Corporate Compliance Health Check in India: Governance, Labour, Contracts, Data, Tax, Licences & Board Risk Guide 2026
A management-level framework for identifying legal and compliance weaknesses before they become regulatory action, litigation, director exposure, deal friction or operating disruption.
A corporate compliance health check is different from a narrow statutory filing review. Its purpose is to identify whether the company’s legal obligations, internal approvals, records, contracts, workforce practices, licences, data controls and dispute-management systems are aligned with the business that is actually being carried on.
A company may be technically incorporated and still carry significant exposure because material contracts are unsigned, related-party dealings are undocumented, employees are misclassified, licences do not match business activity, legal notices are not centrally tracked, data access is uncontrolled or board decisions are not supported by an authority matrix.
1. When should a company conduct a compliance health check?
Common triggers include fundraising, lender diligence, acquisition, rapid expansion, entry into a new State, launch of a new product, leadership change, recurring legal notices, employee disputes, regulatory inspection, data incidents, major customer onboarding or discovery that historic records are incomplete.
Periodic reviews are also valuable because compliance drift occurs gradually. A policy may remain unchanged while the company doubles in size, introduces remote work, outsources critical functions, expands warehouses, adds new vendors or begins processing substantially more customer data.
See the broader Corporate Risk Mitigation in India pillar for the overall enterprise-risk framework.
2. Corporate governance and Companies Act review
The governance review should verify incorporation records, memorandum and articles, statutory registers, board and shareholder minutes, director disclosures, annual filings, share capital records, beneficial ownership obligations where applicable, charges, loans, guarantees, related-party transactions and delegation of authority.
Particular attention should be paid to matters approved informally but never properly recorded. A company should be able to demonstrate who had authority to enter major contracts, open bank accounts, approve capex, appoint senior employees, settle litigation, create security, transact with related parties and commit the company to material obligations.
3. Contract portfolio review
A health check should identify whether the company has a complete contract repository and whether material agreements address scope, price, payment, service levels, termination, confidentiality, data, intellectual property, indemnity, liability caps, force majeure, governing law and dispute resolution.
High-risk contracts include arrangements with automatic renewal, unlimited liability, unilateral termination, broad indemnities, customer audit rights, change-of-control restrictions, weak payment protection, undocumented amendments and business-critical obligations resting only on email or purchase orders.
For deeper contract analysis, the separate Contract Risk Audit cluster article should be used once live.
4. Labour, employment and HR compliance
Review appointment letters, employment contracts, consultant and contractor arrangements, wages and payroll records, attendance, leave, termination procedures, statutory benefit records, gratuity exposure, maternity compliance, POSH governance, employee handbooks, disciplinary records and full-and-final settlements.
The correct legal framework depends on the establishment, State, workforce composition and laws in force for the relevant period. Companies should avoid assuming that one national template resolves every employment issue.
Contract-worker arrangements require special attention where the company exercises extensive supervision and control while documentation presents the worker as independent. Misclassification can create labour, tax and litigation exposure.
5. POSH and workplace governance
Where applicable, verify constitution and composition of the Internal Committee, policy, employee awareness, member orientation, complaint-handling records, confidentiality, annual reporting, implementation of recommendations and management non-interference.
POSH risk is not limited to whether a policy exists. A company can have a policy and still face significant exposure if the committee is improperly constituted, inquiries are delayed, confidentiality is breached or managers informally attempt to suppress complaints.
6. Data protection, confidentiality and cyber controls
The review should map personal and confidential data collected from customers, employees, vendors and users; the purpose for which it is processed; who has access; which processors or SaaS vendors receive it; how long it is retained; and what happens when an incident occurs.
Companies should evaluate the Digital Personal Data Protection Act, 2023 and applicable rules according to their legally operative commencement position. In parallel, existing cyber obligations under the Information Technology framework and CERT-In directions may be relevant to incident reporting, security practice and log retention.
Key controls include access governance, privileged-user review, processor contracts, confidentiality obligations, device controls, breach response, retention, deletion and periodic access recertification.
7. Tax, GST and statutory-dues exposure
A legal health check should not replace specialist tax advice, but it should identify material unresolved notices, demands, GST mismatches, TDS issues, input-tax-credit disputes, related-party concerns, statutory dues, pending assessments and litigation deadlines.
Management should maintain a consolidated statutory-notice register with issue, authority, amount, reply deadline, owner, counsel, current status, financial provision and next action. This prevents legal exposure from being fragmented across email inboxes and departments.
8. Licences and operational permissions
Prepare a location-wise and activity-wise licence register. Verify name of licence holder, business address, scope, expiry, renewal lead time, conditions, inspection history and whether any change in business activity requires amendment or fresh approval.
Typical risks arise where licences remain in a promoter’s name, a branch or warehouse is missing registration, business activity has expanded beyond licensed scope, renewals are handled only when an inspection occurs, or the company assumes that one central registration covers every location.
9. Vendor, procurement and payment controls
Compliance is also operational. Vendor onboarding should capture KYC, tax details, bank verification, conflict checks, contract terms and approval ownership. High-risk vendor changes—particularly bank-account changes—should require independent confirmation.
Useful controls include maker-checker approvals, three-way matching where relevant, vendor-master change logs, periodic re-KYC, related-party declaration, competitive-bid documentation and review of repeated emergency procurement.
See Vendor & Procurement Fraud Risk in India.
10. Litigation, notices and claims management
Every material dispute should be visible to management. Maintain a litigation and notice tracker covering courts, arbitration, tax, labour, consumer, vendor, customer, employee, regulatory and criminal complaints arising from business transactions.
Each matter should record claim value, stage, limitation, key documents, evidence-preservation status, reserve, settlement authority and responsible business owner. A company should also track recurring dispute causes to determine whether litigation is revealing a systemic contract or process failure.
11. Director and promoter exposure
The health check should identify situations where directors or promoters are personally signing guarantees, cheques, statutory declarations, sensitive contracts or operational approvals without documented authority or visibility of the underlying risk.
Review delegation, board reporting, related-party controls, compliance certifications, D&O insurance where appropriate, management override and whether directors receive enough information to make defensible decisions.
See Promoter & Director Risk Assessment in India.
12. Compliance risk-scoring matrix
| Rating | Illustrative condition | Action |
|---|---|---|
| Critical | Operating without material licence, active prosecution risk, major data incident, material statutory default | Immediate board escalation and corrective action |
| High | Significant contract gap, unresolved notice, repeated labour default, related-party weakness | Fix within defined short-term plan |
| Medium | Incomplete documentation or inconsistent control operation | Remediate and test closure |
| Low | Housekeeping or process-improvement item | Close in routine compliance cycle |
13. Board-ready deliverables
- executive compliance heat map;
- critical/high/medium/low risk register;
- department-wise compliance matrix;
- licence and statutory-registration register;
- contract exceptions schedule;
- labour and HR gap report;
- data and cyber control summary;
- litigation and notice tracker;
- director-exposure summary;
- remediation owner and deadline matrix; and
- quarterly board dashboard.
14. 30/60/90-day remediation plan
0–30 days: close critical filings, preserve evidence, respond to urgent notices, identify licence gaps, correct high-risk authority failures and freeze uncontrolled access or payment exceptions.
31–60 days: regularise contracts, update employment documents, refresh POSH and data controls, clean vendor masters, reconcile statutory registers and implement central legal trackers.
61–90 days: test closure, create recurring dashboards, assign control owners, schedule periodic audits and report unresolved high-risk items to the board.
15. Frequently asked questions
Is a compliance health check the same as statutory audit?
No. A statutory audit has a defined accounting and legal scope. A compliance health check examines broader legal, operational and governance exposure.
How often should it be done?
Frequency depends on risk, scale and change. High-growth or regulated businesses may require more frequent reviews than stable low-risk operations.
Should every gap be reported to the board?
The board should receive material and systemic risks. Routine low-level housekeeping can usually be managed operationally with escalation thresholds.
Can the same checklist be used for every company?
No. Sector, State, workforce, licences, data, financing and transaction structure materially change the compliance universe.
What is the most important output?
A prioritised risk register with accountable owners and closure dates—not merely a list of statutes.
Authoritative references
- Companies Act, 2013 — India Code
- Digital Personal Data Protection Act, 2023 — India Code
- CERT-In Directions dated 28 April 2022
Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.