top of page

How to Establish a Vigil Mechanism and Whistleblower Policy Under Section 177(9) of the Companies Act 2013

  • Writer: Kaustav Chowdhury
    Kaustav Chowdhury
  • 3 minutes ago
  • 8 min read

Introduction

A vigil mechanism is a structured channel that allows directors, employees, and other stakeholders to report genuine concerns about unethical behaviour, actual or suspected fraud, violation of company policies, or any other irregularity within a company. Section 177(9) of the Companies Act, 2013, read with Rule 7 of the Companies (Meetings of Board and its Powers) Rules, 2014, mandates that certain categories of companies establish a vigil mechanism. For listed companies, Regulation 22 of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 imposes additional requirements regarding the formulation and disclosure of the vigil mechanism.


This guide provides a comprehensive, step-by-step approach to establishing a vigil mechanism and whistleblower policy, covering applicability, the policy drafting process, audit committee oversight, protections against victimisation, anonymous complaint handling, documentation requirements, and annual disclosures. For a related perspective on whistleblower protections under Indian law, refer to our article on filing a whistleblower complaint under the Whistle Blowers Protection Act 2014.



Which Companies Must Establish a Vigil Mechanism?

Under Section 177(9) read with Rule 7 of the Companies (Meetings of Board and its Powers) Rules, 2014, the following categories of companies are required to establish a vigil mechanism: every listed company, every company which accepts deposits from the public, and every company which has borrowed money from banks and public financial institutions in excess of Rs 50 crore. While these are the statutory categories, it is considered good governance practice for all companies, regardless of size, to voluntarily establish a vigil mechanism as part of their internal compliance framework.


Legal Framework: Section 177(9) and SEBI LODR Regulation 22

Section 177(9) of the Companies Act, 2013 states that every listed company or such class or classes of companies as may be prescribed shall establish a vigil mechanism for directors and employees to report genuine concerns in such manner as may be prescribed. Section 177(10) further provides that the vigil mechanism shall provide for adequate safeguards against victimisation of persons who use such mechanism and shall also provide for direct access to the chairperson of the audit committee in appropriate or exceptional cases.


For listed companies, Regulation 22 of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 imposes additional requirements. The listed entity must formulate a vigil mechanism for directors and employees to report genuine concerns, the vigil mechanism must provide adequate safeguards against victimisation and provide for direct access to the chairperson of the audit committee in appropriate or exceptional cases, and the details of the vigil mechanism must be disclosed on the website of the listed entity and in the annual report. The vigil mechanism policy must also be disseminated on a separate dedicated section of the company's website. For entities with listed non-convertible debt securities of outstanding value of Rs 1,000 crore or above, the requirements for High Value Debt Listed Entities (HVDLEs) also apply, with compliance timelines introduced from April 2025.


Step 1: Board Resolution to Establish the Vigil Mechanism

The process begins with the board of directors passing a resolution to establish the vigil mechanism and adopt the whistleblower policy. The board resolution should record the statutory requirement under Section 177(9), approve the whistleblower policy document, designate the audit committee (or, for companies not required to constitute an audit committee, a director nominated by the board) as the oversight body, appoint a Vigilance Officer or Ethics Officer to receive and process complaints, and authorise the company secretary to take all necessary steps for implementation. For guidance on conducting the board meeting to pass this resolution, refer to our article on how to conduct a board meeting under the Companies Act 2013.


Step 2: Drafting the Whistleblower Policy

The whistleblower policy is the foundational document of the vigil mechanism. A well-drafted policy should cover the following areas. First, the scope and applicability section should define who can raise concerns (directors, employees, contractors, vendors, and other stakeholders), what types of concerns may be raised (fraud, corruption, bribery, misuse of company property, violation of law, financial irregularities, and any unethical conduct), and clarify that the mechanism is not intended for personal grievances, which should be addressed through the company's HR grievance redressal process.


Second, the complaint channel section should specify how complaints can be submitted. This may include a dedicated email address, a physical complaint box at company premises, a toll-free telephone helpline, a web-based portal or application, and direct communication with the Vigilance Officer or the Chairperson of the Audit Committee. Third, the policy must include provisions for handling anonymous complaints. While the identity of the complainant should be kept confidential, the policy should also allow for anonymous reporting where the complainant does not wish to disclose their identity.


Fourth, the investigation process section should set out the steps for processing complaints, including initial screening and acknowledgement (within a specified timeframe, typically 3 to 5 working days), preliminary assessment by the Vigilance Officer, referral to the audit committee for detailed investigation where warranted, appointment of an investigation team (which may include external experts), completion of investigation within a defined timeline (typically 30 to 60 days), and reporting of findings to the audit committee. Fifth, the policy must contain a robust protection against victimisation section, guaranteeing that no adverse action will be taken against any person who makes a complaint in good faith under the vigil mechanism.


Step 3: Audit Committee Oversight

The audit committee plays a central role in the vigil mechanism. Under both Section 177 and SEBI LODR Regulation 22, the audit committee is responsible for overseeing the functioning of the vigil mechanism, reviewing complaints at periodic intervals, ensuring that investigations are conducted fairly and impartially, recommending corrective action to the board based on investigation findings, and monitoring implementation of the corrective measures. The policy must also provide for direct access to the chairperson of the audit committee in exceptional cases, such as when the complaint is against the Vigilance Officer, a member of the audit committee, or a senior management official. For companies where an audit committee is not required to be constituted, the board of directors shall nominate a director to play the role of the audit committee for the purposes of the vigil mechanism. Companies that have an audit committee may also benefit from understanding the governance framework around nominee director rights and oppression claims.


Step 4: Protection Against Victimisation

The protection of whistleblowers from victimisation is not merely a best practice but a statutory requirement under Section 177(10). The policy must include an explicit guarantee that no adverse employment action (such as termination, demotion, suspension, or transfer) will be taken against any person who raises a concern in good faith under the vigil mechanism. If a complainant believes they are being victimised as a result of making a disclosure, they should be entitled to approach the chairperson of the audit committee directly. The policy should also specify the consequences for any person found to have victimised or retaliated against a whistleblower, which may include disciplinary action up to and including termination of employment.


At the same time, the policy should address frivolous or malicious complaints. If an investigation reveals that a complaint was made with mala fide intent or without any reasonable basis, the company may take appropriate action against the complainant. However, the threshold for finding mala fide should be high to ensure that employees are not deterred from raising genuine concerns.


Step 5: Implementation and Communication

Once the policy is approved by the board, it must be effectively communicated to all stakeholders. The implementation steps include publishing the policy on the company's website in a dedicated section (mandatory for listed companies under SEBI LODR Regulation 22), circulating the policy to all employees through internal communications, conducting awareness sessions and training programmes for employees and directors, setting up the complaint channels (email, helpline, portal), appointing and training the Vigilance Officer, and establishing a register to maintain records of all complaints received, investigations conducted, and actions taken.


Step 6: Annual Disclosure and Board Report

Section 177(9) requires that the details of the establishment of the vigil mechanism be disclosed by the company on its website (if any) and in the Board's Report. The annual disclosure should cover a confirmation that the vigil mechanism has been established and is operational, a summary of the number of complaints received during the year (without disclosing the identity of complainants), the number of complaints resolved and pending, whether any complaint remained unresolved for an unreasonable period, and a statement that no personnel have been denied access to the audit committee. For listed companies, the annual report must also include a statement that the company has established a vigil mechanism and that no director or employee has been denied access to the chairperson of the audit committee. The audit committee should review the functioning of the vigil mechanism at least once a year and report its findings to the board. For related governance disclosures, companies preparing their ESOP documentation should also consider the compliance framework discussed in our article on designing and implementing an ESOP under the Companies Act 2013.


Step 7: Periodic Review and Policy Updates

The whistleblower policy is not a static document. It must be reviewed periodically to ensure that it remains aligned with evolving regulatory requirements, organisational changes, and emerging best practices. The audit committee should conduct a comprehensive review of the policy at least once every two years, or more frequently if triggered by regulatory amendments or significant internal developments. The review should assess the effectiveness of the complaint channels, the adequacy of the protections against victimisation, the timeliness and quality of investigations conducted, and whether any structural changes within the organisation require amendments to the policy.


Listed companies should pay particular attention to any amendments to SEBI LODR Regulations, as SEBI periodically updates the corporate governance requirements applicable to listed entities. Similarly, changes to the Companies Act or related rules may necessitate updates to the vigil mechanism. Any amendments to the policy must be approved by the board and communicated to all employees. The updated policy should be published on the company's website and the previous version should be archived for record-keeping purposes.


Documentation and Record-Keeping

Proper documentation is essential for demonstrating compliance with Section 177(9) and for defending the company's position in the event of regulatory scrutiny or litigation. The company should maintain a comprehensive register of all complaints received under the vigil mechanism, the date and mode of receipt, the identity of the complainant (where disclosed), the nature of the complaint, the investigation process followed, the findings and recommendations, and the action taken by the management or the board. All investigation files, including witness statements, documentary evidence, and the investigation report, should be preserved for a minimum period as specified in the company's record retention policy, typically seven to eight years. Access to these records should be restricted to the Vigilance Officer, the audit committee, and authorised personnel to protect the confidentiality of complainants and witnesses.


Consequences of Non-Compliance

Failure to establish a vigil mechanism where required may result in penalties under Section 177(6) of the Companies Act, 2013. Additionally, for listed companies, non-compliance with Regulation 22 of the SEBI LODR Regulations may attract enforcement action by SEBI, including fines and directions. Beyond regulatory consequences, the absence of a vigil mechanism weakens the company's internal controls framework and increases the risk of undetected fraud, corruption, and financial irregularities. It is therefore in the company's interest to not only establish the mechanism but to ensure that it is functional, accessible, and trusted by employees.



Conclusion

Establishing a vigil mechanism under Section 177(9) of the Companies Act, 2013 is not merely a statutory compliance exercise but a fundamental component of sound corporate governance. A well-designed whistleblower policy, backed by audit committee oversight and genuine protections against victimisation, fosters a culture of transparency and accountability within the organisation. By following the steps outlined in this guide, companies can establish a mechanism that meets both the letter and spirit of the law, while providing a safe channel for employees and directors to raise concerns without fear of retaliation. For further reading on corporate governance and director-related compliance, consider our guide on obtaining a DIN and appointing a director under the Companies Act 2013.


Comments


bottom of page