Most ESG conversations in Indian boardrooms start with the same question: what is our carbon footprint?
That is not a bad question. But it is increasingly the only question. And in focusing almost entirely on environmental metrics, most mid-sized Indian companies have quietly built a structural gap in their governance that is about to become visible.
The gap is the ‘S’. Social governance.
What social governance actually is
Social governance is not the same as CSR. It is not a welfare programme, a community investment budget, or an annual charity report. It is the internal architecture that determines how a company manages its obligations to the people connected to it: workers, contractors, suppliers, and surrounding communities.
More specifically, it is the system of policies, controls, ownership structures, and evidence trails that make it possible to answer questions like these under pressure:
- Who is responsible for tracking worker grievances, and what is the resolution timeline?
- How does the company know its tier-one suppliers are meeting minimum social standards?
- If a buyer’s due diligence team arrives next week, what documentation exists to show the company’s social KPIs are real and maintained?
If those questions produce a long pause, the company has a social governance gap. It may have a policy document. It may even have a filed BRSR report. What it does not have is a system.
Why the ‘S’ gets left behind
Environmental sustainability developed a measurement language that made accountability easier. Carbon is quantifiable. Kilowatt hours, tonnes of CO2, litres of water: these are numbers a finance team can wrap a process around. The ESG industry built itself primarily around that language, and the tools, frameworks, and consultant specialisations followed.
Social sustainability operates differently. It requires governing relationships and processes rather than measuring flows. Workforce treatment, supplier accountability, grievance handling, and community obligations do not reduce to a single metric. They require architecture: defined ownership, operational controls, escalation mechanisms, and review cadence.
That is harder to package and harder to sell. So the market largely did not build it.
The result, visible in almost every mid-sized Indian company SVEGA has spoken to, is an environmental reporting infrastructure that has grown steadily over the last five years sitting alongside a social governance infrastructure that is, in most cases, barely past a first draft.
Why this gap matters now
Three converging pressures are making social governance more consequential than it has ever been.
BRSR Core assessment is arriving for the top 1,000 listed companies.
SEBI’s BRSR Core framework requires third-party assessment or assurance of a company’s social KPIs. The glide path started with the top 150 companies in FY 2023-24 and reaches all 1,000 mandated companies by FY 2026-27. Assessment reviewers do not just check whether numbers were disclosed. They check whether the systems that produced those numbers are real, owned, and defensible. A company that has been filing social data without building governance infrastructure will face a very different conversation during an assessment review than it did during a standard BRSR filing exercise.
Investor and buyer due diligence has tightened.
PE firms, institutional investors, and large commercial buyers are asking more specific social governance questions than they were two years ago. Not “do you have a social policy?” but “who owns your grievance mechanism, and what are your resolution rates?” The shift from general ESG questionnaires to operational social governance questions is real and is happening across deal and procurement cycles.
European buyers are pulling compliance requirements upstream.
EU CSRD requires large European companies to report on supply chain sustainability, and that reporting cascades into the questionnaires they send to Indian suppliers. The Forced Labour Regulation and Deforestation Regulation add further specific documentation requirements. Companies that supply to European buyers are seeing longer, more detailed social compliance requests at contract renewal, regardless of whether any Indian regulation directly requires them to file such data.
Together these pressures mean that social governance has moved from a voluntary ethics position to an operational risk management requirement. The companies that treat it as the latter are building defensible systems. The companies that treat it as the former are accumulating a problem they have not yet been asked to explain.
Unmanaged social risk compounds silently until it becomes expensive.
The difference between a policy and a system
A social policy is a document. It states what a company intends to do. In most mid-sized companies, policies exist for worker welfare, supplier conduct, grievance handling, and community engagement. They were written, approved, and filed. They are largely correct as statements of intent.
A social governance system is the operational reality behind that intent. It includes the ownership structure (who is accountable for each social metric and how often they report), the controls (what processes verify that the policy is being followed), the evidence trail (what documentation exists to demonstrate compliance if someone asks), and the review cadence (who sees social governance data at board level and on what schedule).
The gap between the two is where most companies are living. A grievance policy exists. No one can show a closed grievance log. A supplier code of conduct has been signed. No one is monitoring whether it is being followed. A workforce safety record is filed annually. There is no incident tracking system behind it.
When a third-party assessment review, a buyer audit, or a PE due diligence team arrives, they are looking at the system. Not the policy.
The three layers every company needs
Regardless of size or sector, a defensible social governance system requires three layers working together.
Layer 1: Policy.
The documented commitments covering how the company manages its obligations to workers, suppliers, and communities. Most companies have this. It is the starting point, not the finish line.
Layer 2: Process.
The operational controls that make the policy real. Who does what, when, and how often. Grievance intake workflows, supplier monitoring schedules, safety incident reporting chains, KPI data collection cycles. This layer is where most mid-sized companies have the largest gaps.
Layer 3: Governance architecture.
The ownership and oversight structures that connect process to leadership. Which metrics go to which committee, on what schedule, with what escalation triggers. How the board receives social governance data. How performance against social KPIs is reviewed and acted on.
A company can have Layer 1 and no Layer 2. Many do. It can have Layer 1 and Layer 2 and no Layer 3: processes that run without meaningful leadership oversight or board visibility. All three layers are required for a system that holds up under scrutiny.
A five-question self-assessment
These questions do not require external input to answer. They are diagnostic for internal use.
1. Who owns each of your social KPIs?
Can you name a specific individual responsible for each metric in your BRSR social disclosure? If ownership is unclear or shared without defined accountability, you have a governance gap.
2. What does your grievance data show over the last 12 months?
Not the number of grievances received. The number resolved, the average resolution time, and how many were escalated. If you cannot produce that breakdown in 10 minutes, your grievance mechanism is a form, not a system.
3. When did you last audit your tier-one supplier social compliance?
Not receive a signed declaration. Conduct a meaningful review of whether your code of conduct is being followed and what the evidence shows.
4. Can your social KPI data be traced back to source?
If someone asked you to demonstrate how a specific number in your last BRSR filing was derived, could you show the data trail from collection through to disclosure?
5. Who at board level reviews social governance data, and how often?
Not who is ultimately responsible. Who actually sees the data, in what format, and on what schedule.
If any of these questions produce a pause longer than 30 seconds, that question marks a gap worth investigating before an external reviewer finds it first.
Frequently Asked Questions about Social Governance in ESG
What is social governance in ESG?
Social governance refers to the internal systems, controls, and oversight structures that determine how a company manages its obligations to workers, suppliers, contractors, and communities. It is distinct from environmental sustainability, which focuses on measurable resource flows like carbon and energy, and from CSR, which is primarily philanthropic. Social governance is operational and structural: it covers workforce controls, supplier accountability, grievance mechanisms, KPI ownership, and board-level oversight of social performance.
Is social governance the same as CSR?
No. CSR (Corporate Social Responsibility) is about what a company gives back to society, typically through community investment, charitable programmes, or discretionary welfare initiatives governed by Section 135 of the Companies Act. Social governance is about how a company manages its operational obligations to the people connected to it every day, workers, contractors, and suppliers. A company can have an active CSR programme and weak social governance simultaneously. Under BRSR and third-party assessment, reviewers examine governance systems, not CSR spend.
Why do Indian companies need social governance systems?
SEBI’s BRSR framework requires the top 1,000 listed companies to disclose social KPIs annually. BRSR Core, a more rigorous subset of those disclosures, requires third-party assessment or assurance across a phased glide path. Beyond regulation, investor due diligence, buyer ESG audits, and ESG rating agencies all examine whether a company’s social disclosures are supported by real governance systems. Companies without that infrastructure face increasing commercial and regulatory exposure.
What is the difference between a social policy and a social governance system?
A social policy is a document stating what a company intends to do. A social governance system is the operational reality behind that intent: ownership structures, controls, evidence trails, escalation mechanisms, and board-level review cadence. Most mid-sized Indian companies have social policies. Very few have social governance systems. The difference only becomes visible when someone external actually checks.
What does BRSR require on social governance?
BRSR requires disclosure across nine principles of the National Guidelines on Responsible Business Conduct (NGRBC). The social principles cover workforce treatment, human rights, community obligations, and consumer responsibility. BRSR Core goes further, requiring KPI-level disclosure with defined metrics on areas including workforce composition, wage structure, safety performance, and grievance handling.
How do I know if my company has a social governance gap?
Five questions serve as a quick diagnostic.
1. Can you name the specific owner of each social KPI in your BRSR disclosure?
2. Can you produce a 12-month grievance resolution breakdown in 10 minutes?
3. When did you last conduct a meaningful supplier social compliance review?
4. Can your social KPI data be traced back to source documentation?
5. And who at board level sees social governance data, and how often?
If any of these questions produces a long pause, that question marks a gap worth addressing before an external reviewer finds it first.
What is the SVEGA Framework?
The SVEGA Framework is a six-pillar methodology for diagnosing and building social governance systems in mid-sized Indian companies. The six pillars are: Social Risk Intelligence, Workforce Governance Architecture, Ethical Supply Chain Controls, Grievance and Escalation Infrastructure, Social KPI Assessment and Assurance Readiness, and Governance and Board Integration. Every SVEGA engagement operates within this framework, from the initial diagnostic through to system build and ongoing retainer advisory.
What comes next
Social governance is not going to get simpler. The regulatory baseline is moving, buyer requirements are tightening, and investor scrutiny of social disclosures is deepening. The companies that build the system now will be in a materially stronger position in 12 months than the companies that wait for an external prompt.