Compliance Operations
Multi-Entity Compliance Reporting Guide
Entity-aware reporting for local duties, group oversight, controls, evidence, reconciliation, exceptions, certifications, and drill-down.
Direct answer
Multi-entity compliance reporting should preserve each legal entity, jurisdiction, obligation, control, owner, evidence set, cutoff, and certification before producing a group view. Build a governed entity hierarchy, distinguish local duties from group oversight, define shared and local taxonomies, normalize time and currency only where relevant, record eliminations and materiality, reconcile every aggregate to source submissions, and retain lineage, access, exceptions, certifications, and drill-down. A group report does not by itself satisfy a local filing, control, or certification duty.
Definitions
Legal-entity hierarchy
A versioned relationship model showing legal entities, parents, subsidiaries, branches, establishments, groups, and reporting units, with entity type, jurisdiction, effective dates, and source evidence.
Local compliance obligation
A requirement that applies to a named entity, establishment, activity, license, jurisdiction, contract, regulator, or local process and must be assessed and evidenced at that applicable scope.
Group oversight obligation
A parent, holding-company, shared-service, board, risk, or enterprise requirement to monitor, aggregate, escalate, or report information across entities; it does not replace an entity-level duty.
Control owner
The accountable person or function responsible for defining, operating, reviewing, evidencing, and remediating a named control for a stated population and period.
Report owner
The accountable person or function responsible for the completeness, interpretation, approval, distribution, access, and change history of a particular compliance report.
Local definition
An entity- or jurisdiction-specific meaning, threshold, population, status, deadline, evidence rule, or calculation that cannot be safely replaced by a group definition.
Group definition
A controlled common meaning used for cross-entity oversight, with a mapping to local definitions, known differences, applicability rules, and a documented treatment for unmapped values.
Reporting cutoff
The declared date, time, time zone, data-refresh state, and late-submission rule that determine which records, events, evidence, and corrections belong in a report.
Consolidation
An organization-designed process that combines eligible entity-level observations under declared scope, mappings, period, currency, aggregation, duplicate, elimination, adjustment, and unknown-value rules.
Elimination
A documented removal or adjustment applied during aggregation to prevent a defined overlap, double count, intercompany item, duplicate submission, or other explicitly identified distortion.
Materiality
A documented threshold or qualitative trigger used to prioritize review, escalation, correction, certification, disclosure, or reporting treatment for a defined population and decision.
Compliance certification
An attributable statement by an authorized owner about the stated scope, period, criteria, evidence, exceptions, and limitations of a report or control result; it is not proof that every legal duty is satisfied.
Data lineage
The trace from a reported value or status through source record, entity and jurisdiction mapping, transformation, rule version, aggregation, elimination, adjustment, reviewer, and report output.
Reconciliation
A documented comparison between expected and reported populations, values, statuses, or evidence, with a named tolerance, explanation for each material variance, and resolution or accepted exception.
Field definitions
Entity, jurisdiction, and ownership
- entity_id
- Stable identifier for the legal entity or explicitly identified branch, establishment, or reporting unit used by the report.
- Type: Versioned reference
- Requiredness: Always required
- Validation: Resolve to the approved entity master, retain entity type and effective hierarchy, and never reuse an identifier after an entity is retired.
- Owner: Entity data steward
- jurisdiction_id
- Controlled identifier for the jurisdiction, regulator, or authority relevant to an obligation, control, report, or deadline.
- Type: Controlled reference
- Requiredness: Required when applicability or deadline is jurisdictional
- Validation: Store the trigger, source, effective period, local deadline, and applicability decision; distinguish legal jurisdiction from operating location.
- Owner: Compliance owner
- ownership_role
- The named obligation owner, control owner, evidence owner, report owner, local approver, group reviewer, or escalation owner for a record.
- Type: Role-to-person or function reference
- Requiredness: Required for in-scope duties and reports
- Validation: Store role type, accountable principal, delegate, entity scope, effective dates, and approval authority separately.
- Owner: Compliance governance owner
- local_group_scope
- The scope classification and mapping indicating whether a record is local, group, both, or not mapped to a group view.
- Type: Controlled value plus mapping reference
- Requiredness: Always required for consolidated reporting
- Validation: Do not allow a group mapping to erase local applicability, evidence, deadline, owner, certification, or exception state.
- Owner: Reporting taxonomy owner
Obligation, control, and report identity
- obligation_id
- Stable identifier for the applicable obligation, source requirement, license condition, policy duty, contract duty, or reporting requirement.
- Type: Versioned obligation reference
- Requiredness: Required for obligation reporting
- Validation: Link source, applicability, jurisdiction, entity scope, local definition, group mapping, owner, deadline, evidence rule, and version.
- Owner: Obligation register owner
- control_id
- Stable identifier for the control or control activity used to address an obligation or report criterion.
- Type: Versioned control reference
- Requiredness: Required for control reporting
- Validation: Link objective, owner, population, frequency, evidence, test method, exception rule, and related obligations without claiming that one control satisfies every local duty.
- Owner: Control owner
- report_id
- Stable identifier for a local submission, group oversight report, certification package, or restatement.
- Type: Versioned report reference
- Requiredness: Always required for report outputs
- Validation: Store report scope, period, cutoff, owner, audience, source population, version, status, certification state, and parent or derived report relationships.
- Owner: Report owner
- taxonomy_mapping
- The versioned mapping among local obligation, control, entity, business, chart-of-accounts, or reporting taxonomy values and the group reporting values.
- Type: Mapping set with version
- Requiredness: Required when values are aggregated or crosswalked
- Validation: Support one-to-many, many-to-one, unmapped, not-applicable, and deprecated states, with an owner and effective date.
- Owner: Taxonomy steward
Period, amount, and aggregation
- reporting_cutoff
- The period end, cutoff timestamp, time zone, source refresh state, and late-data rule used to determine report inclusion.
- Type: Structured timestamp and period object
- Requiredness: Always required
- Validation: Retain source-local time, canonical time where needed, extraction timestamp, business-calendar rule, correction window, and restatement status.
- Owner: Reporting operations owner
- currency_context
- The source amount, source currency, rate source and date, rate type, target currency, precision, rounding rule, and converted amount for amount-based measures.
- Type: Amount object with units
- Requiredness: Required only for currency-denominated measures
- Validation: Keep counts and statuses out of currency conversion; do not compare local thresholds without preserving the local currency and rule basis.
- Owner: Finance or reporting data steward
- aggregation_treatment
- The rule describing inclusion, grouping, duplication, elimination, adjustment, unknown, and restatement treatment for a value in a group report.
- Type: Versioned method reference
- Requiredness: Required for consolidated outputs
- Validation: Retain pre-aggregation value, elimination or adjustment record, post-aggregation result, reviewer, and drill-down path.
- Owner: Group reporting owner
- materiality_basis
- The quantitative amount, count, percentage, population, or qualitative trigger used to classify the report result or exception.
- Type: Threshold object with unit
- Requiredness: Required for materiality-driven reporting
- Validation: Name the decision, threshold, unit, period, entity or group scope, qualitative triggers, approver, and treatment of unknown data.
- Owner: Compliance risk owner
Evidence, certification, and traceability
- evidence_reference
- A protected reference to the source document, record, test, submission, approval, log, or other evidence supporting a report result.
- Type: Evidence link with classification
- Requiredness: Required for reported control and certification claims
- Validation: Store source owner, period, hash or immutable reference where available, access classification, retention rule, and availability status.
- Owner: Evidence owner
- certification_state
- The state of a report or control certification, including not required, not started, prepared, certified, rejected, withdrawn, restated, or expired.
- Type: Controlled value with decision record
- Requiredness: Required when a certification or attestation is expected
- Validation: Record certifier, authority, scope, period, criteria, evidence, exceptions, decision timestamp, expiry, and withdrawal or restatement reason.
- Owner: Certifying owner
- lineage_id
- Stable trace identifier linking a group value to source entity records, mappings, transformations, eliminations, adjustments, reviewers, and output.
- Type: Trace reference
- Requiredness: Required for material consolidated values
- Validation: A reviewer must be able to move from output to source and back without relying on an undocumented spreadsheet or manual memory.
- Owner: Data lineage steward
- reconciliation_status
- The result of comparing expected and received populations, values, statuses, or evidence at a stated tolerance.
- Type: Controlled value with variance record
- Requiredness: Required before a consolidated report is finalized
- Validation: Store numerator and denominator where applicable, variance amount or count with units, tolerance, cause, owner, resolution, and accepted exception.
- Owner: Reconciliation owner
Controlled vocabulary guidance
- Entity scope
- Examples: Legal entity, branch, establishment, reporting unit, subgroup, group, shared service, external party, or not applicable.
- Governance: Keep legal-entity type distinct from reporting convenience. Version hierarchy relationships and retain source evidence and effective dates.
- Local versus group scope
- Examples: Local duty, local report, group oversight, shared control, group mapping, unmapped, not applicable, and local-only.
- Governance: A group value may summarize local data but cannot replace a local duty, local owner, local evidence set, filing, or certification.
- Applicability
- Examples: Applicable, not applicable, pending review, out of scope, expired, superseded, unknown, or disputed.
- Governance: Require trigger, source, reviewer, effective period, and rationale. Unknown and pending review must remain visible in group reports.
- Compliance status
- Examples: Not started, in progress, met, failed, overdue, waived, accepted risk, not applicable, unknown, submitted, rejected, or restated.
- Governance: Define status transitions, evidence requirements, owner, period, and whether a status is local, group-derived, or manually overridden.
- Certification state
- Examples: Not required, prepared, pending local certification, certified, rejected, withdrawn, expired, or restated.
- Governance: Keep preparation separate from certification. Require scope, period, criteria, certifier authority, evidence, exceptions, and decision timestamp.
- Materiality band
- Examples: Critical, high, medium, low, informational, or not assessed.
- Governance: Use an organization-designed rule with quantitative units and qualitative triggers. Do not allow an aggregate threshold to hide a critical local event.
- Reconciliation result
- Examples: Matched, matched within tolerance, variance explained, variance open, late data, duplicate, missing, adjusted, or not testable.
- Governance: Record the population, comparison basis, tolerance and unit, source, reviewer, cause, action, and effect on certification or publication.
- Lineage state
- Examples: Fully traced, partially traced, source unavailable, transformed, manually adjusted, eliminated, restated, or lineage exception.
- Governance: Material values should not be presented as fully reliable when the source, mapping, transformation, or adjustment cannot be traced.
Practical workflow
State the reporting decisions and boundaries
Write the decisions the report must support, such as local filing readiness, control oversight, board escalation, regulator response, audit support, or remediation funding. Name the legal entities, branches or establishments, jurisdictions, obligation types, controls, periods, systems, reports, and users in scope. Separate group oversight from any local filing, attestation, certification, or submission that must be completed by an applicable entity or authorized local owner.
Build the legal-entity hierarchy
Create a versioned hierarchy with stable entity ID, legal name, entity type, parent and child relationships, ownership or control relationship where relevant, branch or establishment markers, jurisdiction, registration references, lifecycle status, effective dates, and source evidence. Do not model a branch as a separate legal entity unless the applicable source and reporting rule support that treatment. Preserve historical hierarchy versions so prior reports remain reproducible.
Map jurisdictions and applicability
For each obligation, control, report, and entity, record jurisdiction, regulator or authority, activity or license trigger, applicability decision, effective period, local deadline, language or form requirement, and responsible reviewer. Treat jurisdiction as more than an address: a requirement may follow incorporation, establishment, employees, data, customers, products, regulated activity, contract, or filing status. Route uncertain applicability to qualified compliance or legal review and retain the decision.
Separate local duties from group oversight
Maintain distinct records for local obligations, local reports, local evidence, local owners, and local certifications. Link them to group obligations or oversight reports only through an explicit mapping. A group dashboard may show status, trends, and exceptions, but it does not automatically file, certify, or evidence a local duty. Display local non-applicability, late data, unknown status, and unsubmitted items rather than allowing a green group aggregate to hide them.
Define obligation, control, and report ownership
Assign obligation owner, control owner, evidence owner, report owner, local approver, group reviewer, system steward, and escalation owner separately where responsibilities differ. Record accountable and responsible roles, substitutes, approval authority, service boundaries, effective dates, conflicts, and handoff conditions. Never infer ownership from the entity hierarchy alone; a shared service may operate a control while a local entity remains accountable for its duty.
Create local and group definition mappings
Maintain a definition crosswalk for obligation type, control status, evidence state, breach, exception, overdue, certification, materiality, and completion. Give each local value a source, owner, version, applicability, and mapping to a group value where a valid mapping exists. Allow one-to-many, many-to-one, unmapped, and not-applicable states, and expose semantic differences instead of forcing a false common definition.
Design the reporting taxonomy
Define the dimensions needed for the decision: entity, entity type, parent or group, jurisdiction, regulator, obligation, control, report, owner, business activity, period, status, materiality, exception, evidence, and certification. If a report uses financial data, map the relevant chart-of-accounts or financial taxonomy version separately from the compliance obligation taxonomy. Do not use an account code as proof of obligation applicability or control performance.
Specify standard fields and source systems
Use stable fields for entity_id, jurisdiction_id, obligation_id, control_id, report_id, owner_id, period, cutoff, status, evidence reference, exception reference, certification state, currency, time zone, taxonomy version, lineage ID, and reconciliation status. Name the system of record and source priority for each field. Record missing, conflicting, stale, manually overridden, and not-applicable values rather than silently defaulting them.
Set period, clock, and data-cutoff rules
Declare reporting period start and end, local legal deadline, group reporting deadline, source extraction time, cutoff time zone, daylight-saving treatment where relevant, business-calendar rule, late-arriving data policy, correction window, and restatement process. Preserve source-local timestamps and a canonical timestamp when events cross jurisdictions. A submission received after a group cutoff remains late even if it is included in a later restatement.
Handle currency only where the measure needs it
Keep compliance counts, statuses, evidence states, and certification states in their native semantic units. For amount-based measures, store source currency, amount, precision, exchange-rate source, rate date, rate type, target reporting currency, conversion result, and rounding rule. State whether conversion is spot, period average, closing, contractual, or organization-designed. Never imply that currency conversion makes local monetary thresholds interchangeable.
Collect local submissions and evidence
Collect the entity-level report or control result with source records, evidence links, reviewer, owner decision, period, cutoff, applicability, exceptions, certification state, and late or unknown reason. Preserve the local report as an authoritative submission for its declared duty. Store group-facing extracts separately when transformations, mappings, redactions, or aggregation change the representation.
Validate completeness and lineage
Check expected entities, obligations, controls, reports, evidence items, owners, and certifications against received records. For every material group value, retain source entity, source report, source timestamp, mapping version, transformation rule, aggregation step, elimination or adjustment, reviewer, and output location. Reject or flag orphaned records, duplicate IDs, expired definitions, broken links, missing owners, and values that cannot be traced to an approved source.
Apply materiality and exception rules
Define quantitative and qualitative materiality by report, obligation, entity, jurisdiction, control, and decision. Consider missed legal deadlines, unauthorized access, wrong applicability, missing certification, repeated control failure, unreliable lineage, affected population, duration, regulator or client impact, and aggregation risk. Record exception ID, issue, affected scope, reason, compensating control, owner, approver, due date, expiry or review date, and treatment in local and group reports.
Reconcile entity reports before aggregation
Compare expected entity populations to submitted populations, then compare source totals, statuses, evidence counts, and certification states to the entity report. Explain missing, duplicate, late, amended, out-of-period, and manually adjusted records. Use an explicit tolerance with units. Do not roll an unreconciled submission into a clean group total without labeling the variance and its effect on interpretation.
Aggregate with controlled eliminations
Apply the approved hierarchy, definition mappings, period rules, currency treatment, duplicate policy, and aggregation method. Eliminate only named overlaps, intercompany items, duplicate records, or approved adjustments with source, rationale, owner, approval, amount or count, and effective period. Preserve pre-elimination entity values, the elimination journal or record, post-elimination result, and drill-down. An elimination must never remove a local duty or its evidence from the local report.
Review and certify at the right scope
Route each local report and certification to the authorized entity or local owner named by the applicable rule. Route group oversight reports to the group reviewer with the local submission population, exceptions, reconciliations, and limitations attached. Require the certifier to state scope, period, criteria, evidence reviewed, unresolved exceptions, late or unknown records, restatements, and reliance on group or shared-service data. A group certification cannot silently substitute for a required local certification.
Control access, publication, and drill-down
Limit local, group, auditor, regulator, shared-service, and administrator access by entity, jurisdiction, report, evidence sensitivity, role, and action. Separate view, edit, certify, approve, export, administer, and audit permissions. Apply least privilege, recertification, joiner-mover-leaver controls, and logging. Make every group value drill down to permitted entity reports, source evidence, adjustments, and exceptions without exposing restricted local information to an unauthorized user.
Close, restate, and improve the cycle
Publish the report version, data cutoff, received and expected populations, reconciliation results, material exceptions, certifications, access review, and distribution list. Define late-data, correction, restatement, and archival rules. Track unresolved defects, repeated mapping failures, owner gaps, and local-versus-group disagreements. Reapprove taxonomy, formulas, hierarchy, materiality, and access rules after material regulatory, organizational, system, or reporting changes.
Comparison
| Reporting question | Controlled multi-entity method | Unsafe shortcut |
|---|---|---|
| Does the organization satisfy a local duty? | Review the applicable entity, jurisdiction, deadline, local owner, local evidence, and required local submission or certification. | Treat a complete group dashboard or parent certification as proof that every subsidiary or establishment satisfied its local duty. |
| What is the reporting population? | Start from the versioned entity and obligation hierarchy, then reconcile expected and received records before aggregation. | Start from whatever entities happened to submit data and call the resulting denominator the group population. |
| What does a shared definition mean? | Map local definitions to a group vocabulary with version, applicability, differences, unmapped values, and not-applicable treatment. | Rename incompatible local statuses so they fit a group dropdown without preserving their original meaning. |
| Who is accountable? | Separate obligation owner, control owner, evidence owner, report owner, local certifier, group reviewer, and escalation owner. | Assume the parent, shared service, system administrator, or person who exports the report owns every local outcome. |
| How are amounts and periods compared? | Retain source currency, rate basis, time zone, cutoff, precision, period rule, and converted values only for measures that require them. | Convert every value to one currency or time zone and assume the local threshold, deadline, or reporting period has the same meaning. |
| How is a group total made trustworthy? | Reconcile source populations, map definitions, document eliminations and adjustments, preserve lineage, and provide permitted drill-down. | Publish a single total after manual spreadsheet edits with no source trace, tolerance, variance explanation, or elimination record. |
| How are exceptions handled? | Record scope, cause, materiality, owner, approver, compensating control, due date, expiry, local treatment, and group treatment. | Exclude late, missing, unknown, or failed local results so the group report looks complete. |
| What does certification mean? | The authorized certifier confirms the stated scope, period, criteria, evidence, limitations, and exceptions for that report. | Use a certification badge or approval click without defining scope, authority, evidence, open exceptions, or local-versus-group responsibility. |
Limitations and exceptions
- This is an organization-designed reporting and control method, not legal advice, a filing instruction, an audit opinion, a certification standard, or a guarantee that a report satisfies a regulator, client, court, insurer, or professional body.
- A group report, parent control, or shared-service process does not automatically satisfy an entity-level or jurisdiction-specific obligation. Applicability, local evidence, local deadlines, authorized signers, and local submissions require the treatment specified by the applicable source and qualified reviewers.
- Legal-entity hierarchies, ownership relationships, registrations, branches, establishments, tax attributes, and reporting scopes can change. Use authoritative local records and effective-dated governance instead of treating an organization chart or identifier as permanent legal truth.
- A common taxonomy can improve comparison while still losing local meaning. Preserve source definitions, unmapped values, not-applicable decisions, language, thresholds, and rule versions when they affect a local decision.
- Currency conversion, time-zone normalization, chart-of-accounts mappings, eliminations, and aggregation adjustments can create a false appearance of precision. Keep source units, rate or cutoff basis, rounding, transformation, and unresolved variance visible.
- Certification is limited to the stated scope, period, criteria, evidence, authority, and assumptions. It does not prove that all records were found, all obligations were met, all controls operated continuously, or all legal judgments were correct.
- Access controls and drill-down can conflict with confidentiality, privacy, privilege, client restrictions, data residency, or regulator access requirements. Design authorized views and redactions with appropriate legal, security, privacy, records, and compliance owners.
- Lineage and reconciliation can show that a number was derived consistently without proving that the source was complete or legally correct. Preserve source limitations, manual adjustments, late data, exceptions, and restatements in the report record.
Primary sources
Methodology
Use this organization-designed method as a versioned reporting contract. Start with the entity hierarchy and an applicability register; for each local obligation, record entity, jurisdiction, source, local definition, owner, deadline, evidence, certification need, and group mapping. Define group terms separately and preserve a local-to-group crosswalk with unmapped and not-applicable states. Set period, cutoff timestamp, source refresh, time zone, correction window, and late-data rules before collecting submissions. Report entity coverage (%) = entities with an applicable obligation mapped to a local owner and evidence rule / entities expected in scope x 100; the unit is percent of expected legal entities. Local report completeness (%) = local reports accepted by the local cutoff / local reports due x 100; the unit is percent of local reports due, and group reports do not enter this denominator. Control evidence coverage (%) = applicable controls with current evidence / applicable controls due for evidence x 100. Certification coverage (%) = reports certified by an authorized owner at the required scope / reports requiring certification x 100. For amount-based measures, post-elimination group amount [reporting currency] = sum of eligible entity amounts converted under the declared rate basis [reporting currency] - approved eliminations [reporting currency] + approved consolidation adjustments [reporting currency]. Reconciliation difference [reporting currency] = published group amount - computed post-elimination group amount. For counts, use the analogous unit of report, obligation, control, or entity and never mix counts with currency. Define materiality per decision using amount, count, percentage, affected entities, duration, deadline, qualitative impact, and aggregation risk; show both raw variance and rate. Preserve pre-aggregation values, elimination records, mappings, lineage IDs, manual adjustments, exceptions, certifier decisions, access restrictions, and drill-down. A group oversight result may be complete while one local duty is late or uncertified, so expose the local state instead of averaging it away. Review the model as of August 13, 2026 against current source pages, local law, regulator instructions, contracts, policies, and system behavior; qualified legal, tax, accounting, privacy, security, records, and compliance owners decide applicability and final certification.
Bring local compliance reporting into one governed view
Reach out and learn more about our offerings and how CaseDocker can help you
Built for legal operations teams
Share your use case and we will connect you with the right team for product guidance, pricing, and rollout planning.
Clear next steps
Expect a response from our team with the most relevant next step for your inquiry.
Get in Touch
Get in Touch
FAQs
Related CaseDocker capabilities
Compliance management
Coordinate obligations, controls, evidence, owners, exceptions, certifications, remediation, reporting, and review cycles across entity populations.
ExploreLegal playbooks
Turn local submission, reconciliation, escalation, certification, and restatement rules into repeatable governed workflows.
ExploreCase management
Keep entity-specific issues, evidence requests, control exceptions, decisions, and follow-up work linked to accountable owners.
ExploreCompliance management information
Review the compliance-management operating context for obligations, controls, evidence, ownership, reporting, and remediation.
ExploreTurn this guide into an operating plan
Share your current legal workflow and CaseDocker can map the right modules, integrations, controls, and rollout sequence.
