A group policy is not evidence. It is an intention established by head office and, in the best cases, also rolled out to every entity. Whether that has happened, and whether the policy is actually applied, is a different question from whether the policy exists. A board that wants to demonstrate it is in control must be able to bridge that gap: not only showing what has been decided, but also what actually happens in practice at every entity that falls within the scope.
In a group with multiple entities, policy is usually written centrally and executed decentrally. That means the distance between the text of the policy and the practice on the shop floor is greater than in a single company. A subsidiary in another country, with a different language, a different management team and sometimes a different accounting tradition, applies the policy as it understands it. That is not automatically wrong, but it is something that must be established separately. A board that assumes the group policy is applied identically everywhere is making an assumption that is rarely tested until an auditor or regulator asks about it.
Policy is a document. Evidence is something else: an activity, an approval, a deviation that has been flagged and followed up, a check that has actually been carried out at a traceable moment. What counts as evidence for an obligation depends on the nature of that obligation, but the core is always the same: it must be demonstrable that something happened, not just that it should have happened. In a group with multiple entities, this distinction becomes sharper, because the policy is written in one place and the evidence must be retrieved from a completely different place.
The most common problem is not that there is no evidence, but that the evidence exists, scattered across different entities, systems and people responsible, without anyone at group level having an overview. A local controller has kept a spreadsheet, a compliance officer at a subsidiary has saved emails, an external accountant has completed a work programme that is stored nowhere centrally. Where evidence gets scattered is exactly this pattern: not the absence of evidence, but the absence of a place where the evidence comes together. As a group grows larger and more international, this pattern becomes stronger, simply because there are more places where something can be recorded and more people who think someone else is keeping track of it.
To organise demonstrability across multiple entities, a structure is needed that records, per obligation, who is responsible for what, even when that differs per entity. What a control matrix is at a group with multiple entities explains what such a matrix looks like: per obligation an owner, the evidence attached to that obligation and the control that demonstrates the evidence has been checked. For a single company, that matrix is manageable. For a group, each row multiplies by the number of entities to which the obligation applies, and that number is rarely equally clear to everyone within the group.
Demonstrability is only demonstrability once someone from outside the group can follow it. That can be an external auditor, a regulator, or a new board member who has to take over the previous situation. How you store evidence so an auditor finds it is about that findability: not only whether the evidence exists, but whether it is stored in a way that is understandable to someone who does not know the internal structure of the group. With multiple entities, this adds an extra layer of complexity, because findability must work not only within one entity, but also between entities, so that the group level can present a coherent picture instead of a collection of separate files.
An additional complication for a group is that the same European obligation can turn out differently per country. A subsidiary in Germany may fall under a different national implementation than a subsidiary in France, even though the underlying European rule is identical. Which national overlays apply in Germany and which national overlays apply in France show where that difference becomes concrete. A group policy written on the basis of the European text alone therefore does not automatically cover what each entity must demonstrate locally. That is precisely where many groups get caught out: not by the main rule, but by the national overlay that lies beneath it.
Mapping out owners, evidence and controls across multiple entities is work that largely consists of collecting, organising and repeatedly maintaining information that already exists somewhere. That is exactly the type of task for which the work scan from FTE TO AI examines which part can be taken over by AI, per task, without assuming anything about the outcome for your organisation.
Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.