The typical implementation process for the GRC Toolbox software by Swiss GRC and Swiss Infosec AG is highly structured and tailored to each organization’s needs. Here’s a detailed breakdown based on available data:
1. Initial Consultation & Needs Assessment
Conducted by Swiss Infosec AG as the consulting partner.
Focuses on understanding the organization’s GRC maturity, existing processes, and regulatory requirements.
Includes a non-binding inquiry to scope the project and define objectives.
2. Solution Design & Customization
Based on the assessment, a tailored configuration of the GRC Toolbox is proposed.
The platform is modular, so only relevant components (e.g., Risk Management, ICS, ISMS) are selected.
Custom workflows, roles, and reporting structures are defined.
3. Implementation & Integration
Swiss GRC AG handles the technical deployment—either cloud-based or on-premise.
Integration with existing systems (e.g., ERP, HR, document management) is performed.
Data migration and user provisioning are included.
4. Training & Onboarding
Swiss Infosec AG provides user training, including:
Admin and end-user sessions
Role-based access training
Use-case simulations
Training is available in multiple languages, including German, English, French, and Arabic.
5. Go-Live & Support
After testing and validation, the system goes live.
Ongoing support includes:
Helpdesk access
Regular updates
Optional managed services.
Implementation Timeline
Typical duration: 2 to 6 months, depending on:
Number of modules
Customization level
Organization size
Integration complexity
Smaller implementations (e.g., 1–2 modules) may take as little as 4–6 weeks.
Larger enterprise rollouts can extend to 6+ months with phased deployment.
Customisation
GRC Toolbox is highly customizable to meet the specific governance, risk, and compliance needs of different organizations. Key customization features include:
Modular Architecture: Organizations can choose from a wide range of modules such as Risk Management, ICS, ISMS, Data Protection, BCM, Contract Management, and more.
Tailored Workflows: Custom workflows can be created to reflect internal processes and approval chains.
Role-Based Access: Permissions and views can be configured based on user roles and responsibilities.
Custom Reporting: Dashboards and reports can be adapted to meet internal and regulatory reporting requirements.
Integration Capabilities: The software integrates with existing systems like ERP, HR, and document management platforms.
Multilingual Support: Supports languages including English, German, French, Italian, and Arabic, allowing localization for regional teams.
Flexible Deployment: Available as cloud-based or on-premise, with options for regional server hosting.
Customer testimonials from organizations like ETH Zurich and Swiss Post highlight the platform’s scalability, flexibility, and ease of adaptation to complex environments.
Additional Costs
Base License Fee: Starts at approximately CHF 4,900 per year, depending on selected modules.
Setup Fees:
May include initial configuration, data migration, and integration with existing systems.
Setup costs vary based on project scope and complexity.
Customization Charges:
Custom workflows, dashboards, and reports may incur additional fees.
Training Costs:
Onboarding and role-based training are available and may be billed separately.
Maintenance & Updates:
Regular updates and security patches are included in the subscription.
Optional managed services may be offered for an additional fee.
Support Services:
Standard support is included.
Premium support (e.g., dedicated account manager, SLA-based response times) may be available at extra cost.
Swiss GRC emphasizes transparent pricing and encourages organizations to request a custom quote based on their needs.
Training
Swiss GRC provides comprehensive training and support to ensure successful onboarding and long-term use of the GRC Toolbox:
Training Services
Role-Based Training: Tailored sessions for administrators, compliance officers, risk managers, and general users.
Modular Training: Each GRC module (e.g., Risk Management, ICS, ISMS) comes with its own training package.
Multilingual Support: Training is available in English, German, French, Italian, and Arabic, supporting global teams.
Self-Explanatory Interface: The platform is designed to be intuitive, reducing the learning curve.
Workshops & Webinars: Regular sessions are offered to help users stay updated on new features and best practices.
Support Services
Dedicated Account Managers: For strategic guidance and personalized support.
Helpdesk Access: For technical issues and user queries.
Documentation & User Guides: Comprehensive manuals and online resources.
Ongoing Updates: Regular feature enhancements and security patches.
Customer Success Programs: Focused on maximizing value and adoption.
Customers like ETH Zurich and Swiss Post have praised the platform’s ease of use, flexibility, and high-quality support.
Security Measures
The GRC Toolbox is built with robust security architecture to ensure data protection and regulatory compliance:
Core Security Features
Triple ISO Certification: Complies with ISO standards for information security, risk management, and data protection.
Data Encryption: Both in transit and at rest, using industry-standard protocols.
Role-Based Access Control (RBAC): Ensures users only access data relevant to their roles.
Audit Trails: Comprehensive logging of user actions for accountability and compliance.
Secure Hosting Options:
Cloud Deployment: Hosted in regional data centers with high security standards.
On-Premise Deployment: Available for organizations with strict data residency requirements.
Compliance with GDPR: Built-in workflows for managing data subject rights and breach notifications.
Integrated Data Protection Workflows: Helps identify and mitigate data protection risks during project planning and execution.
These measures make the GRC Toolbox suitable for regulated industries such as finance, healthcare, and government.
Updates
The GRC Toolbox follows a structured and proactive update cycle to ensure the platform remains secure, compliant, and feature-rich:
Update Frequency
Regular Updates: Swiss GRC releases updates periodically throughout the year, typically aligned with evolving regulatory requirements and customer feedback.
Security Patches: Issued promptly in response to vulnerabilities or compliance changes (e.g., ISO, GDPR, NIST).
Feature Enhancements: New modules and improvements are rolled out based on industry trends and user needs.
Update Management
Automated Deployment: For cloud-hosted versions, updates are deployed automatically with minimal disruption.
Manual Control: On-premise clients can schedule updates based on internal IT policies.
Change Logs & Documentation: Each update is accompanied by detailed release notes and user guides.
Testing & Validation: Updates are tested in sandbox environments before full deployment.
Customer Notification: Users are informed in advance about major updates and new features.
This approach ensures that organizations using GRC Toolbox stay ahead of compliance and security requirements without compromising operational continuity.
Data Ownership and Portability
Swiss GRC emphasizes data sovereignty, transparency, and portability in its GRC Toolbox platform:
Data Ownership
Customer-Owned Data: All data entered into the GRC Toolbox remains the property of the customer.
No Vendor Lock-In: Swiss GRC does not claim ownership or restrict access to customer data.
Data Portability
Export Capabilities: Users can export data in various formats (e.g., Excel, PDF, CSV) for reporting or migration.
APIs & Integration: Supports data exchange with other systems via secure APIs.
Migration Support: Swiss GRC offers assistance for data migration during onboarding or offboarding.
Compliance with GDPR: Includes workflows for data access, correction, and deletion requests, ensuring full compliance with data subject rights.
These policies make the GRC Toolbox a reliable solution for organizations concerned about data control, especially in regulated sectors like finance, healthcare, and government.
Scaling Up / Down
The GRC Toolbox is designed with scalability and flexibility in mind, allowing organizations to adjust their usage as needs evolve:
Scaling Up
Modular Expansion: Organizations can add new modules (e.g., Data Protection, AI Risk Management, Contract Management) at any time.
User Licensing: Additional user licenses can be purchased to accommodate growing teams.
Cloud-Based Flexibility: Cloud deployments allow for rapid scaling without infrastructure changes.
Custom Workflows: New workflows and integrations can be configured as business processes evolve.
Scaling Down
Module Deactivation: Unused modules can be removed or suspended.
License Adjustment: User licenses can be reduced during contract renewal.
Cost Optimization: Swiss GRC offers tailored pricing based on active modules and users.
Swiss GRC emphasizes transparent pricing and flexible contracts, making it easier for organizations to adapt the platform to changing requirements.
The terms & conditions for contract renewal and cancellation
Contract Renewal
Annual Licensing: Most contracts are based on annual subscriptions.
Automatic Renewal: Contracts may auto-renew unless canceled within the notice period.
Review Period: Clients are encouraged to review module usage and adjust licenses before renewal.
Cancellation Terms
Notice Periods: Defined in the contract; typically 30 to 90 days before renewal.
No Vendor Lock-In: Swiss GRC supports data export and migration, making offboarding straightforward.
Contract Management Features: The GRC Toolbox itself includes tools to monitor contract terms, renewal dates, and cancellation deadlines.
Clients can manage their contracts using the Contract Management module, which includes automated reminders and lifecycle tracking.
Compliance
The GRC Toolbox is built to support and comply with a wide range of international standards and frameworks:
Certifications & Standards
Triple ISO Certification:
ISO 27001 – Information Security Management
ISO 31000 – Risk Management
ISO 37301 – Compliance Management
GDPR – General Data Protection Regulation (EU)
NIST Frameworks – Especially for cybersecurity and AI risk management
EU AI Act – Supported through the AI GRC module
ISO 42001 – AI Management System
Business Continuity Standards – Including ISO 22301
Internal Control Standards – COSO and similar frameworks
These standards make the GRC Toolbox suitable for regulated industries such as finance, healthcare, education, and government.