Skip to main content

Taxmann's Compliance Management Audit & Due Diligence (CMADD/Due Diligence) | CRACKER

Page 1


Sample Read

© All rights reserved

Price : ` 345

Sixth Edition : June 2026

Published by :

Taxmann Publications (P.) Ltd.

Sales & Marketing : 59/32, New Rohtak Road, New Delhi-110 005 India

Phone : +91-11-45562222

Website : www.taxmann.com

E-mail : sales@taxmann.com

Regd. Office : 21/35, West Punjabi Bagh, New Delhi-110 026 India

Printed at :

Tan Prints (India) Pvt. Ltd.

44 Km. Mile Stone, National Highway, Rohtak Road Village Rohad, Distt. Jhajjar (Haryana) India

E-mail : sales@tanprints.com

Disclaimer

Every effort has been made to avoid errors or omissions in this publication. In spite of this, errors may creep in. Any mistake, error or discrepancy noted may be brought to our notice which shall be taken care of in the next edition. It is notified that neither the publisher nor the author or seller will be responsible for any damage or loss of action to any one, of any kind, in any manner, therefrom.

No part of this book may be reproduced or copied in any form or by any means [graphic, electronic or mechanical, including photocopying, recording, taping, or information retrieval systems] or reproduced on any disc, tape, perforated media or other information storage device, etc., without the written permission of the publishers. Breach of this condition is liable for legal action.

For binding mistake, misprints or for missing pages, etc., the publisher’s liability is limited to replacement within seven days of purchase by similar edition. All expenses in this connection are to be borne by the purchaser. All disputes are subject to Delhi jurisdiction only.

CHAPTER 1

Corporate Compliance Framework

Q1. What steps should the Board of Directors take to ensure an effective approach to compliance within the company? [Expected Question]

Ans. To ensure an effective approach to compliance, the following steps are to be undertaken by the Board of Directors:

The participation of senior management in the development and maintenance of a compliance program.

Reviewing the effectiveness of compliance management system at periodic intervals.

To ensure that it remains updated and relevant in terms of modifications/ changes in regulatory regime including acts, rules, regulations etc. and business environment.

Q2. “Compliance Chart is only key component of Corporate Compliance Framework.” Explain. [Dec. 2022 (5 Marks)]

OR

Q3. ABC Limited was engaged in financing and developing infrastructure projects but now defaulted on several debt repayments due to the mismanagement and undisclosed liabilities in ABC group companies. It has triggered a systemic crisis, exposing deep-rooted governance, risk, and compliance failures. As a result, there was a poor board governance, no proper risk management framework and ignorance of statutory and internal Audit flags. State how Corporate Compliance framework can help ABC Limited to serve as a supporting system of risk management system to reduces risk associated with non-compliance. Elucidate the three key components of corporate compliance framework. [Dec. 2025 (5 Marks)]

Ans. ABC Limited’s failure highlights weak governance, absence of a risk management framework, and non-responsiveness to audit warnings. A Corporate Compliance Framework acts as a strong supporting system to the Risk Management System by ensuring adherence to laws, early identification of risks, and prevention of non-compliance, thereby reducing legal, financial, and reputational risks.

How Corporate Compliance Framework helps ABC Limited

Ensures timely compliance with applicable laws, rules, and regulations, reducing regulatory and penal risks.

Helps in identification, assessment, and mitigation of compliance risks, thereby strengthening overall risk management.

Establishes accountability and transparency, improving board oversight and governance.

Ensures proper response to audit observations and red flags, preventing recurrence of defaults.

Builds ethical culture and compliance discipline across the organization. The corporate compliance framework consists of three key components:

(a)Compliance Chart: The Chart provides an overview of the applicable local, state, central and international laws, regulations and standards relating to a business’ operations. The compliance chart also outlines how compliance risk mitigation activities are embedded in business processes.

(b)Compliance Advisory: It advices on compliances of applicable laws and effect of non-compliances. Compliance advisory helps organisation to evaluate their compliance functions, prevent compliance breaches and respond quickly and effectively when a breach occurred.

(c)Compliance Scorecard: It is a tool to analyse the position of an organisation in compliance.

Components of Corporate Compliance Framework

Q4. Unique Ltd., a start-up company launched in the year 2019, manufactures electric two-wheelers. Jayco, the Company Secretary was discussing the corporate compliance framework of the company. One of the consultants suggested that the Compliance Chart is a vital part of the framework and the company must at present first focus on preparation of the Compliance Chart. Explain the activities in preparation of a compliance chart and its contents. [June 2021 (5 Marks)]

Ans. The Compliance Chart is a vital part of the Framework and every organization shall give more focus on the preparation of the compliance chart. The compliance chart of a company is prepared after considering the operations and the structure of the company as the compliance requirements for an organization is based on the type of organization, activity of the organization, industry, sector in which the company operates and laws which are specifically applicable to the company. Broadly, the compliance chart is prepared by considering the following activities: Identification of compliances under applicable Laws, Rules and Regulations; Risk Assessment; Risk Mitigation (includes Training);

Compliance Monitoring (includes Action Tracking);

Compliance Reporting (includes Incident Management).

Contents of Compliance Chart

Q5. ‘‘The Compliance Chart of any company must contain the complete information on compliance dashboard, which provide a detailed compliance procedure to the compliance executor’’. As a Company Secretary, list out the various content of the Compliance Chart. [Dec. 2021 (5 Marks)]

OR

Q6. You are the Company Secretary of the newly formed company Star Infrastructure Ltd. Your chairman has asked you to prepare a compliance chart. What are the various points you would mention in the compliance chart? [June 2022 (5 Marks)]

Ans. The Compliance Chart of any company must contain the complete information on compliance dashboard, which provide a detailed compliance procedure to the compliance executor. This information includes:

Reference to the key compliance related laws, regulations, industry standards and compliance related policies and standards of the company;

Concise statements that capture the relevant internal and external compliance obligations and the risks arising from those obligations;

Inherent and managed risk level (critical, high, medium, low) of the identified obligations;

The business processes or people to which the compliance obligations are linked or on which they have an impact;

Specific compliance risk mitigation activities and compliance risk tracking and monitoring for managing the compliance obligations;

To whom and how frequently compliance related results and findings are reported; and

Clear ownership of the processes, activities and obligations outlined in the chart.

Q7. Write a Short note on: Compliance Dashboard. [Dec. 2018 (3 Marks)]

Ans. The compliance program must provide a single enterprise-wide dashboard for all users to track and trend compliance events. All compliance events should be easily viewed interactively through the enterprise compliance dashboard. Statutory auditors, internal auditors, compliance officers can use the dashboards to make decisions on the compliance status of the organization.

Q8. The Board of A-to-Z Ltd., listed entity incorporated under the Companies Act, 2013 asked you as a Practicing Company Secretary (PCS) to present through a power point presentation the process for setting up of Compliance Framework in the Secretarial Department of the company. Prepare one slide indicating various stages required in this regard. [June 2024 (5 Marks)]

OR

Q9. ABC Ltd. is having a paid-up capital of ` 1,000 crore and annual turnover of ` 2,500 crores. The company has asked you, as a Company Secretary in Practice, to advise it on preparation and finalization of its Compliance Management Framework. Give your advice. [Dec. 2020 (5 Marks)]

Ans. Process for Setting up of Compliance Framework:

Stage: 1 Identification of Compliance Obligations

Applicability of the various Act, Rules, Regulations, Policies and Procedures covering Industry Specific Sector Specific, Specific Activity, Specific Entity, Specific State Law, Local Laws.

Stage: 2 Preparation of Compliance Chart

Setting-up role and responsibilities of senior Management, Legal Department, and Compliance Executor

Stage: 3 Assessment of Historical Compliance Status

Assessment of File/Report/Return Statements/Internal Auditor/Independent agency/ Regulator

Stage: 4 Assessment of Compliance Risk

Identification of possible situations of non-compliance and development of strategy for Risk Mitigation/Risk Monitoring/Risk Reporting

Stage: 5 Compliance/Action Reporting

Report of Internal Auditor/Independent agency/Regulator with the possible consequence such as disqualification/suspension/lock out/license cancellation

Identification of Applicable Laws and Regulations

Q10. Mention the sources for the identification of compliance obligations. [Scoring Question]

Ans.

The sources for the identification of compliance obligations include: Engagement with management and other key staff in Divisions. Laws and regulations.

Permits, licences or other forms of authorisation.

Orders, rules or guidance issues by regulatory agencies.

Judgements of courts or administrative tribunals.

Treaties, conventions and protocols.

Internal policies and procedures.

Voluntary principals or codes of practice.

Q11. X, a member of the sports club has been paying all his fees in time. In the Annual General Meeting of the club, a resolution was passed for expelling X with immediate effect, as a member of the club, without citing any reason or violation of the rules and bye-laws of the club. Examine the legality of the resolution passed by the Annual General Meeting.

[Dec. 2024 (5 Marks)]

Ans. The resolution passed by the sports club is not a legal resolution. X had acquired membership in the Club after paying the requisite fees and was enjoying the rights and privileges guaranteed to the members of the Club. The membership of a person

can be cancelled only after following the related provisions of the Memorandum of Association and Articles of Association of the Club and also the Principles of Natural justice.

In this scenario neither any notice was given to Mr. X nor was any opportunity of being heard provided to Mr. X. Further, the provisions related to expulsion of members as mentioned in the Memorandum of Association and Articles of Association were not followed. Therefore, the resolution to expel Mr. X as a member of the club is invalid.

Q12. A retail company, Cloudtail, sells goods on E-commerce platform. The company sold pressure cookers made by XYZ Limited, which were not compliant with the mandatory standards. On noticing the quality lapses, the consumer wanted their money back, along with damages from the Cloudtail. Whether the Cloudtail shall be liable for damages or XYZ Limited or both? Substantiate your answers with reasons. [Dec. 2024 (5 Marks)]

Ans. In this case, Cloudtail shall be held liable for damages as well as reimbursement of the purchase price to the consumer. Cloudtail sold pressure cookers that were non-compliant with the mandatory standards prescribed under the Domestic Pressure Cooker (Quality Control) Order, 2020, which constitutes an unfair trade practice and a violation of consumer rights.

The CCPA’s fine of ` 1 Lakh and directive for price reimbursement of 1,033 pressure cookers to consumers further solidify Cloudtail’s liability. As the seller, Cloudtail is directly responsible for ensuring the products they sell meet the prescribed standards. Additionally, XYZ Limited, the manufacturer, may also be held liable since it produced the non-compliant pressure cookers. Under consumer protection laws, both the seller and the manufacturer can be jointly held responsible for selling defective or sub-standard goods, as this affects consumer safety and rights.

In conclusion, both Cloudtail and XYZ Limited may be held accountable, but Cloudtail has direct liability due to its role in the transaction and failure to ensure compliance with mandatory standards.

Compliance Risk Assessment: Basis for Compliance Management

Q13. An organisation assesses risks for identification of different types of organisation risks. While identifying inherent risks it needs to consider various risks drivers. Discuss. [Scoring Question]

Ans. An organisation assesses risks for identification of different types of organisation risks. While identifying inherent risks it needs to consider the following risks drivers which can be categorised in the following:

Legal Effect: Non compliances by the organisation can leads to various penalties, fines, imprisonment, debarment, and seizing the products etc. against the organisation and its officers.

Financial Effect: Low share prices of the securities of the organisation, financial losses and low revenues and lowering the trust of the investors are some of its negative effects.

Business Effect: Shutdown of the factories can affect the business operations of the organisation.

Reputational Effect: Loss in customers’ confidence in the brand of the organisation, bad media or social discussion can tarnish the reputation of the organisation.

Compliance Monitoring and Responsibility Centre Mapping/Allocation

Q14. Z Ltd. seeks your opinion on the role of the various levels of management for compliance ownership. Explain the role. [June 2019 (5 Marks)] Ans. The ownership of the various compliances has to be described function wise and individual wise. Clear description of primary and secondary ownership is also very important. While the primary owner is mainly responsible for the compliance, secondary owner (usually the supervisor of the primary owner) has to supervise the compliance. Ex: Secretarial Officer/Asst. Company Secretary may be primarily responsible and Group Company Secretary’s responsibility is secondary.

The role of the various level of management for compliance ownership is illustrated as under:

(

a) Top Management:

Understanding the compliance obligations and recent changes

Approval of policy and procedures

Motivating employees to doing compliance in time

(b) Legal Cell:

Identification of new and changed relevant local laws, regulations and standards

Communication in writing to compliance owner/executor

Review of system and policies and procedures

Resolution of doubts and clarity in directions

Periodical review and assessment

(c) Senior Management & Functional Heads:

Analysis and research on the Regulatory changes

Formation of policy and procedure

Motivating compliance officer for timely compliance

Guiding compliance officer in doing compliance

Tracking the compliance chart

Risk escalation

Conflict resolution

(d) Compliance Officer/Subordinate Staff:

Performing Compliance Obligations

Updating Compliance obligations into the Compliance Chart

Risk Identification and intimation Conflict intimation.

Compliance Risk - Review and Updation

Q15. Discuss about the purpose of the review Compliance risk. [Expected Question] Ans. The purpose of the review is to determine: if the plan is still necessary and accurate if the plan should be combined with another plan or if it should be rescinded if the plan is up to date with current laws and regulations if changes are required to improve the effectiveness or clarity of the plan

Training and Implementation

Q16. Sames Ltd. is a recently listed company. To cater to the growing reporting requirements, the company recruited various professionals across its finance and secretarial team. The Company Secretary was requested to prepare a Compliance training and education programme for providing training to the new recruits. Briefly explain the objective and contents of such Compliance training programme. [June 2021 (5 Marks)] Ans.

(a) Objectives: A strong Compliance training and education programme reinforces the company compliance culture. It builds awareness and understanding of compliance standards, procedures, guidelines and issues. Specifically, it should build awareness and understanding of: Company Framework, including the four conduct-related integrity risk areas; Roles and responsibilities outlined in the policies and framework; Critical and high compliance obligations identified in the Compliance Chart; The process for addressing compliance issues and reporting concerns; and Consequences of failing to meet compliance obligations.

(b) Contents: Plans for Compliance Training and Education Program may include:

Concise statements that capture the relevant internal and external compliance obligations and the risks arising from those obligations; The business processes to which the compliance obligations are linked or on which they have an impact; Brief description of the training or education activity;

Target audience (refresher for existing Employees, induction for new Employees, or Adhoc when required);

Frequency of training or education activity.

Q17. Compliance audit is not fault-finding exercise, rather a device to scaleup compliance mechanism of a company, Commensurate to its size and operations. [Dec. 2014 (4 Marks)]

Ans. Compliance audits may be planned, performed and reported separately to the Board, senior management or Regulators. The compliance audit is completely different from the audit of financial statements and from performance audits.

The compliance audits may be conducted separately on a regular basis, as distinct and clearly-defined audits each related to a specific subject matter. As per CAG Auditing Standards, the Compliance audit is the independent assessment of whether a given subject matter is in compliance with applicable authorities identified as criteria.

Compliance audits are carried out by assessing whether activities, financial transactions and information comply in all material respects, with the authorities who govern the audited entity.

Compliance auditing may be concerned with:

Regulatory: Adherence of the subject matter to the formal criteria emanating from relevant laws, regulations and agreements applicable to the entity.

Propriety: Observance of the general principles governing sound financial management and the ethical conduct of public officials.

Q18. The management of PKG Ltd., has decided to go for an independent audit assessment of whether a given subject matter of the management is in compliance with applicable authorities identified as criteria. Further, it has to carry out by assessing whether activities, financial transactions and information comply in all material respects, with the authorities who govern the audited entity. Explain about the type of audit along with its objectives that PKG Ltd. should carry out. [Dec. 2025 (5 Marks)]

Ans. PKG Ltd. should carry out a Compliance Audit.

Type of Audit: Compliance Audit

As per the Comptroller and Auditor General of India (CAG) Auditing Standards, a Compliance Audit is an independent assessment to determine whether a given subject matter is in compliance with applicable authorities identified as criteria. Compliance audit assesses whether the activities, financial transactions and information of the entity comply in all material respects with the laws, regulations, agreements, policies and standards governing the entity.

Compliance audit is different from financial statement audit and performance audit and may be planned, performed and reported separately to the Board, senior management or Regulators. It may be conducted as a distinct and clearly defined audit related to a specific subject matter.

Objectives of Compliance Audit

The objectives of a Compliance Audit include:

Regulatory Compliance: To verify adherence of the subject matter to formal criteria arising from applicable laws, regulations, rules and agreements governing the entity.

(a) Propriety: To ensure observance of sound financial management principles and ethical conduct in operations and decision-making.

(b) Contracting and Procurement

To verify whether procurement was carried out as per extant rules and delegated financial powers.

To ensure financial propriety during tendering, evaluation and award of contracts.

(c) Operational and Plant Efficiency (where applicable)

To verify whether use of power and fuel is as per approved norms.

To check whether plant shutdowns, production levels and installed capacity comply with approved and regulatory norms.

To ensure compliance with environmental regulations.

(d) Corporate Social Responsibility (CSR)

To verify whether the CSR framework is as per regulatory requirements.

To ensure CSR activities are in line with corporate policy.

To check alignment of CSR policy with relevant regulations and guidelines.

Conclusion

Hence, PKG Ltd. should conduct a Compliance Audit to independently assess compliance of its activities, financial transactions and information with applicable authorities, thereby ensuring regulatory adherence, propriety, ethical conduct and effective governance.

Q19. Critically examine and comment: “Significance of Corporate compliance Management”. [June 2014 (4 Marks)] Ans.

Compliance management program can produce positive results at several levels: Better compliance of the law;

Real time status of legal/statutory compliances;

Improved operations and higher productivity;

Go to the extra mile and lays the foundation for the control environment;

Real time status on the progress of pending litigation before the judicial/ quasi-judicial authority;

Likely to avoid stiff personal penalties, both monetary and imprisonment; Safety valve against unintended non-compliances/prosecutions, etc.;

Cost savings by avoiding penalties/fines and minimizing litigation;

Better employee engagement and retained talent;

Better brand image and positioning of the company in the market;

Enhanced creditworthiness that only a law-abiding company can command;

Recognition as Good corporate citizen.

Secretarial Audit and Compliance Management System

Q20. You have been appointed as Company Secretary of XYZ Ltd., a listed company, having diversified business and multi-operational branch offices. On joining your office, you observed that under the prevailing scenario a comprehensive compliance management system is necessary. Prepare a checklist that should be considered by you about the desired system. What would be your responsibility as Company Secretary of the Company in due compliance of the desired system? [Dec. 2019 (5 Marks)] Ans.

The compliance system and processes in a company are dependent mainly on the following factors:

Nature of business(es).

Geographical domain of its area of operation(s).

Size of the company both in terms of operations as well as investments, technology, multiplicity of business activities and manpower employed.

Jurisdictions in which it operates.

Whether the company is a listed company or not.

Regulatory authority(ies) in respect of its business operations.

Nature of the company viz., private, public, government company, etc.

Based on the above the Secretarial Auditor can constitute a broad idea about the desired system and process to be adopted by a company. For example, a multi-product/ multi operation company is supposed to comply all the applicable corporate laws in addition to regulatory framework applicable at products/operations.

Role of Company Secretaries in Compliance Management

Q21. How CS of the company could play a significant role in helping the board in institutionalizing an adequate and effective compliance management system. [June 2017 (7 Marks)] Ans.

Role of company secretaries in compliance management:

Compliance Management can add substantial business value only if compliance is done with due diligence. A company secretary is the ‘Compliance Manager’ of the company.

These disclosures can be classified into statutory disclosures, no statutory disclosures, specifies disclosures and continuous disclosures. Companies Act, 2013 and SEBI (Listing Obligations and Disclosure Requirements)

Regulation, 2015 spells out elaborately on various aspects of disclosures which are to be made by the company such as contingent liabilities, related party transactions, proceeds from initial public offerings, remuneration of directors and various details giving the threats, risks and opportunities under management discussion and analysis in the corporate governance report which is published in the annual accounts duly certified by the professional like company secretaries.

A company secretary has to ensure that these disclosures are made to shareholders and other stakeholders in true letter and spirit.

The advisory services of the company secretaries’ impact to all components and activities of the compliance framework, as the business receives one-point specialized support and advice to help manage its compliance risks more effectively.

The company secretary plays a proactive advisory role as he advises management, Boards and committees, the compliance executor, and the employees.

The company secretary provide advice on compliance risk, responsibilities, obligations, concerns and other compliance issues that are suitable for the business’ practices and operational constraints of the company.

In nutshell, the company secretary is the professional who guides the Board and the company in all matters, renders advice in terms of compliance and ensures that the Board procedures are duly followed, best global practices are brought in and the organisation is taken forward towards good corporate citizenship.

Directors Responsibility Statement

Q22. Draft the Directors’ Responsibility Statement of ABC Limited, which is to be incorporated in the Directors’ Report. [Dec. 2024 (5 Marks)] Ans.

ABC Limited

Director’s Report

To the Shareholders of ABC Limited

Your Directors confirm that they have prepared the annual accounts carefully, following the applicable accounting standards and policies, and on a going concern basis. Specifically, the Directors report that:

1. While preparing the accounts, all relevant accounting standards were followed, and any important deviations were properly explained.

2. The accounting policies chosen were applied consistently, and the estimates and judgments made were reasonable and prudent, providing a true and fair view of the company’s financial position and performance.

3. Proper care was taken to maintain adequate accounting records as required by law, safeguarding company assets and preventing fraud or other irregularities.

COMPLIANCE MANAGEMENT AUDIT & DUE

DILIGENCE (CMADD/DUE DILIGENCE) | CRACKER

AUTHOR : Ankush Bansal

PUBLISHER : Taxmann

DATE OF PUBLICATION : June 2026

EDITION : 6th Edition

ISBN NO : 9789375611035

NO. OF PAGES : 308

BINDING TYPE : Paperback

Rs. 345

DESCRIPTION

Compliance Management, Audit & Due Diligence – CRACKER is a topic-wise, practice-first question bank for CS-Professional Group 1, Paper 3. It compiles past examination questions, arranges them under named sub-topics within each chapter, and answers every one in full—written to the current law and the latest ICSI standards. Each question is tagged by sitting and marks, with high-yield questions flagged to focus revision. Mapped chapter-for-chapter to the ICSI study material, it serves as the applied companion to conceptual study, and closes with the latest paper solved in full. The Present Publication is the 6th Edition | June 2026, authored by CS Ankush Bansal, with the following noteworthy features:

•[Fully Solved Past Papers] All previous-exam questions answered in full, as per the latest examination pattern

•[Topic-wise Arrangement] Questions organised under each chapter's topics, up to the June 2026 examination

•[Fully Updated Answers] Revised as per the relevant provisions and case laws

•[Marks Distribution & Trend Analysis] Chapter-wise weightage and question trends of past exams

•[Comparison with Study Material] Chapter-wise mapping of the book to the ICSI study material

•[Layered Question Tagging] Every question shows its sitting and marks (including sub-part splits); the author additionally flags [Scoring Question], [Expected Question] and [ICSI Material Question]

•[Recency-weighted Pool] Questions span 2012 through the December 2025 sitting—the period the examiner draws from most

•[Latest Full Paper Solved] A complete, separately set June 2026 Solved Paper (Suggested Answers) for whole-paper practice

•[Current to the Latest Law] Reflects recent changes—the SEBI (LODR) Third Amendment 2024 (Regulation 24A) and the MCA's decriminalisation/e-adjudication framework

•[Standards & Forms Applied] Engages the ICSI Auditing Standards (CSAS-1 to CSAS-4) and statutory forms such as MR-3, MGT-7 and MGT-8

Turn static files into dynamic content formats.

Create a flipbook
Taxmann's Compliance Management Audit & Due Diligence (CMADD/Due Diligence) | CRACKER by Taxmann - Issuu