

RSA Archer and OneTrust GRC are key competitors in the Governance, Risk, and Compliance (GRC) landscape. RSA Archer tends to lead in complex workflow automation and comprehensive risk management capabilities, while OneTrust excels in user-friendliness and privacy management, making it particularly suited for cloud-based environments.
Features: RSA Archer offers advanced workflow automation, robust GRC functionalities, and comprehensive asset management capabilities. It integrates seamlessly with diverse tools and allows high levels of customization to fit specific enterprise needs. OneTrust GRC is renowned for its simplicity and strong privacy management features. It supports cloud-based IT management and vendor risk assessments with efficiency and has a straightforward compliance policy management tool.
Room for Improvement: RSA Archer users express concerns about its complex workflows and outdated user interface, requiring high maintenance and more intuitive customization options. Enhanced seamless integrations could bolster its offerings. OneTrust GRC faces challenges with workflow automation, particularly in multinational operations, and needs better system integrations. Enhanced AI capabilities could improve its functionality across more sophisticated environments.
Ease of Deployment and Customer Service: RSA Archer provides flexibility in deployment options, including on-premises and hybrid cloud, but can pose post-deployment challenges requiring frequent vendor support. Customer service experiences vary, with some users indicating slower response times. OneTrust GRC's deployment in public or private clouds often resolves these issues quickly. The platform is backed by strong community resources, although users sometimes face initial implementation hiccups.
Pricing and ROI: RSA Archer is costly, often deemed cost-effective by large organizations due to its extensive features and high ROI through centralized risk management. Smaller businesses may find the expense prohibitive. OneTrust GRC, while also priced on the higher end, offers pricing flexibility and negotiation leverage, frequently delivering return on investment through its IT risk management tools, particularly valuable at the enterprise level.
It relates to the effectiveness of employees and the time taken to complete tasks manually versus using the RSA system.
The response time from RSA Archer's support team is not an issue; usually, there's no problem getting a timely response, but there could be more knowledgeable agents available.
They are responsive and perform well in technical support.
Scalability depends on the number of servers, including web and service servers.
The level of scalability depends on customization and how skillful our customization team is.
Performance issues arise mainly since it is not a core service for most organizations, so the resources provided are fewer.
The tool has stability, and it allows me to automate whatever process I have.
A remaining area for improvement is integration. There should be built-in integration mechanisms, for example, for organizations switching from platforms like ServiceNow to Archer, instead of custom integrations for each client.
While the AI features are emerging and the cost is comparatively low, it's not yet up to the market standard.
Dashboards are usually effective, but while visibility from the dashboard level is good, drill-down details may be difficult to access, as they don't seem to have direct support for this drill-down.
after comparing it with other products in the market, I would rate it around six or seven out of ten, as the price is relative.
In the banking sector, Archer has been used to automate processes such as business continuity management, transitioning from manual processes to automated systems.
The helpful features of RSA Archer include providing an integrated overview of the landscape in the company, which leads the user to use the same inventory and other components, sharing the same set of references and objects we are working on.
This allows us to show end users and management where the issues lie and effectively demonstrate accountability and visibility in compliance.
| Product | Market Share (%) |
|---|---|
| RSA Archer | 5.8% |
| OneTrust GRC | 3.4% |
| Other | 90.8% |

| Company Size | Count |
|---|---|
| Small Business | 3 |
| Midsize Enterprise | 2 |
| Large Enterprise | 9 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 6 |
| Large Enterprise | 25 |
OneTrust is the largest and most widely used technology platform to operationalize privacy, security and third-party risk management. More than 2,500 customers, both big and small and across 100 countries, use OneTrust to demonstrate compliance with privacy regulations including the GDPR, California Consumer Privacy Act, Brazil LGPD, and hundreds of the world's privacy laws.
OneTrust's size and scale allows it to offer the easiest-to-use and most affordable solution for implementing use cases including: Privacy Maturity Benchmarking, Data Protection by Design and Default (PbD), Data Protection Impact Assessments (PIA/DPIA), Third-Party Vendor Risk Management, Incident and Breach Response, Data Mapping (Records of Processing), Customer Preference Management, Consent Management, Website Scanning & Cookie Compliance, Mobile App Scanning, Data Subject/Consumer Rights Management and Policy & Notice Management.
The platform's intelligence comes from DataGuidance by OneTrust, an in-depth and up-to-date source of privacy and security regulatory summaries, guidance, templates, case law, and analysis. The database is updated daily by over 20 in-house privacy researchers, along with a network of 500 lawyers across over 300 jurisdictions.
OneTrust's 700 employees are located across co-headquarters in Atlanta and in London with additional locations in Bangalore, Melbourne, San Francisco, New York, Munich and Hong Kong. To learn more, visit OneTrust.com.
RSA Archer is a solution designed to help your organization manage policies, controls, risks, assessments, and deficiencies across your lines of business. RSA helps you manage your digital risk with a range of capabilities and expertise including integrated risk management, threat detection and response, identity and access management, as well as fraud prevention.
The solution also allows you to adapt a broad range of solutions to your requirements and is a good option for both big and small companies.
RSA Archer Features
RSA Archer has many valuable key features. Some of the most useful ones include:
RSA Archer Benefits
There are many benefits to implementing RSA Archer. Some of the biggest advantages the solution offers include:
Reviews from Real Users
Below are some reviews and helpful feedback written by PeerSpot users currently using the RSA Archer solution.
A Specialist, RSA Archer at a tech services company, says, “RSA Archer is a valuable tool because it can manage the end-to-end functioning of any enterprise GRC module, such as compliance and risk management or business continuity plans and the entire BCM module. RSA Archer also provides many out-of-the-box solutions, which are use cases derived from the standards for GRC or risk management, governance, and compliance. It provides an end-to-end mechanism for business users on a single platform. That includes reporting, managing workflow, creating documentation, or tracking a process where you need to get approval from the various levels within the organization's hierarchy.”
PeerSpot user Krishnendu S., Vice President at a financial services firm, mentions, "It is enterprise-wide accessible. So, it is very helpful for all the employees in our bank. They can log in and do their risk management activities. It has a few inbuilt modules that are helpful for doing risk management activities, such as issue management, risk identification, risk assessment, and policy exception management. It also has some inbuilt workflows inside these modules. They are also helpful."
A Sr. Internal Auditor at an energy/utilities company comments, "Its user interface is pretty neat, and there is flexibility in generating the data. You can customize reports at any level. You can directly get reports in Tableau format. If you want to generate statistical data, you can create reports with graphs. There is an adequate amount of flexibility for changing the format, the type of graphs, etc."
Another PeerSpot user, Manash B., Technology Manager at a tech services company, explains, "RSA is a very rich application. I like its adaptive suggestion, where based on your users and the class of data, it can actually recommend you the proper control to choose. For example, we have been using PCI DSS as an NIST. So based on application feedback, it will provide you with a suggestion on which control objective needs to be set. Based on that, you can make a decision—you don't need to take the suggestion, but you can customize that particular provided suggestion. RSA Archer's workflow is also good, in terms of process automation."
We monitor all GRC reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.