Risk Core
Risk Core is one platform that runs the whole risk life cycle — identify, assess, monitor, respond, recover — built for Thai corporate groups and the subsidiaries inside them.
Risk Core is one platform with two modules — ERM Core for the risk desk and the RMC, and BCP Core on every employee’s phone. Both run on one shared core inside each company’s own database.
Two modules
Section titled “Two modules”| ERM Core | BCP Core | |
|---|---|---|
| Work | ERM for the risk function | BCM for every employee |
| Main users | Risk Champion, Reviewer, Entity Risk Manager, RMC | staff, team heads, the BCP head and HR |
| Covers | RCSA, Loss Event, KRI, BIA, Dashboards, Group governance | Hazard and early warning, BCP level, Check-in, Call tree |
| Where it lives | the desk and the boardroom pack | the phone, with push notification |
| Standards | built to serve COSO ERM (2017) and the Basel event types | built to serve ISO 22301 |
Take ERM Core only, BCP Core only, or both on the shared core.
What one core gives you
Section titled “What one core gives you”- Organisation structure entered once and used everywhere — imported from a spreadsheet or read from an org-chart image or PDF at onboarding.
- One account, one password, both modules. A person who is both CFO and BCP head signs in once and sees both roles.
- No re-keying between modules. An incident that caused a loss is filed as a loss event; a risk assessed in RCSA can be the hazard BCP Core watches; the BIA in ERM Core tells BCP Core which activities are critical and how fast they must recover.
- One audit log and one action register for every act in either module.
- Your domain, your database. Staff go to their company’s address, sign in on the Risk Core sign-in page and land in their own company’s data. Every company, including sister companies in one group, has its own isolated database; the group is linked only by what each company reports up.
Shared core
Section titled “Shared core”- Staff register — the single list both modules use; accounts are created by e-mail invitation and staff set their own password.
- One identity, many roles — a person’s rights are consolidated by the organisation structure; one sign-in shows every role they hold, managed in one roles panel.
- Sign-in — password plus a 6-digit authenticator code (MFA, TOTP); Microsoft or Google SSO for clients who want it.
- Action register — actions from RCSA, control testing, loss events, KRI breaches, BIA single points of failure, exercises and incidents, with owner, due date and status.
- Audit log — every change in both modules: who, when, before and after.
Who it is for
Section titled “Who it is for”Financial groups and licensed companies. Holding companies whose subsidiaries are supervised by the SEC, BOT or OIC — securities, asset management, digital assets, payments, insurance. Start with ERM Core: group governance that keeps Subsidiary-Independence, group roll-up, RCSA on one group template, and Basel-mapped loss events with materiality tiers.
General corporates and SMEs that need business continuity that works: knowing where their people are in a flood, warning them before a hazard hits, and running the call tree when the plan activates. Start with BCP Core and grow into ERM Core.
Standards and regulation
Section titled “Standards and regulation”- COSO ERM (2017) — ERM Core covers Performance, Review & Revision, and Information, Communication & Reporting. Governance & Culture and Strategy & Objective-Setting are policy and committee work; the system holds their reference data — risk appetite statements, taxonomy, RACI.
- ISO 22301 — ERM Core holds the BIA and the risk assessment; BCP Core supports continuity strategy and plans, exercising, and performance-evaluation evidence.
- Basel — loss events map to the seven Level-1 event types.
- PDPA — QX acts as data processor for personal data held in the service; the service contract includes a Data Processing Agreement.
Risk Core is designed for companies supervised by the SEC, BOT and OIC; it is not endorsed by them.
Delivery
Section titled “Delivery”A cloud service operated by QX. One sign-in page for every client, reached through the client’s own domain; every company has its own isolated database, and companies in a group are linked by report-up. It runs in the browser and mobile browser, in Thai and English. Criteria sets, materiality tiers, MTPD bands and the hazard set are configured with the client’s risk function. Pricing is per company, by modules and user count. Security detail: Security and data.