TL;DR
- A compliance report records its scope, the obligations assessed, the status of each one, the evidence behind that status and what is being done about anything still open.
- Compliance reports go to the board and its committees, to senior management, to entity heads, and in a different form to authorities.
- Automation removes the collection and consolidation effort, not the judgement.
Quick Answer: Compliance reporting is the process of recording and showing that a company meets its legal, regulatory and internal obligations. Across multiple entities, each legal entity's status is collected in one standard format and consolidated into a single view for management and the board. Each entity still meets its own local reporting duties.
Most groups produce two different documents and call both of them a report. One is an internal status record written for management; the other is a disclosure submitted to an authority by a single legal entity. Treating the two as interchangeable is the error that makes group reporting unreliable.
What is compliance reporting?
Compliance reporting is the structured record that an obligation was identified, allocated to a named owner, acted on and evidenced. It sits on top of a compliance programme rather than replacing it, which is why it only works when the underlying obligation register is complete. Reporting is the output, and compliance itself is the activity being measured.
Two distinct outputs carry the same name. An internal compliance report tells senior management and the board how the organisation is tracking against its obligations, in a format the company chooses. A filing made to an authority is a legal submission by one entity under one law, and it follows the form that authority prescribes rather than your internal template. Both report on the same underlying regulatory compliance position.
Why does compliance reporting matter to a group board?
A board cannot supervise what it cannot see entity by entity. Reporting converts scattered local activity into a position the board is able to question, which is where oversight actually happens. It also creates a contemporaneous record that the group acted on an obligation at the time, rather than reconstructing the story afterwards.
What does a compliance report contain?
A compliance report records its scope, the obligations assessed, the status of each one, the evidence behind that status and what is being done about anything still open. The fields below make up the compliance report format most commonly used for group-level reporting.
| Field | What it records |
|---|---|
| Scope and period | The entities, jurisdictions and time span the report covers |
| Obligations covered | The specific obligations assessed, drawn from the obligation register |
| Status | Whether each obligation is complied with, pending or not complied with |
| Evidence reference | The document, acknowledgement or approval that supports the status |
| Exceptions | Open items, failures and anything completed after its own due point |
| Remediation owner and target | The named person accountable for closing an exception, and the agreed target |
| Sign-off | Who reviewed and approved the report before it was issued |
The evidence reference column is the one most often left blank, and it is the one that decides whether the report can be relied on. A status without a document behind it is an assertion, not a record.
How does the report change by reader?
The field set stays the same and the depth changes. A board pack leads with exceptions, ownership and direction of travel, holding the obligation-level detail behind it. An entity pack lists every obligation allocated to that entity, open and closed. Driving both from one standard field set is what allows the two to reconcile.
Who receives compliance reports and how often?
Compliance reports go to the board and its committees, to senior management, to entity heads, and in a different form to authorities. Each audience needs a different level of detail. The board looks for what is unresolved and who owns it, while an entity head needs the open items belonging to that entity alone. Where the group contains a listed entity, the board also carries reporting and internal-control duties of its own, which is the subject of internal-control reporting for listed companies.
Frequency is set by internal policy and by each authority, never by a single group calendar. Internal reporting cycles are a governance choice. The expectation that boards receive regular information on how a business meets its legal and ethical obligations runs through Organisation for Economic Co-operation and Development (OECD) guidance on responsible business conduct. Submissions to authorities follow whatever period the relevant law attaches to them.
How does compliance reporting work across multiple entities and countries?
Group reporting runs as a sequence, and the table below names each step with the failure it prevents. Skipping a step does not remove the work. It moves the work to the consolidation stage, where it is slowest and least visible.
| Step | What goes wrong without it |
|---|---|
| Identify every entity and jurisdiction | Dormant and newly acquired entities sit outside the report and nobody notices |
| Determine the rules each entity is subject to | Entities are assessed against the parent company's obligations instead of their own |
| Collect status per entity | Local teams report activity completed rather than obligations met |
| Standardise and validate | Each country submits a different format, on a different cycle, in its own wording |
| Consolidate and prepare the report | Group figures cannot be reconciled back to any entity's own records |
Where does consolidation usually break?
Consolidation breaks where two entities answer the same question differently. One treats a submission as complete when it is sent, another when it is acknowledged, and the group view then adds two incompatible numbers together. Platforms built for multi-country groups deal with this by fixing the status definitions centrally and letting each entity record against those definitions only.
Does group reporting replace local reporting?
No. A group view is an additional layer, and each entity remains responsible for its own obligations and its own submissions. Group-level reporting is also not confined to internal governance, because authorities exchange information about groups under OECD frameworks on tax transparency and international co-operation. That is an illustration of how a group can be looked at as a whole rather than entity by entity, not a statement that any such framework applies to your group.
How do dashboards show compliance across countries and entities?
Compliance management software with dashboards shows the compliance status of every legal entity and country in one group-level view, filtered by entity, country, obligation owner or overdue item.
From that view a reader drills from a country down to the entity, then to the individual obligation and the evidence attached to it. Overdue items and unassigned obligations are the two filters practitioners reach for first, because both point to where the next failure is likely to come from. A report is a fixed statement of position for a stated period, whereas a compliance dashboard is a live view of the same underlying data.
How is compliance reporting automated?
Automation removes the collection and consolidation effort, not the judgement. It depends on how compliance management software records obligations, owners and evidence, because a report can only roll up what the system already holds. The owner of each obligation confirms status in the system and uploads the evidence at the point of completion. Automation of the reporting cycle then rolls that result up by entity, country and obligation type, with nobody rekeying anything.
What does an automated reporting cycle produce?
Three outputs change the most. Alerts flag missed and approaching items to the owner and to the person accountable above them. A standing group view replaces the periodic request for spreadsheets. An exportable pack gives the board the same figures the operating teams work from, which takes the reconciliation argument out of the meeting.
Where does the platform sit in the reporting chain?
LexComply maps a group's companies in a single instance, allocates only the relevant Acts to each entity, and produces dashboards and reporting from that allocation. Teams evaluating compliance management software should test the consolidation path end to end, from an owner's update through to the board pack, using their own entity structure. Completeness of the underlying legal register, such as a maintained compliance library of Central and State Acts, sets the ceiling on how complete any report can be.
Common Mistakes to Avoid
- Reporting tasks done instead of obligations met. A closed task is not proof that an obligation was satisfied. Status should track the obligation, with the task as supporting detail.
- Letting each entity use its own format. Consolidation then takes longer than the reporting itself, and group figures stop reconciling to entity records.
- Reporting status without evidence links. A status nobody can trace to a document cannot be relied on by the board or by anyone reviewing the group later.
- Confusing an internal report with a submission to an authority. They serve different readers and follow different forms, and one does not discharge the other.
- Hiding exceptions. Open items shown with a named owner and an agreed target build more confidence than a report that shows nothing outstanding.
Legal Disclaimer
This article is general information about compliance reporting practice and does not constitute legal advice. Obligations differ by entity, sector and jurisdiction, so take professional advice on your own position before acting on anything described here.

