For Indian listed companies, whistleblower obligations arise from multiple sources — SEBI’s Listing Obligations and Disclosure Requirements (LODR), the Companies Act 2013, and, for certain sectors, additional RBI or IRDAI guidelines. This article focuses on the core SEBI LODR obligations, which apply to all companies listed on Indian stock exchanges.
The core requirement: a vigil mechanism
Regulation 22 of the SEBI LODR Regulations requires every listed company to establish a vigil mechanism — a formal channel through which directors, employees, and other stakeholders can raise concerns about unethical behaviour, actual or suspected fraud, or violations of the company’s code of conduct or ethics policy.
The vigil mechanism must provide “adequate safeguards against victimisation” and allow direct access to the chairperson of the Audit Committee in exceptional cases. These are not optional features — they are compliance requirements.
What is commonly missed
Gap 1: The mechanism exists on paper but not in practice. Many companies have a Whistle Blower Policy uploaded to their website and disclosed in their annual report — but the actual reporting channel is an email address that routes to HR, with no anonymity, no acknowledgement process, and no defined investigation procedure. This does not meet the standard.
Gap 2: No genuine anonymity. SEBI’s framework does not explicitly mandate anonymity, but the “adequate safeguards against victimisation” requirement is impossible to satisfy if reporters must identify themselves and their identity is accessible to the subject of their report.
Gap 3: No direct access to the Audit Committee. The regulation requires that the mechanism provide access to the Audit Committee chairperson in exceptional cases. In practice, most mechanisms route all reports to HR or a compliance officer, with no defined escalation path to the Audit Committee.
Gap 4: No tracking or reporting to the board. SEBI expects the Audit Committee to review the functioning of the vigil mechanism at least annually.
What a compliant mechanism looks like
A SEBI-compliant vigil mechanism for a listed company should include: a dedicated reporting channel separate from HR and management; technical measures to protect reporter identity; an acknowledgement process with defined timelines; an independent investigation process with Audit Committee oversight; a defined escalation path to the Audit Committee chairperson; and annual reporting to the board on mechanism usage and outcomes.
WhistleSentinel and SEBI compliance
WhistleSentinel is configured to meet SEBI LODR Regulation 22 requirements, including direct-access routing to the Audit Committee, automated acknowledgement within seven days, case tracking and management, and board and committee reporting dashboards. Contact our team for a complimentary gap assessment.