Overview
Client Admins are enterprise-level administrators who manage all aspects of their organization’s Risk Legion instance. They have full access within their enterprise, including user management, configuration, and BRA approval.Key Responsibilities
| Responsibility | Description |
|---|---|
| User Management | Create and manage Assessors and Reviewers |
| Organization Setup | Configure Legal Entities and Business Units |
| Risk Library | Manage Products, Scenarios, Controls, Triggers |
| Risk Appetite | Define and update risk appetite thresholds |
| BRA Approval | Review and approve submitted BRAs |
| Audit Review | Access and review audit logs |
Permissions Matrix
| Feature | Client Admin | Assessor | Reviewer |
|---|---|---|---|
| View Dashboard | ✅ | ✅ | ✅ |
| Create BRA | ✅ | ✅ | ❌ |
| Edit BRA | ✅ | ✅ | ❌ |
| Approve BRA | ✅ | ❌ | ❌ |
| Cancel BRA | ✅ | ❌ | ❌ |
| Manage Risk Library | ✅ | ❌ | ❌ |
| Configure Risk Appetite | ✅ | ❌ | ❌ |
| Manage Organization | ✅ | ❌ | ❌ |
| Manage Users | ✅ | ❌ | ❌ |
| View Audit Logs | ✅ | ❌ | ✅ |
| Create Actions | ✅ | ✅ | ❌ |
| Manage Actions | ✅ | ✅ | ❌ |
Client Admin Workflows
User Management
Creating Users
- Navigate to Settings → Users
- Click Add User
- Enter user details:
- Email address
- Full name
- Role (Assessor or Reviewer)
- Assign entity access (for Assessors/Reviewers)
- Click Create User
New users receive an email invitation to set up their account. They must complete registration before accessing the platform.
Assigning Entity Access
Assessors and Reviewers need entity assignments:- Go to Settings → Users → [User Name]
- Click Manage Assignments
- Select Legal Entities and/or Business Units
- Click Save
Users can only see data for their assigned entities. Client Admins see all entities.
Deactivating Users
- Go to Settings → Users
- Find the user
- Click Deactivate
- Confirm the action
- Cannot log in
- Retain historical assignments
- Can be reactivated later
- Historical audit entries preserved
Organization Setup
Legal Entities
Legal Entities represent your organizational structure:- Navigate to Governance → Organisation Structure
- Click Add Legal Entity
- Enter details:
- Name
- Legal Name
- Entity Type (Bank, Insurance, Investment Firm, etc.)
- Country of Incorporation
- Registration Number
- Parent Entity (for subsidiaries)
- Click Create
Business Units
Business Units are operational divisions within Legal Entities:- Navigate to Governance → Organisation Structure → Business Units
- Click Add Business Unit
- Select parent Legal Entity
- Enter Business Unit name and description
- Click Create
Risk Library Management
Products
Products drive risk scenario relevance:- Go to Governance → Risk Library → Products
- Click Add Product
- Enter:
- Product Name
- Category
- Description
- Customer Types
- Geographic Operations
- Distribution Channels
- Transaction Types
- Click Create
Risk Scenarios
Configure your risk scenario library:- Go to Governance → Risk Library → Risk Scenarios
- Click Add Scenario
- Enter:
- Name
- Category (Credit, Operational, Compliance, etc.)
- Description
- Risk Group (optional)
- Link to relevant Products
- Link suggested Controls
- Link Risk Triggers
- Click Create
Key Controls and Sub-Controls
Build your control library:- Go to Governance → Risk Library → Key Controls
- Click Add Key Control
- Enter control details
- Add Sub-Controls under the Key Control
- Link controls to relevant Risk Scenarios
Risk Appetite Configuration
- Navigate to Governance → Risk Appetite
- Set enterprise-wide default:
- Select maximum acceptable risk level
- Add description/rationale
- Optionally add entity-level overrides
- Review history of changes
BRA Approval
Client Admins approve submitted BRAs:- Navigate to BRAs → Pending Approval
- Click on a BRA to review
- Review:
- Risk scenario assessments
- Control linkages
- Risk ratings and justifications
- Mitigation recommendations
- Either:
- Approve - Creates immutable snapshot
- Request Changes - Returns to Assessor with comments
Audit Log Review
Access comprehensive audit trails:- Navigate to Settings → Audit Logs
- Filter by:
- User
- Action Type
- Entity Type
- Date Range
- Export logs as needed
Dashboard Access
Client Admins see the full enterprise dashboard:Visible Metrics
- Total risks across all entities
- Risks above appetite (enterprise-wide)
- Control effectiveness summary
- Overdue actions count
- Risk heat maps
- Trend indicators
Filtering
- Filter by any Legal Entity
- Filter by any Business Unit
- Date range filtering
- All data accessible
Best Practices
User Management
User Management
- Review user access quarterly
- Remove access promptly when roles change
- Use specific entity assignments
- Document user responsibilities
Organization Setup
Organization Setup
- Mirror legal structure accurately
- Keep business units aligned with operations
- Update when organizational changes occur
- Archive rather than delete
Risk Library
Risk Library
- Start with core scenarios and controls
- Expand based on business needs
- Review annually for relevance
- Link all relationships properly
BRA Approval
BRA Approval
- Review all scenarios thoroughly
- Verify justifications are adequate
- Check control linkages make sense
- Ensure risk appetite is applied correctly
API Access
Client Admins can access all enterprise-level APIs:| API Group | Access Level |
|---|---|
| BRAs | Full CRUD + Approve/Cancel |
| Governance | Full CRUD |
| Risk Library | Full CRUD |
| Controls | Full CRUD |
| Mitigation Actions | Full CRUD |
| Dashboard | Full Read |
| Users | Read + Create (Assessor/Reviewer) |
| Audit Logs | Read |