What users are saying about
1 Rating
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>Score 8 out of 100
Based on 1 reviews and ratings
39 Ratings
<a href='https://www.trustradius.com/static/about-trustradius-scoring' target='_blank' rel='nofollow noopener noreferrer'>trScore algorithm: Learn more.</a>Score 7 out of 100
Based on 39 reviews and ratings
Likelihood to Recommend
KCM GRC Platform
KnowBe4 KCM GRC Platform is well suited for a company that knows what they're doing compliance wise and needs to save time doing it. It won't be something you can spend a few hours on and then put on autopilot. It was made to create a rhythm within your own team, and you'll need to have the buy-in. It's useful for IT and Legal teams that already have a vendor risk management process, but want to have a better handle on it. Giving an outside auditor read-only access to a scope is also a huge time saver.
Information Security Analyst
Randall-ReillyMarketing and Advertising, 201-500 employees
RSA Archer
RSA Archer is fantastic at cataloguing, personalizing assessments, raw reporting, and capacity to add custom fields. It is a little clunky around adding contextual information to notifications, peeking into data before attempting to load pages, quick navigation or determining linked (or sub-linked) relationships. These are all concerns that can either be worked around with an appropriate data scheme or with careful administration of the sub-routines.

Verified User
Analyst in Corporate
Financial Services Company, 501-1000 employeesFeature Rating Comparison
Governance, Risk & Compliance
KCM GRC Platform
9.3
RSA Archer
7.9
Common repository of GRC items
KCM GRC Platform
10.0
RSA Archer
7.4
Risk management
KCM GRC Platform
10.0
RSA Archer
9.0
GRC policy management
KCM GRC Platform
8.0
RSA Archer
6.5
Integration with Corporate Performance Management (CPM) systems
KCM GRC Platform
—
RSA Archer
8.5
Incident management
KCM GRC Platform
—
RSA Archer
8.1
Pros
KCM GRC Platform
- Mapping controls across different compliance frameworks. It saves you a ton of time and energy!
- Performing risk assessments at the granularity that you prefer, splitting assessments across departments and teams if you wish.
Information Security Analyst
Randall-ReillyMarketing and Advertising, 201-500 employees
RSA Archer
- Integration capabilities to multiple enterprise systems
- Control standards and Procedures to address multiple regulatory/authoritative sources, standards and frameworks enabling test once satisfy many requiremnts
- Rapid application development and User friendly tool with configuration capability to customize easily without user requiring programming or coding skills
Manager
DeloitteInformation Technology and Services, 10,001+ employees
Cons
KCM GRC Platform
- Vendor management has a few kinks to work out. We want to be able to do internal questionnaires for vendors as a compliance checklist before we sign off on a contract. Nothing in the works yet, but there are a few workarounds.
- The navigation between different tasks in scope is clunky, and it's easy to lose your place, and it forces you back to the main page of the scope to retrace your steps.
Information Security Analyst
Randall-ReillyMarketing and Advertising, 201-500 employees
RSA Archer
- They release time to time updates, which causes issues in the GUI. However, one has to be careful while installing the update.
- There is no open and free academy to learn more about the tool.
- One cannot stay to a particular product version, they have to move to the next version to keep up with the changes.
Technology Analyst
InfosysInformation Technology and Services, 10,001+ employees
Usability
KCM GRC Platform
No score
No answers yet
No answers on this topic
RSA Archer
RSA Archer 7.0
Based on 3 answers
Good tool to get the information communicated, approval workflow, and easy to add new findings/questionnaires. Seems to be compatible with different browsers and little downtime. Only request for improvement is to add an export feature with fewer clicks. Maybe batch export.

Verified User
Manager in Finance and Accounting
Mining & Metals Company, 10,001+ employeesSupport Rating
KCM GRC Platform
KCM GRC Platform 10.0
Based on 2 answers
Support from KnowBe4 KCM GRC Platform is always great. It's always in-house localized support, with excellent response times, and dedicated Customer Success Managers to answer the bulk of your questions or take your suggestions and make them a feature request. They will also reach out at least quarterly and do health checks to make sure you're using the platform to the best of your ability.
Information Security Analyst
Randall-ReillyMarketing and Advertising, 201-500 employees
RSA Archer
RSA Archer 5.0
Based on 2 answers
Our RSA Archer team is dedicated to finding solutions for our organization. They haven't mentioned any issues with receiving support with deployment or bug fixes, and generally the platform is very dependable. They are always very excited about delivering a version upgrade and presenting any new features that provide more dashboards or chart types.

Verified User
Analyst in Corporate
Financial Services Company, 501-1000 employeesAlternatives Considered
KCM GRC Platform
Quantivate and Fusion were the other two options we checked out. The quantity was high, and a good bit more expensive, but it was the best performing with its platform. They also had more modules that each cost extra to add to your subscription. KnowBe4 KCM GRC Platform was all-in-one and a little less mature, but the better buy. Fusion was hard to follow in the demo, and I was not overly impressed. I may have made my decision early enough in the demo to not pay much more attention to it.
Information Security Analyst
Randall-ReillyMarketing and Advertising, 201-500 employees
RSA Archer
It has been roughly 5 years since I have seen Securevue, so a lot can change, but to me it felt like several products were purchased and an attempt was made to piece them all together into a single solution (and I believe that may have been true). It also required agents on endpoints which did not fit the model I believed customers were looking for. MetricStream appeared to be difficult to install as it took their own engineers some time to get it installed in my lab environment. I did not think their web interface was as intuitive as RSA Archer. Customization to the platform was possible to some degree, but required a lot more work and technical skills than required by Archer. I did like the landing page for MetricStream which called out the important action items for the current user, but Archer v6.X now has this feature.
Information Security Engineer, Principal
ManTech International CorporationInformation Technology and Services, 10,001+ employees
Return on Investment
KCM GRC Platform
- Just having the capacity to do things the right way, and formally, has driven some of our compliance efforts.
- Due to licensing limitations, we likely overspent on seats to the platform that we didn't need but also didn't want to miss out on.
Information Security Analyst
Randall-ReillyMarketing and Advertising, 201-500 employees
RSA Archer
- We were able to achieve approx 63% gain in operational efficiency.
- Reduce the number of findings and exceptions during an Internal audit to almost zero.
- Get compliance to all client contracts tracked through the tool thus increasing the confidence of clients in our systems and processes.

Verified User
C-Level Executive in Information Technology
Outsourcing/Offshoring Company, 1001-5000 employeesScreenshots
Pricing Details
KCM GRC Platform
General
Free Trial
—Free/Freemium Version
—Premium Consulting/Integration Services
—Entry-level set up fee?
No
RSA Archer
General
Free Trial
—Free/Freemium Version
—Premium Consulting/Integration Services
—Entry-level set up fee?
No