# OneTrust Tech Risk &amp; Compliance Reviews
**Vendor:** OneTrust  
**Category:** [Security Compliance Software](https://www.g2.com/categories/security-compliance)  
**Average Rating:** 4.6/5.0  
**Total Reviews:** 108
## About OneTrust Tech Risk &amp; Compliance
OneTrust&#39;s Tech Risk &amp; Compliance solution simplifies compliance and effectively manage risks. You can scale your resources and optimize your risk and compliance lifecycle by automating governance with business-ready content, guidance, and mapping. Simplify business collaboration by turning complex regulations into simple, actionable tasks that fit into your existing processes, and ensure continuous compliance. You can also mature your risk program and contextualize risk across the business to monitor over time, educate stakeholders, report to leadership, and prioritize action. Tech Risk and Compliance includes Compliance Automation and IT &amp; Risk Management tools. Compliance Automation scales your resources while optimizing compliance processes to efficiently scope, manage, and communicate your compliance posture, empowering InfoSec and IT Compliance professionals to automate regulatory guidance, reinforce program governance, and maintain audit readiness. With Compliance Automation you can: -Simplify business collaboration to streamline compliance workflows -Deploy pre-built integrations to automate evidence collection -Collect once, comply many with 50+ ready-to-use frameworks IT Risk Management allows you to proactively identify and mitigate risk, streamline data collection, and map risk relationships to assess and quantify risk across your IT and business ecosystem. Identify risk across complex IT ecosystems by discovering information systems vulnerabilities and cybersecurity risks across an inventory of assets, processes, and vendors. Reflect the interconnected nature of how systems, data, and risk flow throughout your business to monitor changes over time. Standardize and quantify risk with context by balancing qualitative and quantitative metrics with a scalable risk methodology that can mature from a standard matrix to automated calculations to inform risk mitigation prioritization without losing critical business context. You can enhance risk ownership across the business through automation of key enterprise risk management activities such as assessments and control management to effectively engage the business, collect information, evaluate impact, and execute remediation strategies. 



## OneTrust Tech Risk &amp; Compliance Pros & Cons
**What users like:**

- Users find OneTrust Tech Risk &amp; Compliance to be an **intuitive and user-friendly platform** , enhancing efficiency in risk management and compliance. (13 reviews)
- Users praise the **powerful automation features** of OneTrust Tech Risk &amp; Compliance, streamlining workflows and enhancing efficiency. (10 reviews)
- Users value the **automation of compliance** in OneTrust Tech Risk &amp; Compliance, enhancing efficiency and transparency in risk management. (9 reviews)
- Users appreciate the **centralized platform for risk and compliance management** , enhancing efficiency and accountability in tracking. (9 reviews)
- Users appreciate the **centralized platform** of OneTrust Tech Risk &amp; Compliance, enhancing efficiency and visibility in risk management. (7 reviews)
- Users value the **time-saving automation** and reporting features of OneTrust Tech Risk &amp; Compliance for efficient daily management. (7 reviews)
- Workflow Efficiency (7 reviews)
- Users value the **compliance simplification** offered by OneTrust, enhancing efficiency in managing risks and regulations seamlessly. (6 reviews)
- Efficiency (6 reviews)
- Integrations (6 reviews)

**What users dislike:**

- Users find the **complex implementation** of OneTrust Tech Risk &amp; Compliance challenging and time-consuming, especially for newcomers. (6 reviews)
- Users find the **difficult setup** of OneTrust Tech Risk &amp; Compliance time-consuming and challenging for newcomers, impacting usability. (6 reviews)
- Users find the **initial setup complex** and time-consuming, presenting challenges for both new and seasoned users. (5 reviews)
- Users find the **steep learning curve** of OneTrust Tech Risk &amp; Compliance to be complex and time-consuming for newcomers. (5 reviews)
- Users find the **learning difficulty** with OneTrust Tech Risk &amp; Compliance to be significant, hindering effective use and onboarding. (5 reviews)
- Users find the **dashboard interface complex** , requiring more time to navigate and understand effectively. (5 reviews)
- Users struggle with **difficult customization** in OneTrust Tech Risk &amp; Compliance, finding it complex and limiting for their needs. (4 reviews)
- Expensive (4 reviews)
- Pricing Issues (4 reviews)
- Slow Loading (4 reviews)

## OneTrust Tech Risk &amp; Compliance Reviews
  ### 1. The best GRC Product on the Market

**Rating:** 5.0/5.0 stars

**Reviewed by:** Chinua K. | Security Operations Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 24, 2023

**What do you like best about OneTrust Tech Risk & Compliance?**

OneTrust offers different modules that can help automate several GRC tasks, such as third-party risk management, asset management, etc. The application is very easy to use and makes our compliance management much easier

**What do you dislike about OneTrust Tech Risk & Compliance?**

The dashboard UI needs a refresh and the price is a bit high compared to similar products 

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Automating various GRC processes such as Enterpise Risk Management, Incident Management, Access Control Reviews,  3rd Party Risk Management, Asset Management etc

  ### 2. Powerful Automation, But Setup Challenges

**Rating:** 4.5/5.0 stars

**Reviewed by:** SONIA G. | assetent manager

**Reviewed Date:** November 20, 2025

**What do you like best about OneTrust Tech Risk & Compliance?**

I love OneTrust Tech Risk & Compliance for its powerful automation capabilities that significantly reduce the effort and time needed to manage workflows like handling Data Subject Requests (DSRs) and tracking controls. The user-friendly interface is another aspect that I appreciate, as it facilitates easier interaction and navigation through the platform, making complex tasks less daunting. Additionally, the centralized single-dashboard approach to risk and compliance management is extremely beneficial, as it consolidates everything into one place, increasing visibility and streamlining my processes across IT systems and vendors. This integration enables me to manage risks and compliance efficiently, while also simplifying data regulations and audit efforts.

**What do you dislike about OneTrust Tech Risk & Compliance?**

I find the initial setup of OneTrust Tech Risk & Compliance to be complex and challenging, which requires considerable time and effort. The platform also has a steep learning curve, making it daunting for newcomers. Additionally, the reporting and customization options are limited, restricting my ability to tailor outputs to specific needs. Inconsistent customer support is another drawback, as it can delay problem resolution and make the user experience less reliable.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

I use OneTrust Tech Risk & Compliance to automate workflows for risk and compliance management, saving time and effort while managing complex data regulations and mitigating risks across tech stacks efficiently.

  ### 3. Powerful Compliance Tool, But a Steep Learning Curve

**Rating:** 5.0/5.0 stars

**Reviewed by:** Sahana R. | Decision Scientist, Enterprise (> 1000 emp.)

**Reviewed Date:** November 19, 2025

**What do you like best about OneTrust Tech Risk & Compliance?**

I use OneTrust Tech Risk & Compliance to great effect in managing IT and Security risks while maintaining GDPR compliance. It allows for the automation of compliance across multiple frameworks and consolidates workflows into a centralized, collaborative platform. This centralized approach significantly enhances efficiency and transparency in risk management. The software excels in providing real-time dashboards and automated workflows, which simplify tracking and collaboration, making it an indispensable tool for ensuring audit-readiness and maintaining a clear view of our organization's risk posture. Furthermore, the policy management features are invaluable, saving time and ensuring comprehensive policy oversight. The ability to manage everything from one platform enhances operational efficiency, making OneTrust Tech Risk & Compliance a powerful asset. Overall, the platform not only streamlines risk and compliance processes but also ensures our risk management efforts are effective and transparent. It’s a comprehensive solution that I highly recommend to any team looking to strengthen its IT risk management, compliance automation, and policy oversight.

**What do you dislike about OneTrust Tech Risk & Compliance?**

I find that OneTrust Tech Risk & Compliance has a steep learning curve, which can make getting started with the platform somewhat daunting, especially when setting up advanced features. Additionally, configuring frameworks, workflows, and policies requires careful planning and learning time. The initial setup, while manageable, is moderately challenging and complex without guidance and support. Moreover, the cost of the platform can be prohibitive for smaller teams, making it less accessible unless there are ample resources dedicated to its adoption and use.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

I use OneTrust Tech Risk & Compliance to centralize IT and security risk management, automate compliance across frameworks, and maintain a clear view of risk posture, making risk management more efficient and transparent.

  ### 4. Streamlined Approach to Tech Risk and Compliance

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Education Management | Enterprise (> 1000 emp.)

**Reviewed Date:** February 17, 2026

**What do you like best about OneTrust Tech Risk & Compliance?**

What I like best about OneTrust Tech Risk and Compliance is how it brings risk and compliance management into one centralised platform, making tracking and monitoring much easier. The workflows are easy to use and the dashboards provide clear visibility, which helps improve efficiency and accountability.

**What do you dislike about OneTrust Tech Risk & Compliance?**

Some configurations and initial setup can be complex and time-consuming.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

OneTrust addresses the challenge of managing risk and compliance in a centralised, well-organised way, rather than relying on manual tracking. It improves visibility, saves time through automation, and makes it easier to monitor controls and track compliance status efficiently.

  ### 5. One of the leading GRC product among competitors

**Rating:** 5.0/5.0 stars

**Reviewed by:** piyush m. | Senior Manager, Enterprise (> 1000 emp.)

**Reviewed Date:** October 25, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

I have seen it has introduced AI capabilities in the platform - including features like automated risk assessments and evidence collection. It has also added prebuilt integration connectors in the platform.

**What do you dislike about OneTrust Tech Risk & Compliance?**

Pricing is still an issue. Apart from pricing one trust team can work on improvement of platform performanace and responsiveness.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

This product is a GRC enabler for us. With the help of this tool we are completing regulatory and compliance obligations in a timely manner. It is saving our time, efforts and cost in completing these obligations.

  ### 6. Effortless Risk Tracking with Powerful Automation

**Rating:** 5.0/5.0 stars

**Reviewed by:** Parbat S. | Compliances Executive, Mid-Market (51-1000 emp.)

**Reviewed Date:** November 19, 2025

**What do you like best about OneTrust Tech Risk & Compliance?**

I like that One Trust Risk & Compliance makes risk tracking simple and organized. The workflows, dashboards and automation save time and give clear view of our overall risk posture.

**What do you dislike about OneTrust Tech Risk & Compliance?**

Even though it helps keep things organized, some part of the platform can be slow or not as responsive as expected. Occasional tag and loading times make certain tasks take longer than they should.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

It helps centralize risk assessments, track issues and maintain compliance in one place. This reduces manual work and makes it easier to stay aligned with regulatory requirements.

  ### 7. Effective Risk Management, but Dashboard Needs Simplifying

**Rating:** 5.0/5.0 stars

**Reviewed by:** Manish  R. | IT Security Leader, Enterprise (> 1000 emp.)

**Reviewed Date:** October 22, 2025

**What do you like best about OneTrust Tech Risk & Compliance?**

Effectiveness in risk management and automated framework compliance

**What do you dislike about OneTrust Tech Risk & Compliance?**

Risk dashboard is bit complex and can be more user friendly

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Streamlined business risk collaboration and gained Enterprise wide risk awareness

  ### 8. Scalable Solution good for Growing Organizations

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** December 16, 2025

**What do you like best about OneTrust Tech Risk & Compliance?**

Works well for both mid-sized organizations and large enterprises. The Modular approach for scalability lets you start small and expand as needed.

**What do you dislike about OneTrust Tech Risk & Compliance?**

For large-scale deployments, users sometimes report slow load times or lag when handling big data sets.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Connects with tools like ServiceNow, Jira, and cloud platforms, enabling seamless workflows.
Helps unify operational GRC processes with IT operations.

  ### 9. Solid Compliance Platform

**Rating:** 5.0/5.0 stars

**Reviewed by:** Brittany W. | Guest Relations Manager, Small-Business (50 or fewer emp.)

**Reviewed Date:** April 08, 2025

**What do you like best about OneTrust Tech Risk & Compliance?**

user-friendly platform for managing privacy, and compliance. Strong reporting tools.

**What do you dislike about OneTrust Tech Risk & Compliance?**

the setup can be time-consuming, especially for new users. Some modules feel disconnected.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

streamlines our risk and compliance workflows, reduces manual effort, and improves visibility across third-party and internal systems. It helps us stay audit-ready and aligned with privacy regulations like CCPA.

  ### 10. Good about message and working normaly and high loading

**Rating:** 3.5/5.0 stars

**Reviewed by:** Vijay M. | QA, Small-Business (50 or fewer emp.)

**Reviewed Date:** April 01, 2025

**What do you like best about OneTrust Tech Risk & Compliance?**

platform is user-friendly, with strong automation and reporting features and is good in daily uses. Implementation is good if you understand in good.

**What do you dislike about OneTrust Tech Risk & Compliance?**

Complex for in some days after started uses. Nevigation filed is required for more time to understand more this . Also customer support not timely. Not easy to integrate.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

helps in managing regulatory compliance, reducing manual effort through automation, and improving risk visibility.
Vendor risk management features help assess third-party risks efficiently. Overall, it enhances security, simplifies governance, and improves operational efficiency.

  ### 11. OneTrust is very reliable and provides great security

**Rating:** 4.5/5.0 stars

**Reviewed by:** Dhaval M. | Associate, Electrical Engineer - Power/Analog/Controls (PAC), Enterprise (> 1000 emp.)

**Reviewed Date:** April 01, 2025

**What do you like best about OneTrust Tech Risk & Compliance?**

I love how it is easy to manage and use for our computers. The increase security ensures that our data remains safe from leaks.

**What do you dislike about OneTrust Tech Risk & Compliance?**

I dislike that, at times, the software has some connection issues, due to our work location, However, the program works very well overall.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

The software is making sure that we can keep our information secure on our computers and technology. It helps me rest easy knowing that my data is kept safe.

  ### 12. Best in privacy, risk , compliance management

**Rating:** 4.5/5.0 stars

**Reviewed by:** Amita M. | Application lead, Computer Software, Enterprise (> 1000 emp.)

**Reviewed Date:** April 13, 2025

**What do you like best about OneTrust Tech Risk & Compliance?**

it covers majorly all global regulations , more than 50 + regulations and automated workflows reduces manual intervention

**What do you dislike about OneTrust Tech Risk & Compliance?**

It cant be used by any novice and requires training to gain maximum utilization of the software

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

i gave used for vendor risk management, the automated reminders saved time for regular follow ups and assessment

  ### 13. Security product

**Rating:** 5.0/5.0 stars

**Reviewed by:** Mohammed S. | Network Security Engineer, Telecommunications, Mid-Market (51-1000 emp.)

**Reviewed Date:** April 15, 2025

**What do you like best about OneTrust Tech Risk & Compliance?**

A great solution to analysis the events and logs and help the government to

**What do you dislike about OneTrust Tech Risk & Compliance?**

It has a lot of problems like cost, complex for the new users and slower in process

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Help me to handle a lot of incidents occur in my network in all branches and manage it

  ### 14. OneTrust is the only GRC tool that works!

**Rating:** 5.0/5.0 stars

**Reviewed by:** Gerald P. | Governance Risk and Compliance Coordinator, Enterprise (> 1000 emp.)

**Reviewed Date:** September 11, 2024

**What do you like best about OneTrust Tech Risk & Compliance?**

I personally enjoy how customizable OneTrust is when tailoring it to the needs of your organization and how thier UI makes it simple navigate between different modules. The platform itself has a ton of resources to answer any questions that you have when it comes to implementation and troubleshooting which really helps when starting newer projects by having that guidence there for support to make things easier to integrate into your project needs.

**What do you dislike about OneTrust Tech Risk & Compliance?**

The only downside I have about the product is the fact that in many cases when generating reports, the reports really seem to lack depth when it comes to showcasing the full scope of your project and the platform itself doesn't often allow much room to customize report to display the intended data that was collected.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

OneTrust helps my company in categorizing our various resources when it comes to thinks like tracking assest owners and processing third party vendor assessments and privacy request. The benefit from the product is that through the use of automatic notifications our company is able to automate the processing for a speedier completion rate.

  ### 15. Automate my day 🥰

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Security and Investigations | Enterprise (> 1000 emp.)

**Reviewed Date:** April 01, 2025

**What do you like best about OneTrust Tech Risk & Compliance?**

Onetrust makes it so easy to fly through our compliance processes. Snap of a finger pooof

**What do you dislike about OneTrust Tech Risk & Compliance?**

Doesn’t make the verification calls that are needed for us

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

We are able to automate our ccpa and other functions like that almost immediately.

  ### 16. Onetrust GRC solution is great Automation tool to reduce,mitigate risks

**Rating:** 4.0/5.0 stars

**Reviewed by:** Nikhil D. | Senior Information Security Compliance Analyst, Small-Business (50 or fewer emp.)

**Reviewed Date:** October 17, 2024

**What do you like best about OneTrust Tech Risk & Compliance?**

Onetrust GRC solution is great Automation tool to reduce,mitigate risks and provides categorywise distribution of different risks and also streamlines policy,risk and control processes with workflows

**What do you dislike about OneTrust Tech Risk & Compliance?**

need to improve dashboards user interface

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

This emarks in our certification journey smoother and provides ease way to present to the board members.

  ### 17. Complete governance, risk & compliance tool

**Rating:** 5.0/5.0 stars

**Reviewed by:** Yash  S. | Quality Assurance Officer, Small-Business (50 or fewer emp.)

**Reviewed Date:** January 24, 2024

**What do you like best about OneTrust Tech Risk & Compliance?**

Onetrust GRC is No. One in ease of use. Best part is that it help in frequent audit trials as I am in a Pharma company so audits are anytime. Many features like security check for vendors, management of vendor, IT security etc are all in one place. Safety of vulnarable data. This software is used regularly for Quality assurance and security assurance purpose. Its implementation is also easy & can be integarted with other software to meet the compliance  requirment of company.
custmer support & regular updates are best thing in this spftware

**What do you dislike about OneTrust Tech Risk & Compliance?**

As it have many features and a wide interphase it also have bugs. Which makes it slow sometimes. However this can be considerd as okey for a large application like this.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

I am using it for IT Quality assurance & security compliance.
It helps me during audits and regulatory inspections. Its one click audit trial makes hassle-free audits without any other explanations and less documents.

  ### 18. OneTrust GRC and Security Assurance Cloud: A Powerful and  Comprehensive  Security Solution.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Naveen K. | Security  Analyst  | SOC, Mid-Market (51-1000 emp.)

**Reviewed Date:** October 12, 2023

**What do you like best about OneTrust Tech Risk & Compliance?**

I like the best  in OneTrust GRC and Security Assurance Cloud  , it is cloud-based platform ,integrated solution which gives us complete view of organization's  GRC and  security paosture and it is scalable.

**What do you dislike about OneTrust Tech Risk & Compliance?**

My only dislike about OneTrust GRC and Security Assurance Cloud is that it has limited customization options.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

OneTrust GRC and Security Assurance Cloud hepls us to improve our security posture and reduce the risk posture.

  ### 19. A real disappointment since onetrust took over

**Rating:** 0.5/5.0 stars

**Reviewed by:** Verified User in Financial Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** May 05, 2023

**What do you like best about OneTrust Tech Risk & Compliance?**

You get boilerplate policies you can work with and revisions, approvals and commeting on drafts etc and a few integrations to connect for evidence collection.

**What do you dislike about OneTrust Tech Risk & Compliance?**

I am writing this review to express my disappointment since onetrust acquired tugboat. As a customer who has been using this product for some time now, I have noticed a significant decline in the quality of service and feature delivery.

Firstly, I have noticed that the company seems to be focusing more on merging into onetrust than actually delivering value to their customers. This has resulted in fewer features being delivered to the customers. As a result, I have noticed a decrease in the relevance and effectiveness of the product in meeting my needs.

Secondly, the support experience has been extremely poor since the company switched to a separate support portal. It has become increasingly difficult to get in touch with the support team, it is also a separate account that is not the same. 

Furthermore, I was recently assigned a new account manager without being informed, and I have not heard from them since the change which was a couple of months ago. This lack of communication and follow-up is unacceptable and has further added to my frustration with the product.

In addition, I have observed a fundamental flaw in the Google Workspace integration to automatically import users into groups. It seems that the team responsible for this integration does not fully understand the difference between a directory OU and a group as it can only sync the directory OU belonging of users. Although the system allows for syncing users from Google workspace to groups within the system, this is not a feasible solution as users can only belong to one OU in google workspace (and active directory for that mater) while they can belong to multiple groups in the system. This feature works fine for azure ad and okta but not for google workspace.

Besides this the UX experience of the product is very bad, you get lost all the time if you are not a product expert.

Overall, I was once confident in the relevant features that were being delivered by this product. However, the recent changes have left me disappointed and questioning the value of continuing to use this product. I hope that the company takes the necessary steps to address these issues and focus more on delivering value to their customers.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

To help out to make compliance work easier by getting templates and some simple integrations for collecting the evidences but allot is not completed

  ### 20. It such a awesome thing I have ever seen

**Rating:** 5.0/5.0 stars

**Reviewed by:** UTSAV A. | Network Lead, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 29, 2024

**What do you like best about OneTrust Tech Risk & Compliance?**

It is very useful platform to secure our services.

**What do you dislike about OneTrust Tech Risk & Compliance?**

Nothing as such I have seen while using it

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

It very simple to use and provide everything on single pane of glass

  ### 21. Compliance and Risk Management in Comprehensive package.

**Rating:** 3.5/5.0 stars

**Reviewed by:** Gowtham S. | Senior Quality Assurance Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** October 26, 2023

**What do you like best about OneTrust Tech Risk & Compliance?**

Compliance Management ,Risk Management ,Workflow and Task Management , Easily customizable.
Easy Integeration, Vulnerability and Monitoring.
Audit trails  of the tool and customer support.

**What do you dislike about OneTrust Tech Risk & Compliance?**

the tool is quite complicated and the learning for this tool is very high time. Limited available resources to learn. 
This tool is quiet expensive as well.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

The platform facilitates risk assessment and management, enabling organizations to identify, assess, and mitigate risks effectively. This is particularly valuable in today's complex regulatory environment.

  ### 22. The best GRC  in the market!!

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Education Management | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 26, 2023

**What do you like best about OneTrust Tech Risk & Compliance?**

Very powerful data privacy tool. It has got a user friendly interface, all the questionaaire based assesment can be taken effortlessly. The accuracy is another feature that I like about One Trust.Privacy management functions can be integrated into a single platform with more automation. It can be easily managed and maintained and setup is also easy

**What do you dislike about OneTrust Tech Risk & Compliance?**

Some features can be implemented , like compatbility of different local languages and options to translate procedures and policies, so that any kind of people can makeuse of the platform maximum

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

All features are organized well. It helps to effectively manage the risk by third parties, with a lot of automation features reducing the manual input

  ### 23. Flexible GRC and Security Assurance Cloud tool by OneTrust

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Financial Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 26, 2023

**What do you like best about OneTrust Tech Risk & Compliance?**

OneTrust GRC and security Assurance cloud helping us automate our compliance and risk management through its highly efficient workflows and advanced features to manage and automate regular audit processes. It is quite easier to setup without much technical knowledge.

**What do you dislike about OneTrust Tech Risk & Compliance?**

Administrators should have an understanding of different compliances and regulations to setup the policies and procedures into the OneTrust tool. Support services should be improved further.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

It is very flexible tool which helped us in automating our auditing process in a very easier and faster way. We able to conduct lot of external and internal audits with help of OneTrust GRC tool within very shot span of time.

  ### 24. Best support team ever I found we needed lot of help in integration

**Rating:** 5.0/5.0 stars

**Reviewed by:** Snehha R. | Chief Operating Officer, Small-Business (50 or fewer emp.)

**Reviewed Date:** October 26, 2023

**What do you like best about OneTrust Tech Risk & Compliance?**

This was first time where we used risk management tools for our firm and their support team is excellent

**What do you dislike about OneTrust Tech Risk & Compliance?**

nothung as such only if pricing can be less that would be great

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Helped us with risk management and have a detail internal audit so we can proceed towards right direction

  ### 25. Excellent Resource for Security

**Rating:** 4.5/5.0 stars

**Reviewed by:** Jeneen R. | Case Investigator, Mid-Market (51-1000 emp.)

**Reviewed Date:** November 11, 2023

**What do you like best about OneTrust Tech Risk & Compliance?**

I like how easy it is for data mapping and incident responses.

**What do you dislike about OneTrust Tech Risk & Compliance?**

Sometimes the system can slow down and get overwhelmed when too many things are open in the background.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

This software makes it easier for companies to prepare for audits.

  ### 26. Comprehensive and Very good security Feature

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Manufacturing | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 26, 2023

**What do you like best about OneTrust Tech Risk & Compliance?**

It provides a comprehensive and user-friendly solution for managing governance, risk, and compliance and it has good security features and intuitive interface.

**What do you dislike about OneTrust Tech Risk & Compliance?**

the cost associated with its comprehensive suite of tools could be a drawback for smaller businesses with budget constraints.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

This has significantly reduced the risk of non-compliance and data breaches, ultimately benefiting the company's reputation and customer trust.

  ### 27. Logic based platform managment

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Automotive | Enterprise (> 1000 emp.)

**Reviewed Date:** September 28, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

What I like about OneTrust is its automation aspect front and center. From being able to build out risk flags, and generate remediation items, to reporting and reassessments. OneTrust is built to help you automate most of those manual tasks for Vendor Risk assessments. Our organization has received significant positive feedback about the OneTrust tool.

**What do you dislike about OneTrust Tech Risk & Compliance?**

I would say that the engagements feature is not as robust as we would like. We leverage tracking the vendor used by engagement types; this feature is not as rich as I would like it to be.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

OneTrust is helping us solve our Vendor Risk Monitoring and evaluation part. Instead of using an excel spreadsheet with lots of updates and formulas, we can use OneTrust to help us Track and manage our growing third-party population and ensure that proper assessments and checks are completed.

  ### 28. Office Manager

**Rating:** 5.0/5.0 stars

**Reviewed by:** Brittany R. | Office Manager, Small-Business (50 or fewer emp.)

**Reviewed Date:** August 24, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

When I first started using Tugboat, I thought it was a little complex, but after a few months in the software, it is pretty helpful! As I am managing my team's tasks, I can easily see who completed tasks and who did not.

**What do you dislike about OneTrust Tech Risk & Compliance?**

I wish Tugboat had a feature to remind my SOC 2 team of their tasks and send individual reminders with what they have left to complete.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

It is greatly helping manage our SOC 2 compliance and our Security Awareness Training. Both are great to have in one place.

  ### 29. A compliance Accelerator

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Financial Services | Mid-Market (51-1000 emp.)

**Reviewed Date:** October 05, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

Good, guided and coherant approach to achieving and maintaining compliance to standards such as ISO 27001. Saves an enormous amount of time and effort in structuring and achieving the standard.

**What do you dislike about OneTrust Tech Risk & Compliance?**

Automation is good but not yet great, the risk module needs to have a standardised risk format i.e. there is a risk of X happening due to Y, the reporting and dashboards could be improved further to act as a more generic security and compliance management dashboard.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Automation of the compliance process for ISO 27001 (and later for other standards). Removing the legwork from collecting evidence and demonstrating compliance.

  ### 30. Making Security Assurance a Breeze

**Rating:** 4.5/5.0 stars

**Reviewed by:** Jack S. | Security Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** June 06, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

My favorite feature of TBL is the readiness projects. It provides a compartmentalized assessment for SOC, ISO, GDPR, etc. compliance tailored to your product or company.

**What do you dislike about OneTrust Tech Risk & Compliance?**

My division and the broader parent company are utilizing TBL. It took quite a bit of manual work to unlink similar policies and controls, duplicate where necessary, and map them to the correct readiness project. It'd be really nice if TBL enabled this level of segmentation out of the box.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

We are preparing to undergo our first ever SOC audit. The cost alone can be daunting let alone setting up a control framework and building a robust set of policies and procedures. TBL takes all of that stress and time away by providing the framework so we are able to focus on tailoring to our specific needs, start collecting evidence, and prepare for the audit.

**Official Response from Cheryl Rasmuson:**

> Hey Jack thank you for the review! Glad to hear you are enjoying the readiness projects and the custom security programs! If you are still having any trouble with the policies and controls, please reach out to us at support@tugboatlogic.com. If not, I will ensure that the feedback gets passed along to our product team!

  ### 31. Great experience with the Tugboat team

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Small-Business (50 or fewer emp.)

**Reviewed Date:** December 13, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

The team at Tugboat was very knowledgeable and helpful with all the questions that we had regarding the platform

**What do you dislike about OneTrust Tech Risk & Compliance?**

Too many tabs to click on when you are looking for something specific

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

It helps us receive our SOC 11 Type 1 certificate

  ### 32. Tugboat Helpful Tool for Saving Time on Information Security Questions and SOC2 certification

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Marketing and Advertising | Mid-Market (51-1000 emp.)

**Reviewed Date:** June 08, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

I like that we can repurpose previously answered questions via Tugboat's machine learning suggested answers.  Saves a lot of time with onerous InfoSec questions

**What do you dislike about OneTrust Tech Risk & Compliance?**

Tugboat could make the user interface a bit more intuitive so that it's easier to find what you're looking for.  It would be helpful if Tugboat added a capability to conduct video training and testing for behavioral things like employee Phishing avoidance.

**Recommendations to others considering OneTrust Tech Risk & Compliance:**

Tugboat logic is great for companies having lots of Information Security questionnaires

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Tugboat Logic saves all of our previous InfoSec questions and answers and uses machine learning to suggest answers to new InfoSec questions.  Most of the time the answers suggested are good so you can just one click to submit the answer to the new InfoSec questionnaire.

**Official Response from Cheryl Rasmuson:**

> Hi there and thank you for the review! We are currently working on optimizing our UI and customer journey and we would love to hear any feedback you have. Please feel free to reach out (marketing@tugboatlogic.com) and I'll make sure to get the feedback to the right people. 

  ### 33. Much needed clarity and direction

**Rating:** 5.0/5.0 stars

**Reviewed by:** David S. | Project Manager, Small-Business (50 or fewer emp.)

**Reviewed Date:** January 09, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

We were 2 years into developing our own information security process and found ourselves with a mess of borrowed policies and procedures and a set of controls that were not aligned with our organizational goals. We gave up on trying to hack together our security system and decided to work through a framework instead. We initially started down the path of HITRUST and realized after a year of implementation that the requirements needed by HITRUST did not align with the size of our company. We started down the path of SOC and wanted to leverage an existing set of tools and frameworks to help us along. The two vendors we looked at were Tugboat and Vanta. Both companies looked promising but Tugboat was the one that had the right pricing structure for our sized company.

We are 3 months into implementation and we like the following:
1. Policies and controls that more fit our organizational requirements.
2. Easy to read and updateable policies.
3. Easy to manage controls and evidence collection
4. Ability to collaborate with auditors.
5. Ability to manage security questionnaires with existing controls and evidence.
6. Automatic evidence collection with integrations with most of the application we already use.

**What do you dislike about OneTrust Tech Risk & Compliance?**

So far, we like everything we have seen.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

We are developing and managing our information security policy through Tugboat. Pretty big problem to have.

  ### 34. Excellent on-boarding, training and in depth coverage for our security audits.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Scott H. | DevOps Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** December 24, 2021

**What do you like best about OneTrust Tech Risk & Compliance?**

We were able to finally have an easy-to-use platform to start the journey of our security audits. TugBoat is thus far exactly what we were looking for and more, covering all of our security needs. TugBoat has made outlining the necessary steps to becoming SOC 2 compliant far more understandable and achievable.

**What do you dislike about OneTrust Tech Risk & Compliance?**

Currently, still new on the platform and I have nothing to voice in terms of dislikes. There are perhaps small interface problems that can be addressed, but the on-boarding and integration with our systems is going smoothly.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

We are trying to address our security needs and become SOC 2 Type 2 compliant. TugBoat allows us to prepare our policies and procedures along with the necessary evidence collection for a security audit. The platform has benefited us by making this undertaking less daunting and more manageable within a reasonable time frame. As well as ensuring we are continuously meeting our clients expectations in terms of security, and potentially allowing future security audits to go a lot smoother.

  ### 35. Tugboat Logic Review by JAM Direct Inc.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Matthew D. | Security Analyst, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 06, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

The platform makes working with auditors seamless and ultimately streamlines our SOC2 auditing process. Robyn and Jacqui are great resources to ensure we get the most out of the product.

**What do you dislike about OneTrust Tech Risk & Compliance?**

I have no complaints about the platform. I've seen the platform grow and change - getting used to change may take some adjusting but it is simply a part of the improvement process. The Tugboat team always encourages any feedback.

**Recommendations to others considering OneTrust Tech Risk & Compliance:**

We were recommended Tugboat by a trusted security reference, and we deemed Tugboat the best fit. We made the right choice.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

We use Tugboat for policy review and acceptance for our entire staff. We also use it for vendor management and assessment. One of Tugboat's best features is its audit project module. We use this to complete our annual SOC2 Type2 audit, and this module makes evidence collection and auditor collaboration seamless.

  ### 36. Easy to use tool

**Rating:** 3.5/5.0 stars

**Reviewed by:** Zoya A. | Account Executive, Mid-Market (51-1000 emp.)

**Reviewed Date:** October 18, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

Can easily answer risk questionnaires for vendor onboarding

**What do you dislike about OneTrust Tech Risk & Compliance?**

Collaboration features are limited (e.g., cannot tag an individual for them to be notified)

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Simplifies gathering of risk information from vendors

  ### 37. As simple to use as logging in

**Rating:** 5.0/5.0 stars

**Reviewed by:** Nic M. | Compliance Manager, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 13, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

Everything that would be needed was there for you the first time you logged in.  The policies and controls are clear, well linked, and ready for you to edit and submit evidence to.

**What do you dislike about OneTrust Tech Risk & Compliance?**

There's nothing to dislike.  But if I had to suggest something, it would be helpful if there were more resources available for HIPAA compliance.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Passing a SOC2 audit.  Tugboat Logic gives you the confidence to successfully do this without making you want to pull out your hair.  We had tried other platforms that were cumbersome and junky.  Would have saved ourselves a lot of frustration and money had we used Tugboat Logic in the first place.

  ### 38. A lot of help when trying to set up compliance

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Real Estate | Small-Business (50 or fewer emp.)

**Reviewed Date:** October 18, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

The workflows are already created and it makes it easy to configure the workstreams

**What do you dislike about OneTrust Tech Risk & Compliance?**

Stilll need some learning curve to be able to undrstand the tools.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Instead of having to come up with workflows to handle compliance related rquests, the workflows are already there

  ### 39. Used one trust for consent and preferences management by integrating with Okta

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Enterprise (> 1000 emp.)

**Reviewed Date:** October 19, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

The product supports the cloud first mentality and does support flexibility to implement custom requirements

**What do you dislike about OneTrust Tech Risk & Compliance?**

The interface is good but has room to be further enhanced

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Consent management 
preferences management
In line with compliance regulations like GDPR for instance, right to forget

  ### 40. Good working experience with Tugboat Logic products and their support team.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Ali N. | S, Mid-Market (51-1000 emp.)

**Reviewed Date:** June 07, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

Good working experience with Tugboat Logic products and their support team.

**What do you dislike about OneTrust Tech Risk & Compliance?**

You cannot search questions in your own created question bank.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Saving time and money.

**Official Response from Cheryl Rasmuson:**

> Hi Ali and thank you for the review! I've passed along the feedback concerning the question bank and search functions to our product team. 

  ### 41. Tugboat for Compliance

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Hospital & Health Care | Mid-Market (51-1000 emp.)

**Reviewed Date:** June 15, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

Tugboat has been a great resource for policy guidance.

**What do you dislike about OneTrust Tech Risk & Compliance?**

Takes a while getting used to navigating through all the features.

**Recommendations to others considering OneTrust Tech Risk & Compliance:**

Integration with Qualio (QMS)

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

The resources that Tugboat provides has been a great benefit to the organization.

**Official Response from Cheryl Rasmuson:**

> Thank you so much for your review. If you have any specific feedback on navigation and feature organization, we'd love to hear it as we are constantly in the process of improvement. Feel free to reach out to marketing@tugboatlogic.com at any time and we'll make sure you get in contact with the right people.

  ### 42. We use heavily Tugboat Logic to become SOC 2 certified

**Rating:** 5.0/5.0 stars

**Reviewed by:** Mykola S. | Head of Information Security, Mid-Market (51-1000 emp.)

**Reviewed Date:** August 31, 2021

**What do you like best about OneTrust Tech Risk & Compliance?**

The most helpful thing in Tugboat logic is integrations with other services for automatic evidence collection. And some integrations even allow to attach collected data to any evidence task which greatly simplifies preparaness for compliance. Risk register, project readiness, ease of auditor engagement, vendor management, privacy features and ability to get quickly support makes Tugboat Logic as a great service to achive compliance goals.

**What do you dislike about OneTrust Tech Risk & Compliance?**

Its hard to say I dislike something. Rather below points should be improved:
* On and offboarding review and approval need to be improved with adding bulk updates, ability to add custom description for particular access, etc
* Add support of SOC 2 Type I. On this moment platform is mainly focused on SOC 2 Type II with reminders and frequency for evidence collection

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Tugboat Logic helps to spend less time on becoming SOC 2/ISO27k compliant.

  ### 43. Everything you need or a GRC tool

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Small-Business (50 or fewer emp.)

**Reviewed Date:** May 24, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

Modular - allows you to pick and choose the pieces that are relevant to your business

**What do you dislike about OneTrust Tech Risk & Compliance?**

Because it is modular, some of the navigation can be a bit cumbersome

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Robust Security Awareness training platform that is constantly being upgraded to stay relevant. Data mapping automation

  ### 44. FinMain SOC2 Type 1 Audit

**Rating:** 5.0/5.0 stars

**Reviewed by:** Ray H. | Associate, Small-Business (50 or fewer emp.)

**Reviewed Date:** January 24, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

Simplifies tasks and provides helpful insights along the way. We were able to work with our Auditors throughout the Audit period, allowing them full access to request and evaluate the evidence provided.

**What do you dislike about OneTrust Tech Risk & Compliance?**

We were hoping to see additional integration offerings and updated policy templates with fewer typos.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Vendor Management
Security Questionnaires
SOC Audit (Type 1 & 2)

  ### 45. SOC2 audits are bearable with Tugboat

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Hospital & Health Care | Small-Business (50 or fewer emp.)

**Reviewed Date:** June 09, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

Audit coordination features, Azure integrations

**What do you dislike about OneTrust Tech Risk & Compliance?**

There are a few integrations (e.g. Salesforce) that would be helpful.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Managing Information Security projects, including SOC2 Type 1 and 2 audits

**Official Response from Cheryl Rasmuson:**

> Thank you for the review! I've made a note with our Product team about integrations, particularly salesforce, for you. 

  ### 46. Bit pticey!

**Rating:** 2.5/5.0 stars

**Reviewed by:** Verified User in Computer Software | Small-Business (50 or fewer emp.)

**Reviewed Date:** June 07, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

Tugboat Logic provides an efficient Workflow

**What do you dislike about OneTrust Tech Risk & Compliance?**

Tugboat Logic User Interface is too confusing

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Tugboat Logic is a nice project management tool for various compliance requirements

**Official Response from Cheryl Rasmuson:**

> Hi there and thank you for the review. I'm sorry to hear that the UI has been a problem, but the good news is we're in the process of updating it. If you have any feedback you'd like us to hear, please feel free to reach out to me at marketing@tugboatlogic.com and I'll ensure that it gets to the right people.

  ### 47. Amazing Customer service and super easy platform to navigate.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Caleb T. | It Administrator, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 24, 2022

**What do you like best about OneTrust Tech Risk & Compliance?**

I love how the platform allows my team to easily keep track of all of our security policies in one place.  We utilize there vendor assesment and auidt report gatherting.

**What do you dislike about OneTrust Tech Risk & Compliance?**

Sometimes there are too many options to choose from when creating an audit report or questionnaire. It can be an issue when cutting back on specific questions needed.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

We are utilizing tugboat to ensure our company can maintain our SOC2 compliance and certification.  Also, using it to track awareness training for specific policies.

  ### 48. With Tugboat Logic -SOC 2 Type 2s Are Possible in 90 Days with Minimal Impact on Entire Team

**Rating:** 5.0/5.0 stars

**Reviewed by:** Anthea R. | Founder, CEO, Small-Business (50 or fewer emp.)

**Reviewed Date:** June 08, 2021

**What do you like best about OneTrust Tech Risk & Compliance?**

I am a social worker by education and started a non profit organization to help youth in foster care achieve permanency through adoption.  We have a small team- and COVID 19 made that team even smaller.  Increasingly our customers want to know that the applications they leverage are SOC 2 Type 2 compliant.  We knew we had a responsibility to our customers/end users to do whatever it took to give them peace of mind, that our web based app meets and or exceeds the standards the AICPA has set forth. 

As the Founder and CEO,  I became the driver for the SOC 2 Type 2 Audit.  We had gone through a SOC 2 Type 1 in the year prior with a company that charged so much money with an end result consisting nothing more than  a pre-formated report and no way to continue tracking compliance to ready ourselves for a SOC 2 Type 2.   I believed there had to be something out there that could help us and I am so happy I found Tugboat Logic.  Tugboat Logic ensures you are set up for success continuously- and is so easy to use that we found an auditor who charged us 50% of what other auditors in this space charge.  In a timespan of about 90 days and with limited impact on my team- we had a SOC 2 Type 2 report completed. 

The process flow and the way Tugboat Logic connects policies to controls and evidence make organization a breeze. I love how it allows you to document employee training and onboarding/offboarding in a way that is tied to our evidence collection.  No more excel lists, files in Sharepoint- with Tugboat Logic, I can ensure our organization not only achieves SOC 2 Type 2 certification but maintains compliance throughout the year. Tugboat Logic helped us complete a SOC 2 Type 2 in 90 days. No we not only have an audit under our belt but we also have a tool that will make subsequent audits go even faster!

**What do you dislike about OneTrust Tech Risk & Compliance?**

I have no complaints at this time- this software changed my life!

**Recommendations to others considering OneTrust Tech Risk & Compliance:**

Do it! You won't regret making this investment.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

Maintaining compliance is so much easier when you have a central place that not only tracks it but allows you to provide evidence to support the organization's actions throughout the year.

  ### 49. Making a tough topic manageable and easy

**Rating:** 5.0/5.0 stars

**Reviewed by:** Sondra R. | Information Security & Compliance Officer, Mid-Market (51-1000 emp.)

**Reviewed Date:** May 18, 2021

**What do you like best about OneTrust Tech Risk & Compliance?**

I came to my company to create an information security program where there was no formal one. The goal was SOC2 certification. With a list of specific needs, I found that Tugboat Logic was the best option of the nearly dozen that I tried. It provided policy templates, which proved invaluable! It provided controls for each policy which I could take to my tech team and find the ways to implement them that fit with our business. It enabled easy evidence collection and sharing with the auditor. Overall, I can't imagine trying to create a from-scratch InfoSec program without it!

**What do you dislike about OneTrust Tech Risk & Compliance?**

A few user experience approaches aren't particularly intuitive for me, but my customer success contact is always immediately responsive to help me figure out how to get things done quickly.

**Recommendations to others considering OneTrust Tech Risk & Compliance:**

It truly makes compliance management simple and straightforward.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

The problem which needed solving was earning our SOC2 Type II certification. To do that, we needed a formal InfoSec Program, which included Vendor Management and Risk Management. The benefits realized include: the establishment of a complete and continuously evolving InfoSec Program; and we indeed earned our SOC2 Type II.

**Official Response from Shannon Dougall:**

> Sondra, congrats on earning your SOC 2 Type II!   We are so grateful for your kind words; the Tugboat team will be delighted to hear your feedback.   Thank you for taking the time to review us.

  ### 50. A great raodmap to help you with your journey to SOC-2 compliance

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Small-Business (50 or fewer emp.)

**Reviewed Date:** May 28, 2021

**What do you like best about OneTrust Tech Risk & Compliance?**

One central repository for all things compliance-related.  Easy tracking to ensure you keep up to date with evidence collection.

**What do you dislike about OneTrust Tech Risk & Compliance?**

It is still a maturing tool and will gain more robustness as it evolves.  No showstopper, just ease of use of things and things that will make the complete process smoother moving forward.  They already have implemented a change that we suggested!

**Recommendations to others considering OneTrust Tech Risk & Compliance:**

Tugboat Logic is an easy-to-use platform that allowed us to move forward with our compliance that I'm sure it would have taken us months more without them.  They are an absolute joy to work with as they are so helpful.

**What problems is OneTrust Tech Risk & Compliance solving and how is that benefiting you?**

SOC-2 compliance finally got to Type 1 after months and months of trying alone.  I did it in a couple of months with Tugboat.


## OneTrust Tech Risk &amp; Compliance Discussions
  - [Can I use this tool for more than one standard](https://www.g2.com/discussions/41360-can-i-use-this-tool-for-more-than-one-standard) - 2 comments

- [View OneTrust Tech Risk &amp; Compliance pricing details and edition comparison](https://www.g2.com/products/onetrust-tech-risk-compliance/reviews?section=pricing&secure%5Bexpires_at%5D=2026-05-27+11%3A57%3A09+-0500&secure%5Bsession_id%5D=9e729105-3997-444a-a3f5-e4ec83cc9e5d&secure%5Btoken%5D=32c08467e0edfdf802bf863ace1bbe091c113cd7a836af5bcee1c4c9b069a40f&format=llm_user)

## OneTrust Tech Risk &amp; Compliance Features
**Functionality**
- Customized Vendor Pages
- Centralized Vendor Catalog
- Questionnaire Templates
- User Access Control

**Generative AI**
- AI Text Generation

**Generative AI**
- AI Text Generation
- AI Text Summarization

**Risk assessment**
- Risk Scoring
- 4th Party Assessments
- Monitoring And Alerts
- AI Monitoring

**Generative AI - Security Compliance**
- Predictive Risk
- Automated Documentation

**Monitoring - IT Risk Management**
- AI Monitoring

**Platform AI Features - Policy Management**
- Reports
- Workflow Management

**Generative AI - Vendor Security and Privacy Assessment**
- Text Summarization
- Text Generation

**Agentic AI - IT Risk Management**
- Autonomous Task Execution
- Multi-step Planning

## Top OneTrust Tech Risk &amp; Compliance Alternatives
  - [Vanta](https://www.g2.com/products/vanta/reviews) - 4.6/5.0 (2,420 reviews)
  - [Optro](https://www.g2.com/products/optro/reviews) - 4.6/5.0 (1,584 reviews)
  - [Drata](https://www.g2.com/products/drata/reviews) - 4.7/5.0 (1,150 reviews)

