ROC and secretarial compliance
Understanding ROC Compliance for a Private Limited Company
A practical ROC triage map for Indian private companies to separate annual, event, director, auditor, deposit, and internal-record work before choosing the next action.
8 min read
Short answer
ROC compliance is not one annual filing. It is a control system for annual financial-statement and annual-return work, event-triggered changes, director and auditor records, deposit or outstanding-money classification, and statutory registers and minutes. Start with the trigger and company facts, identify the legal and internal records affected, assign an owner and reviewer, then use the specialist workflow for the applicable form or remediation. A calendar helps with known dates, but it cannot replace an event log or accurate source records.
One business week can create several different ROC jobs
Use an event-to-duty map before opening a form
| Workstream | Trigger to test | Core record | Next action |
|---|---|---|---|
| Annual | Financial-year close, AGM status, adoption, and annual return | Financial statements, audit and Board reports, AGM record, members and director data | Use the annual-filing readiness guide; calculate AGM-relative clocks and confirm AOC and annual-return form families. |
| Event filing | Office, capital, charge, allotment, resolution, or another company fact changes | Approval, agreement, register update, effective date, and event evidence | Identify the exact provision and form before the event or immediately when discovered; do not wait for annual filing. |
| Director | Appointment, cessation, particulars change, interest disclosure, DIN or KYC status | Consent, approval, director register, disclosure, identity-status and filing record | Route company-event work separately from the DIN holder's current KYC workflow. |
| Auditor | First appointment, AGM appointment, reappointment, vacancy, resignation, or rotation question | Consent, eligibility, approval, meeting record, appointment term, and notice evidence | Use the auditor appointment guide; determine the event path before deciding authority, notice, form, or clock. |
| Deposit or outstanding money | Receipt, loan, advance, deposit balance, or year-end outstanding amount | Ledger, agreement, source, terms, movement, financial statements, and classification basis | Use the DPT-3 checklist for transaction-by-transaction classification and unresolved-item review. |
| Internal statutory record | Meeting, resolution, member, security, director, contract, or filing changes a statutory fact | Register, minutes, index, approval, certificate or depository evidence, and acknowledgement | Update the controlled source record and reconcile it to books, contracts, MCA data, and later filings. |
Separate annual work from events that cannot wait
Section 92 creates the annual-return workstream. Section 137 creates the financial-statement filing workstream. Their filing clocks depend on AGM and company facts, but neither section turns annual filing into a correction window for every event during the year. If the registered office changes, section 12 has its own notice framework. Certain resolutions and agreements fall within section 117. Director, auditor, capital, charge, beneficial-ownership, and other events each need their current provision and rules checked.
| Question | Annual calendar | Event log |
|---|---|---|
| What starts the work? | Financial-year, AGM, annual return, periodic director or reporting cycle | A decision, transaction, change, appointment, cessation, receipt, default, or discovered mismatch |
| When is it recorded? | At the planning cycle, then refreshed from actual dates | As soon as the event is proposed or discovered |
| What does it contain? | Formula, dependency, owner, reviewer, planned evidence and escalation date | Trigger date, effective date, approvals, records affected, form decision, status and acknowledgement |
| Main failure | Using a generic date that ignores company or AGM facts | Waiting for year-end and losing the event chronology |
Give the company one controlled compliance intake
- 01
Capture the trigger
Record what changed or is due, when it was proposed, when it became effective, and which company or person it concerns. Keep facts separate from assumptions about the form.
- 02
Classify the workstream
Mark annual, event, director, auditor, deposit or outstanding money, internal record, or more than one. If the category is uncertain, escalate classification before selecting a deadline.
- 03
Map records and owners
Name the business owner, compliance preparer, reviewer, approver, signer, and custodian of the source record. An external adviser should not become the company's only record owner.
- 04
Check provision and current workflow
Use the Act, current rules, latest Gazette notification, and live MCA form instructions. Record why the selected specialist path applies and which alternatives were ruled out.
- 05
Close every affected record
Reconcile approvals, registers, minutes, books, contracts, filed forms, acknowledgements, and MCA master data. Portal acceptance is submission evidence, not proof that the underlying facts are correct.
- 06
Carry exceptions visibly
Keep open gaps in an owner-and-reviewer queue with target dates and escalation status. Never backdate a record or bury an unresolved event inside annual working papers.
Keep internal records aligned with filed facts
ROC work does not begin and end with forms. Section 88 requires prescribed registers of members and other security holders. Section 118 addresses minutes of company and Board meetings and resolutions. Section 170 addresses the register of directors and key managerial personnel. These records support annual returns and event filings, but they also have their own maintenance purpose. Reconcile them when the event occurs, not only when a filing preparer requests data months later.
- Use one legal name, CIN, registered-office, capital, director, auditor, and member source across filings and records.
- Preserve approval and effective dates; do not replace chronology with the upload date.
- Link each filed acknowledgement to the event and source records it affects.
- Review MCA master data after filing and escalate a mismatch instead of silently changing internal books.
- Restrict access to minutes, registers, identity records, financial statements, agreements, and signing material.
Sources and review
Published by ThynkBored. Published 13 July 2026. Content review completed 13 July 2026.
- The Companies Act, 2013
India Code, Government of India. Accessed 13 July 2026.
Supports: Official section and subordinate-legislation index for company compliance; ROC duties arise from distinct statutory chapters rather than one universal annual form.
- Section 92: Annual return
India Code, Government of India. Accessed 13 July 2026.
Supports: Annual return is a distinct company workstream; Annual-return particulars include company, capital, member, director, meeting and other prescribed facts.
- Section 137: Copy of financial statement to be filed with Registrar
India Code, Government of India. Accessed 13 July 2026.
Supports: Financial-statement filing is separate from the annual return; AGM, adoption, adjournment, no-AGM and OPC facts can change the filing path.
- Section 12: Registered office of company
India Code, Government of India. Accessed 13 July 2026.
Supports: Registered-office maintenance, verification, display, and change duties are event-based company work.
- Section 117: Resolutions and agreements to be filed
India Code, Government of India. Accessed 13 July 2026.
Supports: Specified resolutions and agreements can create their own filing workstream; Meeting approvals and event filings must remain linked.
- Section 139: Appointment of auditors
India Code, Government of India. Accessed 13 July 2026.
Supports: Auditor work has distinct first-appointment, AGM, vacancy, government-company and other event paths; Auditor consent, eligibility, approval and notice records affect the compliance trail.
- Section 73: Prohibition on acceptance of deposits from public
India Code, Government of India. Accessed 13 July 2026.
Supports: Private-company deposit compliance is a distinct statutory workstream requiring current rules and transaction facts; A receipt cannot be classified from its ledger label alone.
- Section 76: Acceptance of deposits from public by certain companies
India Code, Government of India. Accessed 13 July 2026.
Supports: Public-deposit permission applies only to eligible public companies under the statutory and rules framework; Company class must be established before routing deposit compliance.
- Section 88: Register of members, etc.
India Code, Government of India. Accessed 13 July 2026.
Supports: Companies maintain prescribed registers of members and other security holders; Statutory registers are source records for later company reporting.
- Section 118: Minutes of meetings and resolutions
India Code, Government of India. Accessed 13 July 2026.
Supports: Meeting and Board minutes preserve company proceedings and resolutions; Internal meeting records remain distinct from filing acknowledgements.
- Section 170: Register of directors and key managerial personnel and their shareholding
India Code, Government of India. Accessed 13 July 2026.
Supports: Director and key-managerial-personnel particulars have an internal statutory-register requirement; Director records should reconcile with event and annual filings.
This article is an educational triage map, not a form-selection or legal opinion for a specific company. Actual work depends on company class, event facts, effective dates, approvals, current rules, exemptions, notifications, forms, records, and prior defaults. It does not classify a receipt as a deposit, determine a director or auditor filing path, calculate a deadline or penalty, validate an internal record, or promise portal acceptance or good standing. India Code landing metadata and MCA operational materials can lag later amendments; verify the current provision, rule, Gazette notification, and live portal workflow before action.
Route the company event before choosing a form
Share the company stage, event category, proposed or discovery date, records affected, current status, owner role, and nearest decision date. ThynkBored can help separate annual, event, director, auditor, deposit-classification, and internal-record work.
Use categories and status only. Do not send MCA credentials, OTPs, DSC PINs, DIN/PAN/Aadhaar, personal contact details, bank data, financial statements, minutes, registers, cap tables, agreements, ledgers, identity files, or attachments through the form. Agree a secure handoff before records are shared.
Diagnose this issueQuestions owners ask
What is ROC compliance for a private limited company?
ROC compliance is the company's system for annual financial-statement and annual-return work, event-triggered filings, director and auditor records, deposit or outstanding-money review, and statutory registers and minutes under the Companies Act and current rules. Each duty needs its own trigger, facts, owner, evidence, and specialist workflow.
Why do startups need a ROC compliance calendar?
A calendar makes known annual and periodic dependencies visible, assigns owners, and prompts review before a deadline. It must be paired with a live event log because office, director, auditor, capital, borrowing, resolution, and record changes can arise during the year and should not wait for annual filing.
Useful context for this decision
Follow the records, definitions, comparisons, and next actions connected to this page.