System-Enabled, Cross-Functional Risk Management at Visana with Swiss GRC

Portrait of a man in a business suit with glasses in front of a bright background, Head of Risk and Quality Management at Visana.
René Najer
Head of Risk and Quality Management, Visana
About
Visana is one of the leading Swiss health and accident insurance providers. The company offers health, accident, supplementary, and property insurance for both private and corporate customers. Overall, Visana serves around 900,000 private customers and approximately 17,000 corporate clients. Its headquarters are located in Bern, with around 1,400 employees working in approximately 50 agencies across Switzerland. The total premium volume exceeds CHF 4 billion.
Location
Industry
Company size
Solutions
Risk Management
Information Security (ISMS)
Third-Party Risk Management (TPRM)
Internal Control System (ICS)
Data Protection Management
Contract Management
Compliance
The development and expansion phase associated with the implementation of the Swiss GRC Toolbox was intensive. Significant progress was achieved within a short period of time. The prerequisites for a system-supported, transparent, and cross-functional risk management framework have now been established.

Discover how Visana implemented the Swiss GRC Toolbox to establish a system-supported, transparent, and cross-functional risk management framework.

Initial situation and objectives

Visana was faced with the challenge of harmonizing its GRC landscape and mapping it within a central system solution. A key objective was to strengthen the interaction between existing governance and control systems and to consolidate the previously heterogeneous storage structures into a unified environment.

With the implementation of the Swiss GRC Toolbox, a central platform was established on which all risk-relevant information is systematically captured, managed, and documented. Cross-functional collaboration improved significantly thanks to standardized folder structures, clear user guidance, and transparent processes.

Visana pursued the goal of further developing its GRC system. The focus was on replacing parallel data repositories and introducing largely automated processes for risk assessment. The implementation of an annual cut-off was also important in order to enable transparent and system-supported comparisons.

Implementation and collaboration

Following an evaluation, Visana decided to choose Swiss GRC. The decisive factors were the user-friendliness and clarity of the GRC Toolbox, the high level of flexibility in integrating existing processes, and the future-proof architecture of the solution.

In collaboration with the Swiss GRC consulting team, the new GRC modules were gradually implemented and successfully put into operation.

Challenges and lessons learned

ChallengesSolution approach
Different GRC requirementsModular implementation and iterative expansion
Complexity of regulatory requirementsUse of configured standards and customizable templates

Key outcomes and benefits

Holistic GRC on one platform: All core GRC processes are integrated into a single solution and documented in a traceable and auditable manner.

Traceability and audit readiness: Clear structures and system-supported processes enable easier audits and reviews.

Scalability: The modular design allows flexible further development according to evolving needs.

Increased efficiency: Standardization and digitalization of previously separate processes.

Similar stories

Want to know more about our solutions?

Comprehensive digitalization of your GRC processes with a tool that is tailored to your governance, risk and compliance requirements.

Swiss GRC | Switzerland (HQ) | Germany | UK | UAE