No more typing reviews! Try our Samantha, our new voice AI agent.

SAP BusinessObjects GRC vs Snyk comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 11, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

SAP BusinessObjects GRC
Ranking in GRC
13th
Average Rating
7.4
Reviews Sentiment
4.2
Number of Reviews
7
Ranking in other categories
Continuous Controls Monitoring (2nd)
Snyk
Ranking in GRC
5th
Average Rating
8.2
Reviews Sentiment
7.3
Number of Reviews
51
Ranking in other categories
Application Performance Monitoring (APM) and Observability (21st), Application Security Tools (8th), Static Application Security Testing (SAST) (6th), Cloud Management (13th), Vulnerability Management (19th), Container Security (7th), Software Composition Analysis (SCA) (3rd), Software Development Analytics (2nd), Cloud Security Posture Management (CSPM) (17th), DevSecOps (3rd), Application Security Posture Management (ASPM) (2nd), AI Security (9th)
 

Mindshare comparison

As of May 2026, in the GRC category, the mindshare of SAP BusinessObjects GRC is 1.5%, down from 1.9% compared to the previous year. The mindshare of Snyk is 1.8%, up from 0.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
GRC Mindshare Distribution
ProductMindshare (%)
Snyk1.8%
SAP BusinessObjects GRC1.5%
Other96.7%
GRC
 

Featured Reviews

Vishal Guthula - PeerSpot reviewer
Sr Advanced Analytics Analyst at a manufacturing company with 10,001+ employees
Experienced security and easy understanding with advanced customization enhances efficiency
Regarding automation, they could enhance features for checking real-time data when someone attempts to access data without proper permissions. Currently, we do not receive immediate alerts; we only discover issues after something goes wrong. Having prevention alerts immediately when someone triggers unauthorized actions would allow us to address these situations proactively.
Abhishek-Goyal - PeerSpot reviewer
Software Engineer at a computer software company with 11-50 employees
Improves security posture by actively reducing critical vulnerabilities and guiding remediation
Snyk's main features include open-source vulnerability scanning, code security, container security, infrastructure as code security, risk-based prioritization, development-first integration, continuous monitoring and alerting, automation, and remediation. The best features I appreciate are the vulnerability checking, vulnerability scanning, and code security capabilities, as Snyk scans all open-source dependencies for known vulnerabilities and helps with license compliance for open-source components. Snyk integrates into IDEs, allowing issues to be caught as they appear in the code dynamically and prioritizes risk while providing remediation advice. Snyk provides actionable remediation advice on where vulnerabilities can exist and where code security is compromised, automatically scanning everything and providing timely alerts. Snyk has positively impacted my organization by improving the security posture across all software repositories, resulting in fewer critical vulnerabilities, more confidence in overall product security, and faster security compliance for project clients. Snyk has helped reduce vulnerabilities significantly. Initially, the repository had 17 to 31 critical and high vulnerabilities, but Snyk has helped manage them down to just five vulnerabilities, which are now lower and not high or critical.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The stability of SAP BusinessObjects GRC is acceptable."
"Initial setup was straightforward. It took maybe one week."
"The customization options in the dashboards inside SAP BusinessObjects GRC are highly valuable, and the real-time monitoring feature performs effectively, allowing teams to maintain data security by restricting domain visibility."
"Initial setup was straightforward. It took maybe one week."
"It improved the organization's reporting culture, giving us insights into health, management, and operational results."
"The best features are the scalability and flexibility to implement applications on top of the BW."
"It is wonderful from the control perspective. The GRC tools help you in knowing what are the risk controls, how to mitigate risks, and how to ensure that there are no conflicts between the roles."
"We have enterprise clients for the product."
"It has an accurate database of vulnerabilities with a low amount of false positives."
"I find SCA to be valuable. It can read your libraries, your license and bring the best way to resolve your problem in the best scenario."
"Snyk's ability to scan all of those every time we build, and keep a running status of them and recheck them daily, is extremely valuable for making us aware of what's going on."
"The advantage of Snyk is that Snyk automatically creates a pull request for all the findings that match or are classified according to the policy that we create. So, once we review the PR within Snyk and we approve the PR, Snyk auto-fixes the issue, which is quite interesting and which isn't there in any other product out there. So, Snyk is a step ahead in this particular area."
"We went from 15 vulnerabilities in it to four or five, and those four or five were un-upgradable and we were not affected by them."
"The solution's Open Source feature gives us notifications and suggestions regarding how to address vulnerabilities."
"It helps us meet compliance requirements, by identifying and fixing vulnerabilities, and to have a robust vulnerability management program."
"Snyk is paramount and extremely important for us because anything that goes to production should not have any security vulnerabilities, and every application that goes into production must pass Snyk vulnerability scanning before it can be deployed."
 

Cons

"I think the old system is better than the new one. From an improvement perspective, the tool needs to ensure that the new technologies it offers are better than the old ones."
"BusinessObjects is very dated. It is not that user-friendly. It should be made more user-friendly. In addition, if they could make predictive analytics an embedded part of it where people get to know what is there to offer, it would be great."
"I am working on features that are not functioning as expected, which creates significant difficulties in management."
"The learning curve is high."
"Currently, we do not receive immediate alerts; we only discover issues after something goes wrong."
"Technical support could be better and faster."
"BusinessObjects is very dated. It is not that user-friendly."
"We cannot actively log in to the system. It should also improve support."
"We would like to have upfront knowledge on how easy it should be to just pull in an upgraded dependency, for example, even introduce full automation for dependencies supposed to have no impact on the business side of things."
"Snyk's API and UI features could work better in terms of speed."
"I use Snyk alongside Sonar, and Snyk tends to generate a lot of false positives. Improving the overall report quality and reducing false positives would be beneficial. I don't need additional features; just improving the existing ones would be enough."
"We would like to have upfront knowledge on how easy it should be to just pull in an upgraded dependency, e.g., even introduce full automation for dependencies supposed to have no impact on the business side of things. Therefore, we would like some output when you get the report with the dependencies. We want to get additional information on the expected impact of the business code that is using the dependency with the newer version. This probably won't be easy to add, but it would be helpful."
"The log export function could be easier when shipping logs to other platforms such as Splunk."
"You need to go to the tool, export it as a CSV, and then find it, which is ridiculous."
"All such tools should definitely improve the signatures in their database. Snyk is pretty new to the industry. They have a pretty good knowledge base, but Veracode is on top because Veracode has been in this business for a pretty long time. They do have a pretty large database of all the findings, and the way that the correlation engine works is superb. Snyk is also pretty good, but it is not as good as Veracode in terms of maintaining a large space of all the historical data of vulnerabilities."
"The product could be improved by including other types of security scanning (e.g. SAST or DAST), which is important."
 

Pricing and Cost Advice

"SAP BusinessObjects GRC is expensive."
"The product's licensing costs involve a one-time purchase. The tool also allows others to make annual payments towards the licensing charges of the product."
"The license is costly."
"There is a yearly licensing cost. I would rate their pricing 4 out of 5."
"It is pretty expensive. It is not a cheap product."
"It's good value. That's the primary thing. It's not cheap-cheap, but it's good value."
"On a scale of one to ten, where one is cheap and ten is expensive, I rate the pricing a three. It is a cheap solution."
"Their licensing model is fairly robust and scalable for our needs. I believe we have reached a reasonable agreement on the licensing to enable hundreds of developers to participate in this product offering. The solution is very tailored towards developers and its licensing model works well for us."
"The pricing is acceptable, especially for enterprises. I don't think it's too much of a concern for our customers. Something like $99 per user is reasonable when the stakes are high."
"For what Snyk offers, it has the best cost-benefit I have ever seen because you're buying the license per user."
"The license model is based on the number of contributing developers. Snyk is expensive, for a startup company will most likely use the community edition, while larger companies will buy the licensed version. The price of Snyk is more than other SLA tools."
"The price is good. Snyk had a good price compared to the competition, who had higher pricing than them. Also, their licensing and billing are clear."
report
Use our free recommendation engine to learn which GRC solutions are best for your needs.
893,221 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
12%
Construction Company
11%
Healthcare Company
10%
Financial Services Firm
10%
Financial Services Firm
14%
Computer Software Company
10%
Manufacturing Company
9%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business1
Large Enterprise6
By reviewers
Company SizeCount
Small Business21
Midsize Enterprise9
Large Enterprise22
 

Questions from the Community

What needs improvement with SAP BusinessObjects GRC?
Regarding automation, they could enhance features for checking real-time data when someone attempts to access data without proper permissions. Currently, we do not receive immediate alerts; we only...
What is your primary use case for SAP BusinessObjects GRC?
I work with SAP, and currently I am working with other domains such as Power BI, Microsoft, and in the AI sector. When working with Microsoft, I utilize solutions such as Intune, Configuration Mana...
What advice do you have for others considering SAP BusinessObjects GRC?
The overall rating for SAP BusinessObjects GRC is 8.5 out of 10. I would rate GRC solutions at eight. Nothing is perfect; if someone attempts to hack, they can create issues. The method and process...
How does Snyk compare with SonarQube?
Snyk does a great job identifying and reducing vulnerabilities. This solution is fully automated and monitors 24/7 to find any issues reported on the internet. It will store dependencies that you a...
What needs improvement with Snyk?
There are a lot of false positives that need to be identified and separated. The inclusion of AI to remove false positives would be beneficial. So far, I've not seen any AI features to enhance vuln...
What is your primary use case for Snyk?
I use Snyk ( /products/snyk-reviews ) in the DevOps pipeline to identify vulnerabilities before deploying the application. It integrates with Jenkins ( /products/jenkins-reviews ).
 

Also Known As

BusinessObjects GRC
Fugue, Snyk AppRisk
 

Overview

 

Sample Customers

INEOS Melamines GmbH, Banco Galicia
StartApp, Segment, Skyscanner, DigitalOcean, Comic Relief
Find out what your peers are saying about SAP BusinessObjects GRC vs. Snyk and other solutions. Updated: April 2026.
893,221 professionals have used our research since 2012.