AI Governance, Risk & Compliance

You deploy AI.
Can you take responsibility for it?

Five disciplines decide whether your use of AI stays demonstrably accountable. The AI GRC module of the SwissGRC® Platform covers all of them, completely and connected, from the use case to the model metric.

EU AI ActISO 42001NIST AI RMFFINMA 08/2024
Governance & Oversight Governance& Oversight Risk & Security Management Risk & SecurityManagement Compliance & Regulatory Frameworks Compliance Data Protection & Privacy Data Protection& Privacy Performance & Transparency Performance
01/05 Governance & Oversight BasisISO 42001·EU AI Act Art. 4·FINMA 08/2024

Who decides, who owns it, who reviews it

Every use case and every model has an accountable owner, a lifecycle and a review cadence. Nothing moves without a decision, no decision without a trail.

See it in the module
  1. Governance principles and controls
  2. Policies and ethics guidelines
  3. Roles and accountability
  4. Provider and third party governance
  5. Lifecycle management
  6. Continuous oversight
  7. Risk based internal AI audits
  8. AI literacy and training
02/05 Risk & Security Management BasisNIST AI RMF·ISO 42005·ISO 27001

AI risks assessed, secured, monitored

AI risks run into the same risk register as the rest of your corporate risks, with the same controls, incidents and actions. No separate register, no separate process.

See it in the module
  1. AI risks in the corporate register
  2. Impact and risk assessments
  3. Security controls for AI systems
  4. Integrity of AI models
  5. Resilience and business continuity
  6. Threat intelligence and monitoring
03/05 Compliance & Regulatory Frameworks PrincipleOne mapping·Gap view per requirement·Evidence on demand

Assess once, evidence against every framework

One use case, many obligations. The platform shows per requirement what is met and what remains open. New regulation means a new mapping, not a new data collection.

See it in the module
  1. ISO 42001 management system
  2. EU AI Act with risk classes
  3. FINMA expectations
  4. NIST AI RMF
  5. OCC model risk management
  6. SDAIA AI Ethics Principles
  7. Your own and proprietary frameworks
  8. Conformity assessments
04/05 Data Protection & Privacy BasisSwiss FADP·GDPR Art. 35·ISO 27701

Personal data in AI processes under control

Training and inference data are the sore point of every AI initiative. Impact assessment, retention and anonymization hang directly off the use case and the model.

See it in the module
  1. Data protection frameworks
  2. Privacy impact assessments
  3. Data security controls
  4. Privacy controls at the model
  5. Data governance across the data flow
  6. Retention and anonymization
05/05 Performance & Transparency BasisEU AI Act Art. 13·OCC 2011-12·SR 11-7

Model quality measurable, explainable, evidenced

This is where governance meets data science. Accuracy and stability with thresholds, bias analysis and independent validation. A metric becomes evidence.

See it in the module
  1. Transparency and accountability
  2. Explainability and documentation
  3. Performance monitoring with thresholds
  4. Fairness and bias analysis
  5. Independent validation and calibration
  6. Model optimization

Trusted by leading organizations

What matters

From an AI list
to governance you can evidence

An inventory, a policy and a few assessments are quickly set up. What sets organizations apart is whether they still hold up in operation.

The common starting point

Inventory in spreadsheets, evidence scattered

Anyone keeping AI in spreadsheets knows yesterday's status. Classification, assessments and model metrics live in separate worlds and only come together in the audit.

  • Incomplete inventory, shadow AI undetected
  • Classification as a case by case call without evidence
  • Assessments in documents, model metrics with the specialist team
  • Effectiveness evidenced at go live, not in operation
With the SwissGRC® Platform

Every AI decision backed by evidence

Use cases, models and tools sit in the inventory as governed objects, with classification, assessments, risks, controls and review dates attached. A status that holds at any time.

  • Use cases, models and tools in one lifecycle
  • Classification along the EU AI Act, ISO 42001 and NIST AI RMF
  • Risks and controls anchored in the real process
  • Assessments, audits and validations scheduled and documented
The AI GRC module at a glance

From the use case to the
model metric, in one place

Inventory, classify, assess, monitor. Click through the four views.

Inventory and classification

Every use case governed and classified

Use case, the tools in use and the models in one lifecycle from request to inactive. From your input the platform derives the risk class, the model class and the resulting obligations, visible per framework.

  • Lifecycle from request through review to production
  • Tools with criticality, internal or external
  • Assessment library from GAIRA to PIA
AI use case Corporate Loans with lifecycle, tools and EU AI Act classification in the SwissGRC Platform
Anchored in the process

Risks and controls on the real AI process

The use case is modelled as a process diagram. Models, tools and data flows carry their risks and controls right where they take effect. Gaps in coverage stand out immediately.

  • Models, tools and data flows in the diagram
  • Risks and controls directly on the process step
  • Connected to risk management and ICS
Process diagram of an AI based lending process with linked risks and controls in the SwissGRC Platform
Performance and transparency

Model quality as a governance metric

Accuracy and stability with threshold, history and ownership. AuROC, Gini and KS become a number that holds in the boardroom, backed by documentation and decision logic.

  • Accuracy and stability metrics with thresholds
  • Transparency, explainability and model documentation
  • Assistant explains metrics in context
AI model with accuracy and stability metrics, thresholds and model documentation in the SwissGRC Platform
Continuous oversight

Reviews scheduled, history complete

Assessments, audits, validations and calibrations with due date and owner. The history evidences who reviewed what and when, without anyone having to collect documents.

  • Due assessments, audits and validations in view
  • Complete oversight history per use case
  • Evidence on demand for audit and supervision
Oversight and monitoring with due assessments, audits, model validations and a complete history in the SwissGRC Platform
Built on recognized frameworks, from classification through to the conformity evidence.
EU AI Act ISO 42001 NIST AI RMF FINMA 08/2024
Regulation

The delay is not a free pass,
it is your implementation window

The transparency obligations of the EU AI Act have applied since 2 August 2026. The obligations for high risk AI were postponed to December 2027. Build now and you arrive reviewed, not rushed.

2 February 2025
In force
Prohibited AI practices and AI literacy of staff
2 August 2025
In force
Obligations for general purpose AI models (GPAI)
2 August 2026
In force
Transparency obligations under Art. 50, including labelling of AI content
2 December 2027
Pending
Stand alone high risk AI under Annex III
2 August 2028
Pending
High risk AI embedded in regulated products under Annex I

Important for planning: The postponed deadlines relieve the conformity assessment, not the foundation. Inventory, classification, roles and evidence have to be in place before that, otherwise a delay turns into a backlog. The EU AI Act deadlines were amended in 2026, please confirm the status that applies to you with your legal team.

Frameworks and standards

Collect once,
evidence against all

The module brings the leading frameworks with it and takes yours on top. One data collection, many forms of evidence.

European Union

EU AI Act

Risk classes, roles as provider or deployer and the obligations that follow, per use case.

International

ISO/IEC 42001

Management system for artificial intelligence, as the structure for policies, controls and audits.

International

ISO/IEC 42005

Impact assessment for AI systems, as the method behind your impact assessments.

United States

NIST AI RMF

Govern, Map, Measure and Manage as the structure for assessing and steering AI risks.

Switzerland

FINMA 08/2024

Supervisory expectations on governance and risk management when using AI in the financial sector.

Financial sector

OCC Model Risk Management

Established model validation practice, connected to your metrics and calibrations.

Further

SDAIA and MIT AI Risk Repository

Ethics principles and research based risk taxonomies for internationally positioned organizations.

Your requirements

Your own frameworks

Group policies and your own taxonomies are mapped and assessed like any other framework.

Advantages and benefits

Own your AI
without slowing it down

Governance that allows pace. That is what drives adoption in the business and confidence in the boardroom.

Shadow AI becomes visible

A guided request path brings every new use case into the inventory instead of past governance.

Assess once, evidence many times

One data collection, many frameworks: EU AI Act, ISO 42001, NIST AI RMF and your own requirements from the same base.

Governance meets data science

Model metrics, validations and calibrations sit where policies, risks and controls sit.

Audit ready for supervisors and auditors

Classification, assessment, approval and review are recorded with date, person and evidence.

No isolated AI register

AI risks, controls and actions sit in the same catalogue as the rest of your governance, instead of in a silo beside it.

No compliance standstill

Continuous monitoring replaces the one off approval. Drift, deadlines and deviations report themselves.

Contact and demo

We show you
the AI GRC module live

In a personal demo we walk you through the entire module: inventory, classification, assessments, process anchoring, model metrics and evidence. On one end to end example from practice, with no preparation needed on your side.