Buyer’s Guide: Governance, Risk And Compliance Software (2024)

Published 7 May 2024 by Christine O'Donnell & Bill Pennington &

Access this research

Access all Risk Management content with a strategic subscription or buy this single report

Buy Subscription

Need help or have a question about this report? Contact us for assistance

Executive Summary

This report equips decision-makers in risk management roles who are responsible for the selection, implementation and management of software for governance, risk management and compliance (GRC) with detailed profiles of 14 prominent software platforms in today’s market, drawing on data collected from the vendors via questionnaires. In addition, Verdantix has built a holistic picture of the global GRC vendor landscape through a broader overview of 34 GRC solution providers and an analysis of buyer requirements, using a range of publicly available data and insights generated from our annual global corporate survey of 200 executives in director roles and above (see Verdantix Global Corporate Survey 2023: Risk Management Budgets, Priorities & Tech Preferences). The GRC market today is being reshaped by an intensified push towards the digitization of GRC processes, aiming to enhance operational efficiencies and help firms navigate a growing web of mandatory regulations. Additionally, increasing non-financial risks, such as ESG, climate and cyber security threats, are compelling organizations to adopt technology-led GRC platforms that offer real-time insights and proactive risk management capabilities. Prospective buyers should use this report to support them in their search for GRC software solutions that fit their business requirements.

Table of contents

Buyer’s Guide to the governance, risk and compliance (GRC) software market
Defining GRC software solutions
An evolving risk landscape is driving firms towards a new model of corporate governance
Buyers should apply three key criteria when selecting a GRC solution
Inclusion criteria for the 2024 Buyer’s Guide for GRC software
Archer offers enhanced enterprise decision-making with advanced analytics
Camms focuses on strategic alignment and AI-enhanced GRC solutions
Corporater provides digital twin integration for corporate governance
Diligent delivers targeted strategic insights for board-level governance
LogicGate provides workflow flexibility and automated compliance intelligence
MetricStream prioritizes the incorporation of AI technology to optimize GRC insights
Mitratech offers streamlined legal and compliance solutions through automation
NAVEX supports firms through integrated third-party oversight and management capabilities
Resolver (Kroll) offers specialist consulting to support complex GRC requirements
Riskonnect leverages risk management intelligence with expanded RMIS capabilities
SAI360’s platform enables firms to align ESG risk strategy with business objectives
ServiceNow drives GRC automation with AI-informed workflows and insights
Wolters Kluwer provides tools for strategic governance and integrated ESG frameworks
Workiva supports platform configurability for business agility

Table of figures

Figure 1. Defining GRC software
Figure 2. GRC software functionality overview
Figure 3. Vendor types operating in the GRC software market
Figure 4. GRC software is set to see strong investment growth
Figure 5. Firms make headway in incorporating ESG and sustainability risks in their risk management processes
Figure 6. GRC vendor architecture models for solutions in the market
Figure 7. Pros and cons of GRC architecture models
Figure 8. List of GRC software providers
Figure 9. Archer overview
Figure 10. Camms overview
Figure 11. Corporater overview
Figure 12. Diligent overview
Figure 13. LogicGate overview
Figure 14. MetricStream overview
Figure 15. Mitratech overview
Figure 16. NAVEX overview
Figure 17. Resolver (Kroll) overview
Figure 18. Riskonnect Global overview
Figure 19. SAI360 overview
Figure 20. ServiceNow overview
Figure 21. Wolters Kluwer overview
Figure 22. Workiva overview

Organisations mentioned

7IM, AbbVie, Adidas, Amazon, Amazon Web Services (AWS), American Heart Association, Ansarada, Archer, Ascent, AuditBoard, Axis Health System, Bank of America, Bristol Myers Squibb , Bupa, C&F, Cadillac Fairview, Camms, CannonDesign, Cathay Pacific, CDP, Cigna Corporate Services, Cisco, City of Lethbridge, Clearlake Capital Group, Coca-Cola, Compliance.ai, Corporater, COSO (the Committee of Sponsoring Organizations of the Treadway Commission), Crown Castle, Decision Focus, Deloitte, DentaQuest, Diligent, Empowered Systems, Enbridge, ENGIE, Enhesa, FedEx, First Credit Union, Flisk, Fortune, Fusion Risk Management, Galvanize, Global Reporting Initiative (GRI), Harrods, Hitachi Energy, Hyperproof, Ideagen, IFRS (International Financial Reporting Standards) Foundation, International Organization for Standardization (ISO), JELD-WEN, Johnson & Johnson, Kroll, Lendlease, LexisNexis, Lithia Motors, LogicGate, LogicManager, McKesson Corporation, Merck, MetricStream, Mineral, Mitratech, MODE Global, NAVEX, OneTRust, Onspring, Ontario Teachers’ Pension Plan, OpenAI, Oracle, Origami Risk, Panasonic Energy, PepsiCo, Pilot, Prime Therapeutics, Protecht, Qualys, Quantivate, Questrade, Rapid7, RegScale, RegScan, Resolver, Riskonnect, RiskOptics, SAI360, SAP, ServiceNow, Southwest Airlines, StandardFusion, Starbucks, State of Michigan, Stellantis, Summit Financial Group, SureCloud, Sustainability Accounting Standards Board (SASB), Syntrio, Task Force on Climate-related Financial Disclosures (TCFD), Tenable, The Home Depot, T-Mobile, Topdanmark, Tyson Foods, Uber, University of Oklahoma, US National Institute of Standards and Technology (NIST), Ventiv Technology, Walmart, Wealthsimple, Wendy’s, Wipro, Wolters Kluwer, Workiva

About the authors

Christine O'Donnell

Senior Analyst
Christine is a Senior Analyst in the Verdantix Risk Management practice. Her current research agenda focuses on reputational risk, third-party risk, ESG risk, GRC solutions and regulatory change. Prior to joining Verdantix, Christine worked at Gartner, where she specialized in organizational design and change management. Christine holds a first-class BSc in Geography from the University of Birmingham.

Bill Pennington

VP Research, EHS & Risk Management
Bill is the VP Research for the Verdantix EHS & Risk Management practices. His current agenda focuses on understanding the evolution of EHS and enterprise risk management, evaluating emerging strategic risks and benchmarking technology buyers’ budgets, priorities and preferences globally.

Related Reports

Not a Verdantix client yet?

Register with Verdantix for authoritative data, analysis and advice to allow your business to succeed.