MRI Commercial Management
By MRI Software LLC
MRI Commercial Management typical implementation process:
Initial Assessment and Planning: MRI and the client collaborate to define project goals, requirements, and success metrics. A detailed project plan and implementation checklist are developed at this stage, outlining deliverables, timelines, and resources needed.
System Configuration and Setup: MRI configures the software to match the client’s property portfolio, workflows, user roles, and reporting needs. This includes setting up modules, automating workflows, and integrating with other business systems if required.
Data Migration: Client data (leases, accounting records, tenant info, property details) is cleansed, mapped, and imported into MRI. Ensuring data accuracy and integrity during this phase is crucial for reliability.
User Training: MRI provides interactive training sessions for end-users and administrators to ensure that staff are comfortable and effective with the new system. Materials and resources are tailored to user roles.
Testing and Quality Assurance: The system undergoes user acceptance testing (UAT), where client teams verify functionality, data accuracy, and report generation. Any configuration tweaks are made before go-live.
Go-Live and Support: The solution is launched into the client’s live environment. Initial post-go-live support is strong, with MRI experts and helpdesk partners available to troubleshoot and resolve any issues that arise quickly.
MRI Commercial Management is widely recognized for its high level of customization and configurability, making it suitable for organizations with diverse or complex property management requirements. Here are key data points illustrating the platform’s customization capability:
Highly Configurable Core Platform: Users have access to the same tools as MRI developers, allowing significant tailoring of workflows, reports, dashboards, and user roles to fit specific operational requirements.
Customizable Workflows and Automated Processes: The platform supports the building and modification of automated workflows for tasks like lease administration, renewals, billing, approvals, and maintenance management, enabling you to align software processes directly with your business operations.
Custom Reports and Data Visualization: MRI provides configurable reporting and advanced data visualization tools, so businesses can create bespoke analytics, dashboards, and scheduled reports to meet their unique needs, without compromising user experience or data integrity.
Tailored User Interfaces and Menu Structures: The MRI Application Toolkit and Property Management X suite allow users to customize web pages, views, menus, and notifications, creating an interface specifically optimized for a company’s working methods.
Rule Engine for Payment and Transaction Allocation: MRI’s rule engine enables organizations to define custom rules for payment processing, allocations, and financial transactions across different properties and business units.
Integration with Third-Party Applications: MRI’s open API ecosystem supports integration with numerous external solutions, such as accounting, CRM, IoT, compliance, and facility management tools, making it possible to build a tailored technology stack.
Multi-Module and Sector-Specific Extensions: The solution offers configurable modules (Commercial Management, LeaseFlow, Viewpoint, Electronic Lockbox, etc.) that can be enabled, extended, or left unused based on precise sector and business needs, spanning office, industrial, and retail property requirements.
Scalability for Different Portfolio Sizes: Whether managing a single building or a global, multi-asset portfolio, MRI is designed to scale, with customization options supporting the unique requirements of both small firms and large enterprises.
User-Defined Alerts, Notifications, and Triggers: Businesses can set up custom alerts and notifications for critical events or milestones (like lease expirations, maintenance deadlines, or compliance checks) to fit internal policies and decision protocols.
Custom Integrations via Application Exchange: The MRI Application eXchange allows customization sharing—including custom reports, views, and features—with the broader user community or within an organization for standardized deployment.
MRI Commercial Management offers a suite of training and support resources designed to help new users become proficient and confident in using the platform.
MRI Training Academy:
Offers individual eLearning courses, learning suites, recorded video tutorials, and live webinars. Training is available on-demand or through scheduled sessions, covering essential functions, advanced features, and new modules.
Self-paced eLearning allows users to progress at their own speed, complete with assessments.
Live remote public training is hosted regularly, providing interactive, hands-on experiences with MRI experts.
Custom training solutions are available, including onsite instructor-led sessions and personalized learning plans tailored to organizational needs.
A dedicated learning portal provides user guides, intro videos, and help resources for navigating the training offerings.
Global Client Support:
MRI provides access to a Client Support Helpdesk, which can be reached via email, phone, or an online ticketing system. The myMRI Client Portal allows users to log cases 24/7, view support status, access documentation, and participate in user forums.
Support levels are structured by priority, with response targets such as:
Normal: Initial response within 6 hours
Serious: Initial response within 3 hours
Critical: Live call support for urgent issues
Customers receive a named Account Manager for consistent support and relationship management.
On-site support and additional professional services are available at extra cost for more complex needs or during implementation.
Implementation Support:
MRI’s implementation teams work closely with new clients to assess needs, configure the system, manage data migration, and facilitate user training as part of onboarding.
Post-launch, ongoing optimization reviews are conducted to help clients adopt new features and address evolving requirements.
Resource Access:
Users have access to extensive libraries of training videos, documentation, user guides, and product forums through the MRI portal.
MRI Commercial Management implements a wide range of robust security measures to protect client and tenant data, ensure system integrity, and support regulatory compliance:
Network Security and Infrastructure
Use of edge firewalls with automated threat feeds, network segmentation, and DNS inspection to minimize unauthorized access risks.
Intrusion detection and prevention systems to monitor and defend against cyber threats.
Secure data access via IPsec or TLS VPN gateways in parts of the solution stack.
Data Protection and Encryption
Application of encryption technologies for protecting data both in transit and at rest.
Role-based access controls ensure only authorized personnel can access sensitive data.
Strict password policies and multi-factor authentication (MFA) are enforced for employees and cloud users.
Continuous Monitoring and Incident Response
24/7/365 system monitoring, including real-time activity audit logs, to detect and promptly respond to security events.
Advanced endpoint protection (including XDR—Extended Detection & Response).
Change management processes and patch management to ensure rapid remediation of identified vulnerabilities.
Periodic Risk Assessments and Penetration Testing
Regular vulnerability assessments and penetration testing by accredited third-party audit firms.
Ongoing risk management processes, threat intelligence gathering, and threat hunting engagements to identify and neutralize emerging threats.
Physical and Organizational Security
Data centers and physical facilities are designed to prevent unauthorized access.
Access to systems is limited to authorized staff, with ongoing security awareness and policy training.
Compliance and Privacy Frameworks
Adheres to the EU-U.S. Data Privacy Framework (DPF), UK Extension, and Swiss-U.S. DPF for lawful international data transfers and privacy protection.
Holds SSAE18 SOC 1 Type 2 attestation, demonstrating commitment to financial and operational control integrity
.
Implementation of strict audit trails and activity logs to maintain accountability.
Application and Endpoint Security
Application whitelisting and whitelisted network resources.
Malware protection on all endpoints and application environments.
Regular system hardening to minimize exploitable configurations.
User Security and Awareness
Extensive staff security training and required awareness programs to reduce human error-related vulnerabilities.
Privileged access management ensures that only those with a business need can interact with critical or sensitive systems.
Through modules like MRI Angus, enables web-based visitor registration and access card management, integrating with facility access control systems to mitigate on-site risks.
Update management is handled through a coordinated communication process:
Notification: MRI sends upgrade notifications to designated Client Administrators, who are responsible for making update decisions for their organizations.
Testing Plan: Clients are encouraged to use thorough testing plans for major releases, ensuring all customizations and critical integrations (such as APIs) function as expected following the upgrade.
Support: MRI provides extensive support throughout the upgrade process, including access to test databases and direct contact with Cloud Upgrade teams if timeline changes or assistance are needed.
MRI Commercial Management (MRI Software) maintains a clear policy on data ownership and portability that emphasizes client ownership and compliance with global data protection standards.
Sole and Exclusive Ownership: Clients retain sole and exclusive ownership of all data they input or store within MRI’s Commercial Management solutions. This includes all tenant, lease, financial, and operational data. MRI’s terms explicitly state that “Client and/or Owner retains sole and exclusive ownership to any Client Data”.
Non-Disclosure and Confidentiality: MRI is required to protect client data as confidential information and cannot use, disclose, or share it beyond necessary service delivery without client consent.
Licensing of Usage Data: While clients retain ownership, MRI may use anonymized or aggregated data for legitimate business purposes, in line with applicable laws and contractual permissions.
Right to Data Portability: Clients have the right to request their data in a structured, commonly used, and machine-readable format, facilitating transfer to another service provider if desired.
Support for Data Transfer: MRI assists clients with data access and portability requests, allowing exporting of their data from the platform as required by GDPR and other regulations.
MRI Commercial Management provides comprehensive terms and conditions for contract renewal and cancellation. The following key data points summarize these conditions:
Automatic Renewal: After the initial term specified in the Order Document, SaaS service contracts automatically renew for the same period as the initial term, unless either party gives written notice of non-renewal at least sixty (60) calendar days before the end of the initial or any renewal term.
Notice of Renewal Pricing: MRI will provide written notice of the pricing for the first 12 months of any renewal term not less than ninety (90) calendar days before the end of the current term. This notice can be sent by email or first-class mail.
Mandatory Upgrades: Upon renewal, clients are required to migrate to the latest version of the hosted software.
Termination for Cause: Either party may terminate the agreement (including all schedules) immediately upon written notice if the other party commits a non-remediable material breach, or fails to cure a remediable material breach (or present a written plan to cure) within thirty (30) days after written notice. For payment-related breaches, the cure period is ten (10) days.
Selective Termination: The non-breaching party may choose to terminate the entire agreement or just the affected schedule(s). Any unaffected schedules continue in force.
Post-Termination Data Handling:
Clients must certify that they have returned or destroyed all copies of the software, content, and MRI confidential information.
All rights to use the software are relinquished after termination.
There are generally no refunds for fees paid if MRI terminates the agreement.
MRI will, upon the client's written request (and payment of applicable fees), provide a backup copy of client data at termination (a fee schedule is provided upon request).
Any client data left in the system beyond 30 days after termination may be deleted at MRI's discretion.
Obligation to Pay: Termination does not excuse the client from paying all amounts due. MRI may also accelerate payment of any unpaid amounts for the remainder of the current term if there is a material breach.
MRI Commercial Management (MRI Software) meets several key compliance standards and adheres to robust data protection frameworks for its commercial real estate solutions:
GDPR (General Data Protection Regulation): MRI is compliant with data privacy regulations in the EU, ensuring clients’ personal data is processed, stored, and transferred by EU requirements. This includes data subject rights, breach notification protocols, and processing limitations.
Data Privacy Framework (DPF): MRI participates in the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF. This attests to the company’s adherence to the principles set by the U.S. Department of Commerce, the European Commission, the UK Government, and the Swiss Administration, governing data transfers from these regions to the U.S.
ISO 27001: While not always called out specifically for the Commercial Management product on all web pages, MRI Software is noted in several communications to follow standards like ISO 27001 for information security management, which encompasses risk assessment, cybersecurity policies, and continuous monitoring.
Penetration Testing and Security Protocols: MRI uses independent third-party penetration testing, vulnerability assessments, and a wide range of security technologies: firewalls, threat intelligence, access controls, encryption, and incident response plans. These measures aim to meet or exceed standard information security requirements for cloud and SaaS solutions.
Employee Security & Process Controls: Required security awareness training for MRI employees, advanced endpoint protection, application whitelisting, and multifactor authentication are part of regular operations. MRI keeps its global information security team (InfoSec) tuned to evolving threats and compliance requirements.