Apply for this job

We collaborate with best-in-class platforms, consultants, and technology providers to deliver seamless, future-proof solutions, built to grow with your organization.

Download Whitepaper

We collaborate with best-in-class platforms, consultants, and technology providers to deliver seamless, future-proof solutions, built to grow with your organization.

AI built into every step of your GRC workflow.

Documentation and reporting eat time your team could spend on analysis. CERRIX puts AI to work across your workflow, with conversational GRC so you query and report straight from the AI agent you already use.

GRC challenges

Risk and reporting work, still mostly manual:

  • Writing descriptions eats expert time.
  • Every question means logging into the platform first.
  • Risks sit buried in policy documents.
CERRIX GRC platform

AI that assists, humans who decide:

  • Descriptions created in seconds.
  • Ask, update, and report from the AI chat you use.
  • Risks and controls extracted from your documents.

Meet conversational GRC

With the CERRIX LLM integration you work with your GRC data straight from the AI agent you already use, like Claude or Microsoft Copilot. Querying, updating and reporting that used to be manual now happen straight from your chat.

Solving real-world GRC challenges with one smart platform

Aligned stakeholders across risk, compliance, and audit

Reliable data that supports better decisions

Tailored configuration that matches your governance frameworks

Phased onboarding that reduces risk and accelerates adoption

GRC implementation that goes beyond tool setup

Rolling out GRC implementation is more than launching software. It’s about creating clarity in your processes, consistency in your data, and aligning and motivating all 3 lines to work together. At CERRIX, we guide you through every step.

Configuration completed in one month
Stakeholder-specific dashboards
Cross-country risk and control data

Understand, align, prepare

We begin by forming a strong foundation:

Define objectives, scope, and success criteria
Conduct kickoff & initial training
Engage all key stakeholders from day one
Prepare your governance, communication, and milestone plans

Configure, Customize, Validate

We tailor the platform to your organization’s needs:

Configure your organization, frameworks, and metadata
Align configuration with your policies and risk strategy
Prepare and review data for quality and consistency
Set up reporting dashboards and user access

Test, Train, Launch

We ensure your team is ready to succeed:

Run acceptance testing with full coverage
Conduct role-based user training
Set the official go-live date
Announce internally and provide go-live support

Evaluate, Improve, Expand

Post-go-live, we help you evolve:

Collect lessons learned and evaluate
Refine configuration based on feedback
Plan next steps for continuous improvement
Expand to other business units or use cases

Real Results, Real Impact

How Blauwtrust Groep centralized its control framework in CERRIX GRC Platform

“CERRIX has given us overview, insights and structure. It allows us to demonstrate control in a way that is consistent and efficient, and it supports the way our governance framework continues to evolve.”

How VGZ Strengthens Risk & Compliance Operations with CERRIX

VGZ uses the CERRIX GRC platform to bring core activities, such as control testing, incidents, MoIs, findings and risks, into one environment.

Transforming Compliance: How Menzis Gained Efficiency and Real-Time Insights with CERRIX

Menzis, one of the largest healthcare insurers in the Netherlands, seeking an integrated and automated GRC solution to streamline compliance, enhance risk oversight, and improve operational efficiency.

Structuring Risk and Audit Across Teams: Haier Europe’s Journey

Haier Europe’s approach to risk and audit transformation with CERRIX.

Transforming Risk Culture: How Stater Strengthened First-Line Ownership and Assurance with CERRIX

Stater’s journey to first-line risk ownership and assurance with CERRIX.

Enterprise-grade security

Data protection

ISO/IEC 27001 certified to ensure your organization meets global standards for information security and governance.

Control assurance

ISAE 3402 Type II verified, with independently audited internal controls that guarantee service reliability and compliance.

Financial sector readiness

FSQS-NL registered — pre-qualified for procurement by leading banks and insurers in the Netherlands.

AI-refined risk and control descriptions
Document upload with risk and control extraction
Automated control testing and sampling
Conversational access to your GRC data