Knowledge & Perspectives

The ‘S’ in ESG Is Not Soft: How to Build Social Governance Infrastructure That Holds Up Under Scrutiny

Most Indian companies have social policy documents. Very few have social governance systems. This post explains the difference, walks through the six pillars of governance infrastructure that make social disclosures defensible, identifies the five gaps that show up across companies from small exporters to listed manufacturers, and includes a 10-point self-assessment to test whether your company has a governance system or just a document.
Table of Contents

Governance Architecture

A INR 120 crore garment exporter in Tirupur has a workplace safety policy, a supplier code of conduct, and a grievance redressal document filed with the company secretary. A INR 2,200 crore listed packaging manufacturer in Pune has the same three documents, formatted more expensively. Neither company has social governance. The documents exist. The systems behind them do not.

The difference only becomes visible when someone checks. A European buyer sends a 40-question social compliance questionnaire with a two-week deadline. A PE fund runs ESG due diligence before a capital infusion. A third-party assessor reviews BRSR Core disclosures. In each case, the question is the same: can you show me that these numbers came from a functioning system, not a last-minute spreadsheet exercise?

This post explains what social governance infrastructure looks like, where companies fall short regardless of size, and what it takes to move from a document to a system.

A Safety Policy Is Not a Safety Governance System

Take workplace safety for example. A manufacturer has a safety policy referencing BRSR Principle 3. It covers training requirements, incident reporting, and a commitment to safe working conditions. That document was written two years ago and sits in a folder.

A governance system for the same area looks different: a live incident tracking register with fields for severity, location, and resolution status. A named safety officer at each site with documented accountability. A monthly review cadence where safety data reaches a specific committee. Escalation triggers: any fatality reported to the board within 24 hours, any repeat-category incident within 48 hours. An evidence trail that shows the system is operating, not just that it was designed.

This distinction matters whether a company is a listed manufacturer under BRSR mandate or a INR 50 crore exporter whose UK buyer just asked for proof that a grievance mechanism exists beyond paper.

For listed companies, the regulatory pressure is specific. BRSR Core assessment or assurance is now mandatory for the full top 1,000 listed companies by market capitalisation (SEBI Circular, 12 July 2023; confirmed in SEBI LODR Master Circular, 30 January 2026). The glide path started with the top 150 in FY 2023-24 and expanded each year to the top 250, then 500, and now the full 1,000. The data being collected from April 2026 onwards will be reviewed by a third party.

For smaller companies and exporters, the pressure is commercial. EU companies with 1,000+ employees and EUR 450 million+ turnover still face CSRD reporting obligations after the Omnibus I adjustments (EU Directive 2026/470, 26 February 2026). Their supply chain questionnaires have not gone away. A INR 55 crore leather goods exporter in Kanpur faces the same governance scrutiny from its Italian buyer that a INR 3,000 crore listed company faces from SEBI. The trigger is different. The gap is the same.

Companies entering BRSR Core assessment for the first time should pay attention to what happened to the early cohort. KPMG’s February 2026 analysis of NIFTY100 BRSR reports found that 45 out of 94 covered companies revised their prior-year disclosures after the ISF Industry Standards were published (KPMG India, Accounting and Auditing Update, February 2026). One construction-sector company received a qualified assurance opinion because it could not provide sufficient evidence for certain BRSR Core disclosures. A qualified opinion tells every investor, buyer, and board member that the company’s governance systems could not support its own reported numbers.

If top-100 companies are struggling with this, companies without dedicated ESG teams are starting further behind.

The Six Pillars of Social Governance Infrastructure

SVEGA’s framework is structured around six pillars. The framework applies to a INR 5,000 crore listed manufacturer preparing for BRSR Core assessment and also to a INR 100 crore exporter preparing for a buyer audit. The scale differs. The architecture does not.

Pillar 1: Social Risk Intelligence.

Before building anything, a company needs to know where its social risks sit. Workforce risk mapping by site and employment type, supplier segmentation by sector and geography risk, and a regulatory exposure analysis. The output is a risk register and prioritisation matrix.

Pillar 2: Workforce Governance Architecture.

This is the layer most companies think they have but do not. It covers wage transparency, inclusion metrics, safety controls, and KPI ownership. The question is not whether the company tracks safety incidents. The question is: who owns the data, how is it collected, who reviews it, and what happens when a threshold is breached? The output is a governed workforce operating model.

Pillar 3: Ethical Supply Chain Controls.

Supplier codes of conduct exist in most companies above INR 200 crore. Supplier governance systems do not. This pillar covers supplier code alignment, a due diligence model, and a corrective action structure. For exporters, it addresses pull-through requirements from buyer-side ESG audits. The EU Forced Labour Regulation and EU Deforestation Regulation remain active with unchanged timelines, regardless of CSRD scope reductions.

Pillar 4: Grievance and Escalation Infrastructure.

BRSR Principle 5 requires listed companies to disclose grievance mechanisms and resolution data. Buyer questionnaires ask for the same from exporters. A grievance form on a company intranet is not a grievance system. A governance-grade mechanism has a defined channel accessible to permanent and contract workers, a workflow with documented response timelines, escalation triggers, and leadership visibility on resolution rates.

Pillar 5: Social KPI Assessment and Assurance Readiness.

This is where the evidence trail is built. Data ownership mapping, evidence pack construction, and readiness testing: can the governance system survive third-party scrutiny before the actual review happens? For listed companies, this means BRSR Core assessment simulation. For exporters, it means surviving a buyer audit without scrambling.

Pillar 6: Governance and Board Integration.

Social governance data needs to reach leadership in a structured, recurring format. For listed companies, BRSR Section B, Question 9 requires identification of the committee or director responsible for sustainability matters. KPMG’s February 2026 analysis found that 48 of 94 NIFTY100 companies have a dedicated Sustainability and CSR committee (KPMG India, February 2026). But naming a committee is not the same as giving it real-time visibility on social KPIs and escalation triggers. For smaller companies, this pillar may mean a monthly review with the MD rather than a board committee. The principle is the same: social governance data cannot live only in an annual report.

Five Governance Gaps That Show Up Across Company Sizes

These are not hypothetical. They come from conversations with companies ranging from small exporters to listed manufacturers. The gaps repeat.

Gap 1: Disclosure without ownership.

The company files BRSR disclosures or fills out buyer questionnaires. Nobody in the organisation owns the data behind those disclosures on an ongoing basis. The sustainability team or the export manager assembles numbers at filing time and moves on.

Gap 2: Policy without process.

A supplier code of conduct exists. There is no process for monitoring compliance. No scheduled reviews, no corrective action framework, no documentation of violations. The code is a PDF. The compliance is assumed.

Gap 3: Supplier data without supplier systems.

The company collects supplier questionnaire responses for its BRSR filing or buyer documentation. The responses sit in a spreadsheet. No verification, no risk tiering, no follow-up for incomplete or concerning responses.

Gap 4: KPIs without evidence trails.

The company reports social KPIs. When asked how a specific number was calculated, the answer involves estimates, manual tallies, and good-faith assumptions. The evidence an assessor or auditor would need does not exist in a retrievable form.

Gap 5: Reporting without leadership visibility.

Social data appears in the annual report or the buyer compliance file. Leadership does not receive social KPI updates during the year. No dashboard, no quarterly cadence, no escalation mechanism for safety incidents or grievance spikes between filing cycles.

The contract and migrant workforce makes each of these gaps worse. The share of contract workers in India’s formal manufacturing workforce reached 40.2% in 2021-22, up from 23.1% in 2002-03, according to Annual Survey of Industries data analysed by the Centre for Economic Data and Analysis at Ashoka University (CEDA, November 2024). In many factories, the figure is higher. These workers sit largely outside the governance architecture: not covered by KPI tracking, not included in grievance systems, not visible in leadership reporting. A buyer asking about workforce welfare is asking about the entire workforce.

What Assessment-Ready Actually Means

A company is assessment-ready when it can answer yes to four questions for every social KPI it reports, whether to SEBI or to a buyer.

  1. Ownership: is there a named individual accountable for this metric on an ongoing basis, not just at filing time?
  2. Evidence: does a retrievable, verifiable record exist that supports the reported number? Can the company show the source data within 48 hours of a request?
  3. Process: is the data generated by a repeatable governance process, or was it assembled as a one-time exercise for the annual report or the buyer questionnaire?
  4. Visibility: does this metric reach leadership in a structured format during the year, outside the annual filing cycle?

If the answer to any of these is no, the company has a governance gap. A listed company may still file a BRSR. An exporter may still pass a light buyer review. But neither is assessment-ready.

Self-Assessment: Governance System or Document?

Ten questions to ask before your next BRSR Core assessment cycle or buyer audit. Score one point for each “yes.”

  1. Every social KPI we report has a named owner who is accountable year-round.
  2. Our safety incident tracking system is live and updated in real time, not compiled at year end.
  3. We have a functioning grievance mechanism accessible to both permanent and contract workers.
  4. Our grievance data includes resolution timelines and is reported to a specific person or committee.
  5. Our supplier code of conduct has a defined monitoring and corrective action process behind it.
  6. We can produce source evidence for every social KPI within 48 hours of a request.
  7. Leadership receives social KPI updates at least quarterly, outside the annual filing cycle.
  8. Contract workers are included in our workforce governance and KPI tracking.
  9. We have defined escalation triggers that bring specific social incidents to leadership attention immediately.
  10. We have tested our governance system against assessment or audit criteria before the actual review.

A score of 7 or above suggests a functioning governance system. A score of 4 to 6 suggests policies exist but systems do not. Below 4 means the company is reporting numbers without governance infrastructure behind them.

Talk to SVEGA About Building Your Social Governance Infrastructure

SVEGA builds social governance systems for Indian companies preparing for BRSR Core assessment, buyer audits, and investor due diligence. We work with listed manufacturers in the top 1,000 and with exporters who aren’t listed but have clients in the European Union or any of the other countries following strict supplier verification. The governance gap does not wait for a company to reach a particular revenue threshold. Getting the basics right early is cheaper than retrofitting later.

Our diagnostic engagement takes 3 weeks, maps every governance gap, and delivers a 90-day roadmap for building the systems your disclosures depend on.

Book a 30-minute conversation at svegaconsulting.com.

Picture of Priyanka Bajiraj

Priyanka Bajiraj

Priyanka Bajiraj is a sustainability and social ESG professional with 10 years of experience across sustainability research, social governance advisory, UN exposure, and operational systems thinking.

Through SVEGA, Priyanka focuses on helping organisations move beyond ESG narratives and build practical governance systems that make social responsibility measurable, accountable, and operational.

WHAT'S INCLUDED

Build supplier systems that protect growth and market access.

Regulatory Intelligence

The four labour codes came into force on 21 November 2025, repealing twenty-nine central labour laws, and the final central rules followed on 8 May 2026. For a factory of about a hundred people, several obligations are now settled and headcount-triggered: a new wage definition that lifts provident fund and gratuity costs, appointment letters for every worker, a grievance committee at twenty workers, a works committee at a hundred, and a creche at fifty.

Supplier Accountability

For a growing number of Indian manufacturers and exporters, a SMETA audit has become the compliance test that actually gates the order, ahead of anything SEBI requires. A buyer in Europe or the United States asks for one, and a factory that never had a BRSR obligation suddenly has an auditor at the gate. It matters here for one specific reason: SMETA measures a site against the ETI Base Code as well as Indian law, whichever protects the worker more, so a factory that is fully compliant with the labour codes can still receive findings. This post walks through what the auditor does on the day, and where mid-sized Indian factories most often lose ground.

Social Governance Fundamentals

Most social compliance advice in India is written for the top 1,000 listed companies. The unlisted manufacturers and exporters that carry the bulk of the country’s production sit below the BRSR line but still face buyer audits, the labour codes, and customer questionnaires. This post explains who the missing middle is and what social governance actually means for a company this size.

Governance Architecture

BRSR requires every listed company to disclose grievance mechanisms and resolution data across all nine NGRBC Principles. The Industrial Relations Code, 2020 mandates a Grievance Redressal Committee for any establishment with 20 or more workers. Most companies have the policy document. Very few have a functioning system with documented intake, defined workflows, escalation triggers, and closure records. This post maps the full regulatory requirement, identifies the five failure modes that show up in assessment and audit, provides an eight-step build guide for mid-sized companies, and includes FAQs on contract worker access, zero-grievance red flags, and the distinction between POSH and general grievance mechanisms.

REACH US

If this resonates with the governance challenges you are navigating,

we welcome a focused conversation about where your organisation stands and what building the right systems would look like.