While environmental decarbonization and carbon accounting dominate global headlines, the majority of corporate crises, regulatory fines, and reputational disasters in India stem from failures in the Social (S) and Governance (G) pillars. A company with net-zero emissions can still face catastrophic shareholder value destruction if it encounters a sexual harassment cover-up, factory floor safety fatalities, or related-party transaction fraud. For overall regulatory architecture, consult our Definitive Guide to ESG in India.
Regulatory Warning: Beyond Carbon
1. The Social (S) Compliance Audit Checklist
In India, social responsibility is codified through rigid labor, workplace welfare, and human rights statutes that must be verified during internal audits:
| Statutory Focus Area | Governing Indian Law | Mandatory Legal Requirements | Audit Evidence Required |
|---|---|---|---|
| POSH Act Compliance | Sexual Harassment of Women at Workplace Act, 2013 | Constitute Internal Complaints Committee (ICC) with external NGO member for units with 10+ staff; file annual report with District Officer by Jan 31 | ICC constitution office order, training attendance logs, annual District Officer filing receipt |
| Factory Health & Safety | Factories Act, 1948 & State Factory Rules | Mandatory safety committees, PPE issuance, first aid stations, maximum 48-hour work week, overtime at double rates | Accident registers (Form 18/21), safety committee minutes, annual medical check-up reports |
| Welfare & Statutory Benefits | EPF Act, ESI Act & Payment of Gratuity Act | 100% deduction and deposit of employee and employer PF/ESIC contributions; mandatory gratuity funding | Monthly Electronic Challan cum Return (ECR) receipts, Form 12A, gratuity trust audit report |
| Contract Labor Protection | Contract Labor (Regulation & Abolition) Act, 1970 | Principal employer liability for contract worker statutory dues, canteen/washroom parity | Form V issued to contractors, contractor PF/ESIC payment challans, muster roll verification |
| Equal Opportunity & PwD | Rights of Persons with Disabilities Act, 2016 | Formulation of an Equal Opportunity Policy, barrier-free accessibility ramps/lifts in offices | Equal Opportunity Policy published on portal, accessibility audit certificate |
2. The Governance (G) Compliance Audit Checklist
Governance represents the fiduciary controls and ethical oversight established by the Board of Directors under the Companies Act, 2013 and the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015:
- Board Independence & Composition: Ensuring that independent directors comprise at least 1/3rd (if Chairman is non-executive) or 1/2 (if Chairman is executive) of the board under SEBI LODR Regulation 17. Ensure appointment of at least one independent woman director for top 1,000 listed entities.
- Vigil Mechanism & Whistleblower Protections: Under Section 177(9) of the Companies Act, listed companies must establish a documented whistleblower channel providing direct access to the Audit Committee Chairman, ensuring complete identity protection against retaliation.
- Related Party Transactions (RPT): Prior approval of the Audit Committee and shareholders for all material RPTs exceeding statutory thresholds (lower of ₹1,000 crore or 10% of annual consolidated turnover) under LODR Regulation 23.
- Executive Remuneration Disparity Disclosures: Disclosing the ratio of the remuneration of each director to the median remuneration of the company's employees under Section 197(12) of the Companies Act.
- Anti-Bribery & Prevention of Money Laundering: Enforcing robust anti-bribery policies, code of conduct compliance sign-offs, and compliance with the Prevention of Money Laundering Act (PMLA).
3. Digital Privacy & Cybersecurity: DPDP Act 2023 Mandates
Under modern ESG governance assessments, cybersecurity and data privacy form a core governance indicator under NGRBC Principle 9:
- Consent Architecture: Enterprises acting as Data Fiduciaries must implement clear, multilingual, and withdrawable consent notices before processing personal customer or employee data.
- Breach Notification: Under CERT-In cyber directives and the Digital Personal Data Protection (DPDP) Act, mandatory reporting of cybersecurity incidents within 6 hours of detection.
- Statutory Penalties: Non-compliance with data fiduciary safeguards or failing to prevent data breaches triggers financial penalties up to ₹250 crore per violation adjudicated by the Data Protection Board of India.
4. Preparing the S & G Audit Documentation File
To guarantee smooth third-party reasonable assurance under BRSR Core Requirements, compile the following documentary proofs annually:
- Folder S-1: Annual POSH Committee report submitted to the Local Complaints Committee / District Officer.
- Folder S-2: Safety audit report by Chief Inspector of Factories and factory emergency mock drill logs.
- Folder S-3: ECR challans validating 100% PF and ESIC deposits for all on-roll and contractual employees.
- Folder G-1: Secretarial Audit Report (Form MR-3) issued by an independent Practicing Company Secretary.
- Folder G-2: Board evaluation minutes, independent director performance reviews, and Committee meeting attendance registers.
- Folder G-3: ISO 27001 cybersecurity certification and periodic vulnerability assessment and penetration testing (VAPT) audit sign-offs.