Secretarial Audit

Why a generic MR-3 checklist fails — and what sector intelligence looks like

June 2026 · 7 min read

Secretarial audit under Section 204 asks a company secretary to certify compliance across every law that applies to a company. The quiet difficulty is in the phrase "every law that applies" — because which laws apply depends entirely on what the company does.

Four companies, four regulatory universes

Consider a bank, an NBFC, a pharmaceutical manufacturer and an early-stage tech startup. A bank answers to the RBI, FIU-IND and SEBI. An NBFC sits inside the RBI's four-layer scale-based regulation, where obligations differ between base-layer and upper-layer entities. A pharma company deals with CDSCO, NPPA and state drug authorities, plus a revised Schedule M. A startup navigates DPIIT recognition, angel-tax rules and evolving data-protection obligations. A single generic checklist treats all four as if they were the same company. They are not.

What sector intelligence means in practice

sector.rocprompt.in takes the position that the checklist should change with the sector. Choose the client's industry, and the platform loads the correct legal hierarchy for that sector — Acts, Rules, Regulations, Notifications and Circulars — and presents obligations broken down by regulatory layer or entity sub-type. NBFC base versus upper layer. Scheduled commercial bank versus small finance bank versus payments bank. Life versus general versus composite insurer.

Traceability is the point

Every obligation traces back through a seven-level hierarchy — Act to Rule to Regulation to Notification to Circular to Order to the specific compliance obligation. That chain is what lets an auditor defend a conclusion, and what keeps the audit current when a single circular changes.

Keeping current is half the work

Regulatory change is relentless: DPDP Rules, the Four Labour Codes, the Insurance Laws Amendment Act, MMDR amendments, IFSCA bullion regulations. The value of a sector-aware platform is not just structure — it is that the structure is maintained as the law moves, so the practitioner starts from something current rather than something they have to re-verify from scratch.

← Back to all posts

Keep reading

Next post

Engineering

Multi-tenant SaaS: the architecture decisions clients should ask about

Tenant isolation, role-based access and audit trails aren't features to add later — they're foundations. What we've learned building four multi-tenant products in production.