Governance · Risk · Compliance

One hub for everything you have to prove.

For GRC, InfoSec and privacy teams at multi-site organisations — one system for frameworks, risks, controls, audits, vendors and assets.

Already a customer? Sign in to your workspace

NIS2 · GDPR · ISO 27001 · DORA — answered from one set of controls.

NIS2 GDPR ISO 27001 Audits Vendors Risks GRChub
Built for regulated teams NIS2GDPRISO 27001DORA Patientdatalagen
Trusted in regulated sectors

Built for multi-site teams who answer to more than one regulator.

Retail, healthcare and services organisations across Northern Europe use GRChub to run one connected compliance programme — from entity register to board reporting.

24+Entities in a single programme
140+Controls mapped once
4+Frameworks from one set
“We needed one place where a finding becomes an action, a control satisfies NIS2 and GDPR, and the board sees live status — not a slide deck.”
— GRC programme lead, multi-site organisation
See it in action

The GRC Console — in GRChub branding.

Same navigation, registers and views as the live GRC Console — recoloured for GRChub. Your deployment uses your brand on the header.

GRC Console
Northern Europe · Governance, Risk & Compliance

Northern Europe · Single source of truth

Welcome to the GRC Console

Governance, risk and compliance overview for 22 stores across Denmark, Sweden, Norway, Finland and the Netherlands.

Operational stores

22

Total store staff

412

Optician autorisations

38

Active risks

18

Open actions

12

Stores by country
Denmark
Specsavers
8
stores
Sweden
Synoptik
6
stores
Compliance health
Compliant
Attention
Non-compliant
Risk heat map
Stores requiring attention
#2003 · MalmöAttention
#3003 · TrondheimNon-compliant
#5003 · The HagueAttention

Overview — the same welcome screen, store metrics and compliance health customers see on sign-in.

  • Finding → action in one click

    Every audit finding gets an owner, deadline and linked remediation — tracked in the same register your team already uses.

  • Map once, answer many frameworks

    Attach evidence to a control once and satisfy NIS2, GDPR, ISO 27001 and your internal policies from the same set.

  • Board-ready reporting

    Executive summaries and PDF exports pull live data — no last-minute scramble before a committee meeting.

Outcomes

Three jobs. One connected system.

GRChub is organised around what compliance teams actually deliver — not just a list of modules.

Prove

Demonstrate compliance

Map controls once and show coverage across every framework you answer to.

  • Framework & maturity tracking
  • Linked evidence — not copies
  • Board-ready executive summaries
Run

Operate the programme

Audits, findings, actions and the annual wheel in one workflow your team can maintain.

  • Audit planning & findings register
  • Finding → action with owners
  • Annual wheel & recurring activities
Manage

Control third-party & asset risk

Vendors, assets and privacy assessments tied back to your entities and controls.

  • Vendor tiering & reviews
  • NIS2 asset register per site
  • DPIA & privacy workspace
The platform

Every part of the job, in one place.

No more spreadsheets per framework and screenshots in folders. The registers link to each other, so a finding becomes an action, a risk shows its controls, and an audit updates your maturity — automatically.

Risk register

See inherent and residual risk side by side, link the controls that treat each one, and watch the score move as you act.

Controls & frameworks

Map one set of controls to every framework you answer to, and track maturity as evidence builds.

Audits & findings

Plan audits, score controls, and turn every finding into tracked remediation with an owner and a deadline.

Third-party

Tier vendors by data access and criticality, and keep their assessments on a schedule that won't slip.

Asset register

Keep a live NIS2 inventory of the equipment in every site, reconciled straight from field audits.

Data privacy & DPIA

Run DPIAs and your DP, InfoSec, legal and tiering assessments from one privacy workspace.

How it works

From scattered to accountable in four moves.

GRChub maps to how compliance actually runs, so the tool follows your process instead of fighting it.

01

Bring your entities in

Add your sites, stores or business units — the things you actually have to cover.

02

Map your frameworks

Attach controls once and satisfy NIS2, GDPR, ISO 27001 and more from the same set.

03

Run the work

Audits, findings, actions, vendor and asset reviews flow through one connected system.

04

Report with confidence

Board-ready summaries and linked evidence that are always current — no scramble before a meeting.

Integrations

Runs on the stack you already trust.

Microsoft Entra ID — SSO Azure Static Web Apps Azure Cosmos DB SharePoint evidence links Regional data residency Role-based access
Security & trust

Enterprise-ready by design.

GRChub is built on the same controls it helps you manage. Your data stays governed, in your region, behind your identity provider. Read the trust centre →

Single sign-on

Sign in through Microsoft Entra or your own identity provider, with access scoped per person.

Least-privilege access

People see only what their role needs. Every change is attributable and logged.

Data residency

Hosted on Microsoft Azure, with your data kept in the region you choose.

Evidence linked, not copied

Point to the source of record in SharePoint or your DMS — no shadow copies to keep in sync.

Pricing

Priced to your footprint.

GRChub scales with the entities and frameworks you cover — not per seat, so your whole team can take part. Tell us your size and we'll put a number to it.

Starter

A single entity getting compliance off spreadsheets.

  • One entity or site group
  • Core registers: risk, controls, audits
  • Up to 3 frameworks
  • Email support
Book a demo

GrowthPopular

Multi-site teams answering to several regulators.

  • Multiple entities & sites
  • Vendors, assets & data privacy included
  • Unlimited frameworks & mappings
  • GRC Watch intelligence
Book a demo

Enterprise

Group-wide programmes with SSO and residency needs.

  • Unlimited entities
  • SSO & least-privilege roles
  • Data residency in your region
  • Priority onboarding & support
Talk to us
Feature Starter Growth Enterprise
Entities / sites1 groupMultipleUnlimited
FrameworksUp to 3UnlimitedUnlimited
Risk, controls & audits
Vendors & assets
Data privacy & DPIA
GRC Watch intelligence
Microsoft Entra SSO
Data residency choice
SupportEmailEmailPriority

Pricing is based on your entity footprint, not per user — so your whole GRC, InfoSec and privacy team can participate. Request a quote.

FAQ

Common questions from buyers.

Still deciding? These are the questions compliance and IT teams ask most often.

How long does onboarding take?
Most teams start with one entity and 2–3 frameworks. A typical rollout — entities, control library import and first audit cycle — takes 4–8 weeks depending on scope. We help you sequence it so you see value before the full programme is mapped.
Can we import existing risk and control registers?
Yes. GRChub supports structured JSON import for risks, controls, policies and related data. Spreadsheet-based registers can be migrated during onboarding — we work from what you have rather than forcing a blank start.
Where is data stored? Can we choose region?
Customer data is hosted on Microsoft Azure. Enterprise plans include a choice of region (e.g. West Europe). Your GRC data stays in your tenant's Cosmos DB — not mixed with other customers.
Do you support SSO and role-based access?
Yes. Sign-in is through Microsoft Entra ID (Azure AD). Access to apps and admin functions is scoped per person — least privilege by design. Enterprise includes full SSO and role configuration.
How is pricing calculated?
GRChub is priced by entity footprint and programme scope — not per seat. That means your whole compliance team, auditors and store managers can participate without licence counting. We'll quote based on your entity count, frameworks and support needs.
Can we start in one country and expand?
Absolutely. Many customers begin with a single market or entity group, then add sites and country-specific frameworks (NIS2, GDPR, patient data laws) as the programme matures. Controls mapped once extend to new jurisdictions.

Bring your compliance into one hub.

See GRChub mapped to your frameworks and entity structure. A 30-minute walkthrough with your questions — not a generic slide deck.

Book a demo

We'll reply within one business day to schedule your session.

Thanks — we received your request and will reply within one business day.

Existing customers

Sign in to your workspace

Enter your organisation name to open your apps portal. Access is verified through Microsoft Entra — your identity determines which apps you can use.

About GRChub

Built for teams who have to prove compliance — not just document it.

GRChub is a governance, risk and compliance platform for multi-site organisations in regulated sectors. We help GRC, InfoSec and privacy teams run one connected programme across entities, frameworks and third parties — hosted on Microsoft Azure with Entra ID sign-in.

Book a demo