

RSA Archer and OneTrust GRC are key competitors in the Governance, Risk, and Compliance (GRC) landscape. RSA Archer tends to lead in complex workflow automation and comprehensive risk management capabilities, while OneTrust excels in user-friendliness and privacy management, making it particularly suited for cloud-based environments.
Features: RSA Archer offers advanced workflow automation, robust GRC functionalities, and comprehensive asset management capabilities. It integrates seamlessly with diverse tools and allows high levels of customization to fit specific enterprise needs. OneTrust GRC is renowned for its simplicity and strong privacy management features. It supports cloud-based IT management and vendor risk assessments with efficiency and has a straightforward compliance policy management tool.
Room for Improvement: RSA Archer users express concerns about its complex workflows and outdated user interface, requiring high maintenance and more intuitive customization options. Enhanced seamless integrations could bolster its offerings. OneTrust GRC faces challenges with workflow automation, particularly in multinational operations, and needs better system integrations. Enhanced AI capabilities could improve its functionality across more sophisticated environments.
Ease of Deployment and Customer Service: RSA Archer provides flexibility in deployment options, including on-premises and hybrid cloud, but can pose post-deployment challenges requiring frequent vendor support. Customer service experiences vary, with some users indicating slower response times. OneTrust GRC's deployment in public or private clouds often resolves these issues quickly. The platform is backed by strong community resources, although users sometimes face initial implementation hiccups.
Pricing and ROI: RSA Archer is costly, often deemed cost-effective by large organizations due to its extensive features and high ROI through centralized risk management. Smaller businesses may find the expense prohibitive. OneTrust GRC, while also priced on the higher end, offers pricing flexibility and negotiation leverage, frequently delivering return on investment through its IT risk management tools, particularly valuable at the enterprise level.
It relates to the effectiveness of employees and the time taken to complete tasks manually versus using the RSA system.
The response time from RSA Archer's support team is not an issue; usually, there's no problem getting a timely response, but there could be more knowledgeable agents available.
They are responsive and perform well in technical support.
Scalability depends on the number of servers, including web and service servers.
The level of scalability depends on customization and how skillful our customization team is.
Performance issues arise mainly since it is not a core service for most organizations, so the resources provided are fewer.
The tool has stability, and it allows me to automate whatever process I have.
A remaining area for improvement is integration. There should be built-in integration mechanisms, for example, for organizations switching from platforms like ServiceNow to Archer, instead of custom integrations for each client.
While the AI features are emerging and the cost is comparatively low, it's not yet up to the market standard.
Dashboards are usually effective, but while visibility from the dashboard level is good, drill-down details may be difficult to access, as they don't seem to have direct support for this drill-down.
after comparing it with other products in the market, I would rate it around six or seven out of ten, as the price is relative.
In the banking sector, Archer has been used to automate processes such as business continuity management, transitioning from manual processes to automated systems.
The helpful features of RSA Archer include providing an integrated overview of the landscape in the company, which leads the user to use the same inventory and other components, sharing the same set of references and objects we are working on.
This allows us to show end users and management where the issues lie and effectively demonstrate accountability and visibility in compliance.
| Product | Mindshare (%) |
|---|---|
| RSA Archer | 5.9% |
| OneTrust GRC | 3.1% |
| Other | 91.0% |

| Company Size | Count |
|---|---|
| Small Business | 3 |
| Midsize Enterprise | 2 |
| Large Enterprise | 9 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 6 |
| Large Enterprise | 25 |
OneTrust GRC centralizes privacy program needs with a focus on simplifying procedures through an intuitive interface. It is designed to support compliance for global regulations and enhance productivity with cloud-based IT and vendor risk management tools.
OneTrust GRC provides a comprehensive platform for managing privacy programs, offering key features such as risk assessments, privacy impact assessment automation, and incident management. Its modular setup is adaptable to compliance requirements for regulations including GDPR and CCPA. Organizations benefit from features like the Vendorpedia library, policy management, and seamless integration capabilities. Moreover, built-in templates assist with GDPR and ISO compliance, contributing to efficient multinational operations. Despite some challenges with setup complexity and global scalability, OneTrust GRC stands out in vendor risk management and data protection.
What features does OneTrust GRC offer?Organizations across industries implement OneTrust GRC for comprehensive privacy program management, focusing on compliance with rules like GDPR and CCPA. Key applications include vendor risk management, incident response, and governance risk projects. Companies value its automated data mapping, privacy request handling, IT audits, risk assessments, and project tracking, which improve data protection and streamline workflow.
RSA Archer provides robust risk management, compliance, and vendor management with intuitive features for customizable and streamlined governance tasks.
RSA Archer delivers integrated solutions supporting risk management and compliance tasks. Its adaptive interface and customizable options enhance workflows, making it valuable for organizations requiring automation, advanced workflows, and easy integration capabilities. While offering flexibility and configuration power, users note potential enhancements for integration, reporting, and interface updates.
What are the key features of RSA Archer?In the finance, public, and IT sectors, RSA Archer is utilized for managing risk and compliance. Organizations leverage its capabilities for third-party risk, policy management, and security assessments, providing tailored solutions for regulatory compliance and operational risk management. Integration with platforms like ServiceNow enhances its utility within enterprise environments.
We monitor all GRC reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.