Promoter & Director Risk Assessment in India: Governance, Related Parties, Delegation, Guarantees & Personal Exposure Guide 2026
A board-level framework for identifying where informal decision-making, conflicts, statutory defaults, guarantees and control failures can create company and personal exposure.
Promoter and director risk usually increases when the company operates through informal instructions rather than documented governance. A director may believe a matter is operational, while the underlying transaction actually involves a related party, borrowing, guarantee, statutory default, employee liability, tax exposure or an approval reserved for the board or shareholders.
A meaningful risk assessment therefore asks not only whether a company is compliant, but which decisions can be attributed to which individuals, whether authority was validly exercised, whether conflicts were disclosed, and whether the board record demonstrates an informed and defensible decision process.
1. Director-risk universe
Common exposure areas include board and shareholder approvals, related-party transactions, loans and guarantees, statutory dues, tax and GST, labour and employee claims, cheque-signing authority, data and cyber incidents, regulatory licences, financial statements, borrowing, bank covenants, litigation strategy and commercial settlements.
The starting point should be the company’s actual decision map: who controls bank accounts, who signs contracts, who approves vendors, who can override systems, who communicates with regulators and who is recorded in board minutes as responsible.
See the main Corporate Risk Mitigation in India pillar.
2. Board approvals and decision records
A director-risk review should compare actual major decisions against board minutes, shareholder approvals where required, delegation matrices and statutory filings. Problems arise where significant contracts, guarantees, related-party transactions, borrowings or settlements are executed first and approved later without a clear lawful basis.
Minutes should not be treated as a formality. They should record material agenda, conflicts, information considered, approvals, abstentions where appropriate and responsibility for implementation. A short but accurate contemporaneous record is generally more defensible than reconstructed documentation created after a dispute begins.
3. Director duties and conflicts
Section 166 of the Companies Act sets out statutory duties of directors, including acting in accordance with the articles, good faith for the benefit of the company and its members, and avoiding situations involving direct or indirect interests that conflict or may conflict with the company’s interests.
Conflict controls should therefore cover promoter-owned premises, sister concerns, common vendors, management-fee arrangements, loans, asset transfers, shared employees and other transactions where a director or connected person may have an interest.
4. Related-party transaction risk
Related-party transactions should be identified before approval, not after audit. The company should maintain a current related-party register, commercial rationale, pricing basis, contract, board record and shareholder approval where applicable.
Section 188 of the Companies Act governs specified related-party transactions subject to its statutory framework. A promoter-linked transaction is not automatically improper, but undisclosed or poorly documented dealings can create governance, tax, audit, investor and litigation risk.
5. Loans, guarantees and security
Corporate guarantees and security can create significant balance-sheet and director exposure. Review who authorised the transaction, whether statutory conditions were met, whether lender documents match board authority, whether the company received commercial benefit and whether group-company support has become routine without risk assessment.
Section 186 of the Companies Act is relevant to loans, guarantees, securities and investments in specified situations. Depending on the transaction, additional provisions, lender covenants and sector rules may also apply.
6. Delegation of authority: protection and control
A clear delegation-of-authority matrix is one of the strongest risk controls. It should define approval levels for contracts, procurement, bank payments, hiring, termination, settlement, discounts, credit notes, capital expenditure, litigation, write-offs and vendor onboarding.
Delegation does not mean directors stop supervising material risk. The matrix should identify reserved matters, escalation thresholds, override conditions and periodic review. Shared credentials or undocumented verbal approvals undermine the value of delegation.
7. Statutory default and “officer in default” analysis
Where a statute creates liability for officers or persons responsible, the company should identify actual functional responsibility rather than assume every director has identical exposure. The Companies Act definition of “officer who is in default” and specific statutory provisions should be examined against appointment, responsibility, board records and conduct.
Management should maintain a compliance-responsibility matrix showing each filing, payment, return, licence and regulatory obligation, its accountable executive and escalation path to the board.
8. Banking, cheque and payment authority
Signing authority should be documented and periodically recertified. Review cheque mandates, digital banking rights, maker-checker design, payment limits, emergency payments and dormant user access.
Transaction-specific laws may impose liability on persons responsible for company conduct in particular circumstances. Accordingly, authority records, role descriptions and evidence of actual responsibility can become important in litigation or regulatory proceedings.
9. Management override and promoter instructions
Promoter-led companies can be especially vulnerable to undocumented instructions that bypass policy. Examples include vendor selection outside process, payment acceleration, credit extension, related-party use, inventory movement or hiring without normal checks.
The correct control is not to eliminate commercial discretion. It is to create an exception process: reason, value, approving authority, conflict check, time limit and subsequent independent review.
10. Litigation and settlement risk
Large settlements, admissions, waivers and write-offs should be approved at an appropriate level and supported by a written risk note. The record should identify claim amount, legal merits, commercial exposure, probability, settlement range, recovery rights and authority.
Where a matter involves suspected fraud or management conduct, consider an independent investigation. See Board-Led Corporate Internal Investigations in India.
11. Promoter and director risk matrix
| Risk | Evidence to review | Mitigation |
|---|---|---|
| Missing authority | Board minutes, powers, contract, delegation | Clarify reserved matters and approval matrix |
| Undisclosed conflict | Declarations, vendor/customer links, related-party data | Periodic disclosure and recusal process |
| Guarantee exposure | Loan documents, board approval, financials | Central guarantee register and pre-approval review |
| Statutory default | Compliance calendar, notices, responsibility matrix | Named owners and escalation |
| Management override | ERP, bank, procurement and pricing logs | Override register and independent review |
12. Board-protection toolkit
- delegation-of-authority matrix;
- board and shareholder approval matrix;
- related-party register;
- conflict declaration and recusal process;
- guarantee and security register;
- compliance responsibility matrix;
- bank authority register;
- litigation and settlement tracker;
- management override register;
- director disclosure file;
- periodic legal-risk dashboard; and
- D&O insurance review where appropriate.
For fraud-specific governance, see Corporate Fraud Risk Assessment in India.
13. 30/60/90-day remediation
First 30 days: map actual authority, identify material undocumented decisions, reconcile related parties, review guarantees, bank mandates and open regulatory notices.
Days 31–60: adopt revised delegation, conflict, settlement and override frameworks; update board approval trackers; assign statutory owners; clean banking access.
Days 61–90: introduce quarterly board-risk reporting, periodic related-party reconciliation, director training, compliance certification and high-risk transaction review.
14. Frequently asked questions
Is every director personally liable for company defaults?
No. Personal liability depends on the applicable law, role, responsibility, conduct and facts.
Can a board ratify every past transaction?
No general assumption should be made. Whether ratification is legally effective depends on the provision and transaction.
Are promoter transactions prohibited?
No. The issue is whether the transaction is lawful, disclosed, approved where required and commercially defensible.
Does delegation eliminate director responsibility?
No. Delegation can improve control and clarify responsibility, but directors retain applicable statutory and governance duties.
What is the most useful director-risk document?
A current delegation and reserved-matters matrix, supported by accurate minutes and compliance ownership, is usually foundational.
Authoritative references
Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.