A weak regulatory compliance risk assessment template can hide a ₹5 lakh licensing exposure. This guide gives Indian SMEs a practical register to find and control it.

Indian businesses usually miss compliance because obligations are split among accounts, HR, plant teams, consultants, and inboxes. This guide provides a copyable register and scoring method. It is a management tool, not advice on a specific law; verify every obligation against the current central, state, municipal, and sector rules for your locations and activities.

Why a Compliance Risk Register Prevents Expensive Surprises

A compliance calendar answers one question: when is something due? A compliance risk register answers the harder questions:

That distinction matters. A food manufacturer may remember its monthly GST return but overlook an expiring FSSAI licence. Section 31 of the Food Safety and Standards Act, 2006 requires a food business to operate under a licence, subject to the registration route for petty food businesses described in subsection (2). Carrying on a food business without the required licence can lead to imprisonment up to six months and a fine up to ₹5 lakh under Section 63. The Food Safety and Standards Act on India Code is the primary legal source.

Risk management is also more than a voluntary good practice for many companies. Section 134(3)(n) of the Companies Act, 2013 requires the Board's report to state the development and implementation of a risk management policy, including risks that may threaten the company's existence. For companies required to have an Audit Committee, Section 177(4)(vii) assigns it evaluation of internal financial controls and risk management systems. These provisions do not prescribe this spreadsheet format, but they show why a documented process matters. See the Companies Act, 2013 on India Code.

The register turns that policy into work that can be assigned, checked, and audited.

Copy This Regulatory Compliance Risk Assessment Template

Create one row for each obligation, not one row for each law. The same Act may create several obligations with different owners, deadlines, and consequences.

Field | What to enter

Risk ID | A stable code such as TAX-001 or ENV-MH-003

Business unit and location | Legal entity, factory, branch, warehouse, or state

Activity or trigger | Hiring, manufacturing, discharge, turnover threshold, import, sale, or expansion

Regulator and jurisdiction | Central, state, municipal, or sector regulator

Legal source | Full law or rule name, section, notification, licence condition, and version date

Obligation | The action required in plain language

Frequency or deadline | Event-based, monthly, quarterly, annual, renewal date, or continuous

Failure scenario | Exactly what could be missed or done incorrectly

Inherent likelihood | Score from 1 to 5 before controls

Inherent impact | Score from 1 to 5 before controls

Existing controls | Approval, system rule, reconciliation, checklist, inspection, or expert review

Control owner | One named role, not a department

Evidence | Challan, acknowledgement, register, certificate, return, photo, minutes, or test report

Control effectiveness | Effective, partly effective, ineffective, or not tested

Residual likelihood | Score from 1 to 5 after controls

Residual impact | Score from 1 to 5 after controls

Residual score | Residual likelihood multiplied by residual impact

Treatment | Accept, reduce, avoid, or transfer

Action and due date | Specific next step, accountable owner, and target date

Review trigger | Law change, threshold crossing, new site, incident, audit finding, or scheduled review

Last reviewed | Date and reviewer

Do not write “statutory compliance” in the obligation field. Write “File the annual return with the Registrar within 60 days of the annual general meeting under Companies Act, 2013, Section 92(4).”

Section 92(5) illustrates why the consequence belongs in the same row. A company that misses the Section 92(4) period faces a ₹10,000 penalty plus ₹100 for every continuing day, capped at ₹2 lakh for the company and ₹50,000 for an officer in default. Financial statements have a separate deadline: Section 137(1) generally requires filing within 30 days of the annual general meeting. Combining both as “ROC annual filing” hides two distinct controls.

Score Risks So the Most Dangerous Work Comes First

Use five-point likelihood and impact scales. Multiply them for a score between 1 and 25. It is a prioritisation aid, not a prediction.

Likelihood scale

  1. Rare: Strong automated control, no failure in three years, and no material process change.
  2. Unlikely: Documented control works, but part of the process is manual.
  3. Possible: Several hand-offs, inconsistent evidence, or one failure in the past two years.
  4. Likely: Repeated delays, unclear ownership, or frequent regulatory changes.
  5. Almost certain: No owner, no control, expired approval, or known current breach.

Impact scale

  1. Minor: Correctable administrative issue with negligible cost and no external reporting.
  2. Moderate: Small fee, limited rework, or internal management attention.
  3. Serious: Material penalty, regulator correspondence, delayed shipment, or audit qualification risk.
  4. Major: Licence suspension risk, significant tax demand, customer loss, or prolonged operational restriction.
  5. Critical: Prosecution exposure, plant closure, product recall, loss of core licence, or threat to business continuity.

Suggested response bands are:

Impact must reflect the complete consequence. A small filing fee may accompany a blocked dispatch, suspended licence, or lender breach. Score the obligation from your business facts.

Build the Register in Seven Practical Steps

1. Fix the assessment boundary

List the legal entities, locations, products, employee groups, and activities covered. A Maharashtra factory, a Karnataka sales office, and an online store do not share an identical obligation set. Record what is outside scope so nobody assumes it was assessed.

2. Map business triggers before searching laws

Start with entity type, turnover, employee count, installed power, process, waste streams, storage, imports, and states of operation. Applicability usually turns on these facts.

3. Identify obligations from primary sources

For each trigger, check the Act, rules, current notification, regulator portal, state amendment, and conditions printed on the licence. A blog or consultant checklist may help discovery, but it should not be the final legal source in the register.

Environmental consent shows why jurisdiction must be explicit. Section 25 of the Water (Prevention and Control of Pollution) Act, 1974 governs prior State Pollution Control Board consent for covered outlets and discharges. Section 21 of the Air (Prevention and Control of Pollution) Act, 1981 requires previous State Board consent before establishing or operating an industrial plant in an air pollution control area. The exact application, validity, category, fee, and consent conditions depend on the state board and the unit. One generic “pollution licence” row is inadequate.

4. Describe one failure scenario per row

“GST risk” is not a failure scenario. Better entries include “GSTR-3B filed after the applicable due date,” “input tax credit claimed without supplier-document reconciliation,” and “tax collected but not deposited.” Different failures require different controls.

Under Section 47 of the Central Goods and Services Tax Act, 2017, delayed returns attract a statutory late fee, subject to the section's caps and any applicable relief notification. Section 50 separately imposes interest on delayed payment of tax at the notified rate, not exceeding 18% under subsection (1). The CGST Act published by CBIC separates these consequences; your register should too.

5. Record preventive and detective controls

A preventive control stops the failure, such as a dispatch block after licence expiry or maker-checker approval before filing. A detective control finds it quickly, such as portal-to-ledger reconciliation or overdue-task reporting. Important risks usually need both.

6. Test evidence, not assurances

“The consultant handles it” is not a control test. Select a sample and inspect the actual filing acknowledgement, paid challan, licence, Board minutes, training record, or laboratory report. Confirm that the document belongs to the correct entity, location, and period. Record the tester, date, sample, exception, and remediation.

7. Approve treatment and monitor closure

Every high or critical residual risk needs an action, owner, budget, and due date. The owner of the obligation may perform the work, but a reviewer should independently confirm closure. Keep overdue actions visible at management meetings until evidence is attached.

See What Completed Risk Rows Look Like

These examples are illustrations. Replace dates and applicability with your actual facts.

Risk ID | Failure scenario and legal source | Control | Residual score | Treatment

CORP-001 | Annual return not filed within 60 days of AGM under Companies Act, 2013, Section 92(4) | Company secretary prepares; director approves; MCA acknowledgement stored | 6 | Add 30/15/7-day alerts and quarterly evidence review

TAX-001 | GST return filed late; CGST Act, 2017, Sections 47 and 50 | Books close calendar, maker-checker review, portal acknowledgement | 8 | Reconcile source data five working days before due date

FOOD-001 | Food business operates without the required licence; FSS Act, 2006, Sections 31 and 63 | Licence register, 90-day renewal trigger, dispatch block after expiry | 5 | Verify every premise and product activity against licence scope

ENV-MH-001 | Maharashtra unit operates outside State Board consent conditions; Water Act Section 25 and Air Act Section 21 | Monthly condition checklist, test reports, quarterly plant-head sign-off | 12 | Map each consent condition to evidence and an owner

LAB-001 | Labour-code obligation missed after a workforce or process change | Monthly headcount and contractor review; legal-update check | 9 | Revalidate central and state rules when thresholds change

India's four labour codes took effect on 21 November 2025, including the Occupational Safety, Health and Working Conditions Code, 2020. The Ministry of Labour and Employment now publishes the codes, 2026 Central Rules, FAQs, and a compliance handbook on its official Labour Codes page. State rules and the identity of the appropriate government still matter. Treat implementation as a review trigger across payroll, contractors, safety, welfare, registers, and notices rather than copying an old checklist forward.

Make the Template Produce Decisions, Not Spreadsheet Theatre

Review critical risks monthly, high risks quarterly, and the full register at least annually. Also trigger an immediate review when the business:

Management reporting should fit on one page: top residual risks, overdue actions, failed controls, licences expiring within 90 days, legal changes awaiting review, and repeated exceptions. Show movement from the previous review. Keep the detailed legal inventory beneath that summary.

Common Mistakes That Make the Assessment Useless

Copying a generic checklist: Applicability changes by entity, location, activity, thresholds, and licence conditions. Generic templates are the starting structure, not the completed answer.

Scoring the law instead of the failure: One law can contain a routine filing, a licence condition, and a serious offence. Separate the failure scenarios.

Using department names as owners: “Finance” cannot be held accountable. Assign one named role and an alternate.

Ignoring state and municipal obligations: Central laws are only one layer. Shops and establishment registration, professional tax, pollution consent procedures, fire approvals, trade licences, and local operating conditions can vary.

Never testing the register: A beautiful spreadsheet with expired links and no evidence is merely organised risk. Sample the controls and record exceptions.

Frequently Asked Questions

Is a compliance risk assessment mandatory for every Indian SME?

There is no single law prescribing this exact template for every SME. Specific governance, sector, licence, safety, tax, and environmental duties may require risk controls or records. Companies Act, 2013, Section 134(3)(n) also requires the Board's report to address development and implementation of a risk management policy. Confirm the provisions that apply to your entity and sector.

How often should the register be reviewed?

Review the complete register at least annually, high risks quarterly, and critical risks monthly. Reassess immediately after a legal change, notice, incident, new location, new product, or threshold crossing.

Who should own the assessment?

Management owns the risks. A compliance officer, company secretary, CA, or legal adviser can coordinate the process, but operational owners must perform the controls. The founder or Board should approve priorities and unresolved high risks.

What is the difference between inherent and residual risk?

Inherent risk is the exposure before considering controls. Residual risk is what remains after existing controls operate. The gap shows whether the controls materially reduce the threat or merely document it.

Can Excel be used for the template?

Yes. Excel or Google Sheets works for a small, stable obligation set if access, version history, ownership, reminders, and evidence links are controlled. Move to a dedicated system when multiple entities, states, owners, or frequent regulatory changes make the sheet unreliable.

Should penalties determine every priority?

No. Include prosecution, closure, licence suspension, tax interest, shipment delay, customer contracts, reputation, worker safety, and management time. A low statutory fee can still accompany severe operational damage.

Can a consultant complete the assessment alone?

A consultant can identify laws and test controls, but cannot reliably determine applicability without accurate business facts. Finance, HR, operations, EHS, legal, and management must validate triggers, ownership, and evidence.

Turn Your Risk Register Into a Live Compliance System

A regulatory compliance risk assessment template is valuable only when it reflects your real entities, locations, thresholds, deadlines, and licence conditions. Build the first version, test the highest risks, assign corrective actions, and update it whenever the business or the law changes.

If you are not sure which obligations belong in your register, check your compliance posture free at complianceradar.in. Describe your business once to identify applicable compliances, government schemes, timelines, and regulatory-change alerts before a missed obligation becomes a notice.