Practical Nuances of Governance and Compliance Norms: The Importance of the Board's Role in ESG Disclosures

In today's complex business landscape, distinguishing management fraud from procedural aberrations is vital for addressing control overrides, governance lapses, compliance gaps, and revenue leakages. Effective compliance relies on frameworks like CARO 2020, the Companies Act 2013, SEBI (LODR) Regulations, 2015, and BRSR disclosures. Key areas include compliance certifications, data governance, validation checks, record-to-report controls, and robust communication between management and boards. Since April 2023, mandatory audit trail functionality ensures preservation of electronic evidence with source document support. This article highlights the critical role of Independent Directors in monitoring financial decisions, ensuring impartial investigations, and fostering enhanced disclosure norms to drive transparency and sustainable investments.

Effective governance requires strengthening the vigil mechanism and the board's role to address challenges associated with managerial override of controls, compliance gaps, and revenue leakages. In real-life situations, the operational definition of what constitutes fraud is often blurred and requires a complete sequence of evidential information trail. The challenges include the absence of a governance taxonomy that poses impediments in resolving matters in distinguishing fraudulent practices from genuine procedural lapses. The Environment, Social and Governance (ESG) factors are increasingly demanding and increase the importance of vouching, accounting trails, the preservation of source documents, the validation check, including tracing and tracking of budgets to end use monitoring of the various initiatives and measures taken by the management. Additionally, continuous monitoring of budgets and initiatives taken by management must be tracked and validated to maintain compliance and transparency. In some cases, the failure to escalate matters to governance boards or regulatory agencies results in delayed disclosures or post facto actions that could violate statutory reporting norms such as CARO 2020, applicable provisions of the Companies Act 2013, or SEBI (LODR) Regulations, 2015.

Further, frameworks such as CARO 2020, Internal Audit Standards, organizational policies, and company laws create distinctions between Key Managerial Personnel (KMP), senior management, non-management cadres, workers, and contractual employees. Such classifications are also applied across different segments, including gender, geography, corporate office, registered office, and project offices. A deep understanding of these distinctions is critical for ensuring regulatory compliance and effective ESG disclosures, particularly when considering the practical nuances of corporate governance in a diverse regulatory environment.

This article aims to address this gap by emphasizing the importance of data governance solutions, the necessity of validation checks in compliance certifications, and the creation of an evidential trail for impact assessments, particularly related to sustainability measures.

Data Validation in Business Reporting and ESG Disclosure

In professionally managed corporate business groups, the Chairman typically communicates the company's vision, mission, and ethical values through the Business Responsibility and Sustainability Reporting (BRSR) or erstwhile Business Responsibility Reports (BRR), in the annual report. These documents outline the company's strategic goals, aligned with business outlooks and value creation efforts, and demonstrate the organisation's commitment to ethical business practices.

However, a misclassification of data at the input stage, whether during data validation, accounting categorization, or initial analysis, can have disastrous consequences, in terms of audit risks and control risks. Such errors create long-term risks for organizations that neglect the critical importance of validating data at both the input and analysis stages. The accuracy of secondary data, annual reports, and ESG rating scores is directly linked to the integrity of primary data and the thoroughness of input validation checks. Ignoring these checks compromises the entire reporting framework and can undermine the credibility of ESG disclosures and financial reporting.

Case Study: Budgeting Controls and Financial Management

A foreign company's budgeting process, cost control mechanisms, and cash flow monitoring raised concerns, prompting an independent investigation in its Indian project office. This marked the critical importance of budgeting controls and financial management to report exceptions, abnormalities, overrides, variances and deviations to governance boards, audit committees, and key stakeholders.

The Chief Financial Officer (CFO), whose performance was tied to cost savings and budget utilization, exploited the system by outsourcing bookkeeping to his nephew, engaging in undisclosed related-party transactions, and fabricating expenses using false letterheads and rubber stamps. Revenues and collections were inflated through fictitious documentation, while legal notices added a layer of perceived authenticity.

The investigation was triggered by a seemingly minor anomaly, a handwritten cash memo in Hindi for Rs. 1,000 in Chennai, where Tamil or English is predominantly spoken. The CFO's overconfident statement, "You will find a voucher for every transaction," prompted deeper scrutiny. The audit team uncovered fabricated documents and other incriminating evidence, all meticulously documented.

This case underscores the necessity of robust governance frameworks, vigilance mechanisms, and proactive auditing to detect and address fraud, safeguarding organizational integrity and accountability.

External Validations

How to ascertain a conflict of interest? The chain of money traces from source to various entities, closes the loop on the evidential trail, where the money keeps recycling in various forms till it evaporates completely when it is converted into goods and services in the chain of money trail outside the organisation. This results in Non-Performing Assets (NPA) provisioning in bank records or is provision for bad debts in books of account after a period of limitation is over in recovery of dues, or is reflected in the form of failed projects or discontinued business operations. Often, the mastermind ensures control over the funds in the Payee Listed Entity and Payee Vendor Entity in the chain of money trails. These expense claims are generally booked in subsequent financial years after the closure of books. This makes detection of suspicious transactions difficult due to crossover of financial transactions beyond the audit purview period (generally after the month of April of the next year) spread over months in the next financial years to provide legitimacy in the accounting transactions in breaking down the amount of expense claims to smaller denominations that makes the entire transaction non-material or insignificant beyond scrutiny of the computer aided audit tools and other filtering mechanism.

Whenever there is a transition in leadership, data migration, software version change, or quarter and year-end accounting closures, these are areas of high risk priority in the planning stage of the audit process. These are transitions that require maintaining of records in versions, and require a thorough evaluation of managerial override of controls against any form of manual intervention. The alterations to computer programme codes, cybercrime, and other forms of manipulation are beyond the scope of this article. The primary focus is on the accounting trail, data accuracy, and validation checks in compliance management. A trail of how changes in data structure, contents are taken on record, is important from the point of view of validation of evidential information.

Another area of focus could be contracts executed, signed and liabilities created in the books by outgoing officials exiting the organisation and improper handover procedures. The symptomatic disorders could be:

  • (a) Wherein the greed factor is to recover as much amount as possible before such transfers in roles, within their authority, directly or through proxies and surrogate methods, or delegated authorities, like self-certification of claims without reaching out to reporting supervisors.
  • (b) What cannot be claimed directly called settlement of dues, is indirectly treated as business expense claims.
  • (c) The masking of expense heads in the digital payment system is a serious fraud risk that can impact the quality of financial reporting.
  • (d) The data analysis software can only throw light on abnormalities, whereas it requires an eagle eye, to distinguish personal expenses from regular business expenditures.
  • (e) Expense claims might have contracts in a proxy firm, ensuring monthly rental contracts with the organisation for hire charges, to ensure a parallel cash flow of operations, working in the company managing vehicle loan instalments for EMI that are paid from assured monthly rentals.

Financial Controllership

In Indian Corporations, there is a robust budgeting process and control mechanism, prudent norms on spending, conservatism, thriftiness, and austerity practiced. This is extended to suppliers and vendors in the value chain. All information related to bill passing and budget vs. actuals are routed through HoDs, and where there is collusion or concurrence amongst HoDs, the control fails, resulting in revenue leakages. These Budget Analyses at the functional and entity levels are consolidated, summarized, and reported as the Management Information System. When the findings or variation analyses reach a tipping point, these are escalated to higher authorities wherever there is no satisfactory response from HoDs. The budgeting controls play a crucial role in cost control and compliance management that cannot be seen in isolation. An integrated approach to compliance management, financial reporting, and governance practices would ensure that the big picture is presented before the governance board and its sub-committees.

The role of external consultants and 'outside-in' experts brings credibility to the process of investigation post a mandate from the management, governance board, or audit committee, preferably from independent directors, where there is a case of suspected management fraud or override of managerial controls as described under CARO 2020 and SEBI Regulations. The investigation plan and strategy normally include gathering preliminary information through interviews, survey methods, and process flow diagrams. This risk prioritisation of the issues enables a proper documentation process tuned to auditing standards and guidelines published by regulatory agencies.

Governance Challenges

Over the decades, there have been several corporate scandals where there is a lead and lag in reporting aberrations in the timely reporting of financial irregularities. These primarily relate to suspicious expense claims, expense frauds, and the misreporting of funds utilisation, often personal contributions or self-branding expenses disguised as business expense claims. These practices have been observed across various industries, including notable instances during major events such as large sports events in the country, and sponsorships and social engagements. As distinguished from CSR initiatives, often these events and activities, beyond an entity's business operations, involve crowd-sourcing of funds and settlement processes after the conclusion of the event to remove initial personal contributions. Such expense claims are commonly reviewed for linkages to the manipulation of funds and misclassification of expenses.

Leadership transitions, data migrations, software version changes, and the closing of financial periods (quarter or year-end) often present significant challenges in maintaining data integrity. These transitions require careful record management, especially to ensure the preservation of records across various versions. A thorough evaluation of managerial override of controls is essential during such transitions to prevent manual interventions that could lead to discrepancies. While alterations to program codes and cybercrimes fall outside the scope of this article, the primary focus remains on ensuring accurate accounting trails, maintaining data accuracy, and implementing effective validation checks in compliance management systems.

A detailed record trail is essential when addressing changes in data structure and content, especially from the perspective of validating evidential information. How these modifications or changes are handled must be clear and accountable, ideally with independent approval from a higher authority outside the direct chain of accounting transactions. This process ensures transparency and safeguards the integrity of the records.

While law and secretarial standards do not require verbatim transcription of board proceedings, capturing the essence of discussions effectively is vital. Such documentation serves as an evidential record, archived for future reference. In governance practices, management interactions with the governance board are often informal, verbal, and confidential. This can lead to issues when suspected aberrations or managerial overrides occur, particularly when the absence of documented records, notes, or justifications weakens the defence in a fair trial. Without proper documentation, issues may be dismissed prematurely to protect the brand's reputation, often at the expense of stakeholder interests. It is crucial that communication protocols follow established mandates from engagement terms, organisational procedures, and relevant laws and regulations. Using documented trails such as emails or other formal communication methods provides a strong defence, offering clarity and accountability for all stakeholders, particularly in situations involving scrutiny or legal examination.

Harmonious Interpretation of Laws and Regulations

The Companies Act, 2013, in conjunction with the SEBI (LODR) Regulations 2015, provides a robust framework for corporate governance and compliance. A harmonious reading of key provisions such as Section 2(60), Section 2(76), Section 134, Section 135, Section 138, Section 141, Section 143(12), Section 166, Section 177, Section 188, Section 197, Sections 241 to 246, Section 447, and Section 448 is essential to address the operational, legal, and regulatory aspects of the company's functioning, particularly in relation to Board and committee responsibilities.

The SEBI (LODR) Regulations, 2015 further supplement the Companies Act, 2013 by defining the operational modalities of the Board and its committees, ensuring that the implementation of company law, listing obligations, and transparency in reporting, especially in Environment, Social, and Governance (ESG) matters, are effectively integrated into corporate practices. This alignment is critical for reinforcing the organization's ethical and operational governance.

From a compliance management perspective, it is imperative that auditors, board members, and audit committee members ensure adherence to data governance practices, validating compliance certifications, and verifying the completeness, relevance, and sufficiency of contractual obligations disclosed. Furthermore, proactive measures such as conducting "Propriety Audits" during CFO transitions can significantly mitigate risks related to financial decisions that impact the long-term sustainability of the organization. These audits focus on legacy issues and establish clear accountability for individuals holding fiduciary responsibilities.

Key elements to monitor in this regard include:

  • 1. CFO Transitions: CFO transitions require careful examination of job roles, employment records, and appointment dates to ensure a smooth handover and address legacy issues. Documenting formal handover processes, including board resolutions, is crucial. Propriety audits are recommended to assign accountability for legacy matters in financial management and reporting. Such audits should adhere to legal and regulatory frameworks, including the Companies Act 2013, covering CFO appointments, terms, remuneration, and claim settlements. These measures ensure compliance with board mandates and uphold transparency, fostering trust in financial reporting and governance during CFO transitions.
  • 2. Audit Trails: Examining audit findings, trail actions, and compliance reports is critical to maintaining financial record accuracy and integrity during leadership transitions. The Ministry of Corporate Affairs reinforced this through amendments to Rule 3(1) of the Companies (Accounts) Rules, 2014, mandating the implementation of audit trail functionality. Effective from FY 2023-24, this requirement ensures transparent tracking of financial data modifications, bolstering accountability and regulatory compliance. Such measures strengthen governance frameworks by providing robust documentation, which becomes essential during leadership changes, safeguarding organizational interests, and upholding confidence in financial reporting practices.
  • 3. Regulatory Compliance: Ensuring smooth data migration, seamless role transitions, and proper handling of conflicts of interest requires strict adherence to mandatory secretarial standards, accounting standards, and compliance norms set by the Ministry of Corporate Affairs (MCA). Accurate and transparent disclosures are essential to meet statutory requirements. Special attention must be given to timely and error-free filings, ensuring alignment with regulatory expectations. By prioritizing these measures, organizations can strengthen governance, uphold accountability, and maintain stakeholder confidence throughout role transitions and compliance processes.

By implementing these measures, organizations can enhance governance mechanisms, ensure transparency, and promote long-term sustainability while adhering to the Companies Act, 2013, prescribed rules therein, and SEBI regulations.

Conclusion

This article underscores the significance of strengthening vigil mechanisms, fraud reporting backed by independent scrutiny, and clear communication protocols for senior management personnel in addressing control overrides. It advocates for improved transparency in disclosures and accountability in corporate governance. Emphasizing fraud prevention, data validation, and regulatory compliance, it highlights the role of special investigative assignments in enhancing credibility and attracting sustainable investments. The aim is to foster robust corporate governance and drive long-term sustainability towards value-driven growth in Indian corporates.

References

  • The Companies Act, 2013 https://www.mca.gov.in/
  • The SEBI (Listing Obligations and Disclosure Requirements (LODR)) Regulations, 2015. https://www.sebi.gov.in/
  • The Institute of Chartered Accountants of India (ICAI). (2020). CARO 2020 Companies (Auditor's Report) Order. Guidance Note by ICAI. https://www.icai.org/
  • International Auditing and Assurance Standards Board (IAASB). (2018). https://www.iaasb.org/
  • Ministry of Corporate Affairs (MCA). (2022). Provisions for Compliance Certification and Validation of Accounting Trails. Circulars and Notifications. https://www.mca.gov.in/
  • Reserve Bank of India (RBI). (2021). Guidelines on Risk-Based Internal Audit for NBFCs. Regulatory Advisory. https://www.rbi.org.in/
  • Organisation for Economic Co-operation and Development (OECD). (2019). Guidelines on Corporate Governance. https://www.oecd.org/corporate/
  • Enhanced Framework for Corporate Governance Reporting. SEBI Circular No. SEBI/HO/CFD/CMD-2/P/CIR/2021 is a circular by the Securities and Exchange Board of India (SEBI) that specifies the format for corporate governance compliance reports by listed entities. The circular was issued on May 31, 2021. https://www.sebi.gov.in/
  • International Organization of Securities Commissions (IOSCO). (2020). Good Practices for Audit Committees in Supporting Audit Quality. Regulatory Frameworks. https://www.iosco.org/
  • Institute of Company Secretaries of India (ICSI). (2019). Secretarial Standards on Meetings of the Board of Directors (SS-1). https://www.icsi.edu/