Small businesses in India are used to operating with lean teams and limited HR bandwidth. Compliance has always been part of the picture, but for most SMEs, it’s been a game of prioritising what’s most likely to be checked. The Four Labour Codes changed that calculation significantly, and in 2026, with State-level implementation moving forward, the conversation about PoSH compliance is no longer one that smaller employers can defer.
This isn’t just about new rules on paper. The Labour Codes reorganise how employment obligations interact with each other, and for SMEs in particular, they create a new compliance environment where PoSH obligations sit alongside wage, social security, and occupational safety requirements under a more unified regulatory framework. Understanding what that means in practice what’s changed, what hasn’t, and what the actual exposure looks like is what this piece covers.
PoSH compliance for SMEs isn’t a scaled-down version of what large corporations do. It carries the same legal obligations, the same penalty exposure, and increasingly, the same scrutiny. The only thing smaller businesses often have less of is the internal capacity to manage it without outside support.
What the Four Labour Codes Actually Are
Before getting into the PoSH specifics, it helps to understand what the Four Labour Codes actually consolidate. India’s labour law landscape previously comprised over 40 central laws. The Four Labour Codes — on Wages, Industrial Relations, Social Security, and Occupational Safety, Health and Working Conditions rolled most of these into a single restructured framework:
- Code on Wages — minimum wages, payment timelines, bonus provisions
- Industrial Relations Code — trade unions, standing orders, dispute resolution
- Social Security Code — PF, ESI, gratuity, maternity benefits
- OSH Code — working conditions, contract labour, workplace safety
PoSH, as a standalone legislation, sits outside the Four Codes. The Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013 has not been merged into any of them. But what the Codes do is expand the definition of “worker” and “workplace” in ways that directly affect how SMEs need to think about their PoSH obligations, particularly around who is covered, which premises count as workplaces, and which employees trigger the IC constitution requirement.
How the Labour Codes Expand PoSH Coverage for SMEs
This is the part most SME owners miss. The Four Labour Codes bring platform workers, gig workers, and home-based workers into the formal definition of “worker” for the purposes of social security and safety obligations. The OSH Code, in particular, broadens the definition of workplace to include any place where work is performed, not just registered office premises.
This matters for PoSH because the Act’s own definition of “workplace” was already wide, it covers offices, factories, hospitals, transport undertakings, and any place visited by an employee in the course of employment. The Codes reinforce and extend that logic. For an SME that employs field sales staff, delivery personnel, or remote workers, the question of whether those workers fall within PoSH coverage is now less ambiguous, not more.
Similarly, the expansion of “worker” definitions under the Social Security Code draws gig and contractual workers closer to the formal employment relationship. An SME using third-party or contract staff as many do for cost reasons cannot automatically assume those workers fall outside the PoSH Act’s scope. Courts and regulators have been consistent in interpreting PoSH coverage expansively, and the Labour Codes reinforce that direction.
The practical implication: if your headcount including contractual, part-time, or gig workers crosses 10, your IC obligation applies. Many SMEs that believed they were below the threshold are now finding, on a more careful count, that they aren’t.
What SMEs Are Actually Required to Do Under PoSH
The core obligations haven’t changed, but they bear restating for businesses that are new to them or have been applying them loosely. Any employer with 10 or more employees is required to:
- Constitute an Internal Committee with a Presiding Officer (a senior woman employee), at least two other members from the workforce, and one external member with legal or NGO background
- Ensure the IC has at least 50% women members
- Conduct regular PoSH training for all employees and specialised sessions for IC members
- Maintain a written PoSH policy communicated to all staff
- Handle complaints within defined timelines, inquiry to be completed within 90 days of receiving a complaint
- File an annual report to the District Officer at the end of each year
For businesses that don’t have a senior woman employee to serve as Presiding Officer, a genuine problem for some very small teams, the law provides no automatic exemption. This is one of the most common gaps in SME compliance, and one where an external IC member can fill the structural gap when the internal team can’t.
Common PoSH Compliance Gaps in Small Businesses
SMEs tend to share a predictable set of compliance gaps. Identifying them is the first step to fixing them.
Policy exists but isn’t communicated. A written PoSH policy filed in an HR folder doesn’t satisfy the law. The policy needs to be accessible on the intranet, in the offer letter package, or displayed at the workplace. This is one of the most common mistakes companies make during PoSH compliance and one of the easiest to fix.
IC is constituted but not functional. Having names on an appointment order isn’t compliance. The IC needs to meet, keep minutes, handle complaints through proper process, and file the annual report. A dormant IC creates documented liability without providing any of the protection a functional one does.
Training has happened once. Many SMEs conduct a single awareness session at setup and consider it done. Regulators and courts treat ongoing PoSH training as part of the employer’s duty of care. A company that can’t show any training in the last two years is in a weak position regardless of intent.
Documentation is absent. Attendance records, IC meeting minutes, complaint logs, inquiry records, these are what auditors and courts actually look at. Without them, the employer has no evidence of compliance even if the right processes were followed in practice.
Annual report is not filed. Many small businesses don’t know this obligation exists. It does, and missing it creates a gap that shows up during due diligence, investor checks, and regulatory inspections.
Penalties That Apply to SMEs — Not Just Large Corporates
A common assumption among small business owners is that enforcement action is reserved for companies with a public profile. That’s not how the PoSH Act works. The penalty provisions under Section 26 apply equally regardless of company size.
A first violation including failure to constitute an IC, failure to act on IC recommendations, or non-compliance with reporting requirements can attract a fine of up to ₹50,000. Repeat violations can lead to double the penalty and, critically, cancellation or non-renewal of business licences and registrations. For an SME, a licence cancellation isn’t a manageable inconvenience, it’s an existential threat. The consequences often reach further than the direct penalty, touching client contracts, banking relationships, and vendor approvals in ways that compound quickly.
What SMEs Should Do Right Now
Given where things stand with Labour Code implementation in 2026, SMEs have a window to get their PoSH house in order before regulatory scrutiny increases. The steps aren’t complicated:
- Recount your workforce including contractual and gig workers to confirm whether you’re above the 10-employee threshold
- Check whether your IC is constituted correctly, functional, and within its 3-year appointment term
- Confirm your PoSH policy is current and accessible to all employees
- Verify that training has been conducted and that attendance records exist
- Check whether last year’s PoSH annual report was filed with the District Officer
- Run through the PoSH compliance checklist as a starting point for a full audit of where you stand
The Four Labour Codes didn’t invent new PoSH obligations for small businesses that have existed since 2013. What they’ve done is close the definitional gaps that allowed some SMEs to argue they weren’t covered. In 2026, that argument is harder to make, and the cost of making it unsuccessfully is one most small businesses can’t afford.
Let Transparian Simplify Your PoSH Compliance
From constituting and training the Internal Committee to preparing audit-ready annual reports and District Officer filings, Transparian provides expert PoSH compliance support for HR teams and business owners. Through hands-on ICC training, policy reviews, and experienced compliance consultants, Transparian helps growing businesses stay audit-ready, penalty-free, and fully aligned with every PoSH requirement.
FAQ’s
Yes. The PoSH Act applies to all workplaces in India, irrespective of their size. Businesses with 10 or more employees must constitute an Internal Committee (IC), while smaller organisations must facilitate access to the Local Committee constituted by the District Officer for complaint redressal.
The Four Labour Codes do not replace the PoSH Act but broaden the understanding of workers and workplaces. SMEs should carefully assess whether contractual, remote, or gig workers may affect their compliance obligations and workforce count under applicable laws.
An Internal Committee is mandatory when an organisation employs 10 or more employees. It must include a Presiding Officer (a senior woman employee), at least two employee members, and one external member familiar with women’s rights or legal matters, with at least 50% women representation.
Failure to comply with PoSH requirements may attract a penalty of up to ₹50,000 for a first violation. Repeat offences can result in higher penalties and may lead to cancellation or non-renewal of business licences or registrations as provided under the Act.
Organisations should maintain their PoSH policy, IC constitution documents, training attendance records, meeting minutes, complaint and inquiry records, annual reports, and all related compliance documentation. Proper record-keeping is essential during audits and due diligence exercises.
An SME should review its employee count, verify the constitution and tenure of its Internal Committee, assess training records, confirm policy communication practices, and ensure annual reporting obligations have been fulfilled. Regular compliance audits help identify and address potential gaps before regulatory reviews.























