Discover how the Paul Scherrer Institute (PSI) has digitalized, structured, and future-proofed its risk and internal control processes through the use of Swiss GRC’s GRC Toolbox — seamlessly integrated with existing systems and designed to enable consolidated reporting.
Initial situation
As a national research center of international standing, the Paul Scherrer Institute (PSI) is part of the ETH Domain under the supervision of the Swiss Confederation. In this role, the Institute bears responsibility not only for scientific excellence but also for ensuring safe, compliant, and transparent governance.
Before the project began, risk management and internal control activities were largely manual — decentralized spreadsheets and multiple data silos characterized the landscape. The desire for a structured and auditable solution grew steadily within the compliance function. Additionally, the opportunity to leverage synergies with other institutions within the ETH Domain — some of which were already using Swiss GRC solutions — played a role in PSI’s decision to evaluate Swiss GRC.
Objectives
PSI set out to establish a digitalized and structured representation of its internal risk management, compliance, and control processes with the following goals:
- Clearly define responsibilities,
- Enable centralized evaluation and analysis,
- Facilitate joint reporting structures with partner institutions within the ETH Domain.
Implementation and collaboration
At the outset, PSI considered joining an existing GRC Toolbox instance already in use by another ETH Domain institution. However, a joint analysis soon revealed that this approach would involve too many limitations and too little flexibility. In close coordination, it was therefore decided to establish a dedicated instance for PSI, tailored to the specific needs of the Institute.
Today, PSI actively uses the modules for Risk Management (RM), Internal Control System (ICS), Compliance, and IT Security Management. Three of the four modules include targeted customer-specific extensions beyond the standard version. A key element was the technical integration with SAP Signavio, particularly within the ICS module, to leverage synergies between existing process management and the internal control system — thereby avoiding duplicate documentation.
While the implementation of this interface proved more complex than initially anticipated, it was successfully realized through phased deployment and direct, solution-oriented coordination among all stakeholders — professionally guided by Michael Niedermann, Lead Consulting Europe at Swiss GRC.
Challenges and lessons learned
| Challenge | Solution Approach |
|---|---|
| Desire to use an existing instance from another ETH Domain institution | Analysis revealed limitations → decision to implement a dedicated PSI instance |
| Complexity of SAP Signavio integration | Close technical coordination and phased implementation |
| Need for targeted module extensions | Flexible customization at module level |
Key results and added value
With the GRC Toolbox from Swiss GRC, PSI today benefits from:
- A unified platform for risk management, ICS, and compliance,
- Standardized processes with clearly defined responsibilities,
- Seamless technical integration with existing systems, particularly SAP Signavio,
- A solid foundation for internal reporting and future comparability within the ETH Domain.
The solution has significantly enhanced transparency, governance, and efficiency across all relevant areas.
Conclusion
By implementing the GRC Toolbox from Swiss GRC, PSI has laid the foundation for a professional and scalable governance system. The decisive factors for this choice included Swiss GRC’s proven expertise in the public sector and academic environment, the modular architecture allowing for phased implementation, and the company’s strong consulting and implementation capabilities.
The solution supports PSI not only in maintaining internal standards but also in sustainably strengthening institutional resilience — within an organization that combines scientific excellence with a strong commitment to transparent and reliable governance.
DE


