Quick answer
Corporate groups should give each legal entity its own compliance workspace: separate integrations, controls, evidence, and user access, because that's how regulators and auditors see them. OptiTech supports multiple isolated workspaces under one organization, with shared policy baselines pushed down from the group and a rollup view for the group CISO. Isolation per entity, consistency from the center.
Why one shared workspace goes wrong
It's tempting to run the whole group in one workspace. The problems surface fast:
- Different scopes. The energy subsidiary is an essential entity under NIS2; the consulting arm isn't in scope at all. Mixing them makes both scopes wrong.
- Audit boundaries. A certification audit of one subsidiary shouldn't expose another subsidiary's incidents and evidence to the auditor.
- Access control. Local IT managers need full access to their entity and none to the others.
- Different regulators. A Finnish subsidiary answers to Finnish authorities with different incident-reporting flows than MSB in Sweden.
The structure that works
- One workspace per legal entity (or per clearly separable business unit), each with its own integrations and control status.
- Group baseline from the center. The parent defines the mandatory policy set and control baseline; entities inherit it and extend locally. Updates to the baseline propagate with review, not by email.
- Rollup reporting. The group dashboard shows compliance score and open findings per entity, which is exactly what the board asks for. See board reporting.
- Per-entity auditor access. Each entity grants its own read-only auditor portal scoped to itself.
Shared suppliers, once
Groups often share suppliers (the same payroll provider, the same cloud platform). Register shared suppliers at group level and reference them per entity, so one supplier assessment covers everyone while each entity's supplier register stays accurate. This mirrors how supplier questionnaires already work across company boundaries.

Get a personalized walkthrough of automated compliance for your team. No commitment required.