Business model · Multi-entity

Many entities. One picture.

Diversified companies run governance across business units, subsidiaries, and acquisitions. TruOps lets each run its own program and rolls it all up.

Multi-entity structureeach entity owns its work
Entities
  • Parent
  • Media division · 12 brands
  • Subsidiary A (acquired 2025)
  • Shared services
Roll upwithout flattening
Parent sees
  • Consolidated posture
  • Risk across entities
  • Shared-vendor concentration
  • Deadlines by entity
Illustrative example
In short

TruOps supports multi-entity enterprises in two ways: scope assessments to business units, processes, or systems within one environment and roll results up, or give subsidiaries their own isolated environments with a parent-level view of posture, risk, and deadlines. Either way, the same issue across entities is one finding, and risk is reported consistently.

This page is for you if
  • Subsidiaries and acquisitions run their own programs, or pretend to
  • Leadership wants one risk picture without flattening local obligations
  • Shared vendors create concentration nobody sees

A customer in this space

Hearst

The actual challenge

Holding companies either force one GRC (and get garbage data) or allow islands (and get no roll-up).

  • Each client or entity is a new implementation.
  • The view above is a spreadsheet of exports.
  • Playbooks do not transfer.

What you are probably using today

This is what the book of business, the fund, or the holding company is usually running today.

What you use nowWhere it breaksWith TruOps
Enterprise GRC suitesThey can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project.AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project.
A parent instance nobody in the brands usesThe consolidation is a fiction.Isolated environments or scoped assessments, with live roll-up of posture and risk.
Point tools that do not talkA TPRM portal here, a risk register there, findings in the ticketing tool, the board pack in slides. Each is true in its own world. Leadership gets three answers.One assessment engine, one evidence layer, one register. A document uploaded once, an answer given once, or a control checked once counts everywhere it applies.

Bring one real document. Watch the program get set up from it.

Two ways to structure it

ApproachBest when
Scoped assessments in one environmentBusiness units share systems and policies
Separate environments with a parent viewSubsidiaries are distinct companies, or were acquired

Roll up without flattening

Results roll up from system to business unit to enterprise, but each entity keeps its own frameworks, owners, and findings. Leadership sees consolidated risk; each entity sees its own work. Shared vendors show up as concentration, not as twelve unrelated records.

What this usually replaces

  • A parent GRC instance that subsidiaries will not log into.
  • A new implementation (or a new spreadsheet) after every acquisition.
  • A quarterly pack assembled from twelve exports that cannot be drilled.
  • Vendor lists per entity with no view of concentration.

If this is your situation

Bring one client, portco, or subsidiary's documents to a demo. TruOps will stand up an isolated environment from them and show the parent-level view.

How TruOps helps

Nested scopes
Targets inside targets, with results rolling up.
Parent view
Posture and risk across every entity.
Consolidated vendors
See where entities share vendors and concentration risk.
Consistent scoring
One risk method across the enterprise.
Two structures
Scoped assessments in one environment, or isolated environments with a parent view.
Acquisition-ready
Stand up a new entity from its documents without a services project.

Questions

Can subsidiaries have separate environments?

Yes, with a parent-level view across all of them.

Can we assess by business unit?

Yes. Scope an assessment to a business unit, process, system, or asset; results roll up.

Do we have to rip out the tools we already use?

No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.

Can we bring our existing assessments, control lists, and vendor files?

Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.