Swiss GRC
Swiss GRC AG is a Swiss software company that sells an AI-native, unified GRC platform (GRC Toolbox) connecting risk, compliance, security, and business processes on a shared data foundation. It serves large enterprises and regulated organizations across financial services, insurance, government, energy, and telecom via direct sales across six global offices.
- Company typePrivate
- Founded2016
- HeadquartersLucerne, Switzerland
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Swiss GRC does
Swiss GRC AG, founded in 2016 and headquartered in Lucerne, Switzerland, develops and sells an AI-native, unified Governance, Risk, and Compliance (GRC) software platform called the GRC Toolbox (marketed as GRC.One). The platform connects risk management, information security (ISMS), third-party risk management, internal controls, business continuity, data protection, AI GRC, internal audit, and operational resilience on a single shared data foundation, with optional adjacent modules for business process management (Process Center) and contract lifecycle management (Contraqto). It is configurable rather than programmable, supports cloud or on-premise deployment, and embeds an AI assistant (Grace AI) that performs natural-language analysis of risks, controls, and processes directly on customer data. The platform is triple ISO certified (ISO 27001, ISO 27017, ISO 27701), named GRC Product of the Year by Risk.net, positioned as a Leader in the 2025 SPARK Matrix for GRC Platform by QKS Group, and listed in the Forrester GRC Platforms Landscape Q4 2025.
The company sells primarily to large enterprises and regulated organizations through direct enterprise field sales coordinated across six wholly-owned offices in Switzerland, Germany, the UK, the UAE, India, and Kosovo, supplemented by regional implementation partners (e.g., OpResONE in North America). The GTM is anchored on a 15-minute Discovery Call followed by tailored demos, supported by owned events (SWISS GRC DAY, GCC GRC Day) and industry conference sponsorships. Revenue is generated through modular subscription licensing of the GRC Toolbox (annual cadence, quote-based, unlimited users per module, cloud or on-premise) plus implementation and consulting services. Named customers include NEQSOL Holding (energy/telecom across 11 countries), Visana, PostFinance, Baloise Group, Swiss Post, Mobiliar, Toa Re, IB Langenthal, the Canton of Uri, the City of Zurich, and The BENEFIT Company (fintech). Pricing is not publicly disclosed; all deals are quote-based and handled by sales specialists.
The company is privately held, founder/owner-operated (Founder & CEO Besfort Kuqi), with an affiliated company Swiss Infosec AG under common beneficial ownership. Headcount is disclosed as 11-50; no institutional investors, parent company, or funding rounds are identified. Strategic priorities evident from 2024-2026 activity include geographic expansion (North America via OpResONE), product breadth expansion (Contraqto CLM, Process Center BPM), ecosystem partnerships (Lawrbit Lextech for legal tech, Volatilis for quantitative risk), and AI capability investment (Grace AI, AI GRC module).
Swiss GRC firmographics
Firmographics- Name
- Swiss GRC
- Legal name
- Swiss GRC AG
- Website
- https://swissgrc.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Swiss GRC AG is a Swiss software company that sells an AI-native, unified GRC platform (GRC Toolbox) connecting risk, compliance, security, and business processes on a shared data foundation. It serves large enterprises and regulated organizations across financial services, insurance, government, energy, and telecom via direct sales across six global offices.
- Ownership category
- akta.pro rank
Swiss GRC industry classification
Industry- Product category
- Governance, Risk, and Compliance (GRC) Software
- NAICS
- Software Publishers (5132), Custom Computer Programming Services (541511)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) Platforms (BPAEAPAA)
- akta.pro secondary industries
- Compliance, GRC Workflow & Audit Automation Platforms (HDAEAHAL), Privacy, Consent & Data Protection Management (BPAEAPAF)
Keywords
Where Swiss GRC is headquartered
LocationHeadquarters
- HQ city
- Lucerne
- HQ country
- Switzerland
- HQ region
- Europe
Offices6 records
Markets served
Swiss GRC business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
Revenue model
- Software Licensing (GRC Toolbox): Swiss GRC generates revenue primarily through licensing its AI-native GRC platform (GRC Toolbox). The platform is sold as modular software covering Risk Management, ISMS, TPRM, ICS, BCM, Data Protection, AI GRC, Internal Audit, and Operational Resilience. BPM (Process Center) and CLM (Contraqto) are separate or bundled modules. The platform is offered as cloud (SaaS) or on-premise deployment with unlimited users per module.
- Professional Services / Implementation Consulting: Swiss GRC provides implementation consulting services through its regional offices and certified partners. Consultants assist with platform configuration, regulatory compliance mapping, and rollout across subsidiaries, as evidenced by NEQSOL Holding and BENEFIT implementations.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise modular subscription — all GRC disciplines on one platform |
Go-to-market motion3 records
Distribution channels2 records
Marketing channels9 records
Swiss GRC product offering
Product offeringCore offering
Swiss GRC develops and sells an AI-native, unified Governance, Risk and Compliance (GRC) platform called GRC Toolbox (marketed as GRC.One) that connects risk, compliance, security, and business processes on a single shared data foundation. The platform is sold as modular software covering Risk Management, Information Security (ISMS), Third-Party Risk Management, Internal Controls, Business Continuity, Data Protection, AI GRC, Internal Audit, and Operational Resilience, and extends through a separate Process Center (BPM) product and Contraqto (CLM) product. It is offered as cloud or on-premise deployment, configurable without coding, with unlimited users per module, and includes Grace AI as an embedded AI assistant.
Product overview
Swiss GRC offers the GRC.One platform (GRC Toolbox), an AI-native unified GRC platform that connects risk, compliance, security, and processes on a single configurable platform. The platform includes core modules for Risk Management, RiskQuant (risk quantification with Monte Carlo simulation), Information Security (ISMS), Third-Party Risk Management, Third-Party Intelligence, Internal Controls, Business Continuity, Data Protection, AI GRC, Internal Audit, and Operational Resilience. It extends through Process Center for AI-native business process management and Contraqto for contract lifecycle management. The platform is configurable rather than programmable, triple ISO certified, runs in cloud or on-premise, with unlimited users per module. Grace AI provides natural language processing for querying GRC data.
Differentiator
Problem solved
Functional benefit
Brands
- Contraqto: Contract Lifecycle Management (CLM) software launched by Swiss GRC in July 2025 for managing contracts throughout their lifecycle.
- GRC Toolbox
- Grace AI
- RiskQuant
- Process Center
Products and services
- GRC.One Platform (GRC Toolbox) AI-native unified GRC platform that connects risk, compliance, security and processes on a single platform. Configurable rather than programmable, web-based, triple ISO certified (ISO 27001, ISO 27017, ISO 27701), with regional server locations, cloud or on-premise deployment, and unlimited users per module. Named 'GRC Product of the Year' by Risk.net and Leader in the 2025 SPARK Matrix for GRC platforms by QKS Group.
- Process Center (BPM) AI-native business process management (BPM) software that models, documents and governs business processes, providing an integrated view of processes, risks, controls, responsibilities, IT systems, data and their dependencies, and connecting end-to-end with the GRC platform.
- Contraqto (CLM) Contract Lifecycle Management (CLM) software that manages contracts throughout their lifecycle, extending Swiss GRC's platform capabilities to legal and contract management processes.
- Risk Management Module for managing risks and opportunities across the organization with real-time visibility and aggregation for decision-making bodies.
- RiskQuant Risk quantification module that quantifies risk for the board using Monte Carlo simulation and loss distribution, providing decision-ready aggregated views and clear recommendations for action.
- Information Security (ISMS) Information Security Management System (ISMS) module for systematizing information security, aligned with ISO 27001 and related information security frameworks.
- Third-Party Risk Management (TPRM) Module for managing and monitoring risk across third parties and suppliers, providing structured assessment, continuous monitoring, and risk distribution and trend views.
- Third-Party Intelligence Third-party screening and intelligence platform offering sanctions screening, media search screening, speech and voice analytics, risk spillover detection, dynamic profiling, and ratings to support continuous third-party monitoring.
- Internal Controls (ICS) Internal Control System (ICS) module for monitoring and strengthening controls across the organization, supporting SOX-style and other control frameworks.
- Business Continuity Management (BCM) Business Continuity Management module that helps organizations stay operational through disruption by managing continuity plans, impact analyses, and recovery procedures.
- Data Protection Management Data protection management module for managing data protection consistently in line with GDPR and related data protection regulations.
- AI GRC AI governance module for governing AI risk with confidence, covering AI-specific compliance and risk management requirements such as the EU AI Act and related frameworks.
- Internal Audit Internal audit software module for planning, conducting, and tracking audits, with workflow automation aligned to the Global Internal Audit Standards.
- Operational Resilience Operational Resilience module to protect critical business functions and ensure organizational resilience, including impact tolerances and severe-but-plausible-scenario testing.
Quantifiable outcome
- Risk management harmonized across 4 companies (NEQSOL Holding), enabling group-wide oversight while empowering subsidiaries to manage risks autonomously.
- +4 more outcomes
Companies that use Swiss GRC
Customer profileNamed customers11 records
Segments5 records
Ideal customer profiles5 records
Swiss GRC technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability5 records
Feature8 records
Swiss GRC partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and regional.
- VolatiliscoreSwiss GRC and Volatilis (specialist in quantitative risk management technology) announced a strategic partnership in June 2026. Their joint mission is to make advanced quantitative risk analysis accessible at the board level, enabling decision-makers to lead with confidence. The partnership combines Swiss GRC's GRC platform with Volatilis' quantitative risk technology.
- ContraqtocoreContraqto is Swiss GRC's Contract Lifecycle Management (CLM) product, launched in July 2025. Swiss GRC develops and owns Contraqto as a distinct CLM solution that complements its GRC and BPM platforms. It is accessible at contraqto.com and marketed as part of the Swiss GRC product ecosystem.
- Lawrbit Lextech India Private LimitedcoreIn January 2025, Swiss GRC formed a strategic partnership with Lawrbit Lextech India Private Limited to combine AI-driven legal technologies with GRC platforms. This partnership enables Swiss GRC to enhance its platform with AI-driven legal technology capabilities, extending its value proposition to legal and compliance teams.
- OpResONE, Inc.regionalIn December 2024, Swiss GRC and OpResONE launched a strategic partnership for GRC implementation in North America. OpResONE assists with the deployment and configuration of the Swiss GRC platform for North American enterprise customers.
Scale indicators5 records
Recent moves6 records
Expansion highlights6 records
Swiss GRC competitors and assessment
Company assessmentBroad incumbents
- ServiceNow: ServiceNow's Integrated Risk Management (IRM) and GRC offerings bundle risk, compliance, audit, and TPRM into its broader enterprise workflow platform. Comparable as a unified GRC platform alternative to Swiss GRC's GRC Toolbox, but with vastly broader scope and scale.
- RSA Archer (Regnology): Regnology (which acquired RSA Archer) offers an enterprise GRC platform covering operational risk, regulatory reporting, and IT risk. Comparable as a long-standing enterprise GRC platform incumbent serving banks, insurers, and other regulated firms.
- IBM OpenPages: IBM OpenPages is an enterprise GRC platform focused on operational risk, regulatory compliance, and IT governance within regulated industries. Comparable as an enterprise-grade GRC platform competitor, particularly in banking and insurance.
- SAP (SAP GRC): SAP's GRC and Process Control solutions address enterprise-wide risk, compliance, and access governance inside the SAP ecosystem. Comparable as a platform incumbent in enterprise GRC, particularly with large financial services and regulated buyers that overlap with Swiss GRC's customer base.
Direct peers
- MetricStream: MetricStream is an AI-enabled GRC platform with deep coverage of operational risk, IT GRC, audit, and compliance — directly comparable to Swiss GRC's module suite and enterprise customer profile in regulated industries.
- OneTrust: OneTrust spans privacy, ethics, ESG, GRC, and trust intelligence on a unified platform. Overlaps with Swiss GRC's data protection, compliance, and third-party risk modules and competes for the same large-enterprise governance buyers.
- NAVEX Global: NAVEX Global offers integrated risk and compliance management software including ethics & compliance, risk, and third-party risk. Comparable to Swiss GRC's compliance, risk, and TPRM modules for mid-to-large enterprises.
- LogicGate: LogicGate's Risk Cloud is a no-code GRC platform covering risk, compliance, TPRM, and audit workflows. Comparable to Swiss GRC's configurable (no-code) architecture and enterprise risk/compliance buyer, with overlapping workflow automation positioning.
- Diligent: Diligent (formerly Galvanize/ACL) provides an integrated GRC platform covering audit, risk, compliance, ethics, and board reporting. Closely comparable to Swiss GRC's unified-platform approach and target buyer (governance, risk, audit functions at large enterprises).
- Mitratech (TeamConnect / Alyne): Mitratech's TeamConnect and Alyne provide integrated GRC, risk, and compliance management with strong regulatory framework coverage. Comparable to Swiss GRC's enterprise GRC positioning with overlap in regulated industries and framework-driven compliance use cases.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Swiss GRC social profiles
Digital presenceSwiss GRC compliance and trust
Trust signalCompliance3 records
Swiss GRC financial estimates
Financial estimateRevenue estimate
Valuation estimate
Swiss GRC leadership team
Management profileNumber of profiles
Profiles2 records
Swiss GRC subsidiaries and ownership
Company hierarchySubsidiaries6 records
Swiss GRC funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Swiss GRC M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Swiss GRC
What does Swiss GRC do?
Swiss GRC develops and sells an AI-native, unified Governance, Risk and Compliance (GRC) platform called GRC Toolbox (marketed as GRC.One) that connects risk, compliance, security, and business processes on a single shared data foundation. The platform is sold as modular software covering Risk Management, Information Security (ISMS), Third-Party Risk Management, Internal Controls, Business Continuity, Data Protection, AI GRC, Internal Audit, and Operational Resilience, and extends through a separate Process Center (BPM) product and Contraqto (CLM) product. It is offered as cloud or on-premise deployment, configurable without coding, with unlimited users per module, and includes Grace AI as an embedded AI assistant.
Is Swiss GRC a public or private company?
Swiss GRC is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Swiss GRC founded?
Swiss GRC was founded in 2016. It employs 11 to 50 people.
Where is Swiss GRC based?
Swiss GRC is headquartered in Lucerne, Switzerland, in the Europe region.
How does Swiss GRC make money?
Two revenue lines are on record. Software Licensing (GRC Toolbox) is the primary driver. The others are professional Services / Implementation Consulting.
Who are Swiss GRC's main competitors?
Broad incumbents on record are ServiceNow, RSA Archer (Regnology), IBM OpenPages and SAP (SAP GRC). Direct peers are MetricStream, OneTrust, NAVEX Global, LogicGate, Diligent and Mitratech (TeamConnect / Alyne).
Does Swiss GRC have an API?
No public API is recorded for Swiss GRC.
What industry is Swiss GRC in?
Swiss GRC's product category is Governance, Risk, and Compliance (GRC) Software. Its primary akta.pro industry code is BPAEAPAA, Governance, Risk & Compliance (GRC) Platforms, with a secondary code of HDAEAHAL, Compliance, GRC Workflow & Audit Automation Platforms. Its NAICS code is 5132 and its SIC code is 7372.