The Annual Corporate Compliance Checkup: A Governance Health Check for Unlisted Private and Public Companies
Updated: 7 hours ago
1. Introduction
There is a comfortable assumption in many Indian unlisted companies: that if the annual filings are made and the auditor has signed, the company is compliant. It is a reasonable assumption. It is also, quite often, wrong.
The Companies Act, 2013 does not operate as an annual event. It operates continuously — transaction by transaction, meeting by meeting, disclosure by disclosure. Annual filings are the visible surface. Underneath sit obligations triggered not by the calendar but by what the company chose to do in a given month.
An Annual Corporate Compliance Checkup is a structured review of that underlying layer. It asks a different question from the one an audit asks: given everything this company did in the last twelve months, what did the law require, and can the company demonstrate that it complied?
For unlisted companies this has become more valuable, not less. Unlisted does not mean unwatched. Investors, acquirers, lenders, joint venture partners and — increasingly — the Registrar of Companies through a more data-driven MCA-21 system all read the same corporate records. The migration of filings to the MCA V3 platform, completed for the final set of forms in July 2025, has made the registry more structured and more capable of surfacing inconsistencies than at any point previously. Compliance has become more visible; a company's own visibility over it should keep pace.
2. Compliance Is More Than Annual Filing
It helps to separate compliance into layers, because organizations tend to be strong in one and weak in the rest.
Filing compliance — statutory forms and returns submitted within prescribed timelines. Measurable and visible, and therefore the layer most companies manage well.
Transactional compliance — the approvals, procedures and conditions attaching to a specific corporate action: an allotment, a loan to a group company, a related party contract, a guarantee, a change in management. Triggered by business decisions rather than dates, and the origin of most serious gaps.
Procedural compliance — how an action was carried out: notice, quorum, the type of resolution, interested-director rules, and the sequence of steps. A decision that is commercially sound and substantively permitted can still be defective because the process was wrong.
Governance compliance — whether meetings were genuinely deliberative, required directors and KMPs were in place, and committees that ought to exist were constituted and worked.
Documentation compliance — the ability to demonstrate all of the above through minutes, registers, resolutions, notices, disclosures, agreements, challans and approvals.
Ongoing regulatory compliance — obligations that continue after an action is completed: periodic reporting, maintenance requirements, and conditions attached to earlier approvals.
Completing MCA filings addresses the first layer thoroughly and the others only incidentally. A form is a summary; it reports outcomes, not process. AOC-4 does not test whether a related party transaction was approved correctly — it reports that one existed. That is why a company can hold a clean filing record and a substantial compliance gap simultaneously.
3. Why an Annual Corporate Compliance Checkup Matters
Business. Gaps convert into transaction friction. In fundraising, acquisition and bank borrowing, corporate records are examined by people paid to find problems. Unregistered charges, defective allotments, missing approvals and incomplete registers become conditions precedent, escrows, indemnities or delays. Deals rarely collapse over compliance gaps — but they routinely get slower and more expensive.
Governance. Weak records erode the Board's ability to govern and to demonstrate that it acted diligently.
Regulatory. Enforcement leans heavily on adjudication of penalties by the Registrar alongside inquiry and inspection powers. Defaults once quietly carried forward are more likely to be identified from registry data and pursued.
Financial. Delayed filings attract additional fees that accrue daily and compound across years and forms, and adjudicated penalties often apply to officers in default as well as the company.
Reputational. Filing status, charge registrations and director details are public. A record of chronic delay says something before any conversation begins.
Director-level. Disqualification consequences attach where a company has not filed its financial statements or annual returns for a continuous period of 3 (three) financial years — and the consequence follows the individual, affecting other directorships. Directors of dormant group entities are especially exposed, because nobody is watching those entities.
One point that surprises many promoters: several exemptions available to private companies under the MCA exemption notifications are conditional on the company not being in default in filing its financial statements or annual return, and the revised Secretarial Standards adopt a similar approach for certain exemptions. A filing default does not merely attract fees - it can withdraw relaxations the company has been relying on.
4. Scope of the Annual Compliance Checkup
Applicability of every item below must be determined on the company's own facts — private or public status, capital, turnover, borrowings, deposits, group structure, and the transactions actually undertaken.
4.1 Statutory registers and records. Check the registers of members and other security holders, directors and KMP, charges, contracts in which directors are interested, loans and investments, and investments not held in the company's own name. These are the first documents demanded in a dispute or a data room. Watch for registers never opened, unauthenticated, not updated for transfers, or inconsistent with the annual return.
4.2 Board meetings and processes. Check the number of meetings and the maximum permitted gap; notice, agenda and notes; quorum and interested-director rules; and minutes drafted, signed and entered within time. Frequency requirements are reduced for one person, small and dormant companies — and since the thresholds changed on 1 December 2025, classification should be verified, not assumed. Watch for minutes drafted months later, approvals recorded for matters never on the agenda, and matters requiring a meeting shown as passed by circulation. A defective meeting can taint everything approved at it.
4.3 General meetings and resolutions. Check that the AGM was held within the permitted period, with any Registrar extension where required; notice and explanatory statements; correct classification as ordinary or special resolution; and filing where required. Watch for shorter-notice consent not properly recorded and an ordinary resolution used where a special resolution was needed — if approval was not validly obtained, the underlying action is exposed.
4.4 Directors, KMP and disclosures. Check annual disclosures of interest at the first Board meeting of the year and on change; disqualification declarations; DIN status and KYC; directorship limits; independent directors for unlisted public companies meeting prescribed thresholds; and KMP appointments, including a whole-time Company Secretary where the rule is triggered. Watch for disclosures never refreshed after appointment, KMP appointments delayed years after the threshold was crossed, and DIN KYC lapses that block filings.
4.5 Related party transactions. Check identification of related parties and of transactions in the specified categories; Board approval at a meeting; prior member approval where thresholds are exceeded; the ordinary course and arm's length assessment; audit committee approval where required; disclosure in the Board's Report; and the register of interested contracts. The voting restriction on a related party member differs for private companies, and the audit committee requirement applies only to specified public companies. This is the most common source of substantive findings in unlisted companies, where inter-company dealings are routine and informal. Watch for transactions never identified as related party, approvals obtained after execution, arm's length asserted without analysis, and the auditor's note not matching what the Board approved. Exposure includes penalties, voidability in defined circumstances, and recovery from the person concerned.
4.6 Loans, investments, guarantees and securities. Check loans to directors and to entities in which directors are interested, and whether an exemption or approval route applies; inter-corporate loans, guarantees, securities and investments against applicable limits; and the statutory register. The analysis is fact-dependent - shareholding structure, borrowing levels and the purpose of the loan can each change the answer. Fix by testing every advance, guarantee and investment in the trial balance against the provision, not against how the entry was described.
4.7 Share capital, securities and dematerialization. Check allotments and the private placement sequence, including the separate bank account and the restriction on using subscription money before the return of allotment is filed; rights and bonus issues and stock options; share certificates issued within time; and transfers and transmissions recorded. On dematerialization, unlisted public companies have been covered since Rule 9A in 2018; private companies other than small, government and producer companies were brought in by Rule 9B, with the compliance date last extended to 30th June 2025 (producer companies to 31st March 2028). Rule 9B picks up several sub-rules of Rule 9A, bringing the half-yearly reconciliation of share capital audit report in Form PAS-6 into play for covered companies. A later reclassification as a small company does not automatically undo an obligation already triggered. Watch for the belief that the obligation ended once an ISIN was obtained.
4.8 Beneficial ownership and significant beneficial ownership. Check declarations where the registered holder is not the beneficial owner; identification of significant beneficial owners, declarations received, the register maintained and the return filed; and designation of a person responsible for furnishing information about beneficial interest. Watch for the assumption that this applies only to large or foreign-owned companies, undeclared nominee and trust arrangements, and an analysis never performed because ownership "is obvious".
4.9 Charges and borrowings. Check that every charge created or modified was registered within the permitted timeline, that satisfaction of repaid facilities was filed, and that Board borrowing powers were tested against the limits requiring shareholder approval. Registration has a strict timeline structure with escalating fees, and once the outer limit passes the remedy becomes a formal application. Watch for security created under sanction letters and never registered, and satisfied charges left open for years — very often the thing that blocks a later transaction.
4.10 Deposits and related restrictions. Check whether any amount received falls within the definition of a deposit or the exclusions, whether the conditions for acceptance from members are met, and the annual return relating to deposits and to amounts not treated as deposits. This is the classic trap, because unsecured loans from directors, relatives and group entities are commercially routine and legally sensitive. Watch for a missing declaration from a director on the source of funds lent.
4.11 Financial statements and Board's Report. Check the Board's Report content, including the directors' responsibility statement and disclosure of specified related party contracts; the annual return or its web link; valid auditor appointment intimated to the Registrar; and the accounting software audit trail requirement, on which the auditor also reports. Watch for a Board's Report reproduced from last year with only the numbers changed, and the audit trail disabled for part of the year.
4.12 Annual and event-based filings. Beyond annual filings, track those triggered by facts — returns of allotment, charge forms, changes in directors, specified resolutions, the deposit return, the half-yearly return on dues to micro and small enterprises, director KYC, beneficial ownership filings, CSR reporting, and the share capital reconciliation return. On the current position: the Companies Compliance Facilitation Scheme, 2026 - MCA General Circular No. 01/2026 dated 24 February 2026, extended by General Circular No. 03/2026 dated 8th July 2026 — remains in force until 31st August 2026, allowing eligible companies to complete pending annual filings at a reduced proportion of the additional fees otherwise payable, with immunity in defined circumstances and concessional routes to dormancy or strike-off.
4.13 Secretarial Standards. Check compliance with SS-1 and SS-2 in the revised versions effective from 1st April 2024 — notice content, agenda and notes, quorum, attendance, minutes content and timelines, and resolutions by circulation. Observance is a statutory requirement, not a best practice, and certain exemptions under the revised standards are conditional on the company not being in default in filing its financial statements or annual return.
4.14 CSR, internal audit, secretarial audit and cost records. Each is threshold-based and most commonly missed in the first year the threshold is crossed. CSR brings a policy, an annual action plan, spending obligations, treatment of unspent amounts and reporting, with relief from the committee requirement where the amount to be spent is below the prescribed level. Secretarial audit applies to public companies above prescribed capital or turnover thresholds and, separately, to companies with borrowings from banks or public financial institutions above the prescribed level — which is why some private companies are within scope. Fix by running one applicability test across all four as soon as the accounts are finalised.
4.15 Changes in law. What changed since last year, and does it apply to us? The small company thresholds were revised with effect from 1st December 2025 to paid-up capital of up to ₹10 crore and turnover of up to ₹100 crore, altering the classification of many private companies. Separately, the Corporate Laws (Amendment) Bill, 2026 was introduced in March 2026 and referred to a Joint Parliamentary Committee, which reported in August 2026. It proposes wide-ranging changes including further decriminalisation of procedural defaults, but it is not yet law. Track it; do not act as though it were in force.
5. Private Company vs Unlisted Public Company
Where unlisted public companies carry more. Independent directors where prescribed capital, turnover or borrowing thresholds are met; audit committee and nomination and remuneration committee requirements for specified public companies; KMP requirements framed by reference to public companies at prescribed capital levels; secretarial audit thresholds framed by capital and turnover; a longer-standing dematerialisation obligation; and restrictions on interested-director participation, on voting by related party members, and on kinds of share capital and further issue, all without the relaxations private companies enjoy.
Where private companies have relief — with conditions. The MCA exemption notifications relax several provisions. Two points are frequently missed: the relief is provision-specific rather than general, and its availability is conditional on the company not having defaulted in filing its financial statements or annual return. A private company that treats filings casually can lose relaxations it assumes it holds.
Where a private company is treated as public. A private company that is a subsidiary of a public company is treated as a public company for the purposes of the Act, even though its articles retain private company restrictions. This catches group structures regularly.
Where the label is irrelevant. Internal audit, secretarial audit by reference to borrowings, CSR, cost records, deposit rules, dematerialisation under Rule 9B, and the requirement for a whole-time Company Secretary in a private company above the prescribed capital level are determined by numbers, not by category.
The practical conclusion: a company's compliance profile should be re-derived from its current facts every year, not inherited from what it was at incorporation.
6. Board and Governance Review
This is where a checkup moves from technical verification to genuine governance assessment. Questions worth answering honestly:
Were meetings properly convened — correct notice period and mode, notice to every director, proper handling of shorter notice?
Were agenda and notes actually prepared? A meeting where directors receive no papers in advance meets the count requirement but delivers no governance.
Are minutes complete, timely and accurate — recording the substance of deliberation, dissent where expressed, and the basis of approvals, entered and signed within the prescribed time?
Were directors' disclosures obtained and updated, carried into the register of interested contracts, and used when transactions came to the Board?
Were interested-director requirements addressed? This depends on the company's category and the applicable exemption.
Did committees, where applicable, function — composition, meetings, minutes, and recommendations recorded before Board approval?
Did decisions requiring approvals receive them in the right order — Board first, then members where required, then execution?
Do governance practices match actual operations? If minutes describe a company managed by a full board while one promoter in fact decides everything, the records describe a company that does not exist — a governance problem before it is a compliance problem.
7. Transaction-Based Compliance Review
If a company can do only one part of this exercise properly, it should do this one — because filing processes fail rarely and visibly, while transactions fail frequently and silently.
A missed annual filing announces itself: the fee accrues, the registry shows the default, someone notices. A related party transaction executed without the approval it required announces nothing. It sits in the books, correctly accounted for, fully audited, and entirely non-compliant.
The transactions that most warrant annual review are related party dealings of every kind; loans, advances, guarantees and securities in both directions, including amounts described in the books as advances or current account balances; investments and subscriptions to group entities; borrowings, and whether every secured facility is reflected in a registered charge; share issuances and transfers, including private placements, transfers within promoter families, transmissions on death and gift or trust arrangements; contracts requiring specific approvals, including appointment of a director's relative to any office or place of profit; changes in management; charges created, modified or satisfied; and changes to the registered office, name, objects, articles or capital structure.
The method matters more than the list. Do not start from a checklist and ask "did we do this?" Start from the company's own records — trial balance, bank statements, the year's significant agreements, minutes, and the movement in shareholding — and ask of each item: what did this require?
8. Documentation and Evidence
There is a gap in most organisations between "we did comply" and "we can show we complied." In any external examination, only the second counts.
The test is simple: if a regulator, an acquirer's counsel or a lender asked today for the complete file supporting a corporate action taken eighteen months ago, could the company produce it without reconstruction? That file should hold the notice and agenda, the minutes, the certified resolution, the relevant disclosures, the executed instrument, the register entry, the form filed with its challan and SRN, and any consent obtained.
Three recurring failures: reconstruction after the fact, where minutes and resolutions are prepared months later — usually detectable, and disproportionately damaging to credibility on everything else; records that do not agree with each other, where the register of members, the annual return and the cap table shared with investors each say something different; and template dependence, where standard formats are used without adapting to actual facts, so minutes record deliberation that did not occur and resolutions recite a basis that does not match the provision relied upon.
The organising principle: maintain records as though they will be read by someone with an incentive to find fault. Periodically, they will be.
9. Common Red Flags
These should trigger a deeper review rather than a routine one:
Repeated filing delays, even small ones — a process problem, not an isolated lapse.
Missing or incomplete minutes, particularly for periods with significant transactions.
Statutory registers that are outdated, unopened or unauthenticated.
Related party arrangements with no written agreement or executed after the transaction began.
Directors' disclosures not refreshed annually or absent from the interested contracts register.
Shareholding changes not properly recorded in the register of members.
Unrecorded or unclassified loans and advances, especially long-standing inter-group balances.
Charges not registered, or satisfied charges never closed on the registry.
Corporate actions implemented before the required approval was obtained.
Differences between statutory and financial records — the related party note against Board approvals, borrowings against registered charges, share capital against the register of members.
Templates used without regard to the company's actual facts.
A compliance calendar that tracks only filing dates - the clearest sign that transactional compliance has no owner.
Two further signals: dormant group entities that nobody reviews, and the year in which audited numbers first cross a threshold.
10. Annual Compliance Checkup — A Practical Approach
Collect statutory and corporate records — minutes books, registers, resolutions, filed forms with challans, disclosures, agreements, audited financial statements, and current master data from the MCA portal.
Map applicable law. Determine status — private or public, subsidiary of a public company, whether it qualifies as a small company for the relevant period — and test each threshold-based obligation against audited figures.
Review Board and shareholder actions against both the Act and the Secretarial Standards.
Review transactions, working from the financial statements and the year's significant agreements.
Reconcile statutory records against financial records, the registry position against internal records, the register of members against the annual return, the register of charges against secured borrowings, and the related party note against approvals.
Check registers and documentation for completeness, authentication, and a full supporting file for each significant action.
Identify gaps specifically — what was required, what was done, and the period involved.
Classify by severity. Critical — immediate remediation, formal application or disclosure. Significant — rectifiable within the year. Procedural — corrected by improved practice going forward.
Prepare a corrective action plan — each gap with an owner, a remediation method, a target date, and an estimate of cost or approval required.
Monitor closure, reporting status to the Board until closed. A gap identified and left open is, in some respects, worse than one never identified.
The natural time to run this is after the accounts are finalised and before the AGM — audited numbers are available for threshold testing, and there is still time to place corrective items before the members.
11. My Honest Viewpoint
28 plus years of experience teaches you to watch for patterns rather than incidents. Five observations, offered as professional judgement rather than as law.
Companies discover compliance gaps at the worst possible moment, and it is not an accident. Gaps surface during audit, due diligence, fundraising, borrowing, restructuring, a sale, or regulatory scrutiny — because these are the only occasions on which someone systematically examines the corporate records with an incentive to find problems. Nothing internal generates that examination: the finance team is examined by the auditor, the auditor examines the accounts, and nobody examines the corporate compliance position unless asked. So a company's first honest assessment of itself arrives from a counterparty, at a moment when it has neither time nor leverage. An annual checkup simply means having that conversation with yourself first.
A compliance review must be risk-based, or it becomes busy work. A mechanical checklist verifies the obvious thoroughly and misses the specific entirely. It will confirm the AGM was held and the forms filed — and will not ask whether the guarantee given to a group company in the third quarter required an approval never obtained, because a guarantee was not on the checklist. Risk-based means allocating attention in proportion to consequence, and in unlisted companies the risk concentrates in a few places: related party dealings, inter-group funding, security creation, changes in shareholding, and threshold crossings.
The Company Secretary is a governance function, not a filing function. I say this as an observation about how organisations extract value, not as advocacy for the profession. Engaged only at the point of filing, the function reports decisions after they are taken. It is most valuable earlier — when a transaction is being structured and the question "what will this require?" can still change the sequence. Companies that place it inside the decision process tend to have fewer gaps, and the gaps they do have tend to be procedural rather than substantive.
Directors need visibility over compliance risk, not just compliance status. Boards routinely receive a filing status report; very few receive a compliance risk report. The first says what has been submitted; the second says where the company is exposed, how serious each exposure is, what remediation would cost, and what happens if nothing is done. Directors carry personal consequences and are entitled — I would say obliged — to ask for the second document. A short annual compliance risk report, with gaps classified by severity and a corrective plan attached, is among the highest-value governance practices an unlisted company can adopt, and among the least expensive.
Historical gaps do not age well. On discovering an old lapse, the instinct is often to leave it alone, on the reasoning that raising it invites attention. In practice the opposite tends to be true. Gaps compound: an unregistered charge becomes harder to address as the outer limits recede, a defective allotment affects every capital action built on top of it, and an unaddressed filing default can withdraw exemptions relied on for years and eventually reach director disqualification. Remediation is also easier when the company initiates it. Where a facilitation window is open — as one currently is, until 31st August 2026 — the economics shift in the company's favour for a limited period. Eligibility must be checked on facts, but the principle holds regardless of any particular scheme: the best time to fix a historical gap is now, and it will never be cheaper than today.
12. Key Takeaways
For promoters
Ownership of a company is not authority to act for it. Group transactions, funding arrangements and shareholding changes that feel internal are corporate actions with procedural requirements — and informality is where exposure begins.
Every entity in the group deserves the same attention as the operating company. Dormant and holding entities are where defaults accumulate unnoticed.
For directors
Ask for a compliance risk report, not only a compliance status report — gaps classified by severity, with owners and a corrective plan.
Understand your personal exposure. Disqualification consequences follow sustained default in filing financial statements or annual returns, and follow the individual across other directorships.
Refresh your disclosures of interest at the first Board meeting of each year and on every change, and ensure they are used when transactions come to the Board.
For KMPs and Company Secretaries
Fix the annual checkup in the calendar — after the accounts are finalised and before the AGM, when audited figures are available for threshold testing.
Run the review from the company's transactions upward, not from a generic checklist downward.
Re-derive the applicability map every year. Last year's map is not evidence of this year's position.
Treat documentation as part of executing a transaction, not as follow-up work. A file assembled at the time beats a perfect memory of the decision.
Do not let a discovered gap sit. Classify it, plan the remediation, assign it, and report closure to the Board. Where a facilitation window applies, assess it before it closes.
For CFOs and finance teams
Reconcile statutory records to the financial statements annually — related party disclosures against Board approvals, secured borrowings against registered charges, share capital against the register of members.
Extract and classify every borrowing, advance, guarantee and investment explicitly each year, not by how the entry was described in the books.
13. Conclusion
An Annual Corporate Compliance Checkup is not another item on the compliance calendar. It is the exercise that tells you whether the rest of the calendar is describing reality.
The distinction worth holding on to: filings tell you what a company reported; a compliance checkup tells you what a company did. For most unlisted companies the difference between those two accounts is small. But it is almost never zero — and its size is not knowable until someone looks.
A company that examines itself once a year, honestly and methodically, finds its gaps while they are small, cheap and curable. A company that does not will find them anyway — during a fundraise, a lender's review, an acquisition, or a notice from the Registrar — at a moment chosen by someone else.
The regulatory environment is not becoming more forgiving. It is becoming more visible: a more structured registry, more connected data, deeper disclosure requirements, and consequences that reach individuals more directly. At the same time, the framework is making room for correction. Both point to the same conclusion. Compliance is not a filing obligation to be discharged. It is a governance position to be maintained. And like any position worth maintaining, it needs to be checked — deliberately, annually, and by someone whose job it is to look.
Treat it as a health check. The value of a health check is not that it makes you healthy. It is that it tells you the truth early enough to do something about it.
Comments