Crisis management explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Crisis management is the board's plan for the hours and days after something goes badly wrong: a fraud is found, a key person leaves suddenly, a plant has an accident or a regulator calls. The directors of a private or unlisted public company, its company secretary and its finance head need such a plan because decisions taken in the first day usually decide how bad the second month will be. Boards that want a written, rehearsed response often arrange it under an advanced retainership arrangement.
No statute requires an unlisted company to have a "crisis management plan"; it is good practice, not a legal requirement. The Companies Act, 2013 does touch the subject through the risk management statement in the Board's report, the auditor's duty to report fraud and the vigil mechanism. A good plan names a response team with authority, fixes the first three actions for each kind of crisis, says who speaks for the company, and ends with a written review.
Kinds of crisis a board should think about
Practice varies, but most boards plan for seven kinds: fraud discovered inside the company, the sudden exit or death of a key person, a plant accident, a product recall, a cyber incident, a regulatory action, and a liquidity shock. A company need not plan for all seven in detail. It should plan for those that its own business makes likely.
What the Act says, and where it stops
Three provisions touch the subject. None of them is a crisis plan.
Risk management statement. Section 134(3)(n) requires the Board's report to include a statement indicating the development and implementation of a risk management policy, including identification of elements of risk which in the Board's opinion may threaten the existence of the company. See section 134. Our note on financial risk management shows how a risk register is built.
Fraud reporting by the auditor. Under section 143(12), if an auditor has reason to believe that an offence of fraud involving the prescribed amount is being or has been committed in the company by its officers or employees, he reports to the Central Government within the time and manner prescribed. For a fraud below the prescribed amount he reports to the audit committee, or to the Board where there is none, and the company discloses such frauds in the Board's report in the prescribed manner. The amounts and timelines are in the rules; see fraud reporting under section 143(12).
Vigil mechanism. Section 177(9) requires every listed company, and such classes of companies as are prescribed, to set up a vigil mechanism for directors and employees to report genuine concerns. Under section 177(10) it must give safeguards against victimisation and direct access to the chairperson of the audit committee in appropriate cases. See the post on who must have a vigil mechanism. Where it exists, it is often how a fraud first comes to the board's notice.
Data breaches and cyber incidents carry reporting duties under other laws; see our data protection guides for the authorities and periods. This article states none.
Listed companies have further requirements under the securities regulations, which are not covered here.
The response team
Practice, not a legal requirement: name the team in advance and give it written authority. A workable team has a convenor (usually a director or the managing director), the finance head, the company secretary, a person for legal advice, an operations lead, and one spokesperson. Record in a board resolution that the team may take urgent steps, spend up to a stated limit, and engage outside advisers, and that every step is reported to the board at its next meeting. Boards often convene at short notice; the rules on notice for board meetings are in the post on section 173, and the company's own practice should fix how a meeting is called when time is short.
The first decisions
- Safety first. Where people are at risk, nothing else comes before it.
- Contain. Stop the loss: lock access, suspend payments or lines, secure the premises.
- Preserve evidence. Keep records, emails, logs and devices intact; stop routine deletion.
- Take advice early. Legal advice should be sought at once; consider routing the factual review through counsel, which may help keep its content confidential.
- Decide who speaks. One voice for staff, one for lenders and customers, one for any authority.
- Tell your insurer. Notice conditions in a policy can be strict; see our note on director and officer protections.
Tables (own drafting, practice)
| Crisis | First three actions | Who decides |
|---|---|---|
| Fraud found | Contain access; preserve records; brief counsel | Audit committee or board |
| Key person exit | Secure signing powers and credentials; inform banks as needed; appoint interim lead | Board |
| Plant accident | Safety and medical help; secure the site; inform authorities as the law requires | Operations head, then board |
| Product recall | Stop dispatch; trace batches; prepare the customer message | Managing director |
| Cyber incident | Isolate systems; preserve logs; engage specialist | Response team convenor |
| Regulatory action | Collect the notice; calendar the dates; engage counsel | Board |
| Liquidity shock | Cash forecast; talk to lenders; defer non-essentials | Finance head and board |
One-page response plan outline: purpose and scope; team and deputies with contact numbers; trigger levels; the first-hour checklist; communication roles; record-keeping rules; insurance notice; log of decisions; review date.
Worked example (all details assumed)
Kestrel Components Private Limited (assumed) finds that a senior accounts executive has diverted money over several months. A junior colleague raises it with the finance head, who tells the managing director the same evening.
The board's actions in sequence: first, the executive's system access and bank mandates are suspended that night. Second, the finance head secures a copy of the ledger, bank statements and emails. Third, the managing director convenes the board by the usual notice or on shorter notice if the company's practice allows, and the board forms a response team. Fourth, counsel is engaged and a forensic review is scoped; see forensic audit and investigation and statutory audit compared with forensic audit. Fifth, the statutory auditor is told, and the board notes that the auditor's own duty under section 143(12) may apply once the facts are known. Sixth, the insurer is notified. Seventh, a short script goes to the bank and key customers. After the review, the board records what failed, here an unsupervised payment right, and changes it.
Common lapses
- No named team, so the first day is spent deciding who decides.
- Deleting or overwriting records during clean-up.
- Several people speaking to lenders with different facts.
- Late notice to the insurer.
- Skipping the review afterwards, so the same gap reopens.
Need help with a response plan?
If your board wants a written response plan, a team resolution and a drill, or is already in a crisis and needs a steady hand, our team can help through our advanced retainership services, with reviews done under legal privilege where advisers so advise.
Key takeaways
- No statute requires an unlisted company to keep a crisis management plan; it is good practice.
- The Act touches the subject through sections 134(3)(n), 143(12) and 177(9) and (10).
- Name the team, its authority and its spokesperson before the crisis.
- Safety, containment and evidence come first; advice early.
- Tell the insurer in time.
- Review in writing afterwards.
Read next
- Directors and officers liability insurance and other protections
- Forensic audit and investigation of a company in India
- Statutory audit, investigation and forensic audit compared
- Section 134: the Board's report
Disclaimer: Based on the Companies Act, 2013 (MCA consolidated text) and, for the Essential Commodities Act, 1955, the India Code text showing amendments up to Act 40 of 2021, as consulted on 6 October 2026. Later amendments, rules, notifications and control orders should be checked in their current form. Checklists, report outlines and examples are illustrative drafting by TaxClue with invented names and figures. This article is general information, not legal advice; check the official text before acting.
