Blogs

How Should a Board Assess Compliance Risk?

CS Ranju Goyal   |   26 Aug 2026

(4.3)
25 Views

Compliance failure no longer stops at the company. It reaches directors and key managerial personnel personally, and it surfaces at the worst possible moment: in a data room, in front of an investor, or in front of a regulator.

Quick Answer: A board assesses compliance risk by answering four questions with evidence rather than assurance. First, does a live register exist of every obligation the organisation is actually subject to, across every entity, state and statute. Second, does each obligation have a named owner. Third, what is the current count of overdue or at-risk items. Fourth, when was the last independent audit and what did it find. This sits with the board because personal liability attaches to individuals. Section 164(2) of the Companies Act, 2013 disqualifies a director for five years where the company misses three consecutive years of filings. The Factories Act, the Occupational Safety Code and RERA each impose imprisonment or personal penalty on directors and officers directly.

Last updated: 24 August 2026

Why Is Compliance a Board-Level Risk?

Obligations arrive from four directions at once, and few organisations map all of them before they are forced to. The Centre contributes company law, securities regulation, tax and the labour codes. States add labour departments, shops and establishments registration, professional tax and state GST. Local bodies add trade licences, fire clearances and municipal levies. Cross-border activity adds FEMA and data-protection obligations.

Layered on top of jurisdiction is behaviour. Some obligations are one-time approvals that must simply stay valid. Others are date-based returns that recur and attract automatic penalties the moment a deadline passes. Others are event-based, firing only when a board changes or shares are allotted. A final category is continuous, covering statutory registers and workplace displays that nothing ever reminds a business to check.

Where Does Personal Liability Actually Bite?

Corporate and tax law attract the most board attention. Environment, health and safety (EHS) statutes and sector regulators frequently carry the sharper personal exposure, and are the ones most often left off the map.

Statute Who is exposed Current position
Companies Act, 2013, s.164(2) Directors Disqualification for five years where the company fails to file financial statements or annual returns for three consecutive years
Factories Act, 1948, s.92 Occupier and manager Up to two years imprisonment, or fine up to ₹1 lakh, or both, with daily fines for continuing default
Factories Act, 1948, s.96A Occupier and manager Up to seven years imprisonment and fine up to ₹2 lakh for breach of the hazardous-process duties in ss.41B, 41C and 41H, extending to ten years where the default continues
OSH Code, 2020, s.103 Employer or principal employer Death: up to two years imprisonment, or a fine of not less than ₹5 lakh with no prescribed ceiling, or both. Serious bodily injury: up to one year, or a fine of ₹2 lakh to ₹4 lakh, or both
RERA, 2016, s.59 Promoter Penalty up to 10% of estimated project cost for non-registration, with imprisonment up to three years for continued default
RERA, 2016, s.69 Directors and officers of a promoter company Personal liability where consent, connivance or attributable neglect is established

Note the OSH Code figure carefully. ₹5 lakh is a statutory floor, not a ceiling, and courts may direct that at least half of the fine goes to the victim or the legal heirs.

Which Positions Changed Recently?

Two regimes moved, and material published before those dates is now wrong.

Environmental exposure was decriminalised. Since 1 April 2024, contraventions under the Environment (Protection) Act, 1986 attract a civil penalty of not less than ₹1 lakh and up to ₹15 lakh, determined by an adjudicating officer of Joint Secretary rank or above and appealable to the National Green Tribunal. The five-year imprisonment term was removed.

Does Environmental Imprisonment Still Apply?

Imprisonment did not disappear entirely, and the trigger is the part most often misstated. Where a penalty imposed under the Act is not paid within ninety days, the defaulter becomes liable to imprisonment of up to three years, or a fine of up to twice the penalty, or both. The exposure now attaches to non-payment rather than to the underlying contravention. Any briefing still describing a flat five-to-seven year term predates the change, and the Ministry of Environment, Forest and Climate Change administers the amended framework.

Did RERA Change as Well?

RERA moved in the same direction. With effect from 7 May 2026, Section 68 was substituted to remove imprisonment for an allottee who defies an Appellate Tribunal order, leaving a monetary penalty. Sections 59, 60, 61 and 63, which govern promoter defaults, are unchanged.

Is the Corporate Laws Amendment Bill in Force?

One instrument is frequently cited as though it were already law. The Corporate Laws (Amendment) Bill, 2026, which would amend the Companies Act, 2013 across roughly 107 clauses, proposes expanded grounds for director disqualification. It was reported on by a Joint Parliamentary Committee in August 2026 and has not been enacted. Directors should track it, and should not plan around it as operative law.

How Does a Small Gap Become a Board Problem?

Compliance risk compounds. A missed filing rarely stays a missed filing.

Risk area Immediate consequence Board-level impact
Statutory non-filing Registrar strike-off, account freeze Continuity risk, deal-breaker in diligence
Regulatory penalty Fines, prosecution of officers Cash drain, board credibility, valuation
Labour law breach Inspection, show-cause notice Workforce disruption, governance red flag
Data protection breach Regulatory notice, litigation Customer trust, flagged in any M&A review
SEBI or FEMA violation Adjudication, compounding Restrictions on capital, listing delay

What Should a Board Approve This Quarter?

De-risking does not require a compliance department on day one. It requires a small number of structural decisions, made deliberately and documented.

  1. Approve an authority and responsibility matrix covering every function and location.
  2. Make each function head accountable for compliance in their own domain. Compliance owned by everyone is owned by nobody.
  3. Notify the relevant authorities of the designated compliance owners and contacts.
  4. Run role-based training on the obligations that actually apply to each function.
  5. Maintain a live compliance calendar, not a document reviewed once a year.

Six Questions to Ask Every Quarter

A board that can answer these with evidence is a board protecting its directors.

  1. Does a continuously updated register of every applicable obligation exist?
  2. Who is the named owner of each obligation?
  3. What is the current count of overdue or at-risk items?
  4. Have all key managerial personnel signed off on their individual obligations?
  5. Is there an early-warning mechanism before a deadline lapses?
  6. When was the last independent compliance audit, and what did it find?

Where Does Software Change the Equation?

Everything above describes a discipline. The difficulty is sustaining it once an organisation runs several entities, states or countries, because spreadsheets and inbox reminders break well before that point.

What Does a Platform Do That a Tracker Cannot?

This is the work a compliance risk assessment does, and it is why organisations move it into a dedicated system. A credible platform does four things a spreadsheet cannot. It maps the full compliance universe, so risk is assessed against the obligations that genuinely apply rather than the ones someone remembered. It carries compliance, risk and audit in one register, so evidence sits against the obligation it proves instead of in a separate folder. It exposes real-time status, so the overdue and at-risk counts a board asks for are a dashboard rather than a fire drill. And it monitors regulatory change by category, distinguishing an amendment from a new obligation, a notified extension, or a repealed requirement that should be removed from the calendar.

That last capability is what the two 2024 and 2026 changes above illustrate. An organisation tracking obligations manually would still be applying the pre-2024 environmental position today. LexComply's compliance management platform maintains that register across corporate, labour, environmental and sector-specific law, and routes each change to the business unit it actually affects. Its advisory services cover the independent audit a board should be commissioning, and its registration services handle the licences that sit underneath the register.

Common Mistakes to Avoid

  • Treating compliance as a corporate risk only. Disqualification, personal fines and imprisonment attach to named individuals, separately from anything imposed on the company.
  • Mapping corporate and tax law but stopping there. The sharpest personal-prosecution exposure sits in EHS statutes and sector regulators such as RERA.
  • Quoting penalty figures from older briefings. Environmental penalties became civil in April 2024 and RERA changed in May 2026.
  • Citing the Corporate Laws (Amendment) Bill, 2026 as law. It remains a Bill.
  • Reading a fine floor as a ceiling. The OSH Code sets ₹5 lakh as a minimum where a contravention causes death, with no prescribed upper limit.
  • Assuming environmental imprisonment is gone. It is not. It now attaches to non-payment of the penalty within ninety days, not to the contravention itself.

Frequently Asked Questions

Is non-compliance a personal risk for directors or only a company risk?

It is personal. Directors, key managerial personnel and officers-in-charge carry liability distinct from the company, including individual fines, imprisonment under several statutes, and disqualification. Under Section 164(2) of the Companies Act, 2013, three consecutive years of missed filings disqualify a director for five years.

Which laws carry the highest personal prosecution risk?

Environment, health and safety statutes and sector regulators, rather than corporate law. The Factories Act permits up to seven years imprisonment for hazardous-process breaches, the OSH Code sets a fine floor of ₹5 lakh where a contravention causes death, and RERA extends liability to directors of a promoter company under Section 69.

Did environmental penalties change?

Yes. Since 1 April 2024, contraventions of the Environment (Protection) Act, 1986 attract a civil penalty of ₹1 lakh to ₹15 lakh, decided by an adjudicating officer and appealable to the National Green Tribunal. Imprisonment of up to three years now applies only where the penalty is not paid within ninety days.

Is the Corporate Laws (Amendment) Bill, 2026 in force?

No. A Joint Parliamentary Committee reported on it in August 2026, but it has not been enacted. It should be tracked, and it should not be treated as operative law or relied upon in board papers until it receives assent.

How often should a board review compliance status?

Quarterly at minimum. Each review should confirm that a live register exists and that every obligation has a named owner. It should also establish the current count of overdue items, whether key managerial personnel have signed off, and when the last independent audit took place.

Key Takeaways

  • Personal liability, not corporate penalty, is what makes compliance a board matter. Section 164(2) disqualifies a director for five years after three consecutive years of missed filings.
  • EHS statutes and sector regulators carry sharper personal exposure than corporate law, and are the ones most often left off the compliance map.
  • Two positions changed recently: environmental penalties became civil in April 2024, with imprisonment now attaching to non-payment within ninety days rather than to the contravention, and RERA lost an imprisonment clause in May 2026. The Corporate Laws (Amendment) Bill, 2026 is still a Bill.
  • A board assesses compliance risk through evidence: a live register, named owners, a current overdue count, and a recent independent audit.

To scope a compliance risk assessment for your organisation, talk to the LexComply team.

Legal Disclaimer: This article is for general information and reflects the statutes and amendments referred to as at 24 August 2026. It does not constitute legal advice. Confirm the requirements applicable to your organisation with a qualified adviser.