About us

Software for Governance, Risk & Compliance. In use worldwide.

Swiss GRC builds an integrated platform for GRC, BPM and CLM. More than 250 organisations worldwide work with it, supported by our own entities on the ground and by more than 120 specialists within the group.

Global Reach, Local Excellence
250+Organisations work with our platform
500+Completed projects
120+Specialists across the group
6Entities of our own in Europe, MEA and APAC
SWISS GRC DAY: Swiss GRC on stage in front of the audience
SWISS GRC DAY Where governance, risk and compliance meet for success
Who we are

Three sentences we
hold ourselves to.

Our goal, vision and mission are not a poster on the wall. They decide which features we build and which we do not.

Our goal
Enable organisations to build trust and resilience for sustainable success.

Trust does not come from documents. It comes from decisions that stay traceable. That is why we keep risks, controls, measures and contracts on one shared data foundation instead of managing them in separate tools.

One data foundation for every GRC discipline Every assessment with evidence and history Ready to answer supervisors and auditors
Our vision
Be the world’s leading and most trusted partner for integrated management solutions.

Trustworthiness cannot be claimed, it shows over years. Our clients stay because releases are predictable, because the people they talk to master the domain themselves, and because we hold ourselves to the same standards we map for them.

Certified to ISO 27001, ISO 27017 and ISO 27701 Our own entities instead of pure sales partners A roadmap discussed openly with our community
Our mission
Deliver excellent and innovative software for GRC, BPM and CLM.

Product management and engineering are in house, not with suppliers. Artificial intelligence is part of the architecture and not a button at the edge, from support inside the modules to a dedicated module for AI governance.

GRC, BPM and CLM on one platform Engineering and product management in house An AI-native architecture instead of retrofitted features
Our history

The idea is older
than the company.

A security management solution grew into a complete GRC platform over the years. Every year is clickable.

Origins 1989 to 2012 Build up 2016 to 2020 Growth 2022 to today
1989OriginsWhere the idea comes from
  1. Swiss Infosec AG is founded

    Reto Zbinden, a lawyer and today the chair of our board of directors, founds Swiss Infosec AG. Its consulting practice is where the idea behind the later toolbox comes from.

1993OriginsThe first tool of our own
  1. The ISMS tool is developed

    A prototype for managing information security is built because no solution on the market meets the requirements. The first version goes live the same year.

2005OriginsFrom tool to product
  1. ISMS Toolbox

    The tool is rebuilt as a web application. For the first time organisations run their security management themselves, without a consulting mandate in the background.

2012OriginsFrom security to GRC
  1. GRC Toolbox v1

    Modules such as ICS, ERM and policy management are added. The security management solution becomes a complete GRC solution.

2016Build upThe year we were founded
  1. Swiss GRC AG is founded

    Swiss GRC AG is founded to drive the development of the GRC software consistently: our own team, our own roadmap, our own responsibility. Contract management is added as a new module.

2017Build upFrom clients to a community
  1. The first SWISS GRC DAY

    The first SWISS GRC DAY takes place under the motto where governance, risk and compliance meet for success. The event becomes the annual meeting point for our clients, partners and prospects.

2019Build upTraining our own talent
  1. Swiss GRC AG becomes a training company

    We are approved to train software developers and ICT specialists under the Swiss apprenticeship system. Since then we train professionals ourselves instead of only recruiting them.

2020Build upThird generation
  1. GRC Toolbox v3

    The third generation of the platform is released. Predefined standard reports and dashboards shorten the path from data entry to insight.

2022GrowthProving our own standards
  1. Triple ISO certification

    Certification to ISO 27001 for the ISMS, ISO 27017 for the cloud and ISO 27701 for privacy. We hold ourselves to the standards we map for our clients.

2024GrowthThree milestones
  1. Swiss GRC Germany GmbH

    An entity of our own for the German market, with our own team instead of sales partners.

  2. Strong Contender in the SPARK Matrix

    Quadrant Knowledge Solutions positions Swiss GRC in the GRC platforms category.

  3. Top Company seal

    The kununu seal is based on the ratings of our own employees.

2025GrowthInternational recognition
  1. GRC Product of the Year

    At the Risk Technology Awards 2025 by Risk.net, Swiss GRC is named GRC Product of the Year, against the established global vendors.

  2. Leader in the 2025 SPARK Matrix

    QKS Group positions Swiss GRC as a Leader, for GRC platforms and for IT risk management.

2026GrowthWhere we stand today
  1. An AI-native platform

    Artificial intelligence becomes part of the architecture rather than an add-on at the edge: from support inside the modules to a dedicated module for AI governance and AI risk management.

Recognition

How analysts and
trade media rate us.

Independent analysts, trade media and clients assess our platform regularly. A selection of their findings.

Risk.net
Product of the Year 2025

Best GRC product of the year

At the Risk Technology Awards 2025 by Risk.net, one of the most respected publications worldwide for risk management, compliance and financial technology, Swiss GRC was named GRC Product of the Year.

Before us the title was held by names such as MetricStream, SAI360 and IBM OpenPages.
Leadership Status

Leader in the 2025 SPARK Matrix

Positioned as a Leader by QKS Group, both for GRC platforms and for IT risk management.

Representative Vendor

In the GRC Landscape Report

Forrester lists Swiss GRC in its GRC Landscape Report repeatedly, so far as the only company from the DACH region.

Market Leader

Alongside global market leaders

BARC features Swiss GRC alongside global market leaders in governance, risk and compliance.

Best of Technology 2025

Rated “Excellent”

WirtschaftsWoche rated our third-party risk management solution “Excellent” in 2025.

Representative Vendor

In the RMIS Panorama

The French risk management association AMRAE has listed Swiss GRC in its RMIS Panorama continuously since 2024.

Clients’ Favorite

Highly rated by clients

On the Gartner Digital Markets platforms our solutions receive high client ratings worldwide.

Our team

People who do not just
sell GRC but understand it.

Many of us come from consulting, audit or supervision and know our clients’ questions from our own practice.

Choose a group
Executive Management
Besfort Kuqi
Besfort Kuqi
Founder & CEO
Daniel Arnold
Daniel Arnold
Chief Product Officer (CPO)
Fari Ganji
Fari Ganji
Chief Information Officer (CIO)
Gentian Ajeti
Gentian Ajeti
Chief Customer & Commercial Officer (CCO)
Yahya Mohamed Mao
Yahya Mohamed Mao
Chief Marketing Officer (CMO)
Team Leads
Natalie Metry
Natalie Metry
Head Admin, HR & Finance
Nikolai Tsenov
Nikolai Tsenov
Head Solutions & Innovation
Johannes Weiser
Johannes Weiser
Head Customer Success & Support
Matthias Graf
Matthias Graf
Head Software Engineering
Michael Niedermann
Michael Niedermann
Head Consulting
Shankar Omandhu
Shankar Omandhu
Head Consulting MEA & APAC
Bujar Surdulli
Bujar Surdulli
AI Transformation Manager
Entities and regions
Dr. Fino Scholl
Dr. Fino Scholl
Managing Director, Swiss GRC Germany GmbH
Rajeev Dutt
Rajeev Dutt
General Manager, Swiss GRC Dubai, MEA & APAC
Gentian Ajeti
Gentian Ajeti
Managing Director, Swiss GRC Kosovo L.L.C.
Board of Directors
Reto Zbinden
Reto Zbinden
Chair of the Board of Directors
Besfort Kuqi
Besfort Kuqi
Board member, Founder & CEO
Advisory Board
Prof. Dr. Stefan Hunziker
Prof. Dr. Stefan Hunziker
Advisory Board
Anuschka Küng
Anuschka Küng
Advisory Board
Dr. Patrick Wegmann
Dr. Patrick Wegmann
Advisory Board
Locations

Local teams, worldwide.

Six entities of our own in Europe, the Middle East and Asia. Click a location and the globe turns to it.

Lucerne HeadquartersSwiss GRC AGSwitzerland
MunichSwiss GRC Germany GmbHGermany
LondonSwiss GRC UKUnited Kingdom
PristinaSwiss GRC L.L.C.Kosovo
DubaiSwiss GRC MEA/APACUnited Arab Emirates
MumbaiSwiss GRC IndiaIndia
Working at Swiss GRC

Short paths,
real responsibility.

Our clients are banks, insurers, public authorities and industrial companies. That demands precision and makes your own work visible.

EngineeringLucerne, a five minute walk from the station
Working hours40 hour week, flexible hours, working from home possible
TrainingA certified training company since 2019 for software developers and ICT specialists
  • 01

    Deciding instead of escalating

    Flat hierarchies, short paths. Decisions are made where the expertise sits, not four levels above it.

  • 02

    Responsibility from the first project

    Whoever joins us works on client solutions right away and takes on an area that grows with their own experience.

  • 03

    A demanding domain

    Regulation, risk and processes in one product. If you enjoy connections, you will find work here that is not exhausted after two years.

  • 04

    Training in house

    We have trained our own professionals since 2019 and invest in development instead of turnover. Asking questions counts as a strength here.

  • 05

    Salaries in line with the market

    Transparently justified. Shared goals only work on fair terms.

  • 06

    An international setting

    Projects and colleagues in Europe, the Middle East and Asia, with our own entities on the ground.

Careers at Swiss GRC

Open roles and
speculative applications

We are continuously looking for specialists in engineering, consulting, product and customer success. If none of the openings fits, a speculative application is expressly welcome.

Nikolai Tsenov

Head Solutions & Innovation, Swiss GRC

Nikolai Tsenov is an experienced expert in consulting, product and project management, business development, and sales with over 20 years of industry experience. His areas of expertise include risk and performance management, compliance, fraud detection and prevention, AML, and data analytics.

At Swiss GRC, he heads the Solutions & Innovation division. He was instrumental in the further development of the Third Party Risk Management (TPRM) module, for which Swiss GRC was awarded the Best of Technology Award 2025 by WirtschaftsWoche. He also played a leading role in the development of the AI GRC module, which helps companies manage AI-related risks.

With his strong entrepreneurial spirit and passion for innovation, he has received numerous awards, including the FinTech Breakthrough Awards in the categories Best Company for Transaction Security and Best Platform for Predictive Analytics (2022 and 2020). He also received the 2016 Banking IT Innovation Award from the University of St. Gallen for his concept of the Finnova Analytical Framework.

Dr. Patrick Wegmann

Advisory Board

Dr. Patrick Wegmann is Chairman of the Board of Directors and COO of Lifetec AG, based in Dietikon ZH, a full-service provider for operational first aid and integral risk management. He studied and obtained his doctorate in financial market theory at the University of St. Gallen and has more than 20 years of software and consulting experience in risk management. In 1999, Dr. Patrick Wegmann co-founded Avanon AG, a leading software provider for operational risk management. After the acquisition of Avanon AG by Thomson Reuters, he was Head of Product Business for Enterprise Risk at Thomson Reuters until the beginning of 2019. Patrick Wegmann is a lecturer in risk management at the University of Basel, the Lucerne School of Business, the University of Applied Sciences Northwestern Switzerland, Kalaidos UAS and the Institute of Financial Planning.

Anuschka Küng

Advisory Board

Anuschka Küng has been a partner in the Acons Group since 2005 and has been the managing director of Acons Governance & Audit AG since 2007. She accompanies mandates from various industries in the implementation of the requirements for corporate governance and corporate monitoring. In the area of internal auditing, her client mandates include the management of internal auditing (outsourcing), auditing or consulting activities (co-sourcing) and the performance of quality assessments. In the areas of risk management, ICS, compliance management and process management, she oversees the implementation or further development of corresponding requirements such as the performance of risk assessments (ISO 31000, PS 890, ISO 9001), the design of specific requirements for risk control, the assessment of process control or the ICS, as well as the design of compliance management. She also works as a risk manager for an industrial company, responsible for GL/VR reporting. Anuschka Küng worked for several years as a Risk & Compliance Officer for an asset manager of collective capital investments and is now a member of the Board of Directors. As a lecturer, she teaches at various universities of applied sciences and institutes on the topics of corporate governance, risk management/ICS and internal auditing.

Prof. Dr. Stefan Hunziker

Advisory Board

Prof. Dr Stefan Hunziker is Professor of Enterprise Risk Management and Internal Control Systems at the Lucerne School of Business, Institute of Financial Services Zug IFZ. He is a member of the Institute’s Executive Board and heads the Risk & Compliance Management Competence Centre at IFZ. For more than 15 years he has been committed to further developing risk management in practice, always considering current scientific findings. Stefan Hunziker leads the continuing education programmes CAS Governance, Risk and Compliance (CAS GRC) and the specialist course Corporate Risk Management at the Lucerne University of Applied Sciences and Arts. As head of the MSc International Financial Management, he also trains international students in risk management and internal control. Prof. Hunziker has various teaching assignments in the areas of risk management, internal control systems and financial management. He coaches and advises organisations on the establishment and operation of risk management. Stefan Hunziker is the author of numerous books and articles, especially on holistic risk management and internal control systems. He is heavily involved in practice-oriented research and leads major federally funded projects (innosuisse). He regularly gives presentations at national and international conferences and is thus in close contact with the international risk community.

Besfort Kuqi

CEO & Board of Directors

Besfort Kuqi is the founder and Chief Executive Officer of Swiss GRC AG. He has been involved in the topics of Governance, Risk & Compliance (GRC) for over 10 years. His focus is on the digitalisation, integration and optimisation of management and control systems in companies and organisations. Specifically, Besfort Kuqi deals with issues around risk management, internal control systems (ICS) and compliance and security management. As a Project Management Professional (PMP), Besfort Kuqi supports nationally and internationally active companies and organisations in developing, implementing and presenting company-specific analyses and concepts to solve organisational and technical problems in GRC processes. Besfort Kuqi has co-developed the Swiss GRC Toolbox – a software solution for the systematic mapping and management of the many GRC disciplines – since its inception, he has successfully introduced it at many companies and organisations and has thus contributed to higher efficiency, transparency and acceptance in matters of management and control systems.

Reto Steinmann

Board of Directors

Reto Steinmann, Member of the Executive Board at Swiss Infosec AG and Member of the Board of Directors at Swiss GRC AG, holds a degree in Computer Science HF with a specialisation in Business Informatics. He deepened his knowledge in information security by successfully completing the MAS Information Security at the Lucerne University of Applied Sciences and Arts. Through his various activities as a system engineer, network and security engineer, project manager and IT security officer, he has over 20 years of experience in the areas of information technology, information and IT security as well as valuable know-how in project management. Reto Steinmann works for numerous clients in various industries. He works on mandates in the areas of risk management, information and IT security, setting up and operating information security management systems (ISMS) according to ISO 27001 and security audits. He also regularly takes on mandates as an external security officer. His comprehensive expert know-how and his practice-oriented approach are highly appreciated by his clients, true to the principle that security must be realisable and liveable in practice!