Group governance
Risk Core is built around how a Thai financial group actually works: the subsidiary holds the licence, has its own RMC and answers to its own regulator. The parent oversees; it does not operate.
Three rules
Section titled “Three rules”| Rule | Meaning |
|---|---|
| Down-Only Visibility | A role at the parent can read everything beneath it; a subsidiary sees only itself. No entity ever sees a sibling. |
| Subsidiary-Independence | A parent-level role may read but never act on a subsidiary’s records. No parent user can create, edit, approve or close a subsidiary’s risk, loss event, KRI or action. The database enforces this, not just the screen. |
| Report-Up-Only | Each company runs its own identification, assessment, evaluation and reporting; its only duty to the parent is to report upward. The parent reads and consolidates. Every subsidiary is treated alike — no licensed / unlicensed exceptions. |
The same rules apply in BCP Core: a parent’s group advisory sits beside the subsidiary’s own BCP level, and the subsidiary sets its level by its own act.
One group template, local ownership
Section titled “One group template, local ownership”Criteria sets, materiality tiers and reporting periods are owned by the group root so everything consolidates; each entity’s data is its own.
Personas
Section titled “Personas”| Persona | Role |
|---|---|
| Risk Champion | drafts RCSA and reports loss events for the unit |
| Reviewer / Approver | validates and approves along the submission workflow |
| Entity Risk Manager | runs risk management for the company |
| Executive / RMC | approves and receives reports |
| Group Reader | reads the entities beneath; never acts |
| Administrator | users, roles and settings |
Buttons appear only when the role allows; the database refuses regardless. With row-level security, every reporting view runs with the caller’s own rights.
Audit log
Section titled “Audit log”Every change — who, when, before and after — resolved to the entity it belongs to.