An auditor checking demonstrability asks a simple question: where is the evidence that this obligation has been met, and who can show it. For a single entity, that is often still manageable. In a group with multiple locations, subsidiaries or country organisations, evidence becomes scattered across systems, folders and people who do not know each other. That is not necessarily a sign of poor policy. It is often only a sign that nobody has documented where evidence should be kept, and who is responsible for making sure it stays there.
Evidence is not the policy document itself. An auditor asks for what demonstrates that the policy has also been applied: a decision, an approval, a report, a deviation log, an email in which a responsible person established something. What exactly counts differs per obligation and per moment in the process. What counts as evidence for an obligation sets out which forms of evidence belong to which type of obligation, and why a statement of intent without application usually does not suffice.
In a group with multiple entities, dispersion arises in a number of predictable places. Each entity may keep its own records, in its own system, with its own naming convention for documents. A local director may have made a decision that was never recorded centrally anywhere. A parent company may assume that a subsidiary has arranged something, without ever having verified that. And a national branch may fall under additional rules that the group as a whole is not aware of, meaning that no evidence for it is collected at all. What is mandatory in one country need not be mandatory elsewhere, and vice versa: examples of this can be found at which national add-ons apply in Germany and which national add-ons apply in France. Anyone who only looks at the European rule misses the part that has been added locally, and therefore also the evidence that belongs to it.
Evidence that is not assigned to anyone is usually not kept up to date, or gets lost as soon as someone changes roles. Findability therefore does not start with an archiving system, but with the question of who is the owner for each obligation: who ensures that the evidence is created, who keeps it, and who can show it when asked. In a group with multiple entities, that is rarely a single role for the entire organisation. What that division can look like, and why a single group-level coordinator usually does not suffice, is set out at who owns an obligation in a group with multiple entities.
An auditor looking for evidence does not only check whether an obligation has been written down in policy, but whether that policy has also been followed. A group may have an excellent policy document on supplier assessment, while in practice only part of the entities have ever applied that policy. The difference between those two layers, and how you make that difference visible instead of leaving it hidden, is set out at how you demonstrate that policy is also practice in a group with multiple entities. Evidence that consists only of policy text is insufficient for an auditor, no matter how carefully the policy has been written.
To make evidence findable across multiple entities, it helps to record per obligation: who the owner is, what evidence is expected, and which control demonstrates that the process is repeatable and not dependent on one person. Together, these three elements form an overview that a board can consult without first having to ask each entity individually. What such a matrix involves, and how it can differ per entity without losing coherence, is set out at what a control matrix is in a group with multiple entities.
The Compliance Check maps out which obligations apply to the group, who owns them, which evidence fits them and which control demonstrates that the process is in place. This is not a replacement for an audit, nor a guarantee that an auditor will be satisfied with what is presented. It is a structure that ensures a board knows where the evidence should be, before anyone asks about it.
The tool is under construction. Anyone who wants to use it once it becomes available can sign up for the waiting list.
Recording and maintaining evidence is itself also work: gathering documents, checking versions, keeping overviews up to date across multiple entities. Part of that work is repeatable enough to be supported with AI. FTE TO AI's work scan calculates per task which part of the work qualifies for this, so that it becomes clear where time is spent searching for evidence, and where it is spent actually assessing it.
Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.