POSH Act Compliance for Enterprises: ICC Setup & Annual Report Filing

POSH Act Compliance

A mid-size IT company had an Internal Complaints Committee on paper. Its Presiding Officer had left the organisation eight months earlier, and nobody had reconstituted the committee. When a complaint was filed, the entire inquiry was challenged on the basis of improper constitution, the proceedings were invalidated, and the employer received a show-cause notice from the District Officer. This is not an isolated case. Across India, many organisations have a POSH policy and an Internal Complaints Committee that exist only on paper, and as of 2025 to 2026, that gap has become a serious legal and compliance risk, not merely a procedural formality.

The Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013 applies to every Indian workplace with 10 or more employees, and a significant regulatory change in 2025 has made POSH Act compliance a matter of direct board-level accountability, not just an HR function’s internal responsibility. This guide covers how enterprises should set up and maintain a compliant Internal Committee, the statutory timelines governing complaint handling, and the annual reporting obligations now extending into corporate board disclosures.

What POSH ACT Compliance Requires: The Baseline

POSH compliance applies to every Indian workplace with 10 or more employees, regardless of whether any women are currently on the organisation’s rolls. The core obligations span constitution of a compliant Internal Committee, a written POSH policy, mandatory training and sensitisation, defined complaint and inquiry procedures, and annual reporting, each with its own specific requirements.

Internal Committee Constitution: Getting the Structure Right

Under Section 4 of the POSH Act, every applicable workplace must constitute an Internal Committee, commonly abbreviated as ICC or IC, with a specific, mandatory composition.

Minimum four members. The Committee must have at least four members in total.

At least 50% women. At least half of the Committee’s members must be women, and the Presiding Officer specifically must be a woman employed at a senior level within the organisation.

One external member. The Committee must include at least one external member from an NGO or an organisation committed to the cause of women, or someone with relevant legal or social work background, brought in specifically to bring independence and expertise the internal members may not have.

A maximum three-year term. Committee members serve fixed terms, and the Committee needs to be actively reconstituted before that term expires, not allowed to continue informally past its legal tenure.

The consequence of getting this structure wrong, or allowing it to lapse without reconstitution, is not a minor technicality. As the mid-size IT company example illustrates, an improperly constituted Committee, including one where a key member such as the Presiding Officer has departed without replacement, can result in an entire inquiry being challenged and invalidated after the fact, precisely when the organisation most needs the process to hold up under scrutiny.

The Statutory Inquiry Timeline

Once a complaint is received, the POSH Act imposes a strict, defined sequence of timelines that the Internal Committee must follow.

7 days to send the complaint to the respondent after it is received.

90 days to complete the inquiry from the date the complaint was filed.

10 days after the inquiry concludes to issue the Committee’s report.

60 days for the employer to act on the Committee’s recommendations once the report is issued.

Where a complainant has a legitimate reason for delay in filing, the Internal Committee can condone that delay by up to three months under the current framework, though this discretion should be exercised and documented carefully rather than applied informally.

Confidentiality obligations under Section 16 of the Act apply throughout this entire process. Leaks of complaint details, the identity of parties involved, or inquiry proceedings can themselves trigger penalties and can derail the fairness of the process, which is why maintaining strict, documented confidentiality controls around every stage of a live inquiry is as important as meeting the procedural timelines themselves.

Annual Report Filing: What Changed and What Is Required

Under Section 21 of the POSH Act, every Internal Committee must submit an annual report to the employer and to the District Officer, typically the District Magistrate for the relevant jurisdiction, detailing the complaints received, resolved, and pending during the year, along with the actions taken.

Timing. The annual report covers the calendar year from 1 January to 31 December, and organisations are generally expected to file before 31 January of the following year, since the report summarises the Internal Committee’s activity for the calendar year just completed.

Filing method. Two routes are typically available: hand-delivering one signed original to the District Officer and obtaining a stamped duplicate as proof of submission, or sending it via Registered Post with Acknowledgment Due. The postal receipt or stamped duplicate should be retained indefinitely, since it is generally the organisation’s only concrete proof of timely filing if that filing is ever questioned later. While the government’s SheBox portal is being progressively upgraded for digital filing in specific states, hard-copy or registered post submission remains the more reliable route in most districts as of the current filing cycle.

The 2025 Change That Makes This a Board-Level Issue

In May 2025, the Ministry of Corporate Affairs notified the Companies (Accounts) Second Amendment Rules, 2025, effective from 14 July 2025, fundamentally expanding who must formally disclose POSH compliance and where that disclosure sits. Previously, detailed POSH disclosure within the Board’s Report under Rule 8(5)(x) applied mainly to listed companies or larger companies specifically, leaving many unlisted companies and MSME entities effectively outside formal, mandatory board-level reporting.

Under the amended rules, every company other than One Person Companies and Small Companies must now disclose, within its Board’s Report (submitted via the revised e-Form AOC-4), the number of sexual harassment complaints received, disposed of, and pending beyond 90 days, along with an explicit confirmation that a compliant Internal Committee has actually been constituted.

The practical effect of this change is significant: this is the same underlying data as the Internal Committee’s Annual Report, but it now also lives inside a corporate disclosure document that auditors, lenders, and the Registrar of Companies all read directly. A logistics firm with 38 employees received a Section 134 show-cause notice from the MCA after its Board’s Report for the relevant financial year made no mention of POSH compliance at all, with the company’s director reportedly unaware that this specific disclosure requirement had become mandatory from 14 July 2025.

Any enterprise that has crossed the 10-employee threshold and has not actively revisited its POSH documentation since its Internal Committee was originally constituted should treat this specifically as an immediate compliance review priority, not a routine annual task to be addressed whenever convenient.

Penalties for Non-Compliance

Failure to file the annual report on time, improper constitution of the Internal Committee, or neglect of statutory duties under Section 26 of the POSH Act can result in fines of up to ₹50,000 for the initial violation. Repeated violations can lead to increased fines and, in more serious or persistent cases, cancellation of business licences or registrations. Beyond these direct statutory penalties, non-compliance under the 2025 board reporting rules specifically now also carries exposure under Section 134 of the Companies Act, 2013, as the logistics firm example illustrates, layering corporate governance consequences on top of the POSH Act’s own penalty framework.

Beyond direct financial and regulatory penalties, non-compliance carries real reputational and operational risk: employee trust erodes when a workplace’s stated commitment to a safe environment is not backed by a genuinely functioning process, and organisations discover compliance gaps most often only after a complaint has already been filed and the inquiry itself becomes the point at which the underlying gap surfaces and is challenged.

A Practical POSH Compliance Checklist for Enterprises

Constitute or reconstitute the Internal Committee correctly. Confirm the current Committee meets the minimum four-member, 50% women, external member, and three-year term requirements, and specifically verify that no member, particularly the Presiding Officer, has departed the organisation without formal replacement.

Draft and disseminate a clear, written POSH policy. The policy should define sexual harassment consistent with the Act, set out the complaint mechanism, and be genuinely accessible to all employees, not simply filed away in an onboarding document nobody revisits.

Register the Internal Committee where locally required. Some states and jurisdictions require registration through the SheBox portal or equivalent local mechanisms; this should be confirmed against the specific requirements applicable to each of the organisation’s operating locations.

Conduct regular sensitisation and training. Annual training for all employees, and specific training for Internal Committee members, is treated as essential for both genuine workplace safety and for compliance audit readiness.

Establish and maintain confidential complaint mechanisms. These need to be genuinely accessible and genuinely confidential in practice, not merely described as such in policy documents.

Follow the statutory inquiry timeline precisely for every complaint received. The 7-day, 90-day, 10-day, and 60-day sequence should be tracked actively for each live matter, not managed informally or left to institutional memory.

File the Annual Report to the District Officer by 31 January. Retain proof of filing indefinitely, whether the stamped duplicate from hand delivery or the registered post acknowledgment.

Include accurate POSH disclosures in the Board’s Report via e-Form AOC-4. This applies to every company other than One Person Companies and Small Companies, following the MCA’s Companies (Accounts) Second Amendment Rules, 2025, effective 14 July 2025.

Managing POSH Compliance at Enterprise Scale

For enterprises operating across multiple locations, business units, or subsidiary entities, each requiring its own compliant Internal Committee, tracking constitution status, member terms, inquiry timelines, and annual filing deadlines through informal, HR-team-specific processes creates real risk of exactly the kind of lapse the mid-size IT company example illustrates: a Committee that quietly becomes non-compliant simply because nobody was tracking a departed member’s replacement systematically.

Legistify’s compliance management capabilities support enterprises managing POSH obligations across multiple entities and locations, with tracked Internal Committee tenure and composition, automated alerts ahead of the annual filing deadline and Committee reconstitution dates, and a centralised record connecting POSH compliance status to the broader corporate governance and board reporting obligations that now depend directly on it under the 2025 MCA rules.

Conclusion

POSH compliance in India has moved decisively from an HR administrative task to a genuine corporate governance obligation, with the 2025 Companies (Accounts) Second Amendment Rules extending POSH disclosure directly into the Board’s Report for the vast majority of Indian companies. Enterprises need to treat Internal Committee constitution, statutory inquiry timelines, and annual report filing with the same discipline applied to any other board-level compliance obligation, since a lapsed committee or a missed disclosure is no longer simply an internal HR gap, it is a documented exposure that auditors, lenders, and the Registrar of Companies can now see directly.

Frequently Asked Questions

Which organisations need to comply with the POSH Act in India?

Every Indian workplace with 10 or more employees must comply with the POSH Act, 2013, including constituting an Internal Committee, adopting a written policy, and filing annual reports, regardless of whether the organisation currently has any women employees on its rolls.

What is the required composition of an Internal Committee under the POSH Act?

The Internal Committee must have at least four members, with at least 50% being women, a Presiding Officer who is a senior-level woman employee, and at least one external member from an NGO or with relevant legal or social work background. Members serve a maximum term of three years, after which the Committee must be actively reconstituted.

What is the statutory timeline for handling a POSH complaint?

The complaint must be sent to the respondent within 7 days of receipt, the inquiry must be completed within 90 days, the Committee’s report must be issued within 10 days of the inquiry concluding, and the employer must act on the recommendations within 60 days of the report being issued.

When is the POSH Act’s annual report due, and to whom?

The Internal Committee’s annual report, covering the calendar year from 1 January to 31 December, must be filed with the employer and the District Officer, generally by 31 January of the following year. It can be filed by hand delivery (obtaining a stamped duplicate) or by Registered Post with Acknowledgment Due, and proof of filing should be retained indefinitely.

How did the 2025 MCA rules change POSH compliance obligations?

The Companies (Accounts) Second Amendment Rules, 2025, effective from 14 July 2025, require every company other than One Person Companies and Small Companies to disclose POSH compliance details, complaints received, disposed of, and pending beyond 90 days, along with confirmation that a compliant Internal Committee exists, directly within the Board’s Report via e-Form AOC-4. This extends POSH compliance from an internal HR and District Officer filing obligation into a formal corporate governance disclosure that auditors, lenders, and the Registrar of Companies can review directly.

Leave a Comment

Your email address will not be published. Required fields are marked *