A weak risk management and compliance programme can cost a company ₹3 lakh under Section 134 of the Companies Act, 2013. This practical template shows what to run.

A spreadsheet of laws is not a compliance programme. A real programme shows what applies, who owns it, what proof must exist and what happens when a control fails. This guide gives Indian SMEs, compliance teams, CAs and company secretaries a structure they can run without a large governance department.

Why does an Indian business need a compliance programme?

The immediate consequence is not merely a missed filing. A director may sign a Board's report saying that the company has adequate systems for compliance when the underlying evidence is scattered across email, paper files and a consultant's laptop.

Section 134(5)(f) of the Companies Act, 2013 requires directors to state that they devised proper systems to ensure compliance with all applicable laws and that those systems were adequate and operating effectively. Section 134(3)(n) separately requires the Board's report to describe the development and implementation of a risk management policy, including risks that could threaten the company's existence. Under Section 134(8), default can attract a ₹3 lakh penalty for the company and ₹50,000 for every officer in default.

Those provisions apply to companies. An LLP, partnership or proprietorship should not claim that Section 134 directly governs it. It still needs an operating system for licences, tax, labour, environmental and sector obligations because the underlying laws apply according to activity, location, employee count, turnover and other thresholds.

Listed entities face an additional standard. Regulation 17(9) of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 requires the listed entity to inform its Board about risk assessment and minimisation procedures, while the Board is responsible for framing, implementing and monitoring the risk management plan. An unlisted SME may not be legally bound by that regulation, but the operating discipline is worth copying.

The practical point is simple: your programme must be capable of producing evidence, not just assurances.

What should the risk management and compliance programme contain?

Use this nine-part structure. It is compact enough for a small manufacturer and can expand as the business adds plants, states or regulated activities.

  1. Programme charter: Define entities, sites, functions and laws in scope, plus approval and review dates.
  2. Obligation register: List each applicable registration, return, payment, renewal, record, inspection and event-based obligation.
  3. Risk assessment: Score the likelihood and business impact of failure.
  4. Control library: State what prevents or detects each failure.
  5. Ownership model: Give every obligation one accountable owner and one backup.
  6. Evidence repository: Define the proof, location, naming convention and retention period.
  7. Regulatory change process: Monitor official sources, assess applicability, assign action and document closure.
  8. Incident process: Set escalation rules for missed deadlines, notices and control failures.
  9. Management reporting: Report overdue actions, critical obligations, pending changes and repeat failures.

If any part is missing, the programme becomes unreliable. A register without ownership becomes a wish list. Ownership without evidence produces unverifiable claims. Evidence without change monitoring proves only that yesterday's rule was followed.

Copy this risk management and compliance programme template

Create one controlled document and insert the following sections. Replace the bracketed text with facts about your business.

1. Purpose and scope

This programme identifies, assesses, controls and monitors legal and regulatory obligations applicable to [legal entity names] at [sites and states]. It covers corporate, tax, labour, environment, safety, municipal, sector and licence obligations. It excludes [documented exclusions with reasons].

Record the effective date, version, approver and next review date on page one. Review at least annually and whenever you add a site, cross a statutory threshold, start a new product line or enter a new state.

2. Governance and responsibilities

The Board or proprietor approves the programme. The compliance owner maintains the obligation register and reports exceptions. Function heads execute controls and upload evidence. The legal or CA/CS adviser validates interpretation where required. Internal audit or an independent reviewer tests selected controls.

Use names or roles, but never write “management” as the owner. Management is not a person who can receive an escalation.

3. Risk appetite and escalation

The business has zero tolerance for operating without a mandatory licence, deliberate misstatement, bribery, worker-safety concealment or non-response to a regulator. A critical breach must be escalated to [role] within [hours]. Other overdue obligations follow the escalation matrix below.

Define what “critical” means. A sensible definition includes a threat of closure, prosecution, loss of licence, material financial penalty, worker harm, environmental damage or a filing that blocks another transaction.

4. Operating cycle

Each obligation is identified, assessed, assigned, scheduled, completed, evidenced and reviewed. Regulatory changes enter the same cycle after an applicability assessment. Exceptions remain open until corrective action is verified, not merely promised.

5. Reporting

The compliance owner submits a monthly dashboard containing due, completed, overdue and not-applicable obligations; critical incidents; open notices; regulatory changes; ageing of corrective actions; and repeat failures.

This is the complete skeleton. The next sections turn it into an operating system.

How do you build the obligation register correctly?

Start with the business profile, not a downloaded “all laws” list. Record legal structure, turnover, employee count, worker type, installed power, activities, products, states, premises, waste streams and licences. Applicability depends on these facts. Then build a Compliance Obligation Register as the programme's source of truth.

For each applicable obligation, capture:

Do not assume a central-law checklist covers state obligations. Professional tax, Shops and Establishments registration, state pollution-control consent conditions, fire approvals and municipal trade licences can differ by location. Record each jurisdiction as a separate obligation when the owner, form, deadline or regulator differs.

Thresholds also need proof. Section 4 of the Sexual Harassment of Women at Workplace Act, 2013 requires an Internal Committee at every office or administrative unit with ten or more employees. Section 26 permits a fine of up to ₹50,000 for a first contravention. Store the headcount trigger, committee constitution, member tenure and evidence, not merely “POSH compliant.”

The register is a living inventory. When facts change, applicability must be reassessed.

How should compliance risks and controls be scored?

Use a 1-to-5 likelihood score and separate impact scores for legal, financial, operational, safety and reputation consequences. Take the highest impact rather than averaging away a catastrophic risk. The Regulatory Compliance Risk Assessment Template gives a fuller scoring method.

Then document the control and score the residual risk remaining after it operates. Use a Risk Control Matrix to connect each risk to its preventive and detective controls.

Consider a pollution consent renewal:

“Team will ensure timely renewal” is not a control. A control has an owner, frequency, action, evidence and exception route.

Use four practical priority bands:

The method needs consistent decisions, not mathematical theatre.

What evidence proves the programme is operating?

Require evidence appropriate to the obligation. A “submitted” screenshot may not prove approval, payment or acceptance.

Build an evidence pack with:

Set retention from the governing law, not a universal rule. Section 36 of the Central Goods and Services Tax Act, 2017 generally requires account records to be kept for 72 months from the annual-return due date for the relevant year. Litigation, investigation or appeal can extend retention.

Restrict access to employee, investigation and legal-advice records. Compliance evidence is useful precisely because it is detailed; careless access can create a separate confidentiality problem.

How do you track regulatory changes without drowning in updates?

A change log should answer five questions: what changed, which official source published it, which business facts make it applicable, what action is required, and who verified completion.

Use this workflow:

  1. Monitor the Gazette of India, ministry and regulator websites, state departments, municipal portals and licence-specific communications relevant to your profile.
  2. Capture the notification, circular, order or amendment with publication and effective dates.
  3. Assign a qualified reviewer to classify it as applicable, not applicable or requiring clarification.
  4. For applicable changes, update the obligation, control, procedure, form, training and evidence requirement.
  5. Set an implementation deadline earlier than the legal effective date where possible.
  6. Verify closure and report any residual risk to management.

Do not treat a newsletter headline as the legal source. It may alert you, but the assessment should point to the official instrument. Record not-applicable decisions with reasons so irrelevant updates are not reviewed repeatedly.

This is where a generic downloadable template reaches its limit. Your monitoring universe must reflect your state, industry, products, employee thresholds and licences.

A 90-day implementation plan for an Indian SME

Days 1-15: establish scope

Days 16-35: build the register

Days 36-55: assess and control

Days 56-75: centralise evidence and monitoring

Days 76-90: test and report

Success after 90 days is not a perfect document. It is zero unknown critical licences, named ownership for every high-risk obligation, visible overdue actions and retrievable proof.

Common mistakes that make the programme fail

Turn the template into a business-specific system

This risk management and compliance programme template gives you governance, fields and workflow. It cannot decide every law that applies to your particular entity, state, factory, product or workforce. That is the commercially important part.

Check your compliance posture free at complianceradar.in. Describe your business once to get a personalised timeline of applicable compliances and government schemes, plus alerts when relevant regulations change. Use that output to populate and maintain the programme instead of rebuilding applicability from generic spreadsheets.

Frequently asked questions

Is a risk management and compliance programme mandatory for every Indian SME?

No single provision uses that exact phrase for every business form. Companies have specific Board-report and compliance-system duties under Section 134 of the Companies Act, 2013. Listed entities have additional SEBI LODR duties. Other businesses still need controls for the tax, labour, licence, safety, environment and sector laws that apply to them.

Is this the same as a compliance risk assessment template?

No. A risk assessment identifies and scores failure scenarios. The programme is broader: it includes scope, obligations, controls, owners, evidence, regulatory change monitoring, incident handling and management reporting. The risk assessment is one component.

Who should own the programme in a small company?

Assign one accountable internal owner with access to the founder or Board. The role may sit in finance, legal, company secretarial, operations or EHS depending on the risk profile. External professionals should validate specialised interpretations, not become the invisible owner of business accountability.

How often should the compliance programme be reviewed?

Review the dashboard monthly, high-risk controls at a frequency matched to the obligation, and the whole programme at least annually. Also trigger a review after expansion, acquisition, a new state or product, a material regulatory change, an inspection, a notice or repeated control failure.

Does using this template guarantee legal compliance?

No. It is an operating template, not a legal opinion. Applicability and interpretation should be validated for your entity, activity and jurisdiction. The value of the programme is that assumptions, advice, actions and evidence become visible and reviewable rather than living in someone's memory.

Build the programme before a regulator tests it

A risk management and compliance programme is credible only when it identifies the right obligations, assigns owners, produces evidence and reacts to change. Start with the template, fix critical unknowns first, and make exceptions visible to decision-makers.

Do not wait for a penalty notice to discover that your spreadsheet missed a state rule or licence condition. Check your compliance posture free at complianceradar.in and turn the result into a programme your team can actually operate.