Njordium Launches Inspect360 GRC, Bringing Governance, Risk and Third-Party Risk into One Connected Platform

Oct 1, 2026 | News

Stockholm, Sweden - 1 October 2026 - Njordium Cyber Group AB today announces the official launch of Inspect360 GRC, its new Governance, Risk and Compliance platform, developed in Sweden to give organisations a continuously maintained view of how they are governed, where risk exists, and whether compliance can be demonstrated.

The launch also establishes Inspect360 as Njordium's common platform for governance and risk management. Inspect360 GRC works alongside Inspect360 TPRM, Njordium's Third-Party Risk Management solution, bringing internal governance and external dependencies together rather than treating them as separate programmes.

For many organisations, GRC has become increasingly fragmented. Regulatory requirements are in one system, policies in another, risks in spreadsheets, evidence in shared folders and supplier assessments somewhere else again. At the same time, EU legislation including NIS2, DORA and GDPR now explicitly requires organisations to manage cybersecurity risk, operational resilience and third-party dependencies in a systematic, documented and auditable way: not as periodic exercises, but as a continuous programme with clear accountability. The result of fragmentation is considerable effort spent maintaining compliance information that does not necessarily produce the clearer understanding of risk that the business needs, or the evidence trail that regulators and auditors expect.

Inspect360 GRC takes a different approach. It connects frameworks, requirements, policies, risks, controls, evidence, exceptions and audits into one traceable record. Controls can be mapped once and reused across the regulatory and standards requirements they support, reducing duplicate assessments and repeated evidence collection.

The principle behind the platform reflects Njordium's wider approach to GRC: Governance directs. Risk is managed. Compliance is an outcome.

"Compliance should tell us something about how well an organisation is governed; it should not become the objective in itself," said Mads Becker Jørgensen, CEO of Njordium Cyber Group. "With Inspect360 GRC, we wanted to move the focus away from maintaining individual compliance checklists and towards understanding the relationships between requirements, controls, evidence, decisions and the risks they are intended to manage."

Inspect360 GRC provides framework mapping, policy and control libraries, risk and asset registers, evidence management, applicability decisions, risk treatment, exceptions, audit programmes, incident records and management reporting within the same platform. AI-assisted capabilities help identify gaps, surface overdue actions, extract obligations and explain why something requires attention, while accountable decisions remain with the organisation.

The platform is designed to support multiple regulatory and standards frameworks simultaneously. Rather than maintaining separate control environments for each framework, organisations can map common controls and evidence across overlapping requirements and maintain the individual applicability and reporting needed for each obligation.

GRC and third-party risk in one portfolio

The launch builds on Njordium's third-party risk platform, previously developed under the Third-Party Risk Management and Vendor Management System names and now consolidated as Inspect360 TPRM.

Inspect360 TPRM provides visibility across suppliers, sub-suppliers, services and dependencies, connecting onboarding, due diligence, risk, evidence, financial oversight and ongoing monitoring. Inspect360 GRC brings that information into the organisation's wider governance and risk picture.

Together, the two solutions address both sides of the same question: what does the organisation need to govern, and what does it depend on?

"Organisations don't experience internal risk and third-party risk as two separate realities," said Kim Haverblad, Senior Advisor at Njordium. "A critical supplier can affect a business service, regulatory obligation, control, risk treatment and management decision at the same time. Yet those relationships are often managed in completely different systems. Inspect360 is about connecting that picture so management can understand not just whether something is compliant, but what it affects, who owns the decision and whether the evidence supports it."

European by design, with deployment choice

For organisations operating in regulated environments, where information is stored and who controls it can be as important as the functionality of the platform itself.

Inspect360 is developed in Sweden by Njordium Cyber Group, a European company, and is designed with the requirements of European organisations in mind.

The Inspect360 platform is offered as a SaaS solution for organisations that want a managed service and straightforward deployment. For organisations where regulatory obligations, contractual requirements, internal policies or data sovereignty considerations require greater control over where information resides, Inspect360 can also be deployed on-premises within the customer's own environment.

This deployment flexibility allows organisations to select the model appropriate to their governance and risk requirements without having to compromise the underlying Inspect360 capabilities.

"Data sovereignty should ultimately be a governance decision made by the organisation," said Haverblad. "For some customers, a managed SaaS service is exactly the right model. Others operate under requirements where they need greater control over where information is stored and how the platform is operated. We designed Inspect360 so that the deployment model does not dictate that decision."

Inspect360 GRC and Inspect360 TPRM share the same underlying philosophy: information should be collected once, connected to its context and reused wherever it is relevant. This allows organisations to move from periodic compliance exercises towards continuously maintained governance and risk management.

Key capabilities across the Inspect360 portfolio include:

  • Connected GRC - frameworks, policies, risks, controls, evidence, exceptions and audits maintained as one traceable record.

  • Cross-framework control mapping - map controls and evidence once and reuse them across applicable regulatory and standards requirements.

  • Integrated third-party risk - connect suppliers, sub-suppliers, services and dependencies directly with the wider governance and risk environment.

  • Risk in context - maintain inherent and residual risk, treatment, ownership, approvals and review cycles alongside the controls and evidence that affect them.

  • Traceable decisions - retain who knew what, who made a decision, why it was made and what happened afterwards.

  • API integrations - connect Inspect360 with other business and technology platforms through APIs, with integrations in use today, for example, ServiceNow, Microsoft, Jira, SAP, GitLab and GitHub.

  • Flexible authentication - support Google and Microsoft OAuth authentication flows, including the use of hardware security keys such as YubiKey and Google Titan.

  • Deployment choice - use Inspect360 as a managed SaaS service or deploy it on-premises where regulatory, security or data sovereignty requirements call for greater organisational control.

  • AI-assisted workflows - reduce repetitive work, identify gap sand surface information requiring attention while retaining human accountability.

  • Audit and assurance - maintain evidence and decision histories continuously rather than reconstructing them ahead of an audit.

Both Inspect360 GRC and Inspect360 TPRM are designed to grow with an organisation's maturity, allowing organisations to start with the capabilities they need today and expand as governance, risk and assurance requirements develop.

Inspect360 GRC: Know where you stand. Map the requirements. Govern the risk. Prove the compliance.

Inspect360 TPRM: Know what you depend on. See the ecosystem. Govern the relationship. Manage the risk. Evidence compliance.

About Njordium Cyber Group

Njordium Cyber Group AB is a European cybersecurity and Governance, Risk and Compliance company headquartered in Stockholm, Sweden, with offices in Malmö and Oslo.

Njordium works across information security, governance, risk, compliance, third-party risk management and process improvement. Its Inspect360 platform is developed in Sweden and provides organisations with a connected approach to GRC and third-party risk management, with both SaaS and on-premises deployment options.

Njordium's approach is built around a simple principle: Governance directs, Risk is managed, and Compliance is an outcome. By connecting business context, people, processes, technology and regulatory requirements, Njordium helps organisations move beyond surface-level compliance and build governance that supports informed, traceable decisions.

 

Media Contact:

Kim Haverblad

Senior Advisor

Njordium Cyber Group AB

+46 76 00 46 232
media@njordium.com

 

Njordium is based in the Nordics, and the name comes from Njord, the Norse god of the sea, symbolising insight and deep knowing beyond the surface, a fitting reference for a firm founded to guide organisations navigating the cyber landscape.

Contact

Stockholm: +46 8 5078 05 06

Malmö: +46 40 686 00 46

Oslo: +47 977 59 000
contact@njordium.com