Compliance — Full Study Guide
A structured introduction to corporate legal compliance: how it works, what to study, and where
to focus. India-anchored with global notes.
1. What compliance actually is
Compliance is the function that ensures an organization follows the laws, regulations, industry
standards, and internal policies that apply to it. It sits at the intersection of legal, risk, and operations.
Four sources of obligation:
• Statutory — laws passed by parliament (Companies Act, Income Tax Act)
• Regulatory — rules from regulators (SEBI, RBI, CCI)
• Contractual — what you signed with clients, vendors, lenders
• Internal — code of conduct, ethics policies, board mandates
Cost of non-compliance: fines, license suspension, director disqualification, criminal liability in serious
cases, and reputational damage that kills deals.
2. How a compliance function works
The compliance lifecycle runs continuously through seven steps:
• Identify — map every law and rule that applies to the business
• Assess — risk-rank them by likelihood and impact
• Design — write policies, build controls, create training
• Implement — embed controls into actual workflows
• Monitor — audits, dashboards, whistleblower channels
• Report — to board, regulators, sometimes the public
• Remediate — fix breaches, update controls, retrain
Three Lines of Defense (standard operating model)
• 1st line — business teams who own the risk
• 2nd line — compliance and risk teams who oversee
• 3rd line — internal audit who independently checks both
3. Areas of corporate legal compliance
India-focused, but the structure is universal.
Corporate governance
Companies Act 2013, board duties, related-party transactions, CSR obligations under Section 135.
Securities and capital markets
SEBI Act, LODR (Listing Obligations and Disclosure Requirements), Prohibition of Insider Trading
regulations, Takeover Code.
Financial and AML
Prevention of Money Laundering Act (PMLA), FEMA, KYC norms, RBI Master Directions.
Tax compliance
Income Tax Act, GST, TDS and TCS, transfer pricing.
Labour and employment
POSH Act, the four Labour Codes (Wages, Industrial Relations, Social Security, OSH), Provident
Fund, ESIC.
Data protection and privacy
DPDP Act 2023, IT Act 2000, and GDPR for any business touching EU data.
Competition
Competition Act 2002, CCI merger control thresholds.
Anti-bribery
Prevention of Corruption Act, plus FCPA (US) and UK Bribery Act, both of which apply
extraterritorially to Indian firms dealing with US or UK counterparts.
Sector-specific
Banking, NBFC, insurance, telecom, pharma, fintech each carry their own regulator and licensing
regime on top of the general framework.
4. What to study, in order
Foundation (Month 1 to 2)
• Indian Contract Act 1872 — the base of all commercial law
• Companies Act 2013 — directors, meetings, accounts, audit
• Constitution basics — Articles 14, 19, 21 (they govern regulatory action)
Core regulatory (Month 3 to 4)
• SEBI LODR and Insider Trading regulations
• RBI and FEMA basics
• Income Tax and GST framework
• Labour Codes
Specialty (Month 5 to 6) — pick one
• Data privacy (DPDP + GDPR) — highest demand right now
• AML and KYC — banking and fintech
• Securities compliance — listed companies and investment banking
• ESG compliance — emerging and well-paid
5. Certifications worth your time
India
• CS (Company Secretary), ICSI — the gold standard for corporate compliance in India; 2 to 3
years
• IIBF AML/KYC certification — short, recognised in banking
Global
• CAMS — most respected anti-money laundering credential
• CIPP/E or CIPM (IAPP) — data privacy, globally recognised
• ICA International Diploma in Compliance — broad corporate compliance
6. Free study sources
• ICSI publishes full Company Secretary study material free on its site
• SEBI, RBI, MCA websites — every act and circular, official source
• NPTEL and SWAYAM — Corporate Law and Compliance courses
• Taxmann and LiveLaw — free articles on regulatory updates
7. Career paths in compliance
• Compliance Officer / Chief Compliance Officer (CCO)
• AML or KYC Analyst (banks, fintechs, exchanges)
• Risk and Compliance Manager
• Data Protection Officer (DPO) — mandated for many companies under DPDP and GDPR
• Internal Auditor
• Company Secretary (statutorily required for many Indian companies)
8. Practical note for MarTech / PM roles
If the target is Product Owner or MarTech PM roles, the compliance area with the highest leverage is
data privacy — DPDP Act, GDPR, consent management, cookie and SDK compliance. This is the
legal layer MarTech products live and die by. A CIPP/E credential, or even a focused DPDP
deep-dive, signals far more to a hiring manager than a generic compliance certificate.
Prepared as a study reference. Laws and regulations change — verify current text on official regulator sites
before relying on any specific provision.