Riskonnect
A Thoma Bravo-owned integrated risk management (IRM) suite spanning enterprise risk, third-party risk, business continuity, ESG, and claims/insurance risk management, expanded further in 2024 by acquiring GRC competitor Camms.
Visit Website ↗ + Add to CompareOverview
Riskonnect, founded in 2007 and headquartered in the Atlanta metro area, sells a broad integrated risk management platform used by risk, compliance, audit, and insurance-claims teams. It grew substantially through acquisition over the last decade and is now a portfolio company of private equity firm Thoma Bravo.
In June 2024, Riskonnect acquired Australia-based GRC vendor Camms, consolidating another established governance, risk, and compliance platform into its suite and extending its footprint into APAC and higher-education/government risk markets. This roll-up strategy is typical of the mature GRC software category, where scale and breadth of modules matter as much as any single technical innovation.
Innovation Matrix Assessment
Growth is driven largely by acquisition (e.g., Camms in 2024) rather than fast independent product cycles.
Broad module coverage (ERM, TPRM, business continuity, claims) makes it a practical system of record for enterprise risk operations.
The 2024 Camms acquisition and continued PE backing indicate real commercial traction and consolidation power in the GRC market.
A roll-up of established GRC capabilities rather than a fundamentally new approach to risk management.
Long operating history and enterprise customer base suggest real usage, though no independent efficacy studies were found.
Integrated risk management remains a core enterprise need, but the category is increasingly challenged by faster, AI-native point solutions.
Why CISOs Should Care
CISOs whose organizations already run enterprise risk, insurance/claims, or business-continuity programs on Riskonnect get a natural home for extending cyber and IT risk registers into the same enterprise risk taxonomy the rest of the business already uses.
What Makes It Different
Riskonnect's differentiation is breadth and consolidation — spanning ERM, TPRM, ESG, resilience, and claims management in one suite, reinforced by continued acquisition (most recently Camms) rather than a single novel technical approach.
The Matrix Verdict
50/100 — INCREMENTAL INNOVATOR
A large, well-capitalized, acquisitive incumbent in integrated risk management; operationally solid for enterprise risk teams but scores as an aggregator/consolidator of an established category rather than a category disruptor.
Editorial Note: Claims vs. Verified Findings
Acquisition of Camms and Thoma Bravo ownership are independently reported by trade press; specific customer counts and platform performance claims are vendor-sourced and were not independently verified.
Sources
Alternatives to Riskonnect
Vanta
Continuous automated compliance monitoring platform that replaces manual audit evidence-gathering with live, integration-based control checks.
AuditBoard (rebranded Optro)
Connected-risk platform for audit, SOX, risk, and compliance, recently rebranded from AuditBoard to Optro under an AI-agent-driven repositioning.
Arcova
Cybersecurity advisory and managed services firm, rebranded from MorganFranklin Cyber, offering GRC, IAM, OT security, and a cloud-based…
Credo AI
AI governance platform that discovers, assesses, and continuously monitors enterprise AI systems and agents against regulations like the…
Level 6 Cyber
CISO ReviewedContinuous decision-intelligence platform (LISN) that replaces point-in-time security audits with a live digital twin of a CISO's program.
Drata
Continuous compliance automation platform, Vanta's closest direct competitor, covering SOC 2, ISO 27001/42001, HIPAA, PCI DSS, DORA, and…