Back to GUIDEsVerified Compliance Standard
guideGovernance & Labor

The Social (S) and Governance (G) Audit Checklist for Indian Enterprises

A regulatory compliance audit checklist covering POSH Act compliance, factory labor standards, DPDP Act data privacy, board independence, and whistleblower governance under Indian statutes.

Aditi VermaSenior ESG Compliance Analyst
Updated: September 6, 2026
15 min read

While environmental decarbonization and carbon accounting dominate global headlines, the majority of corporate crises, regulatory fines, and reputational disasters in India stem from failures in the Social (S) and Governance (G) pillars. A company with net-zero emissions can still face catastrophic shareholder value destruction if it encounters a sexual harassment cover-up, factory floor safety fatalities, or related-party transaction fraud. For overall regulatory architecture, consult our Definitive Guide to ESG in India.

Regulatory Warning: Beyond Carbon

Indian regulatory authorities—including the Ministry of Corporate Affairs (MCA), SEBI, Labor Commissioners, and the Data Protection Board of India—actively enforce social and governance mandates. Non-compliance with the POSH Act or DPDP Act triggers criminal prosecution, license cancellations, and statutory penalties up to ₹250 crore.

1. The Social (S) Compliance Audit Checklist

In India, social responsibility is codified through rigid labor, workplace welfare, and human rights statutes that must be verified during internal audits:

Statutory Focus AreaGoverning Indian LawMandatory Legal RequirementsAudit Evidence Required
POSH Act ComplianceSexual Harassment of Women at Workplace Act, 2013Constitute Internal Complaints Committee (ICC) with external NGO member for units with 10+ staff; file annual report with District Officer by Jan 31ICC constitution office order, training attendance logs, annual District Officer filing receipt
Factory Health & SafetyFactories Act, 1948 & State Factory RulesMandatory safety committees, PPE issuance, first aid stations, maximum 48-hour work week, overtime at double ratesAccident registers (Form 18/21), safety committee minutes, annual medical check-up reports
Welfare & Statutory BenefitsEPF Act, ESI Act & Payment of Gratuity Act100% deduction and deposit of employee and employer PF/ESIC contributions; mandatory gratuity fundingMonthly Electronic Challan cum Return (ECR) receipts, Form 12A, gratuity trust audit report
Contract Labor ProtectionContract Labor (Regulation & Abolition) Act, 1970Principal employer liability for contract worker statutory dues, canteen/washroom parityForm V issued to contractors, contractor PF/ESIC payment challans, muster roll verification
Equal Opportunity & PwDRights of Persons with Disabilities Act, 2016Formulation of an Equal Opportunity Policy, barrier-free accessibility ramps/lifts in officesEqual Opportunity Policy published on portal, accessibility audit certificate

2. The Governance (G) Compliance Audit Checklist

Governance represents the fiduciary controls and ethical oversight established by the Board of Directors under the Companies Act, 2013 and the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015:

  • Board Independence & Composition: Ensuring that independent directors comprise at least 1/3rd (if Chairman is non-executive) or 1/2 (if Chairman is executive) of the board under SEBI LODR Regulation 17. Ensure appointment of at least one independent woman director for top 1,000 listed entities.
  • Vigil Mechanism & Whistleblower Protections: Under Section 177(9) of the Companies Act, listed companies must establish a documented whistleblower channel providing direct access to the Audit Committee Chairman, ensuring complete identity protection against retaliation.
  • Related Party Transactions (RPT): Prior approval of the Audit Committee and shareholders for all material RPTs exceeding statutory thresholds (lower of ₹1,000 crore or 10% of annual consolidated turnover) under LODR Regulation 23.
  • Executive Remuneration Disparity Disclosures: Disclosing the ratio of the remuneration of each director to the median remuneration of the company's employees under Section 197(12) of the Companies Act.
  • Anti-Bribery & Prevention of Money Laundering: Enforcing robust anti-bribery policies, code of conduct compliance sign-offs, and compliance with the Prevention of Money Laundering Act (PMLA).

3. Digital Privacy & Cybersecurity: DPDP Act 2023 Mandates

Under modern ESG governance assessments, cybersecurity and data privacy form a core governance indicator under NGRBC Principle 9:

  • Consent Architecture: Enterprises acting as Data Fiduciaries must implement clear, multilingual, and withdrawable consent notices before processing personal customer or employee data.
  • Breach Notification: Under CERT-In cyber directives and the Digital Personal Data Protection (DPDP) Act, mandatory reporting of cybersecurity incidents within 6 hours of detection.
  • Statutory Penalties: Non-compliance with data fiduciary safeguards or failing to prevent data breaches triggers financial penalties up to ₹250 crore per violation adjudicated by the Data Protection Board of India.

4. Preparing the S & G Audit Documentation File

To guarantee smooth third-party reasonable assurance under BRSR Core Requirements, compile the following documentary proofs annually:

  • Folder S-1: Annual POSH Committee report submitted to the Local Complaints Committee / District Officer.
  • Folder S-2: Safety audit report by Chief Inspector of Factories and factory emergency mock drill logs.
  • Folder S-3: ECR challans validating 100% PF and ESIC deposits for all on-roll and contractual employees.
  • Folder G-1: Secretarial Audit Report (Form MR-3) issued by an independent Practicing Company Secretary.
  • Folder G-2: Board evaluation minutes, independent director performance reviews, and Committee meeting attendance registers.
  • Folder G-3: ISO 27001 cybersecurity certification and periodic vulnerability assessment and penetration testing (VAPT) audit sign-offs.

Frequently Asked Questions (FAQ)

Can an Indian private company be penalized for not having an ICC under the POSH Act?

Yes. Any establishment with 10 or more employees (public or private) that fails to constitute an Internal Complaints Committee is liable for a fine of up to ₹50,000, and repeated offenses can lead to cancellation of business licenses.

Who can serve as the external member of an Internal Complaints Committee?

The external member must be from an NGO or association committed to the cause of women, or a person familiar with issues relating to sexual harassment, and cannot have any business or pecuniary relationship with the company.

How does whistleblower governance affect ESG ratings from CRISIL or MSCI?

ESG rating providers heavily penalize companies lacking an independent, third-party managed whistleblower hotline. Documented, board-level reporting of grievance resolution directly drives higher marks in the Governance pillar.
Enterprise Advisory Service

Need Support Preparing Your Compliance Audit?

Schedule a 15-minute technical briefing with AtmoGrade’s lead ISO 14064 & SEBI BRSR auditors to calculate your audit timeline and data boundary.

Schedule Consult