Guide
POSH compliance for a small team in India
By the Capstan team at PeopleCap · Last updated 18 August 2026 · About 7 min read
The Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, usually shortened to POSH, is the compliance obligation Indian founders most often discover late. It is not a payroll matter, so the accountant does not raise it. It is not a filing that generates a reminder. And it applies well before the point at which a company has anyone whose job is HR.
This guide sets out what the obligation is in structure, what a small team actually has to build, and what to keep as evidence. It deliberately states no headcount threshold, no timeline in days and no penalty figure. Those are set by the Act and its rules, they have moved, and reading them from a page like this one rather than from counsel or the statute is exactly how compliance goes wrong. What follows is the shape of the obligation, which does not change.
The four obligations, in outline
A policy. A written policy against sexual harassment at the workplace, communicated so that everyone who works there knows it exists and knows how to use it. Publishing it once in a founding document does not discharge this; it has to reach new joiners too, which is why it belongs in onboarding rather than in an announcement.
An internal committee. Once an establishment reaches the headcount the Act specifies, it must constitute an internal committee with a prescribed composition. That composition is not a matter of preference. It requires a presiding officer who is a senior woman employed at the workplace, members drawn from among the employees, and, importantly for small companies, at least one external member from outside the organisation with relevant experience, typically a lawyer or someone from an organisation working on these issues. The Act also sets a minimum proportion of women on the committee and a maximum term for members.
Awareness and training. The employer must organise awareness for employees and orientation for committee members. This is a standing obligation rather than a one-off event, and it is one of the first things a regulator or a customer’s diligence process asks to see evidence of.
Reporting and record-keeping. An annual report from the committee, and records of complaints and their handling kept as the Act requires.
Confirm each of these against current law with an Indian adviser before you rely on any of it.
Why small companies get caught out
Three reasons, and all of them are structural rather than negligent.
The first is the external member. Every other compliance obligation a small company faces can be discharged internally or by an existing accountant. This one requires you to find, appoint and pay a qualified person from outside your organisation, which means it has a lead time. Companies discover this in the week they are trying to constitute a committee because a complaint has arrived, which is the worst possible week to discover it.
The second is the definition of employee. The Act reaches beyond people on payroll: contract workers, probationers, trainees, apprentices and volunteers are within it, whether or not there is a written contract. If your team is half contractors, POSH does not shrink to fit your headcount definition. This is a good reason to hold employees and contractors in the same directory rather than in two systems, which is how the Capstan core models people, and it is a different question from classification, which contractor vs employee covers.
The third is the definition of workplace. It is broader than the premises: places employees visit in the course of employment and employer-provided transport are included, and conduct on work chat, email and video calls is not outside the scope because it happened on a screen. Distributed teams are covered, and a company with no office is not exempt.
What a small team actually has to build
Write the policy and put it where people find it. In the employee handbook, issued at onboarding, acknowledged with a date and a version recorded. An acknowledgement of an unversioned document is nearly worthless two years later, so record the version the person actually saw.
Constitute the committee properly and record the appointments. Names, roles on the committee, the date of appointment and the date the term expires. Terms expire, and a committee that has quietly lapsed is not a committee. Treat reappointment as a diarised event.
Find your external member before you need one. Ask other founders, ask your counsel, ask an organisation that does this work. Agree the engagement and the fee in advance. This is a phone call in a quiet month and a crisis in a loud one.
Publish the complaint route in more than one place. In the policy, in the handbook, and somewhere a person can find without opening a document. Include the alternative route for when the complaint concerns someone on the committee, because a process with a single door is not a process.
Run the training and keep the attendance record. Awareness for everyone, orientation for the committee. Keep the date, the attendee list and the materials. If you use a Learning module to run and record it, the completion record is the evidence; if you run it as a session, write down who was there.
Diarise the annual report and the review. Put both in your HR compliance calendar alongside document renewals and the other periodic obligations, so they arrive as a task rather than as a memory.
The part where software should stay out
There is a strong instinct to put everything in the HR system. Resist it for the case files.
Complaints under POSH are confidential to the committee, and the handling process has its own rules about who may see what and when. Putting case detail into a general HR system, where a workspace administrator can read anything, is a confidentiality failure waiting to happen even if nobody ever looks. Keep case files in a restricted place with a documented process and a named custodian.
What the HR system should hold is the scaffolding around the process, and there it is genuinely useful:
- Proof the policy was issued and acknowledged, with the date and version.
- Committee appointments with their terms and expiry dates, so lapse is visible.
- Training completion records.
- Document expiry reminders, so the annual obligations arrive on time.
- An activity log showing who accessed which record and when, which is the answer to “who could have seen this” rather than a promise about it.
In the core, documents are collected as part of onboarding and filed against the person, expiry tracking produces reminders, and every action lands in an append-only activity log the admin filters and exports themselves. There is also a design position that matters here: nothing in Capstan scores, ranks or screens a person, and no employee data goes to an outside model. A compliance process about human judgement should not have a machine forming a view in the background.
Evidence, which is the thing you will actually be asked for
Compliance is not what you did. It is what you can show you did, months or years later, to someone who was not there.
Four things carry most of the weight. The policy with a version history, so you can show what it said at a given date. Acknowledgements with dates and versions. Committee appointment records with terms. Training records with attendance.
All four have the same property: they are only useful if they can be read as they stood at a point in time. A policy overwritten in place cannot tell you what it said in 2025. This is the same argument that runs through everything else on this site about record-keeping, and it is set out at length in an HR system is a record of the past. Changes in Capstan are effective-dated for exactly this reason.
If you are answering a customer’s security or compliance questionnaire and POSH comes up, the way to answer is the way you answer everything else: name the control, name the evidence, and name the gap if there is one. How to answer an HR security questionnaire covers the technique.
The first week version
If you are an Indian company with a growing team and none of this exists yet, do these five things in order.
Take advice on whether the committee obligation applies to you today. Write and publish the policy. Start looking for an external member now, because it takes longer than anything else on the list. Put the annual report and the training in your compliance calendar. And make policy acknowledgement part of onboarding so the problem stops growing while you fix it.
None of that is expensive. All of it is materially harder to do after a complaint arrives, which is the only reason this guide exists.
Common questions
What does the POSH Act require a company to do?
In outline, four things. Publish a policy against sexual harassment and make it known to everyone who works there. Constitute an internal committee with the composition the Act prescribes, including an external member from outside the organisation. Provide a complaint process with defined timelines and run awareness and committee training. And report annually. The Act also sets the headcount at which an internal committee becomes mandatory, and the timelines the process must follow, both of which should be confirmed with Indian counsel rather than taken from a blog post.
Who counts as an employee for POSH purposes?
The Act reaches wider than payroll. Its definition of employee covers people engaged on a range of terms, including contract workers, probationers, trainees, apprentices and people working on a voluntary basis, whether or not the employment is written. It also protects any woman visiting the workplace, so a customer, a candidate at interview or a visiting contractor is within scope. A small company that treats POSH as applying only to its salaried staff has drawn the boundary in the wrong place.
Do remote and distributed teams need this?
Yes, and the workplace definition is broader than the office. It extends to places employees visit in the course of employment and to transport provided by the employer, and conduct on work communication channels and video calls is not outside it because it happened on a screen. For a distributed Indian team the practical consequence is that your committee members may be in different cities, your training has to work remotely, and your complaint route has to be usable by someone who never comes to an office.
Where does an HR system fit in POSH compliance?
Around the process, never inside it. A system of record can prove the policy was issued and acknowledged with a date and a version, hold committee appointment terms and their expiry, remind you when training and reappointment fall due, and evidence who had access to what. It should not hold complaint files. Those are confidential to the committee and belong in a restricted place with a documented handling process. Capstan runs no algorithm over people and holds no scoring of anyone, so nothing here interprets a case.