
Compliance libraries are built on the assumption that an organisation holds a framework once. One ISO 27001 certificate, one Cyber Essentials assessment, one toolkit record with one submission date behind it. Plenty of organisations pass that point without noticing, and the second copy arrives without anyone deciding to create it.
Four routes get you there.
You acquire a company and it comes with its own certificate, its own scope and its own renewal date. A customer contract requires certification scoped to the service you deliver them, separate from your corporate scope. You open in a second market and the entity there certifies locally. Or a company you bought has its own NHS toolkit record, with years of published history attached to it.
Each of those routes is a reasonable outcome of doing business. The problem starts when the two copies are run as separate programmes, with separate policies, dates and owners.
There are two situations here and they look identical on a spreadsheet.
The first is one organisation holding one framework across several scopes. That is the multi-site case, it has a defined route, and a single certificate can name several legal entities. The rules are set out in IAF MD 1:2023 and covered in certifying a group.
The second is two organisations that genuinely operate separate management systems. Different leadership, different processes, no central function with authority over both. Two certificates is the honest answer, at least until the integration work is done.
Most groups are somewhere in between and have never said which. The test that matters is whether one person can require a corrective action in both places and have it happen, whatever the org chart shows.
Drift is the expensive part, and it arrives in a predictable order. The second audit fee is the smaller number on the page.
The policy goes first. One entity updates its access control policy, the other keeps the version it certified against, and eighteen months later two documents with the same title say different things. An auditor finding both will ask which one applies.
Review dates follow. The same control gets reviewed in March in one place and in October in the other, so any question about the current position has two answers.
Ownership is the one that hurts. Somebody leaves, their controls get reassigned inside their own entity, and nobody notices the equivalent control in the other entity now has no owner at all.
By the time a buyer asks a question that spans both, answering it means two people comparing two spreadsheets. That is the cost, and it is paid every time somebody asks.
Where a certificate covers several sites, IAF MD 1:2023 requires the certification documents to name all of them with their addresses, and where one site's activities only cover part of the organisation's scope, the certificate carries that site's sub-scope. A buyer checking whether your certificate covers the service they are buying is reading that wording, and they are reading it without you in the room.
Two copies of a framework means two scope statements. It is worth having read both, in full, the way a procurement analyst reads them. The common finding is that neither covers the thing the customer actually assumed was covered, because both were scoped around the entity rather than around the service.
Cyber Essentials makes this concrete. A certificate covers a defined scope and runs for twelve months, and IASME runs those twelve months from the date of submission rather than from the expiry of the certificate it replaces, so renewing early moves your expiry date earlier. Two scopes means two certificates, two submission dates and two clocks that do not line up. Both certificates are listed with IASME, so a buyer comparing them does not need to ask you for either.
Duplicating the framework leaves the obligations underneath it exactly where they were, one set per company.
Article 30(1) of the UK GDPR requires each controller to maintain a record of processing activities under its responsibility. Two entities are two controllers, and each keeps its own record whatever the certification picture looks like. Article 24(1) requires each of them to implement appropriate technical and organisational measures and adds that "those measures shall be reviewed and updated where necessary".
So the second copy of the framework is not the only second thing you now hold. Groups that discover this during a funding round tend to discover it late.
One library of controls and evidence. Several framework instances pointing at it.
The access review happens once and is recorded once. It counts towards the ISO 27001 scope in one entity and the ISO 27001 scope in the other, and towards Cyber Essentials in both, because a control satisfies a requirement wherever that requirement appears. Where the two scopes genuinely differ, that shows up in what each instance requires, instead of in two teams keeping parallel folders.
Try it against the starters and leavers process. Somebody updates it today, and a well-run programme records that once and tells everyone who needs to know. A duplicated one records it twice and tells them eventually.
List every framework instance you hold, with the entity, the scope wording, the renewal or submission date and the named owner. Most organisations doing this for the first time find one instance nobody owns and one scope statement that no longer describes what the entity does.
Then decide, deliberately, which instances are consolidating and which are staying separate. A framework held twice on purpose is a manageable position. Held twice by accident, it is where the next audit finding comes from.
The Naq platform automates GDPR, Cyber Essentials, ISO 27001, ISO 9001 and the NHS DSPT, with controls mapped across frameworks so one piece of evidence satisfies requirements in several standards at once.
The same framework can be set up more than once, so a parent and a subsidiary, or a corporate scope and a contract-specific scope, each have their own instance while the controls and evidence underneath stay in one place. Update the process once and every control referencing it points at the new version, with the owner confirming it still does the job it was attached for. Policies and risks carry a named owner and a named approver, and field edits are written to the activity stream with the previous and the new value, so the two instances can be compared on the record instead of by memory.
Some teams want named people alongside the platform. Naq's in-house Clinical Safety Officers and virtual Data Protection Officers work next to it.
Requirement detail sits on the ISO 27001 and Cyber Essentials framework pages, and compliance across several entities covers the wider case. If several of your certificates renew in the same quarter, several certificates, several dates covers the calendar problem that follows.
If you are holding the same framework in two places and want to see what one library underneath both would look like, book a fifteen-minute demo.