August 17, 2026

Legal Entity Management: Why Excel Spreadsheets Are Your Biggest Audit Risk

Philipp Seibald

By Philipp Seibald

Vice President Sales

28 min read

Share this post

Readers of this article will learn exactly what legal entity management entails, why 89% of companies reach their limits in this area, and the four underlying causes of nearly every governance gap. You’ll discover a tried-and-true approach that helps legal, compliance, and finance teams move from an Excel spreadsheet to an audit-ready, historized investment management system—including a free self-assessment.

Key Takeaways

  • Legal entity management involves the centralized, audit-compliant administration of all of a company’s subsidiaries, equity interests, board seats, and reporting obligations.

  • According to EY and Harvard Law School, 89% of companies report difficulties with legal entity management, mostly due to process complexity.

  • According to the ACC and Deloitte, 31% of companies lack a process that ensures effective governance of their subsidiaries.

  • The four most common root causes are fragmented master data, a lack of historical data, unclear responsibilities, and system silos between Legal, Tax, and Finance.

  • A structured legal entity management system closes these gaps and accelerates the provision of structure-related data for reporting and audits by up to 40% (Goldright project data).

  • Our free Legal Entity Audit Check shows you in 15 minutes where your organization stands today.

What is Legal Entity Management?

Legal Entity Management refers to the systematic administration, control, and documentation of all companies, equity interests, mandates, and controlling relationships of a company or corporate group. In an international context, the term “Legal Entity Management” (LEM) has become established. Both terms describe the same core concept: a centralized, historically tracked master data foundation for every legal entity within a corporate group—from the parent company down to the smallest foreign branch.

Five data dimensions are central to this:

  1. The master data of the companies themselves: name, registered office, legal form, and unique identifiers such as the LEI (Legal Entity Identifier).

  2. Shareholdings and control relationships—that is, who holds how many shares, directly or indirectly, in which company.

  3. The governing bodies and elected officials—executive boards, supervisory boards, managing directors, and their respective terms of office.

  4. The statutory reporting and disclosure requirements, which vary depending on legal form, industry, and country of incorporation.

  5. The associated documents, such as articles of association, minutes, and powers of attorney, which provide legal protection for each company.

Investment management is therefore more than just an administrative task: It forms the basis for consolidated reporting, regulatory filings, related-party transactions, M&A due diligence, and the identification of ultimate beneficial owners (UBOs).

Internationally, the term “Legal Entity Management” (LEM) has become established for this same area of responsibility, often supplemented by the phrase “subsidiary governance.” Both terms—investment management in German-speaking countries and Legal Entity Management internationally—describe the same concept: the audit-compliant maintenance of all of a company’s legal entities. Anyone looking for legal entity management software is generally seeking the same solution as a company looking for an investment management system.

A typical data model for a mature investment management system also includes identifiers such as the Legal Entity Identifier (LEI), which is used internationally to uniquely identify legal entities in financial markets, as well as the recording of ultimate beneficial owners (UBOs). UBO identification, in particular, is gaining importance due to stricter anti-money laundering regulations and transparency register requirements: Those who have not fully documented their own ownership structure can hardly identify ultimate beneficial owners in deeply nested structures reliably and in a timely manner.

Legal Entity Management Using Excel Spreadsheets?

Traditionally, legal entity management is organized using Excel spreadsheets, file folders, and the memories of individual employees. This works as long as a corporate group remains small and stable. As soon as new companies are added, ownership stakes change, or board positions shift, the Excel spreadsheet becomes a risk: It lacks historical data, isn’t automatically validated, and is only as up-to-date as the person who last maintained it. If that person leaves the company or is on vacation when an urgent inquiry comes in, the entire legal entity management process effectively grinds to a halt.

Defining the Terms: Legal Entity Management vs. Investment Controlling

Legal entity management is often confused with investment controlling. Investment controlling focuses on the financial management of subsidiaries (key metrics, budgets, performance), while investment management maps out the legal and organizational structure—that is, the questions “Who owns whom, who represents whom, and since when?” In practice, the two disciplines overlap, as robust investment controlling requires well-maintained investment data.

Legal Entity Management vs. Master Data Management

It is also important to distinguish this from the broader field of master data management. Master Data Management manages all of a company’s master data domains—customers, suppliers, products, materials, and assets. Legal Entity Management is a specialized form of this that focuses exclusively on companies, investments, and corporate governance structures, while following the same basic principles: a central data source, clear governance, and complete historical tracking.

AI in Legal Entity Management

These fundamental principles have become even more important as companies begin to use AI-powered analyses based on their corporate data—for example, to answer questions about investment structures, term lengths, or reporting thresholds in natural language. Such applications are only as reliable as the underlying investment data. An AI assistant that relies on inconsistent Excel spreadsheets will, at best, provide uncertain answers and, at worst, incorrect ones. A cleanly archived, centralized investment management system is therefore not only a means of preparing for audits but is increasingly also a prerequisite for making legal entity data usable for automation and AI in the first place.

Why Is Legal Entity Management Important?

The importance of investment management is growing along with the complexity of modern corporate structures—and the regulatory pressure weighing on them. Five key metrics show why this topic is on every compliance agenda.

89% of companies report difficulties with legal entity management.

The biggest hurdle cited is the complexity of the process itself, according to a joint survey by EY Law and the Center on the Legal Profession at Harvard Law School of more than 2,000 executives from 17 industries and 22 countries. What is notable about this study is that these difficulties occur across all industries—regardless of whether a company manages ten or several hundred entities. Complexity, therefore, arises not only from size but also from a lack of structure.

31% of companies lack a process for effective subsidiary governance.

This is one of the key findings of the annual Legal Entity Management Report by the ACC (Association of Corporate Counsel) and Deloitte, which is based on a survey of 467 organizations across 20 industries and all global regions. Sixty-two percent of respondents cite too many competing priorities as the biggest hurdle, meaning the issue is pushed to the back burner not due to a lack of interest but for capacity reasons. This combination is particularly problematic: Those who know a process is missing but lack the capacity to establish it consciously accept the risk—until an audit or transaction inevitably brings it to light.

According to McKinsey, governance and compliance maturity still has room for improvement.

In the 2025 McKinsey Global GRC Benchmarking Survey, which surveyed 193 decision-makers worldwide—more than 60% of whom are at the C-suite level or one level below—companies rated their compliance maturity at an average of only 2.9 out of 4.0 points and their risk management maturity at 2.6 out of 4.0. 48% of companies have no formal corporate governance procedures, 58% do not use governance manuals, and 53% do not maintain a record of their board resolutions. Notably, larger companies consistently rate their maturity higher than smaller ones—an indication that resource allocation, and not just good intentions, determines the quality of governance.

Investment in governance, risk, and compliance tools will increase by 50% by 2026.

This is Gartner’s forecast in response to stricter regulatory requirements for board and executive oversight, such as those imposed by the U.S. Securities and Exchange Commission (SEC) and the U.S. Department of Justice (DOJ). Gartner attributes this investment surge to the fact that companies can only benefit from voluntary self-reporting of misconduct if they have previously established demonstrably effective compliance programs and functioning controls—a requirement that is virtually impossible to meet without robust ownership and governance data.

More than a quarter of companies lose more than $5 million annually due to poor data quality.

7% lose as much as $25 million or more. According to a recent analysis by the IBM Institute for Business Value, 43% of Chief Data Officers consider data quality to be their top priority. Ownership data is a core component of this master data quality—incorrect ownership structures directly impact consolidation, risk reporting, and regulatory filings. IBM also points out that poor data quality is rarely noticed at the point of origin but only becomes apparent later in the form of delayed reports, flawed analyses, or compliance risks—a pattern that repeats itself almost identically in cases of inadequate investment management.

This trend is also evident outside the world of legal entities: According to Bitkom, 53% of German companies report problems in managing their digital transformation—a percentage that has risen steadily since 2022 (34%). Legal entity management thus reflects a larger problem: Structures are growing faster than processes and systems can keep up—a trend also confirmed by Goldright projects in the finance, insurance, and real estate sectors: When companies conduct a structured review of their investment portfolio, they are approximately 40% faster at monitoring ownership structures (Goldright empirical data).

Taken together, these five key metrics paint a consistent picture: The problem rarely lies in a lack of awareness of the importance of legal entity management, but rather in the gap between aspirations and actual structural implementation.

Legal Entity Management by Industry: What Matters

The urgency of legal entity management varies significantly by industry, even though the underlying root causes are usually the same.

In the financial sector, the focus is on documented, regulatory-compliant investment structures: Banks and capital market participants must comprehensively map complex, cross-border corporate structures, monitor mandates, and meet regulatory requirements such as KYC and anti-money laundering. Fragmented customer data spread across multiple silos further complicates the ability to maintain a comprehensive overview of risks and ownership structures.

In industrial and mechanical engineering, the pressure to act typically stems from organic growth and acquisition strategies: New plants, sales subsidiaries, and joint ventures are added without governance processes automatically scaling up to accommodate them. This makes it difficult to maintain a unified database across plants and national borders and delays the integration of new locations into the corporate structure.

In the energy and utilities sector, the landscape is characterized by extensive infrastructure networks, numerous joint ventures, and fluctuating ownership stakes. Tracking complex legal relationships between network operators and partnerships poses particular challenges for investment management teams, especially when it comes to maintaining complete documentation for regulatory oversight and ESG reporting.

The insurance industry often struggles to maintain an overview of highly complex, international corporate structures: Contracts and documents are stored in decentralized local silos, reconstructing historical ownership structures requires a significant amount of manual effort, and incomplete documentation of corporate bodies and elected officials jeopardizes effective governance.

Finally, in the real estate industry, the lack of clarity in highly complex ownership structures makes it difficult to identify beneficial owners (UBOs) and to carry out transactions quickly—any delay in verifying ownership structures can slow down or jeopardize a deal.

As varied as the starting points may be across different industries, the underlying answer is the same in all five cases—a centralized, historized legal entity management system provides the transparency required for operational decisions, regulatory reporting, and transactions alike.

The Four Root Causes of Poor Legal Entity Management

Anyone who takes the above figures seriously will inevitably ask why mature companies with experienced legal departments fail at what appears to be an administrative task. The answer rarely lies in a lack of expertise. Legal, compliance, and finance teams generally understand very clearly what data they need and why. The real problem runs deeper, in the way this data is generated, maintained, and shared within the organization. In practice, most gaps can be traced back to four recurring causes, each of which is problematic on its own but particularly damaging when combined.

1. Distributed master data without a single source of truth.

In practice, corporate data is often stored in parallel in Excel spreadsheets maintained by the legal department, in the finance department’s ERP system, in local files at individual subsidiaries, and in the minds of long-tenured employees. Without a common data source—a so-called “single source of truth”—these data sets almost inevitably contradict one another. Every new inquiry from the audit, tax, or regulatory departments then triggers yet another manual search. In practice, this means that three departments provide three different answers to the same question about the ownership stake in a subsidiary, and no one can say right away which one is correct.

2. Lack of historical data.

Most Excel-based solutions only reflect the current status. Anyone who wants to know what the ownership structure looked like two years ago or when a specific engagement began must search through email archives and old file versions. For audits, consolidation, and regulatory reporting, however, a reconstruction accurate to a specific reporting date is absolutely essential. This becomes particularly critical in the case of related-party transactions or consolidation issues, where the historical status as of a specific balance sheet date must be documented—not the current status.

3. Unclear responsibilities for maintenance and approval.

Often, there are no clear rules regarding who is authorized to make changes to ownership data, who reviews them, and who approves them. This leads either to gridlock because no one feels responsible, or to uncontrolled changes without the dual-control principle—both of which are problematic from a governance perspective. In many organizations, this gap only becomes apparent when an employee who was informally responsible for maintaining the data leaves the company, taking with them a significant portion of the tacit knowledge about the ownership structure.

4. System Disconnects Between Legal, Tax, Finance, and Compliance.

Each function typically maintains its own view of the same companies: Legal maintains lists of shareholders, Tax manages tax structures, Finance consolidates financial statements in accordance with IFRS, and Compliance documents mandates. Without documented interfaces, data is entered twice, and discrepancies often go unnoticed until an audit—the worst possible time. McKinsey’s observation that 42% of companies rate their IT and GRC system landscape as in need of improvement aligns exactly with this pattern.

These four causes explain why mere digitization—such as a nicer Excel template or a SharePoint folder—does not solve the underlying problem. It merely shifts it to a different format. A nicely formatted Excel sheet is still just an Excel sheet: It doesn’t automatically maintain a history, doesn’t enforce the dual-control principle, and doesn’t synchronize with the ERP system. The four root causes lie deeper, in the organization and in process design—and that is precisely where the solution must begin.

Not an IT Problem, but a Governance Problem

Many companies treat gaps in legal entity management as a technical data storage issue and look for a solution in a new tool. That falls short. The four root causes show that the real problem lies in governance—that is, in responsibilities, processes, and approval workflows—not in a missing data field. To put it another way: It’s rarely a matter of asking, “What tool do we need?” but rather, first and foremost, “Who is actually responsible if an ownership stake changes tomorrow—and how does that person know they need to be notified?”

A system alone does not ensure audit-compliant legal entity management if no one has defined who maintains master data, how changes are approved, and how often the structure is reviewed. Conversely, even the best governance structure remains theoretical if it is not enforced by a system that technically mandates audit trails, roles, and approvals. A sustainable solution therefore combines organizational clarity with a system that ensures this clarity in day-to-day operations.

This distinction has direct consequences for how projects are prioritized. Companies that select a tool first and only then consider roles and processes regularly find that the implementation stalls—not because of the software, but because unresolved organizational issues suddenly come to the fore, for which there are no quick answers. In contrast, those who clarify governance issues first (Who is responsible? Who approves? What are the escalation levels?) can make the subsequent system implementation significantly faster and smoother, because the system merely reflects these decisions that have already been made, rather than enforcing them.

Solution Approach: Five Steps to Audit-Compliant Investment Management

Based on practical experience from more than 30 legal entity management projects, a recurring approach can be derived that specifically addresses the four root causes. The approach is deliberately iterative: Instead of implementing a perfect system all at once, each step creates independent value that the next step builds upon. This reduces project risk and generates early, visible progress that secures internal support for the subsequent steps.

Step 1: Take stock of all companies, investments, and mandates.

The first step is a comprehensive inventory: Which companies, branches, and equity interests exist? What are the direct and indirect ownership stakes? Who are the current mandate holders? This inventory typically reveals the most glaring gaps—such as companies that are no longer listed in any central registry, or mandates whose terms have long since expired. It is recommended to conduct this inventory in collaboration with Legal, Compliance, Tax, and the relevant business units, as differing perspectives across departments often yield the most valuable insights.

Step 2: Establish a central, cross-system master data record.

Instead of parallel Excel lists, a single reference record is created for each company, containing the name, registered office, legal form, identifiers (such as LEI), and links to all equity interests. This “golden record” becomes the authoritative source for Legal, Tax, Finance, and Compliance. All other systems reference this dataset instead of maintaining their own parallel versions—this is precisely what distinguishes a true single source of truth from yet another siloed solution.

Step 3: Implement historical tracking and an audit trail.

Every change to master data or ownership structures is fully logged: who made the change, when, and what was changed. This makes it possible to reconstruct an ownership structure as of any past date—a core requirement of every audit. This point-in-time historical tracking also makes it possible to automatically generate organizational charts and ownership structure diagrams for any desired reference date, rather than having to redraw them manually.

Step 4: Formalize responsibilities and approval processes.

For each company, it is defined who is authorized to maintain master data, who is authorized to review it, and who is authorized to approve it. A dual-control principle with a documented workflow prevents both stagnation and uncontrolled changes. In practice, it is advisable to assign these roles not only to individuals but also to functions—this ensures that accountability is maintained even during personnel changes without having to redesign the entire role concept.

Step 5: Automated deadline management and system integration.

Legal reporting and disclosure requirements—such as commercial registry entries, regulatory filings, or consolidated reporting—are accompanied by automatic reminders. Documented interfaces with ERP, CRM, and reporting systems eliminate the need for manual double-entry. This approach pays off particularly well in regulated industries such as banking and insurance, where additional reporting thresholds—such as those for significant equity interests—must be continuously monitored.

The order is crucial: governance clarity (steps 1, 2, and 4) must come before technical automation (step 5). An automated process based on unclear responsibilities merely automates the chaos. Companies that reverse this order regularly report frustration in their project experience: The new software works flawlessly from a technical standpoint but continues to produce contradictory results because the underlying data and process issues remain unresolved.

Where does your legal entity management stand today?

The 2026 Legal Entity Audit Check assesses your audit readiness through 10 questions across five dimensions—master data, historical data, governing bodies, regulatory compliance, and automation. Developed based on over 20 years of practical experience and real-world projects at more than 30 companies.

  • 9-page practical guide as a ready-to-use PDF

  • Prioritized recommendations for action based on your score

  • 100% free

Best Practices: What Really Works in Practice

Not every theoretically sound solution stands up to the test of practice. There is often a crucial difference between a well-documented five-step plan and an engagement management system that actually works in everyday life: the details of implementation. Seven best practices have emerged from completed projects that make the biggest difference—regardless of whether a company manages ten or several hundred subsidiaries.

One “Golden Record” Instead of Many “Truths.”

Each subsidiary should have exactly one authoritative master data record that all departments can access—not five copies that are reconciled as needed. Reconciliation is error-prone; a single point of reference is not. Companies that consistently implement this principle report that a large portion of recurring back-and-forth between Legal, Tax, and Finance simply disappears because everyone involved is looking at the same data source.

Historical Data from the Start, Not Retroactively.

Systems that are retrofitted with a history function only after implementation usually have gaps in their historical data. Those who plan for historical data tracking from the start can report retroactively without gaps. This is particularly true for point-in-time reporting, where auditors or regulatory authorities want to view a past state rather than the current one.

Define roles before functions.

Before selecting a system, it should be clearly established who is technically responsible for which company. This prevents the system implementation from turning into a belated organizational debate. Experience shows that this step is the most underestimated in the entire project—and at the same time, the one that has the greatest impact on long-term success.

Link committee and term data to deadline management.

The terms of office for board members, supervisory board members, and managing directors expire independently of the calendar year. Automated deadline management that sends timely reminders before expiration prevents governance gaps caused by expired terms—a risk that is surprisingly often underestimated in practice because term durations are rarely monitored centrally.

Link documents directly to the company.

Shareholder agreements, minutes, and powers of attorney should not be stored in a separate document repository but should be linked directly to the respective company record. This significantly reduces search time during audits and ensures that no one has to maintain a separate, outdated document index.

Interfaces Instead of Duplicate Data Entry.

Whenever possible, legal entity data should be integrated with ERP, CRM, and reporting systems via documented APIs. Any manual double entry is an additional source of error and a waste of time. Bidirectional interfaces also ensure that changes do not flow in only one direction, but that systems keep each other up to date.

Regular benchmarking against market standards.

Companies that already manage their legal entity management at an advanced level benefit from periodically comparing themselves with peer companies and industry best practices. This makes it clear whether their own level of maturity is actually keeping pace with growing regulatory requirements.

These best practices already have a noticeable impact individually. However, they only achieve their full effect when working together—which is precisely what a dedicated legal entity management system does by consolidating master data, historical records, governance body management, documents, and interfaces into a single platform, rather than distributing them across multiple standalone solutions.

Excel, Siloed Solutions, or a Legal Entity Management System?

Choosing the right approach depends on the size of the company, the number of subsidiaries, and regulatory pressure. Many companies navigate between these three approaches: They start with Excel, add ad hoc standalone solutions for specific areas—such as committee management or deadline tracking—as needs grow, and eventually reach the limits of this fragmented landscape. The following overview compares the three most common approaches in practice based on criteria critical to audit readiness.

Criterion

Excel spreadsheets & file folders

Domain-specific standalone solution (e.g., tool for committee management only)

Centralized legal entity management system

Central Data Source

No — multiple parallel versions

Partially — only for the respective subarea

Yes — one golden record per company

Historical Data / Audit Trail

Virtually nonexistent

Usually only rudimentary

Complete, accurate as of the reporting date

Create an organizational chart as of a specific date

Manual, time-consuming

Rarely possible

At the click of a button

Deadline Management for Committees & Reports

Manual, prone to errors

Partially automated

Automated with reminders

Interfaces to ERP/CRM/Reporting

Not available

Rarely documented

Documented APIs

Scalability in M&A Growth

Very Low

Medium

High

Audit Effort

High; often requires retroactive data entry

Medium

Low; provides information directly

Typical Risk

Incorrect or late reports

Fragmented partial truths

Lowest risk when implemented correctly

 

The table makes it clear: Standalone solutions often address only one aspect (such as committee management alone) without resolving the underlying master data issues. Only a centralized system that integrates master data, historical data, committees, and interfaces can simultaneously address all four root causes described above.

In practice, this does not mean that every company needs a fully integrated system right away. A company with three stable subsidiaries and little regulatory pressure can get by temporarily with a well-maintained, historized Excel solution. However, as soon as the number of subsidiaries reaches double digits, the structure changes regularly due to M&A activity, or regulatory reporting requirements are added—for example, in the financial, insurance, or energy sectors—the cost-benefit analysis clearly tips in favor of a centralized system. The effort required for recurring manual reconstruction then quickly exceeds the cost of a structured solution.

Regulatory Outlook: Why the Pressure Continues to Mount

The trend toward greater transparency requirements regarding corporate structures is likely to intensify rather than ease in the coming years. Gartner's forecast of a 50 percent increase in investment in governance, risk, and compliance tools by the end of 2026 is not an isolated phenomenon, but rather a reflection of a broader regulatory trend: Regulatory authorities worldwide are increasingly demanding comprehensive documentation of control relationships, beneficial owners, and corporate group structures—not least in response to stricter anti-money laundering and sanctions regimes.

The growing importance of sustainability reporting is also driving this trend: ESG reporting requirements increasingly demand granular data at the level of individual companies and investments, not just at the corporate group level. Companies that already maintain their investment structure centrally and with historical data can meet such new requirements with significantly less additional effort than companies that continue to rely on distributed Excel spreadsheets. Investing in a robust foundation today not only reduces current audit risk but also prepares companies for the foreseeable increase in regulatory requirements in the coming years.

Practical Case Study: How an International Industrial Group Reduced Its Audit Preparation Time from Weeks to Days

An anonymized real-world example that is representative of many medium-sized and large companies with international holdings: A manufacturing conglomerate with several dozen subsidiaries in Europe and overseas managed its ownership structure for years using a combination of centralized Excel spreadsheets and local files maintained by the respective national subsidiaries.

Whenever an external audit took place—whether by the external auditor, the group’s internal audit department, or in response to a regulatory inquiry—the legal department and group controlling first had to painstakingly reconstruct the ownership structure from various sources. Creating an up-to-date organizational chart as of a past reporting date required days of manual research in email archives. Responsibilities for data maintenance were not formally documented, which meant that changes to ownership stakes were sometimes not discovered until weeks later. During an M&A transaction in a neighboring European country, it also came to light that two subsidiaries had been recorded with conflicting ownership stake figures since an internal restructuring years earlier—an error that was discovered only by chance before the transaction was finalized.

The catalyst for the subsequent project was an upcoming group audit, during which it was foreseeable that the previous approach would require several weeks of lead time. As part of a structured legal entity management project, all companies, investments, and mandates were first recorded in a joint inventory by the Legal, Tax, and Group Controlling departments and transferred to a central, historical system. Responsibilities for master data maintenance were clearly assigned for each company, approval processes based on the dual-control principle were introduced, and the legal entity data was linked to the existing ERP system via documented interfaces. The migration of historical data was deliberately carried out in a separate data cleansing sprint to ensure that inconsistent legacy data was not carried over unchanged.

The result: The delivery of structure-related data for finance, risk, and regulatory reports accelerated by about 40 percent compared to the previous, manual process—a finding that has been repeatedly confirmed in comparable projects in the finance, insurance, and real estate industries (Goldright project data). Since then, organizational charts can be generated at the push of a button for any given reporting date, and audit requests are answered without days of manual data entry. The legal department also reported a noticeable decline in recurring inquiries from Finance and Tax, as both functions now access the same dataset instead of maintaining their own parallel lists.

This case exemplifies what the studies cited at the beginning also confirm: The bottleneck rarely lies in a lack of will, but rather in a lack of structural foundation. Once this foundation is in place, the role of investment management shifts noticeably—from a reactive “firefighting” function ahead of every audit to a reliable, continuously up-to-date source of information for strategy, risk, and finance.

Pitfalls: What to Avoid When Setting Up Investment Management

Even well-intentioned projects fail due to the same recurring mistakes. The following pitfalls are particularly common in real-world project practice—and can usually be avoided without significant additional effort by exercising a little foresight during project planning.

Treating the implementation as a purely IT project.

Without involving Legal, Compliance, and the relevant business units from the very beginning, the result is a system that fails to address the realities of data maintenance. The Legal Entity Audit Check 2026 explicitly recommends involving legal, compliance, and business units jointly, as differing perspectives across departments often yield the most valuable insights. If this step is skipped, the result is systems that work on paper but are circumvented in day-to-day operations.

Treating historical data tracking as a “nice-to-have” to be added later.

If the history function is added only after go-live, retroactive data for earlier cut-off dates will be missing—precisely the data that is often needed during an audit. Reconstructing this data retroactively is then often just as time-consuming as in the old Excel-based process, except that additional time has now been invested in the system implementation without resolving the actual pain point.

Migration without prior data cleansing.

Transferring incorrect or inconsistent legacy data into a new system without modification merely shifts the problem rather than solving it. A data cleansing sprint before migration pays off in the long run, even if it delays the project start by a few weeks. The alternative—an “uncleaned” migration followed by corrections during live operations—typically costs significantly more time because errors must then be fixed in the production system.

Lack of accountability for data maintenance after go-live.

A new system does not replace an organization. Without clearly designated owners for each company, data maintenance is neglected within a few months, and the new system degenerates into a more expensive version of the old Excel spreadsheet—technically superior, but just as outdated.

Trying to automate everything at once.

Attempting to automate all reporting processes and interfaces simultaneously often overwhelms project teams and leads to lengthy project timelines without visible interim results. Successful projects, on the other hand, prioritize the two or three largest gaps first, thereby achieving early, visible successes that build internal support for subsequent expansion phases.

Underestimating the compliance requirements of individual industries.

Specific regulatory requirements apply particularly in the financial and insurance sectors—such as the reporting obligations for significant holdings under Section 24 of the German Banking Act (KWG), the holding thresholds of 20%, 30%, and 50% of voting rights or capital—as well as BaFin outsourcing regulations and CRR definitions of significant holdings or close ties. A system that does not account for these reporting thresholds creates a false sense of security: It appears complete but does not meet industry-specific requirements.

Underestimating the effort required for change management.

Even the best system from a technical standpoint will fail if employees at the national subsidiaries continue to maintain their familiar Excel spreadsheets in parallel. Clear communication about why the transition is necessary and a realistic timeline for adapting to new processes are therefore just as important as the technical implementation itself. Experience has shown that it helps to identify one or two advocates early on in the affected subsidiaries who can model the new process in their day-to-day work and answer questions firsthand—this fosters greater acceptance than any central communication effort alone.

Before your next audit: Do you know your blind spots?

In just 15 minutes, use 10 targeted questions to assess how audit-ready your legal entity management really is—and receive specific recommendations tailored to your results.

  • 9-page practical guide as a ready-to-use PDF

  • Prioritized recommendations for action based on your score

  • 100% free

Conclusion: Legal entity management is audit preparation that takes place every day

Legal entity management does not determine success or failure on the day of the audit, but rather every day leading up to it. The numbers are clear: 89% of companies struggle with the complexity of their investment structures, nearly one-third lack a robust governance process, and even companies with established GRC functions rate their own risk and compliance maturity at an average of only 2.6 to 2.9 out of 4.0 points, according to McKinsey. The good news is that this gap can be traced back to four clearly identifiable causes—distributed master data, a lack of historical tracking, unclear responsibilities, and system silos between Legal, Tax, and Finance.

Those who systematically address these four causes—with a central “golden record,” complete historical data, clear approval processes, and documented interfaces—transform investment management from a recurring source of stress into a strategic foundation for reporting, M&A, and regulatory compliance. The crucial first step is not changing systems, but taking an honest look at your own status quo: Which of the five dimensions—master data, historical data, governing bodies, regulatory compliance, and automation—are already robust, and which pose the greatest risk for the next audit?

No company reaches this point overnight, nor does it need to. The key is to be realistic about where you stand and to focus on closing the biggest gaps first—rather than being caught off guard by the next audit.

Frequently asked question about Legal Entity Management

Legal Entity management is the centralized administration of all companies, equity interests, mandates, and reporting obligations of a corporation. It answers the questions of who owns which company and what percentage, who represents it, and what legal obligations are associated with it. Put simply, investment management is a corporate group’s “memory” for its own legal structure—those who master it can respond reliably and quickly to inquiries.
Beteiligungsmanagement is the term commonly used in German-speaking countries, while legal entity management (LEM) is the international term for the same field of activity. In terms of content, the two terms are largely synonymous: They encompass master data, ownership structures, governing bodies, reporting, and document management for legal entities. In international corporations, both terms are often used interchangeably, de
Legal Entity Management maps out the legal and organizational structure of companies (shares, board seats, reporting requirements). Investment controlling focuses on the financial management of these investments, for example through key performance indicators, budgets, and performance. In practice, both disciplines build on each other: Without accurate investment master data, robust investment controlling cannot be carried out, because KPIs must always refer to specific, correctly defined companies.
Key responsibilities include maintaining corporate master data, documenting shareholdings and control relationships, managing corporate bodies and mandates, fulfilling statutory reporting and disclosure obligations, and linking relevant documents to the respective company. In addition, there are operational tasks such as preparing shareholder meetings, providing support for company formations, conversions, and liquidations, and ongoing coordination with Tax, Finance, and Compliance.
Depending on the organization, responsibility lies with the legal department, group controlling, a corporate secretary function, or a combination of legal, tax, and compliance. It is crucial that responsibilities are clearly documented for each company—regardless of which department is formally in charge. In larger corporate groups, a dedicated legal entity management function is increasingly being established to serve as the central interface between the relevant departments.
Manual spreadsheets are prone to errors, lack version control, and are difficult to keep up to date. As corporate structures grow, this leads to conflicting data, missed deadlines, and a lack of traceability—all of which pose a compliance risk. A centralized LEM platform validates data, logs every change, and provides a comprehensive, audit-ready overview.
The market offers both standalone solutions for specific aspects (e.g., committee management) and integrated legal entity management systems that collectively handle master data, historical records, committees, and regulatory reporting. Goldrights Legal Entity Manager is an example of such an integrated approach. When making a selection, it’s worth considering whether a solution truly covers all five dimensions—master data, historical data, governing bodies, regulatory compliance, and automation.
Depending on the industry and legal form, these include, among other things, commercial registry entries, group reporting, and—in the financial sector—reporting obligations under Section 24 of the German Banking Act (KWG). In the insurance and real estate sectors, UBO identification and related-party disclosures also apply. Which specific obligations apply depends on the legal form, industry, and country of incorporation and requires a legal review on a case-by-case basis.
Continuous updates whenever changes occur are preferable to periodic reviews. In addition, it is recommended to perform at least one full reconciliation per year with registry data and external sources to identify discrepancies early on. Companies with a high frequency of M&A activity or those in highly regulated industries should perform this reconciliation more frequently—for example, quarterly—to ensure reliable compliance with reporting deadlines.
The duration depends on the number of companies and the initial state of the data. The first visible results—such as a cleaned-up central master data sheet—can often be achieved within a few weeks, while full integration, including historical data and interfaces, can take several months. A phased approach that starts with the largest gaps typically delivers visible benefits more quickly than attempting to roll out all dimensions at once.
The costs are rarely immediately apparent, but they manifest as time lost during audits, the effort required for retroactive data entry and delayed reporting—and, in the worst-case scenario, fines or delayed transactions. According to IBM, more than a quarter of companies lose more than $5 million annually due to poor data quality, with investment data accounting for a significant portion of this. Added to this are harder to quantify consequences such as slowed M&A processes and reputation loss.
Master Data Management is the overarching approach to managing all types of corporate master data—such as customers, suppliers, products, and materials. Legal Entity Management is a specialized form of this that focuses exclusively on legal entities, equity interests, and organizational structures.
Centralized, validated data with a complete change history and timestamps provide an audit-proof view of ownership interests. Auditors and stakeholders receive evidence accurate as of the reporting date, and governance rules are enforced by the system—which reduces the effort and risk associated with audits.

Sources

EY & Harvard Law School Center on the Legal Profession: "The General Counsel Imperative — How can you evolve entity management into effective governance?" - ey.com / PDF via Harvard Law School

Association of Corporate Counsel (ACC) & Deloitte: "Legal Entity Management Report" - acc.com

McKinsey & Company: "Governance, risk, and compliance: A new lens on best practices" - mckinsey.com

Gartner, Inc.: "Gartner Predicts Legal and Compliance Department Investment in Governance, Risk, and Compliance Tools Will Increase 50% by 2026" - gartner.com

IBM: "The True Cost of Poor Data Quality" - ibm.com

Bitkom e. V.: "Jedes zweite Unternehmen tut sich schwer mit der Digitalisierung" - bitkom.org

PwC: "Entity Governance and Compliance" - pwc.com

Gesetze im Internet (Bundesministerium der Justiz): "§ 24 Kreditwesengesetz (KWG) — Anzeigepflichten der Institute" - gesetze-im-internet.de