Secretarial Audit was introduced with an important governance objective: to provide an independent assessment of whether a company is complying with applicable laws, regulations and secretarial standards and whether its governance processes are operating as intended.
Yet, in practice, the value of Secretarial Audit is often measured by a much narrower question: “Have we complied?”
This creates a fundamental tension. A company may have a compliance calendar, registers, policies, filings and Board minutes that are all in place, while still having weaknesses in the way compliance risks are identified, escalated, monitored and addressed.
The issue, therefore, may not be the absence of a regulatory framework. It is whether Secretarial Audit is being used as an independent governance assurance mechanism, or merely as an annual compliance certification exercise.
The statutory framework requires Secretarial Audit for listed companies and specified classes of companies, with the report in Form MR-3. Listed entities are also subject to the annual Secretarial Compliance Report under Regulation 24A of the SEBI LODR Regulations.
The breadth of the mandate is significant. However, breadth can itself create a risk: when an audit covers a large number of laws and compliances within a defined annual cycle, the exercise can become focused on whether evidence exists for each requirement rather than why a particular compliance matters and whether the underlying process is reliable.
A filing may have been made. A meeting may have been held. An approval may have been obtained. A register may have been maintained.
But governance assurance requires another level of enquiry:
Was the process timely? Was it substantive? Was the right information placed before the Board? Was the deviation identified internally? Was it recurring? And, most importantly, has the underlying weakness been corrected?
This distinction between evidence of compliance and assurance over the compliance environment is central to making Secretarial Audit more effective.
1. Independence begins with the information on which the audit is based
One of the biggest practical risks is that the Secretarial Auditor may receive most of the information through the company secretary or secretarial department.
This is understandable from an administrative perspective, but it can unintentionally make the audit dependent on the same function whose processes are being reviewed.
The auditor should therefore adopt a more cross-functional evidence-gathering approach.
For example:
This does not mean that the Secretarial Department is unreliable. It means that an independent audit should not depend predominantly on a single information channel, especially when that single source is the auditee.
2. Management representation should support — not substitute — verification
Management representation has a legitimate role in an audit. But it becomes problematic when a representation effectively becomes the evidence for a matter that could reasonably have been independently verified.
ICSI’s own Manual on Secretarial Audit states that the Secretarial Auditor may use management representation as part of audit evidence, but also specifically cautions that matters capable of direct verification should be subject to adequate enquiry and that merely obtaining management certification may defeat the purpose of the audit.
This is an important governance principle.
A representation should answer “what management says”. An audit should establish “what the evidence shows.”
The latter may require comparison with MCA filings, stock exchange disclosures, statutory registers, Board and committee minutes, regulatory correspondence, internal records and other independent sources.
3. A clean report does not necessarily mean a strong compliance environment
A company can have no major qualification in its Secretarial Audit Report and still have a weak compliance culture.
Why?
Because governance failures are not always isolated breaches. They can be process failures.
For example, a delayed disclosure may be corrected before year-end. From a narrow compliance perspective, the matter may appear closed. From a governance perspective, however, the more important question is:
Why did the system allow the delay to occur in the first place?
Was responsibility unclear? Was there inadequate escalation? Did the compliance system fail to capture a regulatory change? Was the issue identified internally or only during the audit?
The audit therefore needs to distinguish between:
one-off deviation → recurring deviation → systemic weakness.
The last two are particularly relevant to the Board.
4. The Board receives the report — but does it receive the insight?
The Secretarial Audit Report is ultimately an important governance document. Yet its placement before the Board can become procedural: the report is circulated, taken as read and noted.
That is not necessarily meaningful Board oversight.
The Board should receive a risk-oriented summary of the audit, identifying:
The Secretarial Auditor should have an opportunity to explain these matters directly to the Board or Audit Committee rather than relying entirely on management to present the report.
This becomes particularly important because the Board is not merely interested in whether the company complied with the law yesterday. It needs assurance that the system is capable of complying with the law tomorrow.
5. The real gap may be between detection and remediation
Secretarial Audit is generally performed annually. Consequently, a compliance failure arising shortly after the audit may remain undetected through the rest of the year.
More importantly, even where the auditor identifies an issue, the value of the audit is limited if there is no mechanism to track whether the issue has actually been resolved.
The focus should therefore move from:
“Was a non-compliance reported?”
to:
“Was the root cause addressed, and has the issue stopped recurring?”
A Board-level dashboard tracking significant Secretarial Audit observations across years could therefore be more useful than simply presenting the latest MR-3.
The objective should not be to turn Secretarial Audit into an internal audit function. It should be to ensure that the external assurance provided by the Secretarial Auditor feeds into the company’s governance and remediation process.
6. MR-3 could communicate governance risk more clearly
The standardised format of MR-3 provides consistency, but standardisation can also make it difficult for stakeholders to distinguish between a minor procedural deviation and a significant governance concern.
Phrases such as “generally complied with” may not adequately communicate the nature or significance of a deviation.
Where relevant, the reporting should make clear:
The objective is not to make the report longer. It is to make it more decision-useful.
7. The recent strengthening of auditor appointment is an opportunity
SEBI’s revised framework for listed entities which is applicable from April 1, 2025 has introduced stronger requirements around the appointment and tenure of Secretarial Auditors. An individual can be appointed for one term of up to five consecutive years, while a firm can be appointed for up to two such terms; the tenure cannot be less than five years. The framework also addresses eligibility, disqualifications and prohibited services.
This is significant from a governance perspective.
The longer, defined tenure can potentially give an auditor greater opportunity to understand the company’s systems and identify recurring weaknesses rather than treating each year as an isolated compliance exercise.
But tenure alone does not create independence.
The real test will be whether the auditor is willing to challenge management, whether the Board engages meaningfully with the findings, and whether the audit demonstrates professional scepticism rather than procedural familiarity.
The effectiveness of Secretarial Audit cannot rest with the Secretarial Auditor alone. It requires a corresponding effort from the company.
For the company, this means providing complete and timely information, enabling access to relevant functions and records, being transparent about exceptions and regulatory concerns, and treating audit observations as inputs for remediation rather than merely as matters to be closed before the report is issued.
For the Secretarial Auditor, it means exercising professional scepticism, going beyond information routed through the secretarial function, corroborating management representations, understanding the company’s business and regulatory risk profile, identifying recurring or systemic weaknesses and communicating matters that require Board attention.
The relationship should therefore not be viewed as “the company provides information and the auditor verifies compliance.” It should be viewed as a process in which the company enables transparency and the auditor provides independent challenge.
Ultimately, the quality of Secretarial Audit is a function of both the quality of information made available to the auditor and the quality of challenge applied by the auditor.
The evolution required is therefore not necessarily from “more compliance” to “more compliance.”
It is from:
| Traditional approach | Governance-oriented approach |
|---|---|
| Was the requirement complied with? | Was the compliance process effective? |
| Is documentary evidence available? | Does the evidence establish what actually happened? |
| Management confirms compliance | Management representation is corroborated |
| Annual report of exceptions | Identification of recurring/systemic weaknesses |
| Report placed before the Board | Findings discussed with the Board |
| Issue identified | Root cause and remediation tracked |
| Compliance calendar | Dynamic compliance-risk framework |
| MR-3 as a statutory document | MR-3 as a source of governance assurance |
The effectiveness of Secretarial Audit should not be judged by the number of qualifications in MR-3.
A company with no qualifications is not necessarily a company with no governance risk.
The more meaningful question is whether the Secretarial Auditor is able to provide the Board with an independent view of the quality of the company’s compliance and governance processes — including the areas where the company technically complied but the process itself remains vulnerable.
Secretarial Audit therefore has the potential to move beyond being a statutory certification exercise.
The opportunity is to make it a Board-level early-warning mechanism: one that identifies not only breaches of law, but weaknesses in the systems, processes and governance behaviours that can eventually lead to those breaches.
The real measure of an effective Secretarial Audit is not simply that it finds non-compliance.
It is whether, after the audit, the Board understands where the organisation is vulnerable — and whether the organisation becomes less vulnerable because of it.
Mahima Chopra and Prajesha Nair
© 2026 Excellence Enablers. All Rights Reserved.