Skip to main content
All guides
10 min read·Last updated: 2026-07-31

Business continuity plan for SMEs: IT crises, critical absences and emergency procedures in Switzerland

How to protect invoicing, accounting and day-to-day operations when systems go down, the owner is absent, or a critical supplier interrupts service.

Why business continuity is not just for large companies

A Swiss SME with ten employees does not have a dedicated crisis management office, but often concentrates irreplaceable skills in just a few people: client management, bank approvals, access to the accounting system, relations with the FTA and the pension fund. When the company server stops responding, the owner is ill for three weeks, or the cloud provider interrupts service, operations can grind to a halt within hours.

A business continuity plan (BCP) is not a shelf document for multinationals: it is a set of procedures, responsibilities and resources that allow essential processes to be maintained — or restored quickly. For a Sàrl or sole proprietorship in Ticino, Zurich or Valais, this above all means ensuring invoicing, collections, supplier payments, tax compliance and access to accounting data.

This guide explains how to build a realistic BCP for an SME, with a focus on IT crises, absences of key personnel and emergency procedures aligned with the Swiss regulatory framework in force in 2026.

Most common crisis scenarios for Swiss SMEs

Before writing detailed procedures, it is worth mapping the events that most often affect small and medium-sized Swiss businesses in practice:

IT and cyber crises

Ransomware, hardware failure, accidental data deletion, interruption of the cloud provider or accounting software. The impact is immediate on invoices, bank statements, VAT returns and payroll.

In Switzerland, the National Cyber Security Centre (NCSC) reports a steady increase in attacks targeting SMEs as well. The Federal Act on Data Protection (FADP, in force since 1 September 2023) requires technical and organisational measures appropriate to the risk (Art. 8 FADP).

Absence of the owner or key personnel

Illness, injury, death or prolonged absence of the manager, administrative officer or sole employee who knows the processes. Without delegations and documentation, no one can sign contracts, authorise payments or close the monthly accounts.

The Code of Obligations (CO) does not require SMEs to have a formal BCP, but it requires the manager of a Sàrl to exercise management with due diligence (Art. 812 CO). A lack of continuity may amount to negligence and give rise to civil liability towards the company, shareholders and creditors (Art. 754 CO).

Interruption of critical suppliers

Bank, fiduciary, hosting provider, invoicing software or payment platform unavailable. Even a 48-hour outage during the end of a VAT quarter can cause delays, late-payment interest and tension with clients.

Assessing dependence on a single supplier for email, DNS, backups and accounting is the first step in defining alternatives.

Physical and local events

Fire, flooding, prolonged blackout or inability to access offices. SMEs with paper archives that have not been digitised are particularly vulnerable.

Swiss accounting law (CO, Art. 958f) requires business books and accounting documents to be retained for ten years from the end of the financial year: the BCP must ensure that these documents survive and remain accessible.

Critical functions matrix

An effective BCP for SMEs starts by identifying processes that cannot stop beyond a defined threshold (Recovery Time Objective, RTO). Here is a reference matrix:

Function Indicative RTO Main risks Minimum measure
Invoicing and collections 0–24 hours Accounting system offline, e-banking access blocked Cloud backup, second bank signatory, offline invoice template
Accounting and reporting 24–48 hours Data loss, sole admin user Periodic export, dual admin access, fiduciary review
Supplier payments and payroll 24–72 hours Owner absent, expired mandates Bank power of attorney, documented list of recurring payments
Tax compliance (VAT, income tax) Within legal deadlines Incomplete data, responsible person absent Shared tax calendar, active fiduciary delegation
Client communication 0–4 hours Email and phone not working Alternative number, service interruption notice template
Access to legal documents 48 hours Paper archive destroyed Digitisation, secure off-site storage

The RTO should be adapted to the sector: a workshop with urgent maintenance contracts will have different priorities from a consulting firm with monthly invoicing. The goal is not perfection, but clarity on what to recover first.

IT continuity: accounting data, backups and access

For most Swiss SMEs, an IT crisis is the risk with the greatest immediate operational impact. A structured approach comprises three levels:

1. The 3-2-1 backup rule. Three copies of the data, on two different media, one of which off-site (cloud or external data centre). Backups must include the accounting system, tax documents, payroll, contracts and company email. Test restoration at least once a year: a backup that has never been verified is not a guarantee.

2. Access management. Avoid having a single employee hold all admin passwords. Use a company password manager with emergency access for the owner or fiduciary. Document which users can export data, who approves e-banking payments and who manages the internet domain and DNS.

3. Cloud software and data portability. Cloud accounting solutions such as Accountex reduce the risk of local data loss thanks to automatic backups and access from any device. However, check the contractual terms: who owns the data, how to export it (CSV, PDF, standard format) and what SLA the provider guarantees in the event of an incident.

Ransomware: what to do in the first hours

  • Immediately isolate compromised devices from the network (Wi-Fi, cable).
  • Do not pay the ransom without assessment by an IT expert and, where appropriate, reporting to the NCSC.
  • Activate clean backups and the cloud accounting system to continue invoicing and record-keeping.
  • Assess the obligation to notify the FDPIC if the breach is likely to result in a high risk to the personality or fundamental rights of the data subjects (Art. 24 para. 1 FADP).
  • Document the incident for possible requests from the cyber insurer and the auditor.

Critical absences: owner, administration and key personnel

When the manager of a Sàrl or a sole proprietor is suddenly absent, the gap is not just about leadership: it often blocks signatures, bank access and day-to-day decisions. Here is how to prepare:

Formal delegations and power of attorney

Set up a bank power of attorney for a second signatory (partner, spouse, fiduciary) with clear limits. In the articles of association or bylaws, verify who can represent the company if the manager is unable to act.

For sole proprietorships, consider a general power of attorney deposited with the bank and an internal document indicating who manages operations in the owner's absence.

Internal operations manual

A 5–10 page document covering: Swiss tax calendar (quarterly or semi-annual VAT, withholding tax, OASI), list of critical suppliers with contacts, monthly accounting close procedure, credentials in the password manager and month-end checklist.

Update it every quarter. An auditor or fiduciary can help draft it even without a structured HR department.

In the event of the owner's death, corporate succession, heirs and possible liquidation come into play. For a Sàrl, registration in the Commercial Register shows the shareholders and representatives: ensure that at least one other person knows the procedure for convening a general meeting and appointing an interim manager. Loss-of-earnings or key-person insurance (if taken out) can cover temporary replacement costs, but does not replace operational documentation.

Emergency procedures: chain of command and communication

A lean BCP for SMEs must answer four questions in writing and in an accessible form (paper copy in the office + cloud copy):

Element Content Responsible party
BCP activation Objective criteria: server down > 4 h, owner absent > 5 days, confirmed cyber incident Owner or designated deputy
Crisis team Names, phone numbers, email, escalation order (internal → fiduciary → external IT) Secretary / admin or manager
External communication Email/SMS templates for clients and suppliers; message on the website Commercial contact
Operational priorities Ordered list: collections, payroll, tax deadlines, client orders Administrative officer
IT recovery MSP contact, backup restore procedure, switch to cloud accounting system IT contact (internal or external)
Incident closure Accounting integrity check, internal memo, BCP update Owner + fiduciary

Simulate at least once a year a simple scenario — for example, "the owner cannot be reached for 48 hours" — to verify that someone else knows how to issue an invoice, check the bank balance and meet a VAT deadline. A thirty-minute test is worth more than twenty pages of theory.

Regulatory and accounting aspects in Switzerland

The BCP intersects with several obligations under Swiss law, even though no law explicitly requires SMEs to have a business continuity plan:

Document retention (CO Art. 958f). Business books, accounting documents, management report and audit report must be retained for ten years from the end of the financial year, in a readable and verifiable form. The plan must ensure that backups and digital archives meet this requirement, including the ability to present documents to the FTA or auditor after an incident.

Data protection (FADP). Security measures appropriate to the risk (Art. 8 FADP), record of processing activities where required (Art. 12 FADP), notification to the FDPIC of breaches likely to result in a high risk (Art. 24 FADP). A cyber incident that exposes client data can have reputational and sanction-related consequences.

Duties of the manager (CO Art. 812 and 754). The manager of a Sàrl must act with due diligence (Art. 812 CO). Ignoring known IT risks or having no succession plan for administrative management may be challenged in civil liability proceedings towards the company, shareholders and creditors (Art. 754 CO).

Tax deadlines. Deadlines for VAT returns, withholding tax and OASI contributions do not pause for an internal emergency. Advance delegation to a fiduciary or accounting software with shared access reduces the risk of delays and late-payment interest.

Five-step implementation for SMEs

1

Identify critical processes

List everything that, if interrupted for 24 hours, causes economic or legal damage: invoicing, payments, production, customer support. Involve whoever handles accounting, IT and the main contracts.

2

Define RTO and backup responsible parties

For each process, establish how quickly it must restart and who acts if the primary person is absent. Formalise at least one bank delegation and a second admin in the accounting system.

3

Secure data and access

Enable automatic backups, two-factor authentication on e-banking and email, shared password manager. Periodically export balances and records from the accounting software.

4

Draft the BCP document (max 10 pages)

Emergency contacts, procedures for IT and absences, tax calendar, list of insurance policies (cyber, loss of earnings). Keep a paper copy off-site and a protected digital copy.

5

Test and update every year

Verify a backup restore, simulate an owner absence, review supplier contacts. Update after every change of software, bank or staff. Integrate the BCP into onboarding for new administrative personnel.

Quick operational checklist

Use this list to check your SME's level of preparedness:

  • Automatic backups active and restore test completed in the last 12 months
  • At least two people with admin access to the accounting system
  • Power of attorney or second e-banking signatory configured and tested
  • Company password manager with documented emergency access
  • Shared Swiss tax deadline calendar (VAT, income tax, OASI, occupational pension)
  • Updated internal operations manual (suppliers, monthly procedures, contacts)
  • Crisis communication templates ready for clients and suppliers
  • MSP or external IT support contact with defined SLA
  • Cyber or loss-of-earnings insurance assessment completed
  • Emergency simulation carried out with documented outcome

A business continuity plan does not eliminate crises, but it reduces hesitation when every hour counts. For entrepreneurs and fiduciary firms using digital tools such as Accountex, the combination of documented processes, shared access and accounting data always available in the cloud is the concrete foundation on which to build resilience — without the complexity of a corporate BCP, but with the same logic: knowing in advance who does what, with which tools and within what timeframe.

Simplify your Swiss accounting

AccountEX handles VAT, QR-invoices and bookings with AI. Start for free.