Group Risk Management at Zurich Insurance Group (Zurich) transforms enterprise GRC on IBM OpenPages, without a single line of custom code
Group Risk Management at Zurich Insurance Group, further referred to Zurich’s Group Risk Management, is not a back-office function; it is a strategic imperative. The pressure to govern non-financial risks with precision has only intensified as regulatory requirements expand across jurisdictions, cyber and third-party exposures grow in complexity, and regulators increasingly expect organizations to demonstrate not just awareness of risk, but integrated control over it.
In parallel, the rapid development of artificial intelligence is reshaping the work of risk officers and risk managers. New AI-driven tools offer opportunities to enhance risk identification, assessment and reporting, but they also introduce model, data and ethical risks that require robust governance. To capture these benefits safely and effectively, Zurich’s Group Risk Management sought to make a technology leap forward—modernizing its risk management platforms to be ready to integrate AI capabilities into core risk processes, while maintaining strong oversight, transparency and regulatory compliance.
Group Risk Management at Zurich chose a greenfield approach: design the right data model first, then build core processes on top of it. For the technology layer, Zurich’s Group Risk Management selected IBM OpenPages, an AI-powered, scalable SaaS GRC platform. The choice came down to flexibility, platform maturity, and IBM’s roadmap for AI integration.
As AI becomes embedded in underwriting, claims, and internal operations, having GRC and AI governance on a shared architecture is not a future consideration. It’s a present requirement, particularly when companies look to maintain control, transparency, and regulatory compliance for models and data across jurisdictions in line with emerging AI regulatory requirements.
Zurich’s Group Risk Management chose the SaaS deployment model, transferring responsibility for cloud infrastructure, security operations and platform updates to IBM, keeping the risk team focused on risk, not IT.
IBM Business Partner Pentos, with more than 17 years of IBM OpenPages experience, supported the implementation alongside Zurich’s Group Risk Management as a single delivery team. Every requirement was met using native OpenPages capabilities, UI configuration, workflows, and calculations. Not a single line of custom code was written, reducing long-term complexity and total cost of ownership. This approach also helps ensure that the solution can evolve in line with changing regulatory and governance requirements without being constrained by hard-coded dependencies.
A central design principle was connecting risks and controls in one unified data model, with issues, action plans and regulatory requirements all flowing from the same shared architecture. Running on a SaaS platform with well-defined data residency and auditability controls also supports Zurich’s Group Risk Management’s commitment to data management, enabling clear visibility and control over where risk data resides and how it is governed.
The deployment gives Group Risk Management a global, cloud-based GRC foundation with a unified view of non-financial risk across Zurich Insurance Group. Risk managers and risk owners work through an integrated platform where risks, controls, action plans, and regulatory requirements are connected.
The zero-customization approach reduces system complexity, limits upgrade friction, and eliminates the maintenance overhead that comes with bespoke code.
Looking ahead, Zurich’s Group Risk Management plans to continually evolve the platform to better support the needs of risk owners across Zurich Insurance Group. This includes implementing AI-driven capabilities that enhance usability, streamline workflows and improve the overall user experience.
Zurich’s Group Risk Management provides the governance, frameworks and oversight needed to manage non-financial risk consistently across the Group. Its work supports Zurich’s ability to identify, assess, monitor and mitigate risks across jurisdictions while maintaining transparency, accountability and regulatory alignment.
Pentos is a specialized IBM Business Partner focused on GRC and corporate analytics. With more than 17 years of experience implementing IBM OpenPages for enterprise clients, Pentos advises organizations on translating complex risk management requirements into scalable platform solutions—without customization.
© Copyright IBM Corporation June, 2026.
IBM, the IBM logo, and IBM OpenPages are trademarks of IBM Corp., registered in many jurisdictions worldwide.
Examples presented as illustrative only. Actual results will vary based on client configurations and conditions and, therefore, generally expected results cannot be provided.