A board that is asked to demonstrate that it is in control cannot make do with the statement that policy exists. There must be a structure in place that shows, per obligation, who is responsible, what evidence exists, and which control ensures that evidence remains correct. That structure is called a control matrix. It is not a reporting format or a template that one fills in for an auditor; it is the way an organization can explain to itself what happens and why that is sufficient.
A control matrix consists of more than a list of obligations. For each obligation, at least three things must be established: who the owner is, what the evidence is that shows the obligation has been met, and which control safeguards that evidence remains current and correct. Without an owner, an obligation becomes no one's task. Without evidence, an obligation is an intention. Without control, evidence is a snapshot that ages as soon as the organization changes. Who owns an obligation at a group with multiple entities is therefore not a detail that gets filled in later, but the first thing that must be established before a matrix means anything.
What counts as evidence differs per obligation and per country in which the obligation applies. A European rule that appears unambiguous in its base text is often implemented differently in national transposition: a different form of evidence, a different frequency, a different body that must establish it. A matrix that leaves no room for that looks complete and is not. For a precise elaboration of what counts as evidence in a specific case, what counts as evidence for an obligation at a group with multiple entities is the starting point, not this page.
In a group with multiple entities, multiple countries or multiple departments, evidence rarely originates in one place. Policy sits with legal affairs, execution with a local site, reporting with finance, and approval with a board that does not see the whole picture daily. A control matrix that does not map this out conceals that fragmentation is the actual risk. Not the absence of policy, but the inability to locate the evidence that policy has also been applied. Where exactly this goes wrong and why it occurs more often with group structures than with a single entity is set out at where evidence becomes scattered at a group with multiple entities.
A matrix does not resolve that fragmentation by gathering everything in one place — that is often not feasible and also not necessary. What the matrix does do is indicate where each piece of evidence resides and who can point to it the moment it is requested. That is a different goal than centralization: it is about findability, not collection.
A common error in a control matrix is that the evidence consists of the policy document itself. A policy document shows that an organization has decided something, not that it happens. An auditor or supervisor who probes further wants to know how the policy translates into a concrete, repeatable action: an approval that has been recorded, a check that has been carried out, a deviation that has been flagged and followed up. How that distinction works in practice is explained at how you demonstrate that policy is also practice at a group with multiple entities. A control matrix that does not make this distinction creates false assurance: complete on paper, indefensible in practice.
The value of a control matrix does not depend on how complete it is at the moment it is drawn up, but on how well it holds up at the moment someone from outside asks about it. That means evidence must not only exist, but also be retained in a way that an auditor without prior knowledge of the organization can follow. A matrix that refers to evidence that no one can locate anymore is, in practice, an empty matrix. What is needed in terms of retention and structure is set out at how you retain evidence so that an auditor finds it at a group with multiple entities. At a group with multiple entities this is a separate point of attention, because evidence that is stored locally is rarely automatically visible to those who account for it at group level. More on the structure of the matrix itself at such a structure is set out at what a control matrix is at a group with multiple entities.
A control matrix makes visible who must collect which evidence, keep it current, and be able to show it. That is work that recurs: the same check, the same collection, the same verification, time and again, often across multiple entities and countries at once. Once that repetition becomes visible, the question arises which part of that is a task someone must redo every time, and which part is systematic enough to be organized differently. The work scan of FTE TO AI calculates per task which part of that work can be taken over by AI, based on the tasks as they have already been described in a control matrix.
Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.