By the end of this chapter you'll be able to…

  • 1Apply Section 204's four secretarial-audit applicability categories to a company's specific profile
  • 2State the form and disclosure location of the secretarial auditor's report
  • 3Distinguish the Annual Secretarial Compliance Report from Section 204's secretarial audit in scope and applicable population
  • 4State the 2025 signing-requirement tightening for the Annual Secretarial Compliance Report
  • 5Name the four ICSI Auditing Standards and their current mandatory status
💡
Why this chapter matters in CS Professional
Secretarial audit's private-company borrowing threshold (Rs. 100 crore) is the single most commonly forgotten applicability category, and the 2025 signing-requirement tightening on the Annual Secretarial Compliance Report is genuinely current content.

Before you start — revise these

🔗
Secretarial Standards, the Company Secretary's Role, Inspection and Investigation (CS Executive, earlier in this hub)
This chapter extends Executive-level secretarial-standards knowledge into Professional-level audit and compliance certification.

Compliance Management and Secretarial Audit

Part A of Paper 3 is this hub's most distinctly Company-Secretary-exclusive statutory function — secretarial audit is a certification only a Company Secretary in practice can give, and the compliance-management framework around it is where a Professional-level Company Secretary spends much of their actual practice. Getting the applicability thresholds and the current procedural requirements precisely right matters more here than almost anywhere else on this syllabus, since this content maps directly onto real professional certification work.

1. Compliance management framework

A well-run compliance function is risk-based rather than a flat, undifferentiated checklist — it identifies which regulatory obligations carry the highest consequence of failure (listing obligations, tax filings, labour-law compliance, sector-specific licensing) and allocates monitoring effort accordingly, rather than treating every compliance item as equally urgent.

A Company Secretary in an in-house compliance role typically maintains a compliance calendar, tracks filing deadlines across every applicable statute, and escalates emerging risks to the Board or Audit Committee before they crystallise into an actual violation.

2. Secretarial Audit under Section 204

Section 204 of the Companies Act, read with Rule 9 of the Companies (Appointment and Remuneration of Managerial Personnel) Rules, 2014, makes secretarial audit mandatory for a defined population of companies — and the exact list is worth learning precisely, since it is wider than many candidates initially assume.

CategoryThreshold
Every listed companyNo size threshold — mandatory regardless of scale (including a listed private company that has listed only debt securities)
Every public companyPaid-up share capital of ₹50 crore or more
Every public companyTurnover of ₹250 crore or more
Every company (including private)Outstanding loans or borrowings from banks or public financial institutions of ₹100 crore or more

The last row is the one candidates most frequently overlook: secretarial audit extends even to a private company, purely on the basis of its bank/PFI borrowing crossing ₹100 crore, regardless of whether that company is listed or meets any of the other size thresholds. All these thresholds are assessed as on the last date of the latest audited financial statements.

The secretarial auditor's report is prepared in Form MR-3, and is annexed to the company's Board's Report — making it a document that reaches shareholders and the wider public alongside the company's annual financial disclosures, not a purely internal compliance record.

3. Annual Secretarial Compliance Report (LODR Regulation 24A)

A separate, broader requirement applies specifically to listed entities: the Annual Secretarial Compliance Report under LODR Regulation 24A, covering compliance specifically with SEBI's own regulations and circulars, distinct in scope from Section 204's secretarial audit, which covers compliance with all applicable laws generally.

Because this requirement is tied to listing status rather than Section 204's size/borrowing thresholds, it reaches every listed entity — a wider population than the secretarial-audit-mandatory group, since a small listed company below Section 204's public-company thresholds could still be swept in purely by virtue of being listed.

The report must be filed with the stock exchanges in XBRL format within 60 days of the financial year's end. A recent, precisely dateable tightening: with effect from 1 April 2025, this report must be signed only by the Secretarial Auditor or by a Peer Reviewed Company Secretary — a specific professional-qualification restriction worth stating exactly, since it is a genuinely recent change from the previously broader signing eligibility.

4. ICSI Auditing Standards

ICSI has issued a defined set of Auditing Standards governing how secretarial audit (and other CS-conducted audits) must actually be performed, and knowing their names and scope precisely is directly examinable.

StandardScope
CSAS-1Audit Engagement — the terms and acceptance of an audit assignment
CSAS-2Audit Process and Documentation
CSAS-3Forming of Opinion
CSAS-4Secretarial Audit specifically

These standards became effective on 1 July 2019 on a recommendatory basis, and were made mandatory for all audit engagements conducted under any statute with effect from 1 April 2021 — a two-stage rollout (recommendatory, then mandatory) worth stating precisely if a question asks about their current binding status.

Worked Examples

Example 1. A private company (not listed) has a paid-up share capital of ₹30 crore, a turnover of ₹150 crore, and outstanding borrowings from a public financial institution of ₹120 crore. Is this company required to undergo a secretarial audit under Section 204?

Yes — even though it is private and falls below both the ₹50 crore paid-up-capital and ₹250 crore turnover thresholds that apply to public companies, its ₹120 crore borrowing from a public financial institution exceeds the ₹100 crore threshold that independently extends secretarial audit to any company, including a private one.

Example 2. A small listed company has a paid-up share capital of only ₹10 crore and a turnover of ₹80 crore — both well below the public-company size thresholds. Is it required to undergo secretarial audit?

Yes — every listed company is required to undergo secretarial audit under Section 204 regardless of size; the ₹50 crore and ₹250 crore thresholds apply only to public companies that are not listed.

Example 3. In which form is the secretarial auditor's report prepared, and where is it disclosed?

Form MR-3, annexed to the company's Board's Report — making it publicly disclosed alongside the company's annual report, not merely retained internally.

Example 4. A listed company's Annual Secretarial Compliance Report for the financial year is signed by an in-house Company Secretary who is neither the company's Secretarial Auditor nor a Peer Reviewed Company Secretary. Does this comply with the current requirement?

No — with effect from 1 April 2025, the Annual Secretarial Compliance Report must be signed only by the Secretarial Auditor or by a Peer Reviewed Company Secretary; an in-house Company Secretary who does not hold either of these specific qualifications does not satisfy the current signing requirement.

Example 5. By when must a listed entity file its Annual Secretarial Compliance Report after its financial year ends, and in what format?

Within 60 days of the financial year's end, filed in XBRL format with the stock exchanges.

Example 6. A Company Secretary is drafting the terms of engagement for a new secretarial audit assignment. Which ICSI Auditing Standard specifically governs this stage of the audit?

CSAS-1 (Audit Engagement).

Example 7. Explain the two-stage timeline by which the ICSI Auditing Standards became mandatory, and what a candidate should state if asked about their current binding status.

The Auditing Standards became effective on a recommendatory basis from 1 July 2019, and were made mandatory for all audit engagements conducted under any statute with effect from 1 April 2021. A candidate asked about their current binding status should state that they are currently mandatory (since 1 April 2021), not merely recommendatory, while being able to cite the earlier 2019 date as the standards' original, softer starting point if the question specifically asks about their history.

Summary

Section 204's secretarial audit applies to every listed company regardless of size, every public company crossing ₹50 crore paid-up capital or ₹250 crore turnover, and — the most commonly overlooked category — any company (including private) with bank/PFI borrowings of ₹100 crore or more, with the resulting report prepared in Form MR-3 and annexed to the Board's Report.

The Annual Secretarial Compliance Report under LODR Regulation 24A is a separate, listing-status-triggered requirement (broader in population than Section 204's audit-mandatory group) covering SEBI-specific compliance, filed in XBRL within 60 days of financial-year-end, and — since 1 April 2025 — signable only by the Secretarial Auditor or a Peer Reviewed Company Secretary.

ICSI's four Auditing Standards (CSAS-1 through CSAS-4, covering engagement, process/documentation, opinion-forming and secretarial audit specifically) moved from recommendatory (2019) to mandatory (2021) status, and now govern how every CS-conducted audit engagement under any statute must be performed.

Key formulas & results

Everything to memorise for the exam hall, in one card. Screenshot this for revision.

Section 204 applicability
Any ONE condition triggers mandatory secretarial audit.
ASCR filing
Signable only by the Secretarial Auditor or a Peer Reviewed CS, effective 1 April 2025.
⚠️

Traps CS Professional sets — and how to dodge them

These are the exact option-traps and misreads that cost marks under negative marking.

WATCH OUT
Forgetting that a private company can be swept into secretarial audit purely by its borrowing level
Always check the Rs. 100 crore bank/PFI borrowing threshold independently — it applies to any company, including private companies with no other qualifying characteristic.
Why it happens: This is explicitly the most commonly overlooked of Section 204's four applicability categories.
WATCH OUT
Treating the Annual Secretarial Compliance Report as identical in scope to Section 204's secretarial audit
State that the ASCR covers SEBI-specific regulatory compliance for all listed entities, while Section 204's audit covers all applicable laws generally for a size/borrowing-defined population.
Why it happens: The two are easily conflated since both involve a Company Secretary's certification, but they differ in both scope and the population they apply to.
WATCH OUT
Stating the ICSI Auditing Standards as merely recommendatory
State that they became mandatory for all audit engagements under any statute with effect from 1 April 2021, having only started as recommendatory from 1 July 2019.
Why it happens: A candidate citing only the 2019 recommendatory starting point without the 2021 mandatory date understates their current binding force.

Exam-pattern practice

PYQ-style questions with full solutions. Work through them as a readiness check — mark yourself honestly and get your gap report at the end.

Readiness check

Are you exam-ready for Compliance Management and Secretarial Audit?

8 problems from this chapter. Try each one, reveal the worked solution, mark yourself honestly — get your gap report at the end.

8 questions~6 min worth ~100 marks in CS Professional exams

5-minute revision

The whole chapter, distilled. Read this the night before the exam.

  • Section 204 applies to: every listed company (any size); public company, paid-up capital >= Rs. 50cr; public company, turnover >= Rs. 250cr; ANY company (incl. private), PFI/bank borrowings >= Rs. 100cr.
  • Thresholds assessed as on the last date of the latest audited financial statements.
  • Secretarial auditor's report: Form MR-3, annexed to the Board's Report.
  • ASCR (LODR Reg 24A): applies to ALL listed entities (broader population than Section 204); covers SEBI-specific compliance, distinct from Section 204's all-laws scope.
  • ASCR filing: XBRL format, within 60 days of FY-end; signable ONLY by Secretarial Auditor or Peer Reviewed CS, effective 1 April 2025.
  • ICSI Auditing Standards: CSAS-1 (Engagement), CSAS-2 (Process/Documentation), CSAS-3 (Opinion), CSAS-4 (Secretarial Audit); recommendatory from 1 July 2019, MANDATORY from 1 April 2021.

CS Professional question blueprint

How this topic is asked, tier by tier — so you can prep to the pattern.

Typical weightage: Contributes to CS Professional Paper 3 (100 marks, Part A of Section B)

Question styleMarks eachTypical countWhat it tests
Secretarial audit0conceptualApplying Section 204's four applicability categories to a company profile
ASCR0conceptualDistinguishing ASCR from Section 204 audit and applying the 2025 signing rule
ICSI standards0conceptualNaming the four CSAS standards and their current mandatory status
Prep strategy
  • First pass: memorise Section 204's four applicability categories as a fixed checklist, with the private-company borrowing threshold specifically flagged as easy to forget.
  • Second pass: build a side-by-side comparison of Section 204 secretarial audit vs the ASCR (scope, population, filing format, signing eligibility).
  • Third pass: revise the ICSI Auditing Standards' names and their 2019-to-2021 recommendatory-to-mandatory timeline.

Exam-hall strategy

Battle-tested tips from mentors and toppers for this topic under the sectional clock.

  1. For secretarial-audit applicability questions, always check all four categories independently rather than stopping after the first one that seems relevant — a company can qualify through the borrowing threshold alone even if it fails every other test.
  2. Always state Form MR-3 by name when discussing the secretarial auditor's report, since naming the specific form is a directly credited fact.
  3. For ASCR questions, always distinguish it explicitly from Section 204 audit (scope: SEBI-specific vs all-laws; population: all listed vs size/borrowing-defined) rather than treating the two as interchangeable.
  4. For questions about the ICSI Auditing Standards' current status, always state the 2021 mandatory date, not just the 2019 recommendatory starting point.

Beyond the exam

Where this skill shows up in the job you're competing for — and in life.

Secretarial audit engagement and certification

Correctly determining whether a client company falls within Section 204's mandatory population — especially the easily-missed borrowing-threshold category — is the literal first step of a real secretarial audit engagement.

Listed-entity annual compliance certification

Preparing and correctly signing the Annual Secretarial Compliance Report within its 60-day, XBRL-format deadline is a recurring, high-stakes annual compliance task for a Company Secretary serving a listed entity.

Where else this topic is tested

Prepare once, score in every exam that asks it.

CS ExecutiveModerate — Company Law and Practice's inspection/investigation/compounding content forms the compliance-and-enforcement backdrop this chapter's audit function operates within

Questions aspirants ask

Pulled from the Q&A community and mentor sessions.

Yes, in both directions — a large unlisted public company crossing the size thresholds is subject to Section 204 audit but not the ASCR (which requires listing); a small listed company below the size thresholds is subject to both, since listing alone triggers Section 204 for listed companies and the ASCR for all listed entities.

Yes — peer review is a distinct quality-assurance credential/process a practising professional undergoes, and it is now specifically named as one of the two categories permitted to sign the ASCR, alongside the company's own Secretarial Auditor.

CSAS-4 is specific to secretarial audit, but CSAS-1 through CSAS-3 are framed more generally to govern audit engagement, process/documentation and opinion-forming for CS-conducted audits under any statute, not exclusively Section 204 secretarial audit.
Header Logo