TL;DR: GCC governance is four things built in sequence: a board that satisfies the Companies Act and actually functions, a risk library scored into a heat map with remediation set over short, medium and long horizons, a compliance calendar that runs on statutory dates rather than good intentions, and a first hundred days that installs all three before the operation gets busy. The statutory floor is specific: a private company needs a minimum of two directors, at least one resident in India for 182 days, a first board meeting within 30 days of incorporation, and four meetings a year with no more than 120 days between them. Most GCCs clear that floor and still govern badly, because the floor is not the blueprint.

Why GCC Governance Fails Before It Starts

Financial governance starts with top management reiterating that governance matters, and then walking the talk by investing in processes and systems. Governance is not a side hustle.

Many parent boards get this wrong in a specific way. They assume growth is the only real responsibility, and that somebody else in the team will quietly keep building the processes and systems. The other mistake I see constantly is the unstated, and therefore untested, assumption that processes and systems will make the company bureaucratic. It is entirely possible to build agile processes that are catalytic for the plan rather than a drag on it.

A new GCC is the cheapest moment you will ever get to build them, because there is no legacy to unwind. It is also the moment they are most likely to be deferred, because the entity is small, everyone is busy hiring, and the compliance calendar looks like something the company secretary will handle. Eighteen months later the centre has 200 people, a global mandate, and a governance structure designed for a startup that no longer exists.

The GCCs that get this right treat governance as part of the build, not a follow-on workstream. That is also why we cover it during GCC setup rather than after it.

Board Design: What the Companies Act Actually Requires

Start with the statutory floor, because it is precise and non-negotiable, and because several items on it have clocks attached.

Requirement What the Act says Where it bites
Minimum directors Two for a private company, three for a public company, maximum fifteen unless increased by special resolution Two is a floor, not a design. A two-person board of the parent’s CFO and one nominee has no independent challenge in it
Resident director At least one director who has stayed in India for not less than 182 days during the financial year, applied proportionately in the year of incorporation The most common cause of delayed incorporation for first-time entrants, because parents discover it after filing has begun
First board meeting Within 30 days of the date of incorporation Runs from incorporation, not from the day operations start
Meeting cadence Minimum four meetings a year, with not more than 120 days between two consecutive meetings The 120-day gap is the binding constraint, not the count of four
Notice Not less than seven days’ written notice to every director at their registered address Applies to every director, interested or not
Quorum One-third of total strength or two directors, whichever is higher On a two-person board, both must attend. Every meeting. That is a fragile design
Minutes Recorded and signed within the prescribed period The audit trail that proves the board functioned, not just met

Three design points that sit above the floor and matter more than it.

Two directors is a compliance answer, not a governance answer. A board that consists of the parent’s finance lead and a nominee has nobody whose job is to ask the uncomfortable question. For a GCC that will hold IP and take a global mandate, build in at least one director whose remit is oversight rather than delivery, well before the entity is large enough to require it.

The resident director is a governance role, not a formality. Companies frequently fill this requirement with whoever is available and resident. That person carries directors’ duties and personal liability under Indian law. Choose them as you would choose a director, because that is what they are.

Know your company’s status, and get advice on it. A private company that is a subsidiary of a public company is deemed a public company under the proviso to Section 2(71), which brings a materially heavier compliance load. Whether that deeming applies when the parent is a foreign company is genuinely unsettled. The prevailing professional view is that it does not, because the 2013 Act dropped the equivalent of Section 4(7) of the 1956 Act, but the drafting leaves room for the opposite reading through the definition of “body corporate”. This is not a question to answer by assumption. Get a written opinion during setup and put it in the board file.

The Risk Library and the Heat Map

This is the part most GCC governance discussions skip entirely, and it is the part that does the actual work. It is also, in my experience, the most transferable thing about implementing SOX processes for multinationals: you learn to build a risk library, translate it into heat maps, and think through remediation across short, medium and long time periods.

A risk library is a structured inventory of everything that could materially go wrong, owned by a named person, scored consistently, and reviewed on a cadence. It is not a spreadsheet of worries. The discipline is in four steps.

Step one: build the library by domain, not by anxiety. For a GCC the domains are reasonably standard: statutory and regulatory compliance, financial reporting and controls, transfer pricing and tax, people and labour compliance, data protection and information security, business continuity, third-party and vendor risk, and IP protection. Enumerate within each domain rather than brainstorming at large, or you will end up with forty versions of “attrition” and nothing on entity compliance.

Step two: score on likelihood and impact, and use one scale. The value of a heat map comes entirely from consistency. If different owners score on different scales, the map is decoration. Fix the scale first, then populate.

Step three: assign a single named owner to each risk. Not a function. A person. A risk owned by “Finance” is owned by nobody, which is the same failure that makes fragmented order-to-cash processes expensive.

Step four, the one that separates a real risk library from a compliance artefact: set remediation over three horizons.

Horizon What goes here Example for a new GCC
Short term (0–3 months) Containment. Things that stop the bleeding or close an exposure now Appoint the resident director; register under the OSH Code; file the FLA return
Medium term (3–12 months) Structural fixes. Building the process or control that prevents recurrence Design the delegation of authority; implement the compliance calendar with owners; stand up internal financial controls
Long term (12 months+) Capability. The thing that makes the risk structurally smaller Build a second-line assurance function; mature internal audit; embed control ownership in the operating model

Most risk registers only ever populate the short-term column, which is why they read as a to-do list and get treated as one. The three-horizon split forces the board to distinguish between a problem you are containing and a problem you are actually solving. That distinction is the point of the exercise.

Review the library quarterly at the board, not annually at audit. A risk library that surfaces once a year is a document. One that drives a quarterly board conversation is a control.

The GCC Compliance Calendar

Compliance failures in new entities are rarely failures of intent. They are failures of calendar ownership. Here is the recurring set for a foreign-owned Indian GCC, with the items most often missed marked.

Company law (annual)

Obligation Timing
Annual General Meeting Within six months of financial year end
First auditor appointment By the board, within 30 days of incorporation
Form ADT-1, auditor intimation Within 15 days of the AGM
Form AOC-4, financial statements Within 30 days of the AGM
Form MGT-7 / MGT-7A, annual return Within 60 days of the AGM
DIR-3 KYC, every director holding a DIN Annually, by 30 September
Board meetings Four a year, maximum 120-day gap

Late filing of AOC-4 and MGT-7 attracts a per-day additional fee with no upper cap, and sustained default across three consecutive years exposes directors to disqualification under Section 164(2). The absence of a cap is the part boards underestimate: the cost of forgetting compounds indefinitely.

FEMA and RBI (the one foreign-owned entities miss)

The Annual Return on Foreign Liabilities and Assets is due by 15 July every year, filed on the RBI’s FLAIR portal, and the obligation is triggered by outstanding foreign investment on the balance sheet at 31 March, not by any transaction during the year. A quiet year does not remove it. If the audit is not complete, file provisional figures by 15 July and revise with audited figures by 30 September; waiting for audited accounts is itself the violation. Late filing carries a submission fee and is treated as a FEMA contravention.

Also in this bucket: capital instruments must be issued within 60 days of the inward remittance, with the consideration refundable within 15 days if they are not.

Tax. Corporate return, tax audit where applicable, TDS, GST, and the safe harbour election under the Income-tax Rules, 2026, which is a first-year decision that sets the margin the entity runs on. Transfer pricing documentation and the accountant’s report are required whether or not safe harbour is elected.

Labour. Registration under the OSH Code within 60 days of the establishment’s existence, appointment letters from the first hire, EPF at 20 employees, ESI at 10, a Grievance Redressal Committee at 20 workers, a crèche above 50, and the prescribed registers and displays under the four Labour Codes. The wage definition also drives your statutory cost base, so it belongs in the finance review, not only in HR’s.

PoSH. Constitute the Internal Committee. This is a day-one obligation, not a headcount-triggered one, and it is among the most commonly deferred.

The calendar itself matters less than one thing: every line needs a named owner and a named reviewer. A calendar owned by “the CS firm” is a calendar nobody in the business is watching.

The First 100 Days

Sequence matters, because several of these unlock the others.

Days 1–30: constitute and register.
Hold the first board meeting within 30 days of incorporation. Appoint the first auditor. Confirm the resident director is genuinely resident and understands the role. Adopt the delegation of authority, so people know what they can sign before they need to sign it. Begin OSH Code registration. Constitute the PoSH Internal Committee. Get the written opinion on company status.

Days 31–60: install the spine.
Build the first version of the risk library, scored, owned and heat-mapped. Publish the compliance calendar with named owners and reviewers. Fix the salary architecture against the Code on Wages definition before offers go out, because restructuring compensation after acceptance is a trust problem rather than a payroll one. Settle the transfer pricing position, since it determines the budget the centre actually runs on. Confirm the statutory registers are being maintained from day one rather than reconstructed later.

Days 61–100: prove it works.
Run the second board meeting on a real agenda, not a ratification list. Review the risk library at that meeting and move at least one item across a horizon. Close the first month-end properly, because the first close sets the standard everyone else will meet. Test one control end to end. Agree the reporting pack the parent will actually receive, and the date it lands.

By day 100 the test is simple: can a new director read the board file and understand what the entity does, what could go wrong, who owns each of those things, and what is being done about them? If not, you have a company, not a governed one.

Frequently asked questions

What governance structure should a new GCC in India have?
At minimum, a board satisfying the Companies Act: two directors for a private company, at least one resident in India for 182 days in the financial year, a first board meeting within 30 days of incorporation, and four meetings a year with no more than 120 days between consecutive meetings. Above that floor, a functioning GCC governance structure needs a delegation of authority, a risk library with named owners reviewed quarterly, a compliance calendar with owners and reviewers, and a defined reporting pack to the parent. Two directors satisfies the law; it does not create oversight.
How many board meetings must an Indian GCC hold?
Four a year, with a maximum gap of 120 days between two consecutive meetings, and the first within 30 days of incorporation. Notice of at least seven days must go to every director. Quorum is one-third of total strength or two directors, whichever is higher, which means that on a two-director board every meeting requires both.
Does a GCC need a resident director in India?
Yes. Every company must have at least one director who has stayed in India for not less than 182 days during the financial year, applied proportionately in the year of incorporation. For first-time entrants with no India presence this is frequently the item that delays incorporation, because it is discovered after filing has begun. Treat the appointment as a governance decision: the person carries directors’ duties and personal liability under Indian law.
What is a risk library and how does a GCC build one?
A risk library is a structured inventory of material risks organised by domain, scored on a single consistent likelihood-and-impact scale, each with one named owner, and reviewed on a cadence. For a GCC the domains typically cover statutory compliance, financial reporting and controls, tax and transfer pricing, people and labour, data protection and information security, business continuity, third-party risk and IP. The step that makes it useful is setting remediation across three horizons, short term for containment, medium term for structural fixes, long term for capability, so the board can tell the difference between a risk being contained and one being solved.
What are the annual compliance filings for a foreign-owned GCC in India?
Company law: AGM within six months of year end, ADT-1 within 15 days of the AGM, AOC-4 within 30 days, MGT-7 within 60 days, and DIR-3 KYC by 30 September. FEMA: the Annual Return on Foreign Liabilities and Assets by 15 July, triggered by outstanding foreign investment at 31 March regardless of whether anything happened that year. Plus corporate tax and transfer pricing documentation, GST and TDS, and the labour obligations under the four Codes. The FLA return is the one foreign-owned entities most commonly miss.

What This Comes Down To

Revenue and culture do not guarantee governance. A GCC can be hiring well, delivering well and reporting green to the parent while its statutory registers are incomplete, its FLA return is late and its risk library exists only as a slide in a deck from setup.

Great execution is thinking at the macro level and executing at the micro level. The board, the risk library, the calendar and the first hundred days are the macro. The 30-day first board meeting, the 120-day gap, the FLA return filed on provisional figures rather than waited on, the risk that moved from short-term containment to a medium-term fix because someone owned it: that is the micro. Both, or neither.

How Astravise Services Approaches GCC Governance

Astravise Services builds governance into the GCC setup rather than bolting it on, because the cheapest moment to install agile, catalytic processes is before there is anything to unwind. Our GCC Value Framework, powered by A.C.T.I.O.N., works across strategic alignment, operating model and cross-functional governance, compliance and risk, talent, legal and financial protection, and decision intelligence.

That work sits alongside Strategic CFO and Strategic CHRO capability and Agile Shared Services, because a GCC board oversees finance, people and operations arriving simultaneously, and no single adviser can cover all three. We built a GCC in Hyderabad for a US-listed logistics company covering entity setup, governance and compliance alongside functional support in HR, finance and recruitment, for exactly that reason.

Pressure-test your operating model with the GCC Compass, or talk to us about a governance diagnostic for an existing centre.

[1][2][3][4][5][6][7][8]

Sources

  1. ca2013.com
  2. ca2013.com
  3. taxmann.com
  4. indiacorplaw.in
  5. lexology.com
  6. taxguru.in
  7. labour.gov.in
  8. vstnconsultancy.com