Multi-entity GRC auditing

See your whole group's security posture — multi-framework, one source of truth.

Gjallarhorn is a governance, risk & compliance auditing platform. Score every entity against NIST CSF 2.0, ISO 27001* and the Essential Eight — with inheritance, evidence and a defensible audit trail underneath every number.

Function profile · group (weighted)NIST CSF 2.0
GVIDPRDERSRC
GV Govern3.2
ID Identify2.1
PR Protect2.2
DE Detect1.5
RS Respond1.4
RC Recover1.2
8
entities in one group
3
frameworks & standards — CSF 2.0, ISO 27001*, Essential Eight
666
control assessments
153
evidence attestations
How it works

From org chart to signed-off report.

Set the group up once, then run an assessment against it on whatever cadence you need. Six steps, one cycle.

Org chart · Meridian Industrial Group8 entities · CSF 2.0
Meridian Industrial GroupIndustrial Holding2.1 avg · 96/106 Meridian Digital ServicesShared IT/OT Services2.8 avg · 93/106 Meridian Precision EngineeringCNC Machining & Fabrication2.2 avg · 82/106 Meridian Energy ComponentsEnergy Sector Components2.4 avg · 80/106 Meridian Food SystemsFood Processing Equipment2.3 avg · 77/106 Meridian LogisticsWarehousing & Freight2.1 avg · 71/106 Apex Tooling & DiesTooling Manufacture1.3 avg · 47/106 ProCoat Surface TreatmentsIndustrial Coatings2.9 avg · 24/106
1

Map the group

Add every entity in the corporate group and how they nest — from the holding company down to each plant, service or subsidiary.

2

Assign frameworks & standards per entity

Put each entity on the Framework or standard it actually answers to.

NIST CSF 2.0ISO 27001*Essential Eight
3

Score with evidence

Mark each control local, inherited or hybrid, attach the evidence behind it, and attest. Inherited scores aren't trusted until the chain is verified.

4

Watch posture roll up

Scores aggregate into criticality-weighted group figures, worst-case by function, and the profile radar — the whole group at a glance.

5

Work the gaps

The gap register ranks gaps by criticality and points each at the entity where the fix belongs. Turn any gap into an owned remediation action.

6

Sign off & report

An engagement lead finalises the cycle and exports the audit report — scores, gaps, maturity and evidence, as a dated artifact.

Inheritance

When one entity sets a control, everything below it inherits the score.

Groups aren't flat. Shared services set controls that every subsidiary depends on. Gjallarhorn tracks that inheritance, so a weak score surfaces where the problem actually sits.

Inheritance-aware scoring

Every control is local, inherited, or a blend, and an inherited score isn't trusted until it carries a verified attestation.

Fix upstream, once

Each gap names the entity where the fix belongs and shows how many entities one fix clears.

Criticality-weighted rollups

Group scores weight each entity by how critical it is, and name the weakest one per function.

Frameworks & standards

Different entities, different requirements.

A group can run NIST CSF 2.0 as its common language, keep one subsidiary certified to ISO 27001*, and hold another to the Essential Eight. Each entity is assessed against the framework or standard it answers to, and scored the way that model actually works.

NIST CSF 2.0 · Meridian Industrial Group0–4 · weighted
GV · Govern
3.2
ID · Identify
2.1
PR · Protect
2.2
DE · Detect
1.5
RS · Respond
1.4
RC · Recover
1.2

NIST CSF 2.0

All six functions and 106 subcategories, scored 0–4 against a target profile.

ISO/IEC 27001:2022*

Annex A coverage for the entities that carry certification, in the same posture model as everything else.

Essential Eight

Maturity is gated, not averaged. A strategy reaches ML2 only when every ML1 and ML2 control passes; one failure drops the level.

Remediation

Every gap gets an owner, a due date, and a paper trail.

Gaps come straight from the scores, ranked by criticality, each pointing at the entity where the fix belongs. Assign one to a person with a deadline, track it to done, and close the cycle with a sign-off and a report you can hand to an auditor.

Gap register · where to fix88 gaps
ControlCurrent → TargetWhere to fix
GV.OC-013 4⌖ Fix here → clears 2 gaps
PR.AA-051 4⌖ Fix here → clears 3 gaps
DE.CM-010 3Fix upstream → Digital Services
ID.RA-102 4Fix upstream → Meridian Group
RS.MA-011 3Fix here

Remediation actions

Owned by a named person, with a due date and status; overdue work is flagged.

Findings & exceptions

Rate an observation, or formally accept a risk with an expiry date.

Sign-off & report

An engagement lead signs the cycle off, and the report lays out scores, gaps, maturity and evidence.

Isolated per tenant

Each tenant's data stays separate; access is invite-only and scoped to specific entities.

SSO only

Sign in with Google or Microsoft.

Backed by evidence

Every score links to the evidence and attestation behind it.

See where your group actually stands.

Gjallarhorn
© 2026 · gjallarhornaudit.com
Figures above are the built-in example tenant, “Meridian Industrial Group.”
* ISO/IEC 27001:2022 support is in development — coming soon.