Swiss Post turns Excel chaos into streamlined GRC operations with Swiss GRC

Kevin Helfer - Die Schweizerische Post
Kevin Helfer
Corporate Risk Manager, Swiss Post
Swiss Post achieves GRC clarity with Swiss GRC
About
Swiss Post is one of Switzerland's most important companies and fulfills a public service mandate in the areas of logistics, communication, and finance. As a conglomerate with over 45,000 employees, it combines economic performance with social responsibility and stands for a secure, modern, and reliable infrastructure serving the population and the economy.
Location
Industry
Company size
Solutions
Risk Management
Information Security (ISMS)
Third-Party Risk Management (TPRM)
Internal Control System (ICS)
Data Protection Management
We have a long-standing partnership with Swiss GRC, through which we have established a central and flexible GRC platform. Swiss GRC serves as a trusted partner, guiding, supporting, and empowering Swiss Post throughout its GRC journey. This collaboration enables Swiss Post to not only use the solution, but actively shape and evolve it.

Discover how Swiss Post modernized its GRC processes, moving from manual Excel spreadsheets to an intuitive, digital system with the help of Swiss GRC.

Initial situation

When Swiss Post’s previous Enterprise Risk Management (ERM) solution was discontinued in 2020, the company temporarily managed risks without dedicated tool support, relying instead on Excel spreadsheets and PowerPoint reports. This quickly proved inefficient and error-prone. A modern, robust, and user-friendly GRC solution became essential.

Objectives

As a systemically important company with a public mandate, Swiss Post is subject to strict requirements in the area of Governance, Risk, and Compliance (GRC). In addition to legal regulations such as the Swiss Code of Obligations and the Postal Organization Act, the company’s management is overseen by the Federal Department of the Environment, Transport, Energy and Communications (DETEC), the Postal Regulatory Commission (PostCom), and the Swiss Federal Audit Office (SFAO). The system to be implemented had to fully meet these requirements while being sufficiently flexible to accommodate future regulatory or operational changes.

The goal was to find an intuitive, user-friendly, and easily adaptable platform that could reliably meet all existing needs from the applied risk management and internal control system (ICS) methodology. During the development process, care was taken to avoid unnecessary complexity and to design a solution that could be seamlessly integrated into the existing corporate structure. Furthermore, the solution needed to be scalable to meet future requirements.

Approach and collaboration

Swiss Post began by defining and prioritizing its requirements, then conducting a structured evaluation across multiple providers. Swiss GRC, already known for its work with PostFinance, stood out with a concept that combined strong functionality, flexibility, user-friendliness, and an attractive price-performance ratio.

Swiss Post awarded the contract to Swiss GRC, initially implementing the ERM and ICS modules. Implementation followed a hybrid approach, combining classic project structures with agile, practice-oriented working phases. On the Swiss GRC side, Gentian Ajeti (Head Consulting) and his team coordinated closely with Swiss Post’s corporate risk management function. Thanks to the platform’s intuitive usability, Swiss Post could actively participate and operate independently throughout the rollout.

The success of the first two modules sparked strong interest across the organization, leading to the phased introduction of additional modules, including:

  • Information Security
  • Supplier Security Management (Third-Party Risk Management)
  • Compliance
  • Data Protection
  • Physical Security
  • Audit Management

Project challenges

ChallengeSolution Approach
Complex corporate structure with various business units, group companies, and around 45,000 employeesStep-by-step implementation, close coordination and involvement of departments, targeted prioritization
Heterogeneous requirements and high maturity of the topicsJoint business analysis, agile approach, modular implementation, individual configuration
Need for broad coverage of assurance functionsPlatform-based solution approach with high scalability and flexibility

Key results and impact

With the introduction of the GRC Toolbox, Swiss Post was able to establish a central GRC platform that provides significant added value to the various assurance functions. The modular architecture enables a precise mapping of individual, subject-specific requirements and seamless integration of the solution into the complex corporate structure. Processes are documented transparently and traceably, and responsibilities are clearly assigned. In this way, the GRC toolbox makes a significant contribution to enabling Swiss Post’s assurance functions to perform their tasks efficiently, effectively, and transparently.

In the long-standing collaboration, Swiss GRC is perceived not merely as a software provider, but as a reliable and committed partner. What particularly distinguishes the cooperation with Swiss GRC is not only the technical support, but also the active enablement of Swiss Post to work independently with the GRC toolbox and even further develop it themselves. Thanks to its intuitive usability, minor adjustments and enhancements can be made in-house, without long development cycles or external dependencies.

Similar stories

Want to know more about our solutions?

Comprehensive digitalization of your GRC processes with a tool that is tailored to your governance, risk and compliance requirements.

Swiss GRC | Switzerland (HQ) | Germany | UK | UAE