- Forrester evaluated 12 vendors in the Q2 2026 GRC Platforms Wave and found the market facing real headwinds despite continued growth.
- Many GRC platforms still require heavy manual data entry and offer only basic workflow automation, while remaining complex and expensive relative to what they deliver.
- GRC platforms remain largely a system of record. The market is shifting toward orchestration and automation across a wider ecosystem of risk technologies rather than a single platform owning every capability.
- AI is providing minimal proven value today. Vendors lean heavily into agentic AI messaging that Forrester's own assessment found is not yet realised in practice.
A Wave position is a starting point, not an answer
Every few years, Forrester and Gartner publish a fresh read on the GRC platform market, and every few years, procurement teams treat the resulting quadrant or wave as a shortlist in itself. It isn't one. Forrester's Q2 2026 GRC Platforms Wave assessed twelve vendors against Forrester's own criteria — weighted the way Forrester weights them, tested against use cases Forrester chose to test.
That is genuinely useful research. It is not a substitute for your own criteria. A vendor rated strongly on Forrester's axes can still be a poor fit for an organisation with a specific data residency requirement, a narrow third-party risk use case, or an existing technology stack the Wave never considered.
The market Forrester actually found: heavy on manual work, light on proven AI
The more interesting finding in Forrester's own write-up is not who won. It's the state of the category itself. Forrester describes a market where many platforms still require substantial manual data entry and offer only basic workflow automation — for a category of software whose entire premise is reducing manual risk and compliance work.
At the same time, nearly every vendor in the Wave is now marketing some form of agentic AI. Forrester's assessment is blunt about the gap between that messaging and delivered value: AI is providing minimal proven benefit to customers today. That combination — real cost, real complexity, and marketing that has outpaced the product — is exactly what makes vendor selection a due diligence exercise, not a research-report read.
GRC platforms are becoming orchestration layers, not everything-in-one-box
Forrester also flags a structural shift worth taking seriously: GRC platforms are increasingly expected to orchestrate across a broader ecosystem of specialised risk technologies, rather than attempt to own every capability internally. That has direct implications for how you should be scoring vendors. A platform's own feature list matters less than how cleanly it integrates with the third-party risk tool, the incident management system, and the audit workflow your organisation already runs.
This is a different evaluation question than 'does the platform have this feature.' It's 'does the platform play well with the six other systems your risk and compliance function actually depends on.' Few RFP templates ask that question directly.
What a Wave position cannot tell you about your own organisation
Three things sit outside any analyst report's scope, no matter how rigorous: your organisation's specific regulatory footprint, your existing technology constraints, and the internal politics of who actually has to use the tool day to day.
For an Australian buyer specifically, none of the global analyst reports weight APRA CPS 230 or CPS 234 alignment, Australian data sovereignty, or IRAP assessment status into their scoring — because those criteria are irrelevant to the majority of the vendors' global customer base. A platform can sit in a Wave's leadership zone globally and still fail a hard requirement for an APRA-regulated buyer on day one of due diligence.
Translating analyst research into a board-defensible shortlist
The right way to use Forrester's Wave is as a candidate pool, not a ranking. Take the twelve vendors evaluated, combine them with the wider market of 200+ GRC and risk tools, and filter that universe through your own non-negotiables first — data residency, APRA alignment, integration requirements. Then apply your weighted criteria to the remaining options.
That gives you a shortlist driven by your organisation's reality, informed by analyst research but not governed by it. It is also a shortlist you can explain and defend when the board or audit committee asks why a globally recognised leader didn't make your top three.
Why This Matters for RiskBridge
RiskBridge's Selection module exists precisely because a Wave or Magic Quadrant position answers one question — is this vendor strong in general — and leaves the harder one unanswered: is this vendor right for us. Selection overlays a buyer's own weighted, must-have criteria onto the same 200+ vendor universe Forrester and Gartner track, so the analyst view becomes an input to the decision rather than the decision itself.
RiskBridge is developed and operated by Effective Risk Management Pty Ltd. All product names, trademarks, and analyst frameworks (including Gartner®, Forrester®, APRA®, ISO®, NIST®, COSO®, IIA®) referenced herein belong to their respective registered trademark owners. Reference to these frameworks is provided solely for independent practitioner research and does not imply official affiliation, endorsement, or formal legal advice. GRC platform evaluation and regulatory compliance strategies should always be verified against your organization's specific jurisdictional and legal obligations.
See how RiskBridge applies this in practice.
Run a guided, criteria-driven evaluation across 200+ tracked GRC vendors — or consult with an experienced GRC practitioner about your requirements.
