Skip to content

ERM Core

ERM Core is Risk Core’s ERM module. It runs RCSA, loss events, KRIs, the BIA and dashboards as workflows rather than spreadsheets, for each company and for the whole group.

ERM Core shares its core with BCP Core. The overview is at Risk Core.

ModuleWhat it does
RCSARisk register per entity, scoring against a group-owned criteria set, inherent and residual risk, heat map, submission workflow, control testing
Loss Event and Loss ReportLoss event register mapped to Basel event types, multi-currency with an FX policy, materiality tiers, validation, the monthly cycle with nil returns
KRIKRI library, versioned threshold bands, observations, trend and breach views
BIACritical activities per unit with MTPD, RTO, RPO and minimum staffing; the criticality tier computed from MTPD bands; dependencies and single points of failure; linked to RCSA risks and to hazards; read by BCP Core
Dashboards and reportingExecutive summary per entity, group roll-up, loss report pack
Group governanceDown-Only Visibility, Subsidiary-Independence, Report-Up-Only, personas, audit log

Computed, never typed. Scores, tiers, rating bands and statuses are derived by the system from the inputs; a user cannot type a rating.

Who filed is stamped. Every record and every transition carries its author and time; history is append-only.

The parent reads, the subsidiary acts. Oversight without intervention, because the licensee’s legal duties stand above the group’s convenience.

Reported, then visible. Information travels upward only when the reporting entity has validated it.

Separate by design. Every company has its own database; the group is joined only by what is reported up.

Zero rows is not an error. An empty register shows a clear empty state.

Risk Champion · Reviewer / Approver · Entity Risk Manager · Executive / RMC · Group Reader · Administrator. Each has its own screen set; buttons appear only when the role allows, and the database refuses regardless.