Resolver
by Resolver (a Kroll business) · Audit Management
Enterprise GRC platform for risk, internal audit, controls, compliance and incident management.
Updated August 2026 · By the ERP Research Editorial Team · Independent and vendor-neutral.
- Deployment
- Cloud
- Company size
- Mid-market, Enterprise
- Pricing
- Quote-based
- Headquarters
- Toronto, Canada
Overview
Resolver is an enterprise governance, risk and compliance (GRC) platform covering risk management, internal audit, internal controls, third-party risk, business continuity, IT compliance, regulatory compliance and whistleblower/ethics case management, alongside a separate line of corporate security and investigations products. The company was acquired by risk-advisory firm Kroll in 2022 and now operates as "Resolver, a Kroll Business," folding in the risk-intelligence firm Crisp (acquired 2024) under the Resolver brand.
The platform's internal audit management module centralizes the audit universe (processes, risks, controls and tests) on one data model shared with the rest of the GRC suite, so audit, risk and controls teams work from a common source of truth rather than separate spreadsheets. It supports risk-based audit planning, built-in IPPF-aligned templates for coverage planning through fieldwork and review, a client engagement portal for evidence requests, and one-click audit committee reporting. Resolver states this can produce roughly a 30% improvement in audit process efficiency, though this is a vendor-reported figure rather than an independently verified benchmark.
Resolver reports protecting over 1,000 organizations representing a combined $6.5 trillion in market capitalization, with named customers including Toyota, Starbucks, JetBlue, GitHub, Estee Lauder, Harrods, Cadillac Fairview and Grow Financial. Integration with outside business systems is described generically as API-based, including Workato-partnered connectivity; the vendor does not publicly document named ERP connectors (e.g., SAP, Oracle, NetSuite) for the audit/GRC product line.
Features & capabilities
Audit Universe & Planning
Centralized audit data model shared with risk and controls.
- Single audit universe covering processes, risks, controls and tests
- Risk-based audit planning using real-time risk exposure data
- Shared risk and audit data across departments (single source of truth)
- Built-in IPPF-aligned templates for coverage planning, fieldwork, testing and review
- Consistent, repeatable risk assessment methodology
Fieldwork & Workflow Automation
Automated evidence collection and stakeholder coordination.
- Automated reminders and alerts to stakeholders
- Evidence collection without relying on email or spreadsheets
- First-line client engagement portal for document submission
- Centralized narrative review with a single data-submission requirement
- Task and issue tracking through remediation
Reporting & Dashboards
Real-time, filterable reporting for audit and executive audiences.
- One-click audit committee reports
- Automated visualizations and dashboards
- Filterable views for detailed drill-down analysis
- Real-time risk exposure and issue-status reporting
Adjacent GRC Modules
Modules that share data with internal audit on the same platform.
- Enterprise risk management (COSO / ISO 31000-aligned forms)
- Internal controls management and SOX/ICFR certification workflows
- Third-party/vendor risk management with a vendor portal
- IT compliance mapping to SOC 2, NIST 800-53, GDPR and GLBA
- Business continuity management (BIA, plans, tabletop exercises)
- Whistleblower and ethics case management with AI-assisted triage
AI & Analytics
AI-assisted analysis layered across the GRC data model.
- AI-assisted control drafting for out-of-tolerance risks
- AI-generated case-intake summaries (whistleblower module)
- AI-powered regulatory-change summaries and impact insights (compliance module)
- Smart/AI-assisted control mapping to requirements
Common use cases
- Building a risk-based internal audit plan from real-time enterprise risk data instead of a static annual plan
- Replacing email- and spreadsheet-driven evidence requests with a client engagement portal for auditees
- Producing one-click, board-ready audit committee reports
- Running SOX/ICFR controls testing and certification with a full audit trail
- Managing third-party/vendor risk assessments through a dedicated vendor portal
- Tracking business continuity plans, BIAs and tabletop exercises alongside the risk register
- Operating a confidential, multilingual whistleblower hotline with AI-assisted case triage
Strengths & considerations
Strengths
- Internal audit sits on the same data model as risk, controls, compliance and incident modules, so audit findings, risk registers and controls stay linked rather than siloed
- Built-in IPPF-aligned audit methodology templates spanning planning through fieldwork and review
- Broad module footprint (audit, ERM, controls, third-party risk, BCM, IT compliance, whistleblower) sold as one connected platform from a single vendor now backed by Kroll's risk-advisory scale
Pricing
Custom pricing driven by which solutions/modules are selected, the level of configuration required, and number of active users; the vendor states you only pay for active users managing your program and offers bundle discounts across modules. No published price points or trial. Get an independent shortlist with pricing guidance below.
Technical & security
- Hosting
- SaaS
- Compliance
- SOC 2
About the vendor
- Headquarters
- Toronto, Canada
- Ownership
- Subsidiary of Kroll (acquired 2022)
Alternatives to Resolver in Audit Management
Resolver — frequently asked questions
What does Resolver's internal audit module actually cover?
It centralizes the audit universe (processes, risks, controls and tests), supports risk-based audit planning against real-time risk data, provides IPPF-aligned templates from planning through fieldwork and review, and generates one-click audit committee reports.
Does Resolver publish ERP integrations such as SAP or Oracle connectors?
Not for the audit/GRC product line. Resolver describes its integration approach generically as API-based connectivity, including a Workato partnership for connecting to other business systems, but does not publicly document named ERP connectors.
Who owns Resolver?
Resolver was acquired by risk-advisory firm Kroll in 2022 and now operates as Resolver, a Kroll Business. In 2024, Resolver also absorbed the risk-intelligence firm Crisp under the Resolver brand.
How is Resolver priced?
Pricing is quote-based, driven by which solution modules are selected, the depth of configuration, and the number of active users. Resolver does not publish price points or offer a self-serve free trial.
What other modules does Resolver sell besides internal audit?
Enterprise risk management, internal controls/SOX, third-party risk management, business continuity management, IT compliance, regulatory compliance, whistleblower/ethics case management, plus a separate corporate security and investigations product line.
Evaluating Audit Management?
Tell us your ERP and requirements and we'll send an independent shortlist — including Resolver and the best-fit alternatives — with honest pros and cons.