Skip to content

Risk Core

Risk Core is one platform that runs the whole risk life cycle — identify, assess, monitor, respond, recover — built for Thai corporate groups and the subsidiaries inside them.

Risk Core is one platform with two modules — ERM Core for the risk desk and the RMC, and BCP Core on every employee’s phone. Both run on one shared core inside each company’s own database.

Risk Core platform mapEvery company signs in on one Risk Core sign-in page through its own domain. Each company has its own isolated database holding ERM Core and BCP Core on one core. A risk in RCSA can be the hazard BCP Core watches, BCP Core reads critical activities from the BIA in ERM Core, and an incident becomes a loss event. Companies in a group are linked only by report-up.RISK → HAZARDBIA → CRITICAL ACTIVITIESINCIDENT → LOSS EVENTREPORT-UPREPORT-UPRisk deskRisk Champion · Reviewer · RMCEvery employeephone · push notificationOne Risk Core sign-in pagereached through each company's own domainMODULEERM CoreRCSA · Loss Event · KRIBIA · DashboardsMODULEBCP CoreHazard · BCP level · Check-inCall tree · Exercise logSHAREDCoreorganisation structure · staff register · one identityroles · audit log · action register · risk taxonomyParent companyown database · group roll-upSubsidiaryown databaseSubsidiaryown databaseEACH COMPANY · ITS OWN ISOLATED DATABASEGROUP · LINKED ONLY BY REPORT-UPLEGENDModuleShared in the companyCompanyReport-up
One sign-in page, one database per company, two modules on one core. Companies in a group are linked only by report-up.
ERM CoreBCP Core
WorkERM for the risk functionBCM for every employee
Main usersRisk Champion, Reviewer, Entity Risk Manager, RMCstaff, team heads, the BCP head and HR
CoversRCSA, Loss Event, KRI, BIA, Dashboards, Group governanceHazard and early warning, BCP level, Check-in, Call tree
Where it livesthe desk and the boardroom packthe phone, with push notification
Standardsbuilt to serve COSO ERM (2017) and the Basel event typesbuilt to serve ISO 22301

Take ERM Core only, BCP Core only, or both on the shared core.

  • Organisation structure entered once and used everywhere — imported from a spreadsheet or read from an org-chart image or PDF at onboarding.
  • One account, one password, both modules. A person who is both CFO and BCP head signs in once and sees both roles.
  • No re-keying between modules. An incident that caused a loss is filed as a loss event; a risk assessed in RCSA can be the hazard BCP Core watches; the BIA in ERM Core tells BCP Core which activities are critical and how fast they must recover.
  • One audit log and one action register for every act in either module.
  • Your domain, your database. Staff go to their company’s address, sign in on the Risk Core sign-in page and land in their own company’s data. Every company, including sister companies in one group, has its own isolated database; the group is linked only by what each company reports up.
  • Staff register — the single list both modules use; accounts are created by e-mail invitation and staff set their own password.
  • One identity, many roles — a person’s rights are consolidated by the organisation structure; one sign-in shows every role they hold, managed in one roles panel.
  • Sign-in — password plus a 6-digit authenticator code (MFA, TOTP); Microsoft or Google SSO for clients who want it.
  • Action register — actions from RCSA, control testing, loss events, KRI breaches, BIA single points of failure, exercises and incidents, with owner, due date and status.
  • Audit log — every change in both modules: who, when, before and after.

Financial groups and licensed companies. Holding companies whose subsidiaries are supervised by the SEC, BOT or OIC — securities, asset management, digital assets, payments, insurance. Start with ERM Core: group governance that keeps Subsidiary-Independence, group roll-up, RCSA on one group template, and Basel-mapped loss events with materiality tiers.

General corporates and SMEs that need business continuity that works: knowing where their people are in a flood, warning them before a hazard hits, and running the call tree when the plan activates. Start with BCP Core and grow into ERM Core.

  • COSO ERM (2017) — ERM Core covers Performance, Review & Revision, and Information, Communication & Reporting. Governance & Culture and Strategy & Objective-Setting are policy and committee work; the system holds their reference data — risk appetite statements, taxonomy, RACI.
  • ISO 22301 — ERM Core holds the BIA and the risk assessment; BCP Core supports continuity strategy and plans, exercising, and performance-evaluation evidence.
  • Basel — loss events map to the seven Level-1 event types.
  • PDPA — QX acts as data processor for personal data held in the service; the service contract includes a Data Processing Agreement.

Risk Core is designed for companies supervised by the SEC, BOT and OIC; it is not endorsed by them.

A cloud service operated by QX. One sign-in page for every client, reached through the client’s own domain; every company has its own isolated database, and companies in a group are linked by report-up. It runs in the browser and mobile browser, in Thai and English. Criteria sets, materiality tiers, MTPD bands and the hazard set are configured with the client’s risk function. Pricing is per company, by modules and user count. Security detail: Security and data.