RiskWatch
RiskWatch International · Founded 1993 · Annapolis, MD, USA
Multi-framework transportation compliance platform with 40+ libraries and cross-mapping.
Summary
RiskWatch ships a compliance assessment platform built around pre-mapped control libraries for 40+ regulatory frameworks. For transportation compliance buyers, the relevant libraries cover DOT-aligned controls, CBP C-TPAT Minimum Security Criteria, TAPA FSR 2024 + TSR + PSR, ISO 28000 supply-chain security, ISO 31000 ERM, ISO 39001 road safety, PCI DSS v4 (for carriers processing payment data), HIPAA (for medical-transport operators), NIST 800-53 r5 and NIST 800-171 r3 (for defence-freight carriers), and NIST CSF for cyber controls. The platform combines a survey-based assessment engine, evidence vault with versioning, cross-mapping engine that auto-detects shared controls, and an ASIS-aligned physical security module in one tenant. The product has been in the field since 1993 with federal customers including the US Department of Defense, the FAA, the VA, the DOJ, and the NSA per public press. Single-tenant deployment supports cross-border data residency that international carriers and port operators with TSA, CBP, or EU NIS2 obligations require.
Strengths
- 40+ pre-built framework libraries with cross-mapping that auto-detects shared controls (TAPA FSR / C-TPAT MSC / ISO 28000 overlap is detected, not hand-mapped)
- TAPA FSR 2024, TAPA TSR, and CBP C-TPAT MSC are first-party libraries, not consulting add-ons that most compliance vendors require for transportation buyers
- Physical security assessment module sits in the same tenant as cyber and compliance evidence, useful for port, terminal, warehouse, and rail-yard auditor packages
- Survey-based assessment engine works for non-technical control owners (DOT safety supervisors, station agents, terminal managers); no SQL or workflow-builder skills required
- Single-tenant deployment with customer-owned data residency, an advantage for cross-border operators with TSA, CBP, EU NIS2, or federal data-locality obligations
- 33-year operating history with federal transportation customers including the FAA
- Published support-tier ladder, not gated demos before you see what comes with each tier
- Partial published pricing ($18K Standard + $36K Professional) the second-most transparent in this ranking
Weaknesses
- No native FMCSA portal integration for live CSA BASIC scores; carriers running pure FMCSA programmes pair RiskWatch with Fleetworthy for direct CSA data ingest
- No native driver qualification file workflow aligned to 49 CFR Part 391 with state MVR ingest; carriers running Part 391 at scale pair RiskWatch with SambaSafety or Idelic
- No native aviation SMS module aligned to 14 CFR Part 5 with ASAP confidentiality controls; Part 121 and Part 135 carriers running FAA SMS pair RiskWatch with Ideagen Coruson
- No native drug-and-alcohol testing programme module aligned to 49 CFR Part 382 and DOT Part 40; carriers pair with Idelic or a dedicated D&A consortium platform
- Enterprise tier remains quote-only on the public site (we are working on full public pricing); the partial-transparency badge reflects this gap
- Brand awareness on G2 and Capterra is lower than MetricStream, ServiceNow IRM, or Optro in the transportation buyer pool; total third-party review volume sits below 100
- Smaller integration marketplace than ServiceNow IRM (500+) or Optro, which matters for carriers running deep TMS / dispatch / telematics integrations
Mid-market and regional carriers (motor, rail, maritime, multi-modal 3PL, port operators) running 3+ compliance frameworks (DOT-aligned + TAPA + C-TPAT + PCI or HIPAA) who want one tenant covering supply-chain security, physical security, cyber, and operational compliance with strong cross-mapping and an auditor-defensible evidence vault.
Pure trucking fleets where the load-bearing brief is Part 391 DQF and live CSA BASIC monitoring; SambaSafety, Idelic, or Fleetworthy fit that brief better. Pure Part 121 SMS-only briefs are better served by Ideagen Coruson.
Key features
- Pre-built control libraries for TAPA FSR 2024, TAPA TSR, CBP C-TPAT MSC, ISO 28000, ISO 31000, ISO 39001, PCI DSS v4, HIPAA, NIST 800-53 r5, NIST 800-171 r3, NIST CSF
- Cross-mapping engine that auto-detects shared controls across transportation compliance frameworks
- Survey-based assessment engine for non-technical control owners (terminal managers, DOT safety supervisors, station agents, IMO Designated Person Ashore)
- Evidence vault with versioning and auditor-ready export for CBP, TSA, FAA, FMCSA, and IMO reviewer packages
- Physical security assessment module (ASIS-aligned) for terminals, ports, warehouses, and rail yards
- Vendor and contractor compliance management with prequalification, BAA, and SOC 2 tracking
- Policy management with approval and attestation workflows for driver handbooks, station manuals, and SMS documentation
- Single-tenant deployment with customer-owned data residency
Integrations
25+ native. Notable: Microsoft Entra ID (SAML SSO), Okta, Microsoft 365 / SharePoint, Slack, Jira, Salesforce, Custom REST API.
Target size
100 to 25,000 employees · US · Canada · EU · UK · AU