Governance & Compliance Shield
The startup corporate governance and compliance system. From "good enough" seed-stage governance to board-room ready Series C+ — practical frameworks that satisfy investors, regulators, and auditors without drowning in bureaucracy.
Keywords
board, board of directors, board meeting, board minutes, board resolution, governance, corporate governance, compliance, audit, auditor, statutory audit, internal audit, SOC 2, SOC2, ISO 27001, ISO 9001, ESG, CSR, internal controls, risk management, ERM, whistleblower, anti-bribery, FCPA, UK Bribery Act, related party transaction, RPT, independent director, audit committee, nomination committee, remuneration committee, shareholder meeting, AGM, EGM, proxy, voting, fiduciary duty, D&O, director liability, Companies Act, MCA, ROC, SEBI, LODR, secretarial audit, annual return, corporate social responsibility, Section 135, Section 188, NCLT, CLB, company secretary
How to Use This Skill
| Mode |
Trigger |
What It Does |
| Setup |
"board governance", "setting up board" |
Board structure, committee design, governance docs |
| Comply |
"SOC 2", "ISO 27001", "compliance" |
Certification roadmaps, gap analysis, audit prep |
| Manage |
"board meeting", "board materials" |
Meeting management, materials prep, resolution drafting |
| Audit |
"audit readiness", "preparing for audit" |
Audit preparation, documentation, controls testing |
| Report |
"ESG report", "compliance report" |
Reporting frameworks, disclosure requirements |
| India |
"MCA compliance", "Companies Act" |
India-specific corporate governance compliance |
Chain with existing skills:
legal-ip-fortress for legal compliance and regulatory frameworks
crisis-war-room for board/governance crises
ops-scale-engine for operational compliance integration
fundraising-command-center for investor governance requirements
1. Board Governance by Stage
Board Composition Evolution
| Stage |
Board Size |
Composition |
Meeting Cadence |
| Pre-Seed |
1-2 |
Founders only |
No formal board needed |
| Seed |
3 |
2 founders + 1 investor or advisor |
Quarterly (informal OK) |
| Series A |
3-5 |
2 founders + 1-2 investors + 0-1 independent |
Quarterly (formal) |
| Series B |
5 |
2 founders + 2 investors + 1 independent |
Quarterly + committee meetings |
| Series C+ |
5-7 |
2 management + 2 investors + 1-3 independent |
Monthly board, quarterly committees |
| Pre-IPO |
7-9 |
Majority independent (per exchange rules) |
Monthly + committee cadence |
Board Meeting Management
Pre-Meeting (7 Days Before):
- Send board deck (12-15 slides max)
- Include: financials, KPIs, team update, strategic issues, asks
- Pre-read materials: detailed appendix, data room updates
- Board member 1:1 pre-calls (no surprises in meetings)
Board Deck Template:
| Section |
Slides |
Content |
| Highlights/Lowlights |
1 |
Top 3 wins, top 3 concerns — honest |
| KPI Dashboard |
1-2 |
North star, revenue, growth, burn, runway |
| Financial Summary |
1-2 |
P&L, cash flow, budget vs actual |
| Product Update |
1-2 |
Roadmap progress, key releases, customer feedback |
| Team |
1 |
Headcount, key hires, attrition, open roles |
| Strategic Discussion |
2-3 |
1-2 topics needing board input (frame as decision) |
| Asks |
1 |
Specific asks: intros, advice, approvals |
During Meeting:
- Start on time, end on time
- CEO drives agenda, Chair manages discussion
- Limit presentations — maximize discussion time (60/40 rule)
- Capture action items and decisions in real-time
- Executive session (without management) at end — this is normal and healthy
Post-Meeting (48 Hours After):
- Circulate draft minutes within 48 hours
- Action items with owners and deadlines
- Board-approved resolutions documented
2. Compliance Certification Roadmaps
SOC 2 Type II (Most Common for SaaS)
What: Audit of controls related to Security, Availability, Processing Integrity, Confidentiality, and Privacy
Who needs it: Any SaaS selling to mid-market or enterprise customers
Timeline: 6-12 months (Type I: 3-6 months, Type II requires 6+ month observation)
Cost: $20,000-80,000 (auditor fees) + internal effort
SOC 2 Readiness Checklist:
| Control Area |
Key Requirements |
Common Gaps |
| Security |
Access controls, encryption, MFA, monitoring |
MFA not enforced, no SIEM |
| Availability |
SLA, DR plan, incident response |
No tested DR plan |
| Confidentiality |
Data classification, NDA, encryption at rest |
No data classification policy |
| Processing Integrity |
QA, change management, monitoring |
No formal change management |
| Privacy |
Privacy policy, data retention, consent |
No data retention schedule |
Implementation Timeline:
- Month 1-2: Gap assessment, policy writing
- Month 3-4: Control implementation, tool deployment
- Month 5: Type I audit (point-in-time)
- Month 6-11: Observation period (controls operating)
- Month 12: Type II audit (period of time)
ISO 27001 (Information Security Management)
Who needs it: Companies with EU/global enterprise customers, regulated industries
Timeline: 6-18 months
Cost: $30,000-150,000+
Key difference from SOC 2: Prescriptive controls (Annex A — 93 controls), certification by accredited body
ISO 9001 (Quality Management)
Who needs it: Manufacturing, healthcare, government contractors
Timeline: 6-12 months
Cost: $15,000-50,000
3. Internal Controls Framework
COSO-Lite for Startups
| Component |
Startup Implementation |
Priority by Stage |
| Control Environment |
Tone from the top, code of ethics, org structure |
Seed onwards |
| Risk Assessment |
Quarterly risk review, document top 10 risks |
Series A |
| Control Activities |
Segregation of duties, approval workflows, access controls |
Series A |
| Information & Communication |
Financial reporting, board materials, compliance reporting |
Series A |
| Monitoring |
Internal audit (even informal), control testing |
Series B |
Financial Controls Minimum
| Control |
Description |
When to Implement |
| Dual authorization |
2 signatures for payments >$10K |
Day 1 |
| Bank reconciliation |
Monthly reconciliation of all accounts |
Day 1 |
| Expense approval |
Manager approval for all expenses |
10+ employees |
| Segregation of duties |
No single person controls entire financial process |
25+ employees |
| Budget vs actual |
Monthly variance analysis |
Series A |
| Revenue recognition |
ASC 606 compliant recognition |
Series A |
| Payroll audit |
Monthly payroll reconciliation |
25+ employees |
| Vendor approval |
Formal vendor onboarding and approval |
Series B |
| Internal audit |
Annual internal audit |
Series C |
4. Risk Management Framework
Enterprise Risk Register (Simplified)
| Risk Category |
Example Risks |
Likelihood (1-5) |
Impact (1-5) |
Risk Score |
Mitigation |
| Strategic |
Market shift, competitor disruption |
|
|
L×I |
|
| Financial |
Cash crisis, revenue concentration |
|
|
L×I |
|
| Operational |
Key person loss, system failure |
|
|
L×I |
|
| Compliance |
Regulatory change, data breach |
|
|
L×I |
|
| Reputational |
PR crisis, customer trust loss |
|
|
L×I |
|
Risk Response Options:
- Accept: Risk is low and cost of mitigation exceeds potential impact
- Mitigate: Implement controls to reduce likelihood or impact
- Transfer: Insurance, indemnification, outsourcing
- Avoid: Change plans to eliminate the risk entirely
5. ESG Framework for Startups
ESG Relevance by Stage
| Stage |
ESG Priority |
Why |
| Seed |
Minimal — focus on survival |
Don't over-index |
| Series A |
Foundation — DEI policy, basic carbon awareness |
Investors asking |
| Series B |
Structured — ESG metrics, supply chain review |
Part of DD |
| Series C+ |
Comprehensive — ESG report, science-based targets |
Customer/investor requirement |
| Pre-IPO |
Mandatory — TCFD/CSRD reporting, ESG rating |
Exchange listing requirements |
Minimal Viable ESG (Series A)
| Pillar |
Minimum Actions |
Documentation |
| Environmental |
Measure Scope 1+2 emissions, cloud provider sustainability |
Carbon footprint estimate |
| Social |
DEI policy, pay equity analysis, employee wellness |
DEI metrics, employee survey |
| Governance |
Independent director, board diversity, ethics policy |
Governance charter |
6. India Corporate Governance Stack
Companies Act 2013 — Key Governance Requirements
| Requirement |
Threshold |
Section |
Deadline |
| Board Meetings |
Min 4/year, gap ≤120 days |
Section 173 |
Quarterly |
| First Board Meeting |
Within 30 days of incorporation |
Section 173 |
30 days |
| AGM |
Within 6 months of financial year end |
Section 96 |
September 30 |
| Financial Statements |
Adoption at AGM |
Section 129 |
At AGM |
| Annual Return |
File MGT-7/MGT-7A with ROC |
Section 92 |
Within 60 days of AGM |
| Statutory Audit |
Mandatory for all companies |
Section 139 |
Annual |
| Secretarial Audit |
Listed + prescribed companies |
Section 204 |
Annual |
| CSR |
NW ≥500Cr OR TO ≥1000Cr OR NP ≥5Cr |
Section 135 |
Annual |
| Related Party Transactions |
Board/shareholder approval |
Section 188 |
Per transaction |
| Director Disclosure |
Annual disclosure of interests |
Section 184 |
Annual |
| KYC |
DIR-3 KYC for all directors annually |
MCA Rules |
September 30 |
| Registered Office |
File INC-22 within 30 days |
Section 12 |
At incorporation |
India Board Composition Rules
| Company Type |
Minimum Directors |
Independent Directors |
Woman Director |
| Private Limited |
2 |
Not mandatory (unless listed) |
Not mandatory (unless paid-up ≥100Cr OR TO ≥300Cr) |
| Public Limited |
3 |
Min 1/3 of total board |
Mandatory |
| Listed Company |
3 |
Min 1/3 (or 1/2 if Chair is non-independent) |
Mandatory |
India CSR Requirements (Section 135)
Trigger: Net worth ≥INR 500 Cr OR Turnover ≥INR 1,000 Cr OR Net profit ≥INR 5 Cr (in any of preceding 3 years)
Requirement: Spend 2% of average net profits (preceding 3 years) on CSR activities
CSR Activities (Schedule VII):
- Eradicating hunger, poverty
- Education, gender equality, women empowerment
- Environmental sustainability
- Healthcare, sanitation
- Rural development
- Protection of heritage, art, culture
- Armed forces veterans welfare
- Sports promotion
- Technology incubators (DPIIT approved)
- Rural sports, Paralympic, Olympic training
India Statutory Compliance Officers
| Role |
Requirement |
Qualification |
| Company Secretary |
Mandatory if paid-up capital ≥5Cr |
ICSI member |
| Statutory Auditor |
Mandatory for all companies |
CA (ICAI member) |
| Internal Auditor |
Listed + prescribed companies |
CA or cost accountant |
| Secretarial Auditor |
Listed + prescribed companies |
Practicing CS |
| Cost Auditor |
Prescribed manufacturing companies |
Cost accountant |
7. Anti-Bribery & Ethics
FCPA / UK Bribery Act Essentials (For International Operations)
| Area |
FCPA (US) |
UK Bribery Act |
Prevention of Corruption Act (India) |
| Scope |
US persons, SEC-registered, US-connected payments |
UK-connected companies, worldwide |
India-connected, public servants |
| Prohibited |
Payments to foreign officials |
All bribery (public + commercial) |
Bribing public servants |
| Facilitation Payments |
Narrow exception |
No exception |
No exception |
| Penalty |
Up to $250M fine, imprisonment |
Unlimited fine, imprisonment |
Imprisonment + fine |
| Defense |
Compliance program is mitigating |
"Adequate procedures" defense |
No statutory defense |
Minimum Anti-Corruption Program
Reference Files
For detailed governance documentation, load:
reference/board-templates.md — Board deck template, resolution formats, minutes template
reference/india-governance-calendar.md — Month-by-month India Companies Act compliance calendar
Adversarial Governance Layer
Red Team Governance
Before every major board decision:
1. Assign 2-3 people to build strongest case AGAINST the proposal
2. Give 24-48 hours for evidence-based counter-argument
3. Present counter-case BEFORE the proposal
4. No rebuttal during presentation — listen first
5. Score objections: likelihood x severity. Address anything >7/10.
Devil's Advocate Protocol
1. Rotate role — never same person twice consecutively
2. Give preparation time (unprepared advocacy is theater)
3. Advocate presents FIRST (prevents anchoring)
4. No interruptions during counter-presentation
Effective only when advocate is genuinely prepared, not role-playing.
Pre-Mortem for Strategic Governance
90-MINUTE SESSION before any major commitment:
1. Brief board on proposal (10 min)
2. "Imagine 12 months from now, this FAILED. Write why." (15 min silent)
3. Round robin — one reason per round (30 min)
4. Cluster: Likelihood x Impact 2x2 (20 min)
5. Mitigate top-right quadrant (15 min)
Prospective hindsight increases diagnostic accuracy by 30%.
ACH for Board Decisions
1. List ALL plausible hypotheses (not just obvious two)
2. Evidence matrix: hypotheses as columns, evidence as rows
3. Mark what each evidence DISPROVES (not confirms)
4. Eliminate hypotheses with most inconsistent evidence
5. Surviving hypothesis gets resourced. Others get monitoring triggers.
Source: CIA Structured Analytic Technique (Richards Heuer)
Counter-Intelligence for Governance
Board materials: CONFIDENTIAL default, numbered/watermarked copies, access logging
Social engineering defense: "talk track" for public info, classification system
Insider threat: unusual data access flagged, departing exec access restricted
Quarterly: security awareness refresher, board-level access audit
1---2name: governance-compliance-shield3description: Corporate governance and regulatory compliance operating system covering board management, board meeting protocols, corporate governance best practices, audit readiness, SOC 2/ISO 27001/ISO 9001 certification, ESG framework, data governance, internal controls, risk management framework, whistleblower policy, anti-bribery/FCPA, related party transactions, and regulatory compliance by industry. Includes India governance stack covering Companies Act 2013 governance requirements, MCA/ROC compliance, Board composition rules, CSR obligations (Section 135), related party transactions (Section 188), annual compliance calendar, statutory audit requirements, secretarial audit, SEBI LODR for listed companies, and NCLT proceedings. Use when user mentions board, governance, compliance, audit, SOC 2, ISO, ESG, internal controls, risk management, whistleblower, anti-bribery, FCPA, board meeting, board minutes, independent director, audit committee, CSR, Companies Act, MCA, ROC, SEBI LODR, statutory audit, secretarial audit,4license: MIT5---6
7# Governance & Compliance Shield
8
9The startup corporate governance and compliance system. From "good enough" seed-stage governance to board-room ready Series C+ — practical frameworks that satisfy investors, regulators, and auditors without drowning in bureaucracy.
10
11## Keywords
12
13board, board of directors, board meeting, board minutes, board resolution, governance, corporate governance, compliance, audit, auditor, statutory audit, internal audit, SOC 2, SOC2, ISO 27001, ISO 9001, ESG, CSR, internal controls, risk management, ERM, whistleblower, anti-bribery, FCPA, UK Bribery Act, related party transaction, RPT, independent director, audit committee, nomination committee, remuneration committee, shareholder meeting, AGM, EGM, proxy, voting, fiduciary duty, D&O, director liability, Companies Act, MCA, ROC, SEBI, LODR, secretarial audit, annual return, corporate social responsibility, Section 135, Section 188, NCLT, CLB, company secretary
14
15---
16
17## How to Use This Skill
18
19| Mode | Trigger | What It Does |
20|------|---------|--------------|
21| **Setup** | "board governance", "setting up board" | Board structure, committee design, governance docs |
22| **Comply** | "SOC 2", "ISO 27001", "compliance" | Certification roadmaps, gap analysis, audit prep |
23| **Manage** | "board meeting", "board materials" | Meeting management, materials prep, resolution drafting |
24| **Audit** | "audit readiness", "preparing for audit" | Audit preparation, documentation, controls testing |
25| **Report** | "ESG report", "compliance report" | Reporting frameworks, disclosure requirements |
26| **India** | "MCA compliance", "Companies Act" | India-specific corporate governance compliance |
27
28**Chain with existing skills:**
29- `legal-ip-fortress` for legal compliance and regulatory frameworks
30- `crisis-war-room` for board/governance crises
31- `ops-scale-engine` for operational compliance integration
32- `fundraising-command-center` for investor governance requirements
33
34---
35
36## 1. Board Governance by Stage
37
38### Board Composition Evolution
39
40| Stage | Board Size | Composition | Meeting Cadence |
41|-------|-----------|-------------|-----------------|
42| **Pre-Seed** | 1-2 | Founders only | No formal board needed |
43| **Seed** | 3 | 2 founders + 1 investor or advisor | Quarterly (informal OK) |
44| **Series A** | 3-5 | 2 founders + 1-2 investors + 0-1 independent | Quarterly (formal) |
45| **Series B** | 5 | 2 founders + 2 investors + 1 independent | Quarterly + committee meetings |
46| **Series C+** | 5-7 | 2 management + 2 investors + 1-3 independent | Monthly board, quarterly committees |
47| **Pre-IPO** | 7-9 | Majority independent (per exchange rules) | Monthly + committee cadence |
48
49### Board Meeting Management
50
51**Pre-Meeting (7 Days Before):**
521. Send board deck (12-15 slides max)
532. Include: financials, KPIs, team update, strategic issues, asks
543. Pre-read materials: detailed appendix, data room updates
554. Board member 1:1 pre-calls (no surprises in meetings)
56
57**Board Deck Template:**
58| Section | Slides | Content |
59|---------|--------|---------|
60| Highlights/Lowlights | 1 | Top 3 wins, top 3 concerns — honest |
61| KPI Dashboard | 1-2 | North star, revenue, growth, burn, runway |
62| Financial Summary | 1-2 | P&L, cash flow, budget vs actual |
63| Product Update | 1-2 | Roadmap progress, key releases, customer feedback |
64| Team | 1 | Headcount, key hires, attrition, open roles |
65| Strategic Discussion | 2-3 | 1-2 topics needing board input (frame as decision) |
66| Asks | 1 | Specific asks: intros, advice, approvals |
67
68**During Meeting:**
691. Start on time, end on time
702. CEO drives agenda, Chair manages discussion
713. Limit presentations — maximize discussion time (60/40 rule)
724. Capture action items and decisions in real-time
735. Executive session (without management) at end — this is normal and healthy
74
75**Post-Meeting (48 Hours After):**
761. Circulate draft minutes within 48 hours
772. Action items with owners and deadlines
783. Board-approved resolutions documented
79
80---
81
82## 2. Compliance Certification Roadmaps
83
84### SOC 2 Type II (Most Common for SaaS)
85
86**What**: Audit of controls related to Security, Availability, Processing Integrity, Confidentiality, and Privacy
87**Who needs it**: Any SaaS selling to mid-market or enterprise customers
88**Timeline**: 6-12 months (Type I: 3-6 months, Type II requires 6+ month observation)
89**Cost**: $20,000-80,000 (auditor fees) + internal effort
90
91**SOC 2 Readiness Checklist:**
92
93| Control Area | Key Requirements | Common Gaps |
94|-------------|-----------------|-------------|
95| **Security** | Access controls, encryption, MFA, monitoring | MFA not enforced, no SIEM |
96| **Availability** | SLA, DR plan, incident response | No tested DR plan |
97| **Confidentiality** | Data classification, NDA, encryption at rest | No data classification policy |
98| **Processing Integrity** | QA, change management, monitoring | No formal change management |
99| **Privacy** | Privacy policy, data retention, consent | No data retention schedule |
100
101**Implementation Timeline:**
102- Month 1-2: Gap assessment, policy writing
103- Month 3-4: Control implementation, tool deployment
104- Month 5: Type I audit (point-in-time)
105- Month 6-11: Observation period (controls operating)
106- Month 12: Type II audit (period of time)
107
108### ISO 27001 (Information Security Management)
109
110**Who needs it**: Companies with EU/global enterprise customers, regulated industries
111**Timeline**: 6-18 months
112**Cost**: $30,000-150,000+
113**Key difference from SOC 2**: Prescriptive controls (Annex A — 93 controls), certification by accredited body
114
115### ISO 9001 (Quality Management)
116
117**Who needs it**: Manufacturing, healthcare, government contractors
118**Timeline**: 6-12 months
119**Cost**: $15,000-50,000
120
121---
122
123## 3. Internal Controls Framework
124
125### COSO-Lite for Startups
126
127| Component | Startup Implementation | Priority by Stage |
128|-----------|----------------------|-------------------|
129| **Control Environment** | Tone from the top, code of ethics, org structure | Seed onwards |
130| **Risk Assessment** | Quarterly risk review, document top 10 risks | Series A |
131| **Control Activities** | Segregation of duties, approval workflows, access controls | Series A |
132| **Information & Communication** | Financial reporting, board materials, compliance reporting | Series A |
133| **Monitoring** | Internal audit (even informal), control testing | Series B |
134
135### Financial Controls Minimum
136
137| Control | Description | When to Implement |
138|---------|------------|-------------------|
139| **Dual authorization** | 2 signatures for payments >$10K | Day 1 |
140| **Bank reconciliation** | Monthly reconciliation of all accounts | Day 1 |
141| **Expense approval** | Manager approval for all expenses | 10+ employees |
142| **Segregation of duties** | No single person controls entire financial process | 25+ employees |
143| **Budget vs actual** | Monthly variance analysis | Series A |
144| **Revenue recognition** | ASC 606 compliant recognition | Series A |
145| **Payroll audit** | Monthly payroll reconciliation | 25+ employees |
146| **Vendor approval** | Formal vendor onboarding and approval | Series B |
147| **Internal audit** | Annual internal audit | Series C |
148
149---
150
151## 4. Risk Management Framework
152
153### Enterprise Risk Register (Simplified)
154
155| Risk Category | Example Risks | Likelihood (1-5) | Impact (1-5) | Risk Score | Mitigation |
156|--------------|--------------|-------------------|-------------|-----------|-----------|
157| **Strategic** | Market shift, competitor disruption | | | L×I | |
158| **Financial** | Cash crisis, revenue concentration | | | L×I | |
159| **Operational** | Key person loss, system failure | | | L×I | |
160| **Compliance** | Regulatory change, data breach | | | L×I | |
161| **Reputational** | PR crisis, customer trust loss | | | L×I | |
162
163**Risk Response Options:**
164- **Accept**: Risk is low and cost of mitigation exceeds potential impact
165- **Mitigate**: Implement controls to reduce likelihood or impact
166- **Transfer**: Insurance, indemnification, outsourcing
167- **Avoid**: Change plans to eliminate the risk entirely
168
169---
170
171## 5. ESG Framework for Startups
172
173### ESG Relevance by Stage
174
175| Stage | ESG Priority | Why |
176|-------|-------------|-----|
177| **Seed** | Minimal — focus on survival | Don't over-index |
178| **Series A** | Foundation — DEI policy, basic carbon awareness | Investors asking |
179| **Series B** | Structured — ESG metrics, supply chain review | Part of DD |
180| **Series C+** | Comprehensive — ESG report, science-based targets | Customer/investor requirement |
181| **Pre-IPO** | Mandatory — TCFD/CSRD reporting, ESG rating | Exchange listing requirements |
182
183### Minimal Viable ESG (Series A)
184
185| Pillar | Minimum Actions | Documentation |
186|--------|----------------|---------------|
187| **Environmental** | Measure Scope 1+2 emissions, cloud provider sustainability | Carbon footprint estimate |
188| **Social** | DEI policy, pay equity analysis, employee wellness | DEI metrics, employee survey |
189| **Governance** | Independent director, board diversity, ethics policy | Governance charter |
190
191---
192
193## 6. India Corporate Governance Stack
194
195### Companies Act 2013 — Key Governance Requirements
196
197| Requirement | Threshold | Section | Deadline |
198|------------|-----------|---------|----------|
199| **Board Meetings** | Min 4/year, gap ≤120 days | Section 173 | Quarterly |
200| **First Board Meeting** | Within 30 days of incorporation | Section 173 | 30 days |
201| **AGM** | Within 6 months of financial year end | Section 96 | September 30 |
202| **Financial Statements** | Adoption at AGM | Section 129 | At AGM |
203| **Annual Return** | File MGT-7/MGT-7A with ROC | Section 92 | Within 60 days of AGM |
204| **Statutory Audit** | Mandatory for all companies | Section 139 | Annual |
205| **Secretarial Audit** | Listed + prescribed companies | Section 204 | Annual |
206| **CSR** | NW ≥500Cr OR TO ≥1000Cr OR NP ≥5Cr | Section 135 | Annual |
207| **Related Party Transactions** | Board/shareholder approval | Section 188 | Per transaction |
208| **Director Disclosure** | Annual disclosure of interests | Section 184 | Annual |
209| **KYC** | DIR-3 KYC for all directors annually | MCA Rules | September 30 |
210| **Registered Office** | File INC-22 within 30 days | Section 12 | At incorporation |
211
212### India Board Composition Rules
213
214| Company Type | Minimum Directors | Independent Directors | Woman Director |
215|-------------|------------------|----------------------|---------------|
216| **Private Limited** | 2 | Not mandatory (unless listed) | Not mandatory (unless paid-up ≥100Cr OR TO ≥300Cr) |
217| **Public Limited** | 3 | Min 1/3 of total board | Mandatory |
218| **Listed Company** | 3 | Min 1/3 (or 1/2 if Chair is non-independent) | Mandatory |
219
220### India CSR Requirements (Section 135)
221
222**Trigger**: Net worth ≥INR 500 Cr OR Turnover ≥INR 1,000 Cr OR Net profit ≥INR 5 Cr (in any of preceding 3 years)
223
224**Requirement**: Spend 2% of average net profits (preceding 3 years) on CSR activities
225
226**CSR Activities (Schedule VII):**
227- Eradicating hunger, poverty
228- Education, gender equality, women empowerment
229- Environmental sustainability
230- Healthcare, sanitation
231- Rural development
232- Protection of heritage, art, culture
233- Armed forces veterans welfare
234- Sports promotion
235- Technology incubators (DPIIT approved)
236- Rural sports, Paralympic, Olympic training
237
238### India Statutory Compliance Officers
239
240| Role | Requirement | Qualification |
241|------|------------|--------------|
242| **Company Secretary** | Mandatory if paid-up capital ≥5Cr | ICSI member |
243| **Statutory Auditor** | Mandatory for all companies | CA (ICAI member) |
244| **Internal Auditor** | Listed + prescribed companies | CA or cost accountant |
245| **Secretarial Auditor** | Listed + prescribed companies | Practicing CS |
246| **Cost Auditor** | Prescribed manufacturing companies | Cost accountant |
247
248---
249
250## 7. Anti-Bribery & Ethics
251
252### FCPA / UK Bribery Act Essentials (For International Operations)
253
254| Area | FCPA (US) | UK Bribery Act | Prevention of Corruption Act (India) |
255|------|---------|----------------|-------------------------------------|
256| **Scope** | US persons, SEC-registered, US-connected payments | UK-connected companies, worldwide | India-connected, public servants |
257| **Prohibited** | Payments to foreign officials | All bribery (public + commercial) | Bribing public servants |
258| **Facilitation Payments** | Narrow exception | No exception | No exception |
259| **Penalty** | Up to $250M fine, imprisonment | Unlimited fine, imprisonment | Imprisonment + fine |
260| **Defense** | Compliance program is mitigating | "Adequate procedures" defense | No statutory defense |
261
262### Minimum Anti-Corruption Program
263
264- [ ] Written anti-bribery policy
265- [ ] Tone from the top (board-level commitment)
266- [ ] Due diligence on third parties (agents, distributors, JV partners)
267- [ ] Gifts and hospitality policy (limits, approval, documentation)
268- [ ] Training for employees in at-risk roles
269- [ ] Confidential reporting mechanism (whistleblower)
270- [ ] Regular monitoring and review
271- [ ] Documented investigations of any concerns
272
273---
274
275## Reference Files
276
277For detailed governance documentation, load:
278- [`reference/board-templates.md`](reference/board-templates.md) — Board deck template, resolution formats, minutes template
279- [`reference/india-governance-calendar.md`](reference/india-governance-calendar.md) — Month-by-month India Companies Act compliance calendar
280
281## Adversarial Governance Layer
282
283### Red Team Governance
284
285```
286Before every major board decision:
2871. Assign 2-3 people to build strongest case AGAINST the proposal
2882. Give 24-48 hours for evidence-based counter-argument
2893. Present counter-case BEFORE the proposal
2904. No rebuttal during presentation — listen first
2915. Score objections: likelihood x severity. Address anything >7/10.
292```
293
294### Devil's Advocate Protocol
295
296```
2971. Rotate role — never same person twice consecutively
2982. Give preparation time (unprepared advocacy is theater)
2993. Advocate presents FIRST (prevents anchoring)
3004. No interruptions during counter-presentation
301Effective only when advocate is genuinely prepared, not role-playing.
302```
303
304### Pre-Mortem for Strategic Governance
305
306```
30790-MINUTE SESSION before any major commitment:
3081. Brief board on proposal (10 min)
3092. "Imagine 12 months from now, this FAILED. Write why." (15 min silent)
3103. Round robin — one reason per round (30 min)
3114. Cluster: Likelihood x Impact 2x2 (20 min)
3125. Mitigate top-right quadrant (15 min)
313Prospective hindsight increases diagnostic accuracy by 30%.
314```
315
316### ACH for Board Decisions
317
318```
3191. List ALL plausible hypotheses (not just obvious two)
3202. Evidence matrix: hypotheses as columns, evidence as rows
3213. Mark what each evidence DISPROVES (not confirms)
3224. Eliminate hypotheses with most inconsistent evidence
3235. Surviving hypothesis gets resourced. Others get monitoring triggers.
324Source: CIA Structured Analytic Technique (Richards Heuer)
325```
326
327### Counter-Intelligence for Governance
328
329```
330Board materials: CONFIDENTIAL default, numbered/watermarked copies, access logging
331Social engineering defense: "talk track" for public info, classification system
332Insider threat: unusual data access flagged, departing exec access restricted
333Quarterly: security awareness refresher, board-level access audit
334```