Compliance Management

When the regulator asks,
how fast can you answer?

Assign, implement and evidence regulatory obligations.
From the regulation to the evidence, in one system.

Regulatory inboxillustrativeImplementation2 Aug 2026EU AI Actnew5 units affected, 22 obligations derived41%17 Jan 2025DORA6 units affected, 31 obligations derived87%17 Oct 2024NIS24 units affected, 18 obligations derived79%1 Jan 2024FINMA Circular 2023/13 units affected, 9 obligations derived100%1 Sep 2023Revised Swiss FADP12 units affected, 24 obligations derived100%For every line it takes minutes to evidence who is affected, who implements and what is met. Regulatory inboxillustrative2 Aug 2026new41%EU AI Act5 units, 22 obligations17 Jan 202587%DORA6 units, 31 obligations17 Oct 202479%NIS24 units, 18 obligations1 Jan 2024100%FINMA Circular 2023/13 units, 9 obligations1 Sep 2023100%Revised Swiss FADP12 units, 24 obligationsFor every line it takes minutes to evidence who isaffected, who implements and what is already met.

Trusted by leading organisations

What makes the difference

From the known regulation
to the evidenced obligation

Knowing the regulation is the craft. What sets a function apart is whether every single obligation has an owner, a control and current evidence.

The common starting point

The obligations register lives in Excel

Regulations on a drive, obligations in a spreadsheet, evidence in the inbox. When a new rule arrives, the search starts over.

  • Regulations and obligations spread across sheets and folders
  • Nowhere does it say who owns an obligation
  • Policies, training and whistleblowing run in separate places
  • A supervisory request triggers days of manual work
With the SwissGRC® platform

One obligations register, connected end to end

Regulation, chapter, obligation, owner, control and evidence sit in one model. The state of compliance can be queried at any time.

  • Regulations broken down to the single obligation
  • Every obligation with owner, due date and organizational unit
  • Controls, policies and training attached to the obligation
  • Whistleblowing, incidents and cases in the same network
The platform

Compliance the way
it works day to day

Five views from the compliance module of the SwissGRC® platform, along the chain of regulation, assessment, risk, incident and report.

Obligations register

Every regulation down to the single obligation

Regulations are held by regulatory authority, topic and jurisdiction and broken down into chapters, subchapters and individual obligations. Every obligation carries an owner.

  • Regulatory authority, topic and jurisdiction per regulation
  • Breakdown into chapters, subchapters and obligations
  • Regulatory content entered manually or via a content provider
  • Ownership, due date and organizational unit on the obligation
Regulations and obligations in the SwissGRC® platform
Assessment

Maturity per requirement, with evidence

Standards and regulations are assessed clause by clause, with maturity, findings and attached evidence. Progress stays visible at all times.

  • Assessment along the clause structure of the standard
  • Maturity and compliance state per requirement
  • Findings captured directly on the clause
  • Evidence attached at the point of assessment
Compliance assessment in the SwissGRC® platform
Risk and control

Compliance risk rated and monitored

Compliance risks are rated by category, organizational unit and regulatory topic and linked to controls and actions. The state of remediation reads at a glance.

  • Rating by category, unit and regulatory topic
  • Risk register linked to controls and actions
  • Actions by status, with escalation and due dates
  • Compliance risk map for management and committee
Compliance risk dashboard in the SwissGRC® platform
Case management

From the tip to the closed case file

Breaches, misconduct and suspected fraud are handled as cases, with category, severity, ownership and time of incident. Traceable from detection to resolution.

  • Category, subcategory and severity per case
  • Status from detection through to resolution
  • Ownership and affected organizational unit
  • Link to risk, control and action
Incidents and cases in the SwissGRC® platform
Confidential reporting

A reporting channel that earns trust

A confidential channel guides whistleblowers through the report in three steps, fully anonymous if they choose. The reply channel runs on an access code, without identity.

  • Guided report in three steps, with category selection
  • Anonymous access code for follow-up questions and status
  • No connection data is stored
  • Reports land directly in case management
Confidential reporting portal of the SwissGRC® platform
Built along the common standards and regulations. One obligations register that serves several requirements at once.
ISO 37301 ISO 37001 DORA NIS2 GDPR and FADP AML EU Whistleblower Directive All standards
<
Evidence and oversight

What a compliance system
has to be able to prove

ISO 37301 made compliance management certifiable for the first time. Clause 4.5 requires the identification of compliance obligations, clause 4.6 their risk assessment and clause 8.3 a process for raising concerns. The platform covers exactly these three points.

Identify and assign obligations
Legal, regulatory and contractual requirements as well as internal rules are captured, structured and assigned to an organizational unit. This is the foundation ISO 37301 builds on.
Assess compliance risk
For every obligation the question of likelihood and impact, rated by category, unit and regulatory topic. That is what shows where controls and actions are genuinely needed.
Raise concerns without risk
Switzerland has no general statutory duty to run an internal reporting channel, the corresponding revision of the Code of Obligations was finally rejected in 2020. Groups with entities in the EEA fall under Directive (EU) 2019/1937, and ISO 37301 requires the process regardless.
Evidence policies and training
Policy attestations and mandatory training per role, with date and person. Who confirmed what and when is evidenced, not asserted.
Across GRC
Compliance is strongest where controls, risks
and data sit in the same model.
Advantages

What you get out of it

Not more compliance, but provable compliance. With less manual work.

One obligations register

Every regulation broken down to the single obligation, with authority, topic and jurisdiction. One source instead of five spreadsheets.

Compliance evidenced

For every obligation the control, the evidence and the date. Still readable long after ownership has changed hands.

Regulatory change

New rules are captured, assessed and assigned instead of discovered by accident. The effort stays plannable.

Ownership in the open

Owner, due date and organizational unit on every obligation. Nobody has to ask who is responsible.

Spot concerns early

Whistleblowing reports, incidents and conflicts of interest come together in the same case file. Patterns surface before they get expensive.

Across GRC

Compliance shares the organizational model, controls and actions with risk management, internal control and internal audit. Nothing is maintained twice.

Contact and demo

See our compliance
solution in action

In a personal demo we walk you through the obligations register, the assessment, case management and the reporting channel. You see how a single obligation runs from the regulation all the way to the evidence.