Corporate Risk Mitigation • Promoter & Director Risk • India • 2026

Promoter & Director Risk Assessment in India: Governance, Related Parties, Delegation, Guarantees & Personal Exposure Guide 2026

A board-level framework for identifying where informal decision-making, conflicts, statutory defaults, guarantees and control failures can create company and personal exposure.

GovernanceBoard approvals, minutes, authority and application of mind
ConflictsRelated parties, promoter entities and personal interests
ExposureGuarantees, statutory defaults, banking and litigation
ProtectionDelegation, controls, records, insurance and escalation

Promoter and director risk usually increases when the company operates through informal instructions rather than documented governance. A director may believe a matter is operational, while the underlying transaction actually involves a related party, borrowing, guarantee, statutory default, employee liability, tax exposure or an approval reserved for the board or shareholders.

A meaningful risk assessment therefore asks not only whether a company is compliant, but which decisions can be attributed to which individuals, whether authority was validly exercised, whether conflicts were disclosed, and whether the board record demonstrates an informed and defensible decision process.

Key principle: company liability does not automatically become director liability in every case. Personal exposure depends on the statute, role, conduct, documents, authorisation and specific facts. Risk assessment should avoid treating designation alone as proof of responsibility.

1. Director-risk universe

Common exposure areas include board and shareholder approvals, related-party transactions, loans and guarantees, statutory dues, tax and GST, labour and employee claims, cheque-signing authority, data and cyber incidents, regulatory licences, financial statements, borrowing, bank covenants, litigation strategy and commercial settlements.

The starting point should be the company’s actual decision map: who controls bank accounts, who signs contracts, who approves vendors, who can override systems, who communicates with regulators and who is recorded in board minutes as responsible.

See the main Corporate Risk Mitigation in India pillar.

2. Board approvals and decision records

A director-risk review should compare actual major decisions against board minutes, shareholder approvals where required, delegation matrices and statutory filings. Problems arise where significant contracts, guarantees, related-party transactions, borrowings or settlements are executed first and approved later without a clear lawful basis.

Minutes should not be treated as a formality. They should record material agenda, conflicts, information considered, approvals, abstentions where appropriate and responsibility for implementation. A short but accurate contemporaneous record is generally more defensible than reconstructed documentation created after a dispute begins.

3. Director duties and conflicts

Section 166 of the Companies Act sets out statutory duties of directors, including acting in accordance with the articles, good faith for the benefit of the company and its members, and avoiding situations involving direct or indirect interests that conflict or may conflict with the company’s interests.

Conflict controls should therefore cover promoter-owned premises, sister concerns, common vendors, management-fee arrangements, loans, asset transfers, shared employees and other transactions where a director or connected person may have an interest.

4. Related-party transaction risk

Related-party transactions should be identified before approval, not after audit. The company should maintain a current related-party register, commercial rationale, pricing basis, contract, board record and shareholder approval where applicable.

Section 188 of the Companies Act governs specified related-party transactions subject to its statutory framework. A promoter-linked transaction is not automatically improper, but undisclosed or poorly documented dealings can create governance, tax, audit, investor and litigation risk.

5. Loans, guarantees and security

Corporate guarantees and security can create significant balance-sheet and director exposure. Review who authorised the transaction, whether statutory conditions were met, whether lender documents match board authority, whether the company received commercial benefit and whether group-company support has become routine without risk assessment.

Section 186 of the Companies Act is relevant to loans, guarantees, securities and investments in specified situations. Depending on the transaction, additional provisions, lender covenants and sector rules may also apply.

6. Delegation of authority: protection and control

A clear delegation-of-authority matrix is one of the strongest risk controls. It should define approval levels for contracts, procurement, bank payments, hiring, termination, settlement, discounts, credit notes, capital expenditure, litigation, write-offs and vendor onboarding.

Delegation does not mean directors stop supervising material risk. The matrix should identify reserved matters, escalation thresholds, override conditions and periodic review. Shared credentials or undocumented verbal approvals undermine the value of delegation.

7. Statutory default and “officer in default” analysis

Where a statute creates liability for officers or persons responsible, the company should identify actual functional responsibility rather than assume every director has identical exposure. The Companies Act definition of “officer who is in default” and specific statutory provisions should be examined against appointment, responsibility, board records and conduct.

Management should maintain a compliance-responsibility matrix showing each filing, payment, return, licence and regulatory obligation, its accountable executive and escalation path to the board.

8. Banking, cheque and payment authority

Signing authority should be documented and periodically recertified. Review cheque mandates, digital banking rights, maker-checker design, payment limits, emergency payments and dormant user access.

Transaction-specific laws may impose liability on persons responsible for company conduct in particular circumstances. Accordingly, authority records, role descriptions and evidence of actual responsibility can become important in litigation or regulatory proceedings.

9. Management override and promoter instructions

Promoter-led companies can be especially vulnerable to undocumented instructions that bypass policy. Examples include vendor selection outside process, payment acceleration, credit extension, related-party use, inventory movement or hiring without normal checks.

The correct control is not to eliminate commercial discretion. It is to create an exception process: reason, value, approving authority, conflict check, time limit and subsequent independent review.

10. Litigation and settlement risk

Large settlements, admissions, waivers and write-offs should be approved at an appropriate level and supported by a written risk note. The record should identify claim amount, legal merits, commercial exposure, probability, settlement range, recovery rights and authority.

Where a matter involves suspected fraud or management conduct, consider an independent investigation. See Board-Led Corporate Internal Investigations in India.

11. Promoter and director risk matrix

Risk Evidence to review Mitigation
Missing authority Board minutes, powers, contract, delegation Clarify reserved matters and approval matrix
Undisclosed conflict Declarations, vendor/customer links, related-party data Periodic disclosure and recusal process
Guarantee exposure Loan documents, board approval, financials Central guarantee register and pre-approval review
Statutory default Compliance calendar, notices, responsibility matrix Named owners and escalation
Management override ERP, bank, procurement and pricing logs Override register and independent review

12. Board-protection toolkit

  • delegation-of-authority matrix;
  • board and shareholder approval matrix;
  • related-party register;
  • conflict declaration and recusal process;
  • guarantee and security register;
  • compliance responsibility matrix;
  • bank authority register;
  • litigation and settlement tracker;
  • management override register;
  • director disclosure file;
  • periodic legal-risk dashboard; and
  • D&O insurance review where appropriate.

For fraud-specific governance, see Corporate Fraud Risk Assessment in India.

13. 30/60/90-day remediation

First 30 days: map actual authority, identify material undocumented decisions, reconcile related parties, review guarantees, bank mandates and open regulatory notices.

Days 31–60: adopt revised delegation, conflict, settlement and override frameworks; update board approval trackers; assign statutory owners; clean banking access.

Days 61–90: introduce quarterly board-risk reporting, periodic related-party reconciliation, director training, compliance certification and high-risk transaction review.

14. Frequently asked questions

Is every director personally liable for company defaults?

No. Personal liability depends on the applicable law, role, responsibility, conduct and facts.

Can a board ratify every past transaction?

No general assumption should be made. Whether ratification is legally effective depends on the provision and transaction.

Are promoter transactions prohibited?

No. The issue is whether the transaction is lawful, disclosed, approved where required and commercially defensible.

Does delegation eliminate director responsibility?

No. Delegation can improve control and clarify responsibility, but directors retain applicable statutory and governance duties.

What is the most useful director-risk document?

A current delegation and reserved-matters matrix, supported by accurate minutes and compliance ownership, is usually foundational.

Authoritative references

Firm & Correspondence Information
Fastrack Legal Solutions LLP
Office: B1/32 Basement, Malviya Nagar, New Delhi – 110017
Telephone: +91 76976 71219
Email: advgovind@fastracklegalsolutions.com
Website: fastracklegalsolutions.com
The particulars above are provided solely for identification and correspondence. They do not constitute an advertisement, solicitation, invitation or inducement to engage legal services.
General corporate-risk information only. Director and promoter exposure depends on the specific statute, transaction, role, authorisation and facts.

Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.

Leave a Comment

Your email address will not be published. Required fields are marked *