Njordium unifies GRC and supplier risk with Inspect360

Njordium unifies GRC and supplier risk with Inspect360

Njordium Cyber Group, a Swedish cybersecurity and governance software firm, has introduced Inspect360 GRC, a governance, risk and compliance platform.

The platform gives organisations an always-current picture of how they are run, where their exposures lie and whether they can prove compliance.

The release makes Inspect360 the company’s main brand for governance and risk management. Inspect360 GRC operates alongside Inspect360 TPRM, Njordium’s existing third-party risk management product. Together they manage internal oversight and external supplier dependencies as one programme rather than two.

Njordium says many organisations now handle GRC in scattered pieces. Regulatory obligations, policies, risk registers, supporting evidence and supplier reviews often sit in separate tools, spreadsheets and shared drives. That fragmentation is harder to sustain now that EU rules such as NIS2, DORA and GDPR require firms to manage cyber risk, operational resilience and supplier exposure systematically.

Firms must document that work, keep it auditable and assign clear ownership on an ongoing basis rather than through occasional reviews. According to the company, scattered records demand heavy upkeep yet often fail to give management a sharper grasp of risk or give auditors and supervisors the evidence they expect.

The Inspect360 portfolio keeps frameworks, policies, risks, controls, evidence, exceptions and audits in a single traceable record. Users can map a control and its evidence once and apply it across several regulatory and standards requirements.

Suppliers, sub-suppliers, services and dependencies link directly into the broader risk environment. Inherent and residual risk, treatment plans, owners, approvals and review cycles sit next to the relevant controls. The system also logs who held which information, who made each decision, the reasoning behind it and the outcome.

Integrations cover ServiceNow, Microsoft, Jira, SAP, GitLab and GitHub, among other tools. Users can sign in through Google and Microsoft OAuth, with support for hardware keys such as YubiKey and Google Titan. AI features cut routine tasks, flag gaps and highlight items needing attention while keeping people accountable for decisions. Evidence and decision logs are updated continuously, so teams do not have to rebuild them before an audit.

Njordium builds Inspect360 in Sweden with European organisations’ requirements in mind. Customers can run it as a managed SaaS service or install it on-premises when regulation, contracts, security or data sovereignty call for tighter control.

Njordium Cyber Group CEO Mads Becker Jørgensen said, “Compliance should tell us something about how well an organisation is governed; it should not become the objective in itself. With Inspect360 GRC, we wanted to move the focus away from maintaining individual compliance checklists and towards understanding the relationships between requirements, controls, evidence, decisions and the risks they are intended to manage.”

Njordium Cyber Group senior advisor Kim Haverblad said, “Organisations don’t experience internal risk and third-party risk as two separate realities. A critical supplier can affect a business service, regulatory obligation, control, risk treatment and management decision at the same time. Yet those relationships are often managed in completely different systems. Inspect360 is about connecting that picture so management can understand not just whether something is compliant, but what it affects, who owns the decision and whether the evidence supports it.”

Haverblad added, “Data sovereignty should ultimately be a governance decision made by the organisation. We designed Inspect360 so that the deployment model does not dictate that decision.”

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.