For years, PoSH compliance in most Indian organisations has meant the same three things: an Internal Committee on paper, a policy on the intranet, and one training session a year. Enforcement was rare, so the bar stayed low.
That changed on 19th June 2026, when the National Commission for Women issued a nationwide advisory to every state and Union Territory, directing them to enforce mandatory annual PoSH audits for all establishments with 10 or more employees. It’s the strongest signal yet that the era of self-declared compliance under the PoSH Act, 2013 is ending, and the era of verified compliance is beginning.
Here’s what the advisory actually changes, and what your organisation needs to do before it becomes someone else’s audit finding.
What the Advisory Actually Says
The NCW’s advisory has been sent to chief secretaries, police chiefs, district magistrates, and other senior state officials, asking them to build enforcement infrastructure around the PoSH Act rather than leave it to individual employers’ discretion. The core asks include:
Every establishment with 10 or more employees must conduct a documented annual audit covering Internal Committee constitution, complaint handling, confidentiality safeguards, workplace safety infrastructure, awareness programmes, and use of the government’s SHe-Box platform.
States are being asked to set up dedicated PoSH monitoring cells and digital compliance dashboards, so that implementation is tracked centrally rather than relying on employer self-reporting.
Every district is expected to designate a District Officer as the nodal authority responsible for implementation, monitoring, awareness generation, and grievance redressal, including for the unorganised sector and establishments below the 10-employee threshold, through Local Complaints Committees.
Internal Committee details, complaint procedures, and contact information must be prominently displayed both on office premises and on the organisation’s website, not just in an HR folder nobody opens.
Perhaps the most consequential line in the advisory: non-conduct of the audit is itself being treated as an act of non-compliance under the Act, In other words, organisations can no longer avoid regulatory scrutiny simply by not undertaking an audit.
Why This Is a Bigger Deal Than It Sounds
PoSH compliance has always technically required an Internal Committee, annual reporting to the District Officer under Section 21, and regular awareness workshops. What’s been missing is verification. Most organisations knew this, and knew that a poorly constituted IC or a lapsed external member was unlikely to surface unless a complaint forced the issue.
This advisory removes that gap in two ways. First, it converts an implicit legal obligation into an explicit, audit-triggered one. Second, it pushes accountability down to the district level, with named officers responsible for monitoring, rather than leaving enforcement to a complaint-driven system. For employers, that means the risk profile has shifted from “we might get caught if something goes wrong” to “we will be checked, whether or not anything has gone wrong.”
For organisations that have treated PoSH as a compliance checkbox rather than a working system, this is the moment that stops working.
What an Audit Under This Framework Will Likely Examine
Based on the advisory’s language and the areas it explicitly calls out, an audit is likely to test far more than whether an IC exists on paper. Expect scrutiny on whether the IC has at least 50% women members and a woman Presiding Officer as mandated under Section 4, whether the external member is genuinely independent and has real subject-matter experience rather than being a name of convenience, whether complaints have been resolved within the statutory 90-day inquiry window, whether confidentiality provisions under Section 16 have actually been followed in practice, and whether the organisation’s SHe-Box registration and usage are current.
It will also likely test whether awareness programmes have happened at the frequency the Act intends, at regular intervals, not a single session buried in the new-hire onboarding deck. And it will test whether the mandatory display requirements around IC composition and complaint procedures have been met, both physically and on the company website.
The Gaps We See Most Often
Across the audits and diagnostics we run at Kelp, the same handful of issues come up again and again, and they’re precisely the areas this advisory targets. IC composition drifts as members change roles or leave the organisation, and reconstitution lags behind. External members are appointed once and never revisited, even when their engagement with the IC has effectively lapsed. Complaints are acknowledged but not formally tracked through the inquiry timeline, leaving no clean record if questioned later. And SHe-Box registration, where it exists at all, is rarely kept current.
None of these are exotic failures. They’re the ordinary entropy of a compliance system that nobody has been required to actively maintain, until now.
What to Do Before the Audits Start
The advisory gives states discretion on rollout timelines, which means organisations still have a window to close gaps proactively rather than reactively. Four things are worth prioritising immediately.
- Verify your Internal Committee’s current composition against the Section 4 requirements: minimum four members, at least 50% women, a woman Presiding Officer, and a genuinely engaged external member. Reconstitute if the three-year term has lapsed or if members have exited the organisation.
- Pull your complaint records for the last 12 months and confirm every case can be mapped against the 90-day inquiry timeline, with documentation to support it. Gaps here are the single most common findings in any PoSH review.
- Check that your SHe-Box registration is active and that your organisation’s Nodal Officer actually knows how to use it.
- Confirm your mandatory disclosures,- IC details, complaint procedure, contact information, are genuinely visible, both physically in the workplace and on your website, not just technically present somewhere in a policy document.
How Kelp Can Help
This is exactly the gap our Annual PoSH Diagnostic and PoSH Advisory services are built to close – an independent, structured review of where your organisation stands against the same areas the NCW advisory is asking states to verify, before a district officer or auditor finds them first. We also support IC reconstitution, external member placement, and IC member certification, so the committee your audit reviews is one that can actually withstand scrutiny.
If you haven’t had your PoSH framework independently reviewed in the last year, now is the moment.
Get in touch: info@kelphr.com | 95001 29652 | www.kelphr.com

IN
USA
CA
IN
