Skip to content

28 February 2025 | 3 min

Why GRC Is More Important Than Ever: Navigating a changing World

In a world marked by geopolitical tensions, economic uncertainties, and technological disruptions, Governance, Risk & Compliance (GRC) is becoming increasingly crucial. Businesses are facing unprecedented challenges: geopolitical tensions are escalating, regulatory requirements are tightening, and technological advancements—especially in artificial intelligence (AI)—are rapidly reshaping existing business models. In this article, we will highlight why strong GRC management is not only essential for survival but also a key competitive advantage.

1. Political Uncertainties and Protectionism

The re-election of Donald Trump as U.S. President brings with it a renewed focus on protectionist economic policies. Trade conflicts, tariffs, and national interests are once again taking center stage. This means that globally operating companies must rethink their supply chains and compliance strategies. Additionally, uncertainties in EU politics, such as the future direction of economic policy and potential new trade barriers, add further complexity.

GRC Solution: Companies must adapt their compliance and risk management strategies to be prepared for protectionist measures. A flexible GRC system helps businesses quickly adjust to regulatory changes and identify risks at an early stage.

2. Geopolitical Tensions and Crises

The war in Ukraine and other geopolitical conflicts, such as tensions in the South China Sea, have massive impacts on markets and supply chains. Sanctions and political unrest create economic uncertainty and require strategic risk assessments.

GRC Solution: Companies need a dynamic risk management approach that continuously monitors political changes and provides risk mitigation scenarios. GRC software can assist through real-time monitoring and integrated risk assessment, allowing businesses to respond proactively to geopolitical developments.

3. Economic Uncertainties and Inflation

Rising inflation rates, volatile financial markets, and uncertain economic outlooks pose significant challenges for businesses. At the same time, regulatory pressures are increasing across various industries, forcing companies to engage more intensively with governance and compliance issues.

GRC Solution: A structured GRC system can help businesses better assess financial risks and efficiently implement compliance requirements. AI-powered analytics tools can assist in forecasting future economic developments and making strategic decisions based on solid data.

4. Technological Innovations and Artificial Intelligence

Artificial intelligence is transforming business models and introducing new risks. From automated decision-making to ethical concerns regarding AI usage, companies must ensure compliance with legal requirements and ethical standards.

GRC Solution: A modern GRC software solution can help monitor AI applications and ensure compliance with all regulatory and ethical standards. Automated compliance checks and audits can relieve businesses of administrative burdens and minimize risks.

5. Regulatory Changes and Stricter Compliance Requirements

Regulatory authorities worldwide are tightening requirements for businesses. Data protection laws such as the GDPR, new ESG guidelines, and industry-specific compliance regulations present companies with major challenges.

GRC Solution: A central GRC platform allows businesses to efficiently manage regulatory requirements and continuously monitor compliance. Automated processes help minimize compliance risks and avoid penalties.

Conclusion: GRC as a Key Competitive Advantage

In a world full of uncertainties, GRC is no longer just a nice-to-have but a mission-critical function. Companies that strategically leverage GRC are better prepared for crises, minimize risks, and can adapt more quickly to changing market conditions. A powerful GRC software solution is the key to effective and agile risk management.

Businesses that invest in their GRC strategy now will not only secure compliance and risk transparency but also gain a significant competitive advantage in an ever-changing global economy.

Related posts

25 February 2025 | 2 min

FINMA Supervisory Notice 08/2024: AI use on GRC

The rapid integration of Artificial Intelligence (AI) in the financial sector presents both opportunities and challenges. With the publication of Supervisory Notice 08/2024, FINMA has outlined clear expectations for governance and risk management in relation to AI usage.

Key Points of FINMA Supervisory Notice 08/2024

FINMA emphasizes that although there is no specific AI legislation in Switzerland, existing, technology-neutral regulatory requirements also apply to AI. Financial institutions must actively analyze the impact of AI on their risk profile and adapt their governance, risk management, and control systems accordingly.

Key risks identified include operational risks such as model uncertainties, IT and cyber threats, and increased dependence on third-party providers. FINMA requires institutions to define clear responsibilities, maintain a comprehensive inventory of AI applications, conduct regular testing to ensure data quality and model stability, and implement independent reviews of critical AI systems.

The Impact of Increasing AI Usage on GRC

The growing implementation of AI is significantly transforming Governance, Risk Management, and Compliance (GRC):

  • Governance: AI adoption necessitates adjustments in corporate governance, including the clear assignment of responsibilities for AI development, implementation, and oversight.
  • Risk Management: AI can help identify and mitigate risks by analyzing large datasets and detecting patterns. However, new risks arise, such as faulty algorithms or biased data, which require continuous monitoring.
  • Compliance: AI usage must align with existing regulatory requirements, ensuring transparency in AI-driven decisions and protecting sensitive data.

How GRC Software Can Help

Modern GRC software solutions play a crucial role in addressing AI-related challenges:

  • Automation and Efficiency: AI-powered GRC tools can automate processes, increasing efficiency and accuracy in risk and compliance management.
  • Real-Time Monitoring: AI-driven GRC systems enable continuous risk and compliance monitoring, allowing companies to proactively address potential issues.
  • Integration and Scalability: GRC software integrates seamlessly into existing IT infrastructures and scales to meet the growing demands of AI implementation.

Conclusion

FINMA’s Supervisory Notice 08/2024 highlights the need for robust governance and risk management frameworks in response to AI adoption in the financial sector. As AI continues to shape GRC structures, organizations must adapt their strategies and tools. GRC software solutions provide essential support by automating processes, enabling real-time monitoring, and ensuring seamless integration into existing systems.

17 February 2025 | 2 min

Linking risks and goals

Successful companies set clear corporate goals to achieve growth, efficiency, and competitive advantages. However, these goals are often associated with risks that can negatively impact business success. Effective risk management is therefore essential to identify threats early, take appropriate measures, and ensure the achievement of corporate goals.

Risks as an Integral Part of Corporate Strategy

Every strategic decision carries risks. These can be financial, operational, regulatory, or technological in nature. If risks are not identified early and aligned with corporate goals, they can lead to significant losses. A proactive approach helps minimize uncertainties and maximize opportunities.

The Connection Between Corporate Goals and Risks

1. Identifying Relevant Risks

Companies should systematically identify risks related to their strategic, operational, and financial goals. For example, expanding into new markets can involve currency risks, regulatory uncertainties, and logistical challenges.

2. Risk Assessment and Prioritization

Not all risks have the same impact on corporate goals. Therefore, prioritization is crucial. Companies can use methods such as risk matrices or Monte Carlo simulations to assess probability and potential damage.

3. Developing Risk Management Measures

Once risks are identified and prioritized, measures to manage them must be developed. These may include risk avoidance, mitigation, transfer, or acceptance. For instance, companies can minimize certain risks through insurance or contractual agreements.

4. Continuous Monitoring and Adjustment

Dynamic risk management requires continuous monitoring and adaptation to new developments. Companies should regularly review whether existing measures are still effective or need optimization.

How GRC Tools Simplify Risk Management

Governance, Risk, and Compliance (GRC) tools help companies efficiently manage their risks and align them with corporate goals. These tools provide a centralized platform for identifying, analyzing, and controlling risks while facilitating documentation and reporting. The benefits of a GRC tool include:

  • Automated Risk Assessments: Reduction of manual errors and faster identification of critical risks.
  • Integration with Corporate Goals: Clear linkage between strategic goals and potential risks.
  • Real-Time Monitoring: Continuous monitoring and alerts for deviations.
  • Efficient Reporting: Simplified reporting for decision-makers and auditors.

Conclusion

Linking corporate goals with risk management is crucial for long-term success. A structured approach enables targeted risk control and ensures the achievement of corporate objectives. Modern GRC tools significantly simplify this process, allowing companies to monitor risks in real-time and make informed decisions. Proactive risk management is not just protection against threats but also a competitive advantage.

10 February 2025 | 4 min

FINMA Risk Monitor – Key Risks and Their Impact on Businesses

What is the FINMA Risk Monitor?

The FINMA Risk Monitor is an annual report published by the Swiss Financial Market Supervisory Authority (FINMA). It analyzes the most significant risks for the Swiss financial sector and provides guidance for banks, insurance companies, and financial institutions. The report outlines risks with a time horizon of up to three years and establishes supervisory expectations for regulated entities.

The macroeconomic environment remains uncertain, characterized by inflation, geopolitical tensions, and economic instability. Although inflation has slightly eased, major risks for the financial market persist.


Key Risks in the FINMA Risk Monitor and Their Impact on Businesses

1. Real Estate and Mortgage Risks

  • The Swiss real estate market has cooled somewhat, but overheating risks remain.
  • Banks continue to grant mortgages with high loan-to-value ratios or unsustainable lending criteria.
  • The commercial real estate sector faces additional risks due to the rise of remote work and structural market changes, leading to potential office vacancies.

Impact on Businesses:

  • Banks may face stricter capital requirements and possible regulatory tightening of mortgage lending criteria.
  • Real estate funds could suffer from valuation corrections.
  • Commercial property owners may experience higher vacancy rates and declining property values.

2. Credit Risk – Other Loans

  • Declining profits and falling market valuations may lead to losses on margin loans and corporate loans.
  • Highly leveraged businesses are particularly vulnerable.
  • The UBS acquisition of Credit Suisse remains under close scrutiny, especially regarding its leveraged finance positions.

Impact on Businesses:

  • Companies may face tighter credit conditions.
  • Financing could become more expensive, especially for small and medium-sized enterprises (SMEs).
  • Banks will need to adjust their risk management to identify potential credit risks early.

3. Market Risk – Credit Spread Risk

  • Increasing risk premiums for corporate and government bonds could lead to portfolio devaluations for financial institutions.
  • The uncertain economic outlook may cause higher risk spreads.

Impact on Businesses:

  • Raising capital will become more costly, as bond investors demand higher risk premiums.
  • Banks and insurers may face portfolio losses, weakening their capital positions.

4. Liquidity and Refinancing Risk

  • A loss of depositor confidence could lead to liquidity shortfalls for banks.
  • Systemic crises could trigger liquidity shortages, destabilizing the financial system.

Impact on Businesses:

  • Financial institutions must maintain higher liquidity buffers.
  • Stricter liquidity management requirements are expected.
  • Companies should explore alternative funding sources to mitigate liquidity risks.

5. Market Access

  • Swiss financial institutions continue to face challenges accessing key foreign markets, particularly within the EU.
  • Regulatory fragmentation makes it harder to secure market access.

Impact on Businesses:

  • Banks may encounter additional regulatory hurdles, especially in the EU.
  • Financial service providers may need to restructure their operations to continue offering cross-border services.

6. Money Laundering Risks

  • Stricter anti-money laundering (AML) regulations and increased compliance requirements for financial institutions.
  • Crypto transactions are increasingly linked to money laundering risks.

Impact on Businesses:

  • Financial institutions must invest in enhanced compliance measures.
  • Companies handling international financial transactions must ensure compliance with AML regulations.

7. Sanctions

  • Increased risks from international trade restrictions, particularly concerning Russia sanctions.
  • Enhanced oversight of compliance with sanctions regulations.

Impact on Businesses:

  • Financial institutions must ensure full compliance with sanctions to avoid legal consequences.
  • Companies trading with sanctioned countries may face more restrictive financial services.

8. Outsourcing Risks

  • Growing dependence on third-party providers, especially in IT and cloud services, increases operational risks.
  • Disruptions at critical service providers could severely impact financial institutions.

Impact on Businesses:

  • Banks and insurers must strengthen oversight of their supply chains and IT service providers.
  • Companies should enhance resilience against IT failures.

9. Cyber Risks

  • Cyberattacks on the financial sector are increasing, particularly through ransomware and phishing attacks.
  • Inadequate security measures at financial institutions can lead to data breaches and system failures.

Impact on Businesses:

  • Higher investments in cybersecurity are required.
  • Financial institutions must ensure that third-party providers adhere to strict security standards.
  • Companies should safeguard against financial and operational damage from cyberattacks.

Conclusion: Key Challenges for Businesses in the Swiss Financial Market

The FINMA Risk Monitor highlights significant challenges for financial sector businesses. Banks, insurers, and financial service providers must navigate a volatile market environment, increasing regulatory requirements, and rising technological risks.

Key Takeaways for Businesses:

  1. Strengthen credit risk management, particularly in real estate and corporate lending.
  2. Build liquidity reserves to withstand sudden market disruptions.
  3. Enhance compliance measures to mitigate money laundering and sanction-related risks.
  4. Increase cybersecurity investments to counter growing digital threats.
  5. Ensure IT infrastructure resilience to reduce dependencies on external service providers.

FINMA will continue to closely monitor the situation and may introduce new regulatory measures if necessary. Financial institutions should proactively adjust their risk strategies to maintain their competitive edge.

4 February 2025 | 2 min

WEF Global Risk Report 2025 – Global Risiks and Challenges

The WEF Global Risk Report 2025 by the World Economic Forum (WEF) highlights the evolving global risks for the coming years. Based on a comprehensive survey of over 900 international experts from business, politics, and academia, the report examines both short-term and long-term challenges.

Key Findings of the Global Risk Report 2025

1. Increasing Global Uncertainty

According to the report, 52% of respondents expect an unsettled global landscape in the next two years, while 62% foresee rising geopolitical tensions and economic uncertainty over the next decade.

2. Geopolitical and Geoeconomic Tensions

The geopolitical situation remains unstable, with state-led conflicts topping the list of current risks. The escalation of existing conflicts, particularly in Ukraine, the Middle East, and Sudan, has further exacerbated global security concerns.

3. Technological Challenges and Disinformation

The increasing proliferation of artificial intelligence (AI) and generative AI has heightened the risk of disinformation and cybercrime. Misinformation, targeted manipulation, and cyberattacks threaten democratic processes and economic stability.

4. Environmental Crises as the Most Pressing Long-Term Threat

The effects of climate change are no longer just a long-term concern but an immediate reality. Extreme weather events, environmental pollution, and biodiversity loss rank among the most severe risks through 2035.

Short-Term Risks Until 2027

  • State-led conflicts (e.g., Ukraine, Middle East, Africa)
  • Extreme weather events such as droughts, floods, and storms
  • Geoeconomic confrontations due to sanctions and trade wars
  • Social polarization within societies
  • Disinformation and fake news, amplified by generative AI

Long-Term Risks Until 2035

  • Climate change and environmental destruction as a dominant threat
  • AI and biotechnology risks from uncontrolled technological advancements
  • Social inequality and demographic challenges due to an aging global population
  • Resource shortages and biodiversity loss

Solutions and Required Actions

To mitigate risks, the report calls for enhanced international cooperation, investments in sustainable technologies, and unified regulations for AI and cybersecurity. Businesses and governments must develop strategies to become more resilient to global crises.

Conclusion

The WEF Global Risk Report 2025 presents a bleak outlook for the global landscape but simultaneously emphasizes the necessity for collective efforts in risk mitigation. Particularly, climate change, geopolitical tensions, and technological progress require innovative and multilateral solutions. Only through joint action can a sustainable and secure future be ensured.

27 January 2025 | 2 min

EUDR: EU Deforestation Regulation

The European Union has taken a significant step to combat global deforestation with Regulation (EU) 2023/1115, commonly known as the EU Deforestation Regulation (EUDR). This regulation aims to ensure that products placed on the EU market do not contribute to deforestation or forest degradation.

Implementation Timeline of the EUDR

Initially, the EUDR was scheduled to take effect on December 30, 2024, for medium and large enterprises. However, the start date has been postponed by one year. The obligations will now apply to large market operators and traders from December 30, 2025, while micro and small enterprises have until June 30, 2026, to comply with the requirements.

Key Requirements of the EUDR

The EUDR mandates that companies ensure specific raw materials and products derived from them, marketed within or exported from the EU, are not linked to deforestation or forest degradation. The regulated raw materials include:

  • Wood
  • Beef and leather
  • Soy
  • Coffee
  • Cocoa
  • Palm oil
  • Rubber

Companies must provide evidence that these products do not originate from land that was deforested after December 31, 2020. Additionally, compliance with the relevant national laws of the country of origin is required. A central aspect of the regulation is due diligence: companies must gather detailed information about their supply chain, including the geographical coordinates of cultivation areas, to ensure traceability.

Implementing the EUDR in Businesses

Implementing the EUDR poses significant challenges for businesses. Studies indicate that 80% of companies are behind schedule despite the extended timeline.

To successfully meet the EUDR requirements, companies should follow these steps:

1. Supply Chain Analysis: Conduct a comprehensive analysis of supply chains to identify potential risks related to deforestation.

2. Supplier Selection: Collaborate with suppliers that can demonstrate sustainable practices and compliance with the EUDR requirements.

3. Data Management: Implement systems to collect and manage the required data, including the geographical origin of raw materials.

4. Training and Awareness: Train employees and suppliers on the EUDR requirements and the importance of deforestation-free supply chains.

5. Continuous Monitoring: Establish processes for regular review and updates of supply chain information to ensure compliance.

Early and proactive engagement with the EUDR requirements is crucial to minimize legal risks and maintain competitiveness in the EU market. Companies should use the remaining time before the regulation’s implementation to make necessary adjustments and embed sustainable practices in their supply chains.

21 January 2025 | 3 min

ISO 14001: Guide on successful Implementation

The ISO 14001 standard is a globally recognized framework for environmental management systems (EMS) and serves as the foundation for sustainable operations in companies and organizations. It helps minimize environmental impacts, comply with legal requirements, and enhance operational efficiency.

What is ISO 14001?

ISO 14001 is an international standard that specifies requirements for an environmental management system. Its goal is to help organizations adopt a systematic approach to environmental issues. This includes:

  • Identifying and controlling environmental impacts.
  • Ensuring compliance with legal and regulatory requirements.
  • Continuously improving environmental performance.

The standard is based on the Plan-Do-Check-Act (PDCA) cycle, which provides an iterative approach to process improvement and achieving desired outcomes.

Benefits for Companies and Organizations

Implementing an environmental management system based on ISO 14001 offers numerous benefits:

  1. Legal Compliance: Companies can ensure they meet all relevant environmental laws and regulations.
  2. Cost Reduction: More efficient use of resources and waste minimization can lower operating costs.
  3. Risk Management: Identifying and controlling potential environmental hazards reduces operational risks.
  4. Reputation Enhancement: ISO 14001 demonstrates a commitment to sustainability, improving market position.
  5. Employee Motivation: A strong EMS increases environmental awareness and motivation among employees.

Steps to Implement ISO 14001

For experts leading or optimizing implementation, the following steps are essential:

1. Preparation and Planning:

  • Define the scope of the EMS.
  • Conduct an environmental baseline assessment to evaluate risks and opportunities.

2. Risk Assessment and Goal Setting:

  • Develop environmental objectives based on identified aspects and risks.
  • Establish measurable key performance indicators (KPIs).

3. System Documentation:

  • Create an environmental policy and document relevant processes.
  • Ensure clear assignment of roles and responsibilities.

4. Employee Training and Awareness:

  • Train employees at all levels to strengthen environmental awareness.

5. Implementation and Operation:

  • Execute the defined processes and procedures.
  • Use appropriate technologies to achieve environmental objectives.

6. Monitoring and Evaluation:

  • Regularly review the effectiveness of the EMS.
  • Conduct internal audits and management reviews.

7. Continuous Improvement:

  • Use the results of audits and evaluations to derive improvement measures.

Challenges and Solutions

Implementing an EMS can be complex. Common challenges include:

  • Resource Constraints: Ensure sufficient personnel and financial resources are allocated.
  • Resistance to Change: Clearly communicate the benefits and involve employees early on.
  • Maintaining Compliance: Use digital tools to monitor legal requirements.

Conclusion

ISO 14001 provides experts with a structured framework for effectively implementing and continuously improving environmental management systems. It supports organizations in enhancing their environmental performance, minimizing risks, and aligning with long-term success. By applying proven strategies and technologies, companies can not only meet legal requirements but also contribute significantly to global sustainability.

With the right planning and a dedicated team, implementing ISO 14001 becomes a worthwhile investment in your organization’s future.

13 January 2025 | 3 min

Sustainability Disclosure Standards: IFRS S1 and S2

Sustainability reporting is no longer optional—it’s a critical component of corporate governance and transparency. With the release of IFRS S1 (General Requirements for Disclosure of Sustainability-related Financial Information) and IFRS S2 (Climate-related Disclosures) by the International Sustainability Standards Board (ISSB), businesses worldwide are set to adopt a new global framework for sustainability-related financial reporting. Here’s what you need to know about these standards and their implications for corporate reporting in 2025.

The Core Objectives of IFRS S1 and S2

IFRS S1 establishes a framework for disclosing sustainability-related risks and opportunities, emphasizing their impact on an entity’s cash flows, financial position, and access to capital. It serves as the foundation for all subsequent sustainability reporting under IFRS standards.

IFRS S2, on the other hand, is a thematic standard focusing exclusively on climate-related risks and opportunities. It builds on the Task Force on Climate-Related Financial Disclosures (TCFD) framework, incorporating its four pillars: governance, strategy, risk management, and metrics/targets.

Key Features and Requirements

1. Materiality as a Guiding Principle

Material information is central to IFRS S1 and S2. Entities are required to disclose sustainability-related risks and opportunities that could reasonably affect their financial prospects. Materiality judgments must align with the needs of primary users, including investors and creditors.

2. Holistic Integration with Financial Reporting

Both IFRS S1 and S2 emphasize the connection between sustainability-related disclosures and traditional financial statements. This includes using consistent data and assumptions across both reporting streams to ensure comparability and coherence.

3. Transition Provisions

To ease adoption, the ISSB allows companies to initially focus on climate-related disclosures under IFRS S2 before expanding to all sustainability-related disclosures under IFRS S1. This phased approach supports entities in building robust reporting systems.

4. Industry-Specific Guidance

IFRS S2 requires entities to consider industry-specific disclosure topics and metrics, particularly for greenhouse gas emissions (Scopes 1, 2, and 3). The standards also draw on frameworks like the SASB standards and GRI for additional guidance.

Practical Implications for Businesses

  1. Strengthening Governance Companies must enhance their governance structures to oversee sustainability-related risks effectively. This includes identifying board-level accountability for sustainability strategies.
  2. Data Management and Transparency Businesses will need to invest in systems capable of capturing, analyzing, and reporting sustainability data. Accurate and verifiable information is crucial to meet the standards’ requirements.
  3. Strategic Resilience IFRS S1 and S2 require businesses to disclose how sustainability-related risks impact their strategy and resilience. Scenario analysis and long-term planning will be essential to comply.
  4. Building Stakeholder Trust By adopting these globally recognized standards, companies can enhance their credibility with investors, regulators, and the public, demonstrating a commitment to transparency and sustainability.

Conclusion

IFRS S1 and S2 set a new benchmark for sustainability reporting, addressing the fragmented landscape of voluntary disclosures. As we approach 2025, companies must prioritize compliance to stay competitive and meet evolving stakeholder expectations. Early adoption and strategic alignment with these standards will position organizations as leaders in sustainable business practices.

For more detailed guidance, companies should consult the IFRS Foundation’s publications and seek professional advice tailored to their industry and jurisdiction.

7 January 2025 | 3 min

GRC Challenges 2025

The world of Governance, Risk, and Compliance (GRC) is evolving rapidly – and 2025 is no exception. Companies face a multitude of challenges that can impact not only their efficiency but also their compliance and competitiveness. In this article, we explore the key trends and challenges GRC professionals will encounter in 2025 and outline practical solutions that experts can implement.

1. Increasing Regulatory Complexity

The regulatory landscape is becoming more complex. New laws, such as the EU Digital Operational Resilience Act (DORA) or Germany’s Supply Chain Act, require companies to monitor and document their processes more closely.

Solution:

  • Rule-based compliance management tools: Automation helps efficiently monitor the multitude of regulations.
  • Proactive monitoring: Regular analyses and reports ensure companies stay up to date.

2. Cybersecurity Risks in a Connected World

With increasing digitization, the risks of cyberattacks are also rising. These threats affect not only IT infrastructure but also sensitive company data and compliance with data protection regulations like GDPR.

Solution:

  • Integration of GRC and IT security strategies: Close alignment ensures risks are systematically identified and mitigated.
  • Training and awareness campaigns: Employees are the first line of defense and must be properly sensitized.

3. ESG and Sustainable Corporate Governance

Environmental, Social, and Governance (ESG) is no longer just a trend. Investors and stakeholders are demanding demonstrably sustainable business strategies. A lack of ESG standards can pose not only financial but also reputational risks.

Solution:

  • Implementation of ESG guidelines: GRC systems should seamlessly integrate ESG criteria.
  • Transparent reporting: Clear and understandable reports strengthen stakeholder trust.

4. The Challenge of Data Overload

Big Data is both a blessing and a curse. The volume of data that companies collect and analyze is growing exponentially. This flood of data makes it challenging to make informed decisions while simultaneously meeting legal requirements.

Solution:

  • AI-powered data analytics: Modern technologies can filter and analyze data more efficiently.
  • Privacy by design: Compliance should be considered during the data architecture phase.

5. Talent Shortage in the GRC Field

Qualified professionals in the GRC field are scarce. Companies struggle to attract and retain the right talent.

Solution:

  • Investment in training: Internal training programs can retain and expand expertise within the company.
  • Attractive working conditions: Flexible work models and attractive benefits make companies more appealing to GRC experts.

6. The Role of GRC Software in Overcoming Challenges

GRC software plays a crucial role in efficiently managing the growing complexity and variety of challenges. It offers comprehensive functionalities to align governance, risk management, and compliance.

Solution:

  • Process automation: GRC software helps reduce manual tasks and minimize errors.
  • Integrated platforms: A single platform enables companies to identify risks, ensure compliance, and generate reports.
  • Real-time monitoring: With real-time dashboards and analytics, companies can quickly respond to emerging risks.

Conclusion

The year 2025 presents numerous challenges but also opportunities for companies to future-proof their GRC strategies. By leveraging modern technologies, focusing on sustainability, and developing internal competencies, companies can not only minimize risks but also gain competitive advantages. GRC experts who identify and address these trends early will become indispensable partners in corporate management.

18 December 2024 | 5 min

New Laws 2025: Impact on GRC and Recommendations for Action for Companies

In 2025, several important laws and regulations will come into force in the EU, Germany and Switzerland that will significantly impact the governance, risk and compliance (GRC) management of companies. These new regulations affect areas such as sustainability, supply chains, financial stability and digitalization. Companies must adapt their processes early on to minimize risks and remain compliant with the law. Below is an overview of the most important laws, ordered by their entry into force date.

1. Electronic invoicing requirement in the EU

Entry into force: January 1, 2025

From January 1, 2025, electronic invoicing between companies in the EU will gradually become mandatory. The previously valid PDF invoice is no longer sufficient. Instead, structured data formats such as XML must be used, which enable automated processing. Companies must therefore ensure that their accounting systems and ERP software are compatible and can both receive and create e-invoices.

Impact on GRC:

– Governance: Internal policies must be updated to meet the new requirements.

– Risk management: Companies risk fines and delays in invoice processing if they fail to comply.

– Compliance: Systems must be converted in accordance with legal requirements in order to provide invoice formats that comply with the law.

Recommended action: Companies should review their IT and accounting systems and convert them if necessary. It is advisable to offer training for employees and start pilot projects for the electronic invoice process.

2. Corporate Sustainability Reporting Directive (CSRD)

Entry into force: January 1, 2025 (reporting obligation for the 2024 financial year)

The EU-wide CSRD significantly expands sustainability reporting obligations. In the future, companies will have to disclose extensive information on environmental, social and governance factors (ESG) in their annual reports. The directive will apply to large companies and, in the future, also to medium-sized companies with over 250 employees or a turnover of over 40 million euros.

Impact on GRC:

– Governance: Companies must develop ESG strategies and make them transparent. – Risk management: Lack of or inadequate reporting poses legal and financial risks.

– Compliance: Reports must be auditable and prepared in accordance with the new standards (e.g. ESRS).

Recommended action: Companies should develop a sustainability strategy and optimize reporting processes. The introduction of suitable reporting tools and external audits can help to meet the requirements.

3. EU Supply Chain Act (Corporate Sustainability Due Diligence Directive – CSDDD)

Entry into force: mid-2025 at the earliest

The EU Supply Chain Act obliges large companies to analyze, prevent and reduce human rights and environmental impacts along their entire value chain. The due diligence obligations apply to both their own activities and those of suppliers. Swiss companies that operate in the EU or generate high sales there are also affected.

Impact on GRC:

– Governance: Supply chains must be documented and audited. – Risk management: Companies must identify risks at an early stage and implement measures to minimize risk.

– Compliance: Strict liability regulations threaten in the event of misconduct or insufficient documentation.

Recommended action: Companies should analyze supply chain processes and carry out risk analyses. Digital tools for supply chain monitoring can help ensure compliance with the directive.

4. EU Deforestation Regulation

Entry into force: December 30, 2025

The new EU Deforestation Regulation is intended to ensure that products such as palm oil, wood, soy or cocoa have not contributed to deforestation or forest damage. Companies must prove that their products are deforestation-free and that no clearing has taken place for their production since 2020.

Impact on GRC:

– Governance: Companies must implement new due diligence processes for origin control.

– Risk management: Violations can lead to high penalties and reputational damage.

– Compliance: Companies must submit due diligence declarations in order to retain market access in the EU.

Recommended course of action: Companies should already review their supply chains and create transparency about raw material sources. Certification systems such as FSC or RSPO can provide support.

5. Finalization of Basel III in Switzerland

Entry into force: January 1, 2025

The final Basel III rules are intended to further strengthen the stability of the banking system. Banks must optimize their risk management processes, particularly with regard to the calculation of operational risks and capital requirements orders.

Impact on GRC:

– Governance: Banks must adapt their risk management guidelines.

– Risk Management: New methods for risk identification and assessment are necessary.

– Compliance: Compliance with the stricter capital and liquidity requirements.

Recommendation for action: Banks should revise their internal models and carry out comprehensive tests on risk-bearing capacity.

Conclusion

The year 2025 will bring numerous new laws and regulations that will affect companies in the EU and Switzerland and put GRC management to the test. From electronic invoicing to sustainability reports to supply chain control – companies must act in a timely manner to remain compliant with the law and minimize risks. Early analyses, implementation of IT solutions and training of employees are essential to meet the requirements and maintain the trust of stakeholders.