POSH Act Compliance in India: The Complete Guide for Employees, Employers, ICC Members & Boards (2026 Edition)

Editorial illustration showing a woman standing calmly as her shadow forms a thorn-covered babul tree — symbolizing POSH Act as protection against workplace sexual harassment in India 2026
Table Of Contents
  1. Part I. Understanding the POSH Act
  2. Part II. Building a Legally Compliant POSH Framework (For Employers & HR)
  3. Part III. Internal Committee (ICC)
  4. Part IV. Employees' Guide to the POSH Act
  5. Part V. Global Workplace Compliance
  6. Part VI. Test Your Compliance
  7. Part VII. Advanced POSH Governance for Boards & CHROs
  8. Part VIII. Additional Resources

Part I. Understanding the POSH Act

1. Introduction

🎯 What Job Are You Hiring This Guide For?

👥 Who Should Read This?

2. Case Study: The TCS Nashik Case: When POSH Compliance Exists on Paper But Fails in Practice (2026)

3. History & Legal Evolution

4. Recent Government Action Under POSH Act: 2026 Enforcement Reality

Penalties for Non-Filing or Inaccurate Filing

  • First offence: fine up to ₹50,000
  • Repeat non-compliance: enhanced fines, and in serious/persistent cases, cancellation or withdrawal of business licence
  • Separately, false or misleading POSH statements in a Board’s Report can attract distinct penalties on the company and its directors under the Companies Act framework

These are the filing mistakes I see organisations make most often, especially during their first compliance cycle. 

  • Filing only the Section 21 report and overlooking the separate Section 22/Board’s Report disclosure obligation
  • Under-reporting because complaints were “resolved informally” and never entered the formal register every complaint the ICC formally receives must be reflected, regardless of how it was ultimately resolved
  • Submitting to the wrong authority because the correct District Officer for a given establishment was never confirmed
  • Waiting until the deadline week to reconcile ICC records, training logs, and case data accuracy issues surface exactly when there’s no time left to correct them
  • Assuming a zero-complaint year means no filing obligation

For several years after the enactment of the POSH Act, enforcement largely depended on self-certification by employers, with limited oversight by authorities. The recent judicial interventions and coordinated government action, however, mark a structural shift in how POSH compliance is monitored and enforced in India. From my perspective, 2026 marks a noticeable shift in how POSH compliance is being treated. It’s no longer just an internal HR responsibility; it’s increasingly becoming a governance and regulatory issue. 

Risk LevelNon-Compliance ExampleConsequence
🔴 CriticalNo ICC₹50,000 fine + licence risk
🔴 CriticalICC expired tenureInquiry invalid
🟠 HighNo trainingAudit remark
🟡 ModerateImproper displayTechnical violation

A. Government Audits and District-Wise Verification

Pursuant to the Supreme Court’s directions in Aureliano Fernandes v. State of Goa

Held: Labour departments across States and Union Territories have been instructed to carry out district-wise surveys and physical verification of establishments. These audits focus on:

  • whether an Internal Complaints Committee (ICC) has been constituted,
  • whether the composition of the ICC meets statutory requirements,
  • whether the committee is functional rather than merely existing on paper, and
  • whether employers are maintaining records, reports, and awareness measures under the Act.

Impact: Triggered district-wise compliance audits across India.

Unlike earlier compliance checks, these surveys are time-bound, documented, and reported through a structured administrative hierarchy, from District Labour Officers to State Chief Secretaries. This ensures that lapses are identified systematically, rather than only when individual complaints arise. Importantly, this audit mechanism transforms POSH compliance into a verifiable regulatory condition, similar to labour law inspections.

B. Elevation of POSH to Board-Level Governance

Another significant enforcement development is the movement of POSH compliance into the corporate governance framework. Companies are now required to make specific disclosures in their Board’s Report, including:

  • confirmation of ICC constitution,
  • number of sexual harassment complaints received during the year,
  • number of complaints disposed of, and
  • cases pending beyond statutory timelines.

By mandating disclosure at the board level, responsibility shifts from HR managers to directors and senior leadership, increasing accountability. False, incomplete, or misleading disclosures may expose companies to regulatory action, shareholder scrutiny, and governance risks. This integration also aligns POSH compliance with ESG and transparency norms, where workplace safety and inclusivity are increasingly assessed by investors and regulators.

For leadership teams facing POSH Board’s Report disclosure for the first time, a focused governance briefing can clarify what needs to be disclosed, what records to maintain, and what constitutes adequate compliance at the board level. Book a call with us for Board & Leadership POSH Briefing & Training. 

C. Consequences of Non-Compliance: Legal, Financial, and Reputational

The enforcement framework is supported by clear statutory penalties under Section 26 of the POSH Act. Employers who fail to constitute an ICC, violate procedural requirements, or disregard statutory duties may face:

  • monetary penalties up to ₹50,000 for initial non-compliance,
  • enhanced penalties for repeat violations, and
  • cancellation or non-renewal of licences, registrations, or approvals required to operate the establishment.

Beyond statutory fines, the consequences increasingly extend to reputational damage, particularly where non-compliance is recorded in government databases, board reports, or judicial proceedings. For corporations, adverse disclosures can impact brand value, employee trust, investor confidence, and ESG ratings. For smaller establishments, regulatory action may directly threaten business continuity.

5. It’s time to bust some myths on POSH Act

  • If you believe POSH applies only to large organisations, you are already non-compliant. The law applies to every workplace, regardless of size, sector, or structure, and failure to activate the correct mechanism exposes you to statutory penalties.
  • If your organisation has an anti-harassment policy but has not constituted a valid Internal Complaints Committee, you are exposed to enforcement action. A policy without a functioning ICC is treated as cosmetic compliance.
  • If POSH training was conducted once during onboarding and never repeated, you are violating a continuing statutory duty. The law requires periodic sensitisation and regular ICC orientation, not one-time awareness.
  • If you think only permanent employees are protected, you are excluding legally covered persons. The POSH Act protects contract workers, interns, trainees, volunteers, visitors, clients, and domestic workers.
  • If you believe sexual harassment must involve physical contact, you are ignoring the most frequently prosecuted violations. Digital messages, remarks, gestures, threats, and hostile environments fall squarely within the law.
  • If you assume work-from-home or virtual interactions fall outside POSH, you are operating under a legally outdated assumption. Emails, video calls, messaging platforms, and online meetings are recognised as workplaces when connected to employment.
  • If complaints in your organisation are handled informally by HR without routing them to the ICC, you are bypassing a mandatory statutory process and risking invalidation of the entire inquiry.
  • If you rely on anonymous complaints as formal POSH cases, you are misunderstanding procedural law. The Act mandates written complaints, and anonymous reports do not trigger statutory inquiry obligations.
  • If you believe complaints can only be made against men, you are misreading the law. An aggrieved woman may file a complaint against any person, regardless of gender.
  • If you are an MNC relying solely on global harassment policies, you are exposed to Indian regulatory action. Indian operations must independently comply with Indian POSH law, including ICC constitution.
  • If you think HR professionals cannot be ICC members, you are unnecessarily limiting your compliance options. The law permits HR members, subject to statutory composition safeguards.
  • If your ICC members have continued beyond three years without re-nomination, your committee itself may be invalid. Tenure limits are mandatory, not advisory.
  • If conciliation is treated as a default or forced option, you are violating the complainant’s statutory rights. Conciliation is optional, complainant-initiated, and cannot involve monetary settlement.
  • If ICC recommendations are treated as advisory or discretionary, you are in direct violation of the Act. Employers must implement them within 60 days.
  • If your organisation skipped the annual POSH report because no complaints were filed, you are in reporting default. Annual reporting is mandatory irrespective of complaint volume.
  • If you assume non-compliance only results in small fines, you are underestimating the risk. Penalties include financial sanctions, licence cancellation, regulatory scrutiny, and reputational damage.
  • If POSH compliance is viewed merely as a legal checkbox, you are missing its governance and cultural implications. Non-compliance increasingly affects employee trust, brand value, and ESG assessment.

Part II. Building a Legally Compliant POSH Framework (For Employers & HR)

6. Is your organisation legally safe in 2026? Detailed POSH Act Breakdown

1. What is the POSH Act, 2013?

Under Section 2(n) of the POSH Act, 2013, sexual harassment includes any one or more of the following unwelcome acts or behaviour (whether directly or by implication):

  • Physical contact and advances
  • A demand or request for sexual favours
  • Making sexually coloured remarks
  • Showing pornography
  • Any other unwelcome physical, verbal, or non-verbal conduct of a sexual nature

The key element is that the conduct must be unwelcome, making the woman feel uncomfortable, intimidated, or violated in the workplace.

  • Implied/explicit promise of preferential treatment in exchange
  • Implied/explicit threat of detrimental treatment
  • Implied/explicit threat about present or future employment status
  • Interference with work or creating intimidating/hostile/offensive environment
  • Humiliating treatment likely to affect health or safety

2. Who is covered under the POSH Act?

Domestic worker means a woman engaged in household work in any household for remuneration in cash or kind, whether employed directly or through an agency, on a temporary, permanent, part-time, or full-time basis. It excludes family members of the employer.

Employee means any person working at a workplace on a regular, temporary, ad hoc, or daily wage basis, whether employed directly or through an agent or contractor, with or without remuneration, and with or without the knowledge of the principal employer. It includes co-workers, contract workers, probationers, trainees, apprentices, freelancers, gig workers or any person working under express or implied terms of employment.

Need a workplace policy that protects everyone?
While the POSH Act provides legal protection specifically to aggrieved women, many organisations choose to adopt an additional Gender-Neutral Workplace Harassment Policy to extend internal protection to male employees, LGBTQIA+ employees, and other individuals not covered under the statutory POSH framework. We help organisations draft legally aligned Male & LGBTQIA+ Inclusion Policy Add-ons that complement their POSH Policy without conflicting with the Act. 

3. What is a workplace?

  • Any government, public sector, or government-funded department, organisation, office, branch, unit, or enterprise.
  • Any private sector organisation, including companies, NGOs, trusts, societies, institutions, and service providers engaged in commercial, professional, educational, industrial, health, financial, or other activities.
  • Hospitals and nursing homes.
  • Sports institutes, stadiums, complexes, and venues, whether residential or non-residential.
  • Any place visited by an employee in the course of employment, including employer-provided transportation.
  • A dwelling place or house.
  • Virtual spaces

The “unorganised sector” refers to enterprises owned by individuals or self-employed workers engaged in goods or services, employing fewer than ten workers, if any.

4. Timelines for Inquiry and Reporting

A. Filing of Complaint

  • An aggrieved woman must file a written complaint of sexual harassment with the Internal Complaints Committee (ICC) or Local Complaints Committee (LCC) within three months from the date of the incident.
  • In cases involving a series of incidents, the complaint must be filed within three months from the date of the last incident.
  • The ICC/LCC may extend the filing period by an additional three months if it records reasons in writing and is satisfied that circumstances prevented timely filing.
  • If the woman is unable to submit the complaint in writing, the Committee is legally required to assist her in reducing it to writing.

Conciliation under the POSH Act requires a neutral, experienced facilitator. This is typically handled by the External ICC Member or an appointed specialist. If your organisation is navigating an active case, case management support is available. 

B. Conciliation (Optional Pre-Inquiry Stage)

  • Before initiating a formal inquiry, the ICC/LCC may attempt conciliation only at the request of the aggrieved woman.
  • Monetary settlement is expressly prohibited as a basis of conciliation.
  • The POSH Act permits conciliation only before an inquiry begins, and monetary settlement cannot form its basis. Organisations should not assume that a private settlement agreement or NDA can replace the statutory inquiry process or override the confidentiality obligations under Section 16. Any settlement documentation should be reviewed carefully to ensure it remains consistent with the requirements of the Act. 
  • If a settlement is reached:
    • The terms must be recorded in writing,
    • Copies must be given to both parties, and
    • The employer must implement the settlement.
  • Upon reaching a settlement, the ICC or LCC is required to record the agreed terms and forward a copy of the settlement to the employer or the District Officer, as applicable, for implementation. Copies must also be provided to both the aggrieved woman and the respondent. Once a settlement is recorded under Section 10, no further inquiry is conducted into that complaint. 

Legislative update: The Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Amendment Bill, 2024, currently pending in Parliament, proposes to remove the conciliation provision entirely. Until enacted, Section 10 remains operative law. 

C. Commencement and Completion of Inquiry

  • If conciliation is not requested or fails, the ICC/LCC must initiate a formal inquiry.
  • The inquiry must be conducted in accordance with:
    • applicable service rules, or
    • prescribed procedure under the Act where service rules do not exist.
  • The inquiry must be completed within 90 days from the date the complaint is received.
  • Both parties must be:
    • given an opportunity to be heard, and
    • provided access to the findings of the Committee.

D. Interim Relief During Inquiry

  • During the pendency of the inquiry, the ICC/LCC may recommend interim relief at the written request of the aggrieved woman, including:
    • transfer of either party,
    • grant of leave up to three months (in addition to regular leave), or
    • any other relief as prescribed.
  • The employer is required to implement these recommendations immediately and report compliance to the Committee.

E. Submission of Inquiry Report

  • Upon completion of the inquiry, the ICC/LCC must prepare a reasoned inquiry report.
  • The report must be submitted to the employer or District Officer within 10 days of completion of the inquiry.
  • Copies of the report must be provided to both the aggrieved woman and the respondent.

F. Action on Inquiry Report

  • Where allegations are not proved, the Committee recommends no action.
  • Where allegations are proved, the Committee may recommend:
    • disciplinary action as per service rules, and/or
    • monetary compensation to the aggrieved woman.
  • The employer or District Officer must act on the recommendations within 60 days of receiving the inquiry report.

G. Appeal

  • Any person aggrieved by:
    • the inquiry findings,
    • the recommendations, or
    • non-implementation of recommendations,
  • may file an appeal within 90 days in accordance with applicable service rules or prescribed procedure.

5. Who is employer?

  • In government departments, public sector bodies, or local authorities, the head of the department or unit, or any officer specifically authorised by the appropriate government.
  • In private sector workplaces, any person responsible for the management, supervision, and control of the workplace, including those involved in policy formulation and administration.
  • In workplaces covered above, the person who discharges contractual obligations towards employees.
  • In a dwelling place or household, any person or household that employs or benefits from the services of a domestic worker, regardless of the number, duration, or nature of such employment.

6. Employer duties under section 19

  • Ensure a workplace that is safe for women, including protection from persons coming into contact at the workplace.
  • Display at conspicuous places:
    • The penal consequences of sexual harassment, and
    • The order constituting the Internal Complaints Committee (ICC).
  • Conduct awareness and training programmes
    • Organise regular workshops and awareness programmes for employees on POSH provisions.
    • Conduct orientation programmes for ICC members as prescribed.
  • Make available all necessary facilities to the Internal Committee or Local Committee for:
    • handling complaints, and
    • conducting inquiries.
  • Help secure the attendance of the respondent and witnesses before the ICC/LCC.
  • Make available any information, documents, or records required by the ICC/LCC in relation to the complaint.
  • Provide assistance to the aggrieved woman if she chooses to file a complaint under the Indian Penal Code or any other applicable law.
  • Where the respondent is not an employee, initiate action under criminal law at the workplace where the incident occurred, if the aggrieved woman so desires.
  • Treat sexual harassment as a misconduct under service rules and initiate disciplinary action accordingly.
  • Ensure timely submission of reports by the Internal Complaints Committee.

If you’re reviewing this list and identifying gaps in your current compliance framework, a structured POSH policy implementation or existing policy audit we can help you close them systematically before an inspection does it for you. 

7. How to set up POSH in your organisation

I believe most failed rollouts happen because organisations build these layers out of order, usually policy first, training last, when it should be the reverse.

The Five Layers of Implementation (in sequence, not in parallel)

Layer 1: Statutory Foundation

  • Confirm applicability (10+ employees at any single establishment, not org-wide headcount) and identify every establishment that needs its own ICC.
  • Constitute the ICC per Section 4: Presiding Officer (senior woman employee), minimum 2 internal members “committed to the cause of women” or with legal/social work background, 1 external member from an NGO or someone familiar with sexual harassment issues, minimum 50% women.

Book a call with us for ICC Constitution & Setup 

  • Issue a formal constitution order, not an email announcement. This document is what a District Officer or court asks for first; an ICC that exists only informally cannot conduct a legally valid inquiry.

Layer 2: Policy Drafting

If I need to draft a good policy it needs to clearly answer these questions, in plain language that every employee can understand:

Where does this policy apply? 
It covers remote work, client visits, offsite events, work travel, and even online interactions like official WhatsApp groups or video calls, not just the physical office.One mistake I frequently see is organisations drafting policies that only refer to the physical office. Courts have consistently interpreted “workplace” much more broadly than that.

Who is covered? 
Not just full-time employees, interns, consultants, contract staff, gig workers, and even vendor staff who come to your premises. This is another gap I regularly notice. Many policies simply use the word “employee” without clearly explaining that interns, consultants, contractors, gig workers, and vendor staff are also covered.

How does conciliation actually work?
Conciliation just means the complainant can choose to settle informally, but only if they ask for it themselves. HR or the ICC cannot suggest it, push for it, or involve any money in it. If your policy makes conciliation sound like a step HR offers or recommends, that’s already a mistake.

What relief can someone get while the inquiry is still going on? 
For example, temporary transfer of either person, extra leave, or other support given only when the complainant asks for it in writing, not decided by the ICC on its own.

How is confidentiality protected, and what happens if it’s broken? 
The law says nobody’s identity can be revealed, and breaking this rule has a real penalty attached. Spell out who this rule applies to (ICC members, the employer, witnesses) and what counts as “revealing” something, even casually discussing a case with a senior leader who isn’t on the ICC counts as a breach.

What protection does someone get for speaking up? 
No one can be punished, demoted, or treated badly for filing a complaint or being a witness. In practice, this “retaliation” issue is often what actually ends up in legal trouble, more than the original complaint itself.

What happens if the person accused is a senior, even a founder or a CXO? 
In my experience, this is one of the least discussed parts of POSH policy drafting. Many organisations never think about what happens if the respondent is a founder or CXO until an actual complaint forces that conversation, the whole process can get stuck the moment a real complaint against leadership comes in, simply because nobody knows who has the authority to act. Add in your policy that there’s no seniority exemption in law. The real risk is conflict of interest, so the policy must state upfront that such a person is excluded from managing their own case, with the external member (or board/District Officer) taking over instead. 

And much more…!

Download the complete POSH Policy Template 

Layer 3: Get Your Basic Systems Ready

This is simply about having the right paperwork and systems ready before you actually need them:

  • A simple way to store and track cases – At a small company, a well-organised, access-restricted folder with a case numbering system is enough. Bigger organisations should move to a proper case-tracking tool with controlled access. The reason this matters: when a court or auditor asks “show me your records,” a messy or missing paper trail is the first red flag they look for.

Implement Complaint Register SaaS / Digital Ticketing Tool now, book a call with us

  • Ready-made templates, prepared in advance – You don’t want to be drafting these for the first time after a complaint has already landed; that’s exactly when things get rushed, and mistakes happen. Keep these templates ready: a complaint acknowledgement letter, a notice to the accused person, a witness invitation letter, a form for requesting interim relief, an inquiry report, etc. Having these ready in advance also protects your 90-day legal deadline for completing an inquiry. From what I’ve seen, most delays happen because the law isn’t complicated. They fail because organisations start preparing documents only after receiving a complaint and drafting a document for the first time under pressure you should not be doing.

Get our ready-to-use POSH Inquiry Documentation Toolkit, containing legally structured templates designed to help your ICC respond quickly, consistently, and compliantly. 

  • SHe-Box registration and appointing a Nodal Officer – This was covered earlier in my blog, but it belongs here too, because it’s a system you set up once and maintain, not a one-time policy decision. I’ve found that SHe-Box onboarding is one of the easiest compliance requirements to overlook because it doesn’t feel like part of “writing the policy.”

Layer 4: Display, Communication & Training

  • Put up a physical poster/notice at every office location: This is a legal requirement under Section 19, not just a good practice, and it’s one of the most commonly flagged gaps when district officers inspect a workplace. The poster must clearly display:
    – The names and contact details of all ICC members (so any employee knows exactly who to approach)
    – The penal consequences of sexual harassment under the law
    – A summary of how to file a complaint
    – Update the poster every time your ICC composition changes; an outdated poster with the wrong members’ names is treated the same as not having one at all.
  • Run mandatory POSH sensitisation/training sessions for all employees: This is a legal requirement under Section 19(b), not optional. What this should cover: what counts as sexual harassment, how to file a complaint, and how confidentiality protects the complainant. Every new employee should go through this during onboarding, and the entire workforce should be re-trained at least once every year, not just once when the company was set up. A one-time training three years ago does not count as compliance.

Annual Employee POSH Training: Prepare your own LMS-based POSH awareness training that employees can complete at their own pace while meeting annual compliance requirements or appoint us for an engaging in-person POSH awareness workshop delivered at your workplace both  with attendance recording. Consult now.

  • Give ICC members their own, deeper training: Separate from general employee sensitisation/training. This should cover how to actually conduct an inquiry, how to handle evidence, and how to recognise and avoid personal bias while hearing a case. Ideally, do this once when the ICC is newly constituted, and refresh it at least once during its 3-year term. Personally, I don’t think an ICC should conduct its first real inquiry without ever practising one. Mock inquiries expose procedural gaps before a real employee is affected.

Need assistance with constituting your Internal Committee (ICC), onboarding members, explaining roles and responsibilities, and providing mandatory orientation to help your committee function confidently and compliantly. Reach out to us.

  • Train managers specifically on what to do if someone confides in them informally: In practice, many complaints are first mentioned casually to a manager, not filed directly with the ICC. If managers don’t know that their job is to guide the person to the ICC and not try to “sort it out” themselves informally, this becomes the single biggest source of complaints that never get properly recorded or resolved.

Layer 5: Keep It Running, Not Just Set Up (Ongoing)

One of the biggest misconceptions about POSH is that implementation ends once the policy is launched. In reality, that’s when the ongoing compliance work begins. 

  • Track your ICC’s 3-year term and plan the renewal in advance. If the ICC’s term has technically expired and it still hears a case, the findings of that inquiry can be challenged in court purely on this technical ground, even if everything else about the case was handled correctly.
  • Review your case status every 3 months, not once a year. Check which cases are still pending, whether any are getting close to the 90-day deadline, and whether training has actually happened as planned. If you only look at this once a year, right before the annual report is due, you’ll find problems too late to fix before filing.
  • Treat the annual report as a check-up on how well the whole system is working, not just a form to fill out.

Managing POSH Compliance Across Borders: What Your Global Policy Doesn’t Cover

If your organisation operates with a global HR framework and India is one location among many, there’s a specific compliance gap that shows up repeatedly in MNC subsidiaries: the global anti-harassment policy is treated as sufficient, and the India-specific statutory requirements get quietly assumed to be “covered” by it. They are not the same thing, and regulators don’t treat them as equivalent.

A few things to build into how you manage this:

  • Your global policy protects the company; it doesn’t discharge your Indian statutory obligations. Even with an excellent global Respect at Work policy in place, Indian law still requires a validly constituted ICC at every Indian location with 10+ employees, SHe-Box onboarding, and annual filing independent of what the parent entity does elsewhere. A global policy reference is not a substitute for these.
  • Jurisdiction follows the complainant’s workplace, not the org chart. Where an India-based employee raises a complaint against someone in a different country, department, or even a different group entity, your India ICC is still the correct first point of inquiry for that employee; this has been reinforced by a Supreme Court ruling in December 2025 (Dr Sohail Malik v. Union of India), which held that jurisdiction cannot be used as a reason to deny or delay a complaint. In practice: your ICC should not decline a case on the grounds that “the accused doesn’t report to India”; it should proceed, and coordinate with the relevant overseas entity’s HR for any action outside India’s enforcement reach.
  • Build a two-layer policy document, not one. The strongest structure for a subsidiary is: a Global Anti-Harassment Policy that sets company-wide behavioural standards, plus a standalone India Annexure that mirrors your statutory obligations word-for-word ICC composition, timelines, SHe-Box, annual report. This is also the version that survives a labour department audit; “our global policy covers this” is not an answer inspectors accept.
  • Decide your protocol for genuinely cross-border incidents before you need it, not during a live case. Map out in advance: what happens when an India-based employee’s complaint involves a respondent employed by a group entity in another country? Who does your ICC coordinate with global HR, the local entity’s legal counsel, or both? Having this answered in your policy document (not improvised mid-inquiry) is what protects the timeline and the process from breaking down under pressure.
  • Remote and hybrid work doesn’t dilute your India obligations, it expands what counts as evidence. Calls on Teams or Zoom, WhatsApp threads, and Slack messages connected to work are all within scope under Section 2(n); this is unchanged whether the other party is in the next room or another country. Make sure your evidence-collection process for the ICC explicitly includes digital records, not just in-person testimony.

Implementation of POSH Through Three Lenses

  1. HR Leader at an MNC
  2. HR Leader at a Startup
  3. Founder (Startup)

The five layers + Managing POSH Compliance Across Borders above are universal. What changes is sequencing, resourcing, and where the real friction sits, depending on who’s driving implementation.

🏢 If You’re an HR Leader at an MNC (Indian Subsidiary)

Your constraint isn’t budget or founder buy-in; its scale, jurisdiction, and integration with existing global systems.

  • Multi-establishment ICC constitution is your first real challenge: Every branch office, not just registered offices, needs its own ICC if it independently meets the 10-employee threshold. HR teams frequently constitute one “corporate” ICC and assume it covers all locations; this is a structural non-compliance that surfaces only during a district-wise audit or an actual complaint from a branch office with no ICC of its own.

Implement Complaint Register SaaS / Digital Ticketing Tool now, book a call with us

  • Reconcile your POSH policy with your global anti-harassment/Code of Conduct policy: Don’t let the global policy silently override statutory requirements. A global template that allows monetary settlement in “mediation,” or treats confidentiality as discretionary, directly conflicts with Section 16 and the conciliation provisions. Legal and India HR need to jointly redline the global template, not adopt it as-is with an India-specific addendum bolted on.
  • Your ICC’s external member becomes a recurring sourcing and continuity problem at scale: With multiple establishments, you need multiple external members (or one willing to serve across locations, which raises its own logistics/travel-cost questions). Build this into your annual compliance budget rather than treating it as a one-time setup cost.
  • Integrate, don’t duplicate with your existing Ethics Hotline/whistleblower channel: Employees should have one clear front door; if your whistleblower policy and POSH policy both claim to handle sexual harassment complaints with different processes, you create confusion about which timeline (90-day statutory inquiry vs. internal ethics investigation SLA) actually governs.
  • Board-level disclosure is now a live compliance item, not a future one: Following the Ministry of Corporate Affairs (MCA) notification effective July 2025, POSH-related disclosures in the Board’s Report have moved from a best-practice recommendation to a mandatory, standardised requirement for companies under the Companies Act, 2013, meaning your annual report data now needs to be board-audit ready on a shorter internal timeline than the District Officer deadline alone would suggest.
  • Multi-district filing is an operational project, not a form-filling task: If you operate across states, you’re filing separate annual reports with separate District Officers, and in some states also with the State Women and Child Development (WCD) Department. Build a jurisdiction map (which district office covers which establishment, and its specific deadline and format quirks) as a standing compliance document, not something rebuilt from scratch every January.
  • As POSH increasingly becomes a board-level governance matter, organisations should periodically review their Directors’ & Officers’ (D&O) Liability Insurance to understand how employment-related governance risks are addressed. Insurance coverage varies considerably, and organisations should obtain appropriate legal and insurance advice rather than assuming automatic coverage. 

🚀 If You’re an HR Leader at a Startup

Your constraint is the opposite: you likely have no legal team, a policy budget of near-zero, and a single person (you) accountable for everything from drafting to filing.

  • Avoid relying on generic, one-size-fits-all POSH policy templates downloaded from the internet. Many are legally outdated or too generic to address modern workplace realities such as remote work, contractors, gig workers, or complaints involving founders and senior leadership. Start with a well-drafted, legally compliant template and customize it to reflect your organisation’s structure and operations. 

Get your editable POSH Policy Template 

  • Solve the external member problem early, it’s your single biggest bottleneck: Startups routinely delay ICC constitution for weeks because they can’t identify a willing NGO-affiliated external member. Building a shortlist (local women’s rights NGOs, lawyers with relevant experience) before you cross the 10-employee threshold, not after a complaint arriving before your ICC is properly constituted is a compliance failure that can’t be retroactively fixed.
  • Keep the policy legally complete but operationally lightweight: You don’t need an enterprise-grade case management platform on day one; a well-structured, access-controlled document folder with a numbering convention is legitimate and defensible. What you cannot skip, regardless of size, is the templates (Layer 3) and the confidentiality/non-retaliation language (Layer 2); these are what protect you legally, not the sophistication of your tooling.
  • In my opinion, founder buy-in is more important than policy drafting itself. A perfectly written policy has very little value if leadership isn’t prepared to follow it during a difficult case. If the founder treats this as a compliance checkbox rather than something they’ll personally respect during an actual complaint (especially one involving a senior employee or co-founder), the policy exists on paper only. Get explicit founder sign-off on the escalation path for complaints against leadership before you finalise the policy, not after a complaint forces the question.
  • Remote-first startups need the “workplace” definition addressed explicitly, in writing, on day one: not as an afterthought once someone raises a concern about conduct in a Slack DM or a virtual all-hands. This is one of the most litigated ambiguities in current POSH interpretation and one of the easiest to close proactively.

👤 If You’re a Founder (Startup)

You are not implementing HR process; you are personally managing legal exposure that attaches to you and your company from employee #10 onward, and the decisions below are yours to make, not HR’s to make for you.

  • I’ve spoken with many founders who assume POSH becomes relevant only once the company grows. Legally, that assumption can become one of the most expensive compliance mistakes a startup makes. This is not optional at any headcount above 10, and “we’re too small/informal for this” is the single most expensive assumption a founder can make. Non-compliance penalties start at fines, but the real cost is what happens without a compliant ICC. When a complaint does arise, you lose the ability to conduct a legally valid inquiry, which means you’re managing the situation with founder instinct instead of a defensible process, at exactly the moment the stakes are highest.
  • Decide, explicitly and in writing, who has authority if the complaint is against you or a co-founder: This is the one implementation decision that cannot be delegated to HR, because HR reporting to you creates the exact conflict of interest the Act is designed to prevent. Resolve this before it’s tested by a real complaint, typically by ensuring the ICC’s external member and at least one internal member have a documented, independent escalation path to the board or to the District Officer if the respondent is leadership.
  • Budget for this as a recurring cost, not a one-time setup line item: External member honorarium, annual training, and policy review aren’t optional “add if we grow” expenses; they’re the difference between an ICC that exists on paper and one that can actually function when tested.
  • Investor and enterprise-client due diligence increasingly checks for this directly. A functioning ICC, a properly filed annual report, and documented training records are now common data-room requests and vendor-onboarding compliance checks. Treating POSH as “something we’ll formalise before our Series A” or “before we work with enterprise clients” means scrambling under deal-timeline pressure instead of already having the answer.
  • Your personal exposure doesn’t disappear because you delegated implementation to HR: As the employer, statutory responsibility for constitution, display, training, and annual filing sits with you; HR executes, but sign-off, budget approval, and awareness of where the gaps are should be a standing item you personally review, not something you assume “HR has handled.”

Congratulations on Reaching 10+ Employees!
This is a major milestone and it may also mean your organisation now has new obligations under the POSH Act. Let us help you implement your First-Time POSH Compliance Setup, including ICC constitution, policy drafting, documentation, training, and compliance support. Book a First-Time POSH Setup Call

8. Remote and Digital Workplace Inclusion

The POSH Act, 2013 adopts a broad and evolving definition of “workplace”, making it fully applicable to remote, hybrid, and digital work environments. Sexual harassment is not limited to physical office spaces and can occur wherever work-related interactions take place.

A. Work-from-Home (WFH)
Under the POSH Act, a “workplace” includes any place visited by an employee arising out of or during the course of employment, as well as a dwelling place or house. Accordingly, when employees work from home, their home becomes an extended workplace for POSH purposes. Any unwelcome conduct connected to work by colleagues, managers, or clients can amount to workplace sexual harassment, even if it occurs outside office premises or office hours.

B. Video Calls and Virtual Meetings
Sexual harassment during video conferences or virtual meetings (such as inappropriate comments, gestures, exposure, or coercive behaviour) is covered under POSH. The absence of physical proximity does not dilute liability; virtual presence linked to employment is sufficient to trigger the Act.

C. Digital Communication Platforms
POSH also applies to harassment through digital and electronic communication, including:

  • WhatsApp and text messages
  • Emails
  • Slack, Microsoft Teams, or other collaboration tools
  • Social media interactions connected to work
  • Anonymous internal platforms 

D. Judicial Interpretation of “Workplace”
Unwelcome sexually coloured remarks, repeated personal messages, sharing of explicit content, or inappropriate emojis, memes, casual banter sent in a work-related context can constitute sexual harassment under Section 2(n) of the Act.

Courts in India have consistently interpreted the term “workplace” broadly, recognising that modern work is not confined to physical offices. Judicial decisions have emphasised that the nature of the interaction and its connection to employment, rather than the physical location, is the determining factor.

This interpretation ensures that the POSH Act remains effective in digital, hybrid, and evolving work models, offering protection to women irrespective of where or how work is performed.

E. Cross-Border Teams: Where Does the POSH Act Actually Apply?

One of the most common questions I receive from organisations with global teams is whether the POSH Act automatically applies to every employee simply because the company is registered in India. The short answer is no. While remote work has made the workplace borderless in practice, Indian law is not borderless in principle. 

The POSH Act, 2013 is designed to protect women in workplaces located in India and women employed in India. It does not automatically govern every employee of an Indian-registered company simply because the company is Indian. For organisations with distributed or global teams, three distinct legal layers operate simultaneously, and they don’t collapse into one:

a. The company’s internal policy: A Global Anti-Harassment / Respect at Work Policy can, and should, apply uniformly to every employee regardless of location. This lets the company investigate and take disciplinary action (warning, suspension, termination) under its own contractual authority, independent of which country’s statute is triggered.

b. Employment law: This generally follows the employee’s work location, not the employer’s country of registration. An employee based in Germany is primarily protected by German employment law; an employee based in India falls under the POSH Act.

c. Criminal law: If the conduct amounts to a criminal offence (stalking, threats, non-consensual image sharing, assault), jurisdiction is determined by the country where the offence occurred or the accused/victim is located not by where the parent company is headquartered.

What this means in practice – If a complaint involves an India-based employee and a colleague based overseas say, over Teams, Slack, or email the Indian entity’s ICC still has a duty to inquire where the complainant is India-based, regardless of where the respondent sits. What changes is not whether the ICC acts, but what it can enforce: internal disciplinary action is available globally; the specific protections and penalties under the POSH Act apply to the India leg of the relationship.

Imagine a company headquartered in the US with employees in India, Germany, and Singapore. The company’s Global Anti-Harassment Policy sets one standard of workplace behaviour for everyone. However, if an employee in India files a sexual harassment complaint, the Indian office must also follow the POSH Act, including constituting an ICC, following statutory inquiry timelines, and meeting reporting obligations. Employees in Germany and Singapore would instead be protected under their respective local employment laws. 

The compliance fix – A single India-only POSH Policy is not enough for a company with international teams, and a single global policy without an India-specific annexure is not enough either. The two need to coexist a uniform Global Policy stating company-wide standards, with a country-specific annexure (India Annexure, UK Annexure, and so on) carrying the actual statutory obligations for each jurisdiction where the company employs people. For India, that annexure needs to explicitly reference the POSH Act, ICC constitution, SHe-Box onboarding, and the 90-day inquiry timeline; a generic reference to “local law” is not sufficient documentation in an audit.

Develop a comprehensive Global Anti-Harassment / Respect at Work Policy with us that extends beyond statutory POSH requirements, helping protect all employees while promoting a respectful, inclusive, and legally compliant workplace.

9. ICC vs SHe-Box: Practical Guide

What is the Internal Complaints Committee (ICC) and how does it works?

A. When does the ICC apply?

  • Every employer must constitute an Internal Complaints Committee (ICC) at each workplace where ten or more employees are employed.
  • If an organisation has multiple offices, branches, or administrative units at different locations, a separate ICC must be constituted at each such unit.
  • The ICC is the primary authority for receiving and inquiring into complaints of sexual harassment when the respondent is an employee of the organisation.


B. Constitution of the ICC

The ICC must be constituted by a written order of the employer and must include:

  • A Presiding Officer, who must be a senior woman employee at the workplace (If unavailable, she may be nominated from another office or organisation of the same employer.)
  • At least two employee members, preferably committed to the cause of women or having experience in social work or legal knowledge.
  • One external member from an NGO or association committed to women’s causes, or a person familiar with issues of sexual harassment.

Finding a qualified External ICC Member is a common bottleneck for employers constituting an ICC for the first time. The HR Fix provides External ICC Member services, meeting the statutory requirements under the Act. 

  • At least 50% of the ICC members must be women.
  • The tenure of ICC members cannot exceed three years.

C. How does the ICC function?

**Alt Text:**

A clean, handwritten flowchart illustrating the POSH Act complaint process in India. The diagram begins with the heading **"Sexual Harassment Incident Occurs"** and outlines the steps from filing a written complaint with the Internal Committee (ICC), assistance in drafting the complaint, and a decision on whether the aggrieved woman requests conciliation. The flow then branches into two paths: **conciliation**, leading to a recorded settlement with no further inquiry, or a **formal inquiry**, where the ICC conducts an investigation, provides interim relief if needed, submits its inquiry report, the employer implements recommendations, and either party may appeal within the prescribed timeline. The chart is handwritten in blue ink on an off-white textured background with arrows connecting each step.
POSH Act Complaint Process: Internal Committee (ICC) Workflow

D. Role of the employer in ICC functioning

  • The employer must:
    • provide facilities and support to the ICC,
    • assist in securing attendance of parties and witnesses,
    • treat sexual harassment as misconduct, and
    • ensure timely submission of ICC reports

What is a SHe-Box: How to use it and when it is helpful?

A. What is a SHe-Box?
SHe-Box is a centralised, government-run online portal launched by the Ministry of Women and Child Development (MWCD) to enable women to:

  • File complaints of sexual harassment at the workplace online, and
  • Track the status of such complaints under the POSH Act, 2013.

It also functions as a national repository of information on:

  • Internal Committees (ICs), and
  • Local Committees (LCs)

constituted across government, private, and unorganised sectors

The portal is designed to strengthen implementation, monitoring, transparency, and accountability under the POSH framework.

B. How to Use the SHe-Box Portal
a. Filing a Complaint

  • An aggrieved woman can submit her complaint online through the SHe-Box portal.
  • The portal is user-friendly and includes multilingual support to improve accessibility across regions and social backgrounds.
  • Complaints can be filed by women working in:
    • public sector,
    • private sector,
    • unorganised sector, and
    • domestic work

b. Automatic Routing of Complaint

  • Once submitted, the complaint is automatically forwarded to:
    • the Internal Committee (IC) of the organisation (if it has 10 or more employees), or
    • the Local Committee (LC) of the district (if the organisation has fewer than 10 employees or if the complaint is against the employer).
  • This ensures that the complaint reaches the legally appropriate authority without procedural confusion

c. Tracking and Transparency

  • The complainant can track the status of her complaint in real time.
  • Updates on actions taken are visible to the complainant, ensuring transparency and accountability in the redressal process

d. Role of Nodal Officers

  • Every workplace is required to designate a Nodal Officer for the portal.
  • The Nodal Officer acts as a link between the employer, IC/LC, and the complainant, and is responsible for:
    • updating IC/LC details,
    • monitoring complaint progress,
    • uploading annual reports, and
    • updating information on awareness and training programmes
Infographic explaining when to use the She-Box portal under the POSH Act, 2013. It shows common workplace failures such as the absence of an Internal Committee (ICC), ignored complaints, delayed inquiries, and lack of confidentiality, followed by the She-Box complaint escalation process, including submission, monitoring by authorities, routing to the employer or Local Committee, and time-bound follow-up.
She-Box complaint escalation process under the POSH Act, 2013

For a complete walkthrough of registering your organisation and filing complaints on the government’s official portal, see our detailed SHe-Box Portal guide.

C. When is SHe-Box Helpful?

SHe-Box is particularly useful in the following situations:
a. Absence or Inaccessibility of ICC

  • When a workplace:
    • has not constituted an Internal Committee, or
    • the woman is unable or hesitant to approach the IC directly.

b. Unorganised Sector & Domestic Workers

  • Women working in the unorganised sector or as domestic workers can easily file complaints through SHe-Box.
  • The portal directs such complaints to the appropriate Local Committee based on the location of the workplace.

c. Complaint Against the Employer

  • Where the complaint is against the employer himself/herself, SHe-Box ensures routing to the Local Committee, avoiding conflict of interest.

d. Monitoring Delays & Non-Compliance

  • The centralised system allows authorities to:
    • monitor delays,
    • track non-compliance by employers, and
    • ensure effective enforcement of the POSH Act .

e. Mandatory On-boarding of Workplaces

  • As clarified in the documents, all workplaces including private entities are required to onboard the SHe-Box portal.
  • Unless IC details are uploaded, complaints cannot be routed to that workplace, making onboarding essential for statutory compliance.

ICC vs SHe-Box: Which Route to Use and When?

CriteriaInternal Complaints Committee (ICC)SHe-Box (Sexual Harassment electronic Box)
What it isAn internal statutory committee constituted by the employer under the POSH ActA government-run online portal managed by the Ministry of Women & Child Development
Legal basisPOSH Act, 2013 (Sections 4–13)POSH Act + MWCD initiative + DoPT notification
Where it appliesWorkplaces with 10 or more employeesAll workplaces – public, private, unorganised sector, domestic work
Who can use itWomen employees of that specific organisationAny working woman, regardless of sector or size of workplace
Mode of filingInternal submission (written complaint to ICC)Online complaint filing through a central portal
Who conducts the inquiryICC of the organisationComplaint is routed to ICC or Local Committee (LCC) automatically
Monitoring authorityEmployer-led monitoringGovernment-monitored system
Status trackingDepends on internal processReal-time status tracking available to complainant
When ICC exists and is functionalBest and primary route❌ Not necessary, but still optional
When ICC is not constituted❌ Not availableBest route – complaint routed to LCC
When complaint is against employer / top management⚠️ Conflict of interest possiblePreferred route – routed to LCC
Unorganised sector / domestic workers❌ ICC not applicablePrimary and effective route
Fear of retaliation or inaccessibility⚠️ May discourage direct reportingSafer alternative due to central oversight
Transparency & accountabilityInternal confidentialityHigher accountability through government visibility
Employer obligationMust constitute, support, and act on ICC recommendationsMust onboard on SHe-Box, appoint Nodal Officer, upload ICC details
Failure to complyAttracts penalties under POSH ActNon-onboarding leads to complaints being escalated externally

Setting up your organisation on SHe-Box correctly including Nodal Officer appointment and IC registration is a statutory requirement that most employers delay or get wrong. If you need assistance with onboarding, The HR Fix provides SHe-Box setup support as part of implementation or as a standalone service.

10. The DPDP (Digital Personal Data Protection) Act, 2023: Best practices for handling digital evidence during a POSH inquiry

Today’s POSH inquiries are increasingly built around digital evidence rather than paper records. Emails, Microsoft Teams or Slack messages, WhatsApp chats, screenshots, CCTV footage, access logs, video meeting recordings, and electronic documents often become central to an inquiry. Much of this information may also constitute digital personal data under the Digital Personal Data Protection (DPDP) Act, 2023, requiring organisations to handle it responsibly alongside the confidentiality obligations under Section 16 of the POSH Act.

From a practical standpoint, organisations should collect only the information reasonably necessary for the inquiry. Avoid requesting an employee’s entire phone, mailbox, chat history, or unrelated personal conversations when only a limited set of records is relevant to the allegations. Over-collection of personal data creates unnecessary privacy risks without improving the quality of the inquiry.

Digital evidence should be stored securely and shared strictly on a need-to-know basis. Complaint files, witness statements, screenshots, and inquiry reports should be accessible only to authorised ICC members and designated HR or legal personnel. These records should never be circulated through informal WhatsApp groups, personal email accounts, or unrestricted shared drives simply because they are convenient.

Employees should also preserve digital evidence responsibly. Wherever possible, retain original emails, chat logs, screenshots, and other electronic records rather than edited, cropped, or selectively forwarded versions. Maintaining the original context and metadata, where available, helps strengthen the credibility of evidence during an inquiry.

Organisations should also establish a documented record retention practice for POSH complaints. Sensitive inquiry records should not be retained indefinitely, nor should they be deleted prematurely. A clearly defined retention and secure disposal process helps balance legal, operational, and privacy considerations.

Finally, as organisations increasingly adopt AI tools, complaint documents, witness statements, chat transcripts, or other confidential inquiry materials should not be uploaded to public AI platforms or external services without appropriate organisational safeguards and authorisation. The confidentiality obligations under the POSH Act continue regardless of the technology used to review or process the information.

In my opinion, the strongest POSH framework today isn’t just legally compliant it is also privacy-conscious. As workplace evidence becomes increasingly digital, organisations should treat data governance as an integral part of POSH compliance rather than as a separate IT or legal responsibility.

11. Annual Report Filing: The Consolidated Guide

This is the piece most POSH content treats as a checklist item (“file the annual report”) without explaining what it actually requires, who owns it, or what’s changed recently. Here it is as one complete section instead of scattered mentions.

There Are Two Separate Reports – Not One

This is probably one of the most misunderstood areas of POSH compliance. I’ve noticed many HR professionals assume there’s only one annual filing, when the law actually asks for two different reports, prepared by two different people, going to two different places. Filing only one thinking it covers everything is a compliance gap, even if your ICC itself is working perfectly.

In plain terms:

  • Section 21 Report = the ICC’s own report. The Internal Committee prepares this and sends it to two people: the employer and the District Officer. Think of this as the detailed, factual record of “what happened this year”, how many complaints came in, and what happened to them.
  •  Section 22 Disclosure = the employer’s own reporting duty. The company has to mention its POSH numbers (how many cases, how they were closed) inside the company’s own annual report, the same annual report it prepares for its business/financial reporting. If a company doesn’t prepare that kind of annual report at all (common for smaller companies), it must instead directly inform the District Officer itself, separately from the ICC’s Section 21 filing. For companies registered under the Companies Act, 2013, this obligation has now become a specific line item inside the Board’s Report, the section of a company’s annual report that goes to its own Board of Directors and shareholders.

Section 21 vs. Section 22 

 Section 21 ReportSection 22 Disclosure
Who prepares itThe Internal Committee (ICC)The employer/company itself
Who receives itThe employer AND the District OfficerIncluded in the company’s own annual report (or sent to the District Officer if the company has no such report)
What it containsDetailed case data number of complaints, how many were resolved, how many are still pending, awareness programmes conductedA summary: number of cases filed and how they were disposed of
Where it livesA standalone document submitted externallyA section/paragraph inside a larger existing report (e.g., the Board’s Report)
Who is accountable if it’s missingThe ICC (and, indirectly, the employer for not ensuring it happened)The employer/company and its directors directly
Recent developmentContent requirements unchangedNow a mandatory, standardised disclosure inside the Board’s Report for Companies Act entities (MCA notification effective July 2025)

Why this distinction actually matters in practice: An ICC can file a perfectly accurate Section 21 report, and the company can still be non-compliant if nobody separately made sure the Section 22 disclosure made it into the company’s own annual report or Board’s Report. These are two separate checkboxes, not one.

Avoid filing mistakes. Let us prepare, review, and assist with filing your Annual POSH Report. 

What the Section 21 Report Must Contain

  • Number of complaints of sexual harassment received during the calendar year
  •  Number of complaints disposed of during the year
  •  Number of cases pending for more than 90 days
  • Number of workshops or awareness programmes conducted
  • Nature of action taken by the employer or District Officer

A zero-complaint year still requires a filed “Nil Report.” Not filing because “there was nothing to report” is itself a violation; the report also demonstrates preventive activity (training, awareness), which every organisation has an obligation to conduct regardless of complaint volume.

Timeline

The reporting period follows the calendar year (1 January–31 December), not the financial year, a distinction that trips up organisations used to financial-year-aligned compliance calendars. The commonly cited filing deadline is 31 January of the following year, though this is not uniformly codified nationally several district administrations issue their own local circulars, and at least one major district (Gurugram) has moved its deadline as late as 28 February in recent notifications alongside additional checklist requirements. Given this variance, confirm the specific deadline and format with the relevant District Officer rather than defaulting to 31 January universally and build your internal collection timeline (data from HR, ICC, and department heads) to be ready well ahead of whichever date applies, since there is no condonation of delay built into the framework.

Where to File

  • Submit to the District Officer of the district where each establishment is located.
  • Operate across multiple districts or states → file separately with each District Officer. There is no single centralised national filing that covers multiple locations.
  • Where a District Officer hasn’t been formally appointed in a given state, submission to the State Women & Child Development Department (and, as a safeguard, the Chief Minister’s office) is the fallback route that is worth confirming locally rather than assuming a default contact.
  • SHe-Box registration and reporting is increasingly used to complement, not replace the physical/email submission to the District Officer; treat it as an additional compliance layer, not a substitute for identifying and filing with the correct local authority.

12. Employer POSH Compliance Toolkit (Ready-to-Download Templates)

Get editable HR-ready templates + implementation notes. Download below 👇

These templates are designed for general use. If your organisation requires customised, legally reviewed POSH documentation, ICC constitution orders, inquiry formats, and annual report templates drafted for your specific structure, a complete documentation package is available.

Part III. Internal Committee (ICC)

13. An ICC Member’s Roles & Responsibilities 

One of the biggest misconceptions I see is that employees treat an ICC nomination as just another committee assignment. It isn’t. Being appointed to an Internal Committee is a legal role with statutory powers, statutory duties, and statutory consequences for getting it wrong. Once nominated, every member, Presiding Officer, internal member, or external member steps into the shoes of a quasi-judicial authority. Section 11(3) of the POSH Act gives the ICC the powers of a civil court under the Code of Civil Procedure, 1908, for the purpose of an inquiry: summoning people, examining evidence on oath, and requiring the production of documents. In practice, I’ve noticed many ICC members assume the Presiding Officer is solely responsible for legal compliance. The Act doesn’t work that way. Every member shares responsibility for ensuring the inquiry is fair, lawful, and properly documented. 

This section looks specifically at what that means for you as an individual member, not how the ICC is formed (I’ve covered that already), but what you are personally responsible for once you’re on it, and how a recent Supreme Court ruling has changed what “your case” even means.

Core Responsibilities of an Individual Member

  1. Receiving and acknowledging complaints with neutrality from the first interaction. The moment a complaint reaches the ICC, tone is already being set. A member’s first response whether during intake or the first hearing signals whether the process will feel fair. This means acknowledging the complaint without pre-judging it, and without reacting in a way that signals disbelief toward either party.
  2. Assessing prima facie scope before the inquiry proceeds. Personally, I encourage every ICC member to pause before the inquiry begins and ask one simple question: “Does this complaint legally belong before this ICC? The complaint falls within the definition of sexual harassment under Section 2(n) and relates to a “workplace” as defined under the Act not defer this entirely to the Presiding Officer? Spending a few extra minutes at this stage can prevent procedural mistakes later. 
  3. Active, hands-on participation in the inquiry. This is not a passive seat. Each member is expected to review evidence, ask questions during hearings, and form their own view of the facts not simply defer to the Presiding Officer’s read of the situation. Courts have repeatedly set aside ICC findings where an external member’s involvement was found to be token rather than substantive (Ruchika Kedia v. ICC, Goa Institute of Management, 2020). The same principle applies in substance to any member who checks out of the process.
  4. Maintaining confidentiality as a personal, non-delegable obligation. Section 16 of the Act prohibits disclosure of the identity of the complainant, respondent, witnesses, and the content of the inquiry, except in limited circumstances. This obligation attaches to you, individually, not to the ICC as an abstract entity. A breach by one member, a casual mention in a hallway conversation, a forwarded message is a breach the member is personally answerable for under the employer’s service rules.
  5. Following natural justice at every stage. Both parties must get a fair, equal opportunity to be heard, to respond to evidence against them, and to bring witnesses. This applies symmetrically the complainant’s right to a safe, fair process and the respondent’s right to defend themselves are not in tension; both are legal requirements. A member who treats the inquiry as already decided, in either direction, compromises the finding.
  6. If there’s one habit I recommend every ICC develops, it’s documenting everything in real time. Reconstructing notes after a hearing almost always creates inconsistencies that become difficult to defend later. Poor documentation is one of the most common grounds on which ICC findings are struck down in appeal.
  7. Completing the inquiry within statutory timelines. The inquiry must be completed within 90 days of the complaint being filed, and the report submitted to the employer within 10 days of completing the inquiry (Section 13). Delay is not a neutral failure courts treat it as prejudicial to the complainant and, at times, to the respondent’s right to a timely resolution.
  8. Contributing to the final report and recommendation, not just attending hearings. Under Section 13, the ICC’s recommendations go directly to the employer, who is bound to act on them. A member’s sign-off on the final report is a substantive act, not a formality; it should reflect their own assessment of whether the facts, as established, prove the complaint on a preponderance of evidence.
  9. Recusing when there’s a conflict of interest. If a member has a personal, reporting-line, or social relationship with either party that could reasonably be seen as compromising neutrality, they are expected to disclose this and step back from that specific case not wait to be challenged on it later.
  10. Undergoing training as an ongoing obligation, not a one-time induction. Courts have flagged untrained ICC members as a structural weakness in inquiries. Training isn’t just an onboarding checkbox it needs to be refreshed as case law and procedural expectations evolve.

Recent Legal Developments Every ICC Member Should Know

Jurisdiction can no longer be used to deny or delay a complaint. In Dr Sohail Malik v. Union of India (Supreme Court, 10 December 2025), the Court held that a woman can approach the ICC of her own workplace even if the respondent belongs to a different department, office, or organisation. The Court was direct about this: jurisdiction is not a technicality an ICC or a respondent can hide behind, and the Act must be applied with sensitivity as protective, welfare legislation, not read narrowly like a procedural statute. What this means for you as a member: in cross-functional teams, inter-office assignments, virtual meetings, or client-facing roles, don’t dismiss a complaint at intake because the respondent “isn’t from our office.” Section 13 already requires your report and recommendations to be forwarded to the employer for action; this ruling confirms that principle extends across departmental and organisational lines when required.

Mandatory disclosure and training obligations have been reinforced. Supreme Court directions through 2025 (building on the Aureliano Fernandes v. State of Goa framework) have pushed for stricter, more visible compliance, public disclosure of ICC composition and contact details, and mandatory training and orientation for members on their duties and inquiry procedures. This is a good moment for ICC members to check: is your organisation’s ICC contact information actually published and current, and has your own training been refreshed recently, or was it a one-time session years ago?

Book ICC Training session now

A live, unresolved issue worth tracking: protection for private-sector ICC members themselves. A Public Interest Litigation (Janaki Chaudhary & Anr. v. Ministry of Women and Child Development, filed 2024) is currently before the Supreme Court, arguing that private-sector ICC members have no protection against retaliatory action such as termination for decisions taken during an inquiry, unlike their counterparts in government service who have fixed tenure and safeguards. The Court issued notice to the Ministry of Women and Child Development, the Ministry of Corporate Affairs, and the National Commission for Women in December 2024, and the matter remains pending. This has not been decided yet there is no ruling establishing protection for private-sector members as of now but it directly concerns the personal risk ICC members in India currently carry, and it’s worth watching for how it develops.

Approach and Behaviour During a Case: What “Good” Actually Looks Like

Knowing the law is only half the job. In my experience, employees rarely judge an ICC only by its final decision; they remember how they were treated throughout the process. That’s why behaviour matters just as much as legal compliance. A few behavioural principles matter as much as procedural compliance:

  • Neutral, not detached. Neutrality doesn’t mean coldness. A member can be warm and human while still withholding judgment until the evidence is in.
  • No moral policing. The Delhi High Court has been explicit (December 2020) that an Internal Committee’s job is to assess whether the POSH Act has been violated not to pass judgment on the personal choices, relationships, or lifestyle of either party. Staying inside that boundary is a discipline, especially when a case involves personal or intimate details.
  • Consistent treatment of both parties. The same standard of respect, the same pace of communication, and the same opportunity to be heard should apply to the complainant and the respondent. Visible asymmetry responding faster to one party, being warmer with one over the other undermines the inquiry even if the final finding is correct.
  • No leading questions, no assumptions filled in. A member’s job is to establish facts through the evidence in front of them, not to complete gaps in the story based on what seems “likely” given someone’s role, gender, or past reputation.
  • Trauma-informed listening, not interrogation. Complainants (and respondents) often recount distressing events multiple times through the process. A member’s questioning style should account for this direct and thorough, but not repetitive in a way that re-traumatises.
  • Comfortable saying “I don’t know yet.” A member under social or hierarchical pressure from senior management, from peers to reach a quick conclusion should be able to hold the line and let the process run its course.
  • Discretion outside the room. Confidentiality isn’t just about not naming names; it includes not discussing “the vibe” of a hearing, not signalling an outcome informally, and not allowing body language or workplace behaviour to hint at where the case is headed.

What Else Should Be on Your Radar (and isn’t always covered)

A few things worth adding that don’t get enough attention in most ICC guidance:

  • Personal liability awareness. One topic I don’t see discussed often during ICC training is personal accountability. Every member should understand where their individual legal responsibilities begin and where the employer’s responsibilities end. This distinction matters when a case is later challenged, and most members are never told where that line falls.
  • Emotional load management. Repeated exposure to distressing accounts, especially for members handling multiple cases, is real and under-discussed. Organisations rarely build in any support structure for ICC members themselves.
  • Cross-location and remote-work readiness. Given the December 2025 ruling on jurisdiction and the reality of hybrid teams, members should be prepared to handle complaints involving colleagues they’ve never worked with directly, evidence gathered over video calls or chat logs, and coordination with another department’s HR not just in-person, same-office cases.
  • A working knowledge of what happens after the report. Members sometimes treat their job as done once the report is submitted. Understanding Section 13’s requirement that the employer act on recommendations within 60 days helps a member flag it if that follow-through doesn’t happen which is still, indirectly, part of the ICC’s credibility.

If I could give every first-time ICC member one piece of advice, it would be this: don’t think of yourself as representing HR or management during an inquiry. Your responsibility is to the process itself. A legally sound, fair, and unbiased inquiry protects everyone involved: the complainant, the respondent, the employer, and ultimately, the credibility of the ICC.

Part IV. Employees’ Guide to the POSH Act

14. Practical POSH Guidance for Employees

  1. If You’re an Employee (Aggrieved Woman)
  2. If a Complaint Has Been Filed Against You
  3. If You’re a Male or LGBTQIA+ Employee Facing Workplace Harassment

Every workplace complaint is different, and so is the guidance each employee needs. The sections below explain the practical considerations, legal rights, and common mistakes to be aware of based on your role in the process. 

👩 If You’re an Employee (Aggrieved Woman)

Your biggest challenge usually isn’t understanding whether something felt wrong; it’s understanding whether the conduct falls within the legal framework of the POSH Act and how to present it in a way that allows the ICC to conduct a fair inquiry. The quality of the complaint often shapes the quality of the inquiry.

  • Build evidence as the situation develops, not after months have passed. Emails, Teams or Slack conversations, WhatsApp messages (where work-related), meeting invitations, CCTV availability, travel records, performance reviews, and witness details are often more reliable than recollections made long after the incident. Preserve original records wherever possible rather than edited screenshots or forwarded messages, as authenticity becomes important during an inquiry.
  • Separate evidence from assumptions. An ICC decides complaints on the preponderance of probabilities, not on suspicion or speculation. Focus on documenting what happened, when it happened, who was present, and any contemporaneous communication rather than trying to prove motive.
  • Understand that retaliation itself may become a separate compliance issue. If, after raising a concern, you experience exclusion from meetings, sudden negative performance feedback, denial of promotions, transfer, intimidation, threats, or pressure to resign, maintain a dated chronology with supporting documents. The employer has a continuing obligation to provide a safe working environment under Section 19, and retaliatory conduct may become relevant during the inquiry.
  • Use the interim relief provisions where genuinely required. Under Section 12 of the POSH Act, the ICC may recommend measures such as transfer of either party, leave for the aggrieved woman, or other interim arrangements during the inquiry. Many employees are unaware that these protections exist and instead resign before the inquiry concludes.
  • Confidentiality applies to you as well. Discussing the complaint widely within the workplace, circulating screenshots, or attempting to gather support from colleagues through informal campaigns can unintentionally affect witness testimony, complicate the inquiry, and in some cases undermine confidentiality obligations under Section 16.
  • Finally, understand that the ICC is not your personal legal representative. Its role is to conduct an independent inquiry, not to advocate for either party. Present your complaint honestly, cooperate throughout the process, and allow the inquiry to be decided on the available evidence rather than public opinion or workplace rumours.

Need help understanding your rights before filing a complaint? We offer confidential Employee POSH Consultation & Complaint Drafting Support to help you assess your options, organise evidence, draft a structured complaint, and understand the inquiry process.

⚖️ If a Complaint Has Been Filed Against You

Receiving a POSH complaint does not automatically establish guilt. The ICC’s responsibility is to conduct an impartial inquiry that gives both the complainant and the respondent a fair opportunity to present their case. How you respond during the early stages often has a significant impact on the fairness and credibility of the inquiry.

  • Your first instinct may be to immediately contact the complainant to “clear up the misunderstanding.” Resist that instinct. Any direct communication after a complaint has been filed even if well-intentioned may later be interpreted as pressure, intimidation, interference, or an attempt to influence the inquiry. Allow all communication to take place through the ICC unless specifically advised otherwise.
  • Prepare your defence systematically rather than emotionally. Gather emails, chat records, meeting invitations, access logs, travel records, work product, performance discussions, and identify potential witnesses who have first-hand knowledge of relevant events. Focus on objective evidence rather than character references or workplace popularity.
  • Remember that the inquiry is not a criminal trial. The ICC generally applies the civil standard of proof preponderance of probabilities rather than proof beyond reasonable doubt. Your role is to provide a complete, truthful, and evidence-based response to the allegations rather than attempting to “win” through confrontation.
  • Respect confidentiality throughout the process. Avoid discussing the complaint with colleagues, asking witnesses what they intend to say, or attempting to build support within the organisation. Apart from potentially breaching confidentiality obligations, such conduct can itself become relevant during the inquiry.
  • Natural justice protects you as well. You have the right to know the allegations against you, respond to the complaint, present evidence, identify witnesses, and receive a fair opportunity to be heard. If you believe procedural fairness is being compromised, raise those concerns through the ICC rather than outside the inquiry.
  • Even if the complaint ultimately results in no findings against you, avoid retaliatory conduct afterwards. Performance decisions, team allocations, communication, or workplace interactions involving the complainant should continue to be handled professionally and objectively to avoid creating fresh disputes.

Our Respondent Consultation & Response Preparation service helps employees understand the inquiry process, organise supporting documents, prepare a structured response, and participate confidently in a legally compliant inquiry. Need our assistance, book a call now.

🌈 If You’re a Male or LGBTQIA+ Employee Facing Workplace Harassment

One of the biggest misconceptions in Indian workplaces is that the absence of statutory protection under the POSH Act means you have no options if you experience workplace sexual harassment. While the POSH Act specifically protects women, that does not mean inappropriate workplace behaviour should simply be tolerated.

  • Review your company’s employee handbook, Code of Conduct, Anti-Harassment Policy, Equal Opportunity Policy, Ethics Policy, or whistleblower mechanism. Many organisations provide internal complaint channels that extend workplace harassment protections beyond the statutory scope of the POSH Act.
  • If there is no such policy in place, do not worry. Report the incident to your HR department, your reporting manager (where appropriate), or the organisation’s designated ethics or grievance channel in writing. Keep your communication factual, professional, and retain copies of all correspondence.
  • Preserve emails, chat messages, screenshots, meeting invitations, CCTV availability, witness details, or any other contemporaneous records that may support your account. As with any workplace investigation, objective evidence is generally more persuasive than recollection alone.
  • Depending on the facts, offences such as assault, stalking, criminal intimidation, extortion, or non-consensual sharing of intimate images may attract remedies under other applicable laws. An employer’s internal process and your legal rights outside the organisation are separate and can operate simultaneously.
  • A lawyer can help you understand the remedies available based on the nature of the conduct, your employment terms, and the applicable laws. Don’t assume that the absence of POSH protection means the absence of legal protection altogether.

Need confidential guidance on your options? We offer Employee Workplace Harassment Consultation to help you understand the reporting mechanisms and legal avenues that may be available based on your circumstances.

15. How to File a POSH Complaint (Step-by-Step)

Step 1: Drafting the Complaint

A complaint must be made in writing by the aggrieved woman. It should include:

  • details of the incident(s),
  • date, time, and place of occurrence,
  • name(s) of the respondent(s), and
  • any supporting documents, messages, emails, or witnesses (if available).

Use this template only if your organisation doesn’t already have its own official complaint format if it does, use that one instead, since it may already be linked to your specific Internal Committee’s process. If your organisation doesn’t have a POSH policy or a constituted Internal Committee at all, you can also file your complaint directly through the government’s SHe-Box portal, which is available online to every woman regardless of her employer’s compliance status.

Timeline:

  • The complaint should be filed within 3 months from the date of the incident.
  • In cases of continuing harassment, the limitation period starts from the last incident.
  • The ICC or Local Committee may extend this period by another 3 months if sufficient cause is shown.

Need guidance before filing a complaint? If you’re unsure whether your situation falls under the POSH Act, need help understanding your rights, drafting a legally structured complaint, or require representative support during the process (where permitted by law), you can book a confidential Employee 1:1 Consultation & Representative Support session with us. 

Step 2: Filing the Complaint with ICC or SHe-Box

  • If the organisation has an ICC (mandatory where there are 10 or more employees), the complaint should be submitted to the Internal Complaints Committee.
  • If there is no ICC, or if the complaint is against the employer, the complaint may be filed with the Local Committee or through the SHe-Box portal, which forwards it to the appropriate authority.

At this stage, the complainant may also request interim relief, such as:

  • transfer of either party,
  • leave for up to 3 months, or
  • temporary change in reporting structure.

Step 3: Inquiry Process

Once the complaint is received, the ICC follows a quasi-judicial inquiry process:

  • The respondent is provided a copy of the complaint and given an opportunity to submit a written response.
  • Both parties are heard, evidence is examined, and witnesses may be called.
  • Conciliation may be attempted only at the request of the complainant and without monetary settlement.
  • If conciliation fails or is not requested, a formal inquiry is conducted.

The ICC is required to follow principles of natural justice, ensuring fairness, neutrality, and confidentiality.

Step 4: Timelines for Inquiry and Reporting

  • The inquiry must be completed within 90 days.
  • The ICC must submit its inquiry report within 10 days of completion.
  • Copies of the report are provided to both the complainant and the respondent.
  • The employer is required to act on the recommendations within 60 days.

Strict timelines ensure that complaints are not delayed or ignored.

Step 5: Outcome, Action, and Appeal

  • If the allegations are proved, the ICC may recommend disciplinary action, deduction of compensation from salary, counselling, or other measures.
  • If the complaint is not proved, the matter is closed with recorded reasons.
  • Malicious complaints may attract action, but mere inability to prove allegations does not amount to malice.

Appeal:

Either party may file an appeal against the ICC’s decision before the appropriate authority or court within 90 days, as per service rules or applicable law.

What Happens After the Complaint Is Filed?

Once a complaint is filed:

  • confidentiality must be strictly maintained,
  • retaliation against the complainant or witnesses is prohibited,
  • employers are legally bound to implement ICC recommendations, and
  • failure to comply can attract penalties under Section 26 of the POSH Act.

Part V. Global Workplace Compliance

16. POSH vs Global Compliance on Workplace Sexual Harassment Laws (Top 10 Countries)

CountryLaw / FrameworkDefinition ScopeMandatory PolicyInternal Committee / OfficerInvestigation RequirementTraining MandateReporting RequirementEmployer LiabilityPenalties
🇮🇳 IndiaPOSH Act, 2013Sexual harassment (physical, verbal, digital)✅ Mandatory✅ Internal Committee (10+ employees)Formal inquiry with timelines✅ Mandatory✅ Annual report filingDirect liability for non-complianceFines, license cancellation
🇺🇸 USATitle VII (Civil Rights Act)Sexual harassment = discrimination❌ Not always mandatory (but expected)❌ Not mandatedEmployer must investigate promptly⚠️ State-specific (mandatory in CA/NY)❌ No central reportingHigh litigation riskHeavy damages, lawsuits
🇬🇧 UKEquality Act 2010 + Worker Protection Act 2023Harassment incl. sexual nature✅ Expected❌ No IC requirementEmployer must take “reasonable steps”⚠️ Strongly expected❌ No annual filingProactive duty to preventUnlimited compensation
🇨🇦 CanadaLabour Code + Human Rights LawsSexual + psychological harassment✅ Mandatory❌ No IC, but designated person requiredMandatory resolution process✅ Mandatory⚠️ Internal documentation requiredEmployer responsible for safe workplaceFines + civil liability
🇦🇺 AustraliaSex Discrimination Act + WHSSexual harassment = workplace hazard✅ Mandatory❌ No ICMust investigate & eliminate risks✅ Mandatory⚠️ WHS documentationPositive duty to prevent riskCivil + regulatory penalties
🇫🇷 FranceLabour CodeSexual + moral harassment✅ Mandatory✅ Harassment Officer (250+)Mandatory investigation✅ Mandatory⚠️ Internal reportingStrong employer accountabilityCriminal + civil penalties
🇩🇪 GermanyAGG (Equal Treatment Act)Sexual harassment as discrimination✅ Mandatory❌ No ICMust investigate complaints⚠️ Expected❌ No central reportingEmployer must act or liableCompensation + fines
🇯🇵 JapanLabour Measures ActSexual + power harassment✅ Mandatory❌ No ICMandatory grievance handling⚠️ Recommended❌ No central reportingEmployer must ensure preventionAdministrative penalties
🇸🇬 SingaporePOHA + Tripartite GuidelinesSexual harassment broadly defined✅ Strongly recommended❌ No ICEmployer encouraged to act⚠️ Recommended❌ No reporting mandateEmployee-driven enforcementCourt orders, fines
🇦🇪 UAELabour Law (2021)Sexual harassment prohibited⚠️ Expected❌ No ICMust investigate if complaint arises❌ Not mandatory❌ No reportingEmployer liable for misconductFines, termination, legal action

Want to go beyond annual compliance?
While annual POSH training helps meet statutory requirements, regular Employee POSH Awareness & Sensitisation Sessions reinforce respectful workplace behaviour, encourage early reporting, and keep conversations around workplace safety active throughout the year. Book an Employee POSH Awareness & Sensitisation Sessions.

Part VI. Test Your Compliance

17. Are You Audit-Ready? 10-Point POSH Readiness Test (2026 Enforcement Edition)

✅ 1. Is a legally valid ICC constituted at every unit with 10+ employees?

  • Written constitution order issued?
  • Presiding Officer is a senior woman employee?
  • External member formally appointed?
  • Minimum 50% women members?
  • Separate ICC for each branch/location (if applicable)?

⚠ If “No” → This is immediate statutory non-compliance.


✅ 2. Is the ICC tenure valid?

  • Are members within the 3-year tenure limit?
  • Has re-nomination been formally documented?

⚠ Expired tenure may invalidate inquiries.


✅ 3. Are ICC details displayed conspicuously at the workplace?

  • Penal consequences displayed?
  • ICC composition displayed?
  • Updated display after any change?

⚠ Often flagged in inspections.


✅ 4. Has periodic POSH awareness training been conducted?

  • Annual or periodic sessions (not one-time onboarding)?
  • Separate orientation for ICC members?
  • Attendance records maintained?

⚠ One-time training = continuing violation.


✅ 5. Are inquiry timelines strictly followed?

  • Complaint acknowledged?
  • Inquiry completed within 90 days?
  • Report issued within 10 days?
  • Employer action within 60 days?

⚠ Timeline breaches are audit red flags.


✅ 6. Is confidentiality strictly maintained?

  • No public disclosure of complainant’s identity?
  • No circulation of inquiry details?
  • HR not handling matters outside ICC?

⚠ Breach can attract legal consequences.


✅ 7. Is the organisation onboarded on the SHe-Box portal?

  • ICC details uploaded?
  • Nodal Officer appointed?
  • Annual data updated?

(Portal administered by the Ministry of Women & Child Development)

⚠ Non-onboarding may escalate complaints externally.


✅ 8. Is the Annual POSH Report prepared and filed?

  • Annual report submitted to District Officer?
  • Board’s Report disclosure (if company)?
  • Data consistency maintained?

⚠ Filing is mandatory even if zero complaints were received.


✅ 9. Are records properly documented?

  • Complaint copies
  • Inquiry proceedings
  • Evidence records
  • Final recommendations
  • Action taken reports

⚠ Poor documentation weakens defensibility during audit.


✅ 10. Is POSH compliance reviewed at leadership/board level?

  • Reported to senior management?
  • Risk discussed at governance level?
  • Included in ESG or compliance dashboards?

⚠ POSH is no longer only an HR responsibility.


How to Interpret Your Score

ScoreRisk LevelWhat It Means
9–10 Yes🟢 Low RiskStructurally audit-ready
6–8 Yes🟠 Moderate RiskVulnerable to inspection
3–5 Yes🔴 High RiskLikely non-compliant
0–2 Yes🚨 Critical ExposureImmediate corrective action is required

Scored below 8? Request a compliance gap review.

We help companies build legally defensible POSH systems. Want a full compliance gap report? Leave your work email. Button: Book Compliance Review Call

If I had to summarise the biggest lesson from this entire guide in one sentence, it would be this: Most POSH violations do not arise from intent, but from assumptions, and assumptions are now the biggest compliance risk.

How organisations usually fail in POSH implementation

  • ICC exists only on paper
  • Expired external member
  • No inquiry documentation
  • Training done but undocumented
  • annual report mismatch

Calculate Your POSH Risk Score

  • ICC constituted?
  • External member active?
  • She-Box onboarded?
  • Annual report filed?

Part VII. Advanced POSH Governance for Boards & CHROs

18. Why POSH Is Now a Boardroom Issue, Not Just an HR Issue

For most of the last decade, POSH compliance lived entirely inside HR. A policy got drafted, an Internal Committee got constituted, a training got scheduled once a year, and the topic rarely made it past the CHRO’s desk. That era is over, and if your board still treats POSH as an HR agenda item, you are already behind.

Three things changed this:

  • The MCA notification effective July 2025 made POSH disclosure a mandatory, standardised line item in the Board’s Report not a best-practice add-on.
  •  The Supreme Court’s post-Aureliano Fernandes push for district-wise audits turned POSH into a verifiable regulatory condition, similar to a labour law inspection.
  •  High-profile complaints involving senior leadership have shown investors, media, and regulators that a company’s paperwork can look perfect while its culture quietly fails.

This guide is for the people in the room where POSH numbers now get discussed at board level. It assumes you already understand what the POSH Act says. It focuses on what the Act doesn’t tell you: how to govern this risk the way you’d govern any other material risk on your enterprise risk register.

Legal POV: Under Section 134(5) of the Companies Act, 2013, directors must lay down risk management systems that are “adequate and operating effectively.” A materially under-reported or poorly governed POSH function is increasingly arguable as a gap in that very system.

19. Governance Structure: Who Owns What

The single most common governance failure in POSH isn’t a missing policy it’s a missing org chart. Everyone assumes someone else owns escalation, someone else owns the numbers, someone else owns the board narrative. Get this structure explicit and in writing, before the first real crisis exposes the gap in front of your board, your investors, and possibly the press.

Board Oversight

The board’s job isn’t to run the Internal Committee, it’s to make sure the ICC is structurally independent, and to know when the system is failing before an outsider tells them.

  • Review the quarterly POSH dashboard (Section 3) as a standing agenda item, not an occasional one.
  • Confirm ICC composition and tenure are legally valid at every establishment, not just headquarters.
  •  Maintain a documented, tested protocol for complaints involving a board member, the CEO, or a founder (Section 4).
  • Split ownership across committees: Audit Committee owns compliance and disclosure accuracy; NRC owns anything intersecting executive appointments, promotions, or severance.

Legal POV: Independent directors carry a distinct duty under Section 149(8) read with Schedule IV of the Companies Act, 2013, to satisfy themselves that risk management systems are robust. A board shown only a sanitised annual summary, with no ageing data and no visibility into repeat patterns, cannot credibly discharge that duty.

Management Accountability

Name an executive owner, typically the CHRO, sometimes jointly with the CCO who is personally accountable for the accuracy of what reaches the board, not just for running the process.

Set explicit escalation triggers that management must act on without waiting for a scheduled board meeting:

  • Any complaint against a CXO or board member.
  • Any complaint that has attracted media attention.
  • Any case approaching the 90-day statutory deadline without resolution.
  • Any pattern of three or more complaints against the same individual over time.

These should escalate straight to the Audit Committee Chair or Board Chair not wait for the quarterly cycle.

Role of the CHRO / VP HR

The CHRO usually translates raw case data into board-usable language without minimising uncomfortable numbers or over-editorialising them into a defence brief. In practice, this means:

  • Presenting ageing, repeat-offender, and training-gap data to the board honestly, even when it’s an uncomfortable number.
  •  Keeping the ICC structurally independent of HR reporting lines especially where the person who might suppress a complaint and the person meant to receive it sit in the same chain.
  • Escalating known patterns into the formal ICC process rather than managing them informally.

Legal POV: Where a CHRO is found to have known of a pattern of complaints and failed to escalate them into the formal process, this moves from a compliance failure into individual misconduct and potentially abetment where the underlying conduct is criminal. “I didn’t know” is a weak defence for the one role whose job is visibility into this data.

Role of the General Counsel

General counsel sits at the intersection of the statutory process, litigation exposure, and board disclosure. Core responsibilities:

  • Review every high-risk case (Section 4) for litigation posture before it becomes public.
  •  Advise on when outside counsel or a special investigator is warranted particularly for CEO/founder complaints.
  • Own the legal privilege question: which internal communications about a case are protected, and which aren’t.
  • Advise the ICC on process and risk only never direct or influence its actual findings.

Courts have struck down findings where the process looked ICC-led but was substantively directed by legal or management. Protecting the inquiry’s independence is as much GC’s job as protecting the company.

Role of the Chief Compliance Officer

Where this role exists, it should own the systems layer:

  •  ICC constitution orders are current and filed at every establishment.
  • SHe-Box onboarding is complete and maintained.
  • Annual reports are filed on time in every jurisdiction the company operates in.
  •  The whistleblower/ethics hotline routes POSH-adjacent complaints to the ICC, not into a generic ethics SLA with lower statutory protection.

Audit findings (Section 10) actually get remediated, not just filed away.

Role of the Company Secretary

The Company Secretary typically certifies the accuracy of statutory filings including the Board’s Report disclosures now required under the July 2025 MCA notification. That means:

  • Getting the same access to accurate, current POSH data as the CHRO, not a summary handed over the week before filing.
  • Cross-checking that the Board’s Report POSH disclosure matches the underlying Section 21 filing data.

Legal POV: Sections 92 and 134 of the Companies Act, 2013 place personal liability on the Company Secretary and directors for the accuracy of annual returns and the Board’s Report. An incomplete POSH disclosure inside the Board’s Report is a statutory filing defect with named individual accountability — not a soft HR miss.

Role of ESG Leaders

ESG teams increasingly report harassment metrics externally through BRSR filings, sustainability reports, or investor questionnaires often without independently verifying the numbers against what HR reports internally.

  • Treat the quarterly POSH dashboard as the single source of truth for external reporting.
  • Flag loudly any request to present numbers more favourably externally than they appear internally.
  • Expect pointed governance questions from proxy advisors and ESG rating agencies; inconsistency between internal and external numbers is exactly what gets flagged.

RACI (Responsible, Accountable, Consulted, and Informed) Model for POSH Governance

A simple accountability matrix removes most of the ambiguity that causes governance failures. Adapt roles to your own structure the exercise of forcing every function to agree on where they sit is more valuable than the specific labels.

ActivityBoard / Audit CmteCHROGen. CounselComplianceCo. Secretary
ICC constitution & tenure validityInformedResponsibleConsultedAccountableInformed
Quarterly dashboard reviewAccountableResponsibleConsultedResponsibleInformed
CEO / founder / board complaintAccountableConsultedResponsibleConsultedInformed
Board’s Report / MCA accuracyAccountableConsultedConsultedResponsibleResponsible
Internal / third-party auditInformedConsultedInformedAccountableInformed
Crisis communication sign-offAccountableConsultedResponsibleInformedInformed

20. Board Reporting: Building the Quarterly POSH Dashboard

Most boards that “review POSH” once a year are looking at a single number: total complaints filed. That tells you almost nothing about whether the system is working. A quarterly dashboard with five data cuts turns POSH from a compliance checkbox into an early-warning system.

Number of Complaints

Track this quarter-over-quarter and year-over-year, against your own baseline not as an absolute good-or-bad number.

  • A rising number isn’t automatically bad; it often reflects growing employee trust in the reporting mechanism.
  • A falling number against growing headcount deserves more scrutiny, not less it can signal under-reporting or fear of retaliation.
  • Segment by complainant type (employee, intern, contractor, vendor) and by channel (ICC direct, SHe-Box, manager, ethics hotline).

Need this operationalised? A digital complaint register / ticketing tool turns this from a manually-updated spreadsheet into a live, auditable system that segments by type and channel automatically. Book a call with us to see it set up for your organisation.

Ageing Analysis

This is the single most predictive metric for litigation risk, and the one most boards never see. Every open case should be tracked against the 90-day statutory deadline using a simple traffic-light band:

BandDay RangeWhat It Means
🟢 GREEN Day 0–60On track — comfortably within the 90-day window.
🟡 AMBERDay 61–90Approaching the deadline — needs active monitoring, not just logging.
🔴 REDDay 90+ / at serious riskDeadline breached or about to breach — escalate immediately.

Also separate “time in inquiry” from “time waiting for employer action after the report” the 60-day window under Section 13(4). Boards often assume the ICC is the bottleneck; frequently it’s the employer’s own action step that stalls.

What to do when a case enters the red band:

  • Escalate to the Audit Committee Chair or Board Chair the same week, don’t wait for the quarterly cycle.
  • Get a written reason for the delay from the ICC (evidence complexity, unavailable witness, respondent non-cooperation) and log it this record protects the company if the finding is later challenged.
  • If the delay is on the employer’s side (post-report, within the 60-day action window), identify the specific approval bottleneck and assign a named owner to clear it within a week.

Repeat Offenders and Pattern Tracking

A single unsubstantiated complaint tells you very little. Three complaints against the same individual, across different complainants or teams, tells you a great deal and individual case files, reviewed one at a time, will never surface.

  • This requires a person-level view across cases, not just a case-level log.
  • Ask directly: does your system aggregate by respondent across locations, or does each establishment’s ICC only see its own local history?
  • Multi-establishment organisations often discover, only after a serious incident, that the same individual had unresolved informal complaints in two different offices nobody had connected.

What the company should actually do once a repeat pattern is flagged:

  • Treat the pattern itself as a fresh trigger for review even if no single complaint was individually substantiated, a documented pattern across multiple independent complainants is material and should go to the Audit Committee, not sit in HR.
  • Consider interim measures (reassignment, restricted access to certain teams, heightened supervision) while the current complaint is inquired into, independent of the outcome of past cases.
  • Loop in legal and compliance to assess whether disciplinary action under service rules is warranted on the pattern itself, not only on the outcome of the most recent case.
  • Document the pattern review formally if this individual is later promoted, exited, or involved in another matter, this record needs to exist and be findable.

Training Completion Rates

Track two separate numbers they answer different questions:

  • General employee sensitisation completion a compliance metric tied to Section 19.
  • ICC member skill-building/orientation completion a capability metric tied to inquiry quality and defensibility.
  • Segment both by business unit and seniority and low completion concentrated in senior leadership is a governance red flag in itself.

What to do when leadership training completion lags:

  • Make it non-optional by tying completion to a visible gate promotion eligibility, performance review sign-off, or board committee membership renewal.
  • Report leadership-specific completion separately to the board don’t let a high blended average hide a senior-leadership gap.
  • Set a hard remediation deadline (e.g., one quarter) with named individual follow-up, not a generic reminder email.

Business Unit and Location Trends

Aggregate complaint volume, ageing, and repeat-offender data by business unit, function, and geography. Spotting that one plant, region, or business line generates a disproportionate share of complaints relative to headcount is exactly what a single annual summary buries and a segmented dashboard reveals.

A sample structure for the dashboard itself:

MetricThis QuarterPrior QuarterYoY TrendFlag
Total complaints filed
Cases in red-band ageing
Repeat-respondent cases (2+ prior)
General training completion %
ICC member training completion %
Business units above average rate

Legal POV: A dashboard is also a discoverable document. One that shows the board actively identifying and acting on red flags is strong evidence of good governance in litigation. One that shows ignored red-band ageing over several quarters can become the opposing side’s strongest exhibit.

21. Litigation Risk

Most POSH litigation risk doesn’t come from the underlying allegation; it comes from procedural failures: a delayed inquiry, an improperly constituted committee, a conflicted decision-maker, or visible retaliation. Think of litigation risk here primarily as a process-integrity risk.

High-Profile Complaints

Flag any complaint likely to attract media or social attention to the board and general counsel immediately independent of where it sits in the normal ICC timeline.

  •  Resist the instinct to manage the story before managing the process the inquiry must run on its own statutory timeline regardless of external pressure.
  • Separate who holds pen on any public statement from anyone with a role in the ICC’s substantive findings (Section 6.3).

Complaints Against the CEO

This is the scenario most governance structures are least prepared for; the CEO typically sits atop every internal reporting line the ICC would otherwise rely on. A pre-agreed protocol should look like this:

Complaint Received   →   External IC Member Leads   →   CEO Recused from HR/Legal/Comms Resourcing   →   Board Approves Interim Measures   →   Independent Investigation Runs

Decide in advance whether governance documents require the CEO to step back from operational duties during the inquiry, and who exercises delegated authority in that period deciding this under media pressure, in the moment, is far riskier.

Complaints Against Founders

Founder-led companies carry a distinct risk: founders often hold outsized influence over HR, board composition, and culture even after formal governance exists, and employees may reasonably fear career risk in reporting against one.

  • The key governance decision: does the ICC’s external member (and at least one internal member) have an independent escalation path to the board, or to the District Officer, that doesn’t require founder sign-off at any stage?
  • Investor and enterprise-client due diligence increasingly probes this exact scenario; it’s now a common data-room request, not a hypothetical.

Legal POV: Where the respondent is the employer, or someone whose seniority creates an unavoidable conflict, the Act itself provides a release valve: the complaint can go to the Local Committee, or via SHe-Box for an independent inquiry outside the company’s control. Never structure governance in a way that discourages employees from using this route.

22. Regulatory Risk

Regulatory risk here has moved fast in the last eighteen months from “file a report once a year” to “your board is personally implicated in getting these numbers right.”

MCA Disclosures

Following the MCA notification effective July 2025, POSH disclosure inside the Board’s Report is now mandatory and standardised typically confirming ICC constitution, complaints received and disposed of, and cases pending beyond statutory timelines.

Build the MCA disclosure and the Section 21 filing off the same underlying dataset, reconciled at the same time, so the two documents don’t quietly drift apart from each other year over year.

Annual Reports (Section 21 and Section 22)

  • Section 21 is the ICC’s own filing to the employer and District Officer.
  • Section 22 is the employer’s separate reporting duty, now embedded inside the Board’s Report for Companies Act entities.
  • A perfect Section 21 filing doesn’t protect you if nobody separately confirmed the Section 22 disclosure made it into the Board’s Report; these are two obligations with accountability in two different places.

Legal POV: A zero-complaint year still requires a filed “Nil Report.” Not filing because “there was nothing to report” is itself a compliance default, one of the more common gaps that surfaces in district-wise audits.

ESG and BRSR Reporting

For listed companies, BRSR under SEBI’s LODR framework increasingly captures workplace harassment metrics under the “Social” pillar, a second external audience (investors, ESG rating agencies) reading the same data through a very different lens than a labour inspector does.

Agree the narrative framing for these numbers externally, in advance rising complaint volume as a sign of trust in reporting channels, for instance so the story isn’t being improvised for the first time in front of a rating agency.

23. Reputation Management

A POSH matter that goes public is functionally two simultaneous crises: the legal process, which must run on its own timeline, and the public narrative, which runs on a much faster clock. Confusing the two is where most reputational damage compounds.

Media Handling

  • Decide in advance who is authorised to speak to the media on any POSH matter.
  • Confidentiality under Section 16 applies regardless of media pressure confirming or denying specifics of a live inquiry can itself be a breach.
  • Safest public position: confirm a process exists and is being followed, without engaging on facts, names, or findings while the inquiry is live.

Social Media

  • Social media compresses the crisis timeline from days to hours.
  • Monitor mentions in real time once a matter is public, but resists responding point-by-point to every post that often escalates visibility rather than containing it.

Crisis Communication Protocol

Build this before it’s needed. At minimum:

  • A small cross-functional sign-off group legal, communications lead, and a board representative for CEO/founder-level matters.
  • A pre-approved holding statement template that can be adapted quickly without fresh legal sign-off on every word.
  •  An explicit rule: the people managing the public narrative are never the same people who can influence, or appear to influence, the ICC’s findings.

Legal POV: A company publicly reassuring investors about “no merit” to a complaint while the inquiry is still open has effectively pre-judged the outcome in public very hard to walk back if the ICC’s actual findings differ.

24. Data Governance

POSH case data is among the most sensitive data any organisation holds. Data governance here is core to the confidentiality obligation the Act itself imposes, not a side issue. Please refer section 10 (The DPDP Act, 2023: Best practices for handling digital evidence during a POSH inquiry)

Legal POV: A Section 16 breach by a board member who receives case detail through a board pack is treated the same as a breach by an ICC member or HR independently punishable. Handle POSH board packs with the same discipline as any privileged board material.

25. Insurance

Two distinct policies matter here, covering different people and different exposures confusing them leaves real gaps.

 EPLID&O
What it coversHarassment, discrimination, and wrongful-termination claims brought by employees against the companyClaims against directors/officers personally for alleged wrongful acts in their governance capacity
Who it protectsThe company (and often named individuals as an extension)Directors and officers, personally
Relevant scenario hereThe underlying harassment claim itselfA shareholder/investor/regulator alleging the board failed in its oversight duty (Section 2.1) over how a matter was handled
Common gap to checkSub-limits or exclusions on certain harassment categories; coverage for senior-executive respondentsWhether it responds when an EPLI claim escalates into a governance-failure claim

Legal POV: EPLI and D&O are often underwritten by different desks at different insurers, and the handoff between them, say, a CEO harassment complaint that becomes a shareholder derivative suit about board oversight is exactly where coverage gaps get discovered, usually at the worst possible moment. Have general counsel and risk management review both policies together, specifically for this handoff scenario.

26. Audit

Audit is where governance intent gets tested against operational reality. A board can have excellent policy language, a dashboard, and clear RACI ownership, and still discover only through audit that none of it is being followed consistently at establishment level.

Internal Audit

POSH compliance should sit inside the internal audit function’s regular rotation. Useful scope:

  • ICC constitution validity and tenure at every establishment, not just headquarters.
  • Consistency between what the dashboard reports and what underlying case files actually show.
  • Whether escalation triggers (Section 2.2) were actually followed for any qualifying case in the audit period.
  • Whether SHe-Box onboarding and annual filings are current across every jurisdiction and district.

Report findings to the Audit Committee with the same rigor as financial control findings including a formal remediation timeline and follow-up verification, not a finding logged and left open indefinitely.

Third-Party / External Audit

An independent audit distinct from internal audit and the statutory district-officer inspection is increasingly a data-room expectation in M&A and investor due diligence, and in enterprise-client vendor onboarding.

  • Scope it specifically to test what internal audit is structurally less able to probe objectively: whether informal complaints against senior leaders were ever properly escalated, whether HR or legal influenced ICC findings, and whether confidentiality has actually held in practice.


Legal POV: In M&A, an acquirer inheriting a target’s employees also inherits its POSH liabilities, pending cases, and more subtly its governance failures. A target with informally suppressed complaints represents undisclosed liability that standard financial due diligence won’t surface.

27. What This Conversation Usually Misses

A few things that rarely make it into board-level POSH conversations, but should:

ICC External Member Succession

Boards plan CEO succession as a matter of course, but rarely plan for an ICC external member becoming unavailable mid-case. Build a documented bench of pre-vetted external members before you need one.

Executive Exit and Severance Screening

Screen severance and exit agreements explicitly against any pending or recently resolved POSH matters; a non-disparagement clause that inadvertently conflicts with a complainant’s or witness’s Section 16 rights is a risk that rarely gets flagged in isolation.

Board’s Own Training

Employee and ICC training gets tracked (Section 3.4); board-level training on POSH governance almost never does. A board never briefed on its own oversight obligations is poorly positioned when a real case reaches its level.

Whistleblower / Ethics Hotline Integration Governance

This deserves board-level attention in its own right: a documented, tested protocol for how a complaint arriving through the ethics hotline gets identified and re-routed into the formal POSH process without losing time against the 90-day clock.

Investor and Proxy Advisor Scrutiny

Proxy advisors (ISS, Glass Lewis, and Indian equivalents) increasingly ask specific governance questions about harassment oversight during AGM season. A board unable to answer basic questions here is exposed to a governance-quality challenge unrelated to any specific case.

Business Continuity for the ICC Itself

What happens to a live inquiry if the Presiding Officer resigns or goes on extended leave mid-case? Most organisations have no documented continuity plan for the committee’s own membership, exactly the kind of procedural fragility that gets a finding challenged on appeal.

28. A Board-Level POSH Governance Maturity Checklist – With Fixes

A quick self-assessment. Where the honest answer is “no,” the fix column is your starting point, not a reason to leave it for next year.

Does the board review a quarterly, segmented dashboard, not an annual summary?

Start with a simple spreadsheet tracker covering the 5 metrics in Section 3 and put it on next quarter’s Audit Committee agenda.


Is there a board-approved protocol for CEO/founder/board-member complaints?

Draft a one-page protocol now external-member-led escalation and recusal rules and get board sign-off before it’s ever needed.


Are the Section 21 report and Board’s Report/MCA disclosure built from the same dataset?

Assign one owner (CHRO or Company Secretary) to maintain a single master case log both filings pull from.


Is there a tested crisis communication protocol?

Build a one-page holding statement template and a named sign-off chain now, before a real incident.


Does a country-specific annexure exist for every jurisdiction you operate in?

Start with your largest non-India location, draft a one-page annexure, and expand jurisdiction by jurisdiction.


Have data governance and legal jointly reviewed retention, security, and anonymisation?

Schedule one joint meeting between HR, Legal, and IT security to document current practice as a baseline.


Have EPLI and D&O been reviewed together for the handoff scenario?

Ask your broker, in writing, how both policies respond to one combined scenario e.g. a CEO complaint becoming a shareholder claim.


Has an independent third-party POSH audit run in the last 24 months?

Commission a scoped, limited first audit 2–3 establishments rather than waiting to budget for a full review.


Is there a documented bench of external ICC members and an ICC continuity plan?

Ask your current external member for 1–2 backup referrals now, and write a one-paragraph succession note for the Presiding Officer role.


Has the board been briefed on its own POSH oversight obligations in the last 12 months?

Add a 30-minute briefing to the next board or Audit Committee meeting — this document can serve as the base material.


None of this replaces good HR execution at the ground level; the layers, templates, and operational detail covered elsewhere in this series still matter enormously. What this adds is the governance layer above it: the structure that ensures the board finds out about a systemic problem from its own dashboard, months before it would otherwise find out from a headline.

Part VIII. Additional Resources

29. Frequently Asked Questions

30. Work With The HR Fix

End-to-End POSH Compliance, from first-time ICC setup to board-level governance.

If You’re a Founder or Employer

Policy drafting & implementation, ICC constitution & setup, SHe-Box onboarding, External ICC Member services, Annual Report filing

If You’re HR or Compliance

ICC member training, POSH compliance audits (internal & third-party), complaint register & case management, ready-to-use policy and inquiry templates

If You’re on the Board or a CHRO

Quarterly dashboard setup, governance maturity review, board & leadership briefings

If You’re an Employee

1:1 confidential consultation, complaint filing support, respondent representation support

Subreddits to follow

• r/india • u/The_HR_Fix • r/legaladviceindia • r/jobsearch • r/cscareerquestions • r/recruitinghell • r/resumes • r/consulting •r/workplaceissues • r/EmploymentLaw • r/careeradvice •r/WomenInIndia

31. References

  1. Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013
  2. Supreme Court Judgment: Vishaka and Others v. State of Rajasthan (1997)
  3. Supreme Court Judgment: Aureliano Fernandes v. State of Goa (2023)
  4. Ministry of Women and Child Development – SHe-Box Portal Guidelines
  5. Department of Personnel & Training (DoPT) POSH Office Memorandums

This blog takes a lot of research to keep current. If it helped you, you can buy me a coffee here ☕

Leave a Comment

Scroll to Top