Skip to main content
ComplianceCorporate Legal

POSH Compliance Software for Indian Enterprises

A practical guide to why generic investigation tools fail POSH cases, and what purpose-built compliance software must encode for Indian enterprises.

11 min read1964 words

Introduction

Ask most general counsel where their organisation is quietly exposed, and the POSH Act rarely tops the list — until a complaint actually lands. The moment it does, a strict statutory clock starts running, a quasi-judicial Internal Committee must convene, and every note, email and recommendation becomes potential evidence in a matter that may later reach a labour court or writ petition. This is precisely where purpose-built posh compliance software earns its place: not as another ticketing queue, but as a system that encodes the Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013 into the way a case genuinely moves.

The temptation for many Indian enterprises is to fold POSH matters into a general grievance or investigation workflow — the same tool used for expense fraud, conflict-of-interest disclosures or vendor complaints. It looks efficient on a procurement spreadsheet. In practice it is a liability, because the POSH Act is not a generic misconduct statute. It prescribes who may hear a complaint, how long each stage may take, what may and may not be offered as a settlement, and how the identities of everyone involved must be protected. A tool that treats a harassment complaint like a helpdesk ticket will, sooner or later, cause a procedural lapse that no amount of good intent can cure.

This article is written for compliance heads, company secretaries and general counsel who are deciding whether their existing case-handling setup is defensible — and what a POSH-specific platform should actually do. It focuses less on features for their own sake and more on the statutory obligations the software must make unavoidable.

Why a POSH complaint is not just another investigation

Generic investigation platforms are built around a flexible, configurable case: someone raises an issue, an investigator is assigned, evidence is gathered, a decision is recorded. That flexibility is the problem. The POSH Act removes discretion at exactly the points where a general tool leaves it open. It dictates the composition of the body that hears the matter, the sequence and timing of steps, the availability of conciliation on terms the complainant chooses, and strict confidentiality backed by penalty. None of these are configuration preferences; they are statutory conditions, and failing any one of them can render the entire inquiry challengeable.

The distinction matters most in adversarial hindsight. When a respondent or complainant challenges an outcome, the first line of attack is almost never the merits — it is procedure. Was the Internal Committee validly constituted, with the required external member present? Was the ninety-day timeline observed, or quietly breached? Was conciliation offered only at the aggrieved woman's request, and never dressed up as a monetary settlement? A platform that cannot demonstrate each of these with a timestamped, tamper-evident record leaves the organisation defending its process rather than its findings.

There is also a cultural dimension that generic tooling ignores. Harassment complaints involve a power asymmetry and acute sensitivity around identity. A system that copies HR business partners, line managers or IT administrators into a case by default — as many workflow tools do — silently breaches the confidentiality the Act demands. POSH-specific software starts from a closed, need-to-know model and opens access deliberately, rather than the reverse.

  • The composition of the hearing body is fixed by statute, not chosen per case
  • Timelines are legal deadlines, not internal service-level targets
  • Conciliation is available only on the aggrieved woman's terms and never as a cash settlement of the complaint
  • Confidentiality is a statutory duty carrying a specific penalty, not a best-practice preference

The statutory clock the software must enforce

The POSH Act is unusually explicit about timing, and each deadline is a point where an under-engineered process fails. An aggrieved woman may ordinarily file a written complaint within three months of the incident, or of the last incident in a series, with the Internal Committee empowered to extend that window by a further three months for reasons recorded in writing. The inquiry itself must ordinarily be completed within ninety days. The Committee must then forward its report to the employer within ten days of completing the inquiry, and the employer must act on the recommendations within sixty days.

These are not aspirational milestones. A missed inquiry deadline, or a report that sits with the employer beyond the action window, hands a challenger a clean procedural argument. The difficulty is that these clocks run concurrently across multiple live matters, each at a different stage, often handled by committee members who have full-time roles elsewhere in the business. Manual tracking on a shared spreadsheet is where breaches are born — a member goes on leave, a hearing is rescheduled, and the ninety-day count quietly lapses.

Good posh compliance software treats each deadline as a first-class object: it calculates dates from statutory triggers, escalates automatically as thresholds approach, and refuses to let a stage close without the record that justifies it. When an extension is granted, it captures the written reasons the Act requires rather than allowing a silent slip.

  • Deadlines are computed from statutory triggers, not from when someone remembers to update a tracker
  • Approaching thresholds escalate automatically to the presiding officer and compliance owner
  • Extensions are permitted only with captured written reasons
  • Concurrent cases each carry their own independent clock
3 months
Complaint window
An aggrieved woman may file within three months of the incident, extendable by a further three months for reasons recorded in writing.
90 days
Inquiry deadline
The Internal Committee must ordinarily complete its inquiry within ninety days of receiving the complaint.
10 days
Report turnaround
The Committee must forward its findings and recommendations to the employer within ten days of concluding the inquiry.
60 days
Employer action
The employer must act on the Committee's recommendations within sixty days of receiving the report.

Encoding the Internal Committee into the system

The Act requires every workplace employing ten or more workers to constitute an Internal Committee, and it is prescriptive about who sits on it. The presiding officer must be a senior woman employee; at least half the members must be women; there must be members committed to the cause of women or with relevant social or legal experience; and there must be an external member drawn from a non-governmental organisation or association familiar with issues of sexual harassment. Where an establishment has fewer than ten workers, or where the complaint is against the employer itself, the matter goes to the Local Committee constituted at district level.

These rules have operational consequences that software should carry rather than leave to memory. Committee members' terms are time-bound and must be refreshed; the external member must actually participate for the quorum to hold; and a member with a conflict in a particular matter must be recused and replaced. A system that models the Committee as a living roster — with terms, roles, quorum rules and recusal handling built in — prevents the most common structural defect: an inquiry conducted by an improperly constituted body.

  • The presiding officer must be a senior woman employee
  • At least half the members must be women, with an external member from an NGO or with relevant experience
  • Committee terms are time-bound and must be tracked and renewed
  • Recusal and replacement must be handled where a member has a conflict in a specific case

Quorum and the external member

The external member is not decorative — the intent is independent oversight of a process an employer might otherwise control. Software should treat the external member's participation as a condition for a valid sitting, flagging any hearing scheduled without them and preventing a case from advancing on a defective quorum. This single control closes one of the most frequently litigated gaps in POSH proceedings.

The Local Committee escalation path

When a complaint is against the employer, a director or the most senior person to whom the Committee would report, the appropriate forum is the district Local Committee, not the Internal Committee. The platform should recognise this scenario at intake and route the matter externally rather than allowing an in-house committee to hear a case it is disqualified from touching.

Confidentiality, the DPDP Act and sensitive data handling

Confidentiality under the POSH Act is not a soft expectation. The Act prohibits publication or disclosure of the identity of the aggrieved woman, the respondent, witnesses and the contents of the proceedings, and attaches a penalty to breach. Layered on top of this is the Digital Personal Data Protection Act, 2023, which treats the personal data captured in a harassment case — health details, allegations, witness accounts — as precisely the kind of sensitive information demanding strict purpose limitation, access control and retention discipline. The two regimes point in the same direction: tightly held, minimally shared, deliberately retained data.

Most generic tools fail here not through malice but through default settings. Broad group permissions, automatic manager notifications, indexed search across all cases, and unmanaged data exports all quietly widen the circle of people who can see a matter. A POSH-specific system inverts the default. Access is scoped to the specific committee handling a specific case; documents carry watermarks and access logs; and every view, download and export is recorded so that a confidentiality breach can be traced rather than merely denied.

Retention deserves particular attention. Records must be kept long enough to defend the process and file statutory reports, but indefinite retention of intimate personal data sits uneasily with data-minimisation principles. The software should apply a considered retention schedule with defensible deletion, rather than hoarding sensitive files forever by default.

  • Identities of complainant, respondent and witnesses are protected by statute, with a penalty for breach
  • Sensitive personal data attracts DPDP Act 2023 duties of purpose limitation and access control
  • Access is scoped to the handling committee by default, not opened to HR or management at large
  • Every view, download and export is logged for traceability
  • Retention follows a defensible schedule rather than indefinite storage

The case-management workflow from intake to recommendation

A well-designed POSH workflow mirrors the statutory journey rather than a generic ticket lifecycle. It begins at intake, where the complaint is received through a channel the complainant trusts — including the ability to raise a matter confidentially — and is immediately classified against the Act's scope and timelines. From there it moves through an optional conciliation stage available strictly at the aggrieved woman's request, into a formal inquiry with structured evidence capture and witness statements, and finally to the Committee's findings and recommendations.

What separates competent software from a repurposed form builder is how it handles the evidentiary spine of the case. Statements must be attributable and timestamped; documents must be version-controlled and tamper-evident; and the Committee's reasoning must be captured in a way that survives scrutiny. Because the Internal Committee is vested with powers similar to those of a civil court when conducting an inquiry — including summoning and examining witnesses and requiring documents — the record it produces must be able to withstand exactly that level of formality.

The payoff of encoding this journey is not speed for its own sake. It is defensibility. When a matter is challenged, the organisation can show a clean, sequenced, evidence-backed process rather than reconstructing events from scattered inboxes.

  • Intake classifies the matter against POSH scope and starts the statutory clock
  • Conciliation is offered only at the aggrieved woman's request and never as a monetary settlement
  • Evidence and statements are attributable, timestamped and version-controlled
  • Findings and recommendations are captured in a court-ready record

Conciliation done correctly

The Act permits the Committee to attempt conciliation before an inquiry, but only if the aggrieved woman asks for it, and it expressly bars any monetary payment being made the basis of the settlement. Software should make this optional, complainant-initiated and clearly separated from the inquiry path — never a default step and never a negotiation over compensation. Recording who initiated conciliation, and on what terms, protects the organisation later.

A defensible evidence trail

Because the Committee's proceedings can be tested in later litigation or a writ challenge, the platform should treat the case file as an evidentiary artefact. Chain-of-custody metadata, immutable logs and controlled versioning turn a collection of documents into a record the organisation can stand behind, rather than a folder whose integrity a respondent can plausibly question.

Annual reporting, Board disclosures and BRSR

POSH compliance does not end when a case closes. The Internal Committee and the employer must file an annual report with the District Officer describing the complaints received and disposed of during the year. Beyond that statute, the Companies Act framework requires companies to disclose in their Board's Report that they have complied with the POSH Act, and listed entities face further transparency through SEBI's business responsibility and sustainability reporting, which surfaces workplace-harassment metrics to investors and the market. What was once a purely internal matter is now a governance disclosure with a public dimension.

This is where fragmented handling becomes expensive. If cases live across email threads, personal spreadsheets and individual committee members' notes, producing accurate year-end numbers becomes a stressful reconstruction exercise — and inaccurate disclosures carry their own governance risk. A system that has captured every matter consistently through the year can generate the District Officer report, the Board's Report input and the sustainability-report figures from a single source of truth, with the underlying cases available if a number is queried.

For company secretaries in particular, this closes a real gap: the person accountable for the disclosure is often not the person who handled the cases, and reconciling the two at reporting time is where errors creep in.

  • An annual report on complaints received and disposed must be filed with the District Officer
  • The Board's Report must confirm POSH Act compliance
  • Listed entities disclose harassment metrics through sustainability reporting to the market
  • Year-end figures should flow from a single case record, not a manual reconstruction

What POSH compliance software must do differently

Pulling the threads together, the case for a POSH-specific platform over a generic investigation tool is not about having more features — it is about having fewer choices at the points where the law removes discretion. Generic tooling asks the administrator to configure timelines, permissions and workflows correctly and hopes they do. POSH-specific software makes the statutory path the default and the compliant behaviour the easy one, so that a busy committee doing its best cannot accidentally breach a duty it did not have front of mind.

The editorial point worth stating plainly for any buyer comparing options: a repurposed grievance system can be made to look POSH-ready in a demo, but the gaps show under pressure — the missing external-member check, the silently-breached ninety-day clock, the manager copied into a confidential matter by an old notification rule. These are not exotic edge cases; they are the ordinary failure modes of general tools applied to a specialised statute. Choosing a platform built around the Act is, ultimately, a decision about which risks you are willing to defend in hindsight.

  • Compliant behaviour is the default, not something an administrator must configure correctly
  • Structural checks — quorum, external member, forum — are enforced, not advisory
  • Confidentiality and DPDP duties are built into access design, not bolted on
  • Reporting flows from the same records that handled the cases

Conclusion

For compliance heads, company secretaries and general counsel, the honest question is not whether your organisation takes POSH seriously — it almost certainly does — but whether your current process could withstand a determined challenge to how a single case was handled. If the answer depends on individual diligence, shared spreadsheets and the hope that no deadline slips, the exposure is real and largely invisible until a matter goes wrong. A platform that encodes the Act's clock, committee rules, confidentiality duties and reporting obligations converts that fragile diligence into a defensible, repeatable process.

If you are reassessing how your enterprise manages POSH matters, the most useful next step is to see the statutory workflow modelled end to end against your own scenarios — a complaint against a senior leader, a lapsed committee term, a matter approaching its ninety-day limit — and judge how the system behaves under exactly the pressures that expose generic tools. We would welcome the chance to walk your team through a working demonstration and discuss where your current approach is strongest and where it is most exposed.

Tags

#Compliance#POSHAct#CaseManagement#WorkplaceInvestigations#HRCompliance#LegalOperations

Frequently Asked Questions

Can we just use our existing grievance or investigation tool for POSH cases?

You can, but it is risky. The POSH Act fixes committee composition, timelines, conciliation terms and confidentiality in ways a general tool leaves configurable. Under challenge, procedural defects — a defective quorum, a breached deadline, an over-shared file — are the usual attack surface. A POSH-specific system makes the compliant path the default rather than relying on correct configuration.

Which organisations must constitute an Internal Committee under the POSH Act?

Every workplace employing ten or more workers must constitute an Internal Committee. Establishments with fewer than ten workers, and complaints made against the employer itself, are handled by the district Local Committee. The Committee must include a senior woman as presiding officer, a majority of women members, and an external member familiar with issues of sexual harassment.

What are the key timelines the software should track?

A complaint may ordinarily be filed within three months of the incident, extendable by another three months for recorded reasons. The inquiry should be completed within ninety days. The Committee forwards its report to the employer within ten days of concluding the inquiry, and the employer must act on the recommendations within sixty days. Each runs concurrently across live cases.

How does the DPDP Act 2023 affect POSH case handling?

POSH cases capture sensitive personal data — allegations, health details, witness accounts — that the Digital Personal Data Protection Act, 2023 subjects to purpose limitation, access control and retention discipline. Combined with the POSH Act's own confidentiality penalty, this means access should be scoped to the handling committee, every action logged, and records retained on a defensible schedule rather than stored indefinitely.

What POSH-related reporting do enterprises have to produce?

The Committee and employer must file an annual report on complaints with the District Officer. Companies must confirm POSH compliance in the Board's Report, and listed entities disclose harassment metrics through sustainability reporting to investors. Software that captures cases consistently through the year lets these figures flow from a single source rather than a stressful year-end reconstruction.

Transform Your Legal Operations with AI

Ready to experience the power of AI-driven legal solutions? Vidhaana's platform delivers measurable results across compliance, helping organizations reduce costs, improve accuracy, and scale operations efficiently.

15+
Industries Served
AI-Powered
Document Analysis
Pan-India
Coverage
SOC 2
Aligned Security