ISS Governance
United States · www.issgovernance.com · 15 vendors
Institutional Shareholder Services Inc. (ISS) is a global provider of corporate governance and responsible investment solutions. The company offers data, analytics, research, and recommendations to institutional investors and corporations. Its services help clients make informed investment and stewardship decisions, including proxy voting and managing environmental, social, and governance (ESG) risks.
Resilience scores
- Digital Sovereignty: 73
- Digital Resilience: 9
- Financial Resilience: 8
Technology vendors
- Adobe Inc. — Technology — United States
- Demandware — Technology — United States
- Rain-Task Limited — Technology — United Kingdom
- and 12 more
Services catalogue
3 services in catalogue across 1 category; runs on 15 sub-vendors.
- ISS Governance
- Platform
- Proxy Voting
Insights
Last updated 2026-04-15 · revision 2
15 direct vendors, 201 subvendors
Direct vendors by controlling owner country (sample)
- United States: 11
- Denmark: 1
- United Kingdom: 1
Subvendors by controlling owner country (sample)
- United Kingdom: 7
- Unknown: 1
- Poland: 1
Migration Readiness: 9/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
ISS Governance exhibits very high migration readiness, largely driven by its highly modern and cloud-native technology stack. The existing adoption of Amazon Web Services (AWS) and Microsoft Azure, coupled with containerization technologies like Kubernetes and Docker, indicates that the company's infrastructure and applications are already well-suited for cloud environments and portability. The use of Apache Kafka, Apache Spark, and Snowflake for data processing and warehousing further points to a distributed and scalable architecture. The utilization of REST APIs suggests a microservices-oriented approach, which simplifies migration efforts. The multi-cloud strategy inherently reduces infrastructure-level vendor lock-in. However, specific data on regulatory compliance requirements, data residency constraints, and the company's financial stability to fund a large-scale migration are not available, representing potential unknown challenges. The 'Total Services: 22' with 'Total Vendors: 0' is contradictory, but the strong technical foundation for cloud adoption is the dominant factor in assessing migration readiness.
Compliance
5 in-scope frameworks identified; showing 3.
ISO 27001 (source) — Assessment Required
ISO 27001 is increasingly important for organizations handling sensitive information or providing B2B services. While not legally mandated, it's often required by clients and demonstrates information security maturity. Risk level is medium because lack of certification could impact business opportunities and client trust, especially in governance-related services.
SOC 2 (source) — Assessment Required
SOC2 is critical for service organizations, especially those providing cloud services, SaaS, or handling customer data. Given the 'Governance' in the company name, they may provide governance, risk, or compliance services requiring SOC2. While not legally mandated, SOC2 is often contractually required by clients and essential for business credibility in B2B services.
GDPR (source) — Assessment Required
While ISS Governance is US-headquartered, GDPR applies if they process personal data of EU/EEA residents through any business activities, employee data, or customer interactions. Without knowing their specific operations or client base, there's a moderate risk of GDPR applicability. Non-compliance penalties can reach 4% of annual turnover or €20M, making this a significant risk if applicable.
Financials
Three-year financials
- 2023: revenue ~$390–400 million (LTM)
- 2022: revenue ~$360–370 million
- 2021: revenue ~$330–340 million
Financial Resilience Score: 8/10
ISS Governance demonstrates strong financial resilience underpinned by a dominant market position — holding an estimated 60–65% global market share in proxy advisory services — and a highly recurring, subscription-based revenue model. The subscription structure provides exceptional revenue visibility and low churn, as institutional clients embed ISS data and voting recommendations deeply into their compliance and investment workflows, creating high switching costs. The Deutsche Börse acquisition at USD 2.3 billion, implying an EV/EBITDA multiple of approximately 18–20x on estimated LTM EBITDA of USD $115–130 million, confirms strong profitability and cash generation consistent with high-margin data and analytics peers. The business benefits from structural regulatory tailwinds — including growing ESG disclosure mandates, stewardship codes across the UK and EU, and Say-on-Pay regulations — which have durably expanded demand for governance advisory services. Geographic diversification across North America, Europe, and Asia-Pacific further reduces single-market exposure. Post-acquisition by Deutsche Börse, ISS Governance also gains access to a major European financial infrastructure group with approximately €5.8 billion in FY2023 revenues, providing balance sheet support and expanded distribution. Key risks that temper the resilience score include regulatory scrutiny from the SEC and EU regulators regarding proxy advisor oversight, persistent conflict-of-interest concerns arising from ISS advising both investors and the corporations it rates, and client concentration risk among a relatively small number of large institutional investors. Integration risk post-Deutsche Börse acquisition and political ESG backlash in the US also represent meaningful headwinds. These factors collectively prevent a top-tier resilience score despite the company's otherwise strong financial profile.
Key strengths: Dominant global market share of ~60–65% in proxy advisory services, creating near-duopoly pricing power, Highly recurring, subscription-based revenue model with high client retention and low churn, High EBITDA margins (~30–33% implied), consistent with data/analytics business peers such as MSCI and FactSet, Strong revenue growth trajectory: high-single-digit to low-double-digit CAGR over 2017–2023, Structural regulatory tailwinds from ESG disclosure requirements and stewardship codes globally, High switching costs due to deep client workflow integration, Post-acquisition backing from Deutsche Börse AG, a major European financial infrastructure group, Geographic diversification across North America, Europe, and Asia-Pacific
Risk factors: Regulatory scrutiny: SEC and EU regulators have increased oversight of proxy advisory firms, potentially constraining business practices, Conflict-of-interest concerns: ISS provides advisory services to both investors and the corporations it rates, drawing persistent criticism, Client concentration risk: top institutional investor clients likely represent a disproportionate share of revenue, Competition from Glass Lewis (~35% market share) and in-house proxy research by large asset managers (BlackRock, Vanguard), Integration risk: execution challenges in merging ISS Governance into Deutsche Börse's culture and business model, ESG backlash: political pushback against ESG investing in the US could reduce demand for ESG-linked governance services, No publicly audited standalone financials available, limiting external verification of disclosed metrics
Revenue by geography
- North America (primarily US): 57%
- Europe (UK, EU, Switzerland): 32%
- Asia-Pacific: 10%
- Rest of World: 3%
- Other: 0%
Revenue by product/service
- Proxy Research & Voting (Advisory): 52%
- Governance Data & Analytics: 28%
- Corporate Solutions / Consulting: 13%
- Other / Specialty Research: 5%
- Other: 2%
Workforce by country
- United States: 750
- Europe: 525
- Asia-Pacific: 263
- Rest of World: 63
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.