When Regulators Knock: A Board Primer on Responding to RBI or SEBI Investigations
In today's increasingly regulated business environment, the difference between effective governance and reactive oversight often becomes visible only when a regulator comes calling. Whether it is an RBI inspection, a SEBI inquiry, a cybersecurity incident attracting CERT-In scrutiny, or a broader governance review, the first few hours can significantly influence both outcomes and accountability.
Few professionals understand this intersection of governance, technology risk, and board responsibility as comprehensively as Sriram Vijayakumar.
A Certified Independent Director from the Indian Institute of Corporate Affairs (IICA) and a seasoned Corporate Governance Practitioner, Sriram brings over two decades of leadership experience spanning India, APAC, the United States, and the United Kingdom. His work focuses on helping boards strengthen oversight across technology, cybersecurity, artificial intelligence, regulatory compliance, and enterprise risk management—areas that are rapidly becoming central to boardroom discussions worldwide.
Through his widely respected governance platform, The Boardroom Blueprint, and as the author of multiple books on Corporate Governance and Artificial Intelligence, Sriram has consistently advocated for governance frameworks that move beyond compliance and enable informed, future-ready decision-making. His writings—including Governance 4.0 and The Independent Director's Handbook—have contributed to important conversations around board effectiveness, accountability, and the evolving role of directors in a technology-driven world.
In this exclusive conversation with Global Excellence Digest, Sriram explores one of the most critical yet often misunderstood responsibilities of modern boards: responding effectively when regulators initiate investigations. Drawing on practical governance realities rather than theoretical frameworks, he shares insights on independent director liability, board oversight, disclosure obligations, legal privilege, D&O insurance preparedness, whistleblower considerations, and the governance disciplines that can help organizations navigate regulatory scrutiny with confidence and integrity.
As regulatory expectations continue to rise globally, this discussion serves as an essential guide for directors, executives, governance professionals, and risk leaders seeking to strengthen board preparedness in moments that matter most.
When a regulator initiates an inquiry - whether it's RBI scrutiny of an NBFC's books, a SEBI show-cause notice, or a CERT-In data breach query - most Independent Directors are caught reacting rather than governing. The questions below are the ones IDs actually need answered in the first 72 hours, not the theoretical ones found in compliance manuals.
Q1: The company has just received a regulatory notice. What is the Independent Director's first move?
A1: It is management's job to investigate, so firstly, resist the instinct to ask "what happened." The ID's first move is procedural: confirm the notice has reached the Audit Committee or the full Board (not just been handled by Legal/Compliance in isolation), and ask whether the Board needs to be convened under Regulation 30 of SEBI LODR for material event disclosure. The clock on disclosure obligations often starts before anyone has assessed materiality - so the first question isn't "is this serious," it's "have we triggered our disclosure timeline."
Q2: What information is privileged, and what isn't?
A2: This trips up directors constantly. Privilege attaches to communications made for the purpose of obtaining legal advice - typically between the company and external counsel, or internal counsel acting in a legal (not business) capacity. It does not automatically cover:
● Board minutes recording the discussion of the investigation
● Internal emails between executives discussing the underlying conduct
● Communications with auditors (a separate, narrower privilege regime applies, and in India it's contested territory)
A practical rule IDs should insist on: any internal investigation should be commissioned by external counsel, with findings delivered as privileged legal advice and not as a freestanding "investigation report" that becomes discoverable. If management hasn't structured it this way, that's the first question to raise.
Q3: How much should the full Board see versus a sub-committee?
A3: This is genuinely contested in practice. The instinct to "protect the Board" by routing everything through a small crisis committee is understandable but risky as Indian courts and regulators have increasingly taken the view that the full Board cannot delegate away its oversight duty simply because a committee was formed. The working principle: a special committee can manage the investigation process, but the full Board must retain visibility into material findings, settlement terms, and any decision that could affect disclosure obligations or shareholder interests. Directors who are deliberately kept in the dark "for their own protection" should treat that as a red flag, not a comfort.
Q4: When does personal liability attach to an Independent Director in a regulatory matter?
A4: Under Section 149(12) of the Companies Act, 2013, an Independent Director's liability is limited to acts of omission or commission that occurred with their knowledge (attributable through Board processes), with their consent or connivance, or where they failed to act diligently. In practice, regulators and courts look for:
● Did the director have actual or constructive knowledge of the red flags?
● Did they raise objections, and were those objections minuted?
● Did they exercise independent judgment, or simply rubber-stamp management's representations?
The protective discipline here is unglamorous but essential: dissent recorded in minutes, written queries to management, and documented follow-through on unresolved concerns. An ID who raised the right questions and has the paper trail to prove it is in a fundamentally different position than one who didn't - even if both sat on the same board.
Q5: What about RBI-specific risk - does it work differently from SEBI?
A5: Yes, materially. RBI's supervisory and enforcement powers over regulated entities (banks, NBFCs, HFCs) are broader and more intrusive than SEBI's market-conduct framework - RBI can issue directions, supersede boards, or cancel certificates of registration (as seen in recent Section 45-IA actions against NBFCs) often with limited prior notice. For directors on regulated-entity boards, this means:
● RBI inspection findings (Risk Assessment Reports) should be reviewed by the Board, not just senior management
● Directors should ask whether previous inspection observations were closed out, or are repeat findings - regulators view repeat findings as a governance failure, not just an operational one
● Board-level escalation protocols for RBI communications need to be tighter than for general regulatory correspondence, given RBI's power to act on the entity itself (not just individuals)
Q6: Should the Board engage its own independent counsel, separate from the company's regular legal team?
A6: In any matter where management's own conduct is under scrutiny, yes. The company's regular counsel has an inherent conflict - their primary relationship is with the executives who may be the subject of inquiry. Independent Directors, particularly those on the Audit Committee, should have the standing (and often the explicit right under the company's governance charter) to retain separate counsel reporting directly to the committee. Hesitating to invoke this out of concern about cost or "creating friction" is precisely the hesitation regulators later scrutinize.
Q7: How does D&O insurance actually respond once an investigation is underway?
A7: Three things IDs should verify before a crisis, not during one:
● Notification timing - most D&O policies require notice "as soon as practicable" upon becoming aware of circumstances that could give rise to a claim. Waiting until a formal claim is filed can void coverage. A regulatory notice or inspection often counts as a triggering circumstance.
● Investigation costs coverage - confirm whether the policy covers costs of responding to a regulatory investigation (legal fees, document review) even before any claim or penalty is formally asserted — this is where many policies have gaps.
● Severability and exclusions - check whether fraud or willful misconduct exclusions apply only to the individual found liable, or whether they can taint coverage for the entire board (severability clauses matter enormously here).
An ID who hasn't personally reviewed the D&O policy - not just been told it exists - is flying blind on their own protection.
Q8: What's the single biggest mistake Boards make when a regulator first makes contact?
A8: Treating it as a Legal/Compliance problem to be managed and reported on, rather than a Board governance event requiring active oversight. By the time the Board engages substantively, key documents may already be in a form that limits options - informal communications may have been sent, internal narratives may have hardened, and the window for a controlled, privileged investigation may have narrowed. The Boards that come out of regulatory scrutiny intact are the ones that treated the first 48 hours as a governance moment, not an administrative one.
Q9: Should an Independent Director worry about whistleblower retaliation claims surfacing alongside the regulatory matter?
A9: Yes - these often arrive together, and Boards frequently miss the connection. If an internal whistleblower's complaint preceded the regulatory notice, the Board has a parallel obligation under the company's Vigil Mechanism (mandatory under Section 177 of the Companies Act for listed companies and certain others) to ensure the complainant hasn't been retaliated against during the investigation. Regulators increasingly check whether the original whistleblower was sidelined, transferred, or excluded from the inquiry - and treat that as an aggravating factor, not a footnote. The Audit Committee Chair should explicitly confirm the whistleblower's treatment is being tracked separately from the substantive investigation.
Q10: How should the Board handle external communications - media queries, analyst calls, customer concerns - while the matter is live?
A10: This is where Boards lose control fastest. The principle: one designated spokesperson, vetted lines pre-cleared with counsel, and an explicit prohibition on individual directors - including the ID - speaking to press, analysts, or even concerned shareholders informally. It feels obvious, but in practice, well-meaning directors often try to "reassure" a worried institutional investor in a one-on-one call, inadvertently creating selective disclosure exposure under SEBI's PIT (Prohibition of Insider Trading) and fair disclosure regulations. The Board should formally minute the communication protocol, not just assume everyone knows it.
Q11: At what point should the Board consider a settlement or consent mechanism rather than contesting the regulator's findings?
A11: For SEBI matters, the Consent Order mechanism (settlement without admission or denial of guilt) is often available and can be the more prudent path - it limits reputational drag and caps financial exposure, but it has tradeoffs: it doesn't always preclude follow-on civil litigation, and certain categories of violations (fraud, market manipulation) are excluded from consent eligibility. The ID's role here isn't to negotiate terms - that's management and counsel's job - but to interrogate the decision framework: has the Board compared litigation cost and reputational exposure against settlement cost with genuine rigor, or is the recommendation arriving as a fait accompli from management who simply want the matter closed?
Q12: Once the investigation concludes, what should the Board insist on before considering the matter "resolved"?
A12: Closing a regulatory matter isn't just about resolving the finding - it's about institutionalizing the lesson. Three things IDs should insist appear on a Board agenda before signing off:
● A root-cause review distinct from the legal resolution - what control or governance gap allowed this to occur, and has it actually been remediated (not just patched)?
● An update to the risk register and relevant Board committee charters reflecting the new risk category, if it wasn't previously tracked
● A review of whether similar exposure exists elsewhere in the group structure - regulators increasingly look unfavorably on companies that fix the cited instance but leave the same control gap live in a sister entity or subsidiary
A matter that closes with a fine paid and no structural change is, from a governance standpoint, still open.
To learn more about Sriram Vijayakumar's work in Corporate Governance, Technology Risk, Cybersecurity, AI Governance, and Board Effectiveness, readers may connect with him through the following platforms:
LinkedIn: linkedin.com/in/sriram-vijayakumar-id
Website: www.sriramvijayakumar.com
Through his writings, advisory engagements, speaking assignments, and The Boardroom Blueprint podcast, Sriram continues to contribute to the advancement of responsible governance practices and future-focused board leadership across industries.