POSH Policy Drafting in India: The Complete Legal Guide
What Is POSH Policy Drafting?
POSH policy drafting is the legal process of preparing a written internal policy that documents how an organisation prevents, prohibits and redresses workplace sexual harassment in compliance with the Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013. A drafted policy sets out the Internal Committee (IC) composition, the complaint filing mechanism, the inquiry procedure, interim relief options, the disciplinary framework, awareness obligations and the annual reporting structure — all customised to the company's size, sector and workforce mix.
The distinction between a POSH policy that looks compliant and one that is defensible is where most organisations get caught. A downloadable template with the company name at the top will pass a first-glance HR review, but it will collapse the moment the Internal Committee is asked to defend it in an inquiry, before a District Officer under Rule 14, or before a High Court under a writ challenging an IC recommendation. Real POSH policies are advocate-drafted from the statutory text upward, reflect current Supreme Court and High Court jurisprudence (particularly the 2025 Dr. Sohail Malik ruling), and are tailored to how work actually happens in your organisation — remote, contract, factory-floor, multi-branch, or hybrid.
Regalwhiz Law Chambers has drafted POSH policies for over 450 companies across India, from Series A startups with 12 employees to Nifty 500 listed companies with 40,000+. The workflow is always the same: a discovery call to understand the workforce, gap analysis of any existing policy, sector-specific drafting by an advocate, Board resolution and IC constitution order preparation, and rollout with awareness training. Standard turnaround is 3 working days; urgent 24-hour drafting is available for board-meeting deadlines.
The Governing Statute & Rules
Three legal instruments sit behind every POSH policy in India. A drafting error at any one of these three levels is enough to invalidate the entire policy in the eyes of the Internal Committee and, on escalation, the courts.
The POSH Act, 2013 — full name, the Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013 — is the primary statute. It creates the substantive obligation. Section 19 places the duty on the employer to formulate and widely disseminate an anti-sexual-harassment policy. Section 4 mandates the constitution of an Internal Committee at every workplace with 10 or more employees. Sections 9 through 13 govern complaint filing, inquiry procedure, interim relief, and recommendations. Section 14 penalises false or malicious complaints. Section 16 imposes confidentiality obligations, and Section 26 sets penalties of ₹50,000 for non-compliance, escalating to licence cancellation on repeat default.
The POSH Rules, 2013 operationalise the Act. Rule 4 specifies the qualifications of the External Member. Rule 6 lays down inquiry procedure. Rule 7 governs manner of inquiry into complaints. Rule 8 covers the inquiry report. Rule 14 — critical for every drafter — prescribes the annual report that every employer must submit to the District Officer by 31 January each year covering the preceding calendar year's complaint data.
The Companies Act, 2013, Section 134, layers a corporate reporting obligation on top. Every applicable company must include POSH data in the Directors' Report/Board Report annexed to its financial statements. The Companies (Accounts) Rules, 2014 — as amended by the Companies (Accounts) Second Amendment Rules, 2025 notified in July 2025 — expand the disclosure to include workforce composition, complaint numbers and IC constitution details. Listed companies file additionally under SEBI LODR Regulation 34(2)(f) as part of BRSR Principle 5. Judicial guidance from Vishaka & Ors v. State of Rajasthan (1997), Apparel Export Promotion Council v. A.K. Chopra (1999), Aureliano Fernandes v. State of Goa (2023), and Dr. Sohail Malik v. Union of India (2025) shapes how these instruments are read in practice.
Is a POSH Policy Legally Mandatory in India?
Yes. Under Section 19 of the POSH Act, 2013, every workplace with 10 or more employees must have a written POSH policy and constitute an Internal Committee (IC). The applicability threshold has no exceptions based on sector, entity type, revenue, or workforce composition. It applies uniformly to:
- Private limited companies, public limited companies, and one-person companies
- LLPs, partnerships and proprietorships
- NGOs, trusts, societies, and Section 8 companies
- Hospitals, nursing homes, dispensaries and medical establishments
- Educational institutions — schools, colleges, universities, coaching centres
- Sports institutes and residential training facilities
- Government offices, PSUs, statutory bodies and local authorities
- Any workplace including domestic workers under specific provisions
The 10-employee count includes all workers — regular payroll, contract, temporary, ad-hoc, apprentices, interns, volunteers, whether working on-site, remote, or hybrid. It does not matter whether all 10 are women; the policy is mandatory once the headcount threshold is met.
For workplaces with fewer than 10 employees, and for cases involving domestic workers, complaints go to the Local Committee (LC) constituted by the District Officer under Section 6 of the Act — not to an IC. But the policy obligation attaches to the employer regardless of headcount if a workplace is covered.
Non-compliance attracts a monetary penalty up to ₹50,000 for the first offence under Section 26. For repeat offences, the penalty is doubled and the employer's trade licence or registration can be cancelled, withdrawn, or non-renewed by the relevant authority. Beyond statutory penalties, the reputational and litigation costs of an inquiry falling apart because the underlying policy was defective are substantially higher.
What Must a Compliant POSH Policy Contain?
A defensible POSH policy has at minimum eleven mandatory components. Missing any of these is the single most common reason District Officers reject Rule 14 annual reports and courts remand IC recommendations.
- Statutory definitions — sexual harassment, workplace, employee, aggrieved woman, respondent — reproduced with the specific expansions post the 2025 Sohail Malik ruling covering cross-organisation respondents.
- Scope and applicability — explicit coverage of on-site, remote, hybrid, contract, intern, apprentice, vendor-employee categories, and geographic scope including virtual meetings and third-party premises.
- Internal Committee constitution — Presiding Officer (senior woman), two internal members (at least half must be women), one External Member (NGO panel or advocate under Rule 4), with three-year terms and replacement mechanics.
- Complaint filing mechanism — written complaint format, 3-month filing window (extendable by 3 months on Section 9 grounds), multiple intake channels including email and physical form, translations available, anti-victimisation safeguards.
- Conciliation option — under Section 10, the aggrieved may request conciliation before formal inquiry; the settlement must be non-monetary and recorded.
- Inquiry and investigation procedure — Rules of Natural Justice, 90-day statutory timeline, witness examination, evidence handling, cross-examination rights, IC report format under Rule 8.
- Interim relief options — Section 12 provisions for leave, transfer, no-contact orders, and other measures pending inquiry.
- Confidentiality obligations — Section 16 duties, list of authorised persons, penalties for breach, and the RTI Act carve-out.
- Disciplinary framework — Section 13 recommendations mapped to service rules: warning, written apology, suspension, termination, and monetary compensation deduction from salary.
- Awareness and training obligations — Section 19 employer duties: annual employee training, IC member capacity building, posters in prominent workplace locations, induction integration.
- Annual reporting — the Rule 14 annual report to District Officer, Board Report disclosure under Section 134, and (for listed cos) BRSR Principle 5 hooks.
Beyond these mandatory components, a well-drafted policy will also include: false complaint safeguards under Section 14; whistleblower and retaliation protections; a link to the company's code of conduct without substituting it; and clear delegation of the POSH policy owner (typically the HR Head, CHRO or Company Secretary) with responsibility for annual review, statutory refresh and IC support.
Standard Template vs Advocate-Drafted Policy
The gap between a downloaded template and an advocate-drafted policy is not stylistic — it is defensibility. Here is what District Officers, ICs and courts actually check:
| Element | Template | Advocate-Drafted |
|---|---|---|
| Definition of workplace | Generic — copy from Act | Explicitly covers remote, WFH, virtual meetings, third-party premises, vendor sites |
| Respondent scope | Only own employees | Cross-org respondents per Sohail Malik 2025 |
| IC composition | Names left blank | Board resolution + appointment letters + External Member sourced |
| Inquiry procedure | Reproduces Section 11 verbatim | Step-by-step with hearing scripts, evidence protocols, IC minutes format |
| Sector-specific examples | None | Real scenarios for IT (WFH, virtual), manufacturing (shop-floor, contract), BFSI (branch, client-facing) |
| Language support | English only | Translated poster + handout in workforce languages |
| Annual review | Not addressed | Owner, frequency, statutory trigger events written in |
| Case law citations | Vishaka 1997 only | Vishaka, A.K. Chopra, Aureliano Fernandes 2023, Sohail Malik 2025 |
| BRSR alignment (listed) | None | Cross-references to Principle 5 disclosure hooks |
| Legal opinion | None — user takes the risk | Signed by advocate; you rely on their opinion in an inquiry |
Templates are appropriate as a checklist against which to test an advocate-drafted policy — never as the deliverable itself. Companies that draft in-house from templates typically fail one of two audits: (1) their IC cannot cite the policy to defend a procedural challenge in an inquiry; or (2) their District Officer or SEBI BRSR Core assessor flags the disclosure as inconsistent with the underlying policy language.
How to Draft a POSH Policy: Step-by-Step
The following is the process Regalwhiz follows on every drafting engagement. Even if you draft in-house, this sequence closes the most common gaps.
Step 1 — Discovery & scoping (30 minutes)
Map the workforce: total headcount, split between on-site, remote, contract, and interns; number of women employees and their distribution across levels; number and location of branches/offices; industry sector; languages spoken; and whether the company is listed. This determines the policy shape.
Step 2 — Existing policy gap analysis (1 day)
If a policy exists, audit it clause-by-clause against the eleven mandatory components listed above, and against post-2023 case law. Flag statutory misalignments, missing scope, template language, absence of sector examples, and BRSR non-alignment (for listed cos). Deliver a gap report before drafting.
Step 3 — Advocate-led drafting (1-2 days)
An advocate drafts the policy with sector-specific language, explicit scope for the workforce categories identified in Step 1, IC procedures aligned with Section 11 and Rule 7, and citations to current case law. The draft goes through legal review before it moves to the company.
Step 4 — Board resolution & IC constitution (parallel)
While the draft is being finalised, the Board resolution adopting the policy and constituting the IC is drafted. The External Member is sourced, credentials verified, appointment letter drafted, and consent obtained. The IC constitution order is prepared for company sign-off.
Step 5 — Board adoption & sign-off
The policy is presented to the Board for approval — typically along with the IC constitution order and awareness rollout plan. The Board resolution is minuted and the effective date recorded. For companies with an audit committee, the item is routed through the audit committee before the Board.
Step 6 — Rollout & awareness
Publish the policy on the intranet, email all employees with an acknowledgement request, put up statutory posters in every workplace location including remote-work employee handbooks, run a launch-day awareness session, and integrate the policy into new-hire induction. Regalwhiz delivers the awareness handout, poster (in workforce languages), IC induction training and acknowledgement tracker as part of the Complete package.
Step 7 — Annual review cycle
Set a calendar reminder for annual review — typically aligned with the Rule 14 annual report cycle (before 31 January each year). Refresh the policy for any statutory amendments, fresh case law, IC changes, and organisational changes. Regalwhiz includes a free annual refresh for 12 months post-drafting.
Sector-Specific Considerations
Generic POSH policies fail because harassment risk profiles vary enormously across sectors. Here are the sector-specific angles a drafter must build in:
IT services, SaaS, GCCs
Remote and hybrid workforce means workplace definition must explicitly cover video calls, shared workspaces, Slack/Teams DMs, and remote work-from-home scenarios. Cross-border managers (Indian ICs handling complaints against non-Indian managers) need special handling. Async complaints — text messages, chat platform screenshots — need evidence-handling protocols. GCCs must reconcile with parent-company codes of conduct that often reference US or EU harassment law.
Manufacturing, engineering, factories
Shop-floor scenarios, shift scheduling, low female representation, contract labour, safety officer coordination, and multi-language delivery are the real risk points. Policy poster must be in workforce languages (Tamil, Hindi, Telugu, Marathi, Kannada, etc.). IC members must be trained on shop-floor case types. Contract worker coverage must be explicit — the principal employer is liable regardless of whether the contract worker is on their payroll.
Healthcare, hospitals, nursing homes
Patient-facing staff, night-shift dynamics, hierarchical doctor-nurse-technician power imbalances, and dignity-based complaints that overlap with POSH — all need custom drafting. Third-party premises (patient homes for visiting staff), student interns (medical/nursing students), and consulting doctors on visiting terms all need scope treatment.
BFSI, listed companies
Branch network training, multi-city IC coordination, SEBI BRSR alignment (top 1,000 listed), and RBI compliance overlays. IC composition rules may need to accommodate branch escalation to a central IC. BRSR Principle 5 disclosure hooks must be pre-drafted into the policy so annual reporting is a copy-paste exercise, not a redraft.
Startups, D2C, early-stage companies
Series B due-diligence, cap-table cleanup, investor expectations. First-time HR process. External Member sourcing for lean teams (no in-house legal). POSH policy is one of the first three documents an investor DD lawyer will ask for — a template answer creates a red flag; an advocate-drafted policy is a green flag.
Educational institutions, coaching centres
UGC/AICTE guidelines run parallel to POSH. Student inclusion in policy scope (as complainants and — separately — as third-party respondents). Hostel staff coverage. Vishaka guidelines still apply for the pre-employment relationship, per Aureliano Fernandes 2023. Principal, warden, and admin staff need distinct training tracks.
Board Approval & Publication Requirements
POSH policy adoption is a Board-level act, not an HR function. Three legal reasons:
- The policy binds the company as a whole and creates liability for the Directors under Section 19 read with Section 26. Directors cannot claim ignorance if the policy is defective or absent.
- The Board Report under Section 134 of the Companies Act, 2013 must confirm the company has a POSH policy in place. This confirmation is signed by the Directors.
- The IC constitution and External Member appointment are Board-level appointments in most companies. The External Member's term (three years under Rule 4) is a governance appointment, not an HR one.
The Board resolution should therefore: (a) approve the POSH policy with an effective date; (b) constitute the IC with named members and terms; (c) approve the External Member appointment and remuneration structure; (d) authorise the HR Head or Company Secretary to publish the policy and roll out awareness training; and (e) require annual review at a specified Board or committee meeting.
Publication requirements under Section 19 and the POSH Rules are specific:
- Written policy widely disseminated to all employees
- Statutory poster displayed conspicuously at every workplace (branches, offices, factory locations)
- IC constitution order displayed with member names, contact details and complaint procedure
- Awareness training conducted at least annually
- Induction integration for all new hires
- Policy translated into languages workforce actually reads
For listed companies, additional disclosure requirements attach — website disclosure of the policy (per LODR), Corporate Governance Report reference, and BRSR Principle 5 disclosure alignment.
When Does a POSH Policy Need Revision?
Annual review is baseline. Beyond that, five triggers require an immediate revision — not just a review:
- Statutory amendments — POSH Act, Rules, or Companies (Accounts) Rules amendments. The July 2025 amendment to the Companies (Accounts) Rules is the most recent example.
- Significant judicial rulings — the 2025 Sohail Malik ruling on cross-organisation jurisdiction and the 2023 Aureliano Fernandes ruling on institutional compliance both triggered mandatory revisions.
- Change in External Member — a new External Member appointment, or resignation of an incumbent, requires an IC constitution order update and often a policy footer refresh.
- Organisational change — merger, acquisition, listing, IPO filing, workforce expansion beyond a threshold (e.g., crossing 500 employees triggers additional Companies Act reporting), or new branches/subsidiaries.
- An IC failure or successful challenge — if an IC recommendation is remanded by a court, or a District Officer flags the policy, or an inquiry falls apart because of a policy gap, the policy must be revised before the next inquiry.
Best practice: an advocate-drafted policy comes with a 12-month refresh clause. Regalwhiz includes this at no extra cost. Companies that treat POSH policy as a one-time document, not a living instrument, invariably discover the mismatch during the next inquiry.
10 Common Drafting Errors That Cause IC Failures
Cataloguing what goes wrong is more useful than describing what should go right. In our review of over 200 pre-existing policies before drafting, these ten errors appear again and again:
- Verbatim reproduction of the Act without operational detail — the IC has statutory text but no procedure to run an inquiry.
- Undefined workplace scope — no explicit coverage of remote, virtual meetings, third-party premises, or vendor sites. Post-COVID this is the #1 gap.
- Missing 2025 Sohail Malik coverage — respondent scope limited to own employees, leaving vendor-employee and cross-org complaints unaddressed.
- External Member with vendor conflict — appointed advocate is also the company's panel lawyer, invalidating IC independence.
- Complaint window silence — no explicit statement of the 3-month filing window and 3-month extension mechanism under Section 9.
- Conciliation option omitted — Section 10 skipped entirely, leaving no non-monetary settlement path.
- Inquiry timeline vague — 90-day statutory limit under Section 11(4) not written in with an internal calendar owner.
- No interim relief detail — Section 12 measures listed generically without an approval route or triggering conditions.
- Confidentiality breach penalties absent — Section 16 duties mentioned but no consequence framework for authorised persons who leak.
- No annual reporting link — Rule 14 filing and Board Report disclosure hooks not built into the policy owner's calendar.
Every one of these errors is fixable in re-drafting. What is harder to fix is the trail of IC decisions taken under a defective policy — which is why timing matters. Fix the policy before the next inquiry, not during it.
2025–2026 Legal Updates Affecting POSH Policies
Three developments in 2025 fundamentally reshape what a POSH policy must say. Every policy drafted before mid-2025 needs a refresh to reflect these.
Dr. Sohail Malik v. Union of India (2025)
The Supreme Court held that an Internal Committee has jurisdiction over complaints where the respondent belongs to a different organisation. This means POSH policies must now explicitly extend respondent scope to vendor-employees, contractor personnel, cross-organisation staff at shared workplaces, and client-facing complaints where the aggrieved is an employee of one entity and the respondent is from another. Policies pre-2025 typically limit respondent scope to "any employee of the company," which is now insufficient. Regalwhiz-drafted policies from mid-2025 onwards include explicit cross-org clauses, IC intake procedures for such matters, and template MoUs with vendor firms enabling evidence access.
Companies (Accounts) Second Amendment Rules, 2025 (July 2025)
The July 2025 MCA amendment to Rule 8 of the Companies (Accounts) Rules, 2014 expanded the Board Report disclosure. Every applicable company must now disclose in the Board Report: (a) the number of complaints of sexual harassment received during the FY; (b) the number of complaints disposed of during the FY; (c) the number of cases pending for more than 90 days; and (d) the number of workshops or awareness programmes carried out. The prior narrower disclosure has been superseded. Policies drafted before July 2025 typically have a Board Report reference that no longer aligns.
SEBI Industry Standards on BRSR Core (December 2024)
For listed companies in the top 500 by market cap, FY 2025-26 BRSR filings attract BRSR Core reasonable assurance by an independent third-party. The POSH-related Principle 5 disclosures now face independent audit. Policies for listed cos must therefore build in assurance-ready IC minutes format, complaint register standards, and External Member independence documentation — none of which are addressed in a standard policy template.
Aureliano Fernandes v. State of Goa (2023 — reaffirmed 2025)
The Supreme Court reaffirmed that institutional compliance under the POSH Act is a continuing obligation — not a one-time policy adoption. Employers must demonstrate policy dissemination, IC functionality, ongoing training, and annual reporting. Policies without an annual review owner and reporting calendar are vulnerable to this standard.
Cost of Professional POSH Policy Drafting
Professional POSH policy drafting in India ranges from ₹8,999 for a baseline statutory-compliant policy up to ₹1.5 lakh+ for enterprise-grade multi-entity engagements. The typical Regalwhiz pricing structure:
| Package | Scope | Price |
|---|---|---|
| Basic | Standard baseline policy, 10-50 employees, single location | ₹8,999 |
| Company | Sector-customised, IC constitution, Board resolution, 50-500 employees | ₹18,999 |
| Complete | Policy + IC + training + 12-month advocate support | ₹34,999 |
| Urgent | 24-hour advocate-drafted policy for board-meeting deadlines | ₹49,999 |
| Enterprise | Multi-entity groups, listed companies, BRSR-aligned | Custom quote |
All packages include a free 12-month statutory update refresh — if any statute or ruling requires policy revision within 12 months of drafting, the update is at no additional cost. GST is extra. Prices are indicative; exact quotes depend on workforce size, number of locations and sector complexity.
Compared to the cost of a defective policy — a single IC recommendation quashed by a High Court can cost ₹5-15 lakh in legal fees plus reputational damage — even the Enterprise tier is a fraction of the downside. For SEBI-listed companies facing BRSR Core assurance, a defective policy exposes the company to qualified audit reports and adverse ESG ratings that hit market capitalisation.
Penalties for Non-Compliant POSH Policies
Statutory penalties are only the starting point. The real cost of a non-compliant policy comes from the follow-on consequences.
Direct statutory penalties (Section 26 of the POSH Act, 2013)
- First offence — monetary penalty up to ₹50,000
- Repeat offence — penalty doubled + cancellation/withdrawal/non-renewal of registration, licence or approval by the relevant authority
- Applicable to — every employer who fails to constitute IC, adopt policy, submit annual report, or conduct awareness
Cascading corporate consequences
- Companies Act, Section 134 — Directors' Report must confirm POSH policy exists; false confirmation exposes Directors to Section 447 (fraud) liability
- SEBI LODR (listed cos) — inaccurate BRSR Principle 5 disclosure triggers show-cause notices, monetary penalties, and adverse ESG ratings
- MCA Board Report reconciliation — mismatch between Board Report POSH data and BRSR data invites audit qualifications
- Rule 14 non-filing — District Officer inspection, penalty, and public listing on defaulters (in some states)
- Individual IC decisions vulnerable — every recommendation issued under a defective policy can be challenged and remanded
- Insurance impact — D&O and employment practices liability insurance may deny cover for claims arising under a non-compliant policy
Reputational and workforce impact
Publicly reported POSH failures — either through media coverage of an inquiry gone wrong, an employee lawsuit, or an ESG rating agency downgrade — carry costs that dwarf the statutory penalty. Talent acquisition, employer branding, and institutional investor confidence all take material hits. The 2024 case of a Nifty 500 IT services company that lost a High Court challenge to an IC recommendation, purely on the ground that the underlying policy did not cover remote workers, is the textbook example: statutory penalty ₹50,000, actual cost estimated at ₹8 crore in legal, PR, and workforce retention response.
Legal References & Sources
Statutes
- Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013 — full statute, Sections 1-30 particularly Sections 4, 9-13, 16, 19 and 26
- Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Rules, 2013 — Rules 4, 6, 7, 8, and 14
- Companies Act, 2013 — Section 134 read with Section 447
- Companies (Accounts) Rules, 2014 as amended by Companies (Accounts) Second Amendment Rules, 2025 (notified July 2025) — Rule 8
- SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 — Regulation 34(2)(f) and Schedule V
- Industrial Disputes Act, 1947 (for interplay with disciplinary provisions)
- Constitution of India — Articles 14, 15, 19 and 21 (dignity jurisprudence)
Key case law
- Vishaka & Ors v. State of Rajasthan (1997) 6 SCC 241 — foundational case, Vishaka Guidelines
- Apparel Export Promotion Council v. A.K. Chopra (1999) 1 SCC 759 — extended definition of sexual harassment
- Medha Kotwal Lele v. Union of India (2013) 1 SCC 297 — enforcement of Vishaka Guidelines
- Aureliano Fernandes v. State of Goa (2023) 8 SCC 461 — continuing institutional compliance obligation
- Dr. Sohail Malik v. Union of India (2025) — IC jurisdiction over cross-organisation respondents
SEBI & MCA circulars
- SEBI Circular SEBI/HO/CFD/CFD-SEC-2/P/CIR/2023/122 dated 12 July 2023 — BRSR framework, Annexure II
- SEBI Industry Standards on BRSR Core dated 20 December 2024 — BRSR Core reasonable assurance
- MCA Notification G.S.R. [pending] — Companies (Accounts) Second Amendment Rules, 2025
This guide reflects the legal position current as of 14 August 2026. For matter-specific advice, consult a Bar Council-enrolled advocate. Regalwhiz Law Chambers is available for consultations at +91 96772 38047 or in person at G204, Spencer Plaza, Anna Salai, Chennai 600002.