Skip to main content
Category: Foundational Concepts

Intragroup Arrangement

Also known as: Intra-group arrangement, Intra-group outsourcing, Intra-group services agreement, Intra-group agreement
Simply put

An intragroup arrangement is an agreement in which one company provides services to another company within the same corporate group. Because both parties belong to the same group, these arrangements are often treated differently from dealings with wholly external providers, though they can still fall within the scope of outsourcing and third-party oversight expectations. Depending on the arrangement, they may cover functions such as centralized compliance, support services, or other operational activities shared across affiliated entities.

Formal definition

An intragroup arrangement refers to the provision of services, functions, or support between companies that are part of the same group of companies, typically documented through an intra-group services agreement between affiliated entities. Where such an arrangement involves the transfer of a function to another group entity, it may be characterized as intra-group outsourcing and can fall within the scope of outsourcing guidelines and oversight requirements, though some frameworks and industry respondents have argued for recognition of the distinct benefits and risk profile of intragroup relationships compared with arrangements with unaffiliated third parties. Common membership in a corporate group does not by itself remove oversight obligations: the receiving entity may still be expected to exercise adequate oversight of the arrangement (for example, a group entity's compliance team overseeing services from a centralized compliance function). The precise regulatory treatment, permissibility, and documentation expectations vary by jurisdiction and sector, and this term addresses the intragroup relationship itself rather than any specific control, verification, or continuity measure applied to it.

Why it matters

Intragroup arrangements matter because affiliation within a corporate group can create a false sense of assurance that formal oversight is unnecessary. Common ownership does not, by itself, remove outsourcing or third-party oversight obligations: a group entity receiving services from a centralized function may still be expected to exercise adequate oversight of that arrangement. Treating intragroup dealings as inherently lower risk without documenting the arrangement and defining responsibilities can leave the receiving entity exposed if the shared function underperforms, is disrupted, or falls short of regulatory expectations applied to the entity itself.

At the same time, industry respondents have argued that frameworks should give appropriate recognition to the distinct benefits and risk profile of intragroup relationships compared with arrangements involving unaffiliated third parties. Because both parties belong to the same group, alignment of interests, shared governance, and consistency of controls can differ from dealings with wholly external providers. The practical challenge for risk and compliance teams is to reflect these differences proportionately without treating group membership as a blanket exemption from oversight.

Regulatory treatment adds a further layer of complexity. Whether an intragroup arrangement is characterized as intra-group outsourcing, and what documentation and oversight expectations attach to it, vary by jurisdiction and sector. An arrangement structured acceptably in one regime may carry different permissibility, notification, or evidentiary requirements in another, so organizations operating across borders cannot assume a single approach will satisfy every applicable authority.

Who it's relevant to

Compliance and Risk Officers at Group Entities
Teams within an entity that receives services from an affiliated company are often expected to exercise adequate oversight of the arrangement even though the provider is part of the same group. This is directly relevant where a centralized compliance or support function serves multiple affiliates, as the receiving entity cannot assume group membership removes its own oversight obligations.
Outsourcing and Vendor Governance Teams
Where an intragroup arrangement involves transferring a function to another group entity, it may be characterized as intra-group outsourcing and fall within the scope of outsourcing guidelines. Governance teams need to determine when such arrangements trigger outsourcing oversight expectations rather than treating them as automatically exempt because the counterparty is an affiliate.
Legal and Contract Teams
Intragroup arrangements are typically documented through an intra-group services agreement between affiliated entities. Legal teams draft and maintain these agreements, including provisions defining the services and, where intended, entire-agreement clauses that supersede prior understandings. They also assess how the arrangement should be characterized under applicable frameworks.
Regulatory and Policy Professionals
Because the permissibility, characterization, and documentation expectations for intragroup arrangements vary by jurisdiction and sector, professionals responding to or interpreting regulatory guidance need to track how frameworks treat these relationships, including industry arguments for recognizing the distinct benefits and risk profile of intragroup relationships relative to unaffiliated third parties.

Inside Intragroup Arrangement

Affiliated Entity Relationship
An intragroup arrangement is a contractual or service relationship between entities within the same corporate group or ownership structure, such as a parent providing shared services to subsidiaries or an affiliate delivering IT, treasury, or operational functions to related entities. It is distinguished from a conventional third-party arrangement by the common ownership or control linking the parties.
Service or Function Scope
The specific activities delivered under the arrangement, which may include shared IT infrastructure, hosting, cybersecurity operations, finance and treasury, HR, procurement, or other centralized functions. The scope should be documented explicitly, as the range of services determines which risk domains (information security, operational, financial, compliance) are engaged.
Formalization and Documentation
Intragroup arrangements are often less formally documented than external contracts, sometimes relying on internal policies, service catalogs, or informal understandings rather than arm's-length agreements. In many regulated programs, supervisors expect intragroup arrangements to be governed by written agreements with defined responsibilities, service levels, and exit provisions comparable to those for external providers.
Regulatory Treatment
Depending on the jurisdiction and sector, financial and other regulators may treat intragroup outsourcing as subject to the same or similar oversight obligations as external outsourcing, while sometimes permitting proportionate adjustments. Regulatory expectations for governance, risk assessment, and documentation vary across regions and sectors rather than following a single global standard.
Risk Domains Addressed
The arrangement can carry information security, operational, financial, and compliance risk, as well as concentration risk where multiple group entities depend on a single internal provider. Common ownership does not by itself remove these risks; it changes how they are governed rather than eliminating them.
Exit and Continuity Considerations
Provisions addressing how a group entity would continue operating if the intragroup service were disrupted or if the group structure changed (for example, through divestiture). Business continuity planning for intragroup dependencies is distinct from the disaster recovery capabilities of the internal provider.

Common questions

Answers to the questions practitioners most commonly ask about Intragroup Arrangement.

Does an intragroup arrangement fall outside third-party risk management because the counterparty is part of the same corporate group?
No. While an intragroup arrangement involves an entity within the same corporate group rather than an external supplier, many regulatory regimes and internal frameworks still treat it as a form of outsourcing or dependency that warrants oversight. The shared ownership does not automatically eliminate operational, financial, concentration, or resilience risk, and in some sectors supervisors expect intragroup arrangements to be assessed with rigor comparable to external third-party relationships. Whether it is scoped into a formal TPRM program depends on the applicable jurisdiction, sector, and the criticality of the service provided.
Does using an intragroup provider mean the arrangement is inherently lower risk than using an external third party?
Not necessarily. Common ownership may support alignment of incentives and easier information access, but it does not by itself reduce inherent risk. Intragroup arrangements can introduce distinct concerns, including concentration and single-source dependency within the group, reduced independence in oversight, and the risk that group-wide events affect both the receiving and providing entities simultaneously. Whether residual risk is lower depends on the specific controls, governance, and contractual terms in place, not on the intragroup nature of the relationship alone.
How should intragroup arrangements typically be documented?
In many programs, intragroup arrangements are documented through a formal written agreement even though the parties share ownership, because supervisors and internal governance functions often expect terms comparable to those used with external providers. Documentation typically covers the scope of services, service levels, roles and responsibilities, data handling, and provisions for continuity or exit. The specific documentation expectations vary by jurisdiction and sector, and some regimes place particular emphasis on arms-length terms and enforceability.
Should intragroup arrangements be included in the organization's inventory of critical or important dependencies?
Where the service supports a critical or important function, intragroup arrangements are generally captured in the same inventory used for external dependencies rather than kept separate. Excluding them can create blind spots in concentration risk analysis and resilience planning, because a group-wide disruption could affect an intragroup provider at the same time as other functions. Inclusion criteria typically depend on the criticality of the service and the applicable regulatory expectations rather than on the counterparty's ownership.
How should ongoing monitoring of an intragroup arrangement be approached?
Ongoing monitoring is usually appropriate even when the provider is within the group, because onboarding or initial assessment alone does not address how performance and risk change over time. Depending on the risk tier, monitoring may cover service performance, control effectiveness, financial condition of the providing entity, and continuity readiness. Shared ownership may ease access to information, but it does not remove the need for periodic review, and it can create a temptation to rely on informal assurance rather than structured, evidenced monitoring.
What resilience and exit considerations apply to intragroup arrangements?
Even within a group, it is generally prudent to consider continuity and exit scenarios, particularly where the arrangement supports a critical function. A single point of failure or single-source dependency can exist entirely inside a corporate group, and group-level events may disrupt the providing entity. Planning typically considers whether the service could be substituted, brought in-house, or sourced externally if needed, and how such transitions would be executed. The depth of these considerations usually scales with the criticality of the service and applicable supervisory expectations.

Common misconceptions

Because the counterparty is part of the same group, an intragroup arrangement carries little risk and needs minimal oversight.
Common ownership changes governance dynamics but does not eliminate operational, information security, financial, or concentration risk. In many regulated programs, supervisors expect intragroup arrangements to receive risk assessment and oversight broadly comparable to external outsourcing, sometimes with proportionate adjustments depending on jurisdiction and sector.
Intragroup arrangements do not require formal contracts or defined service levels since the parties are affiliated.
Relying on informal understandings can create gaps in accountability and continuity. Written agreements setting out responsibilities, service levels, and exit provisions are frequently expected, particularly where the arrangement supports critical or regulated functions.
An intragroup provider removes third-party dependency because the service is 'kept in-house.'
Centralizing a function within one group entity can create concentration risk and a single point of failure across multiple dependent affiliates. It also does not remove exposure to any external fourth parties the internal provider itself relies upon.

Best practices

Document intragroup arrangements in written agreements that define scope, responsibilities, service levels, and exit provisions, rather than relying on informal internal understandings.
Apply risk assessment and ongoing monitoring proportionate to the criticality of the service, recognizing that common ownership does not by itself reduce operational, security, or compliance risk.
Confirm the specific regulatory treatment of intragroup outsourcing in each relevant jurisdiction and sector, since expectations vary and some regimes apply the same obligations as for external outsourcing.
Assess concentration risk and single points of failure where multiple group entities depend on one internal provider, and plan for the impact of a disruption or a change in group structure such as a divestiture.
Maintain business continuity plans for critical intragroup dependencies as distinct from the internal provider's disaster recovery capabilities.
Identify and account for any external fourth parties the intragroup provider relies upon, so that Nth-party exposure is not overlooked simply because the direct provider is affiliated.
Application Security Isn’t Optional Anymore.