Lesson: 1 (Compliance Framework)
Key Steps for an Effective Compliance Framework
The Board of Directors must:
Ensure senior management actively participates in compliance program development and
maintenance.
Periodically review the compliance management system for effectiveness.
Keep the compliance framework updated with changes in laws, rules, and business environments.
Conduct secretarial audits to assess compliance effectiveness.
The GRC:
1. Governance
Governance refers to the rules, practices, and standards guiding an organization. Led by the board
of directors to align organizational operations with strategic goals. Ensures executives make well-
informed decisions and implement effective controls.
2. Risk Management
Risk management involves identifying, analyzing, and managing risks that could prevent an
organization from achieving its goals. This includes a range of risks such as financial, technological, and
operational.
Companies address risks based on severity, choosing to mitigate, transfer, accept, or control them. This
ensures that high-priority risks are actively managed while lesser risks are handled efficiently.
3. Compliance
Compliance ensures that the company adheres to all laws, regulations, and company policies.
Compliance is achieved by identifying applicable requirements, evaluating compliance levels, and
prioritizing corrective actions if necessary, balancing the cost of compliance against the risk of
non-compliance.
Components of a Corporate Compliance Framework:
1. Compliance Chart
Provides a clear overview of applicable local, state, central, and international laws. Shows how compliance risk
mitigation is embedded in business processes. Helps organizations meet their obligations towards customers,
regulators, shareholders, and employees. Includes a compliance calendar to track key activities and
deadlines.
2. Compliance Advisory
Offers guidance on applicable laws and the consequences of non-compliance. It provides proactive
support to avoid compliance breaches and quick and effective response to address any breaches that occur.
3. Compliance Scorecard
Serves as a tool to analyze and monitor an organization’s compliance status. Tracks compliance breaches
and their remediation status by notifying responsible personnel. Uses a risk-prioritization system to
address violations based on severity.
1
Role of Company Secretary in creation of Compliance Chart / The compliance chart is prepared by
considering the following activities:
Identification of compliances under applicable Laws, Rules and Regulations;
Risk Assessment;
Risk Mitigation (includes Training);
Compliance Monitoring (includes Action Tracking);
Compliance Reporting (includes Incident Management).
Contents of Compliance Chart
The Compliance Chart serves as a compliance dashboard and must include:
Laws, rules, and policies relevant to the company
Summary of internal and external obligations
Business process or individuals affected by compliance
Risk levels (Critical, High, Medium, Low)
Mitigation and monitoring steps
Reporting frequency
Names of responsible compliance owners.
Key Functions of a Compliance Framework:
1. Compliance Dashboard: A Compliance Dashboard is a visual tool (usually digital) that provides a real-time
overview of an organization’s legal and regulatory compliance status.
2. Compliance Policy and Procedure: Written rules (SOPs) that tell people what to follow. Must be regularly
updated and approved.
3. Access to Rules and Regulations: Alerts and emails when laws change. Helps departments adjust policies
quickly. Keeps company up-to-date with legal changes.
4. Compliance Audit: Facilitates ongoing audits (internal, financial, vendor). Not just annual – now audits
happen in real time!
5. Quality Management: Integrates compliance with quality initiatives like Six Sigma or ISO 9000. Goal: Do
the right thing, the right way, every time.
6. Compliance Training: Conducts employee training to avoid fines due to lack of knowledge.
7. Compliance Task Management: Automates and centralizes compliance reporting and task updates. A
calendar or tool to track who does what and when. Shows real-time status of tasks that is seen by Board,
Compliance Officers, etc.
Process for Setting Up a Compliance Framework: (5-Stage Approach)
Stage-1: Identification of Compliance Obligations
Determine the applicable laws, regulations, policies, and procedures that the organization must comply
with. This includes understanding industry-specific and local regulations.
Stage-2: Preparation of Compliance Chart
Develop a compliance chart that outlines all relevant compliance obligations, risks, and the processes
needed to manage them.
Stage-3: Assessment of Historical Compliance Status
Evaluate past compliance performance and identify areas where the organization may have had
compliance lapses or issues.
Stage-4: Assessment of Compliance Risk
2
Identify potential non-compliance risks, assess their severity, and develop mitigation strategies. This
includes the creation of a monitoring and reporting system for compliance activities.
Stage-5: Compliance/Action Reporting
Regular reporting of compliance status to senior management and regulatory bodies. This includes
internal audits, independent reports, and communication of any compliance breaches or actions taken.
The process of setting up a Corporate Compliance:
1. Compliance Identification:
This step involves identifying the relevant laws, acts, and regulations that apply to the company. It is a
collaborative effort, typically involving the legal team and functional has to identify the applicable
legislations and their corresponding compliance requirements.
2. Compliance Ownership:
Compliance owner: A compliance owner is the person responsible for ensuring that a specific
compliance obligation is met. Ownership is assigned both functionally and individually, with clear
definitions of primary and secondary owners.
Primary owner: This person is directly responsible for compliance.
Secondary owner: Often a supervisor, this person ensures compliance processes are followed and
supervises the primary owner. For example, the Company Secretary may be the primary compliance
owner in a company.
3. Compliance Awareness:
This step focuses on building awareness of legal compliance among individuals responsible for
managing them. Sometimes compliance obligations are handled by those who might not be fully aware
of the requirements, so proper training and awareness programs are necessary. These could include
meetings, workshops, and manuals outlining compliance duties.
4. Compliance Reporting:
In the process of the Compliance Reporting status of compliances or non-compliances should be
communicated to the concerned. Typically, the compliance officer submits reports on compliance
status. These reports are often compiled and shared in Management Information Systems (MIS) to
ensure transparency and timely corrective actions.
The Compliance Management Process: (Compliance Lifecycle / Management Cycle)
1. Development
Identification and evaluation of compliance obligations.
2. Implementation
Mitigate the Compliance risks.
3. Evaluation
Evaluating the performance and reporting needs.
4. Maintenance
Managing the non-compliance and working on continuous improvements.
The Legal Department plays a key role in managing compliance across the organization. Its tasks include:
1. Monitoring Compliances Across Entities, Locations & Departments
2. Tracking Expiry Dates for Contracts that needs to be renewed
3. Managing Litigation Dates, Documents, and Orders
3
4. Complying with Document Policies and Processes.
Key Steps in Risk Assessment
Identify Potential Non-Compliance Areas
Rate the Risks
Assess the Outcomes to decide on the need for training, monitoring, internal controls, or corrective
actions.
Types of Risk Drivers and Their Impacts
Business Effect: Severe non-compliance risks can disrupt operations, leading to possible shutdowns.
Financial Effect: Potential negative outcomes include lower share prices, revenue losses, and reduced
investor confidence.
Legal Effect: Non-compliance can lead to fines, penalties, imprisonment, or even bans on product
distribution, impacting both the organization and its officers.
Reputational Effect: Damage to brand reputation and customer trust can arise from negative media
coverage or public discussions about non-compliance.
Types of Risk Assessments in Compliance Management
Companies generally perform two types of risk assessments:
1. High-Level Risk Assessment
🔍 Focus: Identifying critical and high compliance risks.
📊 Inputs: Needs results from detailed risk assessments.
👥 Conducted by: Risk Management team.
📄 Output: High-Level Risk Assessment Report with:
o Key risks
o Suggested mitigation steps
2. Detailed Risk Assessment
🔍 Focus: Deeper analysis of critical/high-risk areas.
👨🔬 Involves: Support functions like external experts, legal, etc.
🧠 Purpose: Supports high-level assessment with expert inputs.
🔧 Common Techniques Used (for both types):
Desk Assessments
Interviews
🧑🤝🧑 Workshops.
Compliance Ownership Roles and Responsibilities
🧑💼 1. Top Management (Board, MD, CEO) - They set the tone from the top.
Responsibilities:
✅ Approve compliance policies, procedures, and frameworks.
📚 Stay informed on key legal and regulatory obligations.
💬 Encourage and push the entire organization to meet compliance deadlines.
4
👨💼 2. Senior Management & Functional Heads (CFO, Department Heads) - They make sure teams follow
the rules daily.
Responsibilities:
Create compliance policies and processes.
Help monitor and implement compliance across departments.
🚨 Escalate risks and non-compliance issues to top management.
👥 Motivate compliance staff and keep the system running.
👩💻 3. Compliance Officers & Staff - They are the doers.
Responsibilities:
📅 Handle daily compliance tasks (filings, reports, etc.).
🧾 Update the compliance chart (a tracker of obligations).
⚠️Spot and report possible compliance risks or violations.
⚖️4. Legal Department / Legal Cell - They know the law inside out.
Responsibilities:
📣 Inform the company when any law or regulation changes.
🔍 Periodically review compliance systems and solve legal doubts.
📘 Help draft or revise compliance documents to match new laws.
Escalation and Compliance Reporting
Compliance reporting helps organizations assess and address risks effectively. Compliance reporting can be
divided into two main types: cyclical and incident reporting.
Cyclical reporting: Non-financial risk reporting on a quarterly basis. The Compliance officer works with
management and other risk functions for this.
Incident reporting: Material compliance incidents that may harm company are reported. This needs to be
handled through risk management processes.
Material Compliance Incidents: Defined as events that impact company reputation, legal compliance, or
financial performance due to failure to comply with applicable compliance related laws, regulations and
standards.
Key Steps in Compliance Reporting Process
1. Department-Level Reporting
Each functional head (like CFO, HR Head) is responsible for compliance within their area of
ownership:
o CFO: Finance, accounting, and taxation laws.
o HR/Personnel Head: Labour and industrial laws.
2. Data Collection and Classification
Functional heads collect and classify compliance information from various units/locations.
This data is consolidated into a report.
3. Affirmation of Report Accuracy
Each report includes an affirmation from the functional heads stating that:
5
o It is based on inputs received from the respective units/offices.
o Specific compliances and non-compliances are accurately listed.
4. Submission to Key Personnel
Functional heads forward their reports to:
o The Company Secretary (CS).
o The Managing Director (MD).
5. Comprehensive Compliance Report
The CS briefs the MD based on the department-wise reports.
The MD consolidates these reports and prepares a comprehensive compliance report, signed and
presented to the Board of Directors.
Effective Compliance Reporting Requirements: (CLEAR)
C - Clear Language: Use simple, straightforward language.
L - Language is Concise: Avoid unnecessary details; be brief.
E - Executive Summary: Include a summary for quick insights.
A - Actions to be Taken: List the steps for addressing issues.
R - Required Timelines: Provide deadlines for improving non-compliance.
Key Purposes of Compliance Risk Monitoring Plan Review
The review process aims to:
If the monitoring plan is still necessary and accurate.
If the plan reflects current laws, regulations, and compliance standards.
If changes are required to improve plan clarity and effectiveness.
If the plan could be combined with another plan or if it should be discontinued.
Contents of the Compliance Risk Monitoring Plan (CRITICAL)
C - Critical Risks Identification: Identifying inherent and managed risks.
R - Risk Mitigation Activities: Key actions to reduce compliance risks.
I - Incorporate Daily Transactions: Routine business transactions where compliance risks are involved.
T - Tighten Framework and Policies: Implementing the compliance framework organization-wide.
I - In-line with Laws and Standards: Adhering to laws, regulations, standards, and values.
C - Compliance Task Delegation: Cover the tasks assigned to the compliance team like: Handling
complaints, managing privacy-related duties and any other specific delegated obligations.
Monitoring Plan Essentials: (COMPLIANT)
C - Concise Statements: Concise statements of obligations and risks.
O - Operational Linkages: Identify business processes affected by compliance.
M - Mitigation Activities: Specific actions to handle compliance risks.
P - Protection Layers: The Three Lines of Tracking:
First Line: Daily tracking within business activities.
Second Line: Compliance Monitoring.
Third Line: Independent audits by Internal Audit.
L - Logging Methods: Description of how tracking and monitoring activities are performed.
6
I - Intervals: Frequency of tracking and monitoring activities.
A - Audience: Who receives the tracking and monitoring reports.
Assessing the Compliance Mechanism of a Company: (PRIPO)
P - Program Design/Update
R - Risk/Cultural Assessment
I - Implementation, Training and Communication
P - Policies and Procedures
O - Ongoing Self-Assessment, Monitoring, and Reporting
1. Program Design/Update
Review the guidelines, structures, and methods related to the compliance program, including the reporting
structure and communication strategies. Update or enhance the existing compliance program to align with
best practices and regulatory standards, ensuring it remains effective and relevant.
2. Risk/Cultural Assessment
Evaluates the company's ethical and compliance culture at all levels through employee surveys, interviews,
and document reviews. Identifies gaps between current practices and regulatory requirements.
3. Implementation and Training
Effectively communicate and train employees on the company’s policies and procedures. Ensure that
employees not only understand but also adopt the company’s compliance policies into daily practices and
employee attitudes.
4. Policies and Procedures
Develop or update policies addressing areas such as financial reporting, conflicts of interest, anti-trust,
fraud, and employee conduct.
5. Ongoing Self-Assessment, Monitoring, and Reporting
Use tools like employee surveys, internal controls, and monitoring programs to assess the program’s
effectiveness over time. Adapt the compliance program to changing regulations and business conditions.
Five Essential Elements to Create an Effective Compliance Training Program (PIUAO)
1. Make it personal
2. Make it interesting
3. Make it understandable
4. Make it accessible
5. Make it ongoing
Plans for Compliance Training and Education Program may include:
Should be developed and updated annually.
Must specify:
1. Key compliance obligations & risks.
2. Business processes impacted by compliance obligations
3. Frequency of training.
4. Training format & content.
7
5. Target audience (New employees, refresher training, or ad-hoc sessions).
Compliance Audit
A compliance audit is an independent assessment to ensure that an organization’s operations, activities, and
transactions adhere to relevant laws, regulations, standards, and internal policies.
Types of Compliance Audit:
1. Regulatory Compliance: Verifies adherence to relevant laws, regulations, and agreements applicable
to the organization.
2. Propriety Compliance: Ensures that the organization aligns with ethical and sound financial
management principles.
Objectives of a Compliance Audit:
1. Procurement Verification:
o Ensures that procurement processes are carried out according to existing rules and delegated
financial powers.
2. Financial Propriety in Tendering and Contracting:
o Verifies that proper financial management practices were followed during the tendering,
evaluation, and award processes.
3. Plant Efficiency (in industrial contexts):
o Verifies whether the use of power, fuel, and plant operations are aligned with approved norms.
o Assesses whether plant production levels and shutdowns comply with regulatory norms.
o Ensures that plant operations comply with environmental regulations and the design capacity
aligns with regulatory approvals.
4. Corporate Social Responsibility (CSR):
o Verifies that the company’s CSR activities are in line with the corporate policy and comply with
regulatory approvals.
o Ensures that CSR activities align with corporate goals and regulatory guidelines, such as the
Department of Public Enterprises (DPE) guidelines.
Benefits of Corporate Compliance Management:
Compliance with Law: Ensures adherence to laws and regulations.
Operational Improvement: Enhances operations and boosts productivity.
Market Positioning: Strengthens brand image and market presence.
Prevents Penalties: Avoids fines, penalties, and legal costs.
Loyalty Boost: Increases employee and customer loyalty.
Avoids Personal Penalties: Reduces risk of personal liability for leaders.
Talent Retention: Improves employee engagement and retention.
Shareholder Goodwill: Builds trust with shareholders and investors.
Creditworthiness: Boosts credibility and access to credit.
Cost Savings: Reduces expenses related to fines and litigation.
Ethical Culture: Embeds ethics, enhancing reputation and public respect.
Stakeholder Respect: Gains recognition as a responsible corporate citizen.
8
Secretarial Audit and Compliance Management System Dependant Factors: (FACTORS)
A company’s compliance system depends on:
Nature of business (manufacturing, services, etc.)
Locations of operations (domestic, international)
Company size (number of employees, technology use)
Laws & regulations affecting its industry
Public or private status (listed or unlisted)
How Secretarial Auditors Work?
Analyze company size & operations to check applicable laws.
Use Enterprise Resource Planning (ERP) in large companies for audits.
Improve Compliance Systems instead of just fault-finding.
Responsibilities of the Secretarial Auditor in ERP Environments
1. System Access: To conduct a comprehensive audit, the Auditor requires system access, allowing them
to review and assess the compliance mechanisms directly.
2. Compliance Assessment: Auditing is not about identifying faults but ensuring the compliance
framework aligns with the company's size, scope, and operational complexity.
3. Advisory Role: The Auditor provides insights and recommendations to enhance the company's
compliance management system. If the audit reveals areas of non-compliance or weaknesses in the
current framework, the Auditor should advise on corrective actions to strengthen compliance
practices.
Role of Company Secretaries in Compliance Management
Compliance Oversight:
Known as the "Compliance Manager" of a company, a Company Secretary ensures that the
organization aligns with all legal and regulatory requirements.
Corporate Disclosures:
Statutory and non-statutory disclosures, such as contingent liabilities, related party transactions, IPO
proceeds, and management discussions in governance reports. These disclosures are governed by
Companies Act, 2013 and SEBI (LODR) Regulations, 2015.
Advisory Role:
Company Secretaries act as advisors to management, boards, and committees on compliance-related
risks, responsibilities, and obligations resulting in better decision-making.
Corporate Governance:
As governance advisors, they guide boards on best practices, ensuring board procedures are followed
and decisions are documented accurately.
Centralized Compliance Support:
Company Secretaries provide a single-point resource for specialized compliance advice, making it
easier for businesses to address compliance concerns effectively.
9
Corporate Citizenship:
By upholding global standards and best practices, Company Secretaries guide the organization toward
ethical business conduct and responsible corporate citizenship.
Directors Responsibility Statement
The Directors’ Responsibility Statement is required under Section 134(5) of the Act to state as under:
i. In preparing the annual accounts, the applicable accounting standards and proper explanations relating to
material disclosures were followed.
ii. The directors had selected such accounting policies and applied them consistently and made judgments
and estimates that were reasonable and prudent to give a true and fair view of the state of affairs of the
Company at the end of the financial year and of the profit and loss of the Company for that period.
iii. The directors had taken proper and sufficient care for the maintenance of adequate accounting records in
accordance with the Act’s provisions for safeguarding the Company’s assets and for preventing and detecting
fraud and other irregularities.
iv. The directors had prepared the annual accounts on a going concern basis.
v. In the case of a listed company, the directors had laid down internal financial controls to be followed by
the Company and that such internal financial controls are adequate and operating effectively.
vi. The directors had devised a proper system to ensure compliance with all applicable laws and that such
systems are adequate and operating effectively.
Compliance Requirements Under the Companies Act, 2013
1. Director’s Interest Disclosures - Form MBP-1
o Directors must disclose their concern or interest in any entity, including shareholding, during the
first Board meeting they attend in each financial year or upon any changes in their disclosures.
2. Director Disqualification - Form DIR-8
o Directors are disqualified if the company has not filed financial statements or annual returns for
three consecutive years or has failed to repay deposits, interest, or redeem debentures.
o Such disqualification can last up to five years.
o If a director is appointed to a company with such defaults, they are exempt from disqualification for
the first six months.
3. Annual Return Filing - Form MGT-7
o Companies must file the Annual Return within 60 days of holding the AGM. If no AGM is held, it
must be filed within 60 days from the date it should have been held.
o Private companies’ returns must be signed by a director and company secretary, or by a
company secretary in practice if there is no in-house company secretary.
4. Financial Statements Filing - Forms AOC-4 & AOC-4 CFS
10
o Companies must file financial statements, including consolidated financials, within 30 days of the
AGM. If the AGM is adjourned or not held, the provisional statements must be filed within 30
days from the original due date, with reasons for the delay.
5. Certification of Annual Return - Form MGT-8
o Companies with a paid-up share capital of ₹10 crores or more or turnover of ₹50 crores or
more must have their annual return certified by a Company Secretary in Practice.
6. Circulation of Financial Statements
o The company must send approved financial statements (including the auditor’s report and
attached documents) to all members, debenture holders, and entitled persons 21 days before the
AGM.
7. Notice of AGM
o The notice for the AGM must comply with Section 101 of the Companies Act, 2013, and
Secretarial Standard-2. For private companies, Section 101 applies unless the articles specify
otherwise.
8. Board Meetings
o Every company must hold at least 4 Board meetings per year, with the gap between two
meetings not exceeding 120 days. For a company incorporated on June 15, the first meeting must
be held within 30 days, i.e., by July 14.
o One Person Companies, small companies, and dormant companies need to conduct at least one
Board meeting in each half of the calendar year, with a gap of no less than 90 days.
9. Notice of Board Meeting
o A Board meeting must be called with at least 7 days’ notice in writing, delivered to each director
at their registered address. This notice can be sent via hand delivery, post, or electronic means.
o If urgent business needs to be transacted, the meeting can be called at shorter notice, provided:
An independent director is present (if any).
If no independent director is present, the decision must be circulated to all directors and
will be final upon ratification by at least one independent director (if applicable).
10. Appointment of Auditor - Form ADT-1
The auditor must be appointed at the AGM for a period of 5 years.
The company must inform the auditor and file the appointment notice with the Registrar of
Companies (ROC) within 15 days of the AGM in Form ADT-1.
In case of Specified IFSC Private Companies, the filing must be done within 30 days of the
appointment.
11. Appointment of Company Secretary
A private company with a paid-up share capital of ₹10 crores or more must appoint a whole-
time Company Secretary as per the notification dated January 3, 2019.
11
If the Company Secretary is not appointed the company will incur a penalty of ₹5 lakhs, and
every director or key managerial personnel in default will face a penalty of ₹50,000, with an
additional ₹1,000 per day for continued default but not exceeding ₹5 lakhs.
12. Register of Members
Companies are required to maintain the following mandatory registers:
1. Register of Members (residing inside and outside India)
2. Register of Debenture-holders
3. Register of Security Holders.
If a company does not maintain a register of members or debenture-holders or other security holders or fails
to maintain them in accordance with the provisions of the Act, the company shall be liable to a penalty of ₹3
lakhs and every officer of the company who is in default shall be liable to a penalty of ₹50,000.
Case Laws
1. Economy Hotels India Services Pvt. Ltd. Vs. Registrar of Companies & Anr.
Case Citation: Company Appeal (AT) No. 97 of 2020
The appellant company sought confirmation for the reduction of share capital under Section 66 of the
Companies Act, 2013.
There was a typographical error in the minutes, where the required special resolution was
incorrectly referred to as a unanimous ordinary resolution.
The NCLAT ruled in favor of the company, allowing the reduction of share capital as the company had
complied with all statutory requirements, including filing the special resolution with the ROC.
2. Registrar of Companies, West Bengal Vs. Karan Kishore Samtani
Case Citation: Company Appeal (AT) No. 13 of 2019
The respondent director had been a director of more than 20 companies, violating the limit
prescribed under Section 165(1) of the Companies Act, 2013.
The NCLT allowed the compounding application, imposing a compounding fee of ₹50,000, but the
ROC appealed, stating that the minimum fine under Section 165(6) (₹5,000 per day) should apply.
The NCLAT held that the compounding fee should be at least equal to the minimum fine prescribed,
which led to a fine of ₹13,60,000 for the violation.
Provision Involved:
Section 165(6) - If a person holds more than 20 directorships, they are liable to a fine of ₹5,000 to ₹25,000
per day for every day the contravention continues.
Compliance Management Tools: Importance, Objectives, and Key Features
Compliance Management Tools: Compliance Management tools are software products that automate,
monitor, and manage compliance processes to meet the legal and regulatory compliance. These software tools
help to minimize human error, reduce compliance costs, and enhance organizational efficiency.
Features and Objectives of Compliance Management Tools: (DAC)
1. Digitization
o Changes all paper/manual work into digital form.
o Reduces the information and communication gap.
o Enhance visibility and accountability.
12
2. Automation
o Gives automatic legal updates when laws change
o Sends reminders and alerts if any deadline is near or missed
o Shows real-time reports and dashboards to monitor compliance status
3. Compliances
o Facilitate monitoring and ensure compliance with all relevant laws and regulations.
o Help prevent penalties, litigation, and prosecution due to non-compliance.
o Improves internal controls and systems.
o Assist in audit management and audit documentation.
Impact of Cloud Computing on Compliance Management: Cloud-based compliance management has
grown popular due to its scalability and lower maintenance needs. However, it introduces cybersecurity risks.
To address this, SEBI issued a circular, providing a cloud framework to ensure secure and compliant cloud
adoption by regulated entities (REs). The framework helps REs assess risks, implement controls, monitor
compliance, and ensure regulatory adherence in cloud environments.
Types of Compliance Management Tools:
1. All-Purpose Compliance Management Platforms
These tools are designed to be flexible and can be used across various types of organizations.
Focus Areas:
o Corporate Governance
o Risk Remedy
o Technical Issue Resolution.
2. Industry-Specific Compliance Management Tools
Tailored to meet the compliance of laws and regulations of specific industries (e.g., healthcare,
manufacturing, finance). These tools ensure that organizations within certain sectors meet the
particular regulatory and legal requirements that apply to their industry.
3. GRC (Governance, Risk, and Compliance) Software
GRC software is a broad tool designed for:
o Handling Corporate Governance tasks
o Risk Management
o Compliance Risk Monitoring.
Benefits of Compliance Management Tools
1. Reduction in Manual Work
Compliance management tools reduce manual work by automating tasks and reduces time and effort,
helping organizations focus on growth and improvements.
2. Reduces Risk of Human Errors
Improves the compliance programs performance and reduces the risk in human errors. Quickly detects
compliance failures and generates reports.
3. Streamlining Implementation
Facilitates the smooth implementation of compliance frameworks and standards. Helps in smoother
compliance audit and corrective steps.
13
4. Simplification in Monitoring and Reporting
Automates compliance due dates and sends alerts for upcoming deadlines. Ensures timely updates and
easier monitoring of compliance status.
5. Builds Organizational Reputation
Strengthens relationships with customers, employees, and stakeholders, ultimately enhancing the
company’s market reputation.
6. Creates a Roadmap for the Business
Provides a clear view of regulatory requirements and identifies improvement areas. Provides a
"compliance calendar" to prioritize and manage compliance tasks efficiently.
14
Lesson: 2 (Documentation & Maintenance of Records)
Definition of Document and Record
Document:
A document is a part and parcel of any written, printed, or electronic matter that provides
information.
It can be in a structured (organized) or unstructured (informal) format.
Documents be changed and revised as per requirement.
Common examples include emails, reports, and shopping lists.
Record:
A record is a matter of evidence about the past.
Documents often start as general information but become records when they are preserved as proof,
often for legal or business purposes.
Not every document becomes a record, and not all records are documents. For instance, a record
can also include audio recordings or photographs.
Examples of records are final reports, confirmation emails, business contracts, and spreadsheets
used as evidence.
Role of the Company Secretary in Documentation and Record Maintenance
The Company Secretary (CS) plays a crucial role in preparing and maintaining a company’s secretarial and
corporate records and this includes creating, managing, and safeguarding essential corporate
documents. This requires a comprehensive understanding of:
What documents need to be created.
The purpose of each document.
The required level of detail and disclosure.
The CS also ensures document confidentiality and checks each document for consistency, compliance with
corporate policies, and adherence to legal and tax requirements.
Regulatory Framework
The key regulatory framework guiding the CS in record-keeping includes:
The Companies Act, 2013
The Companies (Management and Administration) Rules, 2014
SEBI (LODR) Regulations, 2015
Responsibilities of the Company Secretary
The CS is responsible for the storage, retrieval, and certification of corporate documents, ensuring:
Records are retained for the required period.
Safe storage and backup (hard copy and electronic) for timely access.
Maintenance of documents related to subsidiaries, joint ventures, etc., in both local and international
locations.
In some cases, the CS may rely on local partners to maintain these records but still needs to exercise
oversight. Additionally, the CS may execute documents on the company's behalf and handle document-
related aspects of corporate websites and social media.
15
⚖️Key Case 1: M/s. SDU Holdings Private Limited
🔎 Issue:
During inspection under Section 206, the Registrar found that the company's Register of Members
(MGT-1) was incomplete.
🧾 Action Taken:
The Registrar issued a show cause notice and provided the company and its directors a reasonable
opportunity to be heard.
After the hearing, the Adjudicating Officer imposed a penalty for violating Section 88.
⚖️Key Case 2: Welspun Project Ltd. v. NCLT, Ahmedabad
🔎 Issue:
The company’s Register of Directors' Shareholding (under old Section 307 of Companies Act,
1956, now Section 170 of the 2013 Act) was not properly maintained for over 8 years.
🧾 Action Taken:
The company admitted the violation.
Filed for compounding of offence under Section 621A (now Section 441) of the Companies Act,
2013.
The offence was compounded (i.e., settled) by payment of fine.
Purpose of Documentation
1. Client Service: Documentation enables professionals to serve their clients in a timely and effective manner.
2. Communication: It provides a foundation for clear and accurate communication among professionals.
Provides a reliable, factual, and permanent record for client interactions.
3. Accountability: Documentation demonstrates professional accountability. It can be used in performance
reviews, internal reviews, regulatory processes, or legal proceedings.
4. Professional Responsibility: Maintaining proper documentation is a fundamental part of professional
conduct.
5. Quality: Documentation may be used to evaluate professional practice in terms of peer reviews, audits,
regulatory inspections, and critical incident reviews.
6. Legal Requirement: Many professions are legally required to maintain certain records in line with practice
standards and organizational policies.
7. Research: Documentation provides data for research, client outcome evaluations, and evidence-based
practices.
8. Resource Management: Accurate documentation supports efficient resource allocation and management.
Guiding Principles of Good Documentation
4C Docs Keep Clients' Confidential Info Clear
1. 4C – Clear, Concise, Complete, Consecutive
2. Docs – Correct, Contemporary, Comprehensive
3. Keep Clients' Confidential Info Clear – Client-Centric, Collaborative, Confidential
Good
Documentation Practice:
Good documentation practices are a set of best practices for documentation and recordkeeping that aim to
ensure data integrity and reliability. It can also serve as guidelines for how to record information and store
data appropriately.
Examples of Poor Documentation Practices
16
(Every Work Record Documents Fail, So Overlook Procedures and Charts)
1. Every – Errors, Corrections (Errors in documents are not corrected properly, lack a signature/date, or do
not include a reason for the correction)
2. Work – Write-overs, White-out (Write-overs, multiple line-throughs, and use of "White-out" or other
masking devices)
3. Record – Recording out of Sequence (Recording events not in sequence & tabled)
4. Documents – Delegation not recorded (The delegation of work is not recorded/documented)
5. Fail – Failure to Authorize SOPs (Standard operating procedures adopted by professionals not authorised)
6. So – Out-of-Spec Procedures (Out-of-specification procedure not detailed enough)
7. Overlook – Missing Flowcharts/Checklists (Flow chart and/or checklist not available)
Examples of Good Documentation Practices
(Records Should Clearly Supervise Clear Pictures, Don't Assume!)
1. Records – Records should be completed at the time of activity or when any action is taken
2. Should –Superseded documents should be retained for a specific period of time
3. Clearly – Concise, legible, accurate, traceable
4. Clear – Clear examples should be provided
5. Pictures – A picture is worth a thousand words
6. Don't Assume! – Don’t assume knowledge / information.
Good
Documentation Practices: Do's and Don'ts
Do's Don'ts
Record the data/document as soon as it is Don’t delay in data/document recording.
generated.
Specify when the data/document was recorded, Don’t pre-date or back-date the data/document.
reviewed, and approved.
Add reference notes (if possible) to provide Don’t make the data confusing, vague, or
context. unreadable.
Limit document access to authorized personnel. Don’t intentionally falsify the record/document.
Validate your computerized system or document Don’t encourage handwritten documentation.
software.
Keep data backup, either automatically or by Don’t archive data/documents unless explicitly
storing a true copy in a separate location. authorized.
Electronic
Repository of Documents: Document Management Systems (DMS)
An electronic repository is a system for managing and tracking documents electronically. It involves the use
of Document Management Systems (DMS) to digitize, organize, and securely maintain documents.
A Document Management System (DMS) manages, stores, and tracks documents in an organization
electronically. This includes content capture, workflow management, repositories, and retrieval systems.
Advantages of DMS (TEAR LV N)
1. Tracking – Tracking check-in/check-out by officers
2. Editing – Simultaneous editing
17
3. Auditing – Ease in Audit trail
4. Rolling – Roll-back and Retrieve options
5. Locking – Locking and unlocking of documents
6. Version – Document Version Control
7. Note – Annotation and Stamps.
Advantages
of Electronic Records:
1. Cost-Effectiveness: Digital storage is cheaper compared to physical records. Storage costs keep
decreasing with technological advancements.
2. Labor Savings: Minimal effort required for managing, retrieving, or disposing of records. Tasks like filing,
collating, and stapling can be automated.
3. Ease of Use: Quick and easy to locate and share electronic documents. No need for physical filing -
document management systems handle organization.
4. Searchability: Optical Character Recognition (OCR) makes text searchable by keywords. Finding
information in electronic documents is faster than in paper records.
5. Version Tracking: Changes to documents can be tracked easily. Enables viewing of past versions and
identifying who made changes.
6. Portability: Documents can be easily stored and transported on hard drives or USB devices. No need for
physical storage space like boxes and warehouses.
Disadvantages of Electronic Records/ Media compatibility is one of the biggest challenges in saving
documents electronically
1. Software Risk: Electronic Document Management Systems (EDMS) rely on specific software, which poses
risks if the software company ceases to exist or stops supporting the product. This could lead to the
documents being locked within an unsupported system, requiring costly conversion processes to retrieve
them.
2. Format Risk: While formats like PDF and JPEG are common today, there's no guarantee these formats will
remain accessible in the long term. If future software no longer supports these formats, stored documents may
become unreadable.
3. Reliability: Unlike electronic formats, paper documents are format-independent and can be read without
specialized tools - just a light source and good vision. A person should keep a paper copy of vital documents -
deeds, corporate documents-stored in a safe off-site location.
4. Portability and Security Risks: Since electronic records are highly portable, it’s very easy to misplace or
accidentally delete large amounts of data. Data can be easily transported outside the organization, stolen, or
misplaced if adequate security measures aren’t in place but those safeguards are expensive.
Maintenance
and Inspection of Documents in Electronic Form Under the Companies Act, 2013
Section 120 of the Companies Act, 2013, along with Rule 27 and Rule 28 of the Companies (Management and
Administration) Rules, 2014, specifies the guidelines for maintaining and inspecting documents in electronic
form.
Eligibility for Electronic Record Maintenance:
18
The Act mandates that Listed Companies or companies with at least 1,000 shareholders, debenture
holders, or other security holders are eligible to maintain records electronically.
Such electronic records should be accessible for inspection and copying by authorized personnel or
stakeholders as required under the Act.
Scope of "Document" and "Records":
Section 2(36) – "Document" includes notices, registers, declarations, etc. (whether in paper or electronic
form).
"Records" – Includes registers, agreements, minutes, etc., required under the Act.
Requirement
s for Maintaining Electronic Records
[Link] records must adhere to the same formats and requirements stipulated by the Act and its rules.
[Link] must be capable of being updated as per statutory provisions, with the date of each update.
[Link] recorded electronically must be thorough, clear, and suitable for future reference.
[Link] must be readable, retrievable, and printable.
[Link] signatures are required when stipulated by the Act,
[Link] signed, records should not be editable or alterable.
Security
Measures for Electronic Records (Rule 28)
Responsibility Assignment:
1. The Managing Director, Company Secretary, or any designated officer decided by the Board is responsible
for the maintenance and security of electronic records.
Responsibilities of the Designated Officer:
1. Ensure any non-electronic originals converted to electronic form are accurate, authentic, and legible.
2. Proper indexing for easy location, access and retrieval of Data.
3. Maintain records in non-editable formats (e.g., PDF).
4. Limited access to authorized persons only.
5. Protection against unauthorized access, tampering, or loss.
6. Ensure systems can detect invalid or altered records, maintaining data integrity.
7. Protect the security, integrity, and confidentiality of records at all times.
8. Backup at least once a day, authenticated & stored securely.
Comparison
of physical and virtual data rooms
S. No Particulars Physical Data Room Virtual Data Room
Papers, files, boxes, or other Electronic/digital/soft copies,
1 Form of Documents
tangible items including video/audio files
Security of Depends on the integrity of the in- Secured by log-in credentials,
2
Documents charge passwords, and internet firewalls
Time Required for Can be created within 48 hours once
3 Longer setup time
Creation demands are identified
High (due to personnel
Lower (documents accessible
4 Cost requirements, travel for bidders,
remotely with internet security)
etc.)
19
5 Convenience Manual searching required Faster searching with search tools
6 Accessibility Restricted timings 24/7 access possible
Restricting
7 Difficult to enforce Easily restricted digitally
Document Access
Not always possible, depending on
8 Copying Documents Possible
restrictions
Highlighting New Can be highlighted directly in the data
10 Must be communicated manually
Information room site
Communication
11 Available one-on-one Not typically available
with Seller
Best
Practices for Coding and Nomenclature in Document Management
[Link] vs. Non-Descriptive File Names:
o Descriptive File Names: Clear, meaningful names (e.g., "Board_Minutes_2025.pdf").
Useful for small, well-defined projects.
Include details such as the source material, making them self-explanatory.
Risk: Typos or inconsistent terms can lead to indexing errors.
o Non-Descriptive File Names: System-generated IDs (e.g., "20250401_001.pdf").
Suitable for large-scale digitization projects
Typically system-generated (e.g., numerical IDs, date, and time).
Advantage: Minimized chance of duplicate or non-unique file names within the system.
[Link] Spaces in File Names:
o Spaces can be problematic for some applications, leading to errors in file recognition or processing.
o Use underscores (_) or hyphens (-) instead of spaces.
[Link] Punctuation and Special Characters:
o Avoid symbols such as periods, commas, parentheses, ampersands, and asterisks.
o These characters can interfere with file compatibility, indexing, or file retrieval processes.
Guidelines
for Effective File Naming Conventions
1. Uniqueness and Consistency: File names should be unique and follow a structured pattern.
2. Persistence: Avoid tying names to elements that may change over time.
3. Character Limit: Limit length to 25–35 characters.
4. Sorting: Use leading zeros for numerical order (e.g., 001, 010, 100).
5. File Extensions: Include standard extensions like .pdf, .jpg, or .doc.
6. Date Format: Use standard formats like YYYY-MM-DD or YYYYMMDD.
7. Lowercase Letters: Prefer lowercase; For multi-word names, use uppercase at the start of each word (e.g.,
Document_Title_001.doc).
8. Avoid Symbols: Do not use characters like @, &, *, (,).
9. Spaces: Replace spaces with hyphens (-) or underscores (_).
10. Avoid Complexity: Keep names simple to reduce errors (e.g., avoid "[Link]").
Circulation of
Documents
20
Control and Authorization:
Documents (e.g., instructions, procedures, and drawings) must be reviewed for adequacy and approved by
authorized personnel before release.
Distribution ensures documents are used where activities are performed.
Change Management:
Changes to documents should be reviewed and approved by the same authority or a designated alternate
authority.
Ensures consistency in control over document modifications.
Safety and
Retrieval of Records
To maintain quality and provide evidence of activities, records should meet specific standards:
1. Operating Logs: Names of individuals involved in creating or handling the documents.
2. Records of Review: Capture changes, suggestions, and reasons for approval or rejection.
3. Inspection: List of individuals with inspection rights and access history.
4. Work Monitoring: Tracks file-sharing and usage.
5. Information Analysis: Facilitates effective tracking and retrieval of files.
Three Key
Concepts for Record Management
1. Keeping Together: (Respect the Origin)
o Group records by the department/section responsible for their creation.
o Maintain the original order for evidential value and easier retrieval.
o Relevant for both physical and electronic records.
2. Ensuring the Life Cycle: (Track Every Stage)
o Records go through three phases:
Current Phase: Actively used for ongoing business and stored at the place of origin.
Semi-Current Phase: Used less frequently and stored in a records center.
Non-Current Phase: Destroyed or archived if they hold continuing value.
o Records management throughout the record life cycle is crucial for efficient governance.
3. Record Preservation: (Protect and Maintain)
o Keep records safe and accessible for as long as they’re needed, including
Identify & classify records properly.
Understand what the record contains and why it matters.
Ensure right people can find and use the records when required.
Protect records from damage (water, pests, etc).
Preservation
of Records – SEBI (LODR) Regulations, 2015
The preservation of records is an essential process that ensures the longevity and accessibility of documents
for legal, regulatory, and business purposes. As per the SEBI (Listing Obligations and Disclosure
Requirements) Regulations, 2015, listed entities are mandated to adopt a comprehensive policy for the
preservation and archival of documents. Below are the key provisions and guidelines for preparing such a
policy:
Regulation 9: Preservation of Documents
21
Policy Requirement: A listed entity is required to have a policy for the preservation of documents, which
must be approved by its Board of Directors.
Document Classification:
1. Permanent Preservation: Some documents are to be preserved permanently due to their
historical or legal significance.
2. Preservation for 8 Years: Other documents must be preserved for at least 8 years after the
relevant transactions have been completed.
Electronic Mode: Documents that are classified under these categories can be stored in electronic
format, ensuring that they are accessible without compromising their integrity.
Steps to
Develop a Preservation and Archival Policy
1. Analysis and Restructuring:
o Review laws, policies, and current systems.
o Check what resources (staff, space, budget) are needed.
o Make long-term strategic and business plans.
2. Organizing and Controlling Records:
o Build efficient record-keeping systems.
o Monitor how records are created, stored, and used.
3. Providing Physical Protection:
o Take steps to preserve and protect documents.
o Plan for emergencies (like fire or floods).
o Secure critical or vital records.
4. Managing Records in Records Centers:
o Set up secure record centers.
o Follow proper transfer, storage, and disposal schedules.
o Make sure disposal is legal and timely.
5. Managing Archives:
o Acquire and organize archives using proper methods.
o Describe and document for easy search.
o Allow public access where suitable.
6. Support and Sustainability:
o Promote awareness among public and stakeholders.
o Train staff in record-keeping and archiving.
o Build professionalism in this field.
Regulation
30(8): Archival and Website Disclosure
Disclosure on Website: The listed entity must disclose all events or information disclosed to stock
exchanges (under Regulation 30) on its website.
Minimum Duration: These disclosures should remain available on the website for at least 5 Years.
Post-5 Years: After five years, the information should be maintained as per the company’s archival
policy, which must also be disclosed on its website.
Preservation
of Litigation Documents
22
Court Orders or Judicial Directives: Documents arising out of litigation where a company is a party must
be preserved as per the directions/orders of the relevant court(s), tribunal(s), or other
judicial/authorities.
In the Absence of Specific Orders: If there are no such orders or directions, the documents must be
preserved for at least 8 Consecutive Calendar Years following the conclusion of the litigation.
Deviation from the Policy
A court, tribunal, or other judicial authority can direct a company to produce, preserve, or destroy
documents. If documents are destroyed per SEBI-compliant policies and cannot be reproduced, the company
must seek necessary permissions or provide a statement to the authority.
A.
Documents Whose Preservation Shall Be Permanent in Nature:
1. Property Records:
Purchase and sale deeds
Licenses, copyrights, patents, and trademarks
2. Corporate Records:
Certificate of Incorporation
Common Seal
Minutes of Board, Committee, and Shareholder Meetings
Register of Members and other statutory records.
3. Personal Files of all active employees
4. Other Records:
Any other document as may be decided by the Chief Executive Officer (CEO), Managing
Director (MD), or Whole-time Director (WTD) from time to time.
Documents
Whose Preservation Period Shall Not Be Less Than 8 Years After Completion of the Relevant
Transactions:
1. Books of Account, Bank Statements, and Vouchers
2. Filings with Statutory Authorities:
Stock exchanges, Registrar of Companies, and other statutory authorities
3. Employee Records:
Payroll Records
Employee deduction authorizations
Attendance records
Leave records
Employee medical records
Pension and retiral-related records
4. Corporate Social Responsibility Records
5. Sponsorship Projects Records
6. Correspondence and Internal Memoranda
7. Other Records:
Any other document as may be decided by the CEO from time to time.
Documents
Whose Preservation Shall Be for a Minimum Period of 3 Years After Completion of the Event:
1. Tender Documents
23
2. Lease Deeds and Contracts
3. Legal Files
4. Insurance Records
5. All E-mail Correspondence (Internal & External)
6. Documents under Secretarial Standards:
Proof of Sending Notice of the Meetings
Proof of Sending Agenda and Notes on Agenda
Proof of Sending and Delivery of the Draft of the Resolution
Proof of Sending Draft Minutes of the Board / Committee Meetings
Proof of Sending Signed Minutes of the Board / Committee Meetings
7. Any Other Record:
Any other document as may be decided by the Chief Executive Officer (CEO), Managing
Director (MD), or Whole-time Director (WTD) from time to time.
Model Policy
on Preservation and Archival of Documents
(As per Regulation 9 and 30(8) of SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015)
1. Purpose and Scope
This policy outlines the approach for preservation and archival of the company's documents, both physical
and electronic, in compliance with:
The Companies Act, 2013.
SEBI (LODR) Regulations, 2015.
It provides guidelines for:
Systematic handling of documents.
Identifying documents for retention, maintenance, and destruction.
Ensuring accessibility and retrieval when required.
2. Classification of Documents
Documents are categorized for preservation as:
1. Permanent Preservation
2. Preservation for Eight Years
3. Preservation for Three Years
3. Employee Responsibility
All employees in permanent role must:
Evaluate the preservation needs of documents in their work area.
Make decisions about retaining, preserving, or destroying documents responsibly.
4. Periodical Policy Review
The CEO/Managing Director/Whole-Time Director will periodically review the policy.
5. Suspension of Record Disposal
If the company:
o Receives a notice regarding a document-related request.
o Faces a government investigation or litigation.
Disposal of relevant documents will be suspended until the matter concludes.
6. Statutory Requirements
If any law (e.g., Information Technology Act) mandates a longer preservation period, the respective
document will be preserved accordingly.
7. Web Archival Policy
Events or information disclosed to stock exchanges will also be published on the company's website.
24
These disclosures will be retained on the website for a minimum of five years.
Setting Up of a Record Room:
Establishing a well-organized and secure record room is essential for proper document preservation and
retrieval. Below are the guidelines and factors to consider:
Location and Construction
Convenient Access: The record room should be located at a convenient location for access.
Separate Space: It must be distinct from other administrative units.
Strong Construction: The structure should be robust to bear the weight of records and must be secure
and well maintained.
Environmental Conditions
1. Humidity Control:
o Ideal humidity: 30%–40%, with minimal fluctuations to prevent damage.
o High humidity leads to fungus growth and insects, while low humidity makes paper brittle.
2. Temperature Regulation:
o Lower temperature is better for preservation of records however, it is better to maintain a normal
temperature for human comfort.
3. Light Management:
o Minimize exposure to visible light, infrared, and ultraviolet radiation as it could cause damages.
o Use curtains with UV filters for windows and store documents in dark places when not in use.
Safety and Security Measures
Fire Extinguishers
Special Paints
Security Checks.
Compliance with Public Records Act, 1993:
Public Records Act, 1993: This Act governs the management, administration, and preservation of public
records of Central Government, Union territory Administrations, Public Sector Undertakings, Statutory Bodies,
and other related organizations. The provisions of the Act should be followed when setting up a record room.
Privacy of
Records and Control Measures
In today’s digital and physical data landscape, safeguarding privacy and ensuring the secure handling of
records is critical for every organization. Below is a breakdown of key aspects related to protecting
confidential information and suggested steps for privacy management:
1. Identifying Confidential Documents
The first step in safeguarding privacy is identifying what documents are confidential. Common confidential
information in organizations includes:
Customer and Employee Information: Includes personal data like Aadhaar numbers, mobile numbers,
addresses, and payment information.
Internal Office Plans and Procedures: Documents that detail internal workflows, office layouts, IDs, and
emergency exits.
Contracts, Commercial Documents, and Trade Secrets: Contracts with sensitive details, trade secrets,
and business terms are considered highly confidential.
25
2. Key Confidential Documents and Their Privacy Needs
To effectively manage privacy, it's essential to define which documents need specific privacy controls:
(i) Customer & Employee Information
Protection: Information that can uniquely identify individuals, like personal contact details or payment
information, requires robust security.
Handling: In case of outdated or irrelevant records, proper disposal is mandatory. Partnering with a
trusted information destruction agency ensures secure disposal of both physical and digital copies to
prevent data breaches.
(ii) Office Plans, IDs, and Internal Procedure Manuals
Confidentiality: Office layouts and emergency exit plans should be accessible in case of an emergency,
while internal procedure manuals should be kept on secure network drives with limited printouts.
Access Control: Procedures, internal protocols, and organizational IDs should only be available to
employees who require them for their duties.
(iii) Contracts, Commercial Documents, and Trade Secrets
Strict Confidentiality: Contracts and trade secrets contain commercially sensitive information such as
business terms, valuations, and contracting parties.
Secure Handling: Avoid unnecessary sharing or printing of these documents. Where possible, use
electronic signing tools and limit physical copies to reduce risk.
3. Secure Document Handling Practices
Digital Security Measures:
Use firewalls, encryption, and password-protected access for digital files.
Store confidential files on secure network drives with restricted access and limited sharing permissions.
Physical Document Security:
Use secure filing cabinets or locked storage rooms for physical documents.
Limit access to sensitive files and require authorized sign-in for employees handling these documents.
Destruction of Confidential Information:
Partner with a data destruction agency for physical documents that are no longer needed.
Ensure electronic data is erased following secure data wipe protocols to prevent any chance of recovery.
4. Developing a Document Retention Policy
A secure document retention policy should outline the duration for which documents are retained and the
methods of disposal. The policy should specify:
Retention Periods: Define the length of time for retaining different types of documents, aligned with
regulatory requirements and business needs.
Access Protocols: Establish who has access to specific documents and the steps required to gain access.
Destruction Procedures: Outline the steps for secure disposal, specifying physical shredding for hard
copies and secure deletion for digital files.
Suggestive
Steps for Protecting Confidential Information
1. Physical Security
o Store confidential documents in locked file cabinets or rooms with restricted access.
o Ensure employees clear desks of sensitive information at the end of the day.
26
2. Digital Security
o Use firewalls, encryption, and passwords to secure electronic data.
o Mark all confidential information as “confidential” for clarity.
3. Controlled Access
o Restrict access to confidential data to authorized personnel on a “need-to-know” basis.
4. Data Minimization
o Avoid collecting excessive client data unless absolutely necessary for business transactions.
5. Workplace Best Practices
o Avoid leaving confidential documents visible on computer screens when stepping away.
o Refrain from discussing sensitive information in public places.
o Limit the use of email for transmitting sensitive or controversial information.
6. Proper Disposal
o Shred physical documents before disposal.
o Wipe old computers using secure software or destroy hard drives to eliminate data.
Lesson: 3 (Signing and Certification)
27
What is Pre-Certification? Pre-certification refers to the process by which a professional, such as a Company
Secretary in Practice, verifies and certifies the accuracy of a document before it is filed with the Registrar
as per the Companies Act, 2013. This process ensures that e-forms are correct before they reach the Registrar.
Once a professional certifies an e-form based on the examination of the forms and supporting documents, the
ROC can record it without the need for further scrutiny, relying on the accuracy and truthfulness certified
by the professional.
Rule 8 of the Companies (Registration Offices and Fees) Rules, 2014 details the responsibilities of
professionals when certifying and authenticating e-forms. Key points include:
1. Digital Signature: According to Rule 8(1), (2), and (5), e-forms must be authenticated using digital
signatures by an authorized company signatory. These signatories may include the Managing Director, a
Director, the Company Secretary, or other key managerial personnel.
If there is a change in directors or Company Secretary, the form related to the new appointment must be
signed by a continuing director, the Company Secretary, or another authorized individual.
2. Scanned Original Signatures: Rule 8(6) requires that scanned images of documents attached to e-forms
must be originals with actual signatures. Blank documents or documents lacking the authorized
person’s signature are not permissible.
3. Complete and Legible Attachments: As per Rule 8(7), both the person signing the form and the
certifying professional must ensure that all necessary attachments are complete, legible, and relevant
to the form or application being filed.
4. Signing Requirements under Rule 8A: Effective from January 23, 2023, Rule 8A specifies that e-forms,
when applicable, must be signed by an Insolvency Resolution Professional, Resolution Professional,
or Liquidator in cases where a company is under insolvency or liquidation. These signed e-forms must be
filed with the ROC along with any applicable fees as stipulated.
Certification
Declaration
When certifying an e-form, the professional must make a declaration, which includes:
1. Verification
The professional certifies that they have reviewed the provisions of the Companies Act, 2013 and
the relevant rules.
They also confirm that they have verified the details from the original or certified records of the
company, and all information is true, correct, and complete.
2. Accountability
The professional acknowledges that they are liable under Section 448 of the Companies Act, 2013 for
any false certification.
Importance
of pre-certification
1. Ensuring Correctness
Pre-certification helps ensure that the information submitted in e-forms is accurate as per the provisions
of the Act and Rules thereunder and aligns with the company’s official records.
If any discrepancies or defects are found, the PCS can advise on necessary corrections before certification.
28
2. A Pre-emptive Step
Pre-certification acts as a preventive measure to ensure that forms and returns are complete and in
accordance with the company’s records. The PCS’s certification allows the RoC to take record of the
document without further examination.
3. Encourages Self-Regulation
With pre-certification, independent professionals verify the authenticity of documents, reducing the need
for government intervention i.e, RoC.
If a professional provides a false certification or omits critical information, they face punishment under
the provisions of the Act as well as liable for professional or other misconduct under Company Secretaries
Act, 1980.
4. Aids Good Governance
Ensures transparent disclosures to shareholders & stakeholders. Supports statutory compliance in
financial statements, Board’s report, and annual return. Helps directors and company officers avoid
penalties for misstatements.
Certifications
under the Companies Act, 2013:
Companies (Incorporation) Rules, 2014
1. Declaration of Compliance
o Companies must declare that they have complied with the requirements of the Companies Act,
2013 and related rules for registration.
2. Declaration for Memorandum and Articles of Association
o The company must declare that the draft memorandum and articles conform to Section 8 of the
Companies Act, 2013 and related rules.
Companies (Prospectus and Allotment of Securities) Rules, 2014
Form PAS-6
o Unlisted public companies must submit Form PAS-6 to the Registrar within 60 days from the
conclusion of each half-year.
Companies (Share Capital and Debenture) Rules, 2014
1. Certification of Buyback of Securities
o A professional must certify that the buyback of securities complies with the Companies Act and its
rules.
Companies (Appointment and Remuneration of Managerial Personnel) Rules, 2014
1. Secretarial Audit Report
o Secretarial Audit Report must be issued by a Company Secretary for every listed company, or any
public company with a paid-up share capital of ₹50 crore or more, or a turnover of ₹250 crore or
more.
Companies (Management and Administration) Rules, 2014
1. Certification of Annual Return
o Annual returns of listed companies or those with paid-up share capital of ₹10 crore or more, or
turnover of ₹50 crore or more, must be certified by a professional.
2. Appointment as Scrutinizer
o A Company Secretary must be appointed to scrutinize e-voting for listed companies or those with
over 1,000 shareholders.
29
Pre-
Certification Under SEBI Regulations
1. Regulation 40(9) (Listing Obligations and Disclosure Requirements) Regulations, 2015
o The share transfer agent must produce a certificate from a practicing Company Secretary, verifying
that share certificates were issued within 30 days of the lodgement date.
2. Regulation 24A (Listing Obligations and Disclosure Requirements) Regulations, 2015
o A secretarial audit report must be given by a Company Secretary in practice.
3. Regulation 55A (SEBI (Depositories and Participants) Regulations, 2018)
o Issuers must submit an audit report by a practicing Company Secretary for quarterly
reconciliation of the total issued capital.
4. Regulation 76 (SEBI (Depositories and Participants) Regulations, 2018)
o A reconciliation of share capital audit report must be submitted.
5. SEBI Circular - SEBI/110/DDHS/CIR/P/2018/144
o Disclosures related to debt securities issuance by Large Corporates must be certified by both the
Company Secretary and CFO.
6. SEBI (Buy-Back of Securities) Regulations, 2018
o All filings related to buybacks must be electronically filed with the Board and signed digitally by
the Company Secretary.
Other Certifications under SEBI Regulations
1. Corporate Governance Compliance Certificate
2. Directors’ Disqualification Certification
3. IPO-Related Certifications
4. Bonus Issue Certification
5. Receipt of Money for Allotment
6. Shareholding Pattern Certification
7. Certification for Securities Offer/Allotment in cases where securities are offered or allotted to 50-200
investors.
8. Investment Adviser Compliance
9. Research Analyst Compliance Audit
10. Quarterly Certificates for Application Monies
11. Placement of Securities Pricing Compliance
12. Debenture Terms Certification
13. REITs Units Certification
14. Lock-in Certification.
Pre-
Certification Under Limited Liability Partnership Act, 2008
S. No. Form/Web Form Purpose
1 Form-3 Information on the Limited Liability Partnership Agreement and any changes
made therein.
2 Form-4 Changes in designated partners or partners in the LLP, including appointment
or cessation.
3 Form-11 Annual Return of Limited Liability Partnership.
4 Form-15 Shifting of the registered office of the Limited Liability Partnership.
Preparations
Before Pre Certification
30
1. Understanding Legal Provisions:
The professional should study the provisions of the Companies Act 2013 and the related Rules.
Familiarize themselves with actual practices related to pre-certification tasks.
2. Authorization and Engagement Documentation:
Obtain a Letter of Engagement or Board Resolution that authorizes them to conduct the assignment.
3. Documentation and Record-Keeping:
Maintain scanned or physical copies of all documents that have been verified, while respecting
confidentiality requirements.
4. Verification and Accuracy:
Verify documents against original company records to ensure authenticity.
Check for accuracy and completeness in all records to ensure there are no material discrepancies from
factual information.
Confirm that the form is signed by an authorized person within the company.
5. Familiarity with Relevant Provisions:
Be well-versed with relevant Act provisions, applicable Rules, and company procedures.
Know any approvals required and the steps the company must follow before certifying any form.
6. Quality and Compliance in Attestation:
Maintain a register of all attestation and certification services provided, open for authorized
inspection.
7. Avoiding Professional Misconduct:
According to Part I of the First Schedule of the Company Secretaries Act 1980, a PCS should not allow
non-members or non-partners to sign on their behalf.
Allowing unauthorized individuals to sign certifications constitutes professional misconduct.
Common
Errors Noticed In E-Filing
Digital signature is not registered / expired
Payment of challan not done before the expiry date
Duplicate Payments have been made
The size of the form exceeds size requirements
E-forms are not verified before filing
Incorrect particulars in the e-form
Using older versions of Adobe and Java
Unsupported OS (Windows 2000 or earlier)
Browser compatibility issues
Outdated Adobe Reader version
Incompatible Java version
Consideratio
ns In Filling E-Forms
1. Review Instruction Kit:
Begin by thoroughly reading the instruction kit for each e-form, available on the MCA-21 portal, to
understand the form’s requirements.
2. Director Identification Number (DIN):
Ensure that DIN details of the Directors are up-to-date on the MCA Portal, as DIN is mandatory for e-
filing.
3. Digital Signature Certificate (DSC):
31
A valid Digital Signature Certificate is required, which should be registered on the MCA Portal before
first-time use.
4. Check Company’s Master Data:
Verify the company’s Master Data on the MCA Portal to confirm the accuracy of the details before
submitting any forms.
5. Organize and Attach Supporting Documents:
Ensure all attachments are complete, numbered, and ordered correctly. Attach scanned documents in
PDF format with minimal file size, as required.
6. Timely Filing:
File forms early to avoid last-minute issues, ensuring timely submission and avoiding penalties
associated with late filing.
7. Data Accuracy:
Carefully fill out the form entries, cross-checking each field against the supporting documents to ensure
correctness.
8. No Revision Options:
Note that once submitted, revision or cancellation of e-forms is not permitted on the MCA Portal if the
form is taken on record.
9. Pay Filing Fees Promptly:
If using the “Pay Later” option, ensure that filing fees are paid before the expiry date on the challan, as
non-payment may result in the cancellation of the transaction.
10. Stay Updated on Reportable Events:
As an advisor, monitor reportable events for the company and encourage regular filing of requisite forms
to prevent penalties or regulatory action.
11. Utilize MCA Utilities:
Use portal utilities such as “PREFILL,” “CHECK,” and “PRESCRUTINY” to verify entries, minimize errors,
and enhance accuracy.
12. Verify Authorization Dates:
Double-check the date of resolutions and minutes that authorize the signatory, ensuring the entries
align with the company's official records.
13. Authorized Signatory and DSC:
Confirm that the DSC of the authorized signatory (Director/Secretary) aligns with the authority
delegated by the Board.
Annual
Return Certification:
Legal Requirements and Form Types:
Annual Return Form MGT-7 is the standard form that most companies must file, except for One Person
Companies (OPC) and Small Companies, which use Form MGT-7A starting from the financial year 2020-
2021.
Form MGT-8 is used for certification of the annual return of listed companies, or companies with
specific financial thresholds.
Certification Thresholds (MGT-8):
Certification by a practicing Company Secretary (PCS) is mandatory for:
o Every listed company
o Companies with a paid-up share capital of Rs. 10 crore or more
o Companies with an annual turnover of Rs. 50 crore or more
32
Certification Requirements (Key Points for Form MGT-8):
1. Accuracy and Adequacy of Annual Return Information
o The PCS certifies that the annual return discloses the correct and adequate facts as of the financial
year’s end.
2. Compliance with the Act & Rules:
o PCS verifies compliance across various provisions, including:
Company status and record maintenance
Timely filing of forms and returns with regulatory bodies
Meetings of the Board and members, ensuring proper notices, proceedings, and minutes
Closure of Register of Members
Loans/advances to directors or related parties, per Sections 185 and 188
Securities issuance, allotment, or alterations (e.g., transfer, buy-back, capital changes)
Dividend declarations and transfers to the Investor Education and Protection Fund (IEPF)
Signing of financial statements in compliance with Section 134
Appointments and disclosures regarding Directors and Key Managerial Personnel (KMP)
Auditor appointments and filling of casual vacancies under Section 139
Approvals obtained from authorities, such as Central Government or Courts, if required
Deposits and borrowing practices, charge creation/modification
Loans, guarantees, and investments per Section 186
Alterations in Memorandum or Articles of Association.
3. Verification Checklist for PCS Before Certification:
o PCS must examine:
Statutory registers (members, securities, charges)
Incorporation documents (Memorandum & Articles of Association)
Filed e-forms with MCA (Ministry of Corporate Affairs)
Latest financial statements
List of promoters and shareholding pattern
Minutes from board, committee, and general meetings, including resolutions, notices, and
agendas.
4. Reporting of Qualifications or Remarks:
o If any qualifications, reservations, or adverse remarks arise, the PCS must explicitly mention these in
the relevant sections of the certification to ensure transparency and accuracy.
Signing of the
Annual Return (Section 92(1) of Companies Act, 2013)
Under Section 92(1) of the Companies Act, 2013, the Annual Return must be signed by:
1. A Director and the Company Secretary.
2. If there is no Company Secretary, it must be signed by a Company Secretary in Practice.
Proviso to Section 92(1):
For One Person Companies (OPCs), Small Companies, and Private Companies (if such private company is
a start-up), the Annual Return should be signed by:
The Company Secretary, or if no Company Secretary is available, then by a Director.
Certification of Form MGT-7 (Annual Return)
33
When signing Form MGT-7, the company secretary or PCS, along with the director, certifies:
1. Accurate Disclosure: The facts stated in the return reflect the company’s position as of the financial
year-end.
2. Compliance: Unless otherwise specified, the company has complied with applicable provisions of the
Companies Act during the financial year.
Private Company Certification:
For a Private Company, the Company Secretary/Director also certifies:
The company has not issued any public invitations to subscribe for its securities since the last annual
return was filed or, in the case of the first return, since the company’s incorporation.
If the number of members exceeds 200 (excluding certain persons as per Section 68(2) of the Act), those
not included in the count are appropriately excluded.
Timing and Appointment of Practicing Company Secretary (PCS)
Given the comprehensive nature of verifying the annual return’s contents, it is advisable to appoint the PCS at
the beginning of the financial year. This ensures:
Accuracy: Information in the annual return aligns with financial statements and statutory registers.
Efficiency: The PCS can review and verify records periodically, aiding the preparation of the annual return
for the Board’s report before the annual general meeting.
Key Sections
of the Companies Act, 2013:
Section 92(1):
1. Pertains to the preparation and signing of the Annual Return.
2. If a company has a Company Secretary in employment, they must sign the Annual Return.
3. A Company Secretary in Practice (PCS) cannot sign under this section if the company employs a
full-time Company Secretary.
Good
Practice: Maker-Checker Concept
To maintain accuracy and ensure compliance, adopting the maker-checker mechanism is recommended:
Maker: The Company Secretary in employment prepares and signs the Annual Return under Section
92(1).
Checker: A Company Secretary in Practice or another independent professional verifies and certifies the
document under Section 92(2).
Implications
for Companies with a Full-Time CS
If a company employs a Company Secretary in employment, they must fulfill their responsibility under
Section 92(1) and cannot delegate this role to a PCS.
The PCS’s role is limited to certification under Section 92(2) (if applicable).
Time Limit
for Filing Annual Return
Section 92(4) of the Companies Act, 2013, prescribes the following timelines for filing the Annual Return
(Form MGT-7) with the Registrar of Companies (ROC):
1. Where AGM is held: The Annual Return must be filed within 60 days from the date of the Annual
General Meeting (AGM).
34
2. Where AGM is not held: The Annual Return must be filed within 60 days from the date on which the AGM
should have been held, along with a statement explaining the reasons for not holding the AGM.
Consequences of Non-Filing of Annual Return
1. Penalty for Default
A penalty of ₹10,000 will be imposed on the company and its defaulting officer(s).
In case of continuing failure, an additional penalty of ₹100 per day will apply, subject to a maximum of
₹2,00,000 for the company and ₹50,000 for the officer in default.
2. Director Disqualification
If the company fails to file its financial statements or Annual Return for a continuous period of three
financial years, the directors of such a company:
Become ineligible for re-appointment in the defaulting company.
Are disqualified from being appointed as a director in any other company for a period of 5 years.
Penalties and
Legal Consequences Related to Annual Returns and Misstatements
1. Penalty for Misstatement in Annual Return (Section 448)
False Statements: If a director or any person knowingly makes a false statement in the Annual Return, or
knowingly omits a material fact:
o Imprisonment: Minimum of 6 months, extendable up to 10 years.
o Fine: Not less than the amount involved in the fraud, up to 3 times the amount involved.
2. Class Action Suits (Section 245)
Rights of Shareholders or Depositors: Shareholders or depositors can file a class action suit with the
Tribunal if the company’s management or conduct is prejudicial to the company or their interests.
o Targets: Suits may be filed against the company, directors, officers, experts, or any other person
responsible for wrongful or fraudulent acts.
o Binding Orders: Orders from the Tribunal will be binding on the company and its officers.
3. Consequences for Non-Filing of Annual Return
Penalty (Section 92): If the company fails to file the Annual Return by the due date:
o Company: Penalty of ₹10,000; additional ₹100 per day of delay, up to ₹2,00,000.
o Officers in Default: Penalty of ₹10,000; additional ₹100 per day, up to ₹50,000.
Winding Up (Section 271): If a company defaults in filing Annual Returns for the preceding 5 financial
years, the Tribunal may order the company to be wound up.
Inactive Status (Section 455(1)): If a company has not filed the Annual Return for 2 consecutive
financial years, it will be classified as an inactive company.
Dormant Status (Section 455(4)): If the Annual Return is not filed for 2 consecutive financial years, the
Registrar may issue a notice and record the company as a dormant company in the Register of Dormant
Companies.
4. Compounding of Offences (Section 441)
Procedure: Offences under the Companies Act, 2013, which are compoundable, may follow the process
stipulated in Section 441 to avoid prolonged litigation or harsher penalties.
Consequence
s of Wrong Certification of Annual Return:
35
Under Section 92(6), if a Company Secretary in Practice certifies the Annual Return in violation of
the provisions:
o A penalty of ₹2,00,000 is imposed.
o The Company Secretary may also face disciplinary action under the Company Secretaries
Act, 1980.
Section 448 imposes penalties if any document (such as a return, report, certificate, etc.) contains
false statements or omits material facts.
The Company Secretary may also be subject to penalties under Section 447, 448, and 449 of the
Companies Act, 2013.
Authority to Initiate Action Against Professionals:
As per MCA Circular No. 10/2014, Regional Directors or Registrars of Companies can initiate action
under Sections 448 and 449 for false or misleading information submitted by professionals.
The case may also be referred to the Institute of Company Secretaries of India (ICSI) for disciplinary
proceedings.
The MCA may also debar the professional from filing documents on the MCA portal in the future.
Filing Annual
Return When AGM Is Not Held
1. Time Limit for Filing:
o As per Section 92(4):
If no Annual General Meeting (AGM) is held, the annual return must still be filed within 60
days from the date when the AGM should have been held.
A statement specifying the reasons for not holding the AGM must be attached.
2. Obligation Cannot Be Excused:
o Companies cannot avoid filing the return by claiming that the AGM was not held. The obligation
remains until the company is either wound up or its name is struck off by the Registrar.
3. Consequences of Late Filing:
o As per Section 403, the following applies:
Additional Fee: ₹100 per day for delay.
Higher Additional Fee: For repeated defaults, a higher fee may be imposed.
4. Penalties for Default:
o Both the company and its defaulting officers are liable to:
Payment of prescribed fees and additional fees.
Penalties or punishment as provided under the Act.
Detailed
Scrutiny of Annual Return by PCS
When certifying an annual return, a Practicing Company Secretary (PCS) must ensure due diligence and
caution, as they are legally bound by their certification. Here’s an overview of the scrutiny process and guiding
principles:
Extent of Verification Required
1. Auditing Principle:
Similar to financial auditing, where an auditor uses sampling and does not vouch for every transaction, a
PCS is not expected to verify each shareholder folio or every share transfer individually.
36
2. Practical Constraints:
o Large registrars of members with lakhs of entries.
o Thousands of share transfers or transactions annually.
3. Sampling and Test Checks:
To ensure compliance with timelines, the PCS adopts techniques of sampling and test checks to form a
reasonable opinion that the document represents the company’s true state of affairs.
Key
Principles for Detailed Scrutiny by PCS (IRM)
1. Internal Controls: The PCS shall perform a detailed review of the company's internal controls, systems and
procedures. Effective internal controls reduce the need for extensive checking.
2. Risk Assessment: The PCS shall have a good understanding of the company's industry, governance
practices, and perform risk assessment to identify high-risk areas. High-risk areas, such as shares with
statutory transfer restrictions, require more thorough examination.
3. Materiality: The principle of materiality is crucial, sample chosen for detailed checking should be
representative of the whole data.
Certification
with Reservations/Qualifications/Observations
1. Certification with Reservations: A PCS can certify the Annual Return with reservations or qualifications
if there are material inaccuracies or if the company has not complied with relevant provisions of the
Companies Act, 2013.
2. Observations and Adverse Remarks: If the Annual Return does not present accurate or complete
material facts, or if the company has failed to comply with the applicable legal provisions, the PCS can
provide observations or adverse remarks.
3. ICSI Guidance: The certification of the Annual Return must align with the guidance note provided by the
Institute of Company Secretaries of India (ICSI), and professional judgment must be exercised when
needed.
4. Professional Responsibility: The certifying PCS is responsible for ensuring the Annual Return is
certified with true and fair representation. If necessary, disclaimers or qualifications should be included,
and relevant documents should be reviewed before certification.
Corporate
Governance Certification by Practicing Company Secretary (PCS)
1. SEBI (LODR) Regulations: The certificate is issued under the following regulations:
o Regulations 17 to 27 and clauses (b) to (i) of Regulation 46(2).
o Paragraphs C and D of Schedule V.
2. Annual Compliance Report: Listed entities must submit a quarterly compliance report on corporate
governance to the stock exchange, along with an annual compliance report, within specific timelines:
o Quarterly Report: Must be submitted within 21 days of the quarter's end.
o Half-Yearly Report: Must be submitted six months after the financial year's end.
o Annual Report: Must cover the entire financial year.
o Additional Disclosure: Disclosures on loans, guarantees, comfort letters, or security provided to
promoters or related entities are required, effective from FY 2021-22.
Exemptions
from Corporate Governance Compliance:
37
Certain entities are exempted from adhering to the corporate governance provisions:
1. Entities with:
o Paid-up equity share capital not exceeding ₹10 crore.
o Net worth not exceeding ₹25 crore as of the last day of the previous financial year.
2. Entities listed on the SME Exchange.
Key Points
for PCS in Issuing Corporate Governance Compliance Certificate (CGCC):
1. Communication with Previous Incumbent:
o When a PCS is appointed for the first time to certify corporate governance compliance for a company,
they are required to notify the previous PCS (if any) about their appointment. This communication
should be done through registered post to ensure that the prior incumbent is informed.
2. Access to Company Records:
o The company must provide the PCS with access to all relevant records, such as registers, books of
accounts, papers, documents, reports, and any other necessary information kept by the company.
3. Annual Report Period:
o The CGCC issued by the PCS must pertain to the financial year of the listed company for which the
report is being prepared.
4. Availability for Clarifications:
o The PCS who issues the CGCC should be available at the Annual General Meeting (AGM) of the
company to provide clarifications, if required, regarding the certificate issued.
5. Liability for Negligence:
o If a PCS fails or commits any error while issuing the CGCC, they may face disciplinary actions under
the Company Secretaries Act, 1980. Moreover, the PCS may be held liable for any injury or damage
caused to any person due to negligence in issuing the certificate.
Mode of
Issuing the Corporate Governance Compliance Certificate (CGCC):
1. Obtain Draft Report from the Company:
o The PCS first needs to obtain the draft report on corporate governance from the listed entity.
2. Examine Relevant Records:
o The PCS should examine the relevant records related to corporate governance. This includes checking
the company’s internal procedures, compliance reports, minutes of meetings, and other corporate
governance-related documents.
3. Certify Compliance and Submit Report:
o Based on the examination of records and the information provided by the management, the PCS
certifies that the company has complied with the corporate governance conditions. This certification is
then annexed to the Board’s Report and submitted to the Board of Directors for inclusion in the
company’s Annual Report.
4. Voluntary Guidelines Compliance (if applicable):
38
o If the company has adopted Voluntary Guidelines for corporate governance, the PCS is also required
to certify compliance with these guidelines.
Types of
Corporate Governance Compliance Certification (CGCC)
1. Unqualified Certificate:
o Definition: Issued when the PCS is of the opinion that the company has fully complied with the
corporate governance conditions as required.
o Implication: No non-compliance or inadequacy is found.
2. Qualified Certificate:
o Definition: Issued when the PCS identifies certain specific non-compliances or inadequacies in the
company's adherence to corporate governance standards.
o Content: The certificate must include:
A description of the non-compliance or inadequacies.
The extent of non-compliance.
The qualifications should be highlighted in bold or italics.
3. Inability to Form Opinion:
o Definition: If the PCS is unable to form an opinion on any specific matter, this must be clearly stated in
the certificate, along with the reasons for being unable to form an opinion.
4. Limitations in Scope of Work:
o Definition: If the scope of the work is limited due to factors like access to certain records or
documents being restricted (e.g., with another party or government authority), the certificate must
mention such limitations.
o Material Limitations: If the limitations are so significant that the PCS cannot express an opinion, the
certificate should state:
“In the absence of necessary information and records, the PCS is unable to certify compliance or
non-compliance with the conditions of Corporate Governance by the company.”
Penalties for
False Corporate Governance Compliance Certificate
Professional Misconduct: If the PCS fails to adhere to the code of conduct issued by the Institute of
Company Secretaries of India, they could face professional misconduct charges.
Companies Act - Section 448:
o False Statements: If a person knowingly makes a false statement or omits a material fact in any
document required under the Act, they can be punished under Section 447 for fraud.
Penalties Under Section 449:
o Punishment for False Evidence: If a person gives false evidence (whether on oath or in any
affidavit, deposition, etc.), they could face imprisonment for 3 to 7 years and a fine of up to ₹10
lakhs.
Securities Contracts (Regulation) Act, 1956 (SCRA):
o Section 23H: Failure to comply with the provisions of the SCRA or regulations of stock exchanges
can lead to a penalty up to ₹1 crore.
39
o Section 23M: Contravening or attempting to contravene the provisions of SCRA may lead to:
Imprisonment up to 10 years or a fine up to ₹25 crore or both.
Failure to pay the penalty or comply with directions may also result in imprisonment of 1
month to 10 years and a fine up to ₹25 crore.
Corporate
Governance Principles under Listing Regulations
1. The Rights of Shareholders
The listed entity should protect and facilitate the exercise of the following rights of shareholders:
Right to Participate in Corporate Decisions
Right to Ask Questions in BM and GM
Participation in key CG issues
Exercise of Ownership Rights
Transparency and Information regarding voting procedures
Voting in General Meetings
Grievance Redressal
Protection of Minority Shareholders.
2. Timely Information
The listed entity must provide adequate and timely information to shareholders, including the following:
Meeting Information: Date, location, and agenda of general meetings, as well as detailed information
regarding the issues to be discussed.
Capital Structure: To obtain a degree of control disproportionate to their equity ownership should be
disclosed.
Rights Attached to Shares: The rights attached to various classes and series of shares must be disclosed
to shareholders before they acquire the shares.
3. Equitable Treatment of Shareholders
The listed entity must ensure the equitable treatment of all shareholders, including minority and foreign
shareholders:
Equal Treatment of Shareholders
Facilitation of Shareholder Participation in CG issues.
Voting by Foreign Shareholders
Prevention of Insider Trading and Self-dealing
Equitable Procedures for General Meetings to participate and vote.
Ease of Voting
4. Role of Stakeholders in Corporate Governance
The listed entity must recognize the rights of its stakeholders (such as employees, suppliers, customers, and
other parties with an interest in the company’s success) and encourage cooperation between itself and these
stakeholders. Key points include:
Respect for Stakeholder Rights established by law or through mutual agreements with stakeholders.
Redress for Violation of Rights
Access to reliable, sufficient, and timely information to enable their active participation in corporate
governance processes.
Vigil Mechanism/Whistleblower Policy.
5. Disclosure and Transparency
40
The listed entity should prioritize transparency and accuracy in disclosing material information, ensuring
that stakeholders and the public are well-informed about the company's status and activities. Key provisions
include:
Accurate and Timely Disclosure related to its financial situation, performance, ownership, and governance
in a timely and accurate manner.
Information Dissemination in a manner that provides equal access to all stakeholders on a timely and cost-
efficient basis.
Minutes of Meetings maintained with explicit records of dissenting opinions.
6. Responsibilities of the Board of Directors
The board of directors plays a critical role in ensuring the company's corporate governance framework
functions effectively. The key responsibilities of the board include:
(i) Disclosure of Information
Material Interest Disclosure
Operational Transparency while maintaining the confidentiality of sensitive information to support good
decision-making.
(ii) Key Functions of the Board of Directors
1. Strategic Oversight:
o Review and guide the corporate strategy, major plans of action, risk policies, annual business
plans, and performance objectives.
o Monitor the implementation of these plans and strategies to ensure the company achieves its
targets.
2. Governance Practices:
o Monitor the effectiveness of the company’s governance practices and make necessary
adjustments to improve performance and align with stakeholders' interests.
3. Personnel Management:
o Select, compensate, and monitor the performance of key managerial personnel.
o When necessary, replace underperforming personnel and oversee succession planning to ensure
the company is equipped with the right leadership.
4. Aligning Interests:
o Ensure that the compensation and incentives for the board of directors and key managerial
personnel are aligned with the long-term interests of the company and its shareholders.
5. Ensuring a Transparent Nomination Process:
The board should ensure that the nomination process for new directors is transparent and that the
board is diverse in terms of thought, experience, knowledge, perspective, and gender. This diversity
enhances the board’s ability to make well-rounded decisions.
6. Managing Potential Conflicts of Interest:
The board must monitor and manage potential conflicts of interest involving management, directors,
and shareholders. This includes addressing:
o Misuse of corporate assets.
o Abuse of related party transactions. By identifying and managing these conflicts, the board helps
maintain ethical practices.
7. Ensuring Integrity of Financial Reporting:
The board is responsible for ensuring that the accounting and financial reporting systems are reliable
and that an independent audit is conducted. Key areas include:
o Ensuring the integrity of financial information.
41
o Implementing appropriate risk management systems.
o Establishing financial and operational controls.
o Ensuring compliance with laws and standards.
8. Overseeing the Process of Disclosure and Communications:
The board must ensure that the company follows proper processes for disclosure and communication.
This ensures that shareholders and stakeholders receive timely, accurate, and relevant information.
9. Monitoring Board Evaluation Framework:
The board should regularly monitor and review the board evaluation framework, which includes
assessing the board’s effectiveness and improving governance processes.
(iii) Other Responsibilities of the Board
1. Providing Strategic Guidance:
The board is responsible for providing strategic guidance to the company, ensuring that management is
effectively monitored and held accountable to both the company and its shareholders.
2. Setting Corporate Culture and Values:
The board should set the corporate culture and values that will guide the behavior of executives
throughout the organization. These values shape the company’s approach to ethics, risk, and stakeholder
relationships.
3. Acting on Fully Informed Basis:
Board members must act with due diligence, good faith, and care. They are required to make decisions
in the best interest of the company and its shareholders, always being well-informed.
4. Encouraging Continuing Training:
The board should ensure that members undergo continuing training to stay up-to-date with governance
best practices, legal requirements, and industry trends.
5. Fair Treatment of All Shareholders:
In cases where decisions may affect different shareholder groups differently, the board must ensure that
all shareholders are treated fairly, promoting equity and transparency.
6. Maintaining High Ethical Standards:
The board must uphold high ethical standards, considering not only shareholders’ interests but also the
interests of all stakeholders (e.g., employees, customers, suppliers, and the broader community).
7. Exercising Independent Judgement:
Board members must exercise objective independent judgment when making decisions on corporate
affairs, ensuring that their actions are aligned with the company's long-term goals.
8. Assigning Independent Directors to Conflicted Areas:
The board should assign a sufficient number of non-executive and independent directors to areas
where there is a potential for conflict of interest, ensuring unbiased decision-making.
9. Ensuring Realistic Risk Management:
While encouraging positive thinking, the board should ensure that over-optimism does not blind them
to significant risks or expose the company to excessive risk.
10. Challenging Executive Management:
The board should have the ability to step back and challenge the underlying assumptions of strategies
and major decisions, such as acquisitions or changes in the company’s risk appetite.
11. Defining Committees’ Mandates and Procedures:
When committees are established, the board must define their mandates, composition, and working
procedures and ensure these are disclosed for transparency.
12. Commitment to Responsibilities:
Board members must be able to commit effectively to their roles and responsibilities, ensuring they are
engaged and active in decision-making processes.
42
13. Access to Timely and Relevant Information:
To fulfill their duties, board members must have access to accurate, relevant, and timely information,
ensuring that they can make well-informed decisions.
14. Facilitating Independent Directors’ Role:
The board and senior management should facilitate the role of independent directors, ensuring that they
are able to perform their duties effectively both as board members and committee members.
Signing of
Financial Statements
As per the Companies Act, 2013, the financial statements of a company must be prepared according to
Section 129 and Schedule III of the Act. These statements must then be laid before the shareholders at the
Annual General Meeting (AGM). The key aspects of signing and approval are outlined as follows:
Definition of Financial Statements (Section 2(40))
The term "financial statement" for a company includes the following documents:
1. Balance Sheet as at the end of the financial year.
2. Profit and Loss Account (or Income and Expenditure Account in the case of a not-for-profit
organization).
3. Cash Flow Statement for the financial year.
4. Statement of Changes in Equity, if applicable.
5. Explanatory Notes annexed to or forming part of any document referred to above.
Approval and Signing Requirements (Section 134(1))
1. Approval by the Board of Directors:
The financial statements, including consolidated financial statements (if applicable), must first be
approved by the Board of Directors before they are signed.
2. Signatories to the Financial Statements:
The financial statements must be signed by the following persons:
o Chairperson of the Company (if authorized by the Board), OR
o Two Directors, one of which must be the Managing Director (if appointed).
o Chief Executive Officer (CEO), Company Secretary (CS), or Chief Financial Officer (CFO) of the
company (depending on their appointment).
Additional Requirements and Clarifications
1. Mandatory Signing by Company Secretary:
If the company has a Whole-time Company Secretary, then it is mandatory for the Whole-time
Company Secretary to sign the financial statement.
2. Role of CEO and CFO:
If the company has a Chief Executive Officer (CEO) or Chief Financial Officer (CFO), they are also
required to sign the financial statement.
3. In the Absence of CFO and CS:
If the company does not have a CFO or CS, the Chairperson of the company may sign the financial
statements. If the Chairperson is absent or not authorized, then the two directors, including the
Managing Director, should sign. The CFO, if a director, may also sign.
43
4. One Person Company (OPC):
In the case of a One Person Company (OPC), the financial statement must be signed by only one
director (since there is only one director in such companies).
Auditor's
Report
Once the financial statements are signed, they are submitted to the auditor. The auditor then prepares an
Auditor's Report, which is attached to the financial statements before they are presented to the shareholders.
Adoption in Annual General Meeting (AGM)
The Financial Statements, including consolidated financial statements (if any), must be adopted at
the company’s Annual General Meeting (AGM).
The AGM must be held within 6 months from the end of the financial year, i.e., by September 30 for
companies following an April-to-March financial year.
Circulation of Signed Financial Statements (Section 134(7))
Once signed, the financial statements must be circulated along with the following documents:
1. Auditor’s Report, which provides the auditor’s opinion on the financial statements.
2. Board’s Report, which includes a summary of the company’s performance and key decisions taken by the
board.
3. Notes or Annexures to the financial statements.
Penal Provisions for Non-Compliance (Section 134)
1. The company will face a penalty of ₹3,00,000.
2. Every officer in default will face a penalty of ₹50,000.
Case Law: In
Re HIFFCO Farming Ltd. vs. Registrar of Companies
Key Facts:
The appellant company failed to file its financial statements with the Registrar of Companies (RoC)
since 2006-07.
The company’s name was subsequently struck off from the Register of Companies.
Ruling by NCLAT (National Company Law Appellate Tribunal):
It was observed that the company was still operational and had the right to seek restoration of its name
in the Register of Companies.
The NCLAT directed restoration, subject to the condition that the company files all pending statutory
documents along with applicable late fees.
Key Takeaway:
Non-filing of financial statements can lead to severe consequences like removal from the Register of
Companies, but companies have the right to seek restoration by rectifying their non-compliance.
Professional
Misconduct under the Company Secretaries Act, 1980
Misconduct as Defined in the Second Schedule
Improper Certification
1. A CS will be guilty of professional misconduct if they certify or submit reports on matters not examined
personally by them or a qualified partner/employee.
44
2. A CS will also be guilty of misconduct if they fail to disclose a material fact or report a material
misstatement, or are grossly negligent in their duties.
Disciplinary Actions under Section 21B(3)
If found guilty of professional or other misconduct as per the Second Schedule, a PCS may face:
Reprimand: Formal expression of disapproval.
Removal of Name: From the register of members, either permanently or for a specified period.
Fines: Up to ₹5,00,000.
Actions by
Regulator for Certification Issues under the Companies Act, 2013
1. Deactivation of Digital Signature Certificate:
Rule 8(10) of the Companies (Registration Offices and Fees) Rules, 2014 states that if a person
certifies a form, document, or return containing false, misleading information, or omits material facts,
their Digital Signature Certificate (DSC) may be deactivated by the Central Government until a final
decision is made.
2. Inquiry by Regional Director or Registrar:
If false or misleading information is found in any filed document or return, the Regional Director or
Registrar will initiate an inquiry.
A 15-day notice is given to the professionals who certified the form, the signatories, and any officers
responsible for the false submission.
The Regional Director or Registrar will submit a report within 15 days to the E-Governance Cell of the
Ministry of Corporate Affairs (MCA), with recommendations for action under sections 447 and 448 of the
Companies Act, 2013.
The E-Governance Cell will process the case, initiate action under sections 448 and 449, and refer the
matter to the concerned professional institute (e.g., ICSI) for disciplinary proceedings.
3. Reporting Mechanism:
The Registrar will provide a fortnightly report (Every two weeks) to the Regional Director and E-
Governance Division.
The Regional Director will submit a monthly consolidated report to the Joint Secretary of the E-
Governance Division.
Lesson: 6 (Non-Compliances, Penalties and Adjudications)
45
Key Differences Between Civil and Criminal Law in the Corporate Context
Particulars Civil Law Criminal Law
Nature of Dispute Deals with private disputes or defaults. Addresses offences against society or
public policy.
Objective Aims to resolve disputes or redress To punish the offender and is
damages caused to one party due to reflection of the public policy of a
another's actions or omissions. country
Fine/ Imprisonment Court orders compensation for Court can impose fines,
damages or losses to the aggrieved imprisonment, or both to penalize
party. the guilty.
Indicators in the Act "Liable to penalties" suggests a civil "Punishable with fine and/or
violation, requiring payment for imprisonment" indicates a criminal
damages. offence.
Difference Between Fine and Penalty
Aspect Fine Penalty
Definition A monetary punishment for a crime or A punishment for breaching a law,
offense. rule, or contract.
Applicability Imposed for criminal offenses. Imposed for civil offenses.
Authority to Impose Can only be imposed by a court of law. May be imposed by an administrative
authority.
Purpose A punitive measure to penalize A compensatory measure or for
wrongdoing. breach of obligations.
🧾 Non-
Compliances Under Companies Act
Each section of the Act specifies:
o Documents to be maintained
o Procedures to be followed
o Filing requirements and timelines
⚠️Key Rule:
Delayed compliance ≠ no violation
Company is liable for penalty for the entire period of non-compliance even if later corrected.
✅ Remedy Options:
File a suo-moto compounding application
Or face regulatory action by authorities.
Nature of
Offences Under Section 439
🧑⚖️Section 439 – Cognizance of Offences
1. Court Cognizance
o No court shall take cognizance of offences by a company/officer unless complaint is made in
writing by:
Registrar, OR
Shareholder/member, OR
Person authorized by Central Government
✅ Exception: For offences related to:
o Issue and transfer of securities
46
o Non-payment of dividend
➤ Complaint can also be made by person authorized by SEBI
✅ Further Exception: A company can itself prosecute its officers.
2. Personal Appearance Not Mandatory
o If complaint is filed by Registrar or Govt. authorized person, their court appearance not needed
unless court requires it.
3. Liquidator's Actions – Exclusion
o Section 439 doesn’t apply to offences under Chapter XX (Winding Up) or related provisions.
o Liquidator is not treated as an officer for this purpose.
🔔 Special Notification (5th June, 2015) – For Government Companies
In Section 439(1), the words “Registrar, a shareholder, or” are omitted – so Govt can file directly.
🚓 Section 212(6) – Cognizable & Non-Bailable Offences (Fraud Cases)
Cognizable Offence: Police can arrest without warrant (as per CrPC Section 2(c)).
🛑 Under Section 212(6) – Fraud-related offences under Section 447 are:
Cognizable and Non-Bailable
🔐 Bail Restrictions:
Bail is not allowed unless:
1. Public Prosecutor gets a chance to oppose
2. If opposed, court must be satisfied that:
Accused is not guilty
Accused is not likely to reoffend
✅ Special Consideration:
Court may grant bail to:
Women
Sick/Infirm persons
Children below 16 years
📌 Complaint must be filed by:
Director, Serious Fraud Investigation Office (SFIO) OR
Authorized Central Govt. Officer.
📎 Section 450 – Default Where No Specific Penalty Is Mentioned
If any provision is silent on penalty → Section 450 applies:
Category Amount
Initial Penalty ₹10,000
Continuing Default ₹1,000/day after first day
Max Cap – Company ₹2,00,000
Max Cap – Officer/Other Person ₹50,000
🧾 Classification of Offences (Punishment-wise)
47
Type Punishment
Fraud-related (Section 447) Punished under Section 447 (strict penalties)
Other Offences Fine/imprisonment as per specific section
⚖️Compoundable vs. Non-Compoundable Offences
Offence Type Nature
Non-Compoundable Punishable with imprisonment only, or imprisonment + fine (Section 441(6))
Compoundable Punishable with:
(a) Fine only,
(b) Fine or imprisonment,
(c) Fine or imprisonment or both
Consequence
s of Default and Non-Compliance of the Act:
Despite reduced penal provisions, certain non-compliances continue to attract additional restrictions or
liabilities, including:
1. Withdrawal of benefits for private companies.
2. Ineligibility for Buy-Back of equity shares or specified securities.
3. Disqualification of Directors:
4. Company being classified as inactive company.
Section 447 -
Punishment for Fraud (Companies Act, 2013)
1. Fraud:
o Definition: Fraud includes any act, omission, concealment of facts, or abuse of position, committed
intentionally to deceive, gain undue advantage, or injure the interests of the company, its shareholders,
creditors, or any other person.
o Scope: Fraud can occur with or without wrongful gain or wrongful loss.
Type of Fraud Criteria Punishment
Minor Fraud < ₹10 Lakhs or < 1% of turnover, Imprisonment: Up to 5 years.
whichever is Lower Fine: Up to ₹50 Lakh.
No public interest involved Or both imprisonment and fine.
Significant Fraud ≥ ₹10 Lakhs or ≥ 1% of turnover Imprisonment: 6 months to 10 years.
whichever is Lower Fine: At least the amount involved in fraud, up
to 3 times the amount involved.
Fraud with Public Any amount, public interest involved - Minimum imprisonment: 3 years.
Interest
Section 448:
Punishment for False Statement
This section deals with making false statements in any return, report, certificate, financial statement,
prospectus, statement or other documents required under the Companies Act.
o Clause (a): A false statement made with knowledge that it is false.
o Clause (b): Omitting material facts, knowing them to be material.
A person making such false statements is liable for punishment under Section 447 (punishment for fraud),
which can include penalties and imprisonment.
48
Section 449:
Punishment for False Evidence
If any person intentionally gives false evidence on oath or in affidavits/depositions related to company
matters is punishable.
Punishment:
Imprisonment: Minimum of 3 years, extendable to 7 years and
Fine: Up to ₹10 lakhs.
Section 450:
Punishment Where No Specific Penalty or Punishment is Provided
Applies to contraventions under the Act for which no penalty or punishment is explicitly prescribed.
Penalty:
For the Company and Officers in Default:
o One-time penalty: ₹10,000.
o For continuing contravention: ₹1,000 per day after the first day of the violation.
Maximum penalty: ₹2 lakhs for the company.
Maximum penalty: ₹50,000 for officers in default or any other person.
Section 451:
Punishment for Repeated Defaults
Provision: If a company or officer repeats an offence within 3 years, the fine is double the fine imposed for
the initial contravention, along with any applicable imprisonment.
Section 452:
Punishment for Wrongful Withholding of Property
This section deals with the wrongful possession, withholding, or misuse of a company's property (including
cash) by its officers or employees.
1. Punishment:
o Fine: ₹1,00,000 to ₹5,00,000.
o Court Order: The court may direct the individual to:
Return/refund the wrongfully obtained or withheld property.
Deliver any benefits derived from it.
o Imprisonment: May extend to 2 years.
2. Exception for Imprisonment:
Imprisonment will not apply if the company owes the officer/employee:
o Payments related to provident fund, pension fund, gratuity, or other welfare funds.
o Compensation for injury or death under the Workmen’s Compensation Act, 1923.
Section 453:
Punishment for Improper Use of “Limited” or “Private Limited”
1. Offence:
o Using "Limited," "Private Limited," or any contraction/variation of these words as part of a business
name without proper incorporation as a company with limited liability.
2. Punishment:
49
o Fine: ₹500 to ₹2,000 every day for which that name or title has been used.
Establishmen
t of Special Courts under the Companies Act, 2013
The Companies Act, 2013 introduced provisions for Special Courts to ensure the speedy trial of offences
related to the Act.
Objective:
To provide a speedy trial of offences under the Companies Act, ensuring faster prosecution of defaulting
companies and their officers.
To reduce the burden on regular courts by designating specific courts for company law offences.
The Central Government may establish or designate Special Courts for offences under the Companies Act
(excluding Section 452).
Structure of
Special Courts:
Special Courts are designed to handle cases based on the severity of offences:
Offence Type Judge Appointed Authority
Imprisonment ≥ 2 Session Judge / Additional Session Judge Appointed by CG with concurrence
years of CJ of HC
Other offences Metropolitan Magistrate / Judicial Magistrate Same as above
of First Class
Offences
Triable by Special Courts (Section 436)
Jurisdiction
Only Special Courts have jurisdiction over offences under Section 435(1).
Territorial jurisdiction based on registered office location.
Detention Authority: Judicial Magistrate (15 days max); Executive Magistrate (7 days max).
Special Courts:
o May take direct cognizance of offences.
o Can try connected offences under other laws in the same trial.
o May conduct summary trials for offences with imprisonment ≤ 3 years, but can switch to regular
trial if sentence may exceed 1 year.
Summary Trial by Special Courts
Allowed: If offence punishable ≤ 3 years imprisonment.
Limit: Max 1-year imprisonment in summary trial.
Switch to Regular Trial: If nature of offence demands a higher sentence or better scrutiny.
Application of BNSS – Section 438
BNSS provisions apply to Special Courts.
Special Court is deemed as:
o Sessions Court (for serious offences), or
o Magistrate Court (for lesser offences).
Prosecutors before Special Courts are deemed Public Prosecutors.
Case Laws
a. S. Satyanarayana v. Energo Masch Power Engineering & Consulting (SC)
Even if some accused are not covered under Companies Act, Special Court can try all offences if from the
same transaction — to avoid multiplicity.
50
Adjudication Process under the Companies Act, 2013
Adjudication is the process where a competent authority (judge, arbiter, or adjudicating officer) examines
facts, evidence, and arguments to resolve a dispute and decide the rights and obligations of the involved
parties.
1. Step I: Issue of Show Cause Notice
o The AO issues a show cause notice (SCN) to the company/officer/person in default.
o Time for reply: 15 to 30 days from service (extendable by maximum 15 days with valid reasons).
o The notice must:
State the nature of default.
Highlight relevant legal provisions.
Indicate possible penalties.
✦ Reply must be submitted electronically.
2. Step II: Enquiry by Adjudicating Officer (Notice for Hearing)
o If AO finds physical appearance necessary, he issues a hearing notice within 10 working days of
receiving the reply.
o If the person requests oral representation in their reply, AO must allow it.
o Appearance can be by the person or their authorised representative.
3. Step III: Date of Hearing
o On the hearing date, the adjudicating officer will give the person a reasonable opportunity to be
heard. AO may:
Pass an order.
Adjourn the matter.
Ask for a written reply on other issues for better clarity.
4. Step IV: Order of Adjudicating Officer
o The officer must pass an order:
Within 30 days if no physical appearance is required,
Within 90 days if appearance is made.
o If the order is delayed, the officer must record reasons for the delay.
o A copy is sent to the concerned parties and the Central Government, and it is also uploaded on
the website.
Appeals Against Adjudicating Officer’s Order
Authority: Appeals can be filed with the Regional Director (RD) having jurisdiction.
Timeline: Within 60 days of receiving the AO's order.
MCA
Compliance Monitoring System (MCACMS Portal)
The MCACMS Portal is an AI-driven initiative under MCA 21 by the Ministry of Corporate Affairs, designed
to simplify the compliance process and enforce compliance with the Companies Act, 2013.
Key Features:
Sends Show Cause Notices (SCN) electronically for non-compliance.
51
Allows companies/directors to reply online.
Based on replies, ROC may initiate penal action.
Steps to Reply to SCN on MCACMS Portal:
1. Visit MCA CMS portal.
2. Click “Reply for Show Cause Notice” tab.
3. Select the relevant section under which SCN was issued.
4. Enter the CMS Reference Number mentioned on the SCN and click Search.
5. Click “Send OTP” (OTP sent to registered email).
6. After verification, click “Submit Reply” (Note: Cannot edit after submission).
7. System will show confirmation and update reply status.
Powers and
Penalties of the Adjudicating Officer under the Companies Act, 2013
Powers of the Adjudicating Officer
1. Summon and enforce any person for inquiry after giving written reasons.
2. Order for evidence/documents if deemed relevant.
Penalties Imposed by the Adjudicating Officer
1. Imposition of Penalty:
o Penalty may be imposed on the company, officer in default, or other persons for non-compliance or
defaults under the Act.
o The officer may direct rectification of the default, if deemed necessary.
2. Failure to Respond or Appear:
o If a person neglects or refuses to respond or appear, the officer can impose penalties in their
absence after recording reasons.
3. Quantum of Penalty:
o Factors considered when determining the penalty:
Size of the company.
Nature of business.
Public interest harm.
Nature and repetition of default.
Disproportionate gains or unfair advantage.
Loss caused to investors or creditors.
o Penalties cannot be less than the minimum prescribed under the Act.
4. Fixed Penalty:
o For provisions with a fixed penalty, the specified amount must be imposed.
5. Payment of Penalty:
o Penalties are payable only through the MCA portal, and all collected sums are credited to the
Consolidated Fund of India.
Exemption
from Penalty:
o No penalty if non-compliance under Section 92(4) (Annual Return) or Sections 137(1)/(2)
(Financial Statement) is rectified before or within 30 days of notice issuance.
o Proceedings are deemed concluded for such cases.
Opportunity of Being Heard
52
Reasonable opportunity must be given to the company/officer/person before imposing penalty.
Appeals
Against AO's Order
Authority: Appeals can be filed with the Regional Director (RD).
Timeline: Within 60 days of the order's receipt.
Procedure:
1. File in Form ADJ, stating grounds for appeal, with a certified copy of the AO's order.
2. Attach authorization and written consent if represented by an authorized representative.
3. One appeal for one order only (unless reliefs are linked).
Registration
of Appeal
1. Endorsement and Scrutiny:
o Upon receiving an appeal, the office of the Regional Director (RD) will endorse the date on the
appeal and sign it.
2. Registration:
o If the appeal is in order, it is registered and assigned a serial number.
3. Handling Defective Appeals:
o Rectification of Defects: The RD may grant at least 14 days for the appellant to correct defects
upon intimation.
o Failure to Rectify:
If defects are not corrected within the given time, the RD may refuse to register the appeal,
providing reasons in writing and informing the appellant within 7 days.
4. Extension for Rectification:
o The RD can extend the rectification period by another 14 days, provided the appellant shows
sufficient cause for the delay.
Disposal of
Appeal by Regional Director
1. Copy of Notice to Adjudicating Officer
Upon admission of the appeal, the Regional Director (RD) must serve a copy of the appeal to the
adjudicating officer, along with a notice.
The adjudicating officer is required to file a reply to the appeal within 21 days.
The RD may extend this period by another 21 days if the adjudicating officer provides valid reasons.
2. Reply of Adjudicating Officer
A copy of the reply filed by the adjudicating officer must be served to the appellant.
3. Intimation of Date of Hearing
The RD shall notify both parties of the hearing date, which must be at least 30 days from the notification
date.
4. Hearing by Regional Director
On the hearing date, the RD may pass any order, including an order for adjournment, with reasons
recorded in writing.
Ex-parte Hearing: If either party (appellant or adjudicating officer) does not appear, the RD may proceed
with an ex-parte decision.
5. Setting Aside Ex-Parte Order
If the appellant appears after missing the hearing and proves sufficient cause for non-appearance, the RD
may set aside the ex-parte order and restore the appeal.
6. Order by Regional Director
After hearing both parties, the RD may:
53
o Confirm, modify, or set aside the original order.
The order must be signed and dated by the RD.
7. Communication of the Order
A certified copy of the RD's order must be communicated to:
o The adjudicating officer
o The appellant
o The Central Government.
❗ Penalty for Non-Compliance with RD's Order
Company: ₹25,000 – ₹5,00,000 fine.
Officer in default: ₹25,000 – ₹1,00,000 fine or up to 6 months imprisonment or both.
🔹 SEBI’s Power to Impose Penalties
Under Section 11B of the SEBI Act, 1992, SEBI has the authority to levy penalties after an adjudication
process if it finds any contravention of law.
Penalties are levied under Chapter VIA of the SEBI Act.
The adjudication is not just a fact-finding exercise but involves evaluating:
o The gravity of the offense
o Imposing a proportionate penalty
However, SEBI has often imposed flat-rate penalties in a mechanical or automatic manner.
🔹 Securities Appellate Tribunal (SAT)
SAT is a statutory body under Section 15K of the SEBI Act.
It hears appeals against:
o Orders passed by SEBI
o Orders passed by an Adjudicating Officer
SAT exercises powers under the SEBI Act and other applicable laws.
🔹 SEBI Enforcement Department – Divisions and Functions
1. SAT Litigation Division
o Handles appeals filed before SAT
o Works with Senior Advocates, law firms, and represents SEBI in complex legal matters
o Assists SEBI in drafting affidavits, submissions, and attending hearings.
2. Prosecution Division
o Responsible for filing criminal complaints in courts
o Coordinates with public prosecutors and other government agencies
o Follows up on cases to secure convictions.
3. Settlement Division
o Deals with Settlement Applications under SEBI (Settlement of Administrative and Civil
Proceedings) Regulations, 2014
o Tasks include:
Registration of application
Calculating settlement amount
Organizing Internal Committee Meetings and HPAC Meetings
Getting approval from Whole-Time Members
o If settlement is successful, Settlement Orders are passed.
54
🔹 Other Jurisdictions of SAT
As per Government Notifications, SAT also hears appeals against:
o PFRDA under the PFRDA Act, 2013
o IRDAI under:
Insurance Act, 1938
General Insurance Business (Nationalization) Act, 1972
IRDA Act, 1999
🔹 Shareholder's Right – Injunction Against Ultra Vires Acts
🧑⚖️Case: Bharat Insurance Co. Ltd. v. Kanhya Lal (AIR 1935 Lah 792)
Facts: Shareholder sued the company for making investments without adequate security, violating
company’s MOA.
Court held:
o Matters of internal management – not usually interfered by court.
o But ultra vires acts (beyond company’s powers) can be challenged by even one shareholder.
o Application of funds contrary to MOA is not internal management.
o Hence, injunction granted.
🎯 Application to Arun’s Case:
Arun holds 2% voting rights in M/s BEL Ltd.
Complained proposed investments lacked security and were beyond powers of company. ✅ He can
succeed by relying on the above case since directors' act is ultra vires.
SEBI's Power to Issue Directions – Section 11B
SEBI can issue directions if satisfied (after enquiry) that it is necessary:
1. In the interest of investors or orderly development of the securities market.
2. To prevent affairs of intermediaries/persons being conducted detrimental to investor or market
interest.
3. To ensure proper management of intermediaries or other associated persons.
SEBI may issue directions:
o To any person/class of persons associated with the securities market.
o To any company, regarding capital issue, securities transfer, or related matters.
Disgorgement Power: SEBI can direct a person who made wrongful gain or avoided loss (by violating
the Act/regulations) to return the equivalent amount.
Summary of
Penalties under the SEBI Act, 1992
📌 Section ⚖️Offense 💰 Penalty
15A Failure to furnish info, returns, records ₹1 lakh to ₹1 lakh per day; maximum ₹1 crore
15B Failure to enter into client agreement ₹1 lakh to ₹1 lakh per day; maximum ₹1 crore
15C Failure to redress investor grievances ₹1 lakh to ₹1 lakh per day; maximum ₹1 crore
15D Mutual Funds / CIS defaults (e.g., no registration, ₹1 lakh to ₹1 lakh per day; maximum ₹1 crore
misuse of funds)
15E Non-compliance by AMCs ₹1 lakh to ₹1 lakh per day; maximum ₹1 crore
15EA Non-compliance by AIFs, InvITs, REITs ₹1 lakh to ₹1 lakh per day; maximum ₹1 crore or
3× gains, whichever is higher
55
15EAB Violations by Investment Advisers / Research ₹1 lakh to ₹1 lakh per day; maximum ₹1 crore
Analysts
15F Defaults by Stock Brokers: • ₹1 lakh to ₹1 crore per unissued contract note
• No contract notes • Delay: ₹1 lakh - ₹1 lakh per day; maximum ₹1
• Delay in delivery/payment crore
• Excess brokerage • Excess brokerage: ₹1 lakh or 5× excess amount
charged, whichever is higher
15G Insider Trading: Trading/communicating/aiding Minimum ₹10 lakh; maximum ₹25 crore or 3×
based on UPSI profit made, whichever is higher
15H Non-disclosure during Takeovers ₹10 lakh to ₹25 crore or 3× profit made, whichever
is higher
15HA Fraudulent and Unfair Trade Practices ₹5 lakh to ₹25 crore or 3× profit made, whichever
is higher
15HAA Tampering with records / IT infrastructure ₹1 lakh to ₹10 crore or 3× profit made, whichever
is higher
15HB Contraventions without specific penalty provision ₹1 lakh to ₹1 crore
— Violation of SEBI/SAT Orders Imprisonment up to 10 years or fine up to ₹25
crore, or both
Penalties
under the Securities Contracts (Regulation) Act, 1956
📌 Section ⚖️Default 💰 Penalty Range
23A Failure to furnish required info / false/incomplete details ₹1 lakh – ₹1 crore or ₹1 lakh per day
23A(b) Failure to maintain books of accounts/records ₹1 lakh – ₹1 crore or ₹1 lakh per day
23B Failure to enter into client agreements ₹1 lakh – ₹1 crore or ₹1 lakh per day
23C Failure to redress investor grievances ₹1 lakh – ₹1 crore or ₹1 lakh per day
23D Failure to segregate client securities/money or misuse thereof ₹1 lakh – ₹1 crore
23E Non-compliance with listing/delisting conditions ₹5 lakh – ₹25 crore
23F Excess dematerialisation or delivery of unlisted securities ₹5 lakh – ₹25 crore
23G Failure to furnish periodical returns or amend bye-laws ₹5 lakh – ₹25 crore
23GA Non-compliance in business conduct by stock ₹5 crore – ₹25 crore or 3× gains (whichever
exchange/clearing corp. higher)
23H Contravention of unspecified provisions or SEBI directions ₹1 lakh – ₹1 crore
Power to
Adjudicate - Section 15I of the SEBI Act, 1992
Appointment: SEBI can appoint an officer (not below Division Chief) as an Adjudicating Officer (AO) to
hold inquiries under Sections 15A to 15HB.
Inquiry: AO conducts inquiry in a prescribed manner after giving the person a reasonable opportunity
of being heard.
Powers of AO:
o Summon persons
o Enforce attendance
o Examine witnesses/documents
o Impose penalty if default is found.
SEBI’s Review Power:
o SEBI can review AO’s order.
o Can enhance penalty within 3 months of AO’s order or appeal disposal (whichever is earlier), after
giving a hearing.
Holding an
Inquiry (Same for SEBI and SCRA)
56
1. Issuance of Notice:
o The Board or AO issues a notice to the person concerned, giving them a chance to show why an
inquiry shouldn't be held.
o The notice must specify the alleged offence and allow the person at least 14 days to respond.
2. Proceeding with the Inquiry:
o If the AO decides that an inquiry is needed, a date is fixed for the person's appearance, either
personally or via their representative.
o The AO will explain the offence and the laws allegedly violated, and the person is given the
opportunity to present evidence.
3. Gathering Evidence:
o The AO or Board can summon witnesses and documents that may be relevant to the case. The
hearing may be adjourned for gathering more evidence.
o The procedures of the Evidence Act, 1872 don't strictly apply, but the person is given a fair
opportunity to present their case.
4. Failure to Appear:
o If the person doesn't appear as required, the AO can continue with the inquiry and decide in their
absence after recording reasons for doing so.
Factors to Be
Considered While Adjudging Quantum of Penalty - Section 15J of SEBI Act, 1992
1. Disproportionate Gain or Unfair Advantage, wherever quantifiable, made as a result of the default
2. Loss Caused to individual investors and any group of investors
3. Repetitive Nature of the Default
Section 15JB:
Settlement of Proceedings
Any person under SEBI investigation may apply for settlement. (Both proceedings already initiated
and those pending initiation for the alleged defaults)
SEBI may accept settlement after considering nature, gravity, and impact of default.
No appeal is allowed against the settlement order.
Amounts collected (except legal costs/disgorgement) go to Consolidated Fund.
Recovery of
Amounts (Section 23JB)
Failure to Pay Penalty or Comply
If a person fails to pay penalties, disgorgement amounts, or fees owed to SEBI, the Recovery Officer can take
action to recover the amounts due.
Modes of Recovery
The Recovery Officer may recover the amount through:
1. Attachment and sale of immovable property.
2. Attachment and sale of movable property.
3. Appointment of a receiver to manage movable and immovable properties.
4. Attachment of bank accounts.
5. Arrest and detention in prison.
Property Transfers
If the defaulter transfers movable or immovable property or money (to spouse, minor child, or son's
minor child) without adequate consideration, such assets will still be included for recovery purposes.
57
Even after the minor turns major, such assets will still be treated as part of the defaulter's property.
Application of Income Tax Provisions
The provisions of the Income-tax Act, 1961, and its rules (such as attachment and recovery) apply
with necessary modifications to recovery under this Act.
Recovery Precedence
Recovery of amounts by the Recovery Officer takes precedence over any other claims against the
person.
Recovery Officer's Powers
The Recovery Officer may seek assistance from the local district administration to enforce recovery
powers.
📌 Section
23JC – Continuance of Proceedings
On death of a person, legal representative is liable to pay any sum that was payable by deceased.
⚠️Penalty liability arises only if penalty was imposed before death.
Disgorgement/refund/recovery actions:
o If started before death ➝ continue against legal rep.
o If not started ➝ may be initiated against legal rep.
Legal rep is personally liable only to the extent of estate handled or assets parted with.
Definition of Legal Representative
Legal Representative refers to a person who represents the deceased’s estate, including those who manage
or interfere with the estate, or the person on whom the estate devolves when a party sues or is sued in a
representative capacity.
📌 Section 23L
– Appeal to SAT
Who can appeal? Aggrieved person (by SEBI/AO/stock exchange order).
Where? SAT (Securities Appellate Tribunal).
Time limit: 45 days (extension allowed if sufficient cause shown).
SAT Powers: Confirm, modify, or set aside order.
Order Copy: Sent to parties and adjudicating officer.
Disposal Timeline: To be completed within 6 months, if possible.
📌 Section
23M – Offences
If any person contravenes or abets contravention of the Act or SEBI rules where no specific punishment
is prescribed:
o Punishable with:
Imprisonment up to 10 years, or
Fine up to ₹25 crores, or both.
If a person fails to pay penalty or fails to comply with SEBI/AO orders:
o Minimum 1 month imprisonment, up to 10 years, or
o Fine up to ₹25 crores, or both.
Composition
of Certain Offences (Section 23N)
58
Offences that do not involve imprisonment (or imprisonment with fine) may be compounded (settled by
payment) before or after legal proceedings begin. This can be done by the Securities Appellate Tribunal or
the court before which the proceedings are pending.
📌 Section
23O – Power to Grant Immunity
Who grants immunity? Central Government, on SEBI's recommendation.
When? If:
o Person makes full and true disclosure of violation, and
o CG is satisfied with the disclosure.
Immunity covers:
o Prosecution, or
o Penalty under SEBI Act for the alleged violation.
🔹 Restrictions:
No immunity if prosecution has already been instituted before receipt of application.
SEBI’s recommendation is not binding on the Central Government.
🔸 Withdrawal of Immunity:
If the person:
o Gives false evidence, or
o Violates any condition of immunity.
Consequence: Person can be tried as if immunity was never granted, and is liable for penalty.
📌 Section 24 – Contravention by Companies
1. General Rule:
If a company violates any provision:
o The company, and
o Every person in charge of and responsible for its business ➝ shall be deemed guilty.
2. Protection Clause:
Such persons can avoid punishment by proving:
o Lack of knowledge, or
o Due diligence was exercised to prevent the contravention.
3. Consent/Negligence Clause:
Even if the person is not in charge, if contravention occurred due to:
o Consent,
o Connivance, or
o Gross negligence of any director, manager, secretary, or officer,
➝ that person is also deemed guilty and punishable.
4. Explanation – Definitions:
Company: Includes body corporate, firm, or association of individuals.
Director:
o In case of firm ➝ means a partner.
o In case of association/body ➝ means a controlling member.
Rules for
Copy of Order and Service of Notices/Orders
Rule 6: Copy of the Order
Distribution of Order:
o A copy of every order issued by the Board or adjudicating officer must be sent to:
The concerned person.
59
The Securities and Exchange Board of India (SEBI).
Rule 7: Service of Notices and Orders
1. Modes of Service: A notice or order can be served using the following methods:
o Direct Delivery:
Delivered to the person or their authorized agent.
o Electronic Communication:
Sent via:
Fax (with a note mentioning the number of pages and confirmation of
annexures).
Email or instant messaging services, provided the email is digitally signed by the
competent authority. Note: A bounced email will not count as valid service.
o Postal Delivery:
Sent by courier, speed post, or registered post to:
Last known residential address.
Place of business.
Place of employment (current or last known).
Must be sent with acknowledgment due.
2. Failure to Serve by Regular Methods:
o If service through the above methods fails, the notice or order may be:
Affixed:
On the outer door or another conspicuous part of the person's last known
residence, business premises, or workplace.
This must be done in the presence of 2 witnesses, with a written report
documenting the action.
3. Final Step: Newspaper Publication:
o If affixing fails, the notice or order must be published in:
Two newspapers:
1. An English daily with nationwide circulation.
2. A newspaper in the regional language of the area where the person was last
known to reside, work, or conduct business.
🔴 Penalties –
Section 13
When FEMA is contravened (rules, directions, or authorization conditions): (3Q-2L-5D)
If amount is quantifiable → Penalty up to 3 times the amount.
If not quantifiable → Penalty up to ₹2 lakh.
If continuing contravention → Additional ₹5,000 per day after the first day.
If someone illegally acquires foreign assets above the threshold (Sec 37A(1) proviso):
Penalty up to 3 times the sum involved.
Confiscation of equivalent value in India.
Criminal Prosecution → If Adjudicating Authority recommends and Director of Enforcement agrees.
If above act is proven:
Punishable with up to 5 years imprisonment + fine.
Court can take cognizance only on complaint by officer (min. rank: Assistant Director).
60
Adjudicating Authority can also:
Confiscate currency/securities/property involved.
Direct foreign exchange holdings to be brought back or retained abroad as per directions.
"Property" includes:
Converted bank deposits, Indian currency, or any other form of converted asset.
⚖️
Enforcement of Orders – Section 14
If penalty isn’t paid within 90 days, civil imprisonment may follow.
Before arrest:
Defaulter gets a notice and hearing.
Arrest only if:
o Assets are concealed/transferred to obstruct penalty recovery.
o He had means but refused to pay.
Warrant can be issued if:
There's risk of absconding.
Arrest procedures:
Must be presented to Adjudicating Authority within 24 hours.
Can be released if payment made on the spot.
Post arrest:
Given time/opportunity to pay or furnish security.
If unpaid → civil prison:
o > ₹1 crore: Up to 3 years.
o Others: Up to 6 months.
Release from detention does not discharge the liability for the penalty, but the defaulter cannot be
re-arrested for the same penalty once released.
💸 Recovery of
Penalty – Section 14A
If penalty unpaid after 90 days:
Enforcement Officer (not below the rank of Assistant Director) can recover it.
Powers = same as Income-tax Authority.
Second Schedule of Income-tax Act applies for procedure.
👨⚖️
Appointment of Adjudicating Authority – Section 16
Central Govt appoints Adjudicating Authorities (AAs) via Official Gazette.
AAs hold inquiry, give hearing, then impose penalties.
If absconding risk → AA may require bond/guarantee.
No inquiry unless:
Written complaint by officer authorized by CG.
Person can be represented by:
Legal practitioner or CA.
AAs have Civil Court powers under CrPC & IPC:
Sections 193, 228, 345, 346 apply.
61
Aim: Dispose complaint within 1 year (delay must be recorded).
📝 Appeal to
Special Director (Appeals) – Section 17
CG appoints Special Director(s) (Appeals).
Can hear appeals against orders of AAs (Assistant/Deputy Director of Enforcement).
Appeal Timeline:
Within 45 days (can extend if sufficient cause shown).
Power:
Can confirm, modify, or set aside order.
Has civil court powers like Appellate Tribunal.
Proceedings = judicial under IPC & CrPC.
Appeal to
Appellate Tribunal (Section 19)
Scope: Any person aggrieved by an order from the Adjudicating Authority or Special Director (Appeals)
(except in cases specified under Section 17) can file an appeal to the Appellate Tribunal.
Appeal Conditions: Appeals must be filed within 45 days. The appellant must deposit the penalty
amount, but the Tribunal can waive this in cases of undue hardship.
Procedure: The Appellate Tribunal must decide on the appeal within 180 days, although delays require
justification. The Tribunal has the power to review any order made by the Adjudicating Authority and can
call for records of the proceedings.
Section 34 –
Civil Court Not to Have Jurisdiction
Bar on Civil Courts:
o Cannot entertain suits/proceedings on matters under the authority of:
Adjudicating Authority
Appellate Tribunal
Special Director (Appeals)
No Injunctions:
o Courts/authorities cannot grant injunctions on actions taken under FEMA.
Section 35 –
Appeal to High Court
Who can appeal:
o Any person aggrieved by a decision/order of the Appellate Tribunal.
Ground of appeal:
o Must be on a question of law.
Time limit:
o Within 60 days of communication of Tribunal’s order.
o Extension: Allowed up to further 60 days for sufficient cause.
High Court defined as:
(a) Where aggrieved party resides/works/runs business
(b) If CG is the aggrieved party – where respondent resides/works/runs business
🔍 Rule 4:
Holding of Inquiry
62
1. 📄 Show Cause Notice –
Adjudicating Authority issues a notice requiring the person to explain why an inquiry shouldn't be held.
(Minimum notice period: 10 days)
2. 📝 Content of Notice –
Must clearly state the alleged contravention.
3. 📅 Date of Appearance –
If reply is unsatisfactory, Authority sets a date for personal/legal appearance (by self, lawyer, or CA).
4. Personal Hearing –
Allegations and relevant provisions are explained to the person/legal rep/CA.
5. 📚 Opportunity to Submit Evidence –
o Person can produce documents or evidence.
o Authority can adjourn the hearing.
o Indian Evidence Act need not be followed.
6. 📢 Summoning Powers –
Authority can summon anyone with knowledge of facts or documents.
7. 🚫 Absence of Person –
If person fails to appear, proceedings may continue ex parte (after recording reasons).
8. 🧾 Final Order –
Authority, if convinced of contravention, imposes penalty as per Section 13.
9. 📌 Order Details –
Must include relevant legal provisions and reasons for decision.
10. ✍️Signed & Dated –
The order must be signed and dated by the Authority.
11. 📤 Copy to Person –
Free copy of order to the person concerned and for additional copies on payment of ₹2/page.
12. 💰 Mode of Payment –
Copying fee to be paid in cash or DD in favour of the Adjudicating Authority.
🧾 Rule 5: Appeal to Special Director (Appeals)
1. Form & Fee –
o Appeal to be in Form I, signed, and filed in triplicate.
o Must include 3 copies of the order and a ₹5,000 fee (cash/DD in favour of Special Director).
2. Contents of Appeal –
o Concise grounds of objection.
o No arguments or narrative.
o Grounds must be numbered.
o Must include service address and date of receipt of order.
3. Delay in Filing –
If appeal is filed after 45 days, a petition with reasons and supporting documents is required.
4. Service of Notice –
All notices will be served as per Rule 9 at the specified service address.
Rule 6: Procedure before Special Director (Appeals)
1. Forwarding to Director of Enforcement –
A copy of the appeal and the impugned order is sent to the Directorate of Enforcement.
2. 📆 Hearing Date –
Notices are issued to both parties for the hearing.
63
3. 🎤 Hearing –
o Both the appellant and Directorate's presenting officer are heard.
o Hearing may be adjourned as needed.
4. 📚 Decision in Absence –
If either party fails to appear, the Special Director may decide on merits within 180 days from appeal date.
Rule 10 –
Appeal to Appellate Tribunal
Form II, in triplicate with 3 copies of the order.
Fee: ₹10,000 (cash or DD to Registrar, Appellate Tribunal, New Delhi).
Deposit of Penalty: Mandatory, unless waived due to undue hardship.
Must include:
o Grounds (distinct, numbered).
o Address, date of service, penalty amount, and fee deposit status.
Delay (beyond 45 days): Petition with cause + documents required.
⚠️Section 454A – Penalty for Repeated Default
If a company/person commits same default again within 3 years of penalty order → Penalty = 2x of
original.
Aspect Section 441 – Compounding Section 454 – Adjudication
Authority - Regional Director or an authorized officer No monetary limits apply to the
of the Central Government for offenses up to powers exercised by adjudicating
₹25 lakhs. officers.
- NCLT for offenses above ₹25 lakhs.
Nature of Based on mutual agreement Decision by the adjudicating officer is
Decision between the parties and the arbitrary but ensures reasonable
compounding authority, which has opportunity under Section 454(4).
the final say on the penalty amount.
Appeal The compounding order is final Adjudication orders are appealable to
and generally not appealable once higher authorities, with procedures
agreed upon. outlined in Section 454 and the Rules.
❓ When can
adjudication be ordered under Section 454?
✅ When:
There is a default or non-compliance under the Companies Act.
The RoC, based on document scrutiny, inspection (Sec 206), auditor’s report, or secretarial audit,
identifies the non-compliance.
The violated provision must carry a penalty (not “fine”) – as Sec 454 deals only with penalties.
❓ Who can order adjudication under Sec 454?
The RoC, if satisfied of non-compliance from inspection/audit, can initiate adjudication.
However, if he is also the adjudicating officer, then another independent officer should trigger the
process to avoid bias.
64
📌 Tip: Adjudicating officer should not be the same person who identified the violation.
❓ Do Sec 441 and 454 contradict or override each other?
✅ No, they are independent:
Sec 441 → Voluntary compounding for offences with "fines".
Sec 454 → Penalty adjudication for violations with "penalties".
One does not override the other; they operate parallelly.
💡 What happens in suo motu compounding?
If the defaulter applies voluntarily under Sec 441:
The RD/NCLT may prefer compounding.
But if adjudication is pursued instead, the applicant can challenge the decision if the default was self-
identified, arguing that adjudication shouldn't apply.
Complaint by Registrar and Serious Fraud Investigation Office (SFIO)
The Serious Fraud Investigation Office (SFIO) is an important entity under the Ministry of Corporate
Affairs, established to handle investigations related to corporate frauds and white-collar crimes.
It is a multi-disciplinary body consisting of experts in various fields such as accountancy, forensic
auditing, banking, law, information technology, capital market, and taxation.
Objective of SFIO
The SFIO is tasked with detecting and prosecuting or recommending the prosecution of white-
collar crimes and frauds committed by companies or their officers.
It conducts detailed investigations and takes necessary action for corporate frauds that may not be
detected in routine inspections.
Section 210 -
Investigation into the Affairs of a Company
SFIO is assigned to investigate a company when the Central Government (CG) believes it is necessary, based
on:
1. 📄 Report by Registrar/Inspector under Section 208
2. ⚖️Order by a Court or Tribunal
3. 🌍 Public Interest
4. 📝 Special Resolution by the company.
👩⚖️Powers of
SFIO (Section 212)
1. 🚫 Exclusivity [Section 212(2)]: Once CG assigns a case to SFIO, no other investigating agency
(central/state) can proceed with it.
2. Report Submission [212(3)]: SFIO must submit a report to the CG within the period mentioned in the
order.
3. 👮♂️Investigating Officer [212(4)]: The Director of SFIO appoints inspectors who have powers like an
inspector under Section 217.
4. 🤝 Duty to Assist [212(5)]: It’s the duty of the company, officers, and employees (past or present) to
fully cooperate with SFIO.
⚖️Cognizable
Offences & Bail (Section 212(6))
65
Offences under Section 447 (fraud) are cognizable.
🚫 Bail will not be granted unless:
The Public Prosecutor must be given the opportunity to oppose the bail application.
If the Public Prosecutor objects, the court must be satisfied that there are reasonable grounds to
believe the accused is not guilty and that they will not commit any further offenses if released.
✅ Bail may be given to:
👶 Minor (under 16), 👩🦰 Women, 🤒 Sick/Infirm persons, if the Special Court allows.
📝 No court can take cognizance unless a written complaint is made by:
Director of SFIO, or
Any CG officer authorized by written order.
👮 Power to
Arrest (Section 212(8)–(10))
SFIO officer (min. rank: Additional Director) can arrest a person if they believe the person is guilty of a
Section 447 offence.
The officer must:
Inform the person of grounds of arrest
Send a copy of the arrest order and supporting material to SFIO in a sealed envelope
⏰ Within 24 hours (excluding travel time), the person must be produced before:
Special Court, or
Judicial Magistrate/Metropolitan Magistrate having jurisdiction.
Structure
and Leadership of SFIO
The SFIO is led by a Director who holds the rank of Joint Secretary to the Government of India. This
Director has substantial knowledge and experience in corporate affairs.
The Director is supported by Additional Directors, Joint Directors, Deputy Directors, Senior Assistant
Directors, Assistant Directors, and Prosecutors.
The SFIO’s headquarters is in New Delhi, and it has five regional offices in Mumbai, New Delhi,
Chennai, Hyderabad, and Kolkata.
🚓 SFIO Arrest
Rules – Companies (Arrests...) Rules, 2017
👮 Who Can Arrest?
Director, Additional Director, Assistant Director of SFIO
Must have written reasons based on material in possession
📌 Approval Required Before Arrest:
✅ If arrest by Additional/Assistant Director → Written approval of Director SFIO is mandatory
✅ If arrest involves a Government or Foreign Company → Prior written approval of Central
Government
🔔 Special Intimation for Govt. Company:
Arresting officer must inform:
o 👨💼 MD/person in-charge of Govt. company
o Secretary of administrative ministry (if MD himself is arrested)
66
The arrested individual must be brought before a Special Court or Judicial Magistrate (or Metropolitan
Magistrate) within 24 hours of the arrest. This period excludes travel time to the appropriate court.
📄 Arrest Process & Documentation
🔏 Arrest order + personal search memo (in prescribed Form) must be:
o Signed
o Served to the person being arrested
o Acknowledged in writing by the arrestee.
✉️Within 24 hours, these must be sent (in sealed envelope) to Director, SFIO:
o Arrest order
o Supporting material
o All related documents (signed on each page).
📘
Maintenance of Arrest Register
Maintained in SFIO Director’s office
Must contain:
o 👤 Arrestee details
o 🕒 Date & Time of arrest
o 📋 Information served to arrestee
✍️Entry to be made immediately after documents are received
📦 Records kept for 5 years from:
o (a) Final judgment (if not appealed)
o (b) Final appellate order (if appealed).
🧾 Reporting
to Central Government
📑 Interim Report: If CG directs: SFIO must submit an interim report
📋 Final Investigation Report: SFIO must submit report on completion of investigation to the Central
Government
⚔️Action by Central Government: After legal review of the report, CG may:
Direct SFIO to initiate prosecution
Against:
o Company
o Its officers/employees (present or past)
o Any person/entity connected with the company.
💰 Disgorgement of Benefits → {Section 212(14A)}If report finds fraud and shows:
Any director, KMP, officer, or any person/entity gained undue advantage (cash/property/etc.),
🧾 The CG can file application to Tribunal for:
o Disgorgement of assets/benefits
o Holding such persons personally liable, without limitation of liability.
🔄 Exchange
of Information Between SFIO and Other Departments
📜 Section 212(17) – Mutual Exchange of Information
67
👉 When Other Authorities Must Share Info with SFIO:
If any other agency (like:
o Investigating agencies
o State Government
o Police authority
o Income-tax authorities)
has information/documents relating to any offence under investigation by SFIO,
They must provide such info to SFIO.
🔁 When SFIO Must Share Info with Other Authorities:
SFIO shall share information/documents in its possession with:
o Any investigating agency
o State Govt.
o Police
o Income-tax department
If such info is relevant/useful for their investigation under any other law
Tribunals under the Companies Act, 2013
1. National Company Law Tribunal (NCLT)
Definition: As per Section 2(90) of the Companies Act, 2013, the National Company Law Tribunal
(NCLT) is a quasi-judicial body established under Section 408 of the Companies Act, 2013. It is tasked
with adjudicating matters related to Indian companies, including insolvency, winding-up proceedings,
and other corporate disputes.
Composition: The NCLT consists of a President and both Judicial and Technical Members, whose
number is determined by the Central Government.
2. National Company Law Appellate Tribunal (NCLAT)
Definition: The National Company Law Appellate Tribunal (NCLAT) is the appellate body to hear
appeals against the orders made by the NCLT. It also hears appeals related to decisions under the
Competition Act, 2002.
Composition (Section 410):
o The NCLAT consists of a Chairperson and both Judicial and Technical Members appointed by
the Central Government.
o The NCLAT hears appeals against:
Orders of the NCLT or the National Financial Reporting Authority.
Decisions under the Competition Act, 2002.
3. Qualification of the Chairperson and Members of NCLT (Section 409)
Qualification of the Chairperson:
o The President of NCLT must be a person who is or has been a Judge of a High Court for a
minimum of 5 Years.
Judicial Members:
o To be appointed as a Judicial Member of NCLT or NCLAT, a person must:
Be or have been a Judge of a High Court, or
68
Be or have been a District Judge for at least five years, or
Have been an advocate for at least ten years in a court.
Technical Members:
o A Technical Member is a professional with at least 15 Years of experience in areas such as
corporate law, finance, accounting, or industrial management. The following qualifications
apply:
Member of the Indian Corporate Law Service or Indian Legal Service holding the
rank of Secretary or Additional Secretary to the Government of India.
Chartered Accountant, Cost Accountant, or Company Secretary with at least fifteen
years of practice.
Proven ability and experience in industrial finance, management, reconstruction,
and accountancy for at least 15 Years.
A person who has been a presiding officer of a Labour Court, Tribunal, or National
Tribunal under the Industrial Disputes Act, 1947 for at least five years.
Qualification
of President and Members of Appellate Tribunal (Section 411)
1. Qualification of Chairperson (President of the Appellate Tribunal):
The Chairperson (President) of the National Company Law Appellate Tribunal (NCLAT) must be:
o A person who is or has been a Judge of the Supreme Court or the Chief Justice of a High
Court.
2. Qualification of Judicial Member:
A Judicial Member of the Appellate Tribunal must:
o Be or have been a Judge of a High Court, or
o Be a Judicial Member of the Tribunal for at least 5 Years.
3. Qualification of Technical Member:
A Technical Member must be a person with:
o Proven ability, integrity, and standing.
o Special knowledge and professional experience of not less than 25 Years in the fields of:
Industrial finance,
Industrial management,
Industrial reconstruction,
Investment, and
Accountancy.
Selection of
Members of Tribunal and Appellate Tribunal (Section 412)
1. Appointment of President and Judicial Members:
The President of the Tribunal and the Chairperson and Judicial Members of the Appellate
Tribunal shall be appointed after consultation with the Chief Justice of India.
2. Appointment of Other Members:
Technical Members of the Tribunal and the Members of the Appellate Tribunal are appointed on
the recommendation of a Selection Committee. The committee comprises the following members:
o Chairperson: Chief Justice of India or their nominee.
o Member: A senior Judge of the Supreme Court or Chief Justice of a High Court.
o Member: Secretary in the Ministry of Corporate Affairs.
69
o Member: Secretary in the Ministry of Law and Justice.
3. Decision Making in the Selection Committee:
In case of a tie in votes during a meeting of the Selection Committee, the Chairperson (Chief Justice of
India or nominee) will have a casting vote.
4. Role of Convener:
The Secretary, Ministry of Corporate Affairs acts as the Convener of the Selection Committee.
5. Procedure for Recommendations:
The Selection Committee determines its own procedure for recommending individuals for
appointment as Members of the Tribunal or Appellate Tribunal.
6. Validity of Appointments:
The appointment of Members of the Tribunal or the Appellate Tribunal shall not be considered invalid
merely due to:
o Any vacancy or
o Any defect in the constitution of the Selection Committee.
Term of
Office of President, Chairperson, and Other Members (Section 413)
1. Tribunal (NCLT):
The President and Members of the Tribunal hold office for a term of 5 Years from the date they
assume office.
o Re-appointment: They are eligible for re-appointment for another term of 5 Years.
The term ends when the member attains the following age limits:
o President: Age of 67 years.
o Other Members: Age of 65 years.
2. Appellate Tribunal (NCLAT):
The Chairperson and Members of the Appellate Tribunal hold office for a term of 5 Years from the
date they assume office.
o Re-appointment: They are eligible for re-appointment for another term of 5 Years.
The term ends when the member attains the following age limits:
o Chairperson: Age of 70 years.
o Other Members: Age of 67 years.
3. Eligibility Criteria:
A person under 50 years of age is not eligible for appointment as a member of the Tribunal or the
Appellate Tribunal.
4. Retaining Lien with Parent Cadre:
A Member may retain their lien with their parent cadre, Ministry, or Department for a period not
exceeding 1 Year while holding office.
Powers of the Tribunal under the Act (Section 430) any suit or proceeding that the Tribunal or
Appellate Tribunal is empowered to determine.
Jurisdiction: Civil Courts do not have jurisdiction to entertain Companies Act or any other applicable law.
70
Injunctions: No court or other authority can grant an injunction concerning actions taken or to be taken by
the Tribunal or Appellate Tribunal under the powers conferred by the Companies Act or any other law.
Procedure
Before the Tribunal and Appellate Tribunal (Section 424)
1. Procedural Flexibility:
The Tribunal and Appellate Tribunal are not bound by the procedures of the Code of Civil
Procedure, 1908 but must be guided by principles of natural justice.
They can regulate their own procedures while discharging functions under the Companies Act, 2013
or the Insolvency and Bankruptcy Code, 2016 and associated rules.
2. Powers Equivalent to Civil Court:
For the purposes of discharging their functions, the Tribunal and Appellate Tribunal have the following
powers similar to those of a civil court under the Code of Civil Procedure, 1908:
1. Summoning and enforcing the attendance of any person and examining him on oath.
2. Requiring the discovery and production of documents.
3. Receiving evidence via affidavits.
4. Issuing commissions for witness/document examination.
5. Setting aside default dismissals or ex parte decisions.
6. Dismissing or deciding appeals by default or ex parte.
7. Requisitioning public records or documents.
8. Reviewing their decisions.
9. Other prescribed matters.
3. Enforcement of Orders:
Any order made by the Tribunal or Appellate Tribunal may be enforced as if it were a court decree.
The execution of orders can be sent to the court within the local jurisdiction where:
o For a company: The registered office of the company is located.
o For any individual: The individual resides, carries on business, or works for gain.
4. Judicial Proceedings:
All proceedings before the Tribunal or Appellate Tribunal are considered judicial proceedings
under Indian Penal Code.
They are also deemed civil courts for the purposes Code of Criminal Procedure, 1973.
Orders of
Tribunal (Section 420)
Opportunity to be Heard: The Tribunal must give all parties involved in a proceeding a reasonable
opportunity to be heard before passing an order.
Rectifying Mistakes: The Tribunal can amend its order within 2 Years from the date of the order if there
is an apparent mistake in the record. This amendment will be made if the mistake is brought to the
Tribunal's attention by the parties, but no amendments can be made to orders that are appealed
against.
Sending Copies: The Tribunal must send a copy of every order it makes to all the concerned parties.
Appeal from Orders of Tribunal (Section 421)
71
Filing an Appeal: Any person aggrieved by an order of the Tribunal can appeal to the Appellate
Tribunal.
Consent Orders: No appeal can be made against orders that were made with the consent of the parties.
Appeal Deadline: The appeal must be filed within 45 days from when a copy of the Tribunal's order is
made available to the aggrieved party. The Appellate Tribunal may extend this period by another 45 days
if the appellant proves that there was sufficient cause for the delay.
Procedure: Upon receiving the appeal, the Appellate Tribunal must give the parties involved a
reasonable opportunity to be heard. It can then either confirm, modify, or set aside the Tribunal's order.
Sending Copies: The Appellate Tribunal must send a copy of its order to both the Tribunal and the
parties involved in the appeal.
Appeal to Supreme Court (Section 423)
Filing an Appeal: A person aggrieved by the Appellate Tribunal's order can file an appeal to the
Supreme Court within 60 days from the receipt of the order.
Extension of Time: The Supreme Court can allow an appeal to be filed after the 60-day period if the
appellant provides sufficient cause for the delay. The extension cannot exceed 60 days.
Lesson: 5 (Values, Ethics and Professional Conduct)
Branches of Ethics
Branch Meaning Key Question Alternate
Name
Descriptive Studies what people believe is right or wrong What do people Comparative
Ethics based on customs and laws. think is right? Ethics
72
Normative Defines how people should act based on moral How should people Prescriptive
Ethics principles. act? Ethics
Meta-Ethics Examines the meaning & origins of ethical What does “right” Analytical
concepts like "goodness," "rightness," and even mean? Ethics
"morality."
Applied Applies ethical principles to real-world How do we put -
Ethics situations across different fields. ethics into practice?
Domains of Applied Ethics
Applied ethics is particularly significant for professionals across various fields. Its six key domains include:
1. Business Ethics – Moral code for business operations and corporate governance.
2. Clinical Ethics – Ethical guidelines for medical and healthcare practices.
3. Decision Ethics – Focused on ethical decision-making processes.
4. Social Ethics – Ethical responsibilities in society and public life.
5. Organizational Ethics – Promotes ethical practices within and between organizations.
6. Professional Ethics – Ethical behavior in professions like law, medicine, and teaching.
Key
Differences Between Ethics and Values
Aspect Ethics Values
Definition Rules or guidelines about what is right and Personal beliefs about what is important.
wrong.
Nature A system of moral principles applicable Personal and unique to each individual
universally. based on their thoughts and emotions.
Function Compels individuals to follow a particular Acts as a motivator by influencing
course of action. priorities and emotional states.
Consistency Ethics are consistent across people and Values vary between individuals and may
time. change over time.
Purpose Helps decide what is morally correct or Indicates what a person wants to achieve
incorrect in a given situation. or prioritize in life.
Focus Determines the extent to which actions are Defines personal and professional
right or wrong. priorities.
Example Professional Ethics, Business Ethics, Respect, Integrity, Responsibility, Honesty,
Environmental Ethics, Social Ethics, Empathy, Courage, Fairness, Diversity and
Religious Ethics. Sustainability.
Ethical
Practices:
1. Beneficence
Decision-makers should choose what is right and beneficial, ensuring the greatest good for the most
people. Aligns with the principle of utility, which aims to maximize good and minimize harm.
Example: A doctor prescribes a treatment that benefits the majority of patients with minimal side effects.
2. Least Harm
73
When faced with situations where no choice is entirely beneficial, the principle of least harm guides
decision-makers to select the option that minimizes harm. Aligns with the utilitarian ethical theory, which
aims to causes the least damage.
Example: During budget cuts, a company lays off a few employees instead of shutting down entirely and leaving
everyone jobless.
3. Utilitarian Ethics
Prioritizes outcomes or consequences of actions, that benefit the majority, ensuring collective welfare over
individual interests. Ethical decisions are judged by their results.
Example: Building a bridge benefits thousands, even if a few people are inconvenienced during construction.
4. Autonomy
Individuals should have the freedom to make their own decisions, allowing them to align choices with their
values and goals. It emphasizes respect for personal choice and control.
Example: A manager allows employees to choose how they complete their tasks, trusting their expertise.
5. Justice
Ensures fairness and equality in decision-making. Exceptions should be made only when justifiable.
Example: A company promotes employees based on performance, not personal connections.
Mnemonic for the Principles:
"Be Like U Always Just"
B = Beneficence
L = Least Harm
U = Utilitarian
A = Autonomy
J = Justice
The schedule
VI of the Companies Act, 2013 also states to uphold ethical standards by independent directors:
I. Guidelines of professional conduct:
An independent director shall:
“(1) uphold ethical standards of integrity and probity;
(2) act objectively and constructively while exercising his duties;
(3) exercise his responsibilities in a bona fide manner in the interest of the company;………”
Golden Rules
of Professional Ethics for Company Secretaries
1. Strive for Excellence
Deliver high-quality work that exceeds ordinary standards.
Consistently impress clients and colleagues by maintaining outstanding professionalism.
2. Ethical Behaviour
Follow accepted moral codes and professional standards.
When rules are unclear, act with a clear moral conscience.
3. Loyalty and Transparency
Communicate truthfully, fairly, and clearly.
Build trust and a solid reputation by being honest and ethical.
4. Accountability
74
Take responsibility for all actions and decisions.
Own both successes and mistakes, ensuring credibility.
5. Confidentiality
Protect sensitive information of the organization and colleagues.
Maintain discretion to earn long-term trust and reliability.
6. Trustworthiness
Fulfill commitments and be dependable.
Build long-term professional relationships based on trust.
7. Respect and Courtesy
Treat colleagues, clients, and stakeholders with dignity and politeness.
Avoid conflicts and promote professional harmony.
8. Lead by Example
Set a positive example of professionalism and integrity.
Follow good corporate governance principles in all decisions.
9. Continuous Learning and Competence
Upgrade skills and stay updated with industry developments.
Experience + Continuous Learning = Long-term Success.
ICSA (UK)
Code of Professional Ethics and Conduct - ITPP
The ICSA (UK) Code of Professional Ethics and Conduct outlines four fundamental principles that guide the
conduct of all members, including Fellows, Associates, graduates, students, and affiliated members.
1. Integrity
Integrity reflects honesty, moral soundness, and adherence to ethical codes. Key behaviors include:
Acting professionally in business dealings.
Avoiding or managing conflicts of interest transparently.
Rejecting improper gifts, hospitality, or inducements.
Avoiding unethical, misleading, or illegal behavior.
2. Transparency
Transparency ensures clarity and openness in professional conduct:
Being open and honest in all business dealings.
Avoiding underhand or deceitful practices.
3. Professional Competence
Members must demonstrate competence and deliver high-quality services by:
Keeping professional knowledge and skills up-to-date.
Communicating effectively with clients and stakeholders to facilitate informed decisions.
Working within their competence and admitting limitations if necessary.
Respecting confidentiality unless legally or regulatorily obligated to disclose.
4. Professional Behaviour
Professional behaviour requires adherence to laws, regulations, and institutional standards:
Complying with the laws of the jurisdiction in which business is conducted.
Respecting ICSA’s byelaws and regulations.
Avoiding actions or inactions that could bring disrepute to the profession, such as:
o Bankruptcy or insolvency.
o Conviction of an offense that discredits the Institute or profession.
o Violating professional codes of conduct or ethical standards.
75
Singapore Association of ICSA Code of Professional Conduct and Ethics
The Singapore Association of the Institute of Chartered Secretaries and Administrators (ICSA) emphasizes the
importance of maintaining the highest standards of professional conduct and ethical behavior.
Key Ethical Responsibilities:
1. Uphold the Institute’s Charter and Bye-laws
2. Act responsibly toward the wider community
3. Safeguard interests of employers/clients – avoid illegal or unethical activities
4. Avoid conflicts of interest in any agreement or action
5. Maintain confidentiality – no misuse of client/employer information
6. Stay updated in knowledge and technical skills
7. Preserve the reputation of the Institute at all times.
Ethical Decision Worksheet: Steps for Making Ethical Decisions
1. Analyze the Situation
o Determine the ethical question.
o Identify stakeholders and potential impact.
2. Understand the Facts
o Gather relevant facts.
o Evaluate what action is required.
3. Explore Options
o Identify all possible actions.
o Assess influence of rules, regulations, and ethical principles.
4. Evaluate Consequences
o Consider the outcomes of each option.
o Understand who and how stakeholders will be affected.
5. Test Your Chosen Option
o Select the best course of action.
o Ensure the decision is logical and justifiable.
6. Explain the Decision
o Document the rationale behind the decision for accountability.
7. Take Action
o Implement the decision effectively with a clear plan.
8. Reflect on the Outcome
o Analyze the results and their impact on all parties.
o Learn from the experience for future ethical decision-making.
ICSI Code of Conduct: Key Principles
Fundamental duties and key aspects covered under the Code of Conduct:
"Few Professionals Make Clean, Intelligent Choices Under Intense Client Duty And Discipline."
(i) Fair Dealing - Honest + Ethical + Prompt
76
Principle: Members must treat clients, other members, and students fairly and ethically. They should
not exploit others through manipulation, concealment, abuse of privileged information, or
misrepresentation.
Key Points:
o Always act in the best interests of the client when representing them.
o Maintain honesty and courtesy in all dealings.
o Provide services competently, diligently, and promptly.
o Avoid compromising integrity or professional independence.
o Comply with all relevant rules and legal obligations.
(ii) Professional Opportunity - No Hidden Gains
Principle: Professionals should not exploit opportunities discovered through their position or third
party for personal gain unless the opportunity is disclosed in writing and fully authorized for pursuit.
(iii) Mistakes of Other Solicitors - Don’t Exploit Errors
Principle: A professional must not take unfair advantage of the obvious errors made by another
professional if doing so would benefit a client without proper foundation in law or fact.
(iv) Confidentiality - Keep Secrets Safe
Principle: The Client’s Confidential information is a valuable asset, and professionals must safeguard
it to protect the client's interests. Confidential information should only be disclosed under certain
circumstances, as outlined below.
Key Points:
o Confidential information must be kept secure and should only be used for the benefit of the
client.
o Disclosure of confidential information is only permitted in the following cases:
If the client authorizes it, either expressly or impliedly.
If the professional is compelled by law to disclose it.
To obtain advice in a confidential setting related to the professional’s legal or ethical
obligations.
To prevent a serious criminal offence or imminent harm to the client or others.
If disclosed to the professional’s insurer or associated entities.
(v) Inadvertent Disclosure - See, Stop, Inform
Principle: If a professional inadvertently reads confidential material before being aware of its
confidential status, they must:
1. Notify the relevant party immediately about the inadvertent disclosure.
2. Cease reading the material.
3. If instructed by the client to read confidential material received in error, the professional must
refuse to do so.
(vi) Conflicts of Interest - Disclose, Avoid, No Secret Gains
Principle: Professionals must avoid any conflict of interest where their interests conflict with the
client’s interests. A conflict of interest arises when the professional’s interests or obligations interfere
with their duty to serve the client’s best interests.
Key Points:
o Prompt disclosure of any potential or actual conflicts is required.
77
o No professional should act in a situation where there is a conflict of interest, except when
clearly permitted.
o Professionals must avoid exercising undue influence to benefit themselves at the expense of
the client.
o Professionals should disclose if any commission or financial benefit may arise from a referral
and ensure the client provides informed consent.
o No borrowing money or accepting financial benefits from third parties in transactions
involving a client without full disclosure.
(vii) Undertakings - Promise = Deliver
Principle: Professionals must honor any undertakings made in the course of their practice and ensure
that these commitments are fulfilled timely and effectively unless released by the recipient or a court.
Key Points:
o Professionals must not seek undertakings that require the cooperation of a third party unless
that third party is also a party to the undertaking.
(viii) Integrity of Evidence - Truth Only, No Coaching
Principle: A professional must not:
1. Advise or suggest to a witness that false or misleading evidence should be provided.
2. Coach a witness on how to respond to questions.
Acceptable Actions:
A professional is allowed to:
1. Encourage honesty by advising the witness to tell the truth.
2. Test and question the version of evidence to be given by the witness during preparations, to
assess its consistency and credibility.
3. Point out inconsistencies or other issues in the evidence but must never encourage the
witness to provide information that is contrary to their own understanding or the facts they
believe to be true.
(ix) Client Documents - Return – Retain – Remove (3 Rs)
Principle: Upon the completion or termination of an engagement, a professional is responsible for
ensuring that:
1. The client or authorized party receives any documents related to the client’s matter, including
electronic copies, as soon as reasonably possible.
2. Client documents should be retained for at least 7 years unless instructed otherwise by the
client or dictated by law.
3. Destruction of client documents is permissible only after the 7-year period, unless specific
instructions or legislation prevent it.
(x) Dealing with Other Persons - Be Professional, Not Personal
Principle: A professional must not engage in any action or communication that:
1. Uses unethical tactics, such as those designed to embarrass, frustrate, or cause harm to
another person, beyond the scope of legitimate legal advocacy.
2. Harasses or oppresses persons who are at a significant disadvantage (e.g., due to trauma or
injury) when seeking instructions for legal services.
3. Threatens criminal or disciplinary proceedings to pressure another person into satisfying a
civil liability to the client.
78
4. Misleads or intimidates others through statements that grossly exceed the legitimate
assertion of a client’s rights.
(xi) Anti-Discrimination and Harassment - No Hate, No Harass
Principle: A professional must not engage in:
1. Discriminatory behavior based on race, gender, religion, or other factors.
2. Sexual harassment in the workplace or professional environment.
3. Workplace bullying, including "bullying by proxy," where the bullying is done indirectly,
through another person.
(xii) Dealing with the Media - Speak Responsibly
Principle: A professional must not:
1. Publish or contribute to the publication of material related to current legal proceedings that
could prejudice a fair trial or the administration of justice.
2. Comply with advertising and solicitation regulations and avoiding practices that could lead to
conflicts of interest.
3. Maintaining public confidence and faith in the profession.
Ethical Dilemma:
An ethical dilemma arises when a person is faced with conflicting moral principles, where choosing one
course of action may result in violating another moral standard. This situation can be challenging, as the
person must navigate the conflict between two competing ethical imperatives, each with its own
consequences.
Common Causes of Loss of Ethics and Values:
1. Unclear Policies: Lack of clear ethical guidelines or inconsistent enforcement.
2. Pressure from Management: Focus on profits pressuring employees to ignore ethics.
3. Managerial Decisions: Pressures in decision-making may conflict with ethical principles.
4. Negotiation Challenges: Unethical practices to secure deals or advantages.
5. Conflict of Goals: Clash between organizational and personal goals leading to tough choices.
6. Cultural Differences: Individual values and backgrounds causing ethical dilemmas.
7. Human Nature: Different opinions on what is ethical can create conflicts.
8. Ambition and Discrimination: Personal ambition or bias leading to unethical actions.
OECD Principle: Disclosure and Transparency
The Organisation for Economic Co-operation and Development (OECD) outlines Disclosure and
Transparency as a key principle of corporate governance. This principle emphasizes that:
Disclosure & Transparency: Timely sharing of material matters, including finances and governance.
Stakeholder Alignment: Balancing diverse interests ethically and effectively.
Transparency Checklist for Organizations
1. Board of Directors and Key Staff Information:
o Display the names and contact details of board members and key staff on the organization’s
website.
2. Board Meetings:
o Convey the dates, times, and locations of board meetings at least one week in advance.
79
3. Budgetary reviews
4. Financial Disclosure Statements on their websites
5. Annual Audits
6. Annual Reports on the organization’s website
7. Strategic Plans and Priorities
8. Core Values and Code of Conduct
9. Open Culture and Operations of multiple voices to represent the organization’s interests.
10. Frank, Open Communications including both positive and negative.
How to Resolve Ethical Dilemmas (ERC)
1. Ends-Based Thinking:
o Choose the option that produces the greatest good for the greatest number of people.
2. Rule-Based Thinking:
o Act as if the decision you make sets a universal standard that everyone should follow.
3. Care-Based Thinking:
o Make decisions as though you were the one most affected by the outcome.
Evaluate the situation using all three principles. The approach that aligns best with ethical standards and feels
“most right” should guide your decision.
Human Traits Shaping Behavior and Probable Solutions
Human traits and characteristics profoundly influence behavior, and addressing these effectively is vital for
ethical conduct. Below are some solutions:
(i) Ends Not to Justify the Means
Avoid justifying unethical actions based on good outcomes.
Ensure that both the goals and the methods to achieve them are ethical. Adopt a principle that success
should never come at the cost of values and ethics.
(ii) Character
Uphold the belief: "If character is lost, everything is lost."
Build a strong character based on virtues like honesty, courage, and reliability.
(iii) Ethical Leadership
Leaders may focus solely on outcomes, neglecting the moral values of their strategies.
Leaders must set an example of ethical conduct and good governance by practicing what they preach.
(iv) Satisfaction
Cultivate a mindset of contentment. Reflect on the question, "How much is enough?"
Avoid unethical practices for endless growth and focus on achieving success through valid means.
Recent Cases on Values, Ethics and Professional conduct
1. Punjab National Bank (PNB) Scam
Overview:
o Scam of ₹11,300 crores involving Nirav Modi, Mehul Choksi, and PNB officials.
o Fraudulent Letters of Undertaking (LOUs) were issued without proper credit limits or
collateral.
Key Events:
o FIR Filed: Against Nirav Modi, Mehul Choksi, and others for conspiracy and cheating.
o CBI & ED Involvement:
80
CBI investigated and arrested PNB employees and Nirav Modi's associates.
ED registered a money laundering case and seized assets worth ₹56.74 billion.
o Passports Suspended: Nirav Modi and Mehul Choksi’s passports were revoked.
o Arrests & Warrants: CFO and executives of Nirav Modi's firm were arrested; luxurious assets
were seized.
o Extradition Proceedings:
UK authorities detained Nirav Modi.
Westminster Court issued an arrest warrant and denied bail.
o Fugitive Offender Declaration: Nirav Modi declared a fugitive offender under the Fugitive
Offender Act, 2018.
RBI Actions Post-Fraud:
o Discontinued LOUs/FLCs for trade credits.
o Mandated real-time reconciliation of Nostro accounts to detect unrecorded transactions.
2. YES Bank Crisis
Overview:
o Once a top private bank, YES Bank faced a severe downfall due to fraud, governance issues, and
mismanagement.
o Founded in 2004 by Rana Kapoor and Ashok Kapoor.
Key Reasons for the Crisis:
Non-Performing Assets (NPAs):
Gross NPAs surged, doubling to ₹17,134 crores by September 2019.
Misreporting of NPAs, leading to regulatory scrutiny.
Risky Lending Practices:
Aggressive lending to high-risk borrowers like IL&FS, DHFL, and the Anil Ambani Group.
Governance Failures:
Centralized decision-making by Rana Kapoor.
Governance lapses led to under-reporting of NPAs and capital inadequacy.
Depositor Withdrawals:
Steady withdrawals eroded the bank’s financial stability, burdening its balance sheet.
Steps Taken by RBI:
Took over YES Bank’s management.
Imposed a moratorium on withdrawals.
Drafted a reconstruction plan with SBI investing to acquire a 49% stake in the restructured bank.
81
Lesson: 8 (Concepts of Various Audits)
📘 Introduction to Audit
Audit is an independent, systematic examination of an organization’s:
o Statutory records
o Books of accounts
o Documents and vouchers
It aims to verify whether financial and non-financial statements present a true and fair view.
It provides assurance to:
o Management
o Stakeholders
The auditor forms an opinion based on evidence, and presents it in an audit report.
Origin: The word Audit comes from Latin “Audire”, meaning “to hear”.
🧾 Types of Audits Under Companies Act, 2013
1. Secretarial Audit – Section 204
2. Statutory Audit – Sections 139 to 147
3. Cost Audit – Section 148
4. Internal Audit – Section 138
🔍 Categories of Audit
Financial Audit:
o Includes Statutory Audit, Cost Audit, Internal Audit
Compliance Audit:
o Includes Secretarial Audit, CSR Audit, Corporate Governance Audit, Takeover Audit, Insider
Trading Audit, Labour Law Audit, Cyber Audit, Systems Audit, Social Audit, Forensic Audit
Other Internal Audits (done as part of internal review):
o Stock Audit, HR Audit, Branch Audit, Performance Audit, IT Audit, Environment Audit etc.
Corporate Governance Audit (CGA)
Corporate Governance Audit is an independent review mechanism aimed at evaluating whether a company’s
governance processes are in line with applicable laws, regulations, and best practices. The audit identifies
gaps or shortcomings in governance practices and provides stakeholders with confidence that the
company’s actions are ethical and beneficial to all its stakeholders.
Corporate Governance and Regulatory Framework
1. Companies Act, 2013
2. SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 (LODR Regulations)
3. Schedule II of LODR Regulations
✅ Importance of Corporate Governance Audit
Ensures all governance activities are properly executed.
Identifies gaps in compliance with governance norms.
82
Helps stakeholders make informed decisions.
Serves as a check mechanism on:
o Managerial layer
o Supervisory layer
📌 Often facilitated via Audit Committee and Auditor.
📌 Need for CGA
Acts as a monitoring tool in corporate governance.
Auditors assess management’s commitment to transparency and fair conduct.
Well-governed companies often enjoy:
o Higher market valuation
o Better access to capital (domestic & international)
o Improved public trust and customer base
🎯 Scope of CGA
1. Financial and non-financial disclosures
2. Board composition – mix, independence
3. Stakeholder rights and protections
4. Control environment – internal & external audits
5. Risk management mechanisms
6. Transparency in financial info & executive compensation
7. Strategic planning & social responsibility programs.
🧩 Role of Audit Committee in Corporate Governance
📌 Legal Framework & Applicability
Section 177 of the Companies Act, 2013 mandates constitution of an Audit Committee for:
1. Every listed public company
2. Public companies with:
Paid-up share capital ≥ ₹10 crore
Turnover ≥ ₹100 crore
Outstanding loans/debentures/deposits > ₹50 crore (aggregate)
Composition:
o Minimum 3 directors
o Majority must be independent directors
o Chairperson & majority should be capable of understanding financial statements.
📘 Requirements Under SEBI (LODR) Regulations, 2015 – Regulation 18
Criteria Requirement
Minimum Members 3 Directors
Independent Directors At least 2/3rd must be IDs; if company has SR equity shares → only IDs
(IDs)
Financial Literacy All members must be financially literate; 1 must have accounting/finance
expertise
Chairperson Must be an Independent Director; should attend AGM to answer queries
Company Secretary Acts as Secretary to the Committee
Invitees Finance Director, Head of Internal Audit, Statutory Auditor rep., others as
required
83
Functions & Responsibilities Under LODR
🔎 Financial Oversight
1. Supervise financial reporting and ensure financial statements are:
o Correct
o Sufficient
o Credible
2. Recommend:
o Appointment of auditors
o Remuneration
o Terms of appointment
3. Approve payments for non-audit services to auditors
4. Review annual financial statements before board approval:
o Director’s Responsibility Statement
o Changes in accounting policies
o Major estimates/judgments
o Adjustments due to audit
o Compliance with laws/listing norms
o Related party transactions
o Modified audit opinions
5. Review quarterly financial statements before submission
💰 Monitoring Fund Usage
6. Check application of funds from:
o Public/right/preferential issues
o Monitoring agency reports on fund use
o Misuse of funds, if any
🔍 Audit Quality & Controls
7. Ensure auditor independence and effectiveness
8. Approve or modify related party transactions
9. Scrutinize inter-corporate loans/investments
10. Valuation of undertakings/assets, if necessary
11. Evaluate internal controls and risk management
12. Assess performance of:
Statutory auditors
Internal auditors
13. Examine adequacy of internal audit function:
Structure
Staffing
Reporting line
Coverage & frequency
🧾 Investigations & Whistleblower Oversight
14. Discuss significant findings of internal auditors and follow-up
15. Review internal audit reports on suspected fraud or control failures
16. Hold pre- and post-audit discussions with statutory auditors
84
17. Investigate defaults in payments to:
Depositors
Debenture holders
Shareholders (for unpaid dividends)
Creditors
18. Monitor whistleblower mechanism
👤 Executive Oversight
19. Approve CFO appointment after checking qualifications, experience
20. Perform any additional functions mentioned in its charter
21. Review loans/advances from holding company to subsidiaries if:
Amount > ₹100 crore or
10% of subsidiary's asset size whichever is Lower
22. Evaluate schemes of:
Merger
Demerger
Amalgamation
📌 Especially focus on cost-benefit and stakeholder impact.
✅ Illustrative Checklist for Auditing Corporate Governance System
📝 Purpose: To check whether corporate governance principles are followed effectively.
Used by auditors/PCS to issue a compliance certificate under SEBI (LODR) Regulations.
📌 Key Areas of the Checklist:
🔹 Accountability
Separation of ownership and control.
Executive management accountable to Board.
Board accountable to shareholders.
Audit Committee/Board Charter in place.
Powers of Independent Directors verified.
Frequency & quality of board meetings.
Auditors have access to info and can present views.
Policies on ethics, privacy, fair practices, conflicts of interest, etc.
🔹 Fairness
Equal treatment of all shareholders (incl. minority).
Procedures for resolving violations.
🔹 Transparency
Shareholders informed of rights & changes.
Timely, accurate disclosure of material matters.
Policies on political contributions & insider trading.
Policy on stakeholder rights and sustainability.
🔹 Shareholder Interests
Shareholders’ right to decide on major changes (e.g., mergers, share capital).
Protection of minority shareholders.
✅ 2. Corporate Governance Due Diligence – Coverage
📝 Purpose: To examine governance quality during mergers, investments, or compliance reviews.
85
📌 Key Areas to Cover:
🔹 Board Independence & Governance
Chairperson status (Executive/Non-Executive).
% of Independent Directors (as per SEBI norms).
Woman director & independent woman director status.
Written policies on director induction.
Appointment letters, tenure & resignation gaps.
Separate meetings of independent directors.
D&O insurance, training & orientation details.
🔹 Board Systems & Procedures
Agenda circulation & board meeting records.
Attendance & video conferencing.
Code of conduct for directors/employees.
Succession planning policy.
Review of board effectiveness.
🔹 Board Committees
List of board committees & composition.
Audit committee independence.
Review of RPTs, risk, financial expertise.
Coordination between CFO, internal auditor & audit committee.
Auditor rotation and investor grievances.
🔹 Transparency & Disclosure
Annual Report disclosures.
Remuneration, RPTs, pending legal cases.
Insider trading & compliance certificates (CEO/CFO).
Compliance with Secretarial Standards and Accounting Standards.
Secretarial Audit & audit remarks.
🔹 Consistent Shareholder Value Enhancement
Net worth growth.
Dividend details & policy.
EPS and public shareholding.
Investor satisfaction.
🔹 Other Stakeholder Value Enhancement
Vendor/customer satisfaction.
Employee policies (participation, ESOPs, harassment prevention).
Vendor development policy.
🔹 Corporate Social Responsibility
CSR policy & reports.
Sustainability efforts – energy, water, waste.
CSR budgets.
✅ Secretarial Audit
📌 Meaning & Purpose
Secretarial Audit is an audit of the non-financial and compliance-related aspects of a company.
It ensures the company complies with Companies Act, SEBI laws, FEMA, industry-specific laws,
labour laws, environment laws, and governance practices.
Conducted by a Company Secretary in Practice (PCS).
86
Provides independent and objective assurance to improve risk management, controls, and
governance processes.
📌 Key Benefits
Ensures compliance with applicable laws and secretarial standards.
Detects non-compliances early and allows corrective action.
Enhances transparency, investor confidence, and brand reputation.
Supports ethical culture, employee loyalty, and good market image.
Minimizes legal penalties and risk of imprisonment.
📌 Statutory Applicability – Section 204, Companies Act, 2013
Mandatory for:
✅ Every listed company
✅ Other prescribed companies (as per Rule 9 of Companies Rules, 2014):
o 📌 Public Company with Paid-up Capital ≥ ₹50 crore, or
o 📌 Public Company with Turnover ≥ ₹250 crore, or
o 📌 Any Company with Loans/Borrowings ≥ ₹100 crore from banks/FIs.
Other points:
Report to be annexed with Board's Report (Form MR-3).
Board must explain qualifications or remarks in the report.
Penalty for contravention: ₹2,00,000 on Company/Officers/PCS.
📌 SEBI (LODR) Requirements – Regulation 24A
🟢 Kotak Committee Recommendations led to:
1. Mandatory Secretarial Audit for all listed entities and material unlisted Indian subsidiaries.
🟢 Current Regulation 24A (as amended on 05.05.2021):
Every listed entity and its material unlisted Indian subsidiaries must:
o Annex a Secretarial Audit Report (Form MR-3) with the Annual Report.
o Submit an Annual Secretarial Compliance Report (within 60 days from FY-end) on SEBI
regulations & guidelines compliance.
🟢 No Duplication:
Same MR-3 format is used under Companies Act and SEBI (LODR).
📌 Purpose of Secretarial Audit
Comfort to investors, management, regulators
Ensures diligent compliance with laws & Secretarial Standards
Assists in creating a formal compliance management system
Helps mitigate risk & reputational damage
Builds governance & credibility.
✅ Internal Audit
📌 Meaning & Definition
Internal Audit is a systematic evaluation of a company’s risk management, internal controls, and
governance processes.
Provides independent and objective assurance to help an organisation meet its goals.
87
Internal auditors assess operations efficiency, financial reliability, compliance, and suggest
improvements.
Applicability of Internal Audit as per Rule 13 of the Companies (Accounts) Rules, 2014
1. Listed Companies and Producer Companies
Internal audit is mandatory for all, irrespective of paid-up capital, turnover, or borrowings.
2. Unlisted Public Companies
Outstanding deposits: ₹25 crore or more at any point during the preceding financial year.
Paid-up capital: ₹50 crore or more (during the preceding financial year).
Turnover: ₹200 crore or more (during the preceding financial year).
Outstanding loans and borrowings: Exceeding ₹100 crore from banks or public financial institutions
at any point during the preceding financial year.
3. Private Companies
Turnover: ₹200 crore or more (during the preceding financial year).
Outstanding loans and borrowings: Exceeding ₹100 crore from banks or public financial institutions
at any point during the preceding financial year.
📌 Internal Auditor can be:
→ Chartered Accountant (CA), Cost Accountant (CMA), or
→ Any other professional decided by the Board.
✅ Corporate Social Responsibility (CSR) Audit
⚖️Legal Framework: Applicability – Sec 135, Companies Act, 2013
CSR provisions apply to companies meeting any of these criteria in the preceding financial year:
Net worth ≥ ₹500 crore
Turnover ≥ ₹1000 crore
Net profit ≥ ₹5 crore
Such companies must:
📌 Form a CSR Committee:
o At least 3 directors (including 1 independent director)
o If no independent director is required u/s 149(4), then ≥2 directors
📌 Adopt a CSR Policy
📌 Spend at least 2% of average net profits (last 3 years) on CSR.
🎯 Purpose of CSR Audit
1. Verify compliance to the Companies Act, 2013, including CSR Committee formation, policy adoption,
and spending obligations.
2. Facilitate a mechanism to monitor CSR activities and implementation of the CSR policy effectively.
3. Assess the company’s internal controls and governance practices regarding CSR initiatives.
4. To assess the project life cycle.
5. Verify the utilization of allocated budgets and their effectiveness in achieving desired project outcomes.
88
🔍 CSR Audit Methodology
1. Review: CSR policy, committee structure, governance, partner selection, monitoring & reporting.
2. Stakeholder Interaction: Project team, beneficiaries, company management.
3. Evaluate: Budget allocation, identification of beneficiaries, outcome vs. plan.
4. Financial Analysis: Review CSR spend, direct vs. admin expenses, traceability and genuiness of
expenditure, reasons for inability to spend 2% of profits.
👷 Execution of CSR Audit
Can be conducted internally or by external experts.
CSR Report to be annexed with the Board’s Report.
CSR disclosures also required on company’s website.
📂 Coverage of CSR Audit
Covers:
Human rights, labor practices, environment, health, safety, training, community development, etc.
Based on Schedule VII activities, including:
✅ Hunger, poverty, sanitation, health, drinking water
✅ Education, livelihood, women empowerment
✅ Environment, flora-fauna, Clean Ganga Fund
✅ National heritage, libraries, handicrafts
✅ Armed forces & veterans welfare
✅ Rural and slum development
✅ PM Relief Fund, PM CARES
✅ R&D contributions (IITs, DRDO, ICAR, etc.)
✅ Disaster management
📋 Illustrative CSR Audit Checklist
1. ✅ CSR Committee constituted (if applicable)?
2. ✅ Policy approved by Board?
3. ✅ Schedule VII-based project list?
4. ✅ Transparent monitoring mechanism?
5. ✅ Proper CSR disclosures in Board Report & website?
6. ✅ 2% CSR spend made? If not, reasons explained?
7. ✅ Projects not in ordinary business?
8. ✅ Net profits as per Sec 198?
9. ✅ Admin overheads ≤5% of CSR spend?
10. ✅ Capacity-building expenses within limits?
📊 Impact Assessment Measures
1. Impact of Company Operations: Verify if the company identified key socio-economic changes caused by
its operations in the community.
2. Social Surveys: Check if social surveys were conducted before initiating CSR activities.
3. Impact on Community Lifestyle: Assess how the company identified the possible impacts of its CSR
activities on community lifestyles.
4. Impact Assessment of CSR Activities: Ensure that the company undertakes an assessment of the impact
of its CSR activities periodically.
89
📘 Takeover Audit
Takeover Audit is conducted to verify compliance with:
Companies Act, 2013
SEBI (SAST) Regulations, 2011
Focus: Disclosures, pricing, open offer, and stages of the takeover process.
Key Areas of Takeover Audit
1. Identification and Categorization: Identify and categorize the acquirer, including promoters,
promoter group, persons in control, persons acting in concert (PACs), associates, and immediate
relatives.
2. Monitoring of Promoter Holdings: Monitor the holdings of promoters, their group members, and
PAC.
3. Timely Disclosures: Ensure timely disclosures are made by promoters, members of the promoter
group, and PACs about acquisitions, transfers, and encumbrances.
4. Timely Intimation: Ensure that stock exchanges are promptly informed regarding transfers that are
exempt under the SEBI regulations.
5. Timely Reports under SAST Regulations: Confirm that reports regarding exempt transfers are filed
with both SEBI and stock exchanges as per the SAST regulations.
6. Compliance Monitoring: Use checklist/timeline for full takeover regulation compliance.
Stages of Takeover Audit
Pre-Acquisition: Assess company’s health, legal obligations, potential risks.
Post-Acquisition: Confirm compliance, evaluate integration and strategic goals.
Purpose
Reduce risk through due diligence
Ensure transparent business deals
Support investor confidence
Suggest strategic, cost-benefit driven investment decisions.
Importance of Due Diligence in Takeovers
A strong takeover audit:
Aids in identifying legal, financial, and reputational risks
Helps in fair price negotiation
Enables smooth regulatory compliance.
Consequences of Non-Compliance with SEBI (SAST) Regulations, 2011
📌 SEBI can impose the following penalties:
❌ Divestment of shares acquired
❌ Transfer of shares/sale proceeds to the Investor Protection and Education Fund
❌ Freeze on share transfers by depository
❌ Restriction on voting/other rights over acquired shares
❌ Market access ban for acquirer(s)
❌ Mandatory open offer at SEBI-determined price (with interest for delay)
❌ Restraining asset disposals not disclosed in the offer letter
90
❌ Enforcing compliance with maximum permissible non-public shareholding
❌ Cease and desist orders
⚖️All actions follow principles of natural justice.
📘 Insider Trading Audit
To verify compliance with the SEBI (Prohibition of Insider Trading) Regulations, 2015, including both:
📌 Event-based disclosures
📌 Continuous disclosures
Key Compliance Areas
Area Description
Initial Disclosures By Promoters, KMPs, Directors – About their current holdings (one-time).
Continual Disclosures By Promoter, Director, Employee
For trades > ₹10 lakh/quarter; company must notify exchanges within 2
trading days
Trading Plans Insider may submit plan; needs pre-approval by Compliance Officer
Compliance Officer Appointed to enforce code, monitor trading, close/open windows, approve
plans
Pre-Clearance for Trading Required for designated persons before trading
Codes Required 1. Code of Conduct (Schedule B) 2. Code of Fair Disclosure (Schedule A)
Handling UPSI Ensure protection, restricted sharing, proper digital records
Role of Designated Persons Regulated through training, disclosures, restrictions (e.g., contra trade)
Illustrative Audit Checkpoints
✅ [Link] ✔️What Auditor Checks
1. Is there a Compliance Officer?
2. Is there a digital database of UPSI shared and is it kept for 8 years?
3. Has the Board made Codes of Conduct & Fair Disclosure?
4. Is the code published on website and shared with stock exchange?
5. Does the code mention punishments like wage freeze or suspension?
6. Any violations punished by Board?
7. Is there a valid trading plan, and are disclosures collected?
8. Is the trading plan monitored, reviewed, and sent to stock exchange?
9. Are initial/continual disclosures regularly collected and notified?
10. Are disclosures stored for 5 years minimum?
11. Does Compliance Officer report to Audit Committee or Board?
12. Are whistle-blowers protected from retaliation?
13. Does company follow Chinese Wall policy to prevent data leaks?
14. No contra trades? If done, profits disgorged to SEBI?
15. Any past or present SEBI action on company or KMPs?
16. Any action against non-compliance with the code?
17. Any other steps to prevent insider trading?
📘 Industrial and Labour Law Audit
A compliance audit focused on labour, employment, and industrial laws.
Helps detect non-compliances, avoid penalties, and promote good governance.
91
Conducted by professionals like Company Secretaries to assess compliance level and working
conditions.
Focus is not just financial, but also human rights and welfare of employees.
🎯 Objectives / Benefits
Prevent legal/regulatory action from authorities.
Improve employer-employee relationships.
Promote transparency, governance, and value creation.
Ensure proper systems and processes for labour law compliance.
📍 Scope of Labour Law Audit
Depends on:
o Nature, size & location of the business
o Number of workers employed
Covers Central, State & Local Laws.
Covers records, returns, registers, and actual compliance.
📚 Illustrative Coverage of Key Labour Laws
🏭 Factories Act, 1948
✅ Key Checks:
Applicability: Is the Act applicable to the company?
Applicability confirmed and registration/licensing done.
Manager/Occupier appointed and notified.
Compliance with:
o Health, Safety, Welfare
o Working hours, Young persons
o Leave with wages
📋 Registers/Returns to be checked:
Register of Adult Workers, Leave, Compensatory Holidays
Accident Register, Muster Roll, Inspection Book
Half-Yearly & Annual Returns
Abstract of Act displayed.
⚖️Industrial Disputes Act, 1947
✅ Key Checks:
Applicability: Is the Act applicable to the company?
Is there an industrial dispute? (Sec 2A)
Works Committee (if 100 or more workers)
Grievance Redressal Committee (if 20 or more workers)
21 days’ notice for service condition changes (Form E)
Notice before lockout, especially in (Public Utility) essential services.
Follow proper rules and give compensation for retrenchment (laying off employees)
Compensation is also needed for lay-offs or closing down operations.
💰 Payment of Wages Act, 1936
✅ Key Checks:
92
Applicability: Is the Act applicable to the company?
Timely payment of wages:
o Within 7 days if lesser than 1000 employees are employed
o Within 10 days if greater than 1000 employees are employed
Valid deductions only under Sec 7
Due process for:
o Damage/loss deductions (with notice)
o Unauthorized absence (with hearing)
Records maintained for 3 years
Abstract of Act displayed at workplace.
📘 Minimum Wages Act, 1948
✅ Compliance Checks
📌 Applicability: Is the Act applicable to the company?
💸 Payment of Minimum Wages: Paid as per latest government notifications.
💰 Wages in Kind: Only if permitted and follow proper rules.
⏰ Working Hours & Day: Follow the rules for working hours and working days.
🕐 Overtime Payment: Pay extra for overtime work
📚 Registers Maintained: Keep proper wage and attendance registers.
💼 Unpaid Wages: Follow the procedure for paying dues of employees who have died or can’t be traced.
📉 Deductions: Only allowed deductions should be made from wages.
🕒 Payment Timings: Wages should be paid on time
📄 Notice Displayed: Display the minimum wage rate notice at the workplace entrance.
🏥 Employees’ State Insurance (ESI) Act, 1948
✅ Compliance Checks
🏭 Applicability & Registration: Establishment registered under the Act.
💸 Contributions: Pay the ESI contributions from both employer and employee.
Timely Payment: Contributions deposited within due time.
📋 Employee Register: Maintained as per regulation.
📤 Returns & Reports:
Annual return
Return of contributions
Accident report
Death report (if any)
🩺 Benefits to Employees: Medical, sickness, maternity, etc., as per the Act.
💼 Employees’ Provident Fund (EPF) & MP Act, 1952
✅ Compliance Checks
✔️Applicability: Is the Act applicable?
💰 Contributions: Employer & employee contributions per the EPF Scheme.
📂 Contribution Cards: Keep contribution records up to date.
📑 Returns Submitted: Submit monthly and annual returns regularly.
📘 Registers & Inspection Book: Maintained as per the Act.
📆 Monthly Abstract & Annual Statement: Submitted to Commissioner
Contribution Card + Statement: Sent as required to the Commissioner
⚖️Proceedings: Check if recovery action has been initiated against directors.
93
🏦 Own Trust (if any):
o Are trust terms more beneficial?
o PF Commissioner’s conditions met?
📌 Check if there are any legal actions against the company directors related to EPF
💰 Payment of Bonus Act, 1965 – Audit Checklist
✅ Key Points
• 📌 Applicability: Is the Act applicable to the company?
• 🧮 Correct Bonus Calculation:
o Available surplus
o Allocable surplus
o Bonus as per minimum and maximum limits
• 💸 Deductions: Any deductions must be legally allowed.
• 👥 Eligible Employees: Bonus paid only to eligible employees.
• 🕒 Time of Payment:
o No dispute: within 8 months of financial year-end
o With dispute: within 1 month after resolution
• 📋 Registers Maintained: As required by the rules
• 📤 Annual Return: Filed in Form D within 30 days of the bonus payment deadline.
🏦 Payment of Gratuity Act, 1972
✅ Key Points
• 📌 Applicability: Act applies + check if employee has 5+ years continuous service
• 💰 Timely Payment: Gratuity paid within 30 days of becoming due
• 🪧 Notice Display: Officer name/designation displayed at workplace
• 📝 Nominations: Taken from employees as per rules
• ❌ Forfeiture:
o Valid reason under the law?
o Was the employee given a chance to explain?
• 🪪 Abstract Displayed: At/near main entrance
• Insurance Cover: Gratuity liability insurance obtained by employer (if required).
🧾 Contract Labour (Regulation & Abolition) Act, 1970 – Audit Checklist
✅ Principal Employer Compliance
• 📌 Applicability: Confirm Act applies to the establishment
• 📝 Registration Certificate: Obtained by principal employer
• ❌ Prohibition Check: Has Govt. prohibited contract labour for this work?
• 📒 Registers Maintained:
o Register of contractors
o Annual return (by 15th Feb)
o Start/completion notices within 15 days
• 📢 Notice Display: Wages & abstract of Act and rules
✅ Contractor Compliance
• 🪪 License: Obtained and up-to-date
• 👷 Workmen Count: Matches the licensed number?
• 🧾 Half-Yearly Return: Filed by contractor
• 💵 Wages:
94
o Paid in presence of principal employer’s rep
o Wage slips before payment (if weekly or longer)
o Proper certification on wage cum muster roll
o Wages paid as per official rules
• 📋 Records Maintained (Rule 78):
o Muster Roll
o Wage Register
o Overtime Register
o Fines Register
o Deductions Register
o Advances Register
✅ Welfare & Social Security
• 🏠 Facilities: Restrooms, canteen, wash area, first aid, etc.
• 🧳 Leave & OT: Leave with pay; overtime at double rate
• 🩺 ESI Benefits:
o ESI cards, slips, medical help provided
o ESI/EPF contributions paid; challans submitted
• 📤 EPF Slips: Given to workers
• 🛂 Gate Passes: Signed by contractor + company staff
• 📝 Leave Applications: Signed by contractor or authorized agent.
🤰 Maternity Benefit Act, 1961
✅ Key Points
• 📌 Applicability: Is the Act applicable to the company?
• 🚫 No Employment Post-Delivery: Women should not be employed within 6 weeks after delivery,
miscarriage, or termination of pregnancy.
• ⚠️Light Duty Request: If requested, non-strenuous work must be given 1 month before 6-week pre-
delivery period.
• 💸 Entitlements: Maternity leave, medical bonus, nursing breaks – must be paid as per the Act.
• 🪧 Display: Abstract of the Act and rules displayed at the workplace.
• 📋 Registers: Records and muster rolls properly maintained.
• 📤 Annual Return: Filed as per Government rules.
👶 Child & Adolescent Labour (Prohibition & Regulation) Act, 1986
✅ Key Points
• 📌 Applicability: Confirm whether the Act applies.
• 📝 Notice: Sent to Inspector if any child is employed.
• 🚫 Prohibited Employment: No child should work in banned jobs (Part A & B list).
• 📋 Register (Form A): Maintained with child worker details.
• 🪧 Notice Displayed: Abstract of key provisions (Sec. 3 & 14) displayed on site.
🏢 Industrial Employment (Standing Orders) Act, 1946
✅ Key Points
• 📌 Applicability: Applies if 100+ workers are or were employed in last 12 months.
• 📄 Draft Standing Orders: 5 copies submitted to Certifying Officer.
95
• 📜 Final Standing Orders: Clearly displayed in English and local language.
• ✏️Modification: Only with employee or union agreement.
• 🔍 Suspension: Allowed during inquiry if necessary.
• 💵 Subsistence Allowance: Paid to suspended employees.
⚖️Employees' Compensation Act, 1923
✅ Key Points
• 📌 Applicability: Check if the Act applies.
• 🩹 Injury Compensation: Paid for work-related injuries as per the law.
• 📖 Notice Book: Maintained to record accident notices.
• 📄 Accident Reports:
o Serious/fatal cases reported to Commissioner in prescribed format.
• 💰 Compensation Deposits:
o Death cases – Form A
o Other cases – Form AA
o With Form D (record of deposit)
• 📤 Annual Return: Filed as per state-specific rules.
• 🤝 Agreements: If settled, Form K/L/M submitted to Commissioner.
⚖️Equal Remuneration Act, 1976 – Audit Checklist
✅ Key Points
• 📌 Applicability: Confirm applicability.
• ⚖️Equal Pay: No discrimination in pay for same/similar work – applies to hiring, promotions, etc.
• 📋 Register (Form D): Maintained as per Rule 6.
🧑💼 Employment Exchange (Compulsory Notification of Vacancies) Act, 1959 – Audit Checklist
✅ Key Points
• 📌 Applicability: Check if applicable to the establishment.
• 📢 Vacancy Notification: Notify local employment exchange of vacancies.
• 📤 Returns Filed:
o Quarterly returns
o Biennial returns.
Cyber Audit
Definition:
Cyber security aims to minimize risks of financial loss, disruption, or reputational damage due to IT system
failures. Cyber audit assesses effectiveness of cyber security policies and controls to protect and recover
organizational information.
✅ Objectives of Cyber Audit
• 📌 Assess operating effectiveness of cyber security policies/procedures
• 🔍 Identify and evaluate protection, detection, response, and recovery processes
• Detect internal control or regulatory weaknesses risking the organization.
96
🔐 Key Security & Control Areas in Cyber Audit
• Protection of sensitive data and intellectual property
• Protection of networks connecting multiple information resources
• Responsibility & accountability for devices and contained information.
📋 Scope of Cyber Security Audit
• 📑 Data security policies for network, database, applications
• 🚫 Data loss prevention measures
• 🔐 Network access controls
• Detection/prevention systems
• 🔒 Physical & logical security controls
• 🚨 Incident response program implementation
🧭 Dimensions of Cyber Security Audit Process
1. Management
🏢 They own the responsibility for cyber risk.
⚖️Make decisions based on the risk management process.
✅ Ensure the cyber security controls are working properly day-to-day.
2. Risk Management
🎯 Conduct risk assessments (identify what could go wrong).
💡 Communicate the level of risk to management in clear terms.
Suggest strategies to reduce or manage risk (mitigation).
🔄 Build and maintain a framework to keep improving cyber governance (as threats evolve).
3. Internal Audit (The Independent Reviewers)
👥 Review cyber controls independently — not part of management.
📈 Give unbiased evaluations and advice to improve controls.
🔍 Help management and the board understand and respond to risks.
Sometimes, external auditors are brought in to provide extra assurance on how good the control
design is.
Illustrative Checkpoints for Cyber Security Audit
1. 🆔 Do employees wear ID badges with their photo and role clearly shown?
2. 🔐 Are passwords strong and regularly changed? (No easy or default ones allowed)
3. ⛔ Is access removed immediately when an employee or contractor leaves?
4. 👮 Are entry areas protected with locks, guards, or cameras?
5. 📋 Are background checks done for new staff and contractors?
6. 🚪 Is entry to computer/server areas restricted (sign-in required, visitor badges, etc.)?
7. 👤 Only authorized people can use systems or access sensitive data?
8. Is important data encrypted to keep it safe?
9. Is there a tested disaster recovery plan to recover from cyber attacks?
10. ✔️Are security policies and controls reviewed regularly by management and audited?
Environmental Audit Overview
Environment includes: Water, air, land and how they interact with humans, animals, plants, etc.
97
🎯 Definition & Purpose
An Environmental Audit is an evaluation to:
To verify legal compliance
Find gaps or weaknesses in environmental systems
Suggest ways to improve
Reduce waste and control pollution.
It assesses:
Efficiency in resource use (Man, Machine, Material)
Environmental risks, liabilities, and management weaknesses
Non-compliance with regulatory directives.
💰 Environmental Audit from Financial Perspective
✅ Ensures funds meant for environmental protection are used properly
♻️Conservation of natural resources
📋 These efforts should be mentioned in the Director’s Report
⚠️Consequences of violating environmental laws
👨⚖️Vicarious liabilities imposed by courts/government.
🧾 Types of Environmental Audits
1. Environmental Compliance Audit
2. Environmental Management System (EMS) Audit
1. Environmental Compliance Audit
Checks whether the company follows environmental laws and policies
Focus is only on legal compliance (not on pollution levels)
It’s a narrow audit — doesn't test soil, air, or water quality at the site
Some laws it checks for compliance:
Air Pollution Laws
Motor Vehicles Act, 1988
Factories Act, 1948
Industries (Development & Regulation) Act, 1951
Air (Prevention & Control of Pollution) Act, 1981
Water Pollution Laws
Water (Prevention & Control of Pollution) Act, 1974
Radiation Control
Atomic Energy Act, 1962
Pesticide Control
Poison Act, 1919
Insecticides Act, 1968
Other Environmental Laws
Indian Forest Act, 1927
Wildlife (Protection) Act, 1972
Environment (Protection) Act, 1986
Forest (Conservation) Act
2. Environmental Management System (EMS) Audit
Based on ISO 14001:2015, an international EMS standard
98
It’s voluntary and can be used by any organization
Main Goals of EMS Audit:
Identify and control environmental impact
Keep improving performance
Set and meet environmental goals
Works on PDCA Cycle (Plan-Do-Check-Act):
Plan: Know the environmental context, set goals
Do: Apply controls in operations
Check: Monitor how things are working
Act: Make improvements where needed
Benefits of EMS (ISO 14001):
Reduces environmental risks and saves cost
Recognized globally
Can be aligned with company strategy
🔁 Process of Environmental Audit
1. Pre-Audit / Planning Stage
Understanding the industrial activity
📂 Collection of background information
🎯 Definition of objectives & audit scope
👥 Formation of audit team
📝 Development of audit plan & protocols
2. On-site / Field Audit
📣 Communicate audit objectives
📅 Schedule meetings & staff interviews
🏭 Site/facility inspection
📑 Document & records review
🔍 Identify areas of concern
📋 Initial review of findings
3. Assessing the Impact & Post-Audit
📊 Final evaluation of findings
📝 Submit preliminary report (type & magnitude of impact)
✅ Management approval
📢 Present findings to auditees
📘 Final report with short/long-term actions
4. Follow-up / Review
🔄 Verify actions taken on findings
🔎 Review implementation of recommendations.
📋 Checklist for Environmental Audit
🌿 A. Environmental Policy
1. 📜 Is there a written environmental policy?
2. 🏢 Does it suit the company’s size, activity & legal duties?
3. 🔁 Does it promise improvement, pollution prevention & legal compliance?
99
4. 🧑🤝🧑 Is the policy shared with employees and partners?
5. 🌍 Is the policy publicly available (website or on request)?
🧪 B. Environmental Aspects
6. 🔍 Has the company identified what impacts the environment (air, water, waste, etc.)?
7. ⚠️Have they considered normal, abnormal & emergency conditions?
8. ✅ Are the most serious risks listed and prioritized?
⚖️C. Legal & Other Requirements
9. 🧾 Is there a system to stay updated on environmental laws?
10. 📂 Are required documents (licenses, permits, records) properly maintained?
11. 🪪 Do they have valid:
♻️Waste disposal licenses
Air emission permits
💧 Wastewater discharge permission
☣️Hazardous materials license
12. 💰 Have all fees, fines or registrations been paid on time?
Information Systems Audit
🧾 It is a continuous evaluation of IT controls to ensure:
💼 Assets are protected
🧮 Data integrity is maintained
🎯 Goals are achieved efficiently
💰 Resources are used economically
✅ Supports both:
Attest Objectives (External Auditors) — asset safety + data accuracy
Management Objectives (Internal Auditors) — includes effectiveness & efficiency
🧠 What does the Audit Review? (Scope)
Think of it like auditing everything from computers to passwords:
🧱 System Setup – layout of systems
🧑💻 User Identity & Access – who logs in, and how secure it is
Anti-virus, Network & Firewalls – system protection
📜 Logs & Audit Trails – tracking changes and issues
🧑🏫 Privileged Access Review – monitoring admin access
📦 Backup & Restore Plans – disaster recovery readiness
🎯 Objectives of System Audit
1. ✅ Validate IT organization and controls
2. 🔐 Review access to facilities & systems
3. 🤖 Encourage internal audit automation
4. 🎓 Promote internal IT training
📋 Checklist for Systems Audit
A. 🏢 Management Controls
Does the org have a Security Policy that fits the organization's risks?
100
Does the org have Business Continuity Plan (BCP) & Disaster Recovery (DR) plans?
B. ⚙️Operational Controls
Is physical asset monitoring done regularly and issues fixed?
Are environmental controls like AC, power backup, and cable checks ensured?
C. 🧑💼 Organizational Controls
Are user roles clearly defined vs. IT department responsibilities?
Does the CIO manage Development, Security, and Facility operations?
D. 🧾 Application Controls
Are controls in place for input, processing, and output accuracy?
Are systems compliant with legal requirements?
📊 Mandatory Audits under SEBI
Audit Type Applicable To Purpose of Audit
Annual System Exchanges Ensure robust Business Continuity Plan (BCP) & Disaster
Audit, BCP & DR Recovery (DR) to protect market integrity and investor
confidence during disasters.
Annual System Brokers / Trading Enforce system audit framework for brokers to ensure
Audit of Brokers / Members of National monitoring by exchanges (based on Circular
Trading Members Commodity Derivatives CIR/MRD/DMS/34/2013).
Exchanges
System Audit Mutual Funds / AMCs Standardize and strengthen systems audit for technology-
Framework based asset management operations.
Annual System Market Infrastructure Submit system audit report + MD/CEO certification on IT
Audit of MIIs Institutions (MIIs) security and integrity. Ensure compliance with SEBI
guidelines and address previous audit observations.
Forensic Audit – Detecting Fraud with Proof!
♂️
🔍 What Is It?
A forensic audit is a detailed investigation of financial records to find fraud, embezzlement, or
crime.
"Forensic" means suitable for legal use in court — it’s not just an audit, but evidence-building.
Mixes accounting + auditing + legal + investigative skills.
🎯 Why Is It Done?
Used to:
Fight corruption and white-collar crimes
Gather evidence for court
Support legal teams with expert findings
Resolve disputes — inside or outside the company.
⚙️Two Key Stages
📘 1. Investigation Services
101
Check accounts/statements
Spot defects and possible fraud
Suggest what went wrong and how to fix it
⚖️2. Litigation Services
Help lawyers during court cases
Give expert opinions
Provide evidence, documents, reports
Support in deciding damages or compensation.
📂 Where Forensic Audit Is Used:
Fraud Risk Reviews – loopholes in company systems
📉 Professional Negligence – e.g. carelessness in accounting
🧯 Criminal Investigations – e.g. fund misuse
⚔️Legal Disputes – like shareholder fights or contract issues
🤝 Arbitration Cases – business disputes
🔥 Insurance Settlements – claim investigation.
🔎 Major Types of Fraud Detected
🧑💼 I. Corruption
🤝 Conflict of Interest:
A manager helps a friend in the company (even indirectly).
💰 Bribery:
Giving money/favors to get approvals or contracts.
Extortion:
Threatening someone to gain a benefit (e.g., forcing to award a tender).
II. Asset Misappropriation
Most common fraud.
Involves theft, misuse, or fake use of company property:
o Raising fake invoices
o Paying non-existent employees
o Taking inventory or cash for personal use
📌 Example:
A company driver using the office car for a personal trip.
📊 III. Financial Statement Fraud
Companies do this to look better than they really are:
Forging accounts
Hiding real expenses
Skipping revenue entries
Not following accounting rules
Not disclosing important details
📌 Why?
To attract investors, get bonuses, or reduce losses on paper.
⚙️Procedure of Forensic Auditing Investigation (Step-by-Step)
✅ Step 1 – Accepting the Investigation
102
🔹 Forensic audits are done by independent experts (to ensure fairness).
🔹 Before accepting the case, the audit team must:
Understand the business and suspected fraud
Check if they have the skills/tools/legal knowledge needed
Assess if they can handle it ethically and professionally
🧠 Step 2 – Planning the Investigation
🔹 Key stage where the team sets goals and chooses the right tools to identify fraud.
🔎 Common Fraud Symptoms to Watch For:
Delayed returns, bank remittances or reconciliations
Unusual lifestyle of management/employees
Internal control lapses, losses, policy changes, and cash flow issues
Overdrawn loans, unusual investments, mismatch between profits & cash
📁 Checklist Questions:
Who committed the fraud — management or employee?
Was it corruption, asset misuse, or financial fraud?
Are accounting entries properly shown in the balance sheet?
Are IT returns and bank reconciliations done regularly?
📐 Report Planning Includes:
What type of fraud occurred and for how long?
Who did it and how was it hidden?
How much financial loss?
Evidence for legal action
Tips to prevent future fraud
🔺 Fraud Triangle (Root of All Frauds)
Used to understand why fraud happens:
Pressure – The need or motive
Opportunity – The chance to do it
Rationalization – The excuse or justification
Fraud Risk = Vulnerability to these 3 factors
📥 Step 3 – Gathering Evidence
Methods Used to Collect Proof:
1. Analytical Procedures
➤ Use trends, comparisons, and tech tools (like CAATs) to spot irregularities
2. Discussions & Interviews
➤ Talk to staff and observe reactions
3. Substantive Techniques
➤ Cash counts, reconciliations, document reviews
4. Forensic Data Analysis (FDA)
➤ Use software/technology to detect anomalies, patterns, and fraud indicators
📌 Maintain chain of custody – a clear record of how evidence was collected, to ensure it is court-admissible.
📑 Step 4 – Reporting
📝 The investigation report includes:
Summary of findings & evidence
103
Fraud plan and how it was done
Financial loss estimate
Clear story of how fraud occurred
Suggestions to prevent future frauds
⚖️Step 5 – Court Proceedings
👨⚖️When legal action is needed:
Forensic auditors support lawyers & regulators
May appear in court as expert witnesses
Explain evidence in simple, clear language (especially technical data)
Help judges/lawyers understand the fraud clearly.
🧾 Forensic Audit Report
🔍 A Forensic Audit Report is a formal statement of observations and evidence after a forensic
investigation. It conveys the auditor's opinion, evidence, and conclusions on the fraud.
📑 Illustrative Contents of a Forensic Audit Report:
1. Executive Summary
2. Origin of Audit – Why and how the audit was initiated
3. Audit Objective – What the audit aimed to discover
4. Proposed Audit Outputs – Expected deliverables
5. Audit Implementation Approach – Tools, techniques, and strategy
6. Risk Analysis
7. Internal Environment Risk
➤ Customers, products, competitors
➤ Financial, HR & IT management
➤ Business processes
8. External Environment Risk
➤ Economy, politics, laws, technology in the sector
9. Scope & Incident Coverage
10. Evidence Collection
11. Interviews Conducted
12. Validation of Conclusions
13. Types of Fraud Detected
➤ Conflict of interest, bribery, extortion, theft, fraudulent transactions, asset misuse, inventory or
financial fraud
14. Audit Recommendations
15. Stakeholders Involved.
👥 Social Audit
A Social Audit is a formal review to evaluate an organization’s social and ethical performance, especially its
social responsibility actions. It compares what was promised vs. what is delivered on the ground.
🎯 Objectives of Social Audit:
1. Assess gaps between needs and resources in local development
2. Create awareness among beneficiaries and service providers
3. Increase efficacy and effectiveness of local programmes
104
4. Scrutinize policy decisions based on stakeholder interests
5. Estimate opportunity cost of delayed services
6. Provide feedback to improve community development efforts.
📌 Implications of Social Audit:
Strengthens governance, transparency, and accountability
Gives voice to marginalized groups
Ensures democratic decision-making with stakeholder involvement.
👩⚖️Rights of Social Auditors:
1. Seek clarifications from implementing agencies
2. Scrutinize existing schemes and decisions
3. Access records of income, expenditure, and development work
➡️Requires transparency in planning and implementation
➡️Enforces Right to Information (RTI) to hold agencies accountable.
📋 Aspects Examined in a Social Audit:
Charitable giving and donations
Volunteer work and community involvement
Fair wages, benefits, and work environment
Energy use and sustainability efforts
Organizational transparency
📘 Social Audit – Coverage
A social audit reviews a company’s internal practices or policies and their impact on society, covering
aspects of social responsibility, such as:
Financial stability of the region
Environmental impact
Transparency in reporting
🔄 Scope of Society in Audit:
Flexible: Can be as small as a city or as large as a country or global community
Defined by the company’s goals
📜 Legal Mandate
Regulation 91E of SEBI (LODR) Regulations, 2015: Mandates social audit for Social Enterprises involved
in activities as per Reg. 292E(2)(a) of SEBI (ICDR) Regulations, 2018.
📊 Use of Social Audit Findings
Voluntary in most cases
Positive findings may be disclosed publicly
Negative findings used internally for improvement
E.g.: A company may increase charitable activities after receiving feedback.
Implementation of Social Audit
1. Empowerment of People
Gram Sabha empowered under 73rd Constitutional Amendment for rural audits
RTI Act empowers citizens in cities
2. Proper Documentation
105
Essential documents:
Applications, tenders, proposals
Financial & income-expenditure statements
Worker registers, inspection reports
3. Accessibility of Documents
Must be easily accessible, preferably online
4. Punitive Action
Legal punishments for non-compliance are essential
Currently, not effectively implemented.
📌 Steps for Social Audit
1. Define the Purpose & Goals of local elected bodies
2. Identify Stakeholders (especially marginalized groups)
3. Collect Data – regularly by stakeholders
4. Define Performance Indicators – clear & accepted by all
5. Hold Review Meetings – to assess performance
6. Follow-Up Actions – Panchayat must respond to stakeholder recommendations
7. Establish Independent Group – Local elders, teachers, neutral citizens to verify implementation.
📢 Findings Sharing:
Distribute reports to stakeholders
Display key decisions on walls and boards
Communicate orally for wider reach
✅ Checklist for Social Audit
✔️Are policies defined for rural and poor community development?
✔️Is there regular scrutiny of these policies?
✔️Are gaps in needs vs. resources assessed frequently?
✔️Are voices of minority shareholders considered?
✔️Are necessary actions taken on identified gaps?
📘 ICSI Social Audit Standards
The Institute of Company Secretaries of India (ICSI) has released Social Audit Standards applicable to
Social Enterprises operating in 16 identified areas under Reg. 292E(2)(a) of SEBI (ICDR) Regulations, 2018.
These standards guide ICSI-empanelled Social Auditors for audits as required under:
SEBI (LODR) Regulations, 2015 (Reg. 91E)
SEBI (ICDR) Regulations, 2018
🎯 Objectives of Social Audit
The goal is to evaluate the real impact of the enterprise’s social projects.
▪︎Determine the actual impact vs. intended objectives
▪︎Verify whether projects were genuinely implemented
▪︎Detect gaps between goals and results
▪︎Assess efficiency, cost, and duration of efforts
▪︎Evaluate any unintended positive or negative effects
▪︎Use findings to improve future project design
▪︎Ensure all statutory obligations are fulfilled
106
🌐 Background: Social Stock Exchange (SSE)
➤ SSE is a new platform connecting social enterprises with investors focused on social causes
➤ Acts as a financial bridge between fund seekers and social investors
➤ SEBI introduced mandatory social audits to increase transparency and impact assessment
📋 Scope of Social Audit
The Social Auditor uses technical judgement to decide focus areas, but must address:
◦ Will the project impact local economic, environmental, or social conditions?
◦ Will it alter access to resources like water, energy?
◦ Are there community mechanisms for long-term project outcomes?
◦ Will any vulnerable groups be affected disproportionately?
◦ Is there a likely increase in demand for health or education services?
◦ Will there be demographic shifts in the population?
These questions help anticipate risks and plan for mitigation or adaptation.
📜 Mandatory Nature
✦ Binding on Social Auditors registered under IISA
✦ Must be followed for all audits conducted under SEBI directives
✦ Auditors must retain audit records for 8 years from date of Social Impact Assessment Report
🧩 Eligibility Criteria (SEBI Reg. 292E(2)(a), ICDR, 2018)
The enterprise must work in any of the 16 areas listed below:
1. Hunger, poverty, malnutrition, inequality
2. Healthcare (including mental), sanitation, drinking water
3. Education, employability, livelihoods
4. Gender equality, women and LGBTQIA+ empowerment
5. Environmental sustainability, climate change, wildlife
6. Heritage, art, and culture preservation
7. Sports training (rural, national, Paralympic, Olympic)
8. Supporting social enterprise incubators
9. Strengthening nonprofit ecosystem (fundraising, capacity)
10. Rural/urban livelihoods, small farmer income enhancement
11. Slum development, affordable housing, resilient cities
12. Disaster management (relief, rehab, reconstruction)
13. Financial inclusion
14. Land/property access for disadvantaged groups
15. Bridging digital divide, fighting misinformation, data rights
16. Migrant and displaced persons welfare
📍 Additional areas may be notified by SEBI or Govt. of India in the future
🗂 Record Maintenance Requirement
➣ Social Auditors must preserve:
All documents and evidence gathered during audit
For a minimum period of 8 years
🔎 Benefits & Advantages of Social Audit
107
★ Assessment of Financial Use
Social Audit evaluates:
Sources of funds
Utilisation of funds
Reporting accuracy to the Governing Body
✦ Encourages Social Performance
Highlights real impact of activities
Brings social view to management’s attention
Motivates improved performance
⚡ Strengthens Stakeholder Relations
Implementation of auditor suggestions helps meet stakeholder expectations
Builds long-term trust and collaboration
☘ Comparative Evaluation of Activities
Allows performance comparison of various welfare programs
Identifies which interventions yield better impact
🏅 Boosts Social Reputation
Enhances public image
Demonstrates transparency and accountability
🌱 Fosters Social Responsibility
Encourages shareholders and the public to support welfare efforts
Builds awareness of social contributions
🧾 Overview of ICSI Auditing Standards (CSAS)
The Companies Act, 2013 introduced Secretarial Audit (Section 204) to ensure:
Governance
Statutory compliance
Transparency
👤 Only Practising Company Secretaries (PCS) with CoP can conduct Secretarial Audits and issue reports in
Form MR-3.
📣 PCS is also responsible for detecting and reporting frauds during the audit.
To support PCS, ICSI has established the Auditing Standards Board, which has issued:
📘 ICSI Auditing Standards (Effective from 1st April 2021)
1. CSAS-1: Audit Engagement
o Defines auditor’s role & responsibilities
o Covers agreements with appointing authority
2. CSAS-2: Audit Process & Documentation
o Lays down the audit methodology
o Specifies documentation and record-keeping
3. CSAS-3: Forming of Opinion
o Guides the auditor in drawing conclusions
o Explains how to form a well-reasoned opinion
4. CSAS-4: Secretarial Audit
o Details how to conduct secretarial audits under the Act
o Specifies scope and reporting requirements
Mandatory from:
1st July 2019: Recommendatory
108
1st April 2021: Mandatory
(Postponed applicability initially due to COVID-19).
Lesson: 9 (Audit Engagement)
📘 Meaning of Audit Engagement
An audit engagement is a formal agreement between an auditor and an auditee for the auditor to review and
audit the auditee's transactions.
This agreement is formalized through a document called an Audit Engagement Letter, which details the
terms of appointment, scope of audit, remuneration, and any limiting conditions.
Key Highlights
1. Definition by ICSI (CSAS-1):
o Audit Engagement refers to the detailed terms of reference for the auditor's appointment,
including the scope of audit, remuneration, and any limiting conditions.
2. CSAS-1 Implementation Date:
o Mandatory for audit engagements accepted on or after April 01, 2021.
3. Scope of CSAS-1:
o Applicable to auditors conducting audits under any statute.
o Defines Auditor's role, responsibilities, and process of entering into agreement with the
Appointing Authority
📝 Offer and Acceptance Process
The offer can be initiated by either:
o The auditee, or
o The auditor
Auditor must:
o Fulfill eligibility criteria (e.g., Sec 141 of Companies Act, 2013 for statutory audit)
o Accept the engagement only if qualified
Modes of Appointment:
One-on-one communication
Tendering process
Scenario 1: Auditor Appointed Directly by Management (One-to-One Basis)
When the company directly selects an auditor, the auditor should take the following steps:
109
Step 1: Evaluate the Auditee (Client Screening): The auditor must evaluate the potential risks associated
with taking on the client. This involves considering:
Client Acceptance Risk: Issues like:
o High debt (highly leveraged).
o Frequent legal disputes (habitually litigant).
o Bad media coverage or promoter issues.
o Involvement of Private Equity (PE) investors.
Reputation Risk: The possibility that associating with this client could harm the auditor's reputation.
Performance Risk: Assess if the auditor has enough resources to handle the work.
Engagement Contract Risk: Potential issues or risks associated with the audit agreement itself.
Commercials: Ensuring the fees and payment terms are acceptable.
Step 2: Communicate Willingness
The auditor informs the client his willingness to take up the audit assignment.
Step 3: Conduct a Pre-Engagement Meeting
A detailed discussion with management to understand:
Engagement Terms: Scope of the audit and other conditions.
Business Environment: Internal controls, operations, and risks.
Prior Findings: Issues from previous audits.
Commercials and Timelines: Audit fees, milestones, and deadlines.
Conflict of Interest: Auditor must disclose if there’s any conflict.
Confidentiality: All information shared remains confidential.
Step 4: Sign the Engagement Letter
The agreement is formalized with:
A signed engagement letter with the Management.
A certificate issued by the auditor, confirming compliance with ICSI and legal norms.
Scenario 2: Auditor Appointed Through a Tender Process
When the company invites multiple auditors to bid for the audit, the process involves:
Step 1: Attend Pre-Bid Meeting
A meeting with all interested auditors to discuss the tender details, including:
Scope of work and audit terms.
Prior audit results and reporting framework.
Business operations, internal controls, and audit processes.
Any potential conflicts of interest.
Step 2: Submit a Technical Bid
Auditors submit their proposals based on the requirements outlined in the tender document.
Step 3: Sign the Engagement Letter
The company selects an auditor, and a formal engagement letter is signed.
Step 4: Furnish a Compliance Certificate
Similar to a direct appointment, the auditor must issue a certificate before accepting the audit.
110
Auditor's Certificate to the Appointing Authority:
In both appointment scenarios, the auditor must certify that:
The number of audits taken on is within ICSI's prescribed limit.
No restrictions exist under ICSI guidelines or other laws.
The auditor is not debarred under any disciplinary rules.
No significant conflict of interest exists.
⚙️Preconditions Before Accepting/Continuing Engagement
Before agreeing to or continuing with any audit, the auditor must ensure that:
1. Acceptable Reporting Framework Exists
The reporting framework used by the company for preparing its financial/non-financial statements
is acceptable.
2. Management Acknowledges Responsibility For:
📄 Preparing the financial/non-financial statements according to the applicable reporting
framework, ensuring they are presented fairly.
🧩 Developing and maintaining internal control systems to prevent material misstatements due to
fraud or error.
📂 Providing the auditor with:
o All relevant info & documentation
o Any additional info on request
o Unrestricted access to relevant personnel.
📌 Limitations on Scope of Work
If the management restricts the auditor's scope of work so much that the auditor might have to
disclaim an opinion (meaning they can't form a proper opinion on the financial records), the
engagement should not be accepted.
However, if required by law, the auditor may proceed with such limited engagements.
📌 Factors Affecting Engagement Acceptance
If the preconditions are not met, the auditor must discuss the issues with management. The engagement
should be declined if:
1. The reporting framework is not acceptable.
2. If management has not acknowledged or agreed to the necessary responsibilities.
3. The form and content of reports differ from its expected form and content.
If laws or regulations already clearly define the terms of the engagement, a separate written agreement might
not be needed - just record applicability and acknowledgment by management.
When to Decline or Withdraw from an Engagement
An auditor must assess the situation and decline/withdraw from the engagement if:
111
1. ⚠️Threat to auditor’s independence due to client's background or status.
2. ❌ The auditor’s firm lacks the skills, knowledge, or staff to deliver quality service.
3. 🔍 Other circumstances that might present special/unusual risk to the firm.
📌 Appointing Authority in Audit Engagement
Examples based on type of engagement:
Type of Auditor Appointing Authority
First Statutory Auditor Board of Directors (within 30 days of incorporation)
Subsequent Statutory Auditor Members in AGM (based on board recommendation)
Secretarial Auditor Board of Directors
Internal Auditor Board of Directors (may or may not be employee)
Auditee under CIRP Resolution Professional
Tribunal/Official Liquidator-appointed NCLT (Tribunal) or Official Liquidator
Depository Participant (Company) Board of Directors
Depository Participant (LLP) Designated Partner
Internal Audit of Stock Brokers, etc. Depends on type of auditee
If the law specifies the appointing authority, they may authorize someone to sign the engagement letter. If not
specified by law, the person signing in an official capacity can be considered the appointing authority.
📘 ICSI CSAS-1 defines:
Appointing Authority – Any person or body empowered to appoint the auditor.
Auditee – Person/entity subject to audit
📚 Case Law: Kingston Cotton Mill Co. (1896)
📌 Shareholders passed resolution to appoint auditor; directors refused
Court held: Shareholders have the right to appoint auditor; directors cannot override
Terms and Conditions of Audit Engagement
The scope and objective of an audit are defined by the agreed-upon terms and conditions between the auditor
and the company (auditee). Key aspects requiring specific attention include:
🎯 The objective and purpose of the audit.
👤 The responsibilities of the auditor.
🏢 The responsibilities of management/auditee.
⚠️The audit risk involved.
🚧 The audit limitations.
The audit plan.
112
📄 To formalize these terms, they are documented in an Audit Engagement Letter or a written agreement.
This serves as a reference to address disputes or conflicts during the audit.
📌 If there is a change in law during the engagement:
Auditor must consider the amended law
Any change in terms of engagement should be:
o Judged on merit and properly documented.
💰 Audit Fee & Expenses: The fee charged by the auditor depends on several factors:
🏢 Size of the organization.
🏭 Nature of the business.
⚙️Internal control systems and technology adopted.
📝 Scope of the audit.
📅 Frequency of the audit.
⚖️Audit fees should fairly reflect the value of the work performed, considering the above factors.
🚫 Professional Guidelines on Fees
Contingent fees: Auditors should not accept fees based on specific findings or outcomes unless fixed
by a court or statute.
Percentage-based fees: Generally discouraged, unless authorized by law or recognized practices.
Undercutting fees: Offering excessively low fees to compete can compromise independence and
quality.
Statutory Provisions
Statutory Audit: Remuneration is fixed in the company’s general meeting under Section 142 of the
Companies Act, 2013. They can also claim reimbursement for expenses incurred during the audit.
Secretarial/Internal Audit: Audit fees are decided by the Audit Committee or the Board of
Directors.
Auditing Standard on Audit Engagement (CSAS-1):
Issued by ICSI; applicable to:
Company Secretaries in Practice (PCS) with a valid Certificate of Practice
Applicable for audits under Companies Act, SEBI Act, or other Indian laws
Not mandatory for voluntary audits, but adherence is recommended
Court/Tribunal/Regulator appointments: CSAS-1 applies to the extent possible
📑 CSAS-1 Applies in 3 Scenarios:
CSAS-1 applies in the following scenarios:
1. New Audit Engagement
o First-time audit by a new Auditor.
o Previous period may have been audited by another Auditor
2. Recurring Audit Engagement
113
o Same auditor is reappointed for the next period
o Fresh Audit Engagement Letter must be issued if:
Previous term has expired, or
There are changes in terms
3. Changes in Terms of Audit Engagement
o If the terms of the engagement change during an ongoing audit, a revised Audit Engagement
Letter must be initiated in adherence to CSAS-1.
📌 Key Definitions
👨⚖️Auditor: A member of ICSI with a valid Certificate of Practice under the Company Secretaries Act,
1980, including firms or LLPs registered with ICSI.
🧑💼 Management: Includes the Board of Directors and personnel responsible for governance and
compliance, such as Key Managerial Personnel (KMP) and Senior Management.
Key Managerial Personnel (KMP)
As per Section 2(51) of the Companies Act, 2013, KMP includes:
1. Chief Executive Officer (CEO), Managing Director (MD), or Manager.
2. Chief Financial Officer (CFO).
3. Company Secretary (CS).
4. Whole-time Director.
5. Other officers below directors designated as KMP by the Board.
Senior Management
Defined under SEBI (LODR) Regulations, 2015 and Section 178 of the Companies Act, 2013.
Core, management team excluding Board, includes Company Secretary & CFO and Members one level
below CEO/MD/Whole-time Director.
👤 Predecessor or Previous Auditor
The last Auditor who completed the audit or left the assignment due to resignation, termination, or
other reasons before the current Auditor was engaged.
Audit Engagement Process
1. Pre-Engagement Meeting
Conducted before accepting the audit.
Purpose: Discuss terms, timelines, reporting framework, internal controls, previous findings and
commercial terms.
Auditor must disclose any conflict of interest.
Auditor is bound by confidentiality regarding information discussed.
📝 2. Appointment of Auditor
Made as per applicable laws, rules, standards.
If not specified in law, then appointment is done by the Appointing Authority.
Before acceptance, Auditor must submit an Eligibility Certificate stating:
114
The number of audits taken on is within ICSI's prescribed limit.
No restrictions exist under ICSI guidelines or other laws.
The auditor is not debarred under any disciplinary rules.
No significant conflict of interest exists.
📃 3. Audit Engagement Letter (AEL)
The Auditor must obtain an Audit Engagement Letter from the Appointing Authority along with a
resolution copy, if applicable.
The Auditor provides acceptance of the engagement, which can be communicated:
o On the Audit Engagement Letter.
o Through a separate letter.
o Via email.
📃 Audit Engagement Letter
An Audit Engagement Letter is a formal document detailing the terms of the audit engagement and
ensuring mutual understanding between the Auditor and the Auditee. It establishes the scope, responsibilities,
and other critical aspects of the audit assignment.
Key Features of the Audit Engagement Letter
1. Purpose:
o Defines the scope of the audit.
o Specifies the responsibilities of the Auditor and the Auditee.
o Helps avoid misunderstandings.
2. Legal Context:
o In some cases, where the audit's objective, scope, and responsibilities are clearly established by
law, the engagement letter might simply refer to the relevant law and state that management
acknowledges its responsibilities for record-keeping and compliance systems.
3. Review:
o Should be reviewed annually to ensure relevance.
o Reissuance is not necessary unless the terms of engagement change.
4. Mandatory in Case of Changes:
o A new engagement letter is required if there are changes in the scope, context, or terms of the
audit.
✉️Contents of Audit Engagement Letter:
a. 📌 Objective and scope of the audit.
b. 🤝 Responsibilities of Auditor and Auditee.
c. 📝 Written representations (incl. details of Predecessor Auditor).
d. 🕓 Timelines and milestones for report submission.
e. 💰 Commercial terms: Fees, reimbursements.
f. 🚫 Limitations of audit, if any.
📖 If law defines responsibilities, include reference + Management acknowledgment of duties.
115
👤 Responsibilities of the Auditor
Conduct audit as per agreed terms.
To assign personnel with the necessary knowledge of the relevant laws, under the auditor's overall
supervision.
Ensure:
o ✅ Ethical standards and professionalism.
o 🔒 Confidentiality of audit info.
o 📵 No trading in securities involving unpublished price sensitive information (UPSI)
obtained during the audit.
🧑💼 These duties extend to employees, assistants, and third-party advisors involved in the audit.
🏢 Responsibilities of the Auditee
1. 🚪To provide the auditor with access to the auditee's premises and timely access to all records,
documents, legal opinions, show cause notices, inspection reports, and any other relevant information
needed for the audit.
2. 🧑💼 To identify and assign a responsible official for providing requested documents, information, and
explanations to the Auditor promptly.
3. 📝 To provide written representations during the audit. These serve as evidence for key assertions and
confirm management’s responsibility for their accuracy.
4. 📞 To provide details of Predecessor or Previous Auditor to facilitate communication between the
proposed and previous auditors.
💰 Audit Remuneration & Expenses
🧮 Determining Audit Fee Depends On:
🏢 Nature and type of company (e.g., Listed vs Unlisted).
🔍 Nature of business.
🏭 Sector of operation.
📊 Size of the organisation.
📍 Location(s) of the business and its branches
⚙️Internal control mechanisms.
📅 Frequency of the audit (monthly, quarterly, yearly)
🧑🤝🧑 Type of audit (sole, joint, or concurrent).
👨💼 Auditor’s experience & man-hours required.
🧾 Guidance from ICSI (if any).
➕ Any other relevant factor(s).
⚖️Fairness & Ethics in Fee Arrangement
Fee must reflect the true value of the work.
Mention clearly in Audit Engagement Letter:
o Audit fee.
o Billing arrangement.
o Payment terms.
116
❌ Prohibited Practices:
No contingent fees (based on audit findings/results) allowed.
o Except if fixed by court or public authority.
No commission for securing audit work.
No referral commission for sending clients to others or receiving referrals.
⚠️Relevant Legal Provisions on Professional Misconduct (Company Secretaries Act, 1980)
Clause 2, Schedule I:
o ❌ Not allowed to pay or share fees/commission with non-members (except partners or legal
heirs).
Clause 9, Schedule I:
o ❌ No acceptance of fees based on profit percentage or contingent on audit results.
Risk Disclaimer in Engagement Letter
Audit Engagement Letter must:
⚠️State that due to inherent limitations of audit and internal control, some material non-compliances
may go undetected even in a well-conducted audit.
🤝 Mention any third-party or expert involvement in the audit.
🚧 Specify if any scope limitation is imposed by Appointing Authority.
o ❗ If such a limitation reduces the level of assurance below what law requires, the Auditor must
not accept the engagement (unless mandated by law).
Communication with the Previous Auditor
When taking up a new audit engagement, it is considered professional etiquette for the new Auditor to
communicate with the previous Auditor.
1. Definition of a Previous Auditor:
o A previous or predecessor Auditor is one who conducted the most recent audit assignment or
was engaged but did not complete the assignment due to resignation, termination, or other
reasons.
2. Professional Etiquette:
o The new Auditor must formally notify the previous Auditor about their engagement for the new
audit assignment.
o The communication should be retained as evidence of delivery, using methods like Registered
Acknowledgement Due (RAD), courier, hand delivery with written acknowledgment, or email.
3. Timeline for Acceptance:
o The new Auditor must wait for 7 days from the date of communication before accepting the
audit.
4. Confidentiality:
o Any information received from the previous Auditor must be treated confidentially and used
only for audit purposes.
117
⚖️Relevant Case Law
🔹 Ssay & Associates v. ICAI, Delhi HC (W.P. No. 7674)
Held: NOC is not required from previous auditor.
Only requirement: Mandatory communication with previous auditor before accepting the audit.
📌 Mandatory Communication to Previous Auditor – As per ICSI Council
Before accepting the following assignments, a Company Secretary in Practice (PCS) must communicate in
writing to the previous incumbent as per Clause (8), Part I of the First Schedule to the Company Secretaries
Act, 1980:
✅ Mandatory Cases Requiring Communication
1. MGT-7 – Signing of Annual Return [Sec 92(1)]
2. MGT-8 – Certification of Annual Return [Sec 92(2)]
3. Secretarial Audit Report [Sec 204]
4. Secretarial Audit Report of material unlisted subsidiaries of listed entities [Reg. 24A of SEBI
(LODR)]
5. Annual Secretarial Compliance Report [Reg. 24A, SEBI (LODR)]
6. Director disqualification certification [Schedule V, Part C, Clause 10(i) of SEBI (LODR)]
7. Transfer-related certifications [Reg. 40(9), SEBI (LODR)]
8. Internal Audit of DPs [under Depositories Act & SEBI (DP) Regulations]
9. Reconciliation of Share Capital Audit [SEBI circulars]
10. Compliance Auditor under 3rd Party Scheme (Haryana)
11. Audit under Reg. 76 of SEBI (DP) Regulations, 2018 – for unlisted public companies
12. Diligence Reporting for Banks – Consortium Lending (RBI circular)
13. Internal Audit of Depository Participants
14. Internal Audit of Stock Brokers / Sub-brokers under SCRA, 1956
✅ Format prescribed by ICSI for such communication.
🛑 Limits on Audit Engagements
A PCS shall not exceed the number of audit engagements as per:
Applicable laws, or
ICSI Council guidelines
🔍 Violation may attract disciplinary action.
📏 ICSI Guidelines on Audit Limits
Audit Type Normal Limit Additional (Peer Effective From
Reviewed)
Secretarial Audits 10 per partner / PCS +5 per partner / PCS FY 2016–17
Annual Secretarial 5 per partner / PCS +5 per partner / PCS 1 April 2020
Compliance Reports
118
(ASCR)
Peer Review Mandatory Top 100 Cos. (from Top 500 Cos. (from All Listed (from 2022), All
2020) 2021) Cos. (2023)
⚖️Conflict of Interest – CSAS-1
“Conflict of Interest” refers to any situation where the auditor’s personal or professional interests may
interfere with independence or objectivity.
Substantial conflict of interest: Prohibits accepting an Audit Engagement.
Other conflicts of interest: Can be accepted if disclosed in writing to the Auditee before acceptance or
upon becoming aware.
❌ Substantial Conflict of Interest (Prohibited)
The following cases are considered substantial conflicts of interest, and the Auditor cannot accept the Audit
Engagement:
1. Ownership Conflict:
o Holding more than 2% of paid-up share capital or shares of nominal value exceeding
₹50,000, whichever is Lower.
o Holding more than 2% voting power, individually or jointly with family members dependent on
the Auditor.
2. Indebtedness Conflict:
o Auditor is indebted to the Auditee for any amount exceeding ₹5,00,000, or any level of
indebtedness that could seriously impair the auditor's independence, regardless of the amount.
3. Employment History:
o If the Auditor was employed by the Auditee within the last two years.
✅ Non-Substantial Conflict of Interest (Permitted with Disclosure)
In the following cases, the Auditor may still accept the Audit Engagement, provided they disclose the conflict
in writing:
1. Ownership Interest:
o Holding up to 2% paid-up share capital or shares of nominal value of ₹50,000, whichever is
Lower.
o Holding up to 2% voting power.
2. Indebtedness:
o Auditor is indebted to the Auditee for ₹5,00,000 or less.
3. Former Employment:
o If the Auditor was employed by the Auditee but left the job over two years ago.
Key Points
Disclosure Obligation:
o The Auditor must disclose in writing any non-substantial conflict of interest before accepting
the Audit Engagement.
Combined Holdings:
119
o The limit on ownership and voting power includes holdings of the Auditor, partners, spouse,
parents, siblings, or dependent children.
No Conflict Declaration:
o Auditors must declare the absence of substantial conflicts as per laws and standards applicable
to the audit.
Indebtedness of the Auditor and Conflict of Interest
1. Indebtedness Limit:
o Any indebtedness exceeding ₹5,00,000 to the Auditee or its related parties, other than in the
ordinary course of business, constitutes a substantial conflict of interest.
o The limit applies to the combined indebtedness of the audit firm and its partners, individually or
collectively.
2. Impairment of Independence:
o Any indebtedness, regardless of the amount, that could seriously impair the Auditor's
independence is treated as a substantial conflict of interest.
3. Disclosure Requirement:
o Before accepting an audit, the Auditor must disclose that no conflict of financial interest exists as
per the standards or laws governing the audit.
4. Ordinary Course of Business:
o Transactions in the "ordinary course of business" are not defined but assessed on a case-by-case
basis.
o Example: A bank providing loans at prevailing lending rates under standard terms to its Auditor
is not treated as a financial conflict.
Illustrative Example:
Scenario:
A banking company provides a loan to its Auditor at a standard interest rate in line with its usual
lending practices.
Outcome:
Such a loan is treated as being in the "ordinary course of business" and does not constitute a conflict
of financial interest.
Employment and Conflict of Interest in Audit Engagements
1. Two-Year Cooling-Off Period:
o If an Auditor or a partner/member of a Practicing Company Secretary (PCS) firm was employed by
the Auditee, its holding, or subsidiary company, two years must lapse from the date of cessation
of employment before they can undertake any audit assignments related to the Auditee.
2. Pre-Certificate of Practice Employment:
o A PCS or member of a PCS firm cannot audit an entity where they were employed before
obtaining their Certificate of Practice, unless two years have elapsed from their cessation of
employment.
120
3. Mandatory Disclosure:
o The PCS must disclose to the Auditee if the two-year period has not lapsed since their employment.
⚖️Effect of Substantial Interest (CS Act, 1980)
It is misconduct if a CS expresses opinion without disclosure in cases where:
o He or his partner/firm has a substantial interest in the auditee.
📌 “Substantial interest” is not defined in Companies Act, 2013 → Left to professional judgment.
✔️Must consider what a reasonable third party would conclude in the circumstances.
Conflicts of Interest
Conflicts of interest occur when:
1. Between multiple clients: A professional provides services to two or more clients with conflicting
interests regarding the same matter.
2. Between professional and client: The professional's own interests’ conflict with the client’s interests in
the matter.
Examples of Conflicts of Interest
1. Transaction Advisory Service:
Advising a client acquiring another client audited by the firm, using confidential information obtained
during the audit.
2. Competing Clients:
Auditing two clients simultaneously who are competitors in acquiring the same company.
3. Clients in Legal Dispute:
Accepting audit assignments for two clients engaged in a legal dispute over the same matter.
4. Licensor-Licensee Audit:
Providing an audit report for a licensor on royalties while advising the licensee on royalty calculations.
⚙️Auditor’s Duty in Conflict Situations
✅ Auditor must:
Identify & evaluate any conflict of interest before accepting the engagement.
Disclose any interest to the auditee/client.
Assess threat level using reasonable third-party test.
Apply safeguards, e.g.:
o Restructure the team
o Limit access to confidential info
o Decline or withdraw from the engagement if threat is not manageable
🔐 Must maintain:
Confidentiality at all times, even during internal discussions or while seeking advice.
🔒 Confidentiality – Fundamental Ethical Principle in Audit
121
Auditors often access sensitive, confidential, and privileged information while conducting audits.
They have a duty to protect such information from unauthorized use or disclosure.
📌 Obligations Under the Principle of Confidentiality
Auditor must refrain from the following unless authorized or legally obligated:
❌ Disclosing information acquired during audit to anyone other than the auditee, without consent.
❌ Using such information for personal gain or to benefit third parties.
❌ Disclosing confidential info even in casual/social conversations.
❌ Sharing information of a prospective client received before engagement.
📘 Professional Misconduct (CS Act, 1980 – Second Schedule, Part I, Clause 1)
A Company Secretary in practice is guilty of misconduct if:
"He discloses information acquired during professional engagement to anyone other than the auditee,
without consent, or other than as required by law."
🔍 Note: “Information” includes any detail not publicly available.
Key Rules and Safeguards
Area Auditor’s Responsibility
💰 Using Information for Auditors must not use information acquired through professional
Personal Gain relationships for their personal advantage or the advantage of third
parties.
🔐 Control of staff Ensure staff and consultants also maintain confidentiality
🏢 Within firm Auditors should also maintain the confidentiality of information within
their own firm or employing organization, ensuring that sensitive details
are not unnecessarily shared.
Inadvertent Disclosures Auditors must be vigilant and maintain confidentiality even in social
settings. They should be particularly careful about unintentional
disclosures, especially with long-term business associates, relatives, or
friends.
🆕 Prospective clients The duty of confidentiality extends to information disclosed by a
prospective client or employer, even before a formal engagement.
🔄 Disclosure authority Only with specific, proper authority (e.g. Board or designated person)
📄 Use in reports If the auditor refers to audit evidence or documents while forming their
opinion in the audit report, this is considered a disclosure under legal
obligation or in the performance of duty and is acceptable.
⚖️Judicial references Using decisions of judicial authorities during the audit and while forming
an opinion is not treated as using or sharing confidential information.
📝 Examples of Proper Authority (for disclosure permission)
Company: Board or a director authorized by Board.
LLP: Designated Partner or person authorized by LLP.
🔍 Internal Safeguards to Ensure Confidentiality
✅ Auditor must:
Educate team on confidentiality obligations.
122
Get signed NDAs from staff with access to sensitive info.
Implement reasonable procedures to prevent unauthorized access.
🔁 Changes in Terms of Engagement – Key Principles (CSAS-1 Para 5.1)
The Auditor shall not agree to any change in audit engagement unless there is a reasonable justification.
With reasonable justification and mutual agreement, and changes must not compromise audit scope or
objectivity.
📜 When Change is Allowed
✅ Change in terms is allowed only when:
Circumstances affecting the audit require a revision (e.g., change in law, management restructure).
Both Auditor and Appointing Authority agree in writing via:
o Revised Engagement Letter /
o Supplementary Agreement
The revised agreement must:
Be mutually accepted
Be duly signed
Include justification for change.
❌ Unjustified Change – Not Permitted
🔻 Change is not acceptable when:
Done to avoid a modified/unfavorable audit opinion
Based on incomplete/incorrect information
Attempts to convert audit to a lower assurance engagement (e.g., audit to review)
📌Example: If the auditor cannot obtain sufficient evidence (e.g., on labour law compliance), and the auditee
requests to reduce scope to avoid negative remarks, such change must be resisted.
⚠️Precautions to be Taken by Auditor
1. ❗ No statutory scope reduction – Audit coverage mandated by law cannot be narrowed.
2. ❗ Do not accept changes made to avoid modified opinion.
3. ❗ Changes made to circumvent negative reporting are unethical and unjustified.
4. ❗ Do not ignore audit evidence already collected before the change in terms.
🔍 Before Accepting a Change in Terms
The Auditor must:
Assess if the level of assurance will be impacted.
Accept only if the new terms can still provide adequate assurance, possibly through a modified
report.
Lesson: 10 (Audit Principles and Techniques)
Meaning of Auditing
123
Auditing is the process of examining and evaluating an organization’s internal controls, corporate
governance, and accounting practices to ensure compliance with laws and regulations. It helps in accurate
financial reporting and operational efficiency, benefiting stakeholders such as investors, government,
shareholders, and creditors.
Fundamental Principles Governing Auditing (9 Principles)
1. Integrity, Independence, and Objectivity
Integrity: Auditors must act honestly, fairly, and in the public's trust, complying with ethical principles
and laws while respecting confidentiality.
Independence: Auditors must avoid relationships or conditions compromising their objectivity.
Objectivity: Make impartial decisions based on evidence, avoiding discrimination or undue influence.
2. Confidentiality
Auditors handle sensitive financial data and must protect its confidentiality. Disclosure is only
permissible when legally or professionally required.
Care must be taken to safeguard documents and shared information.
3. Skill and Competence
Auditors must be qualified, continuously update their knowledge, and adapt to changes in auditing or
accounting practices (e.g., new tax laws like GST).
4. Planning
A tailored audit plan enhances efficiency and aligns with the organization’s size, type, scope, and
internal controls.
5. Accounting Systems and Internal Controls
Auditors verify the accuracy of records and ensure the organization’s financial status is represented
fairly. Internal controls must be tested for reliability.
6. Work Performed by Others
Auditors may delegate work but remain fully responsible for its accuracy. Proper supervision and
review of delegated tasks are essential.
7. Documentation
Maintaining records, such as audit plans, notebooks, and files, ensures evidence of audit work.
These documents serve as references for clients or regulatory reviews.
8. Audit Evidence
Auditors must gather sufficient evidence using substantive and compliance procedures. External
evidence is more reliable than internal sources.
9. Audit Conclusions and Reporting
Audit conclusions are formed based on evidence and adherence to accounting standards, legal
requirements, and material disclosures.
⚖️Materiality: A case where an auditor deemed an error immaterial, but it later proved material, leading to
legal action against the company. This emphasizes the need for proper materiality assessment.
124
⚠️ Risk Assessment: An auditor identified a significant risk in inventory management and designed audit
procedures that revealed weaknesses in internal controls. This highlights the importance of thorough risk
assessment and tailored audit procedures.
📉 Lehman Brothers: The 2008 bankruptcy is presented as an example of the failure of audit principles. The
company's financial statements did not accurately reflect its financial position, and auditors failed to identify
risks associated with mortgage-backed securities.
Audit Techniques
Audit techniques are methods and procedures auditors use to gather sufficient and appropriate evidence for
their audit opinion. The choice of technique depends on:
Auditor's judgment
Nature and complexity of the entity audited
1. Examination of Records
Inspecting books, documents, and records to verify the validity of the data presented.
2. Inquiry
Gathering information directly from resource persons within or outside the organization for
clarification or additional details.
3. Sampling
Selecting a sample of items from the accounting records to evaluate characteristics of the entire
dataset.
4. Confirmation
Verifying the accuracy of recorded data by obtaining confirmation directly from external parties, such
as debtors.
5. Compliance
Checking the arithmetical accuracy of records by comparing account balances with vouchers to test the
reliability of the data.
6. Compliance Tests
Checking the effectiveness of internal controls to ensure compliance with policies and procedures.
7. Computer Techniques
Employing software tools like audit software, test packs, and mapping to test the accuracy of data.
8. Substantive Tests
To obtain evidence that data produced by accounting system is accurate or not.
o a. Test of detailed transactions
o b. Test of significant ratios and trends
9. Dependence on Experts and Other Auditors
125
Seeking opinions from specialists like engineers, lawyers, or internal auditors for areas outside the
auditor's expertise.
10. Analytical Review
Studying trends, ratios, and significant changes by comparing past and present data.
Preliminary Preparation for an Audit
1. Understanding the Entity: Gain insight into the organization’s operations, industry, structure, accounting
policies, and risk management processes.
2. Assessing Risks: Identify and evaluate risks associated with the entity’s business operations,
effectiveness of internal controls and financial reporting. This includes risks of material misstatements.
3. Developing an Audit Plan: Create a detailed plan outlining audit scope, objectives, timeline, budget, and
approach, based on risk assessment.
4. Assigning Audit Team Members: Allocate team roles based on experience and knowledge of the entity’s
operations and industry.
5. Communicating with Management: Discuss the audit plan with management, establish a timeline, and
obtain required information, including a representation letter.
6. Developing Audit Programs: The auditor needs to develop audit programs that outline the specific audit
procedures to be performed during the audit. The audit programs should be based on the audit plan and
the risks identified.
7. Establishing an Audit File: Document the audit plan, procedures, and evidence collected during the audit.
Questionnaires in Audits
Questionnaire: A structured series of questions designed to evaluate the existence, operation, and
effectiveness of an organization’s internal controls.
Purpose: To systematically collect information and identify potential weaknesses or inefficiencies in internal
controls.
Key Features of a Questionnaire:
Questions are designed for Yes/No answers:
o "Yes" Answers: Indicate satisfactory control.
o "No" Answers: Indicate potential weaknesses, requiring further details or explanations.
For irrelevant questions, the response is marked "Not Applicable."
Results help the auditor identify and report deficiencies and recommend improvements.
How Questionnaires Are Used in Audits
1. Planning the Audit:
o Review documentation to identify potential risks.
o Design a questionnaire that is tailored to the specific risks and issues identified in the audit
planning process.
2. Administering the Questionnaire:
o Issue the questionnaire to the auditee.
126
o Set a deadline for completion, ensuring all relevant personnel are involved.
3. Analyzing Responses:
o Examine answers for inconsistencies, weaknesses, or potential risks.
o Identify areas requiring additional information or documentation.
4. Follow-Up Interviews:
o Conduct interviews with key personnel to clarify responses.
o Request additional evidence or explanations for discrepancies.
5. Reporting Findings:
o Prepare a detailed report summarizing:
Control deficiencies.
Areas of concern.
Recommendations for improvement.
Interaction Through Interviews in Audits
Interviews in the context of an audit serve three main purposes: orientation, examination, and confirmation.
These purposes can sometimes overlap but are typically distinct from one another.
1. Orientation: Typically occurs during the planning phase of the audit, when the audit team is learning
about the business or area, they are auditing. During orientation, the aim is to explore and
understand the key activities, structures, networks, and documents within the organization.
This might involve asking for presentations of activities, explanations of networks, or interpretations
of documents to identify potential audit subjects or information sources (key personnel,
documentation). Orientation is often unstructured to allow flexibility in exploring new topics.
2. Examination: Examination focuses on more specific issues and is aimed at gathering new
information, often to be used as audit evidence. This could involve uncovering information that hasn’t
been documented yet, relying on the interviewee’s personal experiences or opinions.
In some cases, the auditor might interpret internal documents jointly with the interviewee to gain
new insights. Evidence from interviews often requires corroboration from other data collection
methods.
3. Confirmation: Confirmation verifies previously gathered information. May occur during planning, to
confirm key facts and conditions or during execution, to confirm findings and avoid
misunderstandings.
Interview Techniques
Unstructured Interviews: During the planning phase, the approach is often more flexible and
unstructured to allow the auditor to explore new areas and gather a wide range of insights,
especially when the auditor has limited prior knowledge of the activity being audited.
Structured Interviews: In the execution phase, when the focus is on confirming facts, testing
hypotheses, or gathering specific data, the interview tends to be more structured. By this stage, the
auditor has a clearer understanding of the issues and should know the type of data required.
127
Audit Programmes
An Audit Programme is a step-by-step written plan that guides the audit team on what work to do, who will
do it, and by when.
It helps:
Divide tasks clearly among team members.
Avoid duplication or missing out on key checks.
Ensure the audit is done efficiently and thoroughly.
Key Features of an Audit Programme
Prepared separately for each audit area (e.g., purchases, payroll, inventory).
Clearly assigns:
o Who will perform the task
o What is to be done
o By when it should be completed
Also decides:
o What audit evidence is required
o How much evidence is enough
Becomes part of the Audit Working Papers (official records of the audit).
Types of Audit Programmes:
Standard Audit Programme: This is a base programme with minimum essential tasks that are
applicable for most audits.
Customized Audit Programme: In certain cases, the standard programme is modified to suit the
specific needs of an engagement. For example, when additional or specialized procedures are needed,
the programme can be adjusted accordingly.
Ongoing Audit Programme: For some audit areas, an audit programme might be set for regular
intervals throughout the year.
Difference Between Audit Plan and Audit Programme:
Audit Plan Audit Programme
A detailed outline of the audit strategies, Audit programme is an outline of how the audit is
procedures, timelines, and resources required to to be done, who is to do what work and within
conduct the audit. what time
Covers the following: Covers the following procedures:
Includes: Includes:
– Knowledge of the business – Procedures to verify accounts
– Timing & scope of audit – Document checks
– Control systems – Presentation & disclosure checks
– Coordination – Final report preparation
📘 Identification of Applicable Laws
In India, every business—regardless of size or sector—must comply with multiple laws, rules, and
regulations, which may arise from:
Business structure (e.g., company, LLP, trust),
Business activities (e.g., manufacturing, trading, finance),
128
Business geography (including cross-border operations).
To meet compliance requirements under applicable laws, the management must ensure evidence-backed
adherence to every legal, regulatory, and contractual obligation. This involves adopting a systematic
approach:
1. Inventory of Applicable Laws
o Maintain a detailed, documented inventory of all applicable laws, regulations, and obligations
specific to the organization.
2. Publishing a Compliance Policy
o Develop and publish a comprehensive compliance policy, supported by detailed standards,
procedures, and guidelines.
3. Effective Communication
o Exchange updates on compliance obligations via emails, reports, agendas, minutes, and notes
among stakeholders, such as legal teams, compliance officers, and functional heads.
4. Internal Compliance Reporting-
o Regularly generate internal reports with documented evidence of compliance. Include
management’s assessment and awareness of non-compliance risks.
5. Compliance Assessment and Reviews
o Perform internal audits/reviews to:
Evaluate adherence to laws.
Highlight risks of non-compliance.
Special Considerations for Complex Business Structures
For holding companies, subsidiaries, or joint ventures with varied operations across different geographical
locations, compliance becomes significantly more complex. Requirements will differ based on:
Nature of operations. ⚙️
Location of different operations. 📍➡️🌍
Applicable legal instruments. 📜
Specific sections of relevant laws referred to in those legal instruments. 🔍
Staying Updated with Amendments! 🔄
Keeping pace with changes in laws is a continuous challenge. Companies need a system to:
Monitor updates on compliance requirements. 📰
Track changes in laws and regulations. 📈
Ensure the legal team continuously communicates the impact of these changes on the company,
its holdings, and all geographical areas of operation. ➡️🏢🌍
Support from Regulatory Bodies
Regulatory bodies like MCA (Ministry of Corporate Affairs), RBI (Reserve Bank of India), and SEBI
(Securities and Exchange Board of India) issue periodic updates, including:
129
Master Circulars
Master Directions
Removal of Difficulties Orders
These documents help businesses interpret and implement compliance requirements effectively.
📋 Creation of Master Checklist
Master Checklist Headings: 📂
Entity Operation and Organizations 🏢⚙️
Financial & Non-financial Reporting Requirement 📊📄
Matter of Shareholder and Public Interest 📢🤝
Legal and Regulatory Requirement ⚖️📜
Review of Control Environment ⚙️
1. Entity Operation and Organizations: 🏢⚙️
This section focuses on understanding the fundamental aspects of the company:
Products/Services/Operations: What does the company do?
Geographical Locations: Where does the company operate? 📍
Objects (MOA): What are the company's stated goals? 🎯
Capital Structure & Funding: How is the company financed? 💰
Subsidiaries, JVs, Associates: What other entities are connected? 🔗
Key Managerial Personnel (KMPs): Who are the senior managers? 🧑💼
Promoters & Directors: Who are the key individuals? 🧑💼👩💼
Related Party Transactions: Are there dealings with connected parties? 🤝
Recipients of Products/Services: Who are the customers? 👤
Functional Heads (Audit Responsibility): Who is in charge of the audited areas? 👤
Audit Committee (TOR): What is the structure and mandate of the audit oversight?
Previous Year's Audit Observations: What were the past findings? ⏪
2. Financial & Non-financial Reporting Requirement: 📊📄
This section focuses on the company's disclosures:
Primary Information Sources: Financial statements, directors' report, annual return, websites,
regulatory filings. 📄🌐
Financial Statement Format: Compliance with accounting standards, policies. 📊
Changes Since Last Audit: Any format or policy changes since last audit. 🔄
Non-financial Disclosures: Detailed requirements under legal and regulatory frameworks, including
procedural aspects, limits, eligibility, and criteria on various dates. 📜🔍
3. Legal and Regulatory Requirement: ⚖️📜
This crucial section acknowledges that compliance varies:
Dependence Factors: Nature and status of the company, business activity, area of operation,
geographical location. 🏢🏭📍
Applicable Laws: Relevant central, state, and local laws, rules, and regulations.
Detailed Compliance: Section-wise requirements, highlighting amendments during the audit period.
🔍🔄
130
4. Matter of Shareholder and Public Interest: 📢🤝
This section considers the broader stakeholders:
Indicators of Interest: Public deposits, loans/advances, dividends, CSR activities, small shareholder
interest, media attention. 🏦💰🌱📰
5. Review of Control Environment: ⚙️
This section assesses the overall control framework:
Auditor's Conclusion: Reliability and justifiability of the control environment based on company size
and operations. 🤔
Fundamental Doubts: Reporting any significant concerns about the effectiveness of prevailing
systems and controls to the entity and considering them during the audit. ⚠️
Checkpoints: Management characteristics, philosophy, operation style, commitment, accurate
disclosures and reporting, along with:
o Organizational structure. 🏢
o Culture & ethics of the organization
o Senior management control methods. 🧑💼
o Management's ability to control operations. 💪
o Methods of assigning authority and responsibility. ➡️
o Supervision and monitoring. 👀
o Management commitment to reliable accounting systems. ✅
✅ Master Checklist for Secretarial Audit
(Listed Company – Automobile Sector – Paid-up Capital ₹5000 Cr)
1. Corporate & Organizational Information
Area Checks
👥 Company Profile ☐ Verify CIN, name, registered office, business objects
(MoA)
Business Activity ☐ Confirm nature: manufacturing automobiles (NIC Code)
📈 Capital Structure ☐ Paid-up capital: ₹5000 Cr — verify shareholding pattern
📂 Group Structure ☐ Details of Holding, Subsidiaries, JVs, Associates
🧾 Auditors & Professionals ☐ Statutory, Internal, Cost, Secretarial Auditors appointed
2. Board Structure & Functioning
Area Checks
🧑⚖️Composition ☐ Board structure complies with Sec 149 (Independent Directors, Women
Director)
📝 Board Meetings ☐ Notice, agenda, quorum, minutes as per Sec 173 & SS-1
👨💼 Committees ☐ Audit, NRC, SRC, CSR, Risk Mgmt — check constitution, frequency & minutes
🔄 Changes in KMP ☐ Appointments, resignations, disclosures as per Sec 203
🧾 Registers ☐ Maintain statutory registers (189, 170, etc.) and updates
3. Secretarial Standards & Disclosures
Area Checks
📜 Secretarial Standards ☐ SS-1 (Board Meetings) and SS-2 (General Meetings)
compliance
📆 Annual Return ☐ MGT-7 & MGT-7A filed correctly
131
📄 Director’s Report ☐ Check mandatory disclosures under Sec 134
🧩 CSR Compliance ☐ Applicability under Sec 135, disclosures, CSR policy & report
General Meetings ☐ Convening, quorum, e-voting, minutes (SS-2 compliance)
4. Statutory & Regulatory Compliance
Law/Area Specific Checks
📊 Companies Act, 2013 ☐ All filings on MCA portal (AOC-4, MGT-7, PAS-6, etc.)
💼 SEBI (LODR), 2015 ☐ Compliance with Regulations 17 to 27, disclosures in Annual
Report
🧾 SEBI (PIT), 2015 ☐ Trading window closure, UPSI handling, code of conduct
📈 SEBI (SAST), 2011 ☐ Check if any acquisition or trigger of disclosures occurred
🏦 FEMA / RBI ☐ ODI/FDI/ECB compliance (if applicable)
🏭 Sectoral Laws ☐ Motor Vehicle Act, Environment Laws, Safety Regulations
📃 Legal Updates ☐ Verify amendments, master circulars, notifications compliance
5. Disclosure & Reporting
Area Checks
🌐 Website Disclosure ☐ Company policies, CSR, Annual Reports, shareholder
info
📋 Shareholding Reports ☐ Reconciliation of Share Capital Audit, BEN-2, DIR-3 KYC
XBRL Filings ☐ If applicable, financials in XBRL format
📊 Insider Trading & UPSI ☐ Maintain SDD (Structured Digital Database)
6. Financial & Operational Oversight
Area Checks
💰 Loans & Guarantees ☐ Sec 185, 186 compliance
💸 Related Party Transactions ☐ Sec 188 — approvals, disclosures, audit committee
review
🏭 Cost Records ☐ Maintenance of cost records & cost audit (if applicable)
💼 Contracts & Agreements ☐ Verify major operational & vendor contracts
🔁 Change Management ☐ Any change in capital, registered office, auditors
7. Stakeholder & Public Interest
Area Checks
📤 Dividend Compliance ☐ Sec 123, payment timelines, IEPF transfers
💬 Investor Grievances ☐ Review SCORES filings and grievance redressal
🤝 Shareholder Meetings ☐ AGM notice, explanatory statement, resolutions
passed
🌱 ESG / CSR ☐ Evaluate CSR policy & compliance reports filed
8. Other Key Verifications
Area Checks
🧪 Internal Audit ☐ Applicability & reports as per Sec 138
📁 Secretarial Audit Report ☐ Verify previous audit reports & follow-up on observations
🧾 Maintenance of Records ☐ Minutes books, registers, policy documents in proper
order
132
🔒 Data Protection ☐ Evaluate privacy practices (esp. if IT integrated)
📘 Working Papers & Maintenance of Work Sheet
Audit working papers are documents and records created and retained by an auditor to:
Record procedures performed
Show evidence collected
Support the audit opinion
Document audit team roles, findings, and conclusions.
📋 Purpose & Significance
Audit working papers help in verifying:
Audit was properly planned & executed
It was supervised & reviewed
Evidence gathered is sufficient & appropriate
Judgements and conclusions are well-supported.
📄 Essential Characteristics:
Should be complete, concise, and organized for usability.
Must include only essential details relevant to audit procedures.
Unnecessary working papers should be removed.
🔎 Contents of Working Papers:
Planning documents and audit programs.
Internal control questionnaires, flowcharts, checklists.
Notes and minutes from interviews.
Organizational data (charts, job descriptions, process charts).
Results of control evaluations, tests of transactions, and analytical reviews.
Copies of important documents, letters of confirmation, and representation.
Audit reports, management responses, and audit correspondence.
👀 Special Considerations:
1. Scanned Documents:
o Must reference the source and purpose if not explained elsewhere.
2. Tick Marks:
o Should be consistent within a work paper; explanations must be documented or provided in a
legend.
3. Cross-Referencing:
o Links information across working papers for clarity and completeness.
o Only the primary working paper is cross-referenced to procedures; supporting papers are
linked to the primary. Helps link audit procedures to supporting work papers, ensuring proper
documentation of results and conclusions.
o Used to verify data accuracy and completeness.
🔑 Ownership of Working Papers:
Audit working papers are the property of the auditor, not the client.
The client cannot demand custody but may receive extracts at the auditor's discretion.
133
📂 Standard Set of Audit Working Papers Includes:
1. General File:
o Contains key audit information covering planning, reporting, and comments for future audits.
o Includes draft and final reports and audit responses.
o Audit responses will also be included in the file.
2. Work Paper File:
o Detailed audit procedures and working papers that explain the steps taken to achieve audit
objectives.
3. Future Audit Considerations:
o Auditors are encouraged to develop and document future audit ideas during the course of
their work. This enhances quality of future work.
📘 Types of Working Papers
1. Permanent File
The permanent file usually contains documents and matters of continuing importance of clients’ business
which will be required for more than one audit.
Contents of the Permanent File
A. Statutory & Legal Documents:
Memorandum of Association (MOA)
Articles of Association (AOA)
Certificate of Incorporation
Registrations under various laws
B. Long-term Contracts/Records:
Engagement letter, board resolutions
Royalty agreements, legal contracts
Communication with previous auditor
C. Organizational Details:
Company’s addresses, work description
Organizational chart
List of books, records & signatories
D. Background Information:
Outline history of the company
Significant ratios/trends
Internal controls (notes, flowcharts, questionnaires)
Group structure: holding/subsidiary/associates
List of advisors (bankers, brokers, legal, etc.)
2. Current Audit File
This file contains information relating to the audit of the current period. Typical Inclusions:
Appointment letter for current year (with audit scope)
Board/management meeting extracts
List of responsible officials with contact info
134
Secretarial/Financial Audit Reports (current & previous year)
Follow-up actions on past audit findings
Audit plan/program for the year
Company communications
Representations and confirmations received.
Working Paper Review
The review process ensures that audit working papers are accurate, complete, and relevant to the audit
findings. The key objectives of the review process include verifying relevance, supporting audit findings, and
ensuring proper documentation of conclusions.
Steps in the Working Paper Review Process
1. Check adherence to working paper guidelines and office standards.
2. Ensuring the procedures align with and achieve the audit objectives.
3. Verifying that the working papers support the procedures performed and that all planned
procedures were completed.
4. Ensuring the working papers justify the conclusions presented in the audit report.
5. Confirming communication with management and recording their responses and resolutions.
6. Maintaining a record of the review process and any issues identified.
Filing and Protection of Working Papers
1. Confidentiality:
o Working papers are confidential and the property of the auditor.
o They must be protected from unauthorized access, use, or review.
2. In-Process Control:
o While conducting fieldwork, auditors should secure working papers to prevent any
unauthorized removal, substitution, or alteration.
Retention Policy
1. Ownership:
o All working papers belong to the auditor.
2. Retention Period:
o Working papers must be retained in accordance with legal requirements.
o Ensure compliance with applicable laws and regulations regarding document retention.
Identification of Events & Corporate Actions for Compliance Review
Auditors must verify compliance for key events and actions, especially through statutory filings during
audit planning. Below is a categorized breakdown:
🔁 Restructuring & Capital Changes
1. Acquisition, merger, demerger, sale of units
2. Issue, buyback, consolidation, or reissue of securities
3. Share split, forfeiture, or changes in securities structure
🏦 Board Decisions & Financial Events
4. Board meeting outcomes:
135
o Dividend decisions
o Bonus shares issuance
o Fundraising or capital changes
o Delisting
o Financial results approval
📃 Agreements & Corporate Control
5. Shareholder, JV, or control-impacting agreements
6. Fraud/defaults/arrest involving promoter/KMP
7. Changes in directors, auditors, KMP, compliance officers
Regulatory & Legal Actions
8. Appointment/discontinuation of share transfer agents
9. Debt restructuring / One-time settlement
10. Insolvency cases / winding-up petitions
11. Notices, resolutions, circulars to stakeholders
12. General meeting proceedings (AGM/EGM)
13. MOA & AOA amendments
🏭 Operational Developments
14. Start/postponement of commercial operations
15. New business line, closure, tie-ups
16. Capacity additions or product launches
17. Significant contracts (non-routine)
Compliance Triggers
18. Disruption due to natural disaster/strike/etc.
19. Regulatory framework changes
20. Major litigation or disputes
21. Fraud/default by employees or directors (non-KMP)
22. Stock options (ESOP/ESPS)
23. Guarantees or sureties given
24. Licensing changes
25. Any other significant developments (e.g. tech changes, patent expiry, accounting policy changes).
🔎 Testing Methods Used During Audit Procedures/ Types of Internal Control Tests (5)
1. Inquiry: Asking the Right Questions ❓
Description: Involves asking questions to individuals like managers, accountants, and key staff to gain
insights into processes and controls.
Strength: Simple and helps in understanding business processes and identifying potential risks.
Limitation: Considered a weaker form of evidence as it relies on the truthfulness and accuracy of the
interviewee.
Example: An auditor might ask the business owner about the storage of financial and data security
records. While the response is noted, it's not accepted as sole confirmation and is used to guide further,
more reliable testing.
2. Observation: Seeing is Believing (Sometimes!) 👀
136
Description: The auditor observes activities, procedures, and conditions to verify operations when no
documentation is available.
Strength: Directly confirms stated controls through visual inspection.
Example: Watching an employee unlock a drawer to retrieve secured records or observing IT system
configurations.
3. Examination or Inspection of Evidence: Digging into Documents 📄🔍
Description: Involves scrutinizing records, documents, and tangible assets to determine if controls are
consistently performed and properly documented.
Strength: Reliable to ensure controls are consistently applied and documented.
Limitation: Requires access to relevant and authentic documentation.
Example: Checking if data backups are regularly scheduled or inspecting visitor logs for compliance.
4. Re-performance: Doing it Yourself 🔄⚙️
Description: The auditor manually performs a control to validate its effectiveness, often used when
other methods fail to provide sufficient assurance.
Strength: Considered the strongest form of evidence to test the effectiveness of controls.
Limitation: Time-consuming and used less frequently.
Example: Re-performing an automated calculation to verify accuracy or testing a sample of internal
audit work.
5. Computer-Assisted Audit Technique (CAAT): Leveraging Technology 💻📊
Description: Utilizes software tools to analyze large volumes of data for irregularities, trends, or
fraudulent activities.
Strength: Efficient for handling extensive datasets and uncovering patterns that may indicate errors or
fraud.
Limitation: Requires technical expertise and appropriate tools.
Example: Running scripts over ledgers or databases to identify anomalies.
Audit Sampling
Audit sampling is a technique where auditors select a subset of items from the total population of
transactions or records to conduct an audit. This method allows auditors to form conclusions and issue audit
opinions without having to check every single item, which saves time and resources.
Purpose of Audit Sampling: Why Sample? 🤔
Audit sampling is essential for all types of audits (internal, external, government) to:
Demonstrate full audit completion in accordance with auditing standards. 📜
Gather sufficient evidence to form a conclusive audit opinion. 🔎
Reduce the resources (time, cost, effort) required for the audit. 💰
Provide a basis for auditors to issue a well-supported audit opinion. 👍
Detect errors or fraud that may exist within the population. 🚨
Serve as a tool for investigation when potential issues arise. ♂️
Importance of Audit Sampling: Why Not Check Everything? 🤷♀️
Auditing every single item in financial statements is often impractical due to:
High cost. 💰⬆️
Significant resource consumption. ⏳⬆️
137
Extensive time requirements. ⬆️
Two Forms of Sampling: ✌️
1. Statistical Audit Sampling: 📊🎲
Method: Employs statistical methods, such as random sampling, to select items for verification.
Application: Recommended when dealing with a large number of items or transactions.
Example: A company has 100 inventory transactions. Using statistical sampling, the auditor selects 10
items randomly, and each item has an equal chance of being selected.
Benefit: Allows auditors to form an audit opinion without checking all transactions, saving time and
resources while still providing a statistically sound basis for their conclusions.
2. Non-statistical Audit Sampling: 👨⚖️🎯
Method: Items are not chosen randomly but based on the auditor's professional judgment.
Inference to Population: The results of testing the selected items are not used to formally infer
conclusions about the entire population.
Selection Criteria: Auditors might choose items based on factors like:
o Value of items: Selecting high-value items (e.g., > ₹10 lakhs).
o Specific information: Focusing on items related to a particular company or event.
Example: In the inventory transaction scenario, the auditor might choose to examine the ten most
expensive items or ten items related to a specific supplier based on their judgment of potential risk.
Internal Controls Testing
Internal controls are processes and procedures designed to ensure:
Business continuity
Prevention of fraud
Accuracy and integrity of financial reporting
🔍 Testing of internal controls evaluates whether these controls are properly functioning to detect or prevent
material misstatements.
🎯 Purpose of Testing Internal Controls
1. Shorten the audit process
If controls are proven effective, fewer substantive tests are needed.
2. Provide audit evidence
In situations where substantive procedures alone are insufficient to provide enough evidence of
compliance, effective internal controls can offer that additional assurance.
📌 Control Risk Outcomes:
✅ If controls are effective → Low control risk
❌ If controls are weak or ineffective → High control risk, requiring more audit work
Substantive Testing:
Substantive testing is an auditing method used to detect errors or material misstatements in financial
statements and underlying records. It helps auditors form a reliable opinion on whether financial reports are
accurate, complete, and fairly presented.
📌 It provides direct audit evidence supporting management's assertions about financial information.
138
👥 Who Performs Substantive Testing?
Internal Auditors: Conduct routine testing during the year to maintain system integrity.
External Auditors: Typically perform this at year-end during the formal audit process.
🔁 How Substantive Testing Works – Step-by-Step
1. Company Assertions
Companies make five key assertions during audits:
Presentation/Disclosure: Financial info is clearly and fairly presented.
Accuracy/Valuation: Numbers are correct and appropriately classified.
Occurrence/Existence: Assets/liabilities exist as stated.
Obligations & Rights: Company owns its assets and owes its liabilities.
Completeness: Nothing is left out—includes all transactions and disclosures.
2. Auditor’s Plan Creation
Auditor designs a test plan targeting the above assertions using:
Categories of Auditing Processes:
Inquiry and Confirmation: Asking questions and verifying responses.
Observation: Watching operations or controls in action.
Inspection: Reviewing documents and records.
Recalculation: Re-performing calculations to confirm accuracy.
Analytical Procedures: Compare data trends or ratios.
🔍 Three core testing activities:
Examine journal entries and physical adjustments
Match financial statements with accounting records
Test account balances, transactions, and disclosures
3. Reporting Audit Results
After completing the tests, the auditor writes an official report outlining any findings (errors or
misstatements) and shares it with management. They will also issue their opinion on the accuracy of the
financial statements.
What Happens When Substantive Testing Finds an Error? ⚠️
If errors are found, the auditor may require further testing. A management letter summarizing the errors is
typically issued to the company and the audit committee. Errors or misstatements often occur due to:
Detection Risk: External auditors fail to detect an error during audit procedures. 🧑💼➡️❌
Control Risk: Internal auditors or internal record systems fail to identify or fix an error. 🏢➡️❌
Inherent Risk: Initial errors are not detected when the financial process and reporting begin. ⚠️➡️❌
Examples of Substantive Testing Procedures (CRIPR)
Auditors use various substantive procedures to detect and confirm the accuracy of financial records. These
include:
139
1. Verifying approved dividends by reviewing board minutes.
2. Confirming accounts payable balances by contacting suppliers.
3. Confirming accounts receivable balances by contacting customers.
4. Confirming loan balances by contacting lenders.
5. Confirm fair value of assets acquired via merger with experts.
6. Physically matching fixed asset records to the actual assets.
7. Observing the physical inventory count at the end of each period.
8. Confirm cash balances via bank confirmation.
Audit Trails:
An Audit Trail is a record that tracks all transactions, changes, and edits made in a company’s financial
system. It helps to ensure that all activities can be traced back to the source, providing transparency and
accountability. The audit trail includes details like who made the changes, when the changes were made, and
what changes were made.
Types of Audits Involving Audit Trails
1. Internal Audit: Conducted by the company’s internal staff to check if the books are maintained
correctly.
2. External Audit: Conducted by external auditors to identify any discrepancies or irregularities in the
financial records.
3. Government Audit: Government agencies check for mismanagement or tax evasion.
MCA Audit Trail Rules (Effective from 1st April 2023)
As per MCA Notification (24 March 2021) under Rule 3 of Companies (Accounts) Rules, 2014:
📌 Applicable to all companies (except proprietorships, partnerships, LLPs) that use accounting software.
🔒 Mandatory Requirements:
Software must record edit logs for each transaction
Must capture date/time of changes
Must identify the user who made the changes
Audit trail cannot be disabled.
⚙️How Does Audit Trail Work?
Audit trails capture key information for each access and change, including:
📌 What was changed (transaction details)
📌 Who made the change (user ID)
📌 When it was done (date and time)
📌 If deleted, that too must be recorded
Example:
If a transaction is entered into accounting software:
Original entry is logged
Any edits (like amount or name change) are tracked with timestamp and user ID
Even deletions are recorded
📌 Triple W Approach: When (time), Who (user), What (transaction/data change)
140
🎯 Purpose of an Audit Trail
Record Keeping: Provides a traceable path of every transaction, which can be reviewed if needed.
Error Detection: Helps identify the cause of discrepancies and fraudulent transactions.
Prevent Blind Spots: Ensures there are no gaps in data that could lead to undetectable errors.
Regulatory Compliance: A mandatory requirement for companies to maintain records and comply
with regulations.
⭐ Benefits of an Audit Trail
1. Increased Transparency: Provides a clear record of all transactions, making it easier for regulators
and stakeholders to monitor company activities.
2. Improved Accuracy: Helps prevent errors in financial reporting by ensuring all records are accurate.
3. Accountability: Ensures that employees and the company are responsible for their actions.
4. Regulatory Compliance: Ensures that companies follow laws related to financial reporting and
governance.
5. Company Valuation: A clean audit trail can improve the company’s credibility, helping in fund
generation through loans or capital raising.
Analysis of Audit Findings
Audit Findings: A written summary of all non-conformances or issues identified during an audit.
o These findings should be reviewed with the affected department head and signed off to verify
acceptance and responsibility for any changes.
Plan of Action:
o All identified issues (non-conformances) must be corrected promptly.
o A corrective/preventive action process should be used to track these issues.
o Once corrective actions are in place, auditors should review the effectiveness of the changes.
Lesson: 11 (Audit Process and Documentation)
Introduction: Audit Evidence and Standards
Auditors must plan and conduct audit procedures to gather sufficient and appropriate audit evidence to
form a reasonable basis for their opinions.
Sufficiency refers to the quantity of audit evidence needed. It depends on factors like:
o The strength of internal control systems.
o The level of risk involved in the audit.
o Higher risk necessitates more evidence, while better-quality evidence reduces the need for
additional corroboration.
Appropriateness pertains to the quality of the evidence, ensuring it is both:
141
o Relevant: Connected to the matter being audited.
o Reliable: Trustworthy enough to support conclusions.
Poor-quality evidence, even in large quantities, cannot fulfill the sufficiency requirement.
Objective of CSAS-2: 🎯
The standard aims to establish principles for an Auditor:
(i) To conduct the audit according to a specified audit process.
(ii) To maintain documentation that provides:
(a) A sufficient and appropriate record forming the basis for the Auditor’s Report.
(b) Evidence that the audit was planned and performed in compliance with applicable Auditing
Standards and statutory requirements.
Applicability
Effective and recommendatory: For engagements accepted on or after 1st July 2019.
Mandatory: For engagements accepted on or after 1st April 2021.
Key Definitions under CSAS-2
1. Audit Documents:
Working papers or records created and gathered by the auditor during the audit process.
o Examples include:
Audit plan.
Letters of representation or confirmation.
Abstracts of client documents.
Records of procedures, tests, and analyses.
o Format: May be physical or electronic.
2. Audit Evidence:
o Relevant information and documents collected during the audit to support Auditor’s opinion.
o Forms the foundation for the auditor’s opinion.
Scope of CSAS-2
CSAS-2 is applicable to the auditor who is undertaking audit under any statute and deals with
responsibilities and duties of auditor with respect to Audit Process in conducting audit and maintaining
proper audit documents.
Overview of the Audit Process
The audit process is conducted in three broad phases: Planning, Execution, and Reporting.
1. Audit Planning
Planning lays the foundation for an effective audit. It includes:
📌 Key Actions in Audit Planning:
1. Understanding the company and its operations
2. Establishing audit objectives and scope
142
3. Determining Materiality
4. Risk Assessment
5. Preparation of Audit Plan
6. Preparation of Detailed Audit Programme.
2. Execution of Audit
Effective audit execution relies on the audit plan and the efficiency of the audit team.
📌 Key Actions in Audit Execution:
1. Identification of material events
2. Sampling of various transactions/items
3. Sampling for testing of controls
4. Sampling for substantive test of details
5. Performing controls testing procedures
6. Performing analytical procedures
7. Performing substantive tests
8. Review of working papers
9. Management discussion on draft report.
3. Reporting Phase
In the reporting phase, the auditor evaluates the audit results, draws conclusions, forms an opinion, and
prepares the audit report. It includes:
📌 Key Actions in Reporting:
1. Understanding the Auditee and Operations
2. Understanding Legal Requirements and Applicability
3. Assessment of Internal Controls and Risk Areas
4. Risk Assessment
5. Audit Approach and Evidence Identification
6. Performing Audit Procedures
7. Reviewing Working Papers
8. Audit Conclusions
9. Forming an Opinion.
Audit Planning: A Comprehensive Overview
📌 Audit planning refers to the process of designing an audit to ensure:
Effective performance
Within defined scope
Based on audit engagement terms
📝 It includes forming an overall audit strategy and laying out processes and activities to improve audit
quality.
🔷 Purpose of Audit Plan
To conduct the audit in an efficient, effective, and timely manner
To focus on significant areas and use audit resources wisely
To ensure sufficient & appropriate audit evidence is gathered
143
To document the audit process properly (as audit working paper).
🔷 Key Elements of Audit Plan
📌 What, Where, Who, When, and How:
What are the audit objectives?
Where will audits take place (locations/processes)?
Who is on the audit team?
When will audits occur?
How will audits be executed?
📌 Should include:
Audit schedule
Procedures & timing
Allocation of audit resources
Sample sizes and basis of selection
Materiality level
Risk assessment.
Key Aspects of Audit Planning: ⚙️
Audit planning refers to the preparation done by the auditor before beginning the actual audit work. It
includes understanding the nature of the entity, identifying key risk areas, allocating resources, and
scheduling audit tasks.
Audit planning involves establishing and developing an overall audit process, including but not limited to:
1. Seeking previous audit findings and observations from Management and the Previous.
2. ⚠️ Determination of subject matters and audit areas requiring special attention, when considered
necessary.
3. Identification of broad audit areas.
4. 💰 Risk Assessment and Materiality.
5. Preparation of audit schedule.
6. Allocation of audit resources for the audit.
7. Audit technique.
Audit Approach: Reliance vs. Substantive ➡️🔎
The audit approach can be:
Reliance or Systems-based approach: Adopted when the preliminary assessment indicates robust
controls and proper procedures are consistently followed.
Substantive approach: Adopted when the preliminary assessment reveals poor controls, or testing
shows inconsistent or ineffective control operation during the audit period, or when controls are not
tested (due to resource constraints, lack of expertise, etc.), even if deemed good. 🔎❌
🔷 Audit Approach Decision Based On:
Materiality
Inherent Risk Assessment
Evaluation of Internal Controls.
144
Essentials of Audit Planning
Effective audit planning is crucial for gathering sufficient and appropriate evidence in a cost-efficient manner
to support the audit opinion. Auditors should consider the following essential points:
1. 🎯 Quality Assurance
➤ Audit should be economic, efficient, effective, and timely
2. 🧑🏫 Training & Communication
➤ Staff should be trained on quality control policies, responsibilities, and hierarchy
3. 🔁 Flexibility
➤ Plan should be adaptable to changes with approval from team leader
4. 🔗 Clubbing of Related Steps
➤ Inter-related audit steps should be grouped together for coherence
5. 📄 Documented Audit Plan
➤ Must be prepared and retained as part of audit working papers
6. ✅ Reaching Conclusion
➤ Ensure data collection and analysis are sufficient for reliable audit conclusions.
Key
Components of an Audit Plan
1. 📌 Introduction
➤ Brief overview of the audit being conducted
2. 🏢 Audit Field
➤ Area/sector under audit, applicable regulatory framework, recent changes affecting audit
3. 🎯 Audit Objectives
➤ Define goals based on type of audit (e.g., compliance, operational)
4. 📍 Audit Coverage
➤ Period covered, locations visited, control systems tested, sample details
5. 📊 Materiality
➤ Assessed by value, nature, and context
6. ⚠️Risk Assessment
➤ Includes changes in environment/control systems; evaluate inherent and control risk
7. 🧪 Audit Approach
➤ Procedures to gather audit evidence; level of reliance on internal controls vs. substantive testing
8. 👥 Organisation of Audit Work
➤ Audit team, use of experts, timelines, documentation (possibly electronic).
🔁 Modifications and Updates
Audit plan is dynamic and must be updated based on:
145
o New audit evidence
o Unexpected events
o Regulatory or internal changes (e.g., management, business plans)
All changes must be documented in the audit file with reasons
🧠 Professional Skepticism in Audit Planning
The auditor must plan the audit with professional skepticism, maintaining an objective and questioning
mindset.
It enhances the effectiveness of procedures and reduces the risk of reaching inappropriate conclusions.
Risk Assessment in Audit Engagement as per CSAS-2 Para 2
Risk: A risk is the threat or possibility that an action or event may adversely or beneficially affect the
organization's ability to achieve its objectives.
Risk Assessment: A systematic process of evaluating the potential risks associated with a planned activity or
undertaking. It involves identifying, analyzing, and evaluating risks to determine their significance and
potential impact.
Risk assessment of the auditee must consider:
📊 Industrial & business environment
➤ Includes regulatory changes, judicial orders, compliance and disclosure obligations
🏢 Organisational structure
📜 Compliance requirements.
Auditor’s Evaluation Focus
The auditor should examine:
1. ✅ Internal control systems and processes
➤ Adherence to laws, rules, regulations, standards, constitutional documents
2. 🔄 Changes in compliance team
➤ Frequency of staff changes or attrition
3. 🔍 Level of transparency, prudence and probity
4. ⚠️Identification of high-risk areas.
How to Assess Risk
✔️Understand objectives, KPIs, controls through meetings with key executives
✔️Review risk assessments made by management, internal auditors, or external experts
✔️Analyze risk mitigation policies and procedures.
Tasks Related to Materiality and Risk Assessment: 📝
Key Audit Requirements
1. 🏭 Identify business risks for processed food industry
2. ⚙️Understand inherent and business risks for new client
3. 📉 Assess business risk and risk of material misstatement
4. 💰 Determine planning materiality
5. 🧾 Justify and document the materiality decision.
⚠️Auditing Risk: Accepting a Degree of Uncertainty
146
Auditing risk signifies that an auditor acknowledges and accepts a certain level of uncertainty while
performing audit work. This means there's a possibility that the audit opinion expressed might be incorrect.
To maintain the audit process's purpose and credibility, only a very small degree of audit risk is considered
acceptable.
Three Components of Audit Risk
Audit Risk = Inherent Risk × Control Risk × Detection Risk
1. Inherent Risk: The likelihood that a transaction or class of transactions contains a material
misstatement without considering controls. Example: Genuineness of related party transactions.
2. Control Risk: The risk that internal controls fail to prevent, detect, or correct material
misstatements on time. Example: Delay in filing statutory forms.
3. Detection Risk: The risk that an auditor’s procedures fail to identify a material misstatement.
Example: Overlooking Secretarial Standard compliance during e-form certification.
Audit Risk and Materiality
Inverse Relationship:
o When materiality is high, auditors are willing to accept a higher level of audit risk, as minor
misstatements are unlikely to affect stakeholders' decisions.
o When materiality is low, the auditor reduces audit risk to ensure no significant misstatements
go undetected.
Impact on Audit Procedures:
o Higher Materiality: Fewer, less detailed audit procedures may be sufficient.
o Lower Materiality: Requires more rigorous testing and evidence gathering.
🧭 Risk Assessment Process Overview
1. Identify Key Risks: Based on financial significance, staff turnover, org changes, past audits, etc.
2. Evaluate Risks: Use interviews, surveys, and analysis (e.g., COSO ERM, PESTLE factors: Political,
Economic, Social, etc.)
3. Prioritize Identified Risks: Score departments based on inherent risk, likelihood, and impact.
4. Map Risks to Control Objectives: High-risk areas get mapped to specific internal audit controls.
5. Develop Internal Audit Plan: Define scope based on risks; validate and present to Audit Committee.
6. Ongoing Review: Adjust plan based on events throughout the year.
Sample Internal Audit Risk Assessment Questionnaire
General Information
a. Organizational Chart
b. Risk Assessment completed during the last year
c. Reports or summaries of reviews conducted either internally or by external auditors, including any
recommendations and outcomes.
Risk Assessment Questions
1. What obstacles do you face in achieving your goals and objectives?
147
Strategic
Financial
Operational
Compliance
Reputational
2. What are the main areas of risk your unit is facing? (Like financial risks, legal or regulatory issues,
technology failures, or human resource challenges.)
3. What controls do you have in place to manage these risks?
4. What is the worst thing that has already happened in your unit?
5. Are there any areas within your unit or on campus that you are currently concerned about?
6. Are you aware of any fraud or abuse in your unit?
7. What recent events have occurred in this unit? (Like new leadership, program launches, staff turnover, or
significant operational shifts.)
8. Have you obtained the desired outcome in recent years?
9. How do you measure your performance?
10. Who are your key stakeholders or external constituents?
11. How can Internal Audit meet your expectations?
Information About the Auditee and the Audit Process
Information About the Auditee
According to CSAS-2 para 3, the auditor must obtain relevant information about the auditee for conducting
the audit and forming an opinion. This information should include:
1. Nature of Business
2. Sector and Government/Regulatory Policies
3. Business Size including geographical locations
4. Organizational Structure
5. Corporate Structure such as associates, joint ventures, and subsidiaries
6. Laws and Regulations applicable
7. Registrations and Permissions obtained
8. Court & Regulatory Orders enforced
9. Media Reports.
Audit Checklists
As per CSAS-4 para 4, auditors should use systematic and comprehensive checklists to carry out the audit
and verify compliance requirements. These checklists help ensure no compliance point is overlooked during
the audit process.
Characteristics of Effective Audit Checklists:
Ensures Scope Adherence: Ensures that the audit scope is followed strictly.
Promotes Planning: Helps in the overall planning and timelines of the audit.
Ensures Consistency: Ensures a comprehensive, consistent, and focused audit approach.
Avoids Duplication: Prevents repeated data verification and unnecessary information.
Memory Aid: Serves as a repository for notes and findings, assisting future reference and audit continuity.
148
Audit checklists must be updated periodically to reflect changes in the audit scope and improve
effectiveness. It’s also essential to train the audit team on how to use these checklists to obtain the most
accurate and useful information.
Audit Findings Classification
1. Non-conformity (Major):
o Definition: Major deviations from binding requirements like laws, regulations, or other external
requirements.
o Impact: These deviations can lead to legal consequences, affect occupational safety, health, the
environment, or finances.
o Action Required: Immediate corrective actions, cause analysis, deadlines, and responsible
persons must be identified, along with follow-up procedures.
2. Non-conformity (Minor):
o Definition: Minor or individual deviations from requirements.
o Impact: These have minor consequences, such as limited impact on health, safety, or finances, with
little legal consequence.
o Action Required: Corrective action, cause analysis, deadlines, and responsible persons must be
identified, along with follow-up actions.
3. Opportunity for Improvement:
o Definition: These are instances of best practices or situations where improvements can be made,
but no immediate negative effects are recognized.
o Impact: Positive potential for improving processes, procedures, or overall efficiency.
o Action Required: Evaluate and provide feedback on further actions that can be taken to enhance
performance.
Collection and Verification of Audit Evidence (CSAS-2 para 5)
The auditor is required to gather complete, relevant, and necessary evidence to support the audit opinion.
Various techniques are used to obtain this evidence, which include the following methods:
Methods of Collecting Audit Evidence
1. Testing, Interviews, and Analysis
o The auditor will assess whether controls identified in the preliminary review are functioning as
described by the auditee.
o This phase may involve fieldwork like interviewing staff (formally or informally), reviewing
procedure manuals, and analyzing compliance with policies, procedures, and laws.
o The auditor should test controls, assess compliance, and analyze any findings that emerge to
incorporate them into the audit report.
2. Documents/Records Scrutiny
o This is the primary method of gathering evidence, involving the examination of various documents
such as board resolutions, meeting agendas and minutes, notices, registers, reports, and procedure
manuals.
149
o Due to time and resource constraints, the auditor may not check every document. Instead, they may
use sampling methods to select a representative number of documents for scrutiny.
o Sampling ensures the audit covers enough data while managing uncertainty.
3. Questionnaires
o Auditors may issue formal questionnaires to relevant personnel within the auditee organization to
collect additional information and evidence.
o This helps in obtaining specific responses and clarifications directly from the involved parties.
4. Third Party Confirmation
o This method involves independently confirming certain information with a third party, such as a
registrar, transfer agent, or another external agency.
o Third-party confirmation helps to verify details that cannot be directly confirmed through internal
documents.
5. Analytical Procedures
o Analytical procedures involve comparing data across different records to identify inconsistencies
or unusual fluctuations.
o This can help in identifying areas that require further investigation or clarification, especially when
relationships between data points appear inconsistent.
✔️The Auditor must continue collecting and evaluating evidence until fully satisfied that it is sufficient and
appropriate to form a reliable opinion.
✔️All evidence must be assessed against audit criteria and written responses obtained from responsible
officers of the Auditee.
Third Party Confirmation in Auditing
This involves obtaining a direct response from an external party, independent of the auditee, to verify specific
information related to the audit.
Purpose: Third-party confirmation is used to validate information that relates to external parties, such as
transactions or agreements with other entities. For instance, confirming details with a registrar and
transfer agent or other third-party agencies.
When to Use: During the audit, the auditor may encounter circumstances where third-party confirmation
is required. This is particularly useful for significant transactions, related party transactions, or to verify
events outside the normal course of business.
Process: A written request is made to the third party to confirm specific information. The confirmation
can be in the form of a direct written reply (paper or electronic) to the auditor.
Challenges: Obtaining third-party confirmations may sometimes be difficult due to unresponsive parties
or other barriers. In such cases, auditors are advised to plan for alternative audit procedures to ensure
they gather the necessary evidence.
Analysis of Audit Evidence
150
The Auditor shall evaluate the Audit Evidence to arrive at the conclusion. The Auditor shall verify
compliance with applicable laws, rules and regulations and highlight deviations, if any. Further, the Auditor
has to obtain competent, relevant and reasonable evidence to support his judgment as well as conclusions
relating to the audit.
The process of analyzing audit evidence is simultaneous, systematic and an interactive process involves
several key steps:
Steps in Analyzing Audit Evidence:
1. Gather Evidence: The auditor first gathers evidence through appropriate audit procedures.
2. Evaluate Evidence: The auditor then evaluates the evidence in terms of:
o Sufficiency (quantity): Is there enough evidence to form a conclusion?
o Appropriateness (quality): Is the evidence reliable and relevant?
3. Re-assess Risk: Based on the evidence gathered, the auditor reassesses any identified risks and decides
whether further evidence is needed.
4. Resolving Conflicting Evidence: If conflicting evidence is found, the auditor should: Assess credibility of
each piece, decide if more evidence is needed or apply alternate procedures if required.
5. Consider Criteria: The gathered evidence is compared against the criteria previously identified, ensuring
that the evidence is relevant and reliable.
Handling Conflicting Evidence:
If the auditor finds conflicting evidence, where some evidence supports the audit conclusion while other
evidence contradicts it, the auditor should:
Assess the Conflict: Evaluate the extent and credibility of the conflicting evidence.
Gather More Evidence: If needed, the auditor should collect additional evidence or perform
alternative audit procedures to resolve the conflict.
Reach a Conclusion: Based on all the evidence collected, the auditor will make a final judgment and
conclude whether the evidence supports the audit's objectives.
Audit Documentation: Importance and Requirements
Audit documentation serves as evidence of the audit's scope, findings, and compliance with standards.
🔍 Importance of Audit Documentation:
📄 Confirms and supports the Auditor’s opinion and audit report.
Increases efficiency and effectiveness of audit procedures.
📚 Serves as evidence of compliance with applicable laws, standards, and regulations.
📢 Facilitates report preparation, answering queries from Auditee or other authorities.
Aids in planning, supervision, and review of audit work.
📈 Helps in the professional development of the Auditor.
✅ Confirms that delegated tasks were performed satisfactorily.
🔁 Acts as a reference for future audits.
📘 Requirements:
Audit documents should:
✔️Contain sufficient, relevant, and clear information.
✔️Be comprehensive and understandable.
151
✔️Include significant findings and conclusions.
✔️Be usable by another auditor with no prior connection to the audit.
📌 Must be indexed, referenced, and supplemented by working papers.
🔁 Timing:
Documentation must be done throughout the audit process.
Working papers should be detailed and complete, forming a clear audit trail.
Case Law Example: V. Shankar Vs. Securities and Exchange Board of India (2022)
In V. Shankar vs. SEBI (Appeal No. 283 of 2022), it was ruled that a company secretary is responsible for
authenticating documents but not for verifying the legal compliance of an offer approved by the board,
emphasizing the scope of their responsibilities.
Broad Characteristics of Audit Documentation
📌 Characteristic 📄 Meaning/Explanation
✅ Completeness & Should reflect all procedures, evidence, findings, and conclusions accurately.
Accuracy
✍️Clarity & Conciseness Clearly written and to the point—no unnecessary details.
🔁 Complete Audit Trail Must show the step-by-step flow of the audit: from planning to conclusions.
🔍 Ease of Review Should allow others to easily understand the audit process without extra
clarification.
📁 Ease of Reference Should be well-organized and cross-referenced (e.g. to audit plans, reports).
🎯 Relevance Should include only important, pertinent, and useful information.
Legibility & Neatness Especially important when using photocopies—documents must be easy to
read.
Audit Documentation: Categories and Significance of Matters
Audit documentation can be divided into two main categories: Static Audit Documentation and Current
Audit Documentation.
1. Static Audit Documentation:
This type of documentation remains constant over time, and its primary purpose is to maintain key
background information about the Auditee and the audit process. Examples include:
Auditor Appointment Letter
Communication with Previous Auditor
Audited Financial Statements from Previous Years
Management Details: Information about the management team, including key management personnel
(KMP).
Constitutional Documents: Includes documents like the Memorandum of Association (MOA), Articles of
Association (AOA), LLP agreements, Joint Venture (JV) agreements, and Share Purchase Agreements.
Group Structure: Details of holding, subsidiary, associate companies, and joint ventures.
2. Current Audit Documentation:
This documentation relates to the specific audit process and the current year’s work. Key elements
include:
152
Evidence of the Audit Planning Process: Documentation showing how the audit plan was developed,
including risk assessments, scope determination, and objectives.
Documentation showing that the audit work was properly supervised and reviewed at various stages.
Weaknesses in Internal Control Systems
Audit Confirmations: Written confirmations obtained from the Auditee or third parties during the
audit process.
Communication with Third Parties.
Discussion with Management
Significant matters discussed verbally must be documented.
Especially when there is no written record available.
🔍 Significant Matters Include:
High-risk areas.
Situations where audit procedures were difficult to apply.
Matters that may lead to modification in audit opinion/report.
Q: Should discussions with management be documented?
A: Yes, especially for significant matters without written records.
📦 Record Keeping and Retention
📌 Purpose of Record Retention
✅ Comply with statutory or regulatory duties.
Avoid liability due to improper destruction/alteration in legal cases.
⚖️Support or oppose a position in investigation/litigation.
💸 Prevent unnecessary expense and time in case of legal discovery.
🧾 Maintain control over e-discovery processes.
🔐 Ensure confidentiality, protect from leaks to competitors or attackers.
📁 Key Provisions
📝 Requirement Timeline/Details
Collation of Audit Must be done within 45 days from the date of signing the Auditor’s
Documents Report.
Form of Storage Can be physical or electronic.
Retention Period Must be retained for 8 years from the date of signing the Auditor’s Report.
Storage Requirements Must be safe, secure, and easily retrievable when needed.
Lesson: 12 (Forming an Opinion & Reporting)
153
Audit Report and Opinion Types:
1. The auditor concludes the audit by submitting a report that reflects whether the company’s affairs are:
o Conducted in compliance with applicable laws.
o Free from material misstatements.
2. The report must indicate if the opinion is:
o Unmodified: Reflecting no significant issues.
o Modified: Highlighting concerns, which could be:
Adverse: If financial statements are misleading.
Disclaimer: If sufficient evidence is unavailable to form an opinion.
📘 Essentials of Forming an Opinion
The Auditor should evaluate whether the company:
(a) The Company is in compliance with the applicable laws. 📜✅
(b) The Company has followed all procedures as required under the applicable laws. ✅
(c) The Company has adequately disclosed all relevant information about its affairs.
(d) The Company is consistent with the applicable reporting framework. 🔄
(e) The information presented by the company is relevant, reliable, comparable, and understandable. 👍
(f) The company has provided adequate disclosures to enable the intended users to understand the effect of
material transactions and events on the information.
🔎 CSAS-2 vs CSAS-3:
CSAS-2: Evaluation of audit evidence.
CSAS-3: Evaluation of audit conclusions and expressing the written opinion.
Misstatement: What Constitutes an Error or Omission? ❌
“Misstatement” means any information or statement which is false, incorrect, incomplete, misleading or
misrepresents, omits or suppresses a material fact.
Causes of Misstatements:
(a) An inaccuracy in gathering or processing data or information. 📊
(b) An incorrect misinterpretation of the facts. 🤔
(c) An omission of a disclosure.
(d) Management’s judgments that the Auditor considers unreasonable. 🧑💼⚖️
Unqualified / Unmodified Opinion: A Clean Bill of Health ✅
The Auditor shall express an unmodified/ clean/ unqualified opinion when based on Audit Evidence, the
Auditor concludes that:
(a) there is due compliance with the applicable laws in terms of timelines and process; and
(b) the records as relevant for the audit verified by him as a whole are free from misstatement and
maintained in accordance with applicable laws."
Compliance: Two Key Dimensions
154
1. Compliance in Terms of Timelines
This implies that the company has adhered to deadlines specified in applicable laws, acts, rules, or
regulations for completing tasks, filing returns, or performing any mandatory business procedure.
Example: If the law requires the filing of the Annual Return (Form MGT-7) within 60 days of the Annual
General Meeting, and the company files it within this timeframe, it has complied with the applicable law
properly and within the given timelines.
2. Compliance in Terms of Process
This refers to adhering to the prescribed legal procedures or processes for specific business activities or
transactions.
Example: If a company needs to shift its registered office within the same state and RoC, the Companies Act,
2013, lays down a series of procedures (e.g., conducting a Board Meeting for approval, intimating the RoC in
Form INC-22 with required documents within 15 days of the Board Resolution). Following this entire set of
procedures demonstrates compliance "in terms of process.
🧩 In Short:
An Unmodified Opinion = Auditor’s clean signal that:
📚 Records are proper
📅 Timelines are met
⚙️Procedures are followed
🔍 No material misstatements exist.
Modified Opinion: When Things Aren't Entirely Clean ⚠️
A modified opinion is issued by an auditor when there are reservations or qualifications regarding the
compliance of the auditee’s records, documents, or business activities with applicable laws, timelines, or
processes. It signifies that the auditor has identified issues or uncertainties that affect the reliability or
fairness of the auditee’s information.
Modified Opinion: When Things Aren't Entirely Clean ⚠️
The text clearly states that the Auditor should express a modified opinion when they conclude that:
(a) Based on the Audit Evidence obtained, there is non-compliance with the applicable laws in terms of
timelines or process.
(b) Based on the Audit Evidence obtained, the records as a whole are not free from misstatement; or are
not maintained in accordance with applicable laws.
(c) The auditor is unable to obtain sufficient and appropriate Audit Evidence to conclude that there is due
compliance with the applicable laws in terms of timelines and process.
(d) The auditor is unable to obtain sufficient and appropriate Audit Evidence to conclude that the records
as a whole are free from misstatement; or are maintained in accordance with applicable laws.
🧾 Fair Presentation Framework
If info is insufficient or irrelevant, the auditor must:
o Discuss with management.
155
o Consider modifying opinion depending on how the issue is addressed.
📝 Presentation of a Modified Opinion
In the auditor's report, any modified opinion, including disclaimers, must be presented in italics or
bold letters for clarity.
🧷 Board of Directors' Obligation
When a modified opinion is issued:
The Board of Directors, in their report (as per Section 134(3) of the Companies Act, 2013), must
provide a full explanation for any qualification, observation, or remark made by the auditor in their
report.
⚠️Real Case Reference – CHD Developers Ltd. (SEBI Adjudication)
Company received modified opinion but failed to:
o Disclose audit qualifications and their impact.
o File audited financial results within 60 days.
SEBI held the company and its officers liable under SEBI LODR for:
o Misleading stakeholders by claiming unmodified opinion.
o Failing to provide adequate evidence on qualifications.
➡️Penalty imposed by SEBI for regulatory violation.
Categories of Modified Opinions
1. Qualified Opinion
A qualified opinion is issued when the auditor identifies specific areas of non-compliance or limitations but
believes the overall financial statements are still reliable.
Key Features:
o Includes an additional paragraph explaining the areas of concern.
o Reasons for not issuing an unqualified report are clearly stated.
2. Adverse Opinion
An adverse opinion is given when the auditor concludes that the financial statements significantly deviate
from compliance or contain gross misstatements.
Key Features:
o Indicates that the company’s records are not aligned with its objectives, legal requirements, or
accounting standards.
o May signal fraud or serious mismanagement.
o Entities receiving adverse opinions are often required to take corrective actions.
3. Disclaimer of Opinion
156
A disclaimer of opinion is issued when the auditor is unable to form an opinion due to insufficient
information or cooperation.
Reasons for Disclaimer:
o Inaccessibility of records (e.g., geographical issues, regulatory constraints, or natural
calamities).
o Lack of cooperation from the management.
Key Features:
o Indicates that the auditor could not determine if the financial statements present a true and fair
view.
o This is not considered an opinion but rather an absence of one.
📍Emphasis of Matter (EOM)
The Emphasis of Matter (EOM) paragraph highlights significant issues already disclosed in the financial
statements.
Purpose:
o To draw the reader's attention to matters crucial for understanding the company’s affairs.
o Such matters might have either a positive or negative impact on the company’s future.
The EOM does not modify the auditor's opinion but adds clarity to the report.
📝 Examples of EOM Situations:
Category Example
Regulatory Changes Recent amendments or new laws significantly affecting the company’s
compliance or operations.
Technological Changes Adoption of new or disruptive technology that could materially impact
business operations.
Early Application of New Premature adoption of a significant accounting standard (e.g., a new IFRS)
Accounting Standards that broadly impacts the financial statements.
Uncertainty About Future Pending legal disputes or other exceptional uncertainties about significant
Events future developments.
Major Catastrophes Natural disasters or other catastrophes that materially affect the company’s
financial position.
🔸 These matters must already be disclosed in the Financial Statements, Directors’ Report, or Management
Discussion & Analysis.
📌 If not disclosed, auditor may include them in the audit report under EOM.
Materiality in Auditing
Materiality refers to the significance of an amount, transaction, or error in financial records that could
influence the decision-making of users of the financial statements. It is the magnitude of an omission or
misstatement that could alter the judgment of a reasonable person relying on the information.
Determining materiality involves professional judgment, taking into account the quantitative and qualitative
factors and the users’ needs.
1. Inverse Relationship with Audit Risk:
157
o Higher materiality = Lower audit risk
o Lower materiality = Higher audit risk
2. Dynamic Application:
Materiality is used during:
o Planning and performing the audit.
o Evaluating conclusions and forming opinions.
Principles for Determining Materiality
Principle Meaning Application
✅ Completeness Consider all relevant audit Auditor must not ignore or cherry-pick
evidence supporting documents
🧠 Objectivity Apply professional judgement Auditor must be impartial and ensure
and skepticism factual correctness
Timeliness Report should be issued within Delayed reports may become irrelevant or
appropriate time misleading
🔁 Contradictory Address and resolve conflicting Auditor must verify facts and give auditee a
Process evidence chance to respond
Quantitative and Qualitative Factors:
Materiality consists of both quantitative (e.g., a certain percentage of profit or revenue) and qualitative (e.g.,
the nature of a misstatement, such as fraud or non-compliance) factors.
Professional Judgment and User Needs: 🤔🧑💼
Determining Materiality is a matter of professional judgment and depends on the Auditor’s interpretation of
the users’ needs. A matter is likely material if knowledge of it could influence the decisions of the intended
users. Materiality is a relative concept; what is material for one Auditee may not be for another. It is based on
the Auditor's and their team's experience.
Materiality in Audit Process vs. Forming Opinion: 🔄
Materiality is important both during the audit process and when forming the audit opinion. However, the
parameters for applying materiality could be different when forming the audit opinion compared to when
evaluating Audit Evidence under CSAS-2. CSAS-2 focuses on collecting and evaluating evidence to draw
conclusions, while CSAS-3 deals with evaluating these conclusions to form the overall opinion.
Principles for Auditors in Forming an Opinion
1. Completeness: The auditor must consider all relevant audit evidence before forming an opinion.
This involves gathering sufficient and appropriate evidence regarding the accuracy, completeness, and
validity of data.
The Auditor should not be selective in using available evidence, favoring supporting evidence while
discarding contradictory information without proper justification through the principle of the
contradictory process.
2. Objectivity: The auditor must apply professional judgment and skepticism to ensure that the findings
and conclusions are factually correct and presented in a relevant and appropriate manner.
158
Objectivity means the auditor remains independent and free from bias. The auditor should not allow
personal interests or external pressure to affect their professional integrity or judgment.
Professional skepticism is the cornerstone of good auditing. Auditors should approach documents and
information with an inquiring mind, not assuming they are accurate on face value, but evaluating them
against known facts and evidence from other sources.
3. Timeliness: The audit opinion must be formed and reported in a timely manner, allowing sufficient time
for necessary corrections and adjustments to be made.
4. Contradictory Process: In cases where evidence may be contradictory, the auditor must apply a
contradiction process. This involves careful consideration of any conflicting information and seeking
further clarification to determine the most accurate and complete representation of the auditee's situation.
Types of Threats to Objectivity
1. Self-interest Threat:
o Definition: This occurs when an auditor has a financial or personal interest in the outcome of the
audit. This conflict can influence the auditor’s decisions or opinions.
o Example: If the audit team has not received payment for their services from the client, they might
be inclined to issue a favorable report to help the client secure a loan to pay the overdue fees.
2. Self-review Threat:
o Definition: This threat arises when an auditor is tasked with reviewing or evaluating their own
previous work or judgments. It’s difficult to maintain objectivity when re-evaluating decisions
made in earlier audits or non-audit services.
o Example: An auditor who previously assisted in preparing a company's financial statements might
be asked to audit those same statements. This situation makes it challenging to remain impartial
during the audit.
3. Advocacy Threat:
o Definition: This occurs when an auditor becomes an advocate for the client in an adversarial
situation, such as legal proceedings or disputes. Taking a strong position on behalf of the client
undermines the auditor's objectivity.
o Example: If an auditor is also involved in selling a company and is assisting in securing a higher
sale price, they might issue a favorable audit report to increase the company's valuation.
4. Familiarity or Trust Threat:
o Definition: This threat occurs when the auditor becomes too familiar with the client or too
trusting of the client's management, leading to a lack of rigorous testing or oversight. Over-
familiarity can cause auditors to be overly sympathetic to the client’s interests.
o Example: If an auditor has worked with the same client for many years and has built personal
relationships with the client’s management, such as playing sports together, the auditor might
become too lenient or biased in their review.
5. Intimidation Threat:
159
o Definition: This occurs when an auditor feels pressured or intimidated by the client or any other
party, possibly leading to a biased or compromised audit opinion. The auditor might fear losing a
key client or facing retaliation for unfavorable findings.
o Example: If a large client threatens to switch auditors due to unfavorable conclusions in the audit
report, the auditor might be pressured into issuing a more favorable opinion to retain the client.
Characteristics and Safeguards for Maintaining Objectivity in Auditing
Auditors face various threats to their objectivity during audits. While it is not possible to list all potential
countervailing factors, auditors should adopt the following characteristics and practices within their audit
firms to mitigate such threats:
Key Characteristics for Safeguarding Objectivity
1. Integrity and Objectivity in Professional Judgements:
o Auditors should maintain honesty and impartiality in all professional and business
relationships, setting aside personal views and inclinations.
2. Peer Pressure Towards Integrity:
o Strong peer pressure within the audit firm can ensure that integrity remains a high priority.
Auditors rely on each other’s integrity and collective judgment to safeguard their
reputations and minimize the risks of personal liability.
3. Internal Procedures and Controls:
o Audit firms, regardless of size, should establish robust internal controls and procedures. These
should ensure that sensitive judgments are supported by the collective views of other
auditors. This helps minimize litigation risks and promotes accountability within the firm.
Principles for Timeliness and Contradictory Process in Auditing
To ensure accuracy and professionalism, auditors must adhere to the following principles during the audit
process:
1. Timeliness:
o Definition: The audit report should be prepared and issued in a timely manner, adhering to the
agreed-upon timeline during the engagement.
o Importance: Timeliness is crucial in ensuring that the audit findings are relevant and beneficial to
the intended users. Any deviations from the timeline must be documented, along with the reasons
for such delays.
2. Contradictory Process:
o Definition: This principle involves identifying and resolving contradictions or discrepancies found
during the audit process.
o Process:
160
When auditors encounter conflicting facts regarding the same issue, they must gather
additional evidence to resolve the contradiction. This process continues until one fact is
substantiated and the contradiction is eliminated.
If, despite further investigation, the contradiction remains unresolved, the auditor should
clearly report this in the audit findings. If necessary, the auditor may disclaim an opinion on
that particular matter.
The auditor should check the accuracy of facts with the auditee and incorporate responses
from responsible parties, ensuring that all relevant evidence, even if contradictory, is
considered.
Conclusion in Audit Reporting:
Effect of Non-Compliance: The auditor should detail any non-compliance, its cause, materiality, and
potential impact in their report.
Systemic vs. One-off Issues: Auditors should assess whether non-compliance is a one-off event or a
widespread issue within the company.
Judgement, Clarification, and Conflicting Interpretation in Audit Opinion Formation
1. Judgements
While forming an audit opinion, an auditor may refer to case laws, judicial precedents, and
interpretations to understand legal terms and frame opinions correctly. Such references ensure auditors
interpret laws accurately and consistently while auditing.
2. Clarifications
If ambiguities or contradictory interpretations arise, auditors can rely on clarifications from authoritative
bodies like:
o Ministry of Corporate Affairs (MCA)
o Institute of Company Secretaries of India (ICSI)
o Central Board of Direct Taxes (CBDT)
3. Opinions from Similar Audits
Auditors may consider opinions formed in similar audits. Comparisons depend on factors like:
o Nature of Business
o Transaction Types
o Scale of Operations.
Conflicting interpretations can be resolved by referring back to decided judgments and clarifications issued
by government authorities and regulators.
Role of Precedence and Practices in Audit
Precedence and Practice in auditing imply that the Auditor should evaluate whether the records maintained
and statements prepared are, in all material respects, in accordance with applicable laws, rules, and
regulations based on general or ongoing practices or procedures. This evaluation should also consider the
161
qualitative aspects of the Auditee’s compliance practices, including indicators of potential bias in
Management’s judgments.
The Practices and precedence used by Auditors in forming their opinion can be based on:
Historical perspective: Methods used in the past.
Generally used methods or practices or procedures: Common industry norms or established audit
techniques. ⚙️
Examples of such practices:
Sampling: Selecting a representative sample of the firm's total work and activities for the audit
process, with the sample size depending on factors like the firm's size, scale of operations, and number
of branches. 🤏🏢
Unbiased approach: Auditor must maintain independence and impartiality. They must frame
opinion based on facts, not influence.
Limitations on the Scope of Audit
Limitations on the scope of audit refer to situations where the auditor is unable to obtain sufficient and
appropriate audit evidence due to restrictions or constraints. These limitations can significantly affect the
auditor's ability to provide an accurate and complete audit opinion.
Sources of Scope Limitations:
1. Circumstances Beyond the Auditee’s Control: Natural disasters, loss of records, or unforeseen
external factors.
2. Circumstances Related to the Auditor's Work: Constraints in timing or access to relevant data and
personnel.
3. Limitations Imposed by Management: Refusal to provide certain documents or access to critical
areas or stakeholders.
Steps to Address Scope Limitations:
1. Request for Removal of Limitation: If the auditor believes the limitation will lead to a modified or
disclaimed opinion, they must request the Appointing Authority or Management to remove the
restriction.
2. Seek Alternative Procedures: If the limitation persists, the auditor should explore alternative
methods to gather sufficient and appropriate audit evidence.
3. Communicate the Issue: If alternative procedures are not viable, the auditor must inform those
charged with governance about the limitation.
Determining Implications of Limitations:
The impact of the limitation depends on the materiality and pervasiveness of the unavailable evidence:
1. If Effects Are Not Material: Modify the audit opinion slightly to address the limitation.
2. If Effects Are Material:
162
o Material but Not Pervasive: Issue a qualified opinion stating specific areas affected.
o Material and Pervasive: Issue a disclaimer of opinion, declining to express any opinion due
to significant limitations.
Third Party Reports or Opinions in Audit
A Third Party is a person or expert not directly connected to the audit but provides inputs (e.g., legal,
technical, valuation opinions) relevant to forming the audit conclusion.
Reasons for Use
Geographical limitations
Lack of in-house expertise
Requirement of expert opinion
Auditor’s Responsibilities When Using Third Party Reports
Indicate use of third-party input and reason for it
Disclose if report was provided by Auditee
Evaluate and consider key observations/findings
If feasible, perform supplemental testing for verification
Additional Auditor Considerations
Independence & Objectivity of the Third Party
Professional competence relevant to the audit
Scope and limitations of the third-party work
Cost-effectiveness
Obtain sufficient audit evidence (may involve reviewing third party's working papers)
Consider and discuss significant findings, and conduct additional testing if needed.
⚠️ Caution: Third parties may owe a duty of care only to the original addressee, not the auditor.
Management Representation Letter
Used to obtain written confirmation from management on matters not directly verifiable by the Auditor.
Key Points
Signed by: Managing Director, Company Secretary, or Senior Management.
Forms part of audit evidence.
Should be adapted case-wise using a suggested format.
Must not replace due diligence or direct verification.
⚠️Warning: Sole reliance on MRL for verifiable matters defeats the audit's purpose. Auditor must use:
Reasonable skill
Due diligence
Adequate enquiries.
Opinions Obtained by Management
When auditors raise qualifications, management may respond with their explanation backed by a third-
party opinion.
163
Auditor’s Responsibility
Use professional judgment to assess:
Validity of third-party opinions
Whether to rely on them
📝 Explanation submitted by management may be disclosed in the Directors’ Report.
Auditor's Evaluation of Management-Provided Evidence:
The Auditor must verify if management-provided evidence is:
📍 Accurate and Complete
📍 Sufficiently detailed and precise
📌 Steps to Ensure Reliability
(a) Test accuracy/completeness or controls over that data
(b) Ensure that controls over the provided information are functioning effectively.
Exit Conference:
The Exit Conference is a concluding meeting between the auditor and the company’s management (or
supervisory officers). It allows for the discussion of audit observations and clarifications on findings.
Key Considerations:
Audit observations should be shared with management beforehand.
The meeting provides management an opportunity to clarify or contest findings.
It helps ensure mutual understanding of audit conclusions before finalizing the report.
Evaluation of Audit Evidence and Forming an Opinion:
Role of Audit Evidence:
Audit evidence is critical for forming opinions. It must be competent, relevant, and reasonable to support
the auditor’s judgments and conclusions.
Types and Reliability of Audit Evidence:
Type of Evidence Reliability
Oral Evidence Least reliable; should be corroborated with documentary
confirmation.
Documentary Evidence More reliable than oral evidence.
Evidence from Direct Personal
Most reliable, as it comes from the auditor’s direct observations.
Knowledge
Highly reliable for confirming asset existence, but not
Visual Evidence
ownership or value.
Internal Evidence (Auditee- Reliability depends on the entity’s internal control systems.
Generated)
More reliable than internal evidence, provided it is truly
External Evidence
independent and complete.
Less reliable; conclusions based on figure relationships are
Analytical Review
weaker.
Less reliable than originals; should be certified, and sources
Photocopies
identified.
164
Accepted Evidence by Auditee Considered reliable as it indicates mutual agreement on facts.
Sharing Draft Audit Report with Management and Risk Categorization
After the exit meeting and completion of audit procedures, the auditor should prepare an executive summary
of audit findings. This summary explains key audit issues, the category of risk involved, their resolution, and
agreed adjustments. After discussing this summary, the audit certificate should be signed by both the auditor
and the management (or an authorized person).
The executive summary is a high-level, concise document that should contain sufficient information to stand
alone as a summary of the evidence supporting the audit team's conclusion on the appropriate form of the
audit certificate. It should typically include:
(i) A summary of the auditee’s operations and purpose. 🏢
(ii) A summary of the regulatory framework. 📜
(iii) An explanation of the audit approach (test of controls vs. substantive procedures).
(iv) A summary of key risks identified. ⚠️
(v) A commentary on key balances. 💰
(vi) A commentary on accounting policies and significant account areas. 📊
(vii) A summary of the results of audit procedures. ✅❌
(viii) Details of areas involving difficult questions of principle or judgment. 🤔
(ix) Matters brought forward from the previous year's audit.
(x) A summary of other important matters for attention. 📣
(xi) Outstanding matters (e.g., reappointment orders, authorization letters for amendments). ⏳
(xii) A summary of matters carried forward to the next year's audit. ➡️
(xiii) A conclusion on the appropriate form of audit certificate. 📢
Furthermore, the replies of the management to the auditor's observations and recommendations should be
obtained and recorded in the audit file. If the auditor's opinion is modified opinion
(qualified/adverse/disclaimer), the full rationale should be provided in the executive summary.
Stages of Communication and Report Finalization:
1. Preliminary Draft: At the end of fieldwork, the auditor prepares a draft report and presents it to
management for their comments.
2. Exit Meeting: The auditor discusses the findings, observations, recommendations, and the draft report's
text with management to obtain their comments, achieve consensus, and reach an agreement on the
audit findings.
3. Formal Draft: Based on the exit meeting and other discussions, the auditor prepares a formal draft.
After review by both the auditor and management, the final report is prepared.
4. Final Report: The final report is submitted to the appointing authority or designated members of
management.
Auditor’s Responsibility and Reporting
Section: Auditor’s Responsibility
165
The "Auditor's Responsibility" section in the Audit Report outlines the Auditor's accountability in conducting
the audit.
1. Purpose of the Section:
o To explain the Auditor’s role in expressing an opinion on compliance with applicable laws and
records maintenance.
o To ensure transparency about the Auditor’s procedures and inherent limitations in detecting all
misstatements or non-compliances.
2. Key Points to be Stated:
o Auditing Standards: Whether the audit has been conducted as per the applicable Auditing
Standards.
o Reasonable Assurance: Whether the Auditor has obtained reasonable assurance that the
statements prepared, documents, or records maintained by the Auditee are free from
misstatement.
o Scope of Responsibility: Whether the Auditee has followed applicable laws, acts, rules, or
regulations in maintaining their records, documents, statements, or has complied with applicable
laws or rules while performing any corporate action.
o Inherent Limitations: Acknowledgment that internal, financial, and operational controls have
inherent limitations, making complete detection of all issues unlikely.
Format of the Audit Report
📌 Addressing the Report
Report should be addressed to the Appointing Authority, unless stated otherwise in:
o Audit Engagement Letter
o Applicable Law
Appointing Authority may include:
o Board of Directors (in case of company)
o Court, Tribunal, Regulators, or officers thereof (in special cases)
📄 Structure & Format Requirements
Follow prescribed format (e.g., MR-3 for Secretarial Audit)
If content exceeds prescribed format:
➤ Use Annexures to include additional disclosures
Signature Block Should Include:
Name of Audit Firm
Name of Auditor
Membership Number (Associate/Fellow)
Certificate of Practice (COP) Number
Date & Place of signing
If two auditors sign on different dates or locations, it must be clearly mentioned.
✍️Characteristics of a Good Audit Report
166
Precise, accurate, clear and unbiased
Should include:
o Areas of compliance and non-compliance
o Improvements suggested
o Summary of key observations
o Well-founded opinion on true state of affairs
Must give full disclosure, even if it means adding additional pages or annexures
📘 Pre-requisites for Reporting
An Audit Report should be:
Quality Explanation
1. Accurate Free from errors; faithful to facts.
2. Objective Fair, unbiased, based on relevant info.
3. Clear Logical, easy to understand, avoids jargon.
4. Concise Avoids redundancy or unnecessary details.
5. Constructive Aims to help client improve.
6. Complete Contains all necessary and relevant information.
7. Timely Submitted promptly to enable corrective actions.
Submission of Audit Report
Preparation: Based on management’s clarifications/replies, the auditor prepares the final audit report.
Addressing and Submission: Typically addressed to the members but submitted to the Board.
Contents: Includes the auditor's opinion on whether the company complies with the provisions of
applicable laws. The opinion may be with or without qualifications depending on the findings.
📘 Signing of Audit Report
Signature can be in the name of:
o The audit firm
o The individual auditor
o Or both, depending on jurisdiction
In Secretarial Audit:
o Must be signed by the Secretarial Auditor who conducted or supervised the audit.
o Should include:
FCS/ACS number
Certificate of Practice (CoP) number
In case of PCS Firm:
o Only partners may sign the report.
o Employees cannot sign, even if they hold a CoP.
📘 Reporting with Qualification (Secretarial Audit)
📝 Manner of Reporting
1. Qualifications, Reservations, or Adverse Remarks:
o Must be presented in bold or italics at relevant places.
2. Unable to Express Opinion:
o Clearly mention inability to express opinion with reasons.
3. Scope Limitation:
167
oIf restricted by company or circumstances (e.g., inaccessible records), this must be stated.
o If too material, auditor may declare complete inability to report on that area.
4. Board’s Duty:
o Board must explain all qualifications/remarks in its report under Section 134(3) of
Companies Act, 2013.
Lesson: 13 (Secretarial Audit)
Introduction to Secretarial Audit
Secretarial Audit is a mechanism that examines the non-financial aspects of a company's compliance
framework. It provides confidence to stakeholders such as investors, management, and regulators by
certifying:
Adherence to all applicable laws.
The existence of robust systems and processes for compliance.
In line with the government’s vision of "minimum government, maximum governance," Secretarial Audit
ensures:
Compliance with applicable statutes, rules, and regulations.
Independent verification of records, books, and documents.
Assurance of effective risk management, control, and governance processes.
Thus, Secretarial Audit acts as an objective tool for adding value and improving operational efficiency.
Significance of Secretarial Audit
1. For Companies:
o It drives the adoption of good corporate governance practices, boosting stakeholder
confidence.
o Helps mitigate risks by ensuring legal and procedural compliance.
2. For Stakeholders:
o Enhances trust and confidence in the company’s commitment to ethical practices and
regulatory adherence.
3. For Practicing Company Secretaries:
o Opens new opportunities in the field of governance and compliance.
o Positions PCS as key facilitators in strengthening corporate governance.
Role of the Company Secretary in Practice (PCS)
A Company Secretary in Practice is uniquely qualified to perform Secretarial Audits due to their:
Expertise in statutory, procedural, and practical aspects of laws applicable to companies.
168
Membership in the Institute of Company Secretaries of India (ICSI) and possession of a Certificate
of Practice (CoP).
Only a PCS is authorized under Section 204(1) of the Companies Act, 2013 to:
Conduct Secretarial Audits.
Issue Secretarial Audit Reports.
Guidance for Secretarial Auditors
To conduct an effective audit, auditors are encouraged to refer to:
Auditing Standards issued by ICSI.
Guidance Notes on:
o Auditing Standards.
o Secretarial Audit.
o Annual Secretarial Compliance Report.
Section 204 of the Companies Act, 2013: Secretarial Audit Overview
Applicability of Section 204(1): Mandatory Secretarial Audit (BB)
Companies required to annex a Secretarial Audit Report (Form MR-3) to the Board’s Report:
1. Listed Companies.
2. Public Companies meeting any of these thresholds:
o Paid-up share capital: ₹50 crore or more.
o Turnover: ₹250 crore or more.
3. Companies (public or private) with outstanding loans/borrowings of ₹100 crore or more from
banks or public financial institutions.
Explanation: The applicable thresholds are determined based on the latest audited financial statement.
Key Legal Provisions in Section 204
1. Section 204(2): Duty of the Company
o The company must provide the Practising Company Secretary (PCS) with all necessary
assistance and facilities for conducting the Secretarial Audit.
2. Section 204(3): Addressing Observations
o The Board of Directors, in the Board Report, must provide detailed explanations for any
qualifications, observations, or remarks in the PCS's Secretarial Audit Report.
3. Section 204(4): Penalties
o In case of contravention by the company, its officers, or the PCS:
Penalty: ₹2,00,000 each for the company, officers in default, and the PCS.
Section 2(71): Applicability to Private Companies Subsidiary to Public Companies
A subsidiary of a public company is treated as a public company under the Act, even if it remains a
private company in its Articles of Association.
Therefore, Section 204 applies to such subsidiaries if they meet the prescribed thresholds.
169
💡 Voluntary Audit: Even companies not covered under Section 204 may opt for secretarial audit voluntarily
for better compliance assurance.
Need/ Importance of Secretarial Audit
A strong compliance and governance tool
1. ✅ Compliance Verification
o Ensures laws like Companies Act, SEBI, FEMA are followed
2. 📊 Corporate Governance
o Checks board procedures, ethics, disclosures, etc.
3. ⚠️Risk Mitigation
o Finds internal control issues and reduces legal/reputation risks
4. 🔍 Fraud & Mismanagement Prevention
o Detects fraud, mismanagement or irregularities through records and process checks to prevent or
mitigate fraud / misconduct.
5. 🤝 Stakeholder Confidence
o Boosts trust of investors, lenders, regulators
6. ⚖️Legal Requirement
o Mandatory for specific company classes under law, failure to conduct audit results in penalties,
fines or legal action.
7. ⚙️Efficiency Improvement
o Identifies and fixes inefficiencies, saving cost and time.
🔍 Secretarial Audit as a Tool for Good Corporate Governance
Secretarial Audit supports good corporate governance by promoting transparency, compliance, and
accountability. Here's how:
1. ✅ Ensuring Regulatory Compliance
o Verifies compliance with applicable laws, regulations, and guidelines.
o Reviews corporate records, governance practices, and statutory filings.
2. 🔍 Monitoring Corporate Practices
o Checks if corporate practices align with ethical standards and best practices.
o Assesses board procedures, decision-making, and governance structures.
3. 👥 Assessing Board Effectiveness
o Evaluates board composition, independence, and performance.
o Reviews meeting minutes, director appointments, and governance adherence.
4. 🎯 Supporting Strategic Decision-Making
o Provides insights into governance gaps and compliance issues.
o Aids management and board in making informed, long-term decisions.
5. ⚠️Identifying Risks and Controls
o Identifies risks and evaluates internal control effectiveness.
o Assesses compliance mechanisms and risk management frameworks.
6. 📢 Enhancing Transparency and Disclosure
o Promotes timely and accurate disclosure to stakeholders.
o Reviews disclosure practices, communication, and shareholder relations.
170
📌Conclusion:
Secretarial Audit ensures independent assurance of governance processes, builds trust among
stakeholders, and upholds transparency, accountability, and ethical conduct.
🎯 Objectives of a Secretarial Audit
1. ✅ Verification of Compliance
o With Companies Act, SEBI, FEMA, and other relevant laws.
2. Assessment of Governance Practices
o Reviews board functioning, governance guidelines, and ethical standards.
3. ⚠️Identification of Legal and Regulatory Risks
o Assesses internal controls and risk mitigation mechanisms.
4. 📋 Evaluation of Board Procedures
o Checks how the board makes decisions and meets statutory requirements.
5. Review of Statutory Registers and Records
o Ensures records are accurate, updated, and legally compliant.
6. 📢 Examination of Disclosures and Reporting
o Verifies accuracy and completeness of disclosures to stakeholders.
7. 🤝 Assessment of Related Party Transactions
o Ensures proper controls and disclosures to prevent conflicts of interest.
8. 🚨 Detection of Fraud and Mismanagement
o Identifies irregularities through a thorough review of governance practices.
9. Recommendation of Remedial Measures
o Suggests actions to fix compliance or governance gaps.
10. 🙌 Enhancement of Stakeholder Confidence
o Provides independent assurance to build investor and regulator trust.
Secretarial Audit and Secretarial Compliance Report under SEBI (LODR) Regulations, 2015
🧾 Regulation 24A: Secretarial Audit
Every listed entity and its material unlisted Indian subsidiaries must:
o Undertake secretarial audit
o Annex the secretarial audit report (by a Company Secretary in Practice) with the Annual
Report
o Effective from FY ended March 31, 2019
Material Subsidiary = Subsidiary whose income or net worth > 10% of the consolidated income/net worth
of the listed entity group (previous year)
🔁 Amended Regulation 24A (w.e.f. May 05, 2021):
Listed entities must also:
o Submit Secretarial Compliance Report to stock exchanges within 60 days from end of each
FY
o Report in prescribed format (Annexure-B)
📑 Purpose & Scope
Listed entities & material subsidiaries must provide all documents/information requested by PCS.
Annual Secretarial Compliance Report includes:
171
o Broad check of all laws applicable
o Compliance with SEBI regulations, circulars & guidelines
o Independent verification by PCS of company records and SEBI law compliance.
✅ Applicability: All Listed Entities
🚫 Exemptions (Regulation 15, SEBI LODR):
❌ 15(2)(a):
Not applicable to listed entities with:
o Equity share capital ≤ ₹10 Cr
o Net worth ≤ ₹25 Cr
o Based on the previous financial year
✅ If above thresholds are crossed later, compliance must begin within 6 months and continue for 3
consecutive years even if thresholds fall again.
❌ 15(2)(b):
Not applicable to:
o Entities with securities listed on the SME Exchange
🔍 Other non-company listed entities: Corporate governance provisions apply only if they don’t violate
respective statutes or regulator directives.
Auditing Standard on Secretarial Audit (CSAS-4)
📅 Effective Date
Recommendatory: 1 July 2019
Mandatory: 1 April 2021
Issued by
Auditing Standards Board (ASB) of ICSI
📌 Applicability (BB)
✅ Applicable for:
Secretarial Audit under Section 204 of Companies Act, 2013
Regulation 24A of SEBI (LODR) Regulations, 2015
❌ Not applicable for:
Annual Secretarial Compliance Report (SEBI circular dated 8 Feb 2019)
Voluntary secretarial audits
Third-party/regulatory-mandated audits.
🔗 Link to Other CSAS Standards
The secretarial auditor must also apply:
CSAS-1: Audit Engagement, laying down how the auditor should accept and plan the audit.
CSAS-2: Audit Process & Documentation, guiding auditors on how to document and perform the
audit.
CSAS-3: Forming of Opinion, detailing how auditors should analyze audit findings and form a final
opinion.
CSAS-4 Provides guidelines for conducting secretarial audits and forming audit opinions.
📌Note:
172
CSAS-4 does not apply when secretarial audits are mandated by third-party or regulatory authorities.
However, if the auditor follows the ICSI’s auditing standards, they must acknowledge that they adhered to
these standards (CSAS-1 to CSAS-4).
Periodicity of Secretarial Audit
Secretarial audits should be conducted regularly, ideally on a quarterly, half-yearly, or annual basis.
Adverse findings should be reported to the Board immediately so that corrective measures can be taken in a
timely manner. The audit results should be included in the Board’s Report, allowing all stakeholders to
understand the company’s compliance status and take appropriate action if needed.
Risks of Non-Compliance with Laws and Regulations
Risk Area Impact
🧾 Regulatory Actions Non-compliance with MCA, SEBI, RBI, etc. may lead to actions affecting the
financial and operational stability.
🌱 Environmental Law Non- Non-compliance with environmental laws can result in fines and liabilities,
Compliance and jeopardize sustainability.
🚫 No Approvals/Licenses Failure to obtain proper approvals/permissions/licenses could lead to fines,
penalties and/or imprisonment.
❌ Failure of Legal Non-maintenance of books, unlawful actions (e.g. related party transactions,
Compliance loans to directors) can lead to stakeholder liability and risk corporate
protection.
📝 Inaccurate Records Inaccurate or incomplete records can lead to legal consequences for the
company and its board.
📊 Unmet Reporting May result in default with lenders/investors and reputational damage.
Requirements
✅ Advantages of Secretarial Audit
Ensures compliance with all corporate laws (Companies Act, SEBI Law, Secretarial Standards).
Provides comfort to investors, management, regulators, and stakeholders.
Facilitates early detection and correction of non-compliance.
Acts as a compliance monitoring tool within a formal framework.
🌟 Benefits to Stakeholders:
✅ Better compliance → fewer frauds and prosecutions.
Stakeholder protection and trust building.
📈 Improves investor services and confidence.
🏢 Reduces regulator burden through timely compliance.
🧑⚖️Helps protect directors/companies from unintended violations.
🚨 Audit qualifications alert investors to risks.
🧘♂️Promotes professional discipline and self-regulation.
👥 Audit Audience and Benefits
Audience Benefit
Promoters Assurance that management is legally compliant; ownership is
safeguarded.
Non-executive/Independent Comfort that compliance mechanisms exist; risk mitigation.
Directors
Regulators/Government Easier enforcement and reduced monitoring burden.
173
Investors Helps in informed decision-making.
Other Stakeholders Effective due diligence tool for partners, banks, consumers, etc.
⚠️Risk to Secretarial Auditor (PCS)
Provision Penalty
Section 204(4) ₹2,00,000 penalty for company/officer/PCS if section 204 is contravened.
Section 143 (Listed ₹5,00,000 penalty for PCS.
Company)
Section 143 (Other ₹1,00,000 penalty for PCS.
Companies)
Section 447 (Fraud) Imprisonment: 6 months – 10 years; Fine: ≥ amount involved, up to 3×
amount.
If public interest involved: Minimum 3 years imprisonment.
Section 448 (False Liable under Section 447 if any return/report contains material
Statement) misstatements or omissions.
Section 451 (Repeat Double fine + imprisonment for repeated offences within 3 years.
Offence)
Professional Misconduct (Company Secretaries Act, 1980):
Disciplinary Action: Practicing Company Secretaries can face disciplinary action under the Company
Secretaries Act, 1980 for professional misconduct, both for secretarial audit and other professional
duties.
Types of Misconduct: The misconduct is detailed in Part I of the First and Second Schedule of the
Act.
Disciplinary Committee Actions: If the Disciplinary Committee of ICSI finds a member guilty of
misconduct, the following actions may be taken:
oReprimanding the Member.
o Removing the Member’s Name from the ICSI Register permanently or temporarily.
o Imposing a Fine of up to ₹5 lakh.
🧑⚖️Case Law: Sun Pharmaceutical Industries Ltd
Issue:
PCS failed to report Aditya Medisales Ltd. as related party (RPT) → Violation of Section 188
Facts:
MCA initiated inquiry post whistle-blower complaint (FY 2014–18)
PCS relied on Statutory Auditor’s report instead of performing independent RPT check
Failed to follow ICSI Guidance Note and Section 143(14), 188, and 204
Outcome:
Penalty imposed for failure to perform due diligence and report RPT.
Code of Conduct (BB)
174
A Code of Conduct is a set of principles that outline the responsibilities and practices expected of
individuals, organizations, or parties within a profession. It guides professionals in carrying out their duties in
a manner that ensures trust and integrity. Key Principles of a Professional Code of Conduct:
1. Integrity
2. Independence
3. Objectivity
4. Competence
5. Confidentiality
6. Conformance to Technical Standards
7. Ethical Behavior.
Scope of Secretarial Audit (BB)
The Secretarial Audit involves examining a company's compliance with various laws and regulations. It
includes specific reporting on the company's adherence to the Companies Act, 2013 and related rules, and
other industry-specific laws.
Key Areas of Examination and Reporting:
1. Compliance with the Companies Act, 2013
The auditor reviews the company's compliance with the provisions of the Companies Act and related
rules.
o Annual/Non-event-based: e.g., Annual Return, Annual Report, Secretarial Audit Report.
o Event-based: Triggered by certain actions/events.
2. Compliance with Specific Regulatory Acts
o Securities Contracts (Regulation) Act, 1956 (SCRA)
o Depositories Act, 1996
o Foreign Exchange Management Act, 1999
o SEBI Act, 1992 regulations
o ICSI's Secretarial Standards
3. Compliance with Industry-Specific Laws
o Banking Industry: Compliance with all banking-related laws.
o Petroleum Industry: Compliance with laws specific to the petroleum sector.
4. Compliance with General Laws
o Labor Laws: Ensuring the company adheres to labor-related regulations.
o Environmental Laws: Reviewing the company's compliance with environmental regulations.
5. Compliance with Board Processes
o Constitution of Board of Directors: Ensuring the proper formation and operation of the
board.
o Board Meetings: Reviewing notices, agendas, and minutes of board meetings.
6. Systems and Processes
o Evaluating whether the company has adequate systems and processes in place to monitor
compliance with applicable laws, relative to its size and operations.
175
7. Listing Agreements
o For companies listed on the stock exchange, ensuring compliance with listing agreements.
Steps Involved in the Secretarial Audit Process:
1. Appointment of Secretarial Auditor:
o The Secretarial Auditor must be appointed by a resolution passed in a duly convened board
meeting as per Section 179 of the Companies Act, 2013 and Rule 8 of the Companies (Meetings
of Board and its Powers) Rules, 2014.
o The appointment must comply with the Auditing Standards prescribed by the Institute of
Company Secretaries of India (ICSI).
2. Communication to the Earlier Incumbent:
o If a new Company Secretary is appointed as the secretarial auditor, they must communicate with
the previous incumbent about their proposed engagement via registered or speed post.
3. Acceptance of Appointment:
o A formal letter confirming the appointment is sent by the company, and the secretarial auditor
confirms acceptance in writing.
4. Preliminary Discussions/Surveys:
o The secretarial auditor gathers information about the company and its operations by interacting
with key personnel and conducting surveys to understand the company’s activities.
5. Preliminary Meeting:
o A meeting with senior management and administrative staff helps define the scope, objectives, and
timeframe of the audit. The audit plan is prepared, outlining the steps and processes involved.
6. Finalization of Audit Plan:
o The auditor prepares an audit plan, including allocation of tasks and responsibilities among audit
staff. The audit plan should detail fieldwork, the tools to be used, and the controls to be reviewed.
7. Testing, Interviews, and Analysis:
o The secretarial auditor uses tools and technology to gather relevant data, interviews company staff,
reviews procedures, and assesses compliance with laws and policies. They identify areas of risk
and evaluate the adequacy of internal controls.
8. Working Papers:
o Working papers document the audit process and serve as the basis for the auditor’s opinion. They
link management’s records with the auditor’s findings and form a comprehensive record of the
audit.
9. Audit Summary for Discussions:
o The auditor summarizes key findings and discusses them with management to seek clarifications
or responses.
10. Submission of Secretarial Audit Report:
176
o After receiving management’s responses, the secretarial auditor prepares and submits the
Secretarial Audit Report (Form MR-3) to the Board, addressing compliance with statutory
requirements. The report may contain qualifications or a clean opinion depending on the
findings.
Identification and Segregation of Applicable Laws in Secretarial Audit
1. Industry-Specific Laws:
o The auditee's (Management) responsibility is to identify all applicable laws, including industry-
specific ones. The auditor’s role is to verify if these laws are correctly identified and segregated.
o If the management fails to identify these laws, the auditor must ask for clarification and report
accordingly.
2. Examples of Industry-Specific Laws:
o For example, banks need to comply with laws specific to the banking industry (e.g., Banking
Regulation Act, RBI guidelines), while pharmaceutical companies must comply with laws like the
Drugs and Cosmetics Act, 1940, and other related regulations.
3. General Laws:
o In addition to industry-specific laws, the auditor must also examine general laws (e.g., labour
laws, competition laws, and environmental laws) and ensure that adequate systems and
processes are in place to monitor and ensure compliance with these laws.
4. Segregation of Laws: (BB)
To verify the correctness of the segregation of laws, the auditor considers the following factors:
o Company Status (e.g., Listed/Unlisted).
o Company Type (e.g., Private, Public, Subsidiary).
o Geographic Location (e.g., Registered office, units, or plants).
o Industry Classification (e.g., Manufacturing, Trading, Service, E-commerce).
o Key Financial Parameters (e.g., Turnover, Paid-up Share Capital).
o Employee Classification (e.g., Women workers, contractual employees).
o Registration with Authorities (e.g., SEZ, Sectoral Regulators).
Form MR-3 Requirements
1. Secretarial Auditor’s Report on Compliance of Laws:
o The Form MR-3 (as notified by the MCA under Section 204 of the Companies Act, 2013) requires the
Secretarial Auditor to report on the compliance of other applicable laws specific to the company.
o Addressed to: Although the Secretarial Auditor is appointed by the Board of Directors, the
Secretarial Audit Report is addressed to the members of the company.
o The report includes comments on the adequacy of systems and processes to ensure compliance with
applicable laws, rules, regulations, and guidelines.
Verification of Corporate Conduct and Compliance of Laws
177
Identification of Events/Corporate Actions
1. Role of the Auditor:
o The Secretarial Auditor must identify significant corporate events or actions that occurred during
the audit period. These are events that could impact the company’s functioning or its
stakeholders.
o To identify these events, the auditor will review multiple sources, including:
Websites of the company and regulators
Statutory records (books, papers)
Interaction with the management
Other relevant sources
2. Corporate Actions:
o A corporate action is an event initiated by the company, which brings or could bring a change in
the company’s operations. Examples include:
Investments made
Changes in borrowing limits
Issuance of securities (equity or debt)
Appointment of Key Managerial Personnel (KMPs)
o These actions are typically approved by the Board of Directors or the shareholders and can alter
various aspects of the company's operations.
o Other events may include changes to:
Charter documents (e.g., Articles of Association)
Capital structure (e.g., issue of shares, changes in capital)
Management (e.g., appointment, resignation of directors or KMPs)
Licenses/permissions for business operations
Casual vacancies (e.g., resignation of auditor or director)
Excess borrowing beyond limits under Section 180 of the Companies Act, 2013.
3. Sources for Identifying Corporate Actions:
o The auditor can identify corporate actions and events from:
Financial statements of the company
Annual reports
Agenda and minutes of Board/Committee/Shareholder meetings
Filing and reporting to regulators
Statutory disclosures on the company's website, Ministry of Corporate Affairs website, or
stock exchanges
Third-party sources like registrar and transfer agents, financial auditors, and
stakeholders.
Verification of Compliance
The auditor verifies compliance with relevant laws based on the identified events or corporate actions. To
ensure thorough verification, the auditor uses systematic and comprehensive audit checklists.
Verification Process:
Review all applicable laws, including industry-specific regulations.
Use checklists based on the scope of the audit and the information gathered.
178
Cross-check the compliance status from statutory records, filings to regulators, and other relevant
sources.
Board Composition and Compliance Verification
1. Compliance with Relevant Laws (BB)
The Secretarial Auditor is responsible for verifying the Board Composition of the company, ensuring
compliance with various regulations, including:
Companies Act, 2013
SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015
Industry-Specific Laws/Acts (e.g., Banking Regulation Act, 1949 for banking companies, Insurance
Act, 1938 for insurance companies)
Articles of Association and Agreements with Lenders/Investors
Government Policies for industry promotion
Key Points for Verification:
The auditor must check whether the company adheres to the minimum and maximum board
strength as required by law. For example, companies governed by specific industry laws (such as
banking or insurance companies) may have additional requirements or exemptions related to their
board composition.
2. Special Cases and Industry-Specific Requirements
In certain cases, companies may have unique requirements for their board composition due to the nature of
their business. For example:
Non-scheduled flight operators must obtain prior approval from the Ministry of Civil Aviation for
appointing new board members.
State Bank of India (SBI) follows the guidelines set by the State Bank of India Act, 1955 for board
composition.
For nationalized banks, the auditor should verify compliance with:
Banking Companies (Acquisition and Transfer of Undertakings) Act, 1980
Nationalized Bank (Management & Miscellaneous Provisions) Scheme, 1980
3. Auditor’s Role in Board Composition Verification
The Secretarial Auditor needs to identify all relevant laws and regulations that apply to the company
and ensure that the board composition is in line with those laws. This may include laws such as:
o Banking Regulation Act, 1949 for banking companies
o Companies Act, 2013 and SEBI Regulations for listed companies
o Insurance Act, 1938 for insurance companies
The auditor should verify the minimum and maximum number of directors required by law for the
company, considering both general and specific regulatory requirements.
4. Optimum Combination of the Board (BB)
The board should have an optimum combination of directors to ensure effective governance. This includes
the appropriate proportion of:
Executive and Non-Executive Directors
Independent and Non-Independent Directors
Women Directors (if applicable)
179
Nominee Directors
Provisions Mandating Optimum Composition:
Section 149(2) of the Companies Act, 2013 requires that at least one director must stay in India for
a minimum of 182 days during the financial year.
Section 149(3) mandates that for listed public companies, at least one-third of the board members
must be independent directors. For any fraction of one-third, the number is rounded up to the
nearest whole number.
o An independent director is defined as a director who is not a managing director, whole-
time director, or a nominee director.
1. Woman Director Appointment:
As per Section 149(1) (second proviso) of the Companies Act, 2013, read with Rule 3 of The Companies
(Appointment and Qualification of Directors) Rules, 2014, the following classes of companies must
appoint at least one-woman director:
Every Listed Company
Every Other Public Company having:
o A paid-up share capital of ₹100 crore or more; or
o A turnover of ₹300 crore or more.
The paid-up share capital or turnover for determining this requirement is based on the last audited
financial statements of the company.
2. SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015:
Regulation 17 of the SEBI Listing Regulations sets out the following guidelines for the Board Composition of
listed companies:
The Board of Directors must have an optimum combination of executive and non-executive
directors, with at least one-woman director.
Non-executive directors should comprise at least 50% of the Board.
For the top 1000 listed companies:
At least one independent woman director must be appointed by April 1, 2020.
Board Composition Based on Chairperson:
If the Chairperson of the Board is non-executive, at least one-third of the board must be
independent directors.
If the Chairperson is not non-executive, then at least half of the Board must comprise independent
directors.
In cases where the non-executive Chairperson is a promoter or is related to a promoter or someone in
management, half of the Board must be independent directors.
The top 2000 listed companies (effective April 1, 2020) must have a minimum of 6 Directors on
their Board.
Superior Voting Rights (SR) Shares:
If a listed company has Superior Voting Rights (SR) equity shares, at least half of the Board must
consist of independent directors.
3. Additional Requirements for NSE Prime Companies:
The National Stock Exchange (NSE) launched the NSE Prime framework in December 2021 for companies
that voluntarily choose to adopt higher governance standards. The specific requirements for NSE Prime
companies are:
180
The Board of Directors should consist of at least 8 directors.
The Chairperson of the Board should not be a relative of the Managing Director or CEO of the NSE
Prime company.
If public shareholding exceeds 50%, more than half of the Board should comprise independent
directors.
If public shareholding is 50% or less, at least half of the Board must comprise independent
directors.
By July 1, 2025:
At least two directors must be women, and at least one of them must be an independent woman
director.
Preferable Board Size as per Proxy Advisors
Several proxy advisors suggest an optimal board size for effectiveness:
Iias: Prefers a board size of 6-15 members. Too small a board may lack diversity, while too large a
board may struggle with decision-making.
InGovern: Prefers a board size of 7-15 members. Board sizes outside this range may lead to
ineffective governance or delayed decision-making.
SES: Prefers a board size of 6-15 members. If a company proposes a size outside this range, it must
provide a rationale for it.
1. Verification of Optimum Combination of Directors:
The auditor plays an essential role in verifying whether the Board of Directors of a company maintains an
optimum combination as mandated by applicable laws. This includes ensuring the correct mix of executive,
non-executive, and independent directors on the board. The auditor must:
Check the compliance of the board's composition as per relevant statutes (such as the Companies Act,
2013 and SEBI Regulations).
Report any deviations from the required composition.
The auditor should assess if the board's structure meets the industry-specific laws that may set stricter
guidelines. If discrepancies are found, these should be reported.
2. Eligibility Criteria and Disqualifications of Directors:
The Companies Act, 2013 and other industry-specific laws define the eligibility and disqualifications for
directors. The auditor needs to verify:
The qualifications of the directors against the standards outlined in Section 164 of the Companies
Act, 2013, which specifies disqualifications for directorship, such as non-payment of dues or having
been convicted of an offense.
The compliance with additional criteria set by industry-specific laws (e.g., banking, insurance).
If any director does not meet these eligibility criteria or has disqualifications, the auditor should report the
issue.
3. Constitution and Composition of Committees:
Certain companies must establish Board Committees as per various regulatory requirements, including the
Companies Act, 2013, SEBI Regulations, and industry-specific laws. These committees can include:
Audit Committee
Nomination and Remuneration Committee
Stakeholders' Relationship Committee
CSR Committee
Risk Management Committee
Internal Committees (e.g., under the POSH Act)
181
For banking companies, specific committees must be constituted in compliance with the Banking
Regulation Act, 1949 and the Reserve Bank of India (RBI) guidelines.
The auditor's role in verifying board committees includes:
Checking the constitution of committees to ensure they align with the applicable laws, regulations,
and standards.
Verifying that the committees have the required number of independent members and
appropriate members as per the legal guidelines.
4. Guidelines on Preferable Board Size:
Iias (Institutional Investor Advisory Services): Prefers a board size of 6-15 members. A smaller
board may lack diverse expertise, while a larger one may struggle with decision-making and
consensus. They discourage increasing board size to accommodate family members.
InGovern: Recommends a 7-15 member board for effective decision-making. A smaller board risks
lack of diversity, while a larger board could have delayed decisions and dominance by promoters.
SES (Shareholders Empowerment Services): Supports a 6-15 member board. Any deviation from
this range should be accompanied by a rationale explaining the reasoning behind the decision.
The auditor's role in this regard involves checking the board size and ensuring it adheres to the preferred
size range as per the guidelines of proxy advisors, such as Iias, InGovern, and SES. If the size is outside the
recommended range, the company should provide a clear rationale for it.
Board Processes in Corporate Governance (BB)
The Board of Directors plays a vital role in Corporate Governance, ensuring the transparent, ethical, and
responsible management of a company. To fulfill their fiduciary duties to shareholders and stakeholders, the
board must adhere to specific processes and practices for effective decision-making.
Key Elements of Board Processes
1. Importance of Board Processes
Directors act as fiduciaries, bearing responsibilities to act in the company's and stakeholders' best
interests.
Section 118(10) of the Companies Act, 2013 mandates adherence to Secretarial Standards on the
Meetings of the Board of Directors (SS-1), issued by the Institute of Company Secretaries of India
(ICSI).
SS-1 provides clarity and establishes good governance practices in areas where laws may be silent or
ambiguous.
2. Key Provisions Mandating Board Processes
Board processes include various elements essential for efficient governance:
Appointment and Resignation
Meetings of the Board and Committees
Meeting of Members
Meetings of Committees that exercise powers of the Board under Section 179 of Companies Act, 2013
Board’s Performance Evaluation and Training
Auditor's Role in Verifying Board Processes
Auditors must ensure the company follows robust board processes by verifying:
Notices of Meetings
182
Agenda and Supporting Records
Minutes of Meetings
Compliance with Internal Policies
If deviations from applicable laws or internal processes are observed, these should be reported by the
auditor.
Components of Board Processes
Board processes can be broadly divided into two parts:
Part A – Board Structure
Focuses on the composition and organization of the board, including:
o Size and composition of the board.
o Optimum balance between executive, non-executive, and independent directors.
o Specific roles and responsibilities of board members.
Part B – Board Systems and Procedures
Covers the decision-making processes of the board and its committees, including:
o Preparation and circulation of meeting agendas.
o Effective documentation and compliance with SS-1.
o Regular evaluation of the board's performance.
o Mechanisms to ensure accountability and transparency.
Key Aspects of Board Composition and Board Processes
1. Board Composition
Overall composition: Ensure the board meets the minimum and maximum composition requirements
as set by the Companies Act, SEBI regulations, and the Articles of Association.
Optimum mix: Verify that the board has an appropriate combination of executive, non-executive,
independent, non-independent, woman, and nominee directors as mandated by law.
Eligibility of Directors: Ensure that directors meet the eligibility criteria set out in relevant statutes
(e.g., Companies Act, SEBI).
Committee Composition: Verify that board committees (Audit, Nomination, and Remuneration, etc.)
are properly constituted according to regulatory guidelines.
2. Board Processes
Decision Recording: The auditor verifies that decisions made by the board and its committees are
recorded and comply with legal and internal requirements.
Internal Processes: The auditor checks whether the board follows internal procedures and resolves
conflicts between provisions, ensuring stricter compliance is met.
Role of Systems and Processes in Secretarial Audit
The secretarial auditor’s responsibility is to assess the adequacy and effectiveness of the auditee's systems
and processes concerning its size and operation.
✅ Purpose of Reviewing Systems and Processes:
1. Compliance Assurance – To verify that the company complies with applicable laws, standards, and
guidelines.
183
2. Internal Control Effectiveness – To evaluate whether there are effective controls for timely and proper
compliance.
3. Governance and Escalation – To check whether non-compliance issues are identified, escalated, and
addressed transparently.
✅ Key Steps in Verifying Systems & Processes:
1. Examination of Records – Verify statutory registers, filings, meeting minutes, and policies.
2. Compliance Tracking – Check how the company identifies and monitors compliance requirements and
deadlines.
3. Responsibility Mapping – Review how compliance responsibilities are assigned and monitored.
4. Escalation Mechanism – Assess if non-compliance is reported to senior management and addressed.
5. Review of Legal Notices & Penalties – Analyze past show-cause notices, penalties, prosecution history,
etc.
♂️Detection of Fraud – Auditor’s Role
Must maintain:
o Professional Judgement – Apply experience & ethics
o Professional Scepticism – Questioning mind & critical assessment
🧩 Look Out For:
Conflicting or unreliable audit evidence
Weak internal control systems
Whistleblower complaints
External audit reports
🔍 What is Suspicion?
Suspicion = More definite than speculation, but less than evidence-based knowledge.
Not enough to act unless some tentative evidence exists.
Simple doubt ≠ suspicion.
Examples of suspicious signs:
Recurring negative cash flows despite earnings.
Artificial earnings trends maintained by management.
📌 Auditor's Duty When Fraud is Suspected:
1. Communicate with internal/statutory auditors.
2. Collect sufficient evidence to justify suspicion.
3. Examine:
o Internal control systems
o Whistleblower complaints
o Reports of other auditors
4. Auditor must have justifiable grounds before concluding fraud.
⚠️Fraud-Prone Transactions (Important Areas):
1. Related Party Transactions
184
2. Excessive Managerial Remuneration
3. Insider Trading
4. Inter-company Transactions
5. Mergers / Demergers / Acquisitions
6. IPO Frauds
7. Others:
o Inadequate disclosures
o False info / expenses
o Theft of assets/data
o Dishonest partners
o Corruption
o Fraudulent billing
These examples are guidelines for fraud detection and not an exhaustive list.
🔍 Reporting of Fraud – Section 143(12)
When a Secretarial Auditor (Company Secretary in Practice) finds that a fraud is being or has been
committed by the company’s officers/employees, they must report it.
📜 Legal Duty – Section 143(12)
If fraud ≥ ₹1 crore → Report to Central Government.
If fraud < ₹1 crore → Report to Audit Committee or Board (within 2 days of knowledge).
Such companies must disclose fraud details in Board’s Report if not reported to Central Govt.
🧾 Details to be Reported (for < ₹1 crore fraud)
Must include:
(a) Nature of fraud
(b) Approx. amount involved
(c) Parties involved
📘 Disclosures in Board’s Report
If reported to Audit Committee/Board:
(a) Nature of fraud
(b) Approx. amount
(c) Parties involved (if no action taken)
(d) Remedial actions taken
⚖️Penalty for Non-Compliance (BB)
If CS in Practice fails to report fraud:
₹5 lakh penalty – for listed companies
₹1 lakh penalty – for other companies
(Sec 143(15))
✅ Good Faith Protection: As per Sec 143(13), no action shall be taken against the auditor if the reporting is
done in good faith
👤 Who is Considered as an Auditor for Fraud Reporting?
Auditors covered under Section 143 of the Companies Act, 2013:
✅ Statutory Auditor under Section 139
✅ Company Secretary in Practice doing Secretarial Audit under Section 204
✅ Cost Accountant in Practice doing Cost Audit under Section 148
✅ Branch Auditor under Section 143(8)
185
❌ Not Covered under Sec 143:
Internal Auditors
Tax Auditors under the Income Tax Act
GST Auditors under GST laws
📚 Case Study: M/s ABC & Co. – Fraud of ₹3.5 Crore
Secretarial Auditor found fraud during audit, missed by Statutory Auditor.
As per Rule 13 of Companies (Audit & Auditors) Rules, 2014, the process is:
📝 Step-wise Duty of Reporting (If Fraud ≥ ₹1 crore):
1. Inform Audit Committee/Board within 2 days of knowledge.
2. Wait for their reply/observations (within 45 days).
3. Send report + their reply + your comments to Central Govt within 15 days of reply.
4. If no reply received in 45 days, still send report with a note explaining no response.
5. Send report to MCA Secretary via:
o Registered/Speed Post (sealed cover)
o Followed by email confirmation
6. Use Form ADT-4 for reporting.
⚖️Penalties for Non-Reporting (Section 143(15)):
₹5 lakh → for Listed Companies
₹1 lakh → for Other Companies
🔍 Challenges in Estimating Fraud Amount
Auditors usually rely on management’s reasonable estimates.
Complexity & delay in detection can cause difficulty in estimating loss.
If fraud later crosses ₹1 crore, it must be reported to Central Govt within 45 days from knowing
revised amount.
⚠️Fraud from Regulatory Non-Compliance?
Yes - even regulatory violations (e.g., bribery, money laundering, corruption) are frauds if the monetary
impact is quantifiable.
➡️If amount < ₹1 crore → Report to Audit Committee/Board
➡️If amount ≥ ₹1 crore → Report to Central Government
Auditor must be very careful in estimating fraud amount accurately.
📜 Procedure for Reporting Fraud (BB)
(i) Reporting Fraud Involving Amount Equal To (OR) Greater Than ₹1 Crore:
1. Report to Board/Audit Committee
o Timeline: Within 2 days of auditor’s knowledge of fraud.
o Action: Auditor reports fraud to the Board or Audit Committee and asks for their reply within
45 days.
2. Report to Central Government
o Timeline: After receiving the Board's reply (or observations), auditor must send report +
reply/comments to Central Government within 15 days.
186
3. If No Reply from Board/Audit Committee
o Timeline: If no reply is received within 45 days, auditor sends report directly to Central
Government along with a note explaining the lack of response.
Form ADT 4:
o The report must be in the form of a statement as specified in Form ADT-4 and sent via
Registered Post/Speed Post and confirmed by email.
(ii) Reporting Fraud Involving Amount Less Than ₹1 Crore:
1. Report to Audit Committee/Board
o Timeline: Within 2 days of auditor’s knowledge of fraud.
o Details to Include:
Nature of the fraud
Approximate amount of fraud
Parties involved
2. Board’s Disclosure
o Action: Board must disclose fraud details in the Board’s Report including:
Nature, amount, and parties involved
Remedial actions taken
o Exception: If no remedial action was taken by the Board, the names of involved parties must be
disclosed.
Fraud vs. Non-Compliance
Fraud:
Fraud refers to any act or deception intended to:
1. Gain an unlawful or unfair advantage.
2. Cause harm or injury on someone or something.
3. Induce another party to give up something valuable or a legal right.
Wilful fraud is considered a criminal offense, and it attracts severe penalties, including prosecution
and punishment.
However, incompetence or negligence in managing a business, or reckless behavior like wasting
company assets (for example, speculating in the stock market), does not typically qualify as fraud.
Non-Compliance:
Non-compliance refers to the failure to adhere to laws, rules, regulations, or specific compliance
requirements. This could include failing to follow procedures, file necessary information, meet
eligibility conditions, or report as required.
Relationship Between Fraud and Non-Compliance:
Non-compliance in a company may lead to fraud if the failure to comply results in deceptive actions or
misconduct.
However, fraud can still occur in a compliant company, meaning that non-compliance does not
necessarily have to precede fraud.
Identification and Reporting of Major Events/Actions (BB)
187
Secretarial auditors must identify and report any event or action that has a major bearing on the company’s
affairs or governance, in compliance with applicable laws and regulations. This involves:
1. Assessing Events/Actions with Major Impact on Company’s Affairs
Auditors must identify material events or actions that affect the company’s affairs based on:
🧮 The size of the transaction relative to the company’s turnover, net worth, or profits.
🔄 Whether the transaction is in the ordinary course of business.
📈 Whether the transaction signifies a shift from the company’s strategy.
🔍 Whether failure to report would result in significant market reaction later.
2. Examples of Events Having a Major Bearing on Affairs
These include:
🧩 Mergers or Amalgamations.
⭐ Changes in credit ratings.
⚠️Fraud or defaults by promoters, key managerial personnel, or the company.
📑Important Agreements outside normal business:
o Shareholder agreements
o JV agreements
o Family settlements (affecting management/control)
o Media contracts
o Revisions, terminations, etc.
3. Events Considered Material under SEBI (LODR) Regulations, 2015
The following are considered as major events for listed entities (esp. involving NCDs/NCRPS):
1. ❌ Default in interest/dividend/redemption/security creation
2. 🛑 Prohibitory orders on transfer of NCDs with holder/demat details
3. 🔄 Redemption/Conversion/Cancellation of non-convertible securities
4. 💥 Events affecting interest/dividend payments
5. 🔧 Change in nature/form/rights of listed securities
6. Change in business/natural calamity/disruption of operations
7. ⚙️Strikes or lockouts impacting repayment
8. ✉️Debenture trustee comments on delays/non-payments
9. ⏳ Delays > 3 months in any payment
10. 🔐 Failure to create charge on assets
11. 📉 Default in repayment (interest or principal), rescheduling of dues
"Default" = First instance of non-payment on due date
12. 👥 Major Board changes = Change in control (as per SEBI Takeover Regulations)
13. ⭐ Rating revisions
14. 📝 Board approvals like:
o Skipping interest payments
o Bonus/right issue for debt holders
15. 📄 All disclosures related to NCDs/NCRPS
16. ⚠️Fraud or arrest of promoter/KMP/directors/employees.
Impact of Audit Report
1. Legal and Procedural Confidence
188
It assures directors and key managerial personnel that the company is meeting legal requirements,
allowing them to focus on core business matters.
2. Risk Management Tool
Secretarial Audit serves as an important governance and compliance risk management tool,
identifying potential legal or procedural risks.
3. Informed Investment Decisions
Secretarial Audit helps investors assess the company's compliance and governance practices. This
enables them to make informed investment or joint venture decisions.
4. Due Diligence for Stakeholders
It acts as an effective due diligence tool for prospective investors and partners, ensuring that the
company follows required legal and regulatory norms.
5. Strengthening Goodwill
The audit process enhances the company’s goodwill with regulators and stakeholders, promoting a
positive corporate image.
6. Reputation Enhancement
By analyzing a company's compliance level, Secretarial Audit helps enhance the company’s reputation,
showing it adheres to high governance standards.
Form No. MR-3
Secretarial Audit Report for the Financial Year Ended [Year]
(Pursuant to Section 204(1) of the Companies Act, 2013 and Rule No. 9 of the Companies (Appointment and
Remuneration of Managerial Personnel) Rules, 2014)
To,
The Members,
[Name of the Company]
[Address of the Company]
Dear Members,
I/We have conducted the secretarial audit of the compliance with applicable statutory provisions and the
adherence to good corporate practices by [Name of the Company] ("the Company"). The audit was conducted
in a manner that provided me/us with a reasonable basis for evaluating the corporate conduct and statutory
compliance, and for expressing my/our opinion thereon.
Scope of the Audit
Based on my/our verification of the books, papers, minute books, forms, returns filed, and other records
maintained by the Company and the information provided by the Company's officers, agents, and authorized
representatives, I/We hereby report that:
During the financial year ended [Year], the Company has complied with the statutory provisions listed
below and has established proper Board processes and compliance mechanisms as outlined in this
report:
189
A. Examined Documents and Compliance with Laws
I/We have examined the compliance of the Company with:
1. Companies Act, 2013 and its Rules
2. Securities Contracts (Regulation) Act, 1956 ('SCRA')
3. Depositories Act, 1996 and related Bye-laws
4. Foreign Exchange Management Act, 1999 (including rules on FDI, ODI, and ECBs)
5. Securities and Exchange Board of India (SEBI) Regulations
6. Other Applicable Laws:
(Specify the laws specific to the industry or operations of the Company, such as labor laws, environmental
regulations, etc.)
7. Secretarial Standards issued by the Institute of Company Secretaries of India (ICSI).
8. Listing Agreement (if applicable).
B. Observations
During the period under review, the Company has:
Complied with the provisions of applicable laws and regulations subject to the following observations:
(Provide specific non-compliance details or qualifications, if any.)
C. Corporate Governance and Board Processes
1. The Board of Directors of the Company is duly constituted with a proper balance of Executive, Non-
Executive, and Independent Directors.
2. Notices for Board Meetings were given adequately, along with agenda and supporting documents
shared at least seven days in advance.
3. Decision-making during Board Meetings followed democratic processes, with dissenting views
recorded in the minutes.
D. Systems and Processes
The Company has adequate systems and processes commensurate with its size and operations to ensure
compliance with applicable laws and regulations.
E. Key Events During the Period
During the audit period, the following significant events occurred:
1. Public/Preferential issue of shares or securities.
2. Redemption/Buyback of securities.
3. Merger/Amalgamation/Corporate restructuring.
4. Major decisions under Section 180 of the Companies Act, 2013.
5. Foreign technical collaborations.
(Specify details as applicable.)
Place: [City]
Date: [Date]
190
For [Name of Firm]
Signature:
[Name of Company Secretary in Practice]
ACS/FCS No.: [Membership Number]
C.P. No.: [Certificate of Practice Number]
(Annex additional findings or details, if necessary.)
Lesson: 14 (Internal Audit & Performance Audit)
📖 Definition of Internal Audit: By Institute of Internal Auditors (IIA):
Internal auditing is an Independent, objective assurance & consulting activity designed to add value and
improve operations.
🎯 Key Goals:
Focused on achieving organizational objectives through a systematic, disciplined approach to evaluate and
improve the effectiveness of:
Risk Management
Control Processes
Governance Practices.
📊Internal Audit Focus Areas:
1. Compliance with applicable laws, regulations, and contracts.
2. Effectiveness and efficiency of operations.
3. Reliability and integrity of financial and operational information.
4. Safeguarding assets.
⚙️Nature of Internal Audit
Nature Description
Management Internal Audit is a management tool conducted by employees or external professionals
Tool to evaluate the effectiveness of internal controls and checks. Reports are usually
directed to the Board of Directors or the Audit Committee.
Risk Supports development and evaluation of risk management processes and ensures
Management they align with key objectives. This includes roles in business continuity planning,
Tool information security, and privacy systems.
Continuous Ongoing examination of operations & records Internal Audit acts as a control
Exercise mechanism, examining and assessing the efficacy of other control systems in the
organization.
Control System Reviews and evaluates efficacy of existing controls systems in the organisation.
Internal Audit under the Companies Act, 2013
191
The Companies Act, 2013, under Section 138, recognizes internal audit as a statutory requirement for
certain classes of companies. Below are the key provisions:
Applicability (BB)
Internal Audit is mandatory for:
1. Listed Companies:
All listed companies must appoint an internal auditor.
2. Unlisted Public Companies with any of the following:
o Outstanding Deposits: ₹25 crore or more at any time during the preceding financial year.
o Paid-up Share Capital: ₹50 crore or more during the preceding financial year.
o Outstanding Loans/Borrowings: ₹100 crore or more from banks or financial institutions at any
time during the preceding financial year.
o Turnover: ₹200 crore or more during the preceding financial year.
3. Private Companies with either of the following:
o Outstanding Loans/Borrowings: ₹100 crore or more from banks or financial institutions at any
time during the preceding financial year.
o Turnover: ₹200 crore or more during the preceding financial year.
👩⚖️Who can be appointed as Internal Auditor?
A Chartered Accountant or Cost Accountant (whether in practice or not) (OR)
Any other professional as decided by the Board
📌 Can be:
An individual
A partnership firm
A body corporate
🚫 Statutory Auditor CANNOT be appointed as Internal Auditor.
📅 Periodicity of Internal Audit
No timeline prescribed by law
✅ But quarterly audit is best practice for strong compliance monitoring.
⚠️Penalty for Non-Compliance – Section 450
Situation Penalty
Default ₹10,000
Continuing default ₹1,000 per day
Maximum penalty ₹2,00,000 (Company) / ₹50,000 (Officer in default)
🧑💼 Role of Company Secretary as Internal Auditor (BB)
A CS, if appointed as Internal Auditor, is expected to:
1. ✅ Ensure accounting standards and conventions by the company.
2. ✅ Ensure audit of financial statements and books of accounts.
3. ✅ Design audit methodologies and reporting systems.
192
4. ✅ Oversee compliance tracking and financial risk assessment.
5. ✅ Maintain meeting records and statutory registers.
6. ✅ Advise on finance, litigation, capital, debt, and tax planning.
7. ✅ Prepare cost structures and efficiency indicators.
📋Appointment of Internal Auditor
🧾 Key Rules:
Appointed by: ✅ Board of Directors (Not shareholders/statutory auditor)
➡️By passing Board Resolution
Resolution to be filed with ROC within 30 days in e-Form MGT-14
🧷 Exemption:
📌 Private Companies are exempt from filing MGT-14 (via MCA notification dated 5 June 2015)
➡️Only Public Companies need to file MGT-14 for Internal Auditor appointment.
Terms of Reference for Internal Audit
The terms of reference (or audit manual) formalize the scope of the internal audit and should be approved
by the board, usually through the audit committee. These terms should include:
Should define Internal Audit’s:
🎯 Strategy & Objectives
🔍 Scope of Work
🧩 Role & Responsibilities
🧾 Accountability to Audit Committee
🧑💼 Access to Board & Audit Committee
🔓 Unfettered Access to all info, people, records
🔄 Reporting Lines for management purposes.
Must ensure independence – Internal Audit must not review its own work
Essential Skills for Internal Auditors
General Skills
1. Technical Standards
o Knowledge of applicable accounting standards and their practical application.
2. IT Skills
o Ability to work in IT-driven environments, understand technology integration in operations,
and use IT tools for auditing.
3. Interpersonal Skills + Attitude
o Maintain objectivity and possess effective communication and interpersonal skills.
4. Interviewing Skills
o Proficiency in extracting information through verbal interaction, questioning, and analyzing
processes to identify compliance gaps.
5. Audit Documentation Skills
o Skills to compile, organize, and present audit findings logically, backed by adequate evidence.
6. Reporting Skills
o Draft clear, objective audit reports. Include: Facts, Impact, Cause, Recommendations.
193
Specific Skills (PTM PKM)
1. Planning Audit Engagements
o Conduct risk assessments and prioritize significant issues to focus on during audits.
2. Team Building
o Coordinate and motivate teams. Assign roles, define authority and expectations
3. Managing Audit Engagements
o Meet stakeholders, set clear expectations, and ensure smooth execution.
4. Professional Presentations
o Present to Audit Committee the findings clearly and concisely. Highlight key risks and findings.
5. Knowledge Management Skills
o Understand entity’s operations + external environment. Manage info flow, collate, apply, update
and benchmark knowledge. Decide: What to share? With whom? When?
Additional Skills (Mnemonic: AC-BV-TIC-DL)
Analytical/Critical Thinking
Business Acumen
Vigilant, Inquisitive, Cautious
Trace facts & figures
Independent Decision-making
Courage, Assertiveness, Determination
Leadership via Punctuality, Reliability, Updated Knowledge.
Objectives of Internal Audit (Mnemonic: M-FAVAL)
1. M – Reviewing Managerial functions
2. F – Detection of Frauds and Errors
3. A – Adherence to Accounting Standards
4. V – Verifying assets and liabilities
5. A – Verifying Accuracy of accounts
6. L – Reviewing Internal checks & controls
✅ Detailed Functional Objectives
Internal Audit reviews & appraises the following:
1. 📚 Statutory Compliance
o Checks compliance with laws and regulations
2. 📜 Policy Compliance
o Examines relevance, adequacy, adherence to existing policies, plans, procedures
3. Audit Recommendations
o Tracks implementation status of internal/external audit suggestions
4. 🔄 Operational Control Framework
o Covers core systems across business functions
o Includes fraud risk assessment & mitigation
5. 🧠 Evaluation of Internal Control
o Ensures:
✅ Effectiveness of operations
194
📈 Reliability of financial reports
⚖️Legal compliance
🎯 Goal accomplishment
🔐 Safeguarding assets
6. ⚠️Risk Assessment & Management
o Detects and defines risk areas
o Builds a risk management framework
o Identifies potential threats
o Decides risk responses (control, mitigation)
o Monitors RM processes and outcomes
🔹 Scope of Internal Audit
Defined by the Institute of Internal Auditors:
“Examination and evaluation of the adequacy and effectiveness of the organisation’s internal control system and
quality of actual performance.”
🌐 Key Areas Covered:
🧾 Compliance with laws, policies, and standards
📊 Assessment of actual performance vs goals
🔎 Review of internal control systems
🚦 Evaluation of risk management systems
💼 Review of financial, operational, and strategic controls
🔹Scope of Internal Audit (BB)
It includes detailed review of the following areas of operation:
1. Compliance with Laws, Policies, Plans, Procedures, and Regulations
📜 Objective: To ensure all operations follow relevant legal and internal guidelines.
Auditor evaluates compliance using:
o ✅ System reviews (adequacy of controls)
o 📊 Compliance tests (actual adherence)
o 🔧 Suggests remedies for any weaknesses found.
2. Review of Internal Control Systems and Procedures
Auditor checks if the internal control system suits the organisation’s structure.
Controls should ideally be built into operations where possible and cost-effective.
Each control is analysed in terms of:
o ✅ Cost-benefit
o 📆 Consistency over the entire period of reliance
o ⚠️If any breakdown in control is found, it needs focused attention.
3. Accomplishment of Established Goals for Operations
🔍 Key Focus: Whether the organisation's goals are clearly defined, regularly updated, measurable, and
effectively implemented.
195
🔑 Internal Auditor's Role:
Review enterprise objectives: Ensure they are clearly stated and achievable.
Quantifiable objectives: Ensure objectives are in measurable terms (monetary & non-monetary).
Clear accountability: Every goal or plan component should have a clearly assigned responsible
person/department.
Top management support: Check if departmental plans are approved and supported by higher
management.
Communication: Summaries of plans should be shared, discussed, and aligned across departments
during meetings.
4. Reliability and Integrity of Financial and Operating Information
Internal auditor reviews:
o 🔍 Information systems used to prepare financial & operational data
o 📋 Accuracy, classification, and reporting of such information
This ensures:
o 📈 Reliable and accurate reports to management & external bodies (like govt., trade bodies,
unions)
o Reports are timely and meet statutory deadlines
o 💡 Information is useful and meaningful to users
o 💸 Cost-effective reporting process.
5. Economical and Efficient Use of Resources
🛠 Objective: To check whether resources are being used in a cost-effective and efficient manner.
Internal auditor should verify if operating standards and norms are:
o Clearly established 📏
o Linked to specific responsibilities
o Useful for monitoring performance 📊
Auditor should identify:
o 🔻 Under-utilized assets (e.g., idle machines, unoccupied storage, excessive cash, etc.)
o 🔺 Over-staffing or under-staffing
o 🧍♂️Non-productive work by observing actual duties vs. job descriptions
6. Review of Custodianship & Safeguarding of Assets
🔍 Key Focus: Whether physical and intangible assets are protected, controlled, and adequately insured.
🔑 Internal Auditor's Role:
Asset existence: Verify whether all assets are physically present and recorded.
Control systems: Review whether systems exist to track and secure all assets.
Safeguards against loss: Ensure protection from:
o Fire, theft, negligence and illegal acts
Insurance cover: Check adequacy of insurance for all major risks.
7. Review of Organisational Structure
🏗 Objective: To assess whether the structure supports the enterprise’s objectives and efficient functioning.
196
Auditor evaluates:
o ⚖️Balance of power — authority should match responsibility
o 👥 Span of control — number of subordinates each executive handles
o 📢 Unity of command — each person should report to only one superior
Also reviews:
o 🚪 Flexibility in daily operations — rules shouldn’t suppress initiative
o 🔄 Information flow — free and fast communication reduces rigidity
o 🎓 Managerial development — grooming future leaders is crucial in growing firms.
✅ Internal Audit – Core Principles (As per IIA)
An effective Internal Audit function must consistently demonstrate all of these principles. Missing even one
implies reduced effectiveness.
🔟 Core Principles:
I Can Independently Align Proper Quality Communication for Risky Insightful Promotion.
(Each word stands for one principle!)
1. I – Integrity
2. Can – Competence & care
3. Independently – Independent & objective
4. Align – Aligned with strategies, etc.
5. Proper – Properly positioned & resourced
6. Quality – Quality & improvement
7. Communication – Communicates effectively
8. Risky – Risk-based assurance
9. Insightful – Insightful, proactive, future-focused
10. Promotion – Promotes org improvement.
🧾 Case Study 1 – Credit Suisse: Failure in Risk Assessments
⚠️Key Issues:
Material weaknesses in internal control over financial reporting (2021–2022).
Failure to design and maintain an effective risk assessment process.
Ineffective internal control and poor communication systems.
🔍 Core Principles Violated:
Principle 4: Misalignment with risks.
Principle 8: Weak risk-based assurance.
Principle 7: Ineffective communication.
Principle 6: Lack of continuous improvement.
🎬 Case Study 2 – Netflix: Internal Control Failures
🔍 Background:
Michael Kail, VP of IT (2011–2014), misused position for personal gain.
Approved contracts based on kickbacks worth $500,000+.
Violated ethics policies due to poor internal control & monitoring.
🧩 Root Cause:
Lack of ethical culture, monitoring, and control execution.
197
Netflix had policies (Code of Ethics, etc.), but no strong enforcement or checks.
🛑 COSO Framework Gaps:
Control environment
Monitoring activities
Risk assessment and control activities
🔍 Core Principles Violated:
Principle 1: Integrity failure.
Principle 3: Lack of objectivity.
Principle 6 & 8: Poor control quality and risk assurance.
Principle 10: Failed to promote organisational improvement.
✅ Recommended controls to prevent & detect fraud + Educate on fraud awareness
S. Control Purpose
No.
1 Segregation of Duties Prevents one person from having control over multiple aspects of a
transaction (e.g., maker-checker-approver system).
2 Rotation of Duties Helps uncover fraud by periodically rotating key roles. Example: PNB
fraud happened due to lack of rotation.
3 Mandatory Vacation Allows detection of hidden frauds while key employees are away. Also
improves employee well-being.
4 Treat Employees Well Fair treatment, recognition, and timely promotions reduce the risk of
fraud driven by revenge or dissatisfaction.
5 Regular Audits Helps in early detection of frauds, especially in remote sites or large
projects.
6 Background Checks Ensures trustworthy hiring, especially for high-risk or trusted roles.
7 Whistleblower Hotline Confidential reporting mechanism with no fear of retaliation.
8 Use of Technology Fraud detection software and data analytics can reveal suspicious
patterns.
9 Fraud Awareness Training Educates employees on fraud risks and reporting. Maintain training
proof in HR records.
10 Code of Conduct Clearly outlines ethical expectations and standards for behavior.
11 Management Oversight & Senior leaders and independent directors must model integrity and
Tone at the Top review transactions.
12 Reinforce Accountability Ensure consequences are enforced for wrongdoing to discourage
fraud.
13 Document Retention Policy Keeps necessary records safe, prevents destruction of evidence.
➕ Policy Change Inform all stakeholders (employees, vendors, customers) of any
Communication policy/procedure changes and collect proof of their understanding.
⚖️Independence of Internal Auditor (BB)
Definition:
o Independence = Freedom from conditions that impair unbiased judgment.
o Objectivity = Honest, confident belief in one's work without influence.
Need for Independence:
o Internal audit must be able to evaluate management functions honestly.
o An internal auditor should not be subordinate to lower-level management.
Positioning:
198
o Should report directly to the Board or Audit Committee, not management.
o Enables freedom to define audit scope, share findings, and function independently.
Outsider Advantage:
o Outsourced auditors (CA, CS firms) are usually more independent than company employees.
Note: Though internal audit can be done by employees or professionals (as per Companies Act, 2013),
effective functioning depends on their actual independence.
Factors Impairing the Independence of Internal Auditors
1. Non-audit Services to Audit Clients
o Offering non-audit services creates self-review threats.
2. Family and Personal Relationships
o Close relations with the client can result in familiarity threats and conflicts of interest.
3. Business Relationships
o Commercial or financial interests between the auditor and client lead to self-interest or advocacy
threats.
4. Employment with Audit Client
o Employment relationships create self-review, familiarity, and intimidation threats. It gives the
impression that the audit is not performed independently.
5. Prior Work with Audit Client
o Previous engagements with the client may lead to familiarity threats, particularly if the work
experience resulted in good relationships between them.
6. Gift and Hospitality
o Accepting gifts or hospitality from clients creates self-interest threats, jeopardizing objectivity. It
impairs the auditor’s objectivity.
Internal Audit Techniques (BB)
1. Review of Operating Environment
Understand the company's operations through discussions with employees, external auditor reports,
and risk specialists.
Assess management’s ethical qualities, leadership style, and business practices and evaluate industry
trends and regulations affecting the company.
2. Review Controls
Evaluate the operational effectiveness of a company’s internal controls by analyzing prior audit reports
and interacting with employees involved in control execution.
Utilize Generally Accepted Auditing Standards (GAAS) to assess control mechanisms and
methodologies.
3. Test Controls
Ensures controls are designed well and working. Focuses on preventing fraud/losses and ensuring
clear procedures.
199
4. Account Details Testing (Substantive Testing)
Perform substantive tests on account details and balances to confirm that financial statements are
free from material misstatements.
Investigate potential misstatements caused by errors, fraud, or system weaknesses.
🔁 Internal Audit Process: Step-wise Approach (BB)
1. Define Audit Scope & Objectives – In consultation with management.
2. Understand Business Area – Review documents, interview staff, create flowcharts.
3. Identify Risks – Linked to key activities and transactions.
4. Assess Controls – Map controls to each risk and transaction.
5. Test Controls – Ensure key controls are working effectively.
6. Report Issues & Action Plans – Discuss with management and agree on corrective actions.
7. Follow-up – Use a tracking system to ensure timely implementation.
Evaluation of Internal Audit Function by an Auditor
During the Secretarial Audit, the Secretarial Auditor evaluates the internal audit function to determine its
adequacy and reliability. Key aspects to consider:
🏢 Organizational Status:
o Assess whether internal audit is conducted in-house or outsourced.
o Ensure the internal auditor reports to the highest management level and operates
independently.
📘 Scope of Audit Function:
o Understand the breadth of the internal auditor's responsibilities and how management
addresses their recommendations.
🎓 Technical Competence:
o Review the qualifications, experience, and training of internal audit personnel.
📋 Due Professional Care:
o Verify whether internal audit work is well-planned, documented, and reviewed, supported by
audit manuals and working papers.
🔐 Monitoring of Internal Control:
o Evaluate how effectively the internal audit function reviews and improves control mechanisms.
⚠️Risk Management:
o Examine the internal audit’s role in identifying and managing significant risks.
⚙️Review of Operating Activities:
o Assess the efficiency and effectiveness of operational and non-financial activities.
⚖️Compliance Review:
o Ensure adherence to laws, regulations, management policies, and internal directives.
🧭 Governance:
o Review internal audit’s contribution to governance processes, including ethics, performance
management, and risk communication.
🧱 Corporate Governance Framework
Involves structures and processes led by the Board to guide, control, and manage company resources and
policies towards achieving objectives.
200
🔹 Four Pillars of Corporate Governance
1. Board of Directors
2. Management
3. External Auditor
4. Internal Auditor
📌 Role of Internal Auditor in Governance
Supports the Audit Committee by:
o Reporting internal control issues
o Privately evaluating key managerial capabilities
o Suggesting agenda topics
o Coordinating with external auditor and management to ensure effective, informed decisions.
Case Study: Satyam Computer Services Fraud, India (2009) 🚨
Background:
Founded in 1987 by Ramalinga Raju in Hyderabad and became a top outsourcing IT company with
53,000+ employees.
Trigger Event:
In Dec 2008, Satyam tried to invest $1.6 billion in Maytas (Raju’s family firm) without shareholder
approval and this move failed and raised suspicions → stock plummeted.
Fraud Techniques Used:
Inflated cash/bank balances (₹5040 Cr), overstated debtors, fake interest incomes.
Understated liabilities (₹1230 Cr).
Fake invoices and salary accounts.
Used special software (‘Ontime’, Super User ID) to hide fake transactions.
Personal bank statements were forged.
Manipulated income statements to meet investor expectations.
Why Did It Happen?
Fear of takeover due to poor promoter shareholding.
Greed for reputation and financial gain.
Desire to project consistent growth to attract investors.
Audit Failure:
Internal audit ineffective – didn’t detect fraud.
External auditor PwC trusted forged bank documents without verification.
Audit fees increased unusually from ₹6.5 Mn to ₹37 Mn – suggesting possible bribery.
Outcome:
Govt disbanded Satyam’s board.
Raju & 9 others sentenced to 7 years in 2015.
Tech Mahindra acquired Satyam in 2012, forming India’s 5th largest IT company.
Report Writing – Communicating Engagement Results
Effective internal audit reporting ensures findings and recommendations are clearly communicated to
management and stakeholders.
Objectives of Reporting:
1. Share significant findings and audit results with auditees.
2. Enable management to understand issues and take corrective action.
201
3. Leads to improved performance and strengthen the control framework
4. Facilitate follow-ups on action plans, reporting progress to senior management and the audit committee.
Key Components of Internal Audit Reporting:
1. What is Wrong?
Disclose findings and explain the processes involved in identifying them.
2. Why it is Wrong?
Conduct a root cause analysis to describe the issues.
3. How to Correct It?
Provide actionable recommendations and suggestions for improvement.
4. What Will Be Done?
Include the auditee’s views and action plans.
Key Legal Provisions on Internal Financial Controls and Audit Committees
1. Provisions under the Companies Act, 2013:
Audit Committee (Section 177)
Section 177(4)(vii):
o The Audit Committee must evaluate internal financial controls and risk management
systems as part of its terms of reference specified by the Board.
Section 177(5):
o The Audit Committee may:
Seek auditor’s comments on internal controls and audit scope.
Review financial statements before submission to the Board.
Discuss related matters with internal/statutory auditors and company management.
Auditor’s Report (Section 143(3)(i))
Auditors must report whether:
o The company has an adequate internal financial controls system.
o These controls are operating effectively.
Directors’ Responsibility Statement (Section 134(5)):
Directors of listed companies must confirm their responsibility for internal financial controls as part
of the Directors’ Responsibility Statement.
Companies (Accounts) Rules, 2014 – Rule 8(5)(viii):
The Board’s Report must include details on the adequacy of internal financial controls with reference
to financial statements.
🌐 Appraisal of Management Decisions
🎯 Internal audit has become an important management tool for the following reasons:
1. Ensures compliance with accounting policies/procedures.
2. Verifies effectiveness of internal control & accounting systems.
3. Assesses overall management control independently.
4. Specialized in evaluating business efficiency.
5. Checks accuracy of financial/operational data.
202
6. Ensures reliable and prompt MIS & reports for decision-making.
7. Assists in new ventures, product launches, and business expansions.
8. Overcomes internal ego, bias, and conflicts.
9. Acts as part of management by systems.
🧠 Objective of Appraisal of Management Decisions
To evaluate how decisions are made:
Was a proper decision-making process followed?
Do decisions align with organizational objectives?
Are decisions fairly documented?
✅ Steps in Appraisal of Management Decisions
1. Are decisions clearly defined?
2. Are objectives set clearly & aligned with policies/strategies?
o Should be SMART (Specific, Measurable, Agreed, Realistic, Time-bound).
3. Has management considered:
o Risk, time, scope, alternatives, market capacity, regulators’ role, environmental impact, etc.?
4. For major investments: Were various options considered?
5. Were options analyzed in terms of value, cost, benefit, risks?
6. Was consensus taken after full analysis?
7. Was the chosen alternative implemented efficiently?
8. Is there an ongoing review of decisions and control systems?
📊 Performance Assessment – Summary Notes
✅ Purpose of Performance Assessment
To review management’s expectations vs achievements of internal audit.
To suggest remedial actions for improvement.
Findings are reported to the Board/Audit Committee.
📌 Key Benchmarks for Assessing Audit Performance
1. Coverage of key risk areas.
2. Accuracy of audit findings.
3. Duration and timeliness of audits.
4. Feedback given during audit.
5. Usefulness of audit recommendations.
6. Value addition by the internal audit function.
Lesson: 15 (Peer Review and Quality Review)
Peer Review
203
Peer Review is a process where the work of a professional is examined by others in the same profession (their
peers). This process helps assess the systems, practices, and procedures followed by the Practice Unit. If
necessary, suggestions for improvement are made to enhance the quality of work.
🎯 Key Objectives:
1. Compliance Confirmation: Ensures adherence to:
o ICSI Auditing Standards
o Guidance Notes
o Manuals & Advisories
o Office administration systems
2. Corrective Actions: Identify gaps and suggest improvements.
3. Trust of Clients: Builds confidence among clients about the integrity of the Practice Unit.
4. Enhanced Credibility: Increases public and professional trust.
5. Quality Enhancement: Encourages continuous improvement in services delivered by PCS.
🌟 Benefits of Peer Review
Peer Review is not just a regulatory process—it’s a value addition tool for PCS and Practice Units.
1. ✔️Compliance Comfort
Provides assurance that statutory and documentary standards are being met.
2. 🏅 Credibility Booster
Issuance of Peer Review Certificate enhances the trust and visibility of the Practice Unit.
3. 🤝 Client Confidence
Clients value that the Practice Unit undergoes regular quality checks by ICSI.
4. Scope for Improvement
Identifies deficiencies and offers the chance to improve quality and competence.
5. 🔐 Safe Space (No Disciplinary Action)
Clear distinction between Peer Review and disciplinary actions ensures a non-threatening learning
process.
6. 📚 Knowledge Sharing & Guidance
Peer Review serves as a platform for professional development and mutual learning.
📜 Mandatory Assignments Only For Peer Reviewed PCS
From specified effective dates, only Peer Reviewed PCS are permitted to undertake the following
assignments:
📌 Assignments (with Applicability Dates):
Assignment Applicable From
Secretarial Audit (Sec. 204(1), Co. Act 2013) & SEBI Reg. 1st April 2022 (Listed) / 1st April 2023 (All
24A(1) Cos.)
Annual Secretarial Compliance Report (SEBI Reg. 24A(2)) 1st April 2022/2023
Certification of Annual Return (Sec. 92(2)) 1st April 2022/2023
Compliance Certificate (Schedule V, SEBI LODR) 1st April 2022/2023
SEBI Regulation 40(9) Certificate 1st April 2022/2023
Reconciliation of Share Capital (Reg. 76 SEBI D&P) 1st April 2022/2023
Internal Audit of Depository Participants 1st April 2020
Diligence Report for Banks (Consortium Lending) 1st July 2020
204
SEBI Delisting Due Diligence & Certification 10th June 2021
🔍 Scope Of Peer Review
Peer Review currently applies to specific attestation and audit services rendered by PCS.
✅ Covered Services:
1. MGT-8 Certification under Sec. 92(2), Companies Act, 2013
2. Secretarial Audit Report – Sec. 204, Companies Act, 2013
3. Secretarial Audit of material unlisted subsidiaries – SEBI Reg. 24A
4. Annual Secretarial Compliance Report – SEBI Circular (Feb 8, 2019)
5. Certification re: Director Disqualification – SEBI Reg. 34(3)
6. Certification of Share Transfer Timeliness – SEBI Reg. 40(9)
7. Internal Audit of DPs – As per NSDL/CDSL Byelaws
8. Share Capital Reconciliation – SEBI Reg. 76
9. Compliance Auditor – Haryana Third Party Certification Scheme
10. Diligence Report for Banks – Consortium lending, RBI circular
11. Internal Audit of Stock Brokers/Sub-brokers – SEBI Circulars
12. FEMA Compliance Certificate – Para 9(1)(B)(i), FEMA Notification No. 20
13. Corporate Governance Compliance – SEBI Reg. 34(3), Schedule V
14. MGT-7 (Annual Return) Signing – Sec. 92(1), Companies Act, 2013
15. Delisting Due Diligence Report – SEBI Reg. 10(3)
16. Shares Held by Inactive Shareholders – SEBI Delisting Reg. 21(a)(iii)
17. Compliance for Share-Based Benefits/Sweat Equity – SEBI Reg. 10(b), 13, 26, 27, 36
18. Scrutinizer’s Report – Sec. 108, Rule 20(4)(ix) and (xii)
19. All other Reports requiring UDIN – As per ICSI UDIN Guidelines, 2019
🔄 Dynamic Scope
📌 Note: The scope of Peer Review is dynamic, and the Council/Peer Review Committee may include more
services as regulations evolve.
📌 Key Powers and Functions:
📋 Operational Powers:
Call for relevant information from Practice Units (PUs).
Maintain a panel of qualified Peer Reviewers.
Define terms of appointment and engagement of Reviewers.
Provide a panel of 5 Reviewers to PUs for selection.
o If no choice is made, a second panel of 5 is provided.
o If still not chosen, PU may request names outside its region/state, and bear additional costs.
o If no local reviewers available, PU may choose from entire panel, covering travel and stay.
🔍 Review & Oversight:
Examine records and service compliance with regulations.
Prescribe systems, practices, and procedures to be followed during Peer Review.
🎓 Training & Guidance:
Arrange training and orientation for both Reviewers and PUs.
Provide guidance and advisories on best Peer Review practices.
205
📝 Post-Review Actions:
On receiving Reviewer’s report, the PRB may:
o Issue recommendations to PU.
o Order a further Peer Review.
o Upon satisfactory compliance, issue Peer Review Certificate (physical or digital).
🧭 Policy Recommendations to Council:
Recommend quality enhancement measures.
Suggest guidance frameworks for Attestation and Audit Service improvement.
🔧 General Administrative Powers:
Take incidental actions for functioning.
Form sub-committees for specific tasks if needed.
⚖️Authority & Applicability of Peer Review Guidelines
🔹 When Peer Review Guidelines Apply:
1. Voluntarily requested by the Practice Unit (PU)
2. Random selection by ICSI
3. Based on recommendation from:
o Committee of Discipline
o Disciplinary Committee
o Quality Review Board (QRB)
o Council of ICSI
4. Mandated by Government/Regulators/Statutory Bodies
5. Post-legislative amendments as notified by ICSI Council.
🏢 Peer Review For Practice Units With Branches
📌 Whole Firm Review Principle:
If a Practice Unit has branch office(s), Peer Review is applicable to the entire unit, not just the head office or
any specific branch.
🧑⚖️Qualifications For A Peer Reviewer
To be empanelled, an individual must:
✅ Eligibility Criteria:
Be an ICSI Member with 10+ years post-qualification experience as a Company Secretary
Out of 10 years, have minimum 5 years in continuous practice
Hold a valid Certificate of Practice (COP)
Have completed the Training & Certification Programme for Peer Reviewers.
❌ Disqualifications:
Any disciplinary proceedings pending in the last 3 years
Found guilty of professional/other misconduct by ICSI's disciplinary bodies
206
Convicted by a court (in India or abroad) of an offence involving moral turpitude
Sitting members of:
o Council
o Regional Council
o Chapter Management Committee
o Peer Review Board
→ Cannot act as Peer Reviewers during tenure.
📝 Empanelment Process
The Peer Review Board (PRB) invites applications in a prescribed format
The form captures:
o Professional experience
o Qualifications
o Area(s) of practice
The PRB matches Reviewer profiles with Practice Unit profiles to ensure suitability
The PRB may remove a Reviewer from the panel if the quality of reports is unsatisfactory.
🔍 The Reviewer’s Approach for Peer Review
The Reviewer must approach Peer Review with:
1. Professionalism and Courteousness: The reviewer must maintain a courteous and professional
attitude throughout the review process.
2. Collaborative Approach: The reviewer should work collaboratively with the Practice Unit to ensure
minimal disruption during the review.
3. Appreciation of Good Practices: While identifying areas of improvement, the reviewer should also
acknowledge and appreciate good practices observed in the Practice Unit (PU).
4. Insightful Comments: Provide practical, discussion-based feedback – not just fault-finding
5. Value Addition: Focus on value addition suggestions, not just a tick-box review
6. Verification of Processes: Respect the PU’s professional judgment - verify the process, not override
decisions.
🧠 Pre-Requisites for a Reviewer
A Reviewer must be professionally sound and aware of legal and technical frameworks. They must:
📘 Knowledge Base:
Understand Attestation and Audit Services
Be familiar with the Code of Conduct of ICSI
Study ICSI disciplinary cases
Be aware of court decisions on deficiency in services
Know relevant laws:
o Company Secretaries Act, 1980
o CS Regulations, 1982
o Consumer Protection Act
o Evidence Act
o Indian Penal Code
Tools & Standards:
207
Study:
o ICSI Auditing Standards
o Guidance Notes
o Manuals
o References
o Notifications
o Advisories
Stay updated with best practices and evolving standards
Soft Skills:
Proficient in written and spoken English
Exhibit professional and courteous behaviour
Recognize personal limitations
Be aware of scope boundaries of Peer Review.
🔄 Peer Review Process
📅 Review Period:
Engagement records of the immediately preceding financial year are reviewed.
🧐 Focus Areas:
1. Compliance with:
o ICSI Guidance on Office Administration & Systems
o Auditing Standards, Guidance Notes, Manuals
2. Quality of Reporting
3. Office systems and internal procedures
4. Training Programs for staff and trainees, and availability of infrastructure.
📚 Training & Development For Reviewers
To maintain quality, ICSI offers structured learning opportunities.
🎓 Training Includes:
Regular online/offline training programs
A dedicated Training Module developed by ICSI
Reviewers must be familiar with all procedures and guidance
💼 Capacity Consideration:
Reviewer must self-assess their own ability and availability of trained staff before accepting
assignments.
📅 Validity of Peer Reviewer Empanelment
Valid for 5 years from the date of empanelment
Post 5 years, Reviewer must:
o Re-undergo Training Programme
o Qualify Certification Programme again.
Statement of Confidentiality
📜 Who Must Sign It:
Peer Reviewer
Qualified Assistant(s)
208
Members of the Peer Review Board
Council members or anyone assisting the review
🔒 Confidentiality Obligations:
1. Maintain absolute secrecy of all information obtained during Peer Review
2. No disclosure to any third party
3. No access granted to others to any confidential material.
❗ Violation = Professional Misconduct – As per Section 22 of the Company Secretaries Act, 1980.
🔍 Methodology Followed by the Reviewer
The Reviewer follows a structured methodology, including offsite and onsite reviews:
1. Offsite Review:
o The reviewer studies the information provided by the Practice Unit (PU) in the questionnaire.
Based on this, the reviewer identifies potential areas for improvement and notes aspects to
discuss during the onsite visit.
2. Onsite Review:
o The reviewer verifies the information provided by the PU.
o Conducts test checks on attestation assignments handled by the PU.
o Interacts with the PU’s staff and trainees to gain insights into their practices.
o Inspect records to check adherence to systems & procedures.
📏 Compliance with Peer Review Guidelines
Practice Units must comply with the Peer Review Guidelines to ensure quality standards. Failure to do so may
lead to a review of their quality controls, as directed by the Council. Non-compliance could result in
disciplinary action under the Company Secretaries Act, 1980.
Both Practice Units and Peer Reviewers are required to adhere to timelines established by the Board for the
Peer Review process.
📂 Obligations of the Practice Unit
1. Practice Name Approval:
o The Practice Unit must operate under a name approved and allotted by the ICSI, in line with the
name approval guidelines.
2. Providing Access to Records:
o The Practice Unit must provide access to records and documents when requested by the Peer
Reviewer. This includes:
Providing relevant records and documents that are in the possession of anyone within the
Practice Unit.
Ensuring that explanations or further details are provided if requested by the Reviewer.
Offering assistance throughout the Peer Review process.
3. Access Across Multiple Offices:
o If the Practice Unit has multiple offices, access to relevant documents must be provided from all
locations.
4. Handling Non-Legible Information:
o If any information is recorded in a non-legible form, the Practice Unit must provide a readable
version or a suitable translation in English, as requested by the Reviewer.
209
5. Client Confidentiality:
o The Practice Unit must ensure that the Peer Reviewer does not access confidential client details,
such as names or client records. However, the Reviewer can inspect and take abstracts or copies of
documents as necessary, but not client-specific information.
🧾 Validity of Peer Review Certificate
Scenario Validity Period
General Validity 5 years from the date of issue
If reviewed within 2 years of formation 2 years from the date of issue
✅ Note: The Committee/Board may suo motu or upon request of the Practice Unit, initiate Peer Review
early (i.e., before the expiry of existing certificate).
🔍 Review Framework
Peer Review involves assessment of:
Engagement records
Financial and related statements
The goal is to ensure compliance with:
ICSI Auditing Standards
Guidance Notes
Manuals
References
Advisories issued by the Institute
⚠️Non-compliance may lead to:
Suggestions & recommendations for improvement
A follow-up review if required.
📝 Reporting
A key component of Peer Review is the assessment by the Reviewer. The process includes the following:
Preliminary Report: After an on-site review, if the Reviewer identifies any deficiencies or non-
compliance in the systems and procedures of the Practice Unit, they must communicate a preliminary
report to the Practice Unit.
Final Report: The Reviewer assesses the materiality of non-compliance, frequency of occurrence and
impact on quality of services provided.
What are the basic components of a Reviewer’s Report?
1. Scope of Peer Review
2. Reference to the quality control standards
3. Reference to the preliminary report
4. Statement: quality control is PU’s responsibility
5. Limitations, if any
6. Reasons for a modified report.
210
Can a Reviewer give qualifications in his Review Report?
Yes, a Reviewer can qualify the report under the following circumstances:
1. Violation of ICSI Auditing Standards or Guidance Notes issued by ICSI
2. Absence of internal control systems in PU
3. Inadequate staff training programs
4. Improper file maintenance (current/permanent files)
5. Non-compliance with quality control policies
6. Deficiency in quality control procedures
What does a clean Report mean?
A clean report means that the Reviewer believes the Practice Unit is conducting its affairs in full adherence to
the applicable technical standards. The report indicates that no deficiencies or non-compliance were found
during the review.
📋 Questionnaire For Practice Unit
The Peer Review process involves the Practice Unit (PU) completing a questionnaire that provides basic
information about the PU to the Reviewer. This helps the Reviewer assess the key control areas and internal
mechanisms within the Practice Unit.
Confidentiality: All responses are confidential and will not be shared with third parties.
Importance of Accuracy: Accurate and careful responses are essential, as the Reviewer relies on the
information provided to plan the review.
Internal Control Mechanisms: The questionnaire acts as guidance for the Practice Unit to assess their
internal controls. While the absence of certain measures is not necessarily a failure, having them in
place is considered best practice.
💰 Cost Of Peer Review
💼 Responsibility: Payable by the Practice Unit (PU), not the Reviewer.
🧾 Payment Terms: PU must pay within 30 days of receiving the invoice from the Reviewer.
🏢 Multiple Branches: Each branch or office under review is treated separately for cost purposes.
🔁 Updates: The Committee can revise the cost of Peer Review from time to time.
🔁 Review Process Stages
1. Preparation Stage
Notification & Questionnaire:
o The Practice Unit (PU) receives written notice about the upcoming peer review along with a
Questionnaire to complete.
o PU must complete and return the questionnaire within 7 days of receipt.
Selection of Peer Reviewer:
o PU receives a panel of 5 Reviewers from the Board.
o If none selected, another panel of 5 Reviewers is sent.
211
o If still not selected, PU can request a Reviewer from outside its State/Region but must bear
extra TA/DA costs.
o If no local Reviewer is available, PU may choose any Reviewer from the panel, covering all
travel/stay expenses.
📋 2. Planning Stage
Once the Reviewer accepts the assignment, PU is notified.
Reviewer may request additional information to choose a representative sample of services.
📂 Sampling of Attestation Engagements:
From PU’s client list, Reviewer selects:
o Minimum of 10% (OR) 5 assignments under each category, whichever is Higher.
o If less, Reviewer must justify in the report.
PU is informed about the sample at least 2 weeks in advance.
PU must prepare and present relevant records for the selected assignments.
Execution and Visit Confirmation
PU and Reviewer decide the on-site review date mutually.
On-site visit must be completed within 21 days from the Reviewer’s appointment.
Reviewer can adjust or expand the sample during the visit if it doesn't represent a fair cross-section.
🔍 3. Execution Stage of Peer Review
🏢 A) On-Site Review:
The peer reviewer visits the practice unit's office (like the head office or other officially recorded
office).
It usually takes 1-2 days, depending on the size of the office and the work to be reviewed however, the
review should not take more than 3 days.
The practice unit needs to have all documents and information ready for the review.
B) Initial Meeting:
A meeting happens between the reviewer and the practice unit's designated person (like a partner or
manager).
Purpose of the meeting:
o Discuss the agenda for the visit.
o Clarify and verify the answers given in the questionnaire filled by the practice unit.
o Help the reviewer understand the office system.
o Decide:
How the review will happen.
Who in the office will assist the reviewer.
✅ C) Compliance Review - General Controls:
The reviewer checks if the practice unit follows key controls to maintain quality in their work. These
are:
1. Professional Skills and Standards
2. Independence
3. Outside Consultation
212
4. Staff Supervision and Development
5. Office Administration
What the Reviewer Does:
Asks questions and checks records to ensure these controls are in place.
If some questions don't apply (e.g., the office is small), the reviewer adjusts accordingly.
Evaluates how well the office's control systems work.
📂 4. Selection of Work to Review
The reviewer picks a sample of attestation services engagements (e.g., audits or certifications) to check.
Factors that decide how many and which ones to review:
o Number of practicing members doing attestation work.
o Quality of the practice unit's general controls.
o Total number of attestation jobs done during the review period.
The reviewer picks a balanced sample of work from different types of clients.
Important Note: The reviewer avoids selecting work that has been part of disciplinary action.
5. Review of Records:
The reviewer examines the attestation work papers to see if standards were followed. Two approaches can
be used:
A) Compliance Approach:
o Checks if proper procedures were followed.
o Ensures documentation matches the standards set by the Institute.
o For smaller offices, the approach may not be suitable, and adjustments can be made.
B) Substantive Approach:
o Used when:
General controls are unreliable.
Compliance standards are unsatisfactory.
o The reviewer checks the actual work papers in detail to ensure quality.
📝 6. Reporting
🧾 A. Preliminary Report by Reviewer:
After the on-site review, if any deficiencies or non-compliance are found in the practice unit’s
systems or procedures:
o The reviewer prepares a preliminary report and shares it with the practice unit.
o The report lists the specific areas where the systems or procedures are deficient or non-
compliant.
The practice unit gets 7 days to respond in writing to this preliminary report, either explaining or
justifying their practices.
📘 B. Final Report by Reviewer:
After considering the practice unit’s response, the reviewer submits a Final Report to the Peer Review Board
(PRB), which includes:
Findings of the review: It highlights whether the practice unit complied with:
o ICSI’s Guidance on Office Administration and Systems.
213
o ICSI Auditing Standards, Guidance Notes, Manuals, and Advisories.
The Final Report is also shared with the practice unit.
🏆 Potential Outcomes of Final Report:
1. ✔️Peer Review Certificate
o Issued if PU meets all compliance requirements.
2. 📋 Recommendations Only
o If minor weaknesses found, PU is advised to implement improvements.
3. ⚠️Instructions for Further Review
o If significant non-compliance is found:
The Board may instruct a follow-up Peer Review after a minimum of 6 months.
The instructions will specify exact areas for reassessment.
4. 🔁 Follow-Up Review Required
o If PU has responded, but the Peer Review Board finds that key controls are still not met,
hence a second follow-up becomes necessary.
🏢 Office System and Process
The Peer Reviewer is expected to evaluate whether adequate office systems and procedures are in place in
the Practice Unit (PU), particularly for Compliance Professional Services.
Key Areas the Reviewer Will Examine:
1. Document Management System
o Filing system (hard or soft copy)
o Record storage and retrieval system
2. Assignment Allocation
o Work assigned based on capability of staff/trainees
o Attestation services verified by the proprietor, partner, or qualified assistant.
📚 Training and Development for Staff:
1. Training Diaries:
o Do trainees maintain a daily diary of tasks completed?
o Is the diary regularly checked by the proprietor/partner/qualified assistant?
2. Staff Induction:
o Is there a structured induction process for new staff?
3. Capacity Building:
o Are staff encouraged to attend training programs or other professional development sessions?
4. Library and Resources:
o Does the office have a library or reference material for professional services?
5. Office Décor:
o Is the office environment organized and professional?
📌 Other Key Points:
1. 👩💼 Qualified Assistant:
A person assisting the reviewer must:
o Be a member of ICSI.
214
o Be a partner or associate of the reviewer.
o Has not been held guilty under the Company Secretaries Act, 1980
2. Repeat Peer Review:
A PU may need another peer review if:
o The Peer Review Board (PRB) decides so.
o Upon expiry of the Peer Review Certificate.
3. Protection from Disciplinary Actions:
Peer Review does not provide immunity from disciplinary proceedings under the Code of Conduct.
4. Reviewer’s Refusal of Assignment:
A reviewer can decline an assignment for valid reasons, such as:
o Conflict of interest with the PU.
o Concerns about independence due to past connections.
o Health issues.
o Other work or commitments.
5. Reviewer Access to PU Records:
The reviewer:
o Cannot take copies or extracts of PU or client records.
o May take abstracts for review work but only within the PU’s office.
o PUs can deny access if the reviewer attempts to take documents out.
⚖️Referral of Disputes in Peer Review
1. When Disputes Can Arise:
o Over the Reviewer’s powers, process, conclusions, or other review-related matters.
2. Process for Referral to the Peer Review Board (PRB):
o Who can refer? Practice Unit (PU), Reviewer, or both.
o When? Within 2 months of the issue.
o How? In writing, as per PRB’s guidelines.
3. PRB Decision Process:
o Considers written submissions from both parties.
o Timeline: Decides the dispute within 6 months and communicates the decision within 15
days.
o May issue directions for resolution, requiring:
Compliance within 30 days.
A compliance report submitted within 15 days after resolution.
4. Appeal to the Council:
o If dissatisfied, parties can refer the matter to the Council within 2 months, following the
prescribed procedure.
📋 Quality Review Board (QRB)
215
Purpose:
To review, guide, and improve the quality of services rendered by the members of the ICSI.
Establishment and Composition (Section 29A):
1. Constituted by the Central Government under the Company Secretaries Act, 1980.
2. Consists of:
o A Chairperson and 4 members.
o Members:
2 nominated by the Council.
2 nominated by the Central Government.
o Members are individuals of eminence with experience in law, economics, business, finance, or
accountancy.
🎯 Functions of QRB (Section 29B):
1. Makes recommendations to the Council on the ways to improve quality of services provided by ICSI
members
2. Assess the quality of services provided by the members of the Institute, including Secretarial Audit
services.
3. Guide members in enhancing service quality and compliance with statutory and regulatory
standards.
🧾 Meeting Procedure (Section 29C):
The Board meets at prescribed times and places, following the rules set forth.
💼 Service Terms and Expenses (Section 29D):
1. Terms and allowances for Chairperson and members are specified.
2. Expenses: Borne by the Council of ICSI.
Quality Management System (QMS)
An effective QMS ensures timely delivery and client satisfaction in a Practicing Unit (PU). Weak
understanding of QMS leads to poor execution and dissatisfied stakeholders.
It includes two key components: ✅ Quality Assurance (QA) and 🔍 Quality Control (QC)
1. ✅ Quality Assurance (QA)
o Focus: QA is about preventing defects by setting guidelines, documenting standards, and
ensuring that they are followed to guarantee quality.
o Purpose: To prevent problems before they happen.
o Example: Instruction kits for e-forms help guide users to fill out forms correctly.
o Tools: QA guidelines often include instructions, do’s and don’ts, possible errors, and remedies.
o Risk Mitigation: QA helps manage risk by ensuring the company’s operations adhere to quality
standards and reducing the chances of problems arising.
2. 🔍 Quality Control (QC)
o Focus: QC focuses on reviewing and checking the output after it has been produced, ensuring
it meets the desired quality levels.
o Purpose: To detect and correct any defects.
o Example: Reviewing work based on parameters like time, resubmissions, cost, and expertise.
216
o Objective: To verify that the final product or service conforms to the required standards.
🧾 Quality Review
Quality Review is an evaluation process where a Quality Reviewer assesses a Practice Unit to ensure:
1. Compliance with statutory and regulatory requirements
2. Quality control framework used by members
3. Quality of reporting
Appointment of Quality Reviewers
Eligibility: A Quality Reviewer must:
1. Option 1:
o Be a Fellow member of ICSI.
o Have at least 15 years of post-membership experience (in practice or employment).
o Be currently practicing as a Company Secretary.
2. Option 2:
o Be a Peer Reviewer who has completed at least 5 Peer Review assignments.
Other Conditions:
The person must not have been found guilty of misconduct under the Company Secretaries Act, 1980
in the last 5 years.
Training: Quality Reviewers must have undergone relevant training organized by the Board.
🏢 Selection of Practice Units (PU) for Quality Review
Who decides?: The Quality Review Board (QRB) is empowered to select the Practice Units (PUs) for review.
How is selection done?: Based on objective criteria set by the QRB.
📩 Communication with Selected Practice Unit
Once selected:
PU receives intimation along with a request for basic information.
Based on info received, a Quality Reviewer (QR) is assigned.
QR sends communication to PU with:
o 📅 Review start & expected completion date
o 📄 List of required documents
o 🧑💼 Reviewer identity & contact details
o 👥 Team composition
o 📌 Any other relevant details
🔹 Both parties (QR & PU) should mutually agree on:
o Duration and details of office visits.
o Main contact person in the PU.
o Lead time for document production and query resolution.
o Logistical arrangements and any other support needed.
📄 Submission of Report
217
🔹 Preliminary Report:
Submitted within 3 weeks of assignment
Includes non-compliance observations for PU’s comments
Time limit can be extended by QRB on request
🔹 Final Report:
Prepared after considering PU’s comments
Submitted by QR to QRB.
📝 Consideration of Review Reports by QRB
QRB may take the following actions:
✔️Take the report on record
❓ Seek clarifications from QR / PU
📢 Issue instructions to PU
💡 Recommend best practices to the Council.
📌 Part A: Expectations from Practice Unit
Regulators trust professionals for maintaining quality. Hence, PUs must establish strong internal quality
control systems.
(i) Leadership Responsibilities
Assign a partner/team leader for every assignment to ensure quality.
Responsibilities include:
o 📢 Communicating QC policies to all relevant personnel
o Encouraging feedback on quality issues
o 🧑💼 Defining roles/responsibilities for quality
o 📄 Documenting and circulating QC policies
(ii) Ethical Requirements
Ethical principles are non-negotiable for quality services:
⚖️Independence – No undue influence or relationships with clients
🧑🤝🧑 Familiarity Threat – Avoid over-familiarity with long-term clients
💎 Integrity – Uphold honesty and moral character
⚖️Objectivity – Unbiased, fact-based assessments
🧠 Professional Competence & Due Care – Qualified personnel must handle assignments
🤫 Confidentiality – Preserve client confidentiality always
🧑💼 Professional Conduct – Maintain trust and leadership in the profession
📘 Technical Standards – Stay updated with latest pronouncements and guidelines
(iii) Human Resources: Training & Development
People are the firm’s main asset.
Right recruitment, role alignment, and team composition are essential for quality services.
(iv) Performance Evaluation
Encourage accountability and development:
o Make personnel aware of expectations
o Evaluate personnel performance through a formal mechanism
218
(v) Monitoring
Continuous process to evaluate QC systems.
Includes sample inspections of completed assignments.
Ensures effectiveness of systems, procedures, personnel, and reporting.
📋 Part B: Responsibilities of the Quality Reviewer (QR)
The Quality Reviewer (QR) plays a crucial role in ensuring the quality of the review process. Their
responsibilities include:
1. Knowledge and Experience:
o A Quality Reviewer must have sufficient expertise and experience to effectively conduct the
review.
o They should be committed to ensuring that the review process and final report meet the ICSI's
professional standards.
2. Planning the Review:
o A well-planned review ensures that the process is effective. The reviewer must:
Devote attention to key areas of the review.
Identify and resolve issues promptly.
Direct and supervise the review team efficiently.
3. Review Strategy:
o The reviewer must establish a strategy that outlines the scope, timing, and direction of the
review. This plan should be based on:
The nature of the review assignment (e.g., evaluating systems and compliance).
The PU's characteristics and the complexity of the assignment.
The resources and time needed to conduct the review.
4. On-Site Visit Planning:
o A major part of the review is an on-site visit to the Practice Unit. Proper planning is essential
to minimize disruptions. The reviewer must:
Prepare checklists for the review process.
Create a list of documents needed from the PU.
Coordinate with the PU on the visit's timing and ensure they have an authorized contact
person to assist.
✅ Conducting The Quality Review
The Quality Reviewer (QR) must design appropriate procedures to gather sufficient evidence and draw
conclusions in the quality review report.
🎯 Objectives of Quality Review
To assess whether the Practice Unit (PU) is:
✅ Following ICSI Guidelines, standards, manuals, references, etc.
✅ Implementing an effective quality control system for service engagements
🧾 Procedure of Quality Review
219
🔍 The QR examines PU’s:
Compliance with laws, ICSI standards, and guidelines
Office administration systems
Implementation of controls
Engagement-specific policies and procedures
The process involves:
Interviews
Enquiries
Examination of PU systems & documents
Verification of adherence to professional standards.
📋 Key Steps in Conducting the Review
1. 📋 Quality Review Questionnaire
Prepared by QRB to aid QRs
Contains questions to assess PU’s compliance with ICSI Guidelines
PU must respond to all questions before on-site review
QR analyzes responses for better planning and focus.
2. 🏢 Understanding the Practice Unit (PU)
Prior to review (or during, if required), QR must understand:
📏 Size of practice
🧾 Nature of Business - Sole proprietor, CP holder, LLP, etc.
🧩 Service verticals (types of services offered)
🌍 Geographical presence
Governance structure (roles of partners/staff)
📘 Policies and procedures for compliance
🧪 Methodology used in service delivery
🔍 Tip: It's recommended to do this before on-site review for better preparation.
3. Documentation of Quality Review
1. Gather Documentation: The QR should gather relevant documents, including:
o Control Systems: Evidence of internal controls and procedures.
o Workpapers: Documentation supporting the review of specific assignments.
o Examination of Matters: Information reviewed during the quality check.
2. Conclusion Documentation: The QR should clearly document the conclusions reached, supported
by evidence.
✅ Evaluating the Findings of Quality Review
The Reviewer must evaluate if the evidence collected during the review is sufficient to support conclusions
in the review report.
⚠️Possible Review Findings
Review may reveal:
❗ Deficiencies in PU’s policies and procedures
❗ Poorly designed procedures to ensure quality of services
❗ Inappropriate or insufficient procedures to gather evidence.
220
🔁 Communication with PU
Reviewer should share findings with the PU
PU must be given reasonable time to respond
Reviewer must consider PU’s explanations during evaluation.
🚩 Indicators of Material Deficiency
Presence of any of the following suggests material deficiencies:
1. Non-Compliance by Senior Management: If senior management fails to comply with relevant
regulations or standards.
2. Ineffective Oversight: If the senior management has ineffective oversight over the PU’s external reporting
and compliance systems.
3. Previous Non-Compliance: If there were similar issues in the past, showing a pattern of non-compliance.
4. Undetected Non-Compliance: If a material non-compliance occurs that the PU's control systems failed to
detect.
Note: This is an inclusive list; other factors may also indicate deficiencies.
📝 Documenting a Finding
Each documented finding should include:
📋 Relevant facts and background
📘 Reference to non-complied laws/standards
⚖️Mitigating factors, if any
PU’s explanations/responses
✅ Reviewer’s conclusion, with basis
Tip: To avoid disputes, all discussions and supporting documents should be minuted and signed by both QR and
PU.
🧾 Reporting
🟡 Preliminary Report
📅 Deadline: Within 3 weeks from the assignment date
Sent to the PU
Must include any non-compliance observations to get PU’s comments
🟢 Final Report
📅 Deadline: Within 3 months from the assignment date
Submitted to the Quality Review Board (QRB)
Based on:
o PU’s response to preliminary report
o Reviewer’s final conclusion.
📌 A clean report means proper compliance and quality standards are maintained.
⚠️A qualified report may result from:
221
Non-compliance with ICSI standards/guidance
Non-compliance with laws
Deficiency in quality control design
Failure to follow PU policies
Lack of training/capacity building.
💸 Cost of Quality Review
Particulars Amount/Policy
Fee per review ₹25,000 (after satisfactory report submission)
Local costs (within 50 km) Borne by Reviewer
Travel > 50 km Reimbursed as per QRB policy (travel, accommodation, etc.)
📊 Quality Review vs. Peer Review
Basis of Comparison Quality Review Peer Review
Purpose To assess the quality of professional To ensure that the attestation services are
services rendered by the Practice Unit performed as per applicable technical standards
(PU)
Initiating Authority Quality Review Board (QRB) of ICSI Peer Review Board (PRB) of ICSI
Focus Area Entire quality control system, office Only attestation services and compliance with
systems, compliance with ICSI guidelines, relevant technical and professional standards
etc.
Scope Broader – includes office administration, Narrower – focused on checking technical accuracy
ethics, human resource policies, and procedures followed in attestation work
monitoring, etc.
Standards Referred ICSI Auditing Standards, Guidance Notes, ICSI Auditing Standards and
Office Administration Guidelines technical/professional standards related to
attestation services
Review Report Preliminary Report → PU’s Response → Draft Report → Final Report to Peer Review Board
Submission Final Report to QRB (after considering PU’s representation)
Time Limit for Report Preliminary – within 3 weeks; Final – Generally within 90 days from the date of
Submission within 3 months of assignment acceptance
Confidentiality Strict confidentiality of all PU information Same confidentiality standards apply
is maintained
Training Requirement Option 1: Be an ICSI Member with 10+ years post-
for Reviewer Be a Fellow member of ICSI. qualification experience as a Company Secretary
Have at least 15 years of post- Out of 10 years, have minimum 5 years in
membership experience (in practice or continuous practice
employment). Hold a valid Certificate of Practice (COP)
Be currently practicing as a Company Have completed the Training & Certification
Secretary. Programme for Peer Reviewers.
Option 2:
Be a Peer Reviewer who has completed at
least 5 Peer Review assignments.
222
Documentation Focus Office systems, ethics compliance, quality Engagement-specific documents, working papers,
control systems, human resources evidences for attestation
Nature of Visit On-site review is mandatory and well- Can be on-site or off-site, based on PRB’s
planned discretion
✅ Key Takeaway:
Quality Review = Holistic review of professional service quality
Peer Review = Technical review of attestation service quality.
Lesson: 4 (Legal Framework Governing Company Secretaries)
Core Functions as Defined by Law (Section 205 of the Companies Act, 2013)
1. Reporting to the Board
o Ensures compliance with provisions of the Companies Act, rules, and other applicable laws.
2. Guidance to Directors
o Provides advice to directors on their duties, responsibilities, and powers.
3. Board Assistance
o Aids the Board in conducting company affairs and ensuring good corporate governance.
4. Meeting Facilitation
o Organizes and attends Board, committee, and general meetings and records minutes.
5. Secretarial Standards Compliance
o Verifies the company's adherence to secretarial standards.
6. Regulatory Approvals
o Secures necessary approvals from the Board, general meetings, government, and other
authorities.
7. Representation
o Represents the company before regulators and authorities.
8. Corporate Governance
o Advises the Board on governance requirements and best practices.
9. Other Duties
o Performs duties assigned by the Act, rules, or the Board from time to time.
Key Areas of Expertise
223
A CS is an expert in:
Corporate laws and governance.
Securities laws and compliance.
Strategic management and investor relations.
Human resources, global business collaborations, and treasury management.
Case Law Summary
📌 Mayank Agarwal vs. Technology Frontiers (India) Pvt. Ltd.
⚖️Issue:
Whether a Company Secretary (CS) can file an application before the NCLT without separate Board approval
under Section 90(7) of the Companies Act, 2013?
📌 Background:
CS issued notice to Mayank Agarwal (nominee director) under Section 90(5) to disclose Ultimate
Beneficial Ownership (UBO).
Applicant challenged saying only the company can approach NCLT under Section 90(7) and CS lacked
board authorization.
📌 Respondent CS’s Stand:
His appointment board resolution empowered him to act under Companies Act.
Referred to Section 205 – authorizing CS to represent company before regulators.
Argued no need for separate board resolution to file this petition.
✅ NCLT Judgment:
Dismissed the challenge by the applicant.
Held that CS has rightful authority to act under Section 90(5) to comply with disclosure norms.
Section 90(5) uses the word “company shall give notice”, and CS as a KMP is empowered to act on
behalf of the company.
CS acted diligently and within his scope of duties.
Role of a Company Secretary as Compliance Officer under SEBI (LODR) Regulations, 2015
Regulation 6(2) of SEBI (LODR) requires listed companies to appoint a qualified Company Secretary as the
Compliance Officer. The Compliance Officer's responsibilities include:
Responsibility Explanation
(a) Conformity Ensure compliance with all regulatory provisions.
(b) Coordination Liaise with Board, stock exchanges, depositories.
(c) Authenticity Ensure accuracy & completeness of filings.
(d) Investor Grievance Monitor complaint redressal email ID.
Other SEBI Roles:
Maintain documents and ensure compliance under:
o SEBI (PIT) Regulations, 2015
o SEBI (SAST) Regulations, 2011
Company Secretary in Senior Management
224
Under Regulation 16(d) of SEBI (LODR) Regulations, 2015, senior management includes members of the
core management team, excluding the Board.
The Company Secretary is a part of this team and plays a key role alongside the Chief Financial Officer
and other functional heads.
Opportunities for Company Secretaries
1. In Employment:
o Corporate governance, regulatory compliance, and strategic advisory roles.
2. In Practice:
o Offers consultancy in legal, compliance, governance, and related fields.
Definitions Under Legal Frameworks
1. Company Secretaries Act, 1980
o Section 2(1)(c): A Company Secretary is a member of the Institute of Company Secretaries of
India (ICSI).
o Section 2(1)(j): The Register includes members or firms registered under Sections 19 and 20B.
2. Companies Act, 2013
o Section 2(24): A Company Secretary is appointed by a company to perform statutory functions
under the Act.
o Section 2(25): A Company Secretary in Practice is a CS deemed to be in practice under Section
2(2) of the 1980 Act.
o Section 2(51): Defines Key Managerial Personnel (KMP) to include:
CEO, MD, or Manager.
Company Secretary.
Whole-time Director.
CFO.
Other officers designated as KMP by the Board.
Classes of Membership: Associates and Fellows
The Institute of Company Secretaries of India (ICSI) divides its members into two categories: Associates
and Fellows.
1. Associate Members (ACS)
An Associate is a member who fulfills specific qualifications and requirements under the Company
Secretaries Act, 1980, and the Company Secretaries Regulations, 1982 (as amended).
Eligibility for Associate Membership
As per Section 5 of the Act and Regulation 4(1):
1. A person’s name is entered in the Register of Members upon meeting the following conditions:
o Passing qualifying examinations and completing practical training as prescribed in the
regulations.
o Having completed recognized equivalent training or exams outside India (approved by the
Council or Central Government).
o Being a former student of the Institute of Chartered Secretaries and Administrators (ICSA),
London before December 31, 1972, and having passed their Final or Professional Programme
Examination.
225
o Being an Indian citizen resident abroad, holding membership in the ICSA, and having the
required practical experience or training.
Usage of Title
Upon registration, Associates can use the designation "ACS" after their name.
2. Fellow Members (FCS)
A Fellow is a senior member of ICSI with extensive experience or qualifications in the profession.
Eligibility for Fellow Membership
As per Section 5 of the Act and Regulation 4(2):
1. Mandatory Criteria:
o Must be an Associate member.
o Experience Requirements:
5 years of continuous practice as a Company Secretary in India, or
5 years as an Associate with equivalent qualifications or practical experience as
prescribed by the Council.
2. Exceptions:
o Persons who were Fellows of the dissolved company (ICSA) before the Act commenced or
under earlier regulations.
Disqualifications for Fellow Membership
The Associate must not have been:
o Found guilty of professional misconduct leading to removal from the Register or fined under
Sections 21A(3) or 21B(3) within the last Five Years.
o Lacking the minimum number of Professional Development Credit Hours (PDCs) as
determined by the Council.
Special Provision for Non-Residents
For members not residing permanently in India, the Council may impose additional qualifications or
conditions.
Usage of Title
Fellows can use the designation "FCS" after their name.
Certificate of Practice (CoP)
As per Regulation 2(d) of the Company Secretaries Regulations, 1982:
A Certificate of Practice (CoP) is a certification granted under the regulations allowing its holder to
practice as a Company Secretary.
A member can practice the profession of Company Secretary (in India or abroad) only after obtaining
this certificate.
Register of Members
The Institute of Company Secretaries of India (ICSI) maintains a Register of Members per Regulation 3 of
the Company Secretaries Regulations, 1982.
Contents of the Register
The Register includes:
Full name, date of birth, domicile, and residential/professional addresses.
Membership number and registration date.
Qualifications and whether the member holds a CoP.
226
Contact details (email, mobile, etc.) and other Council-determined particulars.
Updating Details
Members must inform the Institute of any changes within 30 days.
Removal from the Register of Members
Per Section 20 of the Act, the Council may remove a member’s name from the Register in the following cases:
1. Death
2. Voluntary Removal
o Upon the member's request.
3. Non-Payment
o Failure to pay the required fees.
4. Disability or Disqualification
o If the member was subject to a disability under Section 8 at the time of registration or
becomes ineligible later.
5. Disciplinary Action
o If ordered under the Act to remove their name from membership.
Key Authorities in the Disciplinary Mechanism
Authority Role
Disciplinary Directorate (DD) Receives complaints/information and forms prima facie opinion.
Board of Discipline (BoD) Handles First Schedule misconduct (less severe).
Disciplinary Committee (DC) Handles Second Schedule or both First & Second Schedules.
Disciplinary Directorate
Establishment: Section 21 mandates the creation of a Disciplinary Directorate, headed by the
Director (Discipline), to investigate complaints or information regarding professional or other
misconduct by members.
Procedure:
o Upon receiving a complaint or information (with a prescribed fee), the Director forms a prima
facie opinion about the alleged misconduct.
o Investigations follow specified procedures under the Act and related rules.
Role of Director (Discipline)
Receives complaints/information and forms a prima facie opinion.
If First Schedule misconduct → refers to BOD.
If Second or both Schedules misconduct → refers to DC.
Can also close the case if no prima facie case is found.
"Prima facie" means: "at first look" or "on the face of it". So, if there is no obvious or initial proof of
misconduct, it may not go forward — unless the Board feels otherwise.
Board of Discipline
227
Formation: Constituted under Section 21A by the Institute’s Council.
Function: Handles cases of misconduct under the First Schedule through summary disposal
procedures.
The member shall be given an opportunity of being heard before making any order against him.
Powers:
o Reprimand the member.
o Remove the member's name from the register for up to 3 months.
o Impose a fine up to ₹1,00,000.
Decision-making:
o The Director submits cases without a prima facie basis to the Board.
o The Board may agree with the Director’s view and close the case, or direct further investigation
if it disagrees.
Disciplinary Committee
Formation: Established under Section 21B by the Institute’s Council.
Composition:
o Presiding Officer: President or Vice-President of the Council.
o Two elected members: From the Council.
o Two government nominees: Eminent persons with expertise in law, economics, business,
finance, or accountancy.
o Additional Committees may be formed if needed.
Function: Handles cases involving misconduct under the Second Schedule or both Schedules.
The member shall be given an opportunity of being heard before making any order against him.
Powers:
o Reprimand the member.
o Remove the member's name permanently or for a specified period.
o Impose a fine up to ₹5,00,000.
Powers of Civil Court
Under Section 21C, the Authority, Disciplinary Committee, Board of Discipline, and Director
(Discipline) are vested with civil court powers under the Code of Civil Procedure, 1908, to:
o Summon and enforce attendance of persons for examination on oath.
o Receive evidence on affidavit.
o Discover and produce documents.
Appeal to Authority
Section 22A: Appellate Authority
The Appellate Authority under Section 22A of the Chartered Accountants Act, 1949, is also deemed
the Appellate Authority under the Company Secretaries Act, 1980, with necessary modifications.
Right to Appeal
Who can appeal?
1. Any aggrieved member of the Institute dissatisfied with an order of:
Board of Discipline (Section 21A(3)).
Disciplinary Committee (Section 21B(3)).
228
2. Director (Discipline) can also appeal if authorized by the Council.
Time Limit: The appeal must be filed within 90 days of receiving the order.
Extension: The Authority may entertain late appeals if there is sufficient cause for the delay.
Hearing Opportunity: All concerned parties must be given an opportunity to be heard before any
decision is made.
Powers of the Appellate Authority
The Authority, upon reviewing the case, may:
1. Confirm, modify, or set aside the order of the Board or Disciplinary Committee.
2. Impose penalties, or alter (reduce or enhance) penalties imposed in the original order.
3. Remit the case back to the Board or Disciplinary Committee for further investigation.
4. Pass any other appropriate order, ensuring fairness in the circumstances.
Other Misconduct
Supreme Court's Interpretation
In the landmark case Council of the Institute of Chartered Accountants of India v. B. Mukherjee (1957),
the Supreme Court held:
Even if a member’s conduct does not fall under specific provisions of the Schedules of misconduct, the
Council can still initiate an inquiry if the conduct, in its opinion, renders the member unfit to remain
part of the Institute.
Such findings can justify disciplinary actions by the High Court.
Structure of Misconduct
Schedule Part Applies To
First Schedule I CS in Practice
II Members in Employment
III Members Generally
IV Other Misconduct (Members Generally)
Second Schedule I CS in Practice
II Members Generally
III Other Misconduct (Members Generally)
Illustrative Examples of "Other Misconduct"
Not returning client records without reason.
Material misrepresentation.
Using apprentices for non-professional work.
Conviction by court.
False publicity harming clients.
Bringing disrepute to profession/Institute.
Conviction for offences with jail up to 6 months.
False declarations to ICSI/regulators.
Violation of Council Guidelines.
Professional Misconduct in Relation to Company Secretaries in Practice
(Part I of the First Schedule to the Act)
229
Clause (1): Practicing in Another's Name
Misconduct if a PCS lets someone else practice in their name unless:
o The person is also a PCS
o In partnership or employed by the PCS
Test for Partnership (must meet all):
1. Sharing profits/losses
2. Joint decision-making
3. Shared responsibility
4. Authority to bind each other
Non-members (CA/CWA) can become partners only for non-attestation services after relevant
amendments.
❌ Sharing infrastructure ≠ Partnership
Clause (2): Sharing Fees or Profits
PCS cannot share fees/commission with:
o Anyone not a member of ICSI
o Except:
Partner / retired partner / legal heir of deceased partner
Member of another recognized profession (CA, CWA, Advocate, Architect, Actuary,
etc.)
Qualified professionals (B.E., [Link]., [Link]., LLB, MBA, etc.)
📝 Explanation:
Sharing permitted only for rendering professional services
CA/CWA/Advocate may be partners only for non-attestation services
A CA or CWA who is a partner in a multidisciplinary firm cannot issue a Secretarial Audit Report
unless they hold a CoP from ICSI.
Sole proprietorship: After PCS's death, fees sharing not allowed, but payment of goodwill is
permitted.
Clause (3): Accepting Profits from Non-Members
A PCS is guilty of misconduct if they accept or agree to accept any part of profits from the
professional work of a non-member.
✅ Allowed: Sharing of profits/commission/brokerage is permitted with members of other
recognized professional bodies or qualified persons as referred in Clause (2).
🔁 This clause is the reverse of Clause (2) - here, the PCS is the recipient, whereas in Clause (2), the
PCS is the one sharing profits.
🧠 Key Point: Profit sharing with recognized professionals is okay; not with the general public or
non-qualified persons.
Clause (4): Entering into Unauthorised Partnerships
A PCS is guilty of misconduct if he:
o Enters into partnership (in or outside India) with anyone other than:
A Company Secretary in Practice, or
A member of a recognized professional body (per Section 2(2) of the Act), or
A resident abroad whose qualifications are recognized by the Council or Government.
❌ Prohibited: Partnership with non-professionals or for non-CS professional purposes.
✅ Permitted:
230
o With recognized professionals,
o For practicing the profession (not for business).
🌍 Includes foreign partners with equivalent qualifications recognized by ICSI.
Clause (5): Unethical Methods to Secure Business
A PCS is guilty of misconduct if he:
o Secures professional work using:
Non-employees or non-partners, or
Unethical means not open to a Company Secretary.
✅ Permitted: Arrangements as per Clauses (2), (3), and (4).
❌ Prohibited:
o Soliciting work through agents or unprofessional conduct.
o Use of misleading advertisements or indirect solicitation.
🌐 Advertisement Guidelines (2007):
o PCS can launch a website, issue advertisements, etc., within permitted limits.
o Must not imply soliciting/guaranteeing clients.
📌 Violation of these norms = Professional Misconduct.
Clause (6): Prohibition of Soliciting Clients or Professional Work
Key Provision
A Company Secretary in Practice (PCS) is guilty of professional misconduct if they solicit clients or
professional work directly or indirectly through:
Circulars
Advertisements
Personal communication or interviews
Any other means (e.g., telephonic, electronic, or social media).
The core principle is that a professional’s reputation should arise from their credibility, reliability, and
integrity, not aggressive marketing or solicitation.
Permitted Activities
Clause (6) explicitly allows certain actions to ensure professionals can engage appropriately without violating
ethical boundaries:
1. Collaboration with Other Professionals:
o Requesting or inviting work from another PCS.
2. Tenders and Inquiries:
o Responding to tenders or inquiries issued by organizations and securing work through
legitimate responses.
3. Limited Advertisements:
o Publishing basic announcements (e.g., address change, staff recruitment) without implying
professional superiority or solicitation of work.
Prohibited Activities
Direct or Indirect Solicitation of professional work includes (but is not limited to):
1. Advertising services in newspapers, handbills, or circular letters.
2. Highlighting speedy processing times (e.g., registering a company in 2 days).
3. Sending professional profiles or service offerings unsolicited.
4. Making unreasonable / discounted fee / cut-rates offers to attract clients.
5. Claiming to be a "specialist" or superior in professional attainments.
6. Using interviews or public appearances (e.g., TV, social media) to highlight professional superiority.
231
7. Allowing third-party solicitation (e.g., through trade associations).
8. Overemphasizing qualifications in directories (e.g., bold type or multiple listings).
9. Publishing messages that indirectly suggest professional work solicitation.
Examples That Violate Clause (6)
1. Sending unsolicited letters offering secretarial services.
2. Circulars creating an impression of expedited service capabilities.
3. Including client names or affiliations without specific requests.
4. Frequent press announcements about availability or achievements.
5. Highlighting attainments in interviews beyond what’s necessary.
Examples That Do Not Violate Clause (6)
1. Address Changes: Publishing address updates in professional journals or newspapers.
2. Recruitment Ads: Limited to staff recruitment without service promotions.
3. Seasonal Greetings: Sending greetings (e.g., New Year wishes) without listing services or professional
claims.
4. Media Appearances: Participating in media programs with minimal biographical references.
5. Writing for Professional Journals: Contributing articles or editing without soliciting services.
6. Charitable Activities: Joining welfare associations without using the platform for professional gain.
7. Professional Newsletters: Sharing law updates with existing clients.
Special Clarifications by the Council
1. Allowed:
o Responding to tenders or inquiries for professional work.
o Issuing advertisements for branch openings or seeking partnerships (within guidelines).
o Launching websites compliant with the Council’s advertisement guidelines.
2. Not Allowed:
o Mentioning one’s name as a "Company Secretary" in non-professional contexts to solicit work.
o Phrases like "contact the editor for clarification" in journals indirectly soliciting work.
Clause (7): Restrictions on Advertising and Use of Designations
This clause focuses on ethical advertising and proper usage of professional titles for Practicing Company
Secretaries (PCS). This clause covers two aspects –
(i) advertisement of professional attainments or services by a Company Secretary in Practice; and
(ii) using the designation ‘Company Secretary’.
Advertising Restrictions:
o A PCS cannot promote their professional achievements, office infrastructure, or client list in
ways like brochures, circulars, or announcements, except through a council-approved write-up.
o Details like the number of companies handled, specific achievements, or specialties (e.g.,
"expert in tax law") are restricted in general promotions.
Proper Use of Designations:
o A PCS must only use the title "Company Secretary" on official documents, visiting cards, etc.,
unless it's a recognized degree or membership title (like those of ICSI, ICAI).
o Using titles like "Company Law Consultant" or "Corporate Adviser" is not allowed.
Permissible Exceptions:
o PCS names may appear in clients' brochures (e.g., as satisfied software users).
o Responses to specific client requests can include achievements or a client list.
Examples of Violations:
o Highlighting achievements (e.g., public awards) in announcements without proper phrasing.
232
o Listing directorships in companies on professional material.
⚖️Important Council Rulings:
Situation Held as Reason
Misconduct?
Using “Company Secretary & Advocate, High ✅ Yes Unauthorized dual title
Court”
Misusing ICSI letterhead for circulars or brochures ✅ Yes Misleading readers
Listing directorships or awards on letterhead ✅ Yes Indirect promotion
Sending client list upon request ❌ No Specific, not general
circulation
Clause (8): Prior Communication Before Accepting Assignment
A Company Secretary in Practice (PCS) is guilty of professional misconduct if:
He accepts an assignment previously held by another PCS without first communicating with them in writing.
Communication Essentials:
o Communication must be sent in a verifiable manner (e.g., registered letter, email, or WhatsApp,
SMS allowed, only if delivery can be proved).
o Consent or a "no-objection" is not required, but sufficient notice must be given for the previous
PCS to respond.
Communication is required for exclusive assignments, such as:
Signing/Certifying Annual Return
Secretarial Audit Report (Sec 204)
Certificate of Securities Transfers
Reconciliation of Share Capital Audit under SEBI
Internal Audit of Depository Participants
Corporate Governance Certification (under SEBI LODR)
Communication is not mandatory (though desirable) for:
Certifying e-forms
Due diligence for consortium lending
Retainer assignments
Search reports
SEBI (LODR) certifications (non-exclusive)
Legal opinions.
Clause (9): Fee Based on Results – Not Allowed
A PCS is guilty of misconduct if:
“He charges/offers to charge or accepts/offers to accept fees based on percentage of profits or results of the
assignment.”
✅ Essentials:
Contingent fees are prohibited unless allowed by ICSI regulations.
Fee must relate to:
o Time spent
o Expertise required
❌ Example of violation: Quoting a fee in an Excise Refund case as a percentage of the refunded amount.
Clause (10): Engaging in Other Business – Restricted
A PCS is guilty of misconduct if:
“He engages in any business or occupation other than CS practice without Council’s permission.”
✅ Key Principles:
233
Ensures independent identity of the CS profession.
Council won’t issue CoP if:
o Member is in employment
o Member is practicing CA, CMA, or Law full-time without Council's permission.
✅ What is Permitted Without Permission (Regulation 168(2)):
No special Council resolution needed if PCS works as:
Arbitrator, Valuer, Executor, Trustee
Internal Auditor, Appraiser
Management Consultant
Representative in tax or financial matters
Government or Court Appointee (tribunal, etc.)
✅ What is Expressly Permitted by the Council:
PCS can engage (without prior permission) in:
1. Writing books/articles
2. Life insurance agent (only for renewal commission)
3. Public offices (MP, MLA, etc.)
4. Honorary positions in charitable/educational bodies
5. Justice of Peace, Special Executive Magistrate
6. Teaching – max 3 hours per day
7. Exam work – valuer, moderator, head examiner
8. Editor of professional journals
⚠️What Needs Prior Permission (Regulation 168(1)):
PCS must seek specific permission for:
1. Involvement in family business (even with <25% interest)
2. Becoming a Managing Director or Whole-time Director
📌 Substantial Interest – Defined
In a company – owns ≥25% of voting power.
In other concerns – entitled to ≥25% of profits.
Clause (11): Unauthorized Signing – Not Allowed
A PCS is guilty of misconduct if:
“He allows a person who is not a member in practice or not his partner to sign anything that he is required
to certify as a Company Secretary, or any related statements.”
✅ Key Points:
Only the PCS himself or his partner (also a practicing member) can sign.
❌ No delegation via:
o Employee
o Power of Attorney holder
❌ Example of Violation:
PCS allowing an employee to sign Annual Return under Section 92, or Secretarial Audit Report.
🔐 Digital Signature Caution:
PCS must not share Digital Signature password.
Must personally affix the signature to avoid unauthorized usage.
(Part II of the First Schedule to the Act)
🔹 Clause (1): No Sharing of Salary
A member is guilty of misconduct if:
234
“He pays, allows, or agrees to pay any share in his emoluments to any other person.”
✅ Key Points:
Covers both direct and indirect sharing.
Sharing of salary/employment benefits is strictly prohibited, even with other members.
Similar to Clause (2) of Part I (PCS can only share with partners).
🔹 Clause (2): No Secret Commissions
A member is guilty of misconduct if:
“He accepts any part of fees, profits, or gains from a lawyer, CS, broker, agent, or customer of the employer.”
✅ Key Points:
Accepting secret commission, gratification or cuts from third parties dealing with the employer is
misconduct.
Protects the trust of employer and ensures professional integrity.
Similar to Clause (3) of Part I.
Concept Note: Employment vs. Practice
Element Contract of Service (Employment) Contract for Service (Practice)
Selection & Control Employer has power Client-based, independent control
Remuneration Fixed salary/emoluments Based on assignment/project
Supervision Supervised by employer No daily control by client
Termination Subject to dismissal rules Ends on project completion
Part III of the First Schedule: Professional Misconduct for Members Generally
Misconduct in relation to members generally – whether in practice or not
Clause (1): False Claim of Fellowship
If a member not being a Fellow act as a Fellow of the Institute, it is deemed misconduct.
Fellowship denotes status and seniority.
Only those eligible under Regulation 4(2) can use the title.
Wrongfully claiming this = misrepresentation of status.
Clause (2): Non-Compliance with Institute Requests
A member is guilty if he fails to supply information or does not comply with requirements asked by:
ICSI, its Council, Committees
Director (Discipline), Board of Discipline
Disciplinary Committee, Quality Review Board
Appellate Authority
✅ Example: Not disclosing ICAI Certificate of Practice to ICSI during COP renewal.
Every member must comply with any request from these bodies.
Relevance of info presumed – can’t be refused.
Clause (3): False Information in Advertisements or Work Solicitations
A member is guilty if, while inviting or responding to professional work, he gives knowingly false
information.
Includes tenders, enquiries, advertisements, write-ups.
Linked to Items 6 & 7 of Part I (dealing with advertisement norms).
Ensures integrity in self-promotion and marketing.
Part IV of the First Schedule: Other Misconduct for Members Generally
This section addresses broader misconduct that reflects poorly on the profession or the Institute.
235
Clause 1: Guilt by Court (≤ 6 Months Imprisonment)
If a member is held guilty by any civil or criminal court for an offence punishable with imprisonment up
to 6 months, it is misconduct.
Applies irrespective of whether the act is professional or personal.
Clause 2: Acts Bringing Disrepute to the Institute or Profession
If in the opinion of the Council, a member’s action brings disrepute to the profession or Institute, it is
misconduct—even if the act is unrelated to professional work.
🔥 Examples of Misconduct under this Clause:
Sending abusive emails criticizing the Council.
Using filthy or derogatory language in public forums about ICSI or its officers.
Aggressive complaints to MCA using unprofessional language.
Organizing dharnas/agitations outside Govt. or Institute offices.
Inciting students/members to create chaos over syllabus or exams.
Misusing confidential Institute data for personal gain.
Spending excessively to host Government officials at ICSI programs for personal mileage.
Tampering with accounts or minutes of Chapter/Regional Council meetings.
Quick Memory Table – First Schedule
Part Who it applies to Clause Type Misconduct Examples
Part I PCS in Practice Professional Unauthorized signing, fee sharing, false publicity
Misconduct
Part II Members in Employment Professional Sharing salary, accepting secret commissions
Misconduct
Part All Members (Practice/Not) Professional Falsely claiming fellowship, not giving info, false
III Misconduct ads
Part All Members (Practice/Not) Other Court convictions, bringing disrepute through
IV Misconduct actions or language
Part I of the Second Schedule: Professional Misconduct for Company Secretaries in Practice
Part I of the Second Schedule addresses specific actions that may result in professional misconduct for
Company Secretaries in Practice (PCS), and outlines situations where a Disciplinary Committee must take
action.
Clause (1): Disclosure of Client Information
A PCS is guilty if he discloses any information obtained during his professional engagement to anyone other
than the client, unless:
Client has given consent, OR
Law mandates disclosure
✅ Key Points:
Information gained during practice = privileged communication
Consent depends on client type:
o Sole Proprietor → Consent from the proprietor
o Partnership Firm → All partners (if deed says so) or any partner (if deed silent)
o Company (Board-managed) → Consent from the Board
o Managing Director-led → MD’s consent valid
Even documents seen or created by PCS = protected
236
Digital signature use: If PCS retains DSC/password, must take written authorization to avoid misuse
allegations.
Clause (2): Certification of Reports Without Proper Examination
A PCS is guilty if he certifies or submits any report on company secretarial matters without examination of
the relevant statements by:
Himself, OR
His partner, OR
His employee, OR
Another PCS (even if not a partner)
✅ Key Points:
Certification must follow personal or authorized examination
Trainees are not considered employees for this clause
PCS may rely on another PCS's examination (e.g., search reports) but not trainees or unauthorized
sources
Ensures responsibility and accountability in certifications
Clause (3): Using Name in Reports About Future Transactions
A PCS is guilty if he allows his name or firm’s name to be used in reports/statements based on future
transactions in a way that implies he vouches for the accuracy.
✅ Key Points:
PCS must avoid associating with forecasts or projections unless:
o They clearly disclose sources and assumptions
o They do not guarantee accuracy
Future = uncertain. PCS ≠ fortune teller
Should avoid certifying things like:
o Future profitability
o Future shareholding patterns
o Future earning capacity
If forced to sign such documents, must include a clear disclaimer
Clause (4): Conflict of Interest – Substantial Interest
A PCS is guilty if he gives an opinion or signs a report about a business where he, his firm, or his partner has
substantial interest.
✅ Key Points:
Independence is essential when expressing an opinion.
No longer allowed even with disclosure.
"Substantial interest" = 25% or more (as per Council's guideline under Reg. 168).
Applies even if the entity doesn’t have share capital (e.g., clubs).
Clause (5): Hiding a Material Fact
A PCS is guilty if he fails to disclose any material fact known to him which is necessary for a proper report.
✅ Example:
Saying “Company has declared dividends every year” is misleading if it was from reserves for last 3
years.
Should say: "Dividend declared every year since incorporation, but in the last 3 years, it was from
accumulated profits."
237
✅ Key Points:
If PCS does not know the fact → No liability
If PCS knows the fact but believes it's immaterial → Burden of proof is on PCS
Clause (6): Failure to Report Known Misstatement
PCS is guilty if he does not report a material misstatement known to him in any report or statement he’s
professionally involved in.
✅ Key Point:
If PCS is aware that a fact or figure in a report is false or misleading, he must report it.
Silent acceptance = professional misconduct.
Clause (7): Negligence or Lack of Due Diligence
PCS is guilty if he does not exercise due diligence or is grossly negligent in his professional work.
✅ Definitions:
Due diligence = Acting with care and caution expected from a reasonable professional.
Gross negligence = Very high level of carelessness (more than a minor mistake).
✅ Key Quotes:
“PCS is a watchdog, not a bloodhound – but must probe if suspicion arises.”
✅ Examples:
Certifying Annual Return under Section 92 without being a whole-time PCS
Giving certificate to a bank without verifying MoA/AoA
Certifying resolutions without checking minutes book
Clause (8): Insufficient Information or Material Exceptions
PCS is guilty if:
1. He gives an opinion without sufficient info.
2. He expresses an opinion even when exceptions are too material and affect the reliability of the
opinion.
✅ Examples:
Giving a consumption certificate under Import-Export laws without verifying usage details.
Minor exceptions may be allowed, but not material ones that affect the validity of the whole
opinion.
Clause (9): Failure to Report Material Departures from Secretarial Practices
PCS must invite attention to any material deviation from generally accepted secretarial practices.
✅ Examples of such practices:
Share issues and transfers
Servicing securities
Conducting meetings
Approvals and filings
Until official secretarial standards are mandatory, PCS must follow well-recognized best practices and
highlight any major deviation.
Clause (10): Client Money Mishandling
PCS must keep client’s money (other than fees/expenses) in a separate bank account, and use it only for
the specified purpose, within a reasonable time.
✅ Rules:
Statutory payments (filing fees, stamp duty) → Separate account needed
238
Travel/conveyance expenses → Can be handled normally
If purpose is cancelled/postponed → Return money, do not adjust as fee unless authorized by
client
Professional Misconduct in Relation to Members of the Institute (Part II of the Second Schedule)
Part II of the Second Schedule to the Company Secretaries Act, 1980 deals with professional misconduct in
relation to members of the Institute, whether in practice or not. The following are the key clauses and their
implications:
Clause (1): Contravention of Provisions of the Act, Regulations, or Guidelines
Member must follow:
o CS Act, 1980
o CS Regulations, 1982
o ICSI Guidelines (e.g., dress code, compliance certificate, use of logo, PDP attendance)
✅ Example:
Certifying without COP
Violating election rules
Clause (2): Disclosure of Confidential Information
Members in employment must not leak confidential information, unless:
o Permitted by employer, or
o Legally required
✅ Confidential info includes business secrets, strategies, policies, plans, etc.
Clause (3): Knowingly giving false info
Applies when submitting info to:
o Council, Director (Discipline), Board, QRB, Appellate Authority
Only intentional falsehood = misconduct (not honest errors)
✅ Example: Hiding second job while applying for COP.
Clause (4): Defalcation/Embezzlement
Misusing money received in professional role is misconduct.
Must be linked to professional duties (Section 2(2), Reg. 168).
Part III of the Second Schedule: Other Misconduct
Applies to: Members, whether in practice or not.
Clause Misconduct Explanation
Only If a member is held guilty by a civil/criminal court for - Applies only after final appeal is
Clause an offence punishable with imprisonment exceeding over
6 months - Even if offence does not involve
moral turpitude, this clause still
applies.
First Schedule: Professional Misconduct
Claus
Part Misconduct
e
Part I (PCS) (1) Practicing in another's name without partnership or employment.
(2) Sharing fees with unauthorized individuals or non-recognized bodies.
(3) Accepting profits from non-members, except under valid arrangements.
(4) Forming partnerships with non-PCS or unqualified individuals.
239
(5) Securing business through unethical means or non-employees.
(6) Soliciting clients or work through ads, circulars, or other means.
(7) Misuse of advertising and professional designations.
(8) Failing to communicate respectfully with predecessors.
(9) Charging contingent or results-based fees, unless permitted.
(10) Engaging in other business without Council approval.
Part II (Members in
(1) Sharing part of their salary with others.
Service)
(2) Accepting commissions or gratifications related to their employer.
Part III (All Members) (1) Misrepresenting fellowship status.
(2) Failing to provide requested information to authorities.
(3) Providing false information in professional contexts.
Being convicted of an offense punishable with up to 6 months
Part IV (All Members) (1)
imprisonment.
(2) Actions bringing disrepute to the profession or Institute.
Second Schedule: Professional Misconduct
Claus
Part Misconduct
e
Part I (PCS) (1) Disclosing client information without consent or legal obligation.
(2) Certifying reports without proper examination.
(3) Allowing their name on inaccurate reports for future transactions.
(4) Expressing opinions on businesses where they have a substantial interest.
(5) Failing to disclose material facts affecting report accuracy.
(6) Failing to report known material misstatements.
(7) Negligence or lack of due diligence in professional duties.
(8) Failing to gather sufficient information or highlight material exceptions.
(9) Not reporting departures from generally accepted practices.
(10) Mishandling client money (e.g., not depositing in separate accounts).
Part II (All
(1) Violating the Act, Regulations, or Council guidelines.
Members)
(2) Disclosing confidential employment information unlawfully.
(3) Submitting false information in statements, returns, or forms.
(4) Defalcating or embezzling client money received professionally.
Part III (All Conviction by a court for an offense punishable with imprisonment exceeding
(1)
Members) six months.
Complaints & Enquiries: Regulation 15 (Old cases prior to 17.11.2006)
📌 How Complaints Are Handled:
1. Any complaint about a member’s misconduct is handled by the Disciplinary Committee.
2. Frivolous complaints (not serious or with bad intent) may be rejected.
3. Complaint must be:
o In proper form, verified.
o Include details of misconduct and evidence.
o Must be submitted with a ₹50 fee, unless filed by the government.
📝 Initial Scrutiny:
If the complaint is incomplete, the Secretary returns it for correction.
Within 60 days, the Secretary must:
o Inform the concerned member or firm.
o Ask for a written defence from the member within 14 days.
240
⚖️Preliminary Action by the Council:
If prima facie (on the face of it) there is a case → Council refers it to the Disciplinary Committee.
If no case → complaint is dismissed.
📋 Disciplinary Committee Enquiry: Regulation 18
👩⚖️Key Powers and Procedure:
Can examine witnesses, affidavits, and documents.
Both complainant and respondent get a chance to:
o Appear personally or through a legal representative.
If the committee’s members change midway, a new enquiry can be requested within 15 days.
📣 Outcome:
Committee submits a report to the Council for final decision.
Council Hearing: Regulation 19
📚 Process:
1. Council reviews the report of the Disciplinary Committee.
2. If needed, Council can ask for a further enquiry.
3. If not guilty → case closed.
4. If guilty:
o Member is given a chance to be heard.
o Council then passes appropriate orders (e.g., reprimand, fine, suspension).
5. Both parties are informed of the outcome.
🤝 Multidisciplinary Firm (MDF) – Regulation 165A (Added in 2020)
A Company Secretary in Practice can form a MDF with members of other recognized professional
bodies.
Must follow Regulations 168A and 168B and Council guidelines for such firms.
UDIN (Unique Document Identification Number)
Aspect Details
What is UDIN? A 17-digit system-generated number for authenticating documents signed/certified
by CS in Practice
Mandatory from 1st October 2019
Purpose - Prevent forgery/counterfeit
- Ensure document authenticity
- Track attestation services rendered
When to - On signing the document
generate? - Or 7 days in advance of signing
Where to - On all reports, returns, certificates, other docs
mention? - Along with CoP number
- In e-forms (e.g., MGT-7) attach UDIN in optional attachment if no specific field is
given
Why it's useful - Verifies authenticity for stakeholders
- Helps in renewal of CoP by auto-prefilling attestation details
- Ensures compliance with certification limits.
eCSIN - Employee Company Secretary Identification Number
241
Aspect Details
What is eCSIN? A system-generated 18-digit alphanumeric number for identification of employed
Company Secretaries.
Purpose To enable ICSI to track appointments and cessations of CSs in employment (KMP or
otherwise).
Who generates The Company Secretary at the time of joining or leaving a company.
it?
Where to On the designated website with active membership.
register?
Effective from 1st October 2019 – Mandatory as per ICSI Council.
ICSI (Guidelines for Advertisement by Company Secretaries), 2020
The ICSI Guidelines for Advertisement by Company Secretaries (from 1st April 2020) apply to all
advertisements by Company Secretaries rendering advisory, consultancy, or representation services, whether
or not they hold a Certificate of Practice (CoP) from the Institute.
Permitted Advertising Activities:
CS in Practice can:
1. Display scope of work on own website.
2. Use individual logos (as per ICSI guidelines).
3. Show office location, décor, meeting rooms, etc.
4. Display firm name/logo on uniforms, stationery, equipment, and during staff training.
5. Publish professional updates and write-ups.
6. Appear on TV/radio.
7. Deliver speeches at seminars, conferences, training programs, workshops, etc.
8. Host or sponsor professional or community events.
9. Use social media platforms like LinkedIn, Facebook, Twitter, Instagram, WhatsApp, YouTube, etc.
Advertisement Restrictions:
Must NOT Explanation
Violate CS Act Must follow law
Be false or misleading No fake or exaggerated claims
Claim superiority No "best CS in town" types
Be indecent or sensational Must uphold profession’s dignity
Contain false testimonials No fake reviews or endorsements
Use terms like “expert” or “specialist” Not permitted
Use self-praise Avoid words like "best", "better", "cheapest"
Compare services with others No comparison-based advertising
Guarantee outcomes Avoid statements like “we’ll win your case”
Mention contingency fee No promise of “fee only if result”
Highlight past success to guarantee future E.g., “We helped XYZ win – meet the masters” is banned
Be humorous or catchy slogans E.g., “Save ₹XXX, come to us!” is not allowed
⛔ Platforms Not Allowed:
CSs cannot list services on aggregators like Sulekha, OLX, UrbanClap, JustDial, Quikr, etc.
242
Cannot be part of networking or MLM associations requiring member recruitment or non-approved
services.
📝 Mandatory Website Disclaimer:
“The contents or claims in the website issued by the advertiser are the sole and exclusive responsibility of
the Advertiser. The Institute of Company Secretaries of India does not own any responsibility whatsoever
for such contents or claims by the Advertiser.”
📌 Professional Liabilities of a Company Secretary
A Company Secretary, despite having powers and responsibilities, is not free from liabilities. These liabilities
arise from statutes and service contracts, and can lead to penalties or disciplinary action in case of non-
compliance.
✅ Definition:
Professional liability means the CS will be held liable as an “officer in default” for non-compliance with
laws and statutory responsibilities entrusted to him/her.
📚 Types of Liabilities:
Type Explanation
🧾 Statutory Liabilities Arise from legal duties under Companies Act and related laws.
📄 Contractual Liabilities Arise from the service contract between CS and company/client.
🧾 1. Statutory Liabilities (Legal obligations)
A Company Secretary is bound to:
Maintain company records and statutory registers.
Arrange and conduct statutory meetings.
Issue share certificates, dividends, and bonus shares.
Draft and maintain minutes of Board and General Meetings.
Ensure timely filing of returns and overall legal compliance.
⚠️Non-compliance = CS is treated as "officer in default" → penalties apply
🔍 Example:
Failure to file annual return within 60 days from AGM:
o ₹10,000 fine + ₹100/day of continued default
o Max: ₹2 lakh (Company), ₹50,000 (Officer in default)
CS in practice certifying return wrongly:
o Penalty of ₹2 lakh
📌 Important Case Law
Re: Saumil Dilip Mehta v. State of Maharashtra (2001)
📌 Bombay HC held:
A director can resign unilaterally without filing Form 32.
CS is responsible for:
o Processing resignation,
o Filing prescribed forms with ROC,
o Updating company registers, accounts, balance sheets,
o Informing members (ideally in the next AGM).
243
✨ Key takeaway: CS holds statutory duty to give effect to Board’s decisions.
📄 2. Contractual Liabilities
Arising out of service agreements with the company/client. A CS is contractually liable for:
1. Exceeding authority beyond permitted limits.
2. Disclosing confidential info to outsiders.
3. Committing fraud or misconduct.
4. Violating terms of employment/service contract.
5. Failing to protect company’s interest.
Lesson: 16 (Due Diligence)
📘 Definition & Concept
Due Diligence is a comprehensive investigation into the affairs of a company before entering into a
major transaction like:
1) Acquisition
2) Restructuring
3) Fundraising
4) Merger/Amalgamation
It involves analysis, interpretation, and communication of facts to help stakeholders make
informed decisions.
The process is designed to verify accuracy, uncover risks, and assess future prospects.
🔍 Purpose & Scope
Evaluate target company’s:
1) Business operations
2) Financials
3) Legal compliance
4) Environmental context
Conducted pre-, during, and post-transaction phases.
Used in both buyer-side and seller-side evaluations.
🔄 Due Diligence is an Interactive Process
Steps involved:
1) Inquire about data (financial, legal, technical, HR)
2) Analyze the data
3) Interpret results
4) Assess risks and opportunities
📌 Key Points Describing Due Diligence
📊 Business-Oriented Approach – Goes beyond just financials; evaluates the business model and
strategy.
🏭 Industry Context – Considers the industry environment of the target company.
244
⚙️Operational Impact – Examines major aspects affecting future business prospects.
🔍 Business Practices Review – Reviews practices and models being followed.
⏳ Past, Present & Future – Evaluates historical performance, current standing, and likely future.
⚖️Risk-Reward Assessment – Assesses both advantages and risks of a transaction.
📁 Fact-Based Analysis – Relies on actual, verified facts.
🎯 Objectives of Due Diligence
✅ Identify key issues or significant matters.
⚠️Discover risks, threats, or weaknesses.
💡 Enable informed investment decisions.
🔐 Ensure security and confidence in the transaction.
🙌 Build shareholder and investor trust.
📚 Collect relevant material information.
📈 Support SWOT analysis (Strengths, Weaknesses, Opportunities, Threats).
📌 Challenges in Conducting Due Diligence
🔐 Confidentiality Barriers: Target company often avoids disclosing it’s up for sale to:
o Prevent panic among employees
o Avoid negative reactions from customers or competitors.
🤝 Limited Access to Key Stakeholders:
o Buyers often want to assess employee or customer relationships
o Target company may restrict such access fearing reputational or operational risks.
👥 Reliance on Experts:
o Buyers appoint legal, financial, and technical experts for unbiased evaluation
o Trusted internal and external advisors help simulate “what can go wrong” scenarios.
🔁 Renegotiation or Exit Option:
o Post due diligence, if risks are found, buyers may renegotiate or walk away.
📝 Conditional Agreements:
o Purchase price often agreed upon conditionally with a “due diligence clause”
o A confidentiality agreement protects the target company’s sensitive data.
📂 Situations Requiring Due Diligence
✔️Joint Ventures (technical/financial collaboration)
✔️Strategic Alliances & Business Coalitions
✔️Mergers & Acquisitions
✔️Public Issues
✔️Venture Capital Investments
✔️Product/Technology Licensing
✔️Outsourcing Agreements
✔️Partnerships
🎯 Need for Due Diligence
245
🔍 Confirm authenticity of the business
🤝 Build trust between unrelated parties
⚠️Identify risks & opportunities
Minimize post-transaction surprises
📑 Confirm all material facts
💬 Support negotiation and warranty clauses
💵 Set correct price & payment method
🧾 Ensure legal & regulatory compliance
🏭 Inspect tangible & intangible assets
⚖️Analyze antitrust and legal implications
🧭 Scope of Due Diligence
📌 Due Diligence involves disclosure and assimilation of public and proprietary information relating to
the business, including:
⚖️Legal & Regulatory Issues
💼 Financials & Tax matters
🌱 Environmental Compliance
🧑💼 Human Resources
💡 Intellectual Property (IP)
🔍 What Due Diligence Covers
⚖️Tax structure & legal compliance
📊 Valuation and accuracy of assets/liabilities
📉 Hidden liabilities, inflated assets
📚 Review of pending litigations
👥 Management quality & key personnel
🏭 Resource availability, technical & commercial feasibility
🤝 Synergies between acquirer and target
🧾 Contracts, warranties, leases
🔒 Unpaid taxes, judgments, or defaults
💬 Misrepresentation/fraudulent claims
🌍 Cross-border considerations (e.g., double taxation, FX risk)
🏆 Advantages of Due Diligence
🎯 Identifies who owns, administers, and controls the target business
📊 Provides contrastive analysis of the company vs. market
🧠 Understands competitive landscape
💵 Evaluates financial health through ratios (e.g., debt-equity ratio)
📈 Measures revenue trends and growth prospects
💼 Estimates valuation and profitability potential of the target
✅ Factors To Be Kept In Mind While Conducting Due Diligence
🎯 1. Objectives and Purpose
Understand the why behind the transaction:
🔍 Identify goals: revenue, profit potential, market scope.
💪 Check your capacity: resources, effort, commitment.
🧠 See if your skills/experience align with the business.
246
📚 Study the industry via reports, media, experts.
📅 2. Planning the Schedule
Structure the process in phases:
🪜 Outline steps in due diligence
📋 Define areas and aspects to examine (e.g., legal, financial, HR)
📂 List documents & materials to request from the seller
⏳ 3. Negotiation for Time
⚠️Sellers may try to rush the process
🤝 Negotiate for adequate time to verify financial & legal details thoroughly
4. Risk Minimisation
🔍 Double-check financials, tax returns, IP, customer base
🚫 Watch out for creative accounting or hidden liabilities
📊 Analyze:
o Promoters’ background
o Management performance
o Risk management system
o Technology & infrastructure
o Resource utilization & strategy
🌐 5. Information from External Sources
Talk to customers & vendors
✅ Check if target is a preferred client
💬 Use external feedback to re-negotiate price if issues are uncovered
🧾 6. Limit Report to Material Facts
📌 Only include relevant, impactful information
✂️Avoid unnecessary details in the final report
7. Structured Information
🧱 Organize content clearly in the report
🔗 Ensure easy correlation across issues (e.g., legal & financial red flags).
⚠️Challenges in Conducting Due Diligence
🔍 Challenge 💡 Possible Solution
📄 Incomplete or unavailable info Search alternate sources, e.g., public records
⏰ Time constraints Confine checking scope to critical areas
🙅♂️Employee non-cooperation Report resistance to authorities for resolution
247
🔄 Process and Stages of Due Diligence
Due Diligence is conducted in three stages:
🧭 Stage 📝 Key Activities
1. Pre-Diligence LOI, NDA, collating documents, data room setup
2. Diligence Review, identify issues, prepare detailed/summarised report
3. Post- Rectify non-compliances, apply for approvals, negotiate & execute Shareholders
Diligence Agreement
🌟 Pre-Diligence: The preparation phase focuses on organizing documents and setting the deal’s
foundation.
o Sign a Letter of Intent (LOI) or term sheet to outline deal terms, scope, timelines, and deliverables
(e.g., Due Diligence Report).
o Execute a Non-Disclosure Agreement (NDA) with agencies conducting financial, legal, or
secretarial diligence.
o Collate documents using a checklist, organize them in a data room, and identify potential issues.
o Ensure proper management: avoid delays, mark checklist modules, assign a single point of contact,
and maintain a visitor register.
🔍 Diligence: The investigation phase involves scrutinizing documents and preparing a comprehensive
report.
o Review documents for compliance, litigation, financials, and intellectual property.
o Prepare a Due Diligence Report with three sections: Executive Summary (critical issues), Main
Body (detailed findings), and Appendices (supporting data).
o Report outcomes:
💡 Type 📋 Description
❌ Deal Breakers Glaring issues like criminal proceedings or major legal non-compliances
⚠️Deal Diluters Issues that diminish company value (e.g. fines, penalties, tax defaults)
🟡 Deal Cautioners Minor rectifiable non-compliances which may not impact financial, but
call for investor caution.
✅ Deal Makers Clean reports with no issues - rare; highly favorable
o Include suggestions for resolving issues, document lists, assumptions, and risk analysis.
✅ Post-Diligence: The resolution phase addresses findings and finalizes the deal.
o Rectify non-compliances (e.g., filing petitions for compounding offenses).
o Negotiate and execute the Shareholders Agreement, including clauses like tag-along/drag-along
rights and warranties.
o Investors may negotiate harder based on findings, impacting the deal price.
Summary of Due Diligence & Risk Assessment
Objective Analysis
📍 Define project goals to align with business strategy.
248
Know Your Client
👥 Identify client risks to manage relationships effectively.
Examine Financials
💰 Review financial health: Balance sheets, forecasts, debts, and growth trends.
Inspect Documents
📄 Analyze records to understand the organization’s growth and value.
Risk Control Actions
⚠️Monitor risks: Test services, use mystery shopper techniques, and set internal checks.
Incident Response
🚨 Respond to breaches quickly and work with regulators to resolve issues.
📋 Formulate action plans based on:
Service category risk
Service nature (e.g., subscription-based)
Client’s past breach history
🛠 Techniques include:
Mystery shopper testing
Monitoring for complaint spikes or unusual activity
Internal whistle-blower mechanisms
Checks for regulatory compliance
Maintaining a compliance file (records, plans, test results).
🏢 Types of Due Diligence
Due diligence in business transactions varies depending on the company type. Key areas of concern typically
include financial, legal, tax, environmental, and market conditions. Below are the main types of due
diligence:
1) Legal Due Diligence
2) Operational Due Diligence
3) Bank Due Diligence
4) Ethical Due Diligence
5) Financial Due Diligence
6) Human Resource Due Diligence
7) Information Technology Due Diligence
8) Strategic Due Diligence
⚖️Legal Due Diligence
Legal due diligence assesses all legal risks associated with the company's structure, assets, contracts,
intellectual property, and more. Its goal is to safeguard the business transaction by thoroughly understanding
potential legal issues.
Key Components of Legal Due Diligence:
Legal pitfalls and risks
Liabilities of the target company
249
Inter-corporate and intra-corporate transactions
Legal due diligence ensures the safe execution of a transaction, reducing future complications and risks.
🔑 Important Aspects of Legal Due Diligence
1. Regulatory Compliance: Ensures adherence to laws such as:
Company Law
Income Tax Law
Labour Law
RERA Act
SEBI Act and its regulations
Insurance Act
RBI Act
FEMA Act
Intellectual Property Law
2. Documents to Verify:
Memorandum and Articles of Association
Minutes of Board meetings (last 3 years)
Shareholder meeting minutes and actions
Register of Members and Share Transfer deeds
Guarantees and contracts involving the company
Pending litigations, regulatory awards, and rulings
Corporate documents such as organizational charts, ROC returns, and branch/subsidiary
details
3. Company Secretaries' Role:
Act as watchdogs to safeguard corporate governance and stakeholder interests.
Required to ensure the company adheres to sound governance practices.
⚖️Transactions Covered Under Legal Due Diligence
1) Initial Public Offers (IPOs) / FPOs / QIPs
2) Corporate Restructuring
3) Mergers & Acquisitions
4) Joint Ventures
5) Commercial Agreements
6) Private Equity
7) Leveraged Buyouts
8) Corporate Governance Compliance
9) General Compliance Requirements
📋 Scope of Legal Due Diligence
Legal due diligence ensures regulatory compliance with various laws governing corporate operations. This
includes:
Company Law
250
Income Tax Law
Labour Law
RERA
SEBI Act
Insurance Act
RBI and FEMA Act
Intellectual Property Rights (IPR).
🤝 Due Diligence for Merger & Amalgamation
Mergers and amalgamations involve complex integration of companies. Due diligence is critical for
assessing risks, compatibility, and value.
✅ Objectives of M&A Due Diligence
Assess financial, legal, regulatory, and operational aspects
Understand structure, HR, culture, customers, suppliers, competition
Identify deal-killers or deal-shapers
Aid in price setting and integration planning
🧩 Strategic Analysis Before Merger
Identify potential targets
Evaluate strategic, financial, and cultural compatibility
Analyze open and hidden risks
📋 Due Diligence Process in M&A
Stage Buyer’s Role Seller’s Role
Preparation Form M&A strategy, shortlist targets, Structure business plan, shortlist
appoint advisors, create due diligence buyers, appoint advisors
team
Pre-Diligence Approach targets, sign NDA, prepare Share info, sign NDA, creation of Data
data needs room
Due Diligence Inspect data room, analyze risk-return Assist in data room access
Negotiations Make final offer, agree on terms Compile and select best offer,
negotiations
Documentation Sign merger/acquisition agreement Sign final agreement
Regulatory Obtain from board, shareholders, Same as buyer
Approvals regulators
Integration Process of integration of systems,
culture, operations
Post Diligence Post merger integration and cultural Termination of data room and
alignments. ownership exchange.
🏢 Due Diligence for Takeovers
Takeovers are high-risk investments involving legal, financial, and strategic challenges.
🔍 Scope of Takeover Due Diligence
Covers financials, legal, tax, environment, social, history, future
Assesses the overall value and risk
251
Validates deal terms and helps in negotiation
⚖️Importance
Helps avoid financial losses post-takeover
Confirms buyer’s decision or renegotiates terms
Conducted post-LOI or post-agreement
📜 Takeover of companies whose securities are listed on one or more recognized stock exchanges in
India is regulated by:
Provisions of the Listing Agreements with various stock exchanges
Governed by SEBI (Substantial Acquisition of Shares and Takeovers) Regulations, 2011
The compliances under the regulations include:
Event-based/continual disclosures
Open offer, public announcements
Escrow account
Merchant banker obligations
⚖️Key Case Laws / Examples
1. Nirma Industries v. SEBI
o Nirma wanted to withdraw open offer citing fraud.
o SC rejected, held that investor is responsible for its own due diligence.
2. TotalEnergies & Adani Group
o TotalEnergies invested $3.1B in Adani entities post thorough due diligence.
o Highlighted importance of reviewing public domain disclosures and regulatory compliance.
📢 Due Diligence for Issue of Securities
🔍 Purpose
Ensures legal compliance and avoids liabilities.
Preserves reputation of company, promoters, and intermediaries.
Helps avoid material misstatements or omissions in prospectus or offer documents.
📌 Types of Issues & Compliance Required
Public Offer – Prospectus, Companies Act + SEBI Regs
Private Placement – Part II of Chapter III + SEBI rules (if listed)
Rights / Bonus Issue – Companies Act, SEBI rules if listed
Private Companies – Rights, bonus, or private placement as per Companies Act
⚠️Liabilities for Non-Compliance
Incorrect/misleading statements or omissions in prospectus
Civil/criminal liability on issuer, directors, underwriters
In some cases, the entire issue may be cancelled.
💡 Due Diligence in Intellectual Property (IP)
🎯 Objective
252
Determine ownership, scope, and validity of IP
Ensure no infringement claims or legal disputes
🧾 Key Areas to Review
📁 All consulting, licensing, invention, and assignment agreements
🧬 Schedule of patents and applications
Schedule of trademarks, copyrights, brand names
🧷 Details of pending or threatened IP litigations
🌍 List of Indian and international IP holdings
📌 Why It Matters
IP is a valuable intangible asset (like patents, brands, etc.)
Poor IP management can affect valuation and expose company to legal risks
🌱 Due Diligence in Environmental Law
📚 Key Environmental Laws in India
Environment Protection Act, 1986
Air Act, 1981 | Water Act, 1974
Forest Conservation Act, 1980 | Wildlife Protection Act, 1972
National Green Tribunal Act, 2010
Biological Diversity Act, 2002
Public Liability Insurance Act, 1991
🧪 Scope of Environmental Due Diligence
Review of:
o Permits, licenses, and validity
o Use of hazardous materials
o Pollution control methods
o Legal compliance, past violations or investigations
o Litigation or regulatory correspondence
o Environmental liabilities (contingent or ongoing indemnities)
o Whether the company’s disposal methods of various by products are in sync with the
regulated guidelines.
✅ Purpose
Protect acquirers/investors from hidden environmental liabilities
Ensure compliance with environmental norms before corporate deals
👷♂️Labour Law Due Diligence
🎯 Purpose
Identify gaps and non-compliances in labour law application.
Ensure readiness before regulatory audits.
Essential during:
o 📈 Mergers & Acquisitions
o 📊 IPOs
253
o 🤝 Joint Ventures
o 🔚 Liquidation/Winding-up
Key Labour Laws in India
Employees Compensation Act, 1923
Payment of Wages Act, 1936
Minimum Wages Act, 1948
Factories Act, 1948
Maternity Benefits Act, 1961
Payment of Bonus Act, 1965
Payment of Gratuity Act, 1972
Employees State Insurance Act, 1948
Industrial Disputes Act, 1947
Trade Unions Act, 1926
Sexual Harassment at Workplace Act, 2013
📋 Scope of Labour Due Diligence
📝 Employment contracts and amendments
📃 Termination agreements and legal declarations
🧾 Payroll systems and statutory deductions
Record maintenance
⚖️Compliance with central/state/local employment laws
⚖️Competition Law Due Diligence
🎯 Objective
Ensure compliance with the Competition Act, 2002
Detect potential antitrust risks, abuse of dominance, or anti-competitive practices
Influence deal structure, valuation, or cause deal withdrawal.
🧰 Key Components
1. 🔍 Review of company documents
2. 👥 Interviews with company key personnel
3. 📌 Identification of activities that could antitrust exposures
4. 🧩 How to go about the process of DD in Competition Law
🔎 Due Diligence Areas
1. Agreements
📦 Production, supply, distribution agreements
🤝 Agreements with competitors (price, market sharing, etc.)
🧾 Purchase contracts, non-compete clauses
💡 Technology & know-how transfer agreements
2. Dominance and Its Abuse
254
⚙️Existence of dominant position
🌍 Examination of relevant market, product/geographic scope
🚫 Acts of abuse, if any
3. Combinations (M&A Impact)
🔄 Nature of Combination: acquisition, merger, voting rights, etc.
💰 Asset/turnover valuation and threshold applicability
📝 CCI (Competition Commission of India) notification requirements
🧮 Impact on market dominance post-deal.
🌍 FEMA Due Diligence (Foreign Exchange Management Act, 1999)
🎯 Objective
Manage and monitor cross-border transactions effectively.
Ensure compliance with FEMA to avoid heavy penalties.
Covers capital and current account transactions.
📌 Key Coverage Areas
🏦 Capital Account Transactions (FDI, ECB, ODI, share transfer, etc.)
💱 Current Account Transactions (trade payments, services, travel)
💵 Currency Transactions
🧾 RBI Regulations, Master Directions, and Circulars
📜 FDI Policy and Approvals
🏢 Entry Routes:
o Liaison Office (LO)
o Branch Office (BO)
o Project Office (PO)
o Wholly-Owned Subsidiaries (WOS)
o Joint Ventures
o FIIs, FVCIs, NRIs, PIOs
🌐 FCRA Due Diligence (Foreign Contribution Regulation Act, 2010)
🎯 Objective
Regulate foreign contributions received by NGOs in India.
Ensure transparency, legal compliance, and proper use of foreign funds.
📌 Key Points
🚫 NGOs must be registered under FCRA or obtain prior permission.
📊 Post-registration requirements must be fulfilled.
🏢 NGO Types:
o Society
o Trust
o Section 8 Company (Non-profit)
🧾 Annual Return Filing:
255
o With Ministry of Home Affairs (MHA)
o Deadline: Within 9 Months of FY closure
🔍 Regulatory Bodies:
o MHA (FCRA Compliance)
o Income Tax Department (Tax Returns, Audits)
📚 Other Business Laws
🏢 Regulatory Scope
Ensures sustainable and lawful business operations.
Covers sectors beyond corporate and taxation laws.
📌 Includes:
📝 Registrations & Approvals from statutory authorities
🧪 Pollution Control and Environmental Compliance
🏠 Property-related Issues (title deeds, encumbrances)
🌏 FEMA & Insurance Laws
🏭 Factories Act, 1948
Real Estate & Construction Law
👷♀️Labour & Employment Law
🌐 International Business Law
📊 Financial Due Diligence (FDD)
🎯 Objective
Verify accuracy of financials in Information Memorandum.
Understand key financial, operational & strategic risks in a deal.
Ensure informed decision-making for mergers, acquisitions, or investments.
🧾 Key Coverage Areas
✅ Audited financial statements (past 3 years)
✅ Unaudited interim results with prior year comparison
✅ Accounting policies & internal audit procedures
✅ Earnings quality, cash flow analysis
✅ Assets & liabilities: condition, value, potential risks
✅ Tax implications, pending litigations
✅ Internal controls & IT systems reliability
✅ Working capital, inventory, debtors/creditors analysis
🔍 Focus Areas of FDD
💰 1. Quality of Earnings, Margins & Cash Flows
🎯 Seasonality of sales
📈 Gross margin trends, cost impact
🔁 Recurring vs. non-recurring items
256
💵 Stability of cash flows from operations
📦 2. Working Capital Analysis
🏭 Inventory Turnover
💧 Current Ratio
🧾 Debtor aging (above/below 6 months)
🧮 Valuation of WIP
📉 3. Net Debt Analysis
💸 Cash vs. credit transactions
📑 Loan agreements and compliance
🔁 Restructuring schemes
⚠️4. Liabilities & Commitments
📂 Contingent & off-balance sheet items
👴 Pension obligations
📉 Aggressive vs. conservative accounting policies
🔄 5. Structuring / Integration Issues
🔗 Supply chain & systems impact
🧩 Standalone operation feasibility
🤝 Synergies & transition services
🤝 6. Related Party Transactions
📏 Arm’s length nature
🔄 Shared resources or costs
💳 Financial arrangements with related parties.
🧾 Tax Due Diligence (Subset of Financial DD)
📌 Tax compliance status
⚠️Contingent tax liabilities
🔄 Transfer pricing risks
🎯 Tax planning opportunities
⚖️Pending litigation with tax authorities
🏦 Bank Due Diligence
🎯 Purpose
Conducted by banks when a company applies for loans.
Ensures credibility, compliance, and transparency of the borrower.
🔍 Objectives of Bank Due Diligence
🔎 Verify details of directors/promoters
257
📜 Check statutory & procedural compliances
🏦 Review existing/previous charges on assets
⚠️Identify defaulting status of directors
🧾 PCS (Practising Company Secretary) Role
📅 Reporting Period
Half-yearly diligence reporting
📚 Methodology & Access
Company must give PCS full access to:
o 📘 Books & papers
o Statutory filings
o 📜 Minutes, returns & legal records
PCS may request explanations from company officials
For matters not verifiable (e.g. show cause notices, director interests), PCS may obtain a Letter of
Representation
⚖️Reporting Style & Limitations
✍️With Qualifications
📌 Adverse remarks/reservations should be bold/italicized
❓ If PCS cannot form opinion, reason must be clearly stated
🚫 If key records are inaccessible, PCS must disclose limitation:
“In absence of necessary information and records, unable to report compliance(s) or otherwise.”
📑 Professional Care & Responsibility
PCS must:
o 📏 Follow RBI circulars and updates
o 🎯 Maintain integrity, ethics, and accuracy
False diligence reports may lead to:
o 👩⚖️Disciplinary action (under Company Secretaries Act, 1980)
o 💼 Professional misconduct charges
o 💥 Legal liability for damages due to negligence
🚫 Disqualifications to Act as PCS
PCS must not issue a Diligence Report if they are:
🏢 A body corporate
🧑💼 An employee/officer of the borrower company
👥 Partner/employee of company officer
💸 Debtor or guarantor to company > ₹1,000
Holder of voting shares in the company
🔹 Note: Trustee/nominee holdings without beneficial interest are exempted.
258
📌 Disqualification extends to holding/subsidiary companies as well.
🧭 Ethical Due Diligence
Measures the ethical character of a company
Evaluates non-financial risks: ethics, governance, reputation
Used to assess if a partner is ethically viable
Often part of reputation management
Involves assessing:
o 💼 Management and employee alignment with ethical values
o 📈 Ethical performance in career growth
✅ Adds depth and reliability to overall diligence if conducted accurately.
🧠 Strategic Due Diligence
Tests the strategic rationale of a deal: Is the business plan realistic, viable, and sustainable?
Evaluates:
o 💡 Value creation opportunities
o 🔍 Competitive positioning
o 🔧 Critical capabilities
Considers macro and micro-environmental factors
Focus is on long-term commercial viability.
⚙️Operational Due Diligence
Evaluates historical and current operations
Includes:
o 🏢 Facilities, office layout, asset locations
o Age and condition of assets
o 💸 Cost structure & synergy mapping
Verifies:
o 📑 Fixed asset schedules, lease agreements, real estate deeds
o 🧾 Past 3-year sales/purchases of major capital equipment
✅ Benefits:
Detects operational weaknesses and control gaps
Confirms financial accuracy of operational costs
Forecasts expansion-related costs.
👥 Human Resource (HR) Due Diligence
Reviews organizational structure & HR policies
Focuses on:
o 💬 Collective agreements
o 💰 Compensation & bonus trends
o 🔄 Labour turnover & demographics
Assesses potential issues:
o 🔍 Employee litigations (e.g., harassment, discrimination)
o 📋 Pension & benefit scheme details
o 🌐 Cultural alignment in cross-border deals
✅ Key Elements:
📄 Employee list, salaries, contracts (with NDAs, non-competes)
259
🧑⚖️Legal disputes and pending claims
🏥 Health benefits & insurance schemes
📊 Analysis of current & retiring employees
⚠️Cultural fit (esp. in M&A or cross-border transactions).
💻 Information technology (IT) Due Diligence
✅ Importance:
Evaluates all systems, policies, procedures, and IT processes
Ensures the technological health and security posture of an organization
Crucial in mergers, acquisitions, and tech-related partnerships
🎯 Key Benefits:
📊 Understands technological capabilities
🔍 Identifies and assesses tech-related risks
🔐 Evaluates impact of IT on business transactions
📉 Mitigates risk of costly security breaches
Information Security Due Diligence Includes:
🔒 Information security measures
📜 Data protection and sharing policies
🌐 Network and system architecture
📶 Wireless and remote access controls
🚨 Incident management protocols
🧠 Essentials of IT Due Diligence:
🔧 Analyze IT processes & systems
💰 Evaluate current IT investments & costs
Assess IT infrastructure and security controls
Check efficiency of business software & systems.
🤐 Non-Disclosure Agreement (NDA)
📘 Definition:
A legally binding contract establishing a confidential relationship between the disclosing party and
the receiving party
Ensures trade secrets or sensitive info remain protected
🎯 Functions of NDAs:
1. Protect confidential information
2. Safeguard patent rights (prevent public disclosure)
3. Define scope of confidentiality (what’s protected & what’s excluded)
📄 Content of NDAs:
Definitions & Exclusions:
o Specifies what qualifies as confidential information
o Excludes public/common knowledge or pre-known data
Obligations & Time Periods:
o Duties of each party to maintain secrecy
260
o Defines duration of confidentiality (e.g., number of years)
📘 Definition:
“Confidential Information” refers to any information shared or that comes into possession of the Receiving
Party, regardless of form (oral, written, electronic, etc.), and regardless of when disclosed (before or after
the agreement).
📦 What It Includes (Non-exhaustive):
🤝 Info related to the purpose of the agreement
📄 Terms of any agreement or proposal (even if not finalized)
🔍 The fact that the parties are exploring or discussing the purpose
🧪 Info obtained by testing or analysis of provided hardware/software
🧠 All technical, financial, business, or strategic info:
o From the Disclosing Party or its affiliates (parent, subsidiary, etc.)
o In any media (hardcopy, electronic)
o Including IP like software, devices, demos, know-how
🚫 Exceptions To Confidentiality
The protections do not apply if the Receiving Party can prove:
1. 🌐 The info is already public at the time of disclosure.
2. 📣 The info becomes public later, without breaching the NDA.
3. 📁 Info was already lawfully possessed before disclosure.
4. 👥 Info was lawfully disclosed by a third party.
5. Info was independently developed without using the disclosed material.
261