Corporate

Boardroom Priorities for FY27: A Governance Blueprint

India’s boards enter FY27 with a rewritten rulebook: new tax law, tighter RPTs, assured ESG.

By Fiscal Metrics Research14 August 2026 808
Boardroom Priorities for FY27: A Governance Blueprint
· Unsplash

The half-year that ate the agenda

Somewhere around April this year, a great many Indian boards discovered that the two documents they had spent a decade learning to read — the Income-tax Act, 1961, and a comfortably familiar Regulation 23 of the Listing Regulations — no longer said what they used to say. FY27 did not arrive with a bang. It arrived as a substitution.

The macro backdrop, at least, is co-operative. At its August 2026 review the Monetary Policy Committee held the repo rate at 5.25 per cent for a fourth straight meeting, nudged real GDP growth for 2026-27 up to 6.7 per cent, and trimmed the CPI projection to 5 per cent. Governor Sanjay Malhotra was unusually plain that the outlook remained hazy and that the committee wanted greater clarity on the path and composition of inflation before moving, with energy prices still swinging on the West Asia conflict.

So growth is not the problem. Governance is where the work sits. Here is the blueprint.

1. Learn the new statute book — you are already living in it

The Income-tax Act, 2025 took effect on 1 April 2026 and governs income from FY 2026-27 onwards, compressing the old Act’s 819 sections into 536. “Previous year” and “assessment year” have been retired in favour of a single “tax year.” Rates are untouched, and the CBDT has confirmed that pending assessments, appeals and advance pricing agreements continue under the 1961 Act until they are done.

The board-level risk here is not policy. It is plumbing. Every internal policy, board resolution, ESOP document, employment contract, vendor agreement and accounting system that cites a section number now cites a dead one. Ask the CFO for a mapping status report, with a date on it — not a reassurance.

Running alongside is the Corporate Laws (Amendment) Bill, 2026, introduced in the Lok Sabha on 23 March 2026 across 107 clauses, with the Joint Parliamentary Committee tabling its report on 3 August 2026 and broadly backing it. If it is enacted as reported, small company thresholds double to ₹20 crore of paid-up capital and ₹200 crore of turnover; the fast-track merger approval bar drops from 90 per cent to 75 per cent, with exit rights for dissenting shareholders added by the Committee; the CSR committee trigger moves from ₹5 crore of net profit to ₹10 crore, and the window to park unspent CSR funds stretches from 30 days to 90; RSUs and stock appreciation rights get statutory recognition; IBBI becomes the Valuation Authority; and NFRA’s inspection, investigation and disciplinary powers expand.

Notice the trade being offered: procedural relief in exchange for sharper enforcement. That is the through-line of the whole year.

2. Related party transactions: relief at the top, tightening underneath

The LODR Fifth Amendment, notified in November 2025, retired the old “₹1,000 crore or 10 per cent of consolidated turnover, whichever is lower” test and replaced it with a slab-based schedule. Entities up to ₹20,000 crore of turnover still work off 10 per cent; above that the percentage tapers, with an absolute ceiling of ₹5,000 crore. Large conglomerates got headroom, and they were not shy about asking for it.

The other half of the amendment is less comfortable. A related party transaction entered into by a subsidiary — one to which the listed entity is not even a party — now needs the prior approval of the listed entity’s audit committee once it crosses ₹1 crore and the applicable subsidiary threshold. Audit committees that have been reviewing a tidy quarterly RPT summary should assume that summary is now incomplete.

The FY27 question for the chair is unglamorous and entirely answerable: does the group have a system that catches subsidiary-level RPTs before they happen, or one that reports them afterwards?

“Governance failures are rarely a failure of rules. They are a failure of the reporting line that was supposed to carry bad news upstairs before it became a disclosure.”

3. ESG stops being a narrative and becomes an audited number

FY 2026-27 is the year SEBI’s glide path runs out of runway. BRSR Core assessment or assurance now reaches the top 1,000 listed entities by market capitalisation, up from the top 500 in FY 2025-26. For roughly five hundred companies, this is the first year an outsider will test the nine BRSR Core attributes — greenhouse gases, water, energy, waste, wages, diversity and the rest — against actual evidence.

For the top 250, value-chain ESG disclosure remains voluntary from FY 2025-26, with assessment or assurance also voluntary from FY 2026-27, following SEBI’s March 2025 easing that narrowed “value chain” to partners contributing at least 2 per cent of purchases or sales, with disclosure capped at 75 per cent coverage.

Boards should file this under internal controls, not sustainability. The failure modes assurance providers keep reporting are dull ones: KPIs that were never defined, spreadsheets with no source documents behind them, and plant-level data that nobody actually owns.

4. Data protection and AI: two clocks running through FY27

Two dates matter. On 13 November 2026 — inside this financial year — the Data Protection Board’s penalty machinery goes live and Consent Manager registration opens. On 13 May 2027, six weeks after FY27 closes, the substantive DPDP obligations bite in full: notice, consent, data principal rights, retention and deletion, breach reporting, cross-border conditions. The ceiling for failing to take reasonable security safeguards is ₹250 crore. FY27 is the last full financial year in which a board can fix this cheaply and quietly.

On artificial intelligence, India has deliberately declined to write an omnibus statute. MeitY’s India AI Governance Guidelines of 5 November 2025 set out seven guiding principles and hand the detail to sectoral regulators, building on the RBI’s FREE-AI Committee report of 13 August 2025, which recommends board-approved AI policies, model inventories, audit coverage and incident reporting for regulated entities. Financial-sector boards should expect that to harden into supervision. Everyone else should at least be able to answer three questions: what AI is running in this company, who approved it, and what happens the day it is confidently wrong.

5. Audit committees are now themselves being inspected

On 7 January 2026 NFRA issued a circular on communication between statutory auditors and those charged with governance, flagging recurring gaps in what auditors actually tell audit committees, and when. In March 2026 it published inspection reports on the Indian network firms of the Big Four, raising firm-wide independence monitoring, audit documentation, and the procedures used to test arm’s-length pricing on related-party transactions.

Read those two together. NFRA proceedings formally concern the auditor, but the findings land squarely on financial reporting, RPTs, internal controls and audit committee oversight — which is the company’s territory, and the directors’. An audit committee that receives a bland auditor presentation and asks nothing is not staying out of trouble; it is creating a record.

Add the widened insider trading perimeter — the illustrative UPSI list went from five categories to sixteen with effect from June 2025, with externally sourced UPSI to be logged in the structured digital database within two calendar days — and the compliance officer’s FY27 workload is materially heavier than the board calendar suggests.

6. Housekeeping, resilience, and the people in the room

Three short ones.

First, the Companies Compliance Facilitation Scheme, 2026 closes on 31 August 2026, extended from 15 July after a fire at the MCA’s data centre on 5 June. Eligible companies clear pending ROC filings at 10 per cent of the accumulated additional fees. If any group entity is sitting on defaults, that is a ten-day window, not a project plan.

Second, the fire is itself the lesson. If a regulator’s data centre can be out of action for weeks, so can yours. Operational resilience — third-party concentration, recovery testing, and the not-small difference between having a backup and having tested a restore — belongs on the risk committee’s FY27 agenda rather than the IT budget line.

Third, composition. Prime Database’s March 2026 study found that 98 per cent of the 2,285 companies on the NSE main board now have at least one woman director, and women hold 21 per cent of board seats. They are also 14 per cent of key managerial personnel, 10 per cent of executive directors and 5 per cent of managing directors and CEOs. India has largely solved the board seat. It has not solved the pipeline that is supposed to feed it.

What to actually put on the agenda

A workable FY27 blueprint fits on one page:

•       A section-mapping status report under the Income-tax Act, 2025, with a named owner.

•       A refreshed RPT policy that captures subsidiary-level transactions before approval, not after.

•       A BRSR Core assurance readiness review, completed before Q3 rather than during it.

•       A DPDP gap assessment with a board-level sponsor and a May 2027 end date working backwards.

•       An AI inventory — systems, owners, approval trail, failure plan.

•       A minuted conversation with the statutory auditor that goes well past the presentation deck.

•       A succession plan that reaches at least two layers below the board.

None of it is glamorous. Governance rarely is. The boards that look well run in March 2027 will be the ones that started the boring work in August 2026.

 

Sources

1.       PRS Legislative Research — The Corporate Laws (Amendment) Bill, 2026 (bill track, JPC report) — https://prsindia.org/billtrack/the-corporate-laws-amendment-bill-2026

2.       Corporate Laws (Amendment) Bill, 2026 — full text (PDF) — https://prsindia.org/files/bills_acts/bills_parliament/2026/Corporate_Laws_(A)_Bill_2026_Text.pdf

3.       Business Standard — Corporate Laws Amendment Bill, 2026: What changes for India Inc, investors — https://www.business-standard.com/companies/news/corporate-laws-amendment-bill-2026-what-changes-for-india-inc-investors-126080400788_1.html

4.       Income Tax Department — FAQs on Interplay and Transition to the Income-tax Act, 2025 (PDF) — https://www.incometaxindia.gov.in/documents/81799/11848482/FAQs-on-Interplay-and-Transition.pdf

5.       PwC Tax Summaries — India: Corporate significant developments (Income-tax Act, 2025) — https://taxsummaries.pwc.com/india/corporate/significant-developments

6.       Business Standard — RBI MPC keeps repo rate unchanged at 5.25%, August 2026 — https://www.business-standard.com/finance/news/rbi-mpc-meet-august-repo-rate-governor-sanjay-malhotra-inflation-growth-gdp-126080500231_1.html

7.       DMD Advocates — SEBI (LODR) (Fifth Amendment) Regulations, 2025 — https://www.dmd.law/publications/securities-and-exchange-board-of-india-listing-obligations-and-disclosure-requirements-fifth-amendment-regulations-2025/

8.       MMJC — SEBI Board Meeting update: related party transaction revamp — https://www.mmjc.in/sebi-board-meeting-update-september-12-2025-related-party-transaction-revamp/

9.       Slaughter and May — ESG in APAC: India (BRSR Core assurance glide path) — https://www.slaughterandmay.com/services/practices/environmental-social-and-governance/esg-in-apac-2025/india/

10.   Sarthak Law — SEBI circular of 28 March 2025 on BRSR Core, value chain and green credits — https://sarthaklaw.com/sebi-update-esg-disclosures-brsr-core-assessment-assurance-and-green-credit-disclosures/

11.   Fisher Phillips — India’s DPDP Rules: phased deadlines to May 2027 — https://www.fisherphillips.com/en/insights/insights/indias-new-data-privacy-rules-are-here

12.   Press Information Bureau — India AI Governance Guidelines — https://www.pib.gov.in/PressReleasePage.aspx?PRID=2228315&reg=3&lang=2

13.   Saikrishna & Associates — Decoding the India AI Governance Guidelines — https://www.saikrishnaassociates.com/decoding-the-india-ai-governance-guidelines/

14.   S.S. Rana & Co. — MeitY AI Guidelines and the RBI FREE-AI Framework — https://ssrana.in/articles/meity-unveils-indias-approach-towards-regulating-artificial-intelligence/

15.   KPMG India First Notes — NFRA circular on auditor and audit committee communication — https://kpmg.com/in/en/insights/2026/02/firstnotes-bridging-the-gap-nfras-circular-for-enhancing-auditor-tcwg-communication.html

16.   Business Standard — NFRA inspection reports on Big Four network firms, March 2026 — https://www.business-standard.com/companies/news/nfra-suggests-stronger-controls-documentation-audit-firms-latest-inspections-126031600921_1.html

17.   Cyril Amarchand Mangaldas — NFRA Reimagined: what the 2026 Amendment Bill means for boards — https://corporate.cyrilamarchandblogs.com/2026/07/nfra-reimagined-what-the-2026-amendment-bill-means-for-boards-audit-committees-and-auditors/

18.   Vinod Kothari Consultants — Expanded UPSI list under the SEBI PIT (Amendment) Regulations, 2025 — https://vinodkothari.com/2025/06/upsurge-in-list-of-upsi-sebi-prohibition-of-insider-trading-amendment-regulations-2025/

19.   SCC Online — MCA extends the Companies Compliance Facilitation Scheme, 2026 to 31 August 2026 — https://www.scconline.com/blog/post/2026/07/10/mca-extends-companies-compliance-facilitation-scheme-2026/

20.   Business Standard — Prime Database study on women in Indian boardrooms, March 2026 — https://www.business-standard.com/industry/news/women-still-under-represented-in-top-corporate-roles-prime-database-report-126030700308_1.html

Discussion

0 Comments

Sign in to join the discussion.

Related reading