AMRA E Technical Book
Transcription
AMRA E Technical Book
AMRAE Technical Book 2013 Risk Management Information Systems Panorama 5th Edition In partnership with RMIS Panorama 2013 AMRAE wishes to thank the participants who helped produce this document: François Beaume Head of the Risk Management Department Dalkia President of AMRAE’s Information Systems Commission Hélène Dubillot Head of Scientific Coordination AMRAE Jean-Laurent Schwartz Senior Manager – Risk Management Accenture Management Consulting The Association pour le Management des Risques et des Assurances de l’Entreprise (The Association for Corporate Risk and Insurance Management) comprises more than 750 members from 430 French public and private sector firms (including 39 of the 40 publicly listed companies in the CAC40 index). One of the objectives of the association is to develop a Risk Management “culture” within organizations and to assist members in their relationships with actors of the insurance market and public authorities. The association advises members on risk assessment, costs and insurance spending. The association has developed an entity called AMRAE Formation to meet expectations in terms of professional training for members who legitimately look to the association for support. Thus, AMRAE Formation offers theme-based courses, courses leading to qualifications (CEFAR – Risk Management Strategies) and a diploma course (ARM – Associate in Risk Management), all taught by experts in risk management. 2 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Editorial More and more vendors, more and more readers, educational fact sheets and clear diagrams: the RMIS Panorama has undoubtedly found its place in Risk Management landscape, both in France and abroad. This fifth edition of the RMIS Panorama, in partnership with Accenture, keeps all its promises. This year, the enrichment of the questionnaire and an in depth overhaul of the survey framework has allowed us to identify and analyze more accurately the big picture of the market evolutions, in the continuity of the choices we made. The consistency of the methodology adopted from the first editions of the RMIS Panorama and successive improvements now allows us to provide a richer content and a more detailed analysis. Understanding and distinguishing the operational and technical characteristics of one tool over another is not always easy for the Risk Manager, especially because of the increasing number of products available on the market over the past years. By providing a common baseline, our aim is not only to facilitate communication between Risk Managers and IT vendors, who offer insurance or risk solutions, but also to provide Risk Managers the key to understanding this market. This commitment was well understood by vendors, who feed our thinking and analysis throughout the year. We would like to thank them as well. This edition takes into account these exchanges and their remarks, and is therefore the most thorough edition to date. AMRAE also wishes to thank its partner Accenture, particularly Jean-Laurent Schwartz, for his involvement, which is necessary to develop and perpetuate this publication. As usual, this technical book will be available for free download on the AMRAE’s website (www.amrae.fr) in French on 11 February 2013, and in English in March 2013. Enjoy your reading! Gilbert Canaméras, President of AMRAE Aliette Leleux, Head of Risk Management for Accenture France and Benelux François Beaume, President of AMRAE’s Information Systems Commission Copyright © 2013 AMRAE, in partnership with ACCENTURE 3 / 68 RMIS Panorama 2013 Contents Editorial 3 Reasons for developing a RMIS Panorama 6 The RMIS, a tool dedicated to Risk Managers .......................................................................... 6 Main objectives of this RMIS Panorama................................................................................... 6 Developing the panorama: survey questionnaire ..................................................................... 7 Panel of vendors for our 2013 edition ...................................................................................... 7 Analysis of the panel of respondents for our 2013 edition .......................................................... 8 RMIS market analysis 10 Which trends for the RMIS market? ...................................................................................... 10 Which profiles for clients and users of RMIS? ......................................................................... 11 Which trends within the client company? .............................................................................. 12 Towards more modularity for RMIS? ..................................................................................... 13 Towards more interaction between RMIS? ............................................................................ 13 Which forecasted trends for the RMIS?.................................................................................. 14 Summary of results from 2013 Panorama 15 Analysis of the responses ..................................................................................................... 15 Summary approach ............................................................................................................. 15 2013 global results by functional and technical areas .............................................................. 16 The RMIS, a tool tailored for Risk Managers .......................................................................... 18 Stated coverage in 2013 by functional areas .......................................................................... 20 Stated coverage in 2013 by technical areas ............................................................................ 22 Detailed datasheets by vendor 24 1-One ................................................................................................................................. 25 AON eSolutions .................................................................................................................. 26 BVD / Bureau Van Dijk (new respondent) ............................................................................... 27 BWise ................................................................................................................................ 28 Clarity GRC (new respondent) .............................................................................................. 29 Click-N-Manage (new respondent) ........................................................................................ 30 CMO Compliance (new respondent) ...................................................................................... 31 Cogis (new respondent) ....................................................................................................... 32 Covelys .............................................................................................................................. 33 Devoteam .......................................................................................................................... 34 Effisoft ............................................................................................................................... 35 4 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 eFront ................................................................................................................................ 36 Elseware ............................................................................................................................. 37 EMC / RSA .......................................................................................................................... 38 Enablon .............................................................................................................................. 39 Figtree Systems (new respondent) ........................................................................................ 40 Gras Savoye ........................................................................................................................ 41 IBM (new respondent).......................................................................................................... 42 Keyword ............................................................................................................................. 43 LexisNexis .......................................................................................................................... 44 MAAT ................................................................................................................................. 45 Marsh France ...................................................................................................................... 46 Mega International .............................................................................................................. 47 MetricStream(new respondent) ............................................................................................ 48 Novasecur (new respondent) ................................................................................................ 49 Overmind ........................................................................................................................... 50 Oxand ................................................................................................................................ 51 Oxial France ........................................................................................................................ 52 Pentana (new respondent) ................................................................................................... 53 Protiviti .............................................................................................................................. 54 ROK Solution ...................................................................................................................... 55 SAP France ......................................................................................................................... 56 SAS France ......................................................................................................................... 57 Siaci Saint Honoré ............................................................................................................... 58 Software AG ....................................................................................................................... 59 Thomson Reuters (new respondent)...................................................................................... 60 Tinubu Square..................................................................................................................... 61 Appendices 62 Appendix 1: Description of functional and technical areas ....................................................... 62 Appendix 2: Consultation/response results ............................................................................ 64 Copyright © 2013 AMRAE, in partnership with ACCENTURE 5 / 68 RMIS Panorama 2013 Reasons for developing a RMIS Panorama The RMIS, a tool dedicated to Risk Managers The Risk Management function is first and foremost a function that is strongly linked to collecting, analyzing, summarizing and reporting sometimes heterogeneous data. Identifying risks and collecting incidents as close as possible to their occurrence, both geographically and in time, and their evaluation to ensure effective decision making requires the management of data flows in the most relevant possible way. This is precisely the rationale of a Risk Management Information System (RMIS), which aims at sorting through often plentiful data before reporting it to the Risk Manager in a suitable format. This type of tool is therefore not only an analysis and operational tool, but also a tool for communicating and sharing results. RMIS are designed to provide a management tool for every Risk Management actor: – Top Management can have a consolidated view of entailed risks and actions in progress. – Managers in charge of handling a set of risks have this same view and can use it to manage actions within their area of coverage. – The Risk Manager can coordinate all risk management related actions, from identification to treatment, and implement more specific measures (e.g. related to managing loss claims and insurance policies). Main objectives of this RMIS Panorama Since 2008, AMRAE has been carrying out a survey on a yearly basis, listing vendors of existing Risk Management Information Systems (RMIS) and solutions available on the market. This survey is conducted directly with vendors from all over the world and gives rise to an analysis based on functional and technical criteria, the results of which will be examined in this document. This panorama is designed to provide Risk Management actors with answers to every question they may have before initiating any RMIS project, in particular: – What are my needs? – Will the existing solutions meet my needs? – To what extent? – Should I use a single specialized module or an end-to-end solution? 6 / 68 With a view to avoiding potential conflict of interest and meeting the most stringent ethical standards, this work was carried out, from the beginning, on three core tenets: – Neutrality: the panorama does not make any value judgments on vendors and their solutions, nor does it recommend their purchase. It is intended simply to provide a framework to present the tools and main functionalities available on the market. – Objectivity: questions cover the features offered by each solution, and are therefore mainly technical and factual. – Business orientation: questions and analysis performed are directly related to the specific functions and needs of Risk Managers. Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Developing the panorama: survey questionnaire As every year, we have revised the questionnaire used in the previous edition to include perceived evolutions on the risk management market and in the field of information systems. This year, after a review of market actors, a list of 76 vendors was set up, including vendors consulted last years as well as new marked players. These vendors were then directly contacted by AMRAE and invited to participate in an online survey questionnaire (available in English and French) published by the end of 2012 for over a month. This questionnaire allows vendors to describe the complete technical and business functionalities provided by their solutions. Of course, the questionnaire prepared by AMRAE highlights expectations that are deemed relevant for Risk Managers. Panel of vendors for our 2013 edition For our 2013 edition, this technical book is composed of a panel of 37 respondents (+23% compared to last year). 11 new respondents have participated in this edition. 4 vendors only have left the panorama: most of the vendors present in the 2012 panorama have renewed their participation for the 2013 edition (see table in Appendix 2). Legend Copyright © 2013 AMRAE, in partnership with ACCENTURE New respondent Outgoing vendor 7 / 68 RMIS Panorama 2013 Analysis of the panel of respondents for our 2013 edition Analysis of the vendors’ global workforce Respondents can be classified in three main categories: 0 4 10 23 Thomson Reuters SAP France EMC / RSA LexisNexis SAS France IBM Software AG Devoteam Gras Savoye Protiviti MetricStream Marsh France Siaci Saint Honoré BVD / Bureau Van Dijk Enablon AON eSolutions eFront Mega International BWise Oxand Effisoft Tinubu Square CMO Compliance Figtree Systems Pentana Oxial France 1-One Keyword ROK Solution Novasecur Elseware Clarity GRC Click-N-Manage Cogis Overmind MAAT Covelys 10000 20000 30000 40000 50000 60000 70000 80000 90000 Workforce > 20 000 500 ≤ Workforce ≤ 20 000 Enablon AON eSolutions eFront Mega International BWise Oxand Effisoft Tinubu Square CMO Compliance Figtree Systems Pentana Oxial France 1-One Keyword ROK Solution Novasecur Elseware Clarity GRC Click-N-Manage Cogis Overmind MAAT Covelys 0 50 100 150 200 250 300 350 400 Workforce < 500 Most responding RMIS vendors have less than 500 employees, all staff included. 8 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Analysis of the vendors’ workforce dedicated to RMIS Respondents can be classified in two main categories: 0% MAAT 10% 20% 30% 40% 50% 60% 70% 80% 90% 100% Overmind Clarity GRC Novasecur Oxial France Pentana CMO Compliance 15 Effisoft RMIS workforce ≥ 50% of the global workforce BWise Keyword BVD / Bureau Van Dijk AON eSolutions Covelys Elseware Click-N-Manage SAS France Mega International eFront ROK Solution Tinubu Square SAP France 15 MetricStream RMIS workforce < 50% of the global workforce LexisNexis Protiviti Devoteam Thomson Reuters Marsh France EMC / RSA Siaci Saint Honoré Gras Savoye Data about global or RMIS workforce were not provided in the questionnaire by the following seven vendors: – 1-One – Cogis – Enablon – Figtree Systems – IBM – Oxand – Software AG Also note that 70% of vendors are used to work with consulting firms. Copyright © 2013 AMRAE, in partnership with ACCENTURE 9 / 68 RMIS Panorama 2013 RMIS market analysis This year, the enriched questionnaire allows us to provide in this chapter a vision of the RMIS market, as perceived by respondents. Which trends for the RMIS market? Evolution of the frequency of RMIS requests for proposals 6% For the vast majority of respondents, the market is growing compared to last year. More and more requests for proposals 8% This is evidenced by the increase in the frequency of requests of proposals, according to 67% of respondents. 19% Same number as last year Less and less requests for proposals 67% Do not know Percentage of projects conducted in France On all projects reported by the respondents (from the beginning), those that were conducted in France represent 21%. 36% 21% And on all projects realized last year by the respondents, the proportion of projects conducted in France is 36%, which appears to highlight the dynamism of the French market. Overall Origin of organizations having a RMIS Moreover, the French customers represent an average of 35% of responding vendors’ portfolios. Also note that 73% of respondents’ customers are large companies. 10 / 68 Less than a year ago Size of organizations having a RMIS 73% 46% 35% 34% 29% French-only Non-French International organizations organizations organizations Large companies Small and medium companies Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Which profiles for clients and users of RMIS? Industries of organizations having a RMIS Industries of organizations having a RMIS Industry and services On average, clients of the “Industry and services” sector represent more than half of the responding vendors’ portfolios. 52% Banking 21% Insurance The “Banking” and “Insurance” sectors come in second and third position, with respectively 21% and 16% of client portfolios of respondents. 16% Public sector Other 14% 9% Average number of users per RMIS Only 8% of RMIS implemented by respondents are large (more than 1 000 users). 30% 38% of RMIS implemented by respondents are medium sized (between 100 and 1 000 users). And 55% of RMIS implemented by respondents are small (less than 100 users). 14% 11% From 0 to 5 Average number of users per implemented solution From 6 to 50 From 51 to 100 16% 11% 11% 8% From 101 to 200 From 201 to 500 From 501 to 1000 More than 1000 This observation has to be put in perspective with the fact that 73% of the projects are implemented in large structures (see previous page). As a consequence, even in large structures, RMIS generally have less than 1 000 users. Existence of a club of users Existence of a club of users 65% of respondents reported having a club of users. Yes 35% No 65% Copyright © 2013 AMRAE, in partnership with ACCENTURE 11 / 68 RMIS Panorama 2013 Which trends within the client company? Number of departments concerned within the client company RMIS requests for proposals are related to several departments of the client company 3% For 61% of respondents, RMIS requests for proposals concern more often several departments of the client company. 36% Yes, more and more often Yes, sometimes This confirms the observed trend in companies, which consists in converging their risk management systems in order to make them more transversal and more effective. Generally, no No, never 61% Functions most often originating RMIS requests for proposals Functions most often originating RMIS requests for proposals The Risk Management Department is still originating 92% of RMIS requests for proposals, while the Internal Audit and Internal Control Departments are originating 50% of them. The Risk Management Department 92% The Internal Control Department 50% The Internal Audit Department 50% The C-Levels 33% The Insurance Management Department 31% The IT Department And the C-Levels, according to respondents, are at the origin of 33% of the requests for proposals. 19% The Audit Committee 17% The Board of Directors 8% Others 8% Decision makers involved in the choice of a RMIS Decision makers involved in the choice of a RMIS The Head of Risk, Head of Internal Control and Head of Internal Audit are, for the respondents, the decision makers the more involved in the choice of a RMIS. The Head of IT is involved in 62% of cases, and the Head of Insurance is, according to respondents, involved in 57% of cases. 12 / 68 Head of Risk Head of Internal Control Head of Internal Audit Head of Compliance Head of IT Head of Quality Head of Insurance Managing Director or General Secretary Chief Financial Officer Head of Health & Safety Head of IS Security Head of Legal Head of Sustainable Development Other 97% 73% 68% 65% 62% 62% 57% 54% 51% 38% 38% 32% 19% 5% Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Towards more modularity for RMIS? Composition of solutions of respondents 76% of respondents have a solution composed of a single application. 5% Among them, most declare that their respective solutions have several modules. Only 19% of respondents several distinct applications. have Several modules in the same application 16% Several distinct applications A single application 60% 19% Other Towards more interaction between RMIS? Development of connectors with other RMIS 72% of respondents plan to develop or already have connectors with other RMIS. In contrast, 28% of respondents do not plan to develop connectors with other RMIS. Copyright © 2013 AMRAE, in partnership with ACCENTURE Planned 28% 44% 28% Already developed Not planned 13 / 68 RMIS Panorama 2013 Which forecasted trends for the RMIS? Nearly two thirds of respondents reported that their solutions are already integrated with business intelligence platforms or with reporting tools. Just over half of respondents said that their solutions are already integrated with: – Business process modeling tools – Specific business applications – Content management solutions – Data analysis tools – Monitoring tools – Continuous control monitoring tools Integration of solutions with other tools / applications Business process modeling tools 70% 60% 50% 40% 30% 20% 10% 0% More powerful reporting tools Continuous IT security monitoring tools (eg automated audit of vulnerabilities) Already covered Planned Specific business applications Business intelligence platforms Continuous control monitoring tools Content management solutions Monitoring tools Data analysis tools And at least 20% of respondents plan to integrate these tools or applications in the coming years. Nearly 40% of respondents plan to integrate their solutions with data analysis tools in the coming years. Ultimately, it seems that some tools or applications will tend to be preferably integrated within the RMIS, including: – Business process modeling tools – Data analysis tools – Monitoring tools – Reporting tools However, in the coming years, no clear trend emerges for integration within or outside the RMIS for the following components: – Business intelligence platforms – Content management solutions – Continuous control monitoring tools 14 / 68 Ways of integrating solutions with other tools / applications Business process modeling tools 70% More powerful reporting tools 60% 50% Inside the solution Via interfaces Specific business applications 40% 30% Continuous IT security monitoring tools (eg automated audit of vulnerabilities) 20% 10% Business intelligence platforms 0% Content management solutions Continuous control monitoring tools Monitoring tools Data analysis tools Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Summary of results from 2013 Panorama Analysis of the responses Multiple-choice questions were often proposed in the questionnaire in order to provide simple options to the vendors and improve the analysis on a standardized basis. Each of the standardized responses was assigned a certain scoring as per the following scale: – Feature covered with customization: 3 points – Feature only covered in a standard way: 2 points – Feature requiring specific development: 1 point – Feature not covered: 0 point Finally, we would like to point out that, as in previous editions, the analysis carried out was based on vendor statements only. In line with our core tenets mentioned above, no tests or interviews were conducted in order to avoid any judgment whatsoever. This scoring scale allowed an objective analysis of responses in order to obtain individual and global conclusions. These results were then analyzed in the light of the comments and feedback provided by vendors, so as to reflect the characteristics of their products as accurately as possible. Finally, we point out that the methodology used for this 5th edition has significantly changed since last year. The scale described above has evolved: we now consider that, for a given feature, it is preferable that the vendor offers several possible customizations, reflecting its maturity to implement this feature for its customers, rather than a standard-only setting, although simpler to implement, but also possibly less adapted to the client’s needs. This change in valuation method was necessitated both by the evolving needs of clients, and by the increasing maturity of existing solutions. In addition, the questionnaire sent to vendors this year was highly enriched and adapted to the changing market and to evolving user requirements. Summary approach Two presentation levels are provided in this panorama: – A global summary, outlining the main market trends. – Individual reports, by vendor, provided on specific datasheets. As mentioned above, because of changes in the survey questionnaire, we could not reuse the previous analysis grid, which in turn did not allow us to outline the global evolution of respondents and their products (see Appendix 1 for a description of functional and technical areas). Copyright © 2013 AMRAE, in partnership with ACCENTURE Regarding the individual datasheets by vendor, we chose to separate functional criteria from more technical ones on two different radar charts, for the sake of clarity. In addition, in order to go further in the analysis compared to previous editions, we also decided to add in the vendor datasheet a cartridge dedicated to the characteristics of the vendor and of its solution(s). For instance, we have specified the number of RMIS implementations projects, for French clients or not, and indicated if the vendor has set up a club of users, or if it is able to provide a “cloud” hosting mode for its solution. 15 / 68 RMIS Panorama 2013 2013 global results by functional and technical areas The following chart shows aggregated vendor responses on the functional and technical areas. Functional areas Insurance Management 100% Competitive Intelligence 90% Incidents / Losses 80% 70% 60% Quality Management Crisis Management / BCP 50% 40% 30% 20% 10% Governance Risk Management 0% Action Management Risk Mapping Compliance Audit Internal Control RMIS PANORAMA 2013 Note that: – Most functional areas are covered on average by 50% of all respondents. – Management of Incidents / Losses is the area that seems to be best covered by respondents. – There is room for improvement for areas related to Insurance Management and Competitive Intelligence. The description of functional areas is available in Appendix 1. 16 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Technical areas Access Management 100% Technical Architecture 90% Workflow 80% 70% 60% 50% Reporting Currencies 40% 30% 20% 10% 0% Documentation Customization Organization Export Languages Import RMIS PANORAMA 2013 Note that: – Most technical areas are covered on average by 60% of all respondents. – The “Access Management” area is best covered by the respondents, but all technical aspects are covered on average the same way within the panel of respondents of this edition. The description of technical areas is available in Appendix 1. Copyright © 2013 AMRAE, in partnership with ACCENTURE 17 / 68 RMIS Panorama 2013 The RMIS, a tool tailored for Risk Managers Depending on their positioning and role in the company, Risk Managers may have different needs. The most common needs within the community can be classified in two main categories: • Enterprise Risk Management (ERM), based on a global approach, often by process, including the following activities: – Corporate governance – Risk mapping – Risk management – Internal audit – Internal control – Compliance • Corporate Insurance Management, including the following activities: – Premium allocation management, calculation of premiums according to regulations and contracts, and follow-up of premium payment history – Management of insurance portfolios – Budget simulations, identification and monitoring of taxes – Incident management, noncompliance, claims, litigation and legal proceedings We therefore chose to include in the following representation the relative position reported by respondents, based on their coverage of “Insurance” and “ERM” needs, enabling us to group them by general categories. Thus, four groups of vendors emerge, covering rather “Insurance" or rather “ERM”: 1. General RMIS vendors (ERM and Insurance), covering both ERM and Insurance. 2. RMIS vendors specialized in Insurance, covering rather Insurance aspects, and less ERM ones. 3. General RMIS vendors, ERM-oriented, covering rather ERM aspects, and less Insurance ones. 4. Other specialized RMIS vendors, covering other functionalities including, among respondents of this edition: – 1-One, whose solution is designed for the prevention of professional risks, and management of health and safety – BVD / Bureau Van Dijk, who is a specialist of competitive intelligence, knowledge management and organization of information – Elseware, who is specialized in modeling of risk scenarios, in order to optimize insurance coverage depending on risk sensitivity levels – Oxand, whose solution is designed for project risk management – Tinubu Square, who is specialized in credit risk management 18 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 “ERM” coverage 100% General RMIS vendors (ERM and Insurance) 90% General RMIS vendors, ERM-oriented AON eSolutions SAS France 80% Software AG Pentana Keyword Click-N-Manage MetricStream ROK Solution Mega International SAP France MAAT Oxial France Clarity GRC 70% CMO Compliance Figtree Systems BWise Enablon Effisoft eFront IBM Protiviti Devoteam Novasecur Thomson Reuters Gras Savoye LexisNexis Overmind 60% Marsh France EMC / RSA 50% Cogis Other specialized RMIS vendors 40% Tinubu Square Oxand 30% 1-One 20% Covelys RMIS vendors specialized in Insurance BVD / Bureau Van Dijk 10% Siaci Saint Honoré Elseware 0% 0% 10% 20% 30% 40% 50% 60% 70% 80% 90% 100% “Insurance” coverage This macro analysis can be supplemented with our detailed vendor datasheets. The following section presents the results by functional and technical areas. Only respondents who declared covering a given functionality are represented on the corresponding radar chart. They are first sorted by category resulting from the above representation, then by alphabetical order of respondents. The description of analyzed areas is available in Appendix 1. Copyright © 2013 AMRAE, in partnership with ACCENTURE 19 / 68 RMIS Panorama 2013 Stated coverage in 2013 by functional areas INSURANCE MANAGEMENT INCIDENTS / LOSSES AON eSolutions Siaci Saint Honoré 100% 90% Covelys Devoteam 80% Effisoft 60% 40% eFront 30% 10% Enablon Devoteam Effisoft 80% eFront 70% Enablon 60% 50% Software AG Figtree Systems 40% 30% SAP France 20% Elseware 90% 1 -One 50% Marsh France AON eSolutions BWise 100% BVD / Bureau Van Dijk 70% Tinubu Square Siaci Saint Honoré Covelys Tinubu Square BWise Gras Savoye 20% 10% ROK Solution IBM 0% 0% Pentana ROK Solution LexisNexis Figtree Systems Oxial France Overmind Gras Savoye Novasecur Overmind Protiviti MetricStream Thomson Reuters IBM SAS France SAS France Mega International Thomson Reuters MAAT Keyword LexisNexis Novasecur Protiviti CRISIS MANAGEMENT / BCP Tinubu Square Oxand AON eSolutions BWise 100% 90% Marsh France Siaci Saint Honoré Covelys Tinubu Square Effisoft 70% Software AG Enablon 40% 30% 20% ROK Solution IBM Overmind Novasecur MetricStream Protiviti eFront Enablon 60% Elseware 50% 1 -One 30% Figtree Systems 40% Gras Savoye 20% Software AG 0% Devoteam Effisoft 70% Gras Savoye 10% Oxial France 90% 80% Marsh France 50% SAP France Clarity GRC Click - N -Manage AON eSolutions BWise 100% Oxand eFront 60% Cogis RISK MANAGEMENT Devoteam 80% EMC / RSA IBM 10% 0% SAP France LexisNexis ROK Solution Novasecur Pentana Protiviti Oxial France Mega International SAS France MAAT Thomson Reuters Keyword EMC / RSA Clarity GRC Click -N - Manage SAS France Overmind Thomson Reuters MetricStream Mega International RISK MAPPING Covelys Tinubu Square Oxand 70% BVD / Bureau Van Dijk 60% 1-One 50% 40% Software AG 30% Tinubu Square Oxand Software AG eFront Enablon Figtree Systems Gras Savoye 20% SAP France IBM 10% 0% ROK Solution LexisNexis Pentana Novasecur Oxial France Protiviti Overmind SAS France MetricStream Thomson Reuters Mega International MAAT Keyword 20 / 68 EMC / RSA Clarity GRC Click -N - Manage Keyword CMO Compliance GOVERNANCE AON eSolutions BWise 100% Devoteam 90% Effisoft 80% Marsh France MAAT Clarity GRC Click -N-Manage CMO Compliance Cogis SAP France AON eSolutions BWise 100% 90% 80% 70% 60% ROK Solution 50% 40% Pentana 30% Devoteam Effisoft eFront Enablon Figtree Systems 20% Oxial France Gras Savoye 10% 0% Overmind IBM LexisNexis MetricStream Novasecur Mega International Protiviti MAAT SAS France Keyword EMC / RSA Cogis CMO Compliance Thomson Reuters Clarity GRC Click -N-Manage Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 INTERNAL CONTROL Elseware Software AG Oxand AON eSolutions BWise 100% 90% 80% SAP France COMPLIANCE 60% ROK Solution 20% Oxial France Gras Savoye 10% 0% Overmind MetricStream Mega International IBM MAAT LexisNexis Keyword Thomson Reuters Clarity GRC Click -N-Manage AON eSolutions BWise 100% SAP France 90% 80% Software AG SAP France Devoteam Effisoft ROK Solution 40% 20% Devoteam Effisoft eFront Enablon 50% 40% 30% Overmind Figtree Systems 20% 10% MetricStream 0% Overmind 90% 60% Gras Savoye 10% AON eSolutions BWise 100% 70% Oxial France Figtree Systems 30% Oxial France SAS France Thomson Reuters 80% Pentana Enablon 50% Pentana Clarity GRC INTERNAL AUDIT 60% ROK Solution Protiviti CMO Compliance Click -N-Manage eFront 70% Novasecur EMC / RSA ACTION MANAGEMENT Tinubu Square Oxand Software AG Gras Savoye 0% SAS France Cogis CMO Compliance Figtree Systems 20% 10% Protiviti Keyword 30% Overmind Novasecur MAAT Enablon 40% Mega International LexisNexis EMC / RSA 50% MetricStream IBM eFront 60% Figtree Systems 30% Effisoft 70% Pentana Oxial France 40% Devoteam 80% Enablon 50% Pentana 90% ROK Solution eFront 70% AON eSolutions BWise 100% Software AG SAP France Devoteam Effisoft Gras Savoye 0% IBM Mega International MetricStream IBM LexisNexis Mega International MAAT Novasecur MAAT Keyword Protiviti Keyword QUALITY MANAGEMENT Software AG Oxand AON eSolutions BWise 100% SAP France 90% AON eSolutions Siaci Saint Honoré Devoteam Devoteam Enablon 70% Oxand eFront 40% Effisoft 60% 50% BVD / Bureau Van Dijk eFront 40% 30% 30% 20% Figtree System 10% 0% Overmind BWise 80% 50% Oxial France 100% 90% Tinubu Square Effisoft 80% 60% Pentana SAS France Thomson Reuters Clarity GRC COMPETITIVE INTELLIGENCE 70% ROK Solution Protiviti Cogis CMO Compliance Click -N-Manage Thomson Reuters Clarity GRC Click -N-Manage Cogis CMO Compliance Novasecur EMC / RSA SAS France EMC / RSA LexisNexis 20% SAP France Enablon 10% 0% IBM ROK Solution MetricStream Figtree System LexisNexis Mega International Novasecur MAAT Keyword CMO Compliance Click -N-Manage Protiviti SAS France Thomson Reuters Clarity GRC Copyright © 2013 AMRAE, in partnership with ACCENTURE Oxial France IBM Overmind LexisNexis MetricStream Novasecur MAAT SAS France Thomson Reuters 21 / 68 RMIS Panorama 2013 Stated coverage in 2013 by technical areas 22 / 68 ACCESS MANAGEMENT TECHNICAL ARCHITECTURE CURRENCIES DOCUMENTATION EXPORT IMPORT Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 LANGUAGES ORGANIZATION AON eSolutions Siaci Saint Honoré100% BWise Covelys Devoteam Tinubu Square Effisoft 90% 80% Oxand eFront AON eSolutions Siaci Saint Honoré BWise 100% Tinubu Square Devoteam 90% Oxand Effisoft 80% Marsh France eFront 70% BVD / Bureau Van Dijk 50% 1-One 30% Software AG 10% SAP France ROK Solution Pentana Cogis Keyword EMC / RSA Pentana Protiviti AON eSolutions BWise 100% Devoteam Effisoft 90% 80% eFront Marsh France Figtree Systems 50% 40% BVD / Bureau Van Dijk Gras Savoye 30% 20% Software AG Siaci Saint Honoré Covelys Tinubu Square Oxand Enablon 60% 1 -One IBM LexisNexis 0% ROK Solution Novasecur Pentana Overmind 1-One EMC / RSA Cogis 70% 60% 40% 30% Enablon Figtree Systems Gras Savoye IBM 10% SAP France 0% Pentana Protiviti Overmind MetricStream Mega International Clarity GRC Click -N-Manage CMO Compliance LexisNexis Novasecur Oxial France Thomson Reuters MAAT Keyword Cogis Clarity GRC Click-N-Manage CMO Compliance AON eSolutions BWise 100% Devoteam Effisoft 90% 80% eFront 20% ROK Solution Protiviti SAS France Oxial France MetricStream Mega International EMC / RSA 50% Software AG 10% SAP France Thomson Reuters MetricStream Mega International MAAT Keyword REPORTING 70% Marsh France BVD / Bureau Van Dijk SAS France Overmind Clarity GRC CMO Compliance CUSTOMIZATION Siaci Saint Honoré Covelys Tinubu Square Oxand LexisNexis Novasecur Oxial France Thomson Reuters MAAT IBM 0% ROK Solution Protiviti MetricStream Mega International 20% 10% SAS France Overmind Gras Savoye 30% SAP France Novasecur Oxial France 40% Software AG IBM 0% Figtree Systems 50% 1-One Gras Savoye 20% Enablon 60% BVD / Bureau Van Dijk Figtree Systems 40% 70% Marsh France Enablon 60% SAS France Thomson Reuters Click -N-Manage CMO Compliance MAAT Cogis Keyword EMC / RSA Infogov WORKFLOWS AON eSolutions Siaci Saint Honoré 100% BWise Covelys Devoteam 90% Tinubu Square Effisoft Oxand Marsh France BVD / Bureau Van Dijk 1-One Software AG SAP France 80% 70% 60% 50% 40% 30% 20% 10% 0% ROK Solution eFront Enablon Figtree Systems Gras Savoye IBM Novasecur Protiviti Pentana SAS France Oxial France Thomson Reuters Overmind MetricStream Mega International Copyright © 2013 AMRAE, in partnership with ACCENTURE Clarity GRC MAATKeyword Cogis EMC / RSA Click -N-Manage CMO Compliance 23 / 68 RMIS Panorama 2013 Detailed datasheets by vendor The responses provided by each vendor are summarized on a datasheet presented as follows: Contacts details of the vendor Logo of the vendor Contact person within the vendor Panorama SIGR 2013 α SIGR General information about the vendor Name, kind, composition and dominant(s) of the solution Strengths according to the vendor α SIGR α SIGR 12 rue des Risques 750xxParis, France www.alpha-sigr.fr First Name Last Name Director +33 (0) 1 xx xx xx xx / + 33 (0) 6 xx xx xx xx [email protected] VENDOR COMPANY ID CARD Founded in 2002 Global workforce 50 RMIS workforce 15 - RMIS implementation 20 - RMIS consulting 5 Area(s) of presence France, Europe, Africa Vendor statement of its own particularities and differentiating factors A vendor specialized on certain categories of risks XXX VENDOR’S AVAILABLE SOLUTION(S) Solution(s) α SIGR Kind of solution according to the vendor A standard tool integrating extensive possibilities of configuration Composition of the solution Several modules in a same application Dominant(s) ERM and Insurance Club of users Club of users Strengths according to the vendor Yes (12 meetings per year) Created in 2008 Administered by clients and the vendor XXX Data hosting Stated number of implementation projects Vendor statement of its own particularities and differentiating factors At the vendor / At the client Stated number of implementation projects Industries of implemented projects Since the release of the solution In the last 12 months In France 25 In France 89 Abroad 5 Abroad 23 Average number of users per solution From 51 to 100 Bank (12%), Insurance (12%), Industry and services (56%), Public Sector (20%) Coverage of functional areas* Possibility of data hosting Coverage of technical areas* Average number of users per solution Industries of implemented projects *The results transcribed on this form are consistent with responses provided by the vendor Stated coverage of functional areas in 2013 Disclaimer Stated coverage of technical areas in 2013 Note: When the vendor did not answer some questions needed to fill in specific entries of its form, or when answers were not usable, corresponding entries have been marked with “n/r” (for “no reply”). 24 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 1-One 1-One 25 rue Tronchet 75008 Paris, France www.1-one.fr Yann Lucas Development Director +33 (0) 1 83 62 37 70 [email protected] VENDOR COMPANY ID CARD Founded in 2006 Global workforce 26 RMIS workforce n/r - RMIS implementation 8 - RMIS consulting 8 Area(s) of presence France Vendor statement of its own particularities and differentiating factors A vendor specialized on certain categories of risks 1-One : Web-based software designed for the prevention of occupational risks, the hardness at work, the workplace health, the classification and the prevention of chemical risks VENDOR’S AVAILABLE SOLUTION(S) Solution(s) 1-One Kind of solution according to the vendor A completely standard tool Composition of the solution Several modules in a same application Dominant(s) ERM Club of users Strengths according to the vendor Yes (1 meeting per year) Created in 2010 Administered by the vendor Complete web-based risk prevention software Data hosting At the vendor In the last 12 months Since the release of the solution Stated number of implementation projects In France 6 In France 16 Abroad 0 Abroad 0 Industries of implemented projects Industry and services (40%), Public sector (60%) Average number of users per solution From 6 to 50 Coverage of functional areas* Coverage of technical areas* Insurance Management 3,00 Competitive Intelligence Incidents / Losses Quality Management Governance 2,50 2,00 1,50 1,00 0,50 0,00 Crisis Management / BCP Access Management Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Compliance Audit Internal Control Organization Languages Export Import (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 25 / 68 RMIS Panorama 2013 AON eSolutions AON eSolutions 3350 Riverwood Parkway, Suite 80 5th Floor GA 30339 Atlanta, USA www.aon-esolutions.com Eric Leenhardt eSolutions France Manager +33 (0) 1 47 83 05 70 / +33 (0) 6 23 47 61 53 [email protected] VENDOR COMPANY ID CARD Founded in 2001 Global workforce 360 RMIS workforce 182 - RMIS implementation 50 - RMIS consulting 12 Area(s) of presence France, Europe, Asia-Pacific, North America Vendor statement of its own particularities and differentiating factors A specialized vendor in RMIS Designed by Insurance professionals - Dedicated Global support - Over 40 years experience VENDOR’S AVAILABLE SOLUTION(S) Solution(s) Aon RiskConsole Kind of solution according to the vendor A configurable toolbox Composition of the solution Several modules in a same application Dominant(s) ERM Club of users Strengths according to the vendor Aon RiskConsole empowers you with « Business Intelligence » tools to quickly interpret data and make decisions to reduce risks, control losses and avoid business interruption Yes (3 meetings per year) Created in 2008 Administered by the vendor Data hosting At the vendor In the last 12 months Stated number of implementation projects Industries of implemented projects Since the release of the solution In France 6 In France 25 Abroad 50 Abroad 450 Average number of users per solution From 51 to 100 Bank (5%), Insurance (1%), Industry and services (62%), Public sector (10%), Others (22 %) Coverage of functional areas* Coverage of technical areas* Insurance Management 3,00 Competitive Intelligence Incidents / Losses Quality Management Governance 2,50 2,00 1,50 1,00 0,50 0,00 Crisis Management / BCP Access Management Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor 26 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 BVD / Bureau Van Dijk (new respondent) BVD / Bureau Van Dijk 7 rue Drouot 755009 Paris, France www.bvdinfo.com Thomas Perathoner Responsible for customer relationship +33 (0) 1 53 45 46 26 / +33 (0) 6 81 57 48 38 [email protected] VENDOR COMPANY ID CARD Founded in 1989 Vendor statement of its own particularities and differentiating factors Global workforce 500 RMIS workforce 300 A vendor specialized on certain categories of risks and specialized in RMIS / A non specialized vendor / Development of macroeconomic and M&A information tools - RMIS implementation 100 - RMIS consulting 100 Area(s) of presence France, Europe, Asia-Pacific, North America, South America, Africa The added value of our tools lies in the complete integration of dynamic risk management system, which is possible to combine with information from a customer portfolio. Thus, our clients combine and integrate their own models to our financial information on more than 100 million companies worldwide VENDOR’S AVAILABLE SOLUTION(S) Solution(s) Orbis Procurement Catalyst Kind of solution according to the vendor A configurable tool and a development environment Composition of the solution Several distinct applications Dominant(s) ERM Club of users Strengths according to the vendor No Flexibility Data hosting At the vendor / At the client Stated number of implementation projects Industries of implemented projects In the last 12 months Since the release of the solution In France n/r In France n/r Abroad n/r Abroad n/r Average number of users per solution From 6 to 50 Bank (30%), Insurance (10%), Industry and services (55%), Public sector (5%) Coverage of functional areas* Coverage of technical areas* Access Management Insurance Management Competitive Intelligence 3,00 Incidents / Losses Quality Management Governance 2,50 2,00 1,50 1,00 0,50 0,00 Crisis Management / BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 27 / 68 RMIS Panorama 2013 BWise BWise 19 boulevard Malesherbes 75008 Paris, France www.bwise-grc.fr Stéphane Dorchin Director (France) +33 (0) 1 55 27 37 28 / +33 (0) 6 76 96 42 13 [email protected] VENDOR COMPANY ID CARD Founded in 1994 Global workforce 160 RMIS workforce 160 - RMIS implementation 31 - RMIS consulting 40 Area(s) of presence France, Europe, Asia-Pacific, North America, South America, Africa Vendor statement of its own particularities and differentiating factors A specialized vendor in RMIS Bwise offers solutions for : Risk Management, Internal Audit, Internal Control, Compliance Management, and subjects on Sustainable Development and Social Responsibility. Each of these solutions, based on a business expertise, is part of the standard and integrated GRC platform VENDOR’S AVAILABLE SOLUTION(S) Solution(s) BWise Risk Management, BWise Internal Audit, BWise Internal Control, BWise Compliance Management, BWise IT GRC, BWise Sustainable Development Kind of solution according to the vendor A completely standard tool Composition of the solution A single application Dominant(s) ERM and Insurance Club of users Yes (4 meetings per year) Created in 2009 Administered by clients and the vendor Its functional richness associated with a very high flexibility allowing any organization to integrate its methodology by configurating BWise as they wish Strengths according to the vendor Data hosting At the vendor’s subcontractor / At the client Stated number of implementation projects Industries of implemented projects In the last 12 months Since the release of the solution In France 5 In France 13 Abroad 40 Abroad 400 Average number of users per solution From 201 to 500 Bank (20%), Insurance (12%), Industry and services (54%), Public sector (9%), Others (5 %) Coverage of functional areas* Coverage of technical areas* Access Management Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management Customization Action Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Documentation Risk Mapping Export Organization Compliance Audit Languages Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor 28 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Clarity GRC (new respondent) Clarity GRC PO Box 634 GU9 1 HRFarnham, UK www.ClarityGRC.com Stephen Hall Managing Director +44 (0) 14 83 81 09 64 / +44 (0) 77 85 51 17 73 [email protected] VENDOR COMPANY ID CARD Founded in 2004 Global workforce 10 RMIS workforce 10 - RMIS implementation 0 - RMIS consulting 3 Area(s) of presence France, Europe, AsiaPacific, South America, Africa Vendor statement of its own particularities and differentiating factors A vendor specialized on certain categories of risks and specialized in RMIS The most comprehensive and easy to use GRC Software product in EMEA. Support for an Integrated Management System (IMS) to combine the most common compliance standards in a single management framework (e.g. ISO 27001, ISO 22301, ISO 9001, ISO 14001) VENDOR’S AVAILABLE SOLUTION(S) Solution(s) Proteus GRC Kind of solution according to the vendor A completely standard tool Composition of the solution Several modules in a same application Dominant(s) ERM Club of users Strengths according to the vendor No Comprehensive GRC Solution « out of the box » Data hosting At the vendor / At the client In the last 12 months Stated number of implementation projects Industries of implemented projects Since the release of the solution In France n/r In France n/r Abroad n/r Abroad n/r Average number of users per solution From 51 to 100 Bank (25%), Insurance (10%), Industry and services (50%), Public sector (15%) Coverage of functional areas* Coverage of technical areas* Access Management Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 29 / 68 RMIS Panorama 2013 Click-N-Manage (new respondent) Click-N-Manage 3 rue des Plantaporrêts 1205 Genève, Suisse www.click-n-manage.com David Balme CEO +41 (0) 22 73 81 311 / +41 (0) 78 89 26 813 [email protected] VENDOR COMPANY ID CARD Founded in 1994 Vendor statement of its own particularities and differentiating factors Global workforce 10 RMIS workforce 5 A vendor specialized on certain categories of risks and specialized in RMIS / A non specialized vendor - RMIS implementation 8 - RMIS consulting 8 Area(s) of presence n/r Click-N-Manage offers an integrated risk maangement system, allowing to formally evaluate the degree of control by the existing management system and monitor this level of control overe time. It can rely on any management framework (ISO 9001, 14001, OHSAS 18001, ISO 22000, BPF-GMP, ISO 27001, COSO, BASEL II/III ...) VENDOR’S AVAILABLE SOLUTION(S) Solution(s) Click-N-Manage Kind of solution according to the vendor A completely standard tool Composition of the solution Several modules in a same application Dominant(s) ERM Club of users Strengths according to the vendor Yes (1 meeting per year) Created in 2011 Administered by the vendor Compliance to risk management standards Data hosting At the vendor / At the client Stated number of implementation projects Industries of implemented projects In the last 12 months Since the release of the solution In France 10 In France 10 Abroad 2 Abroad 2 Average number of users per solution From 101 to 200 Industry and services (80%), Public sector (20%) Coverage of functional areas* Coverage of technical areas* Access Management Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Audit Languages Export Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor 30 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 CMO Compliance (new respondent) CMO Compliance 91-93 Buckingham Palace Rd SW1W0RPLondres, UK www.cmo-compliance.com Cotton James GRC Solution Director +33 (0) 6 13 95 21 70 77 / +33 (0) 6 13 95 21 70 77 [email protected] VENDOR COMPANY ID CARD Founded in 2002 Global workforce 80 RMIS workforce 80 - RMIS implementation 4 - RMIS consulting 20 Area(s) of presence Europe, AsiaPacific, North America, Africa Vendor statement of its own particularities and differentiating factors A vendor specialized on certain categories of risks and specialized in RMIS CMO COMPLIANCE is a recognized market leader in enterprise governance, risk, compliance and quality software solutions for global corporations and regulators, with a focus on mining, oil & gas and heavy industry. CMO COMPLIANCE solutions are used by leading corporations and regulators such as Barrick Gold, ISS, Orica, Liberty Mutual, Owens Corning, AXA Bank, McCormick, Xstrata and Philip Morris in a range of industries including Financial Services, Food, Energy and Mining, Oil & Gas to manage their GRC processes, regulatory and industry-mandated compliance and corporate governance initiatives VENDOR’S AVAILABLE SOLUTION(S) Solution(s) CMO COMPLIANCE Kind of solution according to the vendor A configurable toolbox Composition of the solution Several modules in a same application Dominant(s) ERM Club of users Strengths according to the vendor Yes (1 meeting per year) Created in 2010 Administered by the vendor Highly configurable & flexible Data hosting At the vendor / At the client Stated number of implementation projects Industries of implemented projects In the last 12 months Since the release of the solution In France 1 In France 1 Abroad 60 Abroad 200 Average number of users per solution More than 1000 Bank (10%), Insurance (10%), Industry and services (60%), Public sector (5%), Others (15 %) Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 31 / 68 RMIS Panorama 2013 Cogis (new respondent) Cogis 1 boulevard Charles de Gaulle 92700 Colombes, France www.cogis-software.com/ Philippe Donguy Operations Director +33 (0) 1 47 82 40 59 / +33 (0) 6 60 45 25 69 [email protected] VENDOR COMPANY ID CARD Founded in 1905 Global workforce 7 RMIS workforce n/r - RMIS implementation 3 - RMIS consulting n/r Area(s) of presence France Vendor statement of its own particularities and differentiating factors A specialized vendor in RMIS Cogis –Software is specialized in the area of monitoring missions related to risks. The Horus Web solution ensures the traceability and “workflow” processes guaranteeing exchanges and the progression of each mission. Ergonomics and standardized exchanges are guarantors of quality in order to provide a basis for monitoring missions and the related actions VENDOR’S AVAILABLE SOLUTION(S) Solution(s) Horus Web, Horus Word, Horus BI Kind of solution according to the vendor A completely standard tool Composition of the solution Several modules in a same application Dominant(s) ERM Club of users - The centralization and monitoring of exchanges between the participants of the mission - The desynchronization in autonomous mode on a laptop and risk analysis Strengths according to the vendor No Data hosting At the vendor / At the vendor’s subcontractor / At the client Stated number of implementation projects Industries of implemented projects In the last 12 months Since the release of the solution In France 5 In France 35 Abroad 1 Abroad 4 Average number of users per solution From 0 to 5 Bank (35%), Insurance (30%), Industry and services (30%), Public sector (5%) Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Audit Languages Export Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor 32 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Covelys Covelys 87 avenue du 8 mai 1945 66700 Argeles Sur Mer, France www.covelys.fr Arnaud Benhamdine Director +33 (0) 9 53 00 00 00 / +33 (0) 6 47 59 63 84 [email protected] VENDOR COMPANY ID CARD Founded in 2012 Global workforce 2 RMIS workforce 1 - RMIS implementation 2 - RMIS consulting 1 Area(s) of presence France Vendor statement of its own particularities and differentiating factors A non specialized vendor Vendor of risk management solutions, legal management and vehicle fleet management VENDOR’S AVAILABLE SOLUTION(S) Solution(s) RMSoft Insurances management module , RMSoft risk management module, RMSoft litigation management module Kind of solution according to the vendor A configurable toolbox Composition of the solution Several modules in a same application Dominant(s) Insurance Club of users Strengths according to the vendor No Automation of administrative processes Data hosting At the vendor’s subcontractor / At the client Stated number of implementation projects In the last 12 months Since the release of the solution Industries of implemented projects Industry and services (80%), Public sector (20%) In France 3 In France 60 Abroad 0 Abroad 0 Average number of users per solution From 0 to 5 Coverage of functional areas* Coverage of technical areas* Access Management Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 33 / 68 RMIS Panorama 2013 Devoteam Devoteam 73 rue Anatole France 92 300 Levallois Perret, France www.rvr.devoteam.com / www.devoteam.com Agnes Poyard Director of Products Marketing and Professional Services RVR PARAD +33 (0) 1 41 49 55 62 / +33 (0) 6 59 91 35 10 [email protected] VENDOR COMPANY ID CARD Founded in 1905 Global workforce 5000 RMIS workforce 130 - RMIS implementation 13 - RMIS consulting 100 Area(s) of presence France, Europe, South America, Africa Vendor statement of its own particularities and differentiating factors A specialized vendor in RMIS RVR PARAD software package solution from the Devoteam Group specialist in Risk Management, Internal Control, Audit and Business Continuity VENDOR’S AVAILABLE SOLUTION(S) Solution(s) RVR PARAD Kind of solution according to the vendor A configurable toolbox Composition of the solution Several modules in a same application Dominant(s) ERM Club of users Strengths according to the vendor Yes (1 meeting per year) Created in 2004 Administered by clients and the vendor Integrated and configurable platform Data hosting At the vendor / At the vendor’s subcontractor / At the client Stated number of implementation projects Industries of implemented projects In the last 12 months Since the release of the solution In France 6 In France 50 Abroad 1 Abroad 8 Average number of users per solution From 501 to 1000 Bank (10%), Insurance (20%), Industry and services (55%), Public sector (15%) Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management Customization 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Documentation Risk Mapping Action Management Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor 34 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Effisoft Effisoft 26 rue d'Athènes 75009 Paris, France www.effisoft.fr Edouard Lefebvre Product Director +33 (0) 1 42 93 72 52 / +33 (0) 6 61 36 87 79 [email protected] VENDOR COMPANY ID CARD Founded in 1990 Global workforce 83 RMIS workforce 83 - RMIS implementation 5 - RMIS consulting 26 Area(s) of presence France, Europe, North America Vendor statement of its own particularities and differentiating factors A specialized vendor in RMIS Effisoft is the independent company that has been publishing Webrisk for over 20 years, the only software developed by and for risk managers and used worldwide. With Webrisk, the daily work of the Risk Management Department is easier, more reliable and efficient VENDOR’S AVAILABLE SOLUTION(S) Solution(s) Webrisk Kind of solution according to the vendor A completely standard tool Composition of the solution A single application Dominant(s) ERM and Insurance Club of users Strengths according to the vendor No Webrisk meets all the needs of risk managers Data hosting At the vendor / At the vendor’s subcontractor / At the client Stated number of implementation projects In the last 12 months Since the release of the solution Industries of implemented projects Bank (11%), Insurance (3%), Industry and services (85%), Public sector (1%) In France n/r In France n/r Abroad n/r Abroad n/r Average number of users per solution From 101 to 200 Coverage of functional areas* Coverage of technical areas* Access Management Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Incidents / Losses Crisis Management/ BCP Risk Management Action Management Workflow Reporting Customization 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Documentation Risk Mapping Organization Compliance Audit Languages Export Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 35 / 68 RMIS Panorama 2013 eFront eFront 2/4 rue Louis David 75116 Paris, France http://fr.efront.com/ERM-GRC_30/ Birame Fall Product Manager +33 (0) 1 49 96 94 31 / +33 (0) 7 78 69 52 21 [email protected] VENDOR COMPANY ID CARD Founded in 1999 Vendor statement of its own particularities and differentiating factors Global workforce 326 RMIS workforce 82 A vendor specialized on certain categories of risks and specialized in RMIS / A non specialized vendor - RMIS implementation 35 - RMIS consulting 20 Area(s) of presence France, Europe, Asia-Pacific, North America, Africa eFront is the only GRC and ERM vendor who has developed and natively integrated a powerful analytics solution (FrontAnalytics) in their GRC and ERM solutions. FrontERM for Solvency II: solution to support ORSA (Own Risk Solvency Assessment) requirement, integration of simulation capabilities (stress testing, back testing).MS Office integration to facilitate the change management process. A large coverage of GRC requirements: •Enterprise risk management, risk mapping •Loss and events •Internal control •Compliance •Action plan •Indicators management • Recommendation •Quantification •Audit management •Crisis management •Business continuity plan •Corporate management •Financial management •Sign and authorization management VENDOR’S AVAILABLE SOLUTION(S) Solution(s) FrontERM, FrontGRC Kind of solution according to the vendor A configurable toolbox Composition of the solution Several modules in a same application Dominant(s) ERM and Insurance Club of users Strengths according to the vendor Provide a standard to avoid starting from scratches and completely configurable to come up with a customized solution Yes (4 meetings per year) Created in 2008 Administered by clients Data hosting At the vendor / At the vendor’s subcontractor / At the client Stated number of implementation projects Industries of implemented projects In the last 12 months Since the release of the solution In France 10 In France 90 Abroad 3 Abroad 15 Average number of users per solution From 101 to 200 Bank (30%), Insurance (30%), Industry and services (20%), Public sector (20%) Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Documentation Customization Action Management Risk Mapping Organization Compliance Audit Languages Export Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor 36 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Elseware Elseware 85 rue Edouard Vaillant 92300 Levallois-Perret, France www.elseware.fr Patrick Naim CEO +33 (0) 1 44 58 93 40 [email protected] VENDOR COMPANY ID CARD Founded in 1993 Global workforce 10 RMIS workforce 5 - RMIS implementation 5 - RMIS consulting 5 Area(s) of presence France Vendor statement of its own particularities and differentiating factors A specialized vendor in RMIS ESLEWARE is an engineering company specialized in the analysis, modeling and quantification of risk scenarios VENDOR’S AVAILABLE SOLUTION(S) Solution(s) MSTAR Kind of solution according to the vendor A completely standard tool Composition of the solution Several modules in a same application Dominant(s) ERM Club of users No Strengths according to the vendor Quantification of scenarios Data hosting At the vendor / At the vendor’s subcontractor / At the client Stated number of implementation projects In the last 12 months Since the release of the solution Industries of implemented projects Bank (60%), Insurance (20%), Industry and services (20%) In France 9 In France 20 Abroad 1 Abroad 2 Average number of users per solution From 0 to 5 Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management Customization Action Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 37 / 68 RMIS Panorama 2013 EMC / RSA EMC / RSA 80 Quai Voltaire, Immeuble River Ouest 95876 Bezons Cedex, France www.emc.com/rsa Philippe Fauchay Sales Director +33 (0) 1 39 96 92 33 [email protected] VENDOR COMPANY ID CARD Founded in 1986 Global workforce 45000 RMIS workforce 500 - RMIS implementation n/r - RMIS consulting n/r Area(s) of presence France, Europe, AsiaPacific, North America, South America, Africa Vendor statement of its own particularities and differentiating factors A non specialized vendor RSA edits and commercializes the Archer solution which is recognized as a world leader in both IT-GRC and Enterprise-GRC. Archer is an open platform featuring 9 thematic modules including: Risk Management, Policy Management, Compliance Management and Incident Management who are often integrated to manage problematics of risk management of our clients VENDOR’S AVAILABLE SOLUTION(S) Solution(s) Archer Kind of solution according to the vendor A completely standard tool Composition of the solution Several modules in a same application Dominant(s) ERM and Insurance Club of users Archer differentiates itself by a greater openness and ease of customization as well as libraries of very rich content including both the main sources of authority and hundreds of controls already mapped to these sources of authority Strengths according to the vendor Stated number of implementation projects Industries of implemented projects In the last 12 months Governance At the vendor / At the vendor’s subcontractor / At the client In France 4 In France 6 Abroad 200 Abroad 500 Average number of users per solution From 201 to 500 Bank (30%), Insurance (15%), Industry and services (30%), Public sector (10%), Others (15 %) Coverage of technical areas* Insurance Management Quality Management Data hosting Since the release of the solution Coverage of functional areas* Competitive Intelligence No 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management Customization Action Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Documentation Risk Mapping Organization Compliance Audit Languages Export Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor 38 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Enablon Enablon 2 boulevard Georges Clemenceau 92400 Courbevoie, France www.enablon.com Nicolas Canteau Product Manager ERM +33 (0) 1 47 33 95 84 [email protected] VENDOR COMPANY ID CARD Founded in 2000 Global workforce 365 RMIS workforce n/r - RMIS implementation n/r - RMIS consulting n/r Area(s) of presence France, AsiaPacific, North America Vendor statement of its own particularities and differentiating factors A vendor specialized on certain categories of risks and specialized in RMIS The particularity of Enablon is its coverage and depth of integrated treatment of topics related to performance. Enablon’s solutions are used by more than 300 companies, 300,000 users and tens of thousands of SMEs in all business sectors VENDOR’S AVAILABLE SOLUTION(S) Solution(s) ERM suite Kind of solution according to the vendor A completely standard tool Composition of the solution Several distinct applications Dominant(s) ERM and Insurance Club of users Strengths according to the vendor The ability to process Sustainable Performance, Risk and Compliance in an integrated manner Yes (2 meetings per year) Created in 2009 Administered by the vendor Data hosting At the vendor / At the vendor’s subcontractor / At the client Stated number of implementation projects Industries of implemented projects In the last 12 months Since the release of the solution In France 15 In France 100 Abroad 15 Abroad 100 Average number of users per solution From 201 to 500 Bank (20%), Insurance (5%), Industry and services (50%), Public sector (10%), Others (15 %) Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management Customization Action Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Documentation Risk Mapping Organization Compliance Audit Languages Export Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 39 / 68 RMIS Panorama 2013 Figtree Systems (new respondent) Figtree Systems 2 Royal Exchange, 3rd Floor, EC3V3DG Londres, UK www.figtreesystems.com Ayaz Merchant Head Of Sales (EMEA) +44 (0) 20 72 20 92 16 [email protected] VENDOR COMPANY ID CARD Founded in 1985 Global workforce 65 RMIS workforce n/r - RMIS implementation n/r - RMIS consulting n/r Area(s) of presence Europe, AsiaPacific, North America Vendor statement of its own particularities and differentiating factors A specialized vendor in RMIS NTT DATA Figtree Systems is a specialist software provider for Risk Management Information Systems. This award winning system is used by clients globally for: Incident and OH&S Management, Claims Management, Corporate Insurance and Employee Benefits Management, Fleet and Asset Management and Enterprise Risk Management. VENDOR’S AVAILABLE SOLUTION(S) Solution(s) NTT DATA Figtree Systems Kind of solution according to the vendor A development environment Composition of the solution Several distinct applications Dominant(s) ERM and Insurance Club of users Strengths according to the vendor Yes (3 meetings per year) Created in 1995 Administered by clients n/r Data hosting At the vendor’s subcontractor Stated number of implementation projects In the last 12 months Since the release of the solution Industries of implemented projects Insurance (25%), Industry and services (25%), Public sector (25%), Others (25 %) In France 1 In France 2 Abroad 6 Abroad 70 Average number of users per solution From 6 to 50 Coverage of functional areas* Coverage of technical areas* Access Management Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management Customization Action Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor 40 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Gras Savoye Gras Savoye 33 quai dion bouton 92800 Paris, France www.grassavoye.com Chantal Carnel Project Manager Universe +33 (0) 1 41 43 69 86 / +33 (0) 6 72 83 44 85 [email protected] VENDOR COMPANY ID CARD Founded in 1907 Global workforce 3700 RMIS workforce 22 - RMIS implementation 10 - RMIS consulting 3 Area(s) of presence France, Europe, Asia-Pacific, North America, South America, Africa Vendor statement of its own particularities and differentiating factors A vendor specialized on certain categories of risks and specialized in RMIS Universe is created by Enablon and Gras Savoye. Enablon provides its technical platforms and Gras Savoye its business skills VENDOR’S AVAILABLE SOLUTION(S) Solution(s) UNIVERSE Kind of solution according to the vendor A configurable toolbox Composition of the solution Several modules in a same application Dominant(s) ERM and Insurance Club of users Strengths according to the vendor Yes (2 meetings per year) Created in 2005 Administered by clients Covers every aspects of Risk Management Data hosting At the vendor / At the vendor’s subcontractor / At the client Stated number of implementation projects Industries of implemented projects In the last 12 months Since the release of the solution In France 3 In France 15 Abroad 2 Abroad 10 Average number of users per solution More than 1000 Bank (50%), Insurance (15%), Industry and services (30%), Public sector (5%) Coverage of functional areas* Coverage of technical areas* Access Management Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management Customization 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Documentation Risk Mapping Action Management Organization Compliance Audit Languages Export Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 41 / 68 RMIS Panorama 2013 IBM (new respondent) IBM 17 avenue de l'Europe 92275 Bois Colombes Cedex, France www.ibm.com/fr/fr/ Stephan Molliere GRC Sales Leader - IBM France +33 (0) 6 37 36 92 18 / +33 (0) 6 37 36 92 18 [email protected] VENDOR COMPANY ID CARD Founded in 1911 Vendor statement of its own particularities and differentiating factors Global workforce 10769 RMIS workforce n/r A vendor specialized on certain categories of risks and specialized in RMIS / A non specialized vendor - RMIS implementation 0 - RMIS consulting n/r Area(s) of presence France, Europe, Asia-Pacific, North America, South America, Africa IBM provides a modular and configurable integrated risk management platform allowing to increase the productivity of risks and controls departments, to improve governance with reporting functions and standard and native analyzes, reduce risks exposures. The risk architecture of IBM, particularly scalable and resilient, enables to secure your investment sustainably VENDOR’S AVAILABLE SOLUTION(S) Solution(s) OpenPages Kind of solution according to the vendor OpenPages is flexible and configurable Composition of the solution A single application Dominant(s) ERM Platform Club of users Strengths according to the vendor Complete, modular, integrated, resilient solution used by hundreds of national and international companies Yes (1 meetings per year) Created in 2004 Administered by the vendor Data hosting n/r In the last 12 months Stated number of implementation projects Industries of implemented projects Since the release of the solution In France 8 In France 8 Abroad 300 Abroad 300 Average number of users per solution From 501 to 1000 n/r Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor 42 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Keyword Keyword 90 Allée Sacha Guitry, ZAC de Tournézy 34070 Montpellier, France www.keyword.fr Daniel Delpuech Manager +33 (0) 4 67 07 72 00 / +33 (0) 6 15 77 44 61 [email protected] VENDOR COMPANY ID CARD Founded in 1985 Vendor statement of its own particularities and differentiating factors Global workforce 21 RMIS workforce 18 A vendor specialized on certain categories of risks and specialized in RMIS ainsi que dans la lutte anti-fraude - RMIS implementation 3 - RMIS consulting 4 Area(s) of presence France, Africa GRC solutions tailored or ready to use – Configurable in agile mode – Integration of IBM specialized software moduls – Open Architecture – High availibility and high performances – Large volumetry – Installation at the client or made available in Cloud/Saas mode – Evolutivity guaranted and configurable by the client VENDOR’S AVAILABLE SOLUTION(S) Solution(s) ISIMAN GRC Kind of solution according to the vendor A configurable toolbox Composition of the solution A platform for any client / any solution and solutions composed of configurable business components Dominant(s) Risk Management and fight against fraud Club of users Strengths according to the vendor The power of ISIMAN Studio to fully configure the components of any ISIMAN GRC solution: processes components and frameworks components Yes (2 meetings per year) Created in 2007 Administered by clients and the vendor Data hosting At the vendor / At the vendor’s subcontractor / At the client In the last 12 months Stated number of implementation projects Industries of implemented projects Since the release of the solution In France 2 In France 15 Abroad 2 Abroad 8 Average number of users per solution From 501 to 1000 Bank (20%), Insurance (30%), Industry and services (20%), Public sector (30%) Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Languages Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 43 / 68 RMIS Panorama 2013 LexisNexis LexisNexis 141 rue de javel 75015 Paris, France www.lexisnexis.fr Jean-Marc Thomas Business Development Director +33 (0) 1 45 58 92 50 / +33 (0) 6 25 13 33 18 [email protected] VENDOR COMPANY ID CARD Founded in 1940 Global workforce 35000 RMIS workforce 3000 - RMIS implementation n/r - RMIS consulting n/r Area(s) of presence France, Europe, Asia-Pacific, North America, South America, Africa Vendor statement of its own particularities and differentiating factors A vendor specialized on certain categories of risks / A non specialized vendor LexisNexis France offers unique solutions for companies to manage their legal risks within their business. Lexis Compliance Insurance notably allows to address Solvency II and Lexis Compliance Thematic, the riskier transversal topics VENDOR’S AVAILABLE SOLUTION(S) Solution(s) LexisNexis Compliance Insurance Kind of solution according to the vendor A configurable toolbox Composition of the solution A single application Dominant(s) ERM and Insurance Club of users Strengths according to the vendor Yes (2 meetings per year) Created in 2010 Administered by the vendor Completeness of regulatory issues within Solvency II Data hosting At the vendor’s subcontractor Stated number of implementation projects Industries of implemented projects In the last 12 months Since the release of the solution In France 10 In France 20 Abroad 0 Abroad 0 Average number of users per solution From 6 to 50 Bank (10%), Insurance (90%) Coverage of functional areas* Coverage of technical areas* Access Management Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor 44 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 MAAT MAAT 10 bis rue du Couvent 91730 Chamarande, France www.maat-ingenierie.fr José-Marie Belda R&D Director +33 (0) 1 60 82 07 89 / +33 (0) 6 24 36 72 80 [email protected] VENDOR COMPANY ID CARD Founded in 2006 Global workforce 3 RMIS workforce 3 - RMIS implementation 2 - RMIS consulting 2 Area(s) of presence France Vendor statement of its own particularities and differentiating factors A specialized vendor in RMIS / A non specialized vendor Versatility, flexibility of use by usage segments : every type of risks, frameworks, deployment modes, trades and business sectors, integrated system VENDOR’S AVAILABLE SOLUTION(S) Solution(s) Maat Pilote : MP-Audits, MP-Forms, MP-Documentary, MP-Planifications, MP-Processus, MPProjects, MP-Vigil, MP-RMIS Kind of solution according to the vendor A configurable toolbox Composition of the solution Several modules in a same application Dominant(s) ERM and Insurance Club of users Strengths according to the vendor No Absolute flexibility for all purposes Data hosting At the vendor’s subcontractor / At the client Stated number of implementation projects In the last 12 months Since the release of the solution In France 1 In France 5 Abroad 0 Abroad 0 Average number of users per solution From 0 to 5 Bank (5%), Insurance (5%), Industry and services (50%), Public sector (30%), Others (10 %) Industries of implemented projects Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Documentation Risk Mapping Action Management Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 45 / 68 RMIS Panorama 2013 Marsh France Marsh France Tour Ariane - La Défense 9 92088 Paris La Défense Cedex, France www.france.marsh.com Nabil Homsi Information Systems Manager – Risk Management at Marsh Risk Consulting +33 (0) 1 41 34 76 04 [email protected] VENDOR COMPANY ID CARD Founded in n/r Global workforce 830 RMIS workforce 11 - RMIS implementation n/r - RMIS consulting 35 Area(s) of presence France, Europe, Asia-Pacific, North America, South America, Africa Vendor statement of its own particularities and differentiating factors Insurance broker offering a RMIS solution Number 1 wordwide in insurance brokerage and management consulting of business risks, Marsh assists its clients at every stages of controlling their risks: - Risks Assessment – Risk Treatment (including transfer) – Disaster Management and associated services VENDOR’S AVAILABLE SOLUTION(S) Solution(s) MARIS (Monitor & Analysis Risk Information System), MarshSat Kind of solution according to the vendor A standard tool integrating extensive possibilities of configuration Composition of the solution Several distinct applications Dominant(s) ERM and Insurance Club of users Strengths according to the vendor A close relationship with the client and the Marsh Risk Consulting team allowing to optimize the implementation, deployment and maintenance of MARIS at our clients No Data hosting At the vendor In the last 12 months Stated number of implementation projects Industries of implemented projects Since the release of the solution In France 5 In France 20 Abroad 0 Abroad 0 Average number of users per solution From 6 to 50 Bank (7%), Insurance (7%), Industry and services (71%), Public sector (15%) Coverage of functional areas* Coverage of technical areas* Access Management Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor 46 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Mega International Mega International 9 avenue René Coty 75014 Paris, France www.mega.com Jean-Marie Zirano Vice-President, Product Strategy +33 (0) 1 42 75 40 00 / +33 (0) 1 42 75 41 10 / +33 (0) 6 08 18 88 38 [email protected] VENDOR COMPANY ID CARD Founded in 1992 Global workforce 300 RMIS workforce 78 - RMIS implementation 130 - RMIS consulting 45 Area(s) of presence France, Europe, Asia-Pacific, North America, South America, Africa Vendor statement of its own particularities and differentiating factors A specialized vendor in RMIS The GRC Solutions of MEGA covers risk management, internal control, compliance and audit. They improve the operational model combining risk management and the control policy to architectural activities, integrating the strategic challenges in a permanent alignment and improvement concern. Self-assessment and action plans make employees key actors of the transformation of their organization VENDOR’S AVAILABLE SOLUTION(S) Solution(s) MEGA GRC Platform Kind of solution according to the vendor A completely standard tool Composition of the solution Several distinct applications Dominant(s) ERM and Insurance Club of users Strengths according to the vendor Integration of risk solutions, control, compliance and audit on a unique platform Oui Created in 2010, Administered by an online community Data hosting At the vendor’s subcontractor / At the client In the last 12 months Stated number of implementation projects Industries of implemented projects Since the release of the solution In France 8 In France 55 Abroad 13 Abroad 38 Average number of users per solution From 501 to 1000 Bank (35%), Insurance (15%), Industry and services (25%), Public sector (15%), Others (10 %) Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Languages Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 47 / 68 RMIS Panorama 2013 MetricStream(new respondent) MetricStream 6th Floor, One London Wall EC2Y 5EB Londres, UK www.metricstream.com Shankar Bhaskaran VP & GM International Business Operations +44 (0) 20 33 18 85 54 / +44 (0) 79 42 85 35 32 [email protected] VENDOR COMPANY ID CARD Founded in 1999 Global workforce 950 RMIS workforce 100 - RMIS implementation 110 - RMIS consulting 275 Area(s) of presence France, Europe, AsiaPacific, North America, South America, Africa Vendor statement of its own particularities and differentiating factors A vendor specialized on certain categories of risks and specialized in RMIS An enterprise-ready GRC Platform with powerful AppStudio - Width of product portfolio allows for ongoing up-sell - Product leadership as GRC markets converge Ecosystem and Partnership Leverage - Partnership strategy: Strategic, Product, Content and Distribution - Ecosystem strategy and partner enablement - Thought leadership and policy level involvement Complete Value Proposition - Consulting and advisory: - Content: ComplianceOnline.com: Compliance training, content, knowledge platform - OnPremise and GRC Express OnDemand solution offerings GRC Cloud - Platform-as-a-service, AppStudio, AppExchange World Class Execution - Sharp sales and marketing execution - Focus on customer delight - Successful financial execution and financial appetite to fuel acquisitions or organic growth Strength of the management team VENDOR’S AVAILABLE SOLUTION(S) Solution(s) MetricStream Risk Management Kind of solution according to the vendor A completely standard tool Composition of the solution Several modules in a same application Dominant(s) ERM and Insurance Strengths according to the vendor Built on the MetricStream GRC Platform’s highly flexible GRC data model, the solution provides a fully integrated framework that meets end-to-end risk management requirements, and enables organizations to achieve their organizational goals while efficiently balancing risk and reward Club of users Yes (1 meeting per year), Created in 2009 Administered by clients and the vendor Data hosting At the vendor / At the client In the last 12 months Stated number of implementation projects Since the release of the solution In France 3 In France 5 Abroad 60 Abroad 300 Average number of users per solution From 51 to 100 Bank (40%), Insurance (10%), Industry and services (30%), Public sector (10%), Others (10 %) Industries of implemented projects Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor 48 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Novasecur (new respondent) Novasecur 8 rue Ferdinand Flocon 75018 Paris, France www.novasecur.com Cécile Coudrai Managing Director +33 (0) 1 42 52 41 51 / +33 (0) 4 42 61 01 66 [email protected] VENDOR COMPANY ID CARD Founded in 2010 Global workforce 12 RMIS workforce 12 - RMIS implementation 2 - RMIS consulting 4 Area(s) of presence France, Europe Vendor statement of its own particularities and differentiating factors A specialized vendor in RMIS Novasecur combines proprietary technologies (Datamining, Artificial Intelligence) with traditional audit and risk management methods, in modular decision-making solutions. Its structuring processes cover: questionnaires, mappings, Analytics, KPI and workflow. Results and alerts are reported on an ergonomic dashboard and dynamic reports VENDOR’S AVAILABLE SOLUTION(S) Solution(s) MyNovasecur ERM & Governance, MyNovasecur BI & Datamining Platform, MyNovasecur Fraud Management System Kind of solution according to the vendor A completely standard tool Composition of the solution Several modules in a same application Dominant(s) ERM and Insurance Club of users Strengths according to the vendor Yes (4 meetings per year) Created in 2011 Administered by clients and the vendor Innovating Data hosting At the vendor’s subcontractor / At the client Stated number of implementation projects Industries of implemented projects In the last 12 months Since the release of the solution In France 9 In France 9 Abroad 1 Abroad 1 Average number of users per solution More than 1000 Insurance (15%), Industry and services (85%) Coverage of functional areas* Coverage of technical areas* Access Management Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Audit Languages Export Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 49 / 68 RMIS Panorama 2013 Overmind Overmind 16 avenue dubonnet 92400 Courbevoie, France www.overmind-dynamic.com Gilles Legrand Manager +33 (0) 9 52 53 58 81 / +33 (0) 6 62 56 62 99 [email protected] VENDOR COMPANY ID CARD Founded in 2007 Vendor statement of its own particularities and differentiating factors Global workforce 5 RMIS workforce 5 A vendor specialized on certain categories of risks and specialized in RMIS / A non specialized vendor - RMIS implementation 0 - RMIS consulting n/r Area(s) of presence France Overmind, specialized in dynamic business modeling, creates dynamic risk management softwares on request. The specificity of Overmind is to take into account the domino effect and in cascade of chains of events over time . The added value of Overmind’s softwares lies in the ability to link qualitative and quantitative events, to combine groups of risks and to suggest optimized answer scenarios during emerging crisis VENDOR’S AVAILABLE SOLUTION(S) Solution(s) Risk Analysis (analyse dynamique amdec), Sim Impact, Global Risk (SGIR dynamique), Crisis Risk Kind of solution according to the vendor A configurable toolbox Composition of the solution Several modules in a same application Dominant(s) ERM and Insurance Club of users Strengths according to the vendor Yes (2 meetings per year) Created in 2010 Administered by clients and the vendor The handling of domino effects over time Data hosting At the vendor / At the client In the last 12 months Stated number of implementation projects Industries of implemented projects Since the release of the solution In France 8 In France 30 Abroad 2 Abroad 3 Average number of users per solution From 6 to 50 Industry and services (100%) Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor 50 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Oxand Oxand 49 avenue Franklin Roosevelt 77210 Avon, France www.oxand.com Jean Le Drogo IT & Software Manager +33 (0) 1 60 39 52 51 [email protected] VENDOR COMPANY ID CARD Founded in 2002 Global workforce 85 RMIS workforce n/r - RMIS implementation 0 - RMIS consulting n/r Area(s) of presence France, Europe, North America Vendor statement of its own particularities and differentiating factors A specialized vendor in RMIS Oxand, management of industrial assets and risks, customized solutions for investors, owners, operators and managers: - Strengthen risk management within large industrial projects – Anticipate effectively the aging effect during the lifecycle management of infrastructures – Realize infrastructure diagnostics and have risks prediction for a better prioritization of maintenance actions – Set up operational systems of management of industrial assets and risks (data bases, planning tools, reporting and monitoring of the status of assets, according to PAS 55 and ISO 31’000) VENDOR’S AVAILABLE SOLUTION(S) Solution(s) SIMEO ERM Kind of solution according to the vendor A completely standard tool Composition of the solution A single application Dominant(s) ERM Club of users Strengths according to the vendor Our risks management culture is our main strength in order to guide our clients to implement a real management of projects risks or risks at the scale of the company In the last 12 months Stated number of implementation projects Industries of implemented projects Governance At the vendor’s subcontractor / At the client Since the release of the solution 1 In France 2 Abroad 2 Abroad 10 Average number of users per solution From 6 to 50 Industry and services (80%), Public sector (20%) Coverage of technical areas* Access Management Insurance Management Quality Management Data hosting In France Coverage of functional areas* Competitive Intelligence No 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 51 / 68 RMIS Panorama 2013 Oxial France Oxial France 15 rue Taitbout 75009 Paris, France www.oxial.com Véronique Bonneau Sales Director +33 (0) 5 56 89 68 79 / +33 (0) 6 72 62 46 84 [email protected] VENDOR COMPANY ID CARD Founded in 1995 Vendor statement of its own particularities and differentiating factors Global workforce 38 RMIS workforce 38 A vendor specialized on certain categories of risks / A specialized vendor in RMIS, - RMIS implementation 18 - RMIS consulting 8 Area(s) of presence Europe BlueSuite is a RMIS, avant-guarde type Straight Through Processing, global, modular and integrated. Easily adopted, spreading the culture of risk control and performance at the heart of the company. It is a collaborative solution, flexible, evolutive and ahead of regulations. A mean of communication, capture know-how, valuing the staff expertise control. A governance dashboard offering the management a clear vision, real and comprehensible of the effectiveness of measures in place VENDOR’S AVAILABLE SOLUTION(S) Solution(s) BlueSuite Kind of solution according to the vendor A preconfigurable and flexible business tool Composition of the solution Several modules in a same application Dominant(s) ERM and Insurance Club of users Strengths according to the vendor Yes (1 meeting per year) Created in 2004 Administered by the vendor Straight Through Processing Data hosting At the vendor / At the vendor’s subcontractor / At the client In the last 12 months Stated number of implementation projects Industries of implemented projects Since the release of the solution In France 3 In France 5 Abroad 4 Abroad 28 Average number of users per solution From 6 to 50 Bank (20%), Insurance (20%), Industry and services (20%), Public sector (40%) Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor 52 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Pentana (new respondent) Pentana Gate House, Fretherne Road AL8 6RD Welwyn Garden City, UK www.pentana.com Ken Ebbage CEO +44 (0) 17 07 37 33 35 [email protected] VENDOR COMPANY ID CARD Founded in 1992 Global workforce 40 RMIS workforce 40 - RMIS implementation 10 - RMIS consulting 6 Area(s) of presence Europe, AsiaPacific, North America, South America, Africa Vendor statement of its own particularities and differentiating factors A specialized vendor in RMIS Pentana provides software for documentation and management of risk reviews and audits. Actions arising from different GRC departments are tracked through a central action repository. Pentana Vision is a SmartClient application that combines the rich interface of a desktop application with the ease of global deployment of a web based system VENDOR’S AVAILABLE SOLUTION(S) Solution(s) Pentana Vision Kind of solution according to the vendor A completely standard tool Composition of the solution Several modules in a same application Dominant(s) ERM Club of users Strengths according to the vendor The technology we use enables both connected and off-line working in a single rich client interface which has the ease of deployment and global use over slow networks normally associated with Web Browser solutions Yes (4 meetings per year) Created in 2002 Administered by clients and the vendor Data hosting At the vendor / At the vendor’s subcontractor / At the client In the last 12 months Stated number of implementation projects Since the release of the solution In France 1 In France 5 Abroad 30 Abroad 350 Average number of users per solution From 6 to 50 Bank (15%), Insurance (3%), Industry and services (62%), Public sector (10%), Others (10 %) Industries of implemented projects Coverage of functional areas* Coverage of technical areas* Access Management Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Audit Languages Export Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 53 / 68 RMIS Panorama 2013 Protiviti Protiviti 21 boulevard Haussmann 75009 Paris, France www.protiviti.com/fr.FR Bernard Drui Managing Director +33 (0) 1 42 96 22 77 [email protected] VENDOR COMPANY ID CARD Founded in 2002 Global workforce 2500 RMIS workforce 120 - RMIS implementation 10 - RMIS consulting 50 Area(s) of presence France, Europe, Asia-Pacific, North America, South America Vendor statement of its own particularities and differentiating factors A specialized vendor in RMIS Consulting firm that has developped a RMIS software editing activity in order to put its know-how at the service of its clients. We consider that RMIS technology is first at the level of the device of global risk of the organization and is thus a tool that needs an exhaustive and simple integrated covering in line with the IS standards VENDOR’S AVAILABLE SOLUTION(S) Solution(s) Governance Portal Kind of solution according to the vendor A configurable toolbox Composition of the solution Several modules in a same application Dominant(s) ERM Club of users Strengths according to the vendor Yes (4 meetings per year) Created in 2007 Administered by clients and the vendor Its functional coverage, the speed and the simplicity of implementation Data hosting At the vendor / At the vendor’s subcontractor / At the client In the last 12 months Stated number of implementation projects Industries of implemented projects Since the release of the solution In France 2 In France 12 Abroad 20 Abroad 300 Average number of users per solution From 51 to 100 Bank (10%), Insurance (10%), Industry and services (80%) Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Documentation Risk Mapping Action Management Organization Compliance Export Audit Languages Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor 54 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 ROK Solution ROK Solution 94 rue Saint Lazare 75009 Paris, France www.rok-solution.com Christophe Veca Marketing Manager +33 (0) 1 42 81 51 98 / +33 (0) 6 95 24 60 99 [email protected] VENDOR COMPANY ID CARD Founded in 2007 Global workforce 14 RMIS workforce 3 - RMIS implementation 3 - RMIS consulting 3 Area(s) of presence France Vendor statement of its own particularities and differentiating factors A non specialized vendor Integrated solution, integration of the risk approach to management of process/ procedures and to the organization. Risks assessment configurable on demand (perimeters management, rules engine and rating scale) VENDOR’S AVAILABLE SOLUTION(S) Solution(s) ROK Solution Kind of solution according to the vendor A configurable toolbox Composition of the solution A single application Dominant(s) Management of processes and the organization Club of users No Strengths according to the vendor Integrated solution business oriented (very few configuration required for Information Systems Directors) Data hosting At the vendor / At the vendor’s subcontractor / At the client In the last 12 months Stated number of implementation projects Industries of implemented projects Since the release of the solution In France 3 In France 3 Abroad 0 Abroad 1 Average number of users per solution From 6 to 50 Industry and services (100%) Coverage of functional areas* Coverage of technical areas* Access Management Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Audit Languages Export Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 55 / 68 RMIS Panorama 2013 SAP France SAP France 32 rue de Monceau 75008 Paris, France www.sap.com Jean-Luc Dené GRC Solutions Specialist +33 (0) 1 44 45 21 28 / +33 (0) 6 63 48 75 74 [email protected] VENDOR COMPANY ID CARD Founded in 1972 Global workforce 60972 RMIS workforce 9837 - RMIS implementation 13731 - RMIS consulting 2118 Area(s) of presence France, Europe, Asia-Pacific, North America, South America, Africa Vendor statement of its own particularities and differentiating factors A non specialized vendor Do you know that more than 2,500 companies have already adopted the SAP GRC solutions in order to manage their operational and financial risks, evaluate the internal control plan, manage internal audit missions, ensure segregation of duties ? View the study to understand how to automate the processes associated with SAP GRC VENDOR’S AVAILABLE SOLUTION(S) Solution(s) SAP Risk Management, SAP Process Control, SAP Access Control, SAP Audit Management, SAP Quality Management, SAP Global Trade Services Kind of solution according to the vendor A completely standard tool Composition of the solution Several distinct applications Dominant(s) ERM Club of users Strengths according to the vendor A complete and integrate GRC suite with a business intelligence platform allowing users to build and customize their own reports and dashboard with the help of a simple mouse such as “drag/ drop” to select sizes and ratios that interests them Yes (2 meetings per year) Created in 1987 Administered by clients Data hosting At an authorized partner In the last 12 months Stated number of implementation projects Industries of implemented projects Since the release of the solution In France 10 In France 70 Abroad 200 Abroad 2500 Average number of users per solution From 101 to 200 Bank (5%), Insurance (5%), Industry and services (85%), Public sector (5%) Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Documentation Customization Action Management Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor 56 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 SAS France SAS France Domaine de Gregy, Gregy sur Yerres 77557 Brie Comte Robert Cedex, France www.sas.com Jean-Loïc Berthet Consultant Risk Solutions Specialist +33 (0) 1 60 62 12 93 / +33 (0) 6 90 26 98 89 [email protected] VENDOR COMPANY ID CARD Founded in 1976 Global workforce 12837 RMIS workforce 3843 - RMIS implementation 1231 - RMIS consulting 417 Area(s) of presence France, Europe, AsiaPacific, North America, South America, Africa Vendor statement of its own particularities and differentiating factors A specialized vendor in RMIS / A non specialized vendor SAS is the world leader of business analytics, whose risk offer is one of the main component. The SAS offer suggests a qualitative and quantitative management of risks through a dedicated analytical platform. It operates the connection between risk management and performance management VENDOR’S AVAILABLE SOLUTION(S) Solution(s) SAS(R) Enterprise GRC Kind of solution according to the vendor A configurable toolbox Composition of the solution Several modules in a same application Dominant(s) ERM and Insurance Club of users Strengths according to the vendor The unequalled functional coverage (processes, risks, incidents, controls, operational losses, basis of external losses, insurances, performance management, quantitative management, reporting,…) Yes (4 meetings per year) Created in 1990 Administered by the vendor Data hosting At the vendor’s subcontractor / At the client In the last 12 months Stated number of implementation projects Industries of implemented projects Since the release of the solution In France 1 In France 2 Abroad 37 Abroad 130 Average number of users per solution From 201 to 500 Bank (40%), Insurance (20%), Industry and services (20%), Public sector (15%), Others (5 %) Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 57 / 68 RMIS Panorama 2013 Siaci Saint Honoré Siaci Saint Honoré 18 rue de Courcelles 75384 Paris, France www.s2hgroup.com Nicolas Zusslin Customer Information Systems Consultant +33 (0) 1 44 20 99 95 [email protected] VENDOR COMPANY ID CARD Founded in 2008 Global workforce 791 RMIS workforce 8 - RMIS implementation n/r - RMIS consulting n/r Area(s) of presence France, Europe, AsiaPacific, North America Vendor statement of its own particularities and differentiating factors A specialist in the Project Ownership Assistance in the deployment of RMIS Our experience in RMIS allows us to cover all the needs of our clients: management of the deployment of a RMIS, turnkey delivery of a solution, integration of a RMIS in the business processes or any other project ownership assistance mission VENDOR’S AVAILABLE SOLUTION(S) Solution(s) Hierarchy, Goods, Policies, Claims, Contacts, Documents, Reports Kind of solution according to the vendor A configurable toolbox Composition of the solution Several modules in a same application Dominant(s) ERM Club of users Strengths according to the vendor No Adaptability Data hosting At the vendor / At the client In the last 12 months Stated number of implementation projects Industries of implemented projects Since the release of the solution In France 0 In France 5 Abroad 2 Abroad 10 Average number of users per solution From 51 to 100 Insurance (5%), Industry and services (80%), Others (15 %) Coverage of functional areas* Coverage of technical areas* Insurance Management Competitive Intelligence Quality Management Governance 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor 58 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Software AG Software AG 20 av. A. Prothin, Tour Europlazza, La Défense 4 92927 Paris La Défense Cedex, France www.softwareag.com Nicolas Choppin De Janvry GRC Solution Manager (Acting) +33 (0) 1 78 99 70 00 / +33 (0) 6 19 21 47 13 [email protected] VENDOR COMPANY ID CARD Founded in 1969 Global workforce 6000 RMIS workforce n/r - RMIS implementation n/r - RMIS consulting n/r Area(s) of presence France, Europe, Asia-Pacific, North America, South America, Africa Vendor statement of its own particularities and differentiating factors A non specialized vendor Software AG offers software products with a standard approach, fast and simple to implement. The evolutions of the product are the result of the integration of the clients needs in an effort of consistency and integration. Coverage and simple implementation of Risk Mapping, Internal Control, Audit, based on the COSO framework. 20 years of experience on the Design and 8 years on risks. Integrated and coherent approach through shared frameworks VENDOR’S AVAILABLE SOLUTION(S) Solution(s) ARIS GRC Kind of solution according to the vendor A configurable toolbox Composition of the solution Several distinct applications Dominant(s) ERM Strengths according to the vendor The ARIS GRC solution is a modular suite allowing to manage in an integrated manner the entire treatment chain and of operational risks assessment and of the internal control: documentation and modelization of processes , identification, assessment and monitoring of risks and check points/ means of control, incidents management and associated losses, creation and monitoring of actions/improvements plans, implementation and monitoring of test campaigns, questionnaires management, audits management, sign-off management, reporting and analysis of results,… Stated number of implementation projects Industries of implemented projects In the last 12 months At the vendor / At the client 2 In France 8 Abroad 8 Abroad 50 Average number of users per solution From 101 to 200 Coverage of technical areas* Insurance Management Governance Data hosting In France Coverage of functional areas* Quality Management Yes (20 meetings per year) Created in 2000 Administered by clients Since the release of the solution Bank (30%), Insurance (25%), Industry and services (25%), Public sector (15%), Others (5 %) Competitive Intelligence Club of users 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Internal Control Languages Import (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 59 / 68 RMIS Panorama 2013 Thomson Reuters (new respondent) Thomson Reuters Vintners Place 68 Upper Thames Street EC4V 3BJ Londres, UK www.accelus.thomsonreuters.com Deborah Roberts Strategic Alliances Director +44 (0) 75 95 41 01 61 / +44 (0) 75 95 41 01 61 [email protected] VENDOR COMPANY ID CARD Founded in 1905 Vendor statement of its own particularities and differentiating factors Global workforce 80000 RMIS workforce 1800 A vendor specialized on certain categories of risks and specialized in RMIS / A non specialized vendor - RMIS implementation n/r - RMIS consulting n/r Area(s) of presence France, Europe, Asia-Pacific, North America, South America, Africa Thomson Reuters GRC is a specialist division within Thomson Reuters, Headquartered in Europe. We have over 1,800 people focussing uniquely on Governance Risk and Compliance Solutions We dynamically connect strategy, operations, and business transactions to the ever changing regulatory environment, enabling firms to accelerate while managing business risk VENDOR’S AVAILABLE SOLUTION(S) Solution(s) Thomson Reuters Accelus, Enterprise GRC Kind of solution according to the vendor A completely standard tool Composition of the solution A modular solution and a separated specialized solution Dominant(s) ERM and Insurance Club of users Strengths according to the vendor Configurable without needing to customise – Client references – Industry content and functionality – Flexibility of a small company backed by a huge organisation – Deployment options – In house, Web Hosted Security Model – Company established player in marketplace – Scalable solution In the last 12 months Stated number of implementation projects Industries of implemented projects Governance At the vendor / At the vendor’s subcontractor / At the client Since the release of the solution 5 In France 10 Abroad 0 Abroad 0 Average number of users per solution From 101 to 200 Bank (50%), Insurance (20%), Others (30 %) Coverage of technical areas* Insurance Management Quality Management Data hosting In France Coverage of functional areas* Competitive Intelligence Yes (12 meetings per year) Created in 1985 Administered by clients and the vendor 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Access Management Incidents / Losses Crisis Management/ BCP Workflow Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Audit Languages Export Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor 60 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Tinubu Square Tinubu Square 1 rue Gaston et René Caudron 92130 Issy Les Moulineaux, France www.tinubu.com Denis Thibaudin Sales Director +33 (0) 1 55 95 85 85 [email protected] VENDOR COMPANY ID CARD Founded in 2000 Global workforce 81 RMIS workforce 14 - RMIS implementation 22 - RMIS consulting 20 Area(s) of presence France, Europe, Asia-Pacific Vendor statement of its own particularities and differentiating factors A vendor specialized on certain categories of risks The cloud solution Tinubu Credit Risk Intelligence is the one and only platform (SaaS) able to provide companies a support of decisional analysis and of operational reporting in terms of credit management, with complete visibility of their credit risk exposure, both locally and internationally VENDOR’S AVAILABLE SOLUTION(S) Solution(s) Tinubu Credit Risk Intelligence Kind of solution according to the vendor A configurable toolbox Composition of the solution Several modules in a same application Dominant(s) ERM Club of users Strengths according to the vendor Stated number of implementation projects Industries of implemented projects Tinubu Credit Risk Intelligence Solutions, the best credit risk management solution that enables companies to see, control and limit their credit risk exposure and to integrate an effective governance on the entire business cycle of the company: from marketing to sales and from the order to receipt In the last 12 months Quality Management Governance At the vendor / At the vendor’s subcontractor Since the release of the solution 5 In France 60 Abroad 9 Abroad 30 Average number of users per solution From 6 to 50 Bank (5%), Insurance (20%), Industry and services (75%) Coverage of technical areas* Access Management Insurance Management Competitive Intelligence Data hosting In France Coverage of functional areas* 3,00 2,50 2,00 1,50 1,00 0,50 0,00 No Workflow Incidents / Losses Crisis Management/ BCP Reporting Risk Management 3,00 2,50 2,00 1,50 1,00 0,50 0,00 Technical Architecture Currencies Customization Action Management Documentation Risk Mapping Organization Compliance Export Audit Languages Import Internal Control (*)The results transcribed on this form are consistent with responses provided by the vendor Copyright © 2013 AMRAE, in partnership with ACCENTURE 61 / 68 RMIS Panorama 2013 Appendices Appendix 1: Description of functional and technical areas Functional areas Insurance Management Incident and Loss Management Crisis Management / BCP Risk Management Risk Mapping Audit Internal Control Compliance Action Management Governance Quality Management Competitive Intelligence 62 / 68 Premium allocation management Calculation of premiums pursuant to regulations and contracts Follow-up of premium payment history Management of insurance portfolios Budget simulations Tax identification and follow-up Description and follow-up (including financial impact) of incidents managed centrally or not, non-compliance, legal proceedings, losses, conditional alerts, etc. History of financial valuation including compensation process follow-up by item (medical expenses, damages, material and immaterial damages, etc.) Management of alerts and notifications Management of alert thresholds, statuses and information workflows Analysis tools for leveraging user feedback Follow-up of specific repositories and related procedures Description and follow-up of action plans Remediation level assessment Prevention management (follow-up of prevention reports) Self-assessment management Description and management of risk assessment visits Objectives setting and achievement follow-up Identification of risks, origins, mitigation factors, responsible parties, etc. Risk assessment and prioritization Mapping follow-up and history Analysis and communication capabilities Audit plan management Management of auditing missions, schedules and work programs Identification of controls and link with processes Management of self-assessment campaigns Compliance with regulations, internal procedures and external standards Action assignment and validation Follow-up of action efficiency by the audit committee and the risk committee Management of the organization, risk management policies and decisions Dashboards with key business/risk/performance indicators, budget management Management of processes, objectives, quality indicators, non-compliant products, preventive and corrective actions, specific procedures, etc. Management of intelligence and information analysis, business intelligence, technology watch Information gathering, treatment, publishing and filing Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 Technical areas Access Management Technical Architecture Multi-Currency Management Document Management Imports Exports Multiple Language Management Organizational Management Customization Analysis and Reporting Workflow Management User access security policy, user management, segregation of duties Delegation of administration rights Management of user authorizations and data confidentiality Type of architecture and hosting used (rich client, Application Service Provider, etc.) Possible database solutions and programming languages Logical security of the technical platform Default currency Other possible currencies Multiple currency conversion engine Document attachment Document management capabilities Import management by a client administrator or an authorized user Import of external data sources in an appropriate format Pre-set export formats Extracting and exporting data in xls, dbf or other formats (for use in spreadsheets or databases) for external use Defining export perimeters, selecting data for exports and limiting and restricting exported scope and data Available languages other than French Existence of a complete RMIS version in French Management of data and label dictionaries Language management by a client administrator Management of tree structures (with more than five levels) along multiple areas and with multiple repositories Management of different employees or various assets (facilities, vehicles, etc.) attached to the tree-structure entities (including processes) Matching of legal and organizational data Screen customization by the client Screen customization by the vendor Other functionalities for the client Business Intelligence Existence of an integrated reporting tool Interfacing with reporting tools and ETL Management of analysis criteria Available reports and supported formats Alert triggering thresholds and workflow customization Tool functionalities for sending emails/SMS, using a mailing list or other Pre-set workflow management with scheduling and task follow-up functionalities Reporting possibilities on workflow information Copyright © 2013 AMRAE, in partnership with ACCENTURE 63 / 68 RMIS Panorama 2013 Appendix 2: Consultation/response results VENDOR RMIS Panorama 2011 RMIS Panorama 2012 RMIS Panorama 2013 Consulted Answered Consulted Answered Consulted Answered 1-One NO YES YES YES YES 80-20 Software YES YES NO YES NO Active Risk NO YES YES YES NO Adexys YES YES NO YES NO Agena AlignAlytics NO YES NO YES NO NO YES NO YES NO Amelia YES NO YES NO NO NO AON eSolutions YES YES YES YES YES YES Arengi Archer Technologies (see EMC / RSA) Asphaleia Axentis (see Wolters Kluwer Financial Services / ARC Logics) Bayesia BI International (see AlignAlytics) BPS Resolver NO YES NO NO NO NO Status 2013 Outgoing YES NO YES NO NO NO YES YES YES NO YES NO YES NO YES NO NO NO YES NO YES NO YES NO YES NO YES NO NO NO NO YES NO YES NO BVD / Bureau Van Dijk NO NO YES YES BWise YES NO YES YES YES YES Certus YES NO YES NO NO NO Clarity GRC NO NO YES YES Incoming Click-N-Manage NO NO YES YES Incoming Incoming CMO Compliance NO YES YES Coda YES NO YES NO YES NO Cogis Control Metrics (see Mega International) Covelys YES NO NO NO YES YES YES NO YES NO NO NO YES YES YES YES YES YES Crystal Ball (see Oracle) YES NO YES NO NO NO CS Stars (see Marsh France) YES NO YES NO NO NO Cura Technologies YES NO YES NO YES NO Devoteam NO YES YES YES YES Diot YES NO YES NO NO NO EADS Apsys YES NO YES NO YES NO eBRP Solutions YES NO YES NO YES NO Effisoft YES YES YES YES YES YES eFront YES YES YES YES YES YES Elseware YES YES YES YES YES YES EMC / RSA NO YES YES YES YES Enablon YES YES YES YES YES YES Equity YES NO YES NO YES NO Figtree Systems YES NO YES NO YES YES Gras Savoye YES YES YES YES YES YES Hyperion (see Oracle) YES NO YES NO NO NO 64 / 68 NO Outgoing Incoming Incoming Incoming Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 VENDOR RMIS Panorama 2011 RMIS Panorama 2012 RMIS Panorama 2013 Consulted Answered Consulted Answered Consulted Answered IAMS Conseil YES NO YES NO YES NO IBM NO YES YES IDS Scheer (see Software AG) YES YES NO NO NO NO i-Flex (see Oracle) YES NO YES NO NO NO Infor YES NO YES NO YES NO InformationBuilders YES NO YES NO YES NO Intellinx NO YES NO YES NO Ivalua YES NO YES NO YES NO Keyword YES NO YES YES YES YES Kilclare software YES NO YES NO YES NO Legisway YES NO YES NO YES NO LexisNexis List France (see Mega International) LogicManager NO YES YES YES YES YES YES NO NO NO YES NO YES NO MSDP Consulting YES NO YES NO YES NO Mageri YES NO YES NO YES NO MAAT YES YES YES YES YES YES MARP NO YES NO NO NO Marsh France YES NO YES YES YES YES Mega International YES YES YES YES YES YES Methodware YES YES YES NO YES NO MetricStream YES NO YES NO YES YES Movaris (see Trintech) YES NO YES NO NO NO Novasecur NO YES YES Noweco YES NO YES NO OpenPages (see IBM) YES NO YES NO NO NO Optimind NO YES NO NO NO Optimum Risk Research NO YES NO NO NO Optirisk NO YES NO YES NO Oracle France YES YES YES YES NO Overmind NO YES YES YES YES Oxand YES YES YES YES YES YES Oxial France YES YES YES YES YES YES Palisade YES NO YES NO YES NO NO NO NO NO NO YES NO Status 2013 Incoming Incoming Incoming Outgoing Pentana YES NO YES NO YES YES Incoming Prodentia YES NO YES YES YES NO Outgoing Protiviti YES NO YES YES YES YES Qumas YES NO YES NO YES NO Riskalis NO YES NO NO NO RiskClick YES YES NO NO NO Risk Decisions NO YES NO YES NO Risk Governance YES YES NO NO NO RMsoft (see Covelys) NO YES NO ROK Solution YES YES YES Copyright © 2013 AMRAE, in partnership with ACCENTURE NO NO NO YES YES YES 65 / 68 RMIS Panorama 2013 VENDOR RMIS Panorama 2011 RMIS Panorama 2012 RMIS Panorama 2013 Consulted Answered Consulted Answered Consulted Answered RuleBurst (see Oracle) YES NO YES NO YES NO RVR Systems (see Devoteam) SAI Global Compliance / Compliance 360 SAP France YES YES NO NO NO NO YES NO YES YES YES YES YES YES SAS France YES YES YES YES YES YES Siaci Saint Honoré YES YES YES YES YES YES Softrisk (see Black Coral) YES NO YES NO NO NO Software AG Strategic Thought Group (see Active Risk) Sword Group NO YES YES YES YES YES NO YES NO NO NO YES NO YES NO YES NO TCI SAS YES NO YES NO NO NO Telelogic (see IBM) YES NO YES NO NO NO Thomson Reuters YES NO YES NO YES YES Tinubu Square NO YES YES YES YES Trintech NO YES NO YES NO Verspieren NO YES NO YES NO VV Trading Wolters Kluwer Financial Services / ARC Logics YES YES NO NO NO YES NO 66 / 68 NO NO NO NO NO Status 2013 Incoming Copyright © 2013 AMRAE, in partnership with ACCENTURE RMIS Panorama 2013 You are a vendor and you wish to participate in the survey of the next edition of the RMIS Panorama? You just need to contact AMRAE in order to take part to the next campaign. Please contact Hélène Dubillot: [email protected] RMIS PANORAMA 2013 5th Edition: february 2013 Panorama based on the results of the 2012 RMIS survey This document is publishable and reproducible provided AMRAE and Accenture are credited This document is available for free download in French or English at: www.amrae.fr For hard copies, please submit your order online at: http://www.amrae.fr/amrae/publications.html AMRAE Permanent Office – Tel: +33 (0) 1 42 89 33 16 – Email: [email protected] Copyright © 2013 AMRAE, in partnership with ACCENTURE 67 / 68 RMIS Panorama 2013 This document is publishable and reproducible provided AMRAE and Accenture are credited AMRAE AMRAE Permanent Office – Tel: +33 (0) 1 42 89 33 16 – Email: [email protected] Hélène Dubillot – Email: [email protected] Accenture France – Risk Management 118 avenue de France – 75636 Paris Cedex 13 Aliette Leleux – Tel: +33 (0) 1 56 52 64 09 – Email: [email protected] Jean-Laurent Schwartz – Tel: +33 (0) 6 09 08 28 32 – Email: [email protected] Price of a hard copy: 14€ VAT included (France) 68 / 68 Copyright © 2013 AMRAE, in partnership with ACCENTURE