Next dueCompany / ROC
14 OCTADT-1 · Auditor appointment (after AGM)in 7 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 23 days 31 OCTMSME-1 · Dues to MSMEs · Apr–Sep 2026in 24 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 45 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 53 days 30 JUNDPT-3 · Return of deposits · FY 2026-27in 266 days 7 OCTTDS / TCS deposit · Deducted in Sep 2026due today 11 OCTGSTR-1 · Outward supplies · Sep 2026in 4 days
All due dates

Crisis management for a company board: the kinds of crisis, the response team, the first decisions, communication, statutory reporting and the review afterwards

No statute requires an unlisted company to have a "crisis management plan"; it is good practice, not a legal requirement. The Companies Act, 2013 does touch the subject through...

Published
Updated
Reading time
7 min
Views
10
Questions
6 answered
  • Expert Reviewed
  • High Complexity
Topic
Corporate Laws
Published
October 6, 2026
Last updated
Oct 6, 2026
Reading time
7 min
0:00
Last updated: October 2026Verified against: Government sources

Crisis management is the board's plan for the hours and days after something goes badly wrong: a fraud is found, a key person leaves suddenly, a plant has an accident or a regulator calls. The directors of a private or unlisted public company, its company secretary and its finance head need such a plan because decisions taken in the first day usually decide how bad the second month will be. Boards that want a written, rehearsed response often arrange it under an advanced retainership arrangement.

Kinds of crisis a board should think about

Practice varies, but most boards plan for seven kinds: fraud discovered inside the company, the sudden exit or death of a key person, a plant accident, a product recall, a cyber incident, a regulatory action, and a liquidity shock. A company need not plan for all seven in detail. It should plan for those that its own business makes likely.

What the Act says, and where it stops

Three provisions touch the subject. None of them is a crisis plan.

Risk management statement. Section 134(3)(n) requires the Board's report to include a statement indicating the development and implementation of a risk management policy, including identification of elements of risk which in the Board's opinion may threaten the existence of the company. See section 134. Our note on financial risk management shows how a risk register is built.

Fraud reporting by the auditor. Under section 143(12), if an auditor has reason to believe that an offence of fraud involving the prescribed amount is being or has been committed in the company by its officers or employees, he reports to the Central Government within the time and manner prescribed. For a fraud below the prescribed amount he reports to the audit committee, or to the Board where there is none, and the company discloses such frauds in the Board's report in the prescribed manner. The amounts and timelines are in the rules; see fraud reporting under section 143(12).

Vigil mechanism. Section 177(9) requires every listed company, and such classes of companies as are prescribed, to set up a vigil mechanism for directors and employees to report genuine concerns. Under section 177(10) it must give safeguards against victimisation and direct access to the chairperson of the audit committee in appropriate cases. See the post on who must have a vigil mechanism. Where it exists, it is often how a fraud first comes to the board's notice.

Data breaches and cyber incidents carry reporting duties under other laws; see our data protection guides for the authorities and periods. This article states none.

Listed companies have further requirements under the securities regulations, which are not covered here.

The response team

Practice, not a legal requirement: name the team in advance and give it written authority. A workable team has a convenor (usually a director or the managing director), the finance head, the company secretary, a person for legal advice, an operations lead, and one spokesperson. Record in a board resolution that the team may take urgent steps, spend up to a stated limit, and engage outside advisers, and that every step is reported to the board at its next meeting. Boards often convene at short notice; the rules on notice for board meetings are in the post on section 173, and the company's own practice should fix how a meeting is called when time is short.

The first decisions

  1. Safety first. Where people are at risk, nothing else comes before it.
  2. Contain. Stop the loss: lock access, suspend payments or lines, secure the premises.
  3. Preserve evidence. Keep records, emails, logs and devices intact; stop routine deletion.
  4. Take advice early. Legal advice should be sought at once; consider routing the factual review through counsel, which may help keep its content confidential.
  5. Decide who speaks. One voice for staff, one for lenders and customers, one for any authority.
  6. Tell your insurer. Notice conditions in a policy can be strict; see our note on director and officer protections.

Tables (own drafting, practice)

CrisisFirst three actionsWho decides
Fraud foundContain access; preserve records; brief counselAudit committee or board
Key person exitSecure signing powers and credentials; inform banks as needed; appoint interim leadBoard
Plant accidentSafety and medical help; secure the site; inform authorities as the law requiresOperations head, then board
Product recallStop dispatch; trace batches; prepare the customer messageManaging director
Cyber incidentIsolate systems; preserve logs; engage specialistResponse team convenor
Regulatory actionCollect the notice; calendar the dates; engage counselBoard
Liquidity shockCash forecast; talk to lenders; defer non-essentialsFinance head and board

One-page response plan outline: purpose and scope; team and deputies with contact numbers; trigger levels; the first-hour checklist; communication roles; record-keeping rules; insurance notice; log of decisions; review date.

Worked example (all details assumed)

Kestrel Components Private Limited (assumed) finds that a senior accounts executive has diverted money over several months. A junior colleague raises it with the finance head, who tells the managing director the same evening.

The board's actions in sequence: first, the executive's system access and bank mandates are suspended that night. Second, the finance head secures a copy of the ledger, bank statements and emails. Third, the managing director convenes the board by the usual notice or on shorter notice if the company's practice allows, and the board forms a response team. Fourth, counsel is engaged and a forensic review is scoped; see forensic audit and investigation and statutory audit compared with forensic audit. Fifth, the statutory auditor is told, and the board notes that the auditor's own duty under section 143(12) may apply once the facts are known. Sixth, the insurer is notified. Seventh, a short script goes to the bank and key customers. After the review, the board records what failed, here an unsupervised payment right, and changes it.

Common lapses

  • No named team, so the first day is spent deciding who decides.
  • Deleting or overwriting records during clean-up.
  • Several people speaking to lenders with different facts.
  • Late notice to the insurer.
  • Skipping the review afterwards, so the same gap reopens.

Need help with a response plan?

If your board wants a written response plan, a team resolution and a drill, or is already in a crisis and needs a steady hand, our team can help through our advanced retainership services, with reviews done under legal privilege where advisers so advise.

Key takeaways

  • No statute requires an unlisted company to keep a crisis management plan; it is good practice.
  • The Act touches the subject through sections 134(3)(n), 143(12) and 177(9) and (10).
  • Name the team, its authority and its spokesperson before the crisis.
  • Safety, containment and evidence come first; advice early.
  • Tell the insurer in time.
  • Review in writing afterwards.

Read next

Disclaimer: Based on the Companies Act, 2013 (MCA consolidated text) and, for the Essential Commodities Act, 1955, the India Code text showing amendments up to Act 40 of 2021, as consulted on 6 October 2026. Later amendments, rules, notifications and control orders should be checked in their current form. Checklists, report outlines and examples are illustrative drafting by TaxClue with invented names and figures. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About Crisis management

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

Does the Companies Act, 2013 require a crisis management plan?

No. It requires a risk management statement in the Board's report (section 134(3)(n)) but does not prescribe a crisis plan for an unlisted company.

Who reports a fraud found in the company?

The auditor has a duty under section 143(12), with amounts and times in the rules. Other reporting duties depend on the facts and other laws.

Keep the acknowledgement. A filing you cannot prove is a filing you may have to defend.

— TaxClue Compliance Desk

Crisis management: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 6 questions readers ask most on this topic.

No. It requires a risk management statement in the Board's report (section 134(3)(n)) but does not prescribe a crisis plan for an unlisted company.

The auditor has a duty under section 143(12), with amounts and times in the rules. Other reporting duties depend on the facts and other laws.

Section 177(9) applies to every listed company and to prescribed classes of companies. See the post on rule 7 for the classes.

One designated spokesperson per audience, named in advance, using facts the response team has confirmed.

It is a common practice, since it may help preserve confidentiality; take legal advice on how it should be done.

Reporting duties arise under other laws; see our data protection guides.