A weak regulatory compliance risk assessment template can hide a ₹5 lakh licensing exposure. This guide gives Indian SMEs a practical register to find and control it.
Indian businesses usually miss compliance because obligations are split among accounts, HR, plant teams, consultants, and inboxes. This guide provides a copyable register and scoring method. It is a management tool, not advice on a specific law; verify every obligation against the current central, state, municipal, and sector rules for your locations and activities.
Why a Compliance Risk Register Prevents Expensive Surprises
A compliance calendar answers one question: when is something due? A compliance risk register answers the harder questions:
- What can go wrong?
- Which law, section, licence condition, or order creates the obligation?
- How likely is the failure?
- What would the financial and operational impact be?
- Which control prevents or detects it?
- Who owns that control?
- What evidence proves completion?
That distinction matters. A food manufacturer may remember its monthly GST return but overlook an expiring FSSAI licence. Section 31 of the Food Safety and Standards Act, 2006 requires a food business to operate under a licence, subject to the registration route for petty food businesses described in subsection (2). Carrying on a food business without the required licence can lead to imprisonment up to six months and a fine up to ₹5 lakh under Section 63. The Food Safety and Standards Act on India Code is the primary legal source.
Risk management is also more than a voluntary good practice for many companies. Section 134(3)(n) of the Companies Act, 2013 requires the Board's report to state the development and implementation of a risk management policy, including risks that may threaten the company's existence. For companies required to have an Audit Committee, Section 177(4)(vii) assigns it evaluation of internal financial controls and risk management systems. These provisions do not prescribe this spreadsheet format, but they show why a documented process matters. See the Companies Act, 2013 on India Code.
The register turns that policy into work that can be assigned, checked, and audited.
Copy This Regulatory Compliance Risk Assessment Template
Create one row for each obligation, not one row for each law. The same Act may create several obligations with different owners, deadlines, and consequences.
Field | What to enter
Risk ID | A stable code such as TAX-001 or ENV-MH-003
Business unit and location | Legal entity, factory, branch, warehouse, or state
Activity or trigger | Hiring, manufacturing, discharge, turnover threshold, import, sale, or expansion
Regulator and jurisdiction | Central, state, municipal, or sector regulator
Legal source | Full law or rule name, section, notification, licence condition, and version date
Obligation | The action required in plain language
Frequency or deadline | Event-based, monthly, quarterly, annual, renewal date, or continuous
Failure scenario | Exactly what could be missed or done incorrectly
Inherent likelihood | Score from 1 to 5 before controls
Inherent impact | Score from 1 to 5 before controls
Existing controls | Approval, system rule, reconciliation, checklist, inspection, or expert review
Control owner | One named role, not a department
Evidence | Challan, acknowledgement, register, certificate, return, photo, minutes, or test report
Control effectiveness | Effective, partly effective, ineffective, or not tested
Residual likelihood | Score from 1 to 5 after controls
Residual impact | Score from 1 to 5 after controls
Residual score | Residual likelihood multiplied by residual impact
Treatment | Accept, reduce, avoid, or transfer
Action and due date | Specific next step, accountable owner, and target date
Review trigger | Law change, threshold crossing, new site, incident, audit finding, or scheduled review
Last reviewed | Date and reviewer
Do not write “statutory compliance” in the obligation field. Write “File the annual return with the Registrar within 60 days of the annual general meeting under Companies Act, 2013, Section 92(4).”
Section 92(5) illustrates why the consequence belongs in the same row. A company that misses the Section 92(4) period faces a ₹10,000 penalty plus ₹100 for every continuing day, capped at ₹2 lakh for the company and ₹50,000 for an officer in default. Financial statements have a separate deadline: Section 137(1) generally requires filing within 30 days of the annual general meeting. Combining both as “ROC annual filing” hides two distinct controls.
Score Risks So the Most Dangerous Work Comes First
Use five-point likelihood and impact scales. Multiply them for a score between 1 and 25. It is a prioritisation aid, not a prediction.
Likelihood scale
- Rare: Strong automated control, no failure in three years, and no material process change.
- Unlikely: Documented control works, but part of the process is manual.
- Possible: Several hand-offs, inconsistent evidence, or one failure in the past two years.
- Likely: Repeated delays, unclear ownership, or frequent regulatory changes.
- Almost certain: No owner, no control, expired approval, or known current breach.
Impact scale
- Minor: Correctable administrative issue with negligible cost and no external reporting.
- Moderate: Small fee, limited rework, or internal management attention.
- Serious: Material penalty, regulator correspondence, delayed shipment, or audit qualification risk.
- Major: Licence suspension risk, significant tax demand, customer loss, or prolonged operational restriction.
- Critical: Prosecution exposure, plant closure, product recall, loss of core licence, or threat to business continuity.
Suggested response bands are:
- 1 to 4, low: Maintain the control and review annually.
- 5 to 9, moderate: Improve weak evidence or manual hand-offs within 90 days.
- 10 to 16, high: Assign a senior owner and treatment date within 30 days.
- 17 to 25, critical: Escalate immediately; obtain legal or specialist advice where needed.
Impact must reflect the complete consequence. A small filing fee may accompany a blocked dispatch, suspended licence, or lender breach. Score the obligation from your business facts.
Build the Register in Seven Practical Steps
1. Fix the assessment boundary
List the legal entities, locations, products, employee groups, and activities covered. A Maharashtra factory, a Karnataka sales office, and an online store do not share an identical obligation set. Record what is outside scope so nobody assumes it was assessed.
2. Map business triggers before searching laws
Start with entity type, turnover, employee count, installed power, process, waste streams, storage, imports, and states of operation. Applicability usually turns on these facts.
3. Identify obligations from primary sources
For each trigger, check the Act, rules, current notification, regulator portal, state amendment, and conditions printed on the licence. A blog or consultant checklist may help discovery, but it should not be the final legal source in the register.
Environmental consent shows why jurisdiction must be explicit. Section 25 of the Water (Prevention and Control of Pollution) Act, 1974 governs prior State Pollution Control Board consent for covered outlets and discharges. Section 21 of the Air (Prevention and Control of Pollution) Act, 1981 requires previous State Board consent before establishing or operating an industrial plant in an air pollution control area. The exact application, validity, category, fee, and consent conditions depend on the state board and the unit. One generic “pollution licence” row is inadequate.
4. Describe one failure scenario per row
“GST risk” is not a failure scenario. Better entries include “GSTR-3B filed after the applicable due date,” “input tax credit claimed without supplier-document reconciliation,” and “tax collected but not deposited.” Different failures require different controls.
Under Section 47 of the Central Goods and Services Tax Act, 2017, delayed returns attract a statutory late fee, subject to the section's caps and any applicable relief notification. Section 50 separately imposes interest on delayed payment of tax at the notified rate, not exceeding 18% under subsection (1). The CGST Act published by CBIC separates these consequences; your register should too.
5. Record preventive and detective controls
A preventive control stops the failure, such as a dispatch block after licence expiry or maker-checker approval before filing. A detective control finds it quickly, such as portal-to-ledger reconciliation or overdue-task reporting. Important risks usually need both.
6. Test evidence, not assurances
“The consultant handles it” is not a control test. Select a sample and inspect the actual filing acknowledgement, paid challan, licence, Board minutes, training record, or laboratory report. Confirm that the document belongs to the correct entity, location, and period. Record the tester, date, sample, exception, and remediation.
7. Approve treatment and monitor closure
Every high or critical residual risk needs an action, owner, budget, and due date. The owner of the obligation may perform the work, but a reviewer should independently confirm closure. Keep overdue actions visible at management meetings until evidence is attached.
See What Completed Risk Rows Look Like
These examples are illustrations. Replace dates and applicability with your actual facts.
Risk ID | Failure scenario and legal source | Control | Residual score | Treatment
CORP-001 | Annual return not filed within 60 days of AGM under Companies Act, 2013, Section 92(4) | Company secretary prepares; director approves; MCA acknowledgement stored | 6 | Add 30/15/7-day alerts and quarterly evidence review
TAX-001 | GST return filed late; CGST Act, 2017, Sections 47 and 50 | Books close calendar, maker-checker review, portal acknowledgement | 8 | Reconcile source data five working days before due date
FOOD-001 | Food business operates without the required licence; FSS Act, 2006, Sections 31 and 63 | Licence register, 90-day renewal trigger, dispatch block after expiry | 5 | Verify every premise and product activity against licence scope
ENV-MH-001 | Maharashtra unit operates outside State Board consent conditions; Water Act Section 25 and Air Act Section 21 | Monthly condition checklist, test reports, quarterly plant-head sign-off | 12 | Map each consent condition to evidence and an owner
LAB-001 | Labour-code obligation missed after a workforce or process change | Monthly headcount and contractor review; legal-update check | 9 | Revalidate central and state rules when thresholds change
India's four labour codes took effect on 21 November 2025, including the Occupational Safety, Health and Working Conditions Code, 2020. The Ministry of Labour and Employment now publishes the codes, 2026 Central Rules, FAQs, and a compliance handbook on its official Labour Codes page. State rules and the identity of the appropriate government still matter. Treat implementation as a review trigger across payroll, contractors, safety, welfare, registers, and notices rather than copying an old checklist forward.
Make the Template Produce Decisions, Not Spreadsheet Theatre
Review critical risks monthly, high risks quarterly, and the full register at least annually. Also trigger an immediate review when the business:
- enters a new state or opens a site;
- crosses a turnover, employee, capacity, or capital threshold;
- launches a regulated product;
- changes a manufacturing process or waste stream;
- appoints a new contractor or importer;
- receives a notice, inspection finding, or audit qualification;
- changes its legal structure; or
- receives a relevant notification, circular, court ruling, or licence amendment.
Management reporting should fit on one page: top residual risks, overdue actions, failed controls, licences expiring within 90 days, legal changes awaiting review, and repeated exceptions. Show movement from the previous review. Keep the detailed legal inventory beneath that summary.
Common Mistakes That Make the Assessment Useless
Copying a generic checklist: Applicability changes by entity, location, activity, thresholds, and licence conditions. Generic templates are the starting structure, not the completed answer.
Scoring the law instead of the failure: One law can contain a routine filing, a licence condition, and a serious offence. Separate the failure scenarios.
Using department names as owners: “Finance” cannot be held accountable. Assign one named role and an alternate.
Ignoring state and municipal obligations: Central laws are only one layer. Shops and establishment registration, professional tax, pollution consent procedures, fire approvals, trade licences, and local operating conditions can vary.
Never testing the register: A beautiful spreadsheet with expired links and no evidence is merely organised risk. Sample the controls and record exceptions.
Frequently Asked Questions
Is a compliance risk assessment mandatory for every Indian SME?
There is no single law prescribing this exact template for every SME. Specific governance, sector, licence, safety, tax, and environmental duties may require risk controls or records. Companies Act, 2013, Section 134(3)(n) also requires the Board's report to address development and implementation of a risk management policy. Confirm the provisions that apply to your entity and sector.
How often should the register be reviewed?
Review the complete register at least annually, high risks quarterly, and critical risks monthly. Reassess immediately after a legal change, notice, incident, new location, new product, or threshold crossing.
Who should own the assessment?
Management owns the risks. A compliance officer, company secretary, CA, or legal adviser can coordinate the process, but operational owners must perform the controls. The founder or Board should approve priorities and unresolved high risks.
What is the difference between inherent and residual risk?
Inherent risk is the exposure before considering controls. Residual risk is what remains after existing controls operate. The gap shows whether the controls materially reduce the threat or merely document it.
Can Excel be used for the template?
Yes. Excel or Google Sheets works for a small, stable obligation set if access, version history, ownership, reminders, and evidence links are controlled. Move to a dedicated system when multiple entities, states, owners, or frequent regulatory changes make the sheet unreliable.
Should penalties determine every priority?
No. Include prosecution, closure, licence suspension, tax interest, shipment delay, customer contracts, reputation, worker safety, and management time. A low statutory fee can still accompany severe operational damage.
Can a consultant complete the assessment alone?
A consultant can identify laws and test controls, but cannot reliably determine applicability without accurate business facts. Finance, HR, operations, EHS, legal, and management must validate triggers, ownership, and evidence.
Turn Your Risk Register Into a Live Compliance System
A regulatory compliance risk assessment template is valuable only when it reflects your real entities, locations, thresholds, deadlines, and licence conditions. Build the first version, test the highest risks, assign corrective actions, and update it whenever the business or the law changes.
If you are not sure which obligations belong in your register, check your compliance posture free at complianceradar.in. Describe your business once to identify applicable compliances, government schemes, timelines, and regulatory-change alerts before a missed obligation becomes a notice.