A group with multiple entities faces a problem that a single company does not: the same obligation can apply in several places at once, with a slightly different interpretation per country, and the evidence that demonstrates compliance often originates locally. A control matrix is the way to make that manageable: a structure that shows, per obligation, which entity is affected, who the owner is, what evidence is required, and which control demonstrates that the process is actually running. Not a report, but a layer of demonstrability on top of the underlying regulation.
A list of obligations works for a single entity. For a group with a parent company, subsidiaries and possibly joint ventures in different countries, a list no longer works, because the same European rule turns out differently per country. What falls below a certain threshold in one country may receive a different qualification in another, with a different reporting obligation or a different supervisory regime. A matrix captures that combination: obligation × entity × country, with each cell showing who owns it and what counts as evidence. Without that structure, there is a risk that an obligation is considered handled at group level, while a subsidiary has a local requirement that was not taken into account.
A cell in the matrix that only says "compliant" is not evidence. Demonstrability requires four elements per obligation: the owner who can be held accountable, the evidence that shows the obligation has been met, the control that describes how that process works in a repeatable way, and the date on which that was last established. What exactly counts as evidence differs per type of obligation; an approved document, a registered agreement or a demonstrably followed process can all qualify, depending on what the rule requires. An overview of what counts as evidence for an obligation helps to clarify those four elements before the matrix is filled in.
In a group with multiple entities, evidence rarely originates in one place. The reporting is drawn up at group level, but the underlying data comes from local systems, approval runs through a local director, and the file an auditor would want to see sometimes sits with a subsidiary that is not involved in group reporting on a daily basis. That fragmentation is not an organisational flaw, it is a consequence of how groups work: decisions are made locally, accountability is requested centrally. A matrix that does not explicitly track that misses the point. An explanation of where evidence becomes scattered shows which type of fragmentation occurs most often and why that is not automatically a problem, as long as the evidence remains findable.
A control matrix is only useful if someone who does not work in it daily — a new CFO, an external accountant, a supervisory authority — can retrieve the evidence within a reasonable time. That requires a fixed location, consistent naming and a fixed reference from the matrix to the underlying document, not a collection of emails and loose files scattered across different server locations per country. An explanation of how to store evidence so an auditor can find it discusses what is needed for that, without prescribing a specific software system. What ownership precisely entails — who may sign off on which obligation and who is held accountable when something goes wrong — relates to the question who owns an obligation, and that question becomes more complex for a group with multiple entities than for a single company, because ownership at group level and at entity level can diverge.
The common thread for a group with multiple entities is that a European rule rarely turns out the same everywhere. A subsidiary in Germany may face a different threshold, a different supervisory body or a different deadline than a subsidiary in France, while both fall under the same European directive. That does not mean the matrix has to be rebuilt per country, but it does mean that each cell must explicitly state which national interpretation applies. An overview of which national requirements apply in Germany and of which national requirements apply in France shows where those differences typically lie, so that a matrix does not silently assume a single regime for the entire group.
A matrix that records ownership, evidence and control per entity also reveals, in one and the same movement, how much work actually goes into maintaining it: who gathers the evidence, who checks it, who updates the matrix when regulation changes. That is a question that goes beyond compliance alone. The work scan from FTE TO AI calculates, per task, what portion of that work can be taken over by AI, so that it becomes clear where people remain necessary for judgment and ownership, and where gathering and organising evidence is a repeatable process that can be automated.
Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.