Protecht ERM is an enterprise GRC suite built in Sydney, Australia, that added an audit management module to a stack already covering vendor risk, operational resilience, compliance, cyber risk, controls, workplace health and safety, ESG and treasury. Its positioning leans hard into financial services and government: banks, credit unions, insurers, fintechs, asset managers, superannuation funds and government agencies are the sectors it names. A private-equity growth investment in 2025 and an acquisition in 2026 both went into risk and vendor-risk products, not the audit module, which is the one thing a buyer evaluating Protecht for internal audit should keep in view. The module description reads well — a risk-based audit universe tied to the same risk taxonomy the second line already uses — but the public evidence for it is thinner than for the platform around it, and most of the named customers proving the sector story are Australian rather than global.
This review covers what Protecht is and who owns it, the modules and how audit fits inside them, a walkthrough by stage, SOX and controls, the Cognita AI assistant and the VISO TRUST acquisition, our 12-area scorecard, fit by situation, public pricing, verified reviews, and how Protecht compares with the audit-native and mid-market platforms in this guide. It is part of the site’s independent buyer’s guide to internal audit software and follows the evidence rules in how we review audit software. Readers choosing between a risk-first suite and a purpose-built audit platform should also see types of internal audit software.
Verdict. Protecht ERM is a credible audit-management choice for a bank, credit union, insurer or other regulated financial institution that wants audit inside the same risk taxonomy the second line already uses, and for any organization consolidating risk, compliance and audit on one platform. It is not built for a SOX-centric public company or an analytics-heavy audit function, and a buyer outside Australia and New Zealand should ask directly for reference customers in their own market before assuming the banking depth on Protecht’s website travels.
Best for. Mid-size audit functions inside banks, credit unions, insurers and other regulated financial institutions; organizations consolidating risk, compliance and audit on one platform; teams that want audit tied to an existing enterprise risk taxonomy.
Not for. SOX-centric public companies, whose controls testing needs a COSO-aligned library Protecht does not publish; analytics-heavy teams that need full-population data testing; large global functions that have not confirmed methodology enforcement and admin effort for themselves.
Evidence. Research-based: vendor documentation and release notes, public procurement records, third-party pricing data, verified user reviews on Gartner Peer Insights and G2, and analyst coverage. We have not used the product hands-on for this review.
Price evidence. No public price. Protecht’s module pages end in a demo request rather than a quote, and Vendr’s Protecht marketplace page, viewed 27 September 2026, carries no median, range or purchase count.
Last verified. 27 September 2026.
In this guide
- What Protecht is, and who owns it
- What you get: modules and how audit fits
- Walkthrough by audit stage
- SOX and controls
- Analytics, integrations and automation
- AI: what is real
- The scorecard
- Fit by situation
- Pricing and contract
- What users say
- Implementation and migration
- How it compares
- Questions about Protecht ERM
- Sources and verification
- Related guides
What Protecht is, and who owns it
Protecht Group is headquartered in Sydney, Australia. PSG Equity’s own portfolio page adds offices in Los Angeles and London; no Protecht-published page independently confirms those two addresses, so treat Sydney as the confirmed headquarters and LA and London as PSG’s characterization rather than Protecht’s own. The company was co-founded by David Tattam and David Bergmark, who met at Price Waterhouse in the late 1980s. Protecht’s own account traces the name, a blend of “protection” and “technology,” to a taxi conversation between Tattam and his wife, and the founders describe building risk-management systems for “over 20 years.” Neither holds a day-to-day executive role today: Bergmark, a former Price Waterhouse auditor and IBJ Australia Bank risk executive, is now Director and Strategic Advisor, and Tattam, a former chief risk officer at two global banks and the author of A Short Guide to Operational Risk, is Protecht’s GRC Thought Leader.
PSG Equity made a US$280 million growth investment in Protecht in 2025, per PSG’s own portfolio page, which gives only the year, with no day or month, and does not say whether the deal was majority or minority. Three PSG staff now sit on Protecht’s board — Adam Marcus, Evan Ocko and Thomas Soule — alongside independent chair John Wilson and director Andrew Birch, a former CEO of Micromine. CEO Jason Phillips, a Harvard MBA with prior CFO and COO roles including at Equifax and American Express, has held the title through both the VISO TRUST and Cognita announcements below. The pattern here is a private-equity growth story rather than the buyout-and-rebrand pattern that produced Optro (formerly AuditBoard) or TeamMate Risk & Compliance elsewhere in this guide; Protecht has kept its name and its founders’ story through the raise.
Two entries in the timeline below carry more weight than the rest: the VISO TRUST acquisition, because it adds a genuinely new capability rather than a badge, and the run of G2 quarterly results, because they show Protecht’s Audit Management standing moving in both directions rather than only up.
| Date | Event | Why it matters to an audit buyer |
|---|---|---|
| 2024 | Named a Leader in Quadrant Knowledge Solutions’ SPARK Matrix for GRC platforms, per Protecht’s own reviews page | A vendor-selected analyst placement, not a Gartner or Forrester Leader seat |
| 2025 (no day or month published) | PSG Equity’s US$280 million growth investment | Real capital behind the roadmap; deal structure undisclosed |
| 8 September 2025 | Cognita AI assistant announced; full release inside Protecht ERM targeted for November 2025 | The AI feature to test in any 2026 demo |
| 22 September 2025 | G2 Fall 2025 report: Leader in 15 categories, including Protecht’s first Audit Management badge, “Best Support” | First public audit-market recognition on G2 |
| 12 December 2025 | G2 Winter 2026 report: Audit Management Leader (Mid-Market), “newly earned,” among 92 reports | Peak of Protecht’s audit-market standing on G2 |
| 20 March 2026 | G2 Spring 2026 report: four Leader badges elsewhere; no Audit Management badge named | The audit badge did not carry over |
| 21 April 2026 | Protecht acquires VISO TRUST, an AI-powered vendor and third-party-risk platform | Adds a distinct, separately branded product rather than a merged feature |
| 4 June 2026 | G2 Summer 2026 report: “High Performer” in Audit Management, down from Leader | The badge kept sliding |
| 1 September 2026 | Stuart Kelly named global CRO, Erin Marks named global CMO | Two of the executive team’s public-facing seats changed hands the same week |
No release in Protecht’s news index claims a Gartner Magic Quadrant or Forrester Wave “Leader,” an IDC MarketScape placement, or a Chartis RiskTech100 leader spot, unlike Optro, LogicGate, Archer and IBM elsewhere in this guide; the site’s guide to reading audit software analyst reports explains why a SPARK Matrix mention is not the same claim.
What you get: modules and how audit fits
Protecht sells one platform as a set of separately marketed modules rather than tiered editions: Enterprise Risk Management, Vendor and Third-Party Risk, Operational Resilience and Business Continuity, Compliance Management, Cyber and IT Risk, Audit Management, Workplace Health and Safety, Controls Management, ESG, CPS 230 compliance, and Asset and Liability or Treasury Management. Cognita AI and an Analytics and Dashboards capability run across all of them. The Audit Management page also cites ISO 19011, the international guideline for auditing management systems, as a framework the module aligns with. That breadth is the whole pitch, and the reason internal audit’s role in enterprise risk management is worth reading alongside this review: audit sits inside the same risk taxonomy, control library and reporting layer as the second line, instead of importing its own.
| Module | What it covers | Relevance to an audit buyer |
|---|---|---|
| Audit Management | Risk-based audit universe and plans, workpapers, findings through to action management, control testing capture, committee reporting | The product this review is about |
| Enterprise Risk Management | Central risk register, bow-tie modeling, risk appetite and reporting | Supplies the risk universe the audit module scopes against |
| Controls Management | Control library aligned to ISO 27001, NIST CSF, SOC 2 and CPS 234; testing templates, owner/operator/tester independence | Adjacent to Audit Management, not merged into it; see SOX and controls below |
| Vendor and Third-Party Risk | Onboarding, assessment and monitoring of vendors | Sits alongside the newly acquired VISO TRUST rather than absorbing it |
| Operational Resilience and BCM | Continuity plans; the CPS 230 resilience workflow | Feeds resilience audits |
| Compliance Management | Obligations register and monitoring | Feeds compliance-audit engagements |
| Cyber and IT Risk | Cyber risk register and controls | IT audit scoping input |
| Workplace Health and Safety; ESG | Incident and hazard management; ESG metrics | Specialist programs audit reads rather than owns |
| Asset and Liability or Treasury Management | Treasury risk workflow | Relevant mainly to financial institutions using it for treasury |
| Cognita AI; Analytics and Dashboards | Cross-cutting AI assistant and reporting layer | Available to whichever modules a customer licenses |
Protecht has not published editions or seat tiers; instead it frames scale by user count, saying it serves “clients with as few as two users through to major organizations with over 20,000 users,” which implies a configuration- and user-count-driven quote rather than a published price list. No Protecht-authored comparison page sets audit against a named rival, unlike Optro’s or LogicGate’s own comparison pages; every comparison figure in this review comes from G2 instead. That module lineup is also why this review rates Protecht a strong fit for organizations consolidating risk, compliance and audit on one platform, the scenario the site’s GRC suite versus standalone audit software guide works through; a function that only wants audit should weigh whether the other nine modules’ breadth is worth paying an administrator to configure.
Walkthrough by audit stage
What follows is drawn from Protecht’s module and capability pages; we have not operated the software, and several mechanics a hands-on reviewer would show — workpaper templates, sign-off chains, screen layouts — are not documented anywhere public we could find. Ask to see them directly in a demo, using the site’s audit software demo script as a checklist.
Planning. Protecht describes “targeted audit plans driven by trending analytic insights,” an audit profiling capability for comparison and planning, and scope “linked to company objectives and the risk universe” for end-to-end annual program management. That last point is the module’s real selling point: because Enterprise Risk Management and Audit Management share a platform, the audit universe can draw on a risk register the second line already maintains, rather than a separate spreadsheet, the general workflow the site’s guide to the annual internal audit risk assessment describes.
Engagement and fieldwork. The module page describes “dynamic audit lifecycle management with multifunctional workflow and alert management,” automatic overdue and upcoming-audit notifications, and a “MyTasks” launchpad. Those are workflow concepts, not screen-level detail; Protecht does not show a planning memo, a risk and control matrix or a test-step library the way a screenshot-based walkthrough would. The site’s risk and control matrix template and audit work program guides describe what to look for in the module’s own equivalents during a demo.
Workpapers and review. Protecht’s own language is limited to “easily generate audit workpapers and reports” and to “attach evidence, workpapers and documents to audit responses.” Nothing public describes versioning, retention rules, review sign-off chains or an audit trail, which is the single biggest documentation gap this review found relative to Optro, TeamMate or Onspring, each reviewed elsewhere in this guide with more specific workpaper language on its own site.
Issues and follow-up. The module records “observations, recommendations and findings through to action management,” captures control test results, and supports root-cause analysis through Protecht’s bow-tie methodology, the same diagramming approach used across Enterprise Risk Management. That reuse is again the platform’s real advantage: a finding’s root cause can be modeled with the same bow-tie tool the risk team already uses, rather than a separate diagram in a separate system.
Reporting. Protecht advertises “off-the-shelf push-button reporting for risk and audit committees,” dashboards linking findings to risks and controls, and trend views by severity, business unit and rolling 12-month history, with Analytics and Dashboards adding scheduled reports and PDF, Excel or PowerPoint export. The module page’s one linked proof point, an Australian Taxation Office case study sourced from Comcover Connect magazine, discusses governance modernization broadly and never names the audit module specifically — worth knowing before citing it as evidence of audit-module use at scale.
SOX and controls
SOX does not appear on either the Audit Management or Controls Management pages. The closest reference on Protecht’s site is a five-minute Knowledge Hub article, “Navigating SOX requirements,” which reads as educational content, not a documented workflow. That is a real gap for a US public company: the Controls Management library is pre-aligned to ISO/IEC 27001:2022, NIST CSF 1.1 and 2.0, SOC 2 and APRA CPS 234, with cross-framework mapping to cut duplicate testing, but no COSO or SOX framework is named among them.
Controls Management is a separate, adjacent module, with its own best-practice testing templates, automated scheduling, real-time issue monitoring, and a stated design goal of independence between control owners, operators and testers. The audit module separately captures control design and operating-effectiveness results inside an engagement, suggesting the two share underlying mechanics rather than being fully walled off, but Protecht’s pages do not spell out how test results move between them. Ask directly whether a control tested in Controls Management can be relied on inside an Audit Management engagement without re-testing, and get the answer in writing; the site’s test of design versus operating effectiveness guide has the underlying distinction to test the answer against.
The other framework Protecht discusses at length is CPS 230, APRA’s Australian operational-resilience standard effective from July 2025, with its own product page and a named case study: Bank First, an Australian mutual bank, moving away from what it called “a tick-the-box compliance exercise” toward embedded, business-owned risk profiles. That is real and specific — but it is a compliance and resilience deployment, and the case study never mentions the audit module. Treat CPS 230 depth as evidence of Protecht’s compliance capability, not its audit-management maturity, and confirm any SOX-specific claim directly rather than assuming the Controls Management framework list will substitute.
Analytics, integrations and automation
Protecht states support for custom-built RESTful APIs, SCIM provisioning and SSO through Okta, Microsoft Active Directory or a generic identity provider, though no public developer-documentation URL was found. The integration layer runs on Workato’s iPaaS, described as more than 600 prebuilt connectors, with named integrations to Microsoft Teams, Outlook, Slack, ServiceNow, Jira, Power BI, Oracle, SAP, Workday, LexisNexis and Corlytics, plus SecurityScorecard, which now overlaps with the third-party risk scoring VISO TRUST brings in-house.
Native analytics run to no-code dashboards, record tagging and filtering, scheduled reports, the bow-tie diagrams mentioned above, and a cross-framework aggregation feature Protecht brands “RiskinMotion.” A separate Marketplace page pitches templated registers, dashboards and reports rather than named third-party integrations. Read together, the integration story is fuller than the complaint theme below implies on its own; the likely gap is between what is technically available through Workato and the API, and what a mid-market administrator can stand up unassisted, which lines up with the KRI and API integration difficulty G2 reviewers cite. None of this amounts to full-population data testing; a function running continuous monitoring or scripted tests at the data layer should keep a dedicated analytics tool alongside Protecht, the trade-off the site’s types of internal audit software guide sets out for the category generally.
AI: what is real
Cognita by Protecht, described as “purpose-built risk AI,” was announced on 8 September 2025, with demos through September and October and a full release inside Protecht ERM targeted for November 2025. No underlying model or provider is named anywhere we found, unlike Optro, Resolver or Onspring elsewhere in this guide, each of which names its AI provider publicly.
The data-use statement is genuinely specific, which is unusual enough to be worth stating plainly: each customer operates in a private, single-tenant AWS environment, no data is shared between customers, and customer data is never used to train third-party AI models. Protecht says sensitive identifiers such as card numbers and government IDs are automatically redacted, that AI output is clearly identified and can be reviewed and edited by users, that Cognita never bypasses existing permissions and does not make decisions or take action on a customer’s behalf, and that interactions are logged. CEO Jason Phillips framed the goal at launch: AI in GRC, he said, should never be a black box. That is a stronger data-governance statement than several larger vendors in this guide publish, and the one AI claim on this page we would call concrete rather than marketing.
Named Cognita features sit in Incident Management (natural-language capture, AI-supported review, duplicate detection), Compliance (in-context navigation, step-by-step guidance) and Reporting (automated executive summaries, trend identification); no audit-specific Cognita feature is named anywhere we found. Whatever AI capability appears in an audit demo in 2026 should be asked about by name, with the data-use questions above answered specifically for audit data, not assumed from the general Cognita statement. Gartner’s April 2026 warning to be “particularly wary of agent-washing” is the right test, and the site’s guide to evaluating AI in audit software has the fuller protocol.
The VISO TRUST acquisition adds what Protecht calls “agentic AI capabilities” for vendor-risk assessment, sold alongside rather than merged into Cognita; VISO TRUST keeps its own name and pricing motion as a separately branded product. For an audit function that relies on third-party risk assessments, covered in general terms in the site’s third-party risk management program guide, that is worth asking about directly, and the site’s audit software due diligence guide has the AI data-use questions to put to both products.
The scorecard
The scorecard uses the 12 areas described on the method page; each level reflects documentation and reviews, not hands-on use. Protecht’s strongest trait is the reuse of one risk taxonomy across audit, risk and controls; its weakest areas are the ones a SOX-centric public company or an analytics-heavy function would need most.
| Area | Level | Evidence |
|---|---|---|
| Risk assessment and planning | Adequate | “Targeted audit plans driven by trending analytic insights,” scope linked to the risk universe; concepts named, no screen-level workflow detail found |
| Engagement workflow | Adequate | “Dynamic audit lifecycle management,” overdue and upcoming notifications, a MyTasks launchpad; no planning-memo or sign-off specifics |
| Workpapers and evidence | Limited | Page language is limited to generating workpapers and attaching evidence; no versioning, retention or audit-trail detail found |
| Issues and follow-up | Adequate | Observations, recommendations and findings through to action management, plus control test-result capture and bow-tie root-cause analysis |
| Reporting | Adequate | Push-button committee reporting, dashboards linking findings to risk and controls; scheduled PDF, Excel and PowerPoint export |
| SOX and controls testing | Limited | SOX not named on the Audit or Controls pages; Controls Management covers ISO 27001, NIST CSF, SOC 2 and CPS 234, no COSO or SOX framework |
| Analytics and automation | Adequate | No-code dashboards, tagging, scheduled reports, bow-tie diagrams and a 600-plus-connector integration layer; no scripted or full-population testing |
| AI features | Adequate | Cognita’s data-use statement (single-tenant AWS, no cross-customer sharing or third-party training, redaction, human-in-the-loop) is concrete; no audit-specific feature named |
| Quality program support | Limited | No QAIP-metrics feature or methodology-enforcement description found |
| Auditee experience | Limited | No dedicated auditee request portal or notification feature described; MyTasks is built for auditors |
| Administration, integrations and security | Adequate | SSO, SCIM, custom REST APIs, ISO 27001 and SOC 2 assessment, AES-256 and TLS 1.2; no FedRAMP, GovRAMP or IRAP despite government being a named sector |
| Cost and contract | Limited | No public pricing page, Vendr median, confirmed Capterra listing or procurement record found anywhere |
| Vendor viability | Adequate | PSG’s US$280 million investment and the VISO TRUST deal signal real capital, but terms are undisclosed, the CRO and CMO both turned over 1 September 2026, and the G2 audit badge slipped from Leader to no badge to High Performer |
Fit by situation
The eight situations are the same on every review in this guide, so ratings can be compared across products. Protecht’s ratings cluster at the two ends its own positioning targets — regulated financial institutions and GRC consolidation — and fall away almost everywhere else.
| Situation | Rating | Reason |
|---|---|---|
| First system for a small team (1 to 5 auditors) | Workable | No public pricing to test against a small budget, but Protecht says it serves clients with as few as two users, and a small team wanting risk, compliance and audit together gets more from one platform than a standalone tool |
| Mid-size function (6 to 25 auditors) | Strong fit | G2’s reviewer segment mix runs roughly 75% mid-market, and the no-code customization reviewers praise most is exactly the configuration effort a function this size can sustain |
| Large or global function (25+ auditors) | Workable | The stated range extends past 20,000 users, but named large customers concentrate in Australia and New Zealand, and complaints about dashboard-building complexity and database-level reporting skill point to real admin load at scale |
| SOX-heavy public company | Poor fit | SOX is not named on the Audit or Controls Management pages, and the Controls library has no COSO or SOX-specific framework among the ones it does name |
| Bank or credit union | Strong fit | Protecht’s stated market and deepest sector page, with named Australian banks, APRA frameworks and a CPS 230 case study; First Tech Federal Credit Union is the one confirmed US name, so ask for reference customers in your own market |
| Public sector, higher education or nonprofit | Workable | Government is a named sector, but every named government customer is Australian, and no FedRAMP, GovRAMP, StateRAMP or IRAP authorization was found |
| Analytics-heavy team | Poor fit | Native analytics are dashboards, tagging and scheduled reports, not full-population data testing; pair Protecht with a dedicated analytics tool rather than expecting it to replace one |
| Consolidating GRC across the three lines | Strong fit | Ten modules and two cross-cutting capabilities on one platform, widened again by the VISO TRUST acquisition, is close to the definition of this situation |
Banks and credit unions using Protecht to track examiner findings as well as internal audit issues should also see the site’s MRA and MRIA lifecycle guide, and any function evaluating Protecht specifically because of its bank and credit union base should read the site’s audit software for banks and credit unions guide before treating the sector fit as settled.
Pricing and contract
Protecht is one of the least transparent products in this guide on price, and not for lack of trying to find a number. A guessed pricing URL 404’d, every module page ends in “Request a demo” rather than a quote or a trial, and no working Capterra listing could be confirmed.
| Source and date | Figure | What it covered | How to read it |
|---|---|---|---|
| Protecht module pages (27 September 2026) | No price published | — | Every page ends in a demo request, not a quote or a trial |
| Vendr marketplace, Protecht page (27 September 2026) | No median, range or purchase count | — | Unlike Vendr’s fuller entries for Optro, Workiva, LogicGate, Onspring and Resolver, Vendr has no deal data for Protecht at all |
| Capterra | No working listing confirmed | — | A guessed URL 404’d; verify any Capterra figure elsewhere before relying on it |
| Public procurement records | None found | — | No procurement record naming Protecht turned up, unlike the West Virginia DOT or City of Norman, OK records for other products in this guide |
| Protecht’s own deployment claim (product page, 27 September 2026) | “As few as two users through to major organizations with over 20,000 users” | A scale claim, not a price | The clearest hint at a user-count-driven quote, but no stated pricing model |
Nothing here is a vendor statement of pricing model; it is our inference from Protecht’s deployment-range language and module structure. Treat every cost driver as an RFP question rather than an assumption: whether Cognita is included with a base license or sold as an add-on, whether Controls Management and VISO TRUST are priced separately from Audit Management, and what implementation and multi-year escalation terms look like, since none of that is published anywhere we found. The site’s vendor-neutral RFP method has the pricing schedule to send, and the internal audit software pricing guide puts what little is public next to every other vendor in this program.
What users say
G2 rates Protecht ERM 4.5 from 64 reviews, with a segment mix of roughly 75% mid-market, 20% enterprise and 5% small business — more mid-market-weighted than Optro or Workiva elsewhere in this guide. Gartner Peer Insights shows 4.6 from 10 ratings, which matches this review’s brief but needs a caveat applied nowhere else in this guide: it is not specific to Gartner’s Audit Management Solutions market used for Optro, TeamMate, Diligent, Workiva, SAP and IBM. Protecht’s Peer Insights page instead aggregates “GRC Tools, Assurance Leaders” and “Integrated Risk Management” ratings, so 4.6 from 10 describes the platform generally, not the audit product specifically. TrustRadius shows 8.0 out of 10 from three ratings, with no themes surfaced on the page we read.
| Theme | Praise or complaint | Where seen |
|---|---|---|
| No-code customization | Praise, cited in 14 reviews | G2 |
| Cross-team collaboration | Praise, cited in 7 reviews | G2 |
| Intuitive interface | Praise, cited in 6 reviews | G2 |
| Consolidating spreadsheets into one source of truth | Praise | G2 |
| Responsive support | Praise | G2 |
| Steep learning curve | Complaint, cited in 7 reviews | G2 |
| KRI and third-party or API integration difficulty | Complaint, cited in 5 reviews | G2 |
| Dashboard-building complexity specifically | Complaint, cited in 4 reviews | G2 |
| Advanced reporting needing database-level skill | Complaint | G2 |
G2’s own quarterly badge results, drawn from Protecht’s press releases rather than an independently loaded category page, tell a more specific story:
| G2 report | Audit Management result |
|---|---|
| Fall 2025 (22 September 2025) | “Best Support” badge |
| Winter 2026 (12 December 2025) | Leader (Mid-Market), “newly earned,” among 92 reports |
| Spring 2026 (20 March 2026) | No Audit Management badge named |
| Summer 2026 (4 June 2026) | “High Performer,” down from Leader |
G2’s own Audit Management category page, which lists 335 products, did not show Protecht on its first page when we checked, so we could not independently verify its rank; the badge history above is Protecht’s self-reported result each quarter, not a rank we confirmed ourselves. G2’s algorithmic alternatives list places Optro, ServiceNow GRC, LogicGate, Workiva, Pirani, Drata, TeamMate, Vanta, Mitti by SafetyCulture and Scrut Automation as the nearest alternatives, each with its own higher score, and G2 states reviewers report those alternatives as generally easier to set up, administer and meet requirements with — which lines up with the learning-curve complaint above.
Implementation and migration
All customers get complimentary access to an online suite of product-training courses, including systems and analytics training. Protecht Academy adds an “Organisational Risk Excellence Series” (a 30-minute fundamentals course and a boards-focused course) and a deeper “Risk Management Mastery Series” covering ERM, controls design, compliance risk and AI governance, plus live six-hour instructor-led sessions with the Risk Management Institute of Australasia carrying CPD points toward RMIA’s CPRA and CPRM credentials; some courses are IIRSM-approved. Commercial models range from pay-as-you-go individual access to corporate subscriptions and custom packages by inquiry.
Named implementation advisors exist, but no standard timeline, admin headcount, or migration tooling — an Excel import path, for instance — is documented anywhere public. Protecht publishes strong specifics about training and AI data governance, and almost nothing about implementation mechanics, worth putting directly to Protecht’s sales team and writing into a contract rather than assuming from the training materials alone. The site’s implementing audit management software guide has the first-120-days checklist to run that conversation against.
How it compares
Optro is the most-reviewed alternative on G2’s own list, with 4.6 from roughly 1,624 reviews against Protecht’s 4.5 from 64, and a published Vendr median of $45,947 a year where Protecht has none. The trade-off this review turns on: Optro is audit-native, with SOX depth covered in the Optro review, while Protecht is risk-native, with audit as one of ten modules. A function centered on SOX should look at Optro first; a bank or insurer wanting audit inside the second line’s risk taxonomy should look at Protecht.
LogicGate Risk Cloud and Workiva sit on G2’s alternatives list too, both with higher review counts and, for LogicGate, free standard and external users that changes the seat-cost math outright; see the LogicGate review and the Workiva review. TeamMate, Wolters Kluwer’s audit-first platform, is the closer public-sector and on-premise comparison; the TeamMate review has the FedRAMP and pricing detail Protecht does not publish.
The one head-to-head comparison with real sub-scores is G2’s own Onspring-versus-Protecht page: Protecht leads on overall ERM score (8.7 versus 8.5 out of 10), mobile access (8.3 versus 6.8) and integration (8.2 versus 7.9), while Onspring leads on risk classification, flexibility and training. Both are no-code platforms with audit as one product among several; the fuller Onspring review covers the mid-market shortlist Protecht sits just outside of on price transparency. Protecht has not published its own “X versus Protecht” page for any of these rivals, unlike Optro or LogicGate; every comparison figure above is G2’s, not Protecht’s own framing. For the wider financial-services shortlist, the site’s audit software for banks and credit unions guide and the best internal audit software roundup cover the rest of the field.
Questions about Protecht ERM
Is Protecht the same as Protecht ERM?
Yes. Protecht Group is the corporate name; Protecht ERM is the product name used on G2, Gartner Peer Insights and TrustRadius, and both refer to the same platform.
Is Protecht’s audit module the same thing as its Controls Management module?
No. Audit Management captures control design and operating-effectiveness results inside an engagement; Controls Management runs the underlying library and testing cycle, aligned to ISO 27001, NIST CSF, SOC 2 and CPS 234. Protecht does not spell out how a test result moves between the two, so ask in a demo.
How much does Protecht ERM cost?
There is no public price. Protecht’s module pages end in a demo request, Vendr has no median or range for it, and no procurement record naming Protecht turned up. Expect a custom quote scoped to user count and module selection, and push for a written pricing schedule.
Is Protecht ERM right for a small internal audit team?
Workable rather than strong. Protecht says it serves clients with as few as two users, and a small team that wants risk, compliance and audit on one platform gets real value from the breadth, but the lack of public pricing makes it hard to size against a small budget without a sales process first.
Does Protecht ERM support SOX compliance?
Not as a named, in-product workflow. SOX does not appear on the Audit Management or Controls Management pages; the only reference is an educational Knowledge Hub article, and the Controls Management library names ISO 27001, NIST CSF, SOC 2 and CPS 234 but no COSO or SOX framework. A SOX-centric public company should look at Optro, TeamMate, Workiva or Diligent One instead.
Is Cognita’s AI safe to use on audit data?
Protecht’s stated data-use terms are specific and reassuring as far as they go: single-tenant AWS per customer, no cross-customer sharing, no third-party model training, automatic redaction of sensitive identifiers, and a human-in-the-loop design. What is missing is any audit-specific Cognita feature; confirm the same terms apply to whatever AI capability actually appears in an audit demo, rather than assuming the general statement covers it.
internalauditguide.com has no commercial relationship with Protecht, VISO TRUST, Optro, LogicGate, Workiva, TeamMate, Onspring or any other vendor named on this page. We take no vendor money, run no affiliate links and accept no sponsored placements, and no vendor saw this page before publication. Product and company names are the trademarks of their owners. Corrections: desk@internalauditguide.com.
Sources and verification
- Protecht: Audit Management — module features, ISO 19011 reference, the Australian Taxation Office case-study link (accessed 27 September 2026).
- Protecht: About Us — founding story, “over 20 years,” Sydney headquarters (accessed 27 September 2026).
- Protecht: Leadership team — CEO Jason Phillips, founders’ current roles, the three PSG board members, independent directors (accessed 27 September 2026).
- PSG Equity: Protecht portfolio page — US$280 million growth investment, 2025, Sydney, Los Angeles and London offices (accessed 27 September 2026).
- Protecht news: VISO TRUST acquisition — 21 April 2026 deal announcement, rationale, no disclosed price (accessed 27 September 2026).
- VISO TRUST: About — founders, LendingClub origin, operating as a Protecht brand (accessed 27 September 2026).
- Protecht news: Cognita launch — 8 September 2025 announcement, timing, CEO quote (accessed 27 September 2026).
- Protecht: Cognita page — single-tenant AWS, no third-party model training, redaction, human-in-the-loop design, feature breakdown by area (accessed 27 September 2026).
- Protecht news: new CRO and CMO — 1 September 2026 announcement (accessed 27 September 2026).
- Protecht: Controls Management — framework library, SOX resource, testing workflow (accessed 27 September 2026).
- Protecht: Integrations — named integrations, Workato iPaaS and connector count, API and SSO language (accessed 27 September 2026).
- Protecht: Security and Compliance — ISO 27001, SOC 2 assessment, GDPR, encryption, penetration testing, SLA (accessed 27 September 2026).
- G2: Protecht ERM reviews — 4.5 from 64 reviews, segment mix, praise and complaint themes with review counts (accessed 27 September 2026).
- Gartner Peer Insights: Protecht ERM — 4.6 from 10 ratings, and the cross-market scoping this review flags (accessed 27 September 2026).
- Vendr: Protecht marketplace page — confirms no pricing data is published for Protecht (accessed 27 September 2026).
Related guides
- Internal audit software: the independent buyer’s guide — every review, comparison and buying guide in one place.
- How we review audit software — the evidence levels, the scorecard and the fit-by-situation method.
- The audit software shortlist finder — eight questions, a shortlist with the reasons from each review.
- The requirements matrix — 156 weighted requirements and vendor scoring in a free Excel workbook.
- Optro review — the audit-native rival with the deepest SOX coverage.
- TeamMate review — the audit-first, public-sector-strong alternative.
- LogicGate Risk Cloud review — a no-code GRC platform with free standard and external users.
- Workiva review — the SOX and SEC reporting suite Protecht does not compete with directly.
- Onspring review — the closest structural peer on G2’s own comparison page.
- GRC suite vs standalone audit software — when consolidation across the three lines is worth it.
- Best internal audit software by use case — all 25 platforms and tools ranked.
- Types of internal audit software — where an enterprise GRC suite sits among the categories.
- Internal audit software pricing — real numbers and negotiation across the market.
- How to read audit software analyst reports — Gartner, Forrester, G2 and the rest, decoded.
- Audit software for banks and credit unions — regulatory issues, exam support and fit.
- The audit software demo script — 25 scenarios that make vendors show, not tell.
- Audit software due diligence — security, data residency, AI data use and vendor stability.
- Selecting an audit management system — the vendor-neutral RFP method.
Leave a Reply