Getting Things Done Together
16.10.2025
Who we are and what defines us: For years, blu Systems has stood for expertise in information security, data protection, sustainable digitalization and compliance. Our goal is to help companies use digital technologies responsibly and in a legally compliant way. As artificial intelligence becomes increasingly important, we are expanding our consulting services: AI consulting as a logical complement to data protection. Our aim is to provide guidance, reduce fears and show concrete ways in which AI can be used in a trustworthy manner within the company.
Use case: AI in practice. So how exactly do we go about it? Let's take an example from our consulting work: First, we start together with the company and look at which AI systems are already in use. The picture is often surprisingly diverse – from the chatbot in customer service to internal analytics tools. This is where the first questions arise: Which systems do I actually have? What risks are associated with them?
To find answers, we combine a strategic view with a compliance perspective. In concrete terms, this means: We create an overview of all AI applications, classify them according to the risk categories of the EU AI Act and derive the relevant obligations from this. This creates clarity about where action is needed and where companies are already well positioned.
Another important step concerns governance. With practical policy templates, we help formulate clear rules that give employees guidance without restricting them. After all, the goal is not to ban AI, but to enable its responsible use.
We also place great emphasis on training and awareness. How can employees be empowered to use AI safely? Which guidelines matter in everyday work? Through workshops and trainings, we address uncertainties and show concrete use cases.
Conclusion: The example shows that AI consulting is not a theoretical construct, but can be integrated into everyday business in a pragmatic and transparent way. Those who start early gain not only legal certainty but also a competitive advantage – whether through greater trust among customers and employees or by participating in tenders that require AI Act compliance. In short: It pays to lay the foundations for tomorrow today.
blu Systems – AI & data protection with responsibility
Typical features of modern GRC tools
Their features go well beyond pure documentation and include: – Workflows & automation (approvals, escalations, reminders). – Dashboards & reporting for management and internal audit. – Interfaces to ERP, HR systems, ticketing and SIEM solutions. – Audit-proof documentation (versioning, audit trails). – Continuous monitoring with alerts. – Role and permission concepts. – Multilingual support & multi-tenancy. – Mobile use and access to emergency plans. – Increasingly AI-powered analytics features.
Example of process visualization in Zazoon:
Licensing models in practice and hands-on experience with blu Guard
Licensing varies widely between vendors and has a significant impact on cost structure and flexibility.
At blu Guard, we have supported various customers in selecting the right GRC tool, implemented the systems together with them and successfully migrated existing information. As a result, we know how the solutions and licensing models of these vendors work in practice and can advise companies in a targeted way – both on tool selection and on implementation. Below, we list the solutions we know and trust.
– Athereon GRC: Cloud-based SaaS model with a modular structure. Free basic version available, can be extended with modules such as ISMS or BCM. No trial version. – Zazoon: Cloud-based, licensed by number of employees. Starting at approx. CHF 500 per month. Free trial access available. – Swiss GRC Toolbox: Cloud or on-premises. Flat-rate model starting at CHF 4,900 per year, regardless of the number of users. Trial version available, individual quotes possible.
Benefits of using GRC tools
Using GRC tools offers a number of benefits, reflected in particular in efficiency, transparency and standardization:
– A central platform instead of isolated solutions. – Greater efficiency through automated workflows and reporting. – Transparency and traceability for management and internal audit.
– Scalability and modular extensibility. – Standardized processes and documentation of evidence. – Better audit readiness through consolidated evidence.
Drawbacks and challenges
At the same time, there are also challenges and potential drawbacks that should be considered when introducing and using a GRC tool: – Implementation costs for licenses and projects. – Complexity of implementation and possibly process adjustments. – Training and adoption effort among employees. – Risk of over-administration (the tool dictates the processes). – Vendor dependency if no exit strategy has been agreed (vendor lock-in). – Integration effort in existing IT landscapes.
Selection and implementation factors
Key selection criteria are: usability, integration capabilities, customization options, a licensing model that fits the size of the company, and a phased implementation (e.g. starting with the ISMS). A clear role model and change management for both the solution and the internal control system (ICS) it maps increase the chances of success.
Conclusion and outlook
GRC tools are indispensable for companies that want to manage regulatory and security requirements holistically. They provide central transparency, efficiency and audit readiness. However, implementation requires clear project structures, budget and stakeholder involvement. In the future, the trend will move toward automation and AI-powered features – for example in risk forecasting or predictive compliance. With blu Guard at their side, companies can ensure that selection, implementation and migration are carried out successfully.
Support from blu Guard
blu Guard supports companies through all key steps of introducing a GRC tool. This starts with selecting the right system, taking into account individual requirements, company size and the regulatory framework. blu Guard then supports the rollout and implementation of the selected tool as well as the migration of existing information from previous solutions such as Excel or Word to the new platform. In addition, we provide comprehensive advice on the necessary ICS (internal control system) processes and review their design for efficiency and compliance. In this way, we ensure that the solution in use
not only works technically, but is also optimally embedded in the organizational structures and delivers real added value in the long term.