CoreStream GRC 3.0 Release Notes

Platform Director Overview This release marks a significant milestone for CoreStream GRC – not just in terms of features, but in how we present ourselves to the world. With the move to version 3.0, we have fully rebranded the CoreStream GRC platform to align with our new, modern identity. Among the headline features is our…

Richard Eddolls Avatar
CoreStream GRC logo against dark blue background and blue and green gradient

Platform Director Overview

This release marks a significant milestone for CoreStream GRC – not just in terms of features, but in how we present ourselves to the world. With the move to version 3.0, we have fully rebranded the CoreStream GRC platform to align with our new, modern identity.

Among the headline features is our brand-new Risk Flightpath visualization – a powerful new way to track and plan the journey of a risk from current to target score, with clear visibility of intermediate actions and due dates. It gives users a much sharper picture of how risks are being managed over time and how plans are working to mitigate the risk.

We have also taken a major step forward in usability with direct editing of SharePoint attachments – a feature a number of clients have requested and demonstrable proof that we are listening! Users can now open and edit files directly in their browser or native applications, with changes saved automatically to the live document – no more downloading, editing, and re-uploading. Even better, we’re actively exploring how to bring this same slick experience to all CoreStream GRC attachments.

Beyond these highlights, the release delivers improvements across the platform – performance boosts of up to 40x in complex form save scenarios, smarter grid and export controls, enhanced logging for reviewing complex workflow processes, more helpful user manager email behavior on UAT sites, and continued refinement of configuration tools for both our team and yours.

As always, thank you for your continued partnership and feedback. We are excited about where the platform is heading and look forward to seeing the difference these new features make in your day-to-day work. As ever, please do keep the feedback coming. It is what helps us improve.

Rich & Cam

About Rich Eddolls

Richard is a co-founder and Chief Product Officer at CoreStream GRC, where he’s redefining the way organizations approach governance, risk, and compliance. With 20 years of experience in business-driven GRC system design and a background at Deloitte, Richard is all about challenging the status quo and delivering technology that actually works. As the visionary behind the CoreStream GRC platform, he’s committed to building solutions that don’t just promise change—but deliver it. Outside of the office, Rich is a golfer, soccer player, and proud husband and father, always looking for the next challenge—whether on the field or at home.

Follow Rich on LinkedIn here.

About Cam McNair

Cam is Head of Platform Design at CoreStream GRC, where he’s redefining how platform innovation happens—from solving day-to-day configuration challenges to building out features that scale. With a background in data analysis and technical solution design, Cam’s all about turning complex business needs into simple, powerful tools that actually work. He leads a team of Solution Architects who double as Product Owners, delivering real impact across the platform. As the driving force behind CoreStream GRC’s product evolution, Cam’s focused on creating solutions that don’t just tick boxes, but move things forward.

See Cam’s LinkedIn post about Product Release 3.0

Follow Cam on LinkedIn here.

FAQ

What was the CoreStream GRC 3.0 release?

The CoreStream GRC 3.0 release marked a major milestone for the platform, introducing a full rebrand and powerful new features that enhanced usability, performance, and visualization. This update aligned with CoreStream GRC’s modern identity and its commitment to delivering intuitive, high-performing GRC solutions.

What were the key new features in CoreStream GRC 3.0?

The headline feature was the Risk Flightpath visualization, which allowed users to track the full lifecycle of a risk—from current score to target—with clear visibility of actions and due dates. Other major improvements included:

Direct editing of SharePoint attachments in-browser.
Up to 40x faster performance in complex form saves.
Smarter grid controls, export tools, and workflow logging.
Improved email behavior on UAT sites to streamline testing.

Who led the CoreStream GRC 3.0 release?

The release was led by Rich Eddolls, Co-founder and Chief Product Officer, and Cam McNair, Head of Platform Design. They oversaw enhancements focused on real-world usability, speed, and client-driven design.

  • From compliance to confidence: a practical guide to a proactive always on data privacy program

    From compliance to confidence: a practical guide to a proactive always on data privacy program

    Most large organizations say they have privacy covered. And on paper, they do. In practice, privacy often lives as disconnected work: documents, templates, and one-off reviews that prove something happened once, not a system that controls what happens next. That gap matters because privacy risk is created by change. A new analytics use case. A…

  • DORA just got a UK handshake: the EU – UK ICT oversight pact is a warning shot for third-party risk

    DORA just got a UK handshake: the EU – UK ICT oversight pact is a warning shot for third-party risk

    If your business depends on a small set of shared providers like cloud, identity, payments, or data platforms, your operational resilience risk is no longer just a “your firm” issue. It’s a system wide dependency. Regulators are now shifting supervision to where that risk sits: at the provider level, not just inside each regulated company.…

  • Beyond the checkbox: A value‑based guide to enterprise conflict of interest management

    Beyond the checkbox: A value‑based guide to enterprise conflict of interest management

    The conflict-of-interest wake-up call Most organizations do have a conflict of interest (COI) policy.  What they actually have, in practice, is this:  Legacy GRC will tell you that’s “good coverage.” It isn’t. It’s paperwork.  Conflicts of interest rarely blow up because they were hidden. They blow up because they were normalized, misunderstood, or never escalated until after a decision was made and challenged.  If you’re trying to run effective value-based…