Bribery and corruption remain core areas for law enforcement, by both domestic as well as international agencies. White-collar crimes in India encompass a broad spectrum of offences, including forgery, cheating, fraud, misappropriation of assets and money laundering.
The Indian criminal justice and regulatory system is not a paper tiger, but rather an active enforcer. Consistent with a trend that has lasted for more than a decade, white-collar crime enforcement remains aggressive in India. As enforcement is conducted through a plethora of enforcement bodies, each with a different statutory mandate, investigations are becoming more complex, with a significant amount of inter-agency reliance as well as competition.
This enforcement climate has also changed the paradigm of internal investigations, which currently do not have de jure recognition but seemingly de facto and strategic merit. Regulatory bodies, as opposed to enforcement bodies, are both recognising and relying on the results of internal investigations, including an organisation’s commitment to corporate governance in their final judgments. This shift is significant, because where enforcement agencies seek to prosecute, regulators seek to evaluate. Thus, companies are going to continue to remain under considerable pressure to conduct swift internal investigations, probably faster than in any other jurisdiction, to be able to effectively respond to and defend themselves against multi-pronged investigations and proceedings.
The propensity of pretrial arrests continues to remain at an all-time high, with judicial reluctance to grant bail in white-collar crime offences becoming a key bone of contention. There are critical constitutional challenges on the mandates and powers of certain law enforcement bodies that are pending before the courts, which are likely to make headway in the coming months. The sectoral trends of corporate investigations have largely remained constant during the past few years, with a sustained focus on defaulting lenders of large loans who have engaged in fraud or misused funds; bribery of government officials; fraud in all forms, with no materiality threshold; corporate governance lapses; and conduct affecting the securities markets.
The foregoing enforcement landscape admits only one rational corporate response: compliance can no longer be reactive or superficial. Failure to invest in robust governance frameworks is no longer just a risk — it is a liability that will not withstand the scrutiny of this enforcement environment. This is a critical inflection point, and companies that do not move decisively may soon find themselves outpaced, outmatched, and exposed.
White-collar crime in India is not governed by a single codified law but by multiple statutes imposing criminal and civil penalties. A corporate crime matter may therefore attract several enforcement agencies investigating the same facts and pursuing distinct charges, including fraud, corruption, insider trading, manipulation of books and records, and tax evasion, under separate statutes and related regulations. These proceedings may run simultaneously before different courts and tribunals, each conducting separate trials on overlapping facts. Enforcement in India therefore does not operate in silos; it typically unfolds through multiple parallel proceedings rather than a single consolidated action.
The most relevant Indian laws and statutes for business crimes are as follows:
- Bharatiya Nyaya Sanhita, 2023 (BNS). This replaces the Indian Penal Code, 1860 (IPC) as the primary criminal code and codifies substantive offences and penalties, including cheating, criminal breach of trust, forgery, and falsification of accounts (the BNS came into force in July 2024, and will not retrospectively apply, and offences prior to 1 July 2024 will continue to be tried under the IPC; see Question 5, below).
- Companies Act, 2013 (CA 2013). This is the principal corporate governance statute. It broadly defines and penalises corporate fraud, including acts, omissions, concealment, or abuse of position intended to deceive, gain undue advantage, or injure the company. It also penalises falsification of accounts and intentional misreporting in financial statements.
- Prevention of Corruption Act, 1988 (PCA). This focuses on bribery of public servants (i.e. individuals discharging a public duty) and brings within its ambit all actions of public servants who receive bribes and individuals or commercial organisations who give bribes to obtain an undue advantage.
- Prevention of Money Laundering Act 2002 (PMLA). This Act is intended to prevent money laundering and is anchored on the commission of a predicate or “scheduled offence” under section 2(y) and enumerated in the Schedule to the PMLA. Money laundering covers property or assets derived from “proceeds of crime” or used in relation to scheduled offences.
- Income Tax Act, 1961 (Tax Act)/Central Goods & Services Tax Act, 2017 (CGST Act). These regulate/govern tax evasion, misreporting taxable income, wrongfully availing oneself of input tax credit, and tax fraud.
- Securities and Exchange Board of India Act, 1992 (SEBI Act). This Act and its allied regulations govern securities law offences including insider trading, market manipulation, front-running, and fraudulent trading practices.
- Foreign Exchange Management Act 1999 (FEMA). This regulates forex transactions.
- Fugitive Economic Offenders Act, 2018 (FEOA). This Act applies to fugitive economic offenders who have left India to evade prosecution.
- Black Money (Undisclosed Foreign Income and Assets) and Imposition of Tax Act, 2015 (Black Money Act). This addresses undisclosed foreign assets.
- Prohibition of Benami Property Transaction Act 1988/Benami Transactions (Prohibition) Amendment Act, 2016 (Benami Property Act). This targets the holding of assets in fictitious names.
- The Digital Personal Data Protection Act, 2023 (DPDP Act)/Information Technology Act, 2000 (IT Act). These Acts govern cyber offences including unauthorised access, data theft, identity fraud, financial cyber fraud and electronic forgery.
- Negotiable Instruments Act, 1881 (NI Act). This criminalises dishonoured cheques, a prevalent form of commercial fraud.
- Competition Act, 2002 (Competition Act). This addresses cartel behaviour and abuse of dominance.
India has ratified several multilateral conventions and entered into bilateral arrangements that supplement its domestic white-collar crime framework. These treaties establish obligations for criminalisation, international cooperation, mutual legal assistance, asset recovery, and extradition.
India has ratified, is a signatory, or is a member of the following key conventions/bodies:
- United Nations Convention against Corruption (UNCAC).
- United Nations Convention against Transnational Organised Crime (UNTOC).
- Financial Action Task Force (FATF).
- Extradition, Mutual Legal Assistance Treaties (MLATs) and Memorandums of Understanding (MoUs) with relevant countries:
- India’s extradition framework is governed by the Indian Extradition Act, 1962. As of April 2026, India has bilateral extradition treaties with 48 foreign states, including the United States (US), the United Kingdom (UK), Switzerland, Germany, France, United Arab Emirates (UAE), and Australia, and extradition arrangements with 12 additional states (mea.gov.in/leta.htm).
- India has bilateral MLATs with 40 countries (including Russia, the US, France, and the UAE; https://cbi.gov.in/MLATs-list), which facilitate cooperation with other contracting states for prevention, investigation and prosecution of crime. Such requests are typically issued and received through letters rogatory (letters of request).
- India has MoUs with at least four countries to combat instances of corruption, serious fraud and organised crime. The securities regulator in India, the Securities and Exchange Board of India (SEBI), has signed various bilateral MoUs with securities regulators globally, for enhancing regulatory cooperation and exchange of information for enforcement and regulatory purposes (see Question 11, below).
- India has been an INTERPOL member since 1949 and actively leverages Red Notices and other INTERPOL tools to pursue fugitive economic offenders. The INTERPOL (ICPO-INTERPOL) framework and other bilateral and multilateral treaties help reduce barriers to cross-border cooperation.
In August 2025 the Directorate of Enforcement (ED) in India (the law enforcement body responsible for investigating issues of money laundering (see Question 7, below)) issued its first INTERPOL Purple notice on “Trade-Based Money Laundering Modus Operandi” (www.enforcementdirectorate.gov.in/media/press-release-documents/4d84be29-c058-45de-b012-16fd01071fb6_Press%20Release%20-%20Purple%20Notices-29.8.2025.pdf) to raise awareness among its international counterparts of emerging trends in cases involving money laundering.
Additionally, India joined INTERPOL’s Silver Notice pilot in January 2025, which tracks illicit assets derived from crimes such as fraud, corruption, drug trafficking, arms trafficking, and environmental crime across borders (i.e. 51 participating states). This reflects India’s commitment to enhancing international cooperation and reinforces the effectiveness of global asset recovery mechanisms.
White-collar crime laws in India apply to both individuals and corporate entities. The default position under Indian criminal jurisprudence is that individual liability is personal in nature, premised on the direct commission of, or complicity in, the offence in question, and that it does not arise merely by virtue of an individual’s designation or position within a corporate structure.
There is no general rule of vicarious criminal liability for individuals, and directors, officers and key managerial personnel cannot be implicated in a company’s alleged misconduct absent sufficient evidence of their active participation, knowledge, and criminal intent. Distinct from this general principle, however, certain statutes governing business crime expressly provide for the extension of liability to officers and key managerial personnel of a corporate entity, where the commission of an offence by the company has first been established. Under such statutory frameworks, once the threshold is met, for instance, by establishing that the individual was in charge of and responsible for the conduct of the business of the company, or that the contravention occurred with their knowledge, consent, connivance, or neglect, liability may extend to such individuals unless they demonstrate that the offence occurred without their knowledge or despite their exercise of due diligence, where such defences are recognised under the relevant statute. For contraventions that are regulatory or civil in nature, such as those arising under the CA 2013, the Tax Act, the Central Goods and Services Tax Act, 2017 or FEMA, the applicable statutes generally specify who may be held liable. These include the company itself and “officers in default”, as defined under section 2(60) of CA 2013, or equivalent formulations under other applicable laws.
Corporate criminal liability
Corporate criminal liability was given legal status by the Supreme Court of India (in Iridium India Telecom Limited v. Motorola Inc (2011) 1 SCC 74) and Standard Chartered Bank and Ors v. Directorate of Enforcement (2006) 4 SCC 278) on the premise that criminal misconduct by a body corporate would be punished by a fine instead of imprisonment (in the event of a conviction), but all other procedural elements of criminal prosecution for a company would be identical to what is followed in the case of an individual’s prosecution.
Corporate criminal liability in India is also attributable by statute. The statutes most relevant to business crime include the BNS, the CA 2013, the Tax Act, the SEBI Act, the Black Money Act, the NI Act, the Competition Act, and the PCA. Where such liability is statutorily recognised, certain prerequisites must usually be met. For example, under the PCA, a company may be charged for an offence committed by an employee only if it was committed for the company’s benefit. Under statutes such as the Benami Property Act (section 62), the Black Money Act (section 56) and the PMLA (section 70), liability of the company and its key officers arises where key managerial personnel had knowledge of, or connived in, the commission of the offence. Similarly, CA 2013 provides for separate liability of the company and its employees for compliance failures and offences.
Recent legislation has also shifted towards express imposition of individual liability on directors, officers and key managerial personnel who oversee misconduct. A key example is the 2018 amendments to the PCA, which expressly provide that company officers may be held liable where they consented to, or conspired in, the commission of an offence.
Indian courts have consistently held that criminal conduct of a company’s “directing mind” may be imputed to the company itself. Whether the directing mind was acting through the company is a factual question to be determined from the circumstances of each case. The accepted position is that where the person or group controlling the affairs of the company commits an offence with criminal intent, that criminality may also be attributed to the company on the basis that they are its “alter ego” (Sunil Bharti Mittal v. CBI (2015) 4 SCC 609; N Magesh v. State of Tamil Nadu 2019 SCC OnLine Mad 38922).
Companies have also been held indictable for criminal acts or omissions of their directors, authorised agents or servants, whether or not mens rea is involved, provided they acted, or purported to act, under the authority of the corporate body or in pursuance of its aims or objects (State of Maharashtra v. Syndicate Transport Co. (P) Ltd, AIR 1964 Bom 195; Aneeta Hada v. Godfather Travels & Tours (P) Ltd (2012) 5 SCC 661).
Individual liability
Indian jurisprudence has consistently held that there is no vicarious liability for individuals in criminal law unless a statute expressly provides for it. In practice, however, enforcement agencies often proceed against key managerial personnel and directors alongside the company, particularly in economic offences, effectively requiring them, at least at the investigation stage, to show lack of knowledge or due diligence. This approach persists despite courts repeatedly holding that directors may be held liable only for actions they oversee or of which they are aware through board processes. It is a settled principle that a corporate entity’s separate legal personality must be respected (Life Insurance Corporation of India v. Escorts Ltd. & Ors. (1986) 1 SCC 264). A director, chairman or officer cannot be implicated in the company’s alleged offence merely by virtue of office. The general rule is that directors and officers are not automatically vicariously liable for a company’s misconduct unless there is sufficient evidence of their active role, knowledge, and criminal intent in the commission of the offence, or a statute specifically imposes liability. Indian courts have therefore made clear that directors cannot be criminally liable for corporate misconduct without personal participation or a clear statutory mandate.
Territorial scope — domestic and foreign entities
Indian white-collar crime laws apply primarily to offences committed within India, regardless of the accused’s nationality but may extend to foreign entities where there is sufficient nexus or impact on India. The BNS, PMLA, PCA, and CA 2013 apply to acts committed within Indian territory. The BNS also extends to any person, irrespective of location, who commits an offence from outside India targeting a computer resource situated in India.
Foreign companies incorporated outside India may be subject to Indian law if they carry on business in India or the offence has a sufficient nexus to India, such as proceeds being laundered through Indian financial institutions. A foreign entity may also be exposed to Indian jurisdiction through its ownership actions or conduct it mandates or directs. Where a parent company or foreign shareholder exercises control over an Indian subsidiary or associate through board resolutions, shareholder directions, or other governance mechanisms, and that control furthers or results in an offence in India, the foreign entity may be held liable on that basis.
FEMA applies to transactions involving India or Indian residents, regardless of where the foreign entity is incorporated. The SEBI Act may also apply to foreign institutional investors, foreign portfolio investors, and other foreign entities accessing Indian capital markets.
Extraterritorial
The Supreme Court of India laid down in GVK Industries Limited v. The Income Tax Officer (2011) 4 SCC 36 that corporate conduct occurring outside India can be subjected to Indian law if it has a nexus with or effect on India. Tax evasion and money laundering are two domains where extraterritorial reach has been both vigorous and publicised. Importantly, authorities are more likely to prosecute criminal conduct than purely regulatory, civil, or private law conduct. Enforcement of penal provisions against offshore corporate conduct occurs only in exceptional circumstances. While the PCA admits prosecution of offshore entities that bribe Indian public officials abroad, authorities in practice prosecute only cases where at least part of the conduct occurred in India. It is more common for authorities to attach assets of a foreign entity in India, or of an Indian or foreign entity outside India, as post-conviction penal consequences — or pre-emptively, as under the PMLA.
As upheld by the Supreme Court in Vijay Madanlal Choudhary v. Union of India & Other 2022 SC OnLine 929, the appropriate authorities appointed by the government are empowered under section 5 of the PMLA to provisionally attach and confiscate assets of equivalent value in India (or abroad if the assets constituting the proceeds of crime are acquired and held abroad and cannot be forfeited). Critically, the PMLA’s attachment powers are not confined to assets located within Indian territory; i.e. where the assets constituting proceeds of crime are acquired and held abroad and cannot be forfeited domestically and so the ED is empowered to proceed against such foreign-situated assets, making the PMLA one of the Indian statutes which has extraterritorial asset recovery reach.
As part of the merger-control regime, the Competition Commission of India (CCI) routinely examines global assets and turnover of companies. Agreements entered outside India can also be investigated if they have an “appreciable adverse effect on competition” in the Indian market. SEBI is empowered to call for information and proceed against “any person” for fraudulent trading in foreign securities issued by an Indian company but traded outside India. Compliance and disclosure obligations under the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 (LODR) extend to material subsidiaries incorporated outside India, representing another form of extraterritorial jurisdiction exercisable by economic regulators. Tax authorities may assess and review offshore transactions of companies incorporated in or outside India. While the Supreme Court’s ruling in Vodafone International Holdings BV v. Union of India (2012) 1 SCR 573 considerably reduced the scope to subject foreign transactions to direct tax, there is a clear emphasis on bringing offshore entities providing online services within the tax net.
The effective exercise of such extraterritorial jurisdiction continues to depend on cross-border cooperation mechanisms, including mutual legal assistance, extradition arrangements, and regulatory coordination (see Question 2, above).
The principal domestic white-collar crime offences/statutes are enumerated in the response provided to Question 1, above.
- Under the PCA, bribery and corruption of public officials are punishable by up to seven years’ imprisonment and a fine.
- Fraud under CA 2013 includes any act, omission, or concealment committed with intent to deceive or gain undue advantage at the expense of the company, shareholders, creditors, or any other person, regardless of whether actual loss has occurred. It is punishable with a minimum of six months and up to 10 years of imprisonment, and a fine up to three times the amount involved. Where the fraud involves public interest, minimum imprisonment is three years.
- Money laundering under PMLA includes the concept of proceeds of crime under the PMLA and allows for forfeiture of assets following the trial and attachment of the assets (including the freezing of bank accounts) before trial. Maximum imprisonment is seven years (extendable to 10 years in specified cases).
- Key offences under the BNS, such as cheating, are punishable with up to three years’ imprisonment and a fine; up to seven years if cheating involves the delivery of property that causes grievous hurt or damage, and falsification of accounts is punishable with imprisonment for up to seven years, a fine, or both.
- Offences such as insider trading under the SEBI Act and the SEBI (Prohibition of Insider Trading) Regulations 2015, market manipulation and price rigging under SEBI (Prohibition of Fraud and Unfair Trade Practices) Regulations 2003 is punishable with imprisonment of up to 10 years and/or with a fine of up to INR 250 million, or three times the amount of profits made out of insider trading (whichever is greater).
Available defences in white-collar crime cases include the compliance defence under the PCA (for commercial organisations that had adequate procedures to prevent bribery), the compelled bribery defence (for bribe-givers who self-report within seven days), due diligence defences under various statutes for vicarious liability, and the general defences codified in the BNS including acts done in good faith, mistake of fact, and acts done under intoxication (in limited circumstances).
The most significant foreign statute directly affecting Indian companies and individuals is the United States Foreign Corrupt Practices Act, 1977 (FCPA), which prohibits bribery of foreign public officials to obtain or retain business and separately requires accurate books, records, and internal accounting controls. Its reach into India is broad: it applies not only to Indian companies listed in the United States, but also to US companies operating in India through subsidiaries, transactions routed through the US dollar clearing system, and Indian entities acting as agents or intermediaries for US companies. This is particularly significant in India, where businesses frequently deal with state-owned enterprises and government-linked bodies in sectors such as banking, energy, infrastructure, and defence procurement, all of which may create FCPA exposure.
A concomitant legislation to the FCPA, the Foreign Extortion Prevention Act, 2023 (FEPA) also has an extraterritorial jurisdiction and would apply to Indian entities. FEPA directly allows the US government to investigate and prosecute foreign officials (i.e. employees of a foreign government (including department, agency, or instrumentality), and also people acting officially/unofficially on behalf of such government or public international organisations that solicit or accept bribes from US entities or individuals.
The United Kingdom Bribery Act, 2010 (UKBA), also operates on similarly broad terms, capturing any company that does business in the UK, including Indian companies with UK subsidiaries or commercial relationships, and goes further than the FCPA by also prohibiting private-sector bribery with no facilitation payments exception.
Penalties under both regimes are severe: the FCPA carries criminal fines of up to USD 2 million per violation as corporate fine, disgorgement of profits, and up to five years’ imprisonment for individuals (along with fines), while the UKBA imposes unlimited corporate fines and up to 10 years’ imprisonment.
Depending on the nature of the offence, potential perpetrators, and other specific circumstances, white-collar criminal laws in jurisdictions such as the Netherlands, Colombia, and France may also apply extraterritorially to investigations involving white-collar offences.
The key law enforcement authorities in India and their jurisdictions are as follows:
- Bribery and corruption. At a federal level, the Central Bureau of Investigation (CBI), and at state level, the anti-corruption bureaus of the state police investigate matters under the PCA. The Central Vigilance Commission serves as the apex coordination body, but is not an investigating agency per se.
- Fraud. The CBI may be conferred jurisdiction to investigate complex fraud and has been at the forefront of banking fraud investigations. Offences under the CA 2013, including fraud, are investigated by the Serious Fraud Investigation Office (SFIO), while BNS offences are investigated (if not by the CBI) by the state police’s economic offences team or local police station (if the threshold of wrongful loss or wrongful gain is not met).
- Securities law. The SEBI is the principal market regulator and has the power to conduct investigations, inspections, and inquiries.
- Money laundering and exchange control. The ED has a dual mandate to investigate cases of money laundering under the PMLA and violations of Indian foreign exchange control laws, such as the FEMA and the FEOA.
- Tax laws. The Income Tax Department and the Directorate of Revenue Intelligence enforce matters pertaining to taxes (direct and indirect) as well as cases of commercial fraud relating to evasion of customs duties and import or export controls.
- Antitrust laws. All antitrust violations are governed by the Competition Act and the CCI carries out inquiries, investigations and prosecution of antitrust violations.
Additionally, sector-specific regulators prescribe regulatory standards, the breach of which may result in fines and penalties. These include the Reserve Bank of India (RBI) for banking, branch, or project offices of foreign companies in India as well as the Insurance Regulatory and Development Authority for insurance companies.
Seeking leniency or plea bargaining
In India, the criminal justice system does not recognise cooperation agreements equivalent to US-style deferred prosecution agreements or non-prosecution agreements. An accused person may, however, be made an “approver” or state witness after arraignment, depending on the extent of cooperation. This is a matter for the court, not law enforcement. On the regulatory side, cooperation carries clearer advantages. Under the SEBI (Settlement Proceedings) Regulations, 2018, breaches of securities law that do not involve market-wide impact or fraud may be settled, with cooperation given specific weight. Likewise, the Competition Act and the Competition Commission of India (Lesser Penalty) Regulations, 2024 provide leniency to cartel participants who cooperate. Cooperation is also important in proving corporate intent and may assist both during trial and, if there is a conviction, at sentencing.
Self-reporting
There is no affirmative legal obligation on non-publicly traded companies to disclose misconduct involving typical white-collar offences. There is a duty to promptly report certain classes of offences under the BNS; these are specified in section 33 of the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS) (applicable to offences committed after 1 July 2024) (and section 39 of the Code of Criminal Procedure, 1973). However, the white-collar criminal offences which are most commonly brought do not fall within the purview of section 33. Therefore, public disclosure and engagement with law enforcement authorities are strategic decisions based on the facts of the case.
A company’s statutory auditor must report fraud to the government under the Companies Act, 2013 where the amount exceeds INR 10 million, and must make disclosures on fraud under the Companies (Auditor’s Report) Order, 2020. A 2023 circular issued by the National Financial Reporting Authority (NFRA) (an independent authority overseeing accounting standards) has also heightened scrutiny of fraud-reporting duties for auditors of companies under its jurisdiction. Listed companies must disclose the initiation of a forensic audit, the identity of the auditor and the reasons for the audit to stock exchanges under the LODR. Public procurement contracts often include integrity pacts requiring parties to avoid bribery and to disclose specified prior transgressions globally.
Self-reporting in India must therefore be carefully calibrated, given the absence of formal cooperation credit and the possibility of prolonged enforcement action. It may be considered where the company appears to be the victim of a rogue employee’s fraud; where media or social media exposure is likely; where the auditor may report first; where a foreign regulator may announce an investigation, settlement or charges; where litigation by employees or third parties may make misconduct public; where statutory exceptions apply, such as coerced bribery reported within seven days under section 8 of the PCA; or where engagement with one regulator, such as SEBI, RBI or the Income Tax Department, may make parallel engagement with others advisable.
Self-reporting outside India also requires careful assessment. Companies must weigh any cooperation credit available abroad against the consequences of disclosure in India, since reporting in one jurisdiction will often trigger reporting in another. Consistency in dealings with regulators is critical because Indian authorities frequently coordinate with foreign counterparts.
Judicial response to cooperation
While courts do not formally recognise cooperation as a ground for reduced punishment in criminal proceedings, cooperation with enforcement agencies can, in practice, influence bail decisions, the framing of charges, and sentencing considerations. Courts have demonstrated a degree of accommodation in cases where accused persons have made restitution or engaged constructively with the investigative process, though no formal sentencing discount regime exists for white-collar offenders.
Internal investigations in India
Internal investigations in India are commonly triggered by whistleblower complaints, audit findings, regulatory inquiries, adverse media reports, internal compliance reviews, or management’s own detection of potential misconduct. As in other common law jurisdictions, companies use internal investigations to assess the nature and extent of potential misconduct, identify legal and regulatory exposure, preserve evidence, manage governance risks, and determine remediation. Indian law generally does not require disclosure of the existence or outcome of such investigations unless a specific statute so provides. The approach is fact-specific and depends on the seriousness of the allegations, the management level involved, the nature of potential legal exposure, and possible accounting, disclosure, or reputational consequences. Although Indian law does not prescribe a uniform framework, certain practical and strategic considerations commonly apply.
Preliminary assessment and investigation mandate
Investigations typically begin with a preliminary assessment of the credibility and materiality of allegations and their likely legal or commercial impact. This may involve reviewing documents and electronic records, engaging with the whistleblower where appropriate, limited fact-finding, and assessing financial, compliance, and governance implications. Companies then define the investigation’s scope, objectives, timeline, relevant functions and custodians, and reporting structure.
A key early decision is determining who will supervise the process, especially where allegations involve senior management, financial irregularities, related-party issues, or regulatory exposure. Depending on sensitivity, oversight may lie with senior management, the audit committee, independent directors, or a special board committee. Companies may also consider early whether auditors, lenders, insurers, or regulators need to be engaged based on initial findings.
Independence, governance oversight, and engagement of advisers
A key aspect of internal investigations in India is ensuring independence and credibility of the process. Companies often engage external legal counsel, forensic accountants, e-discovery providers, and other specialists where allegations may lead to regulatory scrutiny, litigation, financial restatements, or parallel proceedings. External counsel often coordinates investigative workstreams, helps maintain independence from implicated stakeholders, and assists the board or audit committee in oversight. Reporting protocols, escalation thresholds, and update mechanisms are commonly established so that material developments are communicated appropriately. Where allegations involve senior management or create conflicts of interest, companies may form clean teams, involve independent directors, or establish special committees to preserve the integrity of the process. Indian law recognises legal professional privilege under the Bharatiya Sakshya Adhiniyam, 2023, and investigations are often structured with privilege in mind, though this is balanced against governance, remediation, disclosure, and stakeholder-management considerations.
Evidence preservation, document review, and auditor engagement
Once the framework is established, attention turns to preservation and collection of evidence. This usually includes identifying custodians, securing electronic and physical records, preserving emails and messaging applications, reviewing accounting records, and mapping reporting lines and third-party relationships. Preservation notices are commonly issued to employees, contractors, and relevant third parties. Companies also maintain chain-of-custody procedures, access controls, and review logs to protect the integrity of the process. Data review may cover emails, chats, accounting entries, approvals, expense records, contracts, device data, and internal policies. Depending on the allegations, forensic review of financial records, procurement practices, related-party transactions, or internal controls may also be necessary. Auditor engagement often becomes important at this stage, especially where allegations involve fraud, bribery, accounting irregularities, internal control failures, or related-party transactions. Companies may need to assess whether the issues could affect financial reporting, require provisioning or restatement, or trigger reporting obligations for statutory auditors.
Witness interviews, fact development, and recording of notes
As factual themes emerge, investigations typically move to witness interviews and further fact development. Interviews are generally structured fact-finding exercises rather than interrogations and are often sequenced strategically in light of the documentary record. They usually involve prepared outlines, testing statements against contemporaneous documents, and assessing the credibility and consistency of explanations. Companies may also provide Upjohn-style warnings clarifying that counsel represents the company and not the employee individually.
While employees are typically required to cooperate, they retain constitutional protections against self-incrimination under Indian law. Companies must therefore balance cooperation expectations with fairness, procedural safeguards, and employment considerations. Investigation teams maintain contemporaneous interview notes, memoranda, evidentiary assessments, and credibility observations, which may be relevant for internal decision-making, auditor queries, disciplinary proceedings, regulatory scrutiny, shareholder disputes, or litigation.
Ongoing reporting, risk management, and internal decision-making
Internal investigations often run alongside parallel governance, financial, and regulatory considerations. Companies therefore establish ongoing reporting and escalation mechanisms rather than waiting until the end of the process. Periodic updates may be provided to the audit committee, the board, independent directors, senior management, or auditors depending on the seriousness of the allegations and the risks involved. Material interim findings may require immediate decisions on employee suspensions, preservation of assets, regulatory disclosures, third-party communications, financial provisioning, or remediation before the investigation is complete. Companies also maintain records of investigative steps, evidence reviewed, interviews conducted, legal assessments made, and internal decisions reached to demonstrate that the company acted promptly and responsibly.
Findings, board reporting, and remediation
Once the investigation concludes, the results are ordinarily communicated to the audit committee and/or the board through reports, legal memoranda, or presentations. Such reporting generally addresses the factual background, evidence reviewed, conclusions reached, individuals implicated, legal and regulatory exposure, financial implications, and recommended remediation. The findings may then inform decisions on disciplinary action, financial restatements, recovery measures, regulatory engagement, self-reporting, civil or criminal proceedings, and enhancements to compliance systems and internal controls. In significant matters, boards and audit committees are also expected to examine broader governance failures, oversight lapses, and remediation needs arising from the misconduct identified.
India’s legal regime for whistleblower protection remains limited, with no substantive private-sector legislation and only principle-based guidance. Protection largely depends on the strength of a company’s corporate governance framework.
Whistleblower protection has long been a low legislative priority, reflected in the Whistle-Blowers Protection Act, 2014, which has been passed but not notified. In any event, that statute is confined to government officials, public servants, and government-owned enterprises. In the private sector, protection depends mainly on governance mechanisms.
The CA, 2013 requires certain companies, including listed companies, to establish a vigil mechanism under section 177(9) with audit committee oversight, but this does not extend generally to private companies.
The RBI and SEBI have also taken a strong position against victimisation, retaliation, and harassment of whistleblowers, but their protections are limited to regulated entities such as banks and listed companies rather than applying market-wide. Indian law also generally offers no incentives to whistleblowers, except under the SEBI (Prohibition of Insider Trading) Regulations, 2015, which allow SEBI to reward an informant in insider trading cases with up to INR 100 million.
Company’s response to disclosures
Best practice, drawn from regulatory guidance and the positions adopted by SEBI and the SFIO requires companies to:
- promptly escalate disclosures to the Audit Committee without routing them through the implicated employee or officer;
- commission an independent internal investigation, ideally led by external counsels;
- take interim measures to preserve documentary and electronic evidence; and
- where the internal investigation reveals credible evidence of fraud or other criminal conduct, consider mandatory reporting under section 143(12) of the CA 2013 and any applicable disclosure obligations to SEBI.
Companies must also avoid suppression and premature disclosure. A rushed external announcement before the facts are established can disrupt markets and damage reputation, while suppression of a material disclosure (particularly where it reaches the threshold of a significant fraud) can itself constitute a criminal offence under the CA 2013 and trigger regulatory liability under the LODR Regulations. The whistleblower’s identity must at all times be protected, and any form of retaliation can expose the company to regulatory actions and potential civil litigation.
The growth and diversification of businesses, coupled with increasing foreign direct investment (FDI), have expanded the scale and complexity of commercial activity in India. This has heightened exposure to white-collar risks — including corruption, money laundering, insider trading, cyber-enabled fraud, and corporate misconduct and has driven a more complex and evolving legal and enforcement landscape.
The ED, particularly in fiscal year 2026, has communicated a clear objective of investigating violations of foreign direct investment (FDI) norms by companies investing in India. The ED has to date initiated 44,369 investigations under the relevant parent statute (i.e. the FEMA), and in fiscal year 2025–2026 had levied penalties amounting to INR 20,512.7 million (Annual Report, Directorate of Enforcement 2025–2026).
Financial regulators
During 2025–2026, the enforcement department at RBI undertook enforcement action against regulated entities (i.e. the banks, non-banking financial institutions, asset reconstruction companies, credit information companies, and housing finance companies) and imposed 241 penalties aggregating to INR 263.3 million for contraventions/non-compliance (www.rbi.org.in/Scripts/AnnualReportPublications.aspx?Id=1466).
The past year saw an increase of approximately 12% in the number of inspections of stockbrokers by stock exchanges in India. SEBI also conducted search and seizure operations to unearth market misconduct at 86 entities in 71 locations covering 18 cities across the country (SEBI’s Annual Report 2024–2025).
To ensure global regulatory cooperation, SEBI is also a signatory to the International Organization of Securities Commissions (IOSCO) multilateral memorandum of understanding (MMoU) and the enhanced MMoU (EMMoU). SEBI has also signed bilateral MoUs with several foreign securities regulators to enhance co-operation and information exchange for regulatory and enforcement purposes. As of March 31, 2025, SEBI is a signatory to 32 bilateral MoUs, which facilitate sharing of technical domain expertise and support the effective enforcement of laws and regulations governing the securities market. During 2024–2025, 111 requests were received from overseas regulators seeking SEBI’s assistance. SEBI responded to these requests subject to the provisions of the applicable memorandum of understanding. Similarly, 37 requests were made by SEBI to its counterparts in other jurisdictions (SEBI’s Annual Report 2024–2025).
The NFRA has to date debarred almost 85 auditors for reasons such as improper appointments and non-discharge of professional duties as stipulated by statutes and guidelines, to name a few (https://nfra.gov.in/debar/).
Money laundering and bribery
Enforcement into money laundering remains one of the most vigorously prosecuted areas of corporate conduct. In 2025–2026, the ED initiated 1,080 investigations and attached assets exceeding INR 800 billion, reflecting an increasingly proactive enforcement approach (Annual Report, Directorate of Enforcement 2025–2026).
As of March 2026, 8,851 cases have been probed and recorded by the ED out of which at least 80% of the cases fall under the category of fraud (including frauds related to banks, investment schemes, cybercrimes, ponzi scheme, real estate etc.) forgery, corruption and bribery, and illicit trafficking under narcotic, drugs and psychotropic substances (Annual Report, Directorate of Enforcement 2025–2026)
Additionally, since the setting up of the Citizen Financial Cyber Fraud Reporting and Management System by the Ministry of Home Affairs, 2.465 million complaints of financial cyber fraud were reported as of 31 January 2026 (www.pib.gov.in/PressReleasePage.aspx?PRID=2241344®=3&lang=1).
In the bribery and corruption sphere, a Transparency International Report reflects a marginal improvement in India’s standing on the Corruption Perceptions Index: 91 in 2025 as opposed to 96 in 2024 (www.transparency.org/en/countries/india).
Judicial developments have also shaped white-collar crime jurisprudence by clarifying evidentiary standards and liability.
In Sayaji Dashrath Kawade v. The State of Maharashtra 2022 LiveLaw (Bom) 324, the Bombay High Court held that a person cannot be convicted under the PCA until the basic requirement of demand and acceptance of a bribe is proven by the prosecution. In CBI v. Ramesh Gelli (2016) 3 SCC 788, the Supreme Court held that the managing director and executive director of a private bank that was operating under a licence issued by the RBI would be considered “public servants” under the PCA.
In Neeraj Dutta v. State (Govt. of NCT of Delhi) (2023) 4 SCC 731, the Court clarified that demand and acceptance of illegal gratification may be established through circumstantial evidence, and once proven, a presumption arises that the bribe was given as a “motivation or reward” for official action unless rebutted.
Recent legislation has also seen a shift in the imposition of individual liability, expressly requiring directors, officers, and key managerial personnel who oversaw misconduct to be prosecuted (see Question 3, above).
India’s white-collar crime framework is expansive and increasingly active, with multiple statutes and agencies addressing different facets of economic misconduct. However, this structural complexity can make coordination amongst agencies even more cumbersome, particularly where multiple agencies investigate the same facts without a unified investigative authority.
Cross-border investigations present a significant operational challenge. India relies heavily on MLATs to obtain evidence and cooperation from foreign jurisdictions; however, these processes are often slow, bureaucratic, with delays that are inherent to cross-border legal assistance frameworks.
A key structural distinction in India’s enforcement architecture, and one that sets it apart from several common law jurisdictions, is the absence of a comprehensive corporate criminal settlement mechanism equivalent to the DPA or NPA frameworks. While limited settlement or compounding mechanisms exist under specific statutes (such as SEBI and CCI frameworks), companies cannot resolve criminal investigations through negotiated remediation. This limits incentives for voluntary disclosure, reduces cooperation credit, and pushes parties toward binary litigation strategies.
That said, India’s white-collar crime laws have evolved steadily to combat financial and corporate crimes and mandate corporate accountability, with key statutes being continually amended to expand their ambit and regulate newer forms of white-collar offences. This enforcement trajectory is not merely legislative; it is increasingly evident in operational terms, both domestically and globally. The ED, CBI, SEBI, and the SFIO have collectively demonstrated a heightened enforcement posture that signals a decisive shift in India’s white-collar crime regime (see Question 11, above).
The second quarter of 2025 alone witnessed multiple arrests, raids, and investigations by the CBI, SEBI, and the ED. SEBI’s 2025 crackdown on officials of a large private sector bank demonstrates that insider trading probes are no longer ceremonial. In fact, attachments under the Benami Property Act crossed INR 4,520 million in one region alone in the current fiscal year.
India’s international enforcement outreach has also strengthened considerably. Red Notices issued by INTERPOL at India’s request has risen from 100 in 2023 to 107 in 2024, with 56 notices issued in the first six months of 2025. This trend is reflected in the issuance of India’s first Purple Notice through INTERPOL and its participation in the Silver Notice pilot (see Question 2, above).
Given the aggressive enforcement backdrop, we are likely to continue to witness evolving jurisprudence on matters involving corporate criminal misconduct, especially the interplay between the PMLA and other statutes. The Indian criminal justice and regulatory system is not a paper tiger, but rather, as demonstrated above, an active enforcer.
Companies will be under considerable pressure to conduct swift internal investigations (possibly faster than in any other jurisdiction, in our opinion) to effectively respond to and defend against multi-pronged investigations and proceedings. Overall, internal investigations are becoming an inevitable requirement to secure cooperation credit. The introduction of the BNS, the BNSS, and the BSA has initiated a period of flux as enforcement bodies and courts harmonise interpretations, address constitutional challenges (which are common with new legislation), and prosecute or investigate under two different legal regimes.
Once the DPDP Act and its rules are in force they are likely to clarify key areas such as consent requirements, the criteria for identifying data fiduciaries, cross-border data transfers, and obligations following data breaches. Once in force, the DPDP Act’s penalty regime, with fines of up to INR 2,500 million, will increase compliance and enforcement exposure for technology companies, financial institutions, and other data-heavy businesses in India.
The case for preventive compliance and investment in governance has never been stronger in India, driven by legal reform and increased enforcement and regulatory action. This provides a golden opportunity for organisations to enhance their compliance and governance programmes.