A factory in Pune was fined ₹2 lakh under Section 15 of the Environment (Protection) Act, 1986 for operating without a valid Consent to Operate from the Maharashtra Pollution Control Board. The owner had applied for renewal six months late, assumed it was "in process," and kept running. The pollution board did not care about the assumption. The penalty was ₹10,000 minimum plus ₹10,000 for every day the violation continued - and the factory was shut for 11 days until the consent came through.

That is what compliance risk looks like when you do not assess it. You find out from the penalty notice, not from a checklist.

This article gives you a compliance risk assessment template built for Indian businesses - one you can actually use to identify, score, and mitigate the obligations that apply to you across GST, labour, company law, environmental, and sector-specific regulations. It is not theoretical. Every section, penalty amount, and threshold cited here is current as of 2026.

What Is a Compliance Risk Assessment?

A compliance risk assessment is a structured process of identifying every law and regulation that applies to your business, evaluating how likely you are to miss or violate each one, estimating the financial and operational consequence of that failure, and prioritising corrective action accordingly.

Think of it as a health checkup for your business's legal obligations. You would not wait for a heart attack to check your blood pressure. You should not wait for a penalty notice to check whether your PF contributions are being deposited on time.

The assessment answers four questions for every applicable regulation:

  1. What is the obligation, and which law creates it?
  2. How likely are we to miss it - have we missed it before, is it complex, does it depend on a third party?
  3. What happens if we miss it - penalty amount, imprisonment risk, licence cancellation, business shutdown?
  4. What do we need to do to close the gap?

Why Indian SMEs Need This Now More Than Ever

The regulatory landscape in India has shifted significantly in 2025-2026. The Code on Social Security, 2020 came into force on November 21, 2025, subsuming the EPF Act 1952 and changing wage definitions under Section 2(88). The ECR 3.0 system (mandatory from September 2025) now automates Section 7Q interest and Section 14B damages calculation - there is no practical grace period for delayed EPF remittance. GST e-invoice thresholds have dropped. The DPDP Act, 2023 is being enforced. Labour codes are being notified state by state.

For a business owner, this means the compliance surface area is expanding while the tolerance for delay is shrinking. A risk assessment that was "nice to have" in 2023 is now essential.

The cost of not doing one is concrete:

These are not abstract numbers. They are the direct financial consequence of not knowing what applies to you.

The Compliance Risk Assessment Template

Below is a five-step template you can apply to your business today. Each step includes the framework, the scoring methodology, and a worked example.

Step 1: Inventory All Applicable Regulations

List every law, regulation, and filing that applies to your business. This is the foundation - you cannot assess risk for obligations you do not know exist.

Start with these categories and identify what applies based on your business type, industry, location, and employee count:

Company Law (applies to all registered companies)

Tax and GST (applies to all registered businesses)

Labour and Employment (applies based on employee count)

Environmental (applies to manufacturing, processing, and certain service businesses)

Sector-Specific

Action: Create a spreadsheet with columns: Regulation Name | Applicable Act/Section | Jurisdiction (Centre/State/Municipal) | Filing Frequency | Due Date | Responsible Person | Last Filed Date.

Step 2: Score Likelihood of Non-Compliance

For each regulation in your inventory, score how likely you are to miss or violate it. Use a 1-5 scale:

Score | Likelihood | Description

1 | Very Low | Automated, never missed, simple process

2 | Low | Occasionally late but always filed, simple process

3 | Medium | Missed once in the last 12 months, moderate complexity

4 | High | Missed multiple times, complex or depends on third party

5 | Very High | Currently non-compliant or no system to track

Factors that increase likelihood:

Step 3: Score Impact of Non-Compliance

Score the consequence of missing each obligation on a 1-5 scale:

Score | Impact | Description

1 | Very Low | Minor additional fee, no operational impact

2 | Low | Moderate fine, no licence risk

3 | Medium | Significant fine (₹50,000+), possible notice

4 | High | Large fine (₹2,00,000+), licence suspension risk

5 | Very High | Imprisonment risk, business shutdown, criminal liability

Use the penalty data from the section above to assign impact scores. For example:

Step 4: Calculate Risk Score and Prioritise

Multiply Likelihood × Impact to get a Risk Score (1-25). Sort your inventory by risk score in descending order.

Risk Score | Priority | Action Timeline

20-25 | Critical | Fix within 7 days

15-19 | High | Fix within 30 days

10-14 | Medium | Fix within 90 days

5-9 | Low | Monitor and maintain

1-4 | Very Low | Maintain current process

Worked Example: A food processing company in Maharashtra with 35 employees:

Regulation | Likelihood | Impact | Risk Score | Priority

FSSAI licence renewal (Section 63, FSSA 2006) | 3 | 5 | 15 | High

PF remittance (Section 7Q/14B, EPF Act) | 2 | 4 | 8 | Low

Consent to Operate renewal (Section 15, EPA 1986) | 4 | 5 | 20 | Critical

GSTR-3B filing (Section 47, CGST Act) | 1 | 2 | 2 | Very Low

AOC-4 filing (Section 137, Companies Act 2013) | 2 | 3 | 6 | Low

Professional Tax (Maharashtra) | 3 | 2 | 6 | Low

In this example, the Consent to Operate renewal is the highest risk - high likelihood (renewal is overdue or complex) and very high impact (factory can be shut down). That is where the owner should focus first.

Step 5: Build a Mitigation Plan

For each regulation with a risk score of 10 or above, document:

  1. Current status: Compliant / At risk / Non-compliant
  2. Gap description: What specifically is missing or wrong
  3. Action required: The specific step to close the gap
  4. Owner: Who is responsible (internal team, CA, CS, consultant)
  5. Deadline: When the action must be completed
  6. Verification: How you will confirm the gap is closed (receipt, acknowledgement, certificate)

Compliance Risk Assessment Template (Copy This)

Here is a blank template you can copy into a spreadsheet:

COMPLIANCE RISK ASSESSMENT - [Company Name]
Date: [DD/MM/YYYY]
Assessed by: [Name/Role]

| # | Regulation | Act & Section | Jurisdiction | Frequency | Due Date | Responsible | Likelihood (1-5) | Impact (1-5) | Risk Score (L×I) | Priority | Current Status | Action Required | Deadline | Verified |
|--|------|-------|-------|------|-----|------|---------|-------|----------|-----|--------|--------|-----|-----|
| 1 | | | | | | | | | | | | | | |
| 2 | | | | | | | | | | | | | | |
| 3 | | | | | | | | | | | | | | |

SUMMARY
- Critical (20-25): ___ items
- High (15-19): ___ items
- Medium (10-14): ___ items
- Low (1-9): ___ items

NEXT REVIEW DATE: [DD/MM/YYYY]

Review this assessment at least quarterly, and immediately after any of these triggers:

Common Mistakes in Compliance Risk Assessment

Mistake 1: Treating it as a one-time exercise. Regulations change. The PF penalty regime changed in June 2024. The Code on Social Security came into force in November 2025. GST e-invoice thresholds keep dropping. An assessment done in 2024 is already stale.

Mistake 2: Only listing what you already know. The most dangerous regulations are the ones you have not identified. A food business that does not know about Legal Metrology packaging requirements. A manufacturer that does not know about hazardous waste rules. A startup that does not know about ESOP compliance filings. The inventory step must be exhaustive - when in doubt, include it.

Mistake 3: Underestimating impact. Business owners routinely score impact too low because they think "it is just a fine." A ₹2,00,000 penalty under Section 137 of the Companies Act is not just a fine - it is a red flag on your company's MCA record that lenders, investors, and partners can see. Score impact on the worst-case scenario, not the best.

Mistake 4: No ownership. A risk assessment without named owners is a document that nobody acts on. Every regulation in your inventory must have a person - by name, not by department - who is responsible for it.

Mistake 5: Ignoring state-level variation. Professional tax, labour welfare fund, factory licence fees, and pollution board consent processes all vary by state. A business operating in Maharashtra, Karnataka, and Tamil Nadu has three different compliance profiles for the same categories. Your assessment must be state-specific.

How to Use This Assessment With Compliance Radar

The entire point of this template is to move from reactive to proactive compliance. But maintaining a spreadsheet manually is itself a risk - deadlines shift, regulations change, and the spreadsheet goes stale the moment you stop updating it.

Compliance Radar does this assessment for you automatically. You describe your business once - industry, location, employee count, business structure - and the platform builds a complete timeline of every applicable compliance, every government scheme you qualify for, and real-time alerts when a regulation changes.

Instead of scoring likelihood and impact manually, you get a live dashboard showing exactly what is due, what is overdue, and what has changed. The free compliance posture check at complianceradar.in takes five minutes and gives you the same inventory this template helps you build - without the manual research.

FAQ

Q: How often should I do a compliance risk assessment?

At minimum, once per quarter. But also reassess immediately after any structural change - new employees crossing a threshold, new state, new product, funding round, or any notice received.

Q: I am a startup with no employees yet. Do I need this?

Yes. From the day you incorporate, you have ROC filing obligations under the Companies Act, 2013. Missing AOC-4 or MGT-7 triggers penalties under Sections 137(3) and 92(5). The assessment helps you see these obligations before they become penalties.

Q: What if my CA already handles compliance?

Your CA files what you tell them to file. If you do not know what applies to your business, your CA does not either - they are not mind readers. The assessment is your way of ensuring nothing falls through the gaps. Also, under Section 447 of the Companies Act, the directors are personally liable for fraud - not the CA.

Q: How do I know which state-level regulations apply to me?

It depends on where your registered office, factories, and employees are located. Professional tax applies in most states but with different rates and thresholds. Labour Welfare Fund applies in Karnataka, Tamil Nadu, Maharashtra, Gujarat, and a few others. Your assessment must list each state where you operate and identify state-specific obligations separately.

Q: What is the single highest-risk compliance area for Indian SMEs?

Environmental consents (CTE/CTO) for manufacturers, because the impact score is maximum - operating without a valid Consent to Operate can shut your factory down under Section 15 of the Environment (Protection) Act, with penalties from ₹10,000 to ₹15,00,000 plus ₹10,000 per day. Many businesses let consents lapse because renewal is a slow, opaque process.

Q: Can I use this template for multiple business entities?

Yes, but run a separate assessment for each entity. A private limited company and an LLP have different filing obligations. A manufacturing unit and a trading office have different sector-specific requirements. Do not combine them.

Q: What happens if I find I am currently non-compliant?

Fix it immediately. For GST, file the pending returns and pay the late fee under Section 47 - the portal calculates it automatically. For PF, remit the contributions and pay the Section 7Q interest (12% per annum) and Section 14B damages (1% per month for post-June 2024 defaults). For ROC filings, file with additional fees. For environmental consents, apply for renewal immediately and cease operations if directed. Ignorance is not a defence under any of these laws.

Conclusion

A compliance risk assessment is not paperwork - it is the difference between finding out you owe ₹2,00,000 in penalties from a notice and catching the gap 30 days before the deadline. The template above gives you the structure. The penalty amounts and section numbers give you the urgency.

Start with the inventory. Score honestly - if you have missed a filing in the last year, score the likelihood as 3 or above. Prioritise anything with an impact of 4 or 5, because those are the obligations that can shut your business down or put you in legal jeopardy.

Then check your compliance posture free at complianceradar.in. The platform builds this assessment for you in five minutes - every applicable regulation, every deadline, every scheme you qualify for - and alerts you when rules change. Because the best penalty is the one you never receive.