PV
PilotVantage

Multi-Entity Management

Run several companies, regions or business units side by side — each with its own workspace, registers and administrators — while Group Risk keeps the overall picture.

How multi-entity works

Each entity in your group — a subsidiary, a region, or a business unit — gets its own workspace with fully separated data: its own risk registers, controls, policies, incidents, audits and settings. People who work across entities belong to more than one workspace and switch between them from the organisation switcher, without signing out.

Isolation by design
Every entity's data is held separately. Users only ever see the entities they've been added to — there is no cross-entity visibility unless you grant it.

Hierarchical risk management

Risks roll up through a clear hierarchy, so every level of the organisation sees the view it needs:

1

Departmental registers

Teams record and manage risks in their own department's register — focused, without the noise of the wider group.

2

Roll up to the entity register

Significant departmental risks are escalated, with approval, to the business unit's Organisation Register — the consolidated view for that region or entity.

3

Board-level visibility

The most important risks surface in the leadership Board View, giving directors a single, current picture of the risks that matter.

4

Group oversight

Group Risk members hold membership in every entity, so they can review each business unit's register and board view from one login.

Escalation is deliberate, not automatic: a risk owner requests roll-up with a justification, and Risk & Compliance approves or rejects it — so the higher-level registers stay meaningful. See Risk Register for the full escalation workflow.

Delegated administration

Each business unit administers itself. Local administrators manage their own entity's users, departments, settings and data — and nothing beyond it. Group Risk retains overall control by holding the Risk & Compliance or Administrator role in every entity, so central oversight never depends on local teams.

WhoScope
Business-unit administratorsFull administration of their own entity only — users, roles, departments, settings, billing.
Group RiskMembership across all entities: reviews every register, approves escalations, and keeps group-wide standards consistent.
Everyone elseSees only the entities and departments they belong to, according to their role.
Segregation of duties built in
Because approval flows separate the requester from the approver, and roles are scoped per entity and department, the same person can't approve their own work or push high-risk changes unchecked. More in Users & Roles.

Setting up a group structure

1

Create a workspace per entity

Each subsidiary, region or business unit signs up as its own organisation, keeping its data and settings separate.

2

Mirror your structure with departments

Within each entity, create the departments that teams actually work in — that's where day-to-day risks live.

3

Add Group Risk to every entity

Invite your central risk team to each workspace with the Risk & Compliance role so they hold group-wide oversight.

4

Delegate local administration

Give each business unit its own Administrator so local teams run themselves within their boundary.

Works with

  • Risk Register — departmental registers, escalation and the Board View.
  • Users & Roles — roles, department scoping and segregation of duties.
  • Reports — board packs per entity for group reporting.
  • Organisation Settings — each entity tailors its own scoring scales and appetite.