Logo

Speak with an expert

/Get expert consultation
Home/Blog/How to Build a Scalable Corporate Governance Framework Across Countries

How to Build a Scalable Corporate Governance Framework Across Countries

Compliances
How to Build a Scalable Corporate Governance Framework Across Countries

Our latest insights help businesses operate and expand confidently across global markets by navigating complex regulatory landscapes.

Introduction

Global expansion demands a corporate governance framework that can scale across countries while honoring diverse legal and regulatory regimes. A well-designed global governance framework aligns the strategic objectives and risk appetite of the parent company with the operations of each subsidiary, yet respects local laws and cultural differences. It establishes clear roles, decision rights and accountability at every level, from the holding-company board down to local management. Such a framework promotes transparency, accountability and consistency, which are key corporate governance principles that underlie market confidence and long-term value. In practice, multinationals often standardize core policies (ethical standards, risk governance, internal controls, reporting templates, etc.) while allowing subsidiaries flexibility to meet country-specific requirements (for example, local board composition or financial reporting rules).

A robust framework also mitigates risks: it helps prevent regulatory breaches and reputational harm, and it provides a “single source of truth” for entity data and controls across all jurisdictions. By integrating global best practices (from OECD guidelines to industry standards) with local compliance, senior management can ensure consistent oversight of the entire corporate group. This article explains how to build such a scalable corporate governance model for multinational companies, including practical steps, decision-making matrices, and examples. It covers core components (boards, policies, committees, reporting, technology), implementation stages (assessment, policy development, monitoring, review), and common challenges. Where relevant, it highlights Indian law provisions separately from general principles, to guide Indian companies with overseas subsidiaries and foreign companies operating in India.

Key Governance Principles for Multinational Corporations

At its core, corporate governance rests on sound principles such as transparency, accountability, fairness, and responsibility. The OECD’s G20/OECD Principles of Corporate Governance stress that a governance framework should promote efficient markets and investor confidence through clear legal/regulatory regimes and self-regulation. In a multinational context, these principles translate into practices like:

Board oversight and accountability: Boards (at parent and subsidiaries) set strategy, monitor management, and oversee risks through appropriate controls (audit, compliance, internal audit).

Clear decision rights: Written charters, delegation matrices or “schedule of matters reserved” document which issues require board approval (e.g. strategy, large investments) and which can be handled by management.

Risk management and internal controls: A risk framework (often COSO-based) that identifies enterprise risks (market, financial, compliance, operational, ESG) and assigns monitoring responsibilities.

Integrity and ethical culture: Group-wide codes of conduct and anti-bribery policies that apply everywhere, even if local laws are silent. (For instance, OECD anti-corruption guidelines or ICGN principles may inform these).

Stakeholder protection: Especially in civil-law jurisdictions, governance must consider stakeholders (employees, creditors) not just shareholders.

These principles must be embedded in the global model while allowing for local variations. For example, UK and US (common-law) systems emphasize shareholder primacy and board independence; they allow flexible, principles-based governance. Civil-law countries (e.g. Germany, France, Japan) often impose more prescriptive rules (two-tier boards, works councils, creditor protections). Multinationals should therefore adopt a principle-based core (e.g. independence, disclosure, risk oversight) but design detailed policies to satisfy each jurisdiction’s specific rules (for instance, adding works council consultation in Germany or local audit committee rules in India). This balance ensures that the global framework adds value (through consistency and efficiency) without clashing with local requirements.

Global vs. Local Governance Requirements

A scalable governance framework distinguishes group-wide requirements from local mandates. Global requirements are those that the corporation chooses to apply across all operations: for example, a uniform code of ethics, enterprise-wide risk appetite, consolidated financial reporting standards, and group tax and treasury policies. Local requirements, by contrast, are the legal/regulatory rules in each jurisdiction – for instance, board composition rules, statutory meeting calendars, or industry-specific licenses.

In practice, group policy must thread the needle: it complements local law, not contradict it. For example, a global policy might mandate annual board meetings at least quarterly; in India this must align with the Companies Act’s minimum (four meetings/year) and must not exceed statutory gap limits. Similarly, a group-wide director training program should incorporate local legal duties – like India’s requirement to disclose ultimate beneficial ownership (which has strong enforcement), or the EU’s recently expanded corporate sustainability due diligence rules.

Because each country has unique laws, a governance framework usually starts with a jurisdictional mapping exercise. This means cataloging all relevant corporate laws and codes: for example, India’s Companies Act, SEBI LODR (if listed), FEMA (RBI) rules, Indian Secretarial Standards; UK’s Companies Act 2006 and the UK Corporate Governance Code (FRC); US Sarbanes-Oxley Act 2002 (especially Sections 302, 404 on internal controls and CEO/CFO certification) and any state law like Delaware General Corporation Law; EU directives (e.g. 2017/828 on shareholder engagement) and local company laws; Singapore’s Companies Act and Code of CG; UAE’s Federal Corporate Law and DIFC/ADGM regulations. Summaries of key differences should be documented – for example, noting that India requires at least two directors for a private company and annual filings (Forms MGT-7 and AOC-4), whereas US law requires quarterly filings for listed entities.

The entity management function (often led by the corporate secretariat) plays a crucial role here. By maintaining a centralized database of all subsidiaries, their jurisdictions, and statutory requirements, the company can automate compliance tracking. As companies expand, “gaps in oversight of hundreds of subsidiaries” are a major risk. Leading companies use entity management software to consolidate filings, approvals and corporate records into a “single source of truth”. This ensures that no country “falls through the cracks,” even as each subsidiary follows its local laws.

Parent Company and Subsidiary Governance Structures

In a multinational group, there are typically two governance layers: the parent (headquarters) and the subsidiaries. Each level has its own board and responsibilities. The parent company board is accountable to shareholders for the group’s overall performance, strategy, and risk profile. It sets group-wide policies, approves major investments or restructurings, and appoints key leaders (e.g. Group CEO, CFO). The subsidiary board, however, is a separate legal board of the entity in that country. Even if the parent owns 100% of a subsidiary, local directors (often including parent-nominated members) serve on it and owe fiduciary duties to the subsidiary itself. Subsidiary boards “must comply with local regulations” and manage day-to-day operations, even as they align with the parent’s strategy.

These two governance layers often overlap in practice. For example, common models of subsidiary governance include:

Direct control by the parent board: The parent board and its committees exercise virtually all governance functions for the subsidiary. The subsidiary’s board (if it exists) has minimal duties beyond legal compliance. This model (sometimes used in closely held or fully integrated groups) centralizes decision-making, but it can raise “shadow director” liability issues: parent directors effectively manage the subsidiary without formally meeting there. This risk is magnified if local law still considers them de facto directors.

Shared governance (matrix model): The parent and subsidiary share governance. The parent board leads on strategy and group policy, while the subsidiary board handles local operations and compliance. In this common approach, parent representatives on the subsidiary board align the subsidiary’s actions with group goals, and the subsidiary’s local board members focus on meeting regulatory requirements and local business execution. This model balances group oversight with local expertise and is “a common and viable approach balancing the interests of all parties”.

Subsidiary board autonomy: The subsidiary board largely governs independently. It follows its own approved budgets and plans, subject only to high-level direction from the parent. This model maximizes local flexibility and can be suitable for joint ventures or when local market dynamics require autonomy. However, it may pose challenges for tight integration across the group, as noted by governance experts.

The choice among these models is strategic. For critical or highly regulated units, a parent-led model or shared control may be preferred to ensure compliance. For non-core or distant markets, granting more autonomy to the subsidiary board can encourage agility. Regardless of the model, formal documents should capture the arrangement. For instance, a shareholders’ agreement or group governance charter might explicitly list which functions remain at headquarters (reserved matters) versus those the subsidiary can manage.

All subsidiary boards must understand their dual role: they are accountable to local law (and, by extension, local regulators and minority shareholders) as well as to the parent’s group strategy. Case law (such as Delaware’s Chancery Court) emphasizes that parent-company directors cannot simply ignore a foreign subsidiary’s activities or treat it as a mere extension of the parent. In essence, subsidiary governance must allow subsidiaries “to determine what works best for them and their needs” while still ensuring they “conform to the parent’s expectations” on key policies and ethics.

Board Composition and Director Responsibilities

The subsidiary board should have a composition suited to its context. Best practice is a mix of executive, non-executive (independent) and, in some cases, local directors. Typically, one or more board members are appointed by the parent to represent group interests, ensure alignment with group policies, and facilitate information flow between boards. The remaining seats can be filled by independent or local directors who bring market knowledge and an outside perspective. In smaller, non-listed subsidiaries, boards are often two or three members; larger or listed subsidiaries may have larger boards. In India, for example, a private company requires at least two directors and a public company at least three. For listed Indian subsidiaries, the majority must be non-executive with at least one-third independent directors, and independent-dominated audit committees.

Every director (local or parent-nominated) owes fiduciary duties to the subsidiary. They must act in good faith, exercise due care, and promote the company’s success (per local law). Directors are responsible for overseeing strategy execution, ensuring accurate financial reporting, and implementing adequate controls and risk management. In practice, a director should review monthly or quarterly financial performance and budgets, question unusual variances, and ensure risks (operational, regulatory, financial) are identified and mitigated. For example, directors should verify that internal audits are conducted and that corrective action follows any findings.

Committees are key tools of board structure. At group level, boards often form standing committees (audit/risk, nomination/governance, remuneration, etc.) to concentrate on specialized oversight. Subsidiary boards may mirror this where required by law or good practice. For instance, many jurisdictions (including India) legally require certain committees for medium/large companies. A subsidiary might have an Audit Committee (common for listed or large entities), a Risk Management Committee, or (in India) a CSR Committee if it meets size thresholds. These committees are usually composed of board members (often independents) and delve into specific topics, reporting recommendations back to the full board. For example, a subsidiary audit committee focuses on financial controls and audit results, ensuring any issues are escalated to the board. Even if not mandated, committees (or at least designated sub-groups) help localize governance attention on key areas.

Delegation of Authority and Reserved Matters

A cornerstone of any multinational governance framework is a Delegation of Authority (DoA). This defines who in the organization has the power to make which decisions, and ensures critical decisions stay at the right level. In practice, the DoA is often a matrix or table specifying, for each type of decision (budget approval, contract signing, hiring, etc.), the monetary or other threshold and the approving authority (e.g. subsidiary CFO, subsidiary board, parent CEO, parent board).

Typically, day-to-day and operational matters (routine hiring, small purchases, local standard contracts) are delegated to subsidiary management. Strategic and high-impact matters are reserved for the parent. These reserved matters are decisions that the subsidiary cannot make unilaterally. Common examples include: major capital expenditures or investments above a set limit, mergers and acquisitions, incurring significant debt or equity financing, approving annual budgets, altering share capital (e.g. issuing new shares), strategic pivots (entering new countries, exiting lines of business), and appointing or removing key senior officers (like CFO or General Counsel). Many companies list reserved matters in shareholder or joint-venture agreements; subsidiaries’ own articles of association may also codify certain restrictions (for example, requiring board approval for any change to the articles themselves).

Having a clear DoA and reserved matters list reduces confusion and risk. It guarantees that the parent “maintains control over critical matters while empowering subsidiary leaders on day-to-day issues”. For instance, an Indian subsidiary’s DoA might permit its CEO to approve contracts up to INR 10 million, while anything above that requires escalation to the parent. Similarly, only the parent board may approve writing off large receivables or launching a new foreign subsidiary.

Oversight of this structure is essential. In many groups, the parent board (or a designated global executive committee) monitors compliance with the DoA. The Corporate Secretary or CFO often tracks and reports on reserved decisions, ensuring all such approvals are documented. Some organizations use governance software or workflow tools to flag any request that exceeds authority limits and enforce required approvals. The key is to formalize this framework in writing – through charters, board minutes, and policy documents – and to communicate it to all management so that everyone knows their decision rights and limits.

Governance Policies, Charters, and Committees

A multinational governance framework should be grounded in clear, documented policies and charters. At the highest level, the group should have a corporate governance charter or manual, approved by the parent board, that outlines the overall model. This may include the roles of group and local boards, key policies (ethics, risk, compliance), oversight mechanisms, and interfaces between parent and subsidiaries. The charter is not law, but it sets the “tone from the top” and serves as a binding guide for management and directors globally.

Complementing the charter, board charters for each board (parent and each subsidiary) should define that board’s authority, membership rules, meeting frequency and agenda items. For example, a subsidiary board charter will typically be tailored to local law (e.g. annual meetings, quorum requirements) while referencing the parent’s strategic objectives. Similarly, charters for board committees (e.g. Audit, Risk, Compensation) should be in place for any committee, describing its composition, duties and reporting lines.

Key global policies should include (where applicable): a Code of Conduct or Ethics (often mandatory under listing rules or anti-corruption laws), a Whistleblower Policy, Anti-Bribery & Corruption Policy, Risk Management Policy (defining risk appetite and governance structure), and an internal control framework (e.g. COSO-based controls environment). These group policies provide consistent standards – for instance, the same anti-corruption rules or conflict-of-interest standards apply across subsidiaries, even if local laws do not require it. However, each subsidiary must adopt or supplement them to comply with local requirements (for example, adding any industry-specific rules in a particular country).

Global policy development should involve key functions: Legal, Compliance, Finance and Internal Audit usually drive policy content, under the guidance of the board. For each policy, clearly assign accountability – often the Group CFO or General Counsel is the sponsor, with a committee (e.g. Risk or Audit Committee) periodically reviewing compliance with the policy across the group. Once policies are drafted, training and communication are critical. Senior management and directors at all levels should be briefed on new policies and given access to manuals (perhaps via an intranet or governance portal). Regular training (especially on sensitive topics like anti-bribery) helps embed policies into local culture.

Board committees deserve special mention. As noted, effective boards (parent and significant subsidiaries) often establish committees to focus expertise and oversight. An Audit Committee oversees financial reporting, internal controls and audit functions. A Risk Committee (if separate or combined with Audit) oversees enterprise risks and compliance. Nomination/Governance and Remuneration committees (or combined committees) handle board composition, succession planning and compensation issues. In India, for example, large and listed companies are legally required to have separate Audit, Nomination & Remuneration, and Stakeholders Relationship Committees. All committees should operate under board-approved charters and report regularly.

Entity Management and Regulatory Compliance

At the operational level, robust entity management is the foundation of governance and compliance. Each legal entity (subsidiary, branch, joint venture, etc.) must be carefully managed from incorporation to dissolution. This includes maintaining up-to-date legal documents (memorandum/articles of association), share registers, director/secretary registers, contracts, licenses and filings.

Multinationals often encounter a “patchwork” of rules. Every jurisdiction has its own filing obligations: for example, one country might require quarterly board meeting minutes filed with regulators, another might demand detailed beneficial ownership disclosures, and a third might impose strict auditing standards. Some countries criminalize certain directorship violations. For instance, India’s Companies Act disqualifies directors after three years of missing annual filings. Tax and regulatory regimes add complexity (transfer pricing documentation, VAT/GST filings, payroll taxes), and industry-specific rules (e.g. banking licences, environmental permits) layer on top. Language and administrative procedures (notarization, apostille, translations) further complicate cross-border compliance.

Because of this, leading multinationals treat entity management as a strategic program, not just a back-office task. They centralize entity governance so that all deadlines and requirements are tracked in one system. A global entity management system (often software) can list all entities, their corporate details, compliance calendars and obligations. For example, one dashboard might flag that Subsidiary A has an AGM due in July and Subsidiary B needs to appoint a new independent director by next quarter. Real-time dashboards and alerts ensure nothing is overlooked.

In practice, the legal or compliance department (sometimes with a dedicated Corporate Secretary or legal ops team) owns the entity database and calendar. This team works with local counsels or country managers to ensure filings are done. For instance, if Indian subsidiaries require Form FC-GPR to be filed within 30 days of receiving foreign investment, the central compliance team will alert the India office to file that with the RBI. Similarly, global financial reporting deadlines (like IFRS or GAAP consolidations) are linked to local statutory audits.

Synchronization is key. New global rules (e.g. the U.S. Corporate Transparency Act or EU UBO registers) impose deadlines to report ownership. Companies must build these into their global calendar. A best practice is to maintain one consolidated compliance calendar for the entire group, covering all jurisdictions. This calendar is color-coded and includes escalation rules: for example, if an entity misses a filing deadline, an exception report goes automatically to group CFO and the CEO of that region. Quarterly reviews of the calendar help catch any missed obligations in time.

Entity management also involves managing changes: acquisitions, mergers, or new subsidiaries. A formal process should exist so that any change in corporate structure is approved at the corporate level rather than done ad hoc. This ensures new entities are set up with the correct legal form and compliance framework from day one.

Implementation Framework: Steps to Build the Governance Model

Building a multinational governance framework is a multi-step project. While each company’s path may vary, a practical roadmap typically includes:

Current-State Assessment: Conduct a thorough inventory of existing governance practices and compliance processes in every country. Identify all legal entities, board compositions, meeting schedules, reporting lines, and local requirements. Note gaps or duplications. This “as-is” snapshot might reveal, for example, that some subsidiaries have no independent directors though local law requires them, or that two affiliates in different countries hold redundant board meetings. This assessment often involves surveys or interviews with local general counsels and company secretaries.

Jurisdictional Mapping: Compile the specific corporate governance and compliance requirements for each country. This includes corporate law mandates (board meeting frequency, director residency requirements, audit committee rules), securities/regulatory codes (if subsidiaries are listed locally), and other rules (labour laws, data privacy, etc.). Create a comparative matrix: column per country, row per requirement (e.g. “max days between meetings”, “min # of independents”, “statutory audit needed?”). This highlights where group policy must adapt. For instance, if the local law demands a minimum of 4 directors on a board, the subsidiary’s proposed 3 directors would need adjustment.

Governance Risk Assessment: Identify risks in the current governance model. For example, are any critical decisions falling through cracks? Is there a lack of clarity in decision rights? Are compliance responsibilities undefined? Common risk areas include inconsistent meeting cadences, untracked regulatory filings, or overlap/conflict between local and group policies. Prioritize the risks by likelihood and impact. For instance, missing a financial filing might carry heavy fines or even director disqualifications (as with India’s Section 164).

Define Roles and Structure: Based on the above, determine the governance structure. Decide on the model for each subsidiary (direct, shared, or autonomous) and set up oversight bodies. Assign who will sit on which boards (e.g. the Group CFO and one independent for a key subsidiary). Form or reconstitute committees at group and subsidiary levels as needed (audit, risk, nomination). Establish a group legal/compliance function (sometimes called a Global Secretary’s office) to maintain entity records and policies.

Policy and Charter Development: Draft or update the global governance charter and key policies, incorporating international best practices and local legal requirements. For example, the governance charter might state: “All subsidiaries shall have at least one-third independent directors if required by local law, and shall maintain statutory registers in English and the local language.” Policies should cover areas like ethics, conflicts of interest, compliance, internal controls, and risk management. Ensure local counsel vet all documents for legal compliance.

Implementation and Communication: Roll out the new framework. This includes conducting training workshops for boards and senior management across geographies to explain the new roles, policies, and processes. Provide written guidelines and process documents. For example, issue a delegation matrix showing subsidiary managers what approvals they have and when to escalate to group level. If new committees are formed, charter them and schedule their first meetings. Tools like intranets, board portals, or global governance portals can host charters, policies, and committee materials for easy access by all directors.

Technology Enablement: Implement governance technology as needed (see previous section). At a minimum, ensure the compliance calendar and entity database are operational. Board portals or secure document libraries should be ready for distributing board packs and minutes. Train users on these systems.

Monitoring and Reporting: Establish regular reporting to monitor adherence. For example, require each subsidiary to submit quarterly compliance certificates (confirming that all board minutes and filings are up-to-date) to the parent. The Corporate Secretary or Group CFO should compile dashboards on governance metrics (number of board meetings held, audit findings, regulatory issues raised, etc.) for review by the parent board or an executive committee. Schedule internal audits or reviews of the framework – for instance, a yearly “governance audit” to check that subsidiaries are following group policies and local laws.

Periodic Review and Improvement: A governance framework is dynamic. Schedule a formal review of the framework itself at least annually, or whenever significant changes occur (e.g. new regulations, M&A deals). Use lessons learned and audit findings to refine policies. For example, if a compliance review finds that subsidiaries are frequently missing the same filing deadline, the process or automated reminders can be improved. Periodically refresh board training and consider adding new metrics (e.g. time-to-decision for key approvals) to gauge performance.

This step-by-step approach transforms governance from a static checklist into an evolving model that can scale as the company grows into new markets.

Monitoring, Reporting, and Internal Controls

Effective governance requires continuous monitoring and clear reporting lines. Typically, subsidiary management reports to the local board, and that board reports to the parent board. Many groups standardize this via a Management Information System (MIS): each subsidiary delivers monthly or quarterly management reports (P&L, balance sheet, key metrics) in a common format. The parent may also require local compliance reports (e.g. any regulatory changes or legal disputes) on a regular schedule. Consolidated financial statements are prepared at the group level for shareholders and statutory purposes.

From a risk and control perspective, an Internal Audit (IA) function often audits subsidiaries. Large groups may have a Group IA team that periodically reviews subsidiary controls and reports findings to the subsidiary’s audit committee and the parent’s Audit Committee. Smaller entities may rely on external auditors or rotate in-house reviews. The audit function ensures that the subsidiary is not only financially compliant but also adhering to group policies and local laws.

For example, the subsidiary board (and its audit committee) should regularly confirm that external audits were completed and significant audit points addressed. They should also verify that any internal audit recommendations are acted upon. The parent board might request an annual statement from each subsidiary’s CEO/CFO confirming that all internal controls are effective and all material risks are disclosed.

Technology can help in monitoring. Governance portals or workflow systems can track the status of decisions and controls. For instance, if a subsidiary needs to approve an international bank guarantee, the portal could route the request according to the DoA, collect electronic approvals, and store the documentation. Alerts can be set for action items (e.g. if a board minute is pending approval, or if a subsidiary has not filed its tax return by the due date). This ensures real-time visibility of governance and compliance matters, rather than waiting for annual reports to surface issues.

Performance Metrics and Continuous Improvement

To ensure the governance framework is working, the group should define key metrics. These might include:

Board meeting attendance and frequency: Are all mandated meetings held on time (e.g. at least one per quarter)?

Compliance rate: Percentage of entities that filed all required annual reports by deadline. (Regulators in some countries publish defaulting companies, so the goal is to keep that number at zero.)

Control issues: Number of significant audit findings or material compliance incidents per year (ideally trending downward).

Decision timeliness: Average time to finalize key decisions (e.g. from subsidiary proposal to parent board approval). Long cycles may indicate bottlenecks upstream.

Director training: Percentage of directors who completed annual governance training.

Entity rationalization: Number of dormant or redundant entities identified/eliminated per year, reducing complexity.

Collect these indicators in a dashboard for senior management. Regularly review them (e.g. at the parent board’s meetings) and investigate any red flags. This management-by-metrics approach drives accountability (“what gets measured gets managed”) and fosters continuous improvement. For instance, if a sharp increase in late filings is spotted in one region, the root cause can be addressed (perhaps better local resources or process).

Continuous improvement also means keeping the framework current. Governance trends evolve (e.g. ESG oversight, data protection rules, digital meetings norms). The board should commission periodic policy updates – for example, adding a Data Privacy policy in line with GDPR/India’s DPDP Act, or ESG reporting guidelines per global investor demands. A living governance framework will adapt to such changes rather than stagnate.

Challenges in Multinational Governance

Managing governance across borders brings distinct challenges:

Legal Diversity: As noted, legal systems vary. Common-law countries (US, UK) emphasize broad director discretion and disclosure, while civil-law regimes (Germany, Japan, many emerging markets) have more prescriptive rules, two-tier boards or stakeholder considerations. These fundamental differences mean that, for example, a practice of unilateral board decision-making in one country may be impermissible in another. Corporate groups must navigate these legal “fault lines” carefully.

Regulatory Complexity: Subsidiaries might answer to multiple regulators: corporate registries, securities commissions, central banks, tax authorities, etc.. Rules can conflict – for instance, one country may limit data transfer out of the country (data localization), complicating global reporting. Even within regions, standards differ: EU countries have rules for two-tier boards, whereas US or India do not. Compliance calendars must therefore be granular and meticulously maintained.

Cultural and Language Barriers: Different business norms affect governance. For example, in some Asia-Pacific countries, consensus-based decision-making and respect for hierarchy are valued; in Western contexts, direct challenge and debate may be expected. Subsidiary directors from different cultures may interpret ethical issues differently. Communication barriers (language, time zones) can slow down decision cycles – a board meeting in India may be difficult for US-based directors to attend on normal hours. Address these with translated materials, flexible scheduling (video meetings outside business hours), and cross-cultural training. Virtual board portals with multi-language support can help bridge gaps.

Information Fragmentation: Without centralized systems, each subsidiary may use different processes or formats, making group consolidation a headache. This leads to data silos. A consistent governance framework (with standardized board packs and reporting templates) is needed to ensure data integrity.

Local Autonomy vs. Control: Striking the balance is tough. Over-centralization (shadow management) can demotivate local teams and delay agile responses to market changes. Under-centralization can lead to compliance gaps or brand inconsistency. Clear delegation matrices and reserved matters (as discussed) mitigate this tension.

Resource Disparity: Not all subsidiaries have the same level of governance maturity. A well-resourced country team (e.g. US, UK) may have full-time lawyers, internal audit and robust finance systems, while a smaller affiliate in an emerging market may have only a part-time accountant and rely on external counsel. This unevenness means the parent must often provide templates, training and sometimes shared services to uplift weaker subsidiaries.

Currency and Transaction Controls: Financial governance is affected by currency regulations. For example, India’s FEMA rules require strict reporting for foreign investment flows and dividend repatriation. Subsidiaries must follow these cross-border payment regulations, which adds governance overhead. The framework must incorporate treasury guidelines and pre-approval processes for such transactions.

Conflicts between Group and Local Rules: Sometimes group policies must yield to local law. For instance, a global vacation policy might cap accruals, but French labour law mandates certain leave rights. Governance documents should note such exceptions. In India, if the LODR (Listing Obligations) requires independent directors and meetings of minority shareholders, those must be observed even if the group’s model did not originally include them.

Addressing these challenges requires flexibility and local expertise. Often, companies form regional governance committees (e.g. Asia-Pacific Governance Council) to adapt global policies to local contexts, and ensure voice for local issues in global policy-setting.

Special Considerations for India

For Indian multinational groups (or foreign groups with Indian subsidiaries), several local rules are noteworthy. Under the Companies Act, 2013:

subsidiary in India is a separate company where the parent holds >50% of shares or appoints majority directors. It must register as a local company with a board of directors (even if foreign-owned).

Board structure: Private Indian companies need 2 directors; public need 3. One director must be resident in India (at least 182 days/year). Listed subsidiaries need majority non-executives, 1/3 independents, and must form Audit, Nomination & Remuneration Committees.

Meetings and filings: At least one board meeting each quarter (no gap >120 days) and an AGM every year are mandated. Statutory registers (members, directors, charges) must be maintained. Annual filings include Form MGT-7 (annual return) and AOC-4 (financial statements) to the Registrar. Late filings attract heavy fines and director disqualification (Section 164 declares directors disqualified if they fail to file returns for 3 consecutive years). Subsidiaries must also hold AGMs and file income tax returns, GST returns (if registered), and other periodic statutory filings.

Foreign investment reporting: The Reserve Bank of India (RBI) enforces FEMA rules. Any inbound FDI into an Indian subsidiary generally requires filing Form FC-GPR within 30 days of allotting shares. Equity transfers between non-residents or from NRIs to others may require Form FC-TRS. Annual Return on Foreign Liabilities and Assets (FLA return) is due by July each year if the Indian entity has foreign ownership. These reporting requirements must be built into the compliance calendar and treated as compliance priorities.

Corporate governance regulations: SEBI LODR regulations impose additional requirements on listed Indian companies (and, by extension, listed foreign companies with Indian subsidiaries). These include mandatory committees (Audit, NRC, Stakeholders), CEO/CFO certifications on financial controls, disclosure of related party transactions, and enhanced board reporting norms. Large private subsidiaries often voluntarily adopt some LODR-like practices to align with group standards.

Secretarial standards: The Institute of Company Secretaries of India issues Secretarial Standards (SS-1 for meetings, SS-2 for annual general meetings) which, while not law, are deemed compliance standards. Minutes of meetings must conform to SS-1 requirements.

All these make India a demanding governance environment. Global companies should ensure their India compliance team (in-house or outsourced) is up to date. For example, even a wholly-owned subsidiary of a foreign parent must follow the Companies Act as a domestic company, and its directors can be personally liable for lapses (as underscored by recent enforcement cases). Entities must file a registry of persons holding substantial beneficial interest (PBS-1) and update it with each change (regime introduced in 2022).

Best Practices and Checklists

Senior management can use the following checklist and frameworks to guide development of their framework:

Governance Charter Template: Document defining the scope (group and subsidiaries), principles, roles, and oversight structure.

Delegation Matrix: List of decision categories (e.g. capital expenditure, contracts, hiring) with approval authority thresholds (e.g. “Board of Subsidiary up to $1M; Subsidiary CEO up to $250K; Local CFO up to $50K”).

Reserved Matters List: Enumerate items requiring parent/board approval, such as major M&A, changes to group strategy, appointments of subsidiary CFO/CEO, large loans, etc..

Entity Inventory and Compliance Calendar: Spreadsheet or software listing every entity, jurisdiction, and all recurring requirements (annual returns, tax filings, license renewals, board meetings, etc.). Assign an owner for each and escalation contacts. Use color-coding for upcoming deadlines.

Committee Charters: If forming audit/risk committees, have charters that meet local regulations. For example, India’s Audit Committee charter must include reviewing financials and auditor findings.

Board Charter: Template agenda and terms of reference for boards (parent and subsidiaries). Should require, e.g., quarterly review of strategy, annual evaluation of risk framework, etc.

Internal Control Documentation: E.g. COSO-based control matrix for major processes, updated to reflect local variations (currency controls, tax rules, etc.).

Training Plans: Annual schedule for director and management training on governance topics and local regulations. For instance, training on Indian Companies Act changes if an MNC launches a subsidiary in India.

Implementing a framework often follows a pilot-and-rollout approach. For example, the company might first apply the new governance model to the Asia region, learn from that, and then apply improvements globally. Incorporating feedback (from audits or from local management) is crucial.

Overall, building a scalable cross-border governance framework is a strategic endeavor. It requires up-front investment in mapping and policies, but it yields rewards in terms of risk reduction, reputational trust and operational efficiency. By blending global consistency with local adaptability, multinational organizations can exercise effective oversight and accountability without stifling the agility needed in each market.

FAQ

Q: What is a scalable corporate governance framework?
A: It is a governance model designed to support a company’s growth across multiple countries. It provides consistent global principles and policies, yet is flexible enough to comply with each jurisdiction’s laws. A scalable framework defines roles (group vs local), decision rights, controls and reporting mechanisms that can be expanded as the business enters new markets, without re-inventing the wheel each time.

Q: How do we balance global standards with local laws?
A: Start by defining core global standards (e.g. ethical code, risk appetite, board oversight) and then map them against local legal requirements. For each country, adapt the framework so that local mandatory rules (like board composition, meeting frequency, filings) are met. For example, a global policy might require an annual board meeting; if local law requires more frequent meetings, ensure the policy language is “at least annually (or as required by local law).” Use a governance charter to document this balance. In practice, each subsidiary’s board charter would explicitly state compliance with both the group’s policies and the specific statutes of that country.

Q: What are reserved matters in a governance framework?
A: Reserved matters are significant decisions that a subsidiary cannot make on its own and must escalate to the parent or group board. Common examples include approving the annual budget, large capital investments or contracts above a threshold, acquisitions/divestitures, major financing arrangements, strategy changes, and appointing key executives. Listing these matters in the shareholders’ agreement, articles of association, or a delegation matrix ensures clarity. Smaller decisions are delegated to local management, while strategic and risk-sensitive decisions remain “reserved” for higher authority.

Q: How should we govern overseas subsidiaries of an Indian parent (or vice versa)?
A: The key is dual compliance. An Indian parent with foreign subsidiaries must ensure each subsidiary follows that country’s company laws, securities laws, tax and exchange control rules. Globally, the parent sets group strategy, risk policies and aggregate financial targets. In India’s case, the parent should maintain a register of its foreign holdings (per Companies Act reporting) and adhere to FEMA rules for sending money abroad. If the foreign subsidiary is in a low-governance environment, Indian parent directors may need extra oversight (for example, extra board meetings or reports). Conversely, a foreign parent in India must follow India’s Companies Act, RBI regulations and relevant Reserve Bank filings (e.g. FC-GPR, FLA returns), in addition to implementing the group’s global policies locally. The governance framework should explicitly list these India-specific compliance steps as part of the overall model.

Q: What compliance obligations do global companies have for Indian subsidiaries?
A: Indian subsidiaries (including wholly foreign-owned ones) must comply with Indian laws. Immediately after incorporation they must hold a Board meeting within 30 days and appoint an auditor. They must have at least one Indian resident director. Annually, they must hold a Board meeting (at least 4 per year) and an Annual General Meeting within prescribed timelines. Key filings include the annual return (MGT-7) and financial statements (AOC-4) to the Registrar of Companies, and maintain a Beneficial Ownership register. If foreign investment is involved, Reserve Bank filings (like Form FC-GPR for any equity allotment) are required. If the entity is large or listed, committees (Audit, NRC, Stakeholders) must be formed and additional disclosures (e.g. corporate governance report, director certifications) made. A comprehensive governance framework would include a compliance calendar covering all these specific obligations for India.

Q: How can governance performance be measured?
A: Use governance KPIs. Examples include the percentage of board and committee meetings held on time, timely completion of auditor-recommended fixes, timely regulatory filings, and director attendance rates. Some companies track “board decision cycle time” – the average duration from proposal submission to board resolution – to catch bottlenecks. Others measure compliance metrics, like number of late filings or audit issues raised. Employee or stakeholder surveys on governance transparency can also provide feedback. The goal is to detect weaknesses (e.g. if several subsidiaries consistently miss deadlines) so the governance process can be improved.

Q: How often should the governance framework be reviewed?
A: At minimum, conduct a formal review annually. But in practice, it should be continuous: new laws, M&A transactions or control findings may require interim updates. Leading companies treat governance review like any other audit cycle – policies and charters are revised as needed, and directors receive refresher training. A useful practice is to include a governance audit or health check when entering a new jurisdiction, to ensure the framework is applied correctly there. The board should also periodically (e.g. biannually) evaluate the overall framework’s effectiveness and update it based on experience and regulatory change.

Q: Can governance technology help?
A: Absolutely. Tools like GRC software, entity management platforms and secure board portals can dramatically improve scalability and oversight. For example, a cloud-based entity management system can consolidate global entity data, maintain a single calendar of obligations, and flag upcoming compliance deadlines. Board portals allow directors in different countries to access agendas, minutes and reports securely and conduct virtual meetings (a capability that became critical during the COVID era). Some platforms even link entity data to board packs, automatically listing which subsidiaries are discussed at each meeting. The right technology turns governance from a manual, spreadsheet-driven task into an integrated, transparent process, enabling real-time reporting and analytics.

Q: What are the biggest pitfalls in global governance?
A: Common pitfalls include (1) assuming one size fits all: ignoring local laws or customs leads to compliance failures. (2) Over-centralization: having parent micromanage everything can slow decisions and disempower local teams (the “shadow management” syndrome). (3) Under-supporting local offices: small subsidiaries without adequate governance resources may drop the ball. (4) Inconsistent processes: if each country uses different templates or software, consolidation and oversight suffer. These can be avoided by explicitly designing the framework (with DoA and clear roles), providing training and resources globally, and using standardized templates and systems.

Q: How can Indian companies with overseas subsidiaries integrate global and local governance?
A: Indian multinationals should start with the same global principles (OECD-based governance, risk oversight) and then layer on host-country specifics. For example, an Indian parent may require its subsidiaries to adopt an anti-corruption policy consistent with India’s Prevention of Corruption standards, while ensuring they meet the host country’s foreign investment laws. Indian companies often appoint seasoned executives as subsidiary board members to balance understanding of group strategy with local business. They should maintain a foreign investment register (as required by RBI) and consolidate overseas financials per Indian GAAP/IFRS, while each subsidiary also meets local audit and tax rules. Essentially, the global framework acts as the “parent code”, with subsidiary governance charters customized to each jurisdiction’s law.

Talk to us

Stay ahead of global change—connect with our experts to ensure your finance and tax functions remain compliant and transformation-ready.

Find out more about our statutory accounting and tax support here.

Stay ahead of global change

Get the latest updates on compliance, certifications, and global business expansion from CertificationsBay