CABIER Global Assurance · Group and subsidiary assurance
Group and subsidiary assurance
One obligation model for a whole group. Group policies are written once and inherited by every subsidiary and branch, local rules are added only where a local supervisor sets them, and the group position shows the weakest entity rather than hiding it in an average.
Illustrative group structure. Entities, coverage figures and findings are synthetic.
Group structure
Choose an entity to see what it inherits from the group and what it adds locally.
Inherited from the group
- Group operational resilience policy
- Group third-party risk standard
- Group AI use and model risk standard
- Group information security baseline
Added locally
Supervisor: National competent authority
- DORA ICT risk and register of information
- EU AI Act deployer duties
- MiCA, where crypto-asset services are provided
Group position
The consolidated figure and the weakest entity, shown side by side.
Consolidated control coverage
86%
Weakest entity
79%
Canadian branch, Canada
How the rollup works
Write once, inherit everywhere
A group policy is held once. Each subsidiary and branch inherits it and adds only the local obligations its own supervisor sets.
Local overlays stay local
A rule that applies only in one country never leaks into another entity's obligation set, and the reason each obligation applies is recorded.
The group position is not an average
The group view shows the weakest entity alongside the consolidated figure, so a strong parent cannot hide a weak branch.
Accountability follows the legal entity
Every finding names the entity, the local accountable executive and the group owner. Both have to act before it closes.
The local obligations come from the same packs.
See the regulatory packs