The Two Executives the Risk Technology Market Serves Least

Twelve executives own different aspects of integrated risk management inside the modern enterprise, from the board and the CEO down through the CISO, the CFO, and the chief compliance officer, and today's risks move too fast and cut across too many of those aspects for any one of them to work alone. The newly published 2026 IRM Navigator™ Leadership Persona Guide from Wheelhouse Advisors maps which of sixteen IRM50 vendors actually serve each of those twelve, on evidence rather than marketing. Two seats come back nearly empty. The Chief Legal Officer holds a single Primary-fit vendor across the entire field, with the widest Not Served band of any persona. The Chief Human Resources Officer holds none at all.

Those are not the only findings. The guide also produced a three-way tie at the top of the vendor table, a compliance seat so crowded that coverage claims no longer differentiate anyone, and a market whose depth sits almost entirely in two of its four domains. But start with the empty seats, because they say the most about where this market is headed.

The twelve C-suite leadership personas across the four IRM Navigator™ domains. © 2026 Wheelhouse Advisors LLC.

First, the mapping itself. The guide groups the twelve personas into the four IRM Navigator™ domains, from the board, CEO, and legal officer in enterprise risk management around the compass to the risk, compliance, and audit executives in governance, risk, and compliance. The figure below shows who sits where. Each vendor earns one of four fit tiers per persona: Primary, Secondary, Partial, or Not Served. Tier assignments rest on published Vendor Compass evidence, named go-to-market, and verified customer deployment. A vendor that markets to a persona but cannot show deployment evidence does not earn Primary fit on the strength of its messaging.

The sixteen: Archer, Diligent, Drata, Hyperproof, IBM OpenPages, LogicGate, MetricStream, Microsoft, Mitratech, NAVEX, OneTrust, Optro, Riskonnect, SAI360, ServiceNow, and Workiva.

‍Why these sixteen out of the fifty providers in the IRM50? They are the technology vendors with material presence across the four Vendor Compass domains and meaningful fit at multiple personas rather than a single specialist seat. Thirteen earned their place through Compass tier placement in two or more domains. The other three, Microsoft, Drata, and Hyperproof, entered on verifiable persona-level customer evidence, and the guide flags that distinction explicitly. The consulting segment of the IRM50, including the Big Four advisory firms, is evaluated in its own Vendor Compass report and sits outside this persona-mapped reading.

The least served seats in the C-suite

‍The Chief Legal Officer's numbers are stark. One Primary fit across sixteen vendors and the widest Not Served band of any persona, and this at a time when enterprise legal exposure and the legal dimension of AI risk keep expanding. Most of the market simply does not show up for the seat.

The CHRO gap is different in kind. No vendor holds Primary fit for workforce risk, the sharpest single coverage gap in the matrix, but six vendors now hold Secondary fit there, so the first credible Primary-fit move is available to any of them. And the top tier holds two more absences: no vendor reaches Primary fit for the Chief Executive Officer or the Chief Financial Officer either, though both are better covered than the raw count suggests, since the strongest enterprise platforms serve strategic-risk synthesis and financial-risk synthesis at Secondary depth. Put the four together and the least served executives in the C-suite are the CLO and the CHRO, with the CFO and CEO close behind.

For vendors, those seats are the clearest openings available today. For buyers, a warning: if your IRM program assigns legal risk, workforce risk, or strategic-risk or financial-risk synthesis to technology, no platform fully carries that assignment yet. Design the program accordingly.

Breadth wins the ranking, with a caveat‍ ‍

At the other end of the study sits the tie. IBM OpenPages, Riskonnect, and ServiceNow share the top rank, each serving ten of the twelve personas at Primary or Secondary depth. Nobody else gets to ten. Archer and MetricStream sit immediately behind at nine. These platforms were designed to carry risk information across domain boundaries, and the matrix shows what that design choice buys: a seat in more executive conversations than any focused competitor can claim.

Sixteen IRM50 vendors ranked by Primary + Secondary persona fit across the twelve personas. From the 2026 IRM Navigator™ Leadership Persona Guide. © 2026 Wheelhouse Advisors LLC.

Count Primary fits alone and the cast shifts. The longstanding GRC platforms hold the most, with Archer, IBM OpenPages, and MetricStream leading and the audit and board incumbents Diligent and Optro just behind. Their Primary fits cluster where the category was born, in the Chief Risk Officer, Chief Compliance Officer, and Chief Audit Executive seats and at the compliance edge of technology risk. Heritage explains it. The category formed in the Sarbanes-Oxley era, and twenty years of deployments produced the depth and the customer evidence that Primary fit demands in those seats.

A lower rank is not an indictment, though. Drata, Hyperproof, and NAVEX sit toward the bottom of the table for the same reason they win the deals they win: their platforms were built for specific personas, and they serve those personas at Primary depth while conceding the rest of the matrix by design. Drata would not trade its Primary fit at the CISO for three Secondary fits somewhere else. The ranking measures reach. The buyer's question is narrower: which vendor holds Primary fit at the persona who owns this procurement.

The market built where reporting began

The empty seats are not random. Of the 37 Primary fits in the matrix, 33 fall in two domains, 13 in technology risk management and 20 in governance, risk, and compliance. Enterprise and operational risk management, the domains where the CLO, CHRO, CEO, and CFO all sit, hold two apiece. The capability census agrees: of the 61 product gaps it records across the sixteen vendors, 51 sit in ERM and ORM.

Those are the two domains that carry the performance and resilience outcomes of the IRM Navigator™ Model, and they are what boards are asking about now that the agenda has moved past compliance reporting. The market built its depth where risk reporting began. Demand has moved on, and the matrix says the vendors have not yet followed.

The compliance officer has the opposite problem

Eleven of sixteen vendors hold Primary fit at the Chief Compliance Officer, the densest Primary tier in the matrix and the exact inverse of the CHRO. Compliance is where positioning is most saturated and where a coverage claim differentiates nobody. The vendors competing there will separate on depth: DOJ evaluation-criteria alignment, regulatory horizon coverage, whistleblower methodology, and data integration. A CCO buyer should treat "we serve compliance" as table stakes and interrogate those four.

The Chief Digital/Data Officer gap, meanwhile, is closing fast. The prior matrix put two vendors at Primary fit for the CDO. Four hold it now: IBM OpenPages, Microsoft, OneTrust, and ServiceNow. No persona saw faster repositioning, and the reason is regulatory. The EU AI Act, the NIST AI Risk Management Framework, and ISO/IEC 42001 have made AI conformity the fastest-expanding perimeter in the matrix. That territory is contested now. The cleaner openings sit with the legal, workforce, strategic, and financial seats.

A three-year window

The matrix is a snapshot of a market in motion. The guide puts a three-year window on the open gaps, which will close through repositioning, market entry, or consolidation. A vendor that moves inside that window establishes a position at a substantively different cost than one that follows. A buyer evaluating platforms today should weigh where a vendor sits in the matrix and which direction its evidence trail points.

The 2026 IRM Navigator™ Leadership Persona Guide, including the full persona-by-persona fit analysis and the complete exhibit suite, is available at https://www.wheelhouseadvisors.com/irm-navigator-research/p/2026-irm-navigator-leadership-persona-guide.

John A. Wheeler

John A. Wheeler is the founder and CEO of Wheelhouse Advisors, a global risk management strategy and technology advisory firm. With over three decades of experience spanning executive management, finance, risk management, audit, and IT, John is a world-renowned expert in integrated risk management technology, executive leadership, and corporate governance.

https://www.linkedin.com/in/johnawheeler/
Previous
Previous

The Warning to GRC Vendors Buried in NIST's New Guidance

Next
Next

The Fraud Market Is Funding Its Way Toward Autonomous IRM