Governance frameworks and board effectiveness
A governance framework is not a document. It is the arrangement that decides who is allowed to commit the company to what, who checks that it happened, and who hears about it when it did not. This guide covers the parts of that arrangement Indian law actually prescribes, the parts it only encourages, and the machinery that keeps the whole thing current when the rules change underneath you.
What a governance framework is for
Most governance frameworks fail in the same place. The policy exists, the delegation of authority exists, and neither reflects how decisions are actually taken. The test is not whether the document is comprehensive. It is whether someone who joined last month could work out, from the framework alone, who signs off a payment above a stated value, what happens if that person is unavailable, and who would find out if the limit were ignored.
Building one is mostly subtraction. A framework that names an owner for every risk, requires a committee for every decision and generates a report nobody reads is worse than a thin one, because it creates a documented standard the company is visibly not meeting. Where we are asked to design a framework, the first pass is usually removing controls that exist on paper and have never operated.
The audit committee: when it becomes compulsory
Under Rule 6 of the Companies (Meetings of Board and its Powers) Rules 2014, an audit committee is required of every listed public company, and of every public company with paid-up capital of ₹10 crore or more, or turnover of ₹100 crore or more, or aggregate outstanding loans, borrowings, debentures or deposits exceeding ₹50 crore. The figures are those existing on the date of the last audited financial statements. Note the entity class: Rule 6 was amended in May 2018 to read "every listed public company", so a listed entity that is not a public company is outside the listed limb, though it may still be caught by the capital, turnover or borrowings tests.
Section 177(2) requires the Audit Committee to comprise at least three directors, with independent directors forming a majority. A majority of its members, including the Chairperson, must be able to read and understand the financial statement.
Under section 177(4)(vii), the Audit Committee’s terms of reference include evaluating the company’s internal financial controls and risk management systems. That single line is the statutory hook for most of what Guides 2 and 3 describe: it is the committee, not the board as a whole, that owns the question of whether controls work.
For a listed entity, SEBI’s Listing Obligations and Disclosure Requirements Regulations impose a further, stricter layer on top of section 177. Note also that the corporate governance provisions in Regulations 17 to 27 do not apply to a listed entity whose paid-up equity share capital does not exceed ₹10 crore and whose net worth does not exceed ₹25 crore as on the last day of the previous financial year, nor to entities listed on the SME Exchange.
Board effectiveness, and the evaluation the Act asks for
The Board’s report of a listed company, and of every other public company with paid-up share capital of ₹25 crore or more at the end of the preceding financial year, must contain a statement indicating the manner in which formal annual evaluation of the performance of the Board, its committees and individual directors has been made. That is a disclosure obligation about the manner of evaluation. It does not prescribe a method, and there is no statutory template.
Schedule IV, the Code for Independent Directors, adds substance. Re-appointment of an independent director must be on the basis of a performance evaluation report. The separate meeting of independent directors must review the performance of non-independent directors and of the Board as a whole. And the performance evaluation of independent directors is done by the entire Board excluding the director being evaluated, with the outcome determining whether the term is extended.
For listed entities, under Regulations 25(3) and 25(4) of SEBI LODR, independent directors must hold at least one meeting each year without the presence of non-independent directors or members of management. At that meeting they must review the performance of non-independent directors and the Board as a whole, review the Chairperson’s performance after considering the views of executive and non-executive directors, and assess whether the quality, quantity and timeliness of information flowing between management and the Board enable the Board to perform its duties effectively and reasonably.
SEBI issued a Guidance Note on Board Evaluation on 5 January 2017. It is worth reading and it is explicitly guidance that entities "may adopt as considered appropriate", not a mandate. One caution if you use it: it reproduces the pre-amendment wording of both the Companies Act provision and Regulation 17(10), the latter having been substituted with effect from 1 April 2019. Quote the current instruments, not the Guidance Note’s recital of them.
Secretarial standards: the part that is genuinely mandatory
SS-1 (Meetings of the Board of Directors) and SS-2 (General Meetings), issued by the Institute of Company Secretaries of India, are mandatory. The revised versions took effect on 1 April 2024, following Central Government approval accorded by an MCA letter of 2 January 2024. SS-1 applies to board meetings of all companies incorporated under the Act, except a One Person Company with only one director. Section 8 companies are exempt, and the exemptions for section 8 and private companies apply only where the company has not defaulted in filing its financial statements or annual return.
SS-3 (Dividend) and SS-4 (Report of the Board of Directors) are recommendatory. They are frequently presented alongside SS-1 and SS-2 as though all four carried the same weight. They do not, and a board that treats SS-4 as binding is holding itself to a standard the Act does not impose.
Keeping the framework current
A governance framework decays quietly. Nothing announces that a rule has changed underneath a policy, and the failure surfaces at an audit, a diligence exercise or an incident, long after the change. Regulatory change management is the unglamorous half of this guide and, in our experience, the half that most often has no owner at all.
What it takes is narrower than it sounds: a defined list of the instruments that actually bind this company (not a generic watchlist), a named owner for each, a stated review frequency, and a route by which a change reaches the policy, the process and the person doing the work rather than stopping at a circular in an inbox. The test of whether it works is not whether updates are being received. It is whether anyone can show you a process that changed because of one.
Two live examples from these guides make the point. The procedure for reporting a suspected fraud to the Central Government changed in July 2025, and most published guidance still describes the repealed method (Guide 5). The transition deadline for the previous edition of the information security management standard passed on 31 October 2025, which invalidates certificates rather than merely dating them (Guide 4). Neither was announced in a way that would reach a policy owner who was not looking.
A compliance monitoring system is the same discipline pointed the other way: instead of asking what changed, it asks what is being complied with, on what evidence, and how often that evidence is actually looked at. Gap analysis and compliance audits are how you find out; the monitoring system is what stops you needing to find out again next year.
Capability, and the standards that bind the people doing the work
Training in this area works when it is specific to the obligation the person carries and fails when it is a general awareness session. A board needs to understand what it is being asked to conclude and on what evidence. A process owner needs to know which control is theirs and what breaking it causes. Those are different sessions.
On the professional standards behind internal audit work: ICAI’s Standards on Internal Audit are recommendatory as of August 2026. The revised Compendium of Standards on Internal Audit issued in February 2026 is stated by ICAI to be applicable from 1 April 2026. No publicly accessible ICAI notification specifying a mandatory effective date has been identified, so no such date is stated here.
On assurance over sustainability information: ICAI’s SSAE 3000, Assurance Engagements on Sustainability Information, is a final Standard and is mandatory for ICAI members undertaking assurance engagements within its scope for reports covering periods ending on or after 31 March 2024. SEBI does not prescribe SSAE 3000 as the mandatory standard for BRSR Core engagements, and its framework remains profession agnostic. ICAI’s proposed SSA 5000 and Framework for Sustainability Assurance Engagements, issued for public comment on 20 May 2026, remain exposure drafts as of August 2026.
Board level ESG oversight belongs here, in the governance framework, rather than in a reporting calendar. The board’s question is whether ESG risk is identified, owned and reported on the same footing as financial and operational risk. For listed entities that question is partly answered for you: the Risk Management Committee’s mandatory policy must expressly cover sustainability risk, which Guide 3 sets out.
Send an enquiry
Tell us where your governance framework stands: whether you have crossed a threshold and are not sure what it brought with it, whether a board evaluation is due, or whether nobody currently owns regulatory change. A partner replies within one business day.
This page is general information, not professional advice. Indian corporate law positions, MCA rules and SEBI regulations change frequently, and how any of this applies depends on your company’s specific facts. Take professional advice before acting on anything on this page. We are happy to be that adviser, but we do not act on a web page, ours or anyone else’s, without one.