Group-Wide AML/CFT Programmes, Foreign Branches and Subsidiaries
A banking group can move risk across legal entities as easily as it moves payments. Group-wide AML/CFT programmes connect local controls, customer and transaction information, management oversight and independent assurance. A branch is part of its parent legal entity; a subsidiary is a separate entity. Both can face host-country requirements, so the group cannot treat a shared logo or IT platform as proof of legal uniformity.
FATF Recommendation 18 covers group-wide programmes and foreign branches and majority-owned subsidiaries. Its Interpretive Note addresses consistent measures, information sharing and confidentiality safeguards. Where host-country minimum requirements are less demanding than home-country requirements, the group applies the higher standard to the extent host law permits. Where host law prevents proper implementation, additional risk management and notification to the home supervisor are contemplated by the standard; the precise duties come from national implementation.
A group policy should establish a minimum control framework and a maintained local addendum. The addendum identifies binding differences in customer due diligence (CDD), reporting, retention, privacy, sanctions and outsourcing. It must explain conflicts and approved solutions, not simply say that local law prevails and leave the central control blind.
Group AML information sharing is purposeful. Share information needed to assess connected customers, investigate unusual activity and manage risk; limit recipients and record the legal gateway. FATF's framework does not itself grant permission to transfer a SAR across any border. Local reporting confidentiality, privacy and localisation restrictions need separate analysis.
Understand the group before designing the controls
The relevant perimeter extends beyond an organisation chart. A parent can own deposit-taking subsidiaries, payment institutions, investment businesses and shared-service companies. One subsidiary may outsource customer operations to another group company. A foreign branch can book business on behalf of its parent while using host-country processes. A shared-service company may hold information without itself being the entity that owes a reporting duty. Identify ownership, regulated activities, establishments, booking arrangements and service dependencies. Group membership explains a commercial connection; it does not establish identical duties or unrestricted information access.
The distinction between branch and subsidiary has practical consequences. A branch is part of its legal entity, but its location can create host requirements, local supervisory relationships and restrictions relevant to the activity. A subsidiary has its own legal identity and governance, even when wholly owned. The group can require a common control framework while local management remains responsible under applicable law. A customer using two entities can have separate contractual relationships, records and reporting decisions. A group case should connect those facts without pretending that the entities have become one regulated person.
Ownership and control also matter for minority investments and joint ventures. FATF's foreign-entity baseline refers to branches and majority-owned subsidiaries. A minority investment should not automatically be classified as fully covered by that specific standard, nor ignored as irrelevant to group risk. Determine contractual influence, board representation, information rights, service relationships and applicable national requirements. A group may adopt additional controls as policy where it has suitable authority. The record should distinguish that deliberate policy choice from a claim that every investee is subject to the same statutory group programme duty.
A common standard with a meaningful local addendum
The common standard states the outcome the group expects: appropriate customer understanding, relevant risk assessment, coverage of transactions, investigation, reporting, controlled information sharing, training and assurance. Local addenda identify how the outcome is achieved under each entity's framework. They should cover material differences in scope, triggers, deadlines, documentation, retention, restrictions and supervisory expectations. An addendum that merely names the local regulator contributes little. It should identify where local obligations alter procedures or system behaviour and who maintains the interpretation when law or business changes.
The baseline should distinguish legal requirements from policy overlays. A group may require additional approval for certain customers, more frequent review or a common evidence standard beyond local minimums. Staff need to know which rule they are applying and how exceptions are governed. A stricter internal policy cannot authorise conduct prohibited by host law. Conversely, a host minimum that is less demanding does not automatically establish that the group can abandon its home-country framework. Resolve the actual interaction, including legal impediments and additional measures, rather than issuing a slogan that the strictest rule always wins.
Differences should be represented at the point of decision. If two entities use a common onboarding application but different reporting regimes, the legal entity must drive the relevant workflow. If local retention periods differ, the archive needs record-class and entity-specific triggers. If a common customer-risk method is supplemented by local factors, preserve both the source facts and the resulting local decision. The group can compare outcomes, but should not overwrite local classification merely to produce one global label. Harmonisation is useful when it preserves the meaning of each control.
Connected risk and separate legal decisions
A customer network can move activity between booking centres. A company may borrow at one subsidiary, hold deposits at another and use a foreign branch for trade payments. Each centre may see a plausible fragment while the combined pattern raises questions. Group information arrangements should support understanding that network through reliable identity and relationship links. They should also preserve provenance and uncertainty. Two similar company names are not proof of identity; a common director is not proof that two companies are the same customer. Mistaken linkage can spread an incorrect suspicion or restriction across the group.
A central investigator may coordinate the facts, but local reporting officers apply the relevant reporting duties. One entity's report does not automatically discharge another entity's obligation. One entity's decision not to report does not automatically control another's decision when its facts, services or law differ. Preserve the local decision owner, trigger, rule version and filing route. The central record can identify the related work through an authorised link or appropriately scoped status. Protected report content and existence require their own access analysis; coordination should not become uncontrolled replication.
Relationship decisions also remain specific. An authorised restriction at one entity may have no automatic legal effect at another, although it can prompt a risk review. A binding sanctions obligation may apply across some parts of the group and differently elsewhere depending on the relevant law and nexus. A discretionary group exit policy can impose a broader commercial response where lawful, but should be labelled as such. Distinguish the reason for each action so staff do not assume that a group risk alert itself creates authority to freeze funds.
Lawful sharing is a control design problem
Information needed for AML/CFT purposes can include identity, ownership, source of funds, transaction history, unusual patterns and the circumstances of concern. Determine what can be shared, with whom, for which purpose and with what safeguards. SARs, law-enforcement material, privilege and personal data can have different restrictions. A general group policy or customer consent does not necessarily overcome a specific statutory prohibition. Legal analysis should identify the relevant gateway and any conditions, not simply approve the system as a whole. Access should be tied to the authorised role and purpose.
The US example illustrates why categories matter. FinCEN's September 2025 cross-border guidance distinguishes underlying information from SARs and information revealing their existence, and addresses the applicable limits on sharing. It should not be converted into a universal permission for every affiliate or location. A bank designing a global case platform needs a jurisdiction-specific interpretation of that framework and of other local laws. An investigation summary can still reveal protected report existence if it includes filing references or equivalent indicators. Renaming a file does not change its legal character. FinCEN cross-border information sharing and SAR confidentiality.
If a restriction prevents necessary group oversight, record the precise gap and consider lawful alternatives. These can include local analysis, controlled access, limited factual summaries or aggregate assurance, depending on the actual framework. The group must assess whether the alternatives provide enough information to manage the exposure. A vague statement that local law prevents sharing should not end the analysis. Equally, central management should not pressure local staff to bypass a restriction. Escalation, additional risk measures and supervisory engagement follow the applicable requirements and the materiality of the impediment.
Accountability across central and local operations
Central services can provide consistent technology, specialist skills and scale. Local entities still need sufficient understanding to challenge the service, identify missed populations and manage their own decisions. A subsidiary whose monitoring is performed centrally should know what activity enters the service, what rules apply, how urgent cases are handled and how failures are escalated. A service-level agreement based only on uptime is incomplete. Include coverage, data quality, decision timeliness, evidence access, resilience and change notification where those outcomes matter to the entity's programme.
Group senior management needs a view that retains local severity. A consolidated green dashboard can conceal an entity with missing source feeds or unavailable reporting staff. Show material exposures by entity, control and population; identify local departures, legal impediments and overdue remediation. The group should distinguish a centrally resolved defect from one still present in a local configuration. Independent assurance should test the interfaces between group and local responsibilities, because those are frequent places for ownership gaps. Shared technology can improve control consistency, but it does not prove equivalent coverage.
The design objective is a group able to understand connected exposure while respecting the legal and operational identity of each part. Local autonomy should not leave group management blind to material risk, and group standardisation should not erase local obligations. Effective programmes maintain both views. The following sections develop the entity map, information-sharing decisions, implementation tests and a worked cross-border case showing how a group can coordinate concern without collapsing its separate responsibilities.
Home and host control mapping
Build a legal-entity inventory with ownership, licences, supervisors, products, reporting officers and data locations. Map obligations per entity and record which group control implements each one. A subsidiary may use the same monitoring engine as its parent but report to a different FIU, apply different reporting deadlines and retain records under a different schedule.
Link customers through reliable identifiers and confidence levels. A shared name is an investigative lead rather than a proven identity match. Keep the source entity's customer identifier, date, provenance and permitted purpose so a central investigator can request context without altering the local record silently. Group risk assessments should include services provided between entities and exposure to customers booking in multiple centres.
When a host restriction prevents a group data transfer, legal and compliance should determine what can be shared: underlying transaction facts, a risk assessment or a limited notification may have different rules from the SAR itself. Do not relabel a protected report as an ordinary attachment to evade restrictions. Document the gap, local controls, supervisory escalation and residual risk.
Local management remains responsible for implementing controls. Centralisation can support consistent rules and specialist expertise, but requires service-level ownership, local language competence, deadline tracking, resilience and clear escalation. A central queue that obscures a host FIU deadline is an unsafe operating model.
Map the service and the legal entity together
Begin with a service map showing where customers contract, where accounts are booked, where payments are executed and where records are held. Those locations can differ. A regional operations centre may process payments for three subsidiaries; a parent platform may store customer information for a foreign branch; a local entity may use a correspondent for settlement. The map should identify the regulated entity responsible for each service and the dependencies needed to operate its controls. Without that connection, group programme discussions can alternate between a commercial map and a technology map while overlooking the legal perimeter.
Add local governance and reporting contacts to the map. Identify responsible management, compliance and reporting officers, legal support, privacy ownership and supervisory relationships. Record deputies and service dependencies. A central investigator needs to know which local officer can assess a time-sensitive question, while a local officer needs a route to obtain group transaction context. A generic group mailbox can support intake but should not be the sole mechanism for urgent decisions. The operating model should survive absence of a named specialist and differences in business hours.
Review intercompany services explicitly. The provider may operate a data platform, perform case triage or maintain screening configuration. The recipient needs defined service outcomes and the ability to obtain evidence. Group ownership does not eliminate service risk. A central service can fail simultaneously across many entities, and a local change can bypass a central control. Document how each recipient establishes coverage, how the provider communicates incidents and how local management can challenge unsuitable design. Charges and service descriptions in an internal contract do not themselves demonstrate the AML/CFT outcome.
Make local addenda testable
A local addendum should translate material differences into decisions or configuration. For customer identification, specify the relevant evidence and verification requirements for the entity's services. For suspicious reporting, identify the threshold interpretation, responsible role, time calculation and submission route. For retention, identify record classes, periods, triggers and holds. For privacy and confidentiality, identify permitted transfers and access limitations. The text should be clear enough for business analysts and control owners to determine what changes compared with the group baseline. A list of national laws without operational interpretation is insufficient for implementation.
Maintain the interpretation through a controlled process. Legal or appropriately qualified compliance owners assess changes; programme owners identify affected procedures and systems; local management approves implementation within its authority. Preserve the source, version and date behind each conclusion. If a rule is proposed or has a future application date, label it accordingly and plan readiness without describing it as already operative. A global platform release can contain future configuration, but activation must follow the approved timing. The bank should be able to reconstruct which version applied to a historical decision.
The addendum also needs a conflict route. A requirement can be operationally different without being legally incompatible. Different report forms can be implemented locally within a shared workflow. A prohibition on transferring a category of information may create a genuine impediment requiring legal analysis and alternative measures. Distinguish inability to share a report from inability to share underlying customer facts. Distinguish a technology limitation from a legal restriction. A broad local-law exception that combines these issues can become a permanent blind spot that nobody is accountable for resolving.
Shared customer identity without false certainty
A group identity service should retain each source entity's identifiers and the evidence supporting links. Reliable tax, registration or legal identifiers can help, subject to permitted use and data quality. Names, addresses, dates and ownership relationships can provide additional context but often require interpretation. A customer moving between entities may receive a new local identifier without becoming a new person. Conversely, two businesses with similar names can be unrelated. The service should represent confidence, source, review status and effective dates rather than make every match look equally established.
Identity resolution can produce customer harm if unchecked. A person wrongly linked to another entity's concern may face repeated enquiries or restrictions. A company incorrectly merged with a sanctioned namesake may lose access to payments. Design a controlled process for challenging and correcting links. Preserve the original link and correction history so prior decisions remain understandable. Downstream systems need to know when a link is withdrawn; changing the central record while leaving copied relationship data unchanged can perpetuate the error. Correction should be an event with identified consumers, not an isolated database edit.
Ownership networks require their own semantics. A company can share a director with another company without common beneficial ownership. A trustee can have legal control without economic benefit. An alleged relationship from adverse media should remain distinct from verified ownership. Investigators need these differences to evaluate explanations and materiality. A graph that connects every relationship with an identical line can encourage unsupported conclusions. The group should share the provenance and uncertainty needed to interpret a link, not just a visually persuasive diagram.
Central monitoring with local interpretation
A shared engine should map source events to the correct entity and service. Missing entity codes can misroute alerts, apply inappropriate local rules or create reporting delays. Transaction attributes also differ across systems: a payment reference in one source can be an internal batch identifier in another. Establish canonical meanings with source mappings and retain original values. The control owner should understand which events are excluded, transformed or aggregated. A common software product does not eliminate semantic differences between local source platforms.
Scenario design can combine a group view with local conditions. A group rule may identify connected transfers across centres while local rules examine product-specific patterns. Prevent duplicate work where appropriate, but do not suppress necessary local assessment merely because a central case exists. The central coordinator should establish who is evaluating which facts and how new information reaches relevant local teams. If one entity sees activity outside another's information permission, a lawful factual or risk notification may be possible. The actual route requires the appropriate local analysis.
Operational queues should expose legal deadlines and local priority. Central staffing across time zones can improve responsiveness, but a queue sorted by one global age measure can overlook urgent local cases. Store the responsible entity, relevant trigger, legal clock and policy service targets separately. A case moved to a specialist queue should preserve those clocks. The local reporting officer should be able to see pending decisions for the entity and escalate capacity problems. Shared-service convenience should not determine whether a local obligation is fulfilled.
Sharing information with purpose and restraint
Before a transfer, identify the information class and authorised purpose. Ordinary customer information, investigation hypotheses, reporting records, law-enforcement requests and privileged advice can require different treatment. The same case can contain several classes. A user permitted to view customer transactions does not automatically need access to filing dates or legal advice. Permissions should apply to relevant objects and outputs, including exports and notifications, rather than only to the overall case. The operating model needs a practical way to obtain necessary facts without widening protected access indiscriminately.
Prepare information-sharing decisions in advance for recurring situations. Identify origin and destination entities, purpose, legal basis, data categories, recipients, security, retention and onward-sharing conditions. A pre-approved route can accelerate legitimate investigation, but only within its scope. A new destination, purpose or category may require reassessment. Preserve the decision record so a later review can understand why sharing was considered lawful. Customer consent can be relevant in some settings, but should not be assumed to cure a statutory report-confidentiality prohibition or other non-waivable constraint.
Minimisation should preserve usefulness. A summary stripped of all identifiers may not allow the recipient to identify the relevant relationship. An unrestricted document dump can expose unnecessary personal or protected information. Determine the minimum context that supports the authorised purpose, including stable identifiers where permitted and the reason for concern. If uncertainty or contradictory evidence is omitted, the recipient may overstate the risk. A carefully scoped factual summary can be more useful than a large file collection, but it must not conceal a report's existence through equivalent coded language where that disclosure is restricted.
Legal impediments and compensating arrangements
When host law prevents a proposed group control, the local entity should identify the precise provision and affected activity with appropriate legal input. The group should assess the risk created by the limitation and the lawful alternatives. Local review, secure access in the originating location, limited outputs or aggregate assurance can sometimes support oversight. Their adequacy depends on the question. An aggregate summary may support board monitoring but fail to support an urgent individual case. Record which purpose the alternative serves and what uncertainty remains.
Additional measures should be specific. An entity unable to transfer customer-level information might require stronger local investigation capability, independent local assurance or limits on particular group services. A data-localisation constraint might require a different deployment and access architecture. The group may need supervisory engagement under applicable requirements. None of these measures should be presented as automatically satisfying every law. The decision should identify local duties, group requirements, remaining exposure and authority for continuing the activity. Senior management needs a view of the limitation, rather than only assurance that legal has reviewed it.
Review impediments periodically and when circumstances change. A restriction may be narrower than initially understood, a legal route may become available or a proposed service may create new exposure. A temporary operational workaround should not become permanent through repeated extensions without challenge. Equally, changing technology does not automatically remove the underlying legal condition. The programme should retain the history of interpretations and decisions, including why a previous alternative was accepted. That record helps the group explain its conduct when a later examination asks what was known and feasible at the time.
Acquisitions and exits change the perimeter
An acquired subsidiary can bring different customer identifiers, product definitions, reporting records and privacy arrangements. Before migrating to group platforms, inventory populations and compare control coverage. Preserve inherited identifiers and the ability to reconstruct earlier decisions. Reconcile ownership and relationship data as well as account totals. A migration can balance financially while losing beneficial-owner history or case restrictions. The group should decide which controls must operate on Day 1, which remain local temporarily and what evidence supports each stage of integration.
An entity leaving the group creates the reverse problem. Determine which records the group can retain, which access should end, how ongoing cases and authority requests are handled and how shared-service dependencies are separated. A service agreement ending does not necessarily eliminate recordkeeping obligations or authority to preserve particular information. The transaction team, local management, legal and records owners should coordinate a controlled plan. Access revocation, evidence transfer and historical retention should be tested before the group identity or platform is dismantled.
Minority investments and changes in control deserve a documented perimeter reassessment. An increase in ownership may create new group-control expectations, while a reduction can limit available powers and information rights. A joint venture may remain commercially connected without being fully subject to the same group programme arrangement. The group should assess ongoing exposure through actual services and contractual rights. Applying a policy overlay can be sensible, but the decision should state its basis and limitations instead of treating ownership percentage as a complete operational model.
Oversight that preserves local accountability
Group management should see departures from the baseline, material incidents, unresolved legal impediments, overdue actions and assurance limitations by entity. Compare like-for-like measures carefully: local case definitions and reporting regimes can differ. A low filing volume is not inherently a good result, and a high volume does not establish effectiveness. Explain significant patterns through exposure, detection coverage, investigation quality and local obligations. Metrics should help management allocate attention and resources rather than rank entities without understanding their services.
Local management should receive group findings affecting its entity and have a route to challenge the proposed response. Central teams may not know a local product or legal constraint sufficiently to impose a suitable configuration. Conversely, local commercial preferences should not disguise an avoidable departure from the group baseline. The decision record should identify whose expertise supports the conclusion and who has authority to implement it. Independent assurance can then assess the actual arrangement rather than an idealised responsibility chart.
The programme works when the group can identify a connected exposure, lawfully obtain useful context, route decisions to the correct entities and demonstrate execution. Where it cannot, the limitation should be explicit and governed. The relationship between group and local functions is therefore a control in its own right. It requires defined information routes, dependable services, suitable expertise and evidence of decisions. A shared logo, platform or policy manual can support that arrangement but cannot establish it without operational proof.
Testing a group programme
Compare the local addendum with actual system settings and sampled cases. Test onboarding at two entities, a customer moving booking location, shared ownership information, an unusual cross-border payment and an unavailable data service. Verify that a central case does not suppress necessary local reporting decisions.
Board reporting should identify entities outside the baseline, legal impediments, overdue remediation, control coverage and assurance results. Consolidated averages can hide a small entity with serious defects. Record responsibility at both group and local level and use independent testing to challenge claims that a shared platform creates identical protection.
For acquisitions, inventory inherited customer records and feeds before migration. Preserve old identifiers and investigate excluded populations. A cutover reconciled only by account totals can lose beneficial owners, closed-account history or reporting restrictions.
Separate the entity, location and service attributes
The group architecture should represent legal entity, establishment, booking location, processing location and service provider as separate concepts. A transaction processed in a regional hub may belong to a subsidiary elsewhere. A customer address does not determine the entity providing the service. A group customer identifier can connect relationships without replacing the local account's entity identifier. Requirements should specify which attribute drives each decision and where that attribute originates. A field called country is particularly dangerous if different systems use it for nationality, residence, incorporation or processing location.
Consider a payment processed by a central hub for a foreign branch. The source should retain the booking entity and branch, relevant product and original event identifiers. Downstream controls may need additional geography such as originator residence, beneficiary bank location or goods destination. Those are separate facts. Tests should alter one attribute at a time and verify the intended rule response. If changing the processing hub's location changes the reporting entity without a justified rule, the implementation has confused operational geography with legal responsibility.
Maintain effective-dated entity relationships. An acquisition, merger or branch transfer can change ownership and services while historical events remain associated with the original arrangement. A replay should not silently apply the new corporate structure to earlier activity. The entity register should retain predecessor and successor relationships with approved dates and sources. Test events immediately before and after a transfer and include corrections received afterward. Historical reporting and retention questions may require the original entity context even when the current account belongs to a successor.
Tenant boundaries are more than a database setting
A shared case platform needs both collaboration and separation. Local users should receive appropriate access to their entity's work; central specialists may have broader permissions for defined purposes. Information classes can require narrower handling than ordinary tenant access. Protected reporting records, privileged advice and law-enforcement material should not become visible simply because a user can inspect the customer's transactions. The requirements should describe which objects and operations are permitted, including viewing, editing, exporting, forwarding and searching. A single group administrator role should not automatically bypass all legal restrictions.
Test access through normal and indirect routes. A user denied a report attachment may still find its title in search, see a filing date in a dashboard or receive an email containing the identifier. An exported case summary may include hidden fields omitted from the screen. An analytics service can replicate data into a less protected environment. These are functional information-sharing questions, not merely security defects. The testing team should agree expected results with legal and compliance owners and inspect the outputs received by each role, rather than checking only that a forbidden page returns an error.
The architecture should preserve a decision record for permitted transfers. Store source and recipient entities, data categories, purpose, authorisation, relevant conditions and time. Retain evidence of the actual transfer and any onward-sharing restriction. A permission that is appropriate for one investigation may not authorise reuse for marketing or general business analytics. Purpose changes should require reassessment. Automated services need accountable identities and scoped permissions; calling a recipient a system rather than a person does not remove the information-sharing issue.
Local rule overlays need controlled precedence
A rules catalogue should identify the source and scope of group standards, local legal obligations and discretionary policy overlays. Define precedence for cases where more than one rule applies and test whether the outcome is lawful and operationally intelligible. An additional group review can coexist with a local filing duty. It must not delay that filing because the group review is incomplete. A local prohibition on sharing a category of information should remain effective even if the group's general policy encourages collaboration. The engine should surface conflicts rather than silently select whichever rule has the higher numerical priority.
Use explicit decision outputs. A local legal duty, a required group approval and an optional risk-review recommendation should not all produce the same generic block code. Operators need to understand what is required, who can authorise the next step and which evidence supports it. Preserve rule versions and calculation inputs. When a requirement changes, the system should identify affected active cases without rewriting the original decision history. A configuration release needs regression testing across entities because a shared change can unintentionally alter an unrelated local workflow.
Test boundary dates and entity scope. Create otherwise identical fictional customers at two entities and confirm that each receives the correct local process. Move a relationship to a different booking arrangement through the authorised workflow and inspect the effect on new events and historical records. Test a future-dated rule before and after its application date. Include cases with missing or ambiguous entity information; they should enter an exception process rather than default to a convenient headquarters regime. Incorrect scope can be more consequential than an incorrect threshold within the right regime.
Group cases and local reporting tasks
Represent a group investigation as a coordination object linked to local cases, evidence and decisions. The coordinator can track questions and shared facts, while local officers retain their applicable decisions. Avoid one global report-submitted flag that implies every entity's obligations are complete. Separate relevant local triggers, due dates, decision owners, filing routes and acknowledgement states. The system should explain which entity has made which decision through an authorised view. Some users may see operational status without access to protected report details, depending on the approved local framework.
Deduplication needs careful scope. Two alerts about the same event at one entity may be consolidated to avoid repeated investigation, while separate events or duties across entities may require distinct handling. Matching a common customer identifier is not sufficient reason to suppress a local task. Requirements should identify what is being deduplicated: alerts, evidence requests, investigation work or filings. The result should preserve the source events and their relationships. Test retries, amendments, related customers and events received in a different order. A technically elegant suppression mechanism can conceal obligations if its scope is poorly defined.
Local deadlines should survive central workflow changes. Reassignment, translation, legal consultation, case merge and escalation must not erase the original trigger. A central service should expose imminent local deadlines and route urgent decisions to an authorised person. Test weekends and time-zone differences according to the applicable local rule, rather than assuming a global working calendar. Store the basis of the calculation. If a rule relies on when suspicion was formed, changing the alert creation timestamp should not automatically change that legal clock.
Reconcile populations across the group
A group completeness control needs independently established expected populations by entity and source. Global totals can balance while one entity's missing records are offset by duplicates from another. Reconcile meaningful segments such as product, processing date, event type and legal entity. Explain deliberate exclusions and link them to their control treatment. Test missing entity codes, duplicate feeds and late corrections. The expected population should not be generated solely from the same staging process whose completeness is being tested. Otherwise the control can confirm that an incomplete dataset matches itself.
Data freshness and semantic quality also matter. A group customer graph updated weekly may support periodic risk review but be inadequate for a fast-moving investigation. A payment code can have different meanings in two local systems. A central amount field can mix original currency and converted value unless its semantics are governed. Requirements should state the timing and meaning needed for each use. Test a plausible value that is wrong in context, not only a null or malformed record. Many serious defects pass schema validation because the data is structurally valid.
Preserve source-to-output lineage for aggregate reports. A group board metric should identify contributing entities, periods, definitions and exclusions. If one local entity cannot provide reliable data, the report should show that limitation rather than replace the entity with zero. When local definitions differ, explain how consolidation is performed and which comparisons remain unsuitable. Approved snapshots should be retained under the applicable arrangements so later reviewers can reconstruct what management saw. A live dashboard that changes retrospectively without history is weak evidence for an earlier decision.
Distributed resilience and constrained access
A central outage can affect many local entities at once. The continuity plan should identify which services are unavailable, what work can continue locally and what information each entity can lawfully access. A shared fallback spreadsheet can create new confidentiality and data-quality risks. Design the temporary process before an incident: local ownership, urgent decision handling, evidence preservation, reporting access and reconciliation into the normal platform. Test whether local staff can perform their responsibilities without the central service and whether they know when the fallback's capacity is exceeded.
Recovery should reconcile work performed in several places. Local cases created during an outage may overlap central alerts generated later. Preserve identifiers and decision history so the bank can link related work without deleting a necessary local record. Reconcile submissions and acknowledgements before creating retries. Data transfer restrictions still apply during emergencies unless the law provides an applicable route; operational urgency is not a generic exemption. The incident coordinator should identify when legal, reporting or customer-service expertise is required, rather than assume that technology recovery is the only priority.
Where customer-level access is legally limited, assurance should test the agreed alternative. A local independent reviewer may perform specified procedures and provide scoped findings to group management. The group should understand the population, method and limitations behind that conclusion. A statement that local compliance reviewed the programme is too vague to establish control coverage. Test whether the alternative can reveal missing feeds, poor case quality and unresolved incidents. If the information provided cannot support a meaningful conclusion, the remaining risk should be escalated and appropriately managed rather than described as fully assured.
Release and closure criteria for a group change
Before releasing a shared change, require evidence that affected entities and local rule overlays were identified, source semantics were mapped, permissions were tested and responsible local functions assessed readiness. A central product owner coordinates the release; it does not substitute for local legal or reporting authority. Record unresolved dependencies and the permitted deployment scope. A successful pilot in one entity should not automatically approve every other entity using different products, data or rules. Rollback and incident handling should be defined for the affected services, including local communications.
Closure of a group issue should retain entity-level status. A repaired common interface may resolve the problem for entities already using the new version while another remains on a local adapter. The group record should show that difference and its interim treatment. Independent validation should use the relevant local populations and test evidence, not merely the central release note. Senior management can then see what is actually resolved, what remains open and who owns it. The programme's strength lies in coordinated evidence and decisions, rather than a single global colour that conceals incomplete implementation.
Worked home/host conflict
A fictional subsidiary cannot lawfully transmit a protected report to group headquarters through the proposed tool. Headquarters needs to assess linked customers, but the subsidiary's counsel says that the SAR attachment is restricted. The group should explore authorised sharing of underlying facts and risk conclusions, maintain local reporting responsibilities and document any remaining blind spot.
Explain why sending the document through a different email address does not solve the legal conflict. Identify the local decision owner, group escalation, available safeguards and evidence needed for the home supervisor if an implementation impediment must be notified.
Review challenge: a group customer who changes booking centre
A corporate customer transfers a product from one subsidiary to another. The global customer service proposes retaining the same risk label and copying the old due-diligence file. The reviewer should establish which information remains reliable, whether the new entity can use it lawfully and what additional work its service and local framework require. A common identifier supports continuity but does not automatically discharge the new entity's duties. Preserve the old relationship, transfer date, source evidence and new decision. Otherwise the bank can lose the ability to explain which entity knew what during the transition.
Test a transaction booked just before the transfer and corrected afterward. The correction should retain the historical event context while following the approved process for the current servicing arrangement. Test a new beneficial owner disclosed during transfer and ensure the update reaches the appropriate entities through authorised routes. Test a disputed identity link and prevent an unverified match from silently carrying a high-risk label across the group. The expected results should identify facts, permissions and responsible decisions, not merely whether data copied successfully.
Review challenge: the smallest entity has the largest gap
A consolidated report shows ninety-eight percent monitoring coverage. The omitted two percent belongs almost entirely to a small subsidiary processing a specialised product. The group should not infer immateriality from global volume alone. Examine the product's exposure, customers, geography and available controls. Determine whether the excluded population is intentional and appropriately covered or represents a defect. The entity's management needs the relevant information, and group oversight needs a clear account of the limitation. Global aggregation should not erase local significance.
Acceptance evidence should reconcile source events by entity and relevant segment, identify exclusions and explain their treatment. An unexplained missing feed should create a visible exception with an owner. A deliberately unsupported product should require an authorised service decision, not disappear from the denominator. Test whether a local adapter can reject records while the central interface still reports success. The control should detect that distinction. Reports should identify absent or unreliable data explicitly, so management can decide the response rather than assume a zero exposure.
Review challenge: a shared-service agreement measures the wrong outcome
The central investigation service meets its target for acknowledging requests, but local cases wait days for substantive review. The agreement measures acknowledgement rather than the outcome needed by the entity. Review the service design against local decision requirements, complexity and urgency. Define escalation for imminent deadlines and unresolved evidence requests. Local officers need enough visibility and authority to challenge the service. A subsidiary cannot demonstrate timely reporting simply by producing a service-level report that says the central team replied to an email.
Test urgent cases, language requirements, specialist dependencies and absence of the primary local contact. Confirm that reassignment preserves relevant clocks and that staff know which entity is responsible. Simulate central outage and local fallback, then reconcile work when the service resumes. The result should show that the operating model can meet the required decisions under realistic constraints. It should also identify limits: a fallback with capacity for twenty urgent cases cannot support a population of several hundred without additional measures.
Review challenge: legal prevents sharing, or technology does not support it
An entity records every group data request as prohibited because its platform cannot separate ordinary customer evidence from reporting material. The reviewer should distinguish the actual legal restriction from the implementation limitation. Legal analysis may permit a narrower transfer that the system cannot currently produce. That conclusion points to a data-classification or workflow repair, not a permanent blanket exception. Conversely, a system's technical ability to export data does not establish legal permission. Both questions need their own evidence and owners.
The conflict record should identify the affected purpose, information class, origin and recipient, relevant interpretation and available alternatives. Test whether an approved summary remains useful for the intended investigation and whether it exposes restricted content through identifiers or equivalent signals. Assess the remaining oversight gap and the applicable escalation. A workaround should have a defined review date and evidence standard. Repeatedly renewing an exception without reassessing its risk can create a stable-looking register that conceals a growing limitation.
Review challenge: a minority investment is treated as a full subsidiary
A group acquires a minority stake in a payment company and proposes requiring every customer file to enter its global case platform. Review the group's actual legal duties, information rights, contractual powers and services to the investee. A commercially connected entity does not automatically become a majority-owned subsidiary within FATF's specific foreign-entity baseline. The group may need risk management for its exposure and may negotiate additional control rights. State those arrangements accurately rather than relying on a generic group label to justify unrestricted access.
Test the perimeter register after a change in ownership. Confirm that applicable group policies, service relationships and information permissions are reassessed rather than inherited unquestioningly. Identify whether the investee supplies services to a regulated group entity, because that dependency can create separate control questions. Senior management should understand the difference between risk it can influence directly and exposure requiring contractual or commercial measures. An investment committee's approval does not itself create the legal gateway for receiving protected customer or reporting information.
Coordinating supervisory requests
A home supervisor and a host supervisor can ask related questions without requesting identical evidence or exercising identical powers. The group should establish the recipient entity, request scope, deadline and authorised response route for each request. A central coordination team can maintain a request index and identify common factual material, but local responsible functions assess disclosure and approval under the relevant framework. Do not assume that information submitted to one authority is automatically authorised for every other recipient. Preserve the request, source evidence, approved response and submission record.
If two responses describe the same incident differently, investigate whether the difference reflects scope, timing or an error. One response may concern a local adapter while another addresses the central platform. Those distinctions should be explained rather than edited away to produce superficially identical narratives. Group coordination helps avoid contradictory unsupported claims, missed commitments and duplicated extraction. It should also retain local limitations and protect information subject to specific restrictions. Senior management needs a consolidated view of commitments with accountable local and group owners, so an undertaking made in one examination is not lost in another entity's workflow.
Evidence for final group assurance
The final assurance conclusion should identify the entities and services examined, the information available, local departures, legal impediments and material limitations. Show that group controls have operational counterparts locally and that local findings reach appropriate group oversight. Preserve scope differences rather than forcing identical conclusions. Demonstrate customer-linking accuracy, entity-level completeness, lawful sharing, local decision ownership, deadline handling and resilience. Where evidence remains incomplete, state the impact on the conclusion and the action needed. A strong group programme can explain both its connected view and the boundaries of that view.
Architecture and operating responsibilities
The customer-linking service should preserve entity ownership, legal purpose and source lineage. The case system should distinguish group intelligence from local statutory reporting. Role-based access must follow the approved sharing model; copying all subsidiary cases into a universal search index may defeat otherwise careful access rules.
Operations need instructions for central outages, urgent local deadlines and uncertain identity matches. Compliance owns the group baseline and conflict register; local officers validate applicability; legal owns gateway interpretation; technology proves the access and retention controls; independent audit checks actual implementation.
Release evidence should include a permitted-sharing matrix, tested denial paths, timely local escalation and retrieval of historical records after migration. Group cohesion depends on lawful visibility and accountable local execution, not unrestricted central access.
Northbridge Group: one network, three responsible entities
Northbridge is a fictional banking group with a parent bank, an overseas branch and a majority-owned subsidiary. The parent provides corporate lending. The branch handles trade-related payments. The subsidiary maintains operating accounts for regional businesses. A central shared-service company operates the transaction-monitoring platform and coordinates complex investigations. The case assumes that local legal teams have established different reporting and information-sharing conditions for the entities; it does not represent the law of a named country. The teaching question is how the group should operate once those differences are identified.
The customer network includes Alden Trading, its manufacturing subsidiary and a logistics company with a partly shared ownership history. The parent lends to Alden, the branch processes payments for the manufacturer and the local subsidiary holds the logistics company's account. Each local file contains a plausible explanation of activity. The group graph connects the entities through ownership records and directors, but some links are historical and one is based only on a name match. A central investigator receives an alert about circular-looking transfers. The graph is an investigative lead, not proof that all companies are controlled by the same person.
The central view depends on correct identity
The investigator first validates the network. Company registration identifiers confirm the parent and manufacturing subsidiary. The logistics company's current ownership differs from an older group record: a shareholder exited eighteen months earlier. A fourth company with the same trading name is unrelated. The graph service had linked it through an abbreviated address and a shared name. The team records the corrections and retains the original relationships with effective dates. It sends controlled correction events to downstream case and customer-risk systems. Quietly editing the current graph would leave earlier decisions difficult to explain.
The branch's payments include transfers to the logistics company for genuine freight services. Invoices and shipping evidence support some of the flows. Others are described as advance reimbursements with no clear commercial basis. The subsidiary sees rapid onward payments to two unrelated entities. The parent's lending file contains a forecast mentioning a new distribution arrangement, but no information about those counterparties. The central investigator separates explained events from the remaining questions. The task is to combine useful context without forcing a single suspicion conclusion on every entity or event.
The first evidence request is too broad: it asks the subsidiary to upload its complete investigation folder to the global platform. Local counsel identifies restricted material within the folder. The subsidiary does not refuse all cooperation. It classifies identity evidence, transaction facts, analyst hypotheses, protected reporting records and legal advice. The approved route permits a defined factual summary and supporting transaction information for the investigation purpose. Restricted material remains in the local environment. The decision record identifies recipients, information categories, purpose and conditions so later review can assess the transfer.
A common case does not create a common filing decision
The group opens a coordination case linked to local investigations. The local subsidiary's reporting officer assesses its own facts and reporting framework. The branch officer assesses the payments processed by the branch. The parent considers the lending relationship and information now available to it. The central coordinator tracks open questions and operational hand-offs through authorised status fields. It does not demand copies of all reports or assume that one local submission completes every entity's obligations. Local officers retain decision authority and the relevant trigger history.
At one entity, the available facts meet the applicable suspicion-reporting threshold while investigation questions remain open. The reporting process proceeds under that entity's local rule. Another entity requires additional analysis before its responsible officer reaches a decision. These different timings are not necessarily inconsistency. The entities have different services, facts and rules. The central team should identify unexplained differences and ensure useful information reaches the appropriate recipients, but should not delay a local filing to achieve simultaneous group sign-off. Coordination supports duties; it does not replace them.
A business sponsor asks whether the parent should immediately close every relationship in the network. The group risk forum asks for the basis of each proposed action. Reporting, discretionary risk treatment, legally required restrictions and contractual exit have different authorities and consequences. Genuine freight payments remain relevant contrary evidence. The wrongly linked company should not face a restriction based on an error. The group may adopt a lawful policy response for connected unresolved risk, but it must preserve the reason and authority. A central alert is not itself a universal power to freeze funds.
The shared service obscures a local deadline
During the investigation, the branch's local task moves to a central translation queue. The queue calculates age from reassignment rather than the preserved reporting trigger. A local dashboard therefore shows a recently opened task, although the relevant decision has been pending longer. A deputy officer notices the discrepancy through a separate manual control. The immediate response preserves the real dates and routes the case to an authorised decision maker. The technology team records a defect affecting deadline presentation. The group does not treat the discrepancy as a harmless display problem until its population impact is understood.
The defect review finds similar reassigned tasks at two entities. The central team extracts all affected transitions and compares them with original local triggers. Local officers assess whether any obligations or policy targets were affected under their rules. The repair separates legal clock inputs, internal service targets and queue timestamps. Regression tests include translation, merging, reopening and reassignment. The issue remains open until the affected population is reviewed and the repaired display is reconciled with authoritative dates. Correcting the current screen does not establish that historical cases were handled properly.
Senior management receives a paper identifying the affected entities and uncertainties. It states which urgent tasks have been addressed, which historical reviews remain and what resources are needed. The local and group owners are named separately: central technology repairs the shared workflow, local officers assess decisions and the programme function coordinates oversight. Notification questions go to the appropriate local legal and responsible functions. A generic group incident approval cannot answer every entity's legal notification duty. The record preserves those assessments without exposing protected case content to unnecessary recipients.
A legal impediment needs a usable alternative
The subsidiary cannot provide a category of protected reporting information through the central system under the case's assumed legal framework. The group assesses whether the approved factual route and local assurance provide sufficient visibility for the current investigation and programme oversight. Those are different purposes. The factual summary supports investigation of transaction patterns. Independent local testing supports a conclusion about reporting controls. Neither should be described as equivalent to unrestricted access. The group records what it can demonstrate and the remaining limitation, then considers applicable additional measures and supervisory engagement.
Local independent reviewers test the subsidiary's relevant controls using authorised local access. Their work includes source completeness, investigator handling, decision timeliness and confidential access. They provide a scoped conclusion with method and limitations through the approved group route. Group audit challenges whether the procedures address its oversight questions. The group does not request disguised copies of reports to defeat the restriction. If the alternative cannot answer a material question, the residual uncertainty remains visible to senior management rather than disappearing behind a legal-approved label.
The information-sharing arrangement is also tested technically. A central user can see the authorised factual summary but not the restricted attachment. Search results, exports and notifications are checked for report identifiers and equivalent existence indicators. The test reveals that an attachment filename is visible in the global index despite object-level denial. The platform team removes the unauthorised indexing path and examines whether the material was exposed previously. The confidentiality control therefore extends beyond the main case page. The original access matrix would have appeared sound if testing had stopped at screen permissions.
Group findings require local closure evidence
The central platform release repairs the clock and indexing defects, but the subsidiary uses a local connector scheduled for later deployment. The group issue remains open for that entity. It records the temporary safeguards and expected deployment date. Independent review checks the branch and parent on the repaired path while retaining the subsidiary limitation. Management reporting shows the actual entity-level status. A global green flag would incorrectly imply that every entity had received the repair. The release note establishes a change, not full implementation across the perimeter.
The customer-linking defect requires a different closure path. The identity team corrects the rule that generated the false link, reviews affected relationships and sends correction events. Local teams assess any customer impact from the wrong association. The group tests historical and current links using distinct confidence levels and effective dates. It also defines how future disputes will be handled. The programme improves not only detection of connected risk but protection against spreading unsupported conclusions. Accurate separation is as important as accurate connection in a group customer graph.
The case closes when the relevant investigation questions have their own outcomes and programme issues have appropriate evidence. Some local reporting work remains protected in its own environment. Some relationship decisions remain subject to later review. The group coordination record explains the network, information routes, entity responsibilities, limitations and linked actions without pretending to contain every local document. That is a defensible group view. It demonstrates lawful collaboration and accountable local execution rather than unrestricted central access or a single answer imposed on three distinct entities.
References and further reading
Reviewed 2 October 2026. FATF provides international standards; applicable national law determines binding duties. The operating examples are fictional teaching cases.
-
FATF Recommendations, updated June 2026 — relevant anchors: 18 and 21.
-
FinCEN cross-border information sharing and SAR confidentiality, 5 September 2025. National requirements and guidance must be read in their own scope.