Know what
you depend on
Inspect360 connects suppliers, sub-suppliers, services, dependencies, risk, controls and evidence into one continuously maintained view of the third parties your organisation relies on.
From onboarding and assessment through monitoring, evidence and review, one connected process built around how third-party risk is actually managed today.
how it differs from traditional TPRM
Inspect360
Govern the relationship
Manage the risk
Evidence compliance
Collecting evidence is not the same as managing risk
Most organisations still approach third-party risk the way it was approached years ago. A questionnaire at onboarding, an ISO certificate on file, a review scheduled for next year. That was enough when the regulator asked whether you had a process.
The question has changed. NIS2, DORA and the CRA now ask what you actually knew about the supplier the day before the incident, and whether you can show it. A folder of expired attestations doesn't answer that. A living record of what changed, when you saw it, and what you did about it, does.
Hidden dependencies
You contract with Vendor A. Vendor A relies on Supplier B. Supplier B provides a critical service, and you have no relationship with them.
Shared exposure
Five vendors can look like five relationships. If all five sit on the same cloud provider, you have one shared point of failure.
Changing risk
Ownership, security posture, sanctions status and controls change. An annual questionnaire doesn't.
Financial anomalies
A legitimate supplier does not automatically mean a legitimate invoice. Payment patterns can reveal issues assessments never catch.
A tick-box programme cannot see these. A connected view can.
Third-party risk is a process, not a questionnaire
Understanding a supplier is only the beginning. Managing third-party risk means connecting the supplier to the services you rely on, identifying the risks and requirements that matter, gathering evidence, assigning ownership, recording decisions, and keeping the assessment under review.
Understand → Assess → Evidence → Decide → Monitor → Prove
Understand:
Supplier, service and dependency.
Assess:
Risk, requirements and controls.
Evidence:
Questionnaires, certificates and documentation.
Decide:
Review, approve, mitigate or accept.
Monitor:
Changes, findings and emerging risk.
Prove:
Decisions and evidence remain traceable.
Your vendor register isn’t the supplier network
Knowing who you buy from is only the beginning. Inspect360 maps the suppliers, sub-suppliers and dependencies behind them, so you can see the network your organisation actually relies on.



Risk lives in the relationship, not the vendor name
The same supplier can represent very different levels of risk depending on the service they provide, the information they handle, and how critical they are to your organisation.
CIAP (Confidentiality, Integrity, Availability, Privacy) scores every supplier relationship on the four dimensions that actually determine exposure.

See where dependency becomes concentration
Several suppliers can look independent while relying on the same underlying provider. Inspect360 shows where that is the case and how a change in one part of the network can affect other relationships.
Five vendors may look like five separate relationships. If all five depend on the same cloud provider, data centre or software component, you have one shared point of failure, not five.

DEPENDENCY
Who relies on whom?
CONCENTRATION
Where are many relationships dependent on one provider?
IMPACT
Which relationships are affected when risk changes?
Compliance starts before the questionnaire
Inspect360 treats compliance as the result of clear governance and controlled risk management, not as a separate exercise at the end.
GOVERNANCE
Who owns the decision?
Set clear roles, approval rights and segregation of duties. Vendor Managers coordinate the work; Service Owners approve; specialists contribute where needed.
RISK
What are we exposed to?
Understand criticality, dependencies, concentration, risk changes and what those risks mean for the services you rely on.
COMPLIANCE
Can we prove what we did?
Connect assessments, controls, evidence, remediation and decisions to the obligations that apply to your organisation.

Govern every supplier from the start
Vendor Manager gathers and maintains information. Service Owner owns the business relationship and approves. Compliance Manager reviews evidence and requirements. Every supplier moves through the same controlled path, with named accountability at each stage.


Ask the questions that matter
Inspect360 can decide which assessments are relevant based on the supplier, what they provide and the risks or obligations involved.
A supplier processing personal data can trigger privacy questions. A relevant industry classification can trigger AML checks. The point is simple: ask questions because they matter to the relationship, not because they happen to exist in a checklist.
Use a strong baseline, add what your organisation needs
Inspect360 includes baseline questionnaires that can support regulatory, security and third-party due-diligence needs. Organisations can also add their own tenant-specific questionnaires, make them mandatory, or use them only when a particular situation requires it.
Questions can be organised into sections, weighted and made conditional so that follow-up questions appear only when they are relevant. This keeps the assessment focused while still allowing deeper review when the answers call for it.

A risk score without context is just a number
Inspect360 shows what drives the score, which relationships are affected, and where action will have the greatest impact.
Inspect360 brings together supplier risk, service criticality, concentration and external information so that teams can see where attention is needed and why.
Instead of treating every vendor as an isolated score, the dashboard gives management a clearer view of overall exposure, critical suppliers and where risk is accumulating across the network.


Know where your exposure sits
Third-party risk is also geographic. Inspect360 can show where suppliers and related exposure are concentrated, helping teams understand country-level dependencies and where changes in the external environment may matter most.
The point is not another map for its own sake. It is to connect location back to the suppliers, services and risks your organisation depends on.
Risk doesn't stand still
An assessment captures a supplier at one moment. Supplier information changes, certificates expire, findings are raised and closed, services change, new dependencies appear. Inspect360 keeps these connected to the supplier and its risk profile, so the record is a living one rather than another annual assessment file.
The trend is what matters. Is risk improving? Are controls closing gaps? Is intervention needed?
A risk register should show more than the current score. Inspect360 can visualise the relationship between probability and impact, compare risks with appetite and tolerance, and show how treatment changes the position over time.

A supplier can be genuine, but the invoice may not be
Inspect360 can check invoices against supplier information, budgets and expected patterns to flag activity worth reviewing.
Examples include duplicate invoices, unusual amounts or frequency, budget thresholds, currency mismatches, vendor-name mismatches and missing information.
When connected to the payment process, suspicious transactions can be held for review before payment.

Clear ownership where decisions matter
One shared picture, clear ownership, no more finger-pointing.
Inspect360 uses AI to reduce repetitive work and surface useful information without removing accountability from the people who own the decision.
Read documents
Analyse vendor documents and extract evidence.
Surface risks
Highlight potential concerns for review.
Find gaps
Identify missing controls and information.
Summarise suppliers
Turn large amounts of information into a useful overview.
Map evidence
Connect evidence to frameworks and obligations.
Analyse invoices
Look for patterns and anomalies that are worth attention.
Know what happened, who decided, and why
When management, auditors or regulators ask, the answer shouldn't depend on finding an old spreadsheet, questionnaire or email. Inspect360 keeps assessments, evidence, findings, approvals and decisions connected, so the record of how a risk was managed is always there.

What was known:
The information and evidence available at the time.
What was decided:
Who reviewed, approved, mitigated or accepted.
What happened next:
Actions, changes, reassessments, follow-up.
Third-party risk isn’t owned by one department
Different teams hold different parts of the picture. Inspect360 gives them a shared place to contribute, review and act without forcing everyone into the same role.
Procurement
Knows the supplier relationship and commercial context.
Service Owners
Knows what the organisation actually depends on.
Security
Understands technical exposure and control gaps.
Compliance & Privacy
Understand the obligations and evidence required.
Finance
Sees invoices, budgets and unusual payment patterns.
Risk & Audit
See impact, decisions, remediation and proof.
One system. Shared intelligence. Clear accountability.
Grow when you’re ready
Inspect360 does not require enterprise-level maturity from day one. Organisations can begin with a controlled vendor process and add deeper risk, compliance and intelligence capabilities as their needs grow.
01
Foundation
- Vendor Manager
- Service Owner
- Onboarding
- Approvals
- Offboarding
02
Govern
- Compliance Manager
- Questionnaires
- Evidence
- CIAP
- Remediation
03
Understand
- Multi-tier supply chain
- Shared dependencies
- Risk propagation
- External intelligence
04
Assure
- Cross-functional SMEs
- Regulatory reporting
- Financial crime
- Advanced assurance
You don’t need to implement all of Inspect360 to benefit from Inspect360.
Less chasing, fewer blind spots, and better decisions
Less chasing
Bring assessments, evidence and ownership into one controlled process.
Fewer blind spots
See suppliers behind suppliers and shared dependencies across the ecosystem.
Better decisions
Understand what a risk actually affects before deciding what to do.
Less duplication
Reuse information and evidence across requirements instead of collecting it repeatedly.
Earlier intervention
Spot changes, anomalies and suspicious activity before they become larger problems.
Easier assurance
Keep the evidence of assessments, decisions and remediation ready for review.
Questions we’re often asked
Isn't sending questionnaires and collecting certificates enough?
No. Questionnaires and certificates are useful sources of evidence, but they don't by themselves manage third-party risk. Effective risk management also requires understanding what the supplier provides, how critical it is, which dependencies and risks exist, what requirements apply, what actions are needed, who is accountable for decisions, and how the relationship changes over time. Inspect360 connects those activities into a traceable process.
How is Inspect360 different from a traditional TPRM tool?
Traditional TPRM tools focus on sending questionnaires and collecting certificates. Inspect360 manages the relationships between vendors, sub-suppliers, services, dependencies, risks, controls and organisational decisions. The questionnaire becomes one source of evidence inside a larger record, rather than the record itself.
How does NIS2 change third-party risk management?
NIS2 places supply-chain security within the organisation's cybersecurity risk-management measures and increases the importance of management oversight, appropriate security measures and demonstrable implementation. That means third-party risk management needs to go beyond periodically collecting questionnaires and certificates. Organisations need a structured way to assess supplier relationships, manage identified risks, retain evidence, and demonstrate how decisions and actions were handled.
Does Inspect360 replace our existing GRC programme?
No. Inspect360 strengthens an existing GRC programme by connecting third-party relationships, ownership, assessments, evidence, risks, actions and decisions. It complements established governance rather than requiring you to replace it.
We already have a vendor management system. Why would we need Inspect360?
A vendor register is an important starting point, but knowing who your suppliers are is different from understanding the risk they create. Inspect360 connects suppliers to services, sub-suppliers, dependencies, assessments, evidence, risks and decisions, so the organisation can see how third-party relationships affect the services it depends on.
Do all suppliers need the same level of assessment?
No. The level of assessment should reflect the relationship and the risk it creates. A supplier supporting a critical service or handling sensitive information may require substantially more assurance than a low-impact supplier. Inspect360 applies requirements and assessments according to context, so effort is focused where it matters.
Do we need to implement everything at once?
No. Inspect360 is designed to grow with your organisation. You can begin with supplier onboarding, clear ownership and approvals, then introduce questionnaires, deeper risk management, monitoring, financial oversight and advanced assurance as your needs and maturity develop.
Does Inspect360 integrate with our procurement, ERP or ITSM systems?
Yes. Inspect360 has standard connectors for several major systems and supports engagement-specific integrations built per customer. Any system with API documentation can be connected. Where an API isn't available, alternative methods are supported to bring the data in. Integration scope and approach are agreed during a scoping conversation so the effort matches the value.
How deep can we map our supply chain?
There is no fixed tier limit in the relationship model. Vendors and sub-suppliers can be connected across as many levels as needed, helping you identify the indirect dependencies, shared suppliers and concentration risks that a traditional supplier list cannot surface.
Can Inspect360 link services and products to suppliers?
Yes. Services and products can be linked to vendors and sub-suppliers, so you understand not only who your suppliers are but what your organisation depends on them to deliver. That context is what makes it possible to assess the actual impact of supplier risk.
Can we use our own questionnaires?
Yes. Inspect360 includes baseline questionnaires and supports your organisation's own, which can be made mandatory or triggered situationally. More importantly, the questionnaire is part of the assessment process rather than being the assessment itself. Questions and evidence are considered alongside supplier context, risk and applicable requirements.
Where is our data stored and protected?
Inspect360 is hosted in the EU. Supplier information, evidence, assessments and decisions never leave the region, which matters for NIS2, DORA and GDPR obligations, and for buyers with data-residency requirements written into their own governance.
Access is controlled through role-based access control (RBAC), with support for SSO/OAuth and MFA. Data is encrypted both in transit and at rest, and activities are recorded in an audit trail. Detailed encryption standards and our commitments for backup and recovery are documented in our security schedule, available on request.
Can Inspect360 detect suspicious invoices?
When integrated with the payment process, suspicious transactions can be held for investigation before payment. Inspect360 analyses invoice patterns and correlates transactions with supplier, contractual and financial information to flag anomalies for review.
How does Inspect360 use AI?
AI supports work such as document analysis, evidence extraction, control mapping, gap identification, supplier summarisation and invoice analysis. It reduces manual effort, not accountable decision-making. Human accountability remains with the relevant organisational roles.
How does Inspect360 help with audits?
Inspect360 maintains a traceable record of assessments, evidence, reviews, risk decisions, remediation, exceptions and monitoring activity. Instead of just showing that a questionnaire was completed, the organisation can demonstrate what was assessed, what evidence was considered, which risks were identified, who made the decision, and what happened afterwards.
Is Inspect360 available in multiple languages?
Yes. Inspect360's interface is available in English and the Nordic languages. Additional languages are added as needed, initially through AI-assisted translation and refined over time based on user feedback. Users can submit language corrections or suggestions from anywhere in the application, which route directly into our ticketing system. This lets us support new languages quickly while improving the quality of existing ones continuously.
Which regulations and standards can be supported?
Inspect360 is designed to support requirements across multiple regulatory and standards frameworks rather than treating each framework as a separate compliance exercise. Current coverage includes NIS2, DORA, CRA, CER, GDPR, the EU AI Act, eIDAS 2.0, ISO and NIST standards, PCI DSS, and financial-crime controls such as AML and anti-bribery and corruption (ABC). Applicable requirements are connected to assessments, controls and evidence, so one assurance process serves many frameworks.
Know what you depend on
See the ecosystem. Govern the relationship. Manage the risk. Evidence compliance.

Njordium is based in the Nordics, and the name comes from Njord, the Norse god of the sea, symbolising insight and deep knowing beyond the surface, a fitting reference for a firm founded to guide organisations navigating the cyber landscape.