For a single company, the question of who is responsible for what is usually quickly answered. For a group with multiple entities — parent company, subsidiaries, perhaps a joint venture or an entity in another country — that self-evidence disappears. An obligation may be established at group level, but execution lies with a subsidiary that was never explicitly tasked with it. Or the other way around: every entity assumes another entity is handling it.
An organizational chart shows who reports to whom. It doesn't show who is responsible for supplying data, who has to translate policy into local practice, and who can demonstrate that this has been done. Those three can lie with three different people or departments, even within a single entity. With multiple entities, that problem multiplies: the same obligation may lie with the CFO in country A and with an operational manager in country B, without anyone at group level having recorded that difference.
On top of that, some obligations don't apply uniformly. What a group must demonstrate based on a European rule can turn out differently per country as soon as national legislation tightens or interprets that rule differently. Anyone who wants to know which national add-ons apply in Germany or which national add-ons apply in France will see that ownership is therefore not only an organizational question, but also a legal one: the obligation itself can differ per entity.
Ownership is only demonstrable once it has been recorded, not when it is assumed. That means: a name or role linked to a specific obligation, a description of what that person or department is expected to deliver, and a trail showing that this has actually happened. Without that trail, the question "who owns this" cannot be answered with a document during an audit, only with an assumption that no one can verify.
The question of what actually counts as evidence — a policy document, an approval, a dataset, a report — is worked out on the page describing what counts as evidence for an obligation. For a group with multiple entities, an additional requirement applies on top of that: the evidence must be traceable to the entity where the obligation actually applies, not only to the group as a whole.
At a single company, evidence is usually kept in a limited number of places. At a group, it becomes dispersed across separate administrations, separate IT systems, local advisors and teams that don't communicate with each other. A subsidiary in another country may keep evidence in a language and system that the parent company never consults. Anyone who has to demonstrate at group level that an obligation has been met therefore needs to know not only that the evidence exists, but also exactly where it is located and who has access to it.
This fragmentation is one of the most underestimated risks for groups with multiple entities, and is further explored on the page about where evidence becomes dispersed. Without a central overview of where which evidence is located, there is a real chance that an obligation has been assigned on paper but cannot be substantiated in practice at the moment it is needed.
A group can establish a clear policy at central level and still not see it reflected in the practice of every entity. A subsidiary may not know the policy, may interpret it incorrectly, or may follow a different approach for local reasons. The difference between an established policy and an applied policy is precisely where ownership becomes visible: who is responsible for flagging that gap, and who must be able to demonstrate that the gap doesn't exist or has been closed.
How that demonstrability works within a group structure can be found on the page explaining how you demonstrate that policy is also practice at a group with multiple entities. The answer depends heavily on how the group is organized and which obligations apply at which level.
One way to bring ownership, evidence and control together is a matrix in which, per obligation, it is recorded who owns it, what evidence is expected, and which control applies to it. This is not a legal instrument and no guarantee that everything is covered — it is a structure that makes visible where responsibility lies and where a gap still exists. What such a matrix entails for a group with multiple entities is described on the page about what a control matrix is for a group with multiple entities.
Assigning ownership and gathering evidence is not just an organizational question, it is also work: someone has to collect data, check documents, keep track of versions and prepare reports, over and over again, per entity. Anyone who wants insight into which part of those recurring tasks can be taken over by AI and which part remains human work can have this calculated with the workscan from FTE TO AI.
Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.