COLLECTION AMRAE
PANORAMAS
2026 Edition
[ Risk Management Information Systems ]
RMIS
PANORAMA
AMRAE wishes to thank the following participants who helped produce this document:
François
BEAUME
AMRAE President,
SVP Risks and Insurance
Sonepar
Géraldine
BRUGUIÈRE -
FONTENILLE
Project Manager
Scientific Pole
AMRAE
Franck
AURÉ
Group Insurance
Director
OPmobility
Bertrand
RUBIO
Associate Partner
EY Risk Consulting
Wilfried
HOUSSEAU
Manager
EY Risk Consulting
Max
GERMOND
Consultant
EY Risk Consulting
Marie-Lolita
CROMBEZ
Consultant
EY Risk Consulting
Thomas
DEREUX
Project Manager
Scientific Pole
AMRAERMIS PANORAMA 2026
2
Please use arrows to easily navigate
AMRAE really wants to thank all of the organizations (IFRIMA, Club FrancoRisk, FERMA, RIMS et PARIMA)
that help making this new edition of the RMIS Panorama a success:
The International Federation of Risk and Insurance Management Associations (IFRIMA) is extremely proud to support the
RMIS Panorama originally developed by AMRAE in partnership with EY..
Data management is becoming critical to all risk management professionals. The fantastic work done by AMRAE, over the
years in this field, is highly recommendable and constitutes a great example for all Risk Management associations.
Gradually, they have been able to get the support from other associations such as FERMA or PARIMA, and we are sure from
many other members of IFRIMA in the future. As the international umbrella organization for risk management associations
from around the world, this is most definitely a leading example for the entire IFRIMA community.
www.ifrima.org
Franck
BARON
IFRIMA President
Group Deputy Director Risk
Management & Insurance at
International SOS
A special thanks also to: GVNW, BELRIM, ANRA, RVA, ALRIM, SI.RISK, SIRM et AGERS.RMIS PANORAMA 2026
3
Please use arrows to easily navigate
Editorial............................................................................................................................................................... 6
Executive summary......................................................................................................................................... 7
RMIS Panorama introduction........................................................................................................................8
RMIS market insights and trends...............................................................................................................13
RMIS analysis by functional and technical axes.....................................................................................22
Detailed vendors’ map.................................................................................................................................. 26
Leaders’ quadrants........................................................................................................................................ 30
Focused analysis: Embracing Artificial Intelligence...............................................................................40
Expert insight: Selecting and implementing a RMIS.............................................................................44
Expert insight: Embedding ESG controls into your RMIS.....................................................................46
Expert insight: Elevating RMIS with ESG integration............................................................................49
Expert insight: Insurer–Broker perspectives: Transforming RMIS into a strategic enabler........... 51
Risk Managers’ testimonials.......................................................................................................................54
Detailed datasheets by vendor...................................................................................................................64
1-ONE...................................................................................................................................................................................................65
360INCONTROL.............................................................................................................................................................................. 66
ACUREDGE........................................................................................................................................................................................ 67
ALEA360............................................................................................................................................................................................. 68
AMÉTHYSTE..................................................................................................................................................................................... 69
ARCHER.............................................................................................................................................................................................. 70
ARENGI................................................................................................................................................................................................ 71
ARIS......................................................................................................................................................................................................72
BIC GRC.............................................................................................................................................................................................. 73
BIZZDESIGN...................................................................................................................................................................................... 74
BLACKROCK (EFRONT).............................................................................................................................................................. 75
CERRIX................................................................................................................................................................................................ 76
CHALLENGE OPTIMUM.............................................................................................................................................................. 77
COAUDIT GROUP........................................................................................................................................................................... 78
CORPORATER.................................................................................................................................................................................. 79
CRIF AG............................................................................................................................................................................................... 80
CRISAM............................................................................................................................................................................................... 81
DELTA RM.......................................................................................................................................................................................... 82
DILIGENT............................................................................................................................................................................................ 83
DIOT SIACI......................................................................................................................................................................................... 84
EASYLIENCE.................................................................................................................................................................................... 85
EGERIE................................................................................................................................................................................................ 86
Table of contentsRMIS PANORAMA 2026
4
Please use arrows to easily navigate
EMPOWERED................................................................................................................................................................................... 87
GRACE CONNECT GRC............................................................................................................................................................... 88
IBM OPENPAGES........................................................................................................................................................................... 89
INCLUS................................................................................................................................................................................................ 90
KERMOBILE...................................................................................................................................................................................... 91
LOGICMANAGER............................................................................................................................................................................ 92
MAPTYCS.......................................................................................................................................................................................... 93
MOODY’S............................................................................................................................................................................................ 94
MY RISK IO........................................................................................................................................................................................ 95
NOVASECUR.................................................................................................................................................................................... 96
ONETRUST........................................................................................................................................................................................ 97
OPTIMISO........................................................................................................................................................................................... 98
OPTRO................................................................................................................................................................................................. 99
OXIAL................................................................................................................................................................................................. 100
POCKETRESULT.......................................................................................................................................................................... 101
PREWAVE........................................................................................................................................................................................ 102
QUADRATIC................................................................................................................................................................................... 103
QUALITADD.................................................................................................................................................................................... 104
RISKHIVE ERM.............................................................................................................................................................................. 105
RISKID.............................................................................................................................................................................................. 106
RISKONNECT................................................................................................................................................................................. 107
RISMO............................................................................................................................................................................................... 108
ROK SOLUTION........................................................................................................................................................................... 109
SAI360................................................................................................................................................................................................ 110
SCHLEUPEN................................................................................................................................................................................... 111
SERVICENOW................................................................................................................................................................................ 112
SMART GLOBAL GOVERNANCE.......................................................................................................................................... 113
SWISS GRC..................................................................................................................................................................................... 114
TEAMMATE..................................................................................................................................................................................... 115
VALUES ASSOCIATES............................................................................................................................................................... 116
VIRTUESPARK.............................................................................................................................................................................. 117
VISIATIV............................................................................................................................................................................................ 118
WORKIVA......................................................................................................................................................................................... 119
Appendix 1...................................................................................................................................................... 120
RISK MANAGERS’ RESPONDENTS GEOGRAPHICAL PRESENCE......................................................................120
Appendix 2 .................................................................................................................................................... 121
VENDORS’ GEOGRAPHICAL PRESENCE.........................................................................................................................121
Appendix 3...................................................................................................................................................... 122
DESCRIPTION OF FUNCTIONAL MODULES AND TECHNICAL AXES...............................................................122
Appendix 4...................................................................................................................................................... 124
CONSULTATION/RESPONSE RESULTS...........................................................................................................................124RMIS PANORAMA 2026
5
Please use arrows to easily navigate
Franck AURÉ
Group Insurance
Director
OPmobility
Editorial
With the publication of this 18
th
edition of the Risk Management Information Systems (RMIS) Panorama, companies continue to
operate in an increasingly complex and uncertain environment. Echoing the theme of the latest AMRAE conference,
“The Odyssey of Risks: Staying the Course,” organizations
are navigating uncharted waters. Geopolitical tensions,
climate change, and disruptions in global commodities
markets are reshaping the risk landscape. In this context, risk
management is no longer only about protection, but about
navigating uncertainty with clarity and resilience.
At the same time, rapid technological advances, particularly
the rise of Artificial Intelligence, are transforming traditional
risk management practices. AI is opening new perspectives
in predictive analytics, weak signal detection, and decision
support.
In the years ahead, these systems will go far beyond risk
identification and monitoring. They will become essential
instruments for guiding decision-making and enabling more
agile responses to crises.
Today, and even more so tomorrow, the use of an RMIS
is becoming an essential part of the daily work of Risk
Managers. RMIS are therefore emerging as a common
language and a powerful driver of cross-functional alignment
across organizations.
In this context, this new edition of the Panorama aims to
provide a comprehensive overview of market developments,
user expectations, and the innovations shaping the future of
RMIS.
This edition presents the results of international surveys: an
analysis of RMIS vendors (146 vendors identified, including
55 respondents) and a survey of 178 Risk Managers,
complemented by contributions from insurers and brokers.
This new edition provides an in-depth market analysis and
offers a detailed overview of RMIS vendors’ solutions. It also
includes updated vendor profiles, enriched to reflect the latest
market entrants featured in this Panorama.
The 2026 Panorama further incorporates new testimonials
from RMIS users, a detailed analysis of the development of
modules related to climate change and artificial intelligence.
as well as a dedicated cross-perspective analysis bringing
together insurers and brokers, offering complementary
insights into the evolving role of RMIS.
As every year, this technical report is available for free
download on the AMRAE website in both French and English.
It is also complemented by a vendor analysis platform that
enables customized RMIS evaluations by sector, company
size, and modules.
We would like to warmly thank all the vendors, Risk
Managers, insurers, and brokers who contributed to our
surveys.
We have also renewed our partnerships with IFRIMA, FERMA,
PARIMA, and Club FrancoRisk. These collaborations foster
stronger engagement with the global risk management
community
AMRAE would also like to extend its sincere thanks to its
partner, EY, for its continued commitment over the years.
We wish you an enjoyable read.RMIS PANORAMA 2026
6
Please use arrows to easily navigate
Executive summary
The 2026 edition of the RMIS Panorama builds on the 2025 release, featuring new and updated vendor detailed datasheets,
fresh testimonials, and exclusive analysis of brokers and insurers.
2026 RMIS Panorama structure
✦ An analysis of market practices and trends, based on a
survey of 178 Risk Managers respondents in 24 countries,
as well as 55 vendors. Our partners Club FrancoRisk,
FERMA, RIMS, PARIMA and IFRIMA, allow us to maintain
the internationalization of the study.
✦ 55 descriptive vendors sheets have been updated
since the 2025 edition, including 4 new participants.
✦ 9 testimonials from Risk Managers sharing their
experience of setting up or using a RMIS.
✦ Several expert insights: the first one shares best practices
to setup a risk management digital journey, including the
selection and implementation of a RMIS; others focus
on how RMIS can serve as a key lever to support ESG
initiatives.
✦A focused analysis on Artificial Intelligence.
✦An overview of Brokers and Insurers vision of RMIS,
based on the results of a survey conducted among them
by AMRAE in March 2026.
Findings and Trends
✦
The RMIS market remains dynamic (>60% increase
of RFPs on RMIS according to RMIS vendors compared
to last period).
✦Large international companies are no longer the sole
buyers; small and mid-cap firms now account for nearly
half of RMIS purchasers.
✦RMIS implementation duration is 4 months for a majority
of them (68%).
✦The average annual cost of a RMIS (SaaS), excluding
integration services, is now €110k per year, showing
a slight increase.
✦The main benefits of RMIS, as perceived by Risk Managers,
are: increasing data consolidation efficiency and analysis
capabilities, improving information sharing and avoiding
silos.
✦Integrated Risk Management: In nearly all cases (98%),
RMIS projects bring together traditional assurance
functions - such as Risk Management, Audit, Internal
Control, Insurance, and Compliance - within a shared
approach and a unified information system.
✦SaaS is now the most common hosting option, increasingly
favored by both customers and vendors.
✦The main criteria for RMIS selection are Functional
coverage, Easy to use and Customization flexibility;
although nearly half of the risk managers (43%) note
that Customization flexibility does not entirely meet their
expectations.
✦The satisfaction level among Risk Managers over selection
criteria remains high at 72% on average (+4 points), though
there is still room for improvement in Customization
flexibility, Innovation and Reporting capabilities.
✦The satisfaction level across all functional modules (Risk
Mapping, Internal Control, Audit, ESG, etc.) has increased
significantly, rising by 20 points to reach 89%.
✦Artificial Intelligence (AI) is reshaping Risk Management,
with 90% of RMIS integrating or planning to integrate AI
features by 2025, driven by very strong interest from risk
managers and aiming to enhance qualitative analysis,
real-time risk detection, and predictive capabilities.
✦Responsible AI practices are emerging but still
maturing, as most RMIS providers recognize the need
for transparency and accountability, while risk managers
are urged to embrace AI opportunities with agility and
vigilance.RMIS PANORAMA 2026
7
Please use arrows to easily navigate
RMIS Panorama introduction
The RMIS, a fundamental tool dedicated to Risk Management
The Risk Management function is fundamentally centered
around the collection, analysis, synthesis, and reporting
of data—often diverse and fragmented in nature. Timely
identification of risks and prompt reporting of incidents,
both in terms of location and timing, require efficient and
structured management of data flows.
This is precisely the role of a Risk Management Information
System (RMIS), also referred to as GRC (Governance,
Risk, Compliance) or IRM (Integrated Risk Management)
technologies. These systems are designed to process large
volumes of data and deliver it in a format that is actionable
for risk managers. Far from being limited to analytical or
operational purposes, RMIS tools serve as strategic enablers
for communication, collaboration, and the dissemination of
key risk insights across the organization.
RMIS are designed to provide a management tool for every
Risk Management actors:
>Top Management can have a consolidated view of entailed
Risks and actions in progress.
>Managers (Risk Owners) in charge of handling a set of Risks
have this same view and can use it to manage actions within
their area of coverage.
>Risk Management and Insurance:
-The Risk Managers can coordinate all Risk Management
related actions, from identification to treatment, and
implement more specific measures (e.g. related to
managing loss claims and Insurance policies).
-Other functions (Internal Audit, Internal Control,
Compliance, Quality, ESG, Legal, IT...).
>Potential external partners (Brokers, consulting firms…).
Main objectives of this RMIS Panorama
Since 2008, this study has aimed to provide insights to Risk
Management stakeholders seeking structured and objective
information on Risk Management Information Systems
(RMIS). Its primary objective is to support decision-making
by addressing key questions such as:
>What are the actual needs of Risk Management functions?
>To what extent do market solutions address these needs?
>Should organizations favor specialized tools or opt for
integrated RMIS platforms?
>Which key selection criteria should be considered as part of a
call for tender process?
With a view to avoiding potential conflict of interest and
meeting the most stringent ethical standards, this work was
carried out, from the beginning, based on three core tenets.
The Panorama is based on two complementary surveys:
✦An RMIS vendors survey, which allows solution providers
to share their perspectives on market trends and to
self-assess their solutions against detailed functional and
technical coverage criteria.
✦A Risk Managers survey, designed to capture practitioners’
needs, expectations, decision criteria, and feedback based
on their experience with RMIS solutions in operational
contexts.
To avoid any potential conflict of interest and to comply
with the highest ethical standards, this work has, from its
inception, been guided by three core principles:
✦Neutrality: the Panorama does not express value
judgments on vendors or their solutions, nor does it
recommend the purchase of specific products. Its sole
purpose is to provide a structured framework to present
the RMIS solutions and their main functionalities available
on the market.
✦Objectivity: the survey questions focus on the features
delivered by each solution and are primarily technical,
factual, and verifiable. RMIS vendors self-assess
themselves.
✦Business-oriented approach: questions and analyses are
directly linked to the concrete functions, use cases, and
operational needs of Risk Managers.
The Panorama is updated on an alternating basis, with
either a major or a minor update performed each year.
>A minor update mainly affects the detailed data sheets
of all RMIS vendors (such as ID cards, areas of presence,
differentiators, etc.), excluding updates to the radar views
related to functional and technical coverage. It also integrates
newly identified RMIS vendors and provides refreshed expert
opinions and testimonials.
>A major update involves the revision and distribution of
surveys to both RMIS vendors and Risk Managers, enabling a
comprehensive refresh of the study, including market trends,
leaders’ quadrants, detailed vendor maps, and other core
analyses.
The 2026 edition represents a minor update of the 2025
study.RMIS PANORAMA 2026
8
Please use arrows to easily navigate
SCOPE OF RISK MANAGERS’ RESPONSIBILITY
Risk Management 77
%
Insurance 49
%
Internal Control 29
%
Business Continuity 25
%
Compliance 21
%
Crisis Management 19
%
Internal Audit 14
%
ESG* 11
%
Other(s) 9
%
Legal 7
%
Information Systems 7
%
General Management 7
%
Finance 7
%
Surety 3
%
* Environmental, Social, and Governance
Arrows indicating trends variation vs previous survey.
Data coming from the “Risk Managers” survey are highlighted with this logo.
SECTORS OF THE RISK MANAGERS’ COMPANIES
Other(s) 16
%
Diversified Industrial Product / Transportation 16
%
Asset Mgmt, Banking & Capital Markets, Insurance 15
%
Power, Utilities, Oil & Gas, Mining 11
%
Government & Public Sector 11
%
Life Sciences & Chemicals 10
%
Telecom, Media & Technology 9
%
Real Estate, Construction & Hospitalities, Private Equity 7
%
Retail & Consumer Product 5
%
A global Risk Manager survey
With the support of our partners – IFRIMA, FERMA, PARIMA,
RIMS and Club FrancoRisk – we achieved truly global
coverage, collecting and analyzing responses from 178 risk
managers in 24 countries.
51% of the respondent Risk Managers have already
implement an RMIS.
57% of the respondent Risk Managers work for large
companies (Turnover > €1bn).RMIS PANORAMA 2026
9
Please use arrows to easily navigate
A global RMIS vendors survey
The RMIS vendors survey covers market trends as well as
the functional and technical scope of the RMIS solutions
assessed, through a total of 174 questions. The most recent
questions added for the 2025 edition focused in particular on
Analytics and Artificial Intelligence.
This year, after a review of market actors, a list of 144 vendors
was set up, including vendors consulted last years as well
as new market players. These vendors were then directly
contacted by AMRAE or EY and invited to participate in an
online and free survey for over a month.
RMIS panel of respondents
For the 2026, edition, the Panorama is composed of a panel of 55 respondents among consulted vendors.
4 new respondents have participated in this edition.
1-ONE 360INCONTROL ACUREDGE ALEA360 AMÉTHYSTE ARCHER ARENGI ARIS
BIC GRC BIZZDESIGN
BLACKROCK
(EFRONT)
CERRIX
CHALLENGE
OPTIMUM
COAUDIT GROUPCORPORATER CRIF AG
CRISAM DELTA RM DILIGENT DIOT SIACI EASYLIENCE EGERIE EMPOWERED
GRACE
CONNECT GRC
IBM OPENPAGES INCLUS KERMOBILE LOGICMANAGER MAPTYCS MOODY’S MY RISK IO. NOVASECUR
ONETRUST OPTIMISO OPTRO OXIAL POCKETRESULT PREWAVE QUADRATIC QUALITADD
RISKHIVE ERM RISKID RISKONNECT RISMO ROK SOLUTION SAI360 SCHLEUPEN SERVICENOW
SMART GLOBAL
GOVERNANCE
SWISS GRC TEAMMATE
VALUES
ASSOCIATES
VIRTUESPARK VISIATIV WORKIVA
New respondent
MAIN INDUSTRY CHANGES
>AuditBoard has been rebranded as Optro
>Mega has been rebranded and aquired by Bizzdesign
>Iskera has acquired Acuredge, Optimiso and Pocket Result
4 new respondents
55 respondentsRMIS PANORAMA 2026
10
Please use arrows to easily navigate
VENDORS’ WORKFORCE DEDICATED TO RMIS (46/55*)
The companies in the panel show strong heterogeneity in terms of size, particularly regarding the number of employees.
To make meaningful comparisons, we grouped them into four categories based on headcount. Within each group, we
observe varying levels of resources allocated to RMIS, which allows for more relevant benchmarking and highlights
differences in strategic focus among similar-sized companies.
>20.000 employees
IBM OPENPAGES 6 000
1.000-20.000 employees
SERVICENOW 2 300
ACUREDGE 60
CRISAM 82
DIOT SIACI 18
VISIATIV 25
RISKONNECT 1 451
100-1.000 employees
ARCHER 20
BIZZDESIGN 580
SCHLEUPEN 45
SAI360 300
CORPORATER 250
EGERIE 150
<100 employees
CRIF AG 80
BIC GRC 75
EMPOWERED 70
SWISS GRC 605
QUADRATIC 5
SMART GLOBAL GOVERNANCE 55
OXIAL 55
LOGICMANAGER 43
QUALITADD 26
ARENGI 30
EASYLIENCE 25
OPTIMISO 32
POCKETRESULT 32
MAPTYCS 30
CERRIX 28
KERMOBILE 5
VALUES ASSOCIATES 20
INCLUS 20
DELTA RM 20
NOVASECUR 17
COAUDIT GROUP 15
RISKID 14
RISMO 7
1-ONE 8
360INCONTROL 12
ROK SOLUTION 3
AMÉTHYSTE 8
RISKHIVE ERM 6
CHALLENGE OPTIMUM 5
VIRTUESPARK 4
MY RISK IO. 6
GRACE CONNECT GRC 6
ALEA360 5
279 000
14 700
10 940
6 503
5 982
1 675
980
45
555
222
10
55
12
20
5
10
20
3
5
6
11
6
7
2
2
3
Number of Employees working on the RMIS
Non-RMIS Employees
* Data (regarding RMIS headcount) were
not provided by the 9 following vendors:
ARIS, Optro, BlackRock (eFront), OneTrust,
Diligent, Moody’s, Prewave, TeamMate, WorkivaRMIS PANORAMA 2026
11
Please use arrows to easily navigate
RMIS VENDORS GEOGRAPHICAL PRESENCE
Covered by
38 vendors
Covered by
43 vendors
Covered by
55 vendors
Covered by
33 vendors
Covered by
30 vendors
Covered by
27 vendors
Covered by
22 vendors
Covered by
24 vendors
Covered by
28 vendors
Covered by
33 vendors
Covered by
24 vendors
Covered by
31 vendors
Covered by
32 vendors
Covered by
28 vendors
Covered by
45 vendors
>This map shows the presence (commercial and implementation services) of RMIS Vendors by region.
>A description of the Vendors presence is available in
Appendix 2.
Central Africa
East Africa
North Africa
West Africa
South Africa
Central America
North America
South America
Central and Northern Asia
East Asia
South Asia
South East Asia
South West Asia
Central and Eastern Europe
Northern Europe
Western Europe
Oceania
Covered by
25 vendors
Covered by
30 vendorsRMIS PANORAMA 2026
12
Please use arrows to easily navigate
RMIS market insights and trends
This chapter provides an up-to-date overview of the RMIS market, as perceived by both risk managers and RMIS providers.
How is the market evolving?
The RMIS market continues to be dynamic, reinforcing the trend observed in recent years of an increasing number of RMIS Requests for
Proposals (RFPs).
MARKET DYNAMICS ACROSS COMPANY SIZES
54
%
of large
companies
46
%
of small or medium
companies
Which sectors are using RMIS, and how many users are there?
The RMIS landscape is evolving, with a notable shift in user distribution observed in the 2025-2026 survey. The average
number of users now reflects a more diverse range of adoption across organizations with a significant share now exceeding
200 users (26% in 2024 compared to 37% in 2025-2026).
The predominant sectors using RMIS remain consistent, with a strong presence in Industry & Services, and Banking &
Insurance sectors. The increase in larger user bases suggests that organizations are expanding their RMIS capabilities
through multi-module implementations and broader user involvement.
COMPANY SECTORS USING RMIS
Industry & Services 42
%
Banking & Insurance 33
%
Public Sector 13
%
Others 12
%
AVERAGE NUMBER OF USERS
< 50 users 25
%
50-200 users 38
%
> 200 users 37
%
RFP RMIS INFLUX
INTERNATIONAL COMPANIES REMAIN THE MAIN BUYERS
Local International
44
%
56
%
Buyers companies
2013 2015 2017 2019 20252021
#RMIS RFP
62
%
2023
-6
%
+6
%
The shift towards larger user bases suggests that organizations are prioritizing scalable RMIS solutions that can grow with
their needs, reflecting a trend towards flexibility and adaptability in risk management practices (multi-module capabilities
within RMIS).
The dynamism of the market is evident
across all company sizes and location.
62
%
of respondents
report an increase in
calls for tendersRMIS PANORAMA 2026
13
Please use arrows to easily navigate
Why implementing a RMIS?
There is now a well-established global consensus among risk managers regarding the core value a RMIS should deliver –
and these expectations have remained largely consistent across regions and over time.
The RMIS is no longer seen as a mere compliance tool, but increasingly as a driver of efficiency, cross-functional analysis
and improved communication.
PERCEIVED RMIS BENEFITS (vs. position in the list in 2024)
1. Spend less time consolidating data, more time analyzing it ( 2)
2. Facilitate cross departments analysis and avoid silos ( 3)
3. Facilitate sharing of information (including data consolidation)
between entities and corporate ( 1)
4. Real-time data ( 5)
5. Harmonization of practices and reporting ( 4)
6. Data reliability ( 6)
7. Optimize the sharing of risk management best practices ( 8)
8. Decision support tool ( 7)
9. Be compliant with laws/regulations ( 10)
10. Secure sensitive information ( 9)
11. Optimize transfer to insurances ( 11)
Is it a single buyer or a transverse and collaborative selection process?
SEVERAL DEPARTMENTS ARE INVOLVED IN RMIS RFP
Yes, more frequently 86
%
Yes, sometimes 12
%
Generally no 2
%
RMIS MOSTLY COVER SEVERAL MODULES
Yes, a single RMIS for all 50
%
Yes, a single RMIS for several modules 46
%
No, one RMIS per module 4
%
For an increasing and a large majority of vendors (98%) and Risk Managers (96%), RMIS RFPs (Requests For Proposals)
should involve several business departments of the company in a coordinated approach.
Half of the responding Risk Managers (50%) target a single tool for all functional areas (Audit, Risk Management, Insurance,
Internal Control, etc.).
This highlights the need for converging Risk Management systems to make them more integrated and effective.RMIS PANORAMA 2026
14
Please use arrows to easily navigate
Are Risk Managers’ expected budgets in line with RMIS vendors’ proposals?
The expected budgets from Risk Managers in 2025-2026 align with those indicated by RMIS vendors, reflecting a growing
understanding of the financial requirements for effective risk management solutions.
- Limited Budget (<100k€): This budget range appears adequate for a limited functional scope, as outlined in Scenario 1
described on the next page.
- Extended Budget (100-300k€): This range is suitable for a more extensive functional scope, as detailed in Scenario 2.
- Average Annual Cost: The overall average annual cost (SaaS) of an RMIS, excluding integration services, has slightly
increased to 110k€ per year (95k€ in 2024).
RMIS yearly cost
The following costs include licenses only, excluding
integration services. Costing hypotheses are described in
two scenarios (see next page), based on responses from 35
of the 55 RMIS vendors.
RMIS YEARLY COST ESTIMATED BY SCENARIO
Scenario 1 (limited scope) Scenario 2 (extended scope)
14
%
100-250k€
34
%
<20 k€
8
%
20-50k€
39
%
11
%
>250k€
14
%
50-100k€
39
%40
%
RMIS AVERAGE ANNUAL COST (SaaS)
Scenario 1 Scenario 2
(Limited scope) (Extended scope)
150 K€
60 K€
Risk Managers’ expected budget
Expected budget (year 1) indicated by Risk Managers
includes licenses and integration services (from project
launch to the tool go-live).
EXPECTED BUDGET TO ACQUIRE AND IMPLEMENT A RMIS
<100k€ 55
%
100-300k€ 36
%
300-500k€ 5
%
500k€-1M€
4
%
>1M€ 0
%
EXPECTED BUDGET TREND
2024 2025-2026
4
%
4
%
0
%
0
%
<100 k€
55
%
42
%
100-300k€
36
%
500k€-1M€ >1M€300-500k€
10
%
5
%
44
%
0
%
0
%RMIS PANORAMA 2026
15
Please use arrows to easily navigate
Scenario 1 (client profile)
- Company sector: Industry
- Company turnover : €2 billion
- Company maturity in Risk Management: average
- RMIS modules: “Risk Mapping” and “Action Plan
Management”
- RMIS users licenses: 150
Scenario 2 (client profile)
- Company sector: Industry
- Company turnover : €50 billion
- International group, matrix organization
- Company maturity in Risk Management, Audit, Control:
strong
- RMIS modules: “Risk Mapping”, “Internal Control”, Internal
Audit”, “Action Plan Management”
- RMIS users licenses: 500
How long does it take to implement a RMIS?
The RMIS market implementation duration remains stable in 2025-2026 compared to 2024, with a significant majority of RMIS
vendors (68%) reporting that their tools can be implemented in less than 4 months, from project kick-off to go-live.
RMIS AVERAGE IMPLEMENTATION DURATION
<than 4 months 4 to 6 months > than 6 months
68
%
24
%
8
%
This average implementation duration, estimated by 50
vendors, is based on the “simple” scenario 1 described above.
The individual answers are shown on each vendor detailed
datasheet.
4 months
(average
implementation
duration)RMIS PANORAMA 2026
16
Please use arrows to easily navigate
WHO IS INITIATING RMIS TENDERS?
2024 2025-2026 Key function
Head of Risk Management 92
%
90
%
Head of Compliance 60
%
55
%
Head of Internal Control 54
%
59
%
Head of Internal Audit 46
%
51
%
Chief Financial Officer 38
%
37
%
Risk Committee 37
%
31
%
Head of IS Security 37
%
37
%
Head of IT 35
%
41
%
Head of Insurance 25
%
25
%
Head of Legal 21
%
25
%
Managing Director 21
%
27
%
Audit Committee 17
%
16
%
Head of Quality 17
%
20
%
Head of Sustainable Development 12
%
10
%
Head of Health & Safety 8
%
18
%
General Secretary 8
%
12
%
Others 12
%
6
%
How do multiple stakeholders contribute to a collective decision?
The selection of a RMIS remains a collaborative process that
involves multiple stakeholders from the outset, particularly in
identifying organizational needs. The primary functions driving
the demand for these solutions continue to be the Risk, Audit,
Compliance, and Internal Control departments.
As RMIS projects become more cross-functional, CFOs, Risk
Committee, IT and IS Security are becoming key sponsors and
decision makers in RMIS selection process.RMIS PANORAMA 2026
17
Please use arrows to easily navigate
WHO IS THE DECISION MAKER IN RMIS TENDERS?
2024 2025-2026 Key function
Head of Risk Management 92
%
88
%
Head of IT 63
%
63
%
Head of Compliance 63
%
59
%
Chief Financial Officer 62
%
63
%
Head of Internal Audit 60
%
57
%
Head of Internal Control 56
%
57
%
Head of IS Security 48
%
53
%
Managing Director 46
%
57
%
Head of Insurance 31
%
20
%
Head of Legal 25
%
25
%
Head of Quality 21
%
27
%
General Secretary 19
%
18
%
Head of Sustainable Development 13
%
12
%
Head of Health & Safety 8
%
18
%
Others 10
%
4
%RMIS PANORAMA 2026
18
Please use arrows to easily navigate
Which are the key criteria for selecting a RMIS?
This year, the criteria for selecting a RMIS have remained
consistent, with Functional coverage still taking first place,
followed by Customization flexibility. Easy to use continues
to be a crucial selection criterion.
The emphasis on Customization flexibility reflects the specific
needs of customers, who require the ability to tailor their
RMIS to align with their unique business processes. This
trend is supported by the growing demand for integrating
RMIS with other information systems, as well as the
significance of sector-specific expertise within RMIS.
RMIS SELECTION CRITERIA (vs. position in the list in 2024)
1. Functional coverage ( 1)
2. Customization flexibility ( 2)
3. Easy to use ( 3)
4. Interfaces with other information systems ( 7)
5. Reporting capabilities ( 6)
6. Price ( 4)
7. Sector specific expertise ( 11)
8. Company sustainability ( 5)
9. Quality of integration services and support services ( 8)
10. Hosting services (SaaS or internal hosting) ( 9)
11. Innovation (Artificial Intelligence, Chatbots,
Predictive analysis, …) ( 10)
Satisfaction among Risk Managers has improved from 2024 to
2025-2026, with 72% satisfied with their RMIS in 2025-2026, up
slightly from 70% in 2024. Functional coverage remains a strong
point. In 2025-2026, 83% said their expectations were met or
exceeded, compared to 78% in 2024, highlighting the continued
importance of a robust functional scope in RMIS solutions.
Innovation satisfaction has significantly increase (+15% since
2024), even if a significant 42% still feel that innovation falls
below expectations, indicating that there is a considerable
room for growth in Artificial Intelligence, Chatbots, Predictive
analysis,…
While most vendors are increasingly offering integration
options through APIs (two-thirds of vendors now offer it) or
standard imports, many Risk Managers working in multi-source
environments still find these capabilities lacking. Sharing data
via APIs could give users more flexibility and autonomy.
Although Risk Managers’ satisfaction with Reporting capabilities
remains stable, it continues to be a crucial area of focus,
especially concerning the level of autonomy customers
have in creating and customizing reports, as well as the
comprehensiveness of the report library.
FEEDBACK ON SELECTION CRITERIA
Beyond expectations Meet expectations Below expectations Major increase vs 2024 (>10 points)
Customization (flexibility) 43
%
10
%
47
%
Innovation (Artificial Intelligence, Chatbots, Predictive analysis, …) 10
%
48
%
42
%
Sector specific expertise 41
%
8
%
51
%
Reporting capabilities 39
%
6
%
55
%
Interfaces with other information systems 34
%
10
%
56
%
Price 31
%
8
%
61
%
Quality of integration services and support services 22
%
15
%
63
%
Easy to use 20
%
11
%
69
%
Company stability/viability 16
%
12
%
72
%
Functional coverage 5
%
83
%
12
%
Hosting services (SaaS or internal hosting) 5
%
13
%
82
%RMIS PANORAMA 2026
19
Please use arrows to easily navigate
What are the trends in RMIS deployment methods?
Risk Managers do not have a clear preference for financing: subscription-based rental model (which usually includes
hosting), or licence acquisition and maintenance model.
PREFERRED FINANCIAL SOLUTION
SaaS - Licenses rentalLicenses acquisition
52
%
48
%
There is a clear trend toward hosting RMIS by a software vendor’s means (SaaS) with 80% of vendors offerings.
Even though the majority of vendors remain open to hosting within the client’s infrastructure (68% of vendor).
PREFERRED HOSTING SOLUTION
Hosting managed by
RMIS vendor
59
%
In-house
hosting
41
%
A confirmed trend is that Risk Managers
have consistently preferred outsourced
hosting in recent years.
Should the RMIS be accessible to external parties?
Almost the majority of Risk Manager (43%) are anticipating open up their RMIS to external actors.
Brokers and External auditors are those for whom responding Risk Managers are most inclined to share RMIS data.
RMIS ACCESS FOR EXTERNAL ACTORS
Yes I’m considering No
Brokers 23
%
23
%
54
%
External auditors 22
%
26
%
52
%
Actuaries 21
%
25
%
54
%
Experts 16
%
24
%
60
%
Insurers 13
%
24
%
63
%
Consultants 13
%
30
%
57
%
HOSTING SOLUTION OFFERED (BY RMIS VENDORS)
Yes No
Client 32
%
68
%
Vendor (Subcontractor) 20
%
80
%
Vendor 34
%
66
%
While two-thirds of vendors allow their clients to host solutions
on their own IT environments, there is a notable trend towards
SaaS hosting though a subcontractor.RMIS PANORAMA 2026
20
Please use arrows to easily navigate
What will be the next RMIS modules?
While the traditional RMIS modules such as Risk Mapping,
Audit, Internal Control, Compliance and Data Protection
appear to be well covered by vendors, the following modules
and functionalities are noted on the software vendors’
agenda for future development:
✦Artificial Intelligence
✦BCP and Crisis Management
✦ESG
Third Party Risk Management (TPRM) was introduced in the
Panorama for the first time in 2021 and was available in the
majority of RMIS (59%). It now represents a significant portion
of RMIS (75%) and seems to be fully integrated to RMIS
vendors.
The use of Artificial Intelligence functionalities, which can
enhance various functional modules, is still quite limited.
A noteworthy 42% of Risk Managers indicate that innovation
does not meet their expectations, pointing to significant
potential for advancement.
The modules that have been most developed over the last
two years cover Artificial Intelligence (+35 points), Analytics
(+15 points), Advanced reporting (+12 points), and ESG (+10
points).
Which are Risk Managers’ key functional needs?
Risk mapping (98%), Risk Management on Prevention (95%),
Action Plans (94%) and Audit (93%) remain the most highly
expected functional modules of a RMIS.
Expectations also remain high for the following modules:
Analytics (92%), BCP and Crisis Management (91%) and
Third Party Risk Management (90%).
In contrast, expectations for areas such as ESG (86%) and
Governance (77%) are lower.
Artificial Intelligence: we see a very strong increase (from
50% to 86% in 2025-2026) of Risk Manager interest.
FUNCTIONAL NEEDS OF RISK MANAGERS
(vs. position in the list in 2024)
1. Risk Mapping ( 1)
2. Risk management on prevention ( 4)
3. Action Plans ( 2)
4. Audit ( 3)
5. Analytics
6. BCP and Crisis Management ( 9)
7. Compliance ( 7)
8. Third Party Risk Management ( 12)
9. Internal Control ( 5)
10. Quality ( 14)
11. Incidents management ( 6)
12. Cybersecurity ( 10)
13. ESG ( 13)
14. Data Privacy ( 11)
15. Artificial Intelligence ( 17)
16. Insurance ( 8)
17. Governance ( 16)
RMIS ROADMAP, BY FUNCTIONAL MODULES
Already covered by the tool Already covered by interfaces/connectors with external tools To develop within the tool
Interfaces/connectors to develop with external tools Not anticipated
Advanced reporting / Business Intelligence 17
%
79
%
4
%
Analytics 12
%
78
%
8
%
2
%
Third Party Risk Management 12
%
74
%
2
%
10
%
2
%
Data Privacy 10
%
74
%
4
%
4
%
8
%
ESG 8
%
4
%
72
%
12
%
4
%
Artificial Intelligence 8
%
4
%
69
%
20
%
BCP and Crisis Management 10
%
68
%
14
%
2
%
6
%
Cybersecurity 10
%
68
%
6
%
6
%
10
%
Business process modelling 17
%
6
%
53
%
12
%
12
%
Insurance 12
%
23
%
37
%
6
%
22
%RMIS PANORAMA 2026
21
Please use arrows to easily navigate
RMIS analysis by functional and technical axes
Survey methodology for vendors
Regarding the RMIS survey, standard multiple-choice questions were proposed to enable analysis on a standardized basis.
As in previous years, a score is assigned to each of the standardized answers as follows:
COVERAGE SCOREDESCRIPTION
Feature not covered 0 Feature not implemented in the solution
Feature can be covered
with ad hoc development
1 No existing standard, but can be developed with ad hoc development by a specialist (depending
on aspects: vendor, integrator or client IT Department)
Feature covered, but
limited to a standard
behavior
2 Using the existing standard, but not editable/configurable , either by the vendor, the integrator,
the business user or the client IT Department
Feature covered by
technical customization
3 Customization of the standard solution, that can only be performed by a technical expert of the
solution (for instance: people from vendor, integrator, or from client IT Department, previously
trained to technical solution administration)
Feature covered
by business user
customization
4 Customization of the standard solution, that can be performed by a business user,
independently from the client IT Department and from vendor or integrator (possibly after a
nontechnical functional administration training)
This scoring scale provides for a transparent and objective analysis of responses, enabling both individual and global
conclusions.
Finally, we would like to point out that, as in previous editions, the analysis is based solely on vendor self-assessments.
In line with our core tenets mentioned above, no tests or interviews were conducted to avoid any judgment from the team
responsible for developing the Panorama.
As this 2026 edition is a minor release, the technical and functional coverage indicators from the previous edition have been
maintained. The RMIS vendors survey was therefore administered only to newly identified market entrants.RMIS PANORAMA 2026
22
Please use arrows to easily navigate
2025-2026 analysis
The following charts show aggregated vendors responses on functional modules and technical axes and provide
a comparison with the results achieved in the 2024 edition.
FUNCTIONAL MODULES COVERAGE (BASED ON VENDORS’ SELF-ASSESSMENTS)
Average 2025-2026Average 2024
0%
10%
20%
30%
40%
50%
60%
70%
80%
90%
100%
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Analysis:
>Overall stability : the functional coverage across all modules remains relatively stable. This might illustrate an overall maturity of
RMIS offering.
>Artificial Intelligence shows a clear progression (+8 points) illustrating the investments made by the RMIS, however the overall
coverage remains low. This progress highlights a growing recognition of AI’s importance in risk management, but it also
underscores the need for RMIS vendors to still enhance their capabilities on this area.
>The low coverage regarding the ESG module (-15 points) could be explained by a stricter coverage questionnaire this year, but
also by products still needing to be strengthened in order to meet the needs of risk managers.
>Strong maturity for the following modules: Risk Mapping, Audit, Internal Control and Risk Management on Prevention.
>The calculation method for each functional module is only based on vendors who confirmed they have this module.
>The Competitive Intelligence module, present in 2024, has not been kept.
The description of the functional modules is available in
Appendix 3.RMIS PANORAMA 2026
23
Please use arrows to easily navigate
FUNCTIONAL MODULES SATISFACTION LEVEL (BASED ON RISK MANAGERS)
Beyond expectations Meet expectations Below expectations Major increase vs 2024 (>20 points)
Governance 15
%
85
%
Quality 14
%
86
%
Data Privacy 19
%
77
%
4
%
ESG 20
%
76
%
4
%
Cybersecurity 18
%
78
%
4
%
Compliance 20
%
73
%
7
%
Risk Management on Prevention 20
%
72
%
8
%
Incidents Management 14
%
78
%
8
%
Insurance 10
%
80
%
10
%
BCP and Crisis Management 17
%
73
%
10
%
Audit 19
%
70
%
11
%
Risk Mapping 17
%
68
%
15
%
Action Plans 18
%
64
%
18
%
Internal Control 19
%
62
%
19
%
Analytics 16
%
65
%
19
%
Third Party Risk Management 13
%
64
%
23
%
Artificial Intelligence 14
%
61
%
25
%
All modules saw a very significant increase in satisfaction level (+20 points compared to 2024), illustrating significant added
value of RMIS from Risk Managers perspective.
The following modules shows the greatest increase: ESG, Artificial Intelligence, Data Privacy, Quality and Governance.
While looking at some modules recently added, Third Party Risk Management and Artificial Intelligence satisfy more than
75% of respondents.
The Quality and Governance modules have made significant progress this year, becoming the most highly rated modules
among Risk Managers.
RMIS PANORAMA 2026
24
Please use arrows to easily navigate
TECHNICAL AXES COVERAGE (BASED ON VENDORS’ SELF-ASSESSMENTS)
Analysis:
>The general shape of the curve remains substantially the same as in 2024 edition.
>Most technical areas continue to be covered at an average rate of 84% by all respondents.
>The coverage rate of the Configuration axis increased by 6%.
>RMIS access management is still a sensitive area where vendors have a good level of coverage (+3 points).
The description of the technical axes is available in
Appendix 3.
Average 2025-2026Average 2024
0%
10%
20%
30%
40%
50%
60%
70%
80%
90%
100%
Reportings
Import
Export
Mobility
Documentation
Configuration Workflows
Organization
Security
Architecture
Access/Authentication
Languages
CurrenciesRMIS PANORAMA 2026
25
Please use arrows to easily navigate
Detailed vendors’ map
Functional modules
Risk Mapping
Internal Control
Audit
Compliance
Governance
Action Plans
Insurance
Incidents Management
Risk Management on Prevention
Quality
ESG
Third Party Risk Management
BCP and Crisis Management
Cybersecurity
Data Privacy
Analytics
Artificial Intelligence
1-ONE
360INCONTROL
ACUREDGE
ALEA360
AMÉTHYSTE
ARCHER
ARENGI
ARIS
BIC GRC
BIZZDESIGN
BLACKROCK (EFRONT)
CERRIX
CHALLENGE OPTIMUM
COAUDIT GROUP
CORPORATER
CRIF AG
CRISAM
DELTA RM
DILIGENT
DIOT SIACI
EASYLIENCE
EGERIE
EMPOWERED
GRACE CONNECT GRC
IBM OPENPAGES
INCLUS
KERMOBILE
LOGICMANAGER
MAPTYCS
Analysis based on the 2025 vendors’ self-assessments
(and 2026 for the new vendors)RMIS PANORAMA 2026
26
Please use arrows to easily navigate
Functional modules
Risk Mapping
Internal Control
Audit
Compliance
Governance
Action Plans
Insurance
Incidents Management
Risk Management on Prevention
Quality
ESG
Third Party Risk Management
BCP and Crisis Management
Cybersecurity
Data Privacy
Analytics
Artificial Intelligence
MOODY’S
MY RISK IO.
NOVASECUR
ONETRUST
OPTIMISO
OPTRO
OXIAL
POCKETRESULT
PREWAVE
QUADRATIC
QUALITADD
RISKHIVE ERM
RISKID
RISKONNECT
RISMO
ROK SOLUTION
SAI360
SCHLEUPEN
SERVICENOW
SMART GLOBAL GOVERNANCE
SWISS GRC
TEAMMATE
VALUES ASSOCIATES
VIRTUESPARK
VISIATIV
WORKIVA
Analysis based on the 2025 vendors’ self-assessments
(and 2026 for the new vendors)RMIS PANORAMA 2026
27
Please use arrows to easily navigate
Technical axes
Access/Authentication
Security
Architecture
Organization
Languages
Currencies
Workflows
Configuration
Mobility
Documentation
Export
Import
Reportings
1-ONE
360INCONTROL
ACUREDGE
ALEA360
AMÉTHYSTE
ARCHER
ARENGI
ARIS
BIC GRC
BIZZDESIGN
BLACKROCK (EFRONT)
CERRIX
CHALLENGE OPTIMUM
COAUDIT GROUP
CORPORATER
CRIF AG
CRISAM
DELTA RM
DILIGENT
DIOT SIACI
EASYLIENCE
EGERIE
EMPOWERED
GRACE CONNECT GRC
IBM OPENPAGES
INCLUS
KERMOBILE
LOGICMANAGER
MAPTYCS
Analysis based on the 2025 vendors’ self-assessments
(and 2026 for the new vendors)RMIS PANORAMA 2026
28
Please use arrows to easily navigate
Technical axes
Access/Authentication
Security
Architecture
Organization
Languages
Currencies
Workflows
Configuration
Mobility
Documentation
Export
Import
Reportings
MOODY’S
MY RISK IO.
NOVASECUR
ONETRUST
OPTIMISO
OPTRO
OXIAL
POCKETRESULT
PREWAVE
QUADRATIC
QUALITADD
RISKHIVE ERM
RISKID
RISKONNECT
RISMO
ROK SOLUTION
SAI360
SCHLEUPEN
SERVICENOW
SMART GLOBAL GOVERNANCE
SWISS GRC
TEAMMATE
VALUES ASSOCIATES
VIRTUESPARK
VISIATIV
WORKIVA
Analysis based on the 2025 vendors’ self-assessments
(and 2026 for the new vendors)RMIS PANORAMA 2026
29
Please use arrows to easily navigate
Leaders’ quadrants
GRC quadrant
The following RMIS vendors’ maps are built using solely vendors‘ self assessments without any input or analysis
from AMRAE and EY. They are organized by functional module showing only vendors covering this area.
For clarity and transparency, only 20 vendors are displayed on each map using their abbreviated name. These 20 vendors are
selected based on a weighted average score across the modules, where functional modules count for two-thirds and technical
modules for one-third of the total score.
A complete list of all vendors including functional and technical details is available in the vendor profile section.
This item includes :
>Risk Mapping
>Audit
>Internal Control
>Compliance
>Action Plans
>Governance
Functional coverage
Technical coverage
Analysis based on the 2025-2026 respondents panel
100%
100%
85%
75%
Riskonnect
DELTA RM
Oxial
BIZZDESIGN
Schleupen
ServiceNow
Arengi
COAUDIT
BIC GRC
Values associates
Blackrock (Efront)
Smart Global Governance
Qualitadd
ROK SOLUTION
CRISAM
CORPORATER
NOVASECUR
IBM OPENPAGES
Pocket
result
AcuredgeRMIS PANORAMA 2026
30
Please use arrows to easily navigate
Insurance Quadrant
The following RMIS vendors’ maps are built using solely vendors‘ self assessments without any input or analysis
from AMRAE and EY. They are organized by functional module showing only vendors covering this area.
For clarity and transparency, only 20 vendors are displayed on each map using their abbreviated name. These 20 vendors are
selected based on a weighted average score across the modules, where functional modules count for two-thirds and technical
modules for one-third of the total score.
A complete list of all vendors including functional and technical details is available in the vendor profile section.
This item includes :
>Insurance Management
>Incidents Management
>Risk Management on Prevention
>Action Plans
Functional coverage
Technical coverage
Analysis based on the 2025-2026 respondents panel
100%
100%
40%
75%
MY RISK IO.
CRIF AG
VISIATIV
DIOT SIACI AMETHYSTE
ARCHER
SWISS GRC
DELTA RM
SCHLEUPEN
BLACKROCK
(EFRONT)
SMART GLOBAL GOVERNANCE
POCKETRESULT
RISKONNECT
CRISAM GRC
ARENGI
IBM
CORPORATER
QUALIDADD
ACUREDGE
NOVASECURRMIS PANORAMA 2026
31
Please use arrows to easily navigate
Quality Quadrant
The following RMIS vendors’ maps are built using solely vendors‘ self assessments without any input or analysis
from AMRAE and EY. They are organized by functional module showing only vendors covering this area.
For clarity and transparency, only 20 vendors are displayed on each map using their abbreviated name. These 20 vendors are
selected based on a weighted average score across the modules, where functional modules count for two-thirds and technical
modules for one-third of the total score.
A complete list of all vendors including functional and technical details is available in the vendor profile section.
Functional coverage
Technical coverage
Analysis based on the 2025-2026 respondents panel
100%
100%
75%
75%
Acuredge
Oxial
BIZZDESIGN
ServiceNowArengi
Teammate
Qualitadd
ROK SOLUTION
EASYLIENCE
CORPORATER
NOVASECUR
IBM OPENPAGES
Values associatesVisiativ
Schleupen
Smart Global
Governance
CRISAM
POCKET RESULT
AMÉTHYSTE
Blackrock (Efront)RMIS PANORAMA 2026
32
Please use arrows to easily navigate
ESG Quadrant
The following RMIS vendors’ maps are built using solely vendors‘ self assessments without any input or analysis
from AMRAE and EY. They are organized by functional module showing only vendors covering this area.
For clarity and transparency, only 20 vendors are displayed on each map using their abbreviated name. These 20 vendors are
selected based on a weighted average score across the modules, where functional modules count for two-thirds and technical
modules for one-third of the total score.
A complete list of all vendors including functional and technical details is available in the vendor profile section.
Functional coverage
Technical coverage
Analysis based on the 2025-2026 respondents panel
100%
100%
50%
75%
DELTA RM
EMPOWERED SYSTEMS
WORKIVA
BIZZDESIGN
COAUDIT
ARENGI
SCHLEUPEN
NOVASECUR
SWISS GRC
SMART GLOBAL GOVERNANCE
VALUES ASSOCIATES
CRIF AG
RISKONNECT
CORPORATER
IBM
POCKETRESULT
OXIAL
SERVICENOW
ACUREDGE
CRISAM GRCRMIS PANORAMA 2026
33
Please use arrows to easily navigate
Third Party Risk Management Quadrant
The following RMIS vendors’ maps are built using solely vendors‘ self assessments without any input or analysis
from AMRAE and EY. They are organized by functional module showing only vendors covering this area.
For clarity and transparency, only 20 vendors are displayed on each map using their abbreviated name. These 20 vendors are
selected based on a weighted average score across the modules, where functional modules count for two-thirds and technical
modules for one-third of the total score.
A complete list of all vendors including functional and technical details is available in the vendor profile section.
Functional coverage
Technical coverage
Analysis based on the 2025-2026 respondents panel
100%
100%
75%
60%
Schleupen
Qualitadd
empowered
NOVASECUR
IBM Openpages
AcuredgE
BIZZDESIGN
ServiceNow
BIC GRC
CRISAMCORPORATER
OXIAL
POCKET RESULT
Smart Global Governance
SWISS GRC
Teammate
Challenge optimum
Onetrust
values associates
Blackrock (Efront)RMIS PANORAMA 2026
34
Please use arrows to easily navigate
BCP and Crisis Management Quadrant
The following RMIS vendors’ maps are built using solely vendors‘ self assessments without any input or analysis
from AMRAE and EY. They are organized by functional module showing only vendors covering this area.
For clarity and transparency, only 20 vendors are displayed on each map using their abbreviated name. These 20 vendors are
selected based on a weighted average score across the modules, where functional modules count for two-thirds and technical
modules for one-third of the total score.
A complete list of all vendors including functional and technical details is available in the vendor profile section.
Functional coverage
Technical coverage
Analysis based on the 2025-2026 respondents panel
100%
100%
75%
75%
NOVASECUR
IBM
Openpages
BIZZDESIGN
SWISS GRC values associates
Blackrock (Efront)
Acuredge
Archer Oxial
Schleupen
ServiceNow
Arengi
BIC GRC
Smart Global
Governance
RISKONNECT
Qualitadd
EASYLIENCE CRISAM
CORPORATER
POCKET RESULTRMIS PANORAMA 2026
35
Please use arrows to easily navigate
Cybersecurity Quadrant
The following RMIS vendors’ maps are built using solely vendors‘ self assessments without any input or analysis
from AMRAE and EY. They are organized by functional module showing only vendors covering this area.
For clarity and transparency, only 20 vendors are displayed on each map using their abbreviated name. These 20 vendors are
selected based on a weighted average score across the modules, where functional modules count for two-thirds and technical
modules for one-third of the total score.
A complete list of all vendors including functional and technical details is available in the vendor profile section.
Functional coverage
Technical coverage
Analysis based on the 2025-2026 respondents panel
100%
100%
75%
75%
Arengi
Empowered
EGERIE
Smart Global Governance
Riskonnect
NOVASECUR
IBM Openpages
SWISS GRC
values
associates
Blackrock (Efront)
Acuredge DELTA RM
Oxial
Servicenow
BIZZDESIGN
BIC GRC
Easylience
CRISAMCORPORATER
POCKET RESULTRMIS PANORAMA 2026
36
Please use arrows to easily navigate
Data Privacy Quadrant
The following RMIS vendors’ maps are built using solely vendors‘ self assessments without any input or analysis
from AMRAE and EY. They are organized by functional module showing only vendors covering this area.
For clarity and transparency, only 20 vendors are displayed on each map using their abbreviated name. These 20 vendors are
selected based on a weighted average score across the modules, where functional modules count for two-thirds and technical
modules for one-third of the total score.
A complete list of all vendors including functional and technical details is available in the vendor profile section.
Functional coverage
Technical coverage
Analysis based on the 2025-2026 respondents panel
100%
100%
85%
60%
ROK Solution
riskHive ERMInclus
Oxial
Acuredge
BIZZDESIGN
Smart Global Governance
Arengi
Schleupen
ServiceNow
NOVASECUR
IBM Openpages
SWISS GRC
values
associates
Blackrock
(Efront)
BIC GRC
COAUDIT
Qualitadd
CRISAM
CORPORATERRMIS PANORAMA 2026
37
Please use arrows to easily navigate
Analytics Quadrant
The following RMIS vendors’ maps are built using solely vendors‘ self assessments without any input or analysis
from AMRAE and EY. They are organized by functional module showing only vendors covering this area.
For clarity and transparency, only 20 vendors are displayed on each map using their abbreviated name. These 20 vendors are
selected based on a weighted average score across the modules, where functional modules count for two-thirds and technical
modules for one-third of the total score.
A complete list of all vendors including functional and technical details is available in the vendor profile section.
Functional coverage
Technical coverage
Analysis based on the 2025-2026 respondents panel
100%
100%
75%
75%
Workiva
Smart Global Governance
NOVASECUR
Riskonnect
Teammate
AmÉthyste
egerie
IBM Openpages
values associates
Qualitadd
ROK SOLUTION
DELTA RM
ARCHER
Oxial
Schleupen
ServiceNow
Pocket result
COAUDIT
CRISAM
CORPORATERRMIS PANORAMA 2026
38
Please use arrows to easily navigate
Artificial Intelligence Quadrant
The following RMIS vendors’ maps are built using solely vendors‘ self assessments without any input or analysis
from AMRAE and EY. They are organized by functional module showing only vendors covering this area.
For clarity and transparency, only 20 vendors are displayed on each map using their abbreviated name. These 20 vendors are
selected based on a weighted average score across the modules, where functional modules count for two-thirds and technical
modules for one-third of the total score.
A complete list of all vendors including functional and technical details is available in the vendor profile section.
Please note that this quadrant should be interpreted with caution: it reflects the level of coverage as assessed in the 2025 edition,
whereas the RMIS market has experienced significant progress in this area over the past year.
Functional coverage
Technical coverage
Analysis based on the 2025-2026 respondents panel
100%
100%
50%
70%
Arengi
ARCHER
RISKHIVE ERM
BIC GRC
Smart Global Governance
RISKONNECT
My Risk IO.
Qualitadd
ROK SOLUTION
EASYLIENCE CRISAM
CORPORATER
ServiceNow
OXIAL
OPTRO
NOVASECUR
IBM OPENPAGES
Pocket result
Prewave
InclusRMIS PANORAMA 2026
39
Please use arrows to easily navigate
The AI revolution and its relevance to Risk Management
Artificial Intelligence (AI) is reshaping the landscape of various industries, introducing revolutionary changes
that promise to redefine traditional practices. For risk managers, the rapid advancements in AI, particularly
in Generative AI (GenAI), present exciting opportunities to enhance risk management strategies. The question
now stands: Can risk management professionals effectively leverage these AI-driven advancements in their
daily operations?
The integration of AI into risk management tools is not merely a futuristic concept; it is already becoming
a reality. 90% of Risk Management Information Systems (RMIS) have either integrated or plan to integrate AI
functionalities into their products by 2025, marking a 20-point increase compared to 2024. This highlights
the growing recognition of AI’s potential impact on risk management practices.
Focused analysis: Embracing Artificial Intelligence
HAVE YOU ALREADY INTEGRATED GENERATIVE AI INTO YOUR RMIS SOLUTION?
Yes, currently usable by our clientsIn developmentPlanned (2025)
Considered (target 2026) Not planned
46%
25%
19%
8%
2%
Bertrand RUBIO
Associate Partner
EY Risk ConsultingRMIS PANORAMA 2026
40
Please use arrows to easily navigate
A unanimous consensus among RMIS providers is that GenAI will significantly impact their market. Almost
all of them predict a moderate to strong impact (98% vs 55% in 2024), with not a single RMIS provider
disregarding the potential impact of GenAI on their market.
HOW DO RMIS VENDORS ASSESS THE IMPACT THAT GENERATIVE AI
WILL HAVE ON THEIR COMPANY AND ON THE RMIS MARKET?
High Medium Limited No impact
67%
31%
2%
Enhancing qualitative analysis
AI’s incorporation into RMIS is predominantly aimed at enhancing qualitative analysis based on user-generated data. A staggering
95% of RMIS providers agree that this is one of the primary goals of leveraging AI in their systems. This focus on qualitative
insights together with content generation abilities mark a significant evolution from mere quantitative risk assessments. It hints at
a more nuanced, context-rich understanding of risk and prescriptive risk management that only cognitive technologies like AI can
offer.
WHAT WOULD BE THE OBJECTIVES OF GENERATIVE AI INTEGRATED (OR TO BE INTEGRATED) INTO YOUR RMIS?
0%
20%
40%
60%
80%
100% Very useful
Somewhat useful
Not useful
No opinion
Generate content
(example: suggest
an action plan to face
an incident)
Produce qualitative
analyzes based
on data produced
by users
Perform
data analytics
(example:
fraud detection)
Consolidate and
analyze external
information (example:
regulatory monitoring,
analysis of public
indices, etc.)
Tasks automation
for users (examples:
proposing automatic
attachment of an incident
to the risk register)
HOW DO RISK MANAGERS EVALUATE THE IMPACT THAT AI
WILL HAVE ON RISK FUNCTIONS ACTIVITIES?
High Medium Limited No impact
47%
47%
6%RMIS PANORAMA 2026
41
Please use arrows to easily navigate
0%
20%
40%
60%
80%
100%
Very useful
Somewhat useful
Not useful
No opinion
Risk mapping
Risk Management on Prevention
Audit
Inter nal C ontrol
A naly tic s
Ac tion Plan
T hird Par t y Risk Management
Incidents Management
C ompliance
C yber securit y
E SG
Qualit y
Gover nance
BCP and Crisis Management
Data privac y
Insur ance
Key Areas Benefiting from AI
As expected, AI holds an exceptional potential to enhance multiple modules within RMIS, including Risk Mapping, Risk
Management on Prevention, Audit, Internal Control and Analytics.
These areas are characterized by some intricate complexities that might be difficult to address through traditional computing
methods or manual supervision alone. AI offers a new and unique perspective, empowering risk managers to navigate these
challenges more effectively.
ON WHICH MODULES DO YOU THINK THAT GENERATIVE AI IS THE MOST USEFUL?
Which use cases?
Numerous use cases can be envisioned, and the majority of Risk Managers (75% to 85%) express their interest in those
presented in the graph below. Flagging anomalies and classifying data is an interesting aspect to gain efficiency, but respondents
also expect to improve their risk management thanks to AI though better risk prevention, prediction, quantification and detection
in real time.
0%
20%
40%
60%
80%
100%
Very useful
Somewhat useful
Not useful
No opinion
To better
prevent/
detect
risks
(real time
monitoring)
To flag
anomalies,
automate data
classification
in any aspect
of RMIS data
To perform
qualitative
analyses on
a large
amount
of data
To better
analyze
risks through
prediction
or better risk
quantification
To identify
new/ emerging
risks by
analyzing
a variety
of internal
and external
data sources
To support
fraud detection
or compliance
violations
To draft
action
plans to
mitigate
risks,
incidents
or issues
To identify
potentially
relevant
changes
in laws, and
regulations
To provide
on-line
guidance
to end-users
through
the use of
chatbots in
the application
KEY EXPECTATIONS ON USING ARTIFICIAL INTELLIGENCE IN AN RMIS RMIS PANORAMA 2026
42
Please use arrows to easily navigate
Responsible AI: navigating the AI-assisted landscape with confidence
RMIS publishers express strong confidence in their ability to manage the risks associated with AI, ensuring that
the technology remains transparent, accountable, explainable, and private. Notably, 64% of publishers report that
they are implementing responsible AI measures and are either actively working to enhance these measures
or are at the forefront of responsible AI practices, employing state-of-the-art solutions along with continuous
monitoring and improvement processes.
However, despite this confidence, it is essential for RMIS providers to ensure that their risk management
strategies are robust enough to effectively mitigate the risks associated with AI usage. Currently, more than half of
publishers find themselves at an initial or intermediate stage in embedding responsible AI into their RMIS. This
indicates that while progress is being made, full integration remains a work in progress across the market.
Risk managers must remain informed and agile, embracing AI as a component of their strategic toolkit while
managing the underlying risks.
The Dawn of AI-Augmented Risk Management
The integration of AI into risk management tools seems to represent a critical evolution in the field. For risk
managers, adapting to and adopting these technologies is becoming increasingly vital. As RMIS systems continue
to evolve, the role of AI will undoubtedly expand, potentially transforming risk management practices in
unprecedented ways.
But beyond providing AI-driven tools to the risk managers, are RMIS publishers confident in their own risk
management strategies to mitigate their risks following the use of AI? Yes for a large majority (95%), but it might
not reflect the overall maturity of corporates for which implementing an RMIS is not the main answer.
Risk managers, therefore, need to stay informed and agile, embracing AI as a component of their strategic toolkit,
and managing underlying risks. The potential for AI to enhance accuracy, efficiency, and predictability in risk
management is immense, even if practical use cases still often remain theoretical and remain to be demonstrated. RMIS PANORAMA 2026
43
Please use arrows to easily navigate
Selecting the right RMIS for your organization can be a complex and challenging journey.
From the initial requirements gathering to the change management initiatives following implementation,
there are numerous factors to consider.
To help Risk Managers in their RMIS process (selection and implementation), we have summarized the key
activities for each phase in the infographic below. This includes the main activities to be carried out with the
level of involvement required from each stakeholder, such as IT, the Risk Management team, end users,
and software vendors, along with practical advice to guide you through the process.
Business
case
Tool
implementation
• Clarify the vision, prepare communication kits
•Align stakeholders with the target
•Nominate champions
•
• Current organization diagnosis
• Scoping, target operating model
•Budget estimate, support investment justification
• High level business requirements
•Roadmap definition
•Market vendors identifications
Tool selection
(RFI / RFP)
•Request For Proposal design, incl. business requirements
• Demonstration scripts design
• Analysis grid design
• Vendors answers analysis
•Vendors Proof of Concept (POC) review
• Negotiation & contractual aspects
Change
Management
• Business& ITdesign workshops
•Testing: test cases design & rollout
• Data migration
• Definedeployment strategy
• Project management
IT
Users
Vendor
Managem ent
Phases
Think big: anticipate long term
needs, involve key stakeholders of
the 3 lines of defense
Definepriorities by areas
Highlight ROI & qualitative benefits
InvolveITdepartment & purchasing
as early as possible
Prepare real life use case scenarios
Ask competitor tofit a common
frame to simplify the analysis
Use available resources (Panorama,
Quadrant, …) to pre-select vendors
Startfrom business needs
Limit specific developments, stick
to the tool standard as possible
Involve “key users” for business
design & testing
Deployment strategy: Get quick-
wins first
Be “business centric” (avoid a
technical manual for business users)
Adapttraining materials to target
population
Monitor adoption
Get sponsors & share testimonials
Tips
IT
Users
Vendor
Managem ent
IT
Users
Vendor
Managem ent
IT
Users
Vendor
Managem ent
Design & deploy training kits
• Embed new behaviour in the culture & processes
Expert insight: Selecting and implementing a RMIS
Bertrand RUBIO
Associate Partner
EY Risk ConsultingRMIS PANORAMA 2026
44
Please use arrows to easily navigate
We can identify the following main key success factors:
>Identify short-term needs but consider your long-term trajectory. Don’t limit
yourself to a silo approach but consider the opportunity to integrate multiple
domains (Risk, Insurance, Audit, Internal Control, ...). The tool will support you
for several years and could be an important vector to reinforce a coherent
and shared vision of Risk Management.
>Organizations should carefully consider the implications of a “Big Bang”
implementation strategy, where the RMIS is rolled out across multiple
modules or the entire organization simultaneously. While this approach
may offer immediate benefits, it can also introduce significant risks, such as
resistance to change and operational disruptions.
>The sponsor plays a key role in promoting the initiative and the ambition of
the project.
>The project team frequently includes a “group of future users” who, in
support of the core team, participate in certain key stages of the selection
process (review of the specifications, participation in presentations) and
implementation. Make sure that the team is available for the entire period!
>Provide RMIS candidates with demonstration scenarios in advance to
structure the sessions effectively. Consider organizing a “Proof of Concept”
(POC) to test the solutions over several days.
>While it’s important to adapt the RMIS to fit your methodology, be cautious
not to deviate too far from its standard features, as this can introduce risks
of instability and obsolescence.
>Finally, implementing a RMIS often necessitates a cultural shift within the
organization. Developing robust change management strategies, including
comprehensive training and ongoing support for users, can facilitate
smoother transitions and improve adoption rates. By prioritizing these
strategies, organizations can maximize the effectiveness of their RMIS and
achieve their risk management objectives.RMIS PANORAMA 2026
45
Please use arrows to easily navigate
Expert insight: Embedding ESG controls into your RMIS
Thierry MOREAU
Associate Partner
EY Risk Consulting
Regulatory Momentum: CSRD and Beyond
In 2026, ESG (Environmental, Social, and Governance) factors continue to shape the strategic agenda of
companies and their stakeholders. Despite a volatile political and economic environment, ESG remains a
central pillar of long-term value creation and risk mitigation. Regulatory developments, evolving investor
expectations, and increasing scrutiny from civil society continue to reinforce the need for robust ESG
practices across sectors.
Among these developments, the EU Corporate Sustainability Reporting Directive (CSRD) remains a pivotal
anchor. It has already entered its first application cycle for the earliest in-scope companies (for the 2024
financial year, published in 2025), and it continues to drive higher expectations for transparency and
auditability regarding ESG-related risks, opportunities, and impacts.
However, the implementation landscape has materially evolved through the EU “Omnibus” simplification
agenda. This package is explicitly designed to reduce compliance complexity and administrative burden,
while focusing requirements on the largest companies and limiting trickle-down reporting pressure on
smaller entities in the value chain.
In practice, Omnibus-driven changes narrow CSRD scope significantly and introduce safeguards to prevent
excessive information requests to smaller counterparties, supported by a voluntary reporting standard
based on EFRAG’s SME work.
For organizations that remain in scope (or that continue reporting due to stakeholder pressure, financing
requirements, or group expectations), the priority is shifting from “interpreting what to report” to
“operationalizing how to report reliably.” This means building structured ESG risk identification and
assessment processes, establishing traceable data collection mechanisms, and strengthening internal
control over sustainability disclosures to meet assurance and auditability expectations.
In parallel, the regulatory environment is also moving toward simplified and revised ESRS—with the
explicit objective of reducing reporting burden and improving usability, while maintaining decision-useful
disclosures. This reinforces the need for tools and processes that can adapt to evolving standards without
constant rework of the operating model.
In this context, GRC/RMIS platforms must evolve from static compliance repositories into dynamic decision-
support systems: solutions that can accommodate proportional reporting approaches (in-scope vs. value-
chain “capped” requests), maintain traceability from risk assessment to controls and evidence, and support
governance decision-making under evolving regulatory interpretations.RMIS PANORAMA 2026
46
Please use arrows to easily navigate
Practical Recommendations for Strengthening ESG GRC Frameworks
To meet these increasing demands, companies should focus on four priority areas, leveraging digital
GRC/RMIS tools — increasingly powered by artificial intelligence — to support ESG risk management and
internal control efforts.
>Enhance ESG Risk Identification and Mapping
ESG risks should be fully embedded in the broader Enterprise Risk Management (ERM) framework.
Advanced platforms can support dynamic mapping of ESG risk factors by integrating external datasets
(e.g., climate models, supply chain vulnerabilities, geopolitical indices) with internal information (e.g.,
operational data, incidents, audit findings). AI-enabled capabilities can help identify emerging risks
and detect weak signals by scanning large volumes of structured and unstructured data. Double
materiality should guide risk prioritization, ensuring alignment with both financial exposure and
societal/environmental impacts.
Risk mapping should also support multi-tier data sourcing, distinguishing what must be collected for
CSRD-grade reporting versus what is reasonably requested across the value chain under the “cap”
approach and voluntary standards.
>Develop Dedicated ESG Internal Control Systems
Traditional control environments are often ill-equipped to address the complexity and specificity of ESG
risks and disclosures. A growing number of organizations are implementing dedicated ESG control
libraries featuring tailored indicators, preventive and detective controls, and escalation protocols
(e.g., Scope 3 emissions, supply-chain labor practices, DEI initiatives). AI-enabled tools can support
automation of control testing, anomaly detection, and identification of control weaknesses, reinforcing
scalability and consistency.
In 2026, evidence management and audit trail capabilities should be treated as first‑class
requirements, ensuring that each ESG disclosure or key metric is clearly linked to defined ownership,
control activities, supporting documentation, and a documented change history in order to meet
auditability expectations.
>Leverage Digital GRC/RMIS Tools with ESG Modules
Leading vendors increasingly offer ESG-specific modules supporting core processes such as risk
assessment, internal control, compliance monitoring, and sustainability reporting. These platforms
often incorporate AI features for predictive analytics, automated data classification, anomaly detection,
and natural language processing of regulatory texts. The market continues to move toward modular,
cloud-native, and interoperable solutions capable of integrating with IT systems and data platforms,
enabling more efficient reporting and scenario-driven analysis.
ESG modules should be designed with adaptability in mind, so that changes in ESRS requirements and
Omnibus‑driven proportionality rules can be addressed through configuration rather than requiring
major system redesign or reimplementation.
>Foster Cross-Functional Collaboration and Governance
ESG risk ownership is inherently transversal, involving sustainability, compliance, finance, operations,
HR, legal, and procurement teams. GRC/RMIS tools should facilitate collaboration by clarifying roles
and responsibilities, automating workflows, and enabling centralized tracking of actions, decisions, and
remediation progress. AI can further support coordination by prioritizing tasks, flagging inconsistencies,
and generating alerts for time-sensitive issues. At governance level, audit and risk committees require
high-impact dashboards and concise executive summaries to exercise oversight effectively.RMIS PANORAMA 2026
47
Please use arrows to easily navigate
In 2025, the integration of ESG (Environmental, Social, and Governance) considerations into Risk Management
Information Systems (RMIS) is not just a trend but a necessity for forward-thinking organizations. As a
risk manager, involved in this annual release of the RMIS Panorama, I see several key areas where ESG
integration can push RMIS to the next level:
Holistic Risk Management
Incorporating ESG factors into RMIS allows for a more comprehensive understanding of risk. This approach
goes beyond traditional financial and operational risks to include environmental, social, and governance risks.
By doing so, organizations can identify interconnected risks and opportunities that impact their long-term
sustainability and resilience.
Enhanced decision-making
ESG integration enables risk managers to make more informed and strategic decisions. Leveraging ESG
data and analytics helps identify emerging risks, capitalize on opportunities for sustainable growth, and
align strategies with stakeholder expectations. This broader perspective ensures that decisions are not only
financially sound but also socially responsible and environmentally sustainable.
Stakeholder engagement
RMIS that incorporate ESG considerations facilitate better engagement with stakeholders, including investors,
brokers, insurers, customers, employees, and communities. Moreover as part of the double materiality
analysis process, various stakeholders are usually involved in a dialogue with the company. Transparent
disclosure of risk management practices and ESG performance metrics builds trust and credibility, enhancing
reputation and brand value.
Link between ESG and Insurance
The integration of ESG considerations into RMIS also has significant implications for the insurance industry
and for companies’ insurance programs set-up and maintenance. Insurers are increasingly factoring ESG
criteria into their underwriting processes, risk assessments, and claims management. Companies with strong
ESG practices may benefit from more favorable insurance terms, such as lower premiums and broader
coverage, while those with poor ESG performance might face higher premiums or even denial of coverage.
This shift underscores the importance of ESG integration in RMIS, as it not only enhances risk management
but also aligns with the evolving expectations of insurers and other stakeholders. By proactively addressing
ESG risks, organizations can improve or maintain their insurability and demonstrate their commitment to
sustainable and responsible business practices.
Expert insight: Elevating RMIS
with ESG integration
François BEAUME
AMRAE President
SVP Risks and Insurance, SoneparRMIS PANORAMA 2026
48
Please use arrows to easily navigate
Resilience and adaptability
ESG integration fosters organizational resilience by helping anticipate and adapt to evolving environmental,
social, and regulatory trends. Proactively managing ESG risks minimizes potential disruptions, mitigates
liabilities, and seizes opportunities for innovation and differentiation in the market.
Regulatory compliance
As ESG regulations evolve globally, RMIS that integrate ESG considerations help organizations stay ahead of
compliance requirements and demonstrate adherence to sustainability standards. Systematically tracking
and reporting ESG performance metrics streamlines compliance efforts and mitigates the risk of non-
compliance penalties.
Technological integration
The integration of ESG requirements into RMIS roadmaps will drive the adoption of advanced technologies
such as artificial intelligence (AI), machine learning (ML), and big data analytics. AI and ML algorithms
can analyze large volumes of risk and ESG data, identify patterns, and predict potential risk patterns
more accurately. These technologies enhance the ability to proactively manage ESG-related risks and
opportunities, leading to more informed decision-making and better overall performance.
Practical Recommendations for Strengthening ESG GRC Frameworks
To meet increasing demands and cope with current uncertainty, companies should focus on four priority
areas, leveraging RMIS — increasingly powered by artificial intelligence — to support their ESG risk
management efforts:
1. Enhance ESG risk identification and mapping: Embed ESG risks fully into the broader Enterprise Risk
Management (ERM) framework. Advanced RMIS can support more dynamic mapping of ESG risk factors by
integrating external datasets with internal information. AI algorithms can help identify emerging risks and
detect weak signals by scanning large volumes of structured and unstructured data in real-time.
2. Develop dedicated ESG Internal Control Systems (ICS): Implement dedicated ESG control libraries with
tailored indicators, preventive and detective controls, and escalation protocols. AI-enabled RMIS can help
automate control testing, identify anomalies, and propose corrective actions.
3. Leverage RMIS with ESG modules: Utilize ESG-specific modules offered by leading RMIS vendors to
support key processes such as risk assessment, internal control, compliance monitoring, and sustainability
reporting. These platforms increasingly incorporate AI features for predictive analytics, automated data
classification, anomaly detection, and natural language processing of regulatory texts.
4. Leverage RMIS ESG modules into Risk Management Plan: Utilize ESG-specific modules offered by leading
RMIS vendors to support key processes such as risk assessment, internal control, compliance monitoring,
sustainability reporting, prevention plan definition and insurance marketing processes as well as insurer’s
selection.
5. Foster cross-functional collaboration and governance: Facilitate collaboration by clearly defining roles
and responsibilities, automating workflows, and enabling centralized tracking of actions and decisions. AI
can enhance coordination by prioritizing tasks, flagging inconsistencies, and generating alerts for time-
sensitive issues.RMIS PANORAMA 2026
49
Please use arrows to easily navigate
Way Forward
The integration of ESG considerations into risk management practices will necessitate a shift in how risk
managers consider and utilize RMIS, including AI.
By embracing ESG principles as part of risk management and leveraging advanced technologies,
organizations can create value, foster resilience, and drive sustainable growth in an increasingly dynamic
and interconnected world.
As we used to say at AMRAE, “Risk Management is the Foundation of a Responsible Enterprise.”
HAVE RISK MANAGERS INTEGRATED AN ESG APPROACH INTO THEIR RMIS?
Yes
In progress
No
Allow
to run
internal
audit
campaigns
on ESG
topics
Provide
a CSRD-
related ESG
risk
mapping
CSRD
internal
control
monitoring
Data
collection
on significant
ESG topics
Support
the
sustainability
reporting
Measuring
compliance
with CSRD
regulation
Monitor
the
company
ESG
performance
Follow up
on action plans,
trajectory,
roadmaps,
on ESG
topics
0
20
40
60
80
100
WHAT WOULD BE RISK MANAGERS’ KEY EXPECTATIONS OF USING ESG MODULE IN A RMIS?
Very useful
Somewhat useful
Not useful
Allow
to run
internal
audit
campaigns
on ESG
topics
Provide
a CSRD-
related ESG
risk
mapping
CSRD
internal
control
monitoring
Data
collection
on significant
ESG topics
Support
the
sustainability
reporting
Measuring
compliance
with CSRD
regulation
Monitor
the
company
ESG
performance
Follow up
on action plans,
trajectory,
roadmaps,
on ESG
topics
0
20
40
60
80
100RMIS PANORAMA 2026
50
Please use arrows to easily navigate
Expert insight: Insurer–Broker perspectives:
Transforming RMIS into a strategic enabler
Franck AURÉ
Group Insurance Director
OPmobility
Long perceived as technical tools serving only Risk Managers, Risk Management Information Systems
(RMIS / SIGR) are now undergoing a major shift. At the crossroads of governance, performance, and
digital transformation, they are increasingly becoming structuring platforms for risk steering. The
combined perspectives of an insurer and a broker highlight a nuanced reality: while the potential is widely
acknowledged, the conditions for value creation are still taking shape.
An Essential Foundation… Still Seeking Broader Use
The diagnosis is now shared: SIGR is no longer optional but a prerequisite for structuring risk management
in complex environments.
As the insurer puts it, “Having a SIGR is a must in today’s world.”
That said, its use often remains confined to specialist teams: “by nature, information systems
tend to have relatively limited use within the Risk Management community.”
The real challenge therefore lies in expanding usage. A tool only creates value if it is
embedded in business practices. Beyond the technology itself, it is its activation that
determines effectiveness:
“A SIGR is not adopted, it is brought to life. Without business usage and proper support, it
remains an empty tool.”
Behind this observation lies a key reality: the challenge is less technological than cultural. Adoption depends
on change management and integration into existing processes. Opening the system to other functions—such
as finance, audit, and compliance—emerges as a key lever to turn the SIGR into a truly cross functional tool.
AI: From Automated Monitoring to Augmented Decision Making
Artificial intelligence marks a decisive step in the evolution of SIGRs. Beyond productivity gains, it profoundly
transforms risk management practices.
From the insurer’s perspective, initial benefits are mainly operational, with the automation of still largely
manual tasks:
“AI should strengthen and automate risk management monitoring: alerts, reminders,
inconsistency detection.”
But the potential quickly goes beyond simple monitoring. By structuring and analysing data,
the SIGR becomes a tool for risk prioritisation:RMIS PANORAMA 2026
51
Please use arrows to easily navigate
“An AI enhanced SIGR could produce weekly reports with priority level 1 risks.”
The system thus evolves from a data collection tool into a genuine steering and action support
instrument.
The broker extends this evolution to a more strategic dimension, focusing on risk valorisation:
“AI can turn the SIGR into a decision support tool, particularly to structure and defend an insurance
programme.”
At the intersection of these approaches, a new generation of SIGRs is emerging—systems capable not only of tracking
risks, but also of analysing them, prioritising them, and informing decisions.
Data: Strategic Asset… or Blind Spot?
Behind the promises of SIGRs, one reality stands out: without data, there is no risk steering. AI, weak signals, and
advanced analytics all rely first and foremost on the ability to structure reliable information over time.
As the insurer notes, “this requires a long data history with causes and consequences, and the ability to
capture data consistently.”
Yet this effort is often underestimated. Building an exploitable database requires investment, rigorous
processes, and sustained team engagement, all within a context where confidentiality is a major issue:
“It is heavy work, with a strong confidentiality challenge.”
To this is added a structural limitation: a risk view that is still too siloed. The broker offers a broader
perspective:
“The value lies in capturing weak signals from SIGRs and putting them into perspective across multiple
clients and sectors.”
By cross referencing data and experience, brokers contribute to a more global reading of risks—now largely systemic.
Data thus becomes not only an internal asset, but also a lever for collective intelligence.
Transparency: How Far Should It Go?
Sharing SIGR data is increasingly seen as a structuring lever in the insurer–insured relationship. A better understanding
of risk allows for more accurate analysis and more finely calibrated insurance conditions:
“A better known risk leads to better calibrated terms and conditions.” (Insurer)
In practice, this transparency most often translates into improved policy terms, strengthening trust
between the parties.
However, this balance remains fragile. Sharing sensitive data also carries risks for companies, particularly
in cases of partial or biased interpretation:RMIS PANORAMA 2026
52
Please use arrows to easily navigate
“Sharing certain data can itself be a source of risk for the company.”
The challenge therefore lies not merely in access to data, but in the ability to control, explain,
and contextualise it:
“Raw data is not enough; it must be contextualised, otherwise it can work against the insured.”
(Broker)
The SIGR of Tomorrow: A Platform… If It Scales
SIGRs are set to become more open, interconnected, and responsive:
“The future lies in gateways (APIs) and automatic alerts flowing in both directions.” (Insurer)
This would enable real time use cases and better information circulation. The broker extends
this vision further:
“Tomorrow’s SIGR will be a collaborative platform bringing together insureds, insurers, and
partners.”
But this evolution raises a critical question: are organisations ready? Beyond technology, what
is at stake is a transformation of practices. The real test will be among SMEs and mid sized
companies. Adoption will depend on tools that are both modular and simple:
“We need ‘drawer based’ tools, adapted to different levels of risk management maturity.”
(Insurer)
“The SIGR must be as intuitive as a banking app; without simplicity and support, there will be
no large scale adoption.” (Broker)
Ultimately, the question may be less about the tool itself than about its place within
the organisation. Will the SIGR remain just another system, or will it become a genuine
management reflex?
The insurer draws a clear line:
“It must not be only a data tool, but an assistance tool for risk management.”
We warmly thank Denis Stasinski (Zurich) and Paul-Émile Leroy (Union Industrielle)
for their contribution to this cross-perspective..RMIS PANORAMA 2026
53
Please use arrows to easily navigate
Risk Managers’ testimonialsRMIS PANORAMA 2026
54
Please use arrows to easily navigate
Sonepar has launched a gradual process of strengthening and
modernizing its Internal Control, Internal Audit, and Risk Management
system.
As part of this project, the group wanted to deploy a new, more user-
friendly RMIS that would better align and integrate the risk management,
internal control, and internal audit functions.
The implemented solution enables to easily share the Group risk and
control repository and thus harmonizes practices across the various
countries in which the Group operates.
It simplifies the administration of risk assessment and internal control
self-assessment campaigns, allowing more effort to be devoted to the
analysis and challenge of the results obtained.
The RMIS tool manages several risk assessment methods and heat maps:
ERM risks, Sapin 2 risks, and CSRD risks in double materiality.
The tool also enables to quarterly collect and treat fraud cases and to
perform controls outside of campaigns (“continuous monitoring”).
Finally, the solutions provide a cross-functional approach to create and
follow up action plans on risks, controls, audit recommendations and
fraud cases, optimizing the improvement process for the management.
Sonepar chose to interface the selected solution with PowerBI to access a
broader range of analyses and reporting.
The implementation of the solution has met both the objectives of each
department and the need for transversality and integration of the Group’s
Insurance functions.
Grégoire DUTERTRE
Sonepar
Group Risk ManagerRMIS PANORAMA 2026
55
Please use arrows to easily navigate
In the run-up to the call for tenders for the selection of our future RMIS,
I was looking for software publishers capable of presenting a complete
solution. The AMRAE overview enabled me to select publishers that I had
not initially identified.
The Group’s major challenge was the unreliability of the data. This was
the case both in the insurance part (collection of values, monitoring of
insurance budgets) and for our Liability claims. The Group’s complex
organisation and the high degree of autonomy of the local teams made
the data consolidation impossible. It was important to have a common
tool, enabling us to secure our declarations of values to the insurer, to
have better visibility on the costs of our insurance and our claims costs,
but also to standardize some practices.
What impressed me the most about the set-up was the connection made
with our internal systems to retrieve all the information related to our
products involved in claims, based on a basic reference code. This was a
major technical challenge because the internal database was very dense,
and the retrieval of all the information had to be instantaneous. The
solution proposed by the RMIS proved to be very effective.
Initially, we mainly used our RMIS for collecting values to be insured,
calculating premiums, and managing our Liability claims. Its use was
then extended to compliance risk mapping.
Today, the teams that use the RMIS are quite diverse, each finding its use
in different modules and functionalities.
Our staff have fully embraced the tool. We gave it an internal name,
created a logo, and it has become the daily working tool of the
departments in charge of claims management. We are very autonomous
in the configuration changes to be made to the tool according to our
needs, thanks to a member of staff who has trained extensively in her
role as administrator.
One of our directors, who was initially quite skeptical about the project,
recently gave me some interesting feedback: beyond the ‘Data’ aspect,
the tool has brought synergy between the different teams, and a pride
of belonging to the ‘claims’ community that cuts across our different
divisions.
Carmen GAUTHIER
Groupe Atlantic
Insurance ManagerRMIS PANORAMA 2026
56
Please use arrows to easily navigate
A recent merger has resulted in significant changes to the assets as well as
the organization of the company. Many new interactions have been created and
needed to be properly mapped and listed. It became crucial to have reliable data
and consistent reporting for our internal risk management committee and to
provide our insurance partners with an accurate presentation.
Given the complexity of the newly formed Group and its diverse background, it was
essential to implement a single RMIS tool that could integrate the entire Group.
With this goal in mind, the Risk Management Function chose to investigate
alternative solutions that could effectively address the new Group’s strategy in
risk assessment and insurance placement.
The market provided various options, but our main criteria were:
- It needed to have a well-organized structure while also being user-friendly.
- It had to be tailored to the specific insurance needs of Stellantis while also
being standardized for all users.
- It had to ensure data protection and allow us to have ownership of the data.
- It had to generate high-quality reports that could be shared with our stakeholders.
We decided to begin the project by addressing our initial need: the Values
Collection. We are now nearing completion of the Insurance Portfolio database
and will soon focus on Claims management. The decision to divide the project
into dedicated modules allowed us to deploy the tool in a pyramid-like structure:
a solid foundation to build upon and grow towards the top.
It was a challenging team effort, but the results have made all the hard work
worthwhile. We now have a single RMIS tool that is used by all entities globally.
This tool allows us to track and adapt to the ongoing changes within our Group. It
serves as a reliable repository for all our data, increasing their value in the market.
It is evident that our goal is to continue to enhance and leverage the numerous
features offered by our RMIS system, which is now a promising newborn with
great potential.
Benoist CORDELIER
Stellantis
Global Corporate Insurance and Captives DirectorRMIS PANORAMA 2026
57
Please use arrows to easily navigate
Around 112,000 employees contribute to the success of BASF Group’s
worldwide. Our global operations are clustered in six segments:
Chemicals, Materials, Industrial Solutions, Surface Technologies, Nutrition
& Care, as well as Agricultural Solutions and represent the businesses
BASF is conducting. All 12 Operating Divisions of these segments, along
with Service Units, Regions, and Corporate Center Units, report their risks
to the central risk management responsible team at Corporate Finance.
Our risk reporting process is conducted monthly as part of our financial
reporting, and more intensively on an bi-annual basis, where we prepare
a comprehensive risk management report covering each individual risk
at BASF. Additionally, we report ad hoc risks to our management between
the regular reporting cycles.
Two years ago, we’ve introduced the new risk management software to
meet enhanced risk management requirements arising from both our
increased internal needs and the new German annual audit standard for
risk management. This software helps us manage complexity by creating
a single point of truth. Moreover, we have significantly improved the user-
friendliness of the interface, streamlined the risk assessment process,
and increased efficiency through the full automation of reports for both
end users and the corporate risk management team.
Worldwide, more than 100 BASF colleagues across several divisions are
currently using the new risk management software and we are currently
working on a further rollout within BASF.
Claudia TILLINGER
BASF
Group Reporting & Performance ManagementRMIS PANORAMA 2026
58
Please use arrows to easily navigate
A Dynamic Approach to Risk Management: A Dual Synergy Between
People and Business
The Group’s objective is to adopt a comprehensive and dynamic approach
to risk management. To achieve this, we have chosen to implement
a Risk Management Information System (RMIS) that consolidates all
risk-related business lines within a single tool. Our aim is to create
operational synergies, optimize processes, and enhance user experience
by interconnecting risk management, audit, and control functions.
The concept of transversality involves breaking down organizational silos
by encouraging collaboration and coordination to achieve a common goal:
better risk management to support informed decision-making.
To this end, data interoperability efforts are being carried out across the
various business functions. Structuring the data is essential to ensure
that it can be shared, combined, and used consistently. Aligning the
reference frameworks of each business line is a crucial step in building
a transversal RMIS. It is therefore essential that a common language is
used to enable communication and data exchange.
Beyond data interoperability, one of the key features of a transversal
RMIS is discerning the different features that are specific to each team
and those that are shared across different modules. For example, each
team manages action plans, while only the audit team creates audit
missions. For team-specific features, each business line defines its needs
according to its own methodology. Shared features, on the other hand,
require dedicated workshops to build a common approach. Identifying
and creating links between the various modules requires close attention
from all business teams and the software provider.
What makes this approach unique is its ability to align the specific needs
of each business function with the collective and overarching goal of
effective risk management.
Alexia GUELL
Savencia Group
Risk mapping and Business Continuity Plan (BCP) managerRMIS PANORAMA 2026
59
Please use arrows to easily navigate
60
In 2023, we launched a request for proposals to replace our GRC system, with
clearly defined objectives : to acquire a simpler, truly ergonomic tool capable of
fully leveraging native functionalities. We were looking for support teams with
strong responsiveness and a client‑oriented, solution‑driven mindset. Exchanges
needed to be facilitated through the use of the French language, and hosting our
data in a sovereign French environment was also a highly valued requirement.
Another key need involved the ability to industrialize information collection : diverse
questionnaires, prioritization matrices, action plans, and directly usable summaries
requiring minimal reprocessing.
The deployed solution now enables us to cover all GRC use cases across the PHE
Group:
-Internal Control : self‑assessments, compliance testing, action plan monitoring
-Internal Audit : mission summaries, recommendations, action plans
-ERM : major risk mappings, prioritizations, consolidated oversight
- Compliance : maturity questionnaires for our most important regulatory compliance
areas (Commercial Law, Labor Law, Cybersecurity, GDPR, Anti‑corruption,
Whistleblowing system, Environment, etc.)
- Insurance/Provident schemes : questionnaires, action plan management, and
facilitation of broker/insurer interactions.
We have structured this environment under a common identity : PARRTS, which
stands for “Action Plans for the Reduction of Transversal and Strategic Risks. ” This
unified framework strengthens coherence across functions and improves clarity for
operational teams.
The simplicity of the dynamic and fluid interface facilitates adoption among users
with varying levels of maturity.
One of the major benefits lies in the transversal capability we have achieved: a single
shared framework, harmonized governance, and a consolidated view of risks and
action plans. The solution’s modularity now allows us to progressively expand usage
while maintaining cost control, both in RUN and in CHANGE.
Nicolas CHOUBRY
Parts Europe Holding
Director of Internal Audit and ComplianceRMIS PANORAMA 2026
60
Please use arrows to easily navigate
Deploying our RMIS across Enterprise Risk, Internal Control, and Internal
Audit has accelerated our maturity. Because the platform is highly intuitive, we
were able to shift our processes into the system immediately, without lengthy
deployment cycles, complex data migrations, or heavy training. Standard
workflows and templates now structure the ERM cycle end to end—interviews,
evidence collection, response tracking, and a complete audit trail—so the process
is consistent and repeatable across the group.
We now have around 900 users. Embedded questionnaires and integrated
scoring replaced e‑mail/Excel exchanges, reducing manual errors and
improving assessment consistency. We broadened participation to include more
members of top management, which sharpened our risk view and prioritization.
Interconnections between risks, controls, audits, and action plans enable
coverage mapping, faster access to relevant information, and clearer ownership
of mitigation. Strong permissions, data locking once responses are validated,
change history, and automated reminders have strengthened governance
and accountability. Administratively, the ability to adapt fields and workflows
directly—without systematically raising tickets—keeps us improving at pace, and
support has been responsive when needed.
Next, we are preparing to formalize KRI monitoring, leveraging the solution’s
standard models to accelerate design and deployment, with the objective of
further strengthening continuous oversight.
Thomas Lelu
Constellium
Senior Manager Internal AuditRMIS PANORAMA 2026
61
Please use arrows to easily navigate
62
Bpifrance : An Ambitious Transformation of Operational Risk Management
As a key player in financing the French economy, Bpifrance has undertaken a
major overhaul of its operational risk management framework. Following an
initial structuring phase triggered by a regulatory audit, the next challenge was to
industrialize practices by relying on a powerful, scalable, and user-centric solution.
The goal: to integrate incidents, risks, controls, and action plans into a single
ecosystem, while eliminating parallel tools such as Excel. User experience quickly
became a core criterion, as operational risk is managed daily by business teams —
the solution needed to be intuitive and easy to use.
Bpifrance carried out a comprehensive benchmark based on the RMIS landscape
and tested the most relevant solutions during a POC phase. This thorough approach
validated not only the functional coverage and data engine performance, but also
the strength of the partnership with the selected vendor. Adaptability, the ability to
challenge business needs, and a co-construction mindset proved decisive.
The project is now in its implementation phase, with a gradual rollout by module. Each
step is designed to ensure overall consistency and maximize operational impact.
This case study reflects Bpifrance’s ambition to combine technical excellence, project
agility, and user value — making risk management a true performance driver.
Julien BELHASSEN
Bpifrance
Director of Operational RisksRMIS PANORAMA 2026
62
Please use arrows to easily navigate
Managing risk is pivotal to an organization like Stork.
The implemented RMIS and its collaborative features enabled us to
improve our way of working and ensure a better management of the
risks we face as an organization.
Having the ability to co-develop with the RMIS team we were able to
improve the software tool for everyone’s benefit.
Dirk-Jan VOORN
STORK
Chief Risk OfficerRMIS PANORAMA 2026
63
Please use arrows to easily navigate
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) 64
GENERAL INFORMATION
Technical axes coverage
Reportings
Import
Export
Mobility
Documentat ion
Configurat ion Workflows
Organization
Security
Architecture
Access/Authentic ation
Functional modules coverage
Artificial Intelligence
Analytics
Data Privacy
Cybersec urity
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Ma nagem ent
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
VENDOR
LOGO
Jon SNOW
CISO
+33 (0)1 83 83 83 83
jonsnow@thew all.com
Particularities and di fferentiating factors
A RMIS v endor spec ialized in cert ain Risk cat egories
(professional Risk assessment).
Sectors of implemented projects .. ........................ B anking (5%), Insur ance (15%), Industry and s ervices (50%) , Public Sector (30%)
Average numb er of users per solution ............... F rom 101 to 200
RMIS average implementa tion duration .............. 1 months
Creation da te ..................................01/01/2010
Global workfor ce .............................................25
RMIS workforce ................................................19
RMIS implementation work force .................10
RMIS R&D workfor ce ......................................10
Solution(s) .................... ...................................... RMIS
Main focus ..........................................................Audit
Strengths a ccording to the vendor .. ............ Complete and modular professionnal Risk Management software.
Solution ar chitecture .......................................A single applica tion wit h several modules
Number of RMIS clie nts In Europe In Africa In Asia In North America In South America In Ocea nia
Total 1073 4 2 0 1
In the last 12 months 13 0 0 1 0 0
RMIS VENDOR
1
RMIS PANORAM A 2026
Please use arrows to easily navigate
RMIS VENDOR
Liberty Island
New York, NY 1004, United States
www.rmis-vendor.com
VENDOR SELF-ASSESSMENT (2025 update)
Detailed datasheets by vendor
The responses provided by each vendor are summarized on a datasheet presented as follows:
When the vendor did not answer some questions needed to fill in specific entries of its form, or when answers were not usable,
corresponding entries have been leaved as “-”.
* - Company sector: Industry
- Company turnover : €2 billion
- Company maturity in Risk Management: average
- RMIS modules: “Risk Mapping” and “Action Plan Management”
- RMIS users licenses: 150
Stated coverage
of functional
modules
Staffing, scope of
intervention
Kind and
dominant(s) of
the solution
Strengths
(according to the
vendor)
Number of
implementation
projects
Average number
of users per
solution
Stated coverage
of
technical axes
Presence:
Commercial or
implementation
services
Particularities,
differentiating
factors
Sectors of the
implemented
projects
Vendor logo
Vendor contact information Contact person within the vendor
RMIS average
implementation
duration for
the following
scenario*
64RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) 1-One Neuros
25, rue Tronchet
75008, Paris
France
www.1-one.fr
Yann LUCAS
CEO
+33 (0) 1 83 62 37 70
yann.lucas@1-one.fr
Particularities and differentiating factors
1-One is a software publisher specializing in the prevention of occupational risks,
health and safety at work, 1-One software has been in production for more than
10 years in the private and public sectors.
Sectors of implemented projects .......................... Banking (10 %), Insurance (20 %), Industry and Services (20 %), Public Sector (20 %),
Others (30 %)
Average number of users per solution ................ From 201 to 500
RMIS average implementation duration...............6 months
Creation date ...................................09/09/2006
Global workforce ..............................................14
RMIS workforce...................................................8
RMIS implementation workforce ...................4
RMIS R&D workforce .......................................10
Solution(s) ........................................................... Assessment and prevention of occupational risks, coactivity, management of work accidents,
preventive medicine.
Main focus ...........................................................Other
Strengths according to the vendor ............... 1-One is a software that offers a modular suite to address all aspects of occupational risk
prevention and occupational health.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 50 1 0 0 0 0
In the last 12 months 6 1 0 0 0 0
1-ONE
Area(s) of presence:
>Europe (West)
65RMIS PANORAMA 2026
Please use arrows to easily navigate
<<Nom 2>>
<<address>>
<<CP>>, <<ville>>
<<pays>>
<<site web>>
<<prénom>> <<nom>>
<<fonction>>
<<tel>> / <<tel mob>>
<<email>>
Particularities and differentiating factors
<<Particularités…>>
Creation date ................................<<date créa>>
Global workforce .................. <<effectif global>>
RMIS workforce.........................<<effectif sgir>>
RMIS implementation workforce .....<<effectif
intégr>>
RMIS R&D workforce ...........................<<R&D>>Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update)
CISS LTD
Hollenweg 19
4105, Biel-Benken
Switzerland
www.360inControl.com
Andreas VON GREBMER
CEO
+ 41 7 88 81 70 04
avg@ciss.ch
Particularities and differentiating factors
360inControl® - Your GRC Accelerator is your solution for organizing all topics
relating to governance, risk, compliance, information security and data protection
holistically and transparently. Complete adaptability, as it is content- and industry-
neutral. Multi-compliance capable. On just one platform.
Sectors of implemented projects .......................... Banking (10 %), Industry and Services (70 %), Public Sector (5 %), Others (15 %)
Average number of users per solution ................ From 501 to 1000
RMIS average implementation duration............... 3 to 6 months
Creation date ...................................05/12/2016
Global workforce ..............................................12
RMIS workforce.................................................12
RMIS implementation workforce ...................5
RMIS R&D workforce .........................................5
Solution(s) ...........................................................360inControl®
Main focus ...........................................................Internal Control - Compliance
Strengths according to the vendor ............... The Internal Control System 360inControl® offers comprehensive monitoring and control of
business operations, enhancing decision-making with real-time insights. It provides scalability,
customizable workflows, and advanced analytics, improving efficiency. The solution is available
as SaaS and Container version.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 50 2 4 1 0 0
In the last 12 months 5 0 1 0 0 0
360INCONTROL
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
66RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) Acuredge (by Devoteam)
6 rue d’Armaillé
75017, Paris
France
www.acuredge.com
Agnes POYARD BITRAN
Sales and Marketing Director
+33 (0) 6 59 91 35 10
agnes.poyard.bitran@iskera.com
Particularities and differentiating factors
Acuredge is an integrated and modular GRC platform for risk management, internal
control and compliance, audit, ESG report, insurance management and business
continuity. Used by leading companies across all sectors, it is easy to use, highly
flexible and secured, providing a wide range of report capabilities.
Sectors of implemented projects .......................... Banking (10 %), Insurance (25 %), Industry and Services (55 %), Public Sector (10 %)
Average number of users per solution ................ From 201 to 500
RMIS average implementation duration............... 3 to 4 months
Creation date ...................................01/01/2004
Global workforce .......................................11000
RMIS workforce.................................................60
RMIS implementation workforce ....................-
RMIS R&D workforce ..........................................-
Solution(s) ...........................................................Acuredge
Main focus ...........................................................Other
Strengths according to the vendor ............... Solution easy-to-use and intuitive, providing advanced features for multiple projects (ERM, Sapin
2, CSRD, DORA, ...). Flexible and configurable, integrated, offering multiple dashboards and the
possibility to analyze data in customer BI tool (ex: PowerBI). Solution open through web services
APIs, and secured with audit trail. Available in SaaS or On-Premise.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 100 20 0 0 0 0
In the last 12 months 15 5 0 0 0 0
ACUREDGE
Area(s) of presence:
>Africa
>Asia (South West)
>Europe
67RMIS PANORAMA 2026
Please use arrows to easily navigate
<<Nom 2>>
<<address>>
<<CP>>, <<ville>>
<<pays>>
<<site web>>
<<prénom>> <<nom>>
<<fonction>>
<<tel>> / <<tel mob>>
<<email>>
Particularities and differentiating factors
<<Particularités…>>
Creation date ................................<<date créa>>
Global workforce .................. <<effectif global>>
RMIS workforce.........................<<effectif sgir>>
RMIS implementation workforce .....<<effectif
intégr>>
RMIS R&D workforce ...........................<<R&D>>Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT
Area(s) of presence:
>Africa (North)
Alea360
254 Rue Vendôme
69003,, Lyon
France
www.alea360.com
Rudolph TEYSSOT
Founder & CEO
+33 (0) 4 28 29 55 92 / +33 (0) 6 82 63 39 74
rudolph.teyssot@alea360.com
Particularities and differentiating factors
Alea360 is a modular, multi‑site GRC system designed for the operational
management of risks. The platform makes it possible to structure controls, monitor
action plans, centralize indicators, and distribute communications, all within a single
environment that is easy for business users to configure and quick to deploy.
Sectors of implemented projects .......................... Public Sector (20 %), Others (80 %)
Average number of users per solution ................ From 201 to 500
RMIS average implementation duration...............-
Creation date ...................................01/04/2025
Global workforce ................................................5
RMIS workforce...................................................5
RMIS implementation workforce ...................3
RMIS R&D workforce .........................................1
Solution(s) ........................................................... Alea360 Controls (configuration and execution of compliance, handover, comparison and ad-hoc
controls); Alea360 Action Plans (automatic generation, assignment and monitoring of corrective
actions); Alea360 Dashboards (real-time indicators and multi-site consolidated reporting); Alea360
Communication (targeted communications and campaigns to operational teams); Alea360
Documentation (centralized storage of evidence, procedures and supporting documents).
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Alea360 combines operational simplicity with structured multisite management. It enables users
to configure controls and action plans without technical dependency. Modular and quick to
deploy, it supports sustainable risk management.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 4 0 0 0 0 0
In the last 12 months 4 0 0 0 0 0
ALEA360
68RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) AMETHYSTE
1 Chemin des Frémonts
14360, Trouville-sur-Mer
France
www.amethyste.fr
Gaillard AGNES
CEO
+33 (0) 1 40 82 91 59/+33 (0) 6 07 79 79 89
agnes.gaillard@amethyste.fr
Particularities and differentiating factors
Améthyste offers a platform to identify operational threats (equipment, cyber,
resources...) compromising the strategic objectives achievement with a 360° view
of risk exposure. The solution allows the measurement of the weight of threats, the
allocation of inspection/maintenance resources according to the level of risk and the
improvement of production performance.
Sectors of implemented projects .......................... Industry and Services (100 %)
Average number of users per solution ................ From 6 to 50
RMIS average implementation duration...............6 months
Creation date ...................................08/08/1990
Global workforce ................................................8
RMIS workforce...................................................8
RMIS implementation workforce ...................2
RMIS R&D workforce .........................................3
Solution(s) ........................................................... A single platform declined in 3 different brands: orKsoft® dedicated to fossil energies;
Vermarine® dedicated to renewable energies and marine offshore infrastructure; CyberQuartz®
dedicated to Cyber risk management.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Holistic risk approach considering an industrial plant as a set of interconnected physical and
immaterial assets. IoT connectivity to confort probabilistic methods with real-time process
conditions. Easy to deploy, on-prem or in the cloud, short learning curve, multilingual, multi-unit
measurement, secure access, and data protection policies.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 10 21 15 0 4 0
In the last 12 months 2 3 1 0 1 0
AMÉTHYSTE
Area(s) of presence:
>Africa (North, West)
>Asia (South East)
>Europe
69RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) ARCHER
Particularities and differentiating factors
More than just a module: RMIS AI is a comprehensive solution designed for risk
managers. Handles all aspects of insurable risk management: from complex claims
to policy & programme management, risk financing, and premium allocation.
Streamlined incident management: AI-powered intake accelerates time to notification.
All-in-one tool: Manages daily tasks and provides valuable insights for wider GRC
teams.
Sectors of implemented projects .......................... Banking (10 %), Insurance (5 %), Industry and Services (70 %), Public Sector (10 %),
Others (5 %)
Average number of users per solution ................ From 51 to 100
RMIS average implementation duration............... 3 to 6 months
Creation date ...................................01/01/2001
Global workforce ..........................................1000
RMIS workforce.................................................20
RMIS implementation workforce .................18
RMIS R&D workforce .......................................20
Solution(s) ...........................................................RMIS AI
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... With Archer RMIS AI, you can leverage AI-powered analytics to optimize your renewal workflows,
policy administration, claims and incidents. Archer RMIS AI offers an intuitive and cost-effective
solution for insurance policy and exposure data management, claims management, incident
management, and analytics. You can manage claims more effectively and efficiently, reduce and
track insurance costs, and eliminate opportunities for human error resulting in better data and
lower risk. Insurance is a key element of your risk management program but only if you can
increase efficiency and analysis capabilities, improve information sharing and avoid silos.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 5 0 0 9 0 1
In the last 12 months 5 0 0 9 0 1
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
Archer Technologies
Suite 2 First Floor
BS1 6FL, Bristol
United Kingdom
www.archerirm.com
Ellner ROSS
Director, RMIS AI - EMEA
+44 77 14 26 23 51
ross.ellner@archerirm.com
70RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) Arengi
15 rue la Fayette
75009, Paris
France
www.arengi.fr
Jean-Victor LACAVÉ BAIJARD
Operations Director
+33 (0) 7 60 68 08 06
jean.victor.lacave@arengi.fr
Particularities and differentiating factors
The ArengiBox RMIS/GRC solution was created by Arengi, the first French
consulting firm dedicated to governance and global risk management (ERM). Arengi
supports private and public organisations in the implementation of their Risk, Audit,
Compliance and Insurance systems.
Sectors of implemented projects .......................... Banking (10 %), Insurance (10 %), Industry and Services (50 %), Public Sector (25 %),
Others (5 %)
Average number of users per solution ................ From 201 to 500
RMIS average implementation duration...............2 months
Creation date ...................................06/01/2010
Global workforce ..............................................35
RMIS workforce.................................................30
RMIS implementation workforce .................10
RMIS R&D workforce .......................................12
Solution(s) ...........................................................ArengiBox
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... A RMIS/GRC solution designed by risk management experts, providing business answers and
designed as a support tool for the various players (ERM, Insurance, Audit & CI, etc.), in terms of
structuring and facilitating the collection and analysis of data.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 130 1 0 1 0 0
In the last 12 months 12 0 0 1 0 0
ARENGI
Area(s) of presence:
>Africa (North)
>America (North)
>Europe (West)
71RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) ARIS
Particularities and differentiating factors
ARIS offers a fully integrated solution for carrying out Risk Management and
Compliance procedures, process management, and enterprise architecture. The user
interface of the ARIS solution offers an intuitive and collaborative way of internal
control, compliance, operational and business front line a better collaboration,
working, in a web environment equipped with dashboards guaranteeing simplicity of
handling and decision-making.
Sectors of implemented projects .......................... Banking (60 %), Insurance (15 %), Industry and Services (15 %), Public Sector (10 %)
Average number of users per solution ................ From 51 to 100
RMIS average implementation duration...............3 months
Creation date ...................................23/01/1969
Global workforce ..........................................1000
RMIS workforce....................................................-
RMIS implementation workforce ....................-
RMIS R&D workforce ..........................................-
Solution(s) ...........................................................ARIS
Main focus ...........................................................Internal Control - Compliance
Strengths according to the vendor ............... ARIS integrates the GRC approach and its 3 lines of defense into a centralized and collaborative
repository, made up of company processes and all its critical Data. Easy to access, equipped with
operational dashboards, ARIS supports all Risk assessment, control and Audit activities.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 50 5 20 20 0 0
In the last 12 months 20 0 0 0 0 0
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
ARIS
Tour Alto/4, Place des Saisons
92400, Courbevoie La Défense
France
www.aris.com
Nicolas LINSART
Presales Manager – Solution Engineer
+33 (0) 6 45 65 32 05
nicolas.linsart@softwareag.com
72RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) GBTEC GRC
Franz-Klein-Gasse 5
1190, Wien
Austria
www.gbtec.com
Julia DRUSCHEL
Head of Marketing GRC
+43 0 1 36 70 87 60
julia.druschel@gbtec.com
Particularities and differentiating factors
We are motivated by the firm belief that digitalizing GRC processes in a sustainable
way drives the success of innovative organizations. Our efforts center on anchoring
these processes efficiently in everyday business activities. We achieve this through
our software BIC GRC, which offers clients a choice of flexible custom or standard
solutions.
Sectors of implemented projects .......................... Banking (15 %), Insurance (13 %), Industry and Services (69 %), Public Sector (3 %)
Average number of users per solution ................ From 501 to 1000
RMIS average implementation duration...............2 months
Creation date ...................................13/06/2002
Global workforce ..............................................75
RMIS workforce.................................................75
RMIS implementation workforce .................25
RMIS R&D workforce .......................................20
Solution(s) ........................................................... BIC GRC offers a scalable solution for Governance, Risk, and Compliance. BIC Enterprise
Risk manages risks efficiently, while BIC Internal Control detects and controls process risks.
BIC Corporate Sustainability addresses ESG risks, and BIC Information Security identifies
vulnerabilities. BIC Data Protection ensures GDPR compliance, and BIC Business Continuity sets
emergency plans. Lastly, BIC Internal Audit develops and reviews audit programs.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... BIC GRC helps clients achieve goals reliably, manage uncertainty, act with integrity, and improve
their GRC processes continually. It simplifies risk management, uncovers valuable opportunities,
and ensures long-term success for your company.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 218 0 0 0 0 0
In the last 12 months 45 0 0 0 0 0
BIC GRC
Area(s) of presence:
>America
>Asia (South West)
>Europe
>Oceania
73RMIS PANORAMA 2026
Please use arrows to easily navigate
<<Nom 2>>
<<address>>
<<CP>>, <<ville>>
<<pays>>
<<site web>>
<<prénom>> <<nom>>
<<fonction>>
<<tel>> / <<tel mob>>
<<email>>
Particularities and differentiating factors
<<Particularités…>>
Creation date ................................<<date créa>>
Global workforce .................. <<effectif global>>
RMIS workforce.........................<<effectif sgir>>
RMIS implementation workforce .....<<effectif
intégr>>
RMIS R&D workforce ...........................<<R&D>>Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update)
Bizzdesign
Capitool 15
7521 PL, Enschede
Netherlands
www.bizzdesign.com
Yannick RUDLOFF
Director of Product Management
+33 (0) 1 42 75 40 00
y.rudloff@bizzdesign.com
Particularities and differentiating factors
HOPEX GRC is an intuitive and modern solution built for GRC professionals. It unifies
risk management, compliance, business continuity, and internal audit into one
platform. With its unique ability to align cyber resilience with business strategies,
HOPEX GRC is the perfect solution to ensure compliance with DORA and NIS2
regulations.
Sectors of implemented projects .......................... Banking (49 %), Insurance (12 %), Industry and Services (18 %), Public Sector (5 %),
Others (16 %)
Average number of users per solution ................ From 51 to 100
RMIS average implementation duration...............6 months
Creation date ...................................01/01/1992
Global workforce ............................................580
RMIS workforce...............................................180
RMIS implementation workforce .................92
RMIS R&D workforce .......................................88
Solution(s) ........................................................... Bizzdesign Hopex GRC offers 4 modules: GRC: Streamline risk and compliance with tools
for risk & control assessment, mitigation, issue tracking, action plans, and reporting. BCM:
Ensure resilience with Business Impact Analysis, continuity planning, disaster recovery, and
testing. Internal Audit: Manage audits from planning to reporting. Cyber Resilience: Strengthen
operational resilience with cyber risk assessments and incident management.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Bizzdesign Hopex GRC is an intuitive, modern solution for GRC professionals, integrating risk,
compliance, continuity, and audit. Its seamless organizational mapping makes it the perfect tool for enhancing operational resilience.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 75 45 2 7 33 0
In the last 12 months 3 12 3 2 0 0
BIZZDESIGN
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
74RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) BlackRock/eFront
6-18 rue du 4 Septembre
75002, Paris
France
www.efront.com/erm
Martin de BALORRE
Product Director
+33 (0) 6 84 52 01 38
martin.debalorre@blackrock.com
Particularities and differentiating factors
Backed by BlackRock’s Technology division, a powerhouse of 4,600 experts and 3,000
engineers, eFront ERM benefits from unmatched expertise in risk, data, and financial
systems. Our user/provider model, unique in the market, means our technologies are
built and refined hand-in-hand with BlackRock’s own risk teams, ensuring enterprise-
grade quality, rapid innovation cycles, and solutions battle-tested at global scale
before they reach clients.
Sectors of implemented projects .......................... Banking (30 %), Insurance (40 %), Industry and Services (20 %), Public Sector (10 %)
Average number of users per solution ................ From 201 to 500
RMIS average implementation duration...............4 months
Creation date ...................................01/01/1999
Global workforce .......................................20000
RMIS workforce....................................................-
RMIS implementation workforce ....................-
RMIS R&D workforce ..........................................-
Solution(s) ........................................................... eFront ERM offers a full suite of autonomous yet seamlessly interoperable modules covering
Risk, Control, Internal Audit Compliance, BCP, TPRM, and Data Quality Control. This modular
architecture allows organizations to deploy what they need, when they need it, within a unified,
AI-powered GRC ecosystem.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... eFront ERM is a leading European RMIS and end-to-end GRC platform, combining modularity,
rich functionality and effortless configurability. It enables Risk, Control, Audit and Compliance
functions to operate with market best practices, all reinforced by new AI-powered intelligence.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 90 5 0 1 0 0
In the last 12 months 9 0 0 0 0 0
BLACKROCK (EFRONT)
Area(s) of presence:
>Africa (North, South)
>America (North, South)
>Asia (East, South West)
>Europe
>Oceania
75RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) CERRIX
Particularities and differentiating factors
A SaaS solution for compliance-heavy industries that centralizes risk, compliance,
and audit management. By uniting all stakeholders on one platform, it ensures
efficiency, automation, and a single source of truth for 360° control across the entire
ecosystem.
Sectors of implemented projects .......................... Banking (10 %), Insurance (30 %), Industry and Services (20 %), Others (40 %)
Average number of users per solution ................ From 101 to 200
RMIS average implementation duration...............4 months
Creation date ...................................15/10/2014
Global workforce ..............................................28
RMIS workforce.................................................28
RMIS implementation workforce ...................4
RMIS R&D workforce .......................................12
Solution(s) ...........................................................CERRIX
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Integrated Platform – Consolidates all GRC processes across stakeholders. Ease of
Implementation – Rapid deployment and minimal disruption. Automated Testing – Enhance
efficiency through automated testing. Advanced Reporting – Robust insights to support decision-
making.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 90 0 0 0 1 0
In the last 12 months 12 0 0 0 1 0
Area(s) of presence:
>Africa (East)
>America (Central, South)
>Europe
CERRIX B.V.
Jan Pietersz. Coenstraat 7-10
3022DH, Rotterdam
Netherlands
www.cerrix.com
Ruben ANDEWEG
Sales Engineer
+31 6 22 84 89 71
ruben.andeweg@cerrix.com
76RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) Challenge Optimum SA
rue du Midi 3
1003, Lausanne
Switzerland
www.click-n-manage.com
David BALME
CEO
+41 7 88 92 68 13
david.balme@optimum.ch
Particularities and differentiating factors
Click-N-Manage is the ultimate ISO management systems cloud platform: it provides
a comprehensive, user friendly, role based access to any aspect of the operation of
any kind of institution. Stakeholders, requirements, objectives, risks, procedures,
processes, products, services, skills, assets, KPI, non-conformances, actions, job
descriptions are all managed in a single interface allowing any stakeholder to
instantly understand what is expected from him/her or from his/her colleagues.
Sectors of implemented projects .......................... Banking (5 %), Insurance (5 %), Industry and Services (80 %), Public Sector (10 %)
Average number of users per solution ................ From 101 to 200
RMIS average implementation duration...............12 months
Creation date ...................................01/11/1994
Global workforce ................................................7
RMIS workforce...................................................5
RMIS implementation workforce ...................3
RMIS R&D workforce .........................................2
Solution(s) ...........................................................Click-N-Manage
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Compliant with ISO and regulations (e.g. medical devices, pharmaceutical industry, ...)
Mobile Customizable Role based access.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 30 3 1 0 1 0
In the last 12 months 3 0 0 0 0 0
CHALLENGE OPTIMUM
Area(s) of presence:
>America (Central)
>Asia (South East)
>Europe (Central and East, West)
77RMIS PANORAMA 2026
Please use arrows to easily navigate
<<Nom 2>>
<<address>>
<<CP>>, <<ville>>
<<pays>>
<<site web>>
<<prénom>> <<nom>>
<<fonction>>
<<tel>> / <<tel mob>>
<<email>>
Particularities and differentiating factors
<<Particularités…>>
Creation date ................................<<date créa>>
Global workforce .................. <<effectif global>>
RMIS workforce.........................<<effectif sgir>>
RMIS implementation workforce .....<<effectif
intégr>>
RMIS R&D workforce ...........................<<R&D>>Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update)
CoAudit Group
5 rue du Luc
63540, Romagnat
France
www.coauditgroup.fr
Frédérick DUPONT
CEO
+33 (0) 6 08 17 53 27
fdupont@coauditgroup.fr
Particularities and differentiating factors
CoAudit Group developed a truly innovative platform for managing audits, controls
and risks. The fundamentals are simplicity, security (100% Sovereign SecNumCloud
Saas platform with OutScale a branch of Dassault Systèmes) and flexibility. A
platform created by auditors and risk management specialists, and validated by
leading consulting firms. A board of certified experts support solution vision and good
practices for risk, audit and control management.
Creation date ...................................02/05/2017
Global workforce ..............................................20
RMIS workforce.................................................15
RMIS implementation workforce ...................5
RMIS R&D workforce .........................................5
COAUDIT GROUP
Area(s) of presence:
>Europe
Sectors of implemented projects .......................... Banking (10 %), Insurance (20 %), Industry and Services (20 %), Public Sector (40 %),
Others (10 %)
Average number of users per solution ................ From 6 to 50
RMIS average implementation duration............... 1 to 2 months
Solution(s) ...........................................................Sentinely platform
Main focus ...........................................................Other
Strengths according to the vendor ............... Easy to use, flexible, secure and attractive GRC platform, suitable for all contexts and sectors.
Developed by experts in audit compliance and risk management. Hosted in France in a sovereign
cloud or on the customer onsite.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 12 0 0 0 0 0
In the last 12 months 4 0 0 0 0 0
78RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) Corporater AS
Kontorveien 15
4033, Stavanger
Norway
www.corporater.com
Owe LIE-BJELLAND
Director GPRC
+47 48 15 40 00
lie-bjelland@corporater.com
Particularities and differentiating factors
Corporater solutions are trusted by top organizations worldwide, including Global
Fortune 500 companies. Organizations choose Corporater as they seek a single agile
and integrated architecture to automate a range of GRC, performance management,
and other business processes, we call it GPRC.
Sectors of implemented projects .......................... Banking (25 %), Insurance (15 %), Industry and Services (20 %), Public Sector (30 %),
Others (10 %)
Average number of users per solution ................ From 501 to 1000
RMIS average implementation duration...............3 months
Creation date ...................................01/03/2000
Global workforce ............................................250
RMIS workforce...............................................250
RMIS implementation workforce ...............100
RMIS R&D workforce .......................................60
Solution(s) ........................................................... Corporater’s main product is called the Business Management Platform - it is a feature
complete, integrated GPRC (Governance, Performance, Risk and Compliance) software.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Corporater’s platform integrates governance, performance, risk, and compliance management
into a unified solution. It aligns business objectives with operations, automates GRC processes,
and ensures data governance. This holistic approach enhances decision-making, ensures
regulatory compliance, and drives measurable success.
Solution architecture ........................................Other
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total - - - - - -
In the last 12 months - - - - - -
CORPORATER
Area(s) of presence:
>Africa (Central, East, South, West)
>America (Central, North)
>Asia (South, South East, South West)
>Europe
>Oceania
79RMIS PANORAMA 2026
Please use arrows to easily navigate
<<Nom 2>>
<<address>>
<<CP>>, <<ville>>
<<pays>>
<<site web>>
<<prénom>> <<nom>>
<<fonction>>
<<tel>> / <<tel mob>>
<<email>>
Particularities and differentiating factors
<<Particularités…>>
Creation date ................................<<date créa>>
Global workforce .................. <<effectif global>>
RMIS workforce.........................<<effectif sgir>>
RMIS implementation workforce .....<<effectif
intégr>>
RMIS R&D workforce ...........................<<R&D>>Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT
Area(s) of presence:
>Africa (North, South)
>America
>Asia
>Europe
>Oceania
CRIF AG
Hagenholzstrasse 81
8050, Zurich
Switzerland
www.crif.ch
Daniel GAMMA
Director Corporate Sales
+ 41 76 370 12 00 / + 41 76 370 12 00
d.gamma@crif.com
Particularities and differentiating factors
CRIF is the leading provider in Switzerland of credit risk management, fraud
prevention and address management solutions for every phase of the customer
relationship cycle. In addition, CRIF offers analytics and decision support solutions,
particularly through the optimization of credit application, portfolio management and
collection processes.
Sectors of implemented projects .......................... Banking (- %), Insurance (20 %), Industry and Services (60 %), Public Sector (- %),
Others (20 %)
Average number of users per solution ................ From 6 to 50
RMIS average implementation duration...............6-12 month
Creation date ...................................30/12/1994
Global workforce ..............................................90
RMIS workforce.................................................80
RMIS implementation workforce .................40
RMIS R&D workforce .......................................40
Solution(s) ...........................................................In Progress
Main focus ...........................................................Risk Management
Strengths according to the vendor ...............In Progress
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 10 0 0 0 0 0
In the last 12 months 5 0 0 0 0 0
CRIF AG
80RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) CALPANA
Paul-Dessau-Str. 1
22761, Hamburg
Germany
www.crisam.net
Andreas SCHMITZ
Managing Director
+49 4 0 35 98 29 22/+49 17 26 12 48 24
andreas.schmitz@crisam.net
Particularities and differentiating factors
CRISAM GRC platform is a standard GRC platform that is characterized by its flexible
configuration options and can be adapted to a wide variety of company structures and
processes with little effort. All necessary contents, such as evaluation and reporting
options, e.g. for compliance, ISMS, internal controls and many more, are included.
Sectors of implemented projects .......................... Banking (10 %), Insurance (10 %), Industry and Services (35 %), Public Sector (25 %),
Others (20 %)
Average number of users per solution ................ From 501 to 1000
RMIS average implementation duration............... 1.5 to 5 months
Creation date ...................................01/06/2005
Global workforce ..........................................6585
RMIS workforce.................................................82
RMIS implementation workforce .................35
RMIS R&D workforce .......................................21
Solution(s) ........................................................... CRISAM GRC platform, CRISAM Enterprise Risk Management, CRISAM Information Security
Management, CRISAM Internal Controls, CRISAM Compliance, CRISAM Data Protection.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... The GRC platform CRISAM.AI is used by over 500 companies for corporate management.
CRISAM is an intuitive platform that provides appropriate support for all stakeholders in the risk
management process in a guided workflow. It can also be linked to corporate planning so that
risk management becomes a value driver through improved planning reliability.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 665 14 21 25 15 7
In the last 12 months 135 4 6 5 5 2
CRISAM
Area(s) of presence:
>Africa (Central, East, North, South)
>America
>Asia
>Europe
>Oceania
81RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) DELTA RM
Particularities and differentiating factors
A French SaaS GRC vendor specializing in Risk and Insurance Management,
supporting organizations of all sizes and industries for over 10 years with a simple,
powerful, and intuitive GRC platform. Combining deep domain expertise with a strong
pedagogical approach, we turn risk and compliance challenges into actionable
solutions.
Sectors of implemented projects .......................... Banking (25 %), Insurance (18 %), Industry and Services (36 %), Public Sector (15 %),
Others (6 %)
Average number of users per solution ................ From 201 to 500
RMIS average implementation duration...............2 months
Creation date ...................................06/05/2013
Global workforce ..............................................26
RMIS workforce.................................................26
RMIS implementation workforce ...................6
RMIS R&D workforce .......................................13
Solution(s) ........................................................... Delta RM is a modular application with interconnected modules: the Dashboard consolidates
data and access; Risks includes mapping, mitigation, and action plans; Control covers 1st
and 2nd lines of defense; Audit serves as the 3rd line with programs and recommendations;
Insurance manages issues and claims; Incidents involve declaration and management;
Prevention plans site visits and recommendations.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Our tool is developed by Risk Management experts, focusing on Risk Management. We are
independent software editors with one shared version of our software (no upgrade fees) and
unlimited access (Insurance, Risk, Control, Audit).
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 30 6 0 0 0 0
In the last 12 months 10 4 0 0 0 0
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
Delta RM
14 rue du Mail
75002, Paris
France
www.deltarm.com
Pierre SOREL
Development Director
+33 (0) 1 40 41 94 25
pierre.sorel@deltarm.com
82RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) Diligent
25 Bedford street
WC2E 9ES, London
United Kingdom
www.diligent.com
Thibaud SAINT-ROMAIN
Solutions Engineer
+1 (973) 939 9381
tsaintromain@diligent.com
Particularities and differentiating factors
Diligent is the Leader in GRC, we help companies surface the right information
to the C-Suite, Audit and Risk Committee and the board, with the broadest set of
applications to manage risk and compliance, and offer the only platform to automate
controls with our proprietary tool ACL, continuously monitor risk and demonstrate
compliance.
Sectors of implemented projects .......................... Banking (15 %), Insurance (15 %), Industry and Services (60 %), Public Sector (5 %),
Others (5 %)
Average number of users per solution ................ From 6 to 50
RMIS average implementation duration...............2 montrhs
Creation date .................................................1994
Global workforce ..........................................4000
RMIS workforce....................................................-
RMIS implementation workforce ....................-
RMIS R&D workforce ..........................................-
Solution(s) ........................................................... Diligent Enterprise Risk Management (ERM)
Main focus ...........................................................Internal Control - Compliance
Strengths according to the vendor ............... With Diligent’s ERM offering, customers can navigate risk and unlock growth potential by: 1.
Working from a centralized, single source of truth to manage risks and controls in real-time;
2.Providing executive visibility with a comprehensive single view of internal and external risk
with Diligent ERM Reporting, powered by Moody’s; 3.Identifying, assessing, and remediating
risk with automated workflows; 4. Supporting the spread of a real culture of risks across the
organisations; 5. Reporting directly to their Risk Committee using Diligent’s Board application
(connected to the Risk Application).
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 507 24 269 4114 565 65
In the last 12 months 25 5 13 102 13 5
DILIGENT
Area(s) of presence:
>Africa (North, South)
>America
>Asia
>Europe
>Oceania
83RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) DIOT SIACI
Particularities and differentiating factors
Diot Siaci, a leading insurance broker, drives digital transformation in brokerage
processes, offering innovative solutions and personalized support as part of a
comprehensive advisory offering. Our approach combines cutting-edge technology
with tailored advisory services to deliver a 360° view of risks, enhancing insurance
management efficiency and providing a seamless, client-centric digital experience.
Sectors of implemented projects .......................... Banking (5 %), Industry and Services (90 %), Public Sector (5 %)
Average number of users per solution ................ From 101 to 200
RMIS average implementation duration...............2 months
Creation date ...................................01/11/2013
Global workforce ..........................................6000
RMIS workforce.................................................18
RMIS implementation workforce .................10
RMIS R&D workforce .........................................4
Solution(s) ........................................................... UNITY, Diot Siaci’s new risk management portal
Main focus ...........................................................Insurance Management
Strengths according to the vendor ............... Innovative, client-centric solutions with a 360° risk view, no-code digital tools, personalized
advisory services, and optimized insurance management for enhanced efficiency and decision-
making. A centralized, secure space with two-factor authentication and a microservices-based
portal architecture ensures the most innovative and high-performance solutions.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 50 0 0 0 0 0
In the last 12 months 10 0 0 0 0 0
Area(s) of presence:
>Africa
>America (North)
>Asia
>Europe
DIOT SIACI
39, rue Mstislav Rostropovitch
75815, Paris
France
www.s2hgroup.com
Anthony GONDET
RMIS Manager
+33 (0) 6 10 16 17 78
anthony.gondet@s2hgroup.com
84RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) NANOCODE SAS
1137a avenue des Champs Blancs
35510, Cesson-Sévigné
France
www.easylience.com
Thierry de RAVEL
CEO
+33 (0) 9 54 63 12 34
thierry.deravel@easylience.com
Particularities and differentiating factors
easylience® is a comprehensive solution dedicated to crisis and business continuity
management. Leveraging CRISIS 3D® technology, it guides stakeholders in adhering
to the established methodology, risk scenarios, and crisis organization. Finally, our
consulting division supports clients through change management initiatives—ranging
from systems digitization and crisis management training to the organization of
realistic exercises with improvement plans.
Sectors of implemented projects .......................... Banking (35 %), Insurance (15 %), Industry and Services (15 %), Public Sector (20 %),
Others (15 %)
Average number of users per solution ................ More than 1000
RMIS average implementation duration...............3 months
Creation date ...................................23/02/2016
Global workforce ..............................................35
RMIS workforce.................................................25
RMIS implementation workforce .................10
RMIS R&D workforce .......................................15
Solution(s) ........................................................... easylience® : Crisis steering system
Main focus ...........................................................Other
Strengths according to the vendor ............... easylience® unites more than 15 features that facilitate the management of crisis situations.
Accessible through an interface designed for high-stress environments, these features operate
in real time to securely enhance situational awareness, define adverse forecasts, support
decision-making, assign tasks to stakeholders, and coordinate multi-channel communications.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 40 15 21 14 8 3
In the last 12 months 5 3 4 4 2 1
EASYLIENCE
Area(s) of presence:
>Africa (North, South)
>America
>Asia
>Europe
>Oceania
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
85RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) EGERIE
EGERIE
44 boulevard de Strasbourg
83000, Toulon
France
www.egerie.com
Jean LARROUMETS
CEO
+33 (0) 4 94 63 81 09
jean.larroumets@egerie.eu
Particularities and differentiating factors
EGERIE is a collaborative platform that maps and financially quantifies cyber-origin
risks and helps organizations industrialize their risk-driven cybersecurity programs.
EGERIE’s innovative approach and smart technology helps customers centralize and
orchestrate their cyber-risk assessment strategies, by dynamically identifying the
high risks & threats, measuring the results of risk mitigation efforts while getting
buy-in from all levels in the organization.
Sectors of implemented projects .......................... Banking (15 %), Insurance (15 %), Industry and Services (40 %), Public Sector (30 %)
Average number of users per solution ................ From 6 to 50
RMIS average implementation duration...............3 months
Creation date ...................................06/01/2016
Global workforce ............................................150
RMIS workforce...............................................150
RMIS implementation workforce .................20
RMIS R&D workforce .......................................45
Solution(s) ...........................................................EGERIE Platform
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Smart Cyber-Risk Advanced Modeling Engine with pre-built relationships between assets,
vulnerabilities, standard requirements and controls. Integrated libraries for Multi-standard
compliance. Automatic Risk Reduction & dynamic updates. Cyber-Risk Quantification. Advanced
collaboration and integrated audit questionnaires. 360° View on all risks, controls, treatments
across all risk analyses. Monitoring Cockpits and dashboards based on user role. Fully
customizable reports.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 500 55 75 90 45 10
In the last 12 months 100 10 10 15 5 3
Area(s) of presence:
>Africa
>America (North)
>Asia
>Europe
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
86RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) Empowered Systems
6 Lloyds avenue, Suite 4cl
EC3N 3A, London
United Kingdom
www.empoweredsystems.com
Nichol DEADDIS
Chief Customer Officer
+44 77 93 45 84 09
nicholdeaddis@empoweredsystems.com
Particularities and differentiating factors
Connected Risk offers powerful Business Process Automation, supporting risk
management, compliance, regulatory, and third-party risk processes. Its flexible
architecture enables tailored automation of tasks like data inputs, approvals, and
notifications, reducing manual effort. Seamlessly integrating with other systems,
it ensures efficient, customized workflows aligned with operational and regulatory
needs.
Sectors of implemented projects .......................... Banking (50 %), Insurance (15 %), Industry and Services (20 %), Public Sector (5 %),
Others (10 %)
Average number of users per solution ................ From 501 to 1000
RMIS average implementation duration............... 1.5 to 3 months
Creation date ...................................01/11/1998
Global workforce ..............................................70
RMIS workforce.................................................70
RMIS implementation workforce ....................-
RMIS R&D workforce .......................................25
Solution(s) ........................................................... Connected Risk (Application): The Audit Module manages the internal audit lifecycle. The Risk
Management Module covers all risk aspects. The Compliance Management Module oversees
controls. The Policy Management Module handles policies from creation to approval. The Third
Party/ESG Module evaluates third parties, including onboarding and ESG assessments.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Comprehensive Process Automation: Streamlines workflows in risk management, compliance,
and third-party processes, reducing manual tasks and boosting efficiency. Tailored Flexibility:
Enables customized automation for data inputs and approvals. Seamless Integration: Integrates
with existing systems for cohesive workflows.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 102 7 91 109 20 4
In the last 12 months 4 0 3 2 0 0
EMPOWERED
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
87RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) GRACE CONNECT GRC
Grace Connect Sàrl
rue du Laboratoire, 9
1911, Luxembourg
Luxembourg
www.gracegrc.com
Veronika ZUKOVA
CEO
+35 2 6 91 61 52 16
veronika.zukova@gracegrc.com
Particularities and differentiating factors
Grace Connect GRC Suite is a holistic solution designed by experienced Risk
Managers with the aim to propose a valuable and reliable alternative to
spreadsheets. The product is based on more than 50 modules designed to manage
cyber security risk, ensure business continuity, data quality, and compliancy towards
GDPR, NIS2, and DORA.
Sectors of implemented projects .......................... Insurance (80 %), Others (20 %)
Average number of users per solution ................ From 6 to 50
RMIS average implementation duration...............1 month
Creation date ...................................05/08/2020
Global workforce ................................................6
RMIS workforce...................................................6
RMIS implementation workforce ...................5
RMIS R&D workforce .........................................4
Solution(s) ........................................................... Audit: Manages audit activities and findings. Complaints: Handles complaints. Compliance:
Manages conflict declarations and compliance reporting. Data Protection: Manages requests
and GDPR compliance. Incident: Handles incidents and crises. IT Register: Monitors systems and
testing. Risk: Manages Risks, BCM and Third-party assessment. Process: Archives and assesses
processes and procedures. Task: Tracks tasks and events.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Best price/quality ratio in the GRC market. All modules are interconnected in one repository
for audits. The user interface is simple and engaging, with embedded data exports and
synchronization to existing systems. Affordable customization options are available.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 5 0 1 0 1 0
In the last 12 months 2 0 0 0 0 0
Area(s) of presence:
>Africa (North)
>Europe
88RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) IBM
17 avenue de l’Europe
92275, Bois Colombes
France
www.ibm.com
Thomas DOGNIN
AI Sales Market Leader
+33 (0) 6 88 38 09 03
tdognin@fr.ibm.com
Particularities and differentiating factors
IBM is a leader in hybrid cloud, AI, and consulting, assisting clients in over 175 countries
to leverage data insights and reduce costs. IBM OpenPages is a enterprise risk and
compliance management solution that helps organizations manage operational and
compliance risks. It offers an integrated platform for risk and governance, enabling
informed decisions. Key benefits include improved risk visibility, enhanced compliance,
AI support, and cost reduction. Forrester has evaluated user efficiency.
Sectors of implemented projects .......................... Banking (30 %), Insurance (30 %), Industry and Services (15 %), Public Sector (10 %),
Others (15 %)
Average number of users per solution ................ From 201 to 500
RMIS average implementation duration............... 5 to 6 months
Creation date ...................................01/01/1911
Global workforce .....................................285000
RMIS workforce.............................................6000
RMIS implementation workforce .............2000
RMIS R&D workforce .....................................300
Solution(s) ........................................................... IBM OpenPages Operational Risk Management: manage risk and control, assessments
and key indicators. Business Continuity: Plans for disruptions. Financial Controls: Ensures
compliance. Model Risk: Manages financial model risks. IT Governance: Ensures IT
compliance. Policy Management: Oversees policies. Internal Audit: Supports audit planning.
ESG: Manages ESG programs.
Main focus ...........................................................Other
Strengths according to the vendor ............... IBM OpenPages features a user-friendly interface, AI-driven capabilities, and a comprehensive
GRC platform. It promotes a risk-aware culture, provides cost savings, and integrates seamlessly.
Watsonx AI can be deployed on-premise or via SaaS, enhancing risk management and compliance.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 352 45 150 634 340 34
In the last 12 months 40 12 23 80 43 10
IBM OPENPAGES
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
89RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) INCLUS
Inclus
Otakaari 5
02150, Espoo
Finland
www.inclus.com
Jesper NYSTRÖM
Business Development Manager
+35 84 07 64 36 79
jesper.nystrom@inclus.com
Particularities and differentiating factors
Inclus leverages AI-powered tools, visual analysis, and a multicriteria methodology to
foster collaboration and informed decision-making. With roots in peace mediation and
conflict resolution, we empower organizations to navigate risk and uncertainty.
Sectors of implemented projects .......................... Banking (5 %), Industry and Services (60 %), Public Sector (30 %), Others (5 %)
Average number of users per solution ................ From 6 to 50
RMIS average implementation duration...............1 month
Creation date ...................................01/05/2016
Global workforce ..............................................20
RMIS workforce.................................................20
RMIS implementation workforce ...................5
RMIS R&D workforce .......................................10
Solution(s) ...........................................................Inclus
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Inclus offers cloud-based, AI-supported risk management with collaborative workflows, real-time
visual analytics, and automated processes. Our customizable templates and data consolidation
enhance organizational resilience, enabling teams to identify, assess, and address risks and
opportunities efficiently.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 58 2 0 0 0 0
In the last 12 months 15 1 0 0 0 0
Area(s) of presence:
>Africa (North, South)
>America
>Europe
90RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) Kermobile Solutions
30 avenue de Messine
75008, Paris
France
www.kermobile.com
Bruno de TERLINE
General Director
+33 (0) 1 58 62 52 13/+33 (0) 6 09 52 03 87
bruno.deterline@kermobile.com
Particularities and differentiating factors
KerMobile Solutions, mainly through KerClaim, its flagship application, optimise
the management and control of insurance claims, insurance contracts and building
maintenance. By systematising and securing key processes in real-time, these
solutions provide advanced decision support features, while speeding up insurance
claims settlement and optimising premiums.
Sectors of implemented projects .......................... Banking (10 %), Insurance (5 %), Industry and Services (40 %), Public Sector (40 %),
Others (5 %)
Average number of users per solution ................ From 6 to 50
RMIS average implementation duration............... 2 to 6 months
Creation date ...................................15/07/2015
Global workforce ..............................................25
RMIS workforce...................................................5
RMIS implementation workforce ...................1
RMIS R&D workforce .........................................5
Solution(s) ........................................................... KerClaim (management of real-estate related insurance claims); KerPol (management of
insurance contracts); KerDys (building maintenance management).
Main focus ...........................................................Insurance Management
Strengths according to the vendor ............... Combining mobile and web technologies with an advances reporting engine, KerClaim, KerPol
and KerDys are cost-effective professional solutions. Time saving, process quality, reliability &
efficiency are the key features that guarantee fast implementation and intuitive operation. These
applications support collaboration between all company departments (assets management,
finance, real-estate property management, etc.).
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 70 0 0 0 0 0
In the last 12 months 15 0 0 0 0 0
KERMOBILE
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
91RMIS PANORAMA 2026
Please use arrows to easily navigate
<<Nom 2>>
<<address>>
<<CP>>, <<ville>>
<<pays>>
<<site web>>
<<prénom>> <<nom>>
<<fonction>>
<<tel>> / <<tel mob>>
<<email>>
Particularities and differentiating factors
<<Particularités…>>
Creation date ................................<<date créa>>
Global workforce .................. <<effectif global>>
RMIS workforce.........................<<effectif sgir>>
RMIS implementation workforce .....<<effectif
intégr>>
RMIS R&D workforce ...........................<<R&D>>Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT
Area(s) of presence:
>America (Central, North)
>Asia (South West)
>Europe (West)
>Oceania
LogicManager
6 Liberty Square
02109,, Boston
United States
www.logicmanager.com
Katrina SCHEMELTER
Manager of Product Marketing
+ 44 36 17 31 25 / -
katrina.schmelter@logicmanager.com
Particularities and differentiating factors
LogicManager is a specialized ERM solution focused on managing complex,
interconnected risks. Built on a risk-based methodology, the platform connects risk,
controls, and accountability across the organization to transform risk information
into forward-looking insight that strengthens oversight, resilience, and business
performance.
Sectors of implemented projects .......................... Banking (30 %), Insurance (17 %), Industry and Services (52 %), Public Sector (1 %)
Average number of users per solution ................ From 101 to 200
RMIS average implementation duration...............3 months
Creation date ...................................01/01/2005
Global workforce ..............................................55
RMIS workforce.................................................43
RMIS implementation workforce ...................9
RMIS R&D workforce .......................................25
Solution(s) ...........................................................In Progress
Main focus ...........................................................Risk Management
Strengths according to the vendor ...............In Progress
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 2 0 1 154 0 2
In the last 12 months - - - 3 - -
LOGICMANAGER
92RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) Maptycs Inc.
6 Old Country Road
10804, New Rochelle, NY
United States
www.maptycs.com
Jacqueline LEGRAND
CEO & Co-founder
+1 (212) 203 5823
Jacqueline@thelegrand.com
Particularities and differentiating factors
MAPTYCS® is a geospatial analytics solution for property risk mapping, climate
risk assessment, real-time weather events monitoring and custom risk reports.
An additional module, COLLEXTER, provides a secure and reliable environment to
collect risk exposure values and any insurance policies and claims data from multiple
operations and countries.
Sectors of implemented projects .......................... , Insurance (20 %), Industry and Services (80 %)
Average number of users per solution ................ From 6 to 50
RMIS average implementation duration...............1 month
Creation date ...................................21/01/2017
Global workforce ..............................................30
RMIS workforce.................................................30
RMIS implementation workforce ...................5
RMIS R&D workforce .........................................2
Solution(s) ........................................................... Maptycs is a geospatial risk mapping solution to visualize and analyze property and climate
risk exposure. Collexter is a web-based platform for risk managers to collect and manage risk
exposure, policies, and claims data. Policybase is a Generative AI-enabled repository solution
to storage and organize policy documents, generate policy schedules and facilitate search and
deep analysis of policy documents in any language.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Maptycs & Collexter are flexible, user friendly and easy to implement. Users can use their own
templates, taxonomy, and currency to collect risk data, develop dynamic analytics and financial
scenarios. The solution includes climate risk and sustainability data.
Solution architecture ........................................Several distinct applications, but with interfaces
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 15 0 2 24 0 0
In the last 12 months 6 0 1 8 0 0
MAPTYCS
Area(s) of presence:
>America (North)
>Asia (South East)
>Europe
93RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) MOODY’S
Moody’s
Tour Opus 12 -
77 esplanade du Général-de-Gaulle
92800, Puteaux - La Défense, France
www.moodys.com
Julien NORÉ
Director - Relationship Manager
+33 (0) 1 53 45 46 30
julien.nore@moodys.com
Particularities and differentiating factors
Moody’s offers comprehensive risk management solutions, including data, analytics,
and insights to help businesses identify, evaluate, and mitigate risks. They focus
on compliance risk, credit risk, supplier performance, and cyber risk, providing
tools and recommendations to build resilient strategies and ensure compliance with
regulatory demands.
Sectors of implemented projects .......................... Banking (25 %), Insurance (25 %), Industry and Services (25 %), Public Sector (25 %)
Average number of users per solution ................ From 6 to 50
RMIS average implementation duration............... 4 to 6 months
Creation date ...................................01/01/1909
Global workforce .......................................14000
RMIS workforce....................................................-
RMIS implementation workforce ....................-
RMIS R&D workforce ..........................................-
Solution(s) ........................................................... ORBIS: Global database with info on 550M+ companies (corporate structures,, financial
strength, cyber risk, and ESG…). GRID Screening: Adverse media, sanctions, and PEPs profiles.
Compliance Catalyst: Data-driven engine for KYC, AML, and ABAC, integrating ORBIS and GRID
data. Maxsight: Unified Risk Platform for Compliance, Supply Chain & Credit Risk.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Moody’s compliance solutions offer a holistic view of risk, integrating Orbis and GRID data, using
AI to reduce false positives, and streamlining compliance processes.
Solution architecture ........................................Several distinct applications, but with interfaces
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total - - - - - -
In the last 12 months - - - - - -
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
94RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) My Risk Committee
58 rue Monceau
75008, Paris
France
www.myriskcommittee.com
Rudy MIZEL
CEO
+33 (0) 6 26 47 81 95
rudy.mizel@myriskio.com
Particularities and differentiating factors
My Risk Committee Software solution for enterprise risk and insurance management,
based on digital twin technology and real-time data analysis. My Risk Committee
helps companies anticipate and manage material damage risks affecting their real
estate assets, vehicle fleets, and supply chains. Its expertise is primarily aimed at
mid-sized companies, large corporations, brokers, captives, and insurance companies.
Sectors of implemented projects .......................... Insurance (20 %), Industry and Services (80 %)
Average number of users per solution ................ From 6 to 50
RMIS average implementation duration...............5 months
Creation date ...................................01/01/2020
Global workforce ................................................6
RMIS workforce...................................................6
RMIS implementation workforce ...................6
RMIS R&D workforce .........................................6
Solution(s) ........................................................... My Risk io
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... My Risk io is an Enterprise Risk Management software to support companies in the valuation of
operational data for risk management, loss prevention and insurance optimization. A complete,
secure, collaborative and versatile SaaS platform for continuous and real-time monitoring of
business assets, risks and insurance.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 6 1 0 3 0 0
In the last 12 months 2 0 0 2 0 0
MY RISK IO.
Area(s) of presence:
>Africa (North)
>America (North)
>Europe (West)
95RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) NOVASECUR
NOVASECUR
10, rue du 4 Septembre
13100, Aix-en-Provence
France
www.novasecur.com
Nadia TRUPHEME
Sales Manager
+33 (0) 4 42 54 69 61/+33 (0) 7 72 35 26 37
info@novasecur.com
Particularities and differentiating factors
MyNovasecur Advanced ©, a unique RMIS/GRC/ERM solution, pioneer in using
Analytics and AI in Risk Management. Transversal and collaborative between the 3
lines of defense, it maps weak signals to anticipate risks, alerting on atypical data and
recommends controls and actions plans in a simplified 360° reporting interface.
Sectors of implemented projects .......................... Banking (35 %), Insurance (35 %), Industry and Services (25 %), Public Sector (5 %)
Average number of users per solution ................ From 201 to 500
RMIS average implementation duration...............1.5 months
Creation date ...................................10/02/2010
Global workforce ..............................................20
RMIS workforce.................................................17
RMIS implementation workforce ...................5
RMIS R&D workforce .........................................6
Solution(s) ........................................................... MyNovasecur Advanced © RMIS/ERM/GRC; AI/Analytics (Large companies); MyNovasecur© One
(SME); MyNovasecur© AI-DATALAB (prediction/atypical detection/data profiling/data sampling);
MyNovasecur© AI-DOCULAB (AI NLP & document scoring in Risk, HR, Marketing, Legal);
MyNovasecur© Specialty Risks (Cyber, Fraud, Compliance, Third Party Analysis, BCP BRP).
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Use the most complete and technologically advanced cross-functional modular RMIS on the
market with intuitive interfaces built by ergonomists, anticipate invisible risks and increase
decision-making performance (action plans, controls, audits) with AI and Analytics. Drive
strategically with predictive recommendations on remediation optimization.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 28 4 1 1 0 0
In the last 12 months 6 0 0 0 0 0
Area(s) of presence:
>Africa (North)
>America (North)
>Asia (East, South)
>Europe
96RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) OneTrust
24 rue Mogador
75009, Paris
France
www.onetrust.com/fr
Vanessa CUGNIERE
Country Manager France
contactfrance@onetrust.com
Particularities and differentiating factors
The OneTrust platform empowers organizations to responsibly collect, govern, and
use data with full visibility and control. It streamlines risk management, enforces
compliance, and optimizes data strategies for innovation while meeting regulatory
and customer demands. OneTrust’s unified platform, built on a shared data model,
allows viewing all security, risk, and compliance initiatives through a single pane of
glass.
Sectors of implemented projects .......................... Banking (20 %), Insurance (20 %), Industry and Services (20 %), Public Sector (20 %),
Others (20 %)
Average number of users per solution ................ From 6 to 50
RMIS average implementation duration............... 4 to 6 months
Creation date ...................................01/01/2016
Global workforce ..........................................2300
RMIS workforce....................................................-
RMIS implementation workforce ....................-
RMIS R&D workforce ..........................................-
Solution(s) ........................................................... 1)Third-Party Management - Fully manage your third-party lifecycle. 2) Tech Risk and
Compliance - Simplify compliance and manage risks.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... OneTrust’s Tech Risk & Compliance solution automates governance, risk, and compliance (GRC)
processes, integrating business-ready content and mapping to simplify compliance and manage
risks effectively.
Third-Party Risk Management streamlines the third-party lifecycle with data-driven automation,
enhancing assessment efficiency, continuous risk monitoring, and alignment across workflows.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total - - - - - -
In the last 12 months - - - - - -
ONETRUST
Area(s) of presence:
>America (North)
>Asia (Central and North)
>Europe
>Oceania
97RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) OPTIMISO
Particularities and differentiating factors
Optimiso turns regulatory constraints into strengths for the company. Efficient,
flexible and useful to everyone, the solution addresses issues of governance, risks,
internal control and ISO certifications. Benefit from the experience of 27,000 users and
20 years of field expertise. Our asset: the automation of monitoring controls.
Sectors of implemented projects .......................... Banking (5 %), Insurance (15 %), Industry and Services (35 %), Public Sector (30 %),
Others (15 %)
Average number of users per solution ................ From 101 to 200
RMIS average implementation duration...............3 months
Creation date ...................................01/01/2005
Global workforce ..............................................32
RMIS workforce.................................................32
RMIS implementation workforce ...................8
RMIS R&D workforce .........................................7
Solution(s) ........................................................... Optimiso Suite includes several modules: Risks: Evaluate risks easily; Controls: Automate
monitoring; Processes: Model and communicate processes; Procedures: Create clear procedures
quickly; Incidents: Report and manage incidents; Improvements: Track action plans; Norms &
Laws: Prove compliance with standards; Documents: Manage directives and forms; Assets:
Manage information and material assets; Business Intelligence: Reveal key figures in your RMIS.
Main focus ...........................................................Internal Control - Compliance
Strengths according to the vendor ............... An intuitive solution that simplifies RMIS complexity. Management monitors control completion
in real time, helping employees perform controls, read processes, and report incidents. It
features automatic reporting for auditors, including risk mapping and internal control matrices.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 262 6 1 0 4 1
In the last 12 months 10 3 0 0 0 0
Area(s) of presence:
>Africa (Central, South, West)
>America (Central, South)
>Asia (South West)
>Europe (Central and East, West)
>Oceania
Optimiso (Iskera Suisse)
Chemin JB Vandelle 8
1290, Versoix
Switzerland
www.optimiso-group.com
Audrey ROCH
Sales director
+41 2 27 55 21 27
aro@optimiso-group.com
98RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) Optro, Inc.
106-114 Borough High St
SE1 1LB, London
United Kingdom
www.optro.ai
Eric DESERT
Enterprise Account Executive
+ 44 77 89 92 65 86/+1 (877) 769 5444
edesert@optro.ai
Particularities and differentiating factors
Optro’s Connected Risk Platform intelligently automates and integrates GRC
programs, systems, and processes like no other platform on the market. Exceptional
user experiences, seamless interoperability, and recommendations from GRC-trained
AuditBoard AI are just a few of the ways we align assurance teams and drive strategic
business objectives forward.
Sectors of implemented projects ..........................Banking (100 %)
Average number of users per solution ................ More than 1000
RMIS average implementation duration............... 2 to 3 months
Creation date ...................................07/07/2014
Global workforce ............................................870
RMIS workforce...............................................870
RMIS implementation workforce ....................-
RMIS R&D workforce ..........................................-
Solution(s) ........................................................... Optro (formerly AuditBoard) is the GRC system of action enterprises trust to turn risk into
opportunity. It embeds GRC-trained AI and native analytics across its integrated platform to inform,
quantify, and prioritize risk decisions, and provides purpose-built solutions for audit management,
ERM, TPRM, regulatory compliance, cyber risk management, and more.
Main focus ...........................................................Risk management
Strengths according to the vendor ............... Optro is built by practitioners for practitioners, with embedded GRC expertise in every
solution and service. Customers leveraging our connected risk platform, advanced BI, and
proprietary AI report three-year ROIs of 281%.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total - - - - - -
In the last 12 months - - - - - -
OPTRO
Area(s) of presence:
>America (Central, North)
>Asia
>Europe
99RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) OXIAL
Oxial
Domaine de La Borie
33790, Massugas
France
www.oxial.com
Eric BERDEAUX
CEO
+33 (0) 6 85 24 09 82
eric.berdeaux@oxial.net
Particularities and differentiating factors
With over 50,000 users, OXIAL GRC is an integrated, flexible and innovative digital
risk and compliance management solution. It integrates all the essential components
of governance, risk management, internal control, internal audit, and regulatory
compliance on a single modern platform. This solution is distinguished by its
unmatched graphical analysis and reporting capabilities at the user’s fingertips.
Sectors of implemented projects .......................... Banking (40 %), Insurance (30 %), Industry and Services (15 %), Public Sector (5 %),
Others (10 %)
Average number of users per solution ................ From 101 to 200
RMIS average implementation duration............... 3 to 6 months
Creation date ...................................01/01/2005
Global workforce ..............................................55
RMIS workforce.................................................55
RMIS implementation workforce .................23
RMIS R&D workforce .......................................10
Solution(s) ...........................................................Oxial sGRC
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Modular, Integrated, one single data repository, best practices, step by step implementation,
100% feature GRC coverage.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 45 16 0 0 0 0
In the last 12 months 6 6 0 0 0 0
Area(s) of presence:
>Africa (North)
>Europe (Central and East, West)
100RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) PocketResult
15 avenue Carnot
75017, Paris
France
www.pocketresult.com
Remy BELLAVOINE
CEO
+33 (0) 6 51 37 91 22
remy.bellavoine@pocketresult.com
Particularities and differentiating factors
Robust and innovative Analytic system covering Governance, Risk Management and
Compliance, with a core focus on Data utilizing AI to simplify and automate certain
tasks. Flexible and secure, the solution adapts to a wide range of organizations, from
large enterprises to small businesses. Deployment is streamlined by an intuitive
interface.
Sectors of implemented projects .......................... Banking (50 %), Insurance (20 %), Industry and Services (10 %), Public Sector (20 %)
Average number of users per solution ................ From 51 to 100
RMIS average implementation duration...............3 months
Creation date ...................................01/04/2013
Global workforce ..............................................32
RMIS workforce.................................................32
RMIS implementation workforce ...................8
RMIS R&D workforce .......................................22
Solution(s) ........................................................... P-Govern Modules: Pocket Audit; Pocket Risk Manager; Pocket Internal Control; Pocket Business
Continuity; Pocket Compliance; Pocket Data Quality.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... With 350 available connectors, the data core of P-Govern provides a comprehensive and
bespoke view of risks: fully customizable dashboards with virtually unlimited possibilities, and
completely configurable forms and workflows. As a result, clients experience a sense of ‘made-
to-order’ with the benefits of an off-the-shelf solution.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 110 6 4 0 0 0
In the last 12 months 15 5 3 0 0 0
POCKETRESULT
Area(s) of presence:
>Africa
>Asia
>Europe
>Oceania
101RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) PREWAVE
Prewave GmbH
Rothschildplatz 4/Austria Campus 4
1020, Vienna
Austria
www.prewave.com
Vincent TRIBONDEAU
Account Executive
+43 1 30 50 74 3
info@prewave.ai
Particularities and differentiating factors
Prewave is a leading supply chain risk management platform. We excel in AI-powered
Risk Detection, covering Resilience, Sustainability, and Compliance. Our platform
offers an end-to-end solution for managing risks across all tiers of the supply chain,
from identification and assessment to mitigation and reporting.
Sectors of implemented projects ..........................-
Average number of users per solution ................ From 51 to 100
RMIS average implementation duration............... 1 to 6 months
Creation date ...................................01/06/2017
Global workforce ............................................264
RMIS workforce....................................................-
RMIS implementation workforce ....................-
RMIS R&D workforce ..........................................-
Solution(s) ........................................................... Prewave offers AI solutions for supply chain and sustainability challenges. Our Supplier
Monitoring tracks 4 million sources in 400+ languages for 150+ real-time alerts. The 360°
Supplier Scoring provides a comprehensive risk score using various data over five years. Tier N
Transparency identifies sub-supplier ecosystem. Regulatory Compliance automates compliance
with CS3D, EUDR, and UFLPA.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Prewave offers AI supply chain risk detection for Resilience, ESG, and Compliance. Our platform
provides an end-to-end complete view for risk identification and action. Key Differentiators: -
AI Detection - Comprehensive Coverage - End-to-End Management.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 212 0 6 9 2 0
In the last 12 months 72 0 1 7 2 0
Area(s) of presence:
>America
>Asia (South)
>Europe
102RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) QUADRATIC
64, rue Caumartin
75009, Paris
France
www.quadratic-labs.com
Guillaume LOUASIL
Associate
+33 (0) 6 79 66 79 23
guillaume.louasil@quadratic-labs.com
Particularities and differentiating factors
Quadratic, the developer of Argos Manager, specializes in Digital Engineering,
blending Data Science, Software Engineering, and Operational Excellence. We ensure
swift integration of Argos, tailored to specific client needs with ad hoc developments
and custom dashboards, backed by extensive expertise in data science.
Sectors of implemented projects .......................... Banking (50 %), Industry and Services (50 %)
Average number of users per solution ................ From 101 to 200
RMIS average implementation duration............... 1 to 3 months
Creation date ...................................01/07/2021
Global workforce ..............................................62
RMIS workforce...................................................5
RMIS implementation workforce .................10
RMIS R&D workforce .........................................6
Solution(s) ........................................................... ARGOS Manager, a solution dedicated to risk coverage including the management of internal
control campaigns, the management of operational incidents, and the instruction and
monitoring of action plans, thus providing a 360° vision of the level of risk coverage of the
business. Additionally, it includes a Compliance module with various functionalities, namely: the
management of requisitions, the identification of third parties under freeze & sanction lists, and
the monitoring of beneficial owners.
Main focus ...........................................................Internal Control - Compliance
Strengths according to the vendor ............... A simple, accessible, and customizable tool offering the expected functionalities to support a
pragmatic and effective permanent control system.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 4 0 0 0 0 0
In the last 12 months 1 0 0 0 0 0
QUADRATIC
Area(s) of presence:
>Europe (West)
103RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) QUALITADD
Qualitadd
67 rue d’Aguesseau
92100, Boulogne-Billancourt
France
www.qualitadd.com
Viviane LABONNE
Strategic Alliance Manager
+33 (0) 6 83 75 49 05
vlabonne@qualitadd.com
Particularities and differentiating factors
Qualitadd is a French publisher of innovative digital solutions, specializing in risk
management, data governance, and internal control. Founded in 2016, Qualitadd is
the only provider offering a native link between data quality, compliance, and risk,
with advanced connectivity and controlled, transparent costs. With 40 employees
across Paris, Barcelona, and Casablanca, Qualitadd supports over 50 clients,
including CNP Assurances, Bpifrance, Covéa, Carrefour, and Groupama.
Sectors of implemented projects .......................... Banking (11 %), Insurance (74 %), Industry and Services (5 %), Others (10 %)
Average number of users per solution ................ From 51 to 100
RMIS average implementation duration...............6 months
Creation date ...................................26/07/2016
Global workforce ..............................................46
RMIS workforce.................................................26
RMIS implementation workforce ...................9
RMIS R&D workforce .........................................2
Solution(s) ........................................................... Qualitadd GRCI-ERM ©: A risk and compliance management tool for identifying and tracking
risks. Qualitadd Data Governance ©: Ensures data quality and compliance. Qualitadd Insurance
©: Manages insurance policies and claims. Qualitadd PCA ©: Develops business continuity
plans. Qualitadd Internal Audit ©: Facilitates audit planning. Qualitadd Third-Party Assessment
©: Evaluates third-party risks.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... We are pioneers in integrating AI and technological innovation to bridge the worlds of data and
risk management. Our platform transforms information into strategic decisions, enabling our
clients to anticipate and secure their future while meeting regulatory requirements.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 43 3 0 0 0 0
In the last 12 months 9 0 0 0 0 0
Area(s) of presence:
>Africa
>America (North, South)
>Europe
>Oceania
104RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) riskHive ERM
Dilkush
BS48 4PG, Bristol
United Kingdom
www.riskhive.com
Ian BAKER
Founding Director and Futurologist
+44 12 75 54 58 74/+44 78 18 89 89 97
ian.baker@riskhive.com
Particularities and differentiating factors
For over 25 years, organisations across Australasia, EMEA, and the Americas have
trusted riskHive® for ERM solutions. The web‑based riskHive ERM® platform enables
fast, cost‑effective centralisation of risk data and supports managing and reporting
risks, opportunities, issues, actions, and dependencies in one integrated environment.
Sectors of implemented projects .......................... Industry and Services (70 %), Public Sector (30 %)
Average number of users per solution ................ From 501 to 2000
RMIS average implementation duration...............1 month
Creation date ...................................15/11/2000
Global workforce ..............................................14
RMIS workforce...................................................6
RMIS implementation workforce ...................6
RMIS R&D workforce .........................................3
Solution(s) ........................................................... riskHive Enterprise Risk Manager®- Enterprise Risk Management Solution (Cloud or on-
premesis). riskHive Arrisca Risk Analyser - audit & assurance tool to help you to understand any
spreadsheet and run Monte Carlo Simulation and Analysis.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... • Provides enterprise-wide risk control and oversight to improve business performance
• Centralises, speeds-up and improves risk reporting and disclosure across the portfolio
• Rolls- up risk information to provide a clearer foundation for decision making, by improving
the articulation and de-duplication of risks, assumptions and issues.
• Helps compliance with regulations and standards, including emerging risk management.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 40 7 5 1 5 7
In the last 12 months 2 0 1 0 1 1
RISKHIVE ERM
Area(s) of presence:
>America (North, South)
>Asia (South East)
>Europe
>Oceania
105RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) RISKID
RISKID
Rotterdamseweg 183 C
2629 HD, Delft
Netherlands
www.riskid.nl
Calvin LEE
Managing Director
+31 1 52 68 25 68/+31 6 28 99 81 33
calvin.lee@riskid.nl
Particularities and differentiating factors
RISKID is a risk management tool that focuses on two aspects: Collaboration and
Ease of Use. We believe effective risk management can only be achieved by involving
all stakeholders and raising their risk awareness. In a very simple and practical way.
Sectors of implemented projects .......................... Insurance (5 %), Industry and Services (25 %), Public Sector (50 %), Others (20 %)
Average number of users per solution ................ From 51 to 100
RMIS average implementation duration...............2 months
Creation date ...................................24/03/2009
Global workforce ..............................................20
RMIS workforce.................................................14
RMIS implementation workforce ...................3
RMIS R&D workforce .........................................4
Solution(s) ........................................................... RISKID: Collaborative Risk Management solution to engage all stakeholders in the RM process.
RISKID Internal Controls & Compliance: Simple Compliance Software for effective risk-based
compliance. RISKID Incidents: Easily register, track, and report incidents.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... RISKID focuses on collaboration and ease of use. While other vendors claim their software is
user-friendly, ours is scientifically proven to be so. While others say their software is effective
and efficient, ours is proven to identify and evaluate risks in 60% less time.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 103 0 10 0 15 0
In the last 12 months 5 0 2 0 2 0
Area(s) of presence:
>Africa (West)
>America (South)
>Asia (East, South East, South West)
>Europe (North, West)
106RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) Riskonnect, Inc.
380 Interstate North Parkway SE, Suite 400
30339, Atlanta, Georgia
United States
www.riskonnect.com
Andrea BRODY
Chief Marketing Officer
+1 (770) 790 4700
andrea.brody@riskonnect.com
Particularities and differentiating factors
Riskonnect is the only risk and compliance solution provider that integrates both
operational and strategic risk for end-to-end visibility. Our unique risk correlation
technology integrates, connects, and correlates risk relationships to present a clear
view of risk impact and influence across the entire extended enterprise.
Sectors of implemented projects .......................... Banking (20 %), Insurance (20 %), Industry and Services (55 %), Public Sector (5 %)
Average number of users per solution ................ From 51 to 100
RMIS average implementation duration............... 3 to 4 months
Creation date ...................................10/08/2010
Global workforce ..........................................1700
RMIS workforce.............................................1400
RMIS implementation workforce ...............800
RMIS R&D workforce .....................................300
Solution(s) ........................................................... Riskonnect IRM: Integrated RMIS, GRC, and BCR application for managing risk, insurance,
and claims. RMIS: Consolidates insured risk data for a clear view of risks. GRC: Enables
risk, compliance, and audit professionals to share data and collaborate. Resilience: Helps
organizations with impact analyses, stakeholder engagement, compliance, and readiness.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Riskonnect provides an enterprise system that integrates AI analytics for risk management and
claims processing. Only Riskonnect offers: • Market-leading insurance renewal processing • AI risk
intelligence • Configurable business rules and workflows • Integrated GRC, ERM, and Resilience
modules • Multi-lingual and multi-currency support • Extensive certificate management.
Solution architecture ........................................Several distinct applications, but with interfaces
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 679 81 0 1632 0 423
In the last 12 months 4! 5 0 132 0 11
RISKONNECT
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
107RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) RISMO
risk on mind
Postgasse 16/21
1010, Vienna
Austria
www.riskonmind.eu
Stephan DORNER
Managing Director
+43 0 1 34 30 309
stephan.dorner@riskonmind.eu
Particularities and differentiating factors
Risk on mind® offers customized solutions for governance, risk and compliance (GRC)
and helps companies to manage risks efficiently and meet legal requirements. With
the rismo® software, which was developed by risk on mind risk managers, companies
can record, assess and manage risks quickly and intuitively. By taking an economically
oriented and solution-focused approach to consulting, risk on mind® helps companies
to strengthen their resilience, ensure long-term success and guarantee insurability.
Sectors of implemented projects .......................... Insurance (10 %), Industry and Services (85 %), Public Sector (5 %)
Average number of users per solution ................ From 51 to 100
RMIS average implementation duration............... 3 to 6 month
Creation date ...................................01/01/2018
Global workforce ..............................................18
RMIS workforce...................................................7
RMIS implementation workforce ...................5
RMIS R&D workforce .........................................3
Solution(s) ...........................................................rismo
Main focus ...........................................................Other
Strengths according to the vendor ............... rismo is a tool for the whole qualitative risk management process from the analysis, data
collection, document management, AI-Scoring, Risk measures including all necessary
reporting features. Special functionality is the risk transfer and value declaration for insurance
requirements.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 25 0 0 0 0 0
In the last 12 months 15 0 0 0 0 0
Area(s) of presence:
>Europe
108RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) ROK SOLUTION
3 rue du faubourg St Honoré
75008, Paris
France
www.rok-solution.com
Nicolas VIZCAINO
Project Manager
+33 (0) 1 42 51 81 98/+33 (0) 7 69 40 72 60
nicolas.vizcaino@rok-solution.com
Particularities and differentiating factors
ROK publishes ROK Solution collaborative platform; which is the first on the market,
which includes in a cloud based integrated IBPMS, RPA, IA and IAM features. Risks
management and compliance, performance indicators and document management, in
addition of a native unified communication platform (Mail, chat, Voice and video chat)
are included in our product offer. In addition, we’ve also developed a feature which
allow our customers managing SAP authorization and segregation of duties since 2019.
Sectors of implemented projects .......................... Banking (20 %), Insurance (10 %), Industry and Services (60 %), Public Sector (10 %)
Average number of users per solution ................ More than 1000
RMIS average implementation duration...............9 months
Creation date ...................................29/11/2007
Global workforce ..............................................10
RMIS workforce...................................................3
RMIS implementation workforce ...................2
RMIS R&D workforce .........................................3
Solution(s) ........................................................... ROK Solution: Risks & Internal control module - Risks referential definition - Controls points
definition - Link risks to organization. Activities (Process)-Risks link - Risks notations (Impact/
Probability) - Defined perimeter (Organization, job family, process etc.) controls evaluation -
Action plans setting while being linked to control points evaluation.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... ROK avaibility to link organization, processes, risks, IT and document management in order to
form a coherent whole, which allows management to visualize the same information regarding
different approaches (Procedure or Risk management lines).
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 2 - - - - -
In the last 12 months - - - - - -
ROK SOLUTION
Area(s) of presence:
>Europe (West)
109RMIS PANORAMA 2026
Please use arrows to easily navigate
<<Nom 2>>
<<address>>
<<CP>>, <<ville>>
<<pays>>
<<site web>>
<<prénom>> <<nom>>
<<fonction>>
<<tel>> / <<tel mob>>
<<email>>
Particularities and differentiating factors
<<Particularités…>>
Creation date ................................<<date créa>>
Global workforce .................. <<effectif global>>
RMIS workforce.........................<<effectif sgir>>
RMIS implementation workforce .....<<effectif
intégr>>
RMIS R&D workforce ...........................<<R&D>>Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update)
Area(s) of presence:
>Africa (Central, West)
>America (North, South)
>Asia (South, South East)
>Europe (East, West)
>Oceania
VENDOR SELF-ASSESSMENT
SAI360 B.V.
Hambakenwetering 1
5231DD,, S’Hertogenbosch
Netherlands
www.sai360.com
Frédéric BARON
Business Development Manager
+33 (0) 1 59 13 47 33 / -
frederic.baron@sai360.com
Particularities and differentiating factors
SAI360’s GRC Software helps organizations seamlessly balance ethics, risk, and
compliance with an integrated solution that manages all types of risks while
supporting a risk-aware compliance program. Leverage the most connected
integrated risk management (RMIS) software platform and industry-leading content
to see and manage risk from every angle for a more agile, risk-aware culture.
Sectors of implemented projects .......................... Banking (35 %), Insurance (25 %), Industry and Services (20 %), Public Sector (15 %),
Others (5 %)
Average number of users per solution ................ From 201 to 500
RMIS average implementation duration............... 4 to 6 months
Creation date ...................................01/01/2000
Global workforce ............................................522
RMIS workforce...............................................300
RMIS implementation workforce .................20
RMIS R&D workforce .....................................100
Solution(s) ........................................................... SAI360 EGRC is an integrated platform including Business Continuity, Enterprise & Operational
Risk, IT Risk, Third‑Party Risk Management, Horizon Scanning, Incident Management, Internal
Audit and Internal Controls. It also covers Disclosure Management, Conflicts of Interest, Gifts &
Hospitality, Regulatory Change Management, Policy Management, Ethics & Compliance Training,
Whistleblowing & Case Management, and CSRD/EUDR Reporting.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... SAI360’s GRC platform unifies ethics/learning, risk, and compliance with automated workflows,
AI insights, and flexible integrations improving visibility and accelerating data driven decisions in
complex global environments.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 300 34 11 700 25 15
In the last 12 months 15 2 5 35 6 3
SAI360
110RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) Schleupen SE
Otto-Hahn-St. 20
67100, Strasbourg
France
https://grc.schleupen.de/fr/
Samuel WEIGEL
Manager France, BeNeLux & Suisse romande
+33 (0) 6 36 91 01 31
samuel.weigel@schleupen.de
Particularities and differentiating factors
Our GRC software stands out with its comprehensive coverage of risk, compliance,
CSRD, supply chain act, internal control, audit, and IT security. It adapts to all maturity
levels, offers customizable features within a standardized framework, and ensures
compliance with regulations—delivering unmatched flexibility, scalability, and
efficiency for businesses.
Sectors of implemented projects .......................... Banking (1 %), Insurance (10 %), Industry and Services (35 %), Public Sector (25 %),
Others (29 %)
Average number of users per solution ................ From 51 to 100
RMIS average implementation duration............... 1 month or less
Creation date ...................................01/08/1970
Global workforce ............................................600
RMIS workforce.................................................45
RMIS implementation workforce .................13
RMIS R&D workforce .......................................37
Solution(s) ........................................................... R2C: risk management, MC simulation, compliance & whistleblowing, internal control, audit,
policy management, incident management, information security management & GDPR, BCM,
CSRD (double materiality), AI integration.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Comprehensive standard software, yet flexibly adaptable to specific company needs. Available as
SaaS or on-premise solution.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 520 0 5 0 0 0
In the last 12 months 20 0 1 0 0 0
SCHLEUPEN
Area(s) of presence:
>Asia (Central and North, South West)
>Europe
111RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) SERVICENOW
ServiceNow
Dueo Building, 5 Boulevard Gallieni
92130, Issy-les-Moulineaux
France
www.servicenow.com
Antoine ROUSSEAU
Solution Sales Manager - Risk & Security
+33 (0) 6 11 12 79 92
antoine.rousseau@servicenow.com
Particularities and differentiating factors
ServiceNow Integrated Risk Management offers a unified platform to manage
operational risks associated with key assets (technology, 3rd parties, facilities, people,
data) involved in ERM. It enables automation to improve productivity delivering
higher assurance levels with real-time insight to identify operational and security
vulnerabilities. The solution includes customizable reporting, AI-powered analytics,
and a user-friendly interface for insightful decision-making.
Creation date ...................................01/01/2003
Global workforce .......................................17000
RMIS workforce.............................................2300
RMIS implementation workforce ...............350
RMIS R&D workforce .....................................450
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
Sectors of implemented projects .......................... Banking (25 %), Insurance (15 %), Industry and Services (15 %), Public Sector (10 %),
Others (35 %)
Average number of users per solution ................ More than 1000
RMIS average implementation duration............... 4 to 8 months
Solution(s) ........................................................... Integrated Risk Management
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... - Platform: A single platform, a single data model and a single architecture that associates
assets (people, facilities, technology, third parties and data) with advanced automation and
ease of configuration to easily adapt to changes in methodology, regulations, etc. - Integration:
Natively integrates with ServiceNow solutions (ITSM, SPM, ITAM), internal systems of records,
including third-party systems (Teams), delivering many efficiencies. - Innovation: Innovative and
aggressive product roadmap, allowing your 3 lines of defense to benefit from functional but also
technological developments (generative AI/AI Agents) with regular quarterly release cycle.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 400 10 70 750 60 60
In the last 12 months 85 2 16 90 10 9
112RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) Smart Global Governance
300 rue du Vallon
06560, Sophia-Antipolis
France
www.smartglobalgovernance.com
Olivier GUILLO
CEO
+33 (0) 4 12 39 14 71
olivier.guillo@smartglobal.com
Particularities and differentiating factors
Smart Global Governance offers the agile ecosystem that turns your challenges
into opportunities to simplify, automate, and manage your governance, risk, and
compliance priorities. An ecosystem of independent, interconnected software
solutions – use a single module or combine several to boost your productivity.
Creation date ...................................19/09/2019
Global workforce ..............................................55
RMIS workforce.................................................55
RMIS implementation workforce ...................4
RMIS R&D workforce .......................................15
SMART GLOBAL GOVERNANCE
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
Sectors of implemented projects .......................... Banking (5 %), Insurance (15 %), Industry and Services (30 %), Public Sector (5 %),
Others (45 %)
Average number of users per solution ................ More than 1000
RMIS average implementation duration...............2 months
Solution(s) ........................................................... Smart Global Governance’s ecosystem
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Smart Global Governance provides a modular ecosystem for governance, risk, and compliance,
offering up to 40% efficiency improvement. Automating repetitive tasks liberates teams for
strategic initiatives. Recognized globally and certified by ISO 27001, our solutions are secure,
scalable, and adaptable to your needs. Trusted by 300,000 users across 100 countries .
Solution architecture ........................................Several distinct applications, but with interfaces
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 65 6 6 11 11 2
In the last 12 months 15 1 1 1 1 1
113RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) SWISS GRC
Swiss GRC
Hirschmattstrasse 36
6003, Lucerne
Switzerland
www.swissgrc.com
Yahya Mohamed MAO
Head Marketing & Communications
+41 41 220 75 15
yahya.mao@swissgrc.com
Particularities and differentiating factors
Swiss GRC exemplifies Swiss precision and quality, offering advanced software
technology in Governance, Risk, and Compliance, as well as Contract Lifecycle
Management (CLM) and Business Process Management (BPM). The company’s
differentiation lies in its wealth of expertise and tailored approach, resulting in efficiency
and the ability to meet clients’ unique needs with high-quality standards. This mirrors
Switzerland’s reputation for meticulousness and excellence across various sectors.
Creation date ...................................28/12/2016
Global workforce ..............................................65
RMIS workforce.................................................60
RMIS implementation workforce .................30
RMIS R&D workforce .........................................5
Area(s) of presence:
>America (Central, North)
>Asia (South, South East, South West)
>Europe (Central and East, West)
Sectors of implemented projects .......................... Banking (20 %), Insurance (25 %), Industry and Services (20 %), Public Sector (15 %),
Others (20 %)
Average number of users per solution ................ From 51 to 100
RMIS average implementation duration...............3 months
Solution(s) ...........................................................GRC Toolbox
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... The GRC Toolbox by Swiss GRC is a SharePoint-based, highly configurable solution that
simplifies risk and compliance management. It seamlessly integrates into existing IT landscapes,
supports global standards, and offers flexible deployment (On-Premise, Private Cloud, SaaS).
With powerful automation, real-time insights, and multilingual support, it ensures efficiency and
regulatory compliance.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 200 0 8 1 0 0
In the last 12 months 25 0 4 1 0 0
114RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) Wolters Kluwer TeamMate
30 Churchill Place, 8th Floor
E14 0YA, London
United Kingdom
www.wolterskluwer.com
Mulder BRITT
Senior Digital Marketing & Events Specialist
+44 79 77 82 76 77
britt.mulder@wolterskluwer.com
Particularities and differentiating factors
TeamMate, a business unit of Wolters Kluwer, is one of the world’s leading audit
expert solutions. Over 3,000 audit and inspections departments, including 400 banks,
around the world, of all sizes and in all sectors, use TeamMate+ Audit on a daily basis
for their audit work.
Creation date ...................................01/03/1994
Global workforce .......................................23000
RMIS workforce....................................................-
RMIS implementation workforce ....................-
RMIS R&D workforce ..........................................-
TEAMMATE
Area(s) of presence:
>Africa
>America
>Asia
>Europe
>Oceania
Sectors of implemented projects .......................... Banking (30 %), Insurance (10 %), Industry and Services (35 %), Public Sector (20 %),
Others (5 %)
Average number of users per solution ................ From 6 to 50
RMIS average implementation duration...............-
Solution(s) ........................................................... TeamMate+ Audit: Internal Audit and Risk Management; TeamMate Analytics: Data Analytics;
TeamMate+ Controls: Internal Control.
Main focus ...........................................................Audit
Strengths according to the vendor ............... TeamMate+ is specialised in Audit. The solution was created by Auditors for Auditors and is built
for purpose to assist audit teams efficiently and effectively move through the audit workflow:
from establishing annual plans to planning audits, from fieldwork and execution to reporting,
closing audits and follow-up.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total - - - - - -
In the last 12 months - - - - - -
115RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) VALUES ASSOCIATES
Values Associates
49 rue de Ponthieu
75008, Paris
France
www.values-associates.fr
Louis FREMONT
Sales Manager
+33 (0) 1 80 88 66 22/+33 (0) 6 67 67 57 19
louis.fremont@values-associates.com
Particularities and differentiating factors
We are a French publisher of an innovative no code platform focused on digitizing
a variety of activities covering the management of Risks, Internal Control, Internal
Audit and Compliance. We offer a range from standard to custom-made solutions,
everything can be customized. User performance and experience are central, with a
strong focus on data visualization.
Creation date ...................................05/01/2007
Global workforce ..............................................20
RMIS workforce.................................................20
RMIS implementation workforce .................10
RMIS R&D workforce .........................................6
Area(s) of presence:
>Africa (Central, North, West)
>Asia (East, South East, South West)
>Europe (West)
Sectors of implemented projects .......................... Banking (10 %), Insurance (10 %), Industry and Services (70 %), Public Sector (10 %)
Average number of users per solution ................ From 201 to 500
RMIS average implementation duration...............2 months
Solution(s) ........................................................... Risk Mapping: Visualize and assess risks for proactive management. Internal Control: Centralize
documentation and automate monitoring. Internal Audit: Customized to your needs. Sapin 2 :
Anti-corruption compliance modules. Third-Party Risk Management: Simplify and centralize risk
identification.
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... An integrated, intuitive, collaborative, and open solution, deployed in a few weeks. The no-code
approach allows full customization (fields, forms, workflows, profiles, reports) to quickly adapt to
your activities and organization.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 34 1 1 0 0 0
In the last 12 months 13 0 0 0 0 0
116RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) VirtueSpark GmbH
Christoph Merian-Ring 11
4153, Reinach
Switzerland
www.virtuespark.com
Pascal BUSCH
Founder
+41 6 14 13 80 00
contact@virtuespark.com
Particularities and differentiating factors
VirtueSpark focuses on integrated risk and decision management. The platform
enables to control all operational risk and compliance activities and to connect them
with objectives, processes and assets. Led by a vastly experienced team of experts,
VirtueSpark offers consultancy and advanced technology to companies large or
small.
Sectors of implemented projects .......................... Banking (20 %), Industry and Services (80 %)
Average number of users per solution ................ From 101 to 200
RMIS average implementation duration...............3 months
Creation date ...................................17/06/2017
Global workforce ................................................7
RMIS workforce...................................................4
RMIS implementation workforce ...................4
RMIS R&D workforce .........................................2
Solution(s) ........................................................... VirtueSpark Enterprise Platform for GRC
Main focus ...........................................................Risk Management
Strengths according to the vendor ............... Aimed at decision-makers and caring to make life simple for the user, VirtueSpark offers
an intuitive easy-to-use platform for systemic risk identification across the company and
value-chain. Its “autonomous collaboration” features enable operational risk and compliance
collaboration across business units, while supporting individual risk management approaches.
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 6 0 0 0 0 0
In the last 12 months 2 0 0 0 0 0
VIRTUESPARK
Area(s) of presence:
>Europe
117RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Configuration Work-ows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Artificial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) VISIATIV
Visiativ
212 rue de Bercy
75012, Paris
France
www.visiativ.com
Christophe BOUVARD
Managing Director
+33 (0) 4 78 87 29 29/+33 (0) 6 37 85 89 17
christophe.bouvard@visiativ.com
Particularities and differentiating factors
VISIATIV publishes and integrates a collaborative RIMS platform for its clients to
manage Risks and Insurance Data. iSIGR is a collaborative platform adapted for your
actual environment and ready to your future evolutions.
Sectors of implemented projects .......................... Industry and Services (100 %)
Average number of users per solution ................ From 101 to 200
RMIS average implementation duration...............4 months
Creation date ...................................05/04/2004
Global workforce ..........................................1700
RMIS workforce.................................................25
RMIS implementation workforce .................20
RMIS R&D workforce .........................................5
Solution(s) ........................................................... VISIATIV-SIGR platform including modules for: Inventory of insured assets (Value collection),
Policies & Premiums, Claims, Prevention, Predict-climate-weather, Risk Grids & Action Plans,
Geo-decision-making Vision, Insurance Certificate, Chatbot.
Main focus ...........................................................Other
Strengths according to the vendor ............... A standard tool with configurations (labels, forms, workflows, modules...).
Solution architecture ........................................A single application with several modules
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 16 - - - - -
In the last 12 months 3 - - - - -
Area(s) of presence:
>Africa (South)
>America
>Asia
>Europe
>Oceania
118RMIS PANORAMA 2026
Please use arrows to easily navigate
Technical axes coverage
Reportings
Import
Export
Mobility
Documentation
Con-guration Workfiows
Organization
Security
Architecture
Access/Authentication
Functional modules coverage
Data Privacy
Cybersecurity
Analytics
Arti-cial Intelligence
BCP and Crisis
Management
Third Party Risk
Management
ESG
Quality
Incidents Management
Risk Management on Prevention
Action Plans
Insurance
Internal Control
Governance
Compliance
Risk Mapping
Audit
Languages
Currencies
GENERAL INFORMATION
VENDOR SELF-ASSESSMENT (2025 update) Workiva
4 rue Jules Lefebvre
75009, Paris
France
www.workiva.com
Robyn BONNIN
SPMM
+31 6 33 78 45 45
robyn.bonnin@workiva.com
Particularities and differentiating factors
Workiva is the world’s leading connected reporting and compliance platform.
Establish a connected, transparent, and continuous GRC reporting process within the
Workiva platform. Workiva enables you to connect data across outputs with complete
control, from early risk identification to final reports.
Sectors of implemented projects .......................... Banking (8 %), Insurance (13 %), Industry and Services (4 %), Public Sector (2 %),
Others (73 %)
Average number of users per solution ................ From 6 to 50
RMIS average implementation duration...............2 months
Creation date ...................................01/09/2008
Global workforce ..........................................2908
RMIS workforce....................................................-
RMIS implementation workforce ....................-
RMIS R&D workforce ..........................................-
Number of RMIS clients In Europe In Africa In Asia In North America In South America In Oceania
Total 255 40 41 3592 84 16
In the last 12 months 110 15 30 400 35 12
WORKIVA
Area(s) of presence:
>Africa (South)
>America
>Asia
>Europe
>Oceania
Solution(s) ........................................................... Enterprise Risk Management, Internal Controls Management, Internal Audit Management, SOX
Management, Policy & Procedures, Certifications/Attestations, Operational Risk Management,
CASS, IT Risk Management, Control Management Essentials, CGC Compliance, Compliance
Manager, ESG, Assurance, SAPIN ll.
Main focus ...........................................................Other
Strengths according to the vendor ............... Unify people, processes and data to deliver accurate reports required by regulators, leadership
and shareholders. Workiva connects data with context across spreadsheets, documents and
presentations to increase trust in your outputs. Improve productivity with built-in workflow and
automation that scales to teams of all sizes.
Solution architecture ........................................A single application with several modules
119RMIS PANORAMA 2026
Please use arrows to easily navigate
APPENDIX 1
Risk Managers’ respondents geographical presence
REGIONS COUNTRIES
Africa North Tunisia
Africa West Gambia
America Central Panama
America North Canada, United States
Asia East China, Taiwan
Asia South Afghanistan, India
Asia South East Philippines, Malaysia, Singapore, Thailand
Asia South West Saudi Arabia
Europe North Ireland, Lithuania
Europe West Belgium, France, Germany, Italy, Luxembourg, Slovenia,
Spain, SwitzerlandRMIS PANORAMA 2026
120
Please use arrows to easily navigate
APPENDIX 2
Vendors’ geographical presence
REGIONS COUNTRIES
AFR Central
360inControl - Acuredge - Archer - ARIS - Bizzdesign - Corporater - Crisam - Delta RM - Diot-Siaci - easylience - EGERIE -
Empowered - IBM OpenPages - KerMobile - Moody's - Optimiso - PocketResult - Qualitadd - Riskonnect - SAI360 - ServiceNow -
Smart Global Governance - TeamMate - Values Associates
AFR East 360inControl - Acuredge - Archer - ARIS - Bizzdesign - CERRIX - Corporater - Crisam - Delta RM - Diot-Siaci - easylience - EGERIE
- Empowered - IBM OpenPages - KerMobile - Moody's - PocketResult - Qualitadd - Riskonnect - ServiceNow - Smart Global
Governance - TeamMate
AFR North 360inControl - Acuredge - Alea360 - Améthyste - Archer - Arengi - ARIS - Bizzdesign - BlackRock (eFront) - CoAudit - CRIF AG
- Crisam - Delta RM - Diligent - Diot-Siaci - easylience - EGERIE - Empowered - Grace Connect GRC - IBM OpenPages - Inclus
- KerMobile - Moody's - My Risk io. - Novasecur - Oxial - PocketResult - Qualitadd - Riskonnect - ServiceNow - Smart Global
Governance - TeamMate - Values Associates
AFR South 1-One - 360inControl - Archer - BIC GRC - BlackRock (eFront) - CERRIX - Challenge Optimum - CoAudit - Corporater - CRIF AG -
Diligent - Diot-Siaci - easylience - Empowered - IBM OpenPages - KerMobile - Maptycs - Optimiso - Prewave - Qualitadd - RISKID
- rismo - ServiceNow - Swiss GRC - TeamMate - VirtueSpark - Workiva
AFR West 360inControl - Acuredge - Améthyste - Archer - ARIS - Bizzdesign - Corporater - Delta RM - Diot-Siaci - easylience - EGERIE
- Empowered - IBM OpenPages - KerMobile - Moody's - Optimiso - PocketResult - Qualitadd - RISKID - Riskonnect - SAI360 -
ServiceNow - Smart Global Governance - TeamMate - Values Associates
America Central360inControl - Archer - ARIS - BIC GRC - Bizzdesign - CERRIX - Challenge Optimum - Corporater - CRIF AG - Crisam - Delta RM
- Diligent - easylience - EGERIE - Empowered - IBM OpenPages - Inclus - KerMobile - LogicManager - Moody's - Optimiso - Optro -
Prewave - Riskonnect - ServiceNow - Smart Global Governance - Swiss GRC - TeamMate - Visiativ - Workiva
America North360inControl - Archer - Arengi - ARIS - BIC GRC - Bizzdesign - BlackRock (eFront) - CoAudit - Corporater - CRIF AG - Crisam - Delta
RM - Diligent - Diot-Siaci - easylience - EGERIE - Empowered - IBM OpenPages - Inclus - KerMobile - LogicManager - Maptycs -
Moody's - My Risk io. - Novasecur - OneTrust - Optro - Prewave - Qualitadd - Riskonnect - SAI360 - ServiceNow - Smart Global
Governance - Swiss GRC - TeamMate - Visiativ - Workiva
America South360inControl - Archer - ARIS - BIC GRC - Bizzdesign - BlackRock (eFront) - CERRIX - CRIF AG - Crisam - Delta RM - Diligent -
easylience - EGERIE - Empowered - IBM OpenPages - Inclus - KerMobile - Moody's - Optimiso - Prewave - Qualitadd - riskHive ERM
- RISKID - Riskonnect - SAI360 - ServiceNow - Smart Global Governance - TeamMate - Visiativ - Workiva
Asia Central360inControl - Archer - ARIS - Bizzdesign - CRIF AG - Crisam - Delta RM - Diligent - Diot-Siaci - easylience - EGERIE - Empowered
- IBM OpenPages - KerMobile - Moody's - OneTrust - Optro - PocketResult - Riskonnect - ServiceNow - Smart Global Governance -
TeamMate - Visiativ - Workiva
Asia East 360inControl - Archer - ARIS - Bizzdesign - BlackRock (eFront) - CRIF AG - Crisam - Delta RM - Diligent - Diot-Siaci - easylience - EGERIE -
Empowered - IBM OpenPages - KerMobile - Moody's - Novasecur - Optro - PocketResult - RISKID - Riskonnect - ServiceNow - Smart Global
Governance - TeamMate - Values Associates - Visiativ - Workiva
Asia North 360inControl - Archer - ARIS - Bizzdesign - CRIF AG - Crisam - Delta RM - Diligent - Diot-Siaci - easylience - EGERIE - Empowered
- IBM OpenPages - KerMobile - Moody's - Optro - PocketResult - Riskonnect - Schleupen - ServiceNow - Smart Global Governance -
TeamMate - Visiativ - Workiva
Asia South 360inControl - Archer - ARIS - Bizzdesign - Corporater - CRIF AG - Crisam - Delta RM - Diligent - Diot-Siaci - easylience - EGERIE
- Empowered - IBM OpenPages - KerMobile - Moody's - Novasecur - Optro - PocketResult - Prewave - Riskonnect - SAI360 -
ServiceNow - Smart Global Governance - Swiss GRC - TeamMate - Visiativ - Workiva
Asia South East360inControl - Améthyste - Archer - ARIS - Bizzdesign - Challenge Optimum - Corporater - CRIF AG - Crisam - Delta RM - Diligent
- Diot-Siaci - easylience - EGERIE - Empowered - IBM OpenPages - KerMobile - Maptycs - Moody's - Optro - PocketResult - riskHive
ERM - RISKID - Riskonnect - SAI360 - ServiceNow - Smart Global Governance - Swiss GRC - TeamMate - Values Associates -
Visiativ - Workiva
Asia South West360inControl - Acuredge - Archer - ARIS - BIC GRC - Bizzdesign - BlackRock (eFront) - Corporater - CRIF AG - Crisam - Delta
RM - Diligent - Diot-Siaci - easylience - EGERIE - Empowered - IBM OpenPages - KerMobile - LogicManager - Moody's - Optimiso -
Optro - PocketResult - RISKID - Riskonnect - Schleupen - ServiceNow - Smart Global Governance - Swiss GRC - TeamMate - Values
Associates - Visiativ - Workiva
Europe Central360inControl - Acuredge - Améthyste - Archer - ARIS - BIC GRC - Bizzdesign - BlackRock (eFront) - CERRIX - Challenge Optimum -
CoAudit - Corporater - CRIF AG - Crisam - Delta RM - Diligent - Diot-Siaci - easylience - EGERIE - Empowered - Grace Connect GRC -
IBM OpenPages - Inclus - KerMobile - Maptycs - Moody's - Novasecur - OneTrust - Optimiso - Optro - Oxial - PocketResult - Prewave
- Qualitadd - Riskonnect - rismo - Schleupen - ServiceNow - Smart Global Governance - Swiss GRC - TeamMate - VirtueSpark
- Visiativ - Workiva
Europe East 360inControl - Acuredge - Améthyste - Archer - ARIS - BIC GRC - Bizzdesign - CoAudit - Corporater - CRIF AG - Crisam - Delta
RM - Diligent - Diot-Siaci - easylience - EGERIE - Empowered - Grace Connect GRC - IBM OpenPages - Inclus - KerMobile - Moody's
- Novasecur - Optro - PocketResult - Prewave - Qualitadd - riskHive ERM - Riskonnect - rismo - SAI360 - Schleupen - ServiceNow -
Smart Global Governance - TeamMate - VirtueSpark - Visiativ - Workiva
Europe North360inControl - Acuredge - Améthyste - Archer - ARIS - BIC GRC - Bizzdesign - BlackRock (eFront) - CERRIX - CoAudit - Corporater
- CRIF AG - Crisam - Delta RM - Diligent - Diot-Siaci - easylience - EGERIE - Empowered - Grace Connect GRC - IBM OpenPages
- Inclus - KerMobile - Maptycs - Moody's - Novasecur - OneTrust - Optro - PocketResult - Prewave - Qualitadd - riskHive ERM -
RISKID - Riskonnect - rismo - Schleupen - ServiceNow - Smart Global Governance - TeamMate - VirtueSpark - Visiativ - Workiva
Europe West 1-One - 360inControl - Acuredge - Améthyste - Archer - Arengi - ARIS - BIC GRC - Bizzdesign - BlackRock (eFront) - CERRIX - Challenge
Optimum - CoAudit - Corporater - CRIF AG - Crisam - Delta RM - Diligent - Diot-Siaci - easylience - EGERIE - Empowered - Grace Connect
GRC - IBM OpenPages - Inclus - KerMobile - LogicManager - Maptycs - Moody's - My Risk io. - Novasecur - OneTrust - Optimiso - Optro - Oxial -
PocketResult - Prewave - Quadratic - Qualitadd - riskHive ERM - RISKID - Riskonnect - rismo - ROK Solution - SAI360 - Schleupen - ServiceNow
- Smart Global Governance - Swiss GRC - TeamMate - Values Associates - VirtueSpark - Visiativ - Workiva
Oceania 360inControl - Archer - ARIS - BIC GRC - Bizzdesign - BlackRock (eFront) - Corporater - CRIF AG - Crisam - Delta RM - Diligent - easylience
- EGERIE - Empowered - IBM OpenPages - KerMobile - LogicManager - Moody's - OneTrust - Optimiso - PocketResult - Qualitadd - riskHive
ERM - Riskonnect - SAI360 - ServiceNow - Smart Global Governance - TeamMate - Visiativ - WorkivaRMIS PANORAMA 2026
121
Please use arrows to easily navigate
APPENDIX 3
Description of functional modules and technical axes
Functional modules
Risk Mapping >Risk Identification and formalization, Management of a Risk Library, Linkage to strategic objectives
>Risk Evaluation (qualitative or quantitative) and Prioritization
>Risk Indicator Monitoring, Alert thresholds
>Credit, Market and Financial Risk Management (Basel 3)
Internal Control >Identification of controls and link with processes
>Management of self assessment campaigns
Audit >Audit plan management
>Management of Auditing missions, schedules and work programs
Compliance >Compliance with regulations, internal or external standards (interfaces with content providers), self assessments
Governance >Management of the organization, Risk Management policies and decisions
>Dashboards with key indicators, budget management
Action Plans >Actions and Action Plans management (allocation, planning follow-up...)
Insurance >Premium allocation management
>Calculation of premiums pursuant to regulations and contracts
>Follow-up of premium payment history
>Management of Insurance portfolios
>Budget simulations
>Tax identification and follow-up
Incidents Management >Description and follow-up (including financial impact) of incidents managed centrally or not, non-compliance, legal
proceedings, losses, conditional alerts, etc.
>History of financial valuation including compensation process follow-up by item (medical expenses, damages,
material and immaterial damages, etc.)
Risk Management on
Prevention
>Description and management of Risks inspections (planning, documentation, monitoring, etc.)
>Monitoring of Prevention reports and associated notes
>Monitoring of Compliance with regulations and internal or external standards
>Library of prevention / protection measures
>Follow-up of recommendations
Quality >Management of processes, objectives, Quality indicators, non-compliant products, preventive and corrective
actions, specific procedures, etc.
ESG >Ability to manage Sustainability program (metrics, analysis, reporting)
>Ability to support different protocol out of the box: GHG, Emission scope…
>Ability to manage CSR initiatives and other related activities
Third Party Risk
Management
>Provision of third-party libraries
>Enable the set-up, distribution, delegation, collection and follow-up of one or more third party questionnaires (SIG,
GDPR, ISO 27001, etc.)
>Calculate a Risk (inherent and residual) of a third party
>Identify atypical or exceptional transactions
>Provide a consolidated mapping of third-party Risks by process, geography, criticality, etc. ...
>Possibility to manage controls and Audits on third parties
>Possibility of managing third parties through the use of alerts with automated action triggers
BCP and Crisis
Management
>Formalization and use of BCP models
>Impact on Activities Assessment (IAA) and interface with the corporate directory
>Maintenance in operational conditions (MOC); Asset management
>Crisis Management support"
Cybersecurity >Ability to scope ISMS and document Statement of Applicability
>Manage security incidents and vulnerabilities
>Vulnerability Scans
Data Privacy >Perform initial Data Privacy assessment and impact assessment
>Ability to monitor Compliance policy to Data Privacy and detect and manage breaches
>Data Privacy reporting library ready to use for Compliance purposesRMIS PANORAMA 2026
122
Please use arrows to easily navigate
Technical axes
Access/Authentication >User access security policy, user management, segregation of duties
>Delegation of administration rights
>Management of user authorizations and Data confidentiality
Security >Data flow securization
>Users actions traceability
>Penetration testing/vulnerability auditing
>Sensitive data encryption in the database
Architecture >Type of architecture and hosting used (rich client, Application Service Provider, etc.)
>Possible database solutions and programming languages
>Logical security of the technical platform
Organization >Management of tree structures (with more than five levels) along multiple areas and with multiple repositories
>Management of different employees or various assets (facilities, vehicles, etc.) attached to the tree-structure
entities (including processes)
>Matching of legal and organizational Data
Languages >Available languages other than French
>Existence of a complete RMIS version in French
>Management of Data and label dictionaries
>Language management by a client administrator
Currencies >Default currency
>Other possible currencies
>Multiple currency conversion engine
Workflows >Alert triggering thresholds and workflow customization
>Tool functionalities for sending emails/SMS, using a mailing list or other
>Pre-set workflow management with scheduling and task follow-up functionalities
>Reporting possibilities on workflow information
Configuration >Screen customization by the client
>Screen customization by the vendor
>Other functionalities for the client
Mobility >RMIS capacities to adapt itself to mobile devices (smartphones, touch pads …)
>Responsive Design
Documentation >Document attachment
>Document management capabilities
Export >Pre-set export formats
>Extracting and exporting Data in xls, dbf or other formats (for use in spreadsheets or databases) for external use
>Defining export perimeters, selecting Data for exports and limiting and restricting exported scope and Data
Import >Import management by a client administrator or an authorized user
>Import of external Data sources in an appropriate format
Reportings >Business Intelligence
>Existence of an integrated reporting tool
>Interfacing with reporting tools and ETL
>Management of analysis criteria
>Available reports and supported formats
Analytics >Ability to be connected to several Data sources (ERP or others)
>Library of ready to use and predefined controls
>Ability to manage Continuous Control Monitoring activities – Exceptions pushed and managed
Artificial Intelligence >Ability to map or integrate into a map via datavisualization information
>Ability to analyze and evaluate the effectiveness of the Risk Management system in order to produce alternative
recommendations
>Ability to detect weak signals from structured or unstructured Data from multiple sources using Deep Learning
and/or Machine Learning capabilities
>Enable the user of the 1st or 2nd line of control via the use of Natural Language Processing (NLP) to
>Ability to categorize a loss/incident event or match any object to another
>Ability to calculate multiple Risk scenarios and provide simulations with recommendations for decision support
>Highlight information about cognitive biases and deviations in Artificial Intelligence models to effectively manage
model RiskRMIS PANORAMA 2026
123
Please use arrows to easily navigate
APPENDIX 4
Consultation/response results
VENDOR Panorama 2023 Panorama 2024 Panorama 2025 Panorama 2026
Status
2026
ConsultedAnsweredConsultedAnsweredConsultedAnsweredConsultedAnswered
1-One YES YES YES YES YES YES YES YES
360inControl YES YES YES YES YES YES YES YES
80-20 Software YES NO NO NO YES NO YES NO
Acuredge YES YES YES YES YES YES YES YES
Agena YES NO NO NO YES NO YES NO
Alea360 YES YES
NEW
ALL4TEC YES YES YES YES YES NO YES NO
Allgress YES NO NO NO YES NO YES NO
Altarès YES NO NO NO YES NO YES NO
Alyne YES NO NO NO YES NO YES NO
Améthyste YES YES YES YES YES YES YES YES
Aravo YES NO NO NO YES NO YES NO
Archer YES YES YES YES YES YES YES YES
Arengi YES YES YES YES YES YES YES YES
ARIS YES YES YES YES YES YES YES YES
AuSuM YES NO NO NO YES NO YES NO
Avetta YES NO NO NO YES NO YES NO
BIC GRC YES YES YES YES YES YES YES YES
Bizzdesign YES YES YES YES YES YES YES YES
BlackRock (eFront) YES YES YES YES YES YES YES YES
BlueUmbrella YES NO YES NO
CERRIX YES YES YES YES YES YES YES YES
CGERisk YES NO YES NO
Challenge Optimum YES YES YES YES YES YES YES YES
ClearRisk YES NO NO NO YES NO YES NO
CMO Compliance YES NO NO NO YES NO YES NO
NE
CoAudit YES YES YES YES YES YES YES YES
Corporater YES YES YES YES
CovalentSoftware (cf.Ideagen) YES NO YES NO
Crif YES NO YES YES
NEW
Crisam YES YES YES YES YES YES YES YES
Cura Softwere YES NO YES NO
Delta RM YES YES YES YES YES YES YES YES
Diligent YES YES YES YES YES YES YES YES
Diot-Siaci YES YES YES YES YES YES YES YES
Dow Jones YES NO NO NO YES NO YES NO
DWF YES NO NO NO YES NO YES NO
EADS Apsys YES NO NO NO YES NO YES NO
easylience YES YES YES YES YES YES YES YESRMIS PANORAMA 2026
124
Please use arrows to easily navigate
VENDOR Panorama 2023 Panorama 2024 Panorama 2025 Panorama 2026
Status
2026
ConsultedAnsweredConsultedAnsweredConsultedAnsweredConsultedAnswered
EGERIE YES YES YES YES YES YES YES YES
Elseware YES NO NO NO YES NO YES NO
Empowered YES NO NO NO YES YES YES YES
Enablon YES YES YES YES YES NO YES NO
ERM YES NO NO NO YES NO YES NO
F24 YES YES YES NO YES NO
FigtreeSystems (NTTData) YES NO YES NO
Five Sigma Labs YES NO NO NO YES NO YES NO
Fusion Risk Management YES NO NO NO YES NO YES NO
Gecico YES NO NO NO YES NO YES NO
GlobalSuite YES NO YES NO
Grace Connect GRC YES YES YES YES YES YES YES YES
IAMSConseil YES NO YES NO
IBM OpenPages YES NO NO NO YES YES YES YES
Ideagen YES NO NO NO YES NO YES NO
Inclus YES YES YES YES YES YES YES YES
Insurewave YES NO YES NO
Intellinx YES NO YES NO
Ivalua YES NO NO NO YES NO YES NO
iWE YES NO NO NO YES NO YES NO
KerMobile YES YES YES YES YES YES YES YES
LegalSuite YES NO NO NO YES NO YES NO
Legisway YES NO NO NO YES NO YES NO
LexisNexis YES YES YES YES YES NO YES NO
LogicGate YES NO NO NO YES NO YES NO
LogicManager YES NO NO NO YES NO YES YES
NEW
Mageri YES NO NO NO YES NO YES NO
Make IT Safe YES YES YES YES YES NO YES NO
Maptycs YES YES YES YES YES YES YES YES
MeetRisk YES NO NO NO YES NO YES NO
MetricStream YES NO NO NO YES NO YES NO
Mitratech YES YES YES NO YES NO
Moody's YES YES YES YES YES YES
My Risk io. YES YES YES YES YES YES YES YES
Myflisk YES NO NO NO YES NO YES NO
NavexGlobal YES NO YES NO
NEXT Software Solutions YES NO YES NO
Novasecur YES YES YES YES YES YES YES YESRMIS PANORAMA 2026
125
Please use arrows to easily navigate
VENDOR Panorama 2023 Panorama 2024 Panorama 2025 Panorama 2026
Status
2026
ConsultedAnsweredConsultedAnsweredConsultedAnsweredConsultedAnswered
NOweco YES NO NO NO YES NO YES NO
OneConcern YES NO NO NO YES NO YES NO
OneTrust YES YES YES YES YES YES YES YES
Onspring YES NO NO NO YES NO YES NO
Optimiso YES YES YES YES YES YES YES YES
Optirisk NO NO NO NO YES NO YES NO
Optro YES YES YES YES YES YES YES YES
Origami Risk YES YES YES NO
Oxand YES NO NO NO YES NO YES NO
Oxial YES YES YES YES YES YES YES YES
Pcis Vision YES NO NO NO YES NO YES NO
PocketResult YES YES YES YES YES YES
Prevalent YES NO NO NO YES NO YES NO
Prewave YES YES YES YES
ProcessGene YES NO NO NO YES NO YES NO
ProcessUnity YES NO NO NO YES NO YES NO
Prodentia YES NO NO NO YES NO YES NO
ProteusCyber YES NO YES NO
Protiviti YES NO NO NO YES NO YES NO
Pyx24 YES YES YES NO YES NO
Quadratic YES YES YES YES YES YES
Qualitadd YES YES YES YES YES YES YES YES
QuartzIQ YES NO YES NO
Qumas YES NO NO NO YES NO YES NO
ReadiNow YES NO NO NO YES NO YES NO
Reciprocity YES NO NO NO YES NO YES NO
Resilient IA YES NO YES NO
Resolver YES NO NO NO YES NO YES NO
Risk’nTic YES YES YES YES YES NO YES NO
Risk3sixty YES NO NO NO YES NO YES NO
RiskDecisions YES NO YES NO
Riskeeper YES NO NO NO YES NO YES NO
riskHive ERM YES YES YES YES YES YES YES YES
RISKID YES YES YES YES YES YES YES YES
Riskonnect YES YES YES YES YES YES YES YES
RiskPartner YES NO NO NO YES NO YES NO
RiskWatch YES NO NO NO YES NO YES NO
rismo YES YES YES YESRMIS PANORAMA 2026
126
Please use arrows to easily navigate
VENDOR Panorama 2023 Panorama 2024 Panorama 2025 Panorama 2026
Status
2026
ConsultedAnsweredConsultedAnsweredConsultedAnsweredConsultedAnswered
ROK Solution YES YES YES YES YES YES YES YES
SAI360 YES NO YES YES
NEW
SAP YES YES YES YES YES NO YES NO
SAS France YES NO YES NO
Schleupen YES YES YES YES YES YES YES YES
SecondFloor YES NO NO NO YES NO YES NO
ServiceNow YES YES YES YES YES YES YES YES
SideTrade YES NO NO NO YES NO YES NO
Signavio YES NO NO NO YES NO YES NO
Sindup YES NO NO NO YES NO YES NO
Skan1 YES NO NO NO YES NO YES NO
Smart Global Governance YES YES YES YES YES YES YES YES
Spear Tech YES NO NO NO YES NO YES NO
Sphera YES NO NO NO YES NO YES NO
SureCloud YES NO NO NO YES NO YES NO
Swiss GRC YES YES YES YES YES YES
TeamMate YES YES YES YES YES YES YES YES
Théorème YES NO NO NO YES NO YES NO
TinubuSquare YES NO YES NO
TowersWatson YES NO YES NO
Trintech YES NO NO NO YES NO YES NO
Tüv Süd Global Risk Consultants YES YES YES YES YES NO YES NO
Values Associates YES YES YES YES YES YES YES YES
Venminder YES NO NO NO YES NO YES NO
Viclarity YES NO NO NO YES NO YES NO
VirtueSpark YES YES YES YES YES YES YES YES
Visiativ YES YES YES YES YES YES YES YES
VoseSoftware YES NO YES NO
Workiva YES YES YES YES YES YES YES YES
WynyardGroup YES NO YES NORMIS PANORAMA 2026
127
Please use arrows to easily navigate
128
You are a RMIS vendor and you would like to be consulted
for the next edition of the RMIS Panorama?
You just need to contact AMRAE in order to take part to the next campaign.
Please contact:
Géraldine Bruguière-Fontenille: geraldine.bruguiere@amrae.fr
Thomas Dereux: thomas.dereux@amrae.fr
Bertrand Rubio: bertrand.rubio@fr.ey.com
AMRAE – The French Association for Corporate Risk and Insurance Management
AMRAE, the Association for the Management of Corporate Risks and Insurance, brings together key
players in the field of risk management—risk managers, internal controllers and auditors, insurance
professionals, and legal experts.
Through its scientific committees, publications, position papers, and its flagship annual conference,
AMRAE promotes excellence in risk management as a discipline that helps secure corporate strategy
and strengthen organizational resilience..
The Association counts over 2,000 members from 850 private and public organizations.
• Promote the concept of Risk Management • Provide and maintain top-level expertise for Risk
Managers • Anticipate and shape the corporate insurance market • Engage with public authorities and
civil institutions
Through AMRAE Formation, the Association addresses professional training needs by offering high-
level certified courses.
Its flagship event, “Les Rencontres du Risk Management”, is the leading conference for risk and
insurance professionals, gathering more than 4,000 participants in 2026. This three-days event is the
must-attend gathering for all stakeholders in risk management and financing.
Download your free English version of the panorama at
https://www.amrae.fr/bibliotheque-de-amrae/2026-rmis-panorama
Find other Publications www.amrae.fr
This document, property of AMRAE, is protected by copyright law.
Any reproduction, total or partial, is subject to the compulsory indication of copyright.
Copyright © AMRAERMIS PANORAMA 2026
128
Please use arrows to easily navigate
About EY:
EY is building a better working world by creating new value for clients, people, society and the planet,
while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence
and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and
transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse
ecosystem partners, EY teams can provide services in more than 150 countries and territories.
All in to shape the future with confidence.
EY refers to the global organization, and may refer to one or more, of the member firms of Ernst
& Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a
UK company limited by guarantee, does not provide services to clients. Information about how EY
collects and uses personal data and a description of the rights individuals have under data protection
legislation are available via ey.com/privacy. EY member firms do not practice law where prohibited by
local laws. For more information about our organization, please visit ey.com .
© 2026 – Ersnt & Young Advisory
All rights reserved.
SCORE N° 2025-082
This publication is intended for general information purposes only and should not be relied upon as a substitute for professional advice in
accounting, tax, legal or other matters. For specific questions, please consult your advisors. ey.com/frRMIS PANORAMA 2026
129
Please use arrows to easily navigate
This document, property of AMRAE, is protected by copyright law.
Any reproduction, total or partial, is subject to the compulsory indication of copyright
Copyright © AMRAE
Design Center EY France - 2502DC055
36 boulevard de Sébastopol, 75004 Paris - www.amrae.fr
2026 RMIS Panorama
2026 RMIS Panorama
The English version of the 2026 RMIS Panorama is now available for free download. As a market reference, the RMIS Panorama provides useful insights to Risk Managers:
• An analysis of market practices and trends, based on a survey gathering 178 Risk Managers respondents in 24 countries, as well as 55 vendors.
• Several expert insights, covering RMIS selection and implementation, ESG integration, and strategic perspectives from insurers and brokers.
• A focused analysis on Artificial Intelligence, highlighting its growing impact on risk management practices.
• 9 Risk Managers’ testimonials, sharing concrete feedback on RMIS implementation and usage.
• 55 vendors identity cards, updated since 2025, including 4 new vendors.
• Leaders’ quadrants and detailed vendors mapping, providing a structured view of the RMIS market.
As last year, this publication is supplemented by a web-based analyzing platform, which enables filtering by sector, company size, or functional modules.
EY and AMRAE thank all participants in this new edition, especially our partners: IFRIMA, RIMS, FERMA, PARIMA, Club FrancoRisk, who contribute to the international scope of the study.
AUTRES PUBLICATIONS SUR LE MÊME SUJET