Blog
Compliance
ISO 9001
September 7, 2026
Approx min read

Group compliance controls: when a control operates at the centre and not in the subsidiary

Group compliance controls have a failure mode that external certification does not catch quickly. A control written once at the centre and adopted on paper by every company in the group can be running in exactly one of them, and the certificate stays valid throughout, because the external audit programme was never built to look everywhere.

That is arithmetic before it is negligence. IAF MD 1:2023, Issue 3 lets a certification body audit a sample of the sites in a group rather than all of them. Filling that gap is the central function's job, and MD 1 spells out how. Setting one certificate up across separate legal entities is covered in certifying a group across several legal entities.

The control that only runs at head office

Access reviews make the point. The group's access review procedure is one approved document, referenced by the control that satisfies the access requirements in every framework instance the group runs. At head office the review happens and the records go back years. In two of the subsidiaries it has never happened once, because nobody there was told the control applied to them, and the control record at the centre reads the same either way.

MD 1 names this failure in a preamble almost nobody reads. The Section 7 opening requires a certification body's procedures to "establish the way the Certification Body satisfies itself that the single management system governs the processes/activities at all the sites, and is actually applied to all the sites". Applied is doing the work here, and closing the distance between a signed procedure and an applied one falls to the group.

A surveillance year looks at two entities out of nine

Take a group with nine entities on one certificate. Under clause 6.1.3.3 the annual surveillance sample is two of them, so seven are not seen by an external auditor that year.

The centre has no such quiet. Clause 6.1.3.4 requires the central function to be audited at initial certification, at every recertification, and at least once a calendar year as part of surveillance. The part of the group under external scrutiny every year is the part whose job is watching everything else.

The precision matters here. Clause 6.1.2.1 requires the sample to ensure "all processes covered by the scope of certification will be audited", so the guarantee is expressed over processes, and nothing in MD 1 promises that every site is visited across the life of a certificate. Groups outside the sampling route sit under clause 6.2.1, where every site is audited at initial certification and at recertification and 30% are covered in a surveillance calendar year, which narrows the gap without closing it.

For most of a certificate's life, the only thing looking at most of the entities is the group's own assurance. Surveillance audits and recertification covers what the external programme does across a cycle.

What the centre is obliged to be doing between audits

The note to clause 5.6 states the centre's job plainly: "The central function is where operational control and authority from the top management of the organization is exerted over every site." Every site includes the ones no sample reaches.

Clause 5.5 is eleven words.

"All sites shall be subject to the organization's internal audit programme."

It sets no frequency. Sitting inside a multi-site internal audit programme and being audited this year are different states, and the group picks the interval for each entity. That choice is the group's to defend, so the reasoning behind it belongs in the audit programme itself.

Data collection is the second obligation. Clause 5.6 requires the central function to be "responsible for ensuring that data is collected and analyzed from all sites ...", and to demonstrate its authority to initiate change across a list of areas. Item (v) is the one that bites here: "internal audit planning and evaluation of the results".

The duty comes with a power, in clause 3.3.1. "This means that the central function has rights to require that the sites implement corrective actions when needed in any site. Where applicable this should be set out in the formal agreement between the central function and the sites." Where nobody at the centre holds a written right to require a subsidiary to fix something, MD 1 has named the instrument.

One entity's finding becomes the group's investigation

Clause 7.7.1 is worth reading whole, because each sentence does separate work:

"When nonconformities, as defined in ISO/IEC 17021-1, are found at any individual site, either through the organization's internal auditing or from auditing by the Certification Body, investigation shall take place to determine whether the other sites may be affected. Therefore, the Certification Body shall require the organization to review the nonconformities to determine whether or not they indicate an overall system deficiency applicable to other sites. If they are found to do so, corrective action shall be performed and verified both at the central function and at the individual affected sites. If they are found not to do so, the organization shall be able to demonstrate to the Certification Body the justification for limiting its follow-up corrective action."

The trigger includes your own internal audit. Finding a problem yourself opens the same investigation an auditor's finding would.

Remediation lands on the centre too, because a failure spreading across several entities arrived through the system it runs. And a group deciding a finding was a one-off has to justify limiting the follow-up, on the record, at the time.

Getting that judgement wrong has a price. Clause 7.7.2 has the certification body increase its sampling frequency, its sample size, or both, until it is satisfied that control has been re-established. Audit days are billed, and one entity's lapse buys them for the whole group.

The sequence ends at clause 7.8.4. Where any one site does not maintain the necessary provisions, the certification documentation is withdrawn in its entirety. The structural rules underneath that are worth a read before anyone signs off a scope.

Your internal audit results are an input to site selection

The sample is not drawn blind. Clause 6.1.2.4 lists what the certification body weighs when picking sites, and the first two items are yours:

"The site selection shall consider, among others, the following aspects:
• results of internal audits of sites, management reviews and/or previous certification audits;
• records of complaints and other relevant aspects of corrective and preventive action;"

Clause 6.1.3.5 requires the sample size or frequency to be increased where the certification body's risk analysis of the certified processes indicates special circumstances, and it names internal audit results and corrective action records again among the factors.

A group that records what its internal audits found has given the auditor something to steer by, and some of that steering will point where the group already knows it is weak.

Acquisitions move the sample too. Under clause 6.1.3.7 the certification body reviews the sampling foreseen in the audit programme when a group adds an acquired site to the certification boundary. Clause 6.1.4.1 then requires it to determine the required activities before that site joins, and this "shall include consideration of whether or not to audit the new site(s)". A company acquired last year can be on the certificate without an external auditor having been inside it. That is how a control gets adopted on paper and never started. Bringing an acquired company in is a separate exercise, and group compliance controls across several entities and products covers that end of it.

Three things to be able to answer for every group compliance control

For each control in the library, the centre should be able to answer three questions without a call.

Which entities the control operates in. Who owns it in each of them. When it was last evidenced there, and who confirmed that.

A policy document answers none of the three, because it describes what should happen everywhere. The answers live in records tied to a specific control in a specific entity, which is what makes compliance controls across subsidiaries checkable rather than assumed.

Running one control library across several entities with Naq

Naq holds frameworks, requirements, controls and evidence as one chain. A group can run more than one instance of the same framework, each with its own scope and schedule, over a single control library, with each control mapped to the requirements it satisfies.

Every control carries a named owner, and an owner is a person who works somewhere, which is what ties a control to a company. Control status is set from the evidence, and the owner can override it. Evidence is an uploaded file or a link to an internal Naq record, tied to the requirements it proves, and replacing that file or versioning that document forces the owner to re-confirm before it counts again.

The activity stream on each record is chronological, with field edits showing the previous and the new value, and records are archived instead of deleted. The answer to when a control was last evidenced in a given entity, and who confirmed it, sits on that control record.

The ISO 27001 and ISO 9001 framework pages carry the requirement detail. If you are running group compliance controls across several companies and cannot say today which entities each one operates in, book a fifteen-minute demo.