CABIER Global Assurance · Group and subsidiary assurance

    Group and subsidiary assurance

    One obligation model for a whole group. Group policies are written once and inherited by every subsidiary and branch, local rules are added only where a local supervisor sets them, and the group position shows the weakest entity rather than hiding it in an average.

    Illustrative group structure. Entities, coverage figures and findings are synthetic.

    Group structure

    Choose an entity to see what it inherits from the group and what it adds locally.

    Inherited from the group

    • Group operational resilience policy
    • Group third-party risk standard
    • Group AI use and model risk standard
    • Group information security baseline

    Added locally

    Supervisor: National competent authority

    • DORA ICT risk and register of information
    • EU AI Act deployer duties
    • MiCA, where crypto-asset services are provided

    Group position

    The consolidated figure and the weakest entity, shown side by side.

    Consolidated control coverage

    86%

    Weakest entity

    79%

    Canadian branch, Canada

    How the rollup works

    Write once, inherit everywhere

    A group policy is held once. Each subsidiary and branch inherits it and adds only the local obligations its own supervisor sets.

    Local overlays stay local

    A rule that applies only in one country never leaks into another entity's obligation set, and the reason each obligation applies is recorded.

    The group position is not an average

    The group view shows the weakest entity alongside the consolidated figure, so a strong parent cannot hide a weak branch.

    Accountability follows the legal entity

    Every finding names the entity, the local accountable executive and the group owner. Both have to act before it closes.

    The local obligations come from the same packs.

    See the regulatory packs