Skip to content

Compliance Management, Audit and Due Diligence · Compliance Framework

Compliance Framework and Compliance Policy in a Company

Updated 11 October 2026 · Fact-checked

A compliance framework is the structured system a company uses to meet the laws, rules and internal standards that apply to it. Its core elements are a board-approved compliance policy, defined roles, written procedures, monitoring and testing, reporting, training and corrective action. In exams, name each element and apply it to the facts.

Understand Compliance Framework and Compliance Policy

Compliance means acting in line with the laws, regulations, standards and internal rules that bind a company. A company faces many such obligations: the Companies Act, 2013, SEBI rules for listed companies, FEMA, tax and labour laws, and its own code of conduct. Missing one can bring penalties, prosecution or loss of reputation.

A compliance framework turns this duty into a system. Without it, compliance depends on individuals remembering deadlines. With it, the company knows who owns each obligation, how it is done, how it is checked and who is told when something goes wrong.

The compliance policy is the starting document. The board approves it. It states the company's commitment to comply, its scope (which laws and which people), the roles and responsibilities, the reporting channels, and the consequences of breach. It sets the tone from the top. Procedures, checklists and calendars sit below it and make it operational.

A good framework works as a cycle: identify obligations, assign owners, document procedures, carry them out, monitor and test, report to management and board, then correct and improve. Each step feeds the next. Exam answers score well when they show this cycle and tie it to the company in the question.

The Company Secretary usually acts as the compliance anchor, since the CS is a key managerial personnel in many companies and is responsible for ensuring the company complies with applicable laws. Still, the board is ultimately accountable, and each department head owns the compliance of their own area.

Key rules to remember

Elements of a compliance framework
Policy + Roles + Procedures + Monitoring + Reporting + Training + Corrective action
Use this as your answer skeleton. Add a line on each element and link it to the facts.
Compliance cycle
Identify obligations → Assign owners → Document procedures → Execute → Monitor and test → Report → Correct and improve
It is a loop. Findings from monitoring feed back into the obligations register and procedures.
Contents of a compliance policy
Objective + Scope + Roles and responsibilities + Procedures + Reporting and escalation + Consequences of breach + Review
The board approves the policy and reviews it periodically.
Three lines of responsibility
Operating units (own it) → Compliance function (guide and monitor) → Independent assurance (internal and secretarial audit)
A common way to explain division of roles. It is a model, not a statutory requirement.

How to solve Compliance Framework and Compliance Policy questions

Use this method for any question on designing, reviewing or explaining a compliance framework or policy.

  1. 1Read the facts and list the laws and obligations that apply to the company (its type, size, listing status, activities).
  2. 2State what a compliance framework is and why the company needs one, in one or two lines.
  3. 3Set out the elements in order: policy, roles, procedures, monitoring, reporting, training, corrective action.
  4. 4For each element, apply it to the facts. Name who does what, such as the board, CS, department heads and internal auditor.
  5. 5Spot the gap in the facts, such as no owner, no calendar, no escalation or no testing, and say how to fix it.
  6. 6Add practical drafting points: approval by board resolution, periodic review, records kept, and a compliance certificate.
  7. 7Conclude with a clear recommendation or the answer to the exact question asked.

Quickest way: PRPMR-TC answer skeleton

When to use it: Use it when time is short or the question asks you to list or explain elements of a framework.

  1. Write Policy, Roles, Procedures, Monitoring, Reporting, Training, Corrective action as seven short headings.
  2. Under each, write one sentence of meaning and one of application to the facts.
  3. Underline the gap in the case facts and write the fix.
  4. Close with the board's overall accountability and the CS's coordinating role.

Common mistakes in Compliance Framework and Compliance Policy

  • Treating the compliance policy and the framework as the same thing.

    Both words appear together in the chapter title and notes blur them.

    Fix: Say the policy is one element, the board-approved statement of commitment. The framework is the whole system around it.

  • Listing elements without applying them to the facts.

    Students memorise lists and skip the case analysis the paper rewards.

    Fix: After each element, add a sentence tied to the company in the question: its size, sector and the gap you see.

  • Saying the Company Secretary alone is responsible for all compliance.

    The CS is closely linked to compliance, so students overstate the role.

    Fix: Say the board is accountable, department heads own their areas, and the CS coordinates, advises and monitors.

  • Leaving out monitoring and corrective action.

    Students stop at policy and procedures because they feel like the 'design' part.

    Fix: Always include testing, reporting of breaches, root-cause analysis and updates to procedures.

  • Quoting section numbers from memory for framework features.

    The wish to look precise leads to wrong citations.

    Fix: Cite a section only when sure of it. A framework is largely good practice, so explain the principle in plain words.

Worked examples

Example 1

Sundaram Textiles Ltd, an unlisted public company in Coimbatore, has missed two ROC filing deadlines this year. Filing dates are tracked informally by one accounts executive. Advise the board on the framework it should put in place.

Show the solution
  1. Identify the gap: no owner, no calendar, no procedure, no monitoring and no escalation. Compliance depends on one person's memory.
  2. Policy: the board should approve a written compliance policy stating its commitment to comply, its scope and the consequences of breach.
  3. Roles: the board is accountable. The Company Secretary coordinates and maintains the compliance calendar. Each department head owns inputs for their area.
  4. Procedures: prepare a register of applicable laws, a calendar of due dates with internal deadlines earlier than statutory ones, and checklists for each filing.
  5. Monitoring: the CS reviews the calendar regularly and internal or secretarial audit tests it independently.
  6. Reporting: a periodic compliance report goes to the board or audit committee, with any delay and its reason, and a prompt escalation route for imminent defaults.
  7. Corrective action and training: find the cause of the two delays, fix the process, train the staff, and review the policy annually.

Answer: The board should adopt a written compliance policy and build a framework of defined owners, a law register and compliance calendar, checklists, regular monitoring by the CS, periodic board reporting, training and corrective action, replacing the informal tracking that caused the delays.

Example 2

List the contents of a compliance policy and explain who approves it and why periodic review is needed.

Show the solution
  1. Define the policy: a board-level statement of the company's commitment to comply with applicable laws and internal standards.
  2. Contents: objective, scope covering laws and persons, roles and responsibilities, procedures to follow, reporting and escalation channels, consequences of breach, and review mechanism.
  3. Approval: the board approves it, because the board is accountable for compliance and the policy sets the tone from the top.
  4. Review: laws, business activities and risks change. An outdated policy leaves new obligations unowned.
  5. Practical point: record approval by board resolution, circulate the policy to all employees and keep acknowledgements.

Answer: A compliance policy contains objective, scope, roles, procedures, reporting and escalation, consequences of breach and review. The board approves it, and it must be reviewed periodically so it keeps pace with changes in law and business.

Exam tips

  • Use a fixed skeleton of policy, roles, procedures, monitoring, reporting, training and corrective action, then apply each to the case facts.
  • In case questions, point out the specific gap and give a practical fix such as a calendar, owner or escalation route.
  • Show the board as accountable and the CS as coordinator, not sole owner of compliance.
  • Mention drafting points: board resolution, periodic review, records and compliance certificates.
  • Keep answers structured with short headings so the examiner can find each element quickly.

Practice questions from Compliance Framework

Compliance Framework and Compliance Policy: frequently asked questions

What are the main elements of a compliance framework?

The main elements are a board-approved compliance policy, defined roles and responsibilities, written procedures, monitoring and testing, reporting, training and corrective action. Present them as a cycle rather than a simple list.

Who is responsible for compliance in a company?

The board is ultimately accountable. Department heads own compliance in their areas, and the Company Secretary coordinates, advises and monitors. Independent assurance comes from internal and secretarial audit.

What should a compliance policy contain?

It should state the objective, scope, roles, procedures, reporting and escalation channels, consequences of breach and the review process. The board should approve it by resolution.

Is a compliance framework required by law?

Specific laws require specific compliances and certain officers or committees. A complete framework as described here is largely good governance practice. Do not claim a single section prescribes it unless you are sure.