OutThink vs MetaCompliance: when the compliance box is ticked and risk has not moved
If MetaCompliance is on your shortlist, the requirement driving this is probably regulatory. Policy attestation, audit evidence, NIS2, a training record that stands up when someone asks for it. That is a real obligation with a real deadline, and it has to be met.
But compliance and risk reduction are not the same thing. They never have been. A platform can satisfy every auditor you will ever meet and tell you nothing about whether your people are behaving more securely, because completion is a record of activity and risk is a property of behavior.
This page is about what to do when you need both, and it starts with the parts of MetaCompliance we would not choose to write.
Compliance training, phishing simulations, campaigns and awareness months. Table stakes, and not where human risk falls.
All four jobs – Motivate, Educate, Activate, Correct – running autonomously across the whole workforce.
Human risk quantified from real behavioral signal in your security stack, and fed back into SOC, IAM and GRC decisions.
Risk-based access controls, user self-remediation, and behavioral governance extended to AI agents.
MetaCompliance is placed at L1 on evidence, not by category: policy attestation and compliance-training delivery are genuinely strong, and that is L1 done well. Apply the four tests below to both vendors rather than taking either placement on trust.
Before you build the comparison grid
- Your audit requirement is met on day one, either way. Delivery records, completion, attestation and a per-user audit trail are part of the platform rather than a later tier. That is not the decision.
- The decision is what the same deployment can also tell you when someone asks whether human risk is falling, or which fifty people are most at risk today and why. Completion records cannot answer that, because they measure a different thing.
- What changing looks like: RelateCare’s 90% completion satisfied auditors and told leadership nothing. Click rate then fell from 8% to 1%, reporting doubled from 17% to 34%, and credential submission halved.2
- What MetaCompliance does better: 43 languages against our 40+, genuinely good campaign creative, UK, Ireland and Nordic footprint, and a policy-management module we do not sell – though see the table for what we do with your policies instead.
- Who we are: founded in 2019 by CISOs who lived this problem, seven years of purpose-built HRM engineering, 100+ enterprise deployments.
First, what MetaCompliance does well
We compete with them. Discount our opinion accordingly.
- Localization is deeper than ours. 43 languages against our 40+, with regional campaign adaptation rather than translation alone. If your workforce spans more languages than ours covers, that is a real answer and we would rather tell you than have you find out later.
- The campaign creative is genuinely good. Memorable, well-produced awareness content that people talk about, which is harder to do than it sounds and is not something most compliance-first vendors manage.
- They sell policy management and we do not. Policy publication, attestation and tracking sit inside their platform as a module. This is an adjacent capability we do not offer, and if a single system for both training and policy attestation is a hard requirement, that is a legitimate reason to choose them.
- Compliance tooling is complete. Audit-oriented reporting, SCORM and LMS compatibility, and a genuinely useful free resource ecosystem of toolkits, posters and campaign planners.
- European footprint and posture. UK, Ireland, Northern Ireland and, following recent acquisitions, a Nordic base. European ownership and data posture, local references, and procurement familiarity in UK and Irish public sector.
- NIS2 readiness is where they have invested, and the timing of that investment was correct.
If your requirement for this budget cycle is a defensible compliance record with a European vendor your procurement team already knows, MetaCompliance is a rational answer and we would rather say so than pretend otherwise.
The question this page exists to answer is what happens when someone asks a question compliance data cannot answer.
What an auditor accepts and what a board asks
These are two different questions and most programs are only equipped for the first.
The auditor asks: was the training delivered, to whom, when, and can you evidence it. Completion records answer this. So does any platform in this category, including ours, including theirs. This is a solved problem and it should not be the basis of a platform decision.
The board asks: is human risk actually falling, and if we are breached, how fast can we contain it. Completion records cannot answer this. Not because they are recorded badly, but because they measure a different thing. “The user completed training” is technically true in a post-incident review and no defense at all.
And increasingly the disclosure regimes are asking the board’s question rather than the auditor’s, in writing. SEC disclosure rules, DORA and NIS2 all move the requirement from evidence of activity toward evidence of managed risk.
So the useful test for a compliance-led evaluation is not “does this satisfy the audit.” Everything on your shortlist does. It is: does the same platform that satisfies the audit also give you something to say when the board asks the other question. If it does not, you will end up buying a second system, and the two will not share data.
What that looks like in practice
Compliance evidence, unchanged: delivery records, completion, attestation, per-user audit trail, reporting your auditor recognizes.
Then, from the same deployment and the same data:
- Which individuals and which business units carry the most human risk today, and why – not who failed a test
- Prioritized improvement actions across people, process and technology, with evidence attached
- Movement in a human risk score over time, measured against your own starting point
- Human risk context flowing into access approvals, policy exceptions and incident triage, rather than sitting in an awareness console
Where the platforms diverge: the four jobs
The HRM Maturity Model describes four levels of human risk management capability: Reactive (L1), Self-Adapting (L2), Proactive (L3) and Predictive (L4). According to Gartner research, 72% of organizations are at Level 1.1
Compliance-led programs sit at Level 1 by design, and for a defensible reason: L1 is what the regulation asks for. The difficulty is that L1 was never architected to produce behavior change, and a growing share of the questions being asked of security leaders are behavior-change questions.
We are not going to tell you MetaCompliance is a Level 1 platform because of the category it comes from. That is a label, and labels are what this page is trying to get past. Level 2 has a definition and it is testable.
Across more than 100 enterprise deployments we identified four critical jobs every successful human risk program shares: Motivate, Educate, Activate, Correct. All four, running continuously and autonomously across the entire workforce. They are a system rather than a menu, and each job depends on the other three.
No awareness manager, however capable, can execute these four jobs at enterprise scale by hand. Not difficult. Not time-consuming. Impossible. That is why Level 2 is a platform architecture question rather than an effort question, and it is also why an HRM label on a compliance-first platform is worth interrogating rather than accepting.
EducateCampaign delivery or per-person generation
Their strength here is real and it is creative: memorable campaign content across 43 languages with regional adaptation, delivered to groups and audiences on a schedule.
Ours generates the training itself per person, from role, behavior, motivational driver and the choices they make as they go, with roles pre-mapped from your directory and validated by each user, and a dynamic allocation engine that sends fewer modules rather than more.
Ask whether content is selected per individual autonomously, or scheduled to an audience by an administrator. Both are legitimate. They are different jobs.
MotivateWhat the platform knows about why
A short baseline assessment inside the first campaign tells us who responds to personal relevance, who to professional pride, who needs their confidence rebuilt, and who is already a champion. As people work through training they also self-report their ability and motivation for the behaviors they have just learned, mapped to the Fogg behavior model.
Compliance platforms capture completion and quiz results, which are records of activity. Ask what either platform knows about why a person behaves the way they do.
ActivatePractice beyond the module
If practice stops at watching content, the behaviors themselves are never rehearsed. Today that means non-phishing behaviors covered in adaptive training and in nudges triggered by real data-handling, browsing and endpoint events. From late 2026, Cyber Ranges add immersive branching practice across deepfake CEO video, vishing, smishing, data sharing, secure browsing, endpoint, social media and physical security, with the first eight ranges deploying.
Ask what is practiced as opposed to watched, and what is shipping versus roadmap. We have told you ours.
CorrectWhat triggers the intervention
Real-time correction needs live behavioral data from your security systems, an engine that understands the context of each event, and a delivery mechanism that reaches the right person at the right moment. Our nudges fire from live signal in your EDR, DLP, web filter and IAM systems and land in Teams or Slack while the person is still active.
Ask what can trigger an intervention other than a calendar date or a failed simulation.
And then Level 3, which your GRC function can actually use
At L3, human risk becomes quantified on real behavior from your security systems, the attitudes driving it, level of access, how targeted the person is, device security, and workplace factors such as email fatigue and collaboration networks.
Every vendor now claims a risk view, so the question that separates them is what data feeds it. Ask what feeds theirs, and specifically which inputs originate outside their own platform. A view built from completion records and quiz results is a closed loop. Your GRC function can build on a defensible risk number; it cannot build on a completion percentage.
A closed-loop score
- Simulation clicks and reports
- Training completion and quiz results
- Time spent in the vendor’s own modules
- Engagement inside the awareness console
- Vendor-supplied threat intelligence
Measures how people behave inside the vendor’s product. Useful for running the program. Hard for a SOC, IAM or GRC team to act on.
A stack-fed score
- EDR and endpoint events
- DLP and data-handling events
- Web gateway and browsing decisions
- Email and authentication / IAM signal
- Attitudes, access level, how targeted the person is, device security
- Workplace factors: email fatigue, collaboration networks
Measures how people behave at work. Defensible enough to feed access approvals, policy exceptions and incident triage.
Why the order matters
Why the level you buy at decides the levels you can reach
The model is sequential. L2 builds the relationship with users and the behavioral data that makes the platform trusted. L3 establishes the quantification that makes automated thresholds meaningful and defensible.
Only then does L4 become something your organization will actually agree to. Automatically restricting a named employee’s access because a score crossed a threshold is a decision with HR, works council, employee-relations and legal consequences. Nobody signs that off unless the score behind it is trusted and the data feeding it is defensible.
Fewer than 0.1% of organizations are experimenting at L4 today. But Gartner estimates 40% of enterprise applications will integrate AI agents by the end of 2027, and a compliance program built for human users alone will need rebuilding rather than extending.
A multi-year renewal on an L1 platform is not a pause. It is a commitment to spend that window at L1.
The four tests that settle it
Do not take our comparison table on faith, ours or anyone’s. These are the four questions to put to every vendor on your shortlist, including us.
If the answer to the L2, L3 and L4 questions is yes, you have found a genuine HRM platform. If not, you are looking at part of a program rather than a platform for one.
There isn’t one. If the program is built around phishing simulations, generic training campaigns, newsletters, posters and Cybersecurity Awareness Month activities, it is L1.
Can the platform execute all four L2 critical jobs – Motivate, Educate, Activate and Correct – autonomously, across the entire organization, and across the full spectrum of security behaviors?
Is the risk quantification built on actual behavioral data from security systems, or on simulation results and training completion?
Does it surface actionable intelligence from user interactions, generate prioritized improvement actions across people, process and technology, and feed human risk intelligence into SOC, GRC, ticketing and identity systems?
Can the platform adjust access controls from human risk scores, integrating directly with identity providers? Can it enable user self-remediation that shifts responsibility from the SOC to the individual? Is it architected to extend behavioral governance to AI agents, not just human users?
OutThink and MetaCompliance, side by side
The MetaCompliance column contains only statements traceable to their own public material or published third-party sources. Where we cannot verify something, the cell says so and tells you to ask them.
| What to ask | OutThink | MetaCompliance (public information, July 2026) |
|---|---|---|
| Compliance evidence and audit reporting | Broad parity, and it should not decide this. Delivery and completion records, per-user audit trail, attestation reporting, regulatory framing across sector regimes. | Complete and mature. Audit-oriented reporting is a core strength and a long-standing focus. |
| Policy management | What we do instead is turn your policies into training. Feed your policies and risks in, and the platform generates training grounded in your environment, your language and your threats rather than a generic module that may contradict your own rules. Policy publication and attestation stays in your GRC system of record, where your auditors already look for it, and we integrate with it. | Policy management is included in the platform. Worth asking, though: is your policy system of record really an awareness platform, or is it your GRC tool. |
| Localization | 40+ languages across content, the full end-user experience, nudges and Cyber Ranges. | with regional campaign adaptation. Deeper than ours. |
| Position on the HRM Maturity Model | Purpose-built as an HRM platform rather than a training product extended into one. Architected for L2 and L3, with L1 compliance training included as the starting rung rather than the core. L4 sequenced deliberately behind L2 and L3. | Positioned as a European human risk management platform, built on a compliance training, policy and phishing-simulation core. Apply the L2 and L3 tests to judge the architecture rather than the label. |
| How training is targeted | Self-adapting training generated per person from role, behavior, motivational driver and the choices they make as they go. Roles pre-mapped with AI from your directory and validated by each user. A dynamic content-allocation engine assigns modules from real signal rather than sending everyone the full set. | Campaign-based delivery to groups and audiences. Ask how content is selected per individual, and whether that selection is autonomous or an administrator’s decision. |
| What the platform knows about a person | A short baseline assessment produces four motivational segments within days, plus self-reported ability and motivation per behavior mapped to the Fogg model. Every downstream interaction is tailored to it. | Completion, quiz results and campaign engagement. Ask whether attitudes and motivation are captured at all. |
| Analytics depth | Engagement and attention analytics that distinguish people who genuinely engage, people who click through to complete, and people who never start. Plus risk by individual, team and business unit with the drivers behind it. | Completion and quiz-score reporting. Ask to see risk analytics beyond completion: who is actually risky, why, and what changed. |
| Delivery model | Behavior-triggered nudges fired by live signal from EDR, DLP, web gateway and SIEM, delivered in Teams or Slack when the person is active, plus urgent broadcast for a live incident. | Scheduled campaigns. Ask what can trigger an intervention other than a calendar or a failed simulation. |
| Practice beyond phishing | Cyber Ranges: immersive, branching, self-adapting scenarios across deepfake CEO video, vishing, smishing, data handling, secure browsing, endpoint, social media and physical security. First eight deploying late 2026. | Ask what is trained outside the inbox, and whether it is practice or a video module. |
| What feeds the human risk score | Human Risk Intelligence ingests behavior from EDR, DLP, web, email and IAM, plus attitudes, level of access, how targeted the person is, device security and workplace factors. | Ask what feeds their risk view, and specifically which inputs originate outside their own platform. |
| Security-stack integration | Entra ID, Okta, Microsoft Purview, Microsoft Defender, Microsoft Graph, Jamf, Zscaler, ServiceNow, plus threat enrichment via VirusTotal, IBM X-Force, CriminalIP and Spamhaus. | Compliance and LMS integration is documented. Ask specifically about SOC, SIEM and behavioral-signal integrations, and ask to see them live rather than on a roadmap. |
| Motivation and the manager layer | CyberQ: a personal cyber-competence score each person can see and improve, with a manager view so line managers can nudge and recognize their own teams. Feeds HR systems for appraisal where governance allows. | Campaign engagement and creative. Ask what a line manager can see and do. |
| People without corporate email | Delivered to frontline and OT populations without email access. In one deployment, 100% coverage including OT workers with no email, in four languages. | Ask how users without a mailbox are enrolled, reached and evidenced. |
| Campaign creative quality | Our content is generated and adapted per person, which is a different design goal from a memorable brand campaign. If your program runs on a strong annual creative moment, that is not our strength. | Genuinely memorable, well-produced campaign creative that people talk about, which is harder than it sounds. |
| UK, Ireland and Nordic footprint | Enterprise deployments across Europe, but a smaller local reference base in those specific markets. | A strong regional position, including European ownership and data posture and public-sector procurement familiarity in the UK and Ireland. |
| Pricing transparency | No public list price. Packaging mirrors the maturity model, so expansion follows your own journey rather than unbundled modules. L1 includes compliance training, delivery evidence and phishing simulation. See Plans. Human Risk Intelligence, the Real-Time Threats Engine and CyberQ are available from 2,001 licensed users. | No public list price either. Ask what is included at each tier, and specifically whether policy management, phishing simulation and the acquired Nordic content are separately licensed. |
| Implementation and support | Directory and SSO in week one, first campaign and baseline inside week four. Security-stack integrations that feed L3 are scoped separately and sequenced after the program is running. Named CSM and HRM program expertise. | Ask how long to first campaign, and who supports the program day to day across the acquired platforms. |
| Independent ratings | See OutThink on Gartner Peer Insights. | See MetaCompliance on Gartner Peer Insights and on G2. Read reviews of the awareness product specifically, and note that recent reviews may predate the acquired platforms being integrated. |
| Post-acquisition roadmap | Single platform, single roadmap. | Three acquisitions in three years under new ownership. Ask how the acquired platforms are being integrated, what the combined roadmap is, and what support continuity looks like across them. |
| Commercial shape | Packaging mirrors the maturity model, L1 Reactive through L4 Predictive, so expansion is your own maturity journey rather than an upsell. See Plans. | No public pricing. Ask what is included at each tier, and specifically whether policy management, phishing simulation and the acquired Nordic content are separately licensed. |
Sources for the MetaCompliance column. MetaCompliance product and platform pages, their acquisition announcements, and Gartner Peer Insights and G2 category listings. All accessed July 2026.

Building a Culture of Cyber Resilience Across a Global Workforce
VINCI partnered with OutThink to move beyond tick-box compliance, deploying adaptive, role-based security awareness across 270,000 employees in 120 countries - reducing human risk at enterprise scale.
Switching from MetaCompliance: what happens to your compliance position
The reasonable fear in a compliance-led switch is a gap in the audit trail. Worth addressing directly.
- Your evidence requirement is met on day one. L1 compliance training, delivery records and attestation reporting are part of the platform, not a later tier. You do not trade audit readiness for capability.
- Bring your records. Historic completion data can be retained for audit continuity, and OutThink works alongside major LMS platforms if your system of record stays where it is.
- Policy management stays where it is, and that is usually the right answer anyway. We do not replace it. If policy attestation currently lives in MetaCompliance, plan for it to move to your GRC platform or remain separate, and scope that explicitly rather than discovering it at cutover. This is the one genuine gap in a switch and it should be on the table in week one. What does move with you is the useful half: your policies become the source material for training generated around your actual environment.
- Keep your report button. You have spent years training people on the button they recognize, and OutThink integrates with it rather than asking you to retrain the reflex.
- Time it to the audit cycle, not the calendar. Establish your human risk baseline now so the next renewal is a decision rather than a default. The HRM Maturity Assessment does that in one session.
- Start at L1 if that is where you are. Packaging follows the maturity model, so L1 Reactive is a real starting point and L2 is an upgrade path rather than a re-platforming. See Compliance Without the Theater.
Frequently asked questions
For security awareness training and human risk management, yes, and organizations do move. For policy publication and attestation, no. We do not sell that module. What we do instead is use your policies to generate training grounded in your environment, and leave attestation in your GRC system of record. If a single vendor for both training and policy attestation is a hard requirement, weigh that seriously.
They position themselves as one. HRM is being adopted as a label across the market by compliance vendors, email security vendors and awareness platforms alike. The label matters less than the capability behind it, which is what the four tests are for.
Compliance training, delivery evidence, per-user audit trail and regulatory framing are all part of the platform. What changes is that the same deployment also produces a defensible human risk position, so you are not buying a second system to answer the board’s question.
Not to pass an audit. You need it the first time someone asks whether human risk fell, or which fifty people are most at risk today and why. The reason to think about it now rather than later is that the model is sequential, so the platform you commit to at L1 determines whether L2 and L3 are available to you without re-platforming.
For a contract tail, yes, and if policy management stays with them that may be a longer-term arrangement rather than an overlap. For training, running two programs splits the behavioral signal that makes adaptive training and risk quantification work.
By what feeds it. HRI ingests behavior from your EDR, DLP, web, email and IAM systems, plus attitudes, access level, how targeted the person is, device security and workplace factors. Completion analytics measure whether training happened. They are different instruments for different questions.
Pricing follows the maturity model, L1 Reactive through L4 Predictive, and depends on seat count, level and term. What we can tell you without a call: L1 includes compliance training, delivery evidence and phishing simulation rather than gating simulation as an add-on. See Plans, or talk to us for a quote at your seat count.
Directory and SSO connection in week one, first campaign and baseline inside week four, which matters if you are working to an audit date. The security-stack integrations that feed L3 are scoped separately and sequenced after the program is running. Named CSM and HRM program expertise throughout.
Find your level, then decide
Meeting the obligation is not the same as reducing the risk, and you are likely to be asked about both before this contract ends.
The compliance box will still be ticked. The difference is what else you can say.
Footnotes
- Gartner, cited in The End of Security Awareness As We Know It. The HRM Maturity Model describes what is possible, not what every organization must do. ↩
- Outcome figures are each organization’s own results, measured against their own starting point, and are not a benchmark to expect. Starting maturity, sector, workforce profile and program design change the result materially. ↩
Disclaimer
This comparison is an independent analysis by OutThink. Statements about MetaCompliance are drawn from their own public material and published third-party sources, current as of July 2026. Product capabilities change, and you should confirm anything decision-relevant with the vendor directly. Where we could not verify a capability from public sources, we have said so rather than guessed.
OutThink competes with MetaCompliance in security awareness training and human risk management. We have a commercial interest in your conclusion, which is why this page gives you an evaluation framework you can apply without us.
This page is informational and is not legal, financial or professional advice.