Fraud risk, forensic audit and whistleblower mechanisms
Most of these guides are about arrangements made in advance. This guide is about what those arrangements are for. It covers the auditor’s statutory duty to report suspected fraud, whose filing procedure changed in July 2025; the vigil mechanism and who must have one, and the standards that bind a forensic investigation. It also says clearly where Indian law imposes no requirement at all, because that is where the marketing tends to be loudest.
The auditor’s fraud reporting duty
Under section 143(12) of the Companies Act, read with Rule 13 of the Companies (Audit and Auditors) Rules 2014, an auditor who has reason to believe an offence of fraud is being or has been committed against the company by its officers or employees has a reporting duty. Where that fraud involves, individually, ₹1 crore or above, the report goes to the Central Government. Below that figure, it goes to the audit committee or the board.
The sequence for a Central Government reportable fraud is tightly timed. The auditor reports to the board or audit committee immediately but not later than two days of becoming aware, seeking a reply within 45 days. On receiving the reply, the auditor forwards the report, the reply and the auditor’s own comments to the Central Government within 15 days. If no reply comes within the 45 days, the auditor forwards the report anyway, with a note recording that fact. There is no discretion in that last step, which is worth knowing on both sides of the conversation.
The procedure changed with effect from 14 July 2025. Under G.S.R. 359(E) of 30 May 2025, Rule 13(2)(d) was substituted to require the fraud report to be filed electronically in Form ADT-4, and clauses (e) and (f) were omitted. The former procedure, a sealed cover submission to the Secretary, Ministry of Corporate Affairs, by Registered Post with acknowledgement due or Speed Post followed by an email confirming dispatch, no longer applies. The associated requirements about the auditor’s letterhead, signature, seal and membership number were also removed from Rule 13(2). Some guidance and training material may still reproduce the pre-14 July 2025 procedure and should be checked against the amended Rule 13.
For frauds below the threshold, Rule 13(4) prescribes what the Board’s report must disclose: the nature of the fraud with a description, the approximate amount involved, the parties involved if remedial action was not taken, and the remedial actions taken. Section 134(3)(ca) is the statutory hook for that disclosure.
The duty applies mutatis mutandis to cost auditors under section 148 and to secretarial auditors under section 204. It does not apply to an internal auditor merely by virtue of appointment under section 138: section 143(14) and Rule 13(5) extend the procedure to cost auditors and secretarial auditors, but not to internal auditors. Internal auditors may nevertheless carry separate contractual, professional, governance or sector specific obligations to report suspected fraud to management, the audit committee, the board or another designated authority.
Section 447: what counts, and what it costs
Section 447 defines fraud, in relation to the affairs of a company, as any act, omission, concealment of any fact or abuse of position committed by any person or any other person with the connivance in any manner, with intent to deceive, to gain undue advantage from, or to injure the interests of, the company or its shareholders or its creditors or any other person, whether or not there is any wrongful gain or wrongful loss. That closing phrase does a lot of work: loss is not an element of the offence.
The section’s principal punishment applies where the fraud involves an amount of at least ₹10 lakh or one per cent of the turnover of the company, whichever is lower. There the punishment is imprisonment of not less than six months extending to ten years, and a fine of not less than the amount involved extending to three times that amount.
Where the fraud involves less than that threshold and does not involve public interest, a second proviso applies: imprisonment up to five years, or a fine up to ₹20 lakh, or both. A figure of ₹50 lakh appears in some commentary for this proviso and is wrong.
Note what the threshold structure means in practice. It is set by reference to the lower of an absolute figure and a percentage of turnover, so for a large company the one per cent limb is irrelevant and ₹10 lakh governs. For a small company the percentage can pull the threshold well below ₹10 lakh.
The vigil mechanism: who must have one
Under Rule 7 of the Companies (Meetings of Board and its Powers) Rules 2014, a vigil mechanism is required of every listed company, of companies which accept deposits from the public, and of companies which have borrowed money from banks and public financial institutions in excess of ₹50 crore.
Section 177(9) and Rule 7 continue to apply to "every listed company", rather than only to a "listed public company": the 2018 amendment that narrowed the audit committee rule did not touch Rule 7. But that expression must be read with the Companies Act definition of "listed company". A private company whose privately placed non-convertible debt securities are listed is excluded from that definition under Rule 2A, and is therefore not required to establish a vigil mechanism solely because of that listing. It may still be caught by another limb of Rule 7, including the public deposit or borrowing threshold.
The design requirements are short and they are the parts that get skipped. A company required to have an audit committee must operate the mechanism through that committee, with recusal where a member has a conflict. A company without one must nominate a director to play that role. The mechanism must provide adequate safeguards against victimisation. And it must allow direct access to the chairperson of the audit committee in appropriate or exceptional cases, which is the provision that makes the mechanism worth anything: a channel that routes every report through management is not a vigil mechanism, whatever the policy says. Rule 7 also permits suitable action, including reprimand, against repeated frivolous complaints.
For listed entities, SEBI LODR Regulation 22 imposes a parallel requirement in materially the same terms. Note that Regulation 22, like the other corporate governance regulations, does not apply to a listed entity with paid-up equity share capital not exceeding ₹10 crore and net worth not exceeding ₹25 crore, nor to entities listed on the SME Exchange.
SEBI’s informant mechanism
Distinct from the vigil mechanism, and often confused with it, SEBI operates an informant mechanism under the Prohibition of Insider Trading Regulations. It rewards a person who voluntarily provides original information about an insider trading violation.
The reward is 10 per cent of the monetary sanctions collected or recovered, subject to a maximum of ₹10 crore, with an interim reward capped at the lower of the total reward payable or ₹1 crore. The ₹10 crore cap has applied since an amendment of 5 August 2021. The original 2019 cap was ₹1 crore, and a great deal of still-circulating material quotes that figure as current.
Three conditions matter and are routinely dropped from summaries. Monetary sanctions must aggregate at least ₹1 crore for any reward to be payable. Information must be submitted within three years of the first alleged violative trade. And persons legally obliged to report the violation, including compliance officers, are expressly ineligible. If you are designing a whistleblower programme for a compliance function, that last point is worth understanding before anyone forms expectations.
What the auditor reports about fraud and complaints
Paragraph 3(xi) of CARO 2020 requires the auditor to report: (a) whether any fraud by the company or any fraud on the company was noticed or reported during the year and, if so, its nature and the amount involved; (b) whether any report under section 143(12) was filed by the auditors with the Central Government in Form ADT-4 prescribed under Rule 13 of the Companies (Audit and Auditors) Rules 2014; and (c) whether the auditor considered any whistle-blower complaints received by the company during the year.
Two cautions. This reporting applies only where CARO 2020 applies to the company. And sub-clause (c) requires the auditor to consider whistle-blower complaints; it does not, by itself, require the auditor’s report to reproduce the complaints or their contents.
The third limb is still the one worth planning for. Whistleblower complaints received during the year are an input to the statutory audit. A company that receives complaints and cannot show what happened to them has a problem that is no longer internal.
Forensic investigation, and what binds it
A forensic engagement is not an audit with a different name. It is built to produce findings that survive challenge, which changes how evidence is handled, how interviews are conducted, and what the report can and cannot conclude.
ICAI has issued twenty Forensic Accounting and Investigation Standards, and its announcement of 27 July 2023 states they became mandatory for engagements conducted on or after 1 July 2023. The scope of that word matters, and omitting it is misleading: the standards bind members of ICAI performing forensic accounting and investigation engagements. They are a professional obligation arising from ICAI’s disciplinary framework. They are not statutory, they were not notified by the MCA, and they impose no obligation on companies or on non-member practitioners. ICAI’s accompanying Implementation Guide is expressly recommendatory and does not represent the official position of the Institute.
The practical point for a company commissioning an investigation is to know which standards the engagement is actually being conducted under, because that answer depends on who you appoint rather than on what the work is.
On the audit side, the auditor’s own responsibilities relating to fraud sit in ICAI’s Standard on Auditing on that subject. That is an obligation on the auditor, not on the company, and it is not a substitute for the company forming its own view of its fraud exposure.
Anti-bribery: the Indian corporate offence
Section 9 of the Prevention of Corruption Act 1988, inserted by the 2018 amendment with effect from 26 July 2018, makes it an offence for a commercial organisation where a person associated with it gives or promises an undue advantage to a public servant, intending to obtain or retain business or an advantage in the conduct of business for that organisation. It reaches bodies incorporated in or outside India carrying on business in India, and partnership firms formed in or outside India. An associated person is anyone who performs services for or on behalf of the organisation, in whatever capacity, which is wider than employment.
A defence is available where the organisation proves it had in place adequate procedures in compliance with such guidelines as may be prescribed. This is India’s closest analogue to the corporate failure-to-prevent offence under the UK Bribery Act.
The catch, and it is a significant one. As at 16 August 2026, the Central Government had not notified the guidelines contemplated by section 9(5). The defence exists in the statute, but its prescribed compliance benchmark remains unavailable. Organisations should nevertheless maintain proportionate anti-bribery controls: board level oversight, documented risk assessments, third party due diligence, approval controls, training, reporting channels, investigation procedures and periodic monitoring. International frameworks are useful reference points, but compliance with a foreign framework cannot be presented as automatically satisfying the Indian statutory defence.
Under section 10, where a section 9 offence is proved to have been committed with the consent or connivance of a director, manager, secretary or other officer, that person is punishable with imprisonment of not less than three years extending to seven years, and fine.
ISO 37001, anti-bribery management systems, is now in its second edition, ISO 37001:2025, published in February 2025, replacing the 2016 edition and its 2024 amendment. It is a requirements standard and is certifiable. It is a reasonable framework for building the kind of procedures section 9 contemplates, though certification against it is not a statutory defence.
Is a fraud risk assessment mandatory?
Indian company law does not impose a universal requirement on every company to conduct a separate exercise formally designated as a "fraud risk assessment". This does not mean fraud risks may be ignored. Depending on the company’s status and activities, its internal financial control, risk management, audit committee, vigil mechanism, internal audit, listing or sector specific obligations may require fraud risks to be identified, evaluated and addressed in substance.
What does exist, and is worth being precise about: the auditor’s own fraud risk assessment under ICAI’s auditing standards, which is an obligation on the auditor; the board’s risk management policy statement under section 134(3)(n), which is a disclosure obligation and is not fraud-specific; the Risk Management Committee’s mandate for specified listed entities under SEBI LODR, which covers financial, operational, sectoral, sustainability, information and cyber risk rather than fraud as such; the ICAI forensic standards, which bind ICAI members taking forensic engagements; and genuinely mandatory sector regimes.
That last category is real. The RBI directions on fraud risk management of 15 July 2024 require a board-approved fraud risk management policy, a special committee of the board for monitoring frauds, and an early warning signals framework. Those apply to commercial banks and All-India Financial Institutions, with parallel directions for non-banking financial companies and co-operative banks. If you are in one of those sectors, this is a mandate. If you are not, it is good practice being sold to you as one.
None of which is an argument against doing a fraud risk assessment. It is an argument for commissioning one because you have decided it is worth doing, on a scope you set, rather than because someone told you the law required it.
Send an enquiry
Tell us what is in front of you: a suspected fraud and a reporting clock you need to understand, a vigil mechanism that exists on paper, a whistleblower complaint nobody has decided how to handle, or a board that wants its fraud exposure assessed properly. A partner replies within one business day.
This page is general information, not professional advice. Indian corporate law positions, MCA rules and SEBI regulations change frequently, and how any of this applies depends on your company’s specific facts. Where a suspected fraud is involved, timing obligations can be very short. Take professional advice before acting on anything on this page. We are happy to be that adviser, but we do not act on a web page, ours or anyone else’s, without one.