A bank or credit union buying audit management software is not shopping for the same thing a manufacturer or a technology company is. An examiner wants to see how a Matter Requiring Attention moves from finding to independently validated closure, not just how an issue moves from open to closed. A regional bank’s third line needs its findings linked to the model risk inventory the second line already keeps, and a credit union’s audit committee needs a board pack the CEO can hand to an examiner without rebuilding it in a slide deck first. Most of the platforms covered elsewhere on this site were built for corporate audit functions generally and picked up regulated customers later, and the gap shows up exactly where a bank buyer looks first: regulatory issue tracking, exam support, retention and who gets read-only access when an examiner asks for it. A demo built around a manufacturer’s workflow will look impressive and still fail a bank’s own procurement checklist on every one of those points.
This guide sets out what regulated institutions need that a generic buyer does not, then narrows the field to the platforms with a documented bank or credit union base: Archer, MetricStream, IBM OpenPages, SAI360, Empowered Systems’ Connected Risk, Protecht, TeamMate, Optro (formerly AuditBoard) and Diligent One. It covers certifications and hosting product by product, a fit table by institution size from a community bank under $1 billion in assets to a global bank, the analytics tools banks use for full-population testing, and a worked example at a $9 billion regional bank. For the mechanics behind a regulatory finding’s own life cycle, see the site’s guide to the MRA and MRIA lifecycle; for the wider picture of audit inside a regulated institution, see internal audit in financial services.
How to read this guide
What this guide is for. Shortlisting audit management software for a bank, thrift or credit union, where regulatory issue tracking, exam support and model risk linkage matter as much as ordinary engagement workflow.
Evidence. Research-based: vendor documentation and release notes, public procurement records, third-party pricing data, verified user reviews on Gartner Peer Insights and G2, and analyst coverage. We have not used any of these products hands-on for this guide.
Last verified. 27 September 2026.
In this guide
- What examiners expect that a generic audit RFP misses
- The platforms with a bank and credit union base
- Certifications and hosting, product by product
- Fit by institution size
- Analytics for banks: full-population testing tools
- A bank and credit union RFP checklist
- Worked example: Lakeshore Bancorp shortlists a platform
- Questions about audit software for banks and credit unions
- Sources and verification
- Related guides
What examiners expect that a generic audit RFP misses
Every internal audit platform tracks issues, but a Matter Requiring Attention or a Matter Requiring Immediate Attention is not an ordinary finding. It carries a regulator-assigned reference, a validation standard that closes it only after independent testing confirms the root cause is fixed rather than when management reports it fixed, and its own reporting line to the board’s audit or risk committee. A platform that treats an MRA as a tagged category on a regular issue, instead of a distinct object with its own workflow and evidence trail, pushes the audit team or the second line back into a shadow spreadsheet anyway, which defeats the reason for buying software at all. The site’s guide to the MRA and MRIA lifecycle covers finding-to-closure mechanics in full; the table below is what a bank-specific RFP should add to a generic one.
| Capability | Why examiners care | What to check for in a demo |
|---|---|---|
| Regulatory issue tracking (MRA or MRIA) | Examiners test whether validation is independent of management’s self-report | Ask for a regulatory-issue object separate from an ordinary audit finding, with its own validation sign-off field |
| Exam request support | An exam is effectively a compressed, external audit with document requests on a fixed deadline | Ask whether examiners get their own scoped, read-only or upload-only access, not a shared login |
| Model risk and third-party linkage | Model risk and vendor risk both feed audit’s risk assessment and often share findings with the second line | Ask how a model or vendor risk rating surfaces inside audit planning, not only in a separate risk register |
| Board and committee reporting | An audit committee, and a board facing an NCUA or OCC examiner, needs a packaged report, not a raw export | Ask for a sample audit-committee report generated inside the tool, not assembled around it afterward |
| Retention | Examiners can ask for workpapers and evidence years after an audit closed | Confirm the retention period, and what happens to evidence if a license lapses or an engagement is archived |
| Examiner access | Some exams expect the examiner to work inside the institution’s own systems directly | Confirm a scoped guest or examiner role exists, and whether that role carries its own license cost |
None of the nine platforms below were built only for banks; all nine serve a mix of industries. What separates the ones that work well for a regulated buyer is not a banking-specific feature so much as depth on these six points, most of which trace back to the risk categories a bank’s own examiners organize around. The site’s guide to OCC risk categories covers the framework many bank audit universes are built against, and the guide to model risk audits covers the specific linkage examiners look for between audit and the model risk inventory.
The platforms with a bank and credit union base
Nine platforms in this site’s research carry a documented, non-trivial base of bank, credit union or wider financial-services customers, drawn from named logos, case studies or a vendor’s own sector claim. That is a lower bar than proof of exam-readiness, and the table gives what public evidence supports for each, not a ranking.
| Product | Owner | Category | Bank or credit union evidence |
|---|---|---|---|
| Archer | Cinven | Enterprise GRC suite | Claims 37 of the top 50 global banks among 1,300+ customers; named customers include TD Bank, BECU and First National Bank of Omaha. Full review: Archer |
| MetricStream | Private; Blue Torch Capital financing | Enterprise GRC suite | Customer stories name Nordea, BMO Financial Group, CIBC, Standard Chartered and Zurich Insurance Group. Full review: MetricStream |
| IBM OpenPages | IBM Corporation | Enterprise GRC suite | Citi’s roughly 2,500 auditors use an AI-powered audit platform built on OpenPages, per IBM’s own case study (30 October 2025). Full review: IBM OpenPages |
| SAI360 | Symphony Technology Group | Enterprise GRC suite | Claims more than 300 banking and financial-services organizations worldwide, undated. Full review: SAI360 |
| Empowered Systems (Connected Risk) | Private; ownership not disclosed | No-code GRC platform | Named customers include Citi, RBC, TD, Santander, MUFG, Nomura and SMBC, shown as static logos with no case study tying a name to usage. Full review: Empowered Systems |
| Protecht | PSG Equity (growth investment, stake undisclosed) | No-code GRC platform | Names First Tech Federal Credit Union in the US; its other named bank and credit union customers are Australian, and the base overall is Australia and New Zealand-weighted. Full review: Protecht |
| TeamMate | Wolters Kluwer | Internal audit platform | A public two-user price anchor at a US city government and a long audit-market track record; the vendor markets public-sector and credit-union strength specifically. Full review: TeamMate |
| Optro (formerly AuditBoard) | Hg | Internal audit platform | A broad enterprise base (more than half the Fortune 500, claimed) with fewer named bank case studies than the GRC suites above. Full review: Optro |
| Diligent One Platform | Insight Partners | Internal audit platform plus analytics | Its ACL heritage gives it the deepest analytics story on this list for full-population testing, plus a GovCloud option for public-sector-adjacent work. Full review: Diligent One |
Four of the nine are enterprise GRC suites where audit is one module among several: Archer, MetricStream, IBM OpenPages and SAI360. All four carry the heaviest documented bank customer bases here, and all four also carry the least specific public evidence about an audit-module-only implementation timeline or price; a large institution typically buys these as part of a wider enterprise risk and compliance decision, not for audit alone. Two more, Empowered Systems’ Connected Risk and Protecht, are no-code GRC platforms that also name banks and credit unions among their customers, though Empowered’s public footprint is the thinnest on this list (no security or pricing page of any kind was found), and Protecht’s confirmed US financial-services base is a single credit union set against a customer list that otherwise skews heavily Australian.
The remaining three, TeamMate, Optro and Diligent One, are internal audit platforms first, with audit and SOX as the primary product rather than one module inside a broader suite. TeamMate has the clearest small-institution price evidence of the nine; Optro has the broadest enterprise customer base and the deepest published AI feature set; Diligent One pairs its audit workflow with the ACL analytics layer many bank audit teams already use for transaction testing. The third-party risk management program guide and the third-party topical requirement reference cover the vendor-risk side several of these products claim to link into.
Certifications and hosting, product by product
A bank’s own vendor security assessment will go deeper than any public claim, but what a vendor publishes is still the fastest first filter, and the gaps are as telling as the certifications. Two of the nine, MetricStream and Empowered Systems, publish no SOC 2, ISO 27001 or FedRAMP claim of any kind for their GRC or audit product; that does not prove no certification exists, only that a buyer cannot verify one without asking directly, and a bank examiner reviewing third-party risk documentation will ask exactly that question during the vendor’s own annual review. TeamMate and Diligent One are the only two with a FedRAMP-adjacent claim on the public record, and neither is a simple yes.
| Product | SOC 2 | ISO 27001 | FedRAMP or GovRAMP | Hosting |
|---|---|---|---|---|
| Archer | Type 2 (SSAE 18) | 27001, plus 27017 and 27701 | None found | AWS, across seven regions |
| MetricStream | None found | None found | None found | Dedicated single-tenant private cloud; provider not named |
| IBM OpenPages | General IBM Cloud attestation only, not OpenPages-specific | General IBM Cloud attestation only | General IBM Cloud FedRAMP; no OpenPages-specific authorization found | AWS Marketplace, IBM Cloud, on-premises, or Cloud Pak for Data |
| SAI360 | SOC 1 and SOC 2 Type II (with a HIPAA attestation); SOC 2 and HITRUST CSF specifically for Compliance USA | 27001:2022 | None found | “Built on Google Cloud” per the platform page; the security page also names AWS tooling, a discrepancy neither page resolves |
| Empowered Systems | None found | None found | None found | Not disclosed; no security page of any kind was found |
| Protecht | “Assessed” against the AICPA framework; type not stated | Certified; certificate number and expiry not published | None found | An unnamed “trusted provider”; AWS is named only for the Cognita AI workload specifically |
| TeamMate | Type 2 | 27001 | The FedRAMP Marketplace lists TeamMate Audit and Controls as Authorized, Moderate impact, agency path, since 13 May 2022, and Wolters Kluwer’s public-sector page separately claims “FedRAMP and GovRAMP Authorized”; the TeamMate Audit product page itself still describes FedRAMP as “upcoming” | Microsoft Azure (TeamCloud) |
| Optro | Type II (SOC 1 and SOC 2) | 27001 | Hosting “meets FedRAMP moderate impact requirements,” a requirements claim, not a stated authorization | AWS |
| Diligent One | Type II (SSAE 18, annual) | 27001:2013 | GovCloud only: FedRAMP Moderate and DoD IL5, for a separate GovCloud environment; several apps and ACL AI Studio are unsupported there | AWS, nine commercial regions plus GovCloud |
Read the FedRAMP column carefully before it decides a shortlist. TeamMate’s Marketplace listing is the most concrete of the nine, but it names TeamMate Audit and Controls specifically, not the newer TeamMate Risk & Compliance module, and the vendor’s own product page has not caught up with its own Marketplace listing. Diligent One’s FedRAMP Moderate and DoD IL5 status applies only inside GovCloud, a separate environment from the commercial product most banks would actually buy, and it excludes ACL AI Studio along with several other apps. IBM’s FedRAMP authorization is a property of IBM Cloud generally; nothing found here confirms OpenPages itself carries a separate authorization. None of this rules a product out for a bank, which is not a federal agency and rarely needs FedRAMP itself, but a credit union or bank examined alongside public-sector-adjacent programs should ask the vendor to confirm scope directly rather than read a badge on a marketing page as settled.
Fit by institution size
Institution size drives this decision harder than almost any other buyer characteristic in this site’s fit-by-situation method, because it tracks audit-team headcount and procurement complexity at once. All nine platforms above already carry a Strong fit rating for “bank or credit union” in this site’s situation-based scoring; the table below breaks that single rating down by the size band public evidence best supports. “Approach with caution” means the evidence is thin or mixed for that size, not that the fit is poor.
| Institution size | Best-supported shortlist | Why | Approach with caution |
|---|---|---|---|
| Community bank or credit union, under $1 billion in assets | TeamMate, Protecht | TeamMate has a public two-user price anchor under $30,000 all-in; Protecht prices by user count from as few as two and names a US credit union customer directly | Archer, MetricStream, IBM OpenPages, SAI360 and Empowered Systems price and scope for enterprise buyers; none publishes evidence of a workable small-institution deployment |
| Regional bank or credit union, $1 billion to $50 billion in assets | TeamMate, Optro, Diligent One, Protecht, SAI360 (Professional edition or above) | This band is where audit-native platforms compete most directly with mid-tier GRC suites, and where SAI360’s edition structure starts to make financial sense | Empowered Systems remains workable at best here; its named customers are money-center banks, not regional ones |
| Large or global bank | Archer, MetricStream, IBM OpenPages, SAI360, Empowered Systems, Diligent One, Optro | All name large-bank customers, and the enterprise GRC suites in particular are built for the multi-entity, multi-regulator complexity a global bank brings | Smaller audit-native platforms stay workable rather than poor, but a large bank’s second and third line usually already run a suite for risk and compliance, which pulls the decision toward consolidation |
Price evidence tracks the same pattern. TeamMate’s City of Norman, Oklahoma quote (28 February 2025) priced a two-user TeamMate+ Audit Essentials subscription, including TeamMate Analytics and TeamCloud hosting, at $6,150.88 a year, with implementation adding $15,630. Optro’s Vendr-tracked median sits at $45,947 a year across 86 purchases (updated February 2026), with a range from $21,220 to $111,208; Diligent One’s Vendr median of $26,250 a year is mostly board-portal deals and likely understates audit-specific pricing. None of the enterprise GRC suites publishes a comparable figure. The site’s guides to internal audit software pricing and audit software for small teams cover the wider pricing picture beyond banks specifically.
Analytics for banks: full-population testing tools
Bank audit teams test high volumes of loans, transactions and accounts where a sample would miss what a full-population run catches, which is why analytics software sits alongside the platform decision for most banks in this guide’s research rather than inside it. Four tools come up repeatedly in bank and credit union contexts.
| Tool | Owner | What it does | Bank-relevant note |
|---|---|---|---|
| Caseware IDEA | Hg (majority stake) | Desktop and cloud data analysis, scripted tests, the AiDA assistant and dashboards | A long-standing default for loan-file and transaction testing, with a large existing base among bank audit teams. Full review: Caseware IDEA |
| Arbutus Analyzer | Arbutus Software | Full-population testing with scripted and ad hoc analysis; version 9 (May 2025) added AI features | Converts ACL project files directly, which matters for a bank migrating off ACL Analytics or absorbing an acquired institution’s analytics library. Full review: Arbutus Analyzer |
| ACL Analytics | Diligent | Scripted and continuous analytics inside the Diligent One Platform; version 19 (4 December 2025) added AI command and a Databricks connector | ACL AI Studio’s agentic mode (from 2 February 2026) now runs on the Claude 4.6 model, per Diligent’s own release notes (17 September 2026), and ties directly into Diligent One’s audit workflow. Full review: ACL Analytics |
| TeamMate Analytics | Wolters Kluwer | An Excel add-in with more than 150 pre-built tests and a Continuous Analyzer | Bundled into TeamMate’s public-sector price anchor at no extra line item; no independent review-site rating exists for the add-in on its own. Full review: TeamMate Analytics |
None of the four is audit-management software; all four assume a bank already has, or is buying, one of the nine platforms above to hold the plan, the workpapers and the issues, and reach into the core system or the data warehouse for testing a sample-based workpaper cannot support. Public price evidence for these tools is thinner outside banking than the platform pricing above, which is itself a reason to press a vendor for a same-industry reference during procurement rather than accept a generic figure. The site’s guide to audit analytics software compares transaction-testing tools side by side, and IDEA versus Arbutus versus ACL goes deeper on the choice among the three full-population tools.
A bank and credit union RFP checklist
Add these to a generic audit-software RFP; none of them appears in a template written for a manufacturer or a technology company.
Bank and credit union RFP addendum
Regulatory issue object. Require a distinct MRA or MRIA (or state-examiner-equivalent) object with its own identifier, validation sign-off field and board-reporting link, kept separate from an ordinary audit finding.
Examiner access. Ask whether a scoped, time-limited examiner role exists, whether it is read-only or allows document upload, and whether it carries its own license fee.
Model risk and third-party linkage. Ask how a model risk rating or a vendor risk score from the second line surfaces inside audit’s own risk assessment, and whether the link is a live data connection or a manual re-entry.
Board and committee reporting. Ask for a sample audit-committee report generated inside the tool, and whether it can be branded and exported without a separate report-writing add-on.
Retention. Get the retention period in writing, and confirm what happens to evidence and workpapers if the institution stops paying or is acquired.
Certifications on request. Ask for the SOC 2 report, the ISO certificate and any FedRAMP or GovRAMP documentation directly; several vendors in this guide publish none of these, which is worth confirming before a demo, not after a contract.
Data residency. For an institution with state-specific data rules, confirm which region hosts production data, and whether that placement can be guaranteed contractually rather than described only as an option.
Worked example: Lakeshore Bancorp shortlists a platform
Lakeshore Bancorp is this site’s recurring fictional entity: a $9 billion regional bank with 60 branches and 212 key controls. Its six-person audit team runs an annual SOX program alongside safety-and-soundness, BSA/AML and consumer-compliance audits, and its last exam left two open Matters Requiring Attention still tracked in a spreadsheet the chief audit executive does not trust. Applying this guide’s fit table narrows Lakeshore’s shortlist immediately: at $9 billion in assets it sits in the regional band, which points toward TeamMate, Optro, Diligent One, Protecht or SAI360’s Professional edition rather than the enterprise suites built for money-center banks, and rules out treating this as a first-system decision even though six auditors is a small team by headcount alone.
Lakeshore’s specific requirements narrow the list further. Its two open MRAs make the regulatory-issue object in the checklist above non-negotiable, which every platform on the regional shortlist supports through some form of distinct issue tracking, though only a live demo confirms whether validation sign-off is genuinely independent of the finding’s owner. Its SOX program pulls it toward TeamMate or Diligent One, both of which pair audit workflow with a controls or analytics layer rather than requiring a second purchase, and its existing Excel-based testing work points toward whichever platform’s add-in its team already knows, since retraining six auditors on a second, unfamiliar analytics tool at the same time as a new platform is the kind of decision that sinks an implementation. The site’s guide to implementing audit management software covers the first 120 days in more detail than fits here.
Questions about audit software for banks and credit unions
Do we need a FedRAMP-authorized platform if we are not a federal agency?
No bank or credit union is required to buy FedRAMP-authorized software; FedRAMP is a federal-agency accreditation program, not a banking regulation. A FedRAMP or GovRAMP claim is still useful evidence of a vendor’s security maturity and worth asking about directly, since, as the certifications table above shows, the claims among these nine range from a clear agency authorization (TeamMate) to a narrower GovCloud-only status (Diligent One) to no claim at all (MetricStream, Empowered Systems).
Can a $500 million credit union justify Archer or MetricStream?
Public pricing evidence does not answer this directly since neither publishes a price, but both are built and priced for enterprise, multi-module GRC buyers with named customers well into the billions of dollars in assets. A credit union that size is better served starting with TeamMate or Protecht, both of which have public evidence of workable small-institution pricing, and revisiting a GRC suite only if audit later needs to consolidate onto a platform the second line already runs.
Does audit software replace the second line’s GRC platform?
No. Audit management software runs the third line’s own engagements, plan and workpapers; an enterprise GRC suite like Archer, MetricStream, IBM OpenPages or SAI360 more often serves as the platform the second line already runs for risk and compliance, with audit as one module inside it. The site’s guide to GRC suite versus standalone audit management software covers that decision directly.
How is auditing a bank’s MRAs different from tracking a normal finding?
An MRA carries a regulator-assigned reference and closes only after independent testing confirms the root cause is fixed, not when management reports it fixed; it typically carries its own reporting line to the board as well. The site’s guide to the MRA and MRIA lifecycle covers the full process.
What does examiner read-only access actually mean in practice?
It usually means a scoped guest or examiner role that can view or download specific workpapers and evidence on request without a full audit-team license, and sometimes a separate area for the examiner’s own document requests. Not every platform in this guide confirms whether that role is free or licensed separately, which is exactly why it belongs in the checklist above rather than assumed.
Is TeamMate or Optro the better first system for a community bank?
TeamMate’s public price evidence, a two-user quote under $30,000 all-in, undercuts anything found for Optro, whose Vendr-tracked median sits above $45,000 a year before implementation. For a first system at a small institution, that gap alone often decides it, though Optro’s broader customer base and deeper published AI feature set are worth a demo before ruling it out.
internalauditguide.com has no commercial relationship with any vendor named on this page. We take no vendor money, run no affiliate links and accept no sponsored placements, and no vendor saw this page before publication. Product and company names are the trademarks of their owners. Corrections: desk@internalauditguide.com.
Sources and verification
- Archer: clients page — the “37 of the top 50 global banks” claim and named bank customers (accessed 26 September 2026).
- Archer: SaaS Security and Trust — certifications, encryption and hosting regions (accessed 26 September 2026).
- MetricStream: customer stories — named financial-services customers including Nordea, BMO and Standard Chartered (accessed 26 September 2026).
- MetricStream: Trust Center — the absence of a public SOC 2, ISO 27001 or FedRAMP claim (accessed 26 September 2026).
- IBM: Citi case study — the roughly 2,500-auditor figure on OpenPages (accessed 26 September 2026).
- IBM: Cloud compliance page — the general SOC, ISO and FedRAMP programs cited for OpenPages hosting (accessed 26 September 2026).
- SAI360: Financial Services — the “300+” banking and financial-services customer claim (accessed 26 September 2026).
- SAI360: Trust and Security — certifications and the Google Cloud/AWS hosting discrepancy (accessed 26 September 2026).
- Empowered Systems: Connected Risk — the named bank customer logos (accessed 26 September 2026).
- Protecht: ERM case studies — the First Tech Federal Credit Union customer reference (accessed 26 September 2026).
- Protecht: Security and Compliance — ISO 27001, the SOC 2 assessment statement, and encryption (accessed 26 September 2026).
- Wolters Kluwer: TeamMate privacy and security certifications — ISO 27001, SOC 2 Type 2 and the FedRAMP and GovRAMP claim (accessed 26 September 2026).
- FedRAMP Marketplace: TeamMate FedRAMP (FR2207643307) — Moderate impact, agency authorization since 13 May 2022 (accessed 26 September 2026).
- City of Norman, Oklahoma: TeamMate+ quote of 28 February 2025 — the two-user subscription and implementation price (accessed 26 September 2026).
- Optro: trust and security page — certifications, hosting and the FedRAMP requirements language (accessed 26 September 2026).
- Vendr: AuditBoard (Optro) pricing — the median, range and purchase count, updated February 2026 (accessed 26 September 2026).
- Diligent help center: Commercial and GovCloud regions and limitations — the FedRAMP Moderate and DoD IL5 statements and unsupported apps (accessed 26 September 2026).
- Diligent help center: ACL AI Studio release notes — the agentic mode date and the Claude 4.6 model confirmation (accessed 26 September 2026).
Related guides
- Internal audit software: the independent buyer’s guide — every review, comparison and buying guide in one place.
- How we review audit software — the evidence levels, the scorecard and the fit-by-situation method.
- The audit software shortlist finder — eight questions, a shortlist with the reasons from each review.
- The requirements matrix — 156 weighted requirements and vendor scoring in a free Excel workbook.
- Best internal audit software — 25 platforms and tools compared by use case.
- Internal audit software pricing — real numbers, pricing models and how to negotiate.
- Types of internal audit software — audit management, GRC, SOX, compliance and analytics, told apart.
- GRC suite vs standalone audit management software — how to make the call for a regulated buyer.
- Internal audit software vs compliance automation — Optro and TeamMate against Vanta and Drata.
- Evaluating AI in audit software — what is real and what is agent-washing.
- The business case for audit software — getting budget approved by the CFO and the board.
- The audit software demo script — 25 scenarios that make vendors show, not tell.
- Audit software due diligence — security, data residency, AI data use and vendor stability.
- Audit software vs Excel and SharePoint — when to switch, and how big you need to be.
- Implementing audit management software — the first 120 days and migrating off Excel.
- 15 mistakes internal audit teams make when buying software — and how to avoid each.
- Selecting an audit management system — a vendor-neutral RFP method.
- Audit software for small internal audit teams — 1 to 5 auditors, options and real prices.
Leave a Reply