Report:
The Forrester Wave™: Governance, Risk, And Compliance Platforms, Q2 2026
How does Forrester define the Governance, Risk, And Compliance Platforms market in 2026?
The GRC platform market is shifting from systems of record to systems of action. For two decades, GRC platforms have centralized risks, controls, issues, policies, and obligations, but too many programs still rely on manually updating them. A GRC platform's fundamental purpose is to enable organizations to safely take on more risk for more reward. The market is moving toward platforms that can orchestrate action — detecting signals, connecting data, enforcing controls, triggering remediation, and delivering decision-ready insights. Vendors are responding but moving too slowly relative to customer demand. Key market shifts include: 1) GRC platforms evolving from record-keeping to actionable systems with AI, integrations, and analytics; 2) Continuous controls monitoring shifting from audit evidence collection to policy enforcement and GRC engineering; 3) AI delivering minimal transformative value today despite loud marketing, with customers needing to validate experimental capabilities.
Key Facts for The Forrester Wave™: Governance, Risk, And Compliance Platforms, Q2 2026 in 2026
- Publication Date: 29-May-2026
- Document ID: 70075f39
- Summary: In our evaluation of governance, risk, and compliance (GRC) platform providers, we identified the most significant ones and researched, analyzed, and scored them. This report shows how each provider measures up and helps you select the right one for your needs.
- Authors: Paul McKay, Cody Scott
How did the Governance, Risk, And Compliance Platforms market evolve in 2026?
- GRC platforms are evolving from systems of record to systems of action
- Continuous controls monitoring (CCM) is shifting from audit evidence collection to policy enforcement
- AI is receiving the most marketing attention but currently delivers minimal transformative value
- Vendors are moving too slowly to realize the vision of automated, orchestrated GRC at the pace customers demand
- The market is shifting toward platforms that can orchestrate action — detecting signals, connecting data, enforcing controls, triggering remediation, and delivering decision-ready insights
- 12 vendors were evaluated: Optro, Diligent, LogicGate, Vanta (Leaders); ServiceNow, MetricStream, Workiva, OneTrust, Archer (Strong Performers); IBM, Riskonnect, NAVEX (Contenders)
- Evaluation materials were collected by March 4, 2026
What product features are required to be included in this year's evaluation?
- Broad, enterprise-level support. The vendor natively provides all core functions for the GRC market and has a demonstrated track record of supporting large enterprises.
- Substantial revenue in the market. The vendor has at least $40 million in annual revenue from the GRC product in the past four quarters.
- A global customer base. The vendor serves customers in at least three of the four global regions: North America; Latin America; Europe, the Middle East, and Africa; and Asia Pacific. The vendor must not derive more than 50% of its global revenue from a single region.
- Mindshare among Forrester's enterprise clients. Forrester clients frequently mention the product as one they are considering prior to a purchase. We have heard about the product from our clients in the form of inquiries, advisories, consulting engagements, and other interactions over the past year. Other vendors mention this vendor as a competitor.
What are the common features of top products in the Governance, Risk, And Compliance Platforms space?
No common features specified.
Scope Exclusions
- Vendors with less than $40 million in annual GRC product revenue
- Vendors serving fewer than three of the four global regions
- Vendors deriving more than 50% of global revenue from a single region
- Vendors lacking broad enterprise-level support across all core GRC functions
- Vendors without demonstrated track record supporting large enterprises
- Vendors lacking mindshare among Forrester's enterprise clients
- Vendors focused primarily on cybersecurity GRC without enterprise risk management (e.g., Drata)
- Vendors that pivoted away from GRC to other focus areas (e.g., Fusion Risk Management to operational resilience)
- Vendors with reduced customer mindshare since previous evaluations (e.g., Resolver, SAI360)
Inclusion Criteria
Vendors must, among other requirements:
- Broad, enterprise-level support: The vendor natively provides all core functions for the GRC market and has a demonstrated track record of supporting large enterprises
- Substantial revenue in the market: The vendor has at least $40 million in annual revenue from the GRC product in the past four quarters
- A global customer base: The vendor serves customers in at least three of the four global regions: North America; Latin America; Europe, the Middle East, and Africa; and Asia Pacific. The vendor must not derive more than 50% of its global revenue from a single region
- Mindshare among Forrester's enterprise clients: Forrester clients frequently mention the product as one they are considering prior to a purchase
Offering Strengths — Relative Weighting
- AI governance and risk management — 5%
- Audit management — 5%
- Compliance management — 10%
- Continuous controls monitoring — 10%
- Enterprise risk management — 10%
- Integration quality — 5%
- Platform use of AI and AI agents — 5%
- Risk identification — 5%
- Risk intelligence — 5%
- Risk remediation — 5%
- Risk reporting — 5%
- Risk quantification — 5%
- Scenario planning and analysis — 5%
- Technology risk management — 10%
- User experience — 5%
- Workflow management — 5%
Strategy Strength — Relative Weighting
- Vision — 15%
- Innovation — 15%
- Roadmap — 20%
- Partner ecosystem — 15%
- Adoption — 15%
- Pricing flexibility and transparency — 10%
- Supporting services and offerings — 10%
FAQs
Q: What does this research cover?
A: This research evaluates 12 governance, risk, and compliance (GRC) platform providers across current offering capabilities, strategic vision and execution, and customer feedback. It assesses vendors' abilities to deliver comprehensive GRC functionality including enterprise risk management, compliance management, audit management, continuous controls monitoring, technology risk management, AI governance, risk intelligence, and workflow automation.
Q: Who should use this research?
A: GRC platform customers should use this research to inform purchase decisions by understanding how vendors compare across capabilities and strategy. Risk professionals, compliance officers, internal audit teams, and technology leaders evaluating GRC platforms can use this assessment to identify vendors that best fit their specific needs for automation, AI capabilities, continuous monitoring, and integration requirements.
Q: What are the mandatory features of vendors included in this market?
A: To be included in this Forrester Wave evaluation, vendors must meet four mandatory criteria: 1) Broad enterprise-level support - natively providing all core GRC functions with demonstrated track record supporting large enterprises; 2) Substantial market revenue - at least $40 million in annual revenue from GRC product in past four quarters; 3) Global customer base - serving customers in at least three of four global regions (North America, Latin America, EMEA, Asia Pacific) with no more than 50% revenue from single region; 4) Mindshare among Forrester enterprise clients - frequently mentioned by clients in inquiries, advisories, consulting engagements and recognized as competitor by other vendors.
Q: What are some reasons for not being included in this report?
A:
- Insufficient annual revenue from GRC product (less than $40 million)
- Limited geographic presence (fewer than three global regions)
- Over-concentration in single region (more than 50% of revenue)
- Lack of comprehensive enterprise-level GRC functionality
- Missing core GRC modules (e.g., Drata lacks enterprise risk management module)
- Strategic pivot away from GRC market (e.g., Fusion Risk Management pivoted to operational resilience)
- Reduced customer mindshare and market presence
- Primary focus on specialized use cases rather than holistic GRC (e.g., SAI360 for ethics/compliance/third-party risk only)
- Insufficient mindshare among Forrester's enterprise client base
- Lack of demonstrated track record with large enterprise customers
Q: What should buyers consider when evaluating products in this market?
A:
- GRC platforms must be both a system of record and a system of action - avoid platforms that only replace spreadsheets without delivering insights that enable action on risk
- Focus on how platforms help organize data, contextualize it, and deliver actionable insights rather than just centralizing information
- Prioritize continuous controls monitoring that links evidence, monitoring, and enforcement - not just faster audit cycles or evidence collection
- Look for CCM that aligns with GRC engineering: codify requirements, monitor production, and enforce policy before failures occur
- Mind the gap between GRC AI capabilities and marketing hype - validate that AI features work in practice, not just in demos
- Be skeptical of experimental AI capabilities with inconsistent pricing where you're paying for untested features
- Evaluate whether AI delivers transformative value beyond marginal improvements like data summaries and draft narratives
- Assess vendor ability to orchestrate action: detecting signals, connecting data, enforcing controls, triggering remediation, and delivering decision-ready insights
- Consider platform maturity in areas like integrations, risk and control analytics, and workflow automation
- Evaluate support for policy and compliance as code, not just traditional forms-based approaches
Q: How has the Governance, Risk, And Compliance Platforms market evolved in 2026?
A:
- GRC platforms are evolving from systems of record to systems of action, requiring both centralized data management and automated orchestration capabilities
- Continuous controls monitoring is shifting from audit evidence collection to policy enforcement and GRC engineering (codify requirements, monitor production, enforce policy before failures)
- AI implementation in GRC is loud in marketing but delivering minimal transformative value currently, with most capabilities limited to data summaries, draft narratives, and guided search
- Vendors are rapidly rolling out purpose-built GRC agents for multiple use cases, but customers must validate experimental AI capabilities in practice
- Automation improvements in AI implementation, integrations, and risk/control analytics are making orchestration and remediation easier in modern platforms
- The market demands platforms that can detect signals, connect data, enforce controls, trigger remediation, and deliver decision-ready insights
- Inconsistent AI pricing models are deepening buyer skepticism when paying for untested features
- Many vendors still lack strong support for policy and compliance as code despite CCM evolution
Q: What differentiates Strength of Offering vs. Strength of Strategy?
A: Strength of Offering evaluates a vendor's current product capabilities across 16 criteria including core GRC functions (audit, compliance, risk management), technical capabilities (AI, integrations, CCM), and user experience. Total weighting is 100% focused on present-day product functionality. Strength of Strategy evaluates a vendor's future direction and market approach across 7 criteria including vision, innovation, roadmap, partnerships, adoption approach, pricing, and services. Total weighting is 100% focused on strategic positioning and ability to evolve. Current Offering answers 'How good is the product today?' while Strategy answers 'How well-positioned is the vendor for future success?'
Reference
- Forrester, The Forrester Wave™: Governance, Risk, And Compliance Platforms, Q2 2026, 29-May-2026, ID 70075f39
View Leaders
View Vendor Movements