Skip to content
RegulensR
Director liability

Twenty-six thousand obligations carry personal criminal liability

A large share of Indian compliance obligations carry personal criminal liability for named individuals. Most of those individuals cannot tell you which ones. That is a solvable problem.

Ananya BhatHead of Regulatory Research3 min read1 views

Ask a plant head which of his obligations carry imprisonment exposure for him personally. In our experience he will know about three, be uncertain about a dozen more, and be unaware of the rest.

This is not a failure of diligence. Nobody has ever given him the list.

The structure of personal liability in Indian law

Indian compliance statutes attach liability to individuals through several distinct mechanisms, and they behave differently.

Named statutory roles. The occupier under the Factories Act, the manager, the safety officer, the Nominated Person under FSSAI, the Radiological Safety Officer under AERB. These are individuals identified to the authority by name, holding obligations personally.

Officer in default. Under the Companies Act, contraventions attach to whole-time directors, key managerial personnel and, in defined circumstances, any officer who was aware of the contravention. This catches people who never signed anything.

Deemed liability with a reverse burden. Under several statutes — the Factories Act, the Environment Protection Act, the FSS Act — the person in charge of the conduct of business is deemed guilty unless they prove the offence was committed without their knowledge and that they exercised all due diligence.

That third category is the important one. The default position is liability, and the defence is evidentiary. The individual must show they exercised due diligence. If the only evidence of the compliance system is a spreadsheet and an assurance, that is a difficult case to run.

What "all due diligence" looks like in evidence

Statutes that provide a due diligence defence do not define it, and case law is fact-specific. Consistently, though, courts and authorities look for the same features:

  • A documented system for identifying applicable obligations, not reliance on individual knowledge
  • Assignment of each obligation to a named person with authority to act
  • Monitoring by someone other than the person performing the task
  • A record showing detection, action and closure with dates
  • Evidence of resources and authority actually provided to the responsible person
  • Escalation records showing that problems were raised and addressed

The common thread is that a system produces evidence contemporaneously. Evidence assembled after the notice is worth much less, and everyone in the room knows why it was assembled.

The specific gap we see

Organisations generally have some form of compliance tracking. What they typically do not have is the connection between an obligation and the individual who carries personal exposure for it.

The consequence is predictable. The named occupier of a plant is a senior operations person who was nominated years ago, possibly on a form he does not remember signing, and who has never been shown the specific obligations for which he can be prosecuted. He is managing a plant, not a liability register.

When something goes wrong, he discovers his position at the same time as everyone else.

What to do about it

Build the named-role register. Every statutory role, per site, with the individual currently named and the instrument naming them. This is a short exercise with a high strike rate — organisations routinely find roles named to people who left the company.

Attach exposure to obligations. Record against each obligation whether imprisonment attaches, to which role, and the maximum term. It is a field, and it changes how obligations are prioritised.

Show individuals their own list. A named occupier should be able to see, on demand, the obligations for which he carries personal exposure and the current status of each. This is the single change that most reliably improves compliance behaviour, because it converts an abstract risk into a specific one.

Make due diligence evidence a by-product. If detection, assignment, action and closure all happen in one system, the evidence exists because the work happened. That is a materially stronger position than a reconstruction.

An uncomfortable observation

Some organisations resist making personal exposure visible, on the reasoning that it will alarm the individuals concerned.

It should. They already carry the exposure. The only question is whether they carry it knowingly, with the information and authority to manage it, or unknowingly until a notice arrives. The first is uncomfortable; the second is indefensible, and it is also how good operations people end up personally prosecuted for something they were never told was theirs.

Director liabilityGovernanceRisk

Written by Ananya Bhat, Head of Regulatory Research

Part of the team that builds and maintains the Regulens obligation library and platform. If you disagree with something here, we would genuinely like to hear it — get in touch.

Everything here is how the product actually works

If the methodology in these articles matches how you think the problem should be solved, a demonstration will be a short conversation.