Know where
you stand
Inspect360 GRC is a platform that connects frameworks, requirements, policies, risks, controls, evidence and audits into one continuously maintained view of how your organisation is governed.
Process-oriented workflow: from framework mapping and policy ownership through risk, evidence and assurance. It keeps the record current rather than assembling it before each audit.
how it differs from traditional GRC
Inspect360
GRC
Map the requirements
Govern the risk
Prove the compliance
What is Inspect360 GRC?
Governance, risk and compliance in one view
Inspect360 GRC connects the frameworks an organisation is subject to, the policies written to meet them, the risks underneath, and the evidence that its controls are actually operating.
It counts compliance from the current status of each requirement, instead of estimating. It also tracks missing owners, missing evidence and missed review dates as their own visible measures, rather than leaving them for someone to notice.
This matters more than it used to. NIS2, DORA and a growing set of national law ask organisations to show what they actually do, not only what they've written down: who owns each policy, whether the evidence behind a control is current, and what risk remains once it's applied.
A control requirements checklist isn't a governance programme.
How it works
Compliance is the outcome of governance, not a separate exercise
A governance programme means owning the policy behind each requirement, treating the underlying risk, gathering evidence that the control operates, recording the decision, and keeping the whole picture under review.
Map → Own → Assess → Evidence → Decide → Assure
Map:
Map the control requirement and applicability.
Own:
Risk and policy are assigned named owners.
Assess:
Risk, treatment and residual exposure.
Evidence:
Documents, logs, sign-offs and certificates.
Decide:
Review, approve, accept or except.
Assure:
Audit, report and keep it traceable.
A broader picture
A framework list isn't your governance posture
Beyond knowing which regulations and standards apply, Inspect360 GRC organises the whole programme into five categories, so decision-makers can choose the view that best answers the question in front of them:


One record, five ways in.

Risk in context
A framework percentage without a decision behind it is just a number
A requirement can be fully met on paper and still carry risk: there is no owner, its review is overdue, and the evidence is out of date.
In Inspect360 GRC, each risk carries an inherent score, a residual score after treatment, a named owner, an approver and a next review date. The score is shown with the decision behind it.
See where one control answers several requirements
Regulations and standards overlap. The same access-control policy, the same encryption standard, the same incident-response procedure can meet requirements in, for example, ISO 27001, NIS2, DORA and national law at the same time. Most programmes collect evidence several times anyway.
The Controls Library records what the organisation actually does, as opposed to what any single standard asks for. Attach the evidence once and it is mapped to every requirement that the control applies to.

ONE CONTROL
What does a specific control do?
MANY FRAMEWORKS
Which requirements, across which regulations and standards, does it apply to?
ONE EVIDENCE TRAIL
Attach it once and it counts everywhere it applies.
Compliance starts before the audit
Inspect360 GRC treats compliance as the result of clear governance and controlled risk management, not as a separate exercise.
GOVERNANCE
Who owns the decision?
Set policy ownership, approval rights and review cadence. Each policy, standard and process carries a named owner and a version history.
RISK
What are we exposed to?
Understand inherent and residual exposure, treatment status, accepted risk, and what changes when a control weakens or a review lapses.
COMPLIANCE
Can we prove what we did?
Connect requirements, controls, evidence, audits and decisions to the obligations that apply to your organisation.
Map the requirement → Govern the risk → Prove the compliance
Govern every policy and risk from the start
Each policy in the library has a stage, an owner and an approver. Every risk has an owner, an approver and named review assignees. Each requirement has an applicability decision on record rather than an assumption.


Answer the requirements that apply
Inspect360 GRC can record which requirements genuinely apply to your organisation, rather than treating every clause of every standard as equally relevant. A framework can be adopted, assessed, and marked not applicable for the parts that don't apply, with the reasoning kept on record.
The point is simple. Answer the requirements that apply to your organisation, not the ones that happen to exist in a standard.
Know which regulations you're answering
Compliance is also jurisdictional. The framework portfolio holds, for example, EU-level regulation alongside the national law that applies in each market, tracked at the same time.
The point is that, for example, a Swedish requirement, a Norwegian one and a Danish one are owned, evidenced and reported separately, because they are separate obligations.


Risk doesn't stand still
An assessment captures a risk at one moment. Ownership changes, controls weaken, and exceptions expire. Inspect360 GRC keeps the risk, its treatment and its review history connected, so that the record is a living one rather than an annual file.
Every accepted risk carries its own exception record with the reason it was accepted, who approved it, and when that approval expires. An accepted risk isn't accepted indefinitely by default.
Answers you can check, decisions you still own
Inspect360 GRC uses AI to reduce repetitive work and surface what needs attention, without removing accountability from the people who own the decision.
What should I do today
Surfaces what is overdue, pending, or waiting on you specifically.
Spot the gaps
Clarifies what is missing in supplier, policy or control records.
Why is this flagged?
Explains the reasoning behind a status, not just the status.
Suggest a reassessment interval
Proposes a review cadence based on the record's own risk profile.
Extract obligations
Pulls the specific obligations out of a document or contract for review.
Which report answers this?
Points to the report template that already covers the question being asked.
Know what was known, who decided, and what happened next
When a regulator, auditor or board member asks, the answer shouldn't depend on an old spreadsheet or finding a policy nobody can locate.
Inspect360 GRC keeps the audit programme, evidence, policy reviews, risk decisions and exceptions connected, so the record of how the organisation was governed is always there.

What was known:
The requirement, the control, and the evidence available at the time.
What was decided:
Who reviewed, approved, accepted or granted an exception.
What happened next:
Reassessment, remediation, escalation, and closure.
Governance isn't owned by one department
Different teams hold different parts of the picture. Inspect360 GRC gives them a shared place to contribute, review and act without forcing everyone into the same role.

Risk & Compliance
Owns the frameworks, controls and the review cadence behind them.
Procurement
Brings supplier and partner risk in from Inspect360 TPRM.
Security
Understands technical exposure, incidents and control health.
Audit
Owns the audit programme and keeps assurance evidence traceable.
Legal & Privacy
Owns the data protection obligations and the evidence behind them.
Leadership & Board
Sees the organisation in five categories, and what needs a decision.
One system. Shared intelligence. Clear accountability.
Grow when you’re ready
Inspect360 GRC doesn't require full-scale maturity from day one. Organisations can begin with a controlled framework and policy baseline, then add deeper risk, assurance and cross-framework capability as the programme matures.
01
Foundation
- Framework mapping
- Policy Library
- Asset Register
- Risk Register
- Applicability decisions
02
Govern
- Policy ownership
- Review cadence
- Controls Library
- Evidence Store
- Compliance Dashboard
03
Assess
- Risk treatment
- Exceptions
- Audit Programme
- Incident Log
- Questionnaires
04
Assure
- Board and scheduled reporting
- AI assistance
- Cross-framework control reuse
- Third-party risk via
Inspect360 TPRM
You don’t need to implement all of Inspect360 GRC to benefit from Inspect360 GRC.
Less duplication, fewer blind spots, and traceable decisions
Less duplication
Map a control once and reuse it across every framework it is applicable to.
Traceable decisions
Every acceptance and exception carries who decided, and when it expires.
Fewer blind spots
See which requirements that haven't an owner, evidence, or no review scheduled.
Less chasing
Reuse information and evidence across requirements instead of collecting it repeatedly.
Easier assurance
Keep the evidence of assessments, decisions and remediation ready for review.
One connected record
Frameworks, policies, risks, controls, evidence, incidents and audits in one place.
Questions asked
Isn't a spreadsheet of frameworks and policies enough?
No. A framework list and a folder of policies are a starting point, not a governance programme. Effective governance also requires knowing who owns each policy, whether the evidence behind a control is current, what risk sits underneath each requirement, and who decided what and when. Inspect360 GRC connects those activities into a traceable record.
How is Inspect360 GRC different from a compliance spreadsheet or a generic GRC tool?
Generic tools treat each framework as a separate exercise. Inspect360 GRC maps controls once and reuses them across every framework they are applicable to, so evidence gathered for one standard counts toward the others it also covers, instead of being collected repeatedly.
How does Inspect360 GRC relate to Inspect360 TPRM?
They are companion products on the same platform. Inspect360 TPRM manages the suppliers, sub-suppliers and dependencies an organisation relies on. Inspect360 GRC is where that third-party risk becomes part of the wider governance picture, alongside internal policy, risk, controls and audit. Supplier and partner records are shared between the two rather than duplicated.
Does Inspect360 GRC replace our existing GRC programme?
No. It strengthens an existing programme by connecting frameworks, policy ownership, risk, evidence and decisions that are usually scattered across spreadsheets, shared drives and email. It complements established governance rather than requiring you to replace it.
Do all frameworks need the same level of governance?
No. Applicability is a decision, not an assumption. Inspect360 GRC records whether a framework or a requirement is complete, not yet started, or not applicable to your organisation, so effort is focused on what genuinely applies.
Do we need to implement everything at once?
No. Inspect360 GRC is designed to grow with your organisation. You can begin with framework mapping, policy ownership and a risk register, then add risk treatment, audit programmes, evidence management and cross-framework control mapping as your governance matures.
How many frameworks can we track at once?
There is no fixed limit, and national law is tracked separately from the EU instrument it transposes. The platform's own portfolio runs EU-level regulation and Nordic national law side by side, each reported on independently.
Can we use our own policies and controls, or only a standard library?
Inspect360 GRC includes a baseline policy and control library, and organisations can add their own. Every policy carries a version history, an owner, an approver and a compliance status, whichever library it came from.
How does Inspect360 GRC use AI?
AI supports work such as surfacing what needs attention, summarising where a record has gaps, explaining why something is flagged, suggesting a review interval, and extracting obligations from a document. It reduces manual effort, not accountable decision-making. Human accountability remains with the relevant organisational role.
How does Inspect360 GRC help with audits?
The platform maintains a traceable record of frameworks, policies, controls, evidence, risk decisions, exceptions and audit activity.
Where is our data stored and protected?
Inspect360 GRC is hosted in the EU. Information, evidence, assessments and decisions never leave the region, which matters for NIS2, DORA and GDPR obligations, and for buyers with data-residency requirements written into their own governance.
Access is controlled through role-based access control (RBAC), with support for SSO/OAuth and MFA. Data is encrypted both in transit and at rest, and activities are recorded in an audit trail. Detailed encryption standards and our commitments for backup and recovery are documented in our security schedule, available on request.
Is Inspect360 available in multiple languages?
Yes. Inspect360's interface is available in English and the Nordic languages. Additional languages are added as needed, initially through AI-assisted translation and refined over time based on user feedback. Users can submit language corrections or suggestions from anywhere in the application, which route directly into our ticketing system. This lets us support new languages quickly while improving the quality of existing ones continuously.
Know where you stand
Map the requirements. Govern the risk. Prove the compliance.

Njordium is based in the Nordics, and the name comes from Njord, the Norse god of the sea, symbolising insight and deep knowing beyond the surface, a fitting reference for a firm founded to guide organisations navigating the cyber landscape.