,

IBM OpenPages Internal Audit Review: Published Prices, AI Agents and the Fit

IBM OpenPages is the internal audit module inside a nine-module enterprise GRC platform IBM has owned outright since 2010, and the buyer it fits best already runs some other part of that platform, most often for operational, model or IT risk. Bought that way, Internal Audit Management inherits a live risk and control model another function already built, rather than the third line starting from a blank register. Bought as a first audit tool, or by a team of five or fewer auditors, it is a narrower proposition: the platform’s newest, most-marketed features in 2026 are AI agents and a Model Context Protocol server, not audit workflow depth, and the audit module competes for IBM’s attention against eight sibling modules. The one fact worth knowing before any call with IBM: it is one of the only vendors in this guide that states real starting prices on its own website, but it does not say whether they are billed monthly or annually, so the number on the page is a floor, not a quote.

This review covers what Internal Audit Management does at each audit stage per IBM’s own documentation, the separate Financial Controls Management module a SOX-driven buyer has to license alongside it, the dense run of AI releases from OpenPages 9.1 through 9.2.1, the pricing evidence that exists in place of one list price, and the recurring themes in reviews on Gartner Peer Insights and G2. It is one of the product reviews in the site’s independent buyer’s guide to internal audit software and follows the evidence levels and scorecard set out in how we review audit software. Buyers deciding between OpenPages and the other big regulated-industry GRC suite should also read IBM OpenPages vs Archer.

Verdict. IBM OpenPages earns a Strong fit only where a bank, insurer or other large regulated enterprise already runs, or is committed to running, OpenPages for another risk discipline and wants audit on the same shared data; bought alone, or by a small or mid-size team, it is a nine-module platform’s audit slice, priced and administered as an IBM decision rather than an audit-team one.

Best for. Large or global audit functions inside a bank, insurer or other regulated enterprise that already runs, or plans to run, OpenPages for operational, model or IT risk.

Not for. A first system for a team of one to five auditors, a public-sector, higher-education or nonprofit buyer with no existing IBM relationship, or any buyer whose main goal is a fast, audit-only tool the team can configure itself.

Evidence. Research-based: vendor documentation and release notes, public procurement records, third-party pricing data, verified user reviews on Gartner Peer Insights and G2, and analyst coverage. We have not used the product hands-on for this review.

Price evidence. IBM’s own pricing page states ‘starting at’ figures with no billing period given: $3,300 and $6,050 on AWS, $6,250 and $9,000 on IBM Cloud. IBM’s AWS Marketplace listing shows real 12-month contracts instead, with base SaaS plans priced around $7,740 to $8,400 a year before add-ons.

Last verified. 27 September 2026.

In this guide

What IBM OpenPages is, and who owns it

OpenPages traces to a company founded in Amherst, Massachusetts in May 1990, originally named American Computer Innovators and renamed OpenPages in August 2000; it was a Matrix Partners portfolio company with more than 200 enterprise customers by the time it was acquired. IBM completed that acquisition on 21 October 2010, on undisclosed terms, and has not sold, spun off or renamed the product since: OpenPages has had one owner for 16 years, a contrast to the ownership churn this guide documents at Archer, MetricStream and several other suites. That stability cuts both ways. There is no OpenPages-specific chief executive, headquarters or press office to hold accountable, and no private-equity holding period to watch at renewal, but there is also no dedicated OpenPages sales or product organization; IBM Corporation is the vendor of record, and Internal Audit Management is one line item inside IBM’s much larger software portfolio.

IBM’s own materials lean on named customers rather than a company narrative, since there is no separate OpenPages company history to tell after 2010. On 30 October 2025, IBM published a case study saying Citi’s roughly 2,500 auditors use an AI-powered audit platform built on OpenPages for documentation review and risk assessment. On 27 August 2026, it published a second story describing Zurich Insurance Group’s Group Risk Management function — an insurer operating in more than 210 countries and territories with more than 65,000 employees — running OpenPages for non-financial risk, with Cognos Analytics for reporting and a ‘configuration-first’ build described in the implementation section below. French trade press separately reports that the telecom operator Orange selected OpenPages to harmonize its risk management, though the exact selection date was not captured in the source we read. IBM’s own product page also displays logos for Navigator Gas and CNP Vita Assicura with no case-study detail behind either — treat those two as unverified beyond the logo placement.

IBM’s analyst claims follow the pattern nearly every enterprise GRC vendor in this guide follows: a Leader placement, announced by the vendor, in a report that is not specific to audit management. IBM says OpenPages was named a Leader in the 2025 Gartner Magic Quadrant for Governance, Risk and Compliance Tools, Assurance Leaders (4 November 2025), and separately a Leader in two IDC MarketScape reports — Worldwide Governance, Risk and Compliance Software 2025 (22 July 2025), citing analyst Phil Harris, and Worldwide AI-Enabled Financial Governance, Risk and Compliance 2026 (28 July 2026), whose announcement cites IDC’s language calling OpenPages’ product direction “the most forward-looking” and its embedded AI “the most advanced for embedded AI.” Gartner has no Magic Quadrant for audit management specifically; its 13 April 2026 Market Guide for Audit Management Software, by analyst James Bourke, is the document that actually covers this narrower market, and its advice is to be wary of agent-washing — a caution that matters more for OpenPages than for most products in this guide, given how much of its 2026 roadmap is AI features. The guide to reading audit software analyst reports has the full method for weighing claims like these. The timeline below covers the releases and recognitions that shaped the product buyers see today.

DateEventWhy it matters to a buyer
1990Founded in Amherst, Massachusetts as American Computer Innovators (renamed OpenPages in 2000)The product predates IBM ownership by two decades
21 October 2010IBM completes the acquisition of OpenPagesStart of 16 years under one owner, with no further ownership change since
21 June 2023OpenPages 9.0.x reaches general availabilityStandard support ends 30 September 2026; extended support runs to 30 September 2030
3 April 2025OpenPages 9.1 shipsAI-assisted views for model input, SFTP and cloud-storage export, Arabic (RTL) language support, OAuth 2.0
30 October 2025IBM publishes the Citi case studyAbout 2,500 auditors, the largest named audit deployment in this guide
4 November 2025Named a Leader, Gartner Magic Quadrant for GRC Tools, Assurance LeadersA GRC-platform report, not an audit-management one
26 December 2025OpenPages 9.1.3 shipsAn experimental, local Model Context Protocol server and Bring-Your-Own-Model extensions for connecting third-party AI models
23 March 2026 (SaaS; 27 March on-premises; 31 March AWS Marketplace)OpenPages 9.2 rolls outA fully productized, managed OpenPages MCP Server, native watsonx Orchestrate chat, and expanded AI evidence analysis
23 July 2026OpenPages 9.2.1 shipsEight out-of-the-box AI model configurations, including audit-plan creation and questionnaire-response generation
27 August 2026IBM publishes the Zurich Insurance Group storyThe most recent named customer account, describing a configuration-first rollout

What you get: modules and how audit fits

OpenPages is one configurable platform, not separate products bolted together. Internal Audit Management is one of nine listed modules, and IBM’s own module overview says the audit module is specifically built to share data with Financial Controls Management, Operational Risk Management, Policy and Compliance Management and IT Governance, for enterprise-wide visibility. That is the same structural trade-off every enterprise GRC suite in this guide makes: audit inherits real, shared risk and control data where another function already built it, and gets very little advantage where audit is the only function buying.

Deployment options confirmed across IBM’s own materials are SaaS on AWS Marketplace, SaaS or cloud-hosted on IBM Cloud, on-premises, and IBM Cloud Pak for Data, also called IBM Software Hub, a cartridge-based option IBM was still supporting and updating for version 9.1.2.1 as of 15 December 2025. The editions IBM actually names are tied to that deployment choice rather than to a feature tier: AWS ‘Essentials’ and ‘Standard,’ and IBM Cloud ‘Single Solution’ and ‘Enterprise.’ On-premises and Cloud Pak for Data are both quoted individually. The pricing and contract section below has the actual figures; what matters here is that a buyer picks a deployment model first, and the edition follows from it, rather than choosing a feature tier the way a SaaS-only competitor would let them.

ModuleWhat it coversAudit-relevant detail
Internal Audit ManagementAnnual planning, engagement planning, workpaper management, time and expense tracking, audit reporting and wrap-upThe subject of this review
Regulatory Compliance ManagementTracks regulatory change inside a connected compliance frameworkNot the SOX module; IBM’s own documentation places ICFR and SOX-oriented control work in a separate Financial Controls Management module instead, see the SOX section
Operational Risk ManagementLoss events, risk and control self-assessment, key risk indicatorsOne of the modules Internal Audit Management is built to share data with
Policy ManagementPolicy authoring, attestation, lifecycle trackingShares data with Internal Audit Management per IBM’s documentation
IT GovernanceIT risk and controlsShares data with Internal Audit Management per IBM’s documentation
Model Risk GovernanceModel inventory, validation, ongoing monitoringRelevant where the audit plan includes model-risk coverage, common at banks
Third-Party Risk ManagementVendor risk assessment and monitoringFeeds third-party audit engagements
Business Continuity ManagementContinuity and resilience planningOverlaps with operational-resilience audit work
Data Privacy ManagementPrivacy program and data-subject-request workflowsRarely an audit-buying driver on its own

The consequence for a buyer is the one every suite review in this guide reaches: Internal Audit Management is hard to evaluate in isolation, because its value case depends on whether the other eight modules are already live, planned, or simply irrelevant to your organization. Where several of the nine are being bought together, or risk and compliance already run on OpenPages, audit gets real shared data for a marginal cost. Where audit is the only interested buyer, the nine-module architecture is mostly overhead. The GRC suite versus standalone audit management software comparison sets out that trade-off in full, and the audit software demo script has 25 scenarios worth running against OpenPages specifically, since — as with every product in this program — this review is built from documentation and reviews, not a live demo.

Walkthrough by audit stage

Everything below comes from IBM’s own Internal Audit Management module overview and product pages, not from using the product; where IBM’s documentation stops short of workflow detail, we say so rather than filling the gap.

Planning and risk assessment

IBM’s ‘Annual Planning’ function supports audit-universe risk assessment and multi-year plan creation using both top-down and bottom-up methods, with calculations and metrics IBM describes as configurable to any audit methodology. That is a reasonable, if generic, description: it does not name a specific risk-scoring model or say how OpenPages weights inherent risk against control strength, the kind of detail the site’s annual internal audit risk assessment playbook sets out as the method a planning tool should actually serve.

Engagement and fieldwork

‘Engagement Planning’ covers scope definition, objective-setting, resource allocation and work-program creation, and documents the risk assessment, procedures and schedule for each audit. A separate Time and Expense function tracks auditor hours and costs against the plan to flag efficiency deviations — a feature named plainly enough to be useful, though IBM’s documentation does not say how far actual hours have to drift from budget before it flags anything.

Workpapers and review

‘Workpaper Management’ keeps a centralized electronic workpaper library with collaborative authoring and automated review and approval routing, which IBM frames as lowering review cost and improving consistency across engagements. IBM’s documentation does not itemize version history, retention periods or audit-trail detail beyond that framing, so ask to see version control and sign-off in a live demo rather than assuming parity with audit-native competitors that publish more workpaper detail.

Issues and follow-up

‘Audit Reporting and Wrap-Up’ gives audit-at-a-glance reporting on issues and findings and automates issue closure and escalation. IBM’s documentation does not describe validation steps, aging thresholds or management self-reporting features distinctly from that summary, so treat escalation rules and issue aging as unconfirmed until a demo actually shows them.

Reporting

Reporting and analytics run through IBM Cognos Analytics, bundled into every pricing tier rather than sold as an add-on — a real capability, since Cognos is a full business-intelligence product, not a lightweight dashboard bolted on for GRC. The trade-off shows up in the review signal below: several G2 reviewers who praise OpenPages’ reporting power also say Cognos-based reports need more technical skill to build than a purpose-made audit dashboard would.

SOX and controls

OpenPages has no SOX-specific module inside Internal Audit Management itself. IBM’s own module overview names a separate Financial Controls Management module as the integration point for ICFR and SOX work, but none of the pages we read detail certification-of-controls workflows, key-control testing cycles, or Section 302 or 404 sign-off steps inside the audit module — we can confirm the module exists and that Internal Audit Management is designed to share data with it, and nothing more specific than that. A buyer whose purchase is driven by SOX needs to confirm, in writing, whether Financial Controls Management is licensed and priced separately from Internal Audit Management, the same question Archer buyers have to ask about its own Regulatory & Corporate Compliance Management module. The site’s SOX 404 guide and its control deficiency evaluation method are the reference points for what a financial-controls program needs from whatever system runs it.

Analytics, integrations and automation

OpenPages’ integration story runs through a REST API IBM has documented in two places — a general developer API catalog entry and a dedicated IBM Cloud entry for ‘OpenPages as a Service’ — though the endpoint-level detail sits behind pages we could not fully render, so object-level coverage is not verified beyond the API’s existence. Version 9.1, shipped 3 April 2025, added data export to SFTP, IBM Cloud Object Storage and AWS S3 for third-party integration, and reporting throughout runs on the bundled Cognos Analytics layer described above.

The more significant addition is the OpenPages MCP Server, IBM’s implementation of the Model Context Protocol for exposing OpenPages objects and actions to external AI agents. It shipped experimental and local-only in version 9.1.3 (26 December 2025), became a fully managed, cloud-native service for SaaS customers on AWS and IBM Cloud in version 9.2 (23 March 2026 for SaaS), and was broadened again to more SaaS customers in version 9.2.1 (23 July 2026). Alongside it, Bring-Your-Own-Model support lets customers connect third-party or watsonx.ai models via API rather than being limited to one IBM model; 9.1.3 added support for multi-valued enumeration fields and advanced JSON inputs, and 9.2 added pre-runtime validation of those configurations. Neither the MCP Server nor Bring-Your-Own-Model amounts to a scripting or full-population analytics layer of the kind dedicated audit-analytics tools provide; a team that wants that needs to plan for a second tool, which the site’s audit analytics software comparison covers.

AI: what is real

No product in this guide has shipped more dated, named AI features in the past two years than OpenPages, and unusually for this category nearly every one of them carries a specific version number and release date rather than a marketing name with no shipping evidence behind it. That density cuts against IBM in one place: the pages we read state no policy on whether OpenPages or watsonx train on customer data, retain inputs, or let a customer opt out, for any of the features below.

FeatureVersion and dateWhat it does
watsonx.ai and Bring-Your-Own-ModelOngoing, API-basedLets customers route AI features to a third-party model or watsonx.ai instead of one built-in model
OpenPages MCP ServerExperimental and local in 9.1.3 (26 Dec 2025); managed cloud-native for SaaS in 9.2 (23 Mar 2026); broadened again in 9.2.1 (23 Jul 2026)Exposes OpenPages objects and actions to external AI agents
watsonx Orchestrate chat9.2 (23 Mar 2026)Native, embedded conversational interface inside the platform
AI-assisted evidence and file analysisExpanded in 9.2; multi-file and compatible with Gemini and OpenAI models in 9.2.1 (23 Jul 2026)Reviews uploaded evidence and files inside audit workflows
Eight out-of-the-box AI model configurations9.2.1 (23 Jul 2026)Named use cases include audit-plan creation, Basel classification, vendor analysis, document summarization, PII detection and questionnaire-response generation
AI-drafted questionnaire responses9.2.1 (23 Jul 2026)Drafts preliminary responses; IBM states human review is mandatory before use

The eight out-of-the-box models are the feature most relevant to an audit buyer specifically, because two of the named use cases — audit-plan creation and questionnaire-response generation — are audit tasks rather than generic GRC ones, and the mandatory human-review requirement IBM states for drafted questionnaire responses is the kind of checkable-output design this site’s guide to evaluating AI in audit software asks every vendor to show. What IBM has not published is any statement on data use: whether prompts or uploaded evidence train watsonx or third-party models routed through Bring-Your-Own-Model, how long inputs are retained, or whether a customer can opt out. Gartner’s own caution from 13 April 2026 — to be “particularly wary of agent-washing” — applies to OpenPages’ roadmap as much as to any vendor’s, and IBM’s own reviewers already flag one part of it: several G2 reviewers credit ‘Watson AI-driven automation’ as a real time-saver, while Gartner Peer Insights reviewers separately cite gaps in dynamic reporting and collaboration features that the AI push has not yet closed.

The scorecard

The scorecard uses the 12 areas described on the method page; each level reflects documentation and reviews, not hands-on use, and several rows below flag a specific gap in what IBM has published rather than assuming the feature is absent.

AreaLevelEvidence
Risk assessment and planningStrongAnnual Planning supports audit-universe risk assessment and multi-year plan creation via top-down and bottom-up methods, with configurable calculations
Engagement workflowStrongEngagement Planning covers scope, objectives, resource allocation and work-program creation, plus dedicated Time and Expense tracking against the plan
Workpapers and evidenceAdequateA centralized workpaper library with collaborative authoring and automated review and approval routing is documented; version history and retention detail is not
Issues and follow-upAdequateAudit Reporting and Wrap-Up automates issue closure and escalation and gives at-a-glance issue reporting; validation steps and aging thresholds are not described
ReportingAdequateIBM Cognos Analytics is bundled into every tier, a genuine business-intelligence product rather than a bolt-on dashboard, but reviewers say Cognos-based reports need technical skill and no audit-committee-specific template was found
SOX and controls testingLimitedFinancial Controls Management exists as the stated integration point for ICFR and SOX, but certification, key-control testing and 302/404 sign-off detail inside the audit module itself could not be verified
Analytics and automationAdequateA REST API, SFTP and cloud-storage export, an MCP Server and Bring-Your-Own-Model connections are real, but nothing amounts to a scripting or full-population testing layer
AI featuresStrongThe most densely dated AI roadmap in this guide, with eight named model configurations and a managed MCP Server shipped on stated dates, though no data-use or training statement was found for any of it
Quality program supportLimitedNo QAIP-metrics or methodology-enforcement feature is named in the documentation we could read
Auditee experienceLimitedNo auditee-facing request portal, action-plan-update feature or notification workflow specific to audit was named in the pages reviewed
Administration, integrations and securityAdequateOAuth 2.0, a documented REST API and IBM Cloud’s SOC 1, 2 and 3, ISO 27001-family, FedRAMP, HIPAA, PCI DSS and HITRUST programs all apply at the IBM Cloud level; none is confirmed as an OpenPages-specific attestation
Cost and contractAdequateOne of the few vendors in this guide publishing real starting prices, but with no billing period stated and an AWS Marketplace structure that adds storage and concurrent-user overage charges on top
Vendor viabilityStrongWholly owned by IBM since 2010 with no acquisition or spin-off risk and a dense, dated 2024-2026 release cadence, though Internal Audit Management is one of nine modules competing for IBM’s product investment

Fit by situation

The eight situations are the same on every review in this guide, so ratings can be compared across products. OpenPages’ own ratings run to the extremes: Strong fit at the largest and most regulated end, Poor fit at the smallest and in the public sector.

SituationRatingReason
First system for a small team (1 to 5 auditors)Poor fitNo per-seat entry price scaled for a handful of users, no self-service onboarding path found, and a platform built around shared enterprise data a small team has no reason to build first
Mid-size function (6 to 25 auditors)Poor fitThe same dependency at a slightly larger scale: OpenPages’ advantage depends on risk, compliance or IT already running the platform, which most functions this size have not built
Large or global function (25+ auditors)Strong fitNine-module architecture, Cognos-based enterprise reporting, and named deployments at Citi (about 2,500 auditors) and Zurich Insurance Group’s global risk function
SOX-heavy public companyWorkableFinancial Controls Management is real as an integration point, but it is a separate module to license, and 302/404 workflow depth inside the audit module itself is unverified
Bank or credit unionStrong fitThe deepest regulated-industry evidence found for this product — Citi, Zurich Insurance Group, and a Model Risk Governance module built for this sector — plus IBM Cloud’s general SOC and ISO certifications banks expect
Public sector, higher education or nonprofitPoor fitNo OpenPages-specific FedRAMP or GovRAMP authorization was found, no named public-sector or education customer, and no US procurement record for OpenPages turned up in the sources we checked
Analytics-heavy teamWorkableA REST API, an MCP Server and Bring-Your-Own-Model connections give real automation and AI-agent connectivity, but no scripted, full-population testing layer of its own
Consolidating GRC across the three linesStrong fitThis is the buyer OpenPages is built for: nine modules on one data model spanning audit, operational, model, IT, third-party, privacy, policy, continuity and compliance risk

Banks running OpenPages for model risk as well as audit should also see the site’s model risk audit guide, since Model Risk Governance is one of the modules Internal Audit Management is built to share data with.

Pricing and contract

IBM is unusually transparent for this category. Its own pricing page states ‘starting at’ figures directly, something neither Archer nor MetricStream does anywhere on their own sites. The transparency has a real limit, though: IBM does not say whether those figures are billed monthly or annually, and the actual contracts we could find price quite differently from the headline numbers.

Source and dateFigureWhat it coveredHow to read it
IBM’s pricing page (checked 27 Sep 2026)‘Starts at’ $3,300 (AWS Essentials), $6,050 (AWS Standard), $6,250 (IBM Cloud Single Solution), $9,000 (IBM Cloud Enterprise); on-premises is customThe vendor’s own headline figuresNo billing period stated; the page itself says prices are indicative, may vary by country, and exclude taxes and duties, and that watsonx.ai, Assistant and Discovery AI capabilities cost extra
AWS Marketplace, OpenPages SaaS listing (accessed 27 Sep 2026)12-month contracts; base plans around $7,740 to $8,400 a year (essentials, with a high-availability option); add-ons $21,480 to $51,840; per-solution applications $26,520 to $37,080 a year; storage $588 per 200GB (overage $49 per GB); user overage $53 per concurrent userA real, dated contract structureNon-refundable; multi-year deals still require annual commitments, and the total climbs fast once add-ons and overages are included
AWS Marketplace, OpenPages for Cloud Pak for Data listing (accessed 27 Sep 2026)$239,280 for one unit on a 12-month contract, covering deployment across two AWS VPCsA fixed commitment, not usage-meteredA different deployment model from the SaaS listing above; do not average the two
UK G-Cloud 14, Computacenter reseller listing (dated 3 May 2024)£2,600 per instance per month, no education discount, no free trialA procurement-adjacent public recordComputacenter’s own ISO 27001 and PCI DSS accreditation dates appear on the same listing; read those as the reseller’s certifications, not confirmed OpenPages-specific ones
Forrester Total Economic Impact study, commissioned by IBM (July 2023)249% return on investment over three years; risk-adjusted benefits of $1.9 million in reduced risk-management effort, $691,000 in penalty avoidance and $423,000 in avoided legacy-tool costs, totaling $3.05 millionA vendor-commissioned value model, not a priceBuilt from four customer interviews at a composite, roughly 35,000-employee, $19 billion-revenue financial-services organization; useful for a business case, not for budgeting

IBM has not stated a pricing model beyond what the AWS Marketplace structure implies: tiered by edition and solution, with per-solution add-ons plus storage and concurrent-user overage charges, rather than a flat, unlimited-user price the way some rivals price their standard users. Treat every cost driver as a question for the RFP: whether Financial Controls Management is priced separately if SOX is in scope, what the watsonx.ai and Assistant AI capabilities the pricing page flags as extra actually cost, and what a multi-year commitment looks like given the AWS listing’s non-refundable terms. The site’s vendor-neutral RFP method has the pricing schedule to send, and the internal audit software pricing guide puts these figures next to every other vendor’s in this program.

Be skeptical of secondary pricing sources for this product specifically. A widely syndicated blog post, citing a market-research aggregator, claims per-user annual costs from about $3,000 to $5,000 and cites granular, euro-denominated module figures attributed to a German IBM reseller’s page; checked directly, that reseller’s page contains no pricing figures at all and states that IBM pricing is quoted per customer on request, so treat the euro figures as unreliable rather than repeating them. No Vendr.com listing and no US public-sector procurement record for OpenPages turned up in the sources we checked, which is itself worth noting: this is one of the thinner-evidenced products in this guide on the buyer-reported side, even though it is one of the better-evidenced on the vendor-published side.

One date is worth flagging on its own, separate from price: standard support for OpenPages 9.0.x ends on 30 September 2026, days after this review’s last-verified date, with extended support continuing to 30 September 2030. Any buyer still running 9.0.x should already have an upgrade plan in writing, not as a renewal-cycle surprise.

What users say

IBM OpenPages carries two separate listings inside Gartner Peer Insights’ Audit Management Solutions market, and confusing them is an easy mistake. The narrower one, ‘OpenPages Internal Audit Management,’ rates 4.1 from 9 reviews, with praise centered on comprehensive GRC management and scalability, integration and analytics, and a complaint theme citing gaps in blockchain integration, dynamic reporting and collaboration features; most of the review detail sits behind a Gartner login. The broader listing, simply ‘IBM OpenPages,’ rates the same 4.1 from 36 reviews and praises native Watson AI integration, modular architecture and usefulness as a collaborative tool spanning internal audit and external-regulation work, while its complaints cite an interface needing more intuitiveness, unclear field meanings and task routing, heavy customization needs and cost concerns. A separate IBM vendor-aggregate compare page in the same market showed ‘4.1’ with ‘0 Reviews’ when we checked — almost certainly a data-hydration artifact rather than a real third figure, so we have not used it.

G2’s single OpenPages listing rates 4.2 from 76 reviews spanning October 2022 to September 2026, with a segment mix around 25% small business, 60% mid-market and 15% enterprise. Reviewers most often praise risk-management effectiveness, time-saving automation, Watson-driven automation specifically, an interface they call intuitive once learned, and security and compliance strength; they most often complain about a steep learning curve, high cost, customization that needs admin support, and Cognos-based reporting that needs more technical skill than a purpose-built audit dashboard. No Capterra or TrustRadius rating for IBM OpenPages turned up in the searches we ran — not verified, rather than assumed absent.

ThemePraise or complaintWhere seen
Native Watson and AI-driven automationPraiseG2; Gartner Peer Insights, both listings
Comprehensive GRC management and scalabilityPraiseGartner Peer Insights, Internal Audit Management listing
Modular architecturePraiseGartner Peer Insights, IBM OpenPages listing
Risk-management effectiveness and time savingsPraiseG2
Security and compliance strengthPraiseG2
Interface intuitive once learnedPraise, with a catchG2 says intuitive ‘once learned’; Gartner Peer Insights says the interface needs more intuitiveness
Learning curveComplaintG2
CostComplaintG2; Gartner Peer Insights, IBM OpenPages listing
Customization and task-routing clarityComplaintG2 says it needs admin support; Gartner Peer Insights cites unclear field meanings and task routing
Cognos-based reporting complexityComplaintG2
Gaps in dynamic reporting and collaboration featuresComplaintGartner Peer Insights, Internal Audit Management listing

The pattern across every site we checked is consistent: AI and modularity draw the praise, and an interface that takes work to learn and a cost that invites comparison against lighter tools draw the complaints — the same shape this guide’s brief set out to test, and the reviews confirm it without much contradiction.

Implementation and migration

IBM runs formal training rather than publishing an implementation timeline. Three certification tracks exist: ‘IBM Certified Associate Developer — OpenPages Fundamentals,’ ‘IBM Certified Developer — OpenPages,’ and a self-guided ‘OpenPages with Watson Implementation Essentials’ course, confirming real admin and developer training paths exist, even though we could not retrieve their duration or curriculum in full. No vendor-stated implementation timeline, in weeks or months, was found on any page we read, which is a real gap next to competitors who publish at least a rough range.

The one detailed account of an actual rollout is IBM’s own Zurich Insurance Group story from 27 August 2026, which describes a ‘configuration-first’ approach — using UI configuration, workflows and calculations rather than custom code — going live with core capabilities first and extending afterward. IBM attaches no duration to that account, so treat it as a stated philosophy, not a schedule. Given the platform’s nine-module breadth and the customization concerns in its own reviews, budget for a scoped, partner-or-IBM-led implementation rather than a self-service rollout, and put a written timeline and a named admin-training plan into the RFP rather than accepting a verbal estimate in a demo. The site’s audit software due diligence guide has the security, data-residency and AI data-use questions worth adding to that same document, several of which — FedRAMP status specific to OpenPages among them — IBM’s own pages leave unanswered.

How it compares

G2’s own ‘Alternatives’ list for the IBM OpenPages page is topped, by G2’s ratings rather than IBM’s, by ServiceNow GRC (4.2, 118 reviews), Archer (3.6, 20), Optro, formerly AuditBoard (4.6, 1,624), Diligent One Platform (4.3, 154), LogicGate (4.6, 191) and Workiva (4.5, 2,156). Against OpenPages’ own G2 rating of 4.2, four of those six actually rate higher — Optro, Diligent One Platform, LogicGate and Workiva — while ServiceNow GRC ties OpenPages at 4.2 and Archer, at 3.6, rates lower; reviewers on the higher-rated listings most often credit them as easier to administer, buy from or set up than IBM’s product. That is still a real signal worth sitting with before assuming OpenPages is the default regulated-industry choice.

Archer is the closest structural peer and the subject of a dedicated comparison on this site. Cinven has owned Archer since 2023, it claims more than 1,300 customers including 37 of the top 50 global banks, and its audit-specific Gartner Peer Insights rating, 4.3 from 36 reviews, is higher than either of OpenPages’ two listings. The clearest difference is price transparency, and it favors IBM: Archer publishes no figures at all, not even a placeholder that resolves to a real number, where IBM’s pricing page states actual starting figures. IBM OpenPages vs Archer and the Archer review go through the rest of the decision.

MetricStream is the other enterprise GRC suite this guide reviews at similar depth: privately held, with Blue Torch Capital financing since September 2024 and a May 2025 ‘AI-first’ rebrand under new chief executive Marc Levine. Its audit-specific Gartner Peer Insights rating is thinner than either of OpenPages’ listings, 3.6 from just 6 reviews, and like Archer it publishes no price at all. Where OpenPages leans on watsonx and an MCP Server for its AI story, MetricStream leans on a product it calls AiSPIRE and a similarly dense 2026 release cadence; the MetricStream review covers it directly.

ServiceNow IRM is the platform-you-already-own case. Audit Management is not sold as a standalone product: a licensing advisory that tracks ServiceNow’s GRC pricing describes it as bundled inside the broader IRM offering, with auditors needing full ‘fulfiller’ licenses while control owners who only answer surveys get a cheaper ‘stakeholder’ license, and workpapers routed through Office 365 rather than a native editor. Its GRC rating sits at 4.2 from 163 reviews, but in a different Gartner market than the audit-specific one OpenPages is rated in, so the two numbers are not directly comparable. Where IT already runs ServiceNow, that existing relationship usually decides the question before audit gets a vote; see the ServiceNow IRM review.

SAI360 sits a rung down in scale. STG-owned since 2023 with BWise heritage, its GRC Elevate 6.0 release from May 2026 added Essentials and Professional editions aimed at the mid-market rather than the largest banks, and SAI360 does not even appear as a listed vendor on Gartner’s dedicated Audit Management Solutions market page at all. On G2, its Audit Management category rates ‘High Performer’ rather than the ‘Leader’ badge SAI360 earns in ERM, GRC and policy management — a suite that is stronger elsewhere than in the module this guide is reviewing. The SAI360 review has the fuller picture. For a buyer who does not need GRC breadth at all, Optro (formerly AuditBoard) remains the most-reviewed audit-first alternative in this guide, with a published Vendr median of $45,947 a year where none of the four suites above discloses one; the best internal audit software roundup has the fuller shortlist.

Questions about IBM OpenPages

Was IBM OpenPages always an IBM product?

No. OpenPages began as a company founded in Amherst, Massachusetts in 1990, originally called American Computer Innovators and renamed OpenPages in 2000; it operated independently, backed by Matrix Partners, until IBM completed its acquisition on 21 October 2010. It has had one owner since, with no further sale, spin-off or outside financing event found between 2024 and 2026.

How much does IBM OpenPages cost?

IBM publishes ‘starting at’ figures of $3,300 and $6,050 on AWS, and $6,250 and $9,000 on IBM Cloud, with no billing period stated. Real AWS Marketplace contracts run higher once add-ons, storage and concurrent-user overage are included, with base SaaS plans around $7,740 to $8,400 a year before them. On-premises and Cloud Pak for Data deployments are quoted individually; the pricing and contract section above has the full evidence table.

Is IBM OpenPages right for a small audit team?

Generally not as a first system. OpenPages’ value depends on shared risk and control data across other modules that a team of one to five auditors is unlikely to have built, IBM has no published self-service or per-seat entry price scaled to a small team, and the fit ratings in this review mark both small and mid-size functions as Poor fit for that reason. The site’s audit software for small teams guide has better-suited, lower-cost options.

Does OpenPages’ AI train on our data?

IBM has not published a statement either way for OpenPages specifically. Its Bring-Your-Own-Model design lets a customer route AI features to watsonx.ai or to a third-party model of their choice, which is a customer-choice framing rather than a data-use policy, and none of the release notes for versions 9.1 through 9.2.1 state a training, retention or opt-out position. Ask the question directly and get the answer in writing before enabling any AI feature on real workpapers.

Is IBM OpenPages FedRAMP authorized?

Not specifically, as far as we could verify. IBM Cloud’s general compliance page lists FedRAMP among its programs, alongside SOC 1, 2 and 3, the ISO 27001 family, HIPAA, PCI DSS and HITRUST, but none of the pages we read names an OpenPages-specific FedRAMP or GovRAMP authorization, sub-processor list or data-residency commitment. Public-sector buyers should ask IBM directly for an authorization letter or a sponsoring agency rather than assuming the general IBM Cloud programs extend automatically to this product.

What is the OpenPages MCP Server, and does our audit team need it?

It is IBM’s implementation of the Model Context Protocol, a way of exposing OpenPages objects and actions to external AI agents rather than only to IBM’s own interface. It shipped experimental and local-only in version 9.1.3 (26 December 2025), became a managed cloud-native service for SaaS customers in version 9.2 (March 2026), and was broadened again in version 9.2.1 (July 2026). Most audit teams do not need to touch it directly; it matters mainly to whoever administers the platform and is deciding whether to let other AI tools connect to OpenPages data, a decision worth routing through the same due-diligence questions as any other AI feature on this page.

internalauditguide.com has no commercial relationship with IBM or any other vendor named on this page. We take no vendor money, run no affiliate links and accept no sponsored placements, and no vendor saw this page before publication. Product and company names are the trademarks of their owners. Corrections: desk@internalauditguide.com.

Sources and verification

New guides & tools by email

Useful so far?

There are 400+ more guides where this came from. Get new guides, templates and free audit tools by email when they ship. No schedule, no filler.

Free. One confirmation email from WordPress.com, then you’re in. Unsubscribe anytime.

New guides & tools by email

Don’t lose this library.

400+ practitioner-written guides and free tools. Hear when new ones land.

One confirmation email from WordPress.com, then you’re in. Unsubscribe anytime.

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading