Beyond Precedent
Compliances & Regulatory

The False Comfort of Tick-Box Governance

By N&Company Legal  |  Sep 24, 2026
The False Comfort of Tick-Box Governance

Corporate governance in India is at an inflexion point. Regulators, courts, and enforcement agencies are no longer satisfied with documentation that merely checks a box. The question has shifted from "Was the form filed?" to "Did the governance mechanism actually work?"

Tick-box governance refers to a compliance posture where a company or its management discharges formal obligations – filing returns, maintaining registers, passing board resolutions, appointing committees, without ensuring that these mechanisms actually function as intended risk controls. The distinction is between form and substance: formal compliance is visible, auditable, and often complete on paper; substantive compliance requires that the underlying governance objective, which is oversight, accountability, and transparency, is genuinely achieved.

Three foundational concepts define this trap.

First, form versus substance: a policy exists, but that does not mean it is followed; a committee is constituted, but that does not mean it deliberates independently.

Second, paper compliance: documentation is generated to satisfy a regulatory or audit requirement without corresponding real-world action, the classic example being KYC records collected but never verified.

Third, governance culture: systemic tick-box compliance signals an organisational culture in which the fear of a regulatory notice supersedes the goal of effective risk management. This is precisely what regulators and prosecutors now target.

Why Companies Fall Into the Tick-Box Trap

The causes are structural, not incidental. Regulatory pressure and proliferating compliance calendars like MCA filings, SEBI disclosures, and RBI returns incentivise documentation over deliberation. The goal becomes meeting deadlines, not managing risk. Audit culture demands a paper trail, creating a perverse incentive to generate the trail regardless of underlying substance, particularly where penalty exposure is linked to documentation gaps rather than control failures.

Board-level fatigue and information asymmetry compound the problem. Boards often pass resolutions to ratify management decisions already taken; formal approval replaces genuine independent scrutiny. Cost considerations lead companies to appoint nominally independent directors or constitutionally compliant committees without investing in their functional effectiveness.

Enforcement Trends: Technical Compliance Is No Defence

SEBI has consistently held in adjudication orders that compliance with the letter of the LODR Regulations does not insulate listed entities when the spirit of independent oversight is subverted – related-party transactions structured to circumvent thresholds being a key pattern. In multiple investigations, the Ministry of Corporate Affairs (MCA) and the Serious Fraud Investigation Office (SFIO) have looked beyond filed documents to assess whether audit committee minutes reflected genuine deliberation or whether statutory auditors had access to relevant information.

Under the Prevention of Money Laundering Act (PMLA), the Enforcement Directorate does not accept "our KYC was complete" as a defence. The question is whether the regulated entity had a genuine reason to know of suspicious activity, regardless of whether the prescribed documentation was in order. Courts and tribunals are increasingly applying the "substance over form" doctrine, a principle borrowed from tax law and now applied in corporate governance and criminal fraud jurisprudence.

The Legal Framework: Key Statutory Provisions

Companies Act, 2013

Section 134(5) requires directors to affirm the adequacy of internal financial controls (IFC) and that such controls operated effectively during the year. This is not a formality: the SFIO and the National Company Law Tribunal (NCLT) have treated false assertions under Section 134(5) as evidence of fraud under Section 447. The latter is a broad provision that captures not only active misrepresentation but also omission with the intent to deceive. Regulators have used Section 447 to prosecute "technical" compliance that is designed to obscure a company's true financial position.

The obligations on independent directors under Section 149(8) read with Schedule IV are substantive, not ceremonial. The Code for Independent Directors requires them to exercise genuine independent judgment and report concerns. Appointment alone does not discharge this obligation; the independent director must be demonstrably independent in conduct.

Section 177, which governs the Audit Committee, requires review of financial statements, internal audit reports, and related-party transactions. Committees that meet pro forma and do not record substantive queries or disagreements will not protect directors under Section 166 (fiduciary duty). Meanwhile, Section 143 imposes auditor duties, including reporting fraud under Section 143(12). Auditors cannot shelter behind management representations where red flags exist. The National Financial Reporting Authority (NFRA) has disciplined auditors who issued clean reports on accounts that were technically documented but substantively deficient.

SEBI (LODR) Regulations, 2015

Regulation 4 of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 explicitly states that governance is about the "spirit" of the regulations, not merely technical compliance, one of the rare instances where a regulation textually acknowledges the form-substance distinction. Regulation 17 sets minimum requirements for independent directors, but these quantitative thresholds do not, by themselves, ensure independent oversight.

Regulation 23, which deals with related party transactions (RPTs), requires audit committee and, in certain cases, shareholder approval. SEBI has penalised companies that structured RPTs in tranches or routed them through intermediaries to avoid the approval threshold, a paradigmatic example of tick-box avoidance. Regulation 33, governing financial results disclosure, requires quarterly and annual results to be signed off by management and the auditor; a signed form without underlying verification is actionable.

PMLA, 2002 and FEMA, 1999

Under the PMLA, reporting entities like banks, NBFCs, and market intermediaries must maintain records under Section 12 and verify identity under Section 12A. However, compliance with KYC documentation requirements is not an absolute defence if the entity had reason to suspect a transaction and failed to act. The "know your customer" obligation extends to genuine understanding, not form-filling.

Under FEMA, the Reserve Bank of India (RBI) and the ED regularly examine whether foreign exchange transactions have economic substance commensurate with the documentation filed. Round-tripping structures with technically compliant documentation have attracted prosecutors' attention. Both statutes place the burden on the regulated entity to demonstrate that its compliance was substantive – the documentary record is a starting point, not a conclusion.

Internal Financial Controls: A Specific Legal Obligation

Section 134(5)(e) of the Companies Act requires the board to confirm that adequate internal financial controls exist and are operated effectively. The ICAI Guidance Note on IFC (2015) provides a framework, but regulators examine whether control testing actually occurred, not whether the IFC framework was drafted and filed. For listed entities, the Statutory Auditor is required under the Companies (Auditor’s Report) Order, 2020 (CARO 2020), to specifically report on IFC adequacy. A passing CARO report on technically documented controls has not consistently protected companies where operational controls failed.

Red Flags: Where Tick-Box Governance Fails

Signed policies with no implementation. Employee codes of conduct, whistleblower policies, and anti-bribery frameworks are filed with regulators or posted on websites, but no training is provided, no escalation mechanism exists, and no grievance has ever been processed. Regulators treat this as no policy at all.

Rubber-stamp board approvals. Minutes are templated and identical across meetings. No questions are recorded. No dissent is noted. Resolutions are passed in 15-minute board calls. This pattern now triggers SFIO scrutiny in cases of subsequent fraud.

Superficial KYC. Customer identification documents are collected and filed. Beneficial ownership is not verified. The source of funds is not corroborated against declared income. ED investigations routinely expose this gap in PMLA proceedings.

Sham independent directors. IDs appointed on the basis of personal relationships rather than independence or sector expertise. They attend all meetings, vote with management on all resolutions, and have no recorded independent query. SEBI has initiated enforcement action against such IDs under Regulation 25 of the LODR.

Ineffective audit committees. Committees constituted with a minimum of three members but lacking financial literacy or sector expertise. External auditors are never asked probing questions. The committee’s annual report to the board is one paragraph long.

Related party transaction structuring. Transactions with related parties are broken into sub-threshold tranches to avoid audit committee or shareholder approval. SEBI’s real-time surveillance now flags this pattern across listed entity disclosures.

Compliance reports filed, controls not tested. A company files its IFC statement and CARO report, citing adequate controls, but the controls have never been operationally tested. This is a standard SFIO inquiry point in any forensic investigation.

A Substance-Oriented Compliance Roadmap

Moving from tick-box governance to substantive compliance requires specific, actionable measures. The following steps are directed at general counsel, compliance officers, and senior management.

Periodic control testing, not just documentation. Internal audit should include operational testing of controls – walkthrough tests, sample transaction reviews, and control failure tracking. Document testing outcomes, not just control descriptions.

Real board engagement with recorded deliberations. Ensure board and committee minutes reflect genuine discussion. Key concerns, queries, and dissenting observations should be recorded. Templated minutes are a liability in any subsequent investigation.

Audit trail for decision-making. For significant decisions related to party transactions, major capital expenditures, and credit approvals, create a contemporaneous record of the analysis, the options considered, and the basis for the decision.

Independent director effectiveness review. Conduct annual self-assessments of board and committee performance. Ensure independent directors have access to management, independent professional advice, and the ability to commission independent reports.

Training and accountability mechanisms. Policies without training are unenforceable. Maintain training records. Establish KPIs for compliance function performance beyond "filings made on time."

Whistleblower channel with verified independence. Ensure the vigil mechanism under Section 177(9) of the Companies Act is genuinely accessible and that at least some complaints, however minor, have been processed. A nil-complaint record across multiple years is implausible and is treated as an indicator of suppression.

Beneficial ownership mapping. Go beyond the statutory threshold for declaring beneficial ownership. Map the ultimate economic interests of counterparties to material transactions and document the verification.

Legal health audits focused on substance rather than filing status. Periodic internal legal audits should assess not only whether filings are current but also whether governance mechanisms are functioning as designed. External legal audits before fundraising, M&A, or regulatory submissions are increasingly standard.

Calibrate compliance resources to actual risk. A company with a complex related-party structure, a promoter-controlled board, and high-value RPTs requires a compliance function commensurate with that risk, not the minimum prescribed.

Recent Developments and Emerging Trends

Regulatory Scrutiny at Scale

SEBI’s enforcement actions have escalated sharply since 2020. Adjudication proceedings against listed entities and their directors now routinely examine whether governance mechanisms functioned substantively, particularly in cases involving independent director performance and RPT approvals. MCA and SFIO investigations have expanded into mid-cap companies and unlisted entities following the IL&FS and DHFL collapses. Forensic audit has become a standard investigative tool, and digital review of emails, internal communications, and draft documents enables investigators to reconstruct actual decision-making against formal records.

The Enforcement Directorate’s use of PMLA provisional attachment orders against companies with formally compliant KYC and transaction records has demonstrated that documentary compliance is a floor, not a ceiling.

Beneficial Ownership, Ultimate Control, and Real Intent

SEBI’s 2023 circular on beneficial ownership disclosure for Foreign Portfolio Investors (FPIs) and the broader regulatory focus on Significant Beneficial Owners (SBOs) under Section 90 of the Companies Act signal a sustained pivot toward looking through formal legal structures to identify who actually controls and benefits. The SBO framework requires disclosure of individuals holding beneficial interests of 10% or more, but enforcement has moved beyond the threshold question to examine whether the declared SBO structure accurately reflects actual control.

In FEMA enforcement, the question of a transaction's "real intent", whether the declared purpose reflects a genuine commercial rationale, has become central to whether a compounding application is accepted or a prosecution is launched.

Forensic Audits and Data-Driven Investigation

The NFRA, established under the Companies Act, 2013, has shifted from passive oversight to active disciplinary action against audit firms. Its orders in the IL&FS and DHFL matters have reset expectations for what "adequate" audit engagement means. Forensic audit is now deployed not only in insolvency proceedings, IBC Resolution Professionals routinely commission forensic audits under Sections 43 and 66, but also pre-emptively by boards and lenders as a risk management tool.

Technology-assisted review of communications, transaction data, and document metadata makes the gap between what was recorded and what actually happened increasingly detectable. Paper compliance that diverges from operational reality will be exposed. SEBI’s integrated surveillance framework and the MCA’s data-driven identification of shell companies demonstrate that regulatory detection capacity has improved substantially. Accordingly, the probability of paper compliance surviving scrutiny has declined.

The Emerging Standard: Governance Effectiveness, Not Governance Formality

The evolving standard in Indian regulatory and judicial discourse is moving toward "governance effectiveness", whether the board, management, and compliance function collectively managed the company’s risk profile, in fact, not just whether the required processes were formally followed.

This is consistent with global developments. The UK Corporate Governance Code’s "comply or explain" framework, the OECD Principles of Corporate Governance, and SEC enforcement practice in the United States all reflect the same pivot: form without substance is a governance failure, not a governance achievement.

For Indian companies, the practical implication is clear: genuine compliance costs less than enforcement action against paper compliance. More importantly, substantive governance protects directors and officers personally. Tick-box compliance does not.