Forrester has evaluated this market since 2007. Nineteen years, multiple generations of vendors, and hundreds of millions in enterprise licence spend.
Its assessment of the category in 2026 is that many of these platforms still require too much manual data entry, offer only basic workflow automation, and are too complex, unwieldy, and expensive for the function they actually perform.
Manual data entry. In 2026. In a category that has been continuously analysed, funded, and reinvented for nearly two decades.
That verdict is the honest starting point for understanding this market, and it is more useful than any tier placement, because it tells you what to be sceptical about when a vendor demonstrates their platform.
What these platforms hold
A GRC platform is the system of record for how an organisation manages what could go wrong and proves it is managing it.
Underneath that sit several linked registers. A risk register, cataloguing what could harm the organisation, with likelihood, impact, and ownership. A control library, describing the mechanisms in place to mitigate those risks. A regulatory obligation inventory, mapping which rules apply to which parts of the business. Policy management, holding the documents and attestations. Issue and remediation tracking. Audit management, planning and evidencing internal audit work. And increasingly third-party risk, business continuity, and now AI governance.
The connective tissue is what matters. A control mitigates a risk, satisfies an obligation, is evidenced by a test, is owned by a person, and produces a finding when it fails. The platform's value is holding those relationships so that a change in one place propagates, and so that a question from a regulator or a board can be answered with something other than a spreadsheet assembled overnight.
Forrester's current criteria set spans sixteen current offering criteria and seven strategy criteria, including continuous controls monitoring, AI governance and risk management, audit management, risk quantification, scenario planning, integration quality, and user experience.
Why manual data entry persists
The complaint Forrester makes about this category is not a vendor failure so much as a structural one, and understanding why matters if you are about to buy.
The evidence a GRC platform needs lives somewhere else. Whether a control operated last quarter is knowable from the identity system, the ticketing system, the change management system, the HR system, or a signed document in someone's inbox. The GRC platform holds the assertion that the control operated. It rarely holds the underlying proof.
Bridging that gap requires either integration with dozens of systems, each with its own data model and access requirements, or a human who checks and types. Integration is expensive, brittle, and specific to each customer's estate. Typing is cheap to implement and expensive to operate, and it is what most deployments end up doing.
This is why continuous controls monitoring appears as a scored criterion and why it is the capability that would genuinely change the category. A control tested continuously by machine, against live system state, is a different product from a control attested quarterly by a human filling in a form. Everything else in a GRC platform is workflow around that distinction.
Compliance automation vendors built their businesses on solving exactly this for a narrow set of frameworks and cloud-native estates, which is a large part of why one of them now sits among the Leaders in a market previously owned by enterprise risk software.
Nineteen years of vendor replacement
The Forrester Wave: Enterprise Governance, Risk, And Compliance Platforms, Q4 2007, authored by Christopher McClean with Michael Rasmussen and two contributors, evaluated fifteen vendors against approximately one hundred criteria.
BWise led, with AXENTIS, MetricStream, OpenPages, Paisley, and QUMAS completing the Leaders. Strong Performers were 80-20 Software, Compliance 360, Cura, MEGA, and Strategic Thought Group. Certus Software, Mitratech, and Protiviti were Contenders. IBM was placed in a tier Forrester no longer uses, Risky Bet.
The Forrester Wave: Governance, Risk, And Compliance Platforms, Q1 2016, authored by Renee Murphy, evaluated fourteen against thirty criteria: EMC/RSA, Enablon, IBM, LogicManager, MetricStream, Nasdaq BWise, Navex Global, Protiviti, Resolver, Rsam, SAI Global, SAP, Thomson Reuters, and Wolters Kluwer Financial Services.
Two things stand out across those lists. Almost the entire 2007 field is gone as independent companies. And the one vendor Forrester singled out as a risky bet in 2007, IBM, was still in the market nine years later, having acquired OpenPages from the Leaders tier along the way.
The criteria count is the other story. Roughly one hundred criteria in 2007, thirty in 2016, twenty three in 2026. Evaluations narrow as capabilities commoditise, and a seventy-seven percent reduction over nineteen years describes a market where most of what these products do has stopped differentiating them.
Inside The Forrester Wave: Governance, Risk, And Compliance Platforms, Q2 2026
The current evaluation covers twelve vendors across sixteen current offering criteria and seven strategy criteria, and names four Leaders.
LogicGate placed as a Leader, positioning around agentic AI innovation, user experience, and time to value, with a template library, drag-and-drop configuration, and a stated roadmap moving from workflow automation toward agentic orchestration where autonomous agents execute GRC tasks and validate controls.
Optro also placed as a Leader with the highest possible score in AI governance and risk management, audit management, risk quantification, scenario planning and analysis, and user experience, positioned by Forrester as a fit for large enterprises wanting an easy-to-use platform with broad capability.
Vanta placed as a Leader too, which is the most interesting result in the evaluation given where that company came from. Compliance automation for cloud-native companies is a different origin from enterprise risk software, and its presence at the top of this market says something about which problem buyers now consider the hard one.
User experience appearing among the highest-scored criteria for multiple Leaders is not incidental. In a category Forrester describes as complex and unwieldy, being usable is a differentiator rather than a hygiene factor.
The AI pricing problem
The most immediately actionable finding in the current research has nothing to do with capability.
Forrester distinguishes two different things vendors sell under the AI heading. AI for GRC means AI capability delivered across the platform itself, making the product work better. AI governance means tooling that helps risk teams govern the organisation's own AI programmes and use cases.
Those are different products solving different problems, and Forrester's observation is that customers frequently end up paying for both depending on the vendor.
The pricing approaches Forrester encountered ranged from no additional charge, through fixed-price package additions, to consumption-based pricing keyed to the number of AI use cases governed. Reference customers were confused by these approaches and frequently cited a lack of clarity about the value for money they were getting.
Consumption pricing based on AI use cases governed deserves particular scrutiny. It means your GRC bill scales with how much AI your organisation adopts, at exactly the moment when AI adoption is accelerating and largely outside the risk function's control. A pricing model that grows automatically with someone else's decisions is a budget exposure rather than a cost.
Forrester also reports tepid customer feedback on AI adoption plans within these platforms, which is a notable finding in a market where every vendor is leading with AI. The enthusiasm is on the supply side.
What is driving demand anyway
The reason organisations keep buying despite the complaints is regulatory volume, and the numbers are the argument.
Forrester's research notes that one hundred and seventy countries now have cybersecurity and data protection laws, and describes security and risk professionals facing a flood of new regulation over the past five years. The resulting work is deciding which regulations apply, identifying gaps, and implementing controls, and that task scales badly as regulatory volume and pace increase.
That is genuinely a problem software should solve. Mapping one control to eleven obligations across six jurisdictions is exactly the kind of relational bookkeeping a database does well and a spreadsheet does badly.
It also explains why a category with acknowledged usability problems retains its buyers. The alternative is worse, and the cost of getting it wrong is regulatory rather than operational.
Reform, or another cycle
Forrester's forward view is that this market will fundamentally reform its purpose over the next eighteen to twenty four months, with vendors becoming orchestrators of outcomes and action for risk professionals rather than repositories of documentation.
That is the right destination and it is worth holding against the historical record.
The same promise, in different vocabulary, has been made repeatedly across this category's nineteen years. Integrated GRC was going to unify the silos. Risk-based approaches were going to move the function from checklist to insight. Continuous monitoring was going to end periodic attestation. Each wave delivered something real and left the core complaint intact, which is why Forrester is still writing about manual data entry in 2026.
The case that this time differs rests on agents being able to do the specific work that has always blocked the category: going into the systems where evidence actually lives, checking whether a control operated, and recording the result without a human transcribing anything. That is a genuinely different mechanism from workflow automation, which only ever moved the form around faster.
The case against is that agents accessing production systems to validate controls need permissions, governance, and auditability of their own, which is a control problem inside the control system. There is a recursive quality to solving GRC with autonomous software that the vendors have not yet had to answer for.
What a buyer can take from this is narrower than the vendor pitch. The measurable question is what proportion of your control evidence arrives without a human typing it, today, in your environment. That number is the whole category in one figure, and it is knowable before you sign anything.
Analyst Source
Forrester Research
Category definition, vendor inclusion, and evaluation findings in this article draw on Forrester's coverage of governance, risk, and compliance platforms, first evaluated in Q4 2007 against approximately 100 criteria, again in Q1 2016 against 30 criteria, in Q4 2023 with a companion Buyer's Guide built from 49 reference customers, and most recently in Q2 2026 covering 12 vendors against 23 criteria.
Source research
- Announcing The Forrester Wave: Governance, Risk, And Compliance Platforms, Q2 2026
- Buyer's Guide: Governance, Risk, And Compliance Platforms, 2024
- The Forrester Wave: Governance, Risk, And Compliance Platforms, Q1 2016
- The Forrester Wave: Enterprise Governance, Risk, And Compliance Platforms, Q4 2007
Forrester does not endorse any vendor named here, and tier placement should not be read as a recommendation to buy.