A mid-sized private company with ₹60 crore of bank borrowings assumes whistleblower policies are a listed-company thing. The moment its borrowings crossed ₹50 crore, Section 177(9) made a vigil mechanism mandatory, and not having one has been a live compliance default ever since — noticed by nobody until an auditor asks for the policy.
Every listed company, every company accepting public deposits, and every company with bank or public financial institution borrowings above ₹50 crore must establish a vigil mechanism — a whistleblower channel with real protection against retaliation.
The bottom line
Who must establish it: every listed company, companies accepting public deposits, and companies with bank or PFI borrowings over ₹50 crore. Private companies included.
Who runs it: the audit committee, or where there is no audit committee, a director the Board nominates.
What it must guarantee: protection against victimisation, and direct access to the audit committee chairperson in exceptional cases.
What a vigil mechanism is
A formal channel through which directors and employees can report genuine concerns — actual or suspected fraud, unethical behaviour, or breaches of the company's code of conduct.
The purpose is to surface wrongdoing internally and early, instead of letting it fester until it reaches a regulator or a newspaper. That only works if the person who reports is genuinely protected, which is why Section 177(9) does not stop at requiring a channel.
Who has to have one
Section 177(9), read with Rule 7 of the Companies (Meetings of Board and its Powers) Rules, 2014, catches three classes of company: every listed company, companies that accept deposits from the public, and companies that have borrowed from banks or public financial institutions in excess of ₹50 crore.
The borrowings limb is the one that surprises people, because it reaches private companies. A company with no public shareholders and no deposits needs a vigil mechanism from the moment its bank or PFI borrowings cross ₹50 crore — a line a growing company can pass in a single facility without anyone connecting it to this obligation.
Who oversees it
Rule 7(2) and 7(3) split this by whether the company has an audit committee.
Companies required to have one must route the vigil mechanism through it, with any member who has a conflict of interest in a particular case recusing and the others handling it.
Other companies must have the Board nominate a director to play the audit committee's role for this purpose, so there is always an identified person responsible for receiving disclosures. A mechanism where nobody owns the inbox is not a mechanism.
The two safeguards
Section 177(10) and Rule 7(4) require adequate safeguards against victimisation of anyone who uses the mechanism, and direct access to the chairperson of the audit committee, or the nominated director, in appropriate or exceptional cases.
The second one is doing specific work. It exists so that a complaint about senior management can bypass the people it concerns. Without it, an employee reporting their own reporting line is filing a complaint with the person they are complaining about.
Disclosure, and frivolous complaints
Under Rule 7(5), the details of the mechanism must be disclosed on the company's website, where it has one, and in the Board's Report. Visibility is part of the safeguard — a protected channel nobody knows about protects nobody.
The law balances that with discipline. Where a director or employee makes repeated frivolous complaints, the audit committee or nominated director may take suitable action against them, including reprimand.
What non-compliance costs
Contravention of the Section 177 and 178 provisions makes the company liable to ₹5 lakh and every officer in default to ₹1 lakh, under Section 178(8).
The larger exposure is not the penalty. A company with no vigil mechanism, or a hollow one, does not stop wrongdoing happening — it just guarantees the wrongdoing surfaces somewhere it cannot control, through a regulator, the press or litigation, at a point when fixing it internally is no longer an option.
Common mistakes
- Assuming only listed companies need one. Deposit-takers and companies with borrowings above ₹50 crore, including private companies, do too.
- Adopting a policy with no anti-victimisation protection. That safeguard is mandatory.
- Leaving out the escalation route to the audit committee chair, which is what makes a complaint against senior management possible at all.
- Not disclosing the mechanism on the website and in the Board's Report.
- Having no named owner, so disclosures arrive nowhere in particular.
A working routine
- Test applicability against the three triggers: listed, public deposits, or bank and PFI borrowings above ₹50 crore.
- Adopt a board-approved vigil mechanism policy.
- Assign oversight to the audit committee, or nominate a director where there is no committee.
- Build in anti-victimisation safeguards and direct access to the audit committee chair.
- Disclose the mechanism on the website and in the Board's Report.
- Track complaints, report outcomes to the Board, and guard against misuse.
Frequently asked questions
Which companies must have a vigil mechanism? Listed companies, companies accepting public deposits, and companies with bank or PFI borrowings exceeding ₹50 crore, including private companies.
Who oversees it? The audit committee where one exists, and otherwise a director nominated by the Board.
What protections must it provide? Adequate safeguards against victimisation, and direct access to the audit committee chairperson in exceptional cases.
Does it have to be disclosed? Yes, on the company's website if it has one, and in the Board's Report.
What is the penalty for not having one? Under Section 178(8), ₹5 lakh on the company and ₹1 lakh on every officer in default.
Can we act against someone who files baseless complaints? Yes. Repeated frivolous complaints can attract suitable action, including reprimand, from the audit committee or nominated director.
Primary sources
- Sections 177(9) and 177(10), Companies Act, 2013; Rule 7, Companies (Meetings of Board and its Powers) Rules, 2014
- Section 178(8) for the penalty; SEBI (LODR) Regulation 22 for listed companies