Skip to content

Group governance

Risk Core is built around how a Thai financial group actually works: the subsidiary holds the licence, has its own RMC and answers to its own regulator. The parent oversees; it does not operate.

RuleMeaning
Down-Only VisibilityA role at the parent can read everything beneath it; a subsidiary sees only itself. No entity ever sees a sibling.
Subsidiary-IndependenceA parent-level role may read but never act on a subsidiary’s records. No parent user can create, edit, approve or close a subsidiary’s risk, loss event, KRI or action. The database enforces this, not just the screen.
Report-Up-OnlyEach company runs its own identification, assessment, evaluation and reporting; its only duty to the parent is to report upward. The parent reads and consolidates. Every subsidiary is treated alike — no licensed / unlicensed exceptions.

The same rules apply in BCP Core: a parent’s group advisory sits beside the subsidiary’s own BCP level, and the subsidiary sets its level by its own act.

Criteria sets, materiality tiers and reporting periods are owned by the group root so everything consolidates; each entity’s data is its own.

PersonaRole
Risk Championdrafts RCSA and reports loss events for the unit
Reviewer / Approvervalidates and approves along the submission workflow
Entity Risk Managerruns risk management for the company
Executive / RMCapproves and receives reports
Group Readerreads the entities beneath; never acts
Administratorusers, roles and settings

Buttons appear only when the role allows; the database refuses regardless. With row-level security, every reporting view runs with the caller’s own rights.

Every change — who, when, before and after — resolved to the entity it belongs to.