No more typing reviews! Try our Samantha, our new voice AI agent.

MetricStream vs NAVEX One vs RSA Archer comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of May 2026, in the GRC category, the mindshare of MetricStream is 3.2%, down from 5.4% compared to the previous year. The mindshare of NAVEX One is 1.4%, up from 1.1% compared to the previous year. The mindshare of RSA Archer is 5.9%, down from 17.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
GRC Mindshare Distribution
ProductMindshare (%)
RSA Archer5.9%
MetricStream3.2%
NAVEX One1.4%
Other89.5%
GRC
 

Featured Reviews

JQ
Owner at a consultancy with 1-10 employees
Centralized risk libraries have streamlined audits and now highlight clunky workflows and upgrades
MetricStream can be improved in several areas. Sometimes the overall flow of the application can seem a bit clunky, based on feedback from clients. From my understanding and what I have heard from developers within MetricStream during my deeper use of the application, the application seems to have been developed within silos, and the interaction of certain applications internally could definitely be improved in terms of the overall coding that exists between applications within the solution. The only improvement I suggest for MetricStream is to gather a collaborative think tank from several of the largest clients and compile feedback to prioritize suggested enhancements from multiple organizations.
EV
Information Security Business Enablement Mgr. at a insurance company with 5,001-10,000 employees
Useful for risk assessment and has customization capability
The tool helps us with security incidents, policies, business continuity, disaster recovery, and internal audits. The feature I like the most is its customization capability. It acts like a blank canvas where you can construct forms and workflows according to your needs. You can configure and customize a lot yourself, whether starting from scratch or using some out-of-the-box options. The solution has impacted our operations by helping us manage and prioritize environmental risks. It also assists in establishing ownership of risks and enables us to mitigate or mediate existing risks. Additionally, it facilitates tracking risks throughout their entire lifecycle.
CJ
Information Security Specialist at Dubai Health Authority
Centralized management strengthens compliance with good look and feel
From my perspective as a customer and end user, Archer has an impressive look and feel, but the most adaptive feature is its ease of configuration which helps to enhance our process according to our maturity. It's more about our organization getting centralized with an integrated approach that focuses on risk governance and compliance. When can provide a detailed dashboards to management with the details of risks from top-down or bottom-up prioritizing actions based on its criticality or necessity. This allows us to show end users and management where the issues lie and effectively demonstrate accountability and visibility in compliance.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It has good features and good functionality, and our customers feel there is a lot of merit in that."
"Since implementing MetricStream, audit teams have shaved about two weeks off of annual planning across various teams, allowing audit departments of about 140 auditors across maybe 10 teams to squeeze in 10 extra audits, one audit per each team, if not additional testing."
"Key features are usability and ease of configuration, and it allows us to have all the information in a single place and provide real-time indicators and information for our executives."
"Key features are usability and ease of configuration. It allows us to have all the information in a single place and provide real-time indicators and information for our executives."
"The interface is mobile-friendly and it is getting a good response from our customers."
"MetricStream is something like an all-in-one solution where I do not need to write scripts or conduct audits."
"The tool helps us with security incidents, policies, business continuity, disaster recovery, and internal audits. The feature I like the most is its customization capability. It acts like a blank canvas where you can construct forms and workflows according to your needs. You can configure and customize a lot yourself, whether starting from scratch or using some out-of-the-box options."
"It is a very friendly tool. We can easily understand what is going on inside the tool. I like this tool. We can work with the tool for the ERP platform. We can create automated applications based on the requirements."
"Even non-technical people can be masters of the product."
"The Advance Workflow feature simplifies things."
"Good dashboards and reporting features; it's easy to gather reports quickly."
"It's really a one-stop-shop and a great feature compared to what other tools offer."
"It is easy to implement, it is easy to change the workflow, and it is easy to customize the processes."
"The solution has helped our organization manage our internal and external activities."
"The tool has stability, and it allows me to automate whatever process I have."
 

Cons

"MetricStream's scalability is adaptable, though the biggest issue I have encountered with clients has been around upgrades that require re-implementing customizations to the out-of-box solutions after significant upgrades."
"We would like to have more dashboards and reports, such as geographical and trend reports in the next version."
"I would like to see out-of-the-box integration with more security, it would be helpful."
"We would like to have more dashboards and reports, such as geographical and trend reports in the next version. Also, an improvement in the mobile version would be helpful."
"The support part is terrible, rating about one out of ten."
"I would like to see out-of-the-box integration with more security, it would be helpful."
"We think there's room for improvement, especially with customizing NAVEX One. Their development on the roadmap can be slow."
"Archer could be improved by having more customization. I'm not sure if the backend processes have API calls and those kinds of seamless integrations, but from the front, some of the solutions are very out-of-the-box. It's not customizable, so that could be a little problematic since you have to use their features. In terms of the backend structure, I'm not too sure because I'm not a developer—I was an end user and product owner of Archer—and I don't quite know the backend and developmental features. But since it's an out-of-the-box solution, sometimes customization was challenging and support was a little problematic because we had to reach out to them all the time."
"The technology's a little outdated."
"The first improvement I would suggest for RSA Archer is a better search feature. The search criteria needs to be improved. Sometimes I do a search and the search doesn't return the exact item I'm looking for. RSA Archer could also be improved by being more user-friendly. Maybe I have been using a limited version of RSA Archer, but I'm not sure whether it has ESG, environmental and social governance. In the next couple of years, ESG is the next feature that will be integrated into GRC tools. I would recommend RSA Archer adds ESG."
"Slow turnaround time from support team."
"GUI could be improved."
"There is no inbuilt alert in Archer to let us know that a data feed has failed or did not run for different reasons. So, we don't even get to know that a feed has not run until somebody reports it to us. This has been a problem all the time. Data feeds have always been a big headache for us because there is no feature to let us know if a feed has not run or has failed. If Archer had a feature to send us an email notification when a feed has failed, it would've been very helpful. This is the reason why our users are slowly moving away to another platform. Some of the modules that I have been managing are being moved to ServiceNow. Next year, a lot of our modules will be moved from RSA Archer to ServiceNow, and the data feed issue has been one of the main reasons."
"If I were to rate RSA technical support on a scale from one to ten, I would give it about four, as there is definitely room for improvement, but support is available."
"The solution is not at all a cheap product."
 

Pricing and Cost Advice

"They are flexible in terms of customers' needs."
"NAVEX One's pricing comes in the middle range when compared to other products."
"Fairly highly-priced, especially for smaller companies."
"At the higher end of the price scale, but provides better, more accessible functionality and customization than cheaper products."
"As I am a developer and responsible for providing production support, I do not have personal knowledge of the pricing. However, my colleagues claim that it is very expensive in comparison with other tools."
"The solution's price should be reduced. You only have to pay the license and there are no additional fees."
"The license is costly for the solution, but the remaining set up and maintenance is quite cheaper."
"The solution’s pricing is moderate."
"RSA Archer's price is justifiable and not as expensive, compared to ServiceNow. I have heard that the licensing for ServiceNow is much more expensive. I'm unaware whether there are any additional costs after licensing fees."
"I am not 100% familiar with that, especially with their new model. I just know that the way they've licensed per user to scale is good."
report
Use our free recommendation engine to learn which GRC solutions are best for your needs.
896,099 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Healthcare Company
11%
Manufacturing Company
6%
Educational Organization
6%
Financial Services Firm
16%
Retailer
8%
Construction Company
7%
Energy/Utilities Company
6%
Financial Services Firm
20%
Insurance Company
11%
Manufacturing Company
6%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
No data available
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise6
Large Enterprise25
 

Questions from the Community

What needs improvement with MetricStream?
MetricStream can be improved in the area of developers. There are two parts of developers: those who prepare solution...
What is your primary use case for MetricStream?
My main use case for MetricStream was that I was a developer and I prepared templates for a client while also testing...
What advice do you have for others considering MetricStream?
The advice I would give to others looking into using MetricStream is to not use MetricStream. I would rate this recom...
What is your experience regarding pricing and costs for NAVEX One?
NAVEX One's pricing comes in the middle range when compared to other products.
What needs improvement with NAVEX One?
We think there's room for improvement, especially with customizing NAVEX One. Their development on the roadmap can be...
What is your primary use case for NAVEX One?
We use the solution to conduct risk assessments on our environment.
What needs improvement with RSA Archer?
While it provides benefits in terms of security, the pricing is a bit higher than customers typically expect. It woul...
What is your primary use case for RSA Archer?
Regarding the compliance, risk, and governance tools, I am comfortable discussing the tools in the GRC category. The ...
What advice do you have for others considering RSA Archer?
I have been in touch with about three companies who use RSA Archer actively in the compliance area. These companies u...
 

Comparisons

 

Also Known As

No data available
Lockpath Keylight
Archer
 

Overview

 

Sample Customers

Federal Home Loan Bank of Chicago, ACCO Brands Corporation, AgFirst Farm Credit Bank, AIB International, Associated Banc-Corp, BAE Systems, Barclaycard, Dell Inc, DIRECTV, Energizer, Fresenius Kabi, Hasbro, Goodyear, HudsonCity Savings Bank, Infigen Energy, Kaydon, Leroy Merlin, Mountry Financial Corp., Nicholas Piramal, Pepco, Pfizer, Societe Generale, Whitney Bank
Claims Recovery Financial Services (CRFS), Surescript, The University of Chicago
T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
Find out what your peers are saying about RSA, OneTrust, Diligent and others in GRC. Updated: May 2026.
896,099 professionals have used our research since 2012.