When your company grows into a group, compliance quietly multiplies. Each new subsidiary arrives with its own auditor, its own frameworks, and its own spreadsheet, and before long you're running several parallel programs that never talk to each other. The parent has no clear picture, and every entity reinvents work a sibling already finished last quarter.

Group compliance isn't single-entity compliance copied a few times. The hard part is deciding what's shared and what's local, keeping scopes straight when each entity chases a different framework, and rolling everything up into one view your board can actually read. This guide covers how to run one program across many entities with OptiTech, without flattening the differences that matter or drowning in duplicated effort.

Why group structures make compliance hard

A single company has one scope, one set of frameworks, and one owner. A group has none of those things cleanly. Shared services like IT, HR, and security usually sit at the parent level, but each subsidiary carries its own regulatory exposure. Your Swedish operating company might pursue ISO 27001 for enterprise deals. A financial subsidiary falls under DORA. An entity that handles more sensitive personal data draws closer GDPR scrutiny. NIS2 applies to some of your entities and not others, depending on sector and size.

So you can't just clone one program and stamp it on every subsidiary. You also can't run each entity in total isolation, because they share people, systems, and policies. The answer sits in the middle, and getting it right is what separates a group program that scales from one that collapses under its own copies.

Shared controls versus entity-specific controls

Start by sorting your controls into two buckets. Some are genuinely shared. Access management, employee background checks, the information security policy, and the vendor onboarding process are often set once by the parent and inherited by everyone. Others are local. A subsidiary's own list of processors, its office physical security, and its specific data processing activities belong to that entity alone.

Teams get this wrong in two directions. Copy every shared control into every entity, and you maintain the same evidence several times over, so it drifts out of sync the moment someone updates one copy. Force everything to be shared, and you lose the local detail an auditor asks about the moment they scope a single subsidiary.

OptiTech handles this with a shared control library. You define a control once at group level, attach its evidence once, and apply it to every entity in scope. When the evidence changes, you update it in one place and it refreshes everywhere it's used. Entity-specific controls live only on the entity that owns them. You stop maintaining copies and start maintaining one source of truth.

Different frameworks and scopes per entity

No two entities in a group need the same certificate. In OptiTech, each entity selects the frameworks it actually pursues, whether that's SOC 2 Type II, ISO 27001, GDPR, NIS2, or DORA. The scope stays specific to that entity, so an auditor reviewing your financial subsidiary sees exactly its controls and evidence, not the whole group's.

The payoff comes from overlap. A single access management control can satisfy a SOC 2 criterion, an ISO 27001 annex control, and a NIS2 requirement at the same time, across every entity that inherits it. You build the control once and it earns its keep many times over. Map that overlap deliberately, and a group with five frameworks doesn't cost five times the effort of one.

Central oversight with local ownership

The parent company needs to see everything. The subsidiary needs to own its part. Those two needs pull in opposite directions unless your roles are set up for it.

OptiTech gives you both through permissions scoped to entities. A group compliance lead sees every entity, tracks progress across the whole structure, and spots the subsidiary that's fallen behind before an auditor does. A local owner sees and edits only their entity, so they're accountable for their own controls, evidence, and deadlines without wading through everyone else's. Central oversight and local ownership stop being a tradeoff. The board gets its bird's eye view and each entity keeps its hands on the wheel.

Define shared controls before you scale

Sort your controls into shared and entity-specific before you add the second entity, not after the fifth. A clean split at the group level means every new subsidiary inherits your shared library on day one instead of copying stale controls from a sibling.

Consolidated reporting your board can read

A group leadership team doesn't want several separate compliance updates. They want one. Roll-up reporting in OptiTech consolidates the status of every entity into a single view, so you can answer the question the board actually asks: where does the group stand? You see overall progress, then drill into any entity when something needs attention.

The same structure serves your buyers. Each entity can publish its own trust center showing its frameworks, certifications, and data residency, so a customer buying from your financial subsidiary sees that entity's posture, not a vague group statement. All your data stays in the EU, in Stockholm and Frankfurt, which is the answer Nordic buyers and regulators want to hear regardless of which entity they're dealing with.

Getting started

You don't need to unify everything at once. A realistic first pass looks like this:

  1. Map your entities and their frameworks. Write down which subsidiary pursues which framework, and note where regulatory exposure differs.
  2. Build your shared control library at group level. Start with the controls that clearly belong to the parent, like access management and security policy.
  3. Assign a local owner to each entity. Give them scoped permissions so they own their controls without touching anyone else's.
  4. Turn on roll-up reporting and per-entity trust centers. Give leadership one view and give each entity its own public proof.

Group compliance rewards the companies that build the shared foundation once and let each entity extend it. Define what's shared, own what's local, and both your board and your auditors get a clear answer without anyone repeating a sibling's work.

Ready to run one compliance program across your whole group? Book a demo and see how OptiTech connects a shared control library, per-entity scope, and roll-up reporting.