FR-2026-0010

Revolut and Bitcoin Suisse: three questions about trust

Revolut’s Swiss licence application, reported data disclosure and Bitcoin Suisse’s reorganisation raise separate questions about status, authority and access.

Analysis
1
September 30, 2026
1.0
Finance
Verification
Mara Ellison
Editorial pen name
3
1
Application
Revolut’s announcement describes an application, not a granted Swiss banking licence.
Linked sources and reporting limits in the full record.
Application
Revolut’s announcement describes an application, not a granted Swiss banking licence.
Authority
The reported data incident concerns the legitimacy of a request, not just its email address.
Access
An operating change calls for clear responsibilities and a retrievable instruction record.
Check current status, request authority and operating responsibility as separate questions.
The Formal Record is published by Letro, which has a commercial interest in formal communication software. AI assisted the research and drafting. Mara Ellison is an editorial pen name used by The Formal Record; it does not identify a separate staff journalist.
1.0 | 30 Sep 2026 | First published.
revolut-bitcoin-suisse-september-2026-trust-controls

The brief

Revolut announced a Swiss banking licence application and a planned investment exceeding CHF150 million over five years. Separately, reporting on a customer-data disclosure described a fraudulent request sent from a legitimate government email address. Bitcoin Suisse announced an international reorganisation affecting Swiss roles.

The useful distinction is between regulatory status, authority to make a request and control over an operating process. A licence application is not approval; a genuine-looking address does not establish that a particular request is authorised; an operating location alone does not explain access. Our proposed response is to document those three questions separately and test a fictional sensitive-data request before release.

The full record

Three September stories are easy to group under the word trust. Doing so without separating their claims loses the practical lesson. Revolut’s proposed Swiss expansion concerns regulatory status and customer service. A reported fraudulent request concerns the authority to obtain information. Bitcoin Suisse’s reorganisation concerns where work is performed and how responsibilities are arranged.

First question: what is the institution’s current status?

On 16 September, Revolut announced that it had applied for a Swiss banking licence and planned to invest more than CHF150 million over five years. It reported more than 1.3 million Swiss customers. The announcement explicitly says the application remains subject to approval and its outcome is open; existing Swiss customers are served by Revolut Bank UAB in Lithuania.

Our take: a client-facing explanation should distinguish the current provider from a proposed future arrangement. Identify what changes only if approval is obtained, and avoid letting an expansion headline imply that a licence has already been granted. Keep the date and the source of the status statement visible.

Second question: is this particular request authorised?

On 14 September, Investing.com, reporting on Financial Times coverage, said Revolut had contacted 680 customers after information was supplied in response to a fraudulent request from a legitimate government email address. The report said Revolut blocked the address and notified regulators and affected customers. The figure is the reported overall customer count, not a count of Swiss customers.

We have not independently examined the incident or the request. The report supports a narrower operational question than whether a whole platform was compromised: how should the recipient establish the authority and scope of a request before releasing information?

Our take: treat the sender’s address, the claimed role and the requested disclosure as separate checks. In a fictional exercise, ask the receiving team to identify the approved route for handling that type of request, the evidence needed and the person responsible for the decision. Verify through independently established contact information when the process calls for confirmation. Do not use the contact route contained only in the suspect request as its own proof.

The record should explain the request, the basis for the decision and exactly what was released or withheld. This is a proposed process test, not a reconstruction of Revolut’s controls or a substitute for the applicable legal process.

Third question: who can act when operations move?

Reuters reported on 11 September that Bitcoin Suisse planned cuts affecting up to 60 of its 120 Swiss positions as software and back-office work moved towards international hubs. The announcement described a consultation running to 20 September. The upper figure was the announced scope, not evidence in this source that 60 departures had occurred.

Our take: an operating change should prompt a map of responsibilities and access. For one fictional client instruction, identify who receives it, which team acts and which person confirms the outcome. Recheck that the authorised colleague can retrieve the record after the handoff. These questions do not imply that overseas work is inherently unsafe or that domestic hosting alone provides a complete answer.

Turn the three questions into one usable record

For a sensitive request, retain the relevant institutional status, the requester’s verified authority, the scope of the approved action and the result. State uncertainty before acting rather than replacing it with a familiar logo, email domain or geographic label.

This is the practical contribution of formal communication: connect an attributable request to an authorised decision and a retrievable outcome. A technology’s security properties matter, but they do not by themselves decide whether the recipient should comply with the request in front of them. Our September SRA alert register shows related impersonation patterns in legal services; it is a separate dataset and does not include the Revolut incident.

Sources were checked on 30 September 2026. The Revolut expansion item uses its own announcement. The incident item relies on attributed published reporting; we have not independently established the affected population or examined systems. Bitcoin Suisse figures describe the announced reorganisation, not a verified final headcount reduction. Our practical exercises are editorial analysis, not findings about the named firms’ controls.

September 2026: 47 SRA impersonation alerts
september-2026-sra-impersonation-alerts
FR-2026-0011
Report
1
September 30, 2026
Law, Finance, Fiduciaries & trustees
Verification
Our September register links 47 SRA scam alerts and explains what the count measures, the patterns it reveals and how firms can test client verification.
4
1
47
Distinct SRA alert URLs dated in September, as checked at 19:23 BST on 30 September 2026.
SRA September index; 47 linked alerts; checked 30 Sep 2026, 19:23 BST.
47
Distinct SRA alert URLs dated in September, as checked at 19:23 BST on 30 September 2026.
Mara Ellison
1
Revolut and Bitcoin Suisse: three questions about trust
revolut-bitcoin-suisse-september-2026-trust-controls
FR-2026-0010
Analysis
1
September 30, 2026
Finance
Verification
Revolut’s Swiss licence application, reported data disclosure and Bitcoin Suisse’s reorganisation raise separate questions about status, authority and access.
3
1
Application
Revolut’s announcement describes an application, not a granted Swiss banking licence.
Linked sources and reporting limits in the full record.
Application
Revolut’s announcement describes an application, not a granted Swiss banking licence.
Mara Ellison
Swiss wealth management: who owns the client instruction?
september-2026-swiss-wealth-client-instructions
FR-2026-0009
Analysis
1
September 30, 2026
Finance, Fiduciaries & trustees, Law
Communication
New Zurich offices, a boutique launch and DBS’s Swiss adviser model highlight a practical issue: who approves, receives and retains a client instruction?
3
1
Five
Distinct September developments, not a representative market survey.
Linked sources and reporting limits in the full record.
Five
Distinct September developments, not a representative market survey.
Julian Vey
Private markets: access, liquidity and the client record
september-2026-private-markets-investor-communication
FR-2026-0008
Analysis
1
September 30, 2026
Finance, Fiduciaries & trustees
Communication
New distribution routes and fund launches put investor communication under pressure. September’s reports show what a clear, retrievable explanation needs.
3
1
Access
New distribution does not remove eligibility, risk or liquidity conditions.
Linked sources and reporting limits in the full record.
Access
New distribution does not remove eligibility, risk or liquidity conditions.
Julian Vey
Legal technology in September: adoption needs evidence
september-2026-legal-technology-adoption-evidence
FR-2026-0007
Analysis
1
September 30, 2026
Law
AI
September’s legal technology reports show different ways to buy and use AI. The useful comparison is the quality, cost and record of completed work.
3
1
543
Respondents in the LexisNexis survey; reported adoption is not a measure of output quality.
Linked sources and reporting limits in the full record.
543
Respondents in the LexisNexis survey; reported adoption is not a measure of output quality.
Mara Ellison
Swiss investors: the AI–adviser trust gap
swiss-investors-ai-financial-adviser-trust
FR-2026-0006
Analysis
1
September 29, 2026
Finance
AI
A Swiss survey reports a narrow AI–adviser trust gap among Gen Z investors. The useful response is a clear way to check claims clients bring to their adviser.
3
1
February
The survey’s fieldwork month; the findings were published in September 2026.
IFZ/HSLU research article, 28 September 2026; linked in the record.
Snapshot
The reported age-group comparison does not establish a change in trust over time.
Sina Tadayon
FCA AML handover: can law firms retrieve the record?
fca-aml-supervision-law-firm-records
FR-2026-0005
Analysis
1
September 29, 2026
Law
Communication
The FCA plans to begin legal and accounting AML supervision in late 2028. A practical retrieval exercise can help firms examine their decision records.
4
1
Late 2028
When the FCA says it will begin taking on the additional AML supervision described in its speech.
FCA speech, 17 September 2026; linked in the record.
60,000
Entities across legal and accounting sectors in the FCA’s stated scope; not 60,000 law firms.
Mara Ellison
FCA disclosures: delivery is not understanding
fca-investor-disclosures-client-understanding
FR-2026-0004
Analysis
1
September 29, 2026
Finance
Communication
Only 6% of 132 investment disclosures met the FCA’s plain-English readability assessment. Here is a practical way to test what a reader has understood.
3
1
6%
Of 132 documents met the FCA’s plain-English readability assessment; not a measure of investor comprehension.
FCA disclosure review, 2 July 2026; linked in the record.
Documents
The 6% result describes a text assessment, not the share of clients who understood an investment.
Julian Vey
Aquila’s Wecan choice: testing Swiss data control
aquila-swiss-data-control-procurement
FR-2026-0003
Analysis
1
September 29, 2026
Finance, Fiduciaries & trustees, Public sector
Communication
Aquila’s Wecan selection and a Swiss government software study raise a useful buying question: what can an institution demonstrate about control of its data?
3
1
One file
Our proposed procurement test: follow a fictional client file through processing, review and export.
Formal Record analysis; source announcements linked below.
Selection
Wecan announced Aquila’s choice following a competitive process; implementation was underway.
Julian Vey
Brodies’ AI pilot: what law firms should measure
brodies-ai-pilot-law-firm-evaluation
FR-2026-0002
Analysis
1
September 29, 2026
Law
AI
Brodies chose Legora after a three-month, 180-person pilot. Our proposed scorecard helps law firms test quality, review time and readiness before buying.
3
1
180
Colleagues involved in Brodies’ pilot, according to the firm.
Brodies announcement, 25 September 2026; linked in the record.
3 months
Brodies reports testing Legora with legal and business support colleagues before choosing it.
Mara Ellison
SRA scam alerts: verifying client instructions
sra-scam-alerts-client-instruction-verification
FR-2026-0001
Analysis
1
September 29, 2026
Law
Verification
Sixteen SRA alerts in four days expose a practical question for law firms: can a client check who issued an instruction without trusting the message itself?
3
1
16
SRA alerts dated 22–25 September 2026; a publication count, not a count of victims.
SRA alert index; count and linked register in Method.
16
Alerts published over four days. This does not measure the frequency of fraud.
Mara Ellison
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.