Aprovall
  • Platform
  • Solutions
    • Purchasing
    • Finance
    • Compliance
    • CSR & ESG
    • Legal
    • Cybersecurity
  • Success
  • Ressources
    • Our webinars
    • Our articles
    • Our news
English
  • English
  • Français
Login
Request a demo

Home | Our articles | TPRM&TPGRC

  • TPRM&TPGRC

Post-Merger GRC Integration: The Hidden Risks of Fragmented Compliance Tools

Introduction: The Illusion of Coverage Through Accumulation

There is a phenomenon well known to Risk Management and Compliance teams in post-acquisition organisations: tool proliferation. Every absorbed entity brings its own systems — its ERP, its document management tool, its internal control platform, its supplier repository. With each acquisition, the application landscape grows another layer.

Five years into an active acquisition programme, some groups find themselves managing their GRC (Governance, Risk, Compliance) across fifteen, twenty, or even thirty distinct tools.

The paradox is striking: these organisations believe they are better covered because they have more tools. In reality, they are more exposed — because their data is fragmented, their processes are inconsistent, and their view of risk is partial.

Twenty tools that do not communicate with each other produce twenty partial blind spots whose combined effect is far more dangerous than a single imperfect but coherent system.

What is GRC fragmentation?

GRC fragmentation occurs when governance, risk, compliance and supplier management activities are managed across multiple disconnected systems, preventing organisations from maintaining a single, reliable view of risk, compliance status and third-party information.

This is not unique to post-acquisition groups. But mergers and acquisitions amplify and accelerate it in a characteristic way — because they bring together, under a single legal and regulatory entity, heterogeneous supplier portfolios, different risk management cultures, and incompatible information systems.

All of this typically happens under significant calendar pressure. Organisations are pushed to integrate quickly rather than integrate well, creating the conditions for long-term GRC fragmentation.

The Business Risks of Fragmented GRC Systems After an Acquisition

GRC tool fragmentation in a post-acquisition group is not an organisational inconvenience — it is a generator of concrete, measurable risks.

Risk 1: Risk Decisions Made on Incomplete Data

The first risk is epistemic. When supplier data is spread across fifteen distinct systems, no decision-maker has a complete picture.

The Procurement Director sees performance data. The Compliance Manager sees regulatory alerts. The CFO sees financial data. But no one sees all three simultaneously.

As a result, the correlation between a financial deterioration, an emerging documentary non-compliance, and a quality performance decline at the same supplier often goes unnoticed until the failure occurs.

Hutchinson experienced this reality before its transformation. With fifteen unsynchronised supplier databases spread across Procurement, Finance and industrial systems, the group faced permanent data discrepancies. Each department held its own version of the truth about the same suppliers, with no reliable way to reconcile them.

The decision to make Ivalua the group’s master supplier repository and integrate Aprovall into it was not an IT project. It was a governance decision: creating the conditions for a shared view of supplier risk accessible to Procurement, Finance and IT simultaneously.

Risk 2: Regulatory Compliance That Cannot Be Demonstrated

The second risk is evidentiary.

In a merger and acquisition context, regulatory obligations apply to the consolidated entity — not to pre-acquisition entities in isolation. The French Duty of Vigilance, Sapin 2, and the CSRD all reason in terms of the group, the consolidation perimeter, and the integrated value chain.

An organisation that manages compliance through tools fragmented by entity cannot produce credible consolidated reporting.

It may be able to demonstrate that each individual entity met a given standard. What it cannot easily demonstrate is that the group as a whole exercised due diligence across its entire supplier portfolio.

Yet this consolidated demonstration is precisely what regulators and auditors increasingly require.

Eiffage, with 70,000 suppliers and subcontractors spread across dozens of business lines and entities, illustrates this challenge at scale. Before centralising documentary collection through Aprovall integrated into Ivalua, each group entity was collecting the same information from the same suppliers using different tools.

Without sharing. Without consolidation. Without group-level visibility.

Compliance existed in silos. Group reporting did not.

Risk 3: A Degraded Supplier Experience That Signals Internal Disorder

The third risk is relational — and frequently underestimated.

A supplier working with several entities of a post-acquisition group may receive redundant documentary requests, inconsistent questionnaires, and communications from multiple uncoordinated contacts.

For the supplier, the conclusion is immediate: this group is poorly organised.

That perception has tangible consequences. It influences the priority suppliers assign to compliance requests, the quality of responses they provide to ESG or due diligence questionnaires, and their willingness to proactively raise emerging risks rather than manage them quietly.

Over time, supplier engagement deteriorates.

GRC fragmentation therefore creates more than an internal governance problem. It weakens the quality of supplier relationships and, in turn, the quality of the information on which risk management depends.

When suppliers experience disorder, organisations should not be surprised when visibility into supplier risk declines as well.

Risk 4: An Enlarged Attack Surface for Fraud

The fourth risk is financial and security-related.

Fragmented systems mechanically create control gaps — spaces between tools where verifications do not occur, where data is not cross-checked, and where anomalies fail to trigger alerts.

These gaps are rarely visible until they are exploited.

They are also the preferred entry points for payment fraud, supplier identity theft, and attempts to manipulate approval workflows.

In a post-acquisition environment, where processes are still being harmonised and responsibilities are often distributed across multiple entities, the number of these gaps tends to increase rather than decrease.

SPL Lyon Part-Dieu is not a post-acquisition group, but its experience illustrates the mechanism clearly. Before integrating Aprovall and Sis ID, the absence of automated bank account verification and the lack of task separation in the payment chain created precisely this type of vulnerability.

The result nearly cost the organisation €1.7 million in fraud.

In post-acquisition groups, where multiple systems and control frameworks coexist, these vulnerabilities multiply — often without being detected until an incident occurs.

The Four Risks of GRC Fragmentation After an Acquisition

RiskConsequence
Incomplete risk visibilityDecision-makers operate with partial supplier information and miss emerging correlations.
Weak compliance evidenceConsolidated regulatory reporting becomes difficult or impossible to produce.
Poor supplier experienceSuppliers receive duplicate requests and inconsistent communications.
Increased fraud exposureControl gaps emerge between disconnected systems and processes.

Why Mergers and Acquisitions Amplify the Problem

M&A activity creates three conditions that transform GRC fragmentation from a latent risk into an acute one.

Time pressure

Post-acquisition integrations happen under calendar constraints. IT teams are overloaded. Priorities lie with operational continuity, not with rationalising compliance tools. The target’s systems are kept running in parallel with the acquirer’s, with a promise to “rationalise later.” That later frequently becomes never.

Cultural heterogeneity

Two merging organisations do not only have different tools — they have different risk management cultures. What is treated as a critical risk in the acquirer may be managed informally in the target, and vice versa. Without process and standards harmonisation, tool fragmentation is compounded by practice fragmentation — which is even more dangerous.

Extended regulatory perimeter

Every acquisition extends the regulatory obligation perimeter. A group acquiring an entity operating in a new geography inherits its local compliance obligations. A group that exceeds a revenue or headcount threshold may fall under new obligations — the Duty of Vigilance, CSRD reporting. These regulatory extensions often occur in a context where GRC tools are not yet integrated, creating a particularly exposed window of vulnerability.

How to Build a Unified GRC Architecture After an Acquisition

The response to post-acquisition GRC fragmentation is not to eliminate all existing tools and impose a single one.

That approach typically encounters resistance from entities that have invested heavily in their systems, processes and working habits.

Instead, the objective is to build a layered architecture that preserves business-specific tools while creating a common data and compliance layer across the group.

The Hutchinson × Ivalua × Aprovall model illustrates this architecture clearly.

  • Ivalua forms the common SRM layer, acting as the single supplier repository shared across all group entities.
  • Aprovall forms the compliance layer, collecting, controlling and versioning supplier documents consistently across the organisation.
  • Entity-specific operational tools remain in place, but feed a common repository and follow harmonised compliance standards.

The result is a model that balances local autonomy with group-wide visibility.

This architectural principle — a master repository, respected business tools, and a common compliance layer — is exactly what the Eiffage case deployed across 11,000 third parties in three months, achieving an 88% activation rate.

The speed of deployment and level of adoption demonstrate that rationalisation does not require organisations to disrupt established working habits. It requires them to connect those habits through a coherent governance architecture.

Fragmented vs Unified GRC Architecture

Fragmented GRC EnvironmentUnified GRC Environment
Multiple supplier repositoriesSingle supplier source of truth
Different compliance processes by entityHarmonised compliance framework
Duplicate supplier requestsCentralised document collection
Entity-level reporting onlyConsolidated group reporting
Control gaps between systemsStandardised controls and workflows
Inconsistent supplier dataShared, governed supplier data
Limited visibility into emerging risksGroup-wide supplier risk view
Higher administrative burdenGreater operational efficiency

What Executives Expect From a Post-Acquisition GRC Architecture

In a post-acquisition organisation, executive expectations of GRC are particularly precise — and particularly urgent.

The CEO wants a consolidated view of supplier risk

They have acquired an entity with its supplier portfolio, its dependencies, and its risks. They want to know quickly which of the target’s suppliers are critical, which are compliant, and which present risks the acquirer had not anticipated. This view cannot be produced if data remains fragmented between the target’s systems and the acquirer’s.

The CFO wants compliance that is demonstrable at the consolidated level

They know that regulators reason in terms of the consolidated entity. They need to be able to produce, on demand, a report that covers the entire perimeter — not a collection of entity-level reports that no one can rapidly consolidate.

The Chief Compliance Officer wants standards harmonisation

They cannot guarantee that the group complies with anti-corruption regulations if certain entities apply different standards based on their historical practices. Process harmonisation requires tool harmonisation — or at minimum a common layer that imposes the same standards across all entities.

Moët Hennessy addressed this challenge for 27 maisons with strong individual identities by co-constructing a KYS platform that imposes a common framework while preserving each maison’s operational autonomy. The tension between group standardisation and entity autonomy — the heart of the post-acquisition challenge — finds a pragmatic, documented answer there.

Five Questions Before Rationalising Your GRC Environment

For organisations that recognise the GRC fragmentation problem and wish to engage a rationalisation effort, five questions structure the initial diagnostic.

How many distinct supplier repositories coexist across the group? The answer to this question alone says a great deal about the level of fragmentation and the scale of consolidation work required.

What is the overlap rate between the supplier portfolios of different entities? A supplier present in six entities without shared data is solicited six times for the same information. This overlap rate directly measures the unnecessary pressure placed on suppliers.

Can a consolidated supplier compliance report be produced in under 48 hours? If the answer is no, fragmentation is already an active regulatory risk.

Where are the control gaps in the payment chain? Have payment approval processes been harmonised since the acquisition, or do they still coexist with their respective rules and exceptions?

What new regulatory obligations has the acquisition created? The answer to this question determines the urgency of rationalisation — and the consequences of inaction.

How to Start Rationalising GRC After an Acquisition

Recognising fragmentation is one thing. Addressing it requires a structured approach.

Organisations that successfully rationalise post-acquisition GRC environments rarely begin by replacing every existing system. Instead, they focus first on visibility, governance and standardisation.

Three priorities typically come first:

1. Establish a single supplier source of truth

Before processes can be harmonised, organisations need a common repository that identifies suppliers consistently across all acquired entities. Without this foundation, reporting, due diligence and risk monitoring remain fragmented.

2. Standardise compliance requirements across entities

Acquisitions often bring different risk management practices, document requirements and approval workflows. Defining a common compliance framework creates consistency while allowing entities to retain operational autonomy where appropriate.

3. Identify the highest-risk integration gaps

Not every system needs to be integrated immediately. Priority should be given to areas where fragmentation creates the greatest exposure — supplier onboarding, documentary compliance, payment controls and third-party risk monitoring.

The objective is not immediate tool replacement. It is creating a common governance layer that allows the group to manage risk consistently while integration progresses.

Conclusion: GRC Rationalisation Is a Strategic Decision, Not an IT Project

GRC tool fragmentation in post-acquisition groups is often perceived as a technical problem — to be resolved when IT teams have bandwidth, after more urgent matters have been addressed.

This perception is itself the source of the problem. GRC rationalisation is not an IT project. It is a strategic decision that determines the group’s ability to demonstrate its compliance, manage its supplier risks coherently, and protect its reputation and operational continuity.

Hutchinson, Eiffage, Moët Hennessy: three organisations that made this strategic decision — consolidate the repository, create the common compliance layer, unify the supplier risk view — and that now measure the benefits in terms of operational efficiency, data quality, and regulatory credibility.

Twenty fragmented tools do not make a GRC policy. They make twenty blind spots. And in an increasingly demanding regulatory environment, every blind spot is a risk the group carries — often without knowing it.

This article is part of a series exploring best practices in third-party risk management. The Hutchinson, Eiffage, Moët Hennessy, and SPL Lyon Part-Dieu cases illustrate different facets of supplier data rationalisation and large-scale third-party risk governance.

Book a meeting at our booth

Don’t miss this opportunity to connect with our team, see our solutions in action, and discuss how Aprovall can help you drive procurement excellence and stronger supplier risk management.

Book a meeting
Introduction: The Illusion of Coverage Through Accumulation
The Business Risks of Fragmented GRC Systems After an Acquisition
Why Mergers and Acquisitions Amplify the Problem
How to Build a Unified GRC Architecture After an Acquisition
What Executives Expect From a Post-Acquisition GRC Architecture
Five Questions Before Rationalising Your GRC Environment
How to Start Rationalising GRC After an Acquisition
Conclusion: GRC Rationalisation Is a Strategic Decision, Not an IT Project

Share

These articles might interest you

  • Équipe diverse en bureau moderne analysant la gouvernance des tiers à l’échelle européenne, avec repères visuels verts montrant centralisation des données fournisseurs, conformité, cyber, ESG, workflows automatisés et résilience multi-pays.
    09 January 2026
    TPRM&TPGRC
    Why All-in-One TPRM Platforms Are Becoming Essential in Europe
    European companies increasingly rely on a complex network of partners and suppliers. Each new third party enriches this ecosystem but also increases risk. These risks include cyber threats, operational challenges such as financial or ethical risks, and regulatory requirements. Traditional, often fragmented, TPRM solutions are no longer sufficient. That’s why all-in-one TPRM platforms are gaining […]

    Read more

  • TPRM ownership roles: Procurement, IT, Compliance
    23 March 2026
    TPRM&TPGRC
    TPRM ownership: who should own third-party risk management?
    TPRM ownership is rarely a single-team decision. In most organisations, the most resilient model assigns Procurement an operational lead for supplier onboarding, gives IT and security clear authority to validate cyber risk, and uses Compliance and Risk governance to set policy and reporting. Platforms like Aprovall support this operating model at scale for 1,800+ customer […]

    Read more

  • Deux professionnels en bureau moderne analysent une interface transparente de supplier onboarding très marquée par le vert Aprovall, avec étapes de validation, screening conformité, workflow d’approbation, intégration ERP et audit trail.
    20 March 2026
    TPRM&TPGRC
    Supplier Onboarding: Controlled Automation Without Losing Compliance
    Supplier Onboarding: Automate Processes While Preserving Governance Supplier onboarding must balance speed with control. Procurement teams need to onboard vendors faster while ensuring rigorous verification of compliance, banking data, and regulatory exposure. Controlled automation—combining supplier portals, automated screening, workflow approvals, and audit trails—allows organisations to accelerate onboarding while strengthening governance and traceability. Industry research consistently […]

    Read more

  • Supplier risk: team in a bright office reviewing a unified supplier profile with green visual markers for evidence, approvals, monitoring, remediation, and third-party governance in one platform.
    24 April 2026
    TPRM&TPGRC
    Supplier risk: how to centralise third‑party governance in one platform
    Quick Answer Supplier risk grows when third‑party data, assessments, and approvals are split across spreadsheets and disconnected tools. A unified Third‑Party Risk Management (TPRM) and Third‑Party Governance, Risk & Compliance (TPGRC) platform centralises governance, evidence, and workflows so teams share one supplier profile and one audit trail. Platforms like Aprovall are deployed at scale with […]

    Read more

Logo Aprovall

Created in 2008, Aprovall is a French company that develops software for governance, risk management, and continuous evaluation of third-party compliance for its client organizations. This activity is also known by the acronym TPGRC or TPRM.

Platforms
  • Aprovall Manager
  • Aprovall Portal
  • Donneur d'Ordres
Customers
  • Success
Resources
  • Blog
  • News
  • Webinars
  • Glossary
  • Documentation API
Business
  • About us
  • Contact us
  • Career
  • Partner
Follow us
  • Privacy and data protection policy
  • Trust & Compliance Center
  • Legal notice
  • Cookies policy
  • Performance of our services
  • Whistleblowing
  • Vulnerability disclosure policy