Most groups treat entity records as administration. They're a governance exposure, and one that sits closer to the board than almost anyone assumes.
The reason is structural. Directors are accountable for governance across the whole group, including every subsidiary they've never looked at in detail. They rely on the governance team to surface entity-level information when a question arrives. If that team can't produce a verified, current answer quickly, the board's accountability is resting on data nobody can stand behind on demand. Since the The Economic Crime and Corporate Transparency Act 2023 (ECCTA) began tightening what Companies House expects UK groups to confirm and evidence, the window for producing that answer has narrowed.
In short: the risk is rarely that entity data is missing. It's that nobody can produce one verified answer at the speed a bank, regulator, or auditor now expects.Good corporate governance is when boards see governance as an advantage, not a chore. Meetings spark real debate, directors challenge assumptions, and risk management and strategy are woven together.
What does fragmented entity data mean?
Fragmented entity data means the record of who owns what, who directs what, and where each entity is registered exists in several places at once, with no single version anyone can name as authoritative.
It rarely looks like a failure from the inside. Each record is usually correct or was correct when someone last touched it. Governance teams know where most things sit. The fragmentation shows only when a question crosses entities, or when an answer must be evidenced rather than recalled.
Ownership records split across spreadsheets, shared drives, and legacy systems
Group structures accumulate. Someone builds a spreadsheet to track shareholdings during an acquisition. A regional team keeps its own version because the corporate one lags behind local filings. A legacy system inherited through a merger still holds the only complete history for a dozen dormant companies, and one person in finance knows how to query it.
None of that is negligence. Governance professionals build these workarounds to keep working while systems lag behind the group's growth. The cost arrives later, when a director asks who owns a particular subsidiary and in what proportion, and the governance team has to reconcile three sources before answering. That reconciliation is unrecorded work nobody can audit afterwards.
No single source of truth for directors, roles, and jurisdictions
Directorships change more often than ownership does, which makes them harder to hold accurately. A director resigns from four subsidiary boards on the same day. Someone updates the local filings, someone else updates the group register, and the two fall out of step for a period nobody can specify.
Jurisdictional detail compounds this. The same person may hold different roles under different local requirements, with different filing obligations attached. A governance team holding that picture across dozens of entities in half a dozen jurisdictions can answer the question. What they can't do is prove the answer is current without going back to the underlying records one entity at a time.
Accountability now rests on records with a statutory deadline attached
For years, groups absorbed this quietly. The cost was internal: slow answers, duplicated work, the occasional awkward gap found during an audit. What's changed is that external parties now ask specific entity questions with dates attached, and several of those questions carry statutory weight.
ECCTA has made identity verification and registry accuracy a live obligation for UK groups rather than a filing formality. Directors and people with significant control are required to verify their identity with Companies House, and groups are expected to hold registered information that stands up to that scrutiny. The obligation lands on the governance team, and it lands cross-entity.
A group with sixty subsidiaries isn't answering one question sixty times. It's assembling one group-wide picture of directors, PSCs, and registered detail, and confirming it. Where that picture must be reconstructed from several sources, the work expands and the assurance weakens.
Banks and auditors apply the same pressure on a different cycle. A bank onboarding or renewing a relationship asks for a current ownership chain and evidence behind it, usually against a deadline set by the bank. An auditor testing group structure at year-end asks the same of records the governance team hasn't touched since the last filing. Neither party accepts "broadly accurate, we'll confirm next week" without consequence.
The mechanism worth naming is this: boards cannot oversee what they cannot see clearly, and they cannot see clearly through records that need reconciling before anyone trusts them. Directors approve group compliance positions on the assumption that the underlying data is verifiable. The assumption goes untested until someone outside the organisation tests it.
Governance teams hedge, and boards misread it
Here's the part that stays invisible in board papers. Governance teams who know their entity data needs checking build caution into everything they say to the board. They hedge. They promise to come back. They take a question away rather than answering it in the room.
Directors read that hesitation as thoroughness. Sometimes it is. Sometimes it's the only honest response available when nobody can be certain which version of a record is current, and the person answering would rather be slow than wrong in a minuted meeting.
The effect on oversight is real. A board that never gets a direct answer to an entity question stops asking entity questions, because the exchange feels unproductive. Attention moves to the material that comes back cleanly. Over a few cycles, the group's structure drifts out of the board's field of view, not because directors decided it was unimportant but because the information behaved as though it were. Weak information shapes the conversation as much as strong information does, which is the pattern we set out in our state of board reporting research and the reason preparation quality determines what a board can usefully discuss.
Governance teams rarely flag this themselves, because from the inside it reads as diligence rather than a gap. It's worth a chair asking directly how long a specific entity question takes to answer with evidence and treating a long answer as information about the system rather than the person.
Why haven't groups fixed this already?
Because consolidating entity data is hard, and the reasons are worth stating plainly.
Local registries hold legal authority. In most jurisdictions, the filed register is the legal source of truth, not the group's internal system. Any internal record is a mirror, which means consolidation doesn't remove the reconciliation problem so much as move it to a single, maintained point. That's a real improvement, and it's less than "one system, done".
Migration is slow and expensive. Historic records sit in inconsistent formats, dormant entities have incomplete histories, and someone has to make judgement calls about which version to trust before anything goes into a new system. That work needs governance expertise, so it can't be handed to a data team in isolation, and it competes with a filing calendar that doesn't pause.
Local teams lose something. A regional company secretary who keeps their own spreadsheet does so because it fits their filing rhythm. Centralisation asks them to give that up for a group benefit they may not feel. Groups that skip this conversation tend to end up with a central system and a shadow spreadsheet, which is worse than either alone.
None of that argues against consolidating. It argues for treating it as a governance programme with a sponsor and a sequence, usually jurisdiction by jurisdiction, rather than a software purchase.
What does good entity data governance look like?
Good entity data governance means any authorised person can produce a current, evidenced answer about any entity in the group without reconciling sources first. Not whether the data exists, but whether someone can produce it, show where it came from, and show when it last changed.
One structured, auditable source of truth
Structure matters as much as centralisation. A shared drive holding every relevant document in one folder is centralised and still unusable at speed, because someone has to read the documents to extract the answer. Structured data holds ownership percentages, appointment dates, registered addresses, and filing obligations as fields that can be queried directly.
Auditability turns that into governance rather than convenience. When a governance team can show who changed a record, when, and on what basis, they can evidence a position to an auditor or regulator rather than assert it. Directors can then rely on the answer and know what that reliance is built on.
Real-time visibility across the whole group, not just individual entities
The questions that create exposure are almost always cross-entity. "Which of our entities have an unverified director under the Companies House requirements?" is the kind of question a governance team should answer in a moment. Answered entity by entity, it takes days and produces a snapshot that's out of date before it reaches the board.
A quarterly reconciliation tells the board what was true at a point in the past. Directors making a decision this month need the position this month.
This is the problem IQ Entities, Board Intelligence's entity management system, is built to solve: holding entity records in one queryable place so a governance team can answer portfolio-wide questions from the organisation's own data, and automating routine compliance admin with a person reviewing before anything is filed. It doesn't remove the migration work described above, and no system makes a local registry stop being the legal source of truth. What it changes is how long it takes to get from a question to an evidenced answer. It sits alongside the board portal and the rest of our board management software, so what governance teams verify about the group feeds the papers directors read.
Book a demo and see it against your own entities.
Book a demoDirectors don't need to become experts in subsidiary record-keeping. They do need to know whether the answers they rely on can be produced and proved when someone outside the organisation asks. That's a question worth putting on an agenda before a bank, regulator, or auditor puts it there first.
FAQs
-
What is entity data fragmentation?
Entity data fragmentation is when a group's records of ownership, directorships, and jurisdictional detail are spread across multiple spreadsheets, shared drives, and systems, with no single authoritative version. The individual records are often accurate. What's missing is one place where anyone can confirm the current position and show where it came from.
-
Why is fragmented entity data a governance risk?
Fragmented entity data is a governance risk because directors are accountable for compliance across the whole group while relying on others to surface entity-level detail. When records need reconciling before anyone trusts them, the board approves positions nobody can evidence at the speed a bank, regulator, or auditor requires.
-
Who is responsible for entity data governance on a board?
Directors hold accountability for governance across the group, including its subsidiaries, and the governance team or company secretary holds day-to-day responsibility for maintaining and surfacing entity records. Those roles are distinct: a board cannot delegate its accountability, and a governance team cannot exercise the board's oversight on its behalf.
-
How can boards improve entity data governance?
Boards can improve entity data governance by asking how quickly a specific entity question can be answered and evidenced, rather than whether the data exists. That question tends to expose which records need reconciling, and it gives the governance team a mandate to consolidate entity data into one structured, auditable source.
-
What does ECCTA mean for entity data?
The Economic Crime and Corporate Transparency Act 2023 introduced identity verification requirements for directors and people with significant control and tightened what UK groups must confirm and evidence about their registered information. For groups with many subsidiaries, that makes register accuracy a cross-entity exercise rather than something confirmed once and left alone.
