Best Software for 2025 is now live!
Show rating breakdown
Save to My Lists
Claimed
Claimed

Top Rated ZenGRC Alternatives

ZenGRC Reviews & Product Details

Alessio F.
AF
Information Security and Privacy Engineer
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about ZenGRC?

1. Versatility; it can meet a ton of use cases, and is extremely intuitive.

2. Integrations; ZenGRC easily plugs into common productivity tools like JIRA and Slack, which makes it easy to use across a distrusted organization.

3. Customer support; Zen has dedciated support and customer success managers that make it easy to deploy and get started. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

If you are hard pressed to find a GRC solution that meet some very specific or niche requirements (ex. Article 30 reporting for GDPR), Zen may not hit all of your bases, but this is easily made up for by its low price, and general versatility for any framework. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Large scale compliance management, audit management, risk and control management, vendor risk management, and (soon) asset management. Review collected by and hosted on G2.com.

ZenGRC Overview

What is ZenGRC?

ZenGRC offers an established solution to elevate your company's risk and compliance program to the highest infosec standards. The cloud-based SaaS solution fits your existing GRC program and also evolves to guide you throughout your maturity roadmap. With ZenGRC as the central platform for your organization's entire infosec ecosystem, you can achieve continuous monitoring and efficient audit management capabilities, as well as customizable, end-to-end risk management that's built-in — not bolted on. Companies from SMB all the way to Enterprise use ZenGRC for... — Minimized manual effort through automation — Shortened, simplified audit cycles — Risk management that’s built-in—not bolted on — Increased visibility and reporting with dashboards — Direct integrations with ServiceNow, AWS, Qualys, Slack, JIRA, and more.

ZenGRC Details
Discussions
ZenGRC Community
Languages Supported
English
Show LessShow More
Product Description

ZenGRC is a user-friendly GRC software designed to make compliance easy for nimble enterprises.

How do you position yourself against your competitors?

Our intuitive dashboards, pre-built templates, and built-in risk management features easily solve critical problems at scale. ZenGRC + ZenConnect provide a holistic view of your applications containing critical data within a centralized, cloud-based solution, allowing you to continuously monitor your data and mitigate risk in real-time. With dedicated onboarding specialists, customer success managers, and GRC experts you’ll be up and running in weeks—not months.


Seller Details
Seller
Zengrc
Year Founded
2009
HQ Location
San Francisco, CA
Twitter
@riskoptics
608 Twitter followers
LinkedIn® Page
www.linkedin.com
70 employees on LinkedIn®

Ani B.
AB
Overview Provided by:
Founder | CEO at Bisaria & Co.

Recent ZenGRC Reviews

Verified User
A
Verified UserEnterprise (> 1000 emp.)
3.5 out of 5
"Looking for a ISO and NIST GRC tool?"
Zen is very user friendly when conducting ISO 27001 audits for internal reviews.
Verified User
A
Verified UserMid-Market (51-1000 emp.)
4.0 out of 5
"Great GRC tool for mid size companies!"
The tool is very user-friendly, customizable.
Kert John D.
KD
Kert John D.Small-Business (50 or fewer emp.)
5.0 out of 5
"GRC "easy button""
Being newer to leveraging a GRC tool, what attracted me most to ZenGRC was the functionality and manageability versus the others players in that sp...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

ZenGRC Media

ZenGRC Demo - Compliance Dashboard
ZenGRC Compliance Dashboard
ZenGRC Demo - System of Record Detail
ZenGRC System of Record Detail
ZenGRC Demo - Audit Status Dashboard
ZenGRC Audit Status Dashboard
ZenGRC Demo - Risk Assessment
ZenGRC Risk Assessment
ZenGRC Demo - Heat Map
ZenGRC Heat Map
ZenGRC Demo - InfoSec Dashboard
ZenGRC InfoSec Dasboard
Answer a few questions to help the ZenGRC community
Have you used ZenGRC before?
Yes

92 out of 93 Total Reviews for ZenGRC

4.4 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
92 out of 93 Total Reviews for ZenGRC
4.4 out of 5
92 out of 93 Total Reviews for ZenGRC
4.4 out of 5

Overall Review Sentiment for ZenGRCQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
Verified User in Construction
AC
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
What do you like best about ZenGRC?

Zen is very user friendly when conducting ISO 27001 audits for internal reviews. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

There is not already an established integration with Service Now. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Before Zen we ran our audits on excel spreadsheets and normal Outlook. Zen gives you one nice storage location for our ISO audits and has the capabilities to send reminder emails on outstanding tasks. Review collected by and hosted on G2.com.

Kert John D.
KD
Global Director - IT Operations & Security
Small-Business(50 or fewer emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about ZenGRC?

Being newer to leveraging a GRC tool, what attracted me most to ZenGRC was the functionality and manageability versus the others players in that space. "Easy-button" Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

There are no downsides to ZenGRC from my perspective, however we did struggle with where to start in the usage of the tool. We simply leveraged a 3rd-part expert to assist. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Centralized document repository for policies, procedures, and network diagrams, 3rd-party risk questionnaires, and pulling all of the numerous governances cross mappings for our global sites into one tool. Review collected by and hosted on G2.com.

GV
Vendor Management Analyst
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ZenGRC?

I like the following:

1. Bulk upload of Audits

2. Ownership change for the tasks at bulk

3. Able to filter many ways to track the exact Audit

4. End to end audit tracking Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

I wouldn't say I like the following :

1.There is no option shows as the due date for the tasks

2.Also whenever, I changed the owner/assignee for the parent task, it's not reflecting the same for sub-tasks, and I need to update manually every time

3. All future tasks are showing under the To-Do action list

4. Parent tasks should not show under the To-Do action list since it's the main task for auto-creation of sub-tasks

5.Dashboard view is not good

6. System systems are getting cleared whenever I log in fresh

7.Even If I share the read access, the user can edit the tasks

8.Assignee may change over time, and even though the parent request gets updated, it does not reflect in the recurring requests that spin-off it

9.Sometimes, the recurrence gets skipped. In other words, sometimes a month gets skipped

10. we are not able to duplicate a request automatically without recurrence and a manual process Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

Because of it's easy of use, we can recommend at 7 for 10. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Problems are solving but again it's manual job like eg. In order to fix the owner for Parent task - I need to stop occurrence for each parent task & need to update the owner details and again need to start the occurrence for each... Review collected by and hosted on G2.com.

Verified User in Financial Services
AF
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about ZenGRC?

The tool is very user-friendly, customizable. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

The other correlating modules are not mature compared to it's competitors. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

IT is automating the GRC process and taking us away from manual spreadsheets. Review collected by and hosted on G2.com.

Verified User in Retail
AR
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
(Original )Information
What do you like best about ZenGRC?

The tool is easy to navigate in and has a lot of flexibility to add custom attributes to each of the data types, particularly when using it as a system of record for compliance-related activities. The company is also really receptive to feedback as far as its features - they've incorporated a lot of the feedback provided. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

There are some features that aren't super robust - like role-based access controls, uploading multiple files to a record in bulk, and the general setup of the Jira integration. Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

Make sure you understand what you need from your GRC tool. If you're looking to tie into piles and piles of other tools, have complex workflows, and do specialized reporting, you'll want something more robust, heavier, and expensive. Zen was a good balance of functionality and cost for my company. Also, it really helps in implementation if you controls defined in advance. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

ZenGRC is the system of record for a slew of activities at my company, including the risk register, vendors and vendor risks, critical changes, and security controls. The audit functionality will be the next thing we hope to use exclusively. ZenGRC is effectively a "force multiplier" for a one-person GRC team - it would take 2-3 more people to keep track of all the data we keep in Zen, so the cost savings is easily there. Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
(Original )Information
What do you like best about ZenGRC?

ZenGRC is a great tool to manage our complete audit cycle end to end, from automating a request to collect evidence on a defined frequency and closing them with the validation. It can be integrated with many audit frameworks. It creates an easy job in tracking and aligning the collected data in a structured way. It reduces a lot of manual work on tracking things. The tool is very much user-friendly. The support team's response to add features or resolve issues is applauded. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

It would have been wonderful if the licensing is related to the number of users, as we face these issues as our Organization is on tremendous growth now, and we have to onboard several users to the tool. We may also need some more features added to the iterations of the created tasks. Also it would be good if the tools allows some more ways of customization that can be allowed on the taks that are being created. It would be good to have a free trail initially to have a feel on the tool before having user subscriptions Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

I would be very much happy to recommend ZenGRC. It helps in many ways to ease much of the manual work people are held up currently and clear several backlogs. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

We primarily use ZenGRC for SOC 2 and SOC 1 evidence collections for the multiple products (seven products are already in ZenGRC, six are to be onboarded in 2022). It works so smooth and is pretty much aligned with all our requirements related to SOC, and we are planning to have Risk mapping added to this tool.

Audit Collection & Management

Vendor Assessment Survey

Controls Mapping

Compliance Gaps Discovery Review collected by and hosted on G2.com.

Jeneen R.
JR
Case Investigator
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about ZenGRC?

I find it most helpful how it reduced manual efforts and creates an easier process for people who use this tool for business related work. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

I dislike how it is integrates third party apps. This makes the software slower and it is not always accurate. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

It solves the issue of research and makes data analysis easier for everyone. Review collected by and hosted on G2.com.

Verified User in Financial Services
UF
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ZenGRC?

ZenGRC's training and educational content under the knowledge base make it easy to stand up the platform yourself with minimal support. ZenGRC allows for a common approach to risk management across the enterprise and can be used by all business units. ZenGRC also enables a holistic view of how compliance status, program maturity, audit results, and vendors affect the overall risk score of the organization. This solution is easy to use, easy to stand up, and scalable as your organization grows. ZenGRC also offers excellent support. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

A more robust API integration with Jira would be beneficial. Vendor review requests submitted through Jira contain information that needs to be then re-entered into the GRC tool. I would prefer that this information already required for the ticket would be able to feed into the GRC tool without manual re-entry by the risk analyst. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

To increase the throughput of the vendor risk review and management program and to facilitate a common approach to risk management across the enterprise. Immediate benefits include better tracking of artifacts, better risk score reporting, and a better process to solicit information from third parties. Review collected by and hosted on G2.com.

Verified User in Financial Services
UF
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ZenGRC?

Fairly easy to navigate with sidebar menu.

Many options of things to record (audits, issues, etc.)

User access easily integrated into our single sign on capability. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

Could do better withthe side bar menu as not all options are listed and it's a roundabout process to get to some of the options.

Also navigation from one screen or page to another often entails going back to the beginning.

Search functionality could be improved - not always easy to find information within a recorded item.

Could do with having more fields when recording an issue/risk, to include more for action plans/due dates/owners and details for example.

Some of the above might simply be because I am farily new at using it. AS I get more familiar, they might become easier. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Tracking an external audit. Benefit is centralised repository which includes allowing access to external auditor (rather than giving them access to any other internal tools).

Tracking issues/risks. Again centralisation and access control is good. Reporting is fairly good (and I need to learn more about it) Review collected by and hosted on G2.com.

Kanupriya P.
KP
privacy and compliance specialist
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite on behalf of seller
Incentivized Review
What do you like best about ZenGRC?

ZenGRC gives us the ability of using the various aspects of a GRC tool.

It does not restrict based on modules which helps us to implement all modules in the ways that work best for the organization.

The modules provide ease of customizing the fields we want to capture and how we want to import or export bulk data. Also, the controls mapping using SCF is beneficial to link various standards with a common set of controls.

Also loved the dedicated team which was able to answer all pour questions during the demo and POC phases. The product specialists are know the product and really loved that they were working continuously to improve the tool functionality. Review collected by and hosted on G2.com.

What do you dislike about ZenGRC?

The current user interface can be improved.

The report extracts and one view look needs to be improved. Right now, the platform has too many tabs under the same control / risk / issues.. it is highly beneficial if all of this can be brought in a one view look.

The Platform does not allow user access to be restricted per module. Eg: Control owner with editor access can even edit policies and risks which is not a great way to implement segregation fo duties. We need role based access accross the platform. Review collected by and hosted on G2.com.

Recommendations to others considering ZenGRC:

Use the knowledge base which ZenGRC brings with it. The Risk Library, the various templates, the mapped control sets, all these helped us in setting up the tool and starting to use it from day 1 to guide the overall function.

Invest a lot of time in setting up the Tool right from the start. Review collected by and hosted on G2.com.

What problems is ZenGRC solving and how is that benefiting you?

Central tool to consolidate risk management activities.

record external audit results and plan and perform audits and assessments.

vendor management and repository, issue tracking, Business impact analysis and defining common controls framework.

Also intend to use it for expanding our certifications like ISO 27001, SOC 2 etc. Review collected by and hosted on G2.com.