Axiom GRC
Axiom GRC is a London-headquartered Governance, Risk, and Compliance platform serving 40,000+ organizations across 149 countries through ten sub-brands spanning SaaS, eLearning, advisory, and cyber assurance, with operations in the UK, U.S., and Canada.
- Company typePrivate
- Founded-
- HeadquartersLondon, United Kingdom
- Headcount1,001–5,000
- GTM typeB2B
- OfferingSoftware
What Axiom GRC does
Axiom GRC is a London-headquartered Governance, Risk, and Compliance platform serving 40,000+ organizations across 149 countries with 1,500+ professionals, including 1,200+ compliance specialists. The group operates through ten retained sub-brands — CoreStream GRC (no-code enterprise risk platform), Vantify (CAFM and supply chain compliance ecosystem), VinciWorks (800+ course compliance eLearning with the Astute LXP), WorkNest (employment law, HR, health & safety advisory with fixed-fee pricing), Barbour EHS (regulatory intelligence), IMSM (ISO certification consultancy), The DPO Centre (GDPR and AI governance advisory), IS Partners and MHM (North American cyber assurance), and AssurancePoint (SOC and ISO audit) — delivering a mix of SaaS subscriptions and professional/advisory services. Technology is built around CoreStream's configurable component architecture, Vantify's integrated CAFM/supply chain/risk modules, and VinciWorks' adaptive learning platform with DocuSign integration; the platform claims 90%+ client retention and outcomes including 80% reduction in workplace accident risk and an 88% Employment Tribunal success rate. Revenue mechanics combine recurring SaaS subscriptions (CoreStream, VinciWorks, Barbour, DPO Centre), annual fixed-fee advisory retainers (WorkNest), and project-based certification and audit fees (IMSM, IS Partners, MHM, AssurancePoint). The company was formed in 2019 as a division of Marlowe plc, taken private in February 2024 with Inflexion backing, and has since executed seven acquisitions — most recently MHM (Canada, June 2026), AssurancePoint (U.S., January 2026), and IS Partners (U.S., November 2025) — to establish a North American platform alongside its UK-centric base.
Axiom GRC firmographics
Firmographics- Name
- Axiom GRC
- Legal name
- Charis Four Ltd
- Website
- https://axiomgrc.com
- Company type
- Private
- Operating status
- Operating
- Headcount range
- 1,001–5,000 employees
- Short description
- Axiom GRC is a London-headquartered Governance, Risk, and Compliance platform serving 40,000+ organizations across 149 countries through ten sub-brands spanning SaaS, eLearning, advisory, and cyber assurance, with operations in the UK, U.S., and Canada.
- Ownership category
- akta.pro rank
Axiom GRC industry classification
Industry- Product category
- Governance Risk Compliance Software
- NAICS
- Professional, Scientific, and Technical Services (541), Management Consulting Services (54161), Computer Systems Design and Related Services (54151), Other Management Consulting Services (541618)
- SIC
- Services-Prepackaged Software (7372), Services-Engineering, Accounting, Research, Management (8700)
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) Platforms (BPAEAPAA)
- akta.pro secondary industries
- Risk, Controls & Governance (GRC) Platforms (FSAFAOAG), Compliance Technology, GRC Platforms & Controls Automation Advisory (BPAHAFAO), IT Governance, Risk & Compliance (IT GRC) Platforms (HDAEALAK), Compliance, GRC Workflow & Audit Automation Platforms (HDAEAHAL), Privacy, Consent & Data Protection Management (BPAEAPAF), Third-Party Risk, Vendor Due Diligence & Supply Chain Compliance (BPAEAPAG)
Keywords
Where Axiom GRC is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices13 records
Markets served
Axiom GRC business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Others
Revenue model
- Software Subscriptions: SaaS-based compliance software subscriptions across multiple product lines including CoreStream GRC, Vantify CAFM, Supply Chain, Barbour EHS regulatory intelligence platform, and DPO Centre data protection services.
- Professional Services: Advisory and consulting services including health and safety consultancy, employment law services, ISO certification consultancy, cyber security services, and DPO services. WorkNest offers fixed-fee pricing for transparent service delivery.
- eLearning and Training: Compliance eLearning solutions through VinciWorks with over 800 courses serving 2,000 organizations and 1.2 million users globally.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | WorkNest employment law and HR services with fixed-fee pricing |
| Subscription | Annual | Health and safety consultancy with transparent pricing |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels5 records
Axiom GRC product offering
Product offeringCore offering
Axiom GRC operates a global governance, risk, and compliance (GRC) platform combining compliance software with advisory services across health & safety, employment law, cyber security, data protection, compliance eLearning, assurance & certification, enterprise risk, regulatory intelligence, and CAFM & supply chain compliance. The platform is delivered through acquired sub-brands (CoreStream GRC, Vantify, VinciWorks, WorkNest, Barbour EHS, IMSM, DPO Centre, IS Partners, MHM) serving 40,000+ customers across 149 countries.
Product overview
Axiom GRC is a global GRC platform delivering over 50 compliance products combining software and advisory services. The platform operates through distinct sub-brands that function as an integrated ecosystem: CoreStream GRC provides the enterprise risk management platform with its no-code, Lego-brick architecture; Vantify delivers CAFM and supply chain compliance solutions; VinciWorks powers compliance eLearning with 800+ courses and the Astute LXP platform; WorkNest offers employment law, HR, and health & safety services with SafetyNest software; Barbour EHS provides regulatory intelligence; IMSM handles ISO certification; The DPO Centre offers data protection and GDPR support; and IS Partners/MHM deliver cyber assurance and audit services (SOC, HITRUST, PCI DSS). With 1,200+ compliance specialists across 10 countries serving 40,000+ clients in 149 countries, Axiom GRC pairs compliance technology with specialist advisory to deliver a turnkey compliance solution spanning consultancy, software, and audit.
Differentiator
Problem solved
Functional benefit
Brands
- VinciWorks: Cutting-edge, customisable compliance training and eLearning software
- Barbour EHS
- Vantify
- CoreStream GRC
- WorkNest
- IMSM
- DPO Centre
- IS Partners
- Cyber Assurance
- WorkNest Secure
Products and services
- CoreStream GRC Scalable GRC platform with a no-code Lego-Brick approach enabling organizations to build customizable risk and compliance environments from pre-built configurable components, designed for enterprise risk management.
- Vantify Integrated compliance ecosystem combining Computer-Aided Facility Management (CAFM), Supply Chain compliance, Risk Manager, Consultancy, and Intelligence modules, giving facilities and compliance teams single-view visibility across assets, suppliers, and risk.
- VinciWorks Compliance eLearning platform offering 800+ fully customizable courses covering data protection, anti-money laundering, health and safety, workplace diversity, and more, with software that adapts to laws in multiple jurisdictions.
- Barbour EHS Regulatory intelligence SaaS product providing up-to-date legislation, guidance, and industry best practices for health, safety, environmental, and facilities responsibilities across UK, Ireland, and 30+ international jurisdictions.
- WorkNest Employment law, HR, and health & safety services providing specialist advice, consultancy, and software solutions for UK businesses across 48 sectors, including tribunal support under a fixed-fee pricing model.
- IMSM ISO certification consultancy helping businesses achieve and maintain international standards through structured hands-on support covering the full ISO lifecycle from gap analysis to certification.
- The DPO Centre Outsourced Data Protection Officer services, GDPR compliance support, and AI governance services for organizations across life sciences, healthcare, finance, tech, retail, and education sectors.
- IS Partners U.S.-based cyber assurance and IT compliance services provider combining audit and cybersecurity expertise to help organizations achieve SOC, PCI DSS, and HITRUST compliance.
- MHM Canadian-based GRC assurance firm specializing in cybersecurity audit framework solutions including SOC 1, SOC 2, ISO 27001, and ISO 42001 assessments for SME and mid-market clients across North America.
- WorkNest Secure Comprehensive cyber security services including CREST and CHECK certified penetration testing, vulnerability scanning, Red Team exercises, vCISO services, and compliance support for ISO 27001, Cyber Essentials, PCI DSS, and DORA.
- AssurancePoint SOC and ISO audit and advisory services for mid-sized organizations, integrating with IS Partners to form a turnkey compliance solution.
Quantifiable outcome
- 80% reduction in workplace accident risks
- +6 more outcomes
Companies that use Axiom GRC
Customer profileNamed customers18 records
Segments5 records
Ideal customer profiles5 records
Axiom GRC technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration1 record
Feature5 records
Axiom GRC partnerships and signals
Strategic signalScale indicators22 records
Recent moves9 records
Expansion highlights6 records
Axiom GRC competitors and assessment
Company assessmentDirect peers
- NAVEX Global: One of the largest pure-play GRC software and services platforms, offering ethics & compliance, risk, and policy management to enterprise customers. Directly comparable to Axiom GRC's integrated GRC portfolio and broad enterprise customer base.
- Mitratech: PE-backed GRC and legal tech platform providing risk, compliance, and legal operations software (TeamConnect, PolicyHub, Alyne). Highly comparable tech-enabled services model and M&A-driven roll-up strategy.
- Diligent: Governance, risk, and compliance SaaS provider focused on board management, entity governance, and enterprise risk, serving large global enterprises and boards. Comparable customer profile and integrated GRC software-plus-services proposition.
- Riskonnect: Integrated risk management (IRM) and GRC platform offering enterprise risk, compliance, vendor risk, and claims solutions. Directly comparable on enterprise risk management core product (CoreStream equivalent) and PE-backed growth profile.
- OneTrust: Privacy, security and GRC software platform with broad adoption across enterprises for consent management, data protection, and AI governance. Comparable to Axiom GRC's DPO Centre and broader compliance software offering.
- Lockpath / Regnology (formerly OneSumX for Risk): Regulatory reporting, risk, and compliance solutions provider with a long-standing GRC platform heritage (Lockpath/Keylight). Comparable enterprise GRC platform positioning and regulated-industry customer base.
Broad incumbents
- ServiceNow (IRM / GRC): Major enterprise platform with integrated Integrated Risk Management (IRM) and GRC modules sold into large installed base. Competes head-to-head with CoreStream GRC and Vantify for enterprise risk and compliance budget.
- SAP (GRC / SAP GRC): Long-standing enterprise GRC suite (access control, process control, risk management) sold into the largest global enterprises. Comparable enterprise customer base, particularly to CoreStream's enterprise risk line.
Emerging players
- LogicGate: Risk and compliance workflow automation platform with a no-code approach to building GRC use cases. Closest comparable to CoreStream GRC's no-code, configurable architecture and to mid-market GRC buyers.
- Drata: Compliance automation platform focused on SOC 2, ISO 27001, HIPAA and other frameworks, increasingly expanding into broader GRC. Comparable to Axiom GRC's IS Partners / MHM cyber assurance offering and the IMSM ISO certification practice.
Market position
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
Axiom GRC social profiles
Digital presenceAxiom GRC compliance and trust
Trust signalCompliance10 records
Axiom GRC financial estimates
Financial estimateRevenue estimate
Valuation estimate
Axiom GRC leadership team
Management profileNumber of profiles
Profiles15 records
Axiom GRC subsidiaries and ownership
Company hierarchySubsidiaries10 records
Axiom GRC funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Axiom GRC M&A and investment
M&A and investmentM&A4 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Axiom GRC
What does Axiom GRC do?
Axiom GRC operates a global governance, risk, and compliance (GRC) platform combining compliance software with advisory services across health & safety, employment law, cyber security, data protection, compliance eLearning, assurance & certification, enterprise risk, regulatory intelligence, and CAFM & supply chain compliance. The platform is delivered through acquired sub-brands (CoreStream GRC, Vantify, VinciWorks, WorkNest, Barbour EHS, IMSM, DPO Centre, IS Partners, MHM) serving 40,000+ customers across 149 countries.
Is Axiom GRC a public or private company?
Axiom GRC is a private company. It is classified as private equity controlled and is currently operating.
When was Axiom GRC founded?
Axiom GRC was founded in -1. It employs 1,001 to 5,000 people.
Where is Axiom GRC based?
Axiom GRC is headquartered in London, United Kingdom, in the Europe region.
How does Axiom GRC make money?
Three revenue lines are on record. Software Subscriptions are the primary driver. The others are professional Services and eLearning and Training.
Who are Axiom GRC's main competitors?
Direct peers on record are NAVEX Global, Mitratech, Diligent, Riskonnect, OneTrust and Lockpath / Regnology (formerly OneSumX for Risk). Broad incumbents are ServiceNow (IRM / GRC) and SAP (GRC / SAP GRC). Emerging players are LogicGate and Drata.
Does Axiom GRC have an API?
No public API is recorded for Axiom GRC.
What industry is Axiom GRC in?
Axiom GRC's product category is Governance Risk Compliance Software. Its primary akta.pro industry code is BPAEAPAA, Governance, Risk & Compliance (GRC) Platforms, with a secondary code of FSAFAOAG, Risk, Controls & Governance (GRC) Platforms. Its NAICS code is 541 and its SIC code is 7372.