Records & DPIA depth
DataGuard
The GDPR page names Daten-Mapping & VVT, DSFA, third-party risk and Maßnahmen modules, so the DSMS inventory exists on paper, but nothing evidences processing activities linked to legal bases, processors and TOMs in one data model, DPIA triggers derived from the record, or group-reusable templates. Until I see that connected model, I treat this as modules and templates, not a system of record for our register.
OneTrust
The live record of processing drawing from assessments, system integrations and imports into a central processing inventory, automated DPIA and PIA workflows, and vendor due diligence with a centralized record of data processing agreements and security obligations give me a connected data model I could put in front of a supervisory authority. I found no public information on legal bases tied to activities, on DPIA triggers derived from the record, or on multi-client mandate capability, which is what separates this from a full system of record.