• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • Loading categories...

      Browse All Categories

      Loading markets...

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
All Categories
/
IT Risk Management

IT Risk Management (ITRM) Reviews and Ratings

What are ITRM (IT Risk Management) Solutions?

The IT risk management (ITRM) market focuses on solutions that support the ITRM discipline through automating common workflows and requirements. For the purposes of defining this market, IT risks are risks within the scope and responsibility of the IT department. These include IT dependencies that create uncertainty in daily tactical business activities, and IT risk events resulting from inadequate or failed internal IT processes, people or systems, or from external events.

How Categories and Markets Are Defined
Highest Rated By Your Peers
For Willingness to Recommend
Logo of JupiterOne
JupiterOne
Logo of Axonius Cybersecurity Asset Management Platform
Axonius Cybersecurity Asset Management Platform
Logo of Sevco Platform
Sevco Platform
For 50M-1B USD Companies
Logo of Axonius Cybersecurity Asset Management Platform
Axonius Cybersecurity Asset Management Platform
Logo of ServiceNow Governance Risk and Compliance (GRC)
ServiceNow Governance Risk and Compliance (GRC)
Logo of Vanta
Vanta
For North America
Logo of Censinet Third-Party Vendor Risk Management Software Platform
Censinet Third-Party Vendor Risk Management Software Platform
Logo of Axonius Cybersecurity Asset Management Platform
Axonius Cybersecurity Asset Management Platform
Logo of Sevco Platform
Sevco Platform
Integration & Deployment
Logo of isorobot
isorobot
Logo of Sevco Platform
Sevco Platform
Logo of Balbix
Balbix

Product Listings

Filter by

Products 1 - 20 of 77
Sort by
Logo of Archer IT & Security Risk Management

Archer IT & Security Risk Management

By Archer

4.2
(170 Ratings)

Archer IT & Security Risk Management is software designed to enable organizations to identify, assess, monitor, and manage IT and security risks across their enterprise. The software provides centralized visibility into risk and compliance processes while supporting risk assessments, control evaluations, incident management, and regulatory reporting. It allows businesses to automate workflows, track remediation activities, and produce actionable risk insights through customizable dashboards and reports. By streamlining the management of risk, policies, and controls, the software helps organizations address threats, meet regulatory requirements, and align risk management processes with business objectives.

Show More Details
Logo of OneTrust Tech Risk & Compliance

OneTrust Tech Risk & Compliance

By OneTrust

4.2
(101 Ratings)

OneTrust Tech Risk & Compliance is a software designed to help organizations identify, assess, and manage technology-related risks while facilitating adherence to regulatory and policy requirements. The software offers features such as automated risk assessments, control monitoring, regulatory mapping, and workflow management for issue remediation. It supports integration with various technology platforms to provide a centralized view of technology risk and compliance activities. The software enables organizations to document processes, track mitigation efforts, and generate reports that support audit and compliance objectives. It addresses challenges related to complex regulatory environments, fragmented risk data, and manual compliance processes by streamlining risk identification and promoting consistent risk management practices.

Show More Details
Logo of Diligent One Platform

Diligent One Platform

By Diligent

4.3
(92 Ratings)

Diligent One Platform is a software that integrates governance, risk and compliance functionalities to support organizational oversight and decision-making. The software offers modules for board management, risk assessment, internal controls, audit management and compliance tracking. It enables users to centralize documentation, monitor regulatory requirements, and automate reporting processes. By providing analytics and customizable dashboards, the software aims to streamline workflows and enhance transparency in managing risks and meeting compliance obligations. Diligent One Platform is designed to facilitate collaboration among stakeholders, support policy and procedure management, and help organizations address regulatory and operational challenges.

Show More Details
Logo of ServiceNow Governance Risk and Compliance (GRC)

ServiceNow Governance Risk and Compliance (GRC)

By ServiceNow

4.4
(86 Ratings)

ServiceNow Governance Risk and Compliance (GRC) software offers capabilities for managing risk, compliance, and audit processes within organizations. The software integrates policies, controls, and risk assessments into a unified platform, facilitating real-time visibility into risk status and regulatory compliance. It supports automation of workflows for incident response, policy management, and audit tracking, helping organizations streamline reporting and maintain accountability. The software provides dashboards and analytics for monitoring ongoing compliance activities and identifying areas for improvement. By centralizing information and processes, ServiceNow Governance Risk and Compliance software aims to reduce manual efforts, support decision-making, and address regulatory and corporate governance requirements within business operations.

Show More Details
Logo of NAVEX IRM Software (Legacy)

NAVEX IRM Software (Legacy)

By NAVEX

4.4
(61 Ratings)

NAVEX IRM Software is designed to support organizations with integrated risk management by providing tools to identify, assess, and manage risks across various business units. The software enables users to automate risk and compliance workflows, document and track incidents, evaluate controls, and ensure regulatory adherence. Features include centralized dashboards, reporting capabilities, policy management, and audit tracking. NAVEX IRM Software assists businesses in improving visibility into risk exposure and helps facilitate the management of operational, third-party, and IT-related risks to support informed decision-making and organizational governance.

Show More Details
Logo of SAFE One

SAFE One

By Safe Security

4.5
(52 Ratings)

SAFE One is a software developed by SAFE Security designed to provide organizations with capabilities to measure, manage, and mitigate cyber risk across their digital infrastructure. The software utilizes data-driven risk assessment to deliver real-time, quantitative insights into the security posture of various assets, including applications, networks, and endpoints. It offers functionalities for continuous monitoring, risk modeling, and compliance reporting, enabling organizations to identify vulnerabilities, prioritize remediation efforts, and align security investments with business objectives. SAFE One addresses the business challenge of understanding and reducing cyber risk exposure by offering centralized visibility and actionable intelligence for enterprise-wide security management.

Show More Details
Logo of Allgress

Allgress

By Allgress

4.3
(45 Ratings)

Allgress is a software designed to streamline and simplify risk management, compliance, and security operations for organizations. The software assists users in identifying, assessing, and mitigating risks associated with information technology and regulatory requirements. It provides features such as automated risk assessments, compliance tracking, policy management, and reporting capabilities. Allgress software enables businesses to categorize and prioritize risks, monitor regulatory changes, and maintain documentation for audits. By facilitating efficient risk and compliance processes, the software aims to reduce manual effort and help organizations maintain a comprehensive understanding of their risk posture.

Show More Details
Logo of Axonius Cybersecurity Asset Management Platform

Axonius Cybersecurity Asset Management Platform

By Axonius

4.6
(42 Ratings)

Axonius Cybersecurity Asset Management Platform is a software that enables organizations to automate the process of discovering, inventorying, and managing technology assets across their entire infrastructure. The software collects and correlates data from various sources such as cloud providers, endpoint agents, network devices, and security solutions to provide a unified view of all assets. Through its capabilities, the software assists in identifying gaps in coverage, policy violations, and compliance issues, supporting security teams in enforcing security policies and making informed decisions. The software integrates with a wide range of existing tools to provide visibility into devices, users, and software, assisting organizations in addressing challenges related to asset visibility, security control validation, and operational efficiency.

Show More Details
Logo of ZenGRC

ZenGRC

By ZenGRC

4.2
(42 Ratings)

ZenGRC is a governance, risk, and compliance software developed to assist organizations in managing risk and compliance programs across various frameworks and standards. The software centralizes risk and compliance data, automates workflows, and provides insights through customizable dashboards and reporting tools. ZenGRC enables mapping of controls and processes to industry requirements, streamlines evidence collection, and facilitates audit management. It supports integration with other security and IT management systems, aiding organizations in tracking compliance tasks, monitoring risk levels, and ensuring policy adherence. The software addresses the business problem of complex compliance management by reducing manual effort and improving visibility across regulatory and operational requirements.

Show More Details
Logo of IBM OpenPages

IBM OpenPages

By IBM

4.2
(31 Ratings)

IBM OpenPages is a software designed to support integrated risk management and governance, risk, and compliance functions for organizations. The software includes modules for managing operational risk, regulatory compliance, policy management, internal audit, and financial controls. It provides a unified platform that enables businesses to identify, assess, monitor, and report on various types of risks across multiple departments. With analytics, automation capabilities, and centralized data repositories, IBM OpenPages facilitates more efficient tracking and analysis of risks, enhances workflows, and helps organizations to align risk management processes with strategic objectives. This software addresses the business need to manage risks, compliance, and controls in a systematic manner to support governance and accountability.

Show More Details
Logo of Vanta

Vanta

By Vanta

4.4
(27 Ratings)

Vanta’s Trust Management Platform helps organizations identify, assess, and manage IT security risks through automation and continuous monitoring. Over 10,000 teams rely on Vanta to streamline IT risk assessments, maintain compliance with 35+ security frameworks, and improve visibility into risk exposure. By centralizing IT risk management processes, Vanta enables Security, GRC, and IT professionals to reduce operational overhead, improve efficiency, and strengthen their security posture.

Show More Details
Logo of Sai360 IT Risk & Cybersecurity

Sai360 IT Risk & Cybersecurity

By SAI360

4.6
(26 Ratings)

Sai360 IT Risk & Cybersecurity is a software designed to help organizations identify, manage, and mitigate IT risks and cybersecurity threats. The software enables users to assess risk levels, monitor compliance with regulatory frameworks, and establish governance processes for information security. It provides tools for tracking vulnerabilities, managing incidents, performing audits, and automating workflows associated with risk management. Through centralized dashboards and reporting, the software facilitates visibility into risk posture and supports decision-making by providing data on threats, remediation progress, and control effectiveness. Sai360 IT Risk & Cybersecurity addresses the business challenge of safeguarding digital assets and maintaining regulatory compliance within complex IT environments.

Show More Details
Logo of MetricStream IT Risk Management

MetricStream IT Risk Management

By MetricStream

4.4
(21 Ratings)

MetricStream IT Risk Management is a software designed to help organizations identify, assess, monitor, and manage IT risks and compliance requirements. The software provides tools for documenting and tracking IT assets, evaluating vulnerabilities, and implementing risk mitigation strategies. It offers features for automated risk assessments, issue management, policy and compliance tracking, and reporting. MetricStream IT Risk Management supports the alignment of IT risk management processes with organizational objectives and regulatory requirements, enabling a structured approach to risk identification, analysis, and response. The software also facilitates workflows for issue remediation and enables organizations to gain visibility into their IT risk posture.

Show More Details
Logo of Balbix

Balbix

By Safe Security (Balbix)

3.6
(18 Ratings)

Balbix is a cybersecurity software that provides organizations with an automated approach to identify, prioritize, and manage cyber risk across their digital assets. The software uses continuous data collection and advanced analytics to create a comprehensive inventory of assets, assess vulnerabilities, and evaluate risk exposure. Balbix offers features such as risk-based vulnerability management, attack surface analysis, and actionable remediation workflows. It enables teams to quantify cyber risk in financial terms, helping organizations to prioritize resources and investments based on potential impact. The software aims to streamline security operations and supports compliance initiatives by providing detailed reporting and insights into the organization’s security posture.

Show More Details
Logo of LogicManager Enterprise Risk Management Platform

LogicManager Enterprise Risk Management Platform

By LogicManager

4.6
(18 Ratings)

LogicManager is a risk management software designed to help organizations identify, assess, and monitor risks across various business processes. The software enables users to streamline compliance management, automate workflows, and document policies and controls. It offers modules for governance, risk, compliance, incident management, and audit processes, integrating data to enhance reporting and accountability. LogicManager assists organizations in centralizing information, tracking remediation activities, and ensuring alignment with regulatory requirements. Its features support decision-making by providing a structured approach to risk identification and mitigation, making it suitable for managing enterprise risk and improving operational resilience.

Show More Details
Logo of Resolver RiskVision (Legacy)

Resolver RiskVision (Legacy)

By Kroll

4.2
(18 Ratings)

Resolver RiskVision is a software designed to support enterprises in managing governance, risk, and compliance processes. The software enables organizations to identify, assess, and address risks through features such as automated workflow, centralized documentation, and risk assessment tools. It allows for tracking of incidents, monitoring regulatory compliance, and reporting on risk metrics across multiple departments. RiskVision facilitates collaboration among stakeholders and helps standardize risk management practices, aiming to improve visibility into risk posture and streamline the process of responding to potential threats. The software addresses business challenges related to operational risk, regulatory requirements, and policy management by providing a structured framework for risk analysis and mitigation.

Show More Details
Logo of Censinet Third-Party Vendor Risk Management Software Platform

Censinet Third-Party Vendor Risk Management Software Platform

By Censinet

4.8
(15 Ratings)

Censinet Third-Party Vendor Risk Management Software Platform is a software designed to help organizations manage and assess risks associated with third-party vendors. The software offers features for automating vendor assessments, streamlining due diligence processes, and managing documentation related to risk and compliance. It enables users to identify, track, and mitigate risks by providing tools for workflow automation, reporting, and real-time risk scoring. The software is designed to address challenges related to third-party risk visibility, regulatory compliance, and efficient data collection, allowing organizations to make informed decisions about vendor relationships and reduce potential risks across the supply chain.

Show More Details
Logo of Sevco Platform

Sevco Platform

By Sevco Security

4.6
(14 Ratings)

Sevco Security is a cloud-native asset intelligence platform that is delivered across 4 key dimensions:

1. Comprehensive Inventory: Sevco provides a complete, continuous view of an organization's IT environment by tracking all assets integrated with every source of inventory within the enterprise, eliminating blind spots that are present in any single system.

2. Asset context & detail: Sevco aggregates details tracked from each IT and security system into a single, unified view.

3. Tracking multiple asset types: Sevco tracks devices, users, software and vulnerabilities and the relationships between each type.

4. Real-time and recorded history of assets: Sevco monitors every IT and security system in real-time and remembers each asset's history.

The Sevco Venn Diagram and query capabilities identify security gaps and vulnerabilities enabling teams to prioritize risks.

Show More Details
Logo of Panaseer Platform

Panaseer Platform

By Panaseer

4.2
(13 Ratings)

Panaseer Platform is a software designed for cybersecurity and risk management, enabling organizations to automatically aggregate and analyze data from various security tools and IT assets. The software provides visibility into security controls coverage, identifies gaps, and supports compliance reporting by integrating disparate data sources into a unified dashboard. It helps organizations measure security posture, prioritize remediation activities, and generate reports for stakeholders. The software addresses the challenge of manual and fragmented security measurement processes, facilitating data-driven decision making and continuous monitoring of security controls within complex enterprise environments.

Show More Details
Logo of isorobot

isorobot

By Excelledia

5
(11 Ratings)

isorobot is a software designed to facilitate enterprise process automation and management. It enables organizations to map, analyze, and optimize business processes, aiding in the alignment of operations with strategic objectives. The software allows for modeling and monitoring workflows, performance metrics, and compliance with relevant standards. It provides features for document management, incident tracking, and risk management, supporting organizations in identifying process inefficiencies and maintaining regulatory adherence. isorobot is utilized to streamline operations and drive consistency in processes across various business units.

Show More Details

Gartner Research

Magic Quadrant for IT Risk Management
Critical Capabilities for IT Risk Management

Top Trending Products

Axonius Cybersecurity Asset Management Platform

Popular Product Comparisons

Archer IT & Security Risk Management vs ServiceNow Governance Risk and Compliance (GRC)Axonius Cybersecurity Asset Management Platform vs ServiceNow Governance Risk and Compliance (GRC)ServiceNow Governance Risk and Compliance (GRC) vs XactaArcher IT & Security Risk Management vs XactaArcher IT & Security Risk Management vs IBM OpenPages

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.