The CP/CPS of SwissSign Gold Certificate state that:
5.1 "...Two identical clones of the SwissSign Gold CA keys are stored off line in Swiss bank safe deposit boxes."
They even put in their Why SwissSign page as their first "selling point":
The «master key» for our certificates is stored safely at two Swiss banks
Is this common among CAs? Isn't a concern that the private key is printed somewhere? Shouldn't they be inside a HSM without a way to extract it?