Compliance Management and Secretarial Audit
Part A of Paper 3 is this hub's most distinctly Company-Secretary-exclusive statutory function — secretarial audit is a certification only a Company Secretary in practice can give, and the compliance-management framework around it is where a Professional-level Company Secretary spends much of their actual practice. Getting the applicability thresholds and the current procedural requirements precisely right matters more here than almost anywhere else on this syllabus, since this content maps directly onto real professional certification work.
1. Compliance management framework
A well-run compliance function is risk-based rather than a flat, undifferentiated checklist — it identifies which regulatory obligations carry the highest consequence of failure (listing obligations, tax filings, labour-law compliance, sector-specific licensing) and allocates monitoring effort accordingly, rather than treating every compliance item as equally urgent.
A Company Secretary in an in-house compliance role typically maintains a compliance calendar, tracks filing deadlines across every applicable statute, and escalates emerging risks to the Board or Audit Committee before they crystallise into an actual violation.
2. Secretarial Audit under Section 204
Section 204 of the Companies Act, read with Rule 9 of the Companies (Appointment and Remuneration of Managerial Personnel) Rules, 2014, makes secretarial audit mandatory for a defined population of companies — and the exact list is worth learning precisely, since it is wider than many candidates initially assume.
| Category | Threshold |
|---|---|
| Every listed company | No size threshold — mandatory regardless of scale (including a listed private company that has listed only debt securities) |
| Every public company | Paid-up share capital of ₹50 crore or more |
| Every public company | Turnover of ₹250 crore or more |
| Every company (including private) | Outstanding loans or borrowings from banks or public financial institutions of ₹100 crore or more |
The last row is the one candidates most frequently overlook: secretarial audit extends even to a private company, purely on the basis of its bank/PFI borrowing crossing ₹100 crore, regardless of whether that company is listed or meets any of the other size thresholds. All these thresholds are assessed as on the last date of the latest audited financial statements.
The secretarial auditor's report is prepared in Form MR-3, and is annexed to the company's Board's Report — making it a document that reaches shareholders and the wider public alongside the company's annual financial disclosures, not a purely internal compliance record.
3. Annual Secretarial Compliance Report (LODR Regulation 24A)
A separate, broader requirement applies specifically to listed entities: the Annual Secretarial Compliance Report under LODR Regulation 24A, covering compliance specifically with SEBI's own regulations and circulars, distinct in scope from Section 204's secretarial audit, which covers compliance with all applicable laws generally.
Because this requirement is tied to listing status rather than Section 204's size/borrowing thresholds, it reaches every listed entity — a wider population than the secretarial-audit-mandatory group, since a small listed company below Section 204's public-company thresholds could still be swept in purely by virtue of being listed.
The report must be filed with the stock exchanges in XBRL format within 60 days of the financial year's end. A recent, precisely dateable tightening: with effect from 1 April 2025, this report must be signed only by the Secretarial Auditor or by a Peer Reviewed Company Secretary — a specific professional-qualification restriction worth stating exactly, since it is a genuinely recent change from the previously broader signing eligibility.
4. ICSI Auditing Standards
ICSI has issued a defined set of Auditing Standards governing how secretarial audit (and other CS-conducted audits) must actually be performed, and knowing their names and scope precisely is directly examinable.
| Standard | Scope |
|---|---|
| CSAS-1 | Audit Engagement — the terms and acceptance of an audit assignment |
| CSAS-2 | Audit Process and Documentation |
| CSAS-3 | Forming of Opinion |
| CSAS-4 | Secretarial Audit specifically |
These standards became effective on 1 July 2019 on a recommendatory basis, and were made mandatory for all audit engagements conducted under any statute with effect from 1 April 2021 — a two-stage rollout (recommendatory, then mandatory) worth stating precisely if a question asks about their current binding status.
Worked Examples
Example 1. A private company (not listed) has a paid-up share capital of ₹30 crore, a turnover of ₹150 crore, and outstanding borrowings from a public financial institution of ₹120 crore. Is this company required to undergo a secretarial audit under Section 204?
Yes — even though it is private and falls below both the ₹50 crore paid-up-capital and ₹250 crore turnover thresholds that apply to public companies, its ₹120 crore borrowing from a public financial institution exceeds the ₹100 crore threshold that independently extends secretarial audit to any company, including a private one.
Example 2. A small listed company has a paid-up share capital of only ₹10 crore and a turnover of ₹80 crore — both well below the public-company size thresholds. Is it required to undergo secretarial audit?
Yes — every listed company is required to undergo secretarial audit under Section 204 regardless of size; the ₹50 crore and ₹250 crore thresholds apply only to public companies that are not listed.
Example 3. In which form is the secretarial auditor's report prepared, and where is it disclosed?
Form MR-3, annexed to the company's Board's Report — making it publicly disclosed alongside the company's annual report, not merely retained internally.
Example 4. A listed company's Annual Secretarial Compliance Report for the financial year is signed by an in-house Company Secretary who is neither the company's Secretarial Auditor nor a Peer Reviewed Company Secretary. Does this comply with the current requirement?
No — with effect from 1 April 2025, the Annual Secretarial Compliance Report must be signed only by the Secretarial Auditor or by a Peer Reviewed Company Secretary; an in-house Company Secretary who does not hold either of these specific qualifications does not satisfy the current signing requirement.
Example 5. By when must a listed entity file its Annual Secretarial Compliance Report after its financial year ends, and in what format?
Within 60 days of the financial year's end, filed in XBRL format with the stock exchanges.
Example 6. A Company Secretary is drafting the terms of engagement for a new secretarial audit assignment. Which ICSI Auditing Standard specifically governs this stage of the audit?
CSAS-1 (Audit Engagement).
Example 7. Explain the two-stage timeline by which the ICSI Auditing Standards became mandatory, and what a candidate should state if asked about their current binding status.
The Auditing Standards became effective on a recommendatory basis from 1 July 2019, and were made mandatory for all audit engagements conducted under any statute with effect from 1 April 2021. A candidate asked about their current binding status should state that they are currently mandatory (since 1 April 2021), not merely recommendatory, while being able to cite the earlier 2019 date as the standards' original, softer starting point if the question specifically asks about their history.
Summary
Section 204's secretarial audit applies to every listed company regardless of size, every public company crossing ₹50 crore paid-up capital or ₹250 crore turnover, and — the most commonly overlooked category — any company (including private) with bank/PFI borrowings of ₹100 crore or more, with the resulting report prepared in Form MR-3 and annexed to the Board's Report.
The Annual Secretarial Compliance Report under LODR Regulation 24A is a separate, listing-status-triggered requirement (broader in population than Section 204's audit-mandatory group) covering SEBI-specific compliance, filed in XBRL within 60 days of financial-year-end, and — since 1 April 2025 — signable only by the Secretarial Auditor or a Peer Reviewed Company Secretary.
ICSI's four Auditing Standards (CSAS-1 through CSAS-4, covering engagement, process/documentation, opinion-forming and secretarial audit specifically) moved from recommendatory (2019) to mandatory (2021) status, and now govern how every CS-conducted audit engagement under any statute must be performed.
