts)
- Payment procedure (thresholds, double validation)
- Risk register + date of last review
- Standard monthly reporting (KPI + cash)
- BoD meeting minutes + signed circular decisions
- Directors' interest declaration
- Gifts/commissions policy + validation
- VAT file: internal rules on rates 8.1% / 2.6% / 3.8% + controls
- Continuity plan (at least cyber + key person)
Checklist 2 — How to strengthen your SME's governance (concrete actions 2026)
- Set 5 quantified thresholds (commitment, payment, investment, discount, hiring)
- Implement a monthly dashboard (1 page) and maintain it for 12 months
- Create a risk map (10 lines) and review it 4 times a year
- Formalize conflict of interest management (declaration + recusal)
- Secure payments (double validation + IBAN change procedure)
- Centralize BoD documents (one place, access rights)
- Test your backups and cyber plan (at least 1 exercise)
- Quarterly VAT review if you have mixed or international cases
- Clarify if you're affected by AML and document the answer
- Plan BoD agenda over 12 months (fixed dates, less improvisation)
Digitalization: minimum security standards (otherwise you're playing with fire)
We can discuss tools for hours. But there's a non-negotiable foundation:
- MFA enabled on email, bank, ERP, storage tools
- access management (who has what, and removal when someone leaves)
- offline or immutable backups + restoration test
- logging sensitive actions (payments, supplier changes)
- phishing training (short but regular)
The BoD doesn't need to be technical. It must demand proof: reports, tests, dates.
FAQ
What is the legal role of the board of directors of an SME in Switzerland?
The BoD has non-transferable duties: organization, supervision, suitable internal control, major risk management, and oversight of management. You can delegate operations, not responsibility (source: Board of Directors: obligations, responsibilities and risks (admin.ch, CO)).
What new transparency obligations affect SMEs?
It depends on your activity and partners. In practice, transparency requests often come from banks, public clients, investors, and major contractors: beneficial owners, conflicts of interest, anti-corruption policies, payment traceability.
What concrete tools facilitate SME governance?
A standard monthly dashboard, a single document space (minutes, contracts, delegations), a payment validation workflow, and electronic signature for decisions. If you can't prove a decision, it's as if it doesn't exist.
Is a third-party expert (fiduciary, lawyer, external director) necessary?
Not always. But as soon as you have growth, financing, international, or an exposed sector (third-party flows, commissions, public contracts), an external perspective saves time and avoids blind spots. In our opinion, a useful external director is well worth their cost if they prevent a single major mistake.
What mistakes to avoid in 2026 when "strengthening governance"?
Two classics: writing unrealistic procedures no one applies, and buying a tool without clarifying responsibilities. Start with thresholds, validations, monthly reporting, and the risk register.
How do I know if my company is affected by AML?
Ask simply: do you receive, hold, or transfer assets for third parties, or act as a payment intermediary? If yes, you must analyze AML applicability and document the answer (source: Anti-Money Laundering (AML, admin.ch, company obligations)).