Mercer

United States · www.mercer.com · 40 vendors

Mercer is a global consulting firm specializing in talent, health, retirement, and investment solutions. It provides advice and technology-driven solutions to help organizations meet the health, wealth, and career needs of a changing workforce. Mercer is a wholly owned subsidiary of Marsh McLennan.

Resilience scores

Technology vendors

Services catalogue

4 services in catalogue across 1 category; runs on 40 sub-vendors.

Insights

Last updated 2026-08-15 · revision 3

40 direct vendors, 338 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Mercer exhibits a foundational level of migration readiness, primarily driven by its existing adoption of modern cloud platforms like Microsoft Azure and Snowflake, and its use of integrated enterprise solutions such as Salesforce, Workday, and ServiceNow. The explicit mention of 'Cloud-Based HR Technology Integration' as a key technology indicates active engagement with cloud strategies and a potential for further cloud-native adoption. The geographic diversity of its vendor base (9 unique countries) suggests experience in managing complex, multi-national vendor relationships, which can be beneficial during large-scale migrations. However, significant challenges and unknowns temper its overall readiness. Crucially, there is no information available regarding the specific regulatory environment or data residency requirements, which are paramount for a global financial services firm and can introduce substantial complexity and cost to any migration effort. The extent of legacy systems versus cloud-native architecture (e.g., containerization, microservices) is not detailed, making it difficult to assess the technical ease and scope of potential migrations. Furthermore, the actual number of unique vendors is unclear ('Total Vendors: 0' is contradictory to other vendor data), which complicates the assessment of vendor lock-in risk, although 'Total Services: 52' suggests a potentially complex vendor landscape. Financial capacity to fund a large migration is also an unknown due to missing financial data. Given the existing cloud adoption but critical regulatory, data residency, and architectural unknowns, Mercer's migration readiness is assessed as moderate.

Compliance

11 in-scope frameworks identified; showing 3.

CPRA — Assessment Required

Mercer is headquartered in New York and operates extensively in California. As a large enterprise (20,000+ employees, revenues well above $25M annually) processing personal information of California residents, Mercer is subject to CCPA/CPRA. Risk is Medium because: (1) Mercer's Privacy Notice explicitly references California-specific rights (opt-out of sale/sharing, GPC signal recognition) confirming CCPA/CPRA applicability; (2) the California Privacy Protection Agency (CPPA) has begun enforcement actions; (3) Mercer processes sensitive personal information (health data, financial data, SSNs) of California residents; (4) however, Mercer's Privacy Notice demonstrates awareness of CCPA/CPRA requirements and provides required disclosures and opt-out mechanisms; (5) the B2B and employee exemptions under CPRA have expired, expanding scope.

Evidence: https://www.mercer.com/en-us/footer/privacy-notice/, https://globalprivacycontrol.org/, https://cppa.ca.gov/

HIPAA (source) — Assessment Required

Mercer provides health and benefits consulting, pharmacy benefits management (MercerRx), employee well-being programs, and State Medicaid consulting services in the United States. These services involve handling Protected Health Information (PHI) on behalf of employer plan sponsors and government clients. As a Business Associate under HIPAA, Mercer is subject to the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. Risk is Medium because: (1) Mercer explicitly handles health information, medical history, disability information, and insurance claims data as listed in its Privacy Notice; (2) Mercer's State Medicaid consulting practice directly involves government health program data; (3) pharmacy benefits management (MercerRx) involves prescription drug data which is PHI; (4) as a Business Associate, Mercer faces the same penalties as Covered Entities (up to $1.9M per violation category per year); (5) however, Mercer acts primarily as a consultant/advisor rather than a direct healthcare provider, which limits some exposure. No public HIPAA enforcement action against Mercer was found.

Evidence: https://www.mercer.com/en-us/solutions/health-and-benefits/specialty-solutions/pharmacy-solutions-mercerrx/, https://www.mercer.com/en-us/solutions/government/, https://www.mercer.com/en-us/footer/privacy-notice/, https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html

SOC 2 (source) — Assessment Required

Mercer provides technology-enabled services including MercerInsight® (cloud-based asset manager research platform), digital HR implementation, benefits administration platforms, and data analytics services to corporate clients. These services involve processing sensitive client data in cloud environments, making SOC 2 Type II reports highly relevant and likely expected by enterprise clients. Risk is Medium because: (1) enterprise clients in financial services and healthcare routinely require SOC 2 reports from service providers as part of vendor due diligence; (2) absence of SOC 2 certification could be a competitive disadvantage and contractual risk; (3) Mercer's parent Marsh McLennan has a dedicated CISO and cybersecurity program suggesting security controls exist; (4) however, no public SOC 2 report or certification was found, creating uncertainty about formal attestation status. The risk is not High because SOC 2 is a voluntary framework, but client contractual requirements effectively make it mandatory for Mercer's business model.

Evidence: https://www.mercer.com/en-us/solutions/investments/mercerinsight/, https://www.mercer.com/en-us/footer/privacy-notice/, https://www.mercer.com/en-us/about/company/about/

Financials

Three-year financials

Financial Resilience Score: 8/10

Mercer benefits from being a subsidiary of Marsh McLennan (NYSE: MMC), a ~$100B+ market cap, investment-grade rated firm (A-/A3) with strong liquidity, capital markets access, and disciplined M&A capability. Mercer's revenue base is largely recurring or repeat-engagement, spanning health & benefits consulting, retirement/pension consulting, wealth/OCIO management, and career advisory, providing stable cash flows through varied macro cycles. The firm has demonstrated consistent mid-single-digit to high-single-digit organic revenue growth and manages/advises on over US$500 billion in AUM, generating fee-based revenue that grows with markets. Diversified geographies and client segments further support resilience. However, Mercer is exposed to interest-rate and market sensitivity in Wealth (asset-value-linked fees), secular decline in defined-benefit pension consulting, regulatory risk (ERISA, IORP, FCA), and wage inflation in a talent-intensive cost base. The ongoing brand consolidation into Marsh creates short-term transition risk, and Mercer has no standalone financing capability, making its resilience inseparable from parent priorities.

Key strengths: Parent balance sheet backing from Marsh McLennan (investment-grade A-/A3), Recurring, advisory revenue base with corporate and institutional clients, Scale in Investments & Wealth with over US$500B in AUM, Diversified geographies and client segments, Cross-sell opportunities within Marsh McLennan ecosystem, Consistent mid-single-digit organic revenue growth

Risk factors: Interest-rate and market sensitivity in Wealth segment, Secular decline in defined-benefit pension consulting, Regulatory exposure (ERISA, IORP, FCA), Talent-intensive cost base with wage inflation pressure, Brand transition risk from consolidation into Marsh, No standalone financing capability; dependent on parent MMC

Revenue by geography

Revenue by product/service

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report