A INR 120 crore garment exporter in Tirupur has a workplace safety policy, a supplier code of conduct, and a grievance redressal document filed with the company secretary. A INR 2,200 crore listed packaging manufacturer in Pune has the same three documents, formatted more expensively. Neither company has social governance. The documents exist. The systems behind them do not.
The difference only becomes visible when someone checks. A European buyer sends a 40-question social compliance questionnaire with a two-week deadline. A PE fund runs ESG due diligence before a capital infusion. A third-party assessor reviews BRSR Core disclosures. In each case, the question is the same: can you show me that these numbers came from a functioning system, not a last-minute spreadsheet exercise?
This post explains what social governance infrastructure looks like, where companies fall short regardless of size, and what it takes to move from a document to a system.
A Safety Policy Is Not a Safety Governance System
Take workplace safety for example. A manufacturer has a safety policy referencing BRSR Principle 3. It covers training requirements, incident reporting, and a commitment to safe working conditions. That document was written two years ago and sits in a folder.
A governance system for the same area looks different: a live incident tracking register with fields for severity, location, and resolution status. A named safety officer at each site with documented accountability. A monthly review cadence where safety data reaches a specific committee. Escalation triggers: any fatality reported to the board within 24 hours, any repeat-category incident within 48 hours. An evidence trail that shows the system is operating, not just that it was designed.
This distinction matters whether a company is a listed manufacturer under BRSR mandate or a INR 50 crore exporter whose UK buyer just asked for proof that a grievance mechanism exists beyond paper.
For listed companies, the regulatory pressure is specific. BRSR Core assessment or assurance is now mandatory for the full top 1,000 listed companies by market capitalisation (SEBI Circular, 12 July 2023; confirmed in SEBI LODR Master Circular, 30 January 2026). The glide path started with the top 150 in FY 2023-24 and expanded each year to the top 250, then 500, and now the full 1,000. The data being collected from April 2026 onwards will be reviewed by a third party.
For smaller companies and exporters, the pressure is commercial. EU companies with 1,000+ employees and EUR 450 million+ turnover still face CSRD reporting obligations after the Omnibus I adjustments (EU Directive 2026/470, 26 February 2026). Their supply chain questionnaires have not gone away. A INR 55 crore leather goods exporter in Kanpur faces the same governance scrutiny from its Italian buyer that a INR 3,000 crore listed company faces from SEBI. The trigger is different. The gap is the same.
Companies entering BRSR Core assessment for the first time should pay attention to what happened to the early cohort. KPMG’s February 2026 analysis of NIFTY100 BRSR reports found that 45 out of 94 covered companies revised their prior-year disclosures after the ISF Industry Standards were published (KPMG India, Accounting and Auditing Update, February 2026). One construction-sector company received a qualified assurance opinion because it could not provide sufficient evidence for certain BRSR Core disclosures. A qualified opinion tells every investor, buyer, and board member that the company’s governance systems could not support its own reported numbers.
If top-100 companies are struggling with this, companies without dedicated ESG teams are starting further behind.
The Six Pillars of Social Governance Infrastructure
SVEGA’s framework is structured around six pillars. The framework applies to a INR 5,000 crore listed manufacturer preparing for BRSR Core assessment and also to a INR 100 crore exporter preparing for a buyer audit. The scale differs. The architecture does not.
Pillar 1: Social Risk Intelligence.
Before building anything, a company needs to know where its social risks sit. Workforce risk mapping by site and employment type, supplier segmentation by sector and geography risk, and a regulatory exposure analysis. The output is a risk register and prioritisation matrix.
Pillar 2: Workforce Governance Architecture.
This is the layer most companies think they have but do not. It covers wage transparency, inclusion metrics, safety controls, and KPI ownership. The question is not whether the company tracks safety incidents. The question is: who owns the data, how is it collected, who reviews it, and what happens when a threshold is breached? The output is a governed workforce operating model.
Pillar 3: Ethical Supply Chain Controls.
Supplier codes of conduct exist in most companies above INR 200 crore. Supplier governance systems do not. This pillar covers supplier code alignment, a due diligence model, and a corrective action structure. For exporters, it addresses pull-through requirements from buyer-side ESG audits. The EU Forced Labour Regulation and EU Deforestation Regulation remain active with unchanged timelines, regardless of CSRD scope reductions.
Pillar 4: Grievance and Escalation Infrastructure.
BRSR Principle 5 requires listed companies to disclose grievance mechanisms and resolution data. Buyer questionnaires ask for the same from exporters. A grievance form on a company intranet is not a grievance system. A governance-grade mechanism has a defined channel accessible to permanent and contract workers, a workflow with documented response timelines, escalation triggers, and leadership visibility on resolution rates.
Pillar 5: Social KPI Assessment and Assurance Readiness.
This is where the evidence trail is built. Data ownership mapping, evidence pack construction, and readiness testing: can the governance system survive third-party scrutiny before the actual review happens? For listed companies, this means BRSR Core assessment simulation. For exporters, it means surviving a buyer audit without scrambling.
Pillar 6: Governance and Board Integration.
Social governance data needs to reach leadership in a structured, recurring format. For listed companies, BRSR Section B, Question 9 requires identification of the committee or director responsible for sustainability matters. KPMG’s February 2026 analysis found that 48 of 94 NIFTY100 companies have a dedicated Sustainability and CSR committee (KPMG India, February 2026). But naming a committee is not the same as giving it real-time visibility on social KPIs and escalation triggers. For smaller companies, this pillar may mean a monthly review with the MD rather than a board committee. The principle is the same: social governance data cannot live only in an annual report.
Five Governance Gaps That Show Up Across Company Sizes
These are not hypothetical. They come from conversations with companies ranging from small exporters to listed manufacturers. The gaps repeat.
Gap 1: Disclosure without ownership.
The company files BRSR disclosures or fills out buyer questionnaires. Nobody in the organisation owns the data behind those disclosures on an ongoing basis. The sustainability team or the export manager assembles numbers at filing time and moves on.
Gap 2: Policy without process.
A supplier code of conduct exists. There is no process for monitoring compliance. No scheduled reviews, no corrective action framework, no documentation of violations. The code is a PDF. The compliance is assumed.
Gap 3: Supplier data without supplier systems.
The company collects supplier questionnaire responses for its BRSR filing or buyer documentation. The responses sit in a spreadsheet. No verification, no risk tiering, no follow-up for incomplete or concerning responses.
Gap 4: KPIs without evidence trails.
The company reports social KPIs. When asked how a specific number was calculated, the answer involves estimates, manual tallies, and good-faith assumptions. The evidence an assessor or auditor would need does not exist in a retrievable form.
Gap 5: Reporting without leadership visibility.
Social data appears in the annual report or the buyer compliance file. Leadership does not receive social KPI updates during the year. No dashboard, no quarterly cadence, no escalation mechanism for safety incidents or grievance spikes between filing cycles.
The contract and migrant workforce makes each of these gaps worse. The share of contract workers in India’s formal manufacturing workforce reached 40.2% in 2021-22, up from 23.1% in 2002-03, according to Annual Survey of Industries data analysed by the Centre for Economic Data and Analysis at Ashoka University (CEDA, November 2024). In many factories, the figure is higher. These workers sit largely outside the governance architecture: not covered by KPI tracking, not included in grievance systems, not visible in leadership reporting. A buyer asking about workforce welfare is asking about the entire workforce.
What Assessment-Ready Actually Means
A company is assessment-ready when it can answer yes to four questions for every social KPI it reports, whether to SEBI or to a buyer.
- Ownership: is there a named individual accountable for this metric on an ongoing basis, not just at filing time?
- Evidence: does a retrievable, verifiable record exist that supports the reported number? Can the company show the source data within 48 hours of a request?
- Process: is the data generated by a repeatable governance process, or was it assembled as a one-time exercise for the annual report or the buyer questionnaire?
- Visibility: does this metric reach leadership in a structured format during the year, outside the annual filing cycle?
If the answer to any of these is no, the company has a governance gap. A listed company may still file a BRSR. An exporter may still pass a light buyer review. But neither is assessment-ready.
Self-Assessment: Governance System or Document?
Ten questions to ask before your next BRSR Core assessment cycle or buyer audit. Score one point for each “yes.”
- Every social KPI we report has a named owner who is accountable year-round.
- Our safety incident tracking system is live and updated in real time, not compiled at year end.
- We have a functioning grievance mechanism accessible to both permanent and contract workers.
- Our grievance data includes resolution timelines and is reported to a specific person or committee.
- Our supplier code of conduct has a defined monitoring and corrective action process behind it.
- We can produce source evidence for every social KPI within 48 hours of a request.
- Leadership receives social KPI updates at least quarterly, outside the annual filing cycle.
- Contract workers are included in our workforce governance and KPI tracking.
- We have defined escalation triggers that bring specific social incidents to leadership attention immediately.
- We have tested our governance system against assessment or audit criteria before the actual review.
A score of 7 or above suggests a functioning governance system. A score of 4 to 6 suggests policies exist but systems do not. Below 4 means the company is reporting numbers without governance infrastructure behind them.
Talk to SVEGA About Building Your Social Governance Infrastructure
SVEGA builds social governance systems for Indian companies preparing for BRSR Core assessment, buyer audits, and investor due diligence. We work with listed manufacturers in the top 1,000 and with exporters who aren’t listed but have clients in the European Union or any of the other countries following strict supplier verification. The governance gap does not wait for a company to reach a particular revenue threshold. Getting the basics right early is cheaper than retrofitting later.
Our diagnostic engagement takes 3 weeks, maps every governance gap, and delivers a 90-day roadmap for building the systems your disclosures depend on.
Book a 30-minute conversation at svegaconsulting.com.