# How to Manage Governance After an Acquisition **Category:** MA **Author:** AI Assistant **Published:** 2026-09-21 **Read Time:** 8 min read ## Summary The deal closes. The press release goes out. And then the real work begins: absorbing a new corporate structure, new risks, new contracts, and new compliance obligations into a governance framework that was designed for the organisation you were yesterday, not the one you are today. ## Full Content
Post-acquisition governance is the most neglected phase of the M&A lifecycle. Deal teams obsess over valuation. Lawyers obsess over contracts. Bankers obsess over financing. And then the acquisition completes, the advisers leave, and the acquiring group inherits an entity (or a portfolio of entities) that needs to be governed.
The board expects governance to continue seamlessly. In practice, it takes months for acquired entities to be fully absorbed into the group's governance framework, if they ever are. I have audited groups where entities acquired three years ago still have their own separate risk management process, their own compliance standards, and their own filing arrangements managed by a company secretary who left the organisation 18 months after the deal closed.
This is not a minor administrative issue. It is a governance failure that creates regulatory risk, financial risk, and board liability. Let me be specific about what needs to happen and how to make it work.
The immediate priority is getting the acquired entities properly recorded and their statutory positions confirmed. This means:
Companies House filings: File the AP01/AP02 forms for new directors appointed to the acquired entities. File the TM01 forms for outgoing directors. File any change of registered office if the entity is being relocated. Ensure the confirmation statement filing date is known and in the calendar. For acquisitions of UK companies, the PSC register must be updated to reflect the new beneficial ownership structure, and a PSC07 (notice of change) must be filed within 14 days.
Entity register update: Enter all acquired entities into the group's entity register with complete data: incorporation details, registered office, share capital, officer appointments, statutory registers, filing history, and compliance status. If the acquirer does not have a structured entity register, this is the point at which the lack of one becomes acutely painful.
Constitutional review: Review the articles of association of each acquired entity. Identify any provisions that conflict with the group's governance standards (for example, director quorum requirements, reserved matters, pre-emption rights on share transfers). Plan amendments if required.
Once the entity mechanics are in hand, the focus shifts to absorbing the target's risk and compliance profile into the group framework:
Risk register consolidation: Transfer due diligence risk findings into the enterprise risk register. Map the target's existing risks to the group's risk taxonomy. Assign control owners from the acquiring organisation. Establish review dates aligned with the group's risk management cycle.
Compliance gap assessment: Compare the target's compliance posture against the group's standards. This includes data protection (DPAs, privacy notices, processing records), health and safety, employment law compliance, financial reporting standards, and sector-specific regulatory requirements. Document gaps and establish remediation timelines.
Policy deployment: Identify which of the group's policies need to be adopted by the acquired entities immediately and which can wait. Anti-bribery and corruption policies, data protection policies, and whistleblowing policies typically cannot wait. HR policies and operational procedures can be phased in over a longer period.
Contract portfolio review: Complete the review of the target's material contracts against the group's commercial and risk standards. Execute change of control consent processes. Identify contracts for renegotiation, novation, or termination. Update the group contract register.
Governance structure implementation: Establish the acquired entities' position in the group's governance hierarchy. Determine reporting lines, delegated authority levels, and committee structures. Appoint entity-level board members in accordance with the group's governance framework. Establish board meeting schedules and reporting requirements.
Delegated authority framework: Extend the group's delegated authority framework to the acquired entities. This defines who can commit the entity to expenditure, contracts, and other obligations at various threshold levels. Without this, the acquired entity either operates with no authority framework (creating unchecked risk) or operates with its pre-acquisition framework (which may not align with the acquiring group's risk appetite).
Board reporting integration: Incorporate the acquired entities into the group's board reporting framework. Risk reports, compliance reports, and financial reports should include data from the acquired entities alongside existing group entities. The board should see a single consolidated governance picture.
Ongoing monitoring activation: Activate the monitoring processes that will maintain governance standards on an ongoing basis: filing deadline tracking, control testing schedules, compliance review cycles, and board meeting calendars. Without systematic monitoring, the governance gains achieved during the first 60 days will erode within six months.
Post-acquisition governance audit: Conduct a governance audit at the 90 to 100 day mark to verify that all of the above has been completed, that the entity register is accurate, that risk entries are current, that compliance gaps are being remediated on schedule, and that the governance structure is functioning as designed.
The 100-day framework I have described is not complex. The activities are known. The deadlines are definable. The responsibilities are assignable. Yet in my experience, fewer than 20% of acquisitions complete all of these governance activities within 100 days. The reasons are structural:
No ownership: Post-acquisition governance does not belong to any single function. The company secretary handles entity filings. The risk team handles risk register updates. The compliance team handles policy deployment. The legal team handles contract reviews. Nobody owns the overall governance integration, and without ownership, activities fall through the gaps between functions.
No tooling: The tools used for M&A integration (project management platforms, spreadsheets) do not support governance activities. They can track tasks ("update PSC register") but they cannot execute them (generate the filing, calculate the deadline, update the entity register). The governance work requires specialist tools that the integration team does not have access to or expertise in.
No visibility: The board knows the integration is happening. They receive progress reports on synergy realisation and operational milestones. But they rarely receive reports on governance integration specifically. Is the entity register complete? Are all filings current? Has the risk register been consolidated? Are compliance gaps being remediated? These questions are not answered in the standard integration report because the data does not exist in the integration tool.
No connection to ongoing governance: Even when the 100-day activities are completed, they are completed as a project. The project closes, and the ongoing governance of the acquired entities reverts to business-as-usual processes that may or may not be adequate. If the entity register was set up in the integration project but is not maintained in the group's entity management system, it decays immediately. If the risk entries were created during integration but are not connected to the ongoing risk review cycle, they become stale within one quarter.
Post-acquisition governance works when it is managed in the same platform that manages ongoing governance. This means:
Entity data captured during integration flows directly into the group's permanent entity register. It does not need to be migrated from one system to another. The entity exists in the same system on Day 1 of the integration as it does on Day 1,000.
Risk entries created from due diligence findings are injected directly into the enterprise risk register through Automated Risk Injection. They are not temporary integration risks that get archived when the project closes. They are permanent enterprise risks that are reviewed, managed, and reported alongside every other risk in the group.
Contracts reviewed during integration are entered directly into the group's contract register with their risk classifications, obligation schedules, and key dates. They do not sit in a due diligence folder waiting to be processed.
Governance structure changes are implemented in the system that manages the group's governance framework. Board compositions, committee structures, delegated authority levels, and reporting requirements are configured in the platform rather than documented in a PowerPoint that nobody updates after Day 30.
For businesses that acquire regularly (two, three, or more deals per year), post-acquisition governance is not a one-time exercise. It is a repeatable process that needs to be standardised, templated, and automated.
Each acquisition should follow the same governance onboarding workflow: entity registration, statutory filing, risk register consolidation, compliance assessment, contract review, governance structure integration, and monitoring activation. The platform should support templates for each of these activities, pre-configured with the group's standards, risk taxonomies, compliance frameworks, and governance requirements.
When Deal 5 closes, the governance onboarding should be as streamlined as Deal 1. The entity data model is the same. The risk taxonomy is the same. The compliance framework is the same. The process is repeatable because the platform enforces consistency.
Managing governance after an acquisition is not optional, and it is not something that can wait until the integration team has finished the operational workstreams. Entity filings have statutory deadlines. Risk exposure begins on Day 1. Compliance obligations apply from completion. The board's oversight responsibility extends to every entity in the group from the moment the shares are transferred.
The organisations that manage post-acquisition governance effectively are the ones that use a platform designed for it: a governance operating system where entity management, risk management, compliance management, and contract management are unified in a single architecture. Where due diligence findings flow into the risk register. Where entity data is captured once and maintained permanently. Where the board sees a consolidated governance picture from Day 1.
That is Simplif-i. Governance that scales with your ambition.
Compliance, simplif-i'd.
--- Source: https://simplif-i.com/api/blog/readable/ma/manage-governance-after-acquisition Web Version: https://simplif-i.com/blog/ma/manage-governance-after-acquisition © Simplif-i - Unified Business Management Platform