Regulation 22 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
A vigil mechanism is easy to have and hard to make work, and the difference between the two shows up only when something has gone wrong.
Regulation 22 is short. The substance is in two clauses that most policies reproduce and few companies operationalise: adequate safeguards against victimisation, and direct access to the chairperson of the audit committee.
Every listed entity must formulate a vigil mechanism for directors and employees to report genuine concerns. It must provide adequate safeguards against victimisation of the person using it, and direct access to the chairperson of the audit committee in appropriate or exceptional cases. Details of the mechanism go in the board's report and on the website.
What the regulation requires
| Element | Requirement |
|---|---|
| Who may use it | Directors and employees of the listed entity |
| What may be reported | Genuine concerns — unethical behaviour, actual or suspected fraud, violation of the code of conduct |
| Protection | Adequate safeguards against victimisation of persons using the mechanism |
| Escalation | Direct access to the chairperson of the audit committee in appropriate or exceptional cases |
| Oversight | The audit committee reviews the functioning of the mechanism |
| Disclosure | Details in the board's report and on the website |
The Companies Act requires a similar mechanism under Section 177 for certain classes of company. For a listed entity the two run together, and the LODR obligation is not discharged by pointing at the Companies Act policy — the audit committee's review of the mechanism's functioning is a LODR item and belongs in the minutes.
The two clauses that carry the weight
Direct access to the audit committee chairperson. This exists because the most serious reports are the ones that implicate management — and a mechanism routing every complaint through the compliance officer, who reports to management, cannot handle those.
"Direct" means what it says. A published channel that reaches the chairperson without passing through anyone else: a dedicated email address the chairperson controls, or a third-party service instructed to escalate certain categories straight through. A policy that says "in exceptional cases the complainant may approach the audit committee chairperson" without saying how has not created access.
Adequate safeguards against victimisation. The tests that matter in practice:
- Confidentiality of identity, with a stated and narrow list of who learns it;
- anonymous reports accepted, and investigated on their merits rather than dismissed for want of a name;
- an express bar on retaliation — dismissal, transfer, demotion, withheld increments or increased scrutiny — extending to anyone who assists an investigation;
- a separate route for a retaliation complaint, because a complainant facing retaliation cannot report it into the same channel; and
- an investigation conducted by someone independent of the subject matter, which for a report against senior management means outside the reporting line entirely.
The audit committee's review
The audit committee reviews the functioning of the vigil mechanism. What that review should look at:
- the number of complaints received, by category, and how they were disposed of;
- time taken from receipt to conclusion;
- whether any complaint went directly to the chairperson, and what happened;
- whether any retaliation was alleged, and the outcome;
- whether the channels are actually known to employees — induction coverage, periodic reminders, visibility on the intranet. Audit committee →
A mechanism that has never received a complaint is not a clean record. In an organisation of any size it is far more likely to mean people do not know the channel exists, or do not believe it is safe to use. That is a finding for the committee to act on, not a result to report with satisfaction.
Where it connects to insider trading
The Prohibition of Insider Trading Regulations require a listed entity to have an informant mechanism for reporting violations of insider trading law, with its own protections and, in defined circumstances, a reward.
That is a separate mechanism with a separate legal basis. Companies sometimes fold it into the general whistle-blower policy and lose the specific protections in the process. Keep the routes distinct and cross-reference them, so a person reporting suspected insider trading lands in the right regime. SEBI insider trading regulations →
Key takeaways
- Directors and employees, reporting genuine concerns.
- "Direct access" needs a named, usable channel — not a sentence in a policy.
- Anonymous complaints should be investigated, not discarded.
- Retaliation needs its own reporting route, outside the normal channel.
- The audit committee reviews functioning, and should minute what it reviewed.
- Zero complaints is a warning sign, not a result.
- The insider trading informant mechanism is separate. Do not merge them.
Read next
- Regulation 18: The Audit Committee of a Listed Entity
- Regulation 21: Risk Management Committee
- Regulation 46: What Must Be on a Listed Entity's Website
- SEBI Insider Trading Regulations — PIT 2015
Disclaimer: Positions stated as on 5 September 2026. Verify the current text of the Listing Regulations on sebi.gov.in before relying on any requirement here.
Key Facts About Regulation 22
- Applies in: All states across India, under the relevant central law.
- Mode: Mostly online via the official government portal.
- Typical timeline: Ranges from a few days to a few weeks depending on the case.
- Non-compliance: May attract penalties, interest or late fees.
- Expert help: TaxClue completes the entire process end to end for you.
Who can use a listed company's vigil mechanism?
Directors and employees of the listed entity, to report genuine concerns such as unethical behaviour, actual or suspected fraud, or violation of the company's code of conduct.
What protection does Regulation 22 require?
Adequate safeguards against victimisation of persons who use the mechanism, and direct access to the chairperson of the audit committee in appropriate or exceptional cases.
Over 90% of compliance penalties in India arise from missed due dates — timely handling can save businesses thousands of rupees each year.
Regulation 22: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.