Executive summary
Financial services groups run one business through many legal entities. This guide sets out how parent and subsidiary boards should divide and evidence accountability — reserved matters, delegated authority, group policy adoption, intragroup services, escalation and board information — so subsidiary boards govern their entities rather than ratify decisions taken elsewhere.
In financial services groups, accountability rarely fails because nobody is in charge. It fails because too many people are — a parent board setting direction, a group executive committee running the operating model, and subsidiary boards carrying legal and regulatory responsibility for entities whose most significant decisions are effectively taken elsewhere.
Parent-subsidiary governance is the discipline of making that arrangement work honestly: clear about what the group decides, clear about what the subsidiary board must decide for itself, and clear about the evidence each needs to discharge its duties. When it is designed well, it accelerates decisions and improves oversight. When it is left to convention, it produces subsidiary boards that ratify rather than govern — and a parent that discovers problems late.
Why parent-subsidiary governance is difficult in financial services
Financial services groups combine three features that make the parent-subsidiary relationship unusually demanding.
- Regulated entities carry their own licences, capital, liquidity and conduct obligations, and their directors carry personal duties that cannot be delegated upwards.
- Operating models are increasingly centralised — technology, risk, compliance, finance, treasury and operations are frequently delivered from the group rather than the entity.
- Supervisors expect legal-entity substance: a board able to demonstrate that it understands, challenges and controls the business booked in its own entity.
The result is a structural tension. Economically the group is one business; legally and prudentially it is a set of entities, each with its own accountability. Governance has to hold both truths at once rather than pretending one of them away.
Who is really accountable?
The honest answer is that accountability is shared, but not evenly, and not interchangeably.
The parent board
The parent board is accountable for group strategy, capital allocation, group risk appetite, the design of the operating model and the effectiveness of oversight across the group. It is also accountable for ensuring that each subsidiary is governed properly — including that subsidiary boards are competent, adequately informed and genuinely able to exercise judgement.
The subsidiary board
The subsidiary board remains accountable for the entity: its solvency, its regulatory permissions, its customers, its risk profile and its controls. Group policy does not transfer that duty. A subsidiary board that adopts a group framework without assessing its suitability for the entity has made a decision, not avoided one.
Group functions
Group risk, compliance, finance and internal audit often hold the expertise and the data. They are accountable for the quality of what they provide, but they cannot absorb the entity's accountability. Where a group function is the de facto decision-maker, the governance framework should say so explicitly and evidence how the subsidiary board oversees that arrangement.
Most disputes about accountability are, on inspection, disputes about undocumented delegation. That is a solvable problem, and it is usually where a board effectiveness and governance review starts.
Reserved matters: the single most useful instrument
A well-drafted schedule of reserved matters is the clearest expression of where authority sits. It should distinguish three categories:
- Reserved to the parent — group strategy, capital and dividend policy, appointment of subsidiary chairs and key function holders, material acquisitions and disposals, group risk appetite and brand.
- Reserved to the subsidiary board — entity risk appetite within group limits, entity capital and liquidity adequacy, regulatory submissions and attestations, product approval, conduct and customer outcomes, and acceptance of group services.
- Delegated to management — with defined limits, escalation triggers and reporting back.
Two failure modes recur. The first is a schedule so broad that the subsidiary board has little of substance left to decide. The second is a schedule that is technically correct but unknown to the people applying it. Reserved matters only work when they are short enough to be remembered, reviewed annually, and reflected in the actual agenda of both boards.
Group policies and the right of adoption
Centralised policy frameworks are efficient and, in most groups, unavoidable. The governance question is not whether to use them but how the subsidiary adopts them.
Good practice is a formal adoption decision: the subsidiary board considers the group policy, assesses fit against local regulation, customer base and risk profile, records any additions or local overlays, and adopts it explicitly. Where the group policy is less stringent than the entity requires, the subsidiary applies the higher standard. This makes the entity's governance, risk and controls framework demonstrably its own rather than an inherited artefact, and it gives supervisors something concrete to test.
Intragroup services, outsourcing and dependency
Where the subsidiary relies on the group for technology, operations, risk analytics or finance, that dependency should be governed as it would be with any third party: documented service arrangements, defined service levels, cost transparency, performance reporting, exit and substitutability analysis, and a named executive owner within the entity.
Subsidiary boards should be able to answer three questions without hesitation: what do we depend on the group for, how do we know it is being delivered to standard, and what would we do if it stopped? Operational resilience expectations across financial services increasingly make those questions supervisory ones rather than theoretical ones.
A practical test of subsidiary substance
Take the three most significant decisions affecting the entity in the past twelve months. Can the subsidiary board evidence that it debated them, understood the alternatives and could have decided differently? If not, the board is ratifying, not governing.
Information flow and escalation
Accountability follows information. A subsidiary board that receives group-level reporting with an entity column appended is not being equipped to govern its entity.
Entity reporting should present the entity's own capital, liquidity, risk profile, conduct outcomes, control environment and material issues, with group context where it aids interpretation. Escalation should be explicitly two-way and time-bound: material entity issues reach the parent within a defined window, and group decisions that materially affect the entity reach the subsidiary board before they are implemented, not after.
Where boards find this difficult, the constraint is usually the pack rather than the people. Reshaping board information so it supports entity-level judgement is one of the highest-return interventions in group governance, and a recurring theme in our board advisory services.
Composition, independence and the dual-hat question
Group executives frequently sit on subsidiary boards. This is legitimate and often valuable — it carries group context and speeds decisions. It also creates a conflict that must be managed rather than assumed away.
- Maintain a meaningful independent presence on regulated subsidiary boards, with independent directors who understand the entity's market and risks.
- Record conflicts explicitly, particularly on intragroup pricing, dividend and capital decisions, and outsourcing arrangements.
- Give independent directors time without group executives present, and a direct line to the parent chair and to the entity's key function holders.
- Assess subsidiary board effectiveness on its own terms rather than as a subset of the parent's review.
The three lines and group assurance
In group structures, the second and third lines often report into the parent. Subsidiary boards must still be able to rely on them. That requires the entity's audit and risk committees to have visibility of the entity-specific assurance plan, direct access to the group heads of risk, compliance and internal audit, and the ability to commission entity-specific work where their risk profile warrants it. Assurance that is designed only for group materiality thresholds will systematically under-cover smaller regulated entities where the exposure is nonetheless entity-critical.
Warning signs a parent-subsidiary structure is drifting
- Subsidiary agendas dominated by noting items and group updates.
- Reserved matters last reviewed several years and one restructuring ago.
- Group policies applied to the entity with no adoption decision on record.
- Intragroup services delivered without documented arrangements or service reporting.
- Independent directors who cannot describe how a material group decision was reached.
- Supervisory questions consistently answered by group rather than by the entity.
- Escalation that travels upwards reliably and downwards inconsistently.
Strengthening the framework
Improvement rarely requires wholesale redesign. In most groups the sequence is: restate the accountability model in plain language; refresh reserved matters and delegated authorities; formalise policy adoption and intragroup service arrangements; rebuild entity reporting around entity decisions; then test the arrangement against a live decision to see whether it holds. Each step is modest; together they change what a subsidiary board is actually able to do.
How DisInnova supports groups and subsidiary boards
DisInnova works with parent boards, subsidiary boards and group executives in financial services on the governance architecture that connects them — accountability models, reserved matters, delegated authority, intragroup arrangements, board information and committee design.
Clarify accountability across your group
Partner-led support for parent and subsidiary boards on governance structure, reserved matters, delegation, escalation and board effectiveness in regulated groups.
Key takeaways
- Accountability in groups is shared between parent and subsidiary boards, but it is never transferable upwards
- A short, current schedule of reserved matters is the clearest expression of where authority actually sits
- Group policies should be formally adopted by the subsidiary board after an assessment of entity fit
- Intragroup services deserve the same governance discipline as third-party outsourcing
- Entity-level reporting, not group reporting with an entity column, is what enables subsidiary boards to govern
- Dual-hatted group executives add value, but independent presence and recorded conflicts keep the arrangement honest
Written by
DisInnova Editorial Team
DisInnova's insights are prepared by a senior practitioner-led advisory firm with credentials across internal audit, IT audit, governance, risk management, controls, fraud examination, strategy, corporate governance and financial services, including CIA, CISA, CFE, CRMA, CRISC and related professional certifications.
This article is general advisory information and does not constitute legal, regulatory, audit, tax, investment or professional assurance advice.



