A functioning whistle-blower mechanism isn't just a policy document sitting on a company website — SEBI and the Companies Act both require a real, operational escalation path that lets an employee bypass their own management chain and reach the audit committee directly in serious cases.
The dual legal basis
The requirement to maintain a whistle-blower/vigil mechanism comes from two overlapping sources:
- Section 177 of the Companies Act, 2013 — requires listed companies and certain prescribed classes of companies to establish a vigil mechanism for directors and employees to report genuine concerns.
- Regulation 22 of SEBI's LODR Regulations — separately mandates a whistle-blower policy for listed entities, with specific requirements around the mechanism's accessibility and the protections it must provide.
What the mechanism must actually provide
- A channel for directors and employees to report genuine concerns — commonly covering suspected fraud, financial irregularities, unethical conduct, or violation of the company's code of conduct.
- Direct access to the chairperson of the audit committee in appropriate or exceptional cases — this is the key structural requirement: the mechanism cannot simply route every complaint through the normal management hierarchy, since that would defeat the purpose where the concern involves management misconduct itself.
- Protection against victimisation of the person raising the concern.
- Provisions dealing with false or malicious complaints, to guard against misuse of the mechanism.
⚠ "Having a policy" and "having a working mechanism" are different compliance questions: SEBI and auditors increasingly scrutinise not just whether a whistle-blower policy document exists, but whether it has actually been used, how complaints (if any) were handled, and whether the audit committee has genuine visibility into whistle-blower matters as part of its regular oversight — a policy that exists only on paper, with no actual reporting activity or audit committee engagement, is a weaker compliance position than it might appear from the document alone.
Why the audit committee — not the board generally, or HR — is the anchor
The audit committee is specifically designated as the escalation point because it is (by design under both the Companies Act and LODR) composed predominantly of independent directors, giving it a structural independence from day-to-day management that makes it the appropriate body to receive concerns that might implicate management itself — routing whistle-blower complaints through HR or general management would not provide the same independence where the complaint concerns those very functions.
Disclosure obligations
Companies are required to disclose, as part of their corporate governance report, whether the vigil mechanism is in place and whether any personnel have been denied access to the audit committee — this disclosure requirement is itself a compliance check, since a company reporting "no complaints ever received" over many years alongside significant scale and complexity can itself become a point of scrutiny about whether the mechanism is genuinely accessible and trusted by employees.
Interaction with SEBI's broader complaint/informant mechanisms
Separately from the company's internal vigil mechanism, SEBI itself operates an Informant Mechanism under its insider trading regulations, allowing individuals to report suspected securities law violations (particularly insider trading) directly to SEBI, with confidentiality protections and, in some cases, monetary rewards for information leading to enforcement action — this is a distinct, external channel from the company's own internal vigil mechanism, and the two are not mutually exclusive.
Frequently Asked Questions
Is a vigil mechanism mandatory for every company, or only listed ones? ▼
The Companies Act requirement extends to listed companies and certain other prescribed classes of companies (based on criteria like public deposits accepted or loans/borrowings from banks and financial institutions above specified thresholds) — it is not universal to every private company, but does extend somewhat beyond just listed entities.
Can a whistle-blower remain anonymous under the mechanism? ▼
Most company vigil mechanisms are designed to accommodate anonymous or confidential reporting to some degree, though the specific confidentiality protections and how effectively anonymity can be maintained through any investigation depends on the company's specific policy design — this is worth checking in the specific company's published whistle-blower policy rather than assumed to be uniform across all companies.
What recourse does an employee have if they are victimised after raising a genuine concern? ▼
The vigil mechanism itself is required to include protection against victimisation, and the audit committee has oversight responsibility for ensuring this protection is honoured — beyond the internal mechanism, an employee facing retaliation may also have separate recourse under general employment law and, in serious cases, could report the matter to SEBI or other relevant authorities depending on the nature of the underlying concern.