A team meeting with one person speaking to the room

Tips remain the single most important way that fraud comes to light. A vigil mechanism, the term the Companies Act uses for a whistleblower framework, is therefore not just a compliance formality. Designed well, it is one of the most effective anti-fraud controls an organisation can have. Designed badly, it exists on paper and is never used.

What the law requires

Companies Act, 2013. Section 177(9) requires every listed company, and certain other classes of companies, to establish a vigil mechanism for directors and employees to report genuine concerns. Under Rule 7 of the Companies (Meetings of Board and its Powers) Rules, 2014, the requirement extends to companies that accept deposits from the public and to companies that have borrowed more than ₹50 crore from banks and public financial institutions. Section 177(10) requires adequate safeguards against victimisation of people who use the mechanism, provides for direct access to the chairperson of the audit committee in appropriate or exceptional cases, and requires the details of the mechanism to be disclosed on the company's website and in the Board's report. Where a company is not required to have an audit committee, the Board nominates a director to play that role.

SEBI regulations. Regulation 22 of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 requires listed entities to formulate a vigil mechanism or whistleblower policy, with safeguards against victimisation and direct access to the chairperson of the audit committee in appropriate or exceptional cases. Separately, the SEBI (Prohibition of Insider Trading) Regulations, 2015 require listed companies to have a whistleblower policy that enables employees to report instances of leak of unpublished price-sensitive information.

Even where the law does not require one, private companies, partnerships and not-for-profits benefit from a vigil mechanism for the same reason listed companies do: it surfaces problems early.

Design choices that decide whether it works

1. Multiple, accessible channels

People raise concerns in different ways. Offer more than one channel, such as a dedicated email address, a phone line, a web form and a named individual, and include at least one route that bypasses line management entirely.

2. The option of anonymity

Many employees will only speak up if they can do so anonymously. Anonymous reports are harder to investigate, so channels that allow two-way communication with an anonymous reporter are particularly valuable.

3. Genuine protection from retaliation

The law requires safeguards against victimisation, and employees watch closely how the first few reporters are treated. State clearly that retaliation is a disciplinary offence, and monitor the treatment of reporters after a report is made.

4. Independent handling

Reports should go to people who are independent of the matters likely to be reported. Allegations involving senior management must have a route to the audit committee chair or an external party.

5. A clear triage and investigation protocol

Decide in advance who assesses reports, how they are prioritised, who investigates, what timelines apply and how conflicts of interest are handled. Many allegations are about workplace grievances rather than fraud, and a protocol makes sure each is routed to the right place.

6. Feedback to the reporter

Reporters who hear nothing assume nothing was done. Acknowledge every report and, within the limits of confidentiality, tell the reporter when the matter has been addressed.

7. Oversight and reporting

The audit committee should receive regular statistics: the number of reports, their categories, time taken to close them and outcomes. Trends are often as revealing as individual cases.

A useful test: ask a sample of employees whether they know how to raise a concern and whether they would feel safe doing so. Their answers show whether the mechanism works better than any policy document.

Common pitfalls

  • A single email address monitored by the same department the reports are likely to concern.
  • A policy published once and never communicated again.
  • Investigations run by people without the skills or independence to do them properly.
  • No record of reports received, making oversight impossible.

A vigil mechanism is inexpensive to run. The real investment is in the trust that makes people willing to use it, and that trust is earned by how the organisation responds to each report.

This article is general information and not professional advice. It reflects the law and practice as understood on the date of publication. Please read our Disclaimer.