What If Every State Required PoSH Audits?

A policy thought experiment on what state PoSH reviews should test, protect and correct. Maharashtra’s inspection circular provides a concrete reference without becoming a claim of an all-India audit mandate.

PoSH Compliance • October 5, 2026 • 32 views • By Ungender Content Team
Illustration of four people holding documents beneath a rainbow-coloured map of India, with another person in the background.

If every state required a structured review of workplace sexual harassment compliance, the quality of that review would matter as much as its reach. A process that rewards a complete folder could miss an unusable reporting channel. An intrusive review could expose sensitive information without helping anyone obtain redress.

This is a policy thought experiment, not an announcement of a nationwide audit mandate. For employers, HR leaders and policymakers, the useful question is what a credible state review should test, what it should leave alone and how an identified failure should be corrected.

The recommendations below are proposals for audit design and organisational preparation, not additional statutory duties.

Start by distinguishing inspection from a private audit

Section 25 of the PoSH Act gives the appropriate government a route, through a written order and subject to the statutory conditions, to call for information and authorise inspection of records and workplaces.[6] A voluntary review commissioned from a consultant should not be presented as that statutory inspection.

Maharashtra provides a concrete reference point. Its Women and Child Development Department’s circular dated 14 May 2026 authorises designated officers and staff to conduct inspections under section 25 and attaches a compliance checklist.[7] It addresses private, government and semi-government establishments and corporations in the state; it is not an all-India instruction to purchase an annual external audit.[7]

There is a document-quality caution: the main circular is dated 14 May, while the attached checklist’s heading prints 14 June 2026.[7] Employers should retain the complete instrument and seek clarification where this discrepancy affects a formal submission.

Ungender’s existing Maharashtra audit-readiness article covers organisational preparation, including committee records and documentation.[1] This companion asks a different question: how should a wider review system be designed so that it produces useful accountability?

Test whether the process is usable

A proposed audit should distinguish a missing document from a process that exists but cannot be used.

Hypothetical example: An employer produces an up-to-date committee order and a screenshot of its reporting page. During an authorised test using dummy information, the published mailbox rejects the message. The policy is available, but the route described in it fails.

Record both findings. Do not mark the entire reporting arrangement satisfactory because a document contains an email address. Equally, do not treat a failed test as proof that a particular complaint was ignored; investigate that separately if relevant information emerges.

For a practical review, ask staff to demonstrate how someone would locate the committee’s contact details, obtain help with a written complaint and identify the appropriate recipient. Agree the test in advance. Avoid deceptive test complaints or exercises that cause employees to believe a real allegation has been made.

Use a short evidence note: what was tested, at which location, on what date, with what result and with which limitations. A headquarters demonstration should not silently stand in for every worksite.

Assess committee capability without directing findings

Section 19(c) requires regular employee awareness programmes and orientation for committee members.[6] The Maharashtra checklist also asks whether IC members have received training in complaint handling.[7]

For the proposed review, go beyond attendance records by offering a fictional procedural exercise. Ask members to explain how they would identify missing information, organise access to relevant material and record an unresolved procedural question. Assess the explanation against the applicable framework rather than expecting everyone to recite a script.

Keep this exercise separate from live case decisions. A reviewer should not demand a preferred finding, a higher rate of adverse outcomes or quicker closure regardless of what a matter requires. An audit engagement should expressly exclude acting as an informal appeal against an IC’s assessment.

Where a capability gap appears, identify the learning need and arrange a follow-up exercise. “Training completed” should describe an activity; it should not automatically close a finding about whether members can perform the task.

Define access before collecting case material

Section 16 restricts publication or disclosure to the public, press and media of specified complaint and inquiry information.[6] Section 25(2), separately, requires employers and District Officers to produce relevant information and records on demand before the inspecting officer.[6] Confidentiality should not be used as a blanket reason to refuse a lawful inspection.

For a voluntary audit, settle access arrangements before requesting files. Identify the reviewer’s authority, purpose, necessary material, recipients and storage arrangements. Start with non-identifying process information where it can answer the question. Escalate any request for case-level records for a specific legal and confidentiality assessment rather than treating the audit contract as unrestricted permission.

Do not circulate raw complaint narratives in a leadership presentation. A finding about delayed administrative support can describe the failure, its consequence and the required correction without reproducing intimate allegations. Even an unnamed summary deserves scrutiny if a small team could readily identify the people involved.

Make corrective action part of the review

The proposed model should require a finding to identify its basis. Separate a statutory breach, a departure from an applicable state instruction and a recommended improvement. A preferred software feature should not acquire the status of law merely because it appears in an audit template.

Each finding should record:

  • The requirement or recommendation being assessed.
  • The evidence reviewed and any missing evidence.
  • The person responsible for correction and the agreed completion date.
  • How completion will be tested, and who will decide whether the finding can close.

Hypothetical example: A reporting contact has changed, but notices at two sites still show the former address. The correction should include replacing those notices and testing the new route, not just emailing a revised policy to headquarters.

For a public inspection programme, specify how establishments can explain disputed observations and how authorities will assess the applicable consequences. These are proposed safeguards, not a claim that every defect attracts the same sanction or that a reviewer can waive a legal obligation.

Design for workplaces beyond large corporate offices

Section 6 provides for Local Committees to receive complaints from establishments where an IC has not been constituted because there are fewer than ten workers, and where the complaint is against the employer.[6] A policy proposal centred only on corporate IC files would therefore be too narrow.

A wider review programme should examine the accessibility of the relevant route for smaller workplaces too. Consider language, practical access to contact information and the ability to obtain assistance without depending on the person complained against. Do not copy a large company’s documentation expectations into every setting without examining their purpose.

What employers can do without waiting

Commission a bounded review of one part of the process, make its limitations explicit and verify the corrections. For organisations seeking outside help, Ungender’s PoSH audit service describes reviews of policy, IC arrangements, documentation and awareness, with identified gaps.[5] Agree the actual scope and access safeguards before beginning.

If every state introduced a review programme, I would judge its value by whether it exposed a failure that could be corrected, protected the people whose information it handled and followed through on the correction. An audit certificate alone would answer none of those questions.

Sources

[1] https://www.ungender.in/maharashtra-posh-audit-framework

[5] https://www.ungender.in/posh-audit-services

[6] https://megsocialwelfare.gov.in/acts/sexual-harrassment-of-women%20at%20workplace-act-and-rules-2013.pdf

[7] https://gr.maharashtra.gov.in/Site/Upload/Government%20Resolutions/English/202605141652232030.pdf

Key takeaways

  • Distinguish a statutory inspection from a voluntary private audit.
  • Define access to sensitive information before collecting it.
  • Close findings only after verifying the agreed correction.