You deploy AI.
Can you take responsibility for it?
Five disciplines decide whether your use of AI stays demonstrably accountable. The AI GRC module of the SwissGRC® Platform covers all of them, completely and connected, from the use case to the model metric.
Who decides, who owns it, who reviews it
Every use case and every model has an accountable owner, a lifecycle and a review cadence. Nothing moves without a decision, no decision without a trail.
See it in the module- Governance principles and controls
- Policies and ethics guidelines
- Roles and accountability
- Provider and third party governance
- Lifecycle management
- Continuous oversight
- Risk based internal AI audits
- AI literacy and training
AI risks assessed, secured, monitored
AI risks run into the same risk register as the rest of your corporate risks, with the same controls, incidents and actions. No separate register, no separate process.
See it in the module- AI risks in the corporate register
- Impact and risk assessments
- Security controls for AI systems
- Integrity of AI models
- Resilience and business continuity
- Threat intelligence and monitoring
Assess once, evidence against every framework
One use case, many obligations. The platform shows per requirement what is met and what remains open. New regulation means a new mapping, not a new data collection.
See it in the module- ISO 42001 management system
- EU AI Act with risk classes
- FINMA expectations
- NIST AI RMF
- OCC model risk management
- SDAIA AI Ethics Principles
- Your own and proprietary frameworks
- Conformity assessments
Personal data in AI processes under control
Training and inference data are the sore point of every AI initiative. Impact assessment, retention and anonymization hang directly off the use case and the model.
See it in the module- Data protection frameworks
- Privacy impact assessments
- Data security controls
- Privacy controls at the model
- Data governance across the data flow
- Retention and anonymization
Model quality measurable, explainable, evidenced
This is where governance meets data science. Accuracy and stability with thresholds, bias analysis and independent validation. A metric becomes evidence.
See it in the module- Transparency and accountability
- Explainability and documentation
- Performance monitoring with thresholds
- Fairness and bias analysis
- Independent validation and calibration
- Model optimization
Trusted by leading organizations
From an AI list
to governance you can evidence
An inventory, a policy and a few assessments are quickly set up. What sets organizations apart is whether they still hold up in operation.
Inventory in spreadsheets, evidence scattered
Anyone keeping AI in spreadsheets knows yesterday's status. Classification, assessments and model metrics live in separate worlds and only come together in the audit.
- Incomplete inventory, shadow AI undetected
- Classification as a case by case call without evidence
- Assessments in documents, model metrics with the specialist team
- Effectiveness evidenced at go live, not in operation
Every AI decision backed by evidence
Use cases, models and tools sit in the inventory as governed objects, with classification, assessments, risks, controls and review dates attached. A status that holds at any time.
- Use cases, models and tools in one lifecycle
- Classification along the EU AI Act, ISO 42001 and NIST AI RMF
- Risks and controls anchored in the real process
- Assessments, audits and validations scheduled and documented
From the use case to the
model metric, in one place
Inventory, classify, assess, monitor. Click through the four views.
Every use case governed and classified
Use case, the tools in use and the models in one lifecycle from request to inactive. From your input the platform derives the risk class, the model class and the resulting obligations, visible per framework.
- Lifecycle from request through review to production
- Tools with criticality, internal or external
- Assessment library from GAIRA to PIA

Risks and controls on the real AI process
The use case is modelled as a process diagram. Models, tools and data flows carry their risks and controls right where they take effect. Gaps in coverage stand out immediately.
- Models, tools and data flows in the diagram
- Risks and controls directly on the process step
- Connected to risk management and ICS

Model quality as a governance metric
Accuracy and stability with threshold, history and ownership. AuROC, Gini and KS become a number that holds in the boardroom, backed by documentation and decision logic.
- Accuracy and stability metrics with thresholds
- Transparency, explainability and model documentation
- Assistant explains metrics in context

Reviews scheduled, history complete
Assessments, audits, validations and calibrations with due date and owner. The history evidences who reviewed what and when, without anyone having to collect documents.
- Due assessments, audits and validations in view
- Complete oversight history per use case
- Evidence on demand for audit and supervision

The delay is not a free pass,
it is your implementation window
The transparency obligations of the EU AI Act have applied since 2 August 2026. The obligations for high risk AI were postponed to December 2027. Build now and you arrive reviewed, not rushed.
Important for planning: The postponed deadlines relieve the conformity assessment, not the foundation. Inventory, classification, roles and evidence have to be in place before that, otherwise a delay turns into a backlog. The EU AI Act deadlines were amended in 2026, please confirm the status that applies to you with your legal team.
Collect once,
evidence against all
The module brings the leading frameworks with it and takes yours on top. One data collection, many forms of evidence.
EU AI Act
Risk classes, roles as provider or deployer and the obligations that follow, per use case.
ISO/IEC 42001
Management system for artificial intelligence, as the structure for policies, controls and audits.
ISO/IEC 42005
Impact assessment for AI systems, as the method behind your impact assessments.
NIST AI RMF
Govern, Map, Measure and Manage as the structure for assessing and steering AI risks.
FINMA 08/2024
Supervisory expectations on governance and risk management when using AI in the financial sector.
OCC Model Risk Management
Established model validation practice, connected to your metrics and calibrations.
SDAIA and MIT AI Risk Repository
Ethics principles and research based risk taxonomies for internationally positioned organizations.
Your own frameworks
Group policies and your own taxonomies are mapped and assessed like any other framework.
Own your AI
without slowing it down
Governance that allows pace. That is what drives adoption in the business and confidence in the boardroom.
Shadow AI becomes visible
A guided request path brings every new use case into the inventory instead of past governance.
Assess once, evidence many times
One data collection, many frameworks: EU AI Act, ISO 42001, NIST AI RMF and your own requirements from the same base.
Governance meets data science
Model metrics, validations and calibrations sit where policies, risks and controls sit.
Audit ready for supervisors and auditors
Classification, assessment, approval and review are recorded with date, person and evidence.
No isolated AI register
AI risks, controls and actions sit in the same catalogue as the rest of your governance, instead of in a silo beside it.
No compliance standstill
Continuous monitoring replaces the one off approval. Drift, deadlines and deviations report themselves.
We show you
the AI GRC module live
In a personal demo we walk you through the entire module: inventory, classification, assessments, process anchoring, model metrics and evidence. On one end to end example from practice, with no preparation needed on your side.
DE
FR