Home / Insights / Group exposure
17 February 2026
Related parties that sit in the SSM pages and nowhere on the form
SME application files often attach company documents that name common directors, while the application itself still presents a standalone borrower.
A scoring engine will not notice a sister company unless someone puts that sister company into a field. The application file sometimes already knows. The SSM extract lists directors who appear, under slightly different spellings, on another facility in the same branch. The bank statements show round-sum transfers to an entity that is never named on the form. The security schedule mentions a third company as chargor.
None of that is hidden in a sophisticated way. It is unreconciled. Originators assemble packs under time pressure. Group-limit frameworks live in a different manual. The score is called on the applicant in isolation because that is the path the system offers.
A file-level audit does not replace a group data warehouse. It asks whether the pack in hand already contained a related-party story that was not carried onto the application and, therefore, not into the score or the limit. When the answer is yes, the issue is origination discipline, not a missing software feature.
We are careful about the boundary. We do not run a parallel investigation of the Malaysian corporate registry unless instructed. We read what you already collected. That is enough, in many samples, to show that disclosure was possible and did not occur.
Lenders preparing a commercial book for a second-line review find this work useful because it produces examples rather than a theory of concentration. Examples can be discussed with originators. Theories of concentration tend to produce another policy paragraph that the next file will also skip.