A group with multiple entities rarely has a single place where evidence of compliance comes together. One subsidiary keeps policy in a local quality system, another in a shared drive, a third in the head of one employee who has drawn up the same report for years. As long as nobody asks about it, that works. The moment an auditor, a regulator or the board itself wants to see what an obligation consists of and how it is being complied with, it turns out that the evidence is fragmented, outdated or transferable only by word of mouth.
A policy document is not evidence of compliance. It is an intention. Evidence is what demonstrates that the intention was also carried out: a signed procedure, a log of checks performed, an email in which a deviation was reported and followed up, a report that reconciles with the underlying data. In a group with multiple entities, the question is not only what counts as evidence, but also where it should be kept and who is responsible for it. Without an answer to that, chance determines who can find the evidence, and that is no basis on which a board can declare that the organisation is in control.
Evidence becomes scattered along the lines by which a group itself is divided: by entity, by country, by function. A parent company can set a group-wide policy, while each subsidiary carries it out and documents it in its own way, or does not document it at all because nobody locally knows it is mandatory. On top of that comes the national layer. The same European obligation can be implemented differently per country, with its own deadlines, its own competent authorities or its own additional requirements. What counts as sufficient evidence in one country does not count as such in another. Anyone who only looks at the group-wide rule misses that which national add-ons apply in Germany is a different question than which national add-ons apply in France, and that the evidence therefore also needs to be built up and retained differently per country.
Evidence also becomes scattered functionally. Legal keeps contracts, finance keeps reports, HR keeps training records, and none of the three has the full overview. In a merger, acquisition or reorganisation, that problem grows: evidence that sat with one entity does not automatically move along when responsibility shifts.
The question of who must be able to find evidence is linked to the question of who owns an obligation. In a group with multiple entities, that owner is not automatically the person closest to the subject; it can be the parent company, a local director, or a function designated group-wide. Without a recorded answer to who owns an obligation in a group with multiple entities, a situation arises in which everyone assumes someone else manages the evidence, until the moment it is requested and nobody can produce it.
An auditor requesting evidence does not take the group's internal organisational structure into account. They ask for the evidence tied to the obligation, not from the department where it happens to be stored. That means the way evidence is retained must be independent of where it happened to originate. How that works in practice, and which choices belong to it, is described in how you retain evidence so that an auditor can find it in a group with multiple entities.
A second form of fragmentation arises when policy and practice drift apart without anyone noticing. A group-wide policy document can be fully applied in one entity and exist only on paper in another. That difference only becomes visible if there is a systematic way to establish that what was agreed was also carried out. Demonstrating that is a separate step, distinct from setting the policy itself, and is explained in how you demonstrate that policy is also practice in a group with multiple entities.
To prevent every entity from developing its own version of evidence and responsibility, an overview is often used in which obligations, owners and evidence are brought together. In practice, that overview is called a control matrix, and its structure determines whether a group can later demonstrate what was done or can only recount what was intended. The principles of such a matrix, and why it takes a different form in a group with multiple entities than in a single company, are described at what a control matrix is in a group with multiple entities.
The Compliance Check brings these elements together: which obligations apply, who owns them, what counts as evidence and which control belongs to it. Not as a replacement for the regulation itself, but as the layer that makes visible whether a board can demonstrate that it is in control, even when evidence is scattered across multiple entities and countries.
Bringing together scattered evidence is largely recognisable, repeatable work: finding out where a document is located, checking whether it is up to date, linking it to the right obligation and owner. That is precisely the type of task for which the work scan from FTE TO AI calculates which part can be taken over by AI, so that it becomes clear how much of the collecting and organising of evidence remains manual work and how much of it can be delivered in an automated way.
Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.