Try our new research platform with insights from 80,000+ expert users
Senior Consultant at a financial services firm with 10,001+ employees
Real User
Jan 12, 2022
Excellent process automation, audit management and more
Pros and Cons
  • "First of all, its access control feature where it provides application level access, solution level access, and even recall access, as well."
  • "Our clients are using RSA Archer to automate their manual processes and activies to avoid manual intervention and have a clear visibility to leadership."
  • "In terms of what can be improved, our client always says their user experience, IU/UX in RSA Archer. They found it is not as user friendly as other tools."
  • "RSA Archer somehow lags behind in the user interface. Additionally, the reporting capability of Archer should be improved."

What is our primary use case?

We are using RSA Archer to provide GRC services to our client. GRC means, governance, risk and compliance. In Archer we implement business continuity management, policy management, risk management solutions, audit management solutions, and third party governance solutions. We even utilize a privacy governance model of RSA Archer, as well.

Currently, we are analyzing and evaluating software as a service option for one client to reduce effort and time on infra related activities.

How has it helped my organization?

Our clients are using RSA Archer to automate their manual processes and activies to avoid manual intervention and have a clear visibility to leadership. This increased the client's process efficiency, they are more compliant and reduces the risk and overall governance structure improved. Also, it adds some value added features on the reporting and gives clear visibility of the entire business unit or   divisions of the company. Suppose the CEO of company want to see their high risk BUs , he or she can easily see the count and detail. Automated timely email trigger and integration with other tools/application helps client to assess their processes and BUs to find out risks and remediate risk on time.

What is most valuable?

There are lots of features which motivate our client to use RSA Archer. First of all, its access control feature which provides access at application level, access at record level and  at page level. It helps client to avoid any unauthorised access.

Also, there is a strong integration between the RSA Archer modules and also option to integrate with other application/ process help client to increase confidence on data integrity.

Suppose if anyone is using RSA Archer audit management or any out of the box use cases, it also provides some of the inbuilt capability of the assessment, like some of the questionnaires and some of the controls that are available in RSA Archer.

 Capability of sending automated email triggers to the stakeholder on a fix frequency.

Workflow feature, reports and dashboard capability etc. lucrate client towards Archer.

What needs improvement?

 UI/UX can be improved and a feature to allow end user to update assessment question and add or remove recipients from a notification will help client to minimize their dependecy on Archer developer.RSA Archer somehow lag behind in the user interface.

Additionally, the reporting capability of Archer should be improved. Because generally what clients do is analyze processes, their records, their status. They integrate it with either Tableau or Power BI just to customize their reports and see more user friendly reports. So I would suggest to improve reporting capabilities as well.

Buyer's Guide
RSA Archer
March 2026
Learn what your peers think about RSA Archer. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.

What do I think about the stability of the solution?

In terms of stability and performance, Archer is good.

What do I think about the scalability of the solution?

RSA Archer is easy to scale, it's not complex.

It is a requirement to maintain RSA Archer. Our team even provides the managed services to the client, as well.

Some of my clients are moving their GRC solution from other platforms to RSA Archer because of scalability.

How are customer service and support?

Support is good, but sometimes I feel there are some queries or issues, where I or our client need a resolution quickly, but sometimes it gets delayed from the customer support side.

Which solution did I use previously and why did I switch?

Generally client without GRC framework move to Archer to automate their processes.

How was the initial setup?

Generally we deploy the RSA Archer on client's infrastructure. It is not complex, even for the first time user, process to setup Archer is easy if they refer manuals or guide.

Generally, one person can easily install if it is a small or medium and not a complex deployment. But if it is a large scale deployment I think there will be more requirement of other team involvement as well.

Which other solutions did I evaluate?

Yes, we do evaluate other options/framework available in market e.g. ServiceNow GRC, OneTrust etc.

But we suggest best option basis the client requirement and which suites most in terms of cost and effort.

What other advice do I have?

My advice to anyone considering RSA Archer would be to use it for their GRC capability and automate their manual tasks. If they are doing any manual task, they can simply automate through RSA Archer. It will increase efficiency, minimize their risk and will make them more compliant.

On a scale of one to ten, I would give RSA Archer an 8 out of 10

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1746588 - PeerSpot reviewer
Sr. Internal Auditor at a energy/utilities company with 10,001+ employees
Real User
Jan 10, 2022
Highly scalable, provides flexibility for creating reports, and reduces a lot of paperwork
Pros and Cons
  • "Its user interface is pretty neat, and there is flexibility in generating the data. You can customize reports at any level. You can directly get reports in Tableau format. If you want to generate statistical data, you can create reports with graphs. There is an adequate amount of flexibility for changing the format, the type of graphs, etc."
  • "There is absolutely no doubt that it is a very good tool for audit management as a whole."
  • "There should be a way to export and get data from the system in PDF or PowerPoint presentation format. This would be a great addition."
  • "The dashboard that is a part of the RSA Archer could be more aesthetic."

What is our primary use case?

I am using RSA Archer for internal audit management. It is used for the entire life cycle for audit, which includes engagement planning, reporting, action management, and so on. It is also used for internal resource management. The timesheet management, resource management, and training are being managed through the same system. 

It has been deployed on-premises. My organization has 16 groups. It is installed and managed centrally by the headquarters, and we are using the application.

How has it helped my organization?

We got rid of a lot of paperwork. As an internal auditor, we have to comply with IIA guidelines. There are standards that we need to follow while completing an engagement. A lot of requirements have been automated through the system, such as quality assurance, engagement review, audit follow-ups, and so on. It has supported the organization as a whole.

It is highly customized for our organization. It is primarily for GRC, but we are using it for audit management, resource management, timesheet management, and so on. These were add-ons features that were customized and developed by the vendor.

What is most valuable?

Its user interface is pretty neat, and there is flexibility in generating the data. You can customize reports at any level. You can directly get reports in Tableau format. If you want to generate statistical data, you can create reports with graphs. There is an adequate amount of flexibility for changing the format, the type of graphs, etc. 

What needs improvement?

The dashboard that is a part of the RSA Archer could be more aesthetic. 

There should be a way to export and get data from the system in PDF or PowerPoint presentation format. This would be a great addition.

For how long have I used the solution?

It has been almost two years since we have been using the product. We have been using it almost on a daily basis.

What do I think about the stability of the solution?

We have been using the web application, and sometimes, there are issues related to the network availability, etc. Other than that, we have not seen any issues in terms of performance and input and output controls. We never had any reports that were not correct. So, more or less, it is fine.

What do I think about the scalability of the solution?

Scalability-wise, we already have a proven case. Deploying a solution in one company with a fixed, organized structure is one thing, but deploying at a mass level in multiple companies and bringing them all together in one single platform is a completely different thing. It proves the scalability of the solution. There is no doubt that it can be scaled to multiple organizations in one go.

We have more than 200 users. They are internal auditors, but if we also count the auditees who use the same system, the number would be much higher.

How are customer service and support?

Our version of RSA Archer is heavily customized. Therefore, at the initial stage of the deployment, there were a few issues for which we needed support. We had a few workflow issues or anomalies in the reporting. 

At the organization level, we have a uniform IT management system for IT tickets. We have an IT support team at the group level, and then we have a support team in headquarters. It is being managed just like any other solution in the organization. We are satisfied with the support.

Which solution did I use previously and why did I switch?

I have seen the deployment of the SAP-based audit management system in 2013 or 2014, which might have changed a lot over these years. From a user's point of view, RSA Archer has a better user interface. It is easier to use. SAP had a typical structure and user interface. It might not have been user-friendly for everyone. RSA Archer is more user-friendly. Its acceptability is much higher when you are deploying it in an organization.

How was the initial setup?

It followed the usual SDLC life cycle. They came and understood the processes. They understood the way the audit was being managed in our organization. It was a joint effort between our organization and the vendor. There were a lot of sessions to understand how we conduct our processes and what are the challenges that we face. Bringing almost 16 to 17 companies in one single platform was a challenge in itself. Even though we had the same policy procedure, there were some differences in the way things were being done, the formats of the files that we were using, and the way people were doing the audits.

It took a lot of time to have a good base of the design itself, but it was worth it. The deployment was done phase-wise. It was not a single-phase deployment; it was a multi-phase deployment. Initially, we just implemented the basic audit management in which we were able to create engagements and add the findings. Later on, more complexities were added related to quality management, timesheet management, detailed reporting, and so on.

It required a lot of interaction with the group companies and the development team in the HQ. There was one whole team in the HQ that had 15 to 20 people. From each company, there were about two to three people. It was a big team. My estimate is that we had at least 20 to 30 people.

The initial deployment probably happened in a span of six months. Every quarter or every six months, they take feedback from different companies, and they ask for whatever modification is required from our side, and they keep on releasing the updates, small modifications, and so on. It is a continuous process, and we are still fine-tuning the system.

I'm not an administrator, so I don't have information about the maintenance it requires in the backend. Because it is heavily customized, whatever development happens, it happens only internally. The production and the development environments are optimized. Apart from that, the routine activities that we require are related to any data modification with reference to the audit parameters of the attributes. We usually request to change or modify them. There is also an approval process. These are the kinds of interactions that we have as users.

What other advice do I have?

There is absolutely no doubt that it is a very good tool for audit management as a whole. If you are deploying RSA Archer, the most important thing is that you need to be very clear of your requirements and the processes for audit management. It can maintain the organization hierarchy, business hierarchy, processes, projects, and assets. It can maintain a lot of repositories and attributes related to an organization for mapping individual audits. It is a wonderful tool, but if you are not clear about how you want to deploy it, it could be a mess. This is applicable to any enterprise-level tool. 

The reason I'm certifying with RSA Archer is that when you are using it for audit, there is a particular strategy and the way to do it, which may vary from organization to organization. So, you have to be very particular about what you want from the tool before deploying it. You should not deploy it and then define your processes. 

I would rate RSA Archer a nine out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
RSA Archer
March 2026
Learn what your peers think about RSA Archer. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
Manager in Risk Advisory at a consultancy with 10,001+ employees
Real User
Dec 8, 2021
Offers a high degree of automation with easy implementation
Pros and Cons
  • "Easy to implement with a high level of automation."
  • "Among the most valuable features of this solution is the easy implementation and the degree of automation that it offers."
  • "The design and advanced workflow need to be improved."
  • "We've noticed recently with the advanced workflow jobs that we're receiving some errors. It's a showstopper for us and it's clear that some kind of development support is needed."

What is our primary use case?

Our use cases for Archer include third-party management, enterprise risk management, and compliance management. We have a partnership with RSA Archer and I'm a manager in risk advisory.

What is most valuable?

Among the most valuable features of this solution is the easy implementation and the degree of automation that it offers. This product is very compatible with our business processes and the dashboarding features are creative. This is an easy tool to learn and to work on. They have a great community where you can ask any question and be sure to get some responses. 

What needs improvement?

Archer has evolved significantly over the last five to eight years, but there are still some areas that could be improved. We've noticed recently with the advanced workflow jobs that we're receiving some errors. It's a showstopper for us and it's clear that some kind of development support is needed. If there were an improvement in the design and the advanced workflow, jobs would run more smoothly, and a lot of value would be added to the business. Another aspect that could be improved is the UI which has a very old generation feel. For additional features, I'd very much like to see tools added in the next release. This could include a live connection that could be built in order to bring all the client data from the legacy system directly into Archer. Right now it's a data feed. There are currently some ActiveX options for live collections, but not for all the products. 

For how long have I used the solution?

I've been using this solution for five years. 

What do I think about the stability of the solution?

The solution is stable, it's a very mature product and if anything goes wrong we can provide the answers or the Archer community has the answers. We are currently having some problems with performance and our clients are complaining. The issues are with calculations and advanced workflows and it's creating a slow down in the system. We probably have around 5,000 users through our client companies.

What do I think about the scalability of the solution?

The solution is very scalable. The design approaches Archer provides are very easy to change and scale. In an agile project, it's very easy to handle or develop with most of the configurations based on drag and drop as per the document framework.

How are customer service and support?

Most of the issues we've had to escalate to RSA support belong to the advanced workflow section. These problems cannot be solved by Archer's UI and require back-end support or technical support from RSA. We're satisfied to a degree, it can take a few days to get a response. 

How was the initial setup?

The initial setup is straightforward, the complexity lies in the operations. The entire configuration project requires minimal manpower. Archer has a built-in wizard where you can either create a package and send it to the higher environment or just install the package. It doesn't take more than half a day. In the latest versions, we've seen that some of the features are not automatically deployed and manual checks are required. We're expecting to see that rectified in future versions. 

What's my experience with pricing, setup cost, and licensing?

The licensing is more expensive than other similar products and it often makes our clients step back and go for cheaper options. That said, the company is very clean and transparent in terms of pricing. There are no additional costs.

Which other solutions did I evaluate?

I have experience working with other GSU products and as a competitive analysis, I'd rate RSA's capability above that of other products. RSA Archer is more mature in terms of providing solutions. It's only when you compare the UI between solutions that Archer's competitors have an advantage. 

What other advice do I have?

This is an easy solution and it's very good for agile projects when requirements can change abruptly. The only concern we have is with the advanced workflow which should be simplified so that if any errors come up, it's easier to change or modify. I recommend checking the target environment for all the configuration areas, making sure that it has been properly deployed, and checking whether it needs some post-deployment checks.

I would rate the solution very high but because of the error messages we've been receiving which require technical support and cannot be fixed by the Archer UI or the Archer configuration interface, I have to bring the rating down. If they improve the UI, I'd rate them more highly. 

For now, I rate this solution eight out of 10. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Assistant Manager at Deloitte
Real User
Dec 7, 2021
Easy to set up but some issues with stability
Pros and Cons
  • "Solution is scalable."
  • "Archer allows us to define the progress of the organization's processes and helps build the right cyclic process and improve the current structure."
  • "Slow turnaround time from support team."
  • "The tech support team's turnaround time is often slow."

What is our primary use case?

My primary use case varies depending on the requirements, but uses include working on email notifications, fetching data feeds, and working on feed managers.

How has it helped my organization?

Archer allows us to define the progress of the organization's processes and helps build the right cyclic process and improve the current structure. We also track a lot and transfer a lot of vendors and users, and Archer has a repository that allows us to collect that data step by step. It also makes auditing easier.

What is most valuable?

The most valuable features of RSA Archer are notifications, workflow routing, and data filtering.

What needs improvement?

An area for improvement is the turnaround time for advice from the support team. In the next release, I would like to see a maturity rating feature that would provide industry ratings and information on the market.

For how long have I used the solution?

I have been using this solution for about a year and a half.

What do I think about the stability of the solution?

Stability has improved over time, but there's still a lot of latency with some features, like looking up or checking the database.

What do I think about the scalability of the solution?

This solution is scalable.

How are customer service and support?

The tech support team's turnaround time is often slow.

Which solution did I use previously and why did I switch?

Previously, I have used Aravo, and currently, I'm using Process Utility.

How was the initial setup?

The initial setup was fairly straightforward as we were given hands-on training. Deployment took around three months.

What other advice do I have?

When implementing Archer, I recommend looking through the videos supplied and making use of the free sessions that Archer provides. I would rate this product as six out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Technology Manager at a tech services company with 10,001+ employees
Real User
Dec 3, 2021
A rich application with good workflow, but search feature needs improvement
Pros and Cons
  • "RSA is a very rich application. I like its adaptive suggestion, where based on your users and the class of data, it can actually recommend you the proper control to choose. For example, we have been using PCI DSS as an NIST. So based on application feedback, it will provide you with a suggestion on which control objective needs to be set. Based on that, you can make a decision—you don't need to take the suggestion, but you can customize that particular provided suggestion. RSA Archer's workflow is also good, in terms of process automation."
  • "RSA is a very rich application, and I like its adaptive suggestion where, based on your users and the class of data, it can actually recommend you the proper control to choose."
  • "The first improvement I would suggest for RSA Archer is a better search feature. The search criteria needs to be improved. Sometimes I do a search and the search doesn't return the exact item I'm looking for. RSA Archer could also be improved by being more user-friendly. Maybe I have been using a limited version of RSA Archer, but I'm not sure whether it has ESG, environmental and social governance. In the next couple of years, ESG is the next feature that will be integrated into GRC tools. I would recommend RSA Archer adds ESG."
  • "The first improvement I would suggest for RSA Archer is a better search feature; the search criteria needs to be improved because sometimes I do a search and the search doesn't return the exact item I'm looking for."

What is our primary use case?

My use cases of RSA Archer are for WISP and controls-based audit purposes. For WISP, we keep the information security, like written informed consent protocol, and I manage almost 15 applications that I need to review the architecture of. I use RSA Archer to review the design document, the zone the application is hosted in, whether there is any kind of zoning division, the cryptography design, the cryptography used for data in motion, and what encryption they're using. 

Other than that, we have been using RSA Archer for a controls baseline. We had policies set up earlier and, based on those policies, control objectives were stated in RSA Archer for each and every application. 

This solution is deployed on-premise. 

What is most valuable?

RSA is a very rich application. I like its adaptive suggestion, where based on your users and the class of data, it can actually recommend you the proper control to choose. For example, we have been using PCI DSS as an NIST. So based on application feedback, it will provide you with a suggestion on which control objective needs to be set. Based on that, you can make a decision—you don't need to take the suggestion, but you can customize that particular provided suggestion. RSA Archer's workflow is also good, in terms of process automation. 

What needs improvement?

The first improvement I would suggest for RSA Archer is a better search feature. The search criteria needs to be improved. Sometimes I do a search and the search doesn't return the exact item I'm looking for. RSA Archer could also be improved by being more user-friendly. 

Maybe I have been using a limited version of RSA Archer, but I'm not sure whether it has ESG, environmental and social governance. In the next couple of years, ESG is the next feature that will be integrated into GRC tools. I would recommend RSA Archer adds ESG. 

What do I think about the stability of the solution?

I have seen some performance issues. For example, with the search criteria. When I'm searching with some of the IDs, it will return "FND_" and some finding numbers. Their search criteria is a bit cumbersome because I need to actually find what I need, but it's giving me a lot of other information. I have also experienced lagging when viewing an app configuration page, to see the controls associated with that particular app. I'm not certain whether it's a problem with Archer or with our implementation, but there are definitely some performance issues. 

We have a maintenance team responsible for the required maintenance. They handle new patches and some of the new framework rules and updates. They're also planning on implementing and integrating FedRAMP. 

What do I think about the scalability of the solution?

RSA Archer is definitely easy to scale. It's not complex to add applications to our portfolio. For example, we can use one set of controls for one application, and then we can easily map another application with that same set of controls. 

We have a huge organization, so RSA Archer is available for higher management. In our portfolio, there are about 26 users. We don't have plans to increase our usage of RSA Archer because we are migrating to ServiceNow. 

How are customer service and support?

I have the tech support where I evaluate according to a criteria. For example, how frequently that particular software version is being patched, whether the application server is updated with the proper software version or not, whether there is a failover plan, and what our data retention policies are, in terms of issues that are closed or obsolete, and how long we are keeping those. So I evaluate these questions with the maintenance team. 

Which solution did I use previously and why did I switch?

Archer was being used when I started at my company, but I think they were previously using some CA tool. We have been using RSA Archer and RSM, but we are finally migrating to ServiceNow. 

How was the initial setup?

I have not actually set up RSA Archer—a different team handles the setup and installation, and I integrate the frameworks for our applications and set up the control objectives. I have integrated different frameworks, like NIST and PCI DSS, and have found that you can create and upload your control objective from the spreadsheet and work on it. It's one of the easier ways to set your application-specific controls on RSA Archer. 

What about the implementation team?

A different team handled the implementation. 

What was our ROI?

Return on investment is definitely there, in a sense, because with this particular governance, we can mitigate the risks of different kinds of losses. For example, with one of our applications, I have been looking into the portfolio that deals with PCA and PA data. If the upper control objectives are not managed properly, then there may be vulnerabilities which, if not properly remediated, will lead to losses—customer data loss and intellectual property loss. So there is definitely an ROI with this GRC tool. 

What's my experience with pricing, setup cost, and licensing?

RSA Archer's price is justifiable and not as expensive, compared to ServiceNow. I have heard that the licensing for ServiceNow is much more expensive. I'm unaware whether there are any additional costs after licensing fees. 

Which other solutions did I evaluate?

We are migrating to ServiceNow, which isn't as rich as RSA Archer, but it's better in terms of usability. It's easier to integrate each and every control with the entities and it's easier to assign incidents and policies. The process automation and workflow is good in RSA Archer, but it's available in ServiceNow as well. For control audit purposes, since we are migrating to ServiceNow, we have actually mapped the entities and, from there, we are doing the controls-based audit. 

What other advice do I have?

To any teams who are looking to implement RSA Archer, I would say that one problem I faced when we integrated NIST, PCI DSS, and other tools was that there are a lot of common control objectives out there with policies that are actually mapped. So you need to be making sure that you are not making duplicate control objectives. For example, take disaster management. In the data retention policy for the database, one of the control objectives requires proper access management, so that will be applicable for network as well. You can use a similar control objective and map two or more different policies, which will reduce the amount of effort you need to put in. 

I rate this solution a seven out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Cyber security consultant at a financial services firm with 1,001-5,000 employees
Consultant
Nov 30, 2021
Easy to configure, but customization is a challenge
Pros and Cons
  • "This solution helped us with the centralization of our governance data, so we could house all of our controls in one place. We could use that central repository of all our controls to build our risk management strategy and our policy and governance. So we could use controls as a central library and build policy, and then build risk management around it."
  • "This solution helped us with the centralization of our governance data, so we could house all of our controls in one place, use that central repository to build our risk management strategy and our policy and governance, and then build risk management around it."
  • "Archer could be improved by having more customization. I'm not sure if the backend processes have API calls and those kinds of seamless integrations, but from the front, some of the solutions are very out-of-the-box. It's not customizable, so that could be a little problematic since you have to use their features. In terms of the backend structure, I'm not too sure because I'm not a developer—I was an end user and product owner of Archer—and I don't quite know the backend and developmental features. But since it's an out-of-the-box solution, sometimes customization was challenging and support was a little problematic because we had to reach out to them all the time."
  • "Archer could be improved by having more customization."

What is our primary use case?

Our primary use case of this solution is for GRC. I work for a bank and we used this tool to audit our information security team and our cybersecurity team. We had our control library, regulatory requirements, and third-party risks on Archer. So basically, I would say audit, regulatory requirements, third-party risk management solutions, and all kinds of controls, including SOX. These are the integrations we had set up. Right now, it's deployed on-prem. 

How has it helped my organization?

This solution helped us with the centralization of our governance data, so we could house all of our controls in one place. We could use that central repository of all our controls to build our risk management strategy and our policy and governance. So we could use controls as a central library and build policy, and then build risk management around it. 

What is most valuable?

One of the most valuable features is the ease of use. The customizable forms and drop-downs are pretty easy to configure. Automated notifications is another feature that is nice. The whole workflow, basically—if you're going through a workflow process, the whole process is automated with notifications. Basically, it's a pretty straightforward, easy-to-understand interface. I've also had the chance to develop some backend configurations, which is straightforward as well, if you want to add a new field or anything. 

What needs improvement?

Archer could be improved by having more customization. I'm not sure if the backend processes have API calls and those kinds of seamless integrations, but from the front, some of the solutions are very out-of-the-box. It's not customizable, so that could be a little problematic since you have to use their features. In terms of the backend structure, I'm not too sure because I'm not a developer—I was an end user and product owner of Archer—and I don't quite know the backend and developmental features. But since it's an out-of-the-box solution, sometimes customization was challenging and support was a little problematic because we had to reach out to them all the time. 

For how long have I used the solution?

I have been working with this solution for the past 18 months. 

What do I think about the stability of the solution?

We did have a few outages, but otherwise, I must say it's fairly reliable. 

For maintenance, there's an admin dashboard. It's a capability that is handed over to our user and admin has super user access. 

What do I think about the scalability of the solution?

This solution is quite scalable. At that point, it really depends on the strategy. Since we had all our controls on Archer, it was easy for us to scale and deploy other applications or develop other applications seamlessly. But imagine you had your controls on a different application—if it was not on Archer and you had to scale, it would be challenging to move all your data into Archer and then scale. So that is something that could be challenging, but since our strategy was already Archer through and through, we did not find it difficult to scale. 

There are approximately 500 users, across all departments, using Archer. It is being used extensively at the moment. Right now, we don't have plans to increase usage, but I'm sure there's going to be organic growth. 

How are customer service and support?

On a scale of one to five, I would probably rate support a three. I wouldn't say it's the best, but it's not bad either, in terms of both the response time as well as the support. 

Which solution did I use previously and why did I switch?

We used SharePoint for a bit. We switched to Archer because the graph, user interface, and all that was better than SharePoint. I'm not too sure about the strategic decision because I wasn't with the organization back then, but I know that they wanted a centralized location for their governance, risk, and applications. 

How was the initial setup?

I think the deployment process is pretty straightforward. The solution was deployed for us through a third-party consulting agency, so it wasn't Archer or RSA developers, but a third party that implemented the solution for us. During the time of deployment, we were in a CI/CD mode, so we always had new applications, customization, new fields getting added. 

What about the implementation team?

A third party implemented the solution for us. 

What other advice do I have?

If you are considering implementation, my advice would be to decide on a strategy first before you implement a solution. The solution is nice, but unless you have a strategy, I don't see the point in implementing it. 

I rate Archer a seven out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1710315 - PeerSpot reviewer
Sr. Consultant at a retailer with 11-50 employees
Consultant
Nov 24, 2021
Great Advance Workflow feature; ability to create multiple layers with a specified functionality
Pros and Cons
  • "The Advance Workflow feature simplifies things."
  • "This is a good solution compared to others in the market because it is more secure."
  • "The solution can be a little slow due to the Silverlight feature."
  • "In the current version, RSA is a little slow mainly because of Silverlight which I believe has been removed in the next version."

What is our primary use case?

We customize this solution for our clients. We take all their requirements and prepare the design and format by creating fields, notifications, access controls and workflows. We use all the management features that the solution provides to support our clients. We are customers of RSA Archer and I'm a senior consultant. 

What is most valuable?

The Advanced Workflow feature is one of the most valuable and user-friendly. We used to have to write multiple calculations. With Advanced Workflow, things are much easier for the developer and end user. It's a robust feature that allows users to easily identify what they're doing and where they are. We're able to create multiple layers with a specified functionality that gives an understanding of what is required as well as increased flexibility. Archer provides good security, enabling access where necessary. It's also a useful reporting tool, clearly showing functional data and, when needed, the ability for comparison. The default dashboard shows daily activities that are easily captured allowing for information to be extracted. 

What needs improvement?

In the current version, RSA is a little slow mainly because of Silverlight which I believe has been removed in the next version. We have some issues using .NET because migrating requires retraining the custom object every time; it's a manual change which is challenging. For that reason, we don't use the custom object. What's needed is a valueless field, where we can drag and drop, add some values and the process is automatic. I'd also like to see an 'approved' button incorporated in the notifications for updates. It would save time and make life easier for the end users.  

For how long have I used the solution?

I've been using this solution for 11 years. 

What do I think about the scalability of the solution?

This solution is very easy to scale and easy for new users to understand.

How are customer service and support?

Because we use most of the modules we're paying a lot to get good support. We interact with someone from RSA on a weekly basis and deal with any issues on the platform.

How was the initial setup?

The initial setup is straightforward when you understand the system. We put our new users in the sandbox environment and get them to play around with it before setting out our requirements. It can be a bit of a challenge initially but not for long. It's not a common platform and is different from other tools. Once our users are implementing, it's a very smooth process for them. We have a total of seven developers, four are in-house and three are on contract. 

Deployment time depends on the use case; if it's a large implementation, it can take between six and nine months. The solution needs maintenance because of the updates and that often results in patching needs. We're using Archer on a daily basis. 

What's my experience with pricing, setup cost, and licensing?

I'm not sure about the cost of the solution but every year we purchase additional on-demand applications. Archer offers a package that allows the purchase of 10 on-demand applications. You can purchase more than that and the price goes up accordingly. I believe these purchases come with two years of maintenance support. 

What other advice do I have?

This is a good solution compared to others in the market because it is more secure. It's suitable for any size company although smaller companies will only need to use certain modules with larger organizations using multiple modules. This is a one-stop storage device that you can access from anywhere. 

I rate this solution nine out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sameh Hablas - PeerSpot reviewer
CEO at Al Danah Information Systems Solutions
Real User
Top 5Leaderboard
Nov 21, 2021
Simple to use product that gives a great return on investment
Pros and Cons
  • "RSA Archer has reduced the time and effort required for meetings."
  • "First of all, we have gained time back that was previously wasted in management meetings."
  • "The product is expensive."
  • "The product is expensive, and there are additional costs if you need to integrate more licenses or want more features."

What is our primary use case?

My primary use case for this solution is for the customizing and compliance system, especially for the first standard, ISO 27001, related to the information security management system.

How has it helped my organization?

RSA Archer has reduced the time and effort required for meetings because every person or department can enter their asset register by themselves. It's also useful that to get information on the spot, you don't need to have it in an Excel sheet to make it a compiler or a function. It is also a unified product, meaning that every person can enter any font or type of equation they need. It records information for several years, which means if I need to fix any observation from the past five years, I can do so on the system on the spot. Finally, it provides intelligent suggestions for solutions and risk management.

What is most valuable?

The most valuable feature of this solution is that risk mitigation and risk register are very easy - it's very simple to enter the data.

What needs improvement?

I would like to see a version of the product customized for small businesses, perhaps something cloud-based on a monthly basis. I would also like the product to be more easily integrated with the Arabic language. 

For how long have I used the solution?

I have been using RSA Archer for around two years.

What do I think about the stability of the solution?

This product is 100% stable, without a lot of bugs.

What do I think about the scalability of the solution?

The solution is scalable.

How was the initial setup?

The setup was complex, taking around three to six months.

What about the implementation team?

I used a vendor team.

What was our ROI?

First of all, we have gained time back that was previously wasted in management meetings. Secondly, approving any risk is much quicker with this solution, requiring only one click. RSA Archer has given us a return of investment on both time and money.

What's my experience with pricing, setup cost, and licensing?

The product is expensive, and there are additional costs if you need to integrate more licenses or want more features.

Which other solutions did I evaluate?

Before choosing RSA Archer, I evaluated MetricStream.

What other advice do I have?

I totally recommend RSA Archer for anything related to ERC for mid-to-large-sized businesses. I wouldn't recommend it for small businesses as it is very expensive. I would rate this solution as ten out of ten

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free RSA Archer Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free RSA Archer Report and get advice and tips from experienced pros sharing their opinions.