Riskonnect is an integrated risk management platform that added an internal audit module years after it built its name in insurance risk, claims and enterprise risk, and the module still reads that way: capable on the workflow every enterprise GRC suite in this guide ships, thin on the audit-specific depth that audit-native platforms publish in detail. Two 2024 acquisitions changed what a buyer is actually evaluating. Riskonnect bought Ventiv Technology, a risk, claims and insurance-program management specialist, on 11 January 2024, then bought Camms, an Australian-founded GRC, strategy and project-management platform, five months later, folding a second audit-relevant product line into a company already assembling risk, compliance, resilience and now audit under one Thoma Bravo and TA Associates-owned roof. The one fact every buyer should know before the first call: Riskonnect has never published a price, a pricing model, or earned a listing in the Gartner Peer Insights Audit Management Solutions market that every other enterprise GRC suite in this guide has — its audit credibility rests on adjacent risk and compliance ratings, not an audit-specific one.
This review covers Riskonnect’s Internal Audit product inside its Governance, Risk and Compliance module group, what the Camms acquisition actually folded in and what it did not, the AI features Riskonnect launched on Salesforce’s Agentforce platform in February 2026, the pricing evidence that exists in place of a published price, and the review themes on G2 and Gartner Peer Insights. It is one of the product reviews in the site’s independent buyer’s guide to internal audit software and follows the evidence levels and scorecard set out in how we review audit software. Readers deciding between an audit-first platform and a broader risk suite should also see GRC suite versus standalone audit management software.
Verdict. Riskonnect earns a Strong fit only where enterprise risk, insurance claims or a legacy Camms contract already sit on the platform, or where a large or global function is consolidating audit into a wider GRC program; bought for audit alone, it asks a buyer to accept a thinner public record — no audit-specific analyst rating, no published price, no confirmed Camms migration roadmap — than almost any other suite in this guide.
Best for. Large or global risk, compliance and audit functions already running Riskonnect for enterprise risk, insurance claims or business continuity, and organizations consolidating the three lines onto one platform where audit is the newest addition rather than the reason for the purchase.
Not for. A first system for a small audit team, an analytics-heavy function that wants scripted or full-population testing, or a buyer who wants a published price or an audit-specific track record to compare against Gartner Peer Insights and G2 before signing.
Evidence. Research-based: vendor documentation and release notes, public procurement records, third-party pricing data, verified user reviews on Gartner Peer Insights and G2, and analyst coverage. We have not used the product hands-on for this review.
Price evidence. No public price; quote only. Riskonnect’s own Internal Audit page says pricing “depends on the size and complexity of the project” and names “three industry-leading implementation options at different price points” without naming or pricing any of them, and no Vendr marketplace listing for Riskonnect could be found.
Last verified. 27 September 2026.
In this guide
- What Riskonnect is, and who owns it
- What you get: modules and how audit fits
- Walkthrough by audit stage
- SOX and controls
- Analytics, integrations and automation
- AI: what is real
- The scorecard
- Fit by situation
- Pricing and contract
- What users say
- Implementation and migration
- How it compares
- Questions about Riskonnect
- Sources and verification
- Related guides
What Riskonnect is, and who owns it
Riskonnect describes itself as “the leading integrated risk management software solution provider,” a claim like every other vendor’s in this guide: self-reported, not independently ranked. The company was founded in 2007 and is headquartered in Kennesaw, Georgia, in the Atlanta metro area; its own recognition releases use the shorthand “Atlanta” for local workplace awards. A London office is implied by Riskonnect’s EMEA customer base, including BT Group and Transport for London, and by language describing reach across “six continents,” but we could not locate a published street address for it. Jim Wetekamp has been CEO since April 2018, having previously run BravoSolution, a cloud procurement company; his leadership page lists nine other named executives, including CTO Fritz Hesse, previously at Bazaarvoice, Mitek and Intuit, and a strategic advisor, Mark Holt, who was EMEA sales and marketing director at Ventiv Technology before Riskonnect acquired it — a legacy Ventiv executive kept on after the deal.
Thoma Bravo has owned Riskonnect since 2017, running it inside what the private-equity firm calls its “Discover” platform for growth-stage software companies. TA Associates is described, in Riskonnect’s own 11 January 2024 release about the Ventiv acquisition, as the company’s “majority investor,” funding that deal and remaining majority owner at the time — consistent with commonly repeated reporting that TA joined in a 2021 recapitalization, though we could not locate Riskonnect’s own announcement of that transaction to confirm its date, terms, or the current split between the two firms. A buyer signing a multi-year contract is, in practice, signing on to whichever firm controls the roadmap at renewal, and neither has said publicly what that balance is today.
Scale claims move depending on which Riskonnect page states them, and none is independently audited. The company’s own “about us” page, undated, claims “more than 2,000 organizations across six continents” and “more than 800 team members,” with support in 35 languages around the clock. That is lower than both 2024 acquisition announcements, which put the combined customer base at “2,500-plus” and Riskonnect’s headcount, at the Camms deal, at “1,100-plus.” We could not find the higher figures sometimes quoted for Riskonnect elsewhere — customer counts near 2,700, staff counts near 1,500 — on any Riskonnect page we could open, and treat any number above the 2,500/1,100 figures, both dated 2024, as unconfirmed.
The Camms acquisition is the more consequential of the two 2024 deals for an audit buyer, because Camms sold its own governance, risk, strategy and project-management software before the purchase closed on 18 June 2024, advised by Harris Williams and Kirkland & Ellis, with Camms’s then-CEO Adam Collins quoted alongside Wetekamp. Camms’s public marketing site no longer serves independent content in our checks — camms.com and its about page both returned empty pages, consistent with, though not proof of, a redirect folding the brand into riskonnect.com; the Internet Archive was unreachable for us to check the history directly. Gartner Peer Insights has not forgotten the old brand entirely: its Riskonnect vendor page still lists “Camms.Strategy (Legacy)” as its own product, rated 4.0 from 5 reviews in the Productivity and Collaboration market, alongside an unexplained second legacy entry, “SYCLE (Legacy),” rated 4.0 from 2 reviews in Finance, whose origin we could not identify. A Camms customer deciding whether to stay put should ask Riskonnect directly for a written migration and end-of-life timeline, because none is published anywhere we could find.
Analyst recognition is notably absent next to the rest of this guide: Riskonnect claims no placement in Gartner’s Magic Quadrant for GRC Tools, Assurance Leaders (27 October 2025, where Optro (formerly AuditBoard), LogicGate, Archer and IBM each claim a Leader spot) or the Forrester Wave for GRC Platforms (Q2 2026, where Optro, Diligent, LogicGate and Vanta claim Leader placements and MetricStream a Strong Performer). Gartner’s 13 April 2026 Market Guide for Audit Management Software, by analyst James Bourke, is the non-ranking document that actually covers this narrower market and warns buyers to be wary of agent-washing; the guide to reading audit software analyst reports has the full method for weighing claims like these against a vendor with no analyst placement to weigh at all. The timeline below covers the acquisitions and launches that shaped the platform buyers see today.
| Date | Event | Why it matters to a buyer |
|---|---|---|
| 2007 | Riskonnect founded | Nearly two decades of product history before the current ownership settled in |
| 2017 | Thoma Bravo acquires Riskonnect | Start of the current ownership chain, run inside its “Discover” platform |
| 2021 (recapitalization; date not independently confirmed by us) | TA Associates becomes majority investor | Consistent with 2024 releases describing TA as majority owner; Riskonnect has not published this transaction itself |
| 11 Jan 2024 | Acquires Ventiv Technology (RMIS, claims, policy and billing administration) | Adds an insurance-heavy customer base and the “2,500-plus” combined-customer claim |
| 18 Jun 2024 | Acquires Camms (GRC, strategy, projects, people management) | A second audit-relevant product line folds in; the legacy brand lingers on Gartner Peer Insights |
| 15 Dec 2025 | CTO Fritz Hesse byline on AI governance | Signals the AI push that followed two months later |
| 3 Feb 2026 | Launches “Agentforce 360 for Riskonnect” and the Intelligent Risk Framework | Riskonnect’s first named AI agent layer; see the AI section below |
| 21 to 22 Jul 2026 | Partners with Argos Risk on continuous vendor-intelligence monitoring | Extends third-party risk rather than audit specifically |
What you get: modules and how audit fits
Riskonnect organizes its catalog into four groups rather than selling audit as a single stand-alone product: Insurable Risk, built on the Ventiv-heritage lines (RMIS, claims management, policy administration, billing, health and safety); Governance, Risk and Compliance, where Internal Audit sits alongside Business Strategy, Enterprise Risk Management, Compliance, Policy Management, Internal Controls, IT Risk Management, AI Governance, Third-Party Risk Management, Project Risk Management and ESG; Business Continuity and Resilience (BCM, operational resilience, crisis management, threat intelligence, emergency notification); and two standalone products, Active Risk Manager and Portfolio and Program Management. The table below maps the catalog as Riskonnect currently presents it.
| Group | What it covers | Audit-relevant detail |
|---|---|---|
| Insurable Risk | RMIS, claims management, policy administration, billing, health and safety | Ventiv-heritage; feeds insurance and claims data an audit function may need to test, not audit workflow itself |
| Governance, Risk and Compliance | Business Strategy, Enterprise Risk Management, Compliance, Policy Management, Internal Controls, IT Risk Management, AI Governance, Third-Party Risk Management, Project Risk Management, Internal Audit, ESG | Internal Audit is one of eleven lines in this group; Enterprise Risk Management and Internal Controls are the two it depends on most |
| Business Continuity and Resilience | BCM, Operational Resilience, Crisis Management, Threat Intelligence, Emergency Notification | Overlaps with operational-resilience audit work, not audit management itself |
| Active Risk Manager (standalone) | Project and program risk | Rated separately on Gartner Peer Insights, 4.2 from 3 reviews |
| Portfolio and Program Management (standalone) | Project and portfolio tracking | Likely where Camms’s former project-management lines now sit; Riskonnect does not state the mapping directly |
Business Strategy and the project and portfolio lines sit exactly where Camms’s former Camms.Strategy, Camms.Projects and Camms.Risk products would map, which is consistent with, but not proof of, those products being folded into Riskonnect’s own naming rather than sold as distinct editions; Riskonnect’s own pages do not state the mapping explicitly. The consequence for an audit buyer is the one every enterprise GRC suite covered in this guide shares: Internal Audit is licensed and evaluated as one line among many, and Riskonnect’s own FAQ says as much when it ties risk-based scoping directly to whatever the Enterprise Risk Management module already holds, rather than treating audit’s risk model as self-contained. The GRC suite versus standalone audit management software comparison sets out that trade-off for every suite in this guide, not only Riskonnect’s version of it.
Walkthrough by audit stage
Everything below comes from Riskonnect’s own Internal Audit product page and its published FAQ, not from using the product.
Planning and risk assessment
Riskonnect names an audit universe — an inventory of auditable entities — combined with “pre-built risk assessments” to set scope. Its own FAQ is unusually direct about where that risk data actually comes from: when Internal Audit and Enterprise Risk Management “share a platform, the audit plan can be aligned directly with the organization’s ERM risk register.” That is a real advantage for a function that already runs Riskonnect’s ERM module, and a real dependency for one that does not: the FAQ describes alignment to another module’s data, not a standalone audit risk model. The site’s annual internal audit risk assessment playbook and its guide to identifying auditable entities cover the method a tool like this is meant to serve.
Engagement and fieldwork
Riskonnect names “engagement letter creation” as a discrete capability. Beyond that one feature, its Internal Audit page does not describe engagement-level staffing, scheduling or budget tracking in any detail we could find, which is thinner documentation for this stage than several rivals in this guide publish.
Workpapers and review
“Document and Workpaper Management” is the named capability: centralized electronic storage for audit files and evidence, with version control, bundled into the Internal Audit module rather than sold as its own product. Riskonnect’s page does not describe review routing, sign-off steps, or how far the audit trail extends beyond version control, so ask to see this stage in a live demo rather than assume parity with audit-native platforms; the site’s risk and control matrix template is a useful basis for comparing what a workpaper linked to an RCM should carry.
Issues and follow-up
“Audit Findings” is the most specifically described stage on the page: remediation tracking against due dates, follow-up testing to verify that remediation actually happened, and task automation with email reminders. That is a genuinely useful set of named capabilities, and the clearest single area where Riskonnect’s audit documentation matches the depth several audit-native competitors publish for the same stage.
Reporting
Reporting runs through “storyboard-driven dashboards” for communicating audit status, plus a separate “Risk Analytics and Insights” capability described only as customizable reporting and dashboards, with no engine name, version number, or statement of whether it is built in-house or licensed. Nothing in the documentation we read describes an audit-committee-specific report template.
Riskonnect markets “Continuous Controls Testing” as a headline capability sitting apart from the five stages above, described in its FAQ as using robotic process automation and machine learning to test populations of transactions that are, in its words, “sometimes complete,” rather than a sample. No named product or version for this engine, no accuracy figures, and no indication of how new or how automated it actually is in live use were found anywhere in the pages we could open. The Internal Audit page also tells customers to pair the module with the separate Internal Controls, Compliance and Enterprise Risk Management modules for a “complete” program — a reminder that Internal Audit alone is not the complete offering Riskonnect is selling.
SOX and controls
Internal Controls is a distinct module from Internal Audit, and Riskonnect’s own Internal Audit page describes it only in passing: it will “automatically test your controls, provide operational transparency, and demonstrate regulatory compliance.” We could not locate a dedicated Internal Controls product page — two guessed URLs both returned a 404 — so SOX-specific features that Archer and several other suites in this guide document in detail, such as narrative and PBC workflow, Section 302 and 404 certification support, control-to-account mapping, or scoped external-auditor access, cannot be confirmed for Riskonnect the same way. A blog post on rethinking the SOX compliance burden exists on Riskonnect’s site, but it reads as thought leadership rather than product documentation, and we did not rely on it for feature claims. The net position: a buyer whose SOX program is the reason for the purchase should treat Riskonnect’s public SOX documentation as thin next to its GRC-suite peers, and should ask Riskonnect directly, in the RFP, for the narrative, certification and access-scoping detail that Archer and IBM OpenPages publish unprompted; the site’s SOX 404 guide sets out what a program needs from whatever system runs it.
Analytics, integrations and automation
Riskonnect’s own language about data connectivity stays general: it says the platform can connect data from multiple sources and offers APIs for data import and export, with no technical documentation on authentication, rate limits or endpoints published anywhere we could reach. A dedicated integrations section, found through the site’s own integrations sitemap rather than its navigation, lists three named point integrations.
| Integration | What it connects | Audit relevance |
|---|---|---|
| Oracle Primavera P6 | Project and portfolio scheduling data | Likely tied to the Camms-heritage Portfolio and Program Management line, not audit |
| CUBE | Regulatory-content feed | Complements the Compliance module’s regulatory-change tracking |
| SecurityScorecard | Third-party and cyber risk ratings | Feeds Third-Party Risk Management, not Internal Audit directly |
None of the three is audit-specific, and we found no dedicated Internal Audit integration — a general-ledger or ERP connection for continuous testing, or a Salesforce connection documenting how the AI layer below actually reaches customer data — published as its own page. “Risk Analytics and Insights” is described only as customizable reporting and dashboards, again with no engine name or version. A team that wants real data analytics — scripted tests, full-population testing, continuous monitoring built for audit rather than for compliance or third-party risk — should plan for a second, dedicated tool from the outset; the site’s audit analytics software comparison covers the purpose-built options.
AI: what is real
Riskonnect’s current AI branding centers on two names: an “Agentforce 360 for Riskonnect” AI agent library, built on Salesforce’s Agentforce platform, and an umbrella capability called “Intelligent Risk,” organized around three verbs — GUIDE (decision summaries and recommended actions), PREDICT (risk outcomes and pattern identification) and ASSIST (automation and process coordination). Riskonnect announced the launch on 3 February 2026 in a release titled “Riskonnect Announces Enterprise-scale AI for Risk Powered by Agentforce 360,” introducing what it calls an “Intelligent Risk Framework” for automation across the entire enterprise risk landscape — confirmed only through the press index’s headline and summary, since the release body itself returned a 404 on our best-guess URL.
A separate AI Governance module exists as its own product line inside the Governance, Risk and Compliance group, for governing a customer’s own AI risk — a different thing entirely from how Riskonnect uses AI inside its own product, and worth not confusing in a demo. What we could not find anywhere on Riskonnect’s site is any statement about whether its AI features train on customer data, how long inputs are retained, or whether a customer can opt out. That gap is unusual next to LogicGate, reviewed elsewhere in this guide, which publishes an explicit no-training-on-customer-data policy with 30-day retention for its own AI features. Building on Salesforce’s infrastructure implies customer data flows through Salesforce for processing, but that is our inference, not a Riskonnect statement; the site’s guide to evaluating AI in audit software has the questions worth putting to Riskonnect directly before enabling any of this on real workpapers.
The scorecard
The scorecard uses the 12 areas described on the method page; each level reflects documentation and reviews, not hands-on use, and several rows note where public detail runs thinner than for other suites in this guide.
| Area | Level | Evidence |
|---|---|---|
| Risk assessment and planning | Adequate | Audit universe and pre-built risk assessments named, but the FAQ ties risk-based scoping directly to the Enterprise Risk Management module’s data rather than a standalone audit risk model |
| Engagement workflow | Limited | Only “engagement letter creation” is named; no staffing, scheduling or budget-tracking detail found |
| Workpapers and evidence | Adequate | Document and Workpaper Management with version control, bundled into the module; no review routing or sign-off detail published |
| Issues and follow-up | Strong | Audit Findings names remediation tracking against due dates, follow-up testing to verify remediation, and automated email reminders |
| Reporting | Adequate | Storyboard dashboards and Risk Analytics and Insights, both described only generically, with no engine name or committee-specific template |
| SOX and controls testing | Limited | Internal Controls is a separate module described only in passing; no dedicated product page found; Continuous Controls Testing is a marketing claim without published methodology |
| Analytics and automation | Limited | Generic connectivity language; only three named point integrations (Primavera P6, CUBE, SecurityScorecard), none audit-specific |
| AI features | Limited | Named Agentforce 360 and Intelligent Risk branding with a firm launch date, but no data-use, training or retention statement found anywhere |
| Quality program support | Not offered | No QAIP-metrics or methodology-enforcement feature described in any page we could open |
| Auditee experience | Not offered | No auditee-facing request portal or notification feature specific to audit was found |
| Administration, integrations and security | Limited | SOC 2 Type 2 claimed, but the only security page we could reach also cites SSAE 16, superseded by SSAE 18 since 2017, and no ISO 27001, 27017 or 27701 or FedRAMP or GovRAMP claim was found despite selling to the U.S. Army and EMEA customers |
| Cost and contract | Limited | No public price list, no stated pricing model, and no Vendr marketplace listing found — thinner than nearly every other product in this guide |
| Vendor viability | Adequate | Thoma Bravo since 2017 and TA Associates as majority investor by 2024, two 2024 acquisitions showing growth ambition, but inconsistent self-reported scale and no confirmed current ownership split |
Fit by situation
The eight situations are the same on every review in this guide, so ratings can be compared across products. Riskonnect’s own ratings cluster in the middle, with the clearest calls at the extremes.
| Situation | Rating | Reason |
|---|---|---|
| First system for a small team (1 to 5 auditors) | Poor fit | No published price, no self-service path, and a platform built around modules a small team has no reason to buy alongside audit |
| Mid-size function (6 to 25 auditors) | Workable | The audit module can stand largely on its own at this scale, though risk-based scoping still works best paired with the ERM module |
| Large or global function (25+ auditors) | Strong fit | Multi-entity audit universe, a Continuous Controls Testing pitch aimed at scale, and the administrative capacity a large function can dedicate to a GRC-suite deployment |
| SOX-heavy public company | Workable | Internal Controls exists but is thinly documented on its own, and Riskonnect has not published the SOX-specific detail Archer or IBM OpenPages have |
| Bank or credit union | Workable | Named customers and Ventiv-heritage insurance depth help, but no ISO 27001 or FedRAMP claim was found for a sector where examiners ask |
| Public sector, higher education or nonprofit | Workable | The U.S. Army is a named customer and “Aged-Care” appears among the sectors served, but no FedRAMP or GovRAMP authorization claim was found |
| Analytics-heavy team | Poor fit | Continuous Controls Testing is a marketing claim without published methodology, and the only named integrations are project, regulatory-content and third-party-risk feeds, not analytics ones |
| Consolidating GRC across the three lines | Strong fit | This is the buyer Riskonnect is built for: audit, ERM, compliance, third-party risk and business continuity share one data model, broadened further by the Camms acquisition |
Functions consolidating third-party risk alongside audit should also see the site’s third-party risk management program guide, since Riskonnect’s Third-Party Risk Management module — fed in part by the SecurityScorecard integration above — is one of the modules most likely to sit next to Internal Audit in a Situation 8 deployment.
Pricing and contract
Riskonnect is one of the least transparent products in this guide on price, and unlike most of its rivals, it does not even have the usual second-hand proxies to fall back on.
| Source and date | Figure | What it covered | How to read it |
|---|---|---|---|
| Riskonnect Internal Audit page (27 Sep 2026) | No figure; pricing “depends on the size and complexity of the project” | Names, without pricing, three unnamed implementation options at different price points | A model statement with no numbers attached |
| Vendr marketplace, standard URL (27 Sep 2026) | 404; no listing found | — | Unlike Optro, Workiva, LogicGate and Onspring, all Vendr-tracked, Riskonnect may not be tracked at all, or sits at an unfound URL |
| Public procurement records (27 Sep 2026) | None found | — | This research had no working search tool to run targeted government-bid queries; treat as not found, not confirmed absent |
No vendor statement describes a licensing structure — not per user, not per module, not unlimited seats. The only structural hint is the “three implementation options at different price points” language above, which speaks to services and onboarding tiers, not the license or subscription itself. Treat every cost driver as a question for the RFP: whether Internal Controls, Enterprise Risk Management or Third-Party Risk Management carry separate subscriptions if an audit buyer needs the ERM-linked scoping described earlier, what the Agentforce 360 AI layer adds to the bill, and what a Camms or Ventiv legacy customer’s renewal actually changes. The site’s vendor-neutral RFP method has the pricing schedule to send, and the internal audit software pricing guide puts what public figures do exist next to every other vendor’s.
What users say
Riskonnect’s G2 listing shows 4.4 from 71 reviews, skewed toward mid-market customers of 51 to 1,000 employees; G2 does not tag reviews by legacy brand, so the claim that this total includes old Camms reviews could not be independently confirmed one way or the other. Gartner Peer Insights rates Riskonnect 4.4 across 153 reviews vendor-wide, but — unlike Archer, Optro (formerly AuditBoard), IBM OpenPages, MetricStream, TeamMate and Diligent One, all of which are reviewed in Gartner’s Audit Management Solutions market — Riskonnect has no entry in that market at all. Its audit-relevant signal instead sits inside the broader ratings its other modules earn: “Riskonnect GRC Software” rates 4.3 from 12 reviews in the GRC Tools, Assurance Leaders market; “Riskonnect” rates 4.6 from 7 in IT Risk Management and 4.4 from 43 in Integrated Risk Management Solutions, plus “Riskonnect Active Risk Manager” at 4.2 from 3; and “Riskonnect Business Continuity” rates 4.6 from 70. A buyer comparing Riskonnect’s rating to a rival’s audit-specific score is, in every case but G2’s, comparing two different things.
| Theme | Praise or complaint | Where seen |
|---|---|---|
| Ease of use and an intuitive interface | Praise | G2 |
| Breadth: risk, compliance, audit and incident management in one platform, replacing fragmented spreadsheets | Praise | G2 |
| Implementation-team responsiveness | Praise | G2 |
| Configurability without heavy custom development | Praise | G2 |
| Better reporting and dashboard visibility than manual processes | Praise | G2 |
| Performance and lag, especially with frequent project-risk updates | Complaint | G2 |
| Navigation and admin-settings complexity for new users | Complaint | G2 |
| Customization ceilings past standard options, often needing vendor help | Complaint | G2 |
| Long implementation timelines | Complaint | G2 |
| A dated-feeling interface | Complaint | G2 |
The pattern is consistent with what Gartner Peer Insights shows across the adjacent GRC and integrated-risk markets above: ease of use and breadth on one side, implementation complexity and a ceiling on self-service customization on the other — the same trade-off between reach and depth that runs through this entire review.
Implementation and migration
Riskonnect’s Professional Services team is described as supporting customers “from initial kickoff to go-live and beyond,” using project-management tools such as task lists, real-time status and automatic alerts, and handling historical-data migration. The same page claims “most users can get fully up to speed with only minimal training” because of the interface’s intuitiveness — a vendor claim about ease of use, not a documented training curriculum. A Kaiser Permanente customer quote illustrates adoption practice, emphasizing communication and staff input during rollout, but names no timeline, cost or admin-role detail.
What is missing is more informative than what is published: no implementation-timeline figure, no named migration tooling, and — the concrete gap behind this review’s buyer caution — no published roadmap for moving legacy Camms or Ventiv customers onto the current Riskonnect platform. A Camms customer deciding whether to renew or migrate has no public document to check Riskonnect’s verbal promises against, so get any migration commitment, timeline and end-of-life date for legacy Camms products in writing before signing, and treat “minimal training” as a claim to test in the demo rather than a plan to rely on. The site’s audit software due diligence guide has the vendor-stability and migration questions worth adding to that same conversation.
How it compares
MetricStream is the closest structural peer: another enterprise GRC suite where audit is one module among several, similarly light on public detail. Its audit-management product rates 3.6 from just 6 reviews on Gartner Peer Insights — thinner signal even than Riskonnect’s adjacent GRC ratings — and, like Riskonnect, it publishes no price list. Its May 2025 “AI-first” rebrand covers similar ground to Riskonnect’s Agentforce 360 push, launched nine months later. The MetricStream review works through the fit in full.
SAI360, STG-owned since 2023 with BWise heritage, sits closest to Riskonnect on ownership structure: both are private-equity-backed suites layering audit into a wider risk and compliance catalog, and both added mid-market editions or AI features in 2026 aimed at broadening past their core enterprise base. See the SAI360 review for the detail.
Archer is the larger and more bank-heavy version of the same model: 1,300-plus customers including 37 of the top 50 global banks, against Riskonnect’s inconsistent self-reported figures, and named ISO 27001, 27017 and 27701 certifications that Riskonnect’s own security page does not claim. Neither publishes a price. The Archer review and the due diligence guide‘s security questions are worth running against both.
For a buyer who wants audit-first software rather than a GRC suite with audit inside it, Optro (formerly AuditBoard) is the most-reviewed alternative in this guide, with a published Vendr median of $45,947 a year, a dedicated Gartner Peer Insights audit-market listing at 4.5 from 890 reviews, and no adjacent-module dependency for its risk-based scoping. The Optro review sets out that trade-off directly, and the best internal audit software roundup has the fuller shortlist against every product in this guide.
Questions about Riskonnect
Is Riskonnect the same as Camms?
Riskonnect acquired Camms on 18 June 2024, and Camms’s public marketing site no longer serves independent content in our checks, consistent with, though not confirmed proof of, a redirect into Riskonnect’s own site. Gartner Peer Insights still lists a “Camms.Strategy (Legacy)” product separately from current Riskonnect lines, which suggests the brand has not been fully retired everywhere. An existing Camms customer should ask Riskonnect directly for a written migration and end-of-life timeline, since none is published.
How much does Riskonnect cost?
There is no public price. Riskonnect’s own Internal Audit page says pricing depends on project size and complexity and mentions unnamed implementation tiers, and no Vendr marketplace listing or public procurement record could be found. Expect a fully negotiated quote, and push for a written pricing schedule, including what Internal Controls, Enterprise Risk Management and the AI layer add, in the RFP rather than a verbal range in a demo.
Is Riskonnect right for a small audit team?
Generally not as a first system. The fit ratings in this review mark a team of one to five auditors as Poor fit, because Riskonnect’s audit module works best paired with its Enterprise Risk Management and Internal Controls modules, there is no published entry-level price, and no self-service path was found. The site’s audit software for small teams guide has better-suited, lower-cost options.
Does Riskonnect have a standalone SOX product?
No. SOX and ICFR-related functionality sits in the separate Internal Controls module, described on Riskonnect’s Internal Audit page only in passing, and we could not locate a dedicated Internal Controls product page to verify the narrative, certification or external-auditor-access features this guide documents for Archer or IBM OpenPages. Ask Riskonnect directly for that detail before assuming parity.
Does Riskonnect’s AI train on our data?
Riskonnect has not published a data-use, training or retention statement for any of its AI features, including the Agentforce 360 agent library launched in February 2026. Because that layer runs on Salesforce’s Agentforce platform, customer data likely flows through Salesforce for processing, but that is an inference from the architecture, not a Riskonnect statement. Ask the question directly, and get the answer in writing, before enabling any of it on real workpapers.
Is Riskonnect FedRAMP or ISO 27001 certified?
We found no ISO 27001, 27017 or 27701 claim, and no FedRAMP or GovRAMP authorization claim, anywhere in Riskonnect’s published security documentation, despite the U.S. Army appearing as a named customer. The one security page we could reach cites SOC 2 Type 2 alongside SSAE 16, a reporting standard superseded by SSAE 18 in 2017 — worth asking Riskonnect to explain directly rather than assuming the certifications are current.
internalauditguide.com has no commercial relationship with Riskonnect or any other vendor named on this page. We take no vendor money, run no affiliate links and accept no sponsored placements, and no vendor saw this page before publication. Product and company names are the trademarks of their owners. Corrections: desk@internalauditguide.com.
Sources and verification
- Riskonnect: Internal Audit module product page — the five-stage workflow, Continuous Controls Testing language and pricing-tier mention (accessed 27 September 2026).
- Riskonnect homepage — the full module catalog and the Intelligent Risk and Agentforce 360 AI branding (accessed 27 September 2026).
- Riskonnect acquires Camms (BusinessWire, 18 June 2024) — the acquisition’s deal framing, advisors and combined customer and staff counts (accessed 27 September 2026).
- Riskonnect: about us page — the “2,000-plus organizations” and “800-plus team members” claims (accessed 27 September 2026).
- Riskonnect: leadership page — executive names, titles and tenure, including Mark Holt’s prior Ventiv role (accessed 27 September 2026).
- Riskonnect: AI page — the AI branding detail; no data-use statement found (accessed 27 September 2026).
- Riskonnect: Platform Security page — SOC 2 Type 2, SSAE 16, encryption and data-center claims; no ISO or FedRAMP claim found (accessed 27 September 2026).
- Riskonnect: press index — dated headlines including the 3 February 2026 Agentforce 360 launch (accessed 27 September 2026).
- Thoma Bravo: Riskonnect portfolio page — ownership since 2017, founding year, headquarters and the “Discover” platform framing (accessed 27 September 2026).
- Riskonnect: who we serve page — named customers and industries, including “Aged-Care” (accessed 27 September 2026).
- Riskonnect reviews (G2) — the 4.4-from-71 rating and its praise and complaint themes (accessed 27 September 2026).
- Riskonnect vendor page (Gartner Peer Insights) — the vendor-wide rating and the full per-market breakdown, including the Camms.Strategy (Legacy) listing (accessed 27 September 2026).
- Riskonnect acquires Ventiv Technology (press release, 11 January 2024) — the Ventiv deal and TA Associates’ role (accessed 27 September 2026).
- Riskonnect: Professional Services page — the implementation description and the Kaiser Permanente customer quote (accessed 27 September 2026).
- Riskonnect: integrations page — the named point integrations, Oracle Primavera P6, CUBE and SecurityScorecard (accessed 27 September 2026).
Related guides
- Internal audit software: the independent buyer’s guide — every review, comparison and buying guide in one place.
- How we review audit software — the evidence levels, the scorecard and the fit-by-situation method.
- The audit software shortlist finder — eight questions, a shortlist with the reasons from each review.
- The requirements matrix — 156 weighted requirements and vendor scoring in a free Excel workbook.
- Gartner, Forrester, G2 and the rest — how to read audit software analyst reports, and why they say nothing about Riskonnect.
- Best internal audit software — 25 platforms and tools compared by use case.
- Internal audit software pricing — real numbers, pricing models and how to negotiate, for the products that publish them.
- Types of internal audit software — audit management, GRC, SOX, compliance and analytics, and where Riskonnect sits.
- The audit software demo script — 25 scenarios worth running against Riskonnect’s Continuous Controls Testing claim specifically.
- Audit software due diligence — security, data residency, AI data use and vendor stability, the questions Riskonnect’s own pages leave open.
- Selecting an audit management system — the vendor-neutral RFP method, and the pricing schedule to send when a vendor publishes no price.
- MetricStream review — another enterprise GRC suite with audit as one module among several.
- SAI360 review — internal audit and SOX in a financial-services GRC suite with a similar ownership structure.
- Archer review — the larger, more bank-heavy version of the same enterprise GRC model.
- Optro (formerly AuditBoard) review — the audit-first alternative most likely to come up against Riskonnect in a shortlist.
- GRC suite vs standalone audit management software — how to make the call between a suite like Riskonnect and a standalone audit platform.
Leave a Reply