Executive Summary
SEBI's accelerating governance reform agenda through 2025–26 has fundamentally raised the compliance bar for India's listed entities, demanding real-time risk oversight, structured board accountability, and demonstrable independence. Boards that treat these mandates as procedural checklists rather than strategic governance imperatives risk regulatory censure, investor confidence erosion, and reputational damage that no quarterly disclosure can repair.
<p><strong>Executive Summary:</strong> India's securities regulator, SEBI, has pursued one of its most consequential governance reform cycles in recent memory across 2025 and into 2026. Amendments to the Listing Obligations and Disclosure Requirements (LODR) Regulations, expanded mandates on Risk Management Committees, tightened related-party transaction (RPT) frameworks, and the integration of AI governance expectations into board oversight have collectively redefined what effective corporate governance looks like for India's listed entities. For C-suite leaders and board members, the question is no longer whether these regulations apply — it is whether their governance architecture is genuinely fit to meet the standard SEBI now expects. This article unpacks the most material regulatory developments, their practical implications, and the actions boards must take before year-end 2026.</p>
<h2>The Regulatory Landscape: SEBI's Governance Reform Trajectory in 2025–26</h2>
<p>SEBI's governance interventions over the past eighteen months reflect a deliberate philosophical shift: from disclosure-centric compliance to outcomes-oriented accountability. The regulator has made clear, through a series of circulars, consultation papers, and enforcement actions, that form without substance will no longer be tolerated. Three structural themes define this reform cycle.</p>
<p><strong>First, board independence has been redefined in practice, not just on paper.</strong> SEBI's amendments to LODR Regulation 16 and 25 have tightened the criteria for determining the independence of directors, with greater scrutiny on familial relationships, cross-directorships, and pecuniary interests that may not be immediately apparent. Listed entities in the top 1,000 by market capitalisation are now subject to enhanced disclosure requirements around the tenure, qualifications, and skills matrix of their independent directors. The regulator has signalled through its enforcement orders that independent directors who fail to exercise genuine independent judgment — particularly in RPT approvals and audit oversight — will be held personally accountable.</p>
<p><strong>Second, Risk Management Committees (RMCs) have been elevated from a compliance formality to a strategic governance organ.</strong> For the top 1,000 listed entities, SEBI had mandated RMC constitution by 2022, but the 2025 amendments have substantially expanded the RMC's mandate. Committees are now expected to oversee cyber risk, third-party and supply chain risk, ESG-related risks, and — critically — risks arising from artificial intelligence adoption across enterprise operations. Quarterly RMC reporting to the board, with defined Key Risk Indicators (KRIs) and escalation thresholds, is now a regulatory expectation rather than a best practice aspiration.</p>
<p><strong>Third, related-party transaction governance has been significantly tightened.</strong> Following high-profile governance failures at several listed groups, SEBI has reinforced the RPT approval framework under Regulation 23, requiring more granular disclosure of the commercial rationale, pricing benchmarks, and independent validation for material RPTs. Audit Committees are expected to review not just individual transactions but patterns of dealing that may indicate tunnelling or preferential treatment of promoter-linked entities.</p>
<h2>AI Governance Arrives at the Boardroom: SEBI's Emerging Expectations</h2>
<p>Perhaps the most consequential — and least operationally prepared-for — development in the 2025–26 governance cycle is SEBI's expectation that boards exercise meaningful oversight over AI-driven systems deployed in business-critical functions. This aligns with a broader regulatory posture visible across Indian financial sector regulators: RBI's guidance on model risk management for AI/ML systems in banking, and SEBI's own use of AI-powered surveillance tools, have created a regulatory environment where the regulator understands AI risk better than many of the boards it oversees.</p>
<p>For listed entities, this translates into several concrete governance obligations. <strong>Risk Management Committees are expected to receive structured reporting on AI systems that influence material business decisions</strong> — including algorithmic trading systems, credit underwriting models, customer-facing automation, and HR decision-support tools. The RMC's oversight role extends to validating that these systems have been subject to bias testing, explainability assessment, and defined human-override protocols.</p>
<p>SEBI's broader expectation, consistent with global frameworks such as the OECD Principles on AI and the EU AI Act's risk-tiering approach, is that boards move from one-time AI approvals to continuous lifecycle-based monitoring. Static annual reviews of AI deployments are insufficient. Boards need live risk dashboards that surface model drift, data quality degradation, and adverse outcome indicators in near-real time. For most Indian listed entities, this requires a fundamental upgrade to the GRC infrastructure that supports board-level risk reporting.</p>
<p>The practical implication is significant: <strong>boards that cannot demonstrate structured AI governance oversight are exposed to regulatory risk under SEBI's evolving framework</strong>, particularly as the regulator's inspection teams increasingly probe the quality of RMC oversight rather than simply verifying the committee's existence.</p>
<h2>LODR Compliance Gaps: Where Listed Entities Are Most Vulnerable</h2>
<p>Based on SEBI's enforcement orders and inspection findings published through mid-2026, several recurring compliance gaps are evident across listed entities of varying sizes and sectors.</p>
<ul> <li><strong>Audit Committee Composition and Quorum:</strong> A significant number of entities continue to struggle with maintaining compliant Audit Committee composition, particularly following independent director resignations. SEBI has been unequivocal that the regulatory clock does not pause during director search processes — entities must have contingency succession plans for key board committees.</li> <li><strong>Related-Party Transaction Disclosure Quality:</strong> While most entities now obtain the requisite Audit Committee and shareholder approvals for material RPTs, the quality of disclosure — particularly the articulation of commercial rationale and pricing methodology — remains inadequate. SEBI's scrutiny of RPT disclosures in annual reports has intensified.</li> <li><strong>Corporate Governance Report Accuracy:</strong> The Corporate Governance Report filed as part of the Annual Report continues to be a source of non-compliances, ranging from incorrect disclosure of director relationships to inaccurate skills matrix representations. SEBI's automated surveillance systems are increasingly capable of cross-referencing disclosures across filings to identify inconsistencies.</li> <li><strong>Risk Management Framework Documentation:</strong> While RMC minutes and quarterly reports are being filed, the underlying risk management frameworks — including risk appetite statements, KRI definitions, and escalation protocols — are often underdeveloped or not genuinely integrated into business decision-making.</li> <li><strong>Whistle-blower Mechanism Effectiveness:</strong> SEBI's Vigil Mechanism requirements under LODR Regulation 22 mandate not just the existence of a whistle-blower policy but its effective operationalisation. Regulators are increasingly examining whether reported concerns are investigated independently and whether reporters receive appropriate protection.</li> </ul>
<p>For boards and compliance officers, these gaps represent not just technical non-compliances but genuine governance vulnerabilities. <strong>SEBI's enforcement posture in 2026 has shifted toward issuing adjudication orders with meaningful financial penalties rather than relying on administrative warnings</strong>, making the cost of non-compliance materially higher than in prior years.</p>
<h2>Integrated GRC: The Infrastructure Imperative for Board-Level Governance</h2>
<p>A structural challenge underlying many of the compliance gaps identified above is the fragmentation of governance, risk, and compliance data across Indian listed entities. Secretarial compliance, internal audit, risk management, legal, and ESG functions frequently operate in silos, producing reports that reach the board in disconnected formats at different points in the year. This architecture is fundamentally incompatible with what SEBI now expects: real-time, integrated risk intelligence that enables boards to exercise genuine, informed oversight.</p>
<p>The global GRC platform market is projected to grow at a 14.2% CAGR through 2029, and Indian enterprises are increasingly recognising that integrated GRC infrastructure is not a technology investment — it is a governance investment. <strong>A unified GRC platform that consolidates risk data from internal audit, compliance monitoring, third-party risk assessments, and regulatory tracking provides boards and their committees with the single source of truth that meaningful oversight requires.</strong></p>
<p>For SEBI-regulated entities specifically, integrated GRC infrastructure enables several critical capabilities: automated LODR compliance calendars with escalation alerts, real-time RPT monitoring against pre-approved thresholds, consolidated KRI dashboards for RMC reporting, and audit trails that demonstrate the quality of board-level risk deliberation to regulatory inspectors. These are not aspirational capabilities — they are the operational foundation of defensible governance in 2026.</p>
<p>The DPDP Act adds a further dimension to this infrastructure imperative. Listed entities that handle personal data — which encompasses virtually every consumer-facing business — must now demonstrate automated breach response and consent management capabilities. The intersection of DPDP compliance, SEBI's cybersecurity framework for listed entities, and CERT-In's incident reporting requirements creates a complex, multi-regulator compliance environment that siloed teams simply cannot navigate effectively.</p>
<h2>Building a Board-Ready Governance Architecture: A Practical Framework</h2>
<p>For boards and senior leadership teams seeking to move from reactive compliance to proactive governance excellence, Praxis Consulting recommends a structured approach anchored in four interconnected pillars.</p>
<p><strong>Pillar 1 — Governance Architecture Assessment:</strong> Begin with a structured gap assessment of the entity's current governance framework against SEBI's LODR requirements, SEBI's circular on Risk Management Committees, and applicable provisions of the Companies Act, 2013. This assessment should evaluate not just formal compliance but the functional effectiveness of board committees — whether Audit Committees genuinely interrogate management representations, whether RMCs receive risk information that is actionable rather than merely voluminous.</p>
<p><strong>Pillar 2 — Board Capability and Composition:</strong> Evaluate the skills matrix of the board against the entity's current and emerging risk profile. In 2026, a board that lacks directors with meaningful expertise in cybersecurity, AI risk, ESG, and financial risk management is structurally under-equipped to exercise the oversight SEBI expects. Where gaps exist, the Nomination and Remuneration Committee should have a structured plan to address them through targeted director recruitment.</p>
<p><strong>Pillar 3 — Risk Intelligence Infrastructure:</strong> Invest in the GRC infrastructure necessary to provide board committees with real-time, integrated risk data. This includes defining KRIs for each material risk category, establishing escalation thresholds, and implementing dashboards that surface emerging risks before they become reportable events. AI governance oversight should be embedded into the RMC's quarterly reporting cycle, with defined metrics for model performance, bias indicators, and human oversight effectiveness.</p>
<p><strong>Pillar 4 — Culture and Accountability:</strong> Governance frameworks are only as effective as the culture in which they operate. Boards should periodically assess whether the entity's governance culture — including the tone set by the promoter group and senior management — genuinely supports independent oversight, transparent escalation, and accountability for risk outcomes. SEBI's enforcement record makes clear that governance failures are rarely purely technical — they almost always reflect cultural and accountability deficits that structural reforms alone cannot address.</p>
<p>As India's capital markets deepen and institutional investor scrutiny intensifies, corporate governance quality is increasingly a determinant of valuation and investor confidence. <strong>The boards that invest in genuine governance excellence today are not merely managing regulatory risk — they are building the institutional credibility that sustained market leadership requires.</strong></p>
<p>At <strong>Praxis Consulting</strong>, our Risk and Governance Advisory practice works with listed entities across sectors to assess governance architecture, strengthen board committee effectiveness, and build the integrated risk infrastructure that SEBI's evolving expectations demand. If your board is navigating the 2025–26 regulatory cycle and seeking an authoritative, independent perspective on your governance readiness, we invite you to connect with our advisory team for a structured governance diagnostic.</p>
Actionable Recommendations
Commission an independent LODR compliance gap assessment benchmarked against SEBI's 2025–26 amendments, with specific focus on RPT disclosure quality, RMC mandate coverage, and Audit Committee functional effectiveness — and present findings directly to the board, not just the compliance function.
Formally integrate AI governance oversight into the Risk Management Committee's quarterly reporting cycle by defining measurable KRIs for each material AI system, including model drift thresholds, bias indicators, and human-override utilisation rates, to meet SEBI's emerging expectations for lifecycle-based AI risk monitoring.
Invest in an integrated GRC platform that consolidates compliance calendars, risk dashboards, RPT monitoring, and third-party risk data into a single board-accessible interface, eliminating the siloed reporting architecture that undermines genuine board-level risk oversight.
Conduct a board skills matrix review through the NRC to identify gaps in cybersecurity, AI risk, ESG, and financial risk expertise, and develop a structured director succession plan that ensures the board's collective capability remains aligned with the entity's evolving risk profile and SEBI's governance expectations.

Founder & Principal Consultant at Praxis Consulting with 30+ years of expertise in GRC, Enterprise Risk Management, and International Management Standards. A published author of Mastering ISO 17025 and School Safety Blueprint, he has trained over 5,000 professionals worldwide.

