Why POSH Certification is No Longer Optional — New Compliance in 2026

There was a time when many organizations treated POSH compliance as just another annual training requirement or a box to tick during audits. That time is over. In 2026, the expectations have changed dramatically. With greater board-level accountability, increased regulatory scrutiny, digital complaint mechanisms such as the SHe-Box portal, and a growing focus on workplace safety and governance, organizations can no longer afford a reactive approach to preventing sexual harassment. Today, POSH certification is not just about complying with the law. It is about protecting employees, building trust, safeguarding reputation, and demonstrating that an organization genuinely values a safe, respectful, and inclusive workplace. Whether you are an HR professional, manager, Internal Committee member, business leader, or employee, understanding the new compliance landscape has become a business necessity rather than a choice.

Why POSH Certification Is No Longer Optional — The 2026 Compliance Reality
Vskills Certification · Workplace Compliance Desk
Compliance Laws 2026
Compliance Briefing — 2026

Why POSH Certification Is No Longer Optional

Board reports now carry your harassment record. A national portal is building a permanent ledger of every Internal Committee in the country. Here is what actually changed in 2026 — and what it means for HR teams, managers, and the people who train them.

₹50,000+
Penalty for a first-time compliance failure under Section 26
10+
Employees at which an Internal Committee becomes mandatory
Jul 2025
MCA amendment bringing POSH status into the Board’s Report

For thirteen years, the Prevention of Sexual Harassment (POSH) Act sat in the same drawer as most Indian companies’ fire-safety certificate — something you kept filed away, produced if asked, and otherwise didn’t think about. In 2026, that drawer got a window. What was once an internal HR record is now a line item in a company’s public Board Report, a live entry on a government portal, and — increasingly — a credential that employers actively look for on a resume. This piece walks through exactly what changed, why it changed now, and what it means for anyone whose job touches workplace compliance.

What makes this moment different from every previous round of “POSH compliance is important” messaging is that it’s no longer being driven primarily by moral or cultural argument. It’s being driven by paperwork — the kind that regulators, auditors, and investors actually read. A Board Report disclosure requirement, a centralised government portal tracking Internal Committees by name, and a wave of state-level enforcement notices don’t ask an organisation to feel differently about workplace safety. They ask it to prove, on the record, that its systems actually work. That’s a much harder bar to clear with a slide deck dusted off once a year, and it’s exactly the bar this article is about.

📋

A quick note before we start

This article explains the current regulatory landscape in general terms for awareness purposes. It is not legal advice. Every organisation’s obligations depend on its size, location, and sector — when in doubt, consult a qualified POSH practitioner or legal counsel alongside structured training.

01
Where the law came from

From Vishaka to Statute

To understand why 2026 feels like a turning point, it helps to remember that the POSH Act didn’t start as a statute at all — it started as a gap the courts had to fill. In 1997, the Supreme Court’s judgment in Vishaka v. State of Rajasthan laid down the first binding guidelines on workplace sexual harassment in India, in the absence of any dedicated legislation. Those guidelines held the field for sixteen years, applied inconsistently across sectors, until Parliament finally converted them into enforceable law with the Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013.

The 2013 Act did three things the Vishaka guidelines never could: it set out clear timelines, it created a defined penalty structure, and it made the Internal Complaints Committee — now usually called the Internal Committee, or IC — a statutory requirement rather than a best practice. Any workplace with ten or more employees, regardless of sector, had to constitute one. That threshold is worth sitting with, because it is deliberately low. It pulls in not just large corporates but startups, clinics, schools, retail chains, and manufacturing units — anywhere the headcount crosses ten.

1997 Vishaka Guidelines 2013 POSH Act becomes law 2017 SHe-Box portal launches Aug 2024 SHe-Box relaunched Jul 2025 Board Report disclosure begins 2026 State-wide SHe-Box rollout

It’s worth pausing on why India’s framework leans so heavily on an internal, employer-run committee rather than routing every complaint straight to a police station or a labour court. The logic behind the Internal Committee model is accessibility: workplace harassment complaints often involve power imbalances, fear of retaliation, and a reluctance to engage with a slow external legal process. An IC embedded within the organisation, bound by a 90-day timeline and specific procedural safeguards, is designed to give employees a faster, more approachable first line of redressal — while still preserving the right to pursue external legal remedies afterward. That design only works, however, if the IC itself is properly constituted, trained, and trusted. A weak or absent IC doesn’t just fail a compliance checklist; it removes the entire safety net the law was built around.

What’s notable is the pace of change in just the last eighteen months. For most of the Act’s life, the cadence of reform was slow — the statute itself, a set of central rules, the odd High Court clarification. Since mid-2024, that cadence has compressed: a portal relaunch, a Supreme Court direction, a corporate-law amendment, and a wave of state-level mandates have landed in quick succession. Each one closes a loophole that organisations had, in practice, been living inside for over a decade. The next three chapters walk through the three biggest of these: the Board Report requirement, the SHe-Box portal, and the tightening rules around the Internal Committee itself.

§
02
The single biggest change of 2025–26

The Board Report Shockwave

Until mid-2025, POSH compliance was largely invisible outside the company. That changed the moment it moved into the Board’s Report.

In July 2025, the Ministry of Corporate Affairs amended the Companies (Accounts) Rules so that a company’s Board of Directors must now disclose its POSH compliance status as part of the annual Board’s Report — the same document that discloses financial performance, related-party transactions, and corporate governance practices. This single change quietly did more to shift POSH from an HR checkbox to a leadership responsibility than a decade of awareness campaigns.

The moment harassment compliance sits next to financial disclosures, it stops being an HR metric and becomes a governance metric.

The practical effect is that the audience for a company’s POSH record has expanded dramatically. Board Reports are filed with the Registrar of Companies and are, in most cases, publicly accessible. That means investors doing diligence before a funding round, enterprise clients running vendor-risk assessments before signing a contract, and prospective senior hires evaluating an employer can all now see, in black and white, whether a company has a properly constituted Internal Committee, whether it conducted training, and how many complaints it received and resolved.

DimensionBefore July 2025From July 2025 onward
VisibilityInternal HR record; rarely seen outside the companyDisclosed in the Board’s Report filed with the Registrar of Companies
OwnershipTreated as an HR/compliance function taskExplicitly a Board and leadership accountability item
AudienceEmployees, ICC, internal auditorsInvestors, clients, regulators, prospective hires
Consequence of a gapStatutory fine, mostly a private matterFine, plus a public record of the gap attached to the company’s filings
Reporting cadenceAnnual ICC report to the District OfficerAnnual ICC report + Board-level disclosure, both due the same compliance cycle
Table 2.1 — What the July 2025 Companies (Accounts) Rules amendment changed in practice.

For HR and compliance teams, this reframes the whole exercise. A generic annual training session that technically “happened” is no longer enough to write a clean line into a Board Report — because increasingly, the people reading that report know what a properly resourced compliance programme looks like, and they know what a paper-only one looks like too. A nil report, filed year after year without a corresponding increase in awareness training or ICC activity, tends to raise more questions than it answers.

⚠️

The quiet trap in “nil” reporting

A company that has never received a single complaint is not automatically compliant — it may simply be one where employees don’t trust the system enough to use it. Auditors and diligence teams increasingly read a long run of nil reports as a signal to look closer, not a clean bill of health.

Consider how this plays out in practice. A prospective enterprise client running vendor due diligence before signing a multi-year contract will often request a copy of the vendor’s POSH policy, evidence of ICC constitution, and confirmation of recent training — and cross-check it against what’s disclosed in the Board Report. A mismatch between what’s claimed in a vendor questionnaire and what’s actually filed with the Registrar of Companies is no longer a hard thing to catch; it’s a two-minute search. The same logic applies to private equity and venture capital diligence ahead of a funding round, where governance red flags — including a thin or inconsistent POSH record — increasingly factor into risk assessments alongside financial and legal review.

There’s a hiring dimension too. Senior candidates evaluating a job offer, particularly women considering leadership roles, are more likely than before to look at how seriously an organisation treats workplace safety governance — and a public Board Report is one of the few places that signal is verifiable rather than taken on faith from a careers page. In a tight market for senior talent, a credible, well-documented POSH programme has quietly become a small but real part of employer branding.

This is also where certification enters the picture in a very direct way. A Board Report disclosure is only as credible as the process behind it. When the people running training, sitting on the Internal Committee, and drafting the policy are formally certified in the subject, that disclosure has substance behind it rather than just a checkbox that got ticked.

§
03
The infrastructure behind enforcement

SHe-Box: The New Central Ledger

If the Board Report requirement is the “why now,” the Sexual Harassment Electronic Box — SHe-Box — is the “how it gets enforced.” Originally launched in 2017 as a single-window complaint portal, SHe-Box was, for years, a modest tool: a place where a woman could file a workplace harassment complaint online instead of navigating paperwork. On 29 August 2024, the Ministry of Women and Child Development relaunched it with a fundamentally different architecture — one built around mandatory onboarding of Internal Committees, not just complaint intake.

That shift matters enormously. Under the older version, SHe-Box was reactive — it only mattered when someone had already decided to file a complaint. The relaunched version is proactive: it asks every organisation with ten or more employees to register its Internal Committee and Nodal Officer in advance, whether or not a complaint has ever been filed. In effect, the government now maintains a running, centralised registry of which organisations have a compliant IC in place and which don’t — a “phonebook” of compliance, as one industry guide describes it.

The legal push behind this came from the Supreme Court itself. In Aureliano Fernandes v. State of Goa & Ors, the Court directed that establishments with more than ten employees must ensure their Internal Committee and Nodal Officer details are uploaded to the SHe-Box portal, aligning digital registration with the Act’s existing requirements. States have since begun operationalising that direction through their own notices — turning a central-government portal into a state-by-state enforcement mechanism.

JurisdictionActionApprox. Date
Mumbai / MaharashtraLabour Department directed establishments with 10+ employees to upload IC detailsApr–May 2025
NoidaDistrict Probationary Officer instructed all 10+ employee organisations to register ICsApr 2025
Delhi (NCT)Dept. of Women & Child Development issued a public notice mandating registration for PSUs and private orgsJun 2025
GoaSHe-Box compliance mandated for private establishments2025
OdishaMandatory registration for all government departments and private establishmentsNov 2025
Central GovernmentPIB release reaffirming focus on monitoring compliance and SHe-Box registration nationallyFeb 2026
Table 3.1 — Selected state and central actions operationalising SHe-Box registration, 2025–26. This list is illustrative, not exhaustive — check your own state’s latest notices.
🗂️

How registration actually works

An organisation first registers its head office and nominates a Nodal Officer — a role that, by design, cannot also sit on the Internal Committee. The district authority verifies the details and issues login credentials. Once IC member information is uploaded, the portal generates separate access for the Presiding Officer to track complaints. Multi-location companies register the head office first and can add branch offices afterward.

It also helps to understand what the portal actually does once registration is complete, because it changes the day-to-day experience of running an IC. Before the relaunch, a complaint filed through SHe-Box by an employee at an unregistered organisation had nowhere clear to route — it sat in a general queue rather than reaching the right committee. With a registered Internal Committee and Local Committee on file, the portal automatically forwards a complaint to the correct committee the moment it’s filed, and both the complainant and the organisation can track its status in real time. That single change — automatic routing instead of manual escalation — is a meaningful upgrade in accountability, because it removes the possibility of a complaint quietly stalling somewhere between departments.

It’s worth being precise about what SHe-Box does and doesn’t replace. Registering on the portal is additive, not a substitute for any of the organisation’s existing statutory obligations — constituting a compliant IC, running training, filing the annual report to the District Officer, and now reflecting accurate status in the Board Report all remain independently required. Treating SHe-Box registration as the finish line, rather than one piece of a larger compliance picture, is its own kind of half-measure.

The important nuance here is that state mandates have been rolling out unevenly — some regions treat registration as legally mandatory today, others still frame it as “strongly recommended” while signalling that mandatory notification is coming. Either way, the direction of travel is unmistakable: SHe-Box is moving from optional infrastructure to the default mechanism through which the government verifies whether an Internal Committee exists at all. Waiting for your specific state to issue a notice before acting is, at this point, a rear-guard strategy rather than a compliant one.

§
04
Getting the fundamentals right

Anatomy of an Internal Committee

Every other piece of 2026’s compliance architecture — Board disclosure, SHe-Box registration, annual reporting — assumes one thing is already true: that a properly constituted Internal Committee exists. This is the part organisations most often get wrong, and it’s worth slowing down on.

Section 4 of the POSH Act sets out exactly who has to sit on an Internal Committee, and the composition rules are specific by design — they exist to prevent an IC from becoming a rubber stamp controlled entirely by management.

IC composition
  • Presiding Officer — a senior woman employee, chairing the committee.
  • Women members — at least 50% of the total committee must be women.
  • External member — from an NGO or a body committed to women’s rights, typically engaged for a fee.
  • Other members — employees familiar with service rules and organisational context.

Once constituted, the Internal Committee has real procedural obligations: complaints must be addressed within a 90-day inquiry timeline, the inquiry must follow principles of natural justice, interim relief such as a transfer can be granted while the inquiry is ongoing, and recommendations go to the employer for final action. An IC that exists on paper but doesn’t run this process properly is, functionally, no different from having no IC at all — it just looks better in a filing cabinet.

🚩

The most common compliance failure

Industry compliance reviewers consistently flag the same issue: an IC exists on paper but has an expired term, is missing its external member, or still lists a Presiding Officer who has since left the company. None of this shows up until an audit, a Board Report disclosure, or — worse — an actual complaint exposes it.

RoleCore ResponsibilityCommon Failure Point
Presiding OfficerChairs proceedings, ensures fairness, signs off on recommendationsEmployee has resigned or been promoted out of eligibility; role left vacant
Women MembersMaintain the mandated gender balance on the committeeAttrition drops representation below 50% without replacement
External MemberBrings independent, outside perspective; often the only non-employee voiceEngagement lapses or fee arrangement is never formalised
Nodal Officer (SHe-Box)Manages SHe-Box registration and portal access; cannot be an IC memberSame person mistakenly assigned both roles, breaking portal access
Table 4.1 — IC roles and where organisations typically lose compliance without noticing.

This is precisely the kind of gap that structured certification is built to catch. Someone trained specifically on the Act’s composition rules, timelines, and reporting duties is far more likely to notice an expired term or a vacant seat before it becomes a Board Report liability — rather than assuming that “we have a POSH policy” is the same thing as “we have a functioning Internal Committee.”

Internal Committee vs. Local Committee — don’t confuse the two

One recurring source of confusion, especially for smaller businesses, is the difference between an Internal Committee and a Local Committee. Organisations with ten or more employees constitute their own IC. But the Act also anticipated that many workplaces — small offices, domestic workers’ employers, establishments below the ten-employee threshold — would never reach that size, and still needed somewhere for a complaint to go. That’s the role of the Local Committee, constituted at the district level by the government, acting as the equivalent redressal body for smaller establishments and for complaints against the employer themselves. Confusing the two, or assuming a small office has no obligations at all simply because it’s under the IC threshold, is a common and avoidable mistake.

FeatureInternal Committee (IC)Local Committee (LC)
Who constitutes itThe employer, at the organisational levelThe District Officer, at the district level
Applies toWorkplaces with 10+ employeesWorkplaces with fewer than 10 employees, or complaints against the employer
Where it sitsInside the organisationOutside the organisation, under district administration
Common gapComposition lapses, expired termsLow awareness among small-business employees that it exists at all
Table 4.2 — How Internal Committees and Local Committees divide responsibility under the Act.
§
05
What non-compliance actually costs

The Real Cost of Getting It Wrong

The statutory penalty for a first-time compliance failure under Section 26 of the Act — failing to constitute an Internal Committee, failing to conduct training, or failing to act on a complaint — is a fine of up to ₹50,000. Read in isolation, that number can seem almost trivial for a mid-sized or large company. It’s the compounding consequences around it that make non-compliance genuinely expensive.

First-time violation
₹50,000
Repeat violation
Higher fine
Continued non-compliance
Licence / registration risk
Public disclosure gap
Board Report exposure

The escalation structure is intentional. A first offence draws the statutory fine. Repeat non-compliance draws a higher penalty and, in some cases, exposes the business to cancellation or non-renewal of licences or registrations required to operate — a far more disruptive outcome than any fine. And now, layered on top of the statutory penalty structure, sits the reputational cost of a compliance gap that’s visible in a public filing.

💸

Direct cost

Statutory fines, potential licence or registration risk on repeat non-compliance, and legal costs if a complaint escalates to litigation.

📉

Indirect cost

Investor and client diligence flags, difficulty attracting senior talent, and reduced employee trust in internal reporting channels.

There’s also a quieter, harder-to-quantify cost: several high-profile workplace harassment incidents reported in 2026 have exposed shortcomings not in the existence of a policy, but in how it was actually implemented — inconsistent training, an under-resourced IC, or a process that employees didn’t trust enough to use. Surveys across Indian industry consistently suggest that a meaningful share of women experience some form of workplace harassment during their careers, and that a large proportion of those incidents go unreported. A compliance programme that exists mainly on paper does very little to close that gap — and increasingly, that gap is what shows up in an audit, a diligence process, or a Board Report line item.

Picture two versions of the same mid-sized company facing an identical complaint. In the first, the IC’s external member seat has quietly been vacant for eight months because no one renewed the engagement after the previous member’s term lapsed. The inquiry gets delayed while the company scrambles to onboard a replacement, the 90-day timeline slips, and the complainant — already anxious about coming forward — loses confidence in the process partway through. In the second, the same company has a properly constituted, currently trained IC that opens the inquiry within days, follows the timeline, and documents its reasoning clearly. Both companies have “a POSH policy.” Only one of them has a functioning compliance programme — and that difference is exactly what shows up when a regulator, an auditor, or a journalist eventually asks to see the paperwork behind it.

§
06
Where old training decks fall short

The Digital Workplace Blind Spot

For most of the POSH Act’s history, “workplace” meant a physical space — an office floor, a meeting room, a cabin. Policies were written around that assumption, and training followed the same script: what counts as harassment in a shared office, how to report an incident that happened at a desk or in a corridor. That boundary has effectively dissolved. Work now happens on WhatsApp, feedback gets delivered over Teams, relationships build over Slack threads — and, inevitably, so do the lines that get crossed.

This creates a genuinely harder category of case for Internal Committees to handle. Digital harassment rarely arrives as an unambiguous single incident; it tends to build through a pattern — late-night messages, an escalating tone, unwanted familiarity, persistence after a clear “no.” Committees now have to interpret screenshots, chat trails, and context in a way that a decade-old training deck, built entirely around physical-workplace scenarios, never prepared them for.

Digital PatternWhy It’s AmbiguousWhat ICs Need to Evaluate
Late-night or off-hours messagesCould be genuine urgency or a boundary-testing patternFrequency, content, and whether it recurs after being asked to stop
Escalating familiarity in chat toneCasual workplace culture can blur into personal overreachPower dynamic between sender and recipient; consistency across other colleagues
Persistence after a “no”A single follow-up may be innocuous; repeated ones are notWhether disengagement was clearly communicated and ignored
Video call conductCamera-on culture creates new exposure and commentary risksComments on appearance, unsolicited screenshots, recording without consent
Table 6.1 — Illustrative digital-workplace patterns Internal Committees are increasingly asked to evaluate.

What good digital-era training actually covers

Updated POSH training now needs to walk through hybrid and remote scenarios explicitly — not as an afterthought slide, but as a core part of the curriculum — so that both employees and IC members know how digital boundaries map onto the same legal standard as a physical-workplace incident.

This is one of the clearest signs that “we did POSH training once” is no longer a meaningful compliance statement. A programme built for 2018’s workplace, delivered unchanged in 2026, leaves both employees and Internal Committee members underprepared for the kinds of complaints that are now most likely to land on their desks.

Remote and hybrid arrangements add another layer. When a team never shares a physical office, the informal social cues that once helped colleagues self-correct — a raised eyebrow, a visibly uncomfortable silence in a meeting room — largely disappear. Feedback and reprimands that would once have happened face-to-face now happen in writing, which means there’s often a more complete record than before, but also more room for tone to be misread in both directions. Internal Committees handling a hybrid-era complaint need to be comfortable working from a digital record as the primary evidence, rather than treating it as a secondary supplement to in-person testimony.

None of this means the underlying legal test has changed — unwelcome conduct of a sexual nature remains the core standard, regardless of the medium it travels through. What’s changed is the surface area. A training programme that only ever role-plays a hallway or a cabin scenario is quietly teaching employees and IC members to recognise half of the cases they’ll actually encounter.

§
07
Clearing up persistent confusion

Common Myths, Corrected

Across HR forums, compliance webinars, and audit conversations, the same handful of misconceptions keep resurfacing — often held by otherwise well-run organisations. Correcting them is a fast way to close real exposure.

The MythThe Reality
“We’ve never had a complaint, so we don’t really need to worry about this.”A long run of nil reports is increasingly read as a signal to look closer, not proof of a healthy workplace — it may simply mean employees don’t trust the reporting channel.
“POSH is an HR issue, not something the Board needs to think about.”Since July 2025, POSH compliance status is a disclosed line item in the Board’s Report — it is now explicitly a governance responsibility, not solely an HR one.
“We’re a small company, the Act doesn’t really apply to us.”Any workplace with 10 or more employees must constitute an IC. Below that threshold, employees are still covered — via the district-level Local Committee.
“Our external IC member just needs to be listed on paper.”An external member who isn’t genuinely engaged and available creates the exact composition gap that audits flag as the most common compliance failure.
“Something that happened on WhatsApp after work hours isn’t a workplace matter.”Conduct connected to the employment relationship can fall within the Act’s scope regardless of the specific platform or the hour it occurred.
“One training session when someone joins is enough for their whole tenure.”Annual training is the statutory minimum; current guidance increasingly recommends more frequent, role-specific refreshers — especially for managers.
Table 7.1 — Frequently held misconceptions about POSH compliance, and what current guidance actually says.
§
08
Interactive — click a role to explore

Training Is Not One-Size-Fits-All

The single most repeated criticism across current compliance reviews is that most organisations still run one generic annual session for everyone — the same deck for a security guard and a department head. The law, and increasingly the enforcement environment around it, expects role-specific content. Here’s roughly what that looks like in practice for four groups.

What every employee needs to walk away knowing

For most employees, POSH training is the only formal touchpoint they’ll ever have with the Act — which means it has to do real work in a short session, not just tick an attendance box.

  • What legally constitutes sexual harassment under the Act — including verbal, non-verbal, and digital conduct
  • That the Act protects all women at the workplace regardless of employment status — including interns, contractual staff, and trainees
  • Exactly how and where to file a complaint, including through SHe-Box
  • What protections exist against retaliation for raising a complaint in good faith

What managers need on top of the employee baseline

Managers occupy an unusual dual role in this framework: they’re often the first person an employee confides in informally, and they’re also the person whose own conduct gets scrutinised most closely when a complaint involves a power imbalance.

  • How to recognise early warning signs within their own team before they escalate
  • Their obligation to act on disclosures made to them informally, not just formal complaints
  • How to avoid inadvertently pressuring a complainant or shaping the narrative before a formal inquiry
  • How digital-workplace conduct — chat tone, off-hours messaging — applies to their own behaviour as much as their team’s

What Internal Committee members need to run a defensible inquiry

IC members carry the heaviest procedural burden in the whole framework — their decisions can be challenged, appealed, and scrutinised long after the training session that was supposed to prepare them for it.

  • The full 90-day inquiry timeline and the procedural steps within it
  • Principles of natural justice — fair hearing, impartiality, documented reasoning
  • How to evaluate digital evidence: chat trails, screenshots, call logs, context
  • Annual reporting obligations to the District Officer and how these map to SHe-Box entries

What leadership needs to sign off on Board disclosures with confidence

Leadership doesn’t need to run the inquiry process personally — but they do need enough fluency in the framework to ask the right questions before signing off on a public disclosure.

  • How POSH compliance status now feeds directly into the Board’s Report under the Companies Act framework
  • What “audit-ready” actually looks like versus a policy that exists only on paper
  • Why a long run of nil complaint reports can itself be a red flag worth investigating
  • How to resource the IC and Nodal Officer roles so registration and reporting don’t lapse silently
§
09
Interactive self-check

Are You Audit-Ready?

Tick off what’s actually true for your organisation today — not what’s aspirational. This is a quick directional gauge, not a formal audit.

Compliance self-check

8 questions · updates as you check each box

0
/ 8
Get started below
§
10
Beyond the compliance case

The Career Case for Certification

Everything covered so far explains why organisations can no longer treat POSH as a once-a-year formality. But there’s a parallel story here for individuals — one that’s easy to miss if you only think about POSH as a company obligation rather than a professional credential.

As Board Reports start naming who is accountable for compliance, and as Internal Committees face a higher bar for how they run inquiries, the people who actually understand this framework in depth become disproportionately valuable. Not every HR generalist has sat with the fine detail of Section 4 composition rules, the 90-day inquiry process, or how digital evidence should be evaluated — and in 2026, that gap is starting to show.

This also explains a quieter shift in hiring patterns: job postings for HR business partner, compliance officer, and even generalist people-operations roles increasingly list POSH knowledge or certification as a preferred qualification rather than an implicit assumption. Consulting firms that provide external IC members are being asked more pointed questions about their trainers’ credentials before being engaged. And organisations building out an internal training function — rather than outsourcing every session to a consultant — need someone who can be trusted to design a curriculum that actually holds up, not just repeat a template.

  • HR professionals and people managers sit at the front line of POSH compliance — drafting the policy, running the ICC’s administrative side, and being the first point of contact when something goes wrong. A structured certification gives them the legal literacy to do that credibly, not just procedurally.
  • Aspiring and practising POSH trainers need more than familiarity with the Act — they need a recognised credential that signals depth to the organisations hiring them, especially as the external-member role on Internal Committees becomes more scrutinised.
  • Internal Committee members, including the mandatory external member, benefit directly from certification that walks through natural-justice principles and inquiry procedure — the exact areas where a poorly run process creates legal exposure.
  • Legal and compliance practitioners increasingly need POSH literacy as one thread in a broader governance skill set, given how directly it now intersects with Companies Act disclosure requirements.
  • Vskills Certificate in POSHDetail
    FormatSelf-study, online learning via LMS, video and text-based content
    GroundingBuilt on the Vishaka Guidelines and the POSH Act, 2013 framework
    Who it’s designed forHR managers, supervisors, relationship managers, executives, and management-track professionals
    ValidityCertificate issued on qualifying the assessment, with lifetime access noted for the underlying learning material
    Table 9.1 — Overview of the Vskills Certificate in POSH programme. Confirm current fees and syllabus details on the official Vskills course page before enrolling.

    The value proposition isn’t just personal résumé-building, though that matters. It’s structural: an organisation trying to write an honest, defensible line into its Board Report needs people internally — not just an external consultant brought in once a year — who genuinely understand the framework well enough to catch a vacant Presiding Officer seat, an unregistered Nodal Officer, or a training programme that hasn’t touched digital-workplace scenarios. Certification is what turns “we have a POSH policy” into “we can demonstrate exactly how our POSH programme works, end to end.”

    Build the credential the 2026 compliance landscape now expects

    The Vskills Certificate in POSH covers the Act’s legal framework, ICC composition and process, and the organisational responsibilities behind a defensible compliance programme — self-paced, online.

    Explore the Vskills POSH Certificate →
    §
    11
    Straight answers

    Frequently Asked Questions

    Yes. The threshold for mandatory Internal Committee constitution is 10 or more employees, and it applies across sectors — startups, retail, hospitality, manufacturing, and professional services alike. Company size below that threshold doesn’t remove the Act’s broader protections; it changes only the IC-constitution requirement.
    It varies by state and is evolving quickly. Several states — including Maharashtra, Delhi, Odisha, and Goa — have issued specific mandates. In jurisdictions without a formal notice yet, registration is still strongly recommended as proactive compliance, given the clear direction of both Supreme Court guidance and central government messaging. Check your state’s latest labour department circulars.
    An expired or improperly constituted IC is treated as a compliance gap, not a technicality — it’s flagged as one of the most common failure points in current audits. Any complaint received during that gap could be handled by a committee that isn’t legally validly constituted, which creates real exposure. Reconstituting the IC promptly, with all mandated roles filled, is the priority fix.
    It can. The “workplace” under the Act is understood functionally, not just physically — conduct connected to employment, including on work-adjacent digital platforms, can fall within its scope. Internal Committees are increasingly expected to evaluate chat trails and digital context using the same fairness principles applied to physical-workplace incidents.
    Since a July 2025 amendment to the Companies (Accounts) Rules, a company’s Board Report must disclose its POSH compliance status. That links workplace-harassment compliance directly to corporate governance disclosure — the same document used to report financial and governance information to regulators, investors, and the public.
    Annual training remains the statutory minimum, but current compliance guidance increasingly recommends quarterly sessions — particularly for managers — and role-specific content rather than one generic session for the entire organisation. A single yearly session that hasn’t been updated for hybrid and digital scenarios is widely viewed as an incomplete compliance measure.
    At minimum, whoever owns the compliance programme — typically an HR lead — plus Internal Committee members and anyone acting as an internal or external POSH trainer. Managers and people leaders benefit significantly too, since they’re often the first informal point of contact when an employee wants to raise a concern.
    🎯

    The bottom line

    POSH compliance in 2026 is no longer a document sitting in an HR drawer — it’s a live entry on a government portal and a disclosed line in a Board Report. The organisations and individuals who treat it as a genuine competency, backed by real certification rather than a once-a-year formality, are the ones who’ll be able to answer confidently the next time someone actually checks.

    POSH compliance is no longer invisible. It’s in your Board Report now. See what changed in 2026 — before an auditor finds it first.
    Posh Certificate
    Share this post

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    Fill out this field
    Fill out this field
    Please enter a valid email address.

    Top 10 Jobs That Didn’t Exist Five Years Ago (But Companies are Hiring for Today)
    The New Stack: How AI, IoT, and Lean Six Sigma Are Merging in 2026

    Get industry recognized certification – Contact us

    keyboard_arrow_up