Compliance Guide

India Governance, Risk & Compliance for Foreign Companies

As your India entity grows, so does board, control and regulatory risk. We put governance, internal controls and a compliance calendar in place so the parent board can rely on the India operation.

In short: Governance, risk and compliance (GRC) for an Indian subsidiary covers board and secretarial governance (board meetings, statutory registers, ROC filings under the Companies Act), internal financial controls (IFC) and risk mapping, a statutory-compliance calendar (tax, labour, FEMA), data privacy under the new Digital Personal Data Protection (DPDP) Act, and internal and statutory audit. We build the framework and run it so the foreign parent has assurance.

What GRC covers

Board & secretarial governance

Board meetings, statutory registers, board report and annual ROC filings under the Companies Act.

Internal financial controls

IFC over financial reporting, a risk register and a delegation-of-authority matrix.

Statutory compliance calendar

Tax (income tax, TDS, GST), labour (PF, ESI, PT) and FEMA (FC-GPR, FC-TRS, FLA) — one calendar.

Data privacy (DPDP Act)

Consent, purpose limitation and data-principal rights for customer and employee data.

Companies Act governance

  • Board meetings — minimum four a year, with defined gaps
  • Statutory registers (members, directors, charges) and minute books
  • Board’s report each year
  • Annual ROC filings — AOC-4 (financials) and MGT-7 (annual return)
  • Auditor appointment and rotation

Internal financial controls & risk

IFC over financial reporting, a documented risk register and a delegation-of-authority matrix give the parent board assurance that the India operation is controlled — not just compliant on paper.

Data privacy — the DPDP Act

India’s Digital Personal Data Protection Act introduces consent, data-principal rights and processing obligations. Foreign subsidiaries handling customer or employee data must map data flows, appoint contacts and align contracts and notices with the new regime.

Internal & statutory audit

Statutory audit is mandatory for every Indian company. Internal audit is required above certain size thresholds and, beyond that, is a strong control the parent board typically wants over the India operation.

Compliance calendar & ESG basics

We consolidate every deadline — corporate, tax, labour, FEMA — into a single India compliance calendar, and add ESG basics as they become material. See India post-entry support and payroll & HR compliance for the operational stack.

Frequently asked questions

What governance does an Indian subsidiary need?
Under the Companies Act it needs a functioning board (at least four board meetings a year), statutory registers, a board report, annual ROC filings (AOC-4 and MGT-7), and an appointed auditor — plus internal controls the parent board can rely on.
What is the DPDP Act?
The Digital Personal Data Protection Act is India's data-privacy law. It sets rules for collecting and processing personal data — consent, purpose limitation and data-principal rights — with obligations on companies that handle customer or employee data.
What are internal financial controls (IFC)?
IFC are the policies and procedures that ensure orderly, accurate financial reporting and safeguard assets. Indian company law requires the board and auditor to report on their adequacy for many companies.
Does an India subsidiary need an internal audit?
Statutory audit is always required. Internal audit is mandatory above certain size thresholds and is otherwise recommended where the foreign parent wants independent assurance over the India operation.

Reviewed by CA Regi Tom Antony, Regi Tom Antony & Associates. Last updated: July 2026.

Give the parent board assurance.

We put board governance, internal controls and compliance on a single India framework.