Quarterly Board Compliance Dashboard in India: Legal, Regulatory & Risk Reporting Framework 2026
A practical governance system for converting compliance calendars, legal notices, litigation, contracts, workforce issues, data risks and remediation into one decision-ready Board dashboard.
A compliance dashboard is not merely a colourful version of a statutory calendar. Its purpose is to tell directors, promoters and senior management whether the company’s legal and regulatory control environment is functioning—and where it is not.
Many companies already possess the underlying data. The Company Secretary has ROC status; Finance has GST and tax notices; HR has labour, POSH and contractor issues; Legal has disputes and contracts; IT has cyber and access incidents; Procurement has vendor exceptions; Operations has licences and local approvals. The governance failure occurs when these data streams never reach the Board in a coherent, prioritised form.
A quarterly Board compliance dashboard should therefore answer five questions:
- What material obligations applied during the quarter?
- Which were completed, delayed, breached or disputed?
- What financial, regulatory or operational exposure exists?
- What remediation is open and who owns it?
- What decisions, resources or escalation does the Board need to provide?
1. Why a Board dashboard matters legally
The Companies Act, 2013 gives the Board a governance role that cannot sensibly be discharged through annual hindsight alone. Section 134(5) includes a directors’ responsibility statement that, among other matters, addresses proper systems to ensure compliance with applicable laws and whether those systems were adequate and operating effectively. Section 166 requires due and reasonable care, skill, diligence and independent judgment.
Where an Audit Committee is applicable, section 177 places further emphasis on oversight of internal financial controls and risk-management systems. For listed entities, the current SEBI LODR Regulations, last amended 14 July 2026, impose additional Board and committee governance requirements.
The practical implication is not that directors must personally perform every compliance task. It is that management should create a reliable reporting architecture so the Board can identify material defaults, challenge management explanations, record decisions and verify remediation.
For the detailed company-level audit from which a dashboard can be built, see our Legal Compliance Audit for Private Limited Companies in India.
2. Dashboard architecture: one page first, detail behind it
The Board should receive a concise executive page first. Detailed schedules should sit behind it. A useful top page may include:
| Metric | What it shows |
|---|---|
| Applicable obligations | Total material compliance items tracked |
| Completed on time | Control reliability |
| Overdue | Immediate process failure |
| Critical / high risks | Matters needing executive or Board focus |
| Open regulator / legal notices | External enforcement exposure |
| Material litigation | Claim value, stage and trend |
| Overdue remediation | Management execution failure |
| Decisions required | Board approvals / risk acceptance / resources |
The Board should be able to understand the quarter’s legal-risk position within minutes, then drill into the detailed schedules where necessary.
3. Module A: Companies Act and secretarial compliance
This module should cover applicable ROC filings, Board and shareholder meetings, minutes, statutory registers, share capital events, charges, beneficial ownership, director disclosures, related-party approvals and other entity-specific obligations.
Recommended dashboard fields include:
- obligation / form / event;
- statutory due date;
- actual completion date;
- status—green, amber, red;
- penalty or legal consequence if delayed;
- responsible officer;
- evidence reference; and
- remediation if incomplete.
Do not show every routine filing to the Board if it was completed normally. Summarise normal compliance and separately disclose exceptions, significant changes and matters requiring approval.
4. Module B: tax, GST and financial-regulatory exposure
The objective is not to turn directors into tax reviewers. The Board needs exception-level visibility. Useful metrics include:
- material tax/GST notices received during the quarter;
- demands raised and amount disputed;
- appeal deadlines;
- large reconciliation exceptions;
- TDS or statutory-dues delays;
- bank covenant or lender-compliance issues;
- contingent liabilities requiring legal assessment; and
- open items that could affect financial statements or cash flow.
Where a notice is material, the dashboard should state the issue, amount, deadline, management position, counsel/tax-adviser status and next decision—not simply “under process.”
5. Module C: labour, HR and workplace compliance
Since the four Labour Codes became effective on 21 November 2025, companies in 2026 should ensure their workforce-compliance reporting reflects the operative Code framework together with applicable rules, state requirements and continuing transitional issues. The Ministry of Labour and Employment maintains the official Labour Codes resource.
A quarterly dashboard can report:
- wage and social-security exceptions;
- contractor compliance failures;
- working-condition / establishment issues;
- material employee disputes or terminations;
- POSH Internal Committee status where applicable;
- complaints, without inappropriate disclosure of confidential details;
- gratuity / bonus / leave exposure where material;
- BGV or integrity exceptions; and
- policy or appointment-letter remediation.
Board reporting should preserve confidentiality. Sensitive workplace complaints should be escalated through the legally appropriate route, not reproduced in an unnecessarily detailed dashboard.
6. Module D: contracts and commercial exposure
Contract risk deserves Board visibility when it affects revenue, business continuity or large contingent liabilities. Track:
- top contracts expiring in the next 90/180 days;
- change-of-control or consent issues;
- unlimited liability or unusual indemnity exposure;
- major SLA penalties or service credits;
- customer concentration;
- material payment defaults;
- auto-renewals requiring action;
- unresolved contract deviations from approved templates; and
- critical contracts operating without executed documentation.
For deeper contract testing, see our Contract Risk Audit in India.
7. Module E: litigation, notices and investigations
The dashboard should distinguish three separate things:
- Litigation: matters already before courts, tribunals or arbitral forums.
- Regulatory / legal notices: matters that may escalate if not handled.
- Internal investigations: allegations or control failures being examined internally.
For each material external matter, capture forum, claim/demand amount, stage, next deadline, risk assessment, provision/contingency status, counsel owner and decision required. For internal investigations, preserve confidentiality and avoid labelling allegations as proved until findings are reached.
See our Board-Led Corporate Internal Investigations in India for investigation governance.
8. Module F: vendor and third-party risk
The Board does not need every vendor KYC file. It does need visibility into systemic third-party weaknesses such as:
- high-value vendors without complete due diligence;
- related-party or conflict indicators;
- bank-detail change exceptions;
- critical outsourced functions without current contracts;
- data-processing vendors without adequate terms;
- concentration on a single critical supplier;
- repeated procurement-policy overrides; and
- material claims, fraud or service failures.
For the detailed framework, see Third-Party Risk Management in India.
9. Module G: data protection and cyber readiness
MeitY notified the Digital Personal Data Protection Rules, 2025 with staged commencement. A 2026 dashboard should therefore distinguish currently operative obligations from future-dated requirements and track transition readiness.
Useful Board metrics include:
- material cyber incidents;
- personal-data breaches or suspected breaches;
- privileged-access exceptions;
- critical vulnerabilities overdue for remediation;
- employee offboarding failures;
- third-party data-risk exceptions;
- data inventory / retention gaps;
- DPDP readiness milestones; and
- incident-response testing status.
A Board dashboard should not expose sensitive technical details that increase security risk. Report severity, business impact, remediation and residual exposure.
10. Module H: licences, permits and sectoral regulation
For licence-dependent businesses, this can be the most important dashboard module. Track:
- licence / registration;
- issuing authority;
- expiry / renewal date;
- conditions of licence;
- inspection or notice status;
- responsible business owner;
- renewal evidence; and
- business consequence of lapse.
A licence whose lapse can stop operations should automatically be a critical risk well before the expiry date.
11. Build the dashboard around exceptions, not activity
A common reporting failure is to show how much work Legal, HR or Compliance performed. The Board needs risk information, not departmental activity counts. “Reviewed 87 contracts” is less useful than “three critical customer contracts expire within 60 days and one contains a termination-for-convenience right accounting for 28% of revenue.”
Similarly, “conducted employee training” is less useful than “12% of mandatory population remains untrained and two high-risk sites have no completion evidence.”
12. Use a decision-required column
Every Board dashboard should contain a section called Decisions Required. Examples:
- approve settlement authority;
- accept a specified residual risk;
- approve remediation budget;
- authorise external investigation;
- approve policy or delegation change;
- authorise regulatory filing or compounding strategy;
- approve termination of a high-risk vendor;
- approve insurance enhancement; or
- direct management to close an overdue control gap.
This converts reporting from passive information into governance action.
13. Sample quarterly dashboard
| Area | Status | Material exception | Owner | Deadline | Board action |
|---|---|---|---|---|---|
| Corporate | Amber | One charge-satisfaction filing pending | CS / CFO | 15 days | Note remediation |
| Contracts | Red | Critical customer renewal unresolved | Sales / Legal | 30 days | Approve negotiation position |
| Data | Amber | Bulk CRM export control incomplete | CTO | 21 days | Approve remediation budget |
| Litigation | Red | Material claim; interim hearing next month | Legal | Ongoing | Approve settlement ceiling |
14. Certifications behind the dashboard
The Board dashboard should not depend on one person manually guessing whether functions complied. A stronger model uses function-level certifications:
- Company Secretary—corporate and secretarial;
- CFO / Tax Head—tax, finance and lender covenants;
- HR Head—workforce and workplace compliance;
- IT / Security Head—cyber and access-control exceptions;
- Procurement Head—vendor and procurement exceptions;
- Legal Head—litigation, contracts, notices and investigations;
- Business Heads—licences and operational controls.
These certifications should be evidence-based and subject to challenge. A sign-off should not become a ritual that shields weak controls.
15. Link dashboard items to a corporate risk register
Every material dashboard exception should be tested for entry into the enterprise risk register. A late filing may remain a routine compliance exception. A pattern of repeated late filings across entities may become a governance risk. A single contract dispute may remain a legal matter; repeated disputes caused by poor templates may become an enterprise contract-risk issue.
See our Corporate Risk Register in India for the full scoring and ownership framework.
16. What should never be hidden from the Board?
Escalation thresholds should be defined in advance. Matters that commonly warrant prompt Board or committee visibility include:
- material fraud or credible senior-management misconduct allegations;
- significant regulator or enforcement notices;
- material litigation or injunction risk;
- serious cyber or data incidents;
- licence suspension or lapse risk affecting operations;
- large statutory dues or persistent payment defaults;
- significant related-party or conflict concerns;
- repeated control failures after prior remediation;
- major whistleblower allegations;
- events that may materially affect financial statements, continuity or reputation.
The exact threshold should reflect the business, sector and delegation framework.
17. Common dashboard mistakes
- Reporting only statutory filings and ignoring contracts, disputes, vendors and data.
- Calling everything “green” because no regulator has yet acted.
- Using vague statuses such as “under process.”
- Not showing overdue remediation.
- Reporting raw complaint details that should remain confidential.
- Failing to quantify material financial exposure.
- No named owner or deadline.
- No comparison with previous quarter.
- No “decisions required” section.
- Changing scoring criteria quarter to quarter to make performance look better.
18. 30-day implementation plan
Week 1: identify data owners and inventory existing calendars, trackers, notices, litigation schedules, contract registers and risk reports.
Week 2: define materiality, red/amber/green criteria, escalation thresholds and standard reporting fields.
Week 3: create function-level certifications, consolidate open exceptions and validate evidence.
Week 4: prepare the first Board pack, identify decisions required, minute the review and start remediation tracking.
Frequently asked questions
Is a quarterly compliance dashboard mandatory for every private company?
No universal prescribed dashboard applies to every private company. It is a governance mechanism that should be tailored to applicable law, company class, sector, scale and Board structure.
Should every compliance item be presented to the Board?
No. Routine completed items can be summarised. The Board should receive material exceptions, trends, overdue remediation and matters requiring decisions.
Who prepares the dashboard?
One function may coordinate it, but the data should come from accountable business and control owners and be supported by evidence.
Can the dashboard replace a legal compliance audit?
No. A dashboard monitors status. Periodic audits test whether the underlying legal universe, controls and evidence are complete and reliable.
How should sensitive investigations be reported?
At the level necessary for governance, while preserving confidentiality, fairness, privilege considerations and investigation integrity.
Related resources
- Corporate Risk & Compliance Resources
- Corporate Legal Risk Audit in India
- Corporate Legal Health Check Before a Crisis
- Director Liability Risk Mitigation
Organisations seeking a structured discussion on legal compliance dashboards, risk registers, governance reporting or remediation frameworks may use the corporate enquiry form for preliminary information exchange.
Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.