Archer is the enterprise GRC platform a large share of global banks already run for risk and compliance, and internal audit is usually the last function it reaches inside those organizations, not the first. Where an entity already sits on Archer’s shared risk and control model, audit inherits a real advantage: the process, risk and control data it tests is the same data the business and the second line built and keep current. Where audit is the reason an organization would buy Archer in the first place, the case is harder, because the platform is priced, configured and administered as an enterprise decision that the third line rarely owns alone. The one fact every buyer should know before the first call: nobody outside a signed contract knows what Archer costs, and the platform rewards a dedicated administrator far more than it rewards a casual user.
This review covers Archer’s Audit Management module (Audit Planning & Quality, Audit Engagements & Workpapers, and Issues Management) on both classic Archer and the newer Archer Evolv SaaS layer, what a SOX program needs beyond it, the AI features Archer launched between 2024 and 2026 and what they actually say about data handling, the public price evidence that exists in place of a list price, and the recurring themes in reviews on Gartner Peer Insights, G2, Capterra and TrustRadius. It is one of the product reviews in the site’s independent buyer’s guide to internal audit software and follows the evidence levels and scorecard set out in how we review audit software. If audit-first software is closer to what you actually want, Optro vs Archer and the Archer alternatives page are the faster routes to an answer.
Verdict. Archer earns a Strong fit only where a bank, insurer or other large regulated enterprise is already consolidating risk, compliance and audit onto one data model; bought for audit alone, it is an expensive way to get a workflow tool with a great deal of platform attached that the third line rarely needs by itself.
Best for. Large or global audit functions inside a bank, insurer or regulated enterprise that already runs, or plans to run, Archer for risk and compliance; organizations deliberately consolidating the three lines onto one system.
Not for. A first system for a team of one to five auditors, or any buyer whose main goal is a fast, self-service audit tool that the audit team can configure and run on its own.
Evidence. Research-based: vendor documentation and release notes, public procurement records, third-party pricing data, verified user reviews on Gartner Peer Insights and G2, and analyst coverage. We have not used the product hands-on for this review.
Price evidence. Archer publishes no price list. Its own AWS Marketplace listing shows a 12-month contract line item priced at $9,999,999.00, an evident placeholder, and says pricing is not published on the Marketplace; Vendr’s buyer data shows no median or range for Archer, only a $100,000 threshold that triggers its legal review. No public price; quote only.
Last verified. 27 September 2026.
In this guide
- What Archer is, and who owns it
- What you get: modules and how audit fits
- Walkthrough by audit stage
- SOX and controls
- Analytics, integrations and automation
- AI: what is real
- The scorecard
- Fit by situation
- Pricing and contract
- What users say
- Implementation and migration
- How it compares
- Questions about Archer
- Sources and verification
- Related guides
What Archer is, and who owns it
Archer is sold as Archer Integrated Risk Management, or Archer IRM, and traces to 2000; the company is headquartered in Overland Park, Kansas. Bill Diaz has been CEO through every ownership change since at least 2020 and is quoted in nearly every release covered here, from the Compliance.ai and Flisk acquisitions to the Evolv launch. His own biography page cites an MBA from Northwestern’s Kellogg School of Management (2004), fifteen years in risk and insurance software, five businesses led and ten acquisitions completed — but the same page still states “1,000 global customers,” a stale figure next to the more than 1,300 Archer now claims elsewhere on its site.
Archer’s ownership has changed three times in about as many years, and the chain matters more than most vendor histories because it explains why the roadmap has accelerated. Archer began as a product line inside RSA Security, which Symphony Technology Group (STG) bought from Dell in 2020. STG and Clearlake Capital partnered in 2021 to spin Archer out of RSA as an independent company, a period in which Archer says its SaaS annual recurring revenue roughly doubled. Cinven, the European private-equity firm, agreed on 13 April 2023 to acquire Archer from Clearlake and STG, on undisclosed terms, and closed the deal on 10 July 2023; Diaz stayed CEO throughout. A buyer signing a multi-year contract today is really signing on to Cinven’s holding period, and private-equity ownership tends to show up at renewal more than at the demo.
Customer-count claims have grown with each retelling. At the 2023 sale, Archer cited roughly 1,200-plus customers and more than half of the Fortune 500; today’s site claims 1,500-plus clients across 48 countries, 50% of the Fortune 500, 37 of the top 50 global banks and a community of more than 15,000 (the clients page is not even internally consistent, citing both “37” and “38” of the top 50 banks in different places). We use the more conservative figure that recurs across Archer’s own audit-management page and its acquisition announcements — 1,300-plus customers, including 37 of the top 50 global banks — and treat every version of this number as an unaudited vendor claim, not an independently confirmed count.
Analyst recognition follows the same pattern of vendor self-reporting seen across this guide. Archer says it was named a Leader in the Gartner Magic Quadrant for Governance, Risk and Compliance Tools, Assurance Leaders (27 October 2025, 16 vendors assessed) and a Leader in the Verdantix Green Quadrant: GRC Software 2025 (3 September 2025, 15 vendors), the latter citing a top score in regulatory-change management. Neither report is specific to audit management, and Gartner has no Magic Quadrant for that narrower category; its 13 April 2026 Market Guide for Audit Management Software, by analyst James Bourke, is the non-ranking document that actually covers this market, and its advice is to be wary of agent-washing. The guide to reading audit software analyst reports has the full method for weighing claims like these. The timeline below covers the acquisitions, launches and recognitions that shaped the platform buyers see today.
| Date | Event | Why it matters to a buyer |
|---|---|---|
| 2000 | Archer founded | Two and a half decades of product history under several owners |
| 2020 | Symphony Technology Group buys RSA Security, Archer’s then parent, from Dell | Start of the current ownership chain |
| 2021 | Clearlake Capital and STG spin Archer out of RSA as an independent company | Archer says its SaaS annual recurring revenue roughly doubled under this ownership |
| 13 Apr 2023 / 10 Jul 2023 | Cinven agrees to acquire, then completes the purchase of, Archer from Clearlake and STG | Current owner; a private-equity holding period to watch at renewal |
| 20 Feb 2024 | Acquires Compliance.ai, an AI-driven regulatory-change monitoring tool | First of the AI-related acquisitions |
| 20 Mar 2024 | Acquires Flisk, an Austin RMIS startup | Now ships as Archer RMIS AI |
| 4 Feb 2025 | Launches Archer Evolv, a cloud-native SaaS layer | Classic Archer and Evolv now coexist on the same data, per Archer |
| 27 Oct 2025 | Named a Leader, Gartner Magic Quadrant for GRC Tools, Assurance Leaders | A GRC-platform report, not an audit-management one |
| 14 Sep 2026 | Launches Archer Evolv Foundation and Evolv Workplace, an AI “Operators” marketplace | The newest, most AI-heavy layer of the platform |
| 15 Sep 2026 | Launches Archer Evolv AI Compliance, with guardrails run inside the customer’s own AWS account | Archer’s most concrete AI data-handling statement to date |
What you get: modules and how audit fits
Archer describes its architecture as “One Foundation. Three Systems”: a System of Record for data, workflow, permissions, history and controls; a System of Intelligence for the AI layer; and a System of Outcomes, where AI “Operators” act inside existing controls. Two editions coexist rather than one replacing the other: classic Archer, available on-premises or as SaaS, and Archer Evolv, the newer cloud-native layer Archer has been adding module by module since February 2025 and markets as needing “no replatforming” and “no data lift” because it sits on the same underlying data. In practice a buyer chooses an architecture generation module by module, not one Archer product wholesale, and should ask exactly which modules are on Evolv today versus still classic-only.
Audit Management is one of eight modules on the current catalog, each licensed and configured somewhat separately even though they share the same underlying model.
| Module | What it covers | Audit-relevant detail |
|---|---|---|
| Audit Management | Audit Planning & Quality, Audit Engagements & Workpapers, Issues Management | The subject of this review |
| Enterprise & Operational Risk Management | Risk register, RCSA, operational-loss data | Shares the risk data Audit Management scopes against |
| Regulatory & Corporate Compliance Management | Policy, regulatory change, financial-controls monitoring | Where SOX and ICFR work actually lives — see the SOX section |
| IT & Security Risk Management | IT risk, cyber compliance, vendor risk | Feeds IT-related audit findings |
| Third Party Governance | Vendor risk, contracts, performance | Shared vendor data for third-party audits |
| Public Sector | POA&M, Assessment & Authorization, Continuous Monitoring | Federal-style workflows; see the security section on FedRAMP |
| Resilience Management | Business continuity, crisis response | Overlaps with operational-resilience audit work |
| ESG Management | ESG data, disclosures, assurance | Rarely an audit-management buying driver |
The consequence is the same one that applies to every enterprise GRC suite in this guide: Audit Management cannot really be evaluated alone, because its issues register, reporting and shared risk-control data are platform features that also serve risk, compliance and IT security. That is the selling point when several of the three lines are buying together, and the friction when audit is the only function that wants it. The GRC suite versus standalone audit management software comparison sets out that trade-off in full, and the audit software demo script has 25 scenarios worth running against Archer specifically before signature, since the platform’s documentation describes capabilities more often than it demonstrates them.
Walkthrough by audit stage
Everything below comes from Archer’s own help-center documentation and product pages, not from using the product; one page describing deeper workflow detail did not render for us, which is noted where it applies.
Planning and risk assessment
The Audit Entity app defines the audit universe and scopes and risk-assesses it across processes, departments, regulations and infrastructure; the Audit Plan app builds the plan itself, with hours and expense tracking and workflow automation. Archer pitches this as risk-based scoping built on data the organization has already aggregated in its shared risk and control library, rather than a standalone audit-only risk assessment — which is the platform’s core promise and its core dependency: the quality of audit’s risk-based plan is only as good as the risk data the rest of the organization has kept current. The site’s annual internal audit risk assessment playbook covers the method a tool like this is meant to serve.
Engagement and fieldwork
The Audit Engagement app manages scope, staffing, testing and reporting for each engagement, cross-linked to the shared risk and control library so an engagement can pull the controls and risks it is testing rather than re-entering them. Archer’s documentation describes this as one connected record rather than separate engagement files, which is the advantage a buyer already on the platform gets and a new buyer has to build from scratch.
Workpapers and review
Archer does not sell a separate workpaper product; workpaper management is unified inside the Audit Engagement app, described only as “unified workpaper management” with “built-in workflows” in the documentation we could read. That is thinner detail than some rivals publish, and the Issues Management module’s own help-center page did not render for us at all, so we could not verify review routing, sign-off steps or version history beyond the platform’s general audit trail. Ask to see workpaper review and sign-off in a live demo rather than assuming parity with audit-native competitors; the site’s risk and control matrix template is a useful basis for comparing what an RCM-linked workpaper should carry.
Issues and follow-up
A dedicated Issues Management app consolidates issues raised by audit, risk and compliance into one register and tracks remediation to closure, which is the clearest audit-specific benefit of sharing a platform with the other two lines: one issue, one owner, one closure record, regardless of which function raised it. Deeper workflow detail, such as escalation rules, aging and management self-reporting, was not independently verifiable beyond this description.
Reporting
Reporting runs through platform-wide Workspaces and Dashboards rather than an audit-specific reporting product. Workspaces group dashboards by business area; Dashboards are WYSIWYG and widget-based, with each widget carrying up to 15 reports or charts, plus an Admin Dashboard that shows data-feed health and license usage. That is a capable general-purpose reporting layer, but nothing in the documentation we read describes an audit-committee-specific report pack the way some audit-native platforms do, so expect to build committee reporting from the general dashboard tools rather than a template built for that audience.
SOX and controls
Archer has no standalone SOX product. Financial-controls work sits inside Regulatory & Corporate Compliance Management, a separate module from Audit Management, under a use case Archer calls Financial Controls Monitoring. That use case explicitly covers “SOX narratives, 302 certifications, and PBC lists”: controls are authored once against every framework they satisfy and tested once per cycle, with results rolling up to primary controls; financial controls tie to general-ledger accounts and risks; evidence lands in a versioned, scheduled repository; and scoped external-auditor roles can see relevant material without full system access. A separate Controls Assurance Program Management use case sits in the same module, and Archer Evolv separately added a Continuous Controls Monitoring capability for automated IT control assurance.
The practical consequence is licensing, not capability: a buyer whose SOX program is the reason for the purchase needs Regulatory & Corporate Compliance Management alongside Audit Management, not Audit Management on its own, and nothing in the pages we read states how that pairing affects price. That is worth confirming in the RFP before assuming SOX is included. The site’s SOX 404 guide and its control deficiency evaluation method are the reference points for what a financial-controls program needs from whatever system runs it.
Analytics, integrations and automation
Archer’s core integration story is a direct data connection: Audit Management reads from the shared risk and control data model rather than duplicating entry, which Archer’s own materials describe as pulling “pre-existing risk and control data” into an audit engagement. Audit Planning & Quality alone ships seven automated data feeds — among them auto-scoping by risk and workpaper generation by program — and Archer’s help center documents a web-services and REST API, though the authentication and rate-limit detail was not independently confirmed. Positioning material for the AI layer separately claims “identity-bound operators with native IAM and SSO integration,” a claim about the newer Evolv layer rather than the audit module specifically.
None of this amounts to a scripting or full-population analytics layer of the kind dedicated audit-analytics tools provide. A team that wants Archer’s shared-data advantage for engagement and issue workflow while running real data analytics elsewhere should plan for that as a second tool from the start, not an afterthought; the site’s audit analytics software comparison covers the dedicated options.
AI: what is real
Archer’s AI history in this window starts with two 2024 launches: Archer Assurance AI and Archer AI Governance, announced 18 September 2024 alongside a UI refresh. AI Governance is the more developed of the two — an EU AI Act obligations and controls library, AI use-case privacy and ethics assessments, a unified AI inventory, third-party AI risk scoring and “AI incident readiness” — but we found no statement anywhere on whether Archer’s own AI trains on customer data, how long it retains inputs, or whether customers can opt out.
Archer Evolv for Compliance, which shipped with the Evolv platform on 4 February 2025, adds AI-filtered regulatory horizon scanning and gap or conflict identification; Archer said Evolv for Risk would follow “later in 2025,” and we could not confirm from the pages reviewed whether it actually shipped. The newest layer, Archer Evolv Foundation and Evolv Workplace (14 September 2026), is a shared AI model layer plus a marketplace of scoped, supervised AI “Operators” live in Foundation, Audit, Third-Party Risk, IT Risk and Operational Risk, with a roadmap of 200-plus Operators by the end of 2026. Its own marketing states two different training-data counts on two different pages — “492 purpose-built models” trained on a claimed 22 million regulatory documents and 250 million GRC records on one page, and “526 purpose-built GRC models,” “7,000-plus reg sources” and “18 patents, nine years of data” on another — and the two do not reconcile. Treat both as unverified vendor claims rather than picking the one that sounds more impressive.
The most concrete AI data-handling statement Archer has published is also its newest: Archer Evolv AI Compliance, launched 15 September 2026, runs native Amazon Bedrock Guardrails on every prompt before a model responds, inside the customer’s own AWS account and IAM role, so that prompts and model weights stay isolated from Archer itself; Archer says it covers organizational secrets and regulated data classes including GDPR, CCPA, HIPAA, PCI DSS and export controls, with human approval gates before enforcement. That is a real architecture decision, not a marketing line, and it is the AI feature worth asking about first. By contrast, a 30 June 2026 press release headlined “95% Verified Accuracy, 80x Faster, 92% Lower Cost” against general-purpose LLMs on regulatory-change work states no methodology in the material we reviewed; do not accept that figure without asking Archer to show how it was measured. Gartner’s own April 2026 caution — to be wary of agent-washing — is the right lens for every AI claim on this page, and the site’s guide to evaluating AI in audit software has the test protocol.
The scorecard
The scorecard uses the 12 areas described on the method page; each level reflects documentation and reviews, not hands-on use, and several cells below note where the underlying page did not render for us.
| Area | Level | Evidence |
|---|---|---|
| Risk assessment and planning | Strong | Audit Entity and Audit Plan apps scope and risk-assess against the shared data model; hours and expense tracking built in |
| Engagement workflow | Strong | Audit Engagement app manages scope, staffing, testing and reporting, cross-linked to the shared risk and control library |
| Workpapers and evidence | Adequate | Unified inside the Audit Engagement app rather than a separate product; the Issues Management help page did not render, limiting what we could verify about review and sign-off |
| Issues and follow-up | Strong | Dedicated Issues Management app consolidates audit, risk and compliance issues into one register with remediation tracking |
| Reporting | Adequate | Platform-wide Workspaces and Dashboards, widget-based and WYSIWYG; no audit-committee-specific report pack found |
| SOX and controls testing | Adequate | Real Financial Controls Monitoring capability, but it sits in a separate module, Regulatory & Corporate Compliance Management, that a SOX buyer must also license |
| Analytics and automation | Adequate | Seven automated data feeds and a documented REST API; no scripting or full-population testing layer |
| AI features | Adequate | A dense 2024-2026 feature line with one genuinely concrete data-isolation statement, Evolv AI Compliance, but conflicting model-count claims and an unverified benchmark figure |
| Quality program support | Limited | Three QA questionnaires bundled in Audit Planning & Quality; no QAIP-metrics-specific module described in the pages we read |
| Auditee experience | Limited | No auditee-facing request portal or notification feature specific to audit was found; auditees share the same platform accounts as risk and compliance stakeholders |
| Administration, integrations and security | Strong | SOC 2 Type 2, ISO 27001, 27017 and 27701, AES-256 and TLS 1.3, optional BYOK, AWS hosting across seven regions, a 99.5% SLA; no FedRAMP or GovRAMP authorization found despite a Public Sector module |
| Cost and contract | Limited | No public price list at all; the AWS Marketplace listing’s headline price is an evident placeholder and Vendr has no median for Archer |
| Vendor viability | Adequate | Financially backed by Cinven with a steady 2024-2026 release cadence, but three ownership changes since 2020 mean the roadmap has followed whoever owns it |
Fit by situation
The eight situations are the same on every review in this guide, so ratings can be compared across products. Archer’s own ratings run to the extremes: Strong fit at the largest and most regulated end, Poor fit at the smallest.
| Situation | Rating | Reason |
|---|---|---|
| First system for a small team (1 to 5 auditors) | Poor fit | No public price, no self-service path, and a platform built around shared enterprise data a small team has no reason to build first |
| Mid-size function (6 to 25 auditors) | Poor fit | Much the same problem at a slightly larger scale; the platform’s value depends on risk, compliance or IT already running Archer, which most functions this size have not built |
| Large or global function (25+ auditors) | Strong fit | Multi-entity audit universe, shared risk and control data, and the administrative capacity a large function can dedicate to configuration |
| SOX-heavy public company | Workable | Financial Controls Monitoring is real, but it is a second module to license and configure alongside Audit Management, not a bundled feature |
| Bank or credit union | Strong fit | The deepest bank customer base of any product in this guide (Archer claims 37 of the top 50 global banks), named bank customers, and the SOC 2 and ISO certifications banks expect |
| Public sector, higher education or nonprofit | Workable | Carahsoft’s GSA, NASA SEWP V and ITES-SW2 vehicles ease procurement, but no FedRAMP or GovRAMP authorization was found despite a dedicated Public Sector module |
| Analytics-heavy team | Workable | Seven automated data feeds and a REST API, but no scripting or full-population testing layer of its own |
| Consolidating GRC across the three lines | Strong fit | This is the buyer Archer is built for: one data model spanning audit, risk, compliance, IT security and third-party governance |
Banks running Archer to organize how they respond to exam findings, not only internal audit issues, should also see the site’s MRA and MRIA lifecycle guide, since Archer’s Issues Management register is often where those findings end up living alongside audit’s own.
Pricing and contract
Archer is one of the least transparent products in this guide on price. It publishes no list price anywhere we could find, and even the usual proxies are thinner than for most competitors.
| Source and date | Figure | What it covered | How to read it |
|---|---|---|---|
| AWS Marketplace, “Archer SaaS” listing (27 Sep 2026) | 12-month contract line item priced at $9,999,999.00 | A structural placeholder in the listing, not a real quote | An evident placeholder; the listing itself says pricing is not published on the Marketplace and to contact Archer directly |
| AWS Marketplace, Assertiva-resold listing (27 Sep 2026) | “Custom pricing options based on your specific requirements and eligibility” | Private-offer only | No figures at all |
| Vendr marketplace (27 Sep 2026) | No median or range; a $100,000 threshold that triggers Vendr’s legal review; Net 30, annual or quarterly terms | Buyer-reported deal data | The only two data points Vendr has for Archer — too thin to be a benchmark |
| Carahsoft contract vehicles (27 Sep 2026) | GSA MAS (through 21 Aug 2028), NASA SEWP V (through 31 Jan 2027), ITES-SW2 (through 30 Aug 2030), plus state, local and education vehicles | Contract vehicles only | Useful for procurement routing, not for budgeting; no rate cards published |
Archer has not stated a pricing model — not per-user, not per-module, not unlimited. The closest thing to a clue is the AWS listing’s own language, which says to “work with Archer to scope the solutions and users your organization needs, then agree on pricing,” implying a negotiated, solution-plus-user-count structure. That is our inference from the wording, not a vendor statement, and it is worth confirming directly rather than assuming.
Because Archer publishes so little, treat every cost driver as a question to put in writing: whether Regulatory & Corporate Compliance Management is priced separately if SOX is in scope, whether Evolv’s AI features (Foundation, Workplace, AI Compliance) carry their own subscription, and what implementation and professional services typically add, since no vendor figure exists for any of them in the pages we read. A structured RFP matters more here than for almost any other product in this guide; the site’s vendor-neutral RFP method has the pricing schedule to send, and the internal audit software pricing guide puts what public figures do exist next to every other vendor’s.
What users say
Archer’s own audit-management product is rated 4.3 from 36 reviews in Gartner Peer Insights’ Audit Management Solutions market (33% five-star, 47% four-star, 17% three-star, 3% two-star). Vendor-wide across all ten Gartner markets, Archer runs close to 4.2 from about 446 reviews, the figure this guide’s brief used; a check on 27 September 2026 showed 4.1 from 447 — Peer Insights totals move continuously, so treat either as a snapshot. G2 shows 3.6 from 20 reviews on its main Archer listing (roughly 65% enterprise, 30% mid-market, 5% small business); a separate “Archer RFP” listing on G2 likely means the platform’s true G2 review volume is undercounted here. Capterra’s “RSA Archer Suite” listing shows 3.9 from 14 reviews (an unrelated, same-named asset-management product also exists on Capterra — do not confuse the two), and TrustRadius shows 8.4 out of 10 from 49 reviews.
| Theme | Praise or complaint | Where seen |
|---|---|---|
| Single data model across audit, risk and compliance | Praise | GPI audit reviews on centralized data; TrustRadius on consolidating systems into one reporting layer |
| Deep customization | Praise, with a catch | GPI and TrustRadius praise no-code customization; G2 says dashboards work well “when properly configured” |
| Cost | Complaint | GPI audit reviews and G2 both cite cost as a leading complaint |
| Implementation and configuration complexity | Complaint | G2: difficult customization, often needing paid consultants; Capterra: navigation complexity |
| Learning curve | Complaint | G2 and TrustRadius both cite a steep learning curve; TrustRadius adds thin documentation |
| Interface | Complaint | G2 calls the interface “dated”; TrustRadius calls it “outdated-feeling” |
| Workflow rigidity | Complaint | TrustRadius: an approve-or-reject-only workflow that forces resubmissions, and slow performance on calculated fields |
The pattern holds across all four sites we checked: praise centers on breadth and centralization, complaints center on cost, implementation complexity, the interface and the learning curve — the same four themes this guide’s brief set out to test, and the reviews corroborate them without exception.
Implementation and migration
Archer runs implementation through partners rather than publishing its own timeline. Its Velocity Partner Program has three tracks — Strategic Alliances, Value-Added Resellers and Consulting & Implementation partners — with Gold, Silver and Bronze tiers, structured training and certification paths, and a stated 48-business-hour response time on the sales side. Deloitte became a named strategic ally on 15 October 2025, covering strategy and design through build, change management, user adoption and ongoing managed or operational support, including modernization onto Evolv Compliance specifically.
No vendor-published implementation-timeline figure, admin-staffing model or Evolv migration-tooling specification was found in any page we read, which is a real gap next to competitors who publish at least a rough range. Archer’s marketing describes Evolv as adding modules with no replatforming and no data lift, a claim we could not independently confirm. Given the platform’s configuration depth and its own reviewers’ comments about a steep learning curve, budget for partner-led implementation rather than a self-service rollout, and push in the RFP for a written timeline and a named admin-training plan. The site’s audit software due diligence guide has the security, data-residency and vendor-stability questions worth adding to that same RFP, several of which — FedRAMP status among them — Archer’s own pages leave unanswered.
How it compares
MetricStream is the closest structural peer: another enterprise GRC suite, privately held (Blue Torch Capital financing since September 2024), where audit is one module among six platform areas. It is smaller in this specific market — Gartner Peer Insights rates its audit-management product 3.6 from just 6 reviews, against Archer’s 4.3 from 36 — and, like Archer, publishes no price list. MetricStream’s 13 May 2025 “AI-first” rebrand under new CEO Marc Levine covers similar ground to Archer’s Evolv push. The MetricStream vs Archer comparison and the MetricStream review work through where the two actually differ.
ServiceNow IRM is the platform-you-already-own case: Audit Management is sold only inside IRM Pro or IRM Enterprise bundles, workpapers route through Office 365 rather than a native editor, and it is usually IT or the second line, not audit, that already has the ServiceNow relationship. Its GRC listing rates 4.2 from 163 reviews in a different Gartner market than Archer’s audit-specific one, so the two figures are not directly comparable. See Archer vs ServiceNow IRM and the ServiceNow IRM review.
IBM OpenPages is the other regulated-industry GRC suite this guide compares Archer against directly, and it is more transparent on price: IBM publishes AWS “starting at” figures of $3,300 and $6,050, and IBM Cloud figures of $6,250 and $9,000, with no billing period stated. Its AI layer runs through watsonx and an OpenPages MCP Server rather than Archer’s Bedrock-based approach, and its Gartner Peer Insights rating for the audit product specifically is 4.1 from 9 reviews. IBM OpenPages vs Archer and the IBM OpenPages review go through the fit case by case.
For a buyer who wants audit-first software rather than a GRC suite with audit inside it, Optro (formerly AuditBoard) is the most-reviewed alternative in this guide by a wide margin, with a published Vendr median of $45,947 a year where Archer has none; Optro vs Archer sets out that trade-off directly. SAI360, STG-owned since 2023 with BWise heritage, sits in the same bank-leaning suite category at a smaller scale; see the SAI360 review. The Archer alternatives page has the fuller shortlist in both directions, lighter and heavier.
Questions about Archer
Is Archer the same as RSA Archer?
Yes, in lineage. The product began as a line inside RSA Security, and “RSA Archer” is still the name on some older listings and reviews. RSA’s parent sold Archer along the STG-Clearlake-Cinven ownership chain described above, and the product now trades simply as Archer, with no RSA branding on current materials.
Is Archer Evolv a replacement for classic Archer?
No, not yet. Archer has been adding Evolv, a cloud-native SaaS layer, module by module since 4 February 2025, and markets it as sitting on the same data as classic Archer rather than requiring a migration. Confirm which specific modules you need are available on Evolv today, since the two editions are still coexisting rather than one having fully replaced the other.
How much does Archer cost?
There is no public price. The only figures we could find are an evident placeholder ($9,999,999.00) on an AWS Marketplace listing and a $100,000 legal-review threshold in Vendr’s buyer data, with no median or range. Expect a fully negotiated quote scoped to the modules and users you need, and push for a written pricing schedule in the RFP rather than a verbal range in a demo.
Is Archer right for a small audit team?
Generally not as a first system. Archer’s value depends on shared risk and control data that a team of one to five auditors is unlikely to have built yet, there is no public entry-level price, and the fit ratings in this review mark small and mid-size functions as Poor fit for exactly that reason. The site’s audit software for small teams guide and the best internal audit software roundup have better-suited, lower-cost options.
Does Archer’s AI train on our data?
Archer has not published a data-use, retention or opt-out policy for most of its AI features. The one exception is Archer Evolv AI Compliance, launched 15 September 2026, which runs guardrails inside the customer’s own AWS account and IAM role and states that prompts and model weights stay isolated from Archer. For every other AI feature named in this review, ask the question directly and get the answer in writing before enabling it on real workpapers.
Is Archer FedRAMP authorized?
We found no FedRAMP or GovRAMP authorization claim anywhere in Archer’s security documentation, despite a dedicated Public Sector module built around POA&M, Assessment & Authorization and Continuous Monitoring workflows. Federal buyers should ask directly for an authorization letter or a sponsoring agency rather than assuming the Public Sector module implies one; state, local and education buyers have more to work with through Carahsoft’s GSA, NASA SEWP V and ITES-SW2 contract vehicles.
internalauditguide.com has no commercial relationship with Archer or any other vendor named on this page. We take no vendor money, run no affiliate links and accept no sponsored placements, and no vendor saw this page before publication. Product and company names are the trademarks of their owners. Corrections: desk@internalauditguide.com.
Sources and verification
- Cinven to acquire Archer (PR Newswire, 13 April 2023) — the acquisition announcement, founding, headquarters and 2023 customer claims (accessed 26 September 2026).
- Clearlake and STG complete sale of Archer to Cinven — the deal’s close date, the RSA/STG/Clearlake ownership history and the SaaS ARR claim (accessed 26 September 2026).
- Bill Diaz leadership biography (archerirm.com) — the CEO’s background and the stale “1,000 global customers” figure (accessed 26 September 2026).
- Archer: audit management product page — the Audit Management modules, workflow claims and current customer and analyst claims (accessed 26 September 2026).
- Archer platform solutions overview (help center) — the full module catalog (accessed 26 September 2026).
- Audit Planning & Quality documentation (help center) — planning-stage detail, the QA questionnaires and the seven automated data feeds (accessed 26 September 2026).
- Workspaces & Dashboards documentation (help center) — the reporting-stage detail (accessed 26 September 2026).
- Regulatory & Corporate Compliance Management product page — the Financial Controls Monitoring and SOX detail (accessed 26 September 2026).
- Archer introduces Archer Evolv (BusinessWire, 4 February 2025) — the Evolv launch date and scope (accessed 26 September 2026).
- Archer launches Archer Evolv AI Compliance (15 September 2026) — the Bedrock Guardrails architecture and its data-handling claims (accessed 26 September 2026).
- Archer launches a harnessed digital workforce (01net.it, 14 September 2026) — the Evolv Foundation and Workplace launch and its model-count claims (accessed 26 September 2026).
- SaaS Security and Trust (community.archerirm.com) — certifications, encryption, hosting and SLA detail (accessed 26 September 2026).
- Archer SaaS listing (AWS Marketplace) — the placeholder contract price and the pricing-not-published language (accessed 26 September 2026).
- Archer pricing (Vendr marketplace) — the absence of a median price and the legal-review threshold (accessed 26 September 2026).
- Archer contract vehicles (Carahsoft) — the GSA, NASA SEWP V and ITES-SW2 vehicles (accessed 26 September 2026).
- Archer Audit Management reviews (Gartner Peer Insights) — the 4.3-from-36 rating and its themes (accessed 26 September 2026).
- Archer reviews (G2) — the rating, reviewer segments and themes (accessed 26 September 2026).
- RSA Archer Suite reviews (Capterra) — the rating and themes (accessed 26 September 2026).
- Archer Integrated Risk Management Platform reviews (TrustRadius) — the rating and themes (accessed 26 September 2026).
- Archer and Deloitte alliance (BusinessWire, 15 October 2025) — the implementation-partner scope (accessed 26 September 2026).
Related guides
- Internal audit software: the independent buyer’s guide — every review, comparison and buying guide in one place.
- How we review audit software — the evidence levels, the scorecard and the fit-by-situation method.
- The audit software shortlist finder — eight questions, a shortlist with the reasons from each review.
- The requirements matrix — 156 weighted requirements and vendor scoring in a free Excel workbook.
- Archer alternatives — enterprise GRC platforms and lighter options for audit teams.
- Optro vs Archer — audit-first SaaS against the enterprise GRC platform.
- MetricStream vs Archer — two enterprise GRC suites for audit, risk and compliance.
- Archer vs ServiceNow IRM — the GRC decision most large enterprises face.
- IBM OpenPages vs Archer — which regulated-industry GRC platform for audit.
- MetricStream review — audit management inside an AI-first GRC suite.
- ServiceNow IRM audit management review — right only if you already run ServiceNow.
- IBM OpenPages internal audit review — published prices, AI agents and the fit.
- SAI360 review — internal audit and SOX in a financial-services GRC suite.
- GRC suite vs standalone audit management software — how to make the call in 2026.
- Internal audit software pricing — real numbers, pricing models and how to negotiate.
- Selecting an audit management system — the vendor-neutral RFP method.
- Types of internal audit software — audit management, GRC, SOX, compliance and analytics.
- Best internal audit software — 25 platforms and tools compared by use case.
- Archer vs LogicGate — the two compared factor by factor, with cost and fit by situation.
Leave a Reply