Category Leader

Riskonnect: A PE-Backed Leader in a €3 Billion GRC Software Market

Dedale Intelligence's Private Market Leader 360 on Riskonnect covers the €3bn GRC software market, Riskonnect's M&A strategy, product suite, competitive positioning, and AI capabilities across governance, risk, and compliance.

Governance, risk, and compliance software has moved from a specialist IT category into a strategic priority for every large enterprise navigating a world of expanding regulatory complexity. Managing risk via spreadsheets is no longer viable. Disconnected compliance and audit functions create blind spots. And regulators, from GDPR to the EU AI Act, are raising the bar on what organizations must demonstrate and prove. GRC software has become the platform layer that holds this together.

Dedale Intelligence's Private Market Leader 360 on Riskonnect is built on 20 primary expert interviews conducted across Riskonnect alumni, competitor executives at ServiceNow, OneTrust, and Workiva, and customers including Roche. This article draws selectively on the key findings. The full analysis — including the complete comparative assessment across eight KPCs, the detailed AI capabilities benchmark, and the customer use case — is in the report: Download Now!

For a practitioner perspective on how private equity is approaching GRC and adjacent compliance-driven software markets, see Dedale Intelligence's interview with Anna Amadio, Director of Value Creation at Triple PE. For a view on how AI is reshaping adjacent compliance-driven markets, see our expert review on EHS software.

What is GRC software and why does it matter?

GRC software provides a centralized framework for organizations to manage policies, mitigate risks, and ensure compliance with regulations and internal standards. It integrates traditionally siloed functions — governance, risk management, and compliance — into a single platform, enabling a holistic view of an organization's risk and compliance posture.

Key functionalities typically span policy management, IT and cybersecurity risk, operational risk, third-party risk management (TPRM), data privacy, audit management, and ESG program oversight. Companies adopt GRC platforms when three conditions converge: managing complex risk landscapes via spreadsheets has become unscalable, disconnected departments create duplicate work and obscure the true risk profile, and an increasing volume of regulations demands automated tracking to ensure and prove compliance.

GRC software market definition showing core functions including policy management, IT risk, operational risk, TPRM, data privacy, audit management, and ESG oversight — Dedale Intelligence Riskonnect Private Market Leader 360
Source: Dedale Intelligence Analysis

The market: a €3 billion equipped market growing at 15% CAGR

The global GRC software market has a TAM of approximately €28 to €30bn in 2025, with 48% from Europe and 52% from the US. With an average equipment rate of approximately 10%, the resulting equipped market is approximately €3bn, expected to double to approximately €6bn by 2030, implying a 15% CAGR.

Growth is fueled by two structural forces. Regulatory pressure is intensifying, with rising demand for AI governance tools ahead of the EU AI Act. And mid-market demand is accelerating, with mid-market companies and SMBs expected to be the fastest-growing customer segment at a 21% CAGR from 2025 to 2030, compared to approximately 7% for large enterprises. GRC is increasingly a requirement across company sizes, not just for large enterprises with dedicated risk teams.

Dedale Intelligence covers GRC as part of its Horizontal Software expertise. For a broader view of the segment landscape, see the Horizontal Software coverage page.

Riskonnect: company snapshot

Founded in 2007 in the US by Bob Morrell, Riskonnect operates as a PE-backed, cloud-based SaaS GRC platform built on Salesforce. The company was acquired by Thoma Bravo in an LBO in 2017 and has since grown via an aggressive acquisition strategy.

Key facts from the PDF:

  • 1,014 FTEs as of November 2025
  • Revenue of $231m in FY2024
  • Revenue split: 70% software, 30% services
  • Geography: approximately 56% US, approximately 44% international
  • CEO since 2018: Jim Wetekamp, previously CEO of BravoSolution (2008 to 2018)
  • 7 acquisitions since 2018, including Marsh ClearSight (RMIS, 2018), Xactium (GRC expansion, 2020), ICIX (ESG, 2021), Sword GRC (project risk, 2022), Castellan (business continuity, 2022), Ventiv Technology (RMIS, 2024), and Camms (Australian GRC, 2024)
  • The acquisition strategy has been deliberate and targeted: expanding from Riskonnect's historical strength in insurable risk management into core GRC, ESG, business continuity, and geographic reach in Europe and APAC.

Riskonnect company overview showing revenue mix by geography (56% US, 44% international), product split (50% GRC and insurable risk, 35% ESG and healthcare, 15% business continuity), and acquisition timeline from 2007 to 2024 — Dedale Intelligence
Source: Dedale Intelligence Analysis

Product portfolio: four categories, one Salesforce backbone

Riskonnect's platform covers four product categories. Core GRC, which accounts for approximately 50% of revenue, includes Enterprise Risk Management, TPRM, Compliance, and Audit modules, centralizing risk and compliance data for board-level reporting. Insurable Risk, via its RIMS and claims management modules, manages insurable risk data, claims intake, and insurance program administration, and is Riskonnect's historical competitive strength particularly in financial services. ESG and Healthcare together account for approximately 35% of revenue, with the ESG module (formerly ICIX) covering GHG emissions and supplier audits, and the Healthcare GRC module providing patient safety and provider quality workflows. Business Continuity and Resilience (formerly Castellan) accounts for approximately 15% of revenue.

Pricing is modular and calculated primarily per concurrent user. ACV ranges from approximately $70k to $100k for mid-market companies and from approximately $150,000 to $300,000 for enterprise clients. Contracts are typically three to five years.

Download the full Riskonnect Private Market Leader 360 report

Who Riskonnect serves and how decisions are made

Riskonnect's sweet spot is upper mid-market and enterprise clients with complex, multi-entity risk exposure requiring centralized, cross-functional risk management and continuous assurance. Enterprise customers are defined as organizations generating over $1bn in annual revenue. The company has a particularly strong position in insurance and solid exposure across healthcare, retail, financial services, transportation, defense, and manufacturing.

GRC purchase decisions are committee-driven and C-suite sponsored. The primary decision makers are C-level executives in Risk, Compliance, and Legal functions, followed by the Board. The specific stakeholder varies by module: CISO and CTO for IT risk and cybersecurity, CPO and CDO for data privacy, CRO and CCO for risk and compliance management, CFO and CLO for transaction risk, and the COO for business continuity.

Satisfaction scores from Dedale Intelligence's primary research sit at approximately 8 to 9 out of 10, reflecting broad and deep features and strong service. The primary friction points are relatively high cost and complexity for mid-market buyers, and M&A integration complexity where acquired modules remain technically separate from the core Salesforce architecture.

Competitive dynamics: a concentrated enterprise tier, a fragmented mid-market

The enterprise GRC market is served by a small group of international platform vendors. Riskonnect's primary competitors include Archer (US-based legacy leader with strong IT risk capabilities), ServiceNow (originally an ITSM platform that added GRC, with best-in-class workflow automation and modern UI), and MetricStream (US-based legacy GRC vendor with strong IT risk, TPRM, and audit capabilities). In the enterprise tier, Riskonnect is considered a top-tier player, especially in insurance, with broad functionality well aligned to complex GRC requirements.

Additional competition comes from Navex (ethics and whistleblower solutions, approximately $293m revenue in 2025), AuditBoard (modern GRC focused on audit and compliance for agile teams, currently serving 40% of the Fortune 500), Diligent (governance specialist, serving 65% of the Fortune 1000), and Workiva (financial reporting, ESG, and GRC for finance and audit teams, approximately €740m revenue in 2024).

Riskonnect's competitive weakness sits in the mid-market, where the requirement for lengthy and expensive customizations creates a weaker right-to-win, and where agile upmarket challengers including Drata, Vanta, and Hyperproof are gaining ground by offering lighter, more user-friendly alternatives.

GRC software competitive landscape showing enterprise, mid-market, and SMB vendor positioning by geography including Riskonnect, Archer, ServiceNow, MetricStream, Navex, AuditBoard, Diligent, and Workiva — Dedale Intelligence
Source: Dedale Intelligence Analysis

AI in GRC: three areas of transformation

AI has the potential to reshape GRC across three functional areas, each with different criticality profiles according to Dedale Intelligence's assessment.

The first is AI-based real-time risk management, covering AI-powered control monitoring (very high criticality), predictive risk scoring (rather high), and simulation and scenario analysis (medium). The second is AI-powered compliance, covering AI-based evidence gathering (very high criticality), regulatory-driven controls creation (medium), and regulatory change monitoring (rather high). The third is interaction with the GRC tool itself, covering AI-based GRC assistants and chatbot-like interfaces (both rated very high criticality as critical components of user experience and future usability).

In terms of current AI capability benchmarking, ServiceNow is best-in-class in terms of overall AI functionality. Riskonnect stands out for its advanced AI-driven simulation module offering multi-modal simulations across cyber and supply-chain scenarios, alongside summarization and remediation plan generation. Riskonnect's new AI governance suite, launched in July 2025, incorporates built-in regulatory frameworks covering the EU AI Act, GDPR, ISO 42001, and NIST AI RMF, positioning the company to capture regulatory-driven demand as the EU AI Act compliance deadline approaches.

Growth opportunities and structural risks

Three growth opportunities are identified in Dedale Intelligence's research. Continued M&A targeting up to three acquisitions per year remains the primary PE-driven growth strategy, with the GRC market remaining highly fragmented and offering ample room to acquire niche, domain-specific capabilities. AI governance demand, driven by the EU AI Act, creates a mandatory whitespace market for which Riskonnect's July 2025 AI governance suite positions it well. Channel partnerships, targeting 30% of revenues from indirect channels, provide a scalable path to mid-market penetration without proportionally increasing the direct sales team.

Three structural risks temper this outlook. M&A integration complexity has resulted in a fragmented architecture where acquired proprietary platforms remain bolt-on modules not natively integrated with the core Salesforce platform, limiting cross-module automation and making updates cumbersome. Mid-market competitive pressure from agile upmarket challengers threatens Riskonnect's ability to capture the underpenetrated mid-market segment. And high consultant turnover alongside a relatively limited internal R&D team (below 20% of headcount) creates knowledge gaps following key acquisitions.

How Dedale Intelligence researches the GRC software market

Dedale Intelligence's Private Market Leader 360 on Riskonnect is built on 20 primary expert interviews conducted across Riskonnect alumni, competitor executives at ServiceNow, OneTrust, and Workiva, and customers including the Head of Risk Management at Roche. The full report covers the complete product and market framework, the customer use case deep-dive on Roche, the go-to-market channel analysis, the full comparative assessment across eight key purchasing criteria, the AI capabilities benchmark across all GRC vendors, and the detailed growth and risk outlook.

Download the full Riskonnect Private Market Leader 360 report

To discuss how this analysis can support a GRC software investment thesis or go deeper on a specific vendor, segment, or competitive dynamic, contact the Dedale Intelligence team

Get started

Dedale is growing fast and we are continuously looking to widen our reach in the ecosystem. Let's connect!

Members

Join our Community of Industry Veterans that we collaborate with to conduct deep research

Join the community

Investors, Corporates, and M&A Advisors

Learn more about how collaborating with Dedale Intelligence could enhance your intelligence generation efforts

Request an introduction

Talents

We are looking for smart, hungry, humble individuals to join our fast growing team worldwide!

Join the team