My main use case for MetricStream is the automation of the IT audit process, governance, risk, and compliance. I was working for a specific third-party client who was implementing MetricStream, and I was contracted to be the administrator of it. As an administrator, I started setting up MetricStream process by entering the controls and started by entering the business process, followed by the financial controls, and then the supporting IT general controls. For each of these controls, I would identify the point of contact, the process owners, and other relevant parties so that they would be responsible for sign-off on the controls. I configured the setup such that if an analyst or an IT audit GRC analyst sends the control evidence, and if the sign-off is pending from the control owner, the control owner would receive a notification indicating that as part of the audit period, the sign-off has to occur. I also configured dashboards in MetricStream for the specific status of the IT audit, which mostly concerned SOX 404 IT general controls testing.
My main use case for MetricStream is to design the GRC workflow. At PG&E, I leverage MetricStream GRC to support compliance with NERC, the North American Electric Reliability Corporation reliability standards, by designing and configuring the end-to-end compliance workflows. I collaborate with compliance subject matter experts, auditors, and other business stakeholders to translate the NERC standards and requirements into structured controls, assessments, and evidence collection processes, issue management workflows, and remediation tracking within MetricStream. I map regulatory obligations to control activities, configure the approval workflows, automate compliance attestations and notifications, and establish traceability between standards, controls, risks, findings, and corrective action plans. By doing this, it enables centralized compliance monitoring, improves audit readiness, reduces manual tracking efforts, and provides leadership with real-time visibility into compliance status across multiple NERC standards. This solution streamlines compliance operations, reduces manual effort by approximately thirty-five percent, improves audit preparedness, and provides real-time reporting and dashboards for compliance leadership overseeing programs impacting about twenty-three thousand plus employees at PG&E. Overall, this was the specific use case I have used MetricStream for.
Tech Lead And Dev Ops Engineer at a healthcare company with 51-200 employees
Real User
Top 20
Mar 16, 2026
My main use case for MetricStream was that I was a developer and I prepared templates for a client while also testing the UI platform for the client. I can give a specific example of a template I prepared for a client. We had a task about what the client wanted, about the solution, about governance, about the tech template, and about SOX compliance. After we had some points, I created forms. It was basically something similar to Microsoft Forms. I prepared templates within MetricStream and took these blocks to create components together, something resembling Lego parts. When I was a developer, this was a quite narrow template, and it consisted mostly of pieces from a constructor. I created one large form for the client. However, the main issue is that if a client needs something larger or more custom, there are no tools to change these blocks. Instead, I need to create a task for the developer team. Additionally, my customer team from MetricStream is located in India. A significant issue is with technical support because for the first month, they do not have any time and they do not want to change anything. Basically, I only have access to the UI and do not have access to the code base. However, for developers preparing solutions for clients who need to make a change in the code base, it would be much easier to change our own code rather than wait two or three months.
MetricStream is a cloud-based platform providing robust audit, compliance, and risk management tools. Users enjoy features like mobile interfaces and centralized risk libraries, though some report interface flow issues and technical support challenges.MetricStream stands out for its audit, risk, and compliance capabilities, delivering customizable and standardized risk management across departments. Its comprehensive dashboards and reporting tools streamline compliance processes, reducing...
My main use case for MetricStream is the automation of the IT audit process, governance, risk, and compliance. I was working for a specific third-party client who was implementing MetricStream, and I was contracted to be the administrator of it. As an administrator, I started setting up MetricStream process by entering the controls and started by entering the business process, followed by the financial controls, and then the supporting IT general controls. For each of these controls, I would identify the point of contact, the process owners, and other relevant parties so that they would be responsible for sign-off on the controls. I configured the setup such that if an analyst or an IT audit GRC analyst sends the control evidence, and if the sign-off is pending from the control owner, the control owner would receive a notification indicating that as part of the audit period, the sign-off has to occur. I also configured dashboards in MetricStream for the specific status of the IT audit, which mostly concerned SOX 404 IT general controls testing.
My main use case for MetricStream is to design the GRC workflow. At PG&E, I leverage MetricStream GRC to support compliance with NERC, the North American Electric Reliability Corporation reliability standards, by designing and configuring the end-to-end compliance workflows. I collaborate with compliance subject matter experts, auditors, and other business stakeholders to translate the NERC standards and requirements into structured controls, assessments, and evidence collection processes, issue management workflows, and remediation tracking within MetricStream. I map regulatory obligations to control activities, configure the approval workflows, automate compliance attestations and notifications, and establish traceability between standards, controls, risks, findings, and corrective action plans. By doing this, it enables centralized compliance monitoring, improves audit readiness, reduces manual tracking efforts, and provides leadership with real-time visibility into compliance status across multiple NERC standards. This solution streamlines compliance operations, reduces manual effort by approximately thirty-five percent, improves audit preparedness, and provides real-time reporting and dashboards for compliance leadership overseeing programs impacting about twenty-three thousand plus employees at PG&E. Overall, this was the specific use case I have used MetricStream for.
My main use case for MetricStream is for audit and risk management.
My main use case for MetricStream was that I was a developer and I prepared templates for a client while also testing the UI platform for the client. I can give a specific example of a template I prepared for a client. We had a task about what the client wanted, about the solution, about governance, about the tech template, and about SOX compliance. After we had some points, I created forms. It was basically something similar to Microsoft Forms. I prepared templates within MetricStream and took these blocks to create components together, something resembling Lego parts. When I was a developer, this was a quite narrow template, and it consisted mostly of pieces from a constructor. I created one large form for the client. However, the main issue is that if a client needs something larger or more custom, there are no tools to change these blocks. Instead, I need to create a task for the developer team. Additionally, my customer team from MetricStream is located in India. A significant issue is with technical support because for the first month, they do not have any time and they do not want to change anything. Basically, I only have access to the UI and do not have access to the code base. However, for developers preparing solutions for clients who need to make a change in the code base, it would be much easier to change our own code rather than wait two or three months.
We are system integrators. We propose solutions to the customers.
Where we are using it is for enterprise risk management and operations risk management.