Flitz.ai Flitz.ai
← All articles
5 min read

IT Asset Records and Swiss Compliance: Why Your Device Inventory Is a Legal Document, Not Just a Spreadsheet

Under DSG and OR, knowing exactly which device holds which data isn't optional. Here's how a structured IT inventory keeps Swiss SMEs and IT providers audit-ready.

IT Asset Records and Swiss Compliance: Why Your Device Inventory Is a Legal Document, Not Just a Spreadsheet

Ask most Swiss SME owners or IT service providers how many laptops, monitors, and phones they currently manage for each client, and you'll often get a shrug, a sigh, and a promise to "check the spreadsheet." That gap between what's on paper and what's actually deployed in the field is not a minor operational nuisance — it's a compliance exposure.

What Swiss law actually expects from you

The revised Federal Act on Data Protection (DSG) requires businesses to know where personal data lives and to be able to demonstrate appropriate technical and organisational measures to protect it. A laptop is not just a laptop — it's a data-bearing asset. If you can't say with confidence which device holds which customer's data, who last used it, and whether it's patched against known vulnerabilities, you cannot credibly answer a DSG inquiry or a client's own due-diligence request under GDPR if you serve EU customers too.

The Code of Obligations (OR) adds a parallel layer: proper bookkeeping and asset accountability. Devices bought on behalf of a customer, leased hardware, or licences invoiced periodically all need to reconcile with what's actually deployed — otherwise your MWST filings and your asset register can quietly drift apart, which is exactly the kind of discrepancy an auditor or fiduciary will flag.

Where manual inventory processes break down

Most IT providers and internal IT leads manage inventory the same three ways, and each has a compliance blind spot:

  • Spreadsheets shared across customers — data for different clients sits in the same file, which is itself a DSG segregation problem, and nobody updates them consistently once a device leaves the office.
  • Sticky labels and memory — asset tags with no scannable link to a record mean that when a device is lost, stolen, or simply retired, there's no reliable way to prove what happened to the data on it.
  • No patch or vulnerability trail — if a breach occurs and you can't show which devices were missing critical updates and when, you have no documentation to support a "reasonable measures" defence.

None of these failures are dramatic on their own. They just accumulate until an audit, a lost-device incident, or a customer contract review forces the question: can you actually document your IT estate?

Customer-scoped inventory as a compliance boundary

Flitz's IT Management module starts from a principle that maps directly onto DSG segregation requirements: each customer owns their own inventory. There is no shared pool of devices across clients, no accidental cross-visibility. For fiduciaries and MSPs managing multiple customers, this structural separation is itself a control — not an afterthought bolted on later.

Getting existing records into that structure isn't a rebuild-from-scratch exercise. A CSV bulk import with German and English column aliases lets you bring in whatever spreadsheet you already have, in whichever language it was built in, and turn it into a proper per-customer register in one pass.

Turning a device into a traceable record

Documentation only helps if it's retrievable at the moment you need it — during an incident, an audit, or a simple customer question. Flitz generates print-ready 62×29 mm Brother QL labels with your customer's logo, so every physical device carries a scannable identity. Scan it, and the system resolves the asset: colleagues inside your tenant land directly on the full record, while anyone outside sees a minimal public card — no internal data exposed, no manual lookup required.

This is the difference between "we think we know what's on that laptop" and being able to produce, in seconds, a documented chain from physical device to digital record — precisely the kind of evidence a DSG or contractual audit asks for.

Patch status and vulnerabilities, not just a device list

An inventory that only lists make and model doesn't answer the question regulators and customers actually care about: is this device secure right now? The built-in Action1 integration syncs each customer's managed computers hourly, matching them to existing assets by MAC address and serial number, and pulling in live telemetry — OS, CPU, RAM, IP, last seen.

More importantly for compliance, it surfaces missing critical updates per device and the open-CVE count per customer, with one-click jumps into patch management and remote desktop. That means when a client or auditor asks "how exposed are we right now," you have a live answer instead of a promise to look into it — and a record of when patches were applied if you ever need to demonstrate due diligence after an incident.

Letting customers see and manage their own devices

Transparency cuts both ways. Through the customer portal, clients can filter, search, create, and edit their own devices — which reduces disputes about what's actually deployed and reinforces the DSG principle that data subjects and controllers should have visibility into how their assets and data are handled, rather than relying entirely on a third party's word.

Audit-readiness as a byproduct, not a project

The goal isn't to build a compliance department around IT inventory. It's to make the everyday act of onboarding a laptop, printing a label, or checking patch status automatically leave the kind of trail that satisfies OR bookkeeping expectations, DSG data-protection obligations, and basic contractual due diligence with customers. When inventory, patch status, and documentation live in one customer-scoped system instead of scattered spreadsheets and sticky notes, being audit-ready stops being a fire drill and becomes the default state of the business.

Stop Juggling Tools. Start Running Your Business.

Start your free account in 2 minutes. No credit card required.

Create Free Account