Try our new research platform with insights from 80,000+ expert users

OneTrust GRC vs RSA Archer comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

OneTrust GRC
Ranking in GRC
2nd
Ranking in IT Vendor Risk Management
1st
Average Rating
8.2
Number of Reviews
14
Ranking in other categories
No ranking in other categories
RSA Archer
Ranking in GRC
1st
Ranking in IT Vendor Risk Management
2nd
Average Rating
8.0
Reviews Sentiment
5.8
Number of Reviews
38
Ranking in other categories
IT Governance (1st)
 

Mindshare comparison

As of November 2024, in the GRC category, the mindshare of OneTrust GRC is 8.5%, down from 9.1% compared to the previous year. The mindshare of RSA Archer is 16.0%, down from 18.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
GRC
 

Featured Reviews

Gerald Pegg - PeerSpot reviewer
Streamlined incident management with user-friendly automation tools and responsive support
I use OneTrust specifically for incident management. For my company, I helped to create the incident management program that we currently use, particularly with gathering the information and sending out assessments to different vendors to collect information for further research and discovery.  I…
Raviteja Nekkanti - PeerSpot reviewer
User-friendly, minimal learning curve and good for security assessment
My use case is for security assessment. It's my daily task. I use it for security assessment in Azure. We have tickets where users need to submit details about an application, computer, or server. For Archer, my direct task is to assess the security risk of an application, infrastructure, or…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"OneTrust GRC is stable."
"We receive notifications or cases and prioritize them accordingly, which helps us address issues promptly."
"It does help in the automation of our privacy impact assessments."
"The most valuable feature of the solution is that it already has visibility about all the data protection regulations or other cybersecurity regulations related to several countries"
"The platform is especially useful in startup environments where we're typically starting from scratch."
"One of the most beneficial features of the product has been its cloud-based IT and vendor risk management tools, along with built-in templates for GDPR and ISO compliance."
"The product helps us streamline audit and incident management processes."
"We have data from Jira regarding addiction related to Europe as well as California. Additionally, we have data related to the Indian Data Protection Bill. Therefore, GDPR compliance is highly beneficial."
"Archer has simplified our security audits. It's made it easier to raise and trigger questionnaires to customers."
"Its user interface is pretty neat, and there is flexibility in generating the data. You can customize reports at any level. You can directly get reports in Tableau format. If you want to generate statistical data, you can create reports with graphs. There is an adequate amount of flexibility for changing the format, the type of graphs, etc."
"RSA Archer's best features are advanced workflow, reports, dashboards, and notifications."
"The product is very flexible."
"This solution helped us with the centralization of our governance data, so we could house all of our controls in one place. We could use that central repository of all our controls to build our risk management strategy and our policy and governance. So we could use controls as a central library and build policy, and then build risk management around it."
"The part I liked about Archer was the risk assessment for deficiencies and being able to use it there."
"I like how Archer requires very little programming ability. A person with minimum coding experience can configure the necessary fields in Archer. It's more of a drag-and-drop solution."
"The most valuable features are the advanced workflow and the dashboards. This tool can present data wonderfully to management, and it is easy for them to manage the risk plans."
 

Cons

"There could be enhancements related to AI."
"The product is not that easy to set up."
"OneTrust GRC's workflows aren't automated and need to be manually driven."
"The platform was not built in a way that allowed multinational entities to use it seamlessly."
"They could improve by offering free help. A solution, a lot of times, is not just the use of the solution. For example, it is the overall engagement, how well do they support the system, what is their SLA, and how long their response time is to an issue. It would be beneficial if they had some type of professional services where they offer the first five hours of professional services a year for free. That would be a substantial benefit rather than having to buy professional services or professional services packages."
"There are several areas for improvement. One is the integration capability. Connecting various DSAR systems can be time-consuming if a single integration takes months to complete."
"We encounter difficulties creating multiple platforms or interfaces and manual processes for changing certain settings."
"The implementation of OneTrust could have been smoother, particularly in terms of scoping for those outside of governance, risk, and compliance."
"The solution as a whole could be simplified."
"It would be useful for customers if COBIT 2019 could be translated into different languages."
"The solution can be a little slow due to the Silverlight feature."
"GUI could be improved."
"Some of the error reporting isn't very clear. When you're looking for information on error codes, you got to do a lot of digging."
"Archer could be improved by having more customization. I'm not sure if the backend processes have API calls and those kinds of seamless integrations, but from the front, some of the solutions are very out-of-the-box. It's not customizable, so that could be a little problematic since you have to use their features. In terms of the backend structure, I'm not too sure because I'm not a developer—I was an end user and product owner of Archer—and I don't quite know the backend and developmental features. But since it's an out-of-the-box solution, sometimes customization was challenging and support was a little problematic because we had to reach out to them all the time."
"Solution could use more inbuilt applications."
"It would be nice if RSA Archer featured more customization. When customers are updating, they should be notified whether certain updates are optional. The install screen should not proceed to the next page unless we make some selections about which updates we want to install."
 

Pricing and Cost Advice

"On a scale from one to ten, where one is cheap, and ten is too expensive, I rate the solution a seven since it falls under the pricey side."
"OneTrust GRC's licensing costs about $15,000 per module."
"The platform is expensive."
"OneTrust GRC is an expensive solution."
"I found the pricing and setup cost very reasonable."
"The solution is expensive."
"The solution's price should be reduced. You only have to pay the license and there are no additional fees."
"The solution’s pricing is moderate."
"It is not expensive. It is reasonable. We only pay for the licensing."
"The solution is not at all a cheap product."
"The price of RSA Archer is good. The price isn't too high considering it is a leading tool in the market."
"The initial purchase is cheap. You pay a nominal price to start then renew the license annually. You also must buy a license for each module. I'm not too fond of that aspect of the licensing model. You buy the elephant and then spend more money to feed the elephant."
"I am not sure about other companies, but it's quite expensive."
"The price of the solution is very affordable."
report
Use our free recommendation engine to learn which GRC solutions are best for your needs.
816,660 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
12%
Government
7%
Healthcare Company
7%
Educational Organization
52%
Financial Services Firm
12%
Computer Software Company
5%
Manufacturing Company
4%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about OneTrust GRC?
We have data from Jira regarding addiction related to Europe as well as California. Additionally, we have data related to the Indian Data Protection Bill. Therefore, GDPR compliance is highly benef...
What is your experience regarding pricing and costs for OneTrust GRC?
I don't have specifics on pricing. I know it's not very cheap, but the budget aspect is outside my wheelhouse.
What needs improvement with OneTrust GRC?
I wish there were more customization options, particularly within the privacy rights automation module. More customization on the backend would allow for adjusting specific category labels tailored...
What do you like most about RSA Archer?
It has various valuable features. For example, showing us if a control aligns with specific standards or frameworks helps us understand it better and verify its compliance.
What needs improvement with RSA Archer?
The user interface needs work. There are many small text boxes, like credit card size's boxes, where we need to input a lot of text. You can't see what you're typing beyond the tiny window, so you ...
What is your primary use case for RSA Archer?
We primarily use the system control module and specific IT control models for ongoing risk assessment activities. We use it on a day-to-day basis.
 

Comparisons

 

Also Known As

OneTrust Vendor Risk Management
Archer
 

Learn More

 

Overview

 

Sample Customers

randstand, into, halfbrick
T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Find out what your peers are saying about OneTrust GRC vs. RSA Archer and other solutions. Updated: November 2024.
816,660 professionals have used our research since 2012.