›

BENEFIT’s Journey to Combined Assurance with Swiss GRC

Mansoor AlAlwan
Chief Audit Executive, The BENEFIT Company
About
The BENEFIT Company is the Kingdom of Bahrain’s leading provider of electronic financial transactions and fintech services, operating at the core of the national financial infrastructure. Its mandate includes enabling secure, interoperable, and innovative transaction services that support the financial ecosystem of Bahrain.
Location
Industry
Company size
Solutions
Risk Management
Information Security (ISMS)
Business Continuity Management (BCM)
Compliance
Swiss GRC provided exactly what we needed: a flexible, scalable, and highly configurable platform capable of supporting our assurance functions in a unified manner. The collaboration has been instrumental in modernizing our governance and audit capabilities and in achieving full compliance with the Global Internal Audit Standards 2024. The platform is now a key component of our organizational transformation.

The BENEFIT Company has significantly strengthened its governance, risk, and compliance (GRC) capabilities through the implementation of Swiss GRC’s integrated platform. What began as a strategic exploration evolved into a transformation towards true Combined Assurance, enhancing collaboration, automation, and audit excellence across the organization.

Background and strategic starting point

In Q4 2023, BENEFIT launched a strategic initiative driven by the Cyber Risk Committee: to explore Governance, Risk, and Compliance (GRC) solutions and implement a platform capable of automating processes and improving collaboration across assurance functions.

The initiative was closely aligned with Internal Governance Committee discussions, bringing together stakeholders from Compliance, Internal Audit, Business Continuity, Risk Management, Information Security, and Legal. The objective was clear: move away from fragmented and manual processes towards a more integrated and transparent governance framework.

To inform the decision-making process, BENEFIT assessed GRC providers within Bahrain, leveraging insights from organizations that had already implemented such solutions locally.

Challenges Along the Way

The evaluation process revealed two key challenges:

Cost vs. Organization Size
Many GRC solutions were designed for large enterprises with extensive assurance teams, resulting in cost structures that were not aligned with BENEFIT’s organizational size.

Limited Customization
Available solutions lacked the flexibility to adapt to the specific operational and regulatory context in Bahrain, making it difficult to tailor them to BENEFIT’s needs.

These challenges highlighted the need for a solution that could balance sophistication with flexibility and scalability.

A turning point

In January 2024, BENEFIT attended a two-day GRC event in Dubai, where multiple providers presented their solutions. During this event, the team met Rajeev Dutt from Swiss GRC.

What stood out was a simple but decisive question:
«What do you need? What are your expectations?»

This shifted the conversation from product capabilities to organizational requirements.

The immediate question from BENEFIT was:
«Can Swiss GRC be customized to our needs, processes, and budget?»

The answer was a confident «Yes.» From that moment, the foundation for the partnership was established.

Selection and implementation

Following a thorough evaluation and internal alignment process, BENEFIT recommended Swiss GRC to its Board Committees. After approval, the implementation and licensing agreement was signed, and the rollout began. A key differentiator was Swiss GRC’s ability to provide deep customization without impacting other customers. This enabled BENEFIT to design workflows tailored precisely to its internal processes while maintaining a consistent governance structure.

Implementation Approach and Phased Rollout

The implementation was structured in phases to ensure a controlled and sustainable rollout:

Phase 1 – Internal Audit
Internal Audit was the first function to go live, with fully automated workflows aligned to the Global Internal Audit Standards 2024.

Phase 2 – Compliance
Compliance requirements were finalized and prepared for deployment, ensuring regulatory processes would be integrated into the broader governance framework.

Phase 3 – Expansion Across Functions
The platform was further extended to include:

  • Policy Management
  • Risk Management
  • Business Continuity
  • Legal
  • Information Security

One of the platform’s standout capabilities, which will be further leveraged in the future, is its integration potential, providing flexibility for continued expansion and system connectivity.

Achievements and Global Recognition

As part of the implementation, BENEFIT’s Internal Audit function aligned its methodology and digital workflows with the Global Internal Audit Standards (GIAS) 2024, issued by the Institute of Internal Auditors (IIA), the globally recognized authority for the internal audit profession.

An independent external assessment confirmed full conformance, leading to the Internal Audit team receiving the Full Compliance Award from the IIA during the 2025 Audit, Anti-Fraud, and Information Technology Conference in Abu Dhabi.

The award was accepted on 20 November 2025 by Mansoor AlAlwan, Chief Audit Executive, on behalf of The BENEFIT Company. This achievement, acknowledged by representatives of the IIA, ISACA, and ACFE, underscores BENEFIT’s leadership in governance, audit quality, and professional practice. It also reflects the strength of BENEFIT’s operational readiness and the maturity of its internal control environment. Swiss GRC’s platform played an essential role in enabling the digital execution of these standards, providing the structural and functional capabilities required to meet internationally recognized benchmarks.

Key outcomes and benefits

Through the implementation of Swiss GRC’s technology platform, The BENEFIT Company has achieved measurable improvements across its assurance functions, strengthening both operational effectiveness and organizational governance maturity.

Customization and Flexibility
Swiss GRC adapted seamlessly to BENEFIT’s size, processes, and budget, enabling a tailored implementation.

Enhanced Collaboration Across Functions
The platform strengthened coordination between assurance functions, supporting a true Combined Assurance approach.

Global Recognition and Standards Alignment
Full compliance with international audit standards was independently validated and recognized on a global stage.

Similar stories

Want to know more about our solutions?

Comprehensive digitalization of your GRC processes with a tool that is tailored to your governance, risk and compliance requirements.