Skip to main content
People Compliance / POSH

POSH Compliance: Culture and Control

Reviewed by CA Nikhil Gupta · Last reviewed 30 August 2026

Implement POSH through policy, Internal Committee, external member, awareness, confidential complaint handling, inquiry records, non-retaliation and annual reporting.

POSH compliance is not a poster or training certificate. Employees need a credible, independent and confidential redress process.

Quick View

Owner

Board, HR and Internal Committee

Cadence

Continuous, annual reporting

First control

Adopt a current POSH policy.

Core evidence

POSH policy.

Why It Matters

The 2013 POSH Act requires employers to provide a safe workplace and establishes an Internal Committee for workplaces meeting the statutory employee threshold. Smaller workplaces and certain complaints use the Local Committee route.

The committee’s composition, external member, tenure, training and independence matter. A committee formed only after a complaint undermines trust and process.

Complaints and inquiries require confidentiality, natural justice, timely steps, reasoned findings and protection against retaliation. Management should not pressure the committee to reach a preferred result.

Control Framework

ControlWhat it coversOperating rule
FrameworkPolicy and workplace scope are defined.Cover physical and virtual work.
CommitteeEligible members and external member are appointed.Train and replace vacancies promptly.
Complaint processAccess, confidentiality and timelines are clear.Preserve independence.
PreventionAwareness and leadership behaviour are monitored.Act on retaliation and culture risk.

Action Checklist

  1. Adopt a current POSH policy.
  2. Constitute and train the committee.
  3. Publish complaint channels.
  4. Run periodic awareness sessions.
  5. Maintain confidential case records.
  6. Complete required annual reporting.

Practical Example

A startup appoints three senior employees to the committee but no qualified external member. When a complaint arises, the committee’s validity and perceived independence are questioned.

Evidence to Keep

  • POSH policy.
  • Committee appointment orders.
  • External-member qualifications.
  • Training and awareness records.
  • Confidential complaint and inquiry file.
  • Annual report and employer action.

Warning Signs

  • Creating the committee after a complaint.
  • Letting HR investigate informally outside process.
  • Disclosing identities.
  • Retaliating against participants.
  • Treating remote work as outside workplace risk.

Management Decision

Board oversight should focus on whether the system is credible, staffed and free from retaliation—not on directing individual findings.

Use anonymised trend reporting to identify repeated locations, managers or behaviours while protecting statutory confidentiality.

Record the decision, owner, due date and evidence expected. A verbal explanation should become an approved working, board note, contract amendment, statutory filing or reconciliation before the item is treated as closed.

Rules, forms, thresholds and procedures can change. Use the latest official source and the actual company facts rather than copying a prior-year control or another entity’s legal position.

Exception Review

Classify every exception as a timing difference, data error, missing document, legal non-compliance, control-design gap or control-operating failure. This prevents management from treating fundamentally different problems as one ageing list.

The exception file should show amount or exposure, root cause, immediate correction, preventive action, owner and board-escalation threshold. Repeated low-value issues can become material when they reveal weak systems or management override.

Close the item only after the evidence agrees across source documents, books, portal data and management reporting. A screenshot or email promise is not equivalent to a completed filing, lender waiver, signed contract or reconciled ledger.

Board Escalation

The control should operate across the full transaction population, not only the samples management expects a reviewer to inspect. For this topic, the key stages are framework, committee, complaint process, prevention. Each stage should identify the source system, preparer, reviewer, deadline and evidence retained.

A useful management review asks whether the legal document, accounting entry, bank movement, tax treatment and public filing describe the same event. Differences may be valid, but they should be reconciled through a dated working rather than explained from memory during audit or diligence.

Materiality should determine escalation, not whether the company keeps a record. Repeated small exceptions can show weak master data, unclear authority, system bypass or management override. Root cause and preventive action should therefore be documented separately from the immediate correction.

Employment controls should balance legal process, confidentiality, dignity and operational security. The company should preserve a need-to-know record without circulating sensitive complaint, health or disciplinary information through ordinary email groups.

HR, payroll, IT, legal and the employee’s manager should use one controlled case or exit tracker. Separate spreadsheets often cause inconsistent dates, unrecovered assets, continued system access or incorrect statutory reporting.

Common Questions

When is an Internal Committee required?

The Act uses a workplace employee threshold; verify current facts and coverage.

Can HR be the committee?

HR may participate if eligible, but the statutory composition and external member must be satisfied.

Does POSH cover remote interaction?

Workplace concepts can extend beyond the office; assess work-related digital and travel contexts.

Can complaint details be shared with management?

Confidentiality rules limit disclosure; share only what the law and process require.

Official Sources

Use the latest official law, rule, portal instruction and executed company document before filing, issuing, remitting, recognising or taking a board position.

Disclaimer: This article is for educational and general information purposes. It is not legal, tax, audit, accounting, investment, employment, FEMA or regulatory advice. Applicability and outcomes depend on current law and the company’s facts.