What is Risk Legion?
Risk Legion is a modern, cloud-based Business Risk Assessment (BRA) platform designed to help enterprises identify, assess, and manage business risks through a structured control framework.Quick Start
Get up and running with Risk Legion in minutes
Architecture Overview
Understand the system architecture and design
API Reference
Explore the RESTful API endpoints
Deployment Guide
Deploy Risk Legion to production
Key Features
Business Risk Assessment (BRA)
Business Risk Assessment (BRA)
Comprehensive risk assessment workflow with:
- Structured risk identification and categorization
- Impact and likelihood analysis
- Inherent and residual risk calculations
- Heat map visualization
- Multi-stage review and approval process
Control Assurance
Control Assurance
Enterprise control framework management:
- Key control library with 80+ pre-built controls
- Test of Design (ToD) and Test of Effectiveness (ToE) assessment
- Control effectiveness scoring (Strong, Effective, Moderate, Weak, Failing)
- Custom control creation and categorization
- Control-to-risk mapping
Risk Appetite Framework
Risk Appetite Framework
Define organizational risk tolerance:
- Risk category-level appetite configuration
- Impact and likelihood thresholds
- Visual risk appetite boundaries
- Real-time compliance monitoring
Action Plan Management
Action Plan Management
Track risk mitigation activities:
- Action item creation and assignment
- Progress tracking with status updates
- Due date management
- Completion workflow
Enterprise Health Monitoring
Enterprise Health Monitoring
Super admin dashboard with:
- Health score calculation (0-100 scale)
- Health status classification (Healthy/At Risk/Critical)
- Intelligent alert system (8 alert types)
- Historical health tracking
- MRR and subscription tier tracking
Role-Based Access Control
Role-Based Access Control
Four-tier permission system:
- Super Admin: Platform-wide management
- Client Admin: Enterprise management
- Assessor: Risk assessment creation
- Reviewer: Assessment review and approval
Technology Stack
Frontend
- React 18 with TypeScript
- Vite build tool
- TanStack Query v5
- shadcn/ui components
- Recharts for visualizations
Backend
- FastAPI (Python)
- Supabase PostgreSQL
- Row-Level Security (RLS)
- JWT authentication
- Pydantic validation
Infrastructure
- Supabase (Database + Auth)
- AWS EC2 (Backend hosting)
- Vercel (Frontend hosting)
- Docker support
Core Concepts
Business Risk Assessment (BRA)
A BRA is a structured assessment that identifies and evaluates business risks across multiple categories:- Strategic Risks: Market competition, mergers & acquisitions
- Operational Risks: Business continuity, supply chain
- Financial Risks: Fraud, cash flow, budget management
- Compliance Risks: Regulatory compliance, data privacy
- Technology Risks: Cybersecurity, system availability
- Reputational Risks: Brand damage, customer trust
- Impact: Severity of consequences (1-5 scale)
- Likelihood: Probability of occurrence (1-5 scale)
- Inherent Risk: Risk level without controls
- Residual Risk: Risk level after control application
Control Effectiveness
Controls are evaluated using two dimensions:-
Test of Design (ToD): How well the control is designed
- Optimized, Defined, Ad-Hoc, Not Documented
-
Test of Effectiveness (ToE): How well the control operates
- Always Effective, Usually Effective, Sometimes Effective, Rarely Effective, Not Tested
- Strong (90-100): Optimal design and execution
- Effective (70-89): Well-designed and mostly effective
- Moderate (50-69): Adequate but room for improvement
- Weak (30-49): Significant gaps in design or execution
- Failing (0-29): Critical deficiencies
User Workflows
Assessor Workflow
- Create new BRA
- Identify and categorize risks
- Assess impact and likelihood
- Map controls to risks
- Submit for review
Reviewer Workflow
- Review submitted BRAs
- Validate risk assessments
- Request changes if needed
- Approve final assessment
Client Admin Workflow
- Manage enterprise users
- Configure risk appetite
- Create custom controls
- Monitor action plans
- View enterprise dashboards
Super Admin Workflow
- Manage all enterprises
- Monitor enterprise health
- Handle alerts (churn risk, adoption gaps)
- Track platform metrics
- Manage super admin users