Governance · Transformation
June 2026
10 min read

From A to Z: transforming an organisation into a GRC-aware institution

"Who here is responsible for compliance?" In organisations at the beginning of their journey, people point — to a department, a floor, a name. In organisations that have completed it, the question produces a mildly puzzled look: "Well — everyone. Obviously." The distance between those two answers is the transformation this article is about.

There is a question I have asked in many institutions, at many levels, and the answer is always revealing: "Who here is responsible for compliance?" In organisations at the beginning of their journey, people point — to a department, a floor, a name. In organisations that have completed the journey, the question lands differently. People look mildly puzzled and answer some version of: "Well — everyone. Obviously." The distance between those two answers is what this article is about, because I have spent a meaningful part of my career helping institutions travel it.

Transforming an organisation into one that is genuinely GRC-aware — from the executive committee to the newest hire, across every department and every subsidiary — is not a project. Projects have end dates. This is a change in what the institution is, and it follows a logic that I have seen hold true across banks, wealth managers and industrial groups alike.

Start with an honest map, not an aspiration

Every transformation begins with the same temptation: to start building toward the target picture immediately. Resist it. The first investment must be an honest map of where the organisation actually stands — and honesty here is harder than it sounds, because every department will present its best face, and the formal picture (policies exist, trainings completed, attestations signed) almost always flatters the real one.

The real map comes from different questions. Not "does a policy exist?" but "does the team on the fourth floor know what it asks of them, and do they do it when nobody is checking?" Not "was the training completed?" but "can a relationship manager explain, in her own words, why the source-of-wealth question matters?" Not "are the subsidiaries covered by the group framework?" but "what actually happens in the Singapore office on a Tuesday?" The gap between the documented organisation and the lived one is the true starting point — and mapping it without blame is essential, because a diagnostic that feels like a prosecution will never be answered honestly again.

The sequence that works: leadership, translation, embedding, proof

Across every successful transformation I have been part of, the same sequence appears — and attempts to shortcut it consistently struggle.

It begins at the top, visibly. Not with the leadership's approval — approval is cheap — but with its behaviour. The day the executive committee delays a revenue decision because the risk assessment is not yet complete, and lets the organisation see it, is worth more than a year of awareness campaigns. Employees are superb readers of what leadership actually rewards. Until the top demonstrates that GRC considerations genuinely shape decisions, every message about compliance culture is received as weather: noted, and waited out.

Then comes translation. A group-wide framework speaks a language that most of the organisation does not: inherent risk, control objectives, three lines, appetite statements. The transformation succeeds or stalls at the point of translation — where the framework becomes, for each department, a short and concrete answer to the only question employees really ask: "What does this mean for what I do on Monday?" For the trade finance team, it means these five checks, in this order, before release. For HR, it means this screening, this escalation route. For the subsidiary CFO, it means these group thresholds override local practice, and here is whom to call when they conflict. I have seen brilliant frameworks fail for want of this translation, and modest ones succeed because of it.

Then embedding — into the machinery, not alongside it. As long as GRC lives in separate documents, separate trainings and separate systems, it remains optional in practice. The turning point is when it disappears into the normal way things are done: the client-onboarding workflow that will not proceed past a missing verification, the product-approval template in which the risk assessment is a built-in section rather than an attached afterthought, the performance objectives in which conduct carries real weight, the management meeting whose standing agenda includes the risk picture. Culture follows structure more often than the reverse; if the compliant path is also the easy path, most people take it without ceremony.

"An institution is GRC-aware not when everyone can recite the policy, but when the person furthest from head office does the right thing on an ordinary Tuesday — because it is simply how things are done here."

And finally, proof. Transformations run on credibility, and credibility runs on visible consequences — in both directions. The employee who escalated an uncomfortable concern is thanked publicly, and her career does not suffer; everyone notices. The senior producer whose conduct crossed a line experiences consequences despite his revenue; everyone notices that even more. Institutions communicate their real values through their exceptions. A transformation that spares its exceptions announces, quietly and definitively, that nothing has changed.

The subsidiary challenge: one standard, many realities

Extending GRC awareness across subsidiaries deserves its own honesty, because it is where many group-wide programmes meet their hardest terrain. A subsidiary is not a smaller copy of head office. It has its own regulator, its own market practice, its own history, often its own pride — and a long memory of group initiatives that arrived with fanfare and departed with the sponsoring executive.

What works, in my experience, is a firm centre with genuine local ownership. The group sets the non-negotiables — the standards below which no entity may operate, regardless of local custom — and then invests in local translation rather than mechanical rollout: local risk officers with real standing and a direct line to group, local training in local context, local management accountable for the culture and not merely the attestations. The group's role becomes setting the standard, verifying reality against it, and supporting the entities honestly struggling to reach it. The alternative — head-office paper pushed outward and signed obediently — produces perfect documentation and untouched practice, which is the most dangerous combination of all, because it looks like success.

How you know it is working

The metrics will tell you something: training completion, incident trends, audit findings, escalation volumes — which should rise in a healthy transformation before they fall, because rising escalations mean rising trust. But the surest signals are quieter. Business units start inviting the second line into projects early, voluntarily, because its input has proven useful rather than obstructive. Difficult questions are asked in meetings by people whose job descriptions do not require them. New joiners absorb the standards within weeks, from colleagues rather than compliance training. And the question with which I began — "who is responsible for compliance?" — starts to produce that mildly puzzled look, in the subsidiaries too.

None of this is quick. In my experience, the honest horizon for a genuine A-to-Z transformation is measured in years, not quarters, and the work is never entirely finished — regulation moves, people move, and awareness left untended fades. But institutions that make the journey acquire something of permanent worth: they stop experiencing GRC as a cost imposed from outside and start experiencing it as what it truly is — the discipline that lets an institution be trusted with other people's wealth, decade after decade. In private banking, and well beyond it, there is no more commercial asset than that.

SB
Stanislav Bogomolov
Governance & Compliance Leader · Swiss Private Banking & Wealth Management
Senior GRC professional with extensive experience in Swiss private banking and wealth management. Writing on governance, risk management, compliance, board leadership and digital transformation — for practitioners, board members and senior management navigating the Swiss and EU regulatory environment.
All content on this website is the intellectual property of Stanislav Bogomolov and is protected under Swiss copyright law (URG) and applicable international conventions. Reproduction, republication or commercial use of any content without prior written consent is prohibited. Content is provided for informational purposes only and does not constitute legal, financial, regulatory or compliance advice. No liability is accepted for any reliance on content published herein. Personal data is processed in accordance with the Swiss Federal Act on Data Protection (nFADP) and, where applicable, EU GDPR.  ·  Legal Notice & Privacy Policy