
Overview

Product video
MetricStream's industry-leading ConnectedGRC platform enables organizations to Thrive on Risk by providing visibility and control across your organization. Only MetricStream combines deep domain expertise across GRC focus areas, with our in-depth product lines and a flexible SaaS-based integrated risk platform that equips you to make quick, consistent decisions across business units. With product flexibility, scalability and diversity in risk management tools, MetricStream's product suite can be used for a particular use-case and scaled up as requirements increase, to meet all your risk management requirements. Pricing and configuration options range to support mid-sized organizations to global enterprises.
ConnectedGRC Products:
-
BusinessGRC: Enterprise & Operational Risk, Business Continuity Management, Regulatory Compliance, Internal Audit, Third Party Risk, Risk Quantification. Empowers risk leaders across business units to automate processes associated with identifying, managing and converting risk to a strategic advantage.
-
CyberGRC - IT & Cyber Compliance, IT & Cyber Policy, IT & Cyber Risk, IT Vendor Risk, Cyber Risk Quantification. AI & Mobile. Manage IT & Cyber risks across the entire spectrum. Risk Assessments with pre-packaged risk scoring algorithms allow you quickly build Risk Heat Maps and obtain quantified risk ratings. An advanced GRC library allows you to quickly support IT Audits such as ISO 27001, NIST, SOC2 and many more. Integrations with AWS Audit Manager and several industry leading vulnerability scanners, ITSM solutions and content libraries, enable a single, consolidated and intelligent view of risks across the entire organization*.
*CyberGRC Workshop - for a limited time AWS Customers can take advantage of a 'fee waived' CyberGRC Workshop facilitated by MetricStream subject matter experts. Ensure you are building a high-value, sustainable cyber risk management program. What you get: You'll leave with a path to optimize your cyber risk management program, rationalize spend while reducing risk.
Highlights
- Ready to Use from Day 1 with pre-packaged frameworks and embedded AI-powered recommendations
- Fast Time to Value - 2 to 4 weeks to roll out and adopt
- Easy Expansion - Grows with you as you expand your business
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Security credentials achieved
(1)

Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/36 months |
|---|---|---|
CyberGRC - Prime | IT Risk Assessments, Reporting, Scoring and Centralized Management | $180,000.00 |
ESGRC - Prime | Environmental and Social Governance Solution | $180,000.00 |
CyberGRC Workshop | Fee Waived interactive workshop on optimizing your cyber risk program | $1.00 |
Vendor refund policy
Refund Policy is not applicable
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Please contact MetricStream Support by Email or Ticket on additional support support@metricstream.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Centralized risk libraries have streamlined audits and now highlight clunky workflows and upgrades
What is our primary use case?
My main use case for MetricStream is for audit and risk management.
What is most valuable?
We utilize MetricStream for audit and risk management by developing risk dashboarding and risk library development, standardizing libraries across enterprise organizations where risk management, corporate audit, and other business units can all utilize the same system of record and libraries.
MetricStream's shared system works well across all business units by standardizing similar risks and controls that exist across multiple business units. For instance, IT risk management and information security risk management have overlapping risks and controls, but we standardize them into one centralized risk and control.
The best features MetricStream offers take into consideration all the elements of a full governance, risk, and compliance system from both risk management to corporate audit, being able to develop applications within the solution that meet our needs, having a degree of full customization, as well as reporting, utilizing Infolets and Info Centers to establish reports that may not typically be out of the box and are definitely value-added.
MetricStream's customization and reporting have helped my work significantly. Compared to other systems, we have had the ability to essentially write SQL code that allows us to develop a report in real time that gives us insight into various different KPIs or KRIs leveraged across the organization. In comparison to other systems where you might be limited on what you can develop a separate report on, most of the fields and data captured within MetricStream have been reportable.
A favorite aspect I have regarding MetricStream is a love-hate relationship. The record level security sometimes backfires in terms of configuration, but usually it is relatively easy to work around.
MetricStream has positively impacted my organization by reducing silos across the organization. Having a centralized risk library maintained by risk management allows the corporate audit team to shave time off annual planning and enables more audit work to be done by ensuring validity of risks and controls in the system to support audit testing.
Since implementing MetricStream, audit teams have shaved about two weeks off of annual planning across various teams, allowing audit departments of about 140 auditors across maybe 10 teams to squeeze in 10 extra audits, one audit per each team, if not additional testing.
What needs improvement?
MetricStream can be improved in several areas. Sometimes the overall flow of the application can seem a bit clunky, based on feedback from clients.
From my understanding and what I have heard from developers within MetricStream during my deeper use of the application, the application seems to have been developed within silos, and the interaction of certain applications internally could definitely be improved in terms of the overall coding that exists between applications within the solution.
The only improvement I suggest for MetricStream is to gather a collaborative think tank from several of the largest clients and compile feedback to prioritize suggested enhancements from multiple organizations.
For how long have I used the solution?
I have been using MetricStream for a combined total of about six years.
What do I think about the stability of the solution?
MetricStream is mostly stable.
What do I think about the scalability of the solution?
MetricStream's scalability is adaptable, though the biggest issue I have encountered with clients has been around upgrades that require re-implementing customizations to the out-of-box solutions after significant upgrades.
How are customer service and support?
Customer support from MetricStream has been great. We had to engage with senior management from time to time, but they were responsive and quick in working through our issues.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Before MetricStream, we used Archer , Ideagen , and Thomson Reuters Paisley. We switched because MetricStream was much more robust.
What was our ROI?
I have not seen specific metrics on return on investment with MetricStream, outside of reducing silos and allowing time savings off of annual planning.
What's my experience with pricing, setup cost, and licensing?
In terms of pricing, setup cost, and licensing for MetricStream, we did run into issues with insufficient licensing, but the ability to acquire new licenses was relatively quick and effortless.
Which other solutions did I evaluate?
Before choosing MetricStream, we did evaluate other options depending on the client. We chose Archer for one installation and Thomson Reuters for another implementation.
What other advice do I have?
My advice for others looking into using MetricStream is to ensure collective representation from all business units that will be clients of the application across the organization. For example, in a bank, make sure you have audit, risk management, and other departments involved. I would rate this review a 7.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Limited customization has forced reliance on support but has provided structured audit dashboards
What is our primary use case?
My main use case for MetricStream was that I was a developer and I prepared templates for a client while also testing the UI platform for the client.
I can give a specific example of a template I prepared for a client. We had a task about what the client wanted, about the solution, about governance, about the tech template, and about SOX compliance. After we had some points, I created forms. It was basically something similar to Microsoft Forms. I prepared templates within MetricStream and took these blocks to create components together, something resembling Lego parts.
When I was a developer, this was a quite narrow template, and it consisted mostly of pieces from a constructor. I created one large form for the client. However, the main issue is that if a client needs something larger or more custom, there are no tools to change these blocks. Instead, I need to create a task for the developer team. Additionally, my customer team from MetricStream is located in India. A significant issue is with technical support because for the first month, they do not have any time and they do not want to change anything. Basically, I only have access to the UI and do not have access to the code base. However, for developers preparing solutions for clients who need to make a change in the code base, it would be much easier to change our own code rather than wait two or three months.
What is most valuable?
The best features MetricStream offers are the nice dashboards. However, I believe that the same system could be built much cheaper. With the help of one Python developer and one data engineer, it could be created more easily. To me, it appears to be mostly a marketing-driven product, functioning basically as a better package for something similar to Microsoft Forms.
Regarding features, I think it was nice when I knew what was needed, and when a client had seen the issue beforehand. MetricStream is something like an all-in-one solution where I do not need to write scripts or conduct audits. However, it may be a cheaper option when an audit is not necessary, such as a Microsoft audit or governance audit. It might be cheaper for two or three months, but when deeper research on a company is needed, it is not suitable. Essentially, it is an audit platform with a nice dashboard.
MetricStream has positively impacted my organization because we sell it in Europe. However, I implemented it at a couple of companies and I do not see any positive impact. For the client, they can see a nice platform with a friendly UI and a dashboard. For a developer, there is basically no added value because all these things can be obtained from scripts. Scripts can be written easily and are a really cheap alternative. I do not see any reason to buy MetricStream for a couple of thousand euros per month when scripts can be written with internal audit, cyber risk audit, or policy searching capabilities. Essentially, it is a business version of Grafana .
A specific example of how a client benefited from using MetricStream is that it is better for usability. If a client needs to check risk inside a cloud environment or internal environment, they have a nice dashboard with compliance status, open issues, and key risk information. If the management part is implemented, there is also a nice dashboard with compliance status ranging from zero to 100, control test requests and results, and a nice dashboard from the forms.
What needs improvement?
MetricStream can be improved in the area of developers. There are two parts of developers: those who prepare solutions for clients and those from India who support the application. The support part is terrible, rating about one out of ten. The support quality needs significant improvement.
For how long have I used the solution?
I have been using MetricStream for one to one and a half years.
What do I think about the stability of the solution?
MetricStream is stable, but if there is an issue, it will be complicated to resolve with the support team.
What do I think about the scalability of the solution?
The scalability of MetricStream is basically easy. I can create many forms, but there is a cost associated with it.
How are customer service and support?
The customer support of MetricStream is terrible.
Which solution did I use previously and why did I switch?
Before MetricStream, we used Databricks and scripts for audit checks and our cybersecurity implementation. However, the business decided to switch to MetricStream and started selling MetricStream to other clients. I do not think it was a good solution because after a couple of months or years, we came back to manual checks.
How was the initial setup?
I did not purchase MetricStream through the AWS Marketplace .
What about the implementation team?
My company had a business relationship with the vendor other than being a customer because I was a reseller at my old company. Currently, I do not use MetricStream in my current job.
What was our ROI?
I have not seen a return on investment.
What other advice do I have?
The advice I would give to others looking into using MetricStream is to not use MetricStream. I would rate this recommendation a four out of ten.