Accountable for risk you do not operate
A holding board answers for the portfolio and runs none of it. One subsidiary reports to SAMA, another to the CST, another carries the NCA ECC, and a fourth answers to nobody in particular. Nothing consolidates, because the obligations are not the same shape.
Is this you, or are you a multi-entity group?
The two structures look similar on an org chart and are different problems. Worth thirty seconds before reading further.
A portfolio of different businesses
Subsidiaries operate in different sectors, answer to different regulators, and are held at different ownership levels. The holding entity often has no operations of its own.
The problem is accountability without operational control, across obligations that do not compare to one another.
One organisation, several entities
Entities share a sector, a regulator, and broadly the same obligations — branches, regional offices, or subsidiaries doing the same thing in different places.
The problem is isolation and consolidation of work that is genuinely comparable. That page is here.
Many organisations are both — a group of similar operating entities sitting under a holding company that also owns unrelated businesses. If that is you, read both; the platform handles the structure either way, but the questions your board asks are different.
Why portfolio compliance does not consolidate
From the compliance programmes we build and run in Saudi Arabia: the difficulty is not collecting subsidiary reports. It is that a maturity level under the SAMA CSF, an implementation status under the NCA ECC and a compliance level under the CST framework are not the same measurement, and averaging them produces a number that means nothing.
So the holding company does one of two things. It asks for narrative updates, which are unverifiable and arrive in different formats from each subsidiary. Or it imposes a single scheme on everyone, which forces each subsidiary to translate its regulatory position into a group language — introducing error between what the regulator will see and what the board sees.
Neither answers the question a holding board actually asks, which is narrower than it sounds: where is our exposure concentrated, and who is already dealing with it?
| A subsidiary in | Answers to | Assessed as |
|---|---|---|
| Banking or finance | SAMA | Maturity level against the CSF domains |
| Telecoms or IT | CST | Compliance level assigned by the regulator |
| Government-adjacent work | NCA | Implementation status per control |
| Health | Sector authority | Its own requirements, on its own schedule |
| Anything handling personal data | SDAIA | PDPL obligations, regardless of sector |
| An unregulated sector | Your board, and its customers | Whatever the group standard requires |
Note the last row. The subsidiary nobody regulates is frequently the one carrying the most unmanaged risk, precisely because no external party forces the question.
What you can actually require
A holding company's authority over a subsidiary is not uniform, and pretending otherwise produces a group policy that half the portfolio quietly ignores.
Group standards apply directly, the board appoints management, and compliance can be operated centrally if you choose. The practical constraint is capability in the subsidiary, not authority over it.
You can set direction, but minority shareholders have rights and interests that shape how far a group mandate reaches. Group standards usually arrive through the board rather than as an instruction.
Governance follows the shareholders' agreement. What you can require depends on what was negotiated, which means the compliance conversation starts with the agreement rather than with the framework.
You may have board representation and information rights and no ability to mandate anything. Visibility is the realistic objective here, and it is worth pursuing — a minority position still carries reputational and financial exposure.
The governance question is always the same one: what do our rights in this entity actually let us require, and what can we only request? Recording that answer per subsidiary is unglamorous and it prevents the most common failure — a group policy issued to entities that were never obliged to follow it.
Holding company structures in Govrly
Each subsidiary runs its own programme against its own regulator. The holding company sees across them without flattening the differences.
Subsidiaries never see each other
Each entity works in its own space — its controls, its evidence, its findings, its risks. A competitor you also own does not see your portfolio neighbour's open findings, which matters more in a diversified holding than in a single group.
Each against its own regulator
One subsidiary on the SAMA CSF, another on the CST framework, another on the NCA ECC — each scored the way its regulator scores it, not converted into a group scheme that its regulator would not recognise.
Applied where you can require it
A holding company standard defined once as a custom framework and applied to the entities your governance rights actually reach — recorded per subsidiary rather than assumed portfolio-wide.
A view across, without flattening
Coverage, open findings, overdue items and accepted risks visible across the portfolio, each expressed in its own framework's terms. Comparable where comparison is meaningful, and separate where it is not.
Where the same weakness repeats
The same control failing in four subsidiaries is a portfolio issue, not four local ones. That pattern is invisible in narrative reporting and obvious when the underlying records are structured.
The question actually asked
Where exposure concentrates and who owns the remediation — rather than a percentage that averaged three incompatible scoring schemes into a number nobody can defend.
Acquisitions and divestments
The part of portfolio compliance nobody writes about, and the part that reliably goes wrong.
You are buying a compliance position
Along with the business. Open findings, accepted risks, unremediated audit points and whatever the target has not told its regulator all transfer with the shares. Asking for the register during diligence is cheaper than discovering it afterwards.
The target's obligations become yours
Its regulator does not pause for integration. A newly acquired entity carries its own deadlines from completion, and the group's first contact with that regulator is usually a report it was not ready to file.
Onboard without flattening
A new subsidiary joins the portfolio with its own framework and its own scoring, visible to the holding company immediately rather than after a migration project that takes two quarters.
Carving out the records
When a subsidiary is sold, its controls, evidence and findings leave with it. A structure where everything was merged into a single group programme makes that separation painful and sometimes impossible to do cleanly.
Personal data moves too
Acquisition and divestment both change who controls personal data under the PDPL, which is a question to answer before completion rather than in the following quarter.
Evidence survives the transaction
An entity that changes hands still needs to show its regulator an unbroken record. Evidence held per entity survives the transaction; evidence assembled into group reports does not.
The structural point runs through all six: an architecture that isolates entities makes acquisition and divestment routine, while one that consolidates everything makes both expensive. That is worth knowing before the portfolio changes rather than during.
Setting it up
The order matters. Most holding companies start at step four and work backwards painfully.
- Map the portfolio as it actually isEvery entity, its sector, its regulator, and your ownership level. This document usually does not exist in one place, and building it is the first useful output.
- Record what your rights let you requirePer subsidiary. Mandate, or request. Getting this wrong is how a group policy ends up issued to entities that were never obliged to follow it.
- Let each subsidiary keep its own frameworkIts regulator assesses it their way. Converting that into a group scheme introduces error between what the regulator sees and what the board sees — and the regulator's view is the one that carries consequences.
- Define the group standard, narrowlyWhat the holding company requires everywhere, beyond what regulators require locally. Keep it short. A long group standard is ignored; a short one is followed.
- Decide what the board actually needsUsually concentration of exposure and ownership of remediation, not a compliance percentage. Design the reporting around the question rather than around what is easy to produce.
- Set the escalation thresholdWhat a subsidiary must tell the holding company, and when. Without this, the group learns about material issues from the regulator or the press.
- Include new acquisitions from completionNot after integration. The target's regulatory deadlines start at completion, and the gap between completion and onboarding is where the avoidable failures sit.
- Keep entity records separableBecause some of these businesses will be sold. Architecture that assumes permanence makes divestment expensive.
Each subsidiary runs its own programme against its own regulator in its own isolated space, while the holding company sees coverage, open findings and concentration across the portfolio — with a group standard applied only to the entities your governance rights actually reach.
See it in a demo →Holding companies — FAQs
How is this different from a multi-entity group?
A multi-entity group is one organisation with several entities carrying broadly the same obligations — the problem is isolation and consolidation of comparable work. A holding company is a portfolio of different businesses answering to different regulators at different ownership levels, and the problem is accountability without operational control. Many organisations are both.
Can we see one compliance score across the portfolio?
You can, and we would advise against it. A maturity level under the SAMA CSF, an implementation status under the NCA ECC and a compliance level under the CST framework are not the same measurement, and averaging them produces a number that cannot be defended to a board or a regulator. What works is portfolio visibility of coverage, open findings and concentration, each expressed in its own framework's terms.
Can subsidiaries see each other's compliance data?
No. Each entity works in its own isolated space with its own controls, evidence, findings and risks. This matters more in a diversified holding than in a single group, because portfolio companies are sometimes competitors, sometimes counterparties, and occasionally both.
What about subsidiaries we do not control?
Your authority follows the shareholders' agreement and applicable law rather than a fixed ownership percentage. For a minority position, visibility is usually the realistic objective — and worth pursuing, because a stake you cannot direct still carries reputational and financial exposure. Recording per subsidiary what you can require and what you can only request prevents issuing a group mandate to entities that were never obliged to follow it.
Can we impose a group standard across the portfolio?
Where your governance rights reach, yes — defined once as a custom framework and applied to those entities. It sits alongside each subsidiary's regulatory obligations rather than replacing them, which is the important distinction: your group standard does not discharge what SAMA or the NCA requires of that entity.
What happens when we acquire a company?
It joins with its own framework and its own scoring, visible immediately rather than after a migration project. The point worth planning for is that the target's regulatory deadlines start at completion — its regulator does not pause for integration, and the gap between completion and onboarding is where avoidable failures sit.
And when we sell one?
Its controls, evidence and findings leave with it, because they were held against that entity rather than merged into a group programme. An entity changing hands still needs to show its regulator an unbroken record, and a structure that consolidated everything makes that separation painful and sometimes impossible to do cleanly.
Does the holding company need its own compliance programme?
Usually yes, and it is often overlooked because the holding entity has no operations. It holds personal data about employees and shareholders, makes decisions that carry group-wide consequences, and in a listed structure carries governance obligations of its own. A holding company with no programme of its own is a gap that stands out precisely because everything below it is covered.
Which subsidiary carries the most unmanaged risk?
In our experience, frequently the one nobody regulates. Regulated subsidiaries have an external party forcing the question on a schedule. An unregulated one has only your group standard and its own management, and if the group standard is vague the answer is nobody. It is worth checking that assumption directly.
How much visibility should the holding company have?
Enough to answer where exposure concentrates and who owns remediation, which is narrower than full operational detail. Holding companies that pull every control status into the centre create reporting burden without improving decisions, and tend to find subsidiaries managing the report rather than the risk.
See the portfolio without flattening it
Each subsidiary against its own regulator, and one view across for the board.