CSJ June 2026 Article — Transcript
Full transcript
- 0:00From custodian to architect, emerging
- 0:02digital tools, analytical models and the
- 0:05transformation of practicing company
- 0:08secretaries work in India. Author CAS
- 0:11Ishan Medar ACS abstract the profession
- 0:14of the practicing company secretary PCs
- 0:18in India has never stood still but the
- 0:20pace of its current transformation is
- 0:23qualitatively different from anything
- 0:25the profession has experienced before.
- 0:28The convergence of an increasingly dense
- 0:31regulatory architecture with genuinely
- 0:34powerful digital tools has created both
- 0:36an unprecedented challenge and a
- 0:38remarkable opportunity.
- 0:41This article examines that convergence
- 0:43honestly. What the tools are, what they
- 0:46can and cannot do, how they intersect
- 0:49with the company's act.
- 0:522013 SCBI loader regulations the digital
- 0:56personal data protection act 2023 and
- 1:00MCA's continuing digitization agenda and
- 1:03critically how a PC's professional can
- 1:06move from passive adoption to active
- 1:08deployment. The article gives particular
- 1:12attention to interactive analytical
- 1:14dashboards and compliance visualization
- 1:17models as emerging instruments for
- 1:19client advisory, governance diagnostics
- 1:22and regulatory communication. Arguing
- 1:25that the PCs who can translate a complex
- 1:28market surveillance anomaly or a
- 1:30compliance obligation matrix into a
- 1:32dynamic visual model for a board is
- 1:35delivering a categorically different
- 1:37quality of professional service.
- 1:40The underlying argument is
- 1:42straightforward. Technology does not
- 1:44replace the PCs.
- 1:46But a PCs without technology is rapidly
- 1:49being replaced by one who has it. One a
- 1:53profession at a crossroads. And why this
- 1:56moment is different. There is a telling
- 1:58symmetry in how the profession of
- 2:00company secretarship has evolved. The
- 2:04first generation of company secretaries
- 2:06in independent India occupied a largely
- 2:09clerical terrain maintaining statutory
- 2:11registers coordinating board meetings
- 2:14and navigating a nassent corporate law
- 2:17framework.
- 2:18The second generation inherited the
- 2:20company's act 1956 and gradually built a
- 2:24professional identity rooted in
- 2:26procedural mastery and statutory
- 2:29compliance.
- 2:30The third operating under the company's
- 2:33act 2013 found themselves increasingly
- 2:37recognized as governance professionals,
- 2:40participants in audit committees,
- 2:42signaries on secretarial audit reports,
- 2:45advisers to boards on director
- 2:47appointments and related party
- 2:49transactions. The current generation is
- 2:52confronting something more radical. The
- 2:54simultaneous arrival of genuine
- 2:56artificial intelligence tools. near
- 2:59total digital regulatory infrastructure
- 3:01and a data privacy regime that
- 3:03fundamentally
- 3:05changes the governance of personal
- 3:07information.
- 3:09This is not merely an upgrade of
- 3:12existing tools. It is a structural shift
- 3:15in the nature of compliance work itself
- 3:18and it demands a correspondingly
- 3:20structural response from practitioners.
- 3:22What separates the present moment from
- 3:24previous inflections is the simultenity
- 3:27of the pressures. MCA's centralization
- 3:30of processing through MCA2 version 3.0
- 3:34zero SCBI's expanding continuous
- 3:37disclosure obligations under loader, the
- 3:40activation of the DPDP rules in November
- 3:432025 with their 18month enforcement
- 3:47clock and the progressive expansion of
- 3:50BRSR core assurance requirements. All of
- 3:53these are live and operational at the
- 3:55same time, not sequential. A PC's
- 3:59advising a midcap listed company in FY
- 4:022025 to 26 is simultaneously managing
- 4:06quarterly loader filings,
- 4:09BRS core disclosures for the first time,
- 4:12a DPDP compliance gap assessment and a
- 4:15secretarial audit under section 204. All
- 4:19while their client expects real-time
- 4:21governance visibility rather than
- 4:23quarterly paper reports. A company
- 4:25secretary embracing AI and machine
- 4:28learning is like a Formula 1 driver with
- 4:31a finely tuned F1 car. Precision, speed,
- 4:34and control. Without it, they are still
- 4:38skilled, but racing with a road car on
- 4:40the same track. The purpose of this
- 4:43article is not to celebrate technology
- 4:46for its own sake. Several of the tools
- 4:49now available to PCs professionals carry
- 4:52real risks of misplaced reliance, data
- 4:55privacy exposure, professional
- 4:57liability, and what one might call the
- 5:00confident wrongness problem of AI
- 5:02generated outputs that sound
- 5:04authoritative but contain errors. The
- 5:07purpose is to examine the tools
- 5:09honestly, situate them within the
- 5:12regulatory framework and offer a
- 5:14practitioner level assessment of where
- 5:16they genuinely add value to the
- 5:19regulatory architecture complexity as
- 5:22the new normal to point one the
- 5:24company's act 2013 and the weight of
- 5:28statutory responsibility. The company's
- 5:30act 2013 is by any honest assessment
- 5:35a formidable compliance instrument.
- 5:38Its 470 sections, seven schedules and
- 5:42accompanying rules create a compliance
- 5:44universe that demands sustained
- 5:46professional attention. For the PCs, the
- 5:50most significant provisions are
- 5:52simultaneously the most consequential
- 5:55section 204 mandating secretarial audits
- 5:58for prescribed companies. Section 205
- 6:01defining the company secretaries
- 6:03functions as a key managerial personnel
- 6:06and the punel provisions under section
- 6:08454 that can directly implicate the
- 6:11professional for non-compliance. The
- 6:14secretarial audit report in form MR3 has
- 6:17emerged over the last decade as a proxy
- 6:21document read by institutional
- 6:23investors, lenders and increasingly by
- 6:27SCBI itself
- 6:29as an indicator of a company's
- 6:31governance health. When a PCs signs that
- 6:35report, the professional is not merely
- 6:38certifying historical compliance.
- 6:41They are in practice placing their
- 6:43professional reputation on the quality
- 6:45of the company's governance processes.
- 6:48That weight has grown and the tools
- 6:51available to discharge that
- 6:53responsibility must grow with it to
- 6:55point to SCBI loader, a framework of
- 6:58continuous obligations for PC's
- 7:01professionals advising listed entities.
- 7:03The SCBI listing obligations and
- 7:06disclosure requirements regulations 2015
- 7:10as they have been amended through 2023
- 7:13and 2024
- 7:16constitute an intricate layer of ongoing
- 7:19obligations that sit alongside not
- 7:22beneath the company's act framework.
- 7:25Quarterly compliance reports. The annual
- 7:28secretarial compliance report under SEBI
- 7:31circular dated 29th March 2019. Material
- 7:36event disclosures within 24 hours and in
- 7:40some cases 30 minutes of a board
- 7:42decision and the increasingly detailed
- 7:45related party transaction disclosure
- 7:47norms together constitute a compliance
- 7:50burden that simply cannot be managed
- 7:52sustainably through manual systems.
- 7:55The SEBI loader also brought the
- 7:58business responsibility and
- 8:00sustainability report into mandatory
- 8:02territory for the top 1,000 listed
- 8:05companies by market capitalization, a
- 8:08disclosure requirement that has now
- 8:11expanded into BRS core, a subset of key
- 8:15performance indicators requiring
- 8:17independent assurance. The applicability
- 8:20of BRSR core assurance expanded from the
- 8:23top 150 companies in FY2023
- 8:28to 24 to the top 500 in FY 2025 to 26
- 8:33with the full top 1,000 captured by FY
- 8:372026 to 27. BRS core milestones
- 8:41applicable entities key regulatory
- 8:43scope. FY2023
- 8:46to 24 top 150 listed companies mandatory
- 8:50BRSR core assessment. FY 2024 to 25 top
- 8:55to 50 listed companies BRSR core value
- 8:58chain ESG disclosures. FY 2025 to 26 top
- 9:03500 listed companies mandatory BRSR core
- 9:06assessment. FY 2026 to 27 top 1,000
- 9:11listed companies full BRSR core value
- 9:15chain assurance sources times SCBI
- 9:18circular no SCBI host CFD CFD set to
- 9:23PCIR 2023/12
- 9:26dated 12th July 2023 regarding BRS core
- 9:31and ESG disclosures
- 9:34times SCBI circular no SEBI host CFD CFD
- 9:39pod to PCIR 2024/99
- 9:43and related implementation guidance
- 9:45times KPMG India emerging trends in BRSR
- 9:49reporting by listed companies issue 115
- 9:53to 0 to6 dot times Glossert
- 9:56International BRSR core assurance
- 9:58readiness guide for Indian companies
- 10:012026
- 10:03dot 2.3 the DPDP act 2023. A new
- 10:08governance frontier, the Digital
- 10:10Personal Data Protection Act 2023 and
- 10:14the DPDP rules formally notified in
- 10:17November 2025
- 10:19represent the most consequential
- 10:21addition to the PCS's responsibility
- 10:23matrix in recent years.
- 10:26The act establishes a data fiduciary
- 10:29framework under which organizations
- 10:31processing personal data bear absolute
- 10:34accountability for collection,
- 10:36processing, storage and deletion of that
- 10:39data with financial penalties structured
- 10:42to compel genuine compliance rather than
- 10:44token gesture for the PCs. The DPDP act
- 10:48has direct professional implications.
- 10:51statutory registers, director
- 10:54identification details, shareholder
- 10:56records, KMP personal data and employee
- 10:59information maintained under the
- 11:01company's act are all personal data
- 11:04within the acts definition. The PC's
- 11:07advising on governance architecture must
- 11:10now integrate data protection
- 11:12considerations into every process. Board
- 11:15minute drafting,
- 11:17statutory register maintenance, document
- 11:20retention policies, and the choice of
- 11:22technology vendors who process client
- 11:25data on the firm's behalf. DPDP
- 11:27compliance timeline target milestone
- 11:30significance for PCs. November 13th to
- 11:3314th, 2025. Rules notification data
- 11:37protection board activated. 18 month
- 11:40clock begins. June to August 2026.
- 11:44Integration readiness consent management
- 11:46systems must be interoperable. November
- 11:492026 legacy data revalidation historical
- 11:53consent records must be revalidated. Q1
- 11:572027 first SDF audit cycle. Independent
- 12:01audits mandatory for significant data
- 12:04fiduciaries May 2027 full enforcement
- 12:08complete panel powers finds up to 250 cr
- 12:12rupees active. sources times digital
- 12:15personal data protection act
- 12:182023
- 12:20times DPDP rules 2025
- 12:23notified on 13 to 14 November 2025
- 12:28dot times ministry of electronics and
- 12:31information technology matey
- 12:34notifications implementation guidance
- 12:37and stakeholder consultation documents
- 12:39times industry and legal analyszis
- 12:42interpreting the phased implementation
- 12:44roadmap under the DPDP framework three
- 12:48emerging tools and assessment 3.1
- 12:51artificial intelligence and generative
- 12:54AI in compliance work artificial
- 12:56intelligence in its practical enterprise
- 12:59manifestation is already embedded in
- 13:02several compliance adjacent functions AI
- 13:05powered contract analysis tools can
- 13:08process hundreds of pages in minutes
- 13:11flagging clauses that implicate
- 13:13regulatory thresholds or related party
- 13:16transaction norms. Natural language
- 13:19processing systems monitor SEBI
- 13:22circulars and MCA notifications in real
- 13:25time, generating summarized compliance
- 13:27implications for specific company
- 13:30profiles within hours of a new
- 13:32notifications release. Generative AI
- 13:34tools, large language models accessible
- 13:37via API or enterprise platform have
- 13:40opened a specific and genuinely useful
- 13:43channel for PC's professionals the
- 13:46ability to draft, summarize and analyze
- 13:49regulatory content at speed. A PCs who
- 13:53needs to draft an initial AGM notice,
- 13:56prepare a first cut analysis of a SEBI
- 13:59circulars applicability or generate a
- 14:02comparison of section 149 of the
- 14:05company's act with regulation 17 of SCBI
- 14:08loader on independent director
- 14:11requirements
- 14:12can use a well ststructured prompt to
- 14:14accelerate that work from hours to
- 14:17minutes. However, the profession must be
- 14:19unambiguous about the limits. These
- 14:22models predict the statistically
- 14:24probable next word. They do not reason
- 14:27from first principles of law. They can
- 14:30confidently misquote a statutory
- 14:33provision, cite a non-existent circular,
- 14:36or miss a nuanced carveout in a SEBI
- 14:39amendment. The professional
- 14:41responsibility and the legal liability
- 14:44remains with the PCs regardless of how
- 14:47the first draft was generated. AI
- 14:50accelerates the process. Professional
- 14:52judgment determines whether the output
- 14:55is usable critically. Working with
- 14:57generative AI tools requires a skill
- 15:00that is genuinely new for the
- 15:02profession. Prompt engineering.
- 15:04The utility of an AI tool is directly
- 15:07proportional to the precision of the
- 15:09instructions given to it. Three elements
- 15:12determine the quality of any AI
- 15:15generated output. Role assignment
- 15:17explicitly telling the model it is a
- 15:19legal researcher specializing in Indian
- 15:22corporate governance. Task description
- 15:24specifying the precise objective with
- 15:27relevant context and constraints
- 15:29defining the format. word limit,
- 15:32regulatory sources to be cited, and the
- 15:35level of technical detail required. A
- 15:38PCs who has invested in developing this
- 15:41skill has access to a research
- 15:43accelerator of genuine power. One who
- 15:47treats AI tools as autonomous unser
- 15:49machines will predictably be
- 15:52disappointed and potentially exposed
- 15:54three point to robotic process
- 15:56automation. the workhorse of digital
- 15:59compliance. If generative AI captures
- 16:01the imagination, robotic process
- 16:04automation is the quiet engine running
- 16:06beneath much of what digital compliance
- 16:09has already become. RPA tools are
- 16:12designed precisely for the structured
- 16:15rules-based high volume tasks that
- 16:18constitute a significant proportion of
- 16:20PC's practice. population MCA21 forms
- 16:24from internal data sources. Verifying
- 16:27DIN details against the MCA register,
- 16:31extracting board resolution data for
- 16:33form filings, reconciling share capital
- 16:36audit figures against depository records
- 16:39for a PC's practice managing 60 to 100
- 16:42client companies. A single RPA workflow
- 16:45that extracts data from board minutes
- 16:48and populates form MGT7 or DIR 12 can
- 16:52reduce processing time from 3 hours to
- 16:5530 minutes per client while
- 16:57simultaneously generating an auditable
- 16:59data tray. The aggregate efficiency gain
- 17:03and the corresponding capacity to serve
- 17:06more clients without proportional
- 17:08headcount increase is material. More
- 17:11importantly, RPA eliminates the category
- 17:14of errors caused by manual
- 17:16transcription, the wrong DIN, the
- 17:18incorrect date, the msque pan. These
- 17:22errors are not merely embarrassing.
- 17:25Under MCA21's
- 17:27centralized adjudication module, they
- 17:30can trigger penalty proceedings, 3.3
- 17:33compliance dashboards, and interactive
- 17:36analytical models. The most
- 17:38transformative tool available to the
- 17:40modern PCs and the one least discussed
- 17:43in professional literature is the
- 17:45interactive compliance dashboard.
- 17:48Not the static spreadsheet as tracker
- 17:50that most practices still rely on, but
- 17:53the dynamic realtime graphically rich
- 17:56compliance intelligence platform that
- 17:58converts regulatory complexity into
- 18:00actionable visual information.
- 18:03The distinction matters enormously both
- 18:06operationally and in the advisory
- 18:08relationship with clients. Consider a
- 18:12scenario that will resonate with any PCs
- 18:15advising a listed company. SCBI issues a
- 18:18material amendment to the loader related
- 18:21party transaction norms. The traditional
- 18:24response is a written memorandum
- 18:26circulated by email, reviewed
- 18:29inconsistently, and filed in a folder
- 18:31that no one revisits until the next
- 18:34compliance review. The dashboard enabled
- 18:37response is entirely different.
- 18:40The amendment is mapped within 48 hours
- 18:43against the specific company's existing
- 18:45RPT framework, existing audit committee
- 18:48charter, and upcoming board meeting
- 18:50schedule, generating a visual action
- 18:53tracker with color-coded urgency levels
- 18:56and deadline alerts that the compliance
- 18:59officer and CFO can access on any
- 19:02device.
- 19:03The value proposition extends beyond
- 19:05operational efficiency into client
- 19:08communication.
- 19:09Boards are composed of individuals with
- 19:12varying degrees of regulatory
- 19:14familiarity.
- 19:16An independent director joining from an
- 19:19operational background may understand
- 19:21their fiduciary obligations in principle
- 19:24but struggle to navigate the procedural
- 19:26sequence of an RPT approval process
- 19:29across sections 177 and 188 of the
- 19:33company's act the load norms and the
- 19:36specific timeline requirements for
- 19:39shareholder approval at prescribed
- 19:41thresholds
- 19:42a PCs who presents this as a dense Legal
- 19:46memorandum is delivering information a
- 19:49PCs who presents it as a clear
- 19:52interactive process flow color-coded by
- 19:54regulatory source annotated with
- 19:57threshold values linked to the company's
- 20:00specific upcoming compliance calendar is
- 20:03delivering understanding the company
- 20:05secretary who can turn regulatory
- 20:07complexity into actionable intelligence
- 20:10is not just a compliance officer. They
- 20:13are a strategic partner competing with
- 20:15global advisory giants.
- 20:183.4 SCBI market surveillance models and
- 20:22anomaly detection. A particularly
- 20:24sophisticated application of analytical
- 20:27modeling in the PC's context is the
- 20:29deployment of market surveillance
- 20:32and anomaly detection frameworks. tools
- 20:35that until recently were the exclusive
- 20:38preserve of SEBI itself and large
- 20:41institutional compliance teams. The
- 20:44democratization of such capabilities
- 20:47through modern data platforms has opened
- 20:50a genuinely important opportunity for
- 20:52PC's professionals advising listed
- 20:55entities on insider trading compliance.
- 20:58The SCBI prohibition of insider trading
- 21:01regulations 2015 specifically
- 21:05regulations 3 5 and 3 six impose a
- 21:09non-negotiable obligation on listed
- 21:11entities to maintain a structured
- 21:14digital database recording all
- 21:16individuals with access to unpublished
- 21:18price sensitive information. The nature
- 21:21of that information and the recipient
- 21:24span details
- 21:26SCBI mandates cryptographic timestamping
- 21:30internal hosting complete tamperproofing
- 21:32and an 8-year retention minimum.
- 21:35Managing this through standard office
- 21:37software is not merely impractical. It
- 21:41is legally indefensible. Certified SDDD
- 21:44software platforms now incorporate
- 21:46anomaly detection logic that tracks the
- 21:49flow of oopsy autonomously.
- 21:51When a listed company's board begins
- 21:54deliberating a merger, the system logs
- 21:57every internal and external transmission
- 21:59of that information without manual
- 22:02intervention, enforcing role-based
- 22:04access controls and generating an
- 22:07alterable audit tray. More sophisticated
- 22:10implementations layer trading pattern
- 22:13analysis at top the oopsy tracking
- 22:15flagging instances where a director's
- 22:18personal trading activity shows
- 22:20statistical correlation with oopsy
- 22:22access events in ways that would concern
- 22:25a SCBI examination team. This is
- 22:29precisely the domain where the market
- 22:31surveillance dashboard model becomes
- 22:34professionally relevant for the PCs. A
- 22:37compliance officer reviewing a
- 22:39color-coded anomaly heat map of insider
- 22:42trading flags, showing visually the
- 22:44temporal relationship between oopsy
- 22:46events and trading activity can identify
- 22:50and escalate a potential violation far
- 22:52more reliably than one reviewing a flat
- 22:55data log. The PCs who builds such a
- 22:58dashboard for a client or who deploys a
- 23:02platform that generates one is providing
- 23:05assurance at a level that the
- 23:07traditional secretarial audit cycle
- 23:09simply cannot match 3.5 client
- 23:12segmentation analytics a practice
- 23:15management tool a less discussed but
- 23:17practically significant application of
- 23:20analytical modeling for the PCs is
- 23:22within practice management itself
- 23:24specifically the use of client
- 23:26segmentation analytics to differentiate
- 23:29advisory offerings and resource
- 23:31allocation across a heterogeneous client
- 23:34portfolio. A typical multiclient PC's
- 23:38practice serves entities that range in
- 23:41their governance complexity and
- 23:43compliance burden from dormant shell
- 23:45companies to listed entities with active
- 23:48SEBI compliance obligations.
- 23:51startup founders preparing for series A
- 23:54governance audits and unlisted public
- 23:57companies navigating the recently
- 23:59expanded demand compliance requirements.
- 24:02Treating all of these clients with the
- 24:04same advisory model, periodic visits,
- 24:07standard checklists, reactive responses
- 24:10is an inefficient deployment of
- 24:12professional capacity and more
- 24:15importantly a disservice to clients
- 24:17whose actual governance needs are poorly
- 24:20understood. K means clustering and
- 24:22related segmentation models applied to a
- 24:25firm's client portfolio data company
- 24:28type listing status annual turnover
- 24:31compliance history sector specific
- 24:33regulatory exposure can generate
- 24:36meaningful client clusters that allow
- 24:39the PCs to differentiate service
- 24:41intensity
- 24:43anticipate regulatory transitions before
- 24:46they become crisis and present
- 24:48datadriven recommendations on
- 24:50governance. investments that clients in
- 24:52each segment should be making. This is
- 24:56not an exotic academic exercise. It is
- 24:59the application of standard data
- 25:01analysis to the practical challenge of
- 25:03running an intelligent professional
- 25:06services firm. Four case studies
- 25:09governance failures as professional
- 25:11benchmarks. No discussion of emerging
- 25:14tools in PC's practice would be
- 25:16professionally responsible without an
- 25:18examination of what happens when
- 25:21governance architecture digital or
- 25:24otherwise fails. The Indian corporate
- 25:28and startup landscape has provided
- 25:30instructive if painful case studies in
- 25:33recent years. the absence of governance
- 25:36structures capable of using information
- 25:39any information to hold executive
- 25:42decisionmaking to account. In several of
- 25:45these cases, board minutes reflected a
- 25:48sanitized narrative that board limited
- 25:50relationship to the actual substance of
- 25:53board deliberations.
- 25:55Audit committee compositions met the
- 25:57letter of independence requirements
- 25:59while failing their spirit. Related
- 26:02party transactions were disclosed
- 26:04selectively and the individuals
- 26:07responsible for governance certification
- 26:09were either complicit or inadequately
- 26:12equipped to identify what they were
- 26:14certifying.
- 26:16The lesson for the PCs is double-edged
- 26:20can prevent the category of failures
- 26:22caused by process breakdown, missed
- 26:25deadlines, incomplete disclosures,
- 26:27administrative oversightes.
- 26:30It cannot prevent the category of
- 26:32failures caused by deliberate
- 26:34circumvention or captured governance.
- 26:37What it can do, however, is make
- 26:40deliberate circumvention harder to
- 26:42sustain. An SDD system that timestamps
- 26:46every oopsy access event creates a
- 26:48forensic record that is extremely
- 26:50difficult to explain away. A compliance
- 26:54dashboard that flags the non-execution
- 26:56of an audit committee meeting before a
- 26:59board decision makes the sequence of
- 27:01governance events visible in a way that
- 27:03a manually maintained calendar does not.
- 27:07A market surveillance anomaly detection
- 27:09model that identifies statistical
- 27:12irregularities in trading patterns
- 27:14provides an early warning capability
- 27:16that changes the conversation from
- 27:18postfacto investigation to preemptive
- 27:21escalation. The PCs's role in this
- 27:24context is unambiguous. Build governance
- 27:27structures early. Ensure independent
- 27:29director appointments carry substance
- 27:32rather than form. And use technology to
- 27:35make the governance record more
- 27:37transparent, more complete and more
- 27:39defensible. Not to make non-compliance
- 27:43easier to camouflage.
- 27:45Five legal and ethical dimensions of
- 27:48technology adoption. 5.1. Statutory
- 27:51duties and the limits of delegation to
- 27:54algorithms. Section 2051
- 27:57of the company's act 2013 imposes a
- 28:01non-deligible duty on the company
- 28:03secretary to report to the board
- 28:05regarding the company's compliance with
- 28:07applicable laws. Section 204 mandates
- 28:11the secretarial audit. Neither provision
- 28:14contemplates an algorithmic co-author.
- 28:17both place the professional
- 28:19responsibility squarely on the
- 28:21individual holding the designation. This
- 28:23has a specific implication for AI
- 28:26generated compliance outputs. They
- 28:28constitute research assistance, not
- 28:31professional conclusions. A genai tool
- 28:34that drafts a preliminary analysis of a
- 28:37SCBI amendment's implications is
- 28:39providing a first document,
- 28:42not a legal opinion. The PCs who
- 28:45presents that output to a client board
- 28:48without independent verification is not
- 28:50merely taking a professional risk. They
- 28:53are potentially misrepresenting the
- 28:55quality of the advice being delivered.
- 28:57Digital records generated by compliance
- 29:00platforms must also be capable of
- 29:02withstanding legal scrutiny. The
- 29:06information technology act and the
- 29:08Indian evidence act as adapted through
- 29:11the Bhartya Sakia Adinium 2023
- 29:14impose specific standards on the
- 29:17admissibility of electronic records. an
- 29:20AI generated compliance report whose
- 29:23algorithmic logic is opaque whose data
- 29:26inputs cannot be traced and whose
- 29:28outputs lack non-repudiable digital
- 29:31authentication may simply not survive
- 29:33regulatory adjudication
- 29:36the concept of explainable AI the
- 29:39ability to articulate in human
- 29:41understandable terms precisely how an
- 29:44algorithm reached a conclusion is not
- 29:46merely a technical aspiration it is a
- 29:49legal Necessity for evidence-grade
- 29:51digital compliance records. 5 point to
- 29:54data privacy and the DPDP obligations of
- 29:57the PC's firm. The DPDP acts 2023. Data
- 30:02fiduciary framework applies to the PC's
- 30:05firm itself, not merely to the companies
- 30:08it advises.
- 30:10When a PC's practice processes personal
- 30:12data of client directors, shareholders
- 30:15or employees,
- 30:17which it does as a matter of routine in
- 30:20maintaining statutory records and
- 30:23preparing compliance filings, the firm
- 30:25is a data fiduciary and bears the
- 30:28associated obligations. This has an
- 30:30immediate practical implication for the
- 30:33use of cloud-based compliance platforms
- 30:35and AI tools. Uploading unredacted board
- 30:39minutes, KMP personal details or pan
- 30:42data to a public AI model constitutes a
- 30:45data privacy breach under the DPDP
- 30:48framework. The PCs must establish clear
- 30:51internal policies. AI tools used for
- 30:54drafting and analysis should receive
- 30:57anonymized or hypothetical data, never
- 31:00clientspecific personal information.
- 31:03Cloud platforms processing client data
- 31:06must be vetted for data residency,
- 31:08access control and breach notification
- 31:12protocols and this vetting must be
- 31:15contractually embedded not merely
- 31:17assumed. 5.3 professional disclosure and
- 31:21the ethics of AI assisted practice. A
- 31:23question the profession has only begun
- 31:26to engage with is whether a PCs should
- 31:28disclose to clients that AI tools were
- 31:31used in preparing compliance filings or
- 31:34governance reports. There is currently
- 31:37no statutory requirement for such
- 31:40disclosure under Indian law. However,
- 31:43the ICSI's code of professional conducts
- 31:46principles of transparency and
- 31:48professional integrity would support a
- 31:50disclosure framework, particularly where
- 31:53AI tools have processed the client's
- 31:55confidential information. The profession
- 31:58would benefit from proactive engagement
- 32:00with the ICSI on developing explicit
- 32:03guidelines for AI tool usage, disclosure
- 32:07standards, and vendor due diligence
- 32:09protocols.
- 32:11Waiting for a governance incident to
- 32:13precipitate reactive regulation is not a
- 32:16strategy the profession can afford given
- 32:18the speed at which AI capabilities are
- 32:21advancing. Six, the future from
- 32:25compliance calendar to realtime
- 32:26governance architecture. 6.1 the
- 32:29dashboard as a governance instrument.
- 32:32The compliance dashboard of the near
- 32:34future will not merely track filing
- 32:36deadlines.
- 32:38It will integrate live data from the
- 32:40MCA21 portal, SCBI scores to point.0
- 32:44zero platform internal document
- 32:47management systems and market
- 32:49surveillance feeds to present a
- 32:50comprehensive real-time picture of a
- 32:53company's governance health on a single
- 32:55interface board composition against
- 32:58company's act and loader requirements
- 33:01pending investor grievances on scores
- 33:04overdue committee recommendations BRS
- 33:07performance metrics against disclosed
- 33:09targets and DPD compliance status all
- 33:13visible simultaneously ly updated
- 33:15continuously for the PCs providing
- 33:18governance advisory services. The
- 33:20ability to offer a client this kind of
- 33:23real-time governance dashboard not as a
- 33:26periodic deliverable but as a live
- 33:28instrument changes the nature of the
- 33:30advisory relationship.
- 33:34The PCs becomes a governance monitor
- 33:36rather than a periodic report preparer.
- 33:40This is not a dimmonition of the
- 33:42professional role. It is its elevation.
- 33:45The professional judgment required to
- 33:47design such a system, calibrate its
- 33:50thresholds and interpret its outputs for
- 33:53a board is considerably more
- 33:55sophisticated than the judgment required
- 33:57to compile a quarterly compliance
- 33:59checklist. Six point to predictive
- 34:01analytics and forward-looking risk
- 34:03management. The next evolution of legal
- 34:06technology for PC's practice will move
- 34:09beyond historical tracking into
- 34:11predictive risk assessment. For the PCs
- 34:14conducting a secretarial audit, an AI
- 34:18assisted audit tool trained on the
- 34:20parameters of form MR3 and ICSI's
- 34:23guidance notes can flag variances
- 34:25between disclosed information and
- 34:28regulatory requirements systematically.
- 34:31covering a larger sample with greater
- 34:34consistency than a manual review
- 34:36permits. The professional's contribution
- 34:39then shifts from data collection, which
- 34:42is where most audit time currently goes
- 34:44to the analytical interpretation of
- 34:46flagged findings and the professional
- 34:49judgment required to reach a defensible
- 34:51conclusion. 6.3 visual governance
- 34:54communication as a core PC's competency.
- 34:57There is one underappreciated competency
- 35:00that will differentiate
- 35:02the effective PCs of the next decade.
- 35:05The ability to translate regulatory
- 35:08complexity into visual clarity for
- 35:10non-speist audiences.
- 35:13Boards are composed of professionals
- 35:15from diverse backgrounds. A newly
- 35:18appointed independent director from an
- 35:21engineering or medical background may
- 35:23have excellent judgment on operational
- 35:25matters and genuine commitment to
- 35:28governance responsibilities
- 35:30while finding the procedural
- 35:31architecture of the SCBI loader its
- 35:34committee structures disclosure
- 35:36timelines and approval sequences
- 35:39genuinely bewildering in written form. A
- 35:42PCs who responds to this challenge with
- 35:44a dense legal memorandum is delivering
- 35:47technically accurate information in a
- 35:50format that may not produce
- 35:53understanding.
- 35:54one who uses an interactive process flow
- 35:57showing visually the RPT approval
- 36:00workflow from audit committee
- 36:02pre-clarance through board approval to
- 36:04shareholder resolution color-coded by
- 36:07regulatory source and annotated with
- 36:10specific threshold values is delivering
- 36:12regulatory compliance in a form that a
- 36:15board member can internalize and act on.
- 36:19Similarly, ISCBI market surveillance
- 36:21anomaly heat map, a DPDP compliance
- 36:24status wheel or an ESG metric tracker
- 36:27linked to the company's BRSR
- 36:29commitments. These are not merely
- 36:32aesthetic choices. They are
- 36:34communication tools that determine
- 36:36whether governance information produces
- 36:39governance action. Seven conclusion. The
- 36:42transformation underway in PC's practice
- 36:45is not a gradual upgrade of familiar
- 36:48tools. It is a structural shift in what
- 36:51it means to practice company
- 36:53secretarship competently in India's
- 36:55current regulatory environment. The
- 36:58convergence of AI powered compliance
- 37:01tools, real-time digital regulatory
- 37:03infrastructure, data privacy obligations
- 37:06and ESG assurance requirements has
- 37:09created a professional landscape where
- 37:11the PCs with only traditional skills is
- 37:14operating at a material disadvantage.
- 37:16And yet the tools for all their genuine
- 37:19power do not diminish the importance of
- 37:22professional judgment. They raise its
- 37:24stakes.
- 37:26An AI that drafts a board resolution
- 37:29faster than any human can still produce
- 37:32a legally defective document if the
- 37:34professional who directed it did not
- 37:36understand the statutory requirements.
- 37:39A compliance dashboard that tracks 300
- 37:42regulatory obligations in real time is
- 37:45worthless if the PCs cannot interpret a
- 37:48red flag and advise a board on its
- 37:50implications.
- 37:52A market surveillance anomaly model that
- 37:55identifies a suspicious trading pattern
- 37:57cannot escalate that finding to the
- 38:00right person without a professional who
- 38:02understands both what the model is
- 38:04detecting and what the regulatory
- 38:06consequences of that detection are. The
- 38:09PCs of this generation has an
- 38:11opportunity that no previous generation
- 38:14of the profession has had to move from
- 38:16the compliance engine room of Indian
- 38:19corporate governance to its bridge. The
- 38:22tools exist. The regulatory environment
- 38:25demands their deployment. The question
- 38:28is whether the profession will engage
- 38:31with that opportunity deliberately with
- 38:34intellectual seriousness and
- 38:35professional rigor or whether it will
- 38:38arrive at digital practice by default
- 38:40reactive inadequately trained and
- 38:43playing permanent catchup with a
- 38:45regulatory architecture that does not
- 38:47wait the seven decades of professional
- 38:49tradition that ICSI has built argue for
- 38:52the former. This moment deserves no less
- 38:56references. Brief sources. One BRS core
- 39:00assurance readiness guide for Indian
- 39:02companies. Glossert International 20126.
- 39:06Two Companies Act 2013 sections 2 24 118
- 39:14129
- 39:16149
- 39:18177
- 39:20184
- 39:22185
- 39:24188 204 205
- 39:28454 and rules there. Ministry of
- 39:33Corporate Affairs, Government of India
- 39:353, Digital Personal Data Protection Act
- 39:392023 and DPDP Rules 2025
- 39:44notified November 13th to 14th, 2025.
- 39:49Ministry of Electronics and Information
- 39:52Technology, Government of India 4, GRI
- 39:56Standards 2021
- 39:59Global Reporting Initiative
- 40:02Sus Standards Sustainability Accounting
- 40:05Standards Board 5 KPMG India Emerging
- 40:09Trends in BRSR Reporting by listed
- 40:12companies accounting and auditing update
- 40:15issue 115 to 0 to6
- 40:18available at assets.kpmg.com kpmg.com
- 40:22six prompting for productivity a guide
- 40:24for company secretaries chartered
- 40:27secretary journal October 20125
- 40:31institute of company secretaries of
- 40:33India 7BI
- 40:36listing obligations and disclosure
- 40:38requirements regulations 2015 as amended
- 40:43up to 2024
- 40:46securities and exchange board of India
- 40:49Eight. SCBI prohibition of insider
- 40:52trading regulations 2015 as amended.
- 40:57Regulations 3 5 and 3 six on structured
- 41:02digital database 9. SEBI circular on
- 41:06annual secretarial compliance report
- 41:09SEBI host CFD CMDCP
- 41:122019/47
- 41:14dated 29th March 201910
- 41:19SEBI circular on business responsibility
- 41:22and sustainability report BRS SCBI host
- 41:26CFD CMD to PCIR 2021/562
- 41:31dated 10th May 2021 111.
- 41:35The algorithmic witness, company
- 41:37secretary as architect of AI governance,
- 41:41chartered secretary journal, July 2025.
- 41:45Institute of company secretaries of
- 41:48India 12. Udot committee report on
- 41:51corporate governance, securities and
- 41:54exchange board of India October 2017.
About this transcript
This page contains the full transcript of CSJ June 2026 Article by The Institute of Company Secretaries of India, generated from the public captions YouTube serves with the video. The transcript has 4,662 words across 907 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.