A listed company in India is required by law to maintain a specific set of board-approved policies, publish several of them on its website, and review some on a fixed cycle. The requirements are spread across the SEBI Listing Regulations, the Insider Trading Regulations and the Companies Act, 2013, which is why so many company secretaries keep their own spreadsheet to track them.
This checklist brings them together in one place. It is based on the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015, as last amended on 14 July 2026, the SEBI (Prohibition of Insider Trading) Regulations, 2015, and the Companies Act, 2013.
For each policy, we note where the requirement comes from, who it applies to, and what makes it hard to keep current. At the end, we look at the part most checklists skip: making sure the employees these policies govern actually know what they say.
Why mandatory policies are a disclosure issue, not just a governance one
For a listed company, a missing or outdated policy is visible. Regulation 46 of the Listing Regulations requires a functional website with a separate section for investor information, including the code of conduct, the whistleblower mechanism, the related party transactions policy and the material subsidiaries policy. Several others must be linked from the annual report or disclosed to the stock exchanges.
That means shareholders, proxy advisors and regulators can see whether your policies exist, whether they are current, and whether they match what the regulations now require. An RPT policy that still quotes a threshold SEBI replaced last year is not a private problem.
Policies every listed company must have
1. Code of conduct for directors and senior management
Source: Regulation 17(5). The board must lay down a code of conduct for all board members and senior management, and it must incorporate the duties of independent directors set out in the Companies Act, 2013. The code must be published on the company’s website under Regulation 46.
2. Whistleblower policy and vigil mechanism
Source: Regulation 22, and Section 177(9) and (10) of the Companies Act. The company must establish a vigil mechanism for directors and employees to report genuine concerns. It must provide adequate safeguards against victimization of anyone who uses it, and direct access to the chairperson of the audit committee in appropriate or exceptional cases. Details must be disclosed on the website and in the Board’s report.
A whistleblower policy only works if employees know it exists and trust it. This is the policy where proof of awareness matters most.
3. Related party transactions policy
Source: Regulation 23(1). The company must have a policy on materiality of related party transactions and on dealing with them, with clear threshold limits approved by the board. The board must review the policy at least once every three years. The audit committee must also define “material modifications” and disclose that definition as part of this policy.
This is the policy most likely to be out of date right now. With effect from 19 December 2025, SEBI replaced the single materiality threshold (the lower of ₹1,000 crore or 10% of annual consolidated turnover) with the scale-based thresholds in Schedule XII of the Listing Regulations. If your RPT policy still quotes the old figure, it needs updating.
4. Policy for determining material subsidiaries
Source: Regulation 16(1)(c). A material subsidiary is one whose turnover or net worth exceeds 10% of the consolidated turnover or net worth of the listed entity and its subsidiaries in the previous financial year. The company must formulate a policy for determining material subsidiaries and publish it on its website.
5. Policy for determination of materiality of events and information
Source: Regulation 30(4)(ii). The board must approve a policy, based on the criteria in the regulation, for deciding which events and information must be disclosed to the stock exchanges, and publish it on the website. Since 2023, the regulation states that this policy must assist relevant employees in identifying potential material events and reporting them to the authorized Key Managerial Personnel.
Read that requirement carefully. SEBI is not only asking for a document. It is asking for a policy that works at the level of the employee who first learns about a material event. That is an awareness and training obligation hiding inside a disclosure rule.
6. Archival policy
Source: Regulation 30(8). Every disclosure made to the stock exchanges under Regulation 30 must be hosted on the company’s website for a minimum of five years, and after that as per the company’s archival policy, which must itself be disclosed on the website.
7. Policy for preservation of documents
Source: Regulation 9. The board must approve a policy that classifies documents into at least two categories: those to be preserved permanently, and those to be preserved for not less than eight years after completion of the relevant transactions. Documents may be kept in electronic form.
8. Remuneration policy
Source: Part D of Schedule II to the Listing Regulations, and Section 178(3) and (4) of the Companies Act. The Nomination and Remuneration Committee must recommend to the board a policy relating to the remuneration of directors, key managerial personnel and other employees. The Companies Act requires that remuneration be reasonable and sufficient to attract, retain and motivate the directors the company needs.
9. Board diversity policy
Source: Part D of Schedule II. Devising a policy on diversity of the board is part of the Nomination and Remuneration Committee’s mandated role.
10. Succession planning
Source: Regulation 17(4). The board must satisfy itself that plans are in place for orderly succession for appointments to the board and to senior management. Many companies document this as a board-approved succession policy.
Additional policies for the top 1000 listed companies
11. Dividend distribution policy
Source: Regulation 43A. The top 1000 listed entities by market capitalization must formulate a dividend distribution policy, publish it on their website and link it from the annual report. The regulation lists what it must cover: when shareholders may or may not expect a dividend, the financial parameters considered, internal and external factors, how retained earnings will be used, and parameters for different classes of shares.
Policies, simplified with AI-powered automation
Book a 20-minute demo to see how PolicyCentral.ai streamlines policy creation, distribution, and compliance across your enterprise.
Book a Demo12. Risk management policy
Source: Regulation 21 and Part D of Schedule II. The Risk Management Committee, mandatory for the top 1000 listed entities and for high value debt listed entities, must formulate a detailed risk management policy. It must cover a framework for identifying internal and external risks, explicitly including financial, operational, sectoral, sustainability and ESG, information and cyber security risks, along with mitigation measures and a business continuity plan. The committee must review the policy at least once in two years.
Separately, Section 134(3)(n) of the Companies Act requires the Board’s report of every company to include a statement on the development and implementation of a risk management policy.
Insider trading codes
13. Code of practices and procedures for fair disclosure
Source: Regulation 8 of the Insider Trading Regulations. The board of every listed company must formulate and publish on its website a code for fair disclosure of unpublished price sensitive information, following the principles in Schedule A. Every amendment must be promptly intimated to the stock exchanges.
14. Code of conduct to regulate, monitor and report trading
Source: Regulation 9 of the Insider Trading Regulations. The board must ensure that the chief executive officer or managing director formulates a code of conduct, with the board’s approval, to regulate, monitor and report trading by designated persons and their immediate relatives, adopting at least the minimum standards in Schedule B.
The insider trading code applies to a defined population of designated persons that changes every time someone joins, moves role or leaves. Keeping the list current, and proving each designated person received the current code, is an ongoing task rather than an annual one.
Companies Act policies that apply beyond listed status
15. Corporate Social Responsibility policy
Source: Section 135. Every company with a net worth of ₹500 crore or more, turnover of ₹1,000 crore or more, or net profit of ₹5 crore or more in the preceding financial year must constitute a CSR Committee. The committee formulates and recommends a CSR Policy, and the board approves it, discloses its contents in the Board’s report and places it on the company’s website.
Listed companies that also qualify as high value debt listed entities have parallel obligations for several of these policies under Chapter VA of the Listing Regulations, including the vigil mechanism and RPT policy.
The review calendar most companies miss
Writing these policies once is not enough. Several carry explicit review cycles, and all of them need revisiting when the underlying regulation changes:
- Every two years: risk management policy.
- Every three years: related party transactions policy, with thresholds updated for Schedule XII.
- On every amendment: the fair disclosure code must be re-intimated to the stock exchanges.
- On every regulatory change: any policy that restates a threshold, a timeline or a definition from the regulations.
The Listing Regulations have been amended repeatedly in the last two years. A policy approved in 2023 may be accurate on its face and still be out of step with the current text. This is the scenario our guide to policy version control addresses: you need to know which version was in force on any given date, and why it changed.
The part checklists skip: getting policies to employees
Most of the policies above are approved by the board and published for investors. But several of them only work if employees know and follow them. The whistleblower policy is useless if staff do not know how to raise a concern. The materiality policy now explicitly exists to help employees spot and escalate material events. The insider trading code binds every designated person individually.
That creates a last-mile obligation: distribute each current policy to the people it governs, capture a record that they read it, and repeat the cycle every time the policy changes. For companies with plants, branches and field teams, it also means delivering policies in the languages employees actually read. Our articles on acknowledgment tracking and the policy audit checklist go deeper on what good evidence looks like.
If you are drafting or refreshing any of these, our free Code of Conduct and Ethics Policy, Whistleblower and Ethics Policy, Conflict of Interest Policy and CSR Policy templates are a practical starting point. For structure and drafting guidance, see how to write a policy document.
How PolicyCentral.ai helps listed companies
PolicyCentral.ai keeps the full set of mandatory policies in one governed library. Each policy has an owner, an approval trail, a version history and a review date, so the two-year and three-year cycles are tracked automatically rather than in a spreadsheet. Approved versions are distributed to exactly the right audience, such as all employees for the whistleblower policy or designated persons for the insider trading code, and employees acknowledge each policy in English, with a response button or a digital signature.
Employees can also ask plain-language questions, such as “Can I trade this week?” or “How do I report a concern anonymously?”, and get an answer from PolicyGPT, which searches your approved policies directly. You can try it on our PolicyGPT demo page. If your secretarial team is still tracking mandatory policies by hand, request a demo and bring your review calendar.
Frequently Asked Questions
Which policies are mandatory for a listed company in India?
Under the SEBI Listing Regulations, every listed company needs a code of conduct for directors and senior management, a whistleblower policy or vigil mechanism, a related party transactions policy, a policy for determining material subsidiaries, a policy for determining materiality of events, an archival policy, a policy for preservation of documents, a remuneration policy and a board diversity policy. The Insider Trading Regulations add a fair disclosure code and a code of conduct for trading. The top 1000 listed companies also need a dividend distribution policy and a risk management policy.
How often must the related party transactions policy be reviewed?
Regulation 23(1) requires the board to review the policy on materiality of related party transactions and on dealing with them at least once every three years and update it accordingly. Since 19 December 2025, materiality is determined using the scale-based thresholds in Schedule XII of the Listing Regulations, so policies that quote the older single threshold need to be updated.
How often must the risk management policy be reviewed?
The Risk Management Committee must review the risk management policy at least once in two years, taking into account changing industry dynamics and evolving complexity. The Risk Management Committee is mandatory for the top 1000 listed entities and for high value debt listed entities.
Which policies must be published on a listed company’s website?
Regulation 46 requires the website to carry, among other items, the code of conduct for directors and senior management, details of the vigil mechanism, the policy on related party transactions and the policy for determining material subsidiaries. The materiality of events policy, the archival policy, the dividend distribution policy and the fair disclosure code must also be published on the website under their respective regulations.
Does the Companies Act require a whistleblower policy?
Yes. Section 177(9) requires every listed company, and other prescribed classes of companies, to establish a vigil mechanism for directors and employees to report genuine concerns. Section 177(10) requires safeguards against victimization and direct access to the chairperson of the audit committee in appropriate or exceptional cases.
How can PolicyCentral.ai help with LODR policy compliance?
PolicyCentral.ai maintains every mandatory policy with its approval trail, version history and review date, automates the two-year and three-year review cycles, distributes policies to the right audience such as designated persons for the insider trading code, tracks acknowledgment in English through a response button or digital signature, and gives employees PolicyGPT, an AI assistant that answers questions from the current approved text.