Riskonnect: A PE-Backed Leader in a €3 Billion GRC Software Market
Category Leader
Riskonnect: A PE-Backed Leader in a €3 Billion GRC Software Market
Dedale Intelligence's Private Market Leader 360 on Riskonnect covers the €3bn GRC software market, Riskonnect's M&A strategy, product suite, competitive positioning, and AI capabilities across governance, risk, and compliance.
Governance, risk, and compliance software has moved from a specialist IT category into a strategic priority for every large enterprise navigating a world of expanding regulatory complexity. Managing risk via spreadsheets is no longer viable. Disconnected compliance and audit functions create blind spots. And regulators, from GDPR to the EU AI Act, are raising the bar on what organizations must demonstrate and prove. GRC software has become the platform layer that holds this together.
Dedale Intelligence's Private Market Leader 360 on Riskonnect is built on 20 primary expert interviews conducted across Riskonnect alumni, competitor executives at ServiceNow, OneTrust, and Workiva, and customers including Roche. This article draws selectively on the key findings. The full analysis — including the complete comparative assessment across eight KPCs, the detailed AI capabilities benchmark, and the customer use case — is in the report: Download Now!
GRC software provides a centralized framework for organizations to manage policies, mitigate risks, and ensure compliance with regulations and internal standards. It integrates traditionally siloed functions — governance, risk management, and compliance — into a single platform, enabling a holistic view of an organization's risk and compliance posture.
Key functionalities typically span policy management, IT and cybersecurity risk, operational risk, third-party risk management (TPRM), data privacy, audit management, and ESG program oversight. Companies adopt GRC platforms when three conditions converge: managing complex risk landscapes via spreadsheets has become unscalable, disconnected departments create duplicate work and obscure the true risk profile, and an increasing volume of regulations demands automated tracking to ensure and prove compliance.
Source: Dedale Intelligence Analysis
The market: a €3 billion equipped market growing at 15% CAGR
The global GRC software market has a TAM of approximately €28 to €30bn in 2025, with 48% from Europe and 52% from the US. With an average equipment rate of approximately 10%, the resulting equipped market is approximately €3bn, expected to double to approximately €6bn by 2030, implying a 15% CAGR.
Growth is fueled by two structural forces. Regulatory pressure is intensifying, with rising demand for AI governance tools ahead of the EU AI Act. And mid-market demand is accelerating, with mid-market companies and SMBs expected to be the fastest-growing customer segment at a 21% CAGR from 2025 to 2030, compared to approximately 7% for large enterprises. GRC is increasingly a requirement across company sizes, not just for large enterprises with dedicated risk teams.
Dedale Intelligence covers GRC as part of its Horizontal Software expertise. For a broader view of the segment landscape, see the Horizontal Software coverage page.
Riskonnect: company snapshot
Founded in 2007 in the US by Bob Morrell, Riskonnect operates as a PE-backed, cloud-based SaaS GRC platform built on Salesforce. The company was acquired by Thoma Bravo in an LBO in 2017 and has since grown via an aggressive acquisition strategy.
Key facts from the PDF:
1,014 FTEs as of November 2025
Revenue of $231m in FY2024
Revenue split: 70% software, 30% services
Geography: approximately 56% US, approximately 44% international
CEO since 2018: Jim Wetekamp, previously CEO of BravoSolution (2008 to 2018)
The acquisition strategy has been deliberate and targeted: expanding from Riskonnect's historical strength in insurable risk management into core GRC, ESG, business continuity, and geographic reach in Europe and APAC.
Source: Dedale Intelligence Analysis
Product portfolio: four categories, one Salesforce backbone
Riskonnect's platform covers four product categories. Core GRC, which accounts for approximately 50% of revenue, includes Enterprise Risk Management, TPRM, Compliance, and Audit modules, centralizing risk and compliance data for board-level reporting. Insurable Risk, via its RIMS and claims management modules, manages insurable risk data, claims intake, and insurance program administration, and is Riskonnect's historical competitive strength particularly in financial services. ESG and Healthcare together account for approximately 35% of revenue, with the ESG module (formerly ICIX) covering GHG emissions and supplier audits, and the Healthcare GRC module providing patient safety and provider quality workflows. Business Continuity and Resilience (formerly Castellan) accounts for approximately 15% of revenue.
Pricing is modular and calculated primarily per concurrent user. ACV ranges from approximately $70k to $100k for mid-market companies and from approximately $150,000 to $300,000 for enterprise clients. Contracts are typically three to five years.
Riskonnect's sweet spot is upper mid-market and enterprise clients with complex, multi-entity risk exposure requiring centralized, cross-functional risk management and continuous assurance. Enterprise customers are defined as organizations generating over $1bn in annual revenue. The company has a particularly strong position in insurance and solid exposure across healthcare, retail, financial services, transportation, defense, and manufacturing.
GRC purchase decisions are committee-driven and C-suite sponsored. The primary decision makers are C-level executives in Risk, Compliance, and Legal functions, followed by the Board. The specific stakeholder varies by module: CISO and CTO for IT risk and cybersecurity, CPO and CDO for data privacy, CRO and CCO for risk and compliance management, CFO and CLO for transaction risk, and the COO for business continuity.
Satisfaction scores from Dedale Intelligence's primary research sit at approximately 8 to 9 out of 10, reflecting broad and deep features and strong service. The primary friction points are relatively high cost and complexity for mid-market buyers, and M&A integration complexity where acquired modules remain technically separate from the core Salesforce architecture.
Competitive dynamics: a concentrated enterprise tier, a fragmented mid-market
The enterprise GRC market is served by a small group of international platform vendors. Riskonnect's primary competitors include Archer (US-based legacy leader with strong IT risk capabilities), ServiceNow (originally an ITSM platform that added GRC, with best-in-class workflow automation and modern UI), and MetricStream (US-based legacy GRC vendor with strong IT risk, TPRM, and audit capabilities). In the enterprise tier, Riskonnect is considered a top-tier player, especially in insurance, with broad functionality well aligned to complex GRC requirements.
Additional competition comes from Navex (ethics and whistleblower solutions, approximately $293m revenue in 2025), AuditBoard (modern GRC focused on audit and compliance for agile teams, currently serving 40% of the Fortune 500), Diligent (governance specialist, serving 65% of the Fortune 1000), and Workiva (financial reporting, ESG, and GRC for finance and audit teams, approximately €740m revenue in 2024).
Riskonnect's competitive weakness sits in the mid-market, where the requirement for lengthy and expensive customizations creates a weaker right-to-win, and where agile upmarket challengers including Drata, Vanta, and Hyperproof are gaining ground by offering lighter, more user-friendly alternatives.
Source: Dedale Intelligence Analysis
AI in GRC: three areas of transformation
AI has the potential to reshape GRC across three functional areas, each with different criticality profiles according to Dedale Intelligence's assessment.
The first is AI-based real-time risk management, covering AI-powered control monitoring (very high criticality), predictive risk scoring (rather high), and simulation and scenario analysis (medium). The second is AI-powered compliance, covering AI-based evidence gathering (very high criticality), regulatory-driven controls creation (medium), and regulatory change monitoring (rather high). The third is interaction with the GRC tool itself, covering AI-based GRC assistants and chatbot-like interfaces (both rated very high criticality as critical components of user experience and future usability).
In terms of current AI capability benchmarking, ServiceNow is best-in-class in terms of overall AI functionality. Riskonnect stands out for its advanced AI-driven simulation module offering multi-modal simulations across cyber and supply-chain scenarios, alongside summarization and remediation plan generation. Riskonnect's new AI governance suite, launched in July 2025, incorporates built-in regulatory frameworks covering the EU AI Act, GDPR, ISO 42001, and NIST AI RMF, positioning the company to capture regulatory-driven demand as the EU AI Act compliance deadline approaches.
Growth opportunities and structural risks
Three growth opportunities are identified in Dedale Intelligence's research. Continued M&A targeting up to three acquisitions per year remains the primary PE-driven growth strategy, with the GRC market remaining highly fragmented and offering ample room to acquire niche, domain-specific capabilities. AI governance demand, driven by the EU AI Act, creates a mandatory whitespace market for which Riskonnect's July 2025 AI governance suite positions it well. Channel partnerships, targeting 30% of revenues from indirect channels, provide a scalable path to mid-market penetration without proportionally increasing the direct sales team.
Three structural risks temper this outlook. M&A integration complexity has resulted in a fragmented architecture where acquired proprietary platforms remain bolt-on modules not natively integrated with the core Salesforce platform, limiting cross-module automation and making updates cumbersome. Mid-market competitive pressure from agile upmarket challengers threatens Riskonnect's ability to capture the underpenetrated mid-market segment. And high consultant turnover alongside a relatively limited internal R&D team (below 20% of headcount) creates knowledge gaps following key acquisitions.
How Dedale Intelligence researches the GRC software market
Dedale Intelligence's Private Market Leader 360 on Riskonnect is built on 20 primary expert interviews conducted across Riskonnect alumni, competitor executives at ServiceNow, OneTrust, and Workiva, and customers including the Head of Risk Management at Roche. The full report covers the complete product and market framework, the customer use case deep-dive on Roche, the go-to-market channel analysis, the full comparative assessment across eight key purchasing criteria, the AI capabilities benchmark across all GRC vendors, and the detailed growth and risk outlook.
To discuss how this analysis can support a GRC software investment thesis or go deeper on a specific vendor, segment, or competitive dynamic, contact the Dedale Intelligence team