No more typing reviews! Try our Samantha, our new voice AI agent.

OneTrust GRC vs Scytale comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

OneTrust GRC
Ranking in GRC
2nd
Ranking in IT Vendor Risk Management
2nd
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
14
Ranking in other categories
No ranking in other categories
Scytale
Ranking in GRC
27th
Ranking in IT Vendor Risk Management
19th
Average Rating
1.0
Reviews Sentiment
2.4
Number of Reviews
1
Ranking in other categories
AI Legal & Compliance (8th)
 

Mindshare comparison

As of June 2026, in the GRC category, the mindshare of OneTrust GRC is 2.9%, down from 8.8% compared to the previous year. The mindshare of Scytale is 0.9%. It is calculated based on PeerSpot user engagement data.
GRC Mindshare Distribution
ProductMindshare (%)
OneTrust GRC2.9%
Scytale0.9%
Other96.2%
GRC
 

Featured Reviews

Gerald Pegg - PeerSpot reviewer
Governance Risk and Compliance Coordinator at HUB International
Streamlined incident management with user-friendly automation tools and responsive support
I use OneTrust specifically for incident management. For my company, I helped to create the incident management program that we currently use, particularly with gathering the information and sending out assessments to different vendors to collect information for further research and discovery.  I…
reviewer2814822 - PeerSpot reviewer
CEO at a tech vendor with 11-50 employees
Sudden access suspension has disrupted compliance work and raises serious trust concerns
Scytale unilaterally suspended access because in their opinion, I don't know why they did that. I'm assuming they think that we're competitive, which we're not. They sold us the system and sent a contract to us in full knowledge of what we do as a business. Compliance is a very broad word; we provide compliance into nonprofits, housing associations, markets that these guys do not serve. Somebody inside Scytale likely thought, "Oh my God, these guys must be competitive, so let's just cut them off." I'm assuming that's what happened, but there was no explanation, nothing. Scytale did not help me streamline my compliance processes. It didn't really identify gaps. There was no gap analysis in there that we could see. I didn't really get that far to use the effectiveness of Scytale's real-time insights in identifying potential compliance issues. All my experiences with Scytale have been negative. We haven't used the automated evidence collection of Scytale. Scytale has not helped me allocate resources more efficiently for compliance; it's been the opposite experience. We have put six months of effort into looking at the controls on 27001, talking about auditors, getting audit-ready, and so forth. But we've invested significant time, which has now been a complete waste of time. Scytale is not only unreliable, considering they can suspend access without any notice or formal reason, but this lack of stability results in serious concerns about their dependability as a partner. If they can do that without explanation, my fear is that even if they switch it on again, who's to know in three months' time that the same thing couldn't happen again?

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We have data from Jira regarding addiction related to Europe as well as California. Additionally, we have data related to the Indian Data Protection Bill. Therefore, GDPR compliance is highly beneficial."
"Vendors can be assessed and rated out of the tool, and assessments can be scheduled for updates at certain intervals."
"We receive notifications or cases and prioritize them accordingly, which helps us address issues promptly."
"One of the valuable features of this solution is it has the ability to review fourth and fifth parties to the nth degree."
"The privacy impact assessment automation tool and the incident management tool are very user-friendly."
"OneTrust GRC offers policy management, including documentation, distribution, attestation, and policy management."
"The most valuable feature of the solution is that it already has visibility about all the data protection regulations or other cybersecurity regulations related to several countries"
"OneTrust GRC is stable."
"The processes I participated in during the setup of Scytale were straightforward; it was acceptable and fine."
 

Cons

"OneTrust GRC's workflows aren't automated and need to be manually driven."
"I wish there were more customization options, particularly within the privacy rights automation module."
"I haven't seen any return on investment using the solution. If I had the opportunity, I would use a different solution."
"The product is not that easy to set up."
"The implementation of OneTrust could have been smoother, particularly in terms of scoping for those outside of governance, risk, and compliance."
"They could improve by offering free help. A solution, a lot of times, is not just the use of the solution. For example, it is the overall engagement, how well do they support the system, what is their SLA, and how long their response time is to an issue. It would be beneficial if they had some type of professional services where they offer the first five hours of professional services a year for free. That would be a substantial benefit rather than having to buy professional services or professional services packages."
"There are several areas for improvement. One is the integration capability. Connecting various DSAR systems can be time-consuming if a single integration takes months to complete."
"The Vendor Risk dashboard is quite basic today and not interactive, but improvements are in coming the next releases."
"Scytale is not reliable at all; not stable. You would be unwise to put a mission-critical function like ISO 27001 on Scytale."
 

Pricing and Cost Advice

"The solution is expensive."
"OneTrust GRC's licensing costs about $15,000 per module."
"OneTrust GRC is an expensive solution."
"I found the pricing and setup cost very reasonable."
"On a scale from one to ten, where one is cheap, and ten is too expensive, I rate the solution a seven since it falls under the pricey side."
"The platform is expensive."
Information not available
report
Use our free recommendation engine to learn which GRC solutions are best for your needs.
899,258 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Retailer
7%
Energy/Utilities Company
7%
Comms Service Provider
6%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise2
Large Enterprise9
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for OneTrust GRC?
I don't have specifics on pricing. I know it's not very cheap, but the budget aspect is outside my wheelhouse.
What needs improvement with OneTrust GRC?
I wish there were more customization options, particularly within the privacy rights automation module. More customization on the backend would allow for adjusting specific category labels tailored...
What is your primary use case for OneTrust GRC?
I use OneTrust specifically for incident management. For my company, I helped to create the incident management program that we currently use, particularly with gathering the information and sendin...
What needs improvement with Scytale?
Scytale unilaterally suspended access because in their opinion, I don't know why they did that. I'm assuming they think that we're competitive, which we're not. They sold us the system and sent a c...
What is your primary use case for Scytale?
My usual use case for Scytale is for ISO 27001 compliance.
What advice do you have for others considering Scytale?
We're going to sue Scytale, and we're going to sue Amazon as well because they're technically the people we're paying. My feedback on Scytale is that it's terrible. Currently, it's actually useless...
 

Comparisons

 

Also Known As

OneTrust Vendor Risk Management
No data available
 

Overview

 

Sample Customers

randstand, into, halfbrick
Deel, Guesty, Berlitz, AXS Guard, vSure, KOR, Trial X, Tune Insight, Agora, Leen, Upsolver. For a full list of customers and testimonials, please visit: https://scytale.ai/customers/
Find out what your peers are saying about RSA, OneTrust, Diligent and others in GRC. Updated: May 2026.
899,258 professionals have used our research since 2012.