A factory in Pune was fined ₹2 lakh under Section 15 of the Environment (Protection) Act, 1986 for operating without a valid Consent to Operate from the Maharashtra Pollution Control Board. The owner had applied for renewal six months late, assumed it was "in process," and kept running. The pollution board did not care about the assumption. The penalty was ₹10,000 minimum plus ₹10,000 for every day the violation continued - and the factory was shut for 11 days until the consent came through.
That is what compliance risk looks like when you do not assess it. You find out from the penalty notice, not from a checklist.
This article gives you a compliance risk assessment template built for Indian businesses - one you can actually use to identify, score, and mitigate the obligations that apply to you across GST, labour, company law, environmental, and sector-specific regulations. It is not theoretical. Every section, penalty amount, and threshold cited here is current as of 2026.
What Is a Compliance Risk Assessment?
A compliance risk assessment is a structured process of identifying every law and regulation that applies to your business, evaluating how likely you are to miss or violate each one, estimating the financial and operational consequence of that failure, and prioritising corrective action accordingly.
Think of it as a health checkup for your business's legal obligations. You would not wait for a heart attack to check your blood pressure. You should not wait for a penalty notice to check whether your PF contributions are being deposited on time.
The assessment answers four questions for every applicable regulation:
- What is the obligation, and which law creates it?
- How likely are we to miss it - have we missed it before, is it complex, does it depend on a third party?
- What happens if we miss it - penalty amount, imprisonment risk, licence cancellation, business shutdown?
- What do we need to do to close the gap?
Why Indian SMEs Need This Now More Than Ever
The regulatory landscape in India has shifted significantly in 2025-2026. The Code on Social Security, 2020 came into force on November 21, 2025, subsuming the EPF Act 1952 and changing wage definitions under Section 2(88). The ECR 3.0 system (mandatory from September 2025) now automates Section 7Q interest and Section 14B damages calculation - there is no practical grace period for delayed EPF remittance. GST e-invoice thresholds have dropped. The DPDP Act, 2023 is being enforced. Labour codes are being notified state by state.
For a business owner, this means the compliance surface area is expanding while the tolerance for delay is shrinking. A risk assessment that was "nice to have" in 2023 is now essential.
The cost of not doing one is concrete:
- GST late filing: ₹50 per day (₹25 CGST + ₹25 SGST) under Section 47 of the CGST Act, capped at ₹10,000 per return, plus 18% annual interest on unpaid tax under Section 50.
- AOC-4 late filing: ₹10,000 fine plus ₹100 per day under Section 137(3) of the Companies Act, 2013, capped at ₹2,00,000 for the company and ₹50,000 per officer.
- MGT-7 late filing: ₹10,000 plus ₹100 per day under Section 92(5), same caps.
- PF default: Section 7Q interest at 12% per annum plus Section 14B damages - now a flat 1% per month under the amended Paragraph 32A for post-June 2024 defaults.
- FSSAI operation without licence: penalty up to ₹10,00,000 under Section 63 of the Food Safety and Standards Act, 2006.
- Environmental violation: ₹10,000 to ₹15,00,000 under Section 15 of the Environment (Protection) Act, 1986, plus ₹10,000 per day for continuing contravention.
- Fraud under Companies Act: Section 447 prescribes imprisonment from six months to ten years and fine up to three times the amount involved - for fraud involving ₹10 lakh or 1% of turnover, whichever is lower.
These are not abstract numbers. They are the direct financial consequence of not knowing what applies to you.
The Compliance Risk Assessment Template
Below is a five-step template you can apply to your business today. Each step includes the framework, the scoring methodology, and a worked example.
Step 1: Inventory All Applicable Regulations
List every law, regulation, and filing that applies to your business. This is the foundation - you cannot assess risk for obligations you do not know exist.
Start with these categories and identify what applies based on your business type, industry, location, and employee count:
Company Law (applies to all registered companies)
- Companies Act, 2013 - ROC filings (AOC-4, MGT-7), DIN compliance, Section 134 disclosures
- Section 92: Annual return filing within 60 days of AGM
- Section 137: Financial statement filing (AOC-4) within 30 days of AGM
- Section 447: Fraud prevention and reporting
Tax and GST (applies to all registered businesses)
- CGST/SGST Act, 2017 - GSTR-1, GSTR-3B, annual return
- Income Tax Act, 1961 - TDS returns (now Form 140, formerly 26Q), advance tax, ITR
- Section 47: Late fee for delayed GST returns
- Section 50: Interest on unpaid GST at 18% per annum
- E-invoice: mandatory if turnover exceeds ₹5 crore (threshold has been progressively lowered)
Labour and Employment (applies based on employee count)
- EPF Act, 1952 (now under Code on Social Security, 2020) - mandatory at 20+ employees
- ESI Act, 1948 - mandatory at 10+ employees in applicable states (wage ceiling ₹21,000/month)
- Professional Tax - state-specific, varies by state
- Labour Welfare Fund - state-specific (Karnataka, Tamil Nadu, Maharashtra, etc.)
- Minimum Wages Act, 1948
- Payment of Gratuity Act, 1972 - mandatory at 10+ employees
- Factories Act, 1948 - applies to manufacturing units with 10+ workers (with power) or 20+ (without power)
Environmental (applies to manufacturing, processing, and certain service businesses)
- Environment (Protection) Act, 1986 - Consent to Establish (CTE) and Consent to Operate (CTO) from State Pollution Control Board
- Water (Prevention and Control of Pollution) Act, 1974
- Air (Prevention and Control of Pollution) Act, 1981
- Hazardous waste management rules - if applicable to your industry
Sector-Specific
- FSSAI - Food Safety and Standards Act, 2006 (food businesses)
- Legal Metrology Act, 2009 (packaged goods, e-commerce)
- BIS certification (specific product categories)
- CDSCO (pharma, medical devices)
- RERA (real estate)
Action: Create a spreadsheet with columns: Regulation Name | Applicable Act/Section | Jurisdiction (Centre/State/Municipal) | Filing Frequency | Due Date | Responsible Person | Last Filed Date.
Step 2: Score Likelihood of Non-Compliance
For each regulation in your inventory, score how likely you are to miss or violate it. Use a 1-5 scale:
Score | Likelihood | Description
1 | Very Low | Automated, never missed, simple process
2 | Low | Occasionally late but always filed, simple process
3 | Medium | Missed once in the last 12 months, moderate complexity
4 | High | Missed multiple times, complex or depends on third party
5 | Very High | Currently non-compliant or no system to track
Factors that increase likelihood:
- The filing depends on a CA/CS who is reactive, not proactive
- The deadline changes (e.g., GST return dates vary by month)
- Multiple jurisdictions are involved (central + state + municipal)
- You have crossed a threshold recently (e.g., hired your 20th employee, triggering PF)
- The regulation was recently amended and you are unsure of the new requirements
- You rely on manual tracking (Excel, calendar reminders) rather than automated monitoring
Step 3: Score Impact of Non-Compliance
Score the consequence of missing each obligation on a 1-5 scale:
Score | Impact | Description
1 | Very Low | Minor additional fee, no operational impact
2 | Low | Moderate fine, no licence risk
3 | Medium | Significant fine (₹50,000+), possible notice
4 | High | Large fine (₹2,00,000+), licence suspension risk
5 | Very High | Imprisonment risk, business shutdown, criminal liability
Use the penalty data from the section above to assign impact scores. For example:
- GST return late filing (Section 47): Impact = 2 (capped at ₹10,000 per return, no licence risk)
- AOC-4 / MGT-7 late filing (Sections 137/92): Impact = 3 (₹2,00,000 company cap, officer liability)
- PF default (Sections 7Q + 14B): Impact = 4 (12% interest + damages, EPFO assessment, reputational damage)
- Operating without FSSAI licence (Section 63): Impact = 5 (₹10,00,000 penalty, business shutdown)
- Environmental violation (Section 15, EPA): Impact = 5 (₹15,00,000 + daily penalty + factory closure)
Step 4: Calculate Risk Score and Prioritise
Multiply Likelihood × Impact to get a Risk Score (1-25). Sort your inventory by risk score in descending order.
Risk Score | Priority | Action Timeline
20-25 | Critical | Fix within 7 days
15-19 | High | Fix within 30 days
10-14 | Medium | Fix within 90 days
5-9 | Low | Monitor and maintain
1-4 | Very Low | Maintain current process
Worked Example: A food processing company in Maharashtra with 35 employees:
Regulation | Likelihood | Impact | Risk Score | Priority
FSSAI licence renewal (Section 63, FSSA 2006) | 3 | 5 | 15 | High
PF remittance (Section 7Q/14B, EPF Act) | 2 | 4 | 8 | Low
Consent to Operate renewal (Section 15, EPA 1986) | 4 | 5 | 20 | Critical
GSTR-3B filing (Section 47, CGST Act) | 1 | 2 | 2 | Very Low
AOC-4 filing (Section 137, Companies Act 2013) | 2 | 3 | 6 | Low
Professional Tax (Maharashtra) | 3 | 2 | 6 | Low
In this example, the Consent to Operate renewal is the highest risk - high likelihood (renewal is overdue or complex) and very high impact (factory can be shut down). That is where the owner should focus first.
Step 5: Build a Mitigation Plan
For each regulation with a risk score of 10 or above, document:
- Current status: Compliant / At risk / Non-compliant
- Gap description: What specifically is missing or wrong
- Action required: The specific step to close the gap
- Owner: Who is responsible (internal team, CA, CS, consultant)
- Deadline: When the action must be completed
- Verification: How you will confirm the gap is closed (receipt, acknowledgement, certificate)
Compliance Risk Assessment Template (Copy This)
Here is a blank template you can copy into a spreadsheet:
COMPLIANCE RISK ASSESSMENT - [Company Name]
Date: [DD/MM/YYYY]
Assessed by: [Name/Role]
| # | Regulation | Act & Section | Jurisdiction | Frequency | Due Date | Responsible | Likelihood (1-5) | Impact (1-5) | Risk Score (L×I) | Priority | Current Status | Action Required | Deadline | Verified |
|--|------|-------|-------|------|-----|------|---------|-------|----------|-----|--------|--------|-----|-----|
| 1 | | | | | | | | | | | | | | |
| 2 | | | | | | | | | | | | | | |
| 3 | | | | | | | | | | | | | | |
SUMMARY
- Critical (20-25): ___ items
- High (15-19): ___ items
- Medium (10-14): ___ items
- Low (1-9): ___ items
NEXT REVIEW DATE: [DD/MM/YYYY]
Review this assessment at least quarterly, and immediately after any of these triggers:
- Hiring employees past a regulatory threshold (10, 20, 50, 100)
- Expanding to a new state or city
- Adding a new product line or service
- Receiving any notice or inspection
- A regulatory amendment in your industry
Common Mistakes in Compliance Risk Assessment
Mistake 1: Treating it as a one-time exercise. Regulations change. The PF penalty regime changed in June 2024. The Code on Social Security came into force in November 2025. GST e-invoice thresholds keep dropping. An assessment done in 2024 is already stale.
Mistake 2: Only listing what you already know. The most dangerous regulations are the ones you have not identified. A food business that does not know about Legal Metrology packaging requirements. A manufacturer that does not know about hazardous waste rules. A startup that does not know about ESOP compliance filings. The inventory step must be exhaustive - when in doubt, include it.
Mistake 3: Underestimating impact. Business owners routinely score impact too low because they think "it is just a fine." A ₹2,00,000 penalty under Section 137 of the Companies Act is not just a fine - it is a red flag on your company's MCA record that lenders, investors, and partners can see. Score impact on the worst-case scenario, not the best.
Mistake 4: No ownership. A risk assessment without named owners is a document that nobody acts on. Every regulation in your inventory must have a person - by name, not by department - who is responsible for it.
Mistake 5: Ignoring state-level variation. Professional tax, labour welfare fund, factory licence fees, and pollution board consent processes all vary by state. A business operating in Maharashtra, Karnataka, and Tamil Nadu has three different compliance profiles for the same categories. Your assessment must be state-specific.
How to Use This Assessment With Compliance Radar
The entire point of this template is to move from reactive to proactive compliance. But maintaining a spreadsheet manually is itself a risk - deadlines shift, regulations change, and the spreadsheet goes stale the moment you stop updating it.
Compliance Radar does this assessment for you automatically. You describe your business once - industry, location, employee count, business structure - and the platform builds a complete timeline of every applicable compliance, every government scheme you qualify for, and real-time alerts when a regulation changes.
Instead of scoring likelihood and impact manually, you get a live dashboard showing exactly what is due, what is overdue, and what has changed. The free compliance posture check at complianceradar.in takes five minutes and gives you the same inventory this template helps you build - without the manual research.
FAQ
Q: How often should I do a compliance risk assessment?
At minimum, once per quarter. But also reassess immediately after any structural change - new employees crossing a threshold, new state, new product, funding round, or any notice received.
Q: I am a startup with no employees yet. Do I need this?
Yes. From the day you incorporate, you have ROC filing obligations under the Companies Act, 2013. Missing AOC-4 or MGT-7 triggers penalties under Sections 137(3) and 92(5). The assessment helps you see these obligations before they become penalties.
Q: What if my CA already handles compliance?
Your CA files what you tell them to file. If you do not know what applies to your business, your CA does not either - they are not mind readers. The assessment is your way of ensuring nothing falls through the gaps. Also, under Section 447 of the Companies Act, the directors are personally liable for fraud - not the CA.
Q: How do I know which state-level regulations apply to me?
It depends on where your registered office, factories, and employees are located. Professional tax applies in most states but with different rates and thresholds. Labour Welfare Fund applies in Karnataka, Tamil Nadu, Maharashtra, Gujarat, and a few others. Your assessment must list each state where you operate and identify state-specific obligations separately.
Q: What is the single highest-risk compliance area for Indian SMEs?
Environmental consents (CTE/CTO) for manufacturers, because the impact score is maximum - operating without a valid Consent to Operate can shut your factory down under Section 15 of the Environment (Protection) Act, with penalties from ₹10,000 to ₹15,00,000 plus ₹10,000 per day. Many businesses let consents lapse because renewal is a slow, opaque process.
Q: Can I use this template for multiple business entities?
Yes, but run a separate assessment for each entity. A private limited company and an LLP have different filing obligations. A manufacturing unit and a trading office have different sector-specific requirements. Do not combine them.
Q: What happens if I find I am currently non-compliant?
Fix it immediately. For GST, file the pending returns and pay the late fee under Section 47 - the portal calculates it automatically. For PF, remit the contributions and pay the Section 7Q interest (12% per annum) and Section 14B damages (1% per month for post-June 2024 defaults). For ROC filings, file with additional fees. For environmental consents, apply for renewal immediately and cease operations if directed. Ignorance is not a defence under any of these laws.
Conclusion
A compliance risk assessment is not paperwork - it is the difference between finding out you owe ₹2,00,000 in penalties from a notice and catching the gap 30 days before the deadline. The template above gives you the structure. The penalty amounts and section numbers give you the urgency.
Start with the inventory. Score honestly - if you have missed a filing in the last year, score the likelihood as 3 or above. Prioritise anything with an impact of 4 or 5, because those are the obligations that can shut your business down or put you in legal jeopardy.
Then check your compliance posture free at complianceradar.in. The platform builds this assessment for you in five minutes - every applicable regulation, every deadline, every scheme you qualify for - and alerts you when rules change. Because the best penalty is the one you never receive.