Governance, risk and internal control
Filing on time and controlling well are two different disciplines. A company can have a clean compliance calendar and still have no reliable answer to the questions an audit committee actually asks: does this control operate, who tested it, what happens when the system that runs it goes down, and how would we know if someone inside were stealing. This part of our website is about that second question. It is written for the person accountable for whether the control environment works, not for the person accountable for the filings.
- Written for the audit committee, the CFO and the head of internal audit, not for the secretarial function
- Threshold-first: every guide starts by telling you whether the obligation reaches you at all
- Every regulatory claim checked against the notified instrument during this build, and reviewed by a qualified professional before it goes live
Assurance, not just adherence
We tell you when an obligation does not reach you
Most of what is written about Indian governance assumes every rule applies to every company. Statutory internal audit, the risk management committee and the vigil mechanism are all threshold-triggered. The first useful thing an adviser can do is tell you which side of the threshold you sit on.
We separate what is law from what is good practice
A professional body standard, an ISO standard and a notified rule are three different kinds of obligation binding three different people. Copy that runs them together reads authoritative and is useless for deciding what you actually have to do.
We say when something is not in force yet
India’s data protection regime is enacted, partly commenced, and carries penalties that cannot yet be levied. That distinction changes what you should be doing this quarter, so we state it rather than letting a headline number imply an immediate exposure.
Five guides, one control environment
Guides 1, 2, 3 and 5 are written for the audit committee, the CFO and the head of internal audit. Guide 4 addresses a different owner, usually a CIO, CISO or data protection lead, and is written so it can be read on its own. Start with whichever question is actually in front of you.
Governance Frameworks and Board Effectiveness
The architecture: audit committee thresholds, board and committee evaluation, secretarial standards, and the machinery that keeps a compliance framework current when the rules move.
Internal Financial Controls and Internal Audit
When statutory internal audit becomes compulsory, the two different internal financial controls obligations that routinely get blended into one, and what the auditor reports about your internal audit system.
Enterprise Risk Management and Business Continuity
What the board actually has to report on risk, the Risk Management Committee for listed entities, and what ISO 31000, ISO 22301 and COSO are (and are not).
Technology Risk, Cybersecurity and Data Protection
The CERT-In obligation that binds you today, the DPDP Act that is enacted but not yet fully in force, and the accounting software audit trail nobody talks about.
Fraud Risk, Forensic Audit and Whistleblower Mechanisms
The auditor’s statutory fraud reporting duty and the 2025 change to how that report is filed, the vigil mechanism, and what a forensic engagement is bound by.
What these pages do not cover
Two boundaries are worth stating, because they are where a reader is most likely to expect something that is deliberately not here.
Statutory filings and secretarial compliance. Incorporation, annual returns, board composition rules, related party transaction approval and the SEBI disclosure calendar are a separate discipline with a separate owner, and Exactitude International covers them separately. These pages assume those obligations are someone else’s brief and concentrate on whether the controls behind them work.
ESG reporting obligations. Who must file a Business Responsibility and Sustainability Report, and by when, is a reporting obligation covered elsewhere in our material. What appears in these guides is the narrower question of board level oversight of ESG risk (Guide 1) and independent assurance over non-financial data (Guide 2).
Send an enquiry
Tell us what is actually prompting the question: an audit committee asking for assurance it does not have, a control failure, a regulator, a customer security questionnaire, or a board that wants to know where it stands. A partner replies within one business day.
This page is general information, not professional advice. Indian corporate, data protection and securities law positions change frequently, and how any of this applies depends on your company’s specific facts. Take professional advice before acting on anything on this page. We are happy to be that adviser, but we do not act on a web page, ours or anyone else’s, without one.