Meta description: Build a compliance KPI dashboard for an Indian SME using 12 measurable indicators for deadlines, legal changes, evidence, owners and risk control.
One missed annual return can expose a company to a ₹10,000 penalty plus ₹100 for every continuing day under Section 92(5) of the Companies Act, 2013. Yet a dashboard that shows only “95% compliant” can hide that exact failure. A useful compliance KPI dashboard tells an owner what is late, what can fail next and who must act before the cost grows.
This guide gives Indian SME owners, compliance officers and CA/CS practices 12 practical metrics, calculation formulas, reporting thresholds and a monthly review routine. It also explains how to connect the dashboard to the underlying law, obligation, evidence and business entity so that a green chart reflects reality rather than tidy reporting.
Why a Compliance KPI Dashboard Must Show Risk, Not Activity
Compliance teams often report activity: 43 filings completed, 19 circulars reviewed and eight licences renewed. Those numbers prove that work happened. They do not answer management's real questions:
- Which legal duty is already overdue?
- Which high-consequence task is due before the next review?
- Has a regulatory change been assessed for every affected site?
- Can the business produce evidence if an inspector arrives tomorrow?
- Is the same control failing month after month?
A dashboard is the reporting layer, not the source of truth. Every number should trace back to a compliance obligation register, a dated task, a named owner and acceptable evidence. If the denominator is incomplete, a perfect percentage is meaningless.
Do not combine all laws into one national score. Indian businesses can face central, state, municipal, sectoral and licence-specific duties at the same time. Report by legal entity and establishment, then break the results down by jurisdiction and risk. A Maharashtra factory and a Karnataka sales office do not have the same obligation set.
The law does not prescribe one universal “compliance score” for Indian companies. The metrics and thresholds below are management controls. The underlying deadlines and consequences remain those in the applicable Act, rules, notification, licence or order.
Use These 12 Compliance KPI Dashboard Metrics
Start with these metrics. Add a measure only when it changes a decision or triggers an action.
1. On-time completion rate
Formula: obligations completed on or before the due date ÷ obligations due in the period × 100.
Count a task as complete only when the action and required review are finished. A consultant saying “filed” is not completion if the acknowledgement is missing. Show the percentage beside the raw count so that “99%” cannot conceal one serious default.
Suggested internal threshold: green at 98% or more, amber at 95% to 97.9%, and red below 95%. Override the colour to red whenever a critical obligation is late, regardless of the aggregate rate.
2. Critical overdue obligations
Formula: count of overdue obligations rated critical under the approved risk method.
The target is zero. List each exception with the legal source, entity, site, due date, days overdue, owner and immediate remedy. Do not let ten low-risk training records dilute an overdue statutory payment.
For example, Paragraph 38 of the Employees' Provident Funds Scheme, 1952 requires covered employers to remit contributions within 15 days after the close of the month. An EPFO order applying Paragraph 38 and Section 7Q confirms 12% annual interest on delayed amounts; Section 14B of the Employees' Provident Funds and Miscellaneous Provisions Act, 1952 also permits damages. A late EPF remittance belongs in the critical exception list, not inside a blended percentage.
3. Weighted overdue exposure
Formula: sum of each overdue item's risk score, using likelihood × consequence × days-overdue band.
Use an approved scoring method from your regulatory compliance risk assessment. Keep statutory penalties separate from estimated operational exposure. Do not present the theoretical maximum penalty as a certain liability.
A simple model can score consequence from 1 to 5, likelihood from 1 to 5 and ageing as 1 for 1-7 days, 2 for 8-30 days and 3 for more than 30 days. The model is an internal prioritisation tool, not a legal conclusion.
4. Due-soon coverage
Formula: obligations due in the next 30 days with an owner, planned completion date and evidence requirement ÷ all obligations due in that window × 100.
This is the dashboard's early-warning metric. Report separate seven-day and 30-day views. A deadline known only to the consultant is not covered; an internal owner must know what will be filed, paid, renewed or approved.
5. Applicability review freshness
Formula: applicable and not-applicable obligations reviewed within the approved interval ÷ total obligations × 100.
Record the facts behind applicability: employee count, turnover, activity, state, installed power, product category, licence and business structure. “Not applicable” must have evidence and a next review trigger. New hiring, a factory expansion, entry into another state or a new product can make an old conclusion wrong overnight.
6. Regulatory change triage time
Formula: median hours from publication or verified receipt of a regulatory change to relevance classification.
Triage means deciding whether a notification, circular, amendment or order could affect the business. It does not mean implementing it. Track the median and the slowest critical case. The clock should use the original regulator publication where available, not the date a newsletter happened to mention it.
7. Change implementation lead time
Formula: median days from a change being marked applicable to all required controls, documents and training being completed.
Connect every change to affected entities, processes, owners, tasks and proof. A legal memo without an updated payroll rule, label, register or operating procedure is interpretation, not implementation. Track overdue change actions separately from routine filings.
8. Evidence completeness rate
Formula: completed obligations with the defined evidence package ÷ completed obligations sampled × 100.
Evidence might include a portal acknowledgement, challan, signed register, licence, board minutes, inspection record or training attendance. Define the package before the task starts. A screenshot without the entity, period or reference number may prove nothing.
For Employee State Insurance, Regulation 31 of the Employees' State Insurance (General) Regulations, 1950 requires payment within 15 days after the relevant month. The ESIC's 2017 amendment changed the period from 21 days to 15 days. The evidence pack should therefore link payroll inputs, contribution computation, challan, payment proof and the correct employer code and period.
9. First-pass review acceptance
Formula: submissions accepted by the reviewer without correction ÷ submissions reviewed × 100.
This reveals quality problems that on-time completion misses. Tag the reason for rejection: wrong entity, incorrect period, missing attachment, inconsistent amount, outdated form or absent approval. Use the trend to fix the process rather than blame the filer.
10. Repeat exception rate
Formula: current-period exceptions whose root cause appeared in an earlier period ÷ all current-period exceptions × 100.
A repeat miss means the corrective action failed or never happened. Link each exception to a root cause, corrective owner, target date and effectiveness test. “Team reminded” is not a durable control.
11. Entity and site coverage
Formula: active entities and establishments with a current obligation register and calendar ÷ total active entities and establishments × 100.
Reconcile the denominator to finance, HR and operations records. Include warehouses, branches, shops, project sites and factories where they create separate duties. A new site absent from the system makes every other dashboard percentage suspect.
12. Management action closure
Formula: compliance actions closed by the agreed date ÷ compliance actions due in the period × 100.
This prevents review meetings from becoming theatre. Each action needs one owner, one date and proof of closure. Keep overdue high-risk actions visible until independently verified; do not reset their dates to make the chart green.
Build the Dashboard from a Complete Compliance Data Model
The dashboard needs one row per obligation occurrence, not one row per Act. At minimum, store:
- legal entity and establishment;
- central, state, municipal or sectoral jurisdiction;
- full law, section, rule, notification or licence condition;
- plain-language obligation and applicability basis;
- risk rating and consequence type;
- frequency, trigger and calculated due date;
- responsible owner and independent reviewer;
- status, completion date and review date;
- required evidence and evidence link;
- regulatory-change source and last verification date; and
- exception, root cause and corrective action.
Keep status definitions strict. “In progress” should not pause ageing. “Completed” should require evidence. “Not applicable” should require an approved reason. “Awaiting consultant” should still have an internal owner.
Your dashboard should let a reviewer move from a red metric to the affected obligation in one click. If the chart and evidence live in separate files with inconsistent IDs, reconciliation will eat the time that automation was supposed to save.
Test the Dashboard with Real Indian Compliance Scenarios
Before management relies on the numbers, test whether the model handles real rules correctly.
Company annual return: Section 92(4) of the Companies Act, 2013 requires a company to file its annual return within 60 days of the annual general meeting, or the date on which the meeting should have been held. Under Section 92(5) in the official Companies Act text, failure attracts a ₹10,000 penalty plus ₹100 for each continuing day, capped at ₹2 lakh for the company and ₹50,000 for an officer in default. The dashboard should calculate the due date from the AGM date, identify the company and form, and show the acknowledgement.
Monthly social-security payment: EPF and ESI use a recurring 15-day payment rule, but they arise under different statutes and require different calculations and evidence. They should remain separate obligations even if payroll owns both.
POSH annual reporting: Section 21 of the Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013 requires the Internal Committee or Local Committee to prepare an annual report each calendar year. Section 22 requires the employer to include case and disposal information in its organisation's annual report or intimate it to the District Officer where no such report is required. Section 26 permits a fine up to ₹50,000 for non-compliance. The official Act text should anchor the obligation; applicable rules and local District Officer instructions should define the submission evidence.
These tests expose weak design. A dashboard fails if it cannot distinguish a calendar-year report from a monthly payment, calculate an event-based company filing or preserve different evidence by establishment.
Run a 30-Minute Monthly Compliance Review
Send the dashboard one business day before the meeting. Do not spend the meeting reading it aloud.
Use this agenda:
- Critical exceptions, 10 minutes: decide immediate containment, filing, payment, regulator communication or legal review.
- Next 30 days, 5 minutes: confirm owner, reviewer, planned date and dependencies for every high-risk obligation.
- Regulatory changes, 5 minutes: approve applicability conclusions and implementation actions.
- Repeat failures, 5 minutes: review root cause and whether the corrective control worked.
- Decisions and resources, 5 minutes: assign one owner and date to every management action.
Archive the dashboard version, attendance, decisions and action log. The meeting record should show what management knew and what it authorised. Restrict access to sensitive information, especially complaint details. A POSH dashboard should report permitted aggregate status; Section 16 of the 2013 Act prohibits publication or disclosure of complaint and inquiry contents in the manner specified there.
Start with a spreadsheet only if one person manages a small, stable obligation set. Once the business spans several entities, sites or advisers, manual reconciliation becomes a control risk. This comparison of compliance calendar software and Excel gives a practical switching test.
Compliance Radar can map the rules that apply to the business, turn them into a timeline and monitor regulatory changes across jurisdictions. That gives the dashboard a live obligation base instead of a workbook that decays after its creator leaves.
Compliance KPI Dashboard FAQ
What is the most important compliance KPI for an Indian SME?
Critical overdue obligations is the first metric to review because one serious miss can matter more than hundreds of completed low-risk tasks. Pair it with due-soon coverage so management sees both failure and prevention.
Is there a legally prescribed compliance score in India?
No universal score applies to every Indian business. Specific laws prescribe duties, dates, records, returns and penalties. A dashboard score is an internal management control and must remain traceable to those sources.
How often should the dashboard be updated?
Update task status and evidence as work happens. Review critical exceptions at least weekly and run a formal management review monthly. Businesses with daily regulatory exposure may need more frequent change monitoring.
Should penalties be added into one exposure number?
Not blindly. Separate fixed penalties, continuing penalties, interest, damages, prosecution risk, licence risk and operational loss. Have counsel or the relevant professional validate legal exposure; use weighted risk scores only for internal prioritisation.
Can a CA, CS or consultant own the dashboard?
An adviser can prepare filings and maintain data, but the business should retain a named internal owner for each obligation. Management controls the facts, resources and operating changes that determine compliance.
How do we stop teams gaming the metrics?
Lock definitions, require evidence for completion, preserve original due dates and audit a sample each month. Show raw counts beside percentages and make every critical miss red regardless of the overall score.
What should a board or founder see on one page?
Show critical overdue items, the 30-day risk window, regulatory changes awaiting action, repeat exceptions, evidence gaps and overdue management actions. Keep operational detail available through drill-down rather than crowding the summary.
Turn the Compliance KPI Dashboard into an Early-Warning System
A compliance KPI dashboard earns its place only when it changes action before a deadline, inspection or penalty. Build it from complete obligations, keep jurisdictions separate, require evidence and force every red item to have one owner and one date.
Do not wait for a neat percentage to tell you the underlying register is incomplete. Check your compliance posture free at complianceradar.in and build the dashboard on the rules that actually apply to your business.