Lead with clarity. Operate with truth.
Pierag Consulting is a global consulting firm with a unique business model that blends domestic proficiency with global expertise to serve clients globally. As a consulting organization, our expertise spans across various industries, allowing us to provide tailored solutions that address the unique challenges organizations face.
Our Philosophy
Rethink the Frame
Thinking Beyond the Box
+
We challenge conventional boundaries, bringing fresh perspectives and bold ideas that redefine how businesses solve problems and capture opportunities.
01
Always Heading Upwards
+
Growth is our constant direction. With every engagement, we aim to elevate performance, strengthen resilience, and create long-term impact for our clients.
02
A Multidimensional Approach
+
We bring together diverse expertise, data-driven insights, and human-centered thinking to design solutions that are practical, holistic, and future-ready.
03
Thinking Beyond the Box
+
We challenge conventional boundaries, bringing fresh perspectives and bold ideas that redefine how businesses solve problems and capture opportunities.
01
Always Heading Upwards
+
Growth is our constant direction. With every engagement, we aim to elevate performance, strengthen resilience, and create long-term impact for our clients.
02
A Multidimensional Approach
+
We bring together diverse expertise, data-driven insights, and human-centered thinking to design solutions that are practical, holistic, and future-ready.
03
Thinking Beyond the Box
+
We challenge conventional boundaries, bringing fresh perspectives and bold ideas that redefine how businesses solve problems and capture opportunities.
01
Always Heading Upwards
+
Growth is our constant direction. With every engagement, we aim to elevate performance, strengthen resilience, and create long-term impact for our clients.
02
A Multidimensional Approach
+
We bring together diverse expertise, data-driven insights, and human-centered thinking to design solutions that are practical, holistic, and future-ready.
03
Our Insights
Real Problems, Real Thinking
How Did ESG Reporting in India Reach This Point? India's ESG reporting journey has been defined by progressive regulatory intent. For over a decade, listed companies were expected to report on their business responsibility practices, but the framework remained largely narrative and discretionary. Structured, comparable, and independently verified ESG data was the exception, not the norm.  The inflection point came in 2021, when the Securities and Exchange Board of India (SEBI) replaced the Business Responsibility Report (BRR) with the Business Responsibility and Sustainability Report (BRSR), mandating it for the top 1,000 listed entities from FY2022-23. For the first time, sustainability disclosures had standardised metrics, defined principles, and measurable KPIs.  However, standardisation alone did not resolve the credibility question. Disclosed data, however well structured, remained unverified. Investors, lenders, and regulators increasingly demanded that ESG metrics carry the same evidentiary weight as financial figures. That demand gave rise to BRSR Core and, with it, the requirement for independent assurance on a defined set of key ESG performance indicators  under 9 ESG attributes  It is within this context that BRSR Core assurance emerges as the next phase in India's ESG evolution, a shift from reporting intent to validated performance. For companies now falling within SEBI’s phased assurance thresholds , the question is no longer whether to engage with assurance, but how to build systems that can sustain it. This transition is accelerating demand for credible BRSR assurance services in India.  What Is BRSR Core? Understanding the Framework BRSR Core is a focused subset of the broader BRSR framework, built around a specific set of decision-relevant ESG metrics that are standardised enough for independent verification. While the full BRSR covers a wide range of qualitative and quantitative disclosures, BRSR Core narrows the scope to high-impact, comparable indicators supported by standardized intensity ratios and other verifiable metrics across environmental, social, and governance dimensions.  Structurally, BRSR Core covers nine ESG attributes identified by SEBI as critical for comparability and assurance . These attributes span environmental, social, and governance dimensions, including:  Greenhouse gas footprint (Scope 1 and Scope 2)  Energy footprint  Water footprint  Embracing circularity - details related to waste management by the entity  Enabling Gender Diversity in Business  Enhancing Employee Wellbeing and Safety  Enabling Inclusive Development  Fairness in Engaging with Customers and Suppliers  Open-ness of business  Together, the KPIs under these attributes form the audit-ready core of India's ESG reporting architecture. The SEBI circular SEBI/HO/CFD/CFD-SEC-2/P/CIR/2023/122 issued on 12 July 2023 formally established this framework and introduced the phased mandatory assurance schedule.  What Is the Phased Rollout Timeline? SEBI has implemented BRSR Core assurance requirements progressively, based on market capitalisation. The complete phased schedule is as follows:  FY2023-24: Top 150 listed entities  FY2024-25: Top 250 listed entities  FY2025-26: Top 500 listed entities   FY2026-27: Top 1,000 listed entities   This phased schedule means that companies entering scope in any given year must be prepared for assurance before the close of their reporting period. For example, companies ranked between 251 and 500 face their first year of mandatory assurance in FY2025-26,  requiring  scoping of engagements, assessment of internal controls , and readiness evaluation well before the reporting cycle concludes on 31 March .  A critical dimension that is often underestimated: from FY2026-27, the top 250 companies are also required to obtain assurance on value chain ESG disclosures on voluntary basis, covering upstream suppliers and downstream distributors.   Why Does the Move to Assurance Matter?Why Does the Move to Assurance Matter? The shift from disclosure to assurance is not administrative. It represents a structural change in how ESG data is produced, governed, and evaluated.  Historically, sustainability disclosures relied on internally reported figures with no external validation. This improved transparency but left open questions around accuracy, comparability, and the risk of greenwashing. Boards and investors had no independent basis for trusting the numbers.  BRSR Core assurance directly addresses this by introducing independent verification of ESG metrics. Unlike certification, which delivers a pass-or-fail outcome, assurance provides a professional opinion on the reliability of disclosures, based on evidence-backed evaluation of data, processes, and controls.  ESG data is now actively used in investment decisions, lending assessments, credit ratings, and regulatory risk analysis. As a result, its credibility has become as important as its availability. For companies, this changes the nature of ESG reporting entirely. It is no longer sufficient to disclose data. Organisations must now ensure that data is traceable, consistent, and verifiable.  What Changes in Practice for Companies? The introduction of BRSR Core assurance materially changes how ESG data is prepared, governed, and reviewed within organisations.  Central to this transition is SEBI’s requirement that companies obtain  assurance of their BRSR Core disclosures. Reasonable assurance remains the defined benchmark and represents a notably high standard. Unlike limited assurance, which relies on analytical review and plausibility checks, reasonable assurance involves detailed testing of underlying data, validation of calculation methodologies, assessment of internal control systems, and sampling across business units and sites.  This brings ESG reporting closer in rigour to financial audits. Companies must maintain clear evidence trails for all BRSR Core KPIs, supported by documentation, defined methodologies, and controlled processes. Data that was previously collated at year-end must now be tracked and validated continuously throughout the reporting cycle.  In parallel, ESG reporting is becoming more integrated with financial reporting systems, requiring closer coordination between sustainability, finance, and compliance functions. For many organisations, this represents a transition from fragmented, spreadsheet-driven practices to a more governed and traceable data environment. This shift is accelerating engagement with structured BRSR assurance services in India to support readiness, gap assessment, and validation.  How Does a BRSR Core Assurance Engagement Work? From a consulting and implementation standpoint, BRSR assurance follows a structured methodology grounded in established standards.  The engagement begins with defining the scope, including reporting boundaries, and the assurance level to be applied. A detailed planning phase follows, in which assurers assess risks associated with data accuracy, internal controls, and reporting processes.  The core of the engagement is data verification and testing. This involves validating disclosed figures against source records, reviewing calculation methodologies and underlying assumptions, and performing sampling across business units or plant locations. Assurers also evaluate the effectiveness of internal controls, including standard operating procedures, approval workflows, and data validation mechanisms.  Gaps and inconsistencies are documented, management responses are assessed, and the engagement concludes with the issuance of an assurance statement, which reflects the assurer's independent opinion on the reliability of the BRSR Core disclosures.  The key insight this process surfaces: assurance does not simply verify numbers. It evaluates the systems and processes that generate those numbers. A disclosure that appears complete but lacks supporting evidence may not withstand scrutiny. Conversely, a disclosure that acknowledges limitations but is supported by clear methodologies and documented controls is often more defensible.  Who Drives Assurance Readiness Internally? BRSR Core assurance is an organisation-wide responsibility, not a standalone ESG activity. Multiple functions must coordinate to produce and sustain audit-ready disclosures.  Board and senior management: oversight, accountability, and tone at the top  ESG and sustainability function: process coordination and KPI ownership  HR, operations, procurement, and finance: data generation and underlying records  Plant and unit teams: source-level documentation and evidence maintenance  Internal audit: reliability checks, control testing, and assurance readiness  Technology teams: data traceability, system integration, and automated validation  Company Secretary: regulatory alignment with SEBI requirements and statutory filings  This multi-layered involvement underscores the need for clearly defined ownership, documented processes, and coordinated governance. Where these elements are absent, even complete-looking data will struggle under assurance.  Which Standards and Frameworks Govern BRSR Core Assurance? BRSR Core assurance draws on a combination of globally recognised standards, which provide structure and consistency to engagement methodologies.  ISAE 3000 (revised): The primary international standard for non-financial assurance, widely used in audit-led BRSR engagements  AA1000AS: Adds a stakeholder-centric dimension, focusing on materiality, completeness, and responsiveness  ISSA 5000: An emerging global standard expected to progressively harmonise sustainability assurance practices  ISAE 3410: Assurance engagements on GHG statements  Indian Standards: SSAE 3000 (Assurance  on sustainability information) and SAE 3410 (Assurance  on GHG statements)  In practice, assurance engagements often draw on multiple standards simultaneously to balance technical rigour with stakeholder relevance. The choice of standards is typically agreed between the organisation and the assurance provider during the scoping phase.  What Are the Operational Challenges for Companies Under BRSR Core Assurance? As the BRSR Core assurance requirement expands across companies in SEBI’s phased rollout, the operational implications are significant and varied.  Many companies continue to rely on manual processes and spreadsheets for ESG data collection, which creates challenges under reasonable assurance. Data gaps, inconsistent methodologies across sites, and weak evidence trails are among the most common issues surfaced during assurance engagements. As a result, there is a growing demand for technology-enabled ESG reporting platforms that provide data traceability, automated validation, and audit-ready documentation.  Complex measurement areas, including Scope 1 and Scope 2 emissions calculations, water intensity metrics, and social indicators such as workforce diversity ratios and wage data, add further challenges. These often require coordination with third-party data sources, HR systems, and operational databases, increasing the need for structured data governance.  For companies entering the assurance requirement for the first time, the most common mistakes include treating assurance as a year-end exercise, underestimating the evidence burden for the BRSR Core KPIs, and failing to assign clear ownership across functions. Engaging experienced BRSR assurance services in India early in the reporting cycle significantly reduces these risks.  A Practical Approach to BRSR Core Assurance Readiness Given the scale of internal change required, organisations are increasingly adopting a structured readiness approach rather than treating assurance as a one-time compliance exercise.  The starting point is an honest assessment of current reporting maturity, benchmarked against the BRSR Core KPIs. This identifies which data points are already traceable, which lack documentation, and where calculation methodologies need to be formalised.  From there, the focus shifts to strengthening governance frameworks, defining ownership across functions, and establishing standardised data collection processes. Technology implementation plays a central role at this stage, whether through dedicated ESG platforms or integration with existing ERP and HR systems.  Many organisations conduct mock assurance assessments before formal engagement, which surface evidence gaps and control weaknesses while there is still time to address them. Critically, this readiness work should be treated as an ongoing capability, not a one-time exercise. As assurance requirements expand to include value chain disclosures and new KPIs, the organisations with strong foundational systems will adapt most effectively.  Pierag's ESG and Sustainability practice supports organisations across this full readiness journey, from gap assessment and governance design through to assurance preparation, execution of BRSR Core assurance engagements, and ongoing ESG reporting.   What Does the Road Ahead Look Like? BRSR Core assurance is expected to expand in both scope and depth. A key development is the requirement for value chain disclosures by the top 250 companies, which commenced on a voluntary basis from FY 2025-26, with assurance of these disclosures applicable from FY 2026-27 on voluntary basis. This requires organisations to collect and verify ESG data from upstream suppliers and downstream distributors, a step that demands early engagement with value chain partners and robust third-party data protocols.  Regulatory scrutiny is also expected to intensify, particularly around data integrity, consistency across reporting periods, and the quality of internal controls supporting BRSR Core KPI calculations.   Globally, the convergence of sustainability assurance standards, particularly the emergence of ISSA 5000, is likely to progressively align Indian assurance practices with international frameworks, increasing comparability and investor confidence in BRSR Core disclosures.  Conclusion BRSR Core assurance marks a decisive shift in India's ESG landscape, moving from disclosure-driven reporting to system-driven validation. For companies now falling within SEBI’s phased assurance thresholds, this transition calls for more than compliance. It requires a fundamental rethinking of how ESG data is generated, governed, and verified across the organisation.  The KPIs across nine ESG attributes that form BRSR Core are not simply a reporting checklist. They are the foundation of a credible, audit-ready sustainability practice. Organisations that invest now in building robust controls, clear ownership structures, and traceable data systems will not only meet the current assurance requirement, but will be better positioned as the scope expands to value chain disclosures and the top 1,000 listed entities.  As BRSR assurance services in India continue to evolve, the focus is converging on a straightforward but critical outcome: sustainability reporting that is not only comprehensive, but credible, consistent, and defensible.  Frequently Asked Questions What is BRSR Core assurance?  BRSR Core assurance is the independent verification of a company's key ESG performance indicators under India's BRSR framework. It involves a professional assurance provider reviewing the data, processes, and controls behind  specific KPIs across nine ESG attributes and issuing an opinion on their reliability. SEBI has mandated assurance, the highest standard, for India's top listed companies on a phased schedule.  What is the difference between BRSR and BRSR Core?  BRSR is the full Business Responsibility and Sustainability Report, which covers a wide range of qualitative and quantitative ESG disclosures across nine NGRBC principles. BRSR Core is a curated subset of BRSR, focused on high-impact KPIs that are standardised and measurable enough for independent assurance. BRSR Core carries stricter requirements, including mandatory assurance for the top 1,000 listed entities in a phased manner.  What is the difference between limited assurance and reasonable assurance?  Limited assurance involves analytical review and plausibility checks, resulting in a conclusion that nothing came to the assurer's attention that would suggest the disclosures are materially misstated. Reasonable assurance,  involves a higher level of evidence gathering, including detailed data testing, sampling across sites, and internal controls assessment. It results in a positive opinion on the reliability of the disclosures.  Which companies need BRSR Core assurance in FY2026-27?  All listed entities ranked within the top 1000 by market capitalisation are required to obtain reasonable assurance on their BRSR Core disclosures for FY2026-27. This includes:   Top 150 entities, who have been subject to the requirement since FY2023 24  Companies ranked 151 to 250, who have been subject to the requirement since FY2024 25  Companies ranked 251 to 500, who entered scope in FY2025 26  Companies ranked 501 to 1,000, who are entering the assurance requirement for the first time in FY2026 27  In addition, the top 250 companies are required to provide value chain ESG disclosures on a voluntary basis, with assurance of those disclosures also applicable from FY2026 27.  What are the nine attributes of BRSR Core?  BRSR Core is structured around nine ESG attributes aligned with SEBI's nine NGRBC principles. These cover: Open-ness of business; fairness in engaging with customers and suppliers; enabling inclusive development; enabling gender diversity in business ; enhancing employee wellbeing and safety; Embracing circularity - details related to waste management by the entity; water footprint; energy footprint; and GHG footprint.    
A Defined contribution plan  audit is an independent examination of a company's retirement plan financial statements and operations, required under ERISA when a plan crosses certain participant thresholds. Plan sponsors with 100 or more eligible participants at the start of the plan year generally need an audit as part of their Form 5500 filing, performed by a qualified CPA firm independent of the plan sponsor. Audit costs typically range from a few thousand dollars for a small, straightforward plan to well over $25,000 for a large plan with multiple investment options or prior-year errors to remediate. The rest of this guide breaks down the participant-count trigger in detail, what the audit actually examines, and the factors that drive cost up or down. The 100-Participant Rule, Explained Plainly The Employee Retirement Income Security Act (ERISA) requires plans with 100 or more eligible participants at the beginning of the plan year to file as a "large plan" with the Department of Labor, which triggers the independent audit requirement attached to Form 5500. There is an important exception plan sponsors often miss: the 80-120 participant rule. If the number of participants at the beginning of the plan year is between 80 and 120, the plan may file in the same category (large or small) as it filed the prior year. This means a plan that filed as a small plan can continue to do so, without triggering the audit requirement, as long as its beginning-of-year count stays at 120 or below. This buffer exists specifically so growing companies are not forced into an audit the moment they cross 100 participants by a handful of employees. Important recent change: For plan years beginning on or after January 1, 2023, the Department of Labor changed how the 100-participant threshold is counted for defined contribution plans (such as 401(k) plans). Under the prior rule, the count included all eligible employees, whether or not they actually participated. Under the new rule, only participants with an account balance at the beginning of the plan year are counted. This is a significant change. Plans with many eligible-but-non-participating employees may now fall below 100 counted participants and avoid the large-plan audit requirement entirely. The DOL estimated the change would remove the audit requirement for roughly 20,000 defined contribution plans. The 80-120 rule still applies, but now uses this account-balance count. Any assessment of whether a plan needs an audit should use the current account-balance methodology, not the older eligible-employee count. One clarification that prevents miscounts: for defined contribution plans under the current rule, the count is participants with an account balance at the start of the plan year, which includes not just active contributing employees but also terminated or retired employees who still hold a balance in the plan. Sponsors sometimes undercount by looking only at current active contributors. For plan years before 2023, the count was broader still, including all eligible employees regardless of participation. Does Every Growing Plan Trigger an Audit Right Away? Not immediately, because of the 80-120 rule above, but the trigger becomes unavoidable once the plan consistently sits above 120 participants or the sponsor chooses to file as a large plan. A common scenario: a company hires aggressively during a growth year, crosses 100 participants by year's end, and the finance team only realizes the audit requirement applies when preparing the Form 5500 months later, leaving little time to select an auditor and gather records. This is the single most common reason plan sponsors end up paying rush fees or scrambling for an auditor close to the filing deadline. Tracking participant counts each plan year, not just at filing time, avoids this. Filing Deadline: Form 5500 is due the last day of the seventh month after the plan year ends, which is July 31 for a calendar-year plan. A one-time 2.5-month extension to October 15 is available by filing Form 5558 by the original due date. Because the audit report must be attached to a completed Form 5500, the practical deadline for finishing audit fieldwork is tighter than these dates suggest, which is why late auditor selection drives rush fees. What Does a defined contribution plan Auditor Actually Examine? A Defined contribution plan audit,  is not the same as a corporate financial statement audit, even though both result in an opinion. The auditor examines: Plan financial statements, including the statement of net assets available for benefits and changes in those net assets Participant contributions and whether they were remitted to the plan in a timely manner, a frequent source of findings Eligibility and enrollment records, confirming the plan administrator correctly applied plan terms Distributions and loans, checking that they were processed and approved according to the plan document Investment valuations, particularly for plans holding less liquid or non-standard investment options Late remittance of employee contributions is consistently one of the most common findings in EBP audits, since Department of Labor guidance treats delayed deposits as a fiduciary breach even when the delay is short and unintentional. When late remittances are identified, they are correctable. The Department of Labor’s Voluntary Fiduciary Correction Program (VFCP) lets sponsors self-correct delinquent participant contributions by depositing the missed amounts plus lost earnings, and the IRS Employee Plans Compliance Resolution System (EPCRS) covers related qualification failures. Correcting proactively, and documenting the correction, is far less costly than having the issue surface unresolved in an audit or DOL inquiry. Limited Scope Versus Full Scope: A Distinction That Changes the Audit Plan sponsors using a qualifying trustee or custodian, such as a bank or insurance company that certifies investment information, can elect a limited scope audit, where the auditor does not independently verify the certified investment data. A full scope audit requires the auditor to test investment valuations directly, which generally takes more time and costs more. The AICPA  (through SAS 136) has moved away from the term "limited scope" toward "ERISA Section 103(a)(3)(C) audit" under newer auditing standards, but the practical distinction for plan sponsors remains the same: a certified-investment election narrows what the auditor needs to independently test, which affects both audit duration and fee. What Drives the Cost of a ndefined contribution plan Audit? Audit fees vary based on several factors that plan sponsors can usually identify before requesting a proposal: Plan size and complexity: A plan with a single recordkeeper and standard mutual fund investments costs less to audit than one with multiple investment platforms, company stock, or alternative investments. First-year audit versus repeat engagement: A first-time EBP audit typically costs more because the auditor has no prior-year workpapers to build from and needs to understand plan documents and processes from scratch. Audit scope election: A full scope audit, where investment valuations are tested directly rather than relying on trustee certification, generally costs more than a limited scope or Section 103(a)(3)(C) audit. Quality of plan recordkeeping: Plans with clean, well-organized census data, timely contribution records, and an updated plan document typically move through audit fieldwork faster than plans with scattered records across multiple systems or providers. Findings requiring remediation: If the audit uncovers issues like late contribution remittances or eligibility errors, additional time goes into documenting these findings and advising on correction, which adds to the overall fee. For most mid-sized plans, audit fees commonly fall somewhere between $8,000 and $18,000 annually, though this range shifts meaningfully based on the factors above, and sponsors should treat any quote received without a plan census and prior Form 5500 review as a rough estimate at best. What Happens If a Required Audit Is Skipped or Filed Late? Form 5500 filings missing a required audit report, or filed with a qualified or adverse audit opinion that isn't resolved, draw attention from the Department of Labor. The DOL has run targeted enforcement initiatives specifically focused on EBP audit quality, since deficient audits were found across a meaningful share of CPA firms performing this niche audit type in past DOL studies. Selecting a CPA firm with specific Employee Benefit Plan audit experience, rather than a general practice firm doing one occasionally, reduces this exposure. Plan sponsors are personally responsible as fiduciaries for selecting a qualified auditor, so this is not a decision that can be delegated entirely to a recordkeeper or third-party administrator without sponsor oversight. The financial exposure is concrete. Under ERISA Section 502(c)(2), the DOL can assess a civil penalty of up to $2,739 per day, with no maximum, for a late or incomplete Form 5500, and the IRS can separately assess up to $250 per day (capped at $150,000 per plan year). These are two distinct penalties for the same late filing. Sponsors who discover a delinquency before the DOL contacts them can use the Delinquent Filer Voluntary Compliance Program (DFVCP), which caps the penalty at a substantially reduced amount, typically in the range of a few hundred to a few thousand dollars per filing. Where CPA Outsourcing Fits Into This Picture Many CPA firms handling EBP audits face the same constraint every audit season: a narrow filing window, a shortage of staff with EBP-specific training, and a workload that spikes sharply around the same few months. Outsourcing the fieldwork-heavy, repetitive portions of an EBP audit, like testing contribution remittance timing, distribution sampling, and census data reconciliation, to a dedicated outsourcing partner lets the engagement partner focus on judgment-heavy areas and final review. This is the core of what our Assurance & CPA Outsourcing practice supports for US CPA firms: structured EBP audit fieldwork support that follows the engagement partner's methodology and review standards, rather than a generic offshore staffing arrangement. How Pierag Consulting Supports CPA Firms and Plan Sponsors Pierag Consulting works with US CPA firms on Employee Benefit Plan audit fieldwork, financial statement audit support, and compilation engagements through structured CPA outsourcing arrangements. This includes contribution testing, census data reconciliation, and workpaper preparation aligned to the engaging firm's own audit methodology and review process. Frequently Asked Questions How many participants trigger a mandatory defined contribution plan audit? A plan generally needs an audit once it has 100 or more eligible participants at the start of the plan year, though the 80-120 participant rule allows a one-year buffer for plans growing past the 100 mark for the first time. What is the difference between a limited scope and a full scope defined contribution plan audit? A limited scope audit, now often called a Section 103(a)(3)(C) audit, relies on a qualifying trustee's certification of investment data rather than independent testing. A full scope audit requires the auditor to independently verify investment valuations, which generally increases cost and fieldwork time. Why do defined contribution plan audits often find issues with contribution timing? The Department of Labor treats delayed remittance of employee contributions as a fiduciary breach, even for short delays. This is one of the most frequently cited findings in EBP audits because many plan sponsors do not have a documented, consistent remittance timeline. Does a first-year define contribution plan audit cost more than a repeat audit? Yes, typically. A first-year audit requires the auditor to build an understanding of plan documents, processes, and prior history from scratch, since there are no prior-year workpapers to reference, which generally increases the time and cost involved. Who is responsible for selecting a qualified defined contribution plan auditor? The plan sponsor, acting as a fiduciary, is responsible for selecting a qualified, independent auditor. This responsibility cannot be fully delegated to a recordkeeper or third-party administrator without sponsor oversight.
An Employee Benefit Plan (EBP) audit is an independent examination of a retirement or welfare benefit plan's financial statements and operations, required under ERISA for plans with 100 or more eligible participants, and the audit only goes smoothly when every party involved, the plan sponsor, the recordkeeper, HR and payroll, and the auditor, understands exactly what they are responsible for. Most plan sponsors only interact with this process once a year, which is exactly why confusion about who provides what tends to slow the audit down. This guide organizes the entire process by responsibility, not by audit phase, so plan sponsors know precisely what to prepare and who to ask when something is missing. The plan sponsor bears ultimate fiduciary responsibility for the audit's quality, even though much of the work is performed by other parties. Understanding where that responsibility actually sits is the foundation of everything else in this guide. What the Plan Sponsor Is Responsible For The plan sponsor, typically the employer offering the plan, is legally responsible for selecting a qualified, independent auditor and for the overall integrity of the audit process, even when most of the day-to-day coordination is handled by HR, finance, or an outsourced administrator. This responsibility cannot be fully delegated. The Department of Labor has been explicit that fiduciaries who hire an unqualified auditor, or who fail to review the auditor's qualifications and the final report, can be held responsible for resulting deficiencies. Practically, this means the plan sponsor should review the auditor's specific EBP audit experience before engagement, not just their general audit credentials, since a CPA firm with strong general audit experience but limited EBP-specific volume is statistically more likely to produce a deficient audit according to past Department of Labor studies on audit quality across the profession. The plan sponsor should also personally review the final audit report and any management letter before it is filed with Form 5500, rather than treating the auditor's sign-off as the final step requiring no further sponsor involvement. What the Recordkeeper or Third-Party Administrator Handles The recordkeeper or third-party administrator (TPA) maintains the plan's transactional records: contributions received, distributions processed, loan activity, and investment transactions. During an audit, the recordkeeper typically provides the trust statements, transaction detail reports, and participant-level data the auditor needs to test against the plan's records. A common friction point is timing: recordkeepers often have a standard turnaround time for producing audit-specific reports, and if the plan sponsor does not request these reports early in the audit cycle, the recordkeeper's response time becomes the bottleneck that delays the entire engagement. Plan sponsors working with a recordkeeper for the first time, or going through a recordkeeper transition during the plan year, should flag this early, since a mid-year recordkeeper change typically requires reconciling data from two separate systems for the audit period. One responsibility that is easy to overlook sits at the boundary between the recordkeeper and the sponsor: the SOC 1 (System and Organization Controls 1) report. The recordkeeper should provide a SOC 1 report describing the controls at its service organization, which the auditor uses to assess those controls rather than testing them from scratch. That report also lists complementary user entity controls (CUECs), the control activities the plan sponsor is expected to perform on its side depending on the applicability of CUEC. Confirming those user entity controls are actually in place is the sponsor’s responsibility, and a gap here can create a finding even when the recordkeeper’s own controls are sound. What HR and Payroll Need to Prepare HR and payroll functions own the data that connects employee status to plan eligibility: hire dates, termination dates, compensation used for plan contribution calculations, and eligibility determinations. Auditors test a sample of employees against this data to confirm that the plan correctly applied its own eligibility and contribution rules, which means inconsistent or incomplete personnel records create audit findings even when the retirement plan itself was administered correctly. The most frequent issue in this category is a mismatch between the compensation definition used for payroll purposes and the compensation definition specified in the plan document, particularly when bonuses, overtime, or other variable pay components are excluded from contribution calculations inconsistently across employees. Reconciling payroll's compensation definition against the plan document before the audit begins, rather than during fieldwork, avoids a finding that otherwise takes considerable back-and-forth to resolve and document. A practical way to compress the timeline is to assemble the standard audit request list before fieldwork begins. Auditors typically need: the signed plan document and all amendments, the current SOC 1 report from the recordkeeper, trust and custodial statements, the year-end census file, payroll registers reconciled to the plan’s compensation definition, contribution remittance records showing deposit dates, distribution and loan documentation, and the draft Form 5500. Having these ready in one place, reconciled, is the single biggest factor in how smoothly the audit runs. What the Auditor Actually Tests During Fieldwork The auditor's fieldwork centers on five core areas: plan financial statement balances, contribution testing, including timeliness of remittance, distribution and loan testing against plan document terms, eligibility and enrollment testing, and investment valuation, with the depth of investment testing depending on whether the engagement is an  ERISA Section 103(a)(3)(C) audit (Formerly know as limited scope) or Non-ERISA Section 103(a)(3)(C) audit (Formerly known as full scope audit). Contribution remittance timing deserves specific attention because it is consistently one of the most cited findings in EBP audits nationally. The Department of Labor's guidance treats delayed deposit of employee contributions withheld from payroll as a fiduciary breach, and auditors are required to test the actual time elapsed between withholding and deposit against the plan's established remittance pattern, not against a generic regulatory deadline. Plan sponsors who do not have a documented, consistent remittance schedule make this testing area harder to clear cleanly. What Happens After the Audit Report Is Issued The signed audit report and the auditor's opinion are attached to Form 5500 as part of the annual filing. If the auditor issues a qualified, adverse, or disclaimed opinion, or if a management letter identifies operational deficiencies, the plan sponsor needs a documented plan for addressing those findings before the next audit cycle, since unresolved findings carried forward year after year tend to draw additional regulatory scrutiny. Plan sponsors should also use this period to review whether the audit process itself ran efficiently. If specific data requests took unusually long to fulfill, or if the same finding keeps recurring, that is the signal to fix the underlying process, whether it is a payroll reconciliation gap or a recordkeeper reporting delay, well before the next plan year closes, rather than waiting until the next audit surfaces it again. A note for plans undergoing their first audit: a first-year engagement generally requires the auditor to establish that the opening balances are fairly stated, which can mean additional procedures over the prior period that was never audited. This is a common surprise for sponsors and is part of why a first-year audit typically takes more time and costs more than a recurring one. Flagging a first-year plan to the auditor early lets both sides plan for this. Common Fiduciary Mistakes That Lead to DOL Attention A few patterns show up repeatedly in plans that draw additional Department of Labor scrutiny. Hiring an auditor based primarily on price rather than EBP-specific experience is one of the most consequential, since the Department of Labor has specifically flagged audit quality variance tied to how much EBP audit volume a given CPA firm actually handles. Treating the 80-120 participant rule as a permanent exemption rather than a one-time buffer is another, where sponsors assume they remain a small plan indefinitely after using the exception once. Failing to document a consistent contribution remittance schedule and not reviewing the final audit report personally before filing rounds out the most common patterns. None of these mistakes is about dishonesty. They are almost always about treating the audit as an annual compliance task handled entirely by someone else, rather than a fiduciary responsibility the plan sponsor needs to stay actively engaged with. Where CPA Firms Can Get Outsourcing Support for EBP Audit Fieldwork For CPA firms performing these audits, the fieldwork-heavy testing areas described above, contribution remittance testing, distribution sampling, census data reconciliation, and workpaper preparation, are well-suited to structured outsourcing support, particularly during the concentrated filing season when EBP audit volume spikes sharply. This lets the engagement partner focus review time on judgment calls, like evaluating the severity of an exception or assessing investment valuation methodology, rather than the repetitive testing work that consumes most of an EBP engagement's hours. This is the core of what our Assurance & CPA Outsourcing practice supports for US CPA firms managing EBP audit engagements, working within the engaging firm's own methodology and review standards rather than as a generic offshore staffing arrangement. Frequently Asked Questions Who is legally responsible for the quality of an Employee Benefit Plan audit? The plan sponsor, acting as a fiduciary, is responsible for selecting a qualified auditor and reviewing the final audit report, even though the recordkeeper, payroll, and the auditor each handle specific pieces of the process. What is the most common finding in Employee Benefit Plan audits? Delayed remittance of employee contributions withheld from payroll is one of the most frequently cited findings, since the Department of Labor treats inconsistent or delayed deposit timing as a fiduciary breach regardless of intent. Why do payroll records matter so much in an EBP audit? Auditors test employee eligibility and contribution calculations against payroll and HR data. A mismatch between the plan document's compensation definition and how payroll actually calculates contributions creates findings even if the retirement plan itself was administered correctly. What should a plan sponsor do if the auditor issues a qualified or adverse opinion? The plan sponsor needs a documented remediation plan addressing the underlying issue before the next audit cycle, since unresolved findings carried forward year after year tend to draw additional regulatory attention. Can a CPA firm outsource parts of an Employee Benefit Plan audit? Yes. Fieldwork-heavy testing areas like contribution testing, distribution sampling, and workpaper preparation are commonly outsourced to specialized support teams working within the engaging firm's methodology, letting the engagement partner focus on judgment-heavy review work.
In Brief Following a large acquisition, the client inherited 2,000+ unstructured Vendor Service Level Agreements across a highly regulated industry with no visibility into what they contained or what risk they carried Pierag deployed SmartXtract's contract analysis agent: a customised, AI-enabled workflow combining automated data extraction, human expert validation and live data visualisation Planned review time reduced by over 60%. The client gained full portfolio visibility and new strategic capabilities across vendor negotiation, benchmarking and risk management. The Situation When a large enterprise acquires a business entity, it also acquires everything that business has signed. In this case, that meant over 2,000 Vendor Service Level Agreements — unstructured in format, scattered across repositories, and never comprehensively reviewed. Operating in a highly regulated industry made this more than an operational headache. Outdated or expired contracts, non-compliant contractual terms, buried penalty clauses, rebate entitlements, and auto-renewal provisions created significant legal, regulatory, and financial exposure. With no central repository or common taxonomy, and contracts written in highly specialised industry language, the legal and procurement teams had no practical starting point. Manual review was not a viable option. The volume was too large, the timeline too short, and the cost of a missed clause too high. The Challenge The Approach Pierag deployed SmartXtract's contract analysis agent configured for the client's industry and contract portfolio through a six-step workflow designed to move every agreement from unstructured document to structured, actionable intelligence. 01 · Secure Contract Upload All agreements ingested through a secure layer with full data confidentiality and audit traceability from day one. 02 · AI-Enabled Data Extraction Proprietary models extracted and classified key fields across all agreements simultaneously - parties, term dates, Service Level Agreement obligations, penalty clauses, rebate terms, renewal conditions and niche industry-specific terminology. 03 · Human-in-the-Loop Review Complex and ambiguous clauses routed to subject-matter experts ensuring accuracy where contractual nuance cannot be left to pattern recognition alone. 04 · Automated Dual-Model Validation Every output cross-checked for consistency and completeness. Exceptions flagged before results moved forward. 05 · Data Protection The tool was built on a stateless architecture ensuring no data left the client’s system during processing. 06 · Standardised Output All contract data delivered in a uniform, structured format ready for immediate integration into legal, procurement and finance workflows. 07 · Data Visualisation Extracted insights surfaced through a live dashboard giving leadership visibility into the full contract portfolio.   The Impact 60% reduction in planned review time from a projected six months to under two. Beyond speed, the engagement delivered capabilities the client did not have before: Operational  Faster contract reviews at scale, improved transparency across the acquired portfolio, reliable extraction of critical clauses and terms, standardised outputs for analysis and reporting, and significantly reduced dependency on manual review — freeing the team for strategic and risk-focused work. Strategic Vendor negotiation leverage: At renewal, the procurement team can access the dashboard, view the exact penalty framework against vendor performance and negotiate from evidence rather than assumption. Service Level Agreement benchmarking : Similar vendors - catering, IT services, logistics can now be compared on contractual terms, identifying who holds the most favourable conditions and where renegotiation is warranted. Concentration risk visibility : Leadership can see whether too many critical operational dependencies are tied to a single vendor group — and whether the contractual terms governing those relationships are adequate. Standardisation gaps identified : Older contracts lacking modern indemnification or penalty clauses have been surfaced and queued for remediation — giving legal a clear, sequenced workload. From reactive to proactive: Instead of digging through documents after a vendor failure, the team can see risk profiles instantly - and act before issues escalate. About SmartXtract SmartXtract is Pierag's AI-agentic platform hosting specialised finance agents built for real use cases — contract analysis, technical accounting, reconciliations, reporting and more. Each agent mirrors the workflows of finance professionals by extracting data, interpreting standards and delivering structured outputs. Developed on Azure Platform, securely hosted and easily scalable, SmartXtract integrates with your data to provide accurate, actionable insights in real time.   Discover how Pierag's AI & Digital lab helps organisations convert unstructured documents into actionable intelligence.
Research report | 8-10 Min Read The National Financial Reporting Authority has moved from a reactive enforcement body into something closer to an active quality regulator. Inspection volume is rising, findings are getting more granular, and NFRA is now testing AI tools to support its own review process. For audit firms and the audit committees that rely on them, understanding what NFRA is actually finding matters more than understanding that NFRA exists. This report reviews recent NFRA inspection findings and outreach activity through 2026 to identify the recurring gaps in Indian audit practice and what they signal for audit firms, boards, and finance leaders preparing for their next inspection cycle. What Is an NFRA Inspection? NFRA inspections are structured reviews of how an audit firm actually performs its work, not just what its policies say. Inspectors check whether the firm follows auditing standards, maintains genuine independence from the client, applies proper quality control procedures, and can produce documentation that supports the judgments made during the audit. Inspection reports are made public, which means findings function as both enforcement outcomes and a public signal to the rest of the audit profession about where scrutiny is concentrated. NFRA has stated it will complete inspections of ten audit firms in FY26, the highest annual figure in the regulator's history, alongside a series of city-based outreach programs launched from September 2025 to engage smaller and mid-tier firms directly rather than waiting for inspection findings to force the conversation. What Recent Inspections Reveal Across recent public NFRA inspection reports, a consistent set of themes recurs regardless of firm size: Auditor independence gaps, particularly around cross-network service provisions and undisclosed relationships between auditors and clients. Independence policy manuals that are not updated between inspection cycles remain a repeated finding. Related party transaction (RPT) documentation weaknesses, including insufficient verification of RPT disclosures and inadequate arm's length price testing. Revenue recognition deficiencies, where audit evidence does not sufficiently support the judgments applied to complex or unusual revenue arrangements. Internal financial control gaps, especially concerning controls over revenue, related party transactions, and impairment of non-financial assets. Documentation and evidence chain weaknesses, where audit files lack the contemporaneous, unambiguous evidence needed to demonstrate that professional scepticism was actually applied, not just procedurally recorded. From Reactive Enforcement to Proactive Oversight NFRA's historical approach centred on issuing inspection reports after the fact, flagging shortcomings, and applying penalties or sanctions where warranted. That model is shifting. NFRA's outreach programs, starting in Hyderabad and Indore, signal a deliberate move toward engaging firms before problems surface in an inspection, without reducing enforcement activity. NFRA has also indicated it is testing AI tools internally to support faster review of financial statements, flag questionable transactions, and improve the consistency of its own oversight process, while stating that explainability remains a core requirement rather than a black box approach. This shift matters for how audit firms should read NFRA's direction. Enforcement is not softening. It is becoming better resourced, more consistent, and harder to treat as a low-probability event. What This Means for Audit Firms Firms preparing for the current inspection cycle should treat the following as priority areas, based on where NFRA's public findings have concentrated: Revisit independence policies and confirm they reflect any changes advised in prior inspection cycles, not just the version on file at the time of the last review Strengthen documentation practices around related party transactions, including arm's length testing evidence Ensure audit files demonstrate the reasoning behind judgments on revenue recognition and estimates, not just the conclusion reached Review internal quality control procedures for consistency across engagement teams, since NFRA's outreach explicitly targets smaller and mid-tier firms that may lack Big Four-level resourcing Treat group audits with cross-border components as higher scrutiny areas, since NFRA's push has direct implications for how Indian component teams support foreign group auditors What This Means for Audit Committees and Finance Leaders For companies rather than audit firms, NFRA's tightening oversight has a direct read-through. A cleaner audit relationship starts with the underlying data and documentation a company provides, not only with the auditor's own procedures. Audit committees should expect: More detailed documentation requests from auditors around related party transactions and revenue recognition support Closer scrutiny of internal controls over financial reporting, particularly where prior audits have flagged deficiencies Longer lead times are built into the audit timeline as firms adjust to more rigorous internal quality reviews ahead of their own NFRA inspections Companies that treat audit readiness as a year-round discipline, rather than a pre-audit scramble, are consistently better positioned when NFRA's tightening standards flow through to the audit relationship. Frequently Asked Questions What is NFRA, and what does it inspect? NFRA is India's National Financial Reporting Authority. It conducts structured inspections of audit firms to check compliance with auditing standards, independence requirements, and quality control procedures, and publishes its findings publicly. What are the most common findings in NFRA inspection reports? Recent public inspection reports show recurring findings in auditor independence, related party transaction documentation, revenue recognition evidence, internal financial controls, and the completeness of audit documentation. How many audit firms does NFRA inspect each year? NFRA has stated it will complete inspections of ten audit firms in FY26, its highest annual number to date, alongside targeted outreach to smaller and mid-tier firms. Is NFRA's approach becoming stricter or more collaborative? Both. NFRA is expanding proactive outreach programs to engage firms before issues surface in an inspection, while continuing full enforcement activity, including inspections and penalties, without reducing scrutiny. Does NFRA's increased inspection activity affect companies, not just audit firms? Yes. As auditors face more rigorous NFRA scrutiny, companies typically see more detailed documentation requests and closer review of internal controls during their own audit engagements. Who should read NFRA inspection insights like this? Audit partners, audit committee members, CFOs, controllers, and internal audit leaders are responsible for audit readiness and the quality of financial reporting oversight. Get the Full Report This overview covers the confirmed public themes in NFRA's recent inspection activity. The complete report includes detailed analysis of specific inspection findings, firm-level patterns, and practical audit readiness recommendations for management teams, audit committees, and internal audit leaders. Related reading: Material Weakness Trends 2026 | Beyond Compliance: Internal Auditor's Role in Implementing SEBI's New RPT Framework | Audit Trail: Ensuring Financial Integrity and Accountability
Business implications for global capability centre strategy in India  Haryana’s Global Capability Centre Policy 2026 is more substantive than a generic investment announcement. The policy was notified effective 27 May 2026 and will remain in force for five years from the date of notification or until superseded by a new policy/amendment. It sets clear entry thresholds, location-linked incentives, employment-linked benefits, and R&D support measures that indicate a deliberate attempt to make Haryana a competitive GCC destination, particularly for higher-value and scalable operations.  Policy highlights at a glance  Eligibility thresholds  Minimum employment threshold: 100 employees on payroll or contract with ESI/PF numbers within 3 years of commencement of operations.  Large unit threshold: INR 125 crore fixed capital investment, or INR 50 crore with 500 direct employees.  Mega unit threshold: INR 400-700 crore fixed capital investment, or INR 125 crore with 1,250 direct employees.  Ultra-mega threshold: INR 1,500-6,000 crore fixed capital investment. Existing Unit Eligibility:  Existing GCC units expanding operations on or after 1 January 2026 are eligible  Investments made in the one-year period preceding policy notification qualify for retroactive benefits Human Resource Development and Night Shifts for Women  Employment generation subsidy: % of average gross monthly salary for 10 years (requires 1+ year continuous employment, valid ESI/PF)  Local employment threshold: >15% of total workforce  Floor subsidy: INR 48,000 p.a. when average monthly salary < INR 48,000  Night shifts for women: Three shifts permitted including night shifts, with mandated transportation and safety provisions  Innovation and R&D Support  Job-readiness support reimburses 50% of a 6-month stipend, up to INR 15,000 per month for 50 interns per annum.  For DSIR or CSIR-recognised R&D centres, capital subsidy is available at 50% of eligible capital cost, up to INR 10-50 crore, to be distributed in 5 annual instalments. Operational cost reimbursement benefit of 50% upto 2 crore per year CAPEX vs OPEX Support What stands out in the policy design  The policy is notable because it does not rely on a single headline incentive. Instead, it combines entry thresholds, location-based capital support, operating cost reimbursements, employment-linked subsidies, women-specific provisions, and innovation incentives into a layered package. This is closer to how new age GCC policies are typically structured: the business case is built across setup, scale, and sustained operations rather than around a one-time benefit.  Another important design feature is the location differentiation. Haryana is effectively signalling that it wants to balance the attractiveness of Gurugram with stronger relative support in other districts, explicitly prioritising investment in non-Gurugram districts to promote balanced regional development and position Tier-2 cities such as Panchkula and Hisar as GCC destinations. That has implications for companies evaluating whether they need immediate access to the NCR corporate ecosystem or are willing to trade some of that proximity for stronger incentive economics elsewhere in the state.  The policy also explicitly addresses women workforce participation through night shift allowances, enhanced subsidies, and safety/transportation provisions, making it more progressive than many earlier industrial policies.  What businesses should assess  For businesses, the policy should be assessed on three levels.   First, there is threshold fit: whether the planned investment and employment model aligns with the policy’s eligibility structure.   Second, there is commercial fit: whether the CAPEX, OPEX, and employment-linked benefits are material enough to change the economics of the proposed GCC.   Third, there is execution fit: whether the company can realistically access, document, and sustain compliance with the benefit conditions over time.  This is particularly relevant for firms planning phased expansion. Since benefits are tied to defined investment and employment thresholds, the sequencing of hiring, fit-out, and operational launch may materially influence the eventual value capture. In other words, policy value here is not just about where a GCC is located, but also how the rollout is planned.  Market implications  The policy strengthens Haryana case as a GCC destination for organisations looking beyond traditional metro concentration. Its combination of NCR adjacency, enterprise density, policy-backed support, specific R&D provisions, women-specific workforce provisions, and streamlined facilitation through the AI-enabled Single Window 2.0 (Intelligent Investment Facilitation Portal) established in Gurugram for streamlined approvals, land allocation, and incentive access makes it especially relevant for companies building more specialised and higher-value centres rather than simple cost-arbitrage units.  At the same time, the policy also raises the competitive bar for companies comparing Indian states. The decision is likely to turn less on headline visibility and more on the detailed interplay between incentive value, location suitability, talent access, and implementation ease.  Closing perspective  For organisations assessing India-based GCC expansion, the Haryana policy is best read as a location strategy input rather than a standalone decision trigger. The policy becomes most meaningful when tested against the intended operating model, talent design, timeline, and long-term scale ambition of the proposed GCC.  That is also where a more measured advisory lens becomes useful: not to oversell the policy, but to evaluate whether it genuinely improves the business case compared with other options. A well-grounded market entry or expansion plan should therefore connect policy interpretation with execution realities such as entity structuring, hiring ramp-up, real estate planning, and governance design.  Pierag Consulting supports organisations with GCC expansion by helping translate policy incentives into a workable business case, operating model design, and execution roadmap across feasibility, setup, and scale phases.
For over a decade, India’s Global Capability Centres (GCCs) operated with a clearly defined value proposition: cheaper, faster, scalable. They were the engines of efficiency—delivering back-office support, technology services, and operational scale at a fraction of global costs. But that narrative has run its course. Today, India stands at a defining moment in the evolution of GCCs. Declared the GCC Capital of the World by NASSCOM in 2024, the country is no longer just an outsourcing destination—it is a strategic nerve center for global enterprises. As we move deeper into this decade, it is increasingly clear that this is India’s decade to lead the GCC transformation globally. The numbers tell a compelling story. India’s GCC market, currently valued at $82.1 billion, is projected to grow to $100–110 billion by 2030. This growth reflects more than scale—it signals a shift in perception. India has decisively transitioned from being a low-cost destination to becoming the world’s preferred hub for high-value digital, engineering, and research work. Yet, despite this progress, one fundamental truth remains: Relevance is no longer driven by cost—it is earned by creating value. The Resource Provider Trap Many organizations still fall into what can be termed the “resource provider trap”—where success is measured by headcount, utilization, and cost arbitrage rather than business outcomes. This approach is increasingly fragile. It leaves organizations exposed to automation, macroeconomic uncertainties, and the growing risk of commoditization. Even more concerning is the disconnect between perception and reality. While over 90% of GCC leaders acknowledge their expanded strategic role, performance metrics in many organizations continue to revolve around full-time equivalents (FTEs) rather than measurable impact. This gap is no longer just an operational inefficiency—it represents a strategic vulnerability. At the same time, global disruptions have highlighted another critical capability: agility and resilience. GCCs have emerged as vital anchors of business continuity. During COVID-19, India-based teams rapidly adapted to remote work models, ensuring uninterrupted operations. More broadly, in scenarios of geopolitical instability or regional disruption at headquarters, GCCs provide a distributed execution model that enables business continuity. In essence, GCCs are no longer just delivery arms—they are risk mitigators and continuity enablers. India’s Moment: Scale Meets Strategic Value India’s GCC ecosystem is not only expanding—it is deepening in capability and influence. The country today hosts over 2,100 GCCs operating across more than 3,700 units, with approximately 506 Forbes Global 2000 companies maintaining a presence in India. This reflects an unparalleled level of global enterprise integration. The growth trajectory remains strong, with projections indicating an 8.3% CAGR between 2025 and 2035. Importantly, expansion is no longer limited to metropolitan hubs. The rise of Tier II cities is reshaping the landscape. Private equity firms are playing a pivotal role in this shift, driven by a combination of supportive government policies, robust digital infrastructure, lower setup costs, and a growing preference among talent to avoid high-cost urban centers. Simultaneously, global corporations are making bold bets on India’s future. Microsoft’s planned $17.5 billion investment between 2026 and 2029 to expand cloud and AI infrastructure, along with Amazon’s $35 billion commitment by 2030, underscores the strategic importance of India in shaping the next wave of technology and innovation. The signal is unmistakable: India is no longer a participant in the global GCC ecosystem—it is leading it. The New Value Playbook The transformation of GCCs from cost centers to value creators is already underway, and investment patterns reveal this shift. Organizations are increasingly channeling resources into technology transformation (25%) and capability development (23%). Leading GCCs are distinguishing themselves through three key shifts: Owning Outcomes, Not Just Activities The traditional model of execution is giving way to ownership. GCCs are no longer evaluated on the volume of work delivered, but on the business outcomes they influence—whether in engineering innovation, financial optimization, or operational excellence. Turning AI into a Competitive Advantage The rapid adoption of generative AI is accelerating this transformation. Forward-looking GCCs are embedding AI into core business processes—not merely to improve efficiency, but to drive innovation and create differentiated value. Anchoring to Enterprise Strategy Alignment with global headquarters is no longer optional. The most successful GCCs operate as integrated extensions of enterprise strategy, playing a direct role in shaping decision-making and enabling growth. These shifts are redefining GCCs as enterprise nerve centers, rather than support functions. Leadership Transformation: From Managers to Micro-CEOs Perhaps the most significant evolution is happening at the leadership level. The role of GCC leaders is expanding beyond operational management into strategic influence. While they may not always hold final decision-making authority, they increasingly shape critical enterprise outcomes. Influence, therefore, is emerging as a key currency. This shift demands a new leadership mindset—one where GCC heads operate as “micro-CEOs”, balancing execution excellence with strategic vision, stakeholder alignment, and value creation. The Real Shift India’s GCC journey has progressed through multiple phases—from cost efficiency to scale, from scale to co-creation. Today, it is entering its most critical phase yet: value leadership. However, there is an important caveat. If organizations continue to anchor their GCC strategy solely in cost savings and talent availability, they risk relegating these centers to processing units rather than strategic enablers. The opportunity is far greater. GCCs have the potential to evolve into innovation engines, decision hubs, and growth catalysts—but only if organizations fully embrace the shift from cost-centric thinking to value-driven execution. Conclusion This transformation is not merely a shift in geography—it is a shift in identity. From resources to revenue drivers, From execution to influence, From support functions to strategic partners. India is not just keeping pace with this shift—it is setting the direction. As the GCC ecosystem continues to evolve, one thing is clear: The future will not belong to the most cost-efficient centers—it will belong to the most value-driven ones.
A New Era of Trade and Climate Policy The European Union’s Carbon Border Adjustment Mechanism (CBAM) is no longer a distant policy experiment. From 1 January 2026, it became a binding financial obligation for exporters of carbon‑intensive products such as iron and steel, aluminium, cement, fertilisers, hydrogen, and electricity. The EU’s goal is simple but ambitious: prevent carbon leakage, where companies shift production to countries with weaker climate rules, undermining global climate progress. This mechanism is not just about Europe. The EU is the world’s largest single market, and by attaching a carbon price to imports, it is effectively exporting its climate standards worldwide. Any exporter who wants access to Europe must either prove low‑carbon production or pay the difference.  The First Price Signal On 7 April 2026, the European Commission published the first official CBAM certificate price: €75.36 per tonne of CO₂ equivalent Uniform across all sectors Based on the average EU ETS auction clearing prices for Q1 2026 This number is only the starting point. What matters more is the carbon intensity of each product. Steel, for example, is far more carbon‑intensive than aluminium, meaning the same certificate price translates into vastly different burdens. India’s Early Exposure  The impact is already visible even before financial obligations began. During the reporting phase alone: Steel and aluminium exports to the EU fell 24.4% from $7.71 billion in FY24 to $5.82 billion in FY25. Iron and steel exports also saw a sharp contraction during the reporting phase, reflecting the compliance burden and uncertainty faced by EU buyers. This contraction reflects the compliance burden of reporting requirements and the uncertainty EU buyers face when suppliers cannot provide verified emissions data. The financial phase will only amplify this pressure.  The Preparedness Gap  Most Indian manufacturers understand CBAM in theory. Far fewer are prepared in practice. True preparedness requires: Verified plant‑level emissions data aligned with EU standards. GHG accounting systems that meet EU methodology, often requiring 40 to 80 staff hours annually. Without verified data, exporters are forced to rely on EU default values. These are deliberately conservative, often higher than actual emissions, designed to push companies toward verification. Relying on them is not neutral; it inflates costs, weakens negotiations, and erodes competitiveness.  The Investment Reality One misconception needs to be addressed: international carbon credits, offsets, or green certificates do not reduce CBAM liability. The mechanism only recognizes documented reductions at source or domestic carbon pricing formally accepted by the EU. That leaves exporters with two options: Decarbonisation at source: requiring significant capital investment. Absorbing the cost: which erodes already thin margins in price‑sensitive markets. Neither path is easy, but waiting is not an option.  The Expanding Scope  CBAM is not stopping at bulk industrial sectors. From January 2028, the EU plans to extend coverage to nearly 180 additional products, including: Fabricated metal products Auto components Machinery parts Plastics and polymers Chemicals For downstream manufacturers, this is not “someone else’s problem.” It is a ticking clock.  The Signal, Not the Endpoint  CBAM is more than a compliance mechanism. It is a signal that carbon intensity is now a trade variable. Key milestones ahead include: Q2 price publication: July 2026 First declaration deadline: September 2027 Scope expansion: January 2028 The companies that act today by building data infrastructure, verifying emissions, and modelling carbon costs will manage this transition on their own terms. Those that wait will be managed by it. Author - Anshit Dhawan ( Senior)
Artificial intelligence is no longer a fringe innovation topic or a limited pilot initiative. It has moved firmly into the enterprise mainstream, and the market conversation has shifted accordingly: from experimentation to scale, governance, operating models, and measurable value creation. That shift matters because adoption is no longer the real test of maturity. Most enterprises today can access leading models, license copilots, launch pilots, and introduce AI-enabled tools into selected functions. Yet the presence of AI in the technology stack does not, by itself, improve business performance. The more important question is whether AI has been embedded in a way that meaningfully improves how work gets done. This is where many enterprise AI programs begin to lose clarity. Attention often centres on model selection, tool comparisons, or the promise of the latest platform release. Those decisions are relevant, but they are not usually what determines long-term value. In practice, the more difficult and more consequential challenge is execution: defining where AI belongs within a business process, where conventional automation is more effective, where human judgment must remain central, and how all of it is governed at scale. Recent enterprise experience has made this distinction increasingly visible. Many of the most instructive AI stories are not about whether the technology works in principle. Instead, they are about cost overruns, unclear returns, weak process fit, inconsistent usage, and the difficulty of scaling tools that were introduced without sufficient operational discipline. That is why enterprise AI strategy should not begin with access to technology. It must begin with the design of work. Shifting the Focus: From Access to Execution A more effective starting point is the business workflow itself. To build a grounded, impactful AI roadmap, leaders must step back from the technology and begin by asking critical diagnostic questions: Process Centrality: Which processes are genuinely central to our operational performance? Friction Points: Where do teams currently lose time to review, rework, handoffs, or fragmented information? Cognitive Demands: Which activities depend most heavily on pattern recognition, contextual interpretation, or complex exception handling? Value Leverage: Where would better support improve quality, consistency, customer experience, or the speed of decision-making? These questions tend to produce a much more grounded roadmap than a technology-first approach. They also lead to an essential realization: not every business problem requires AI, and not every step within an AI-enabled process should be handled by AI. Deconstructing the Workflow Enterprise workflows contain distinct categories of work, and each category demands a different tool. Some steps are deterministic and governed by stable rules. Others are repetitive and process-driven. Some involve ambiguity, unstructured information, or complex contextual interpretation. Others require legal accountability, commercial judgment, or strict compliance oversight. Treating all of these as the same kind of problem is one of the most common errors in enterprise AI design. Strong AI programs are rarely built by maximizing the amount of AI in a process; they are built by assigning the right capability to the right type of task. The vendor invoice process offers a highly practical illustration of this multi-layered framework. Consider a multinational enterprise managing thousands of global suppliers. Seeking a quick win, leadership deploys a generic, off-the-shelf AI co-pilot to automatically read and approve all incoming invoices. In reality, the initiative quickly derails. The generic AI hallucinates on standard tax fields because it does not understand the firm's strict internal data boundaries. It wastes expensive computational power simply routing a PDF from a manager to a VP. Worst of all, it mistakenly approves a disputed, high-value transaction because it lacks the commercial context of an ongoing vendor lawsuit. This failure occurs because the enterprise treats the entire workflow as an "AI problem." In reality, to succeed, the process must be deconstructed into a layered operating model: Rules with Predictable Outcomes: Validating invoice data against purchase orders and tax requirements is entirely rule-based. A classic rules engine is the most cost-effective and reliable tool here. Automating Repetitive Tasks: Procedural steps, including routing approvals and updating ERP systems, are highly repeatable. Standard workflow automation is best suited to these status-based actions. AI Where Context and Judgment Are Required: AI becomes highly valuable during exceptions—unusual charges, incomplete documentation, or subtle inconsistencies. Here, AI can analyze unstructured supporting material, highlight anomalies, and assist a reviewer in narrowing down the issues. Humans When Accountability Counts: Human oversight remains strictly necessary where commercial judgment, regulatory sensitivity, supplier disputes, or high-value decisions require a level of accountability that cannot be delegated to an algorithm. This layered operating model is far more effective than the blanket idea of “AI everywhere.” It respects the unique strengths of rules, automation, AI, and human expertise. Custom Architecture vs. Generic SaaS Because strategic enterprise workflows require this precise, multi-layered coordination, managing the handoffs between strict business rules, standard automation, and cognitive AI assistance requires a cohesive, tailored orchestrator. Generic, off-the-shelf software rarely has the inherent flexibility to stitch these four layers together seamlessly. This raises a critical question for enterprise leaders: when is a standard platform sufficient, and when is custom development justified? The most effective standard operating procedure (SOP) relies on a simple distinction: Core versus Context. Context Workflows (Buy/Standard SaaS): These are non-differentiating processes that every company handles similarly—such as standard payroll processing, routine expense categorization, or basic accounts payable routing. For these, standard, off-the-shelf platform tools are completely sufficient. There is no strategic value in reinventing the wheel. Core Workflows (Build/Custom Orchestration): These are the proprietary processes where an enterprise actually wins its market—whether that is an investment bank's proprietary M&A valuation model, an consulting firm’s technical accounting expertise, or a multinational's complex forecasting engine. This challenge has become top-of-mind as adoption timelines compress. Research from the Wharton School and GBK Collective indicates that generative AI is fast-tracking into the core of the enterprise, with decision-makers increasingly shifting budgets from experimentation to integration. Yet, as adoption accelerates, the gap between high-performing and average organizations becomes clearer. McKinsey’s research indicates that while AI use is now widespread, the ability to translate that use into actual business impact remains highly uneven. Crucially, high-performing organizations are far more likely to redesign workflows fundamentally to support this multi-layered reality, rather than simply overlaying AI onto existing, broken activity. Enterprise value is created not when AI is added on top of work, but when work itself is redesigned to use AI appropriately. In specialized, "Core" environments, durable value typically comes not from buying another off-the-shelf license, but from configuring bespoke solutions that align perfectly with the unique operating model of the business. Governance and the Power of Human Augmentation To support this bespoke architecture, an enterprise operating model must prioritize governance and human enablement from day one. Cost control, usage discipline, data boundaries, and security guardrails cannot be added as an afterthought. The growing emphasis in enterprise research on production readiness and ROI measurement reflects exactly this concern. For instance, ISG’s reporting focuses heavily on spending trends, governance, and scaling challenges, while other market research increasingly evaluates AI not by its novelty, but by its deep integration and structural guardrails. Crucially, those guardrails are not just technical—they are human. One of the most persistent misconceptions is that AI's primary value lies in replacing human labor. In reality, the International Monetary Fund’s (IMF) analysis of labor exposure continually emphasizes complementarity—the immense potential of technology to work alongside people, amplifying their capability rather than substituting it. AI does not create enterprise value simply because it is available. It creates value when employees are trained and empowered to co-pilot with it: Understanding precisely where the technology adds cognitive leverage. Knowing exactly where its outputs must be challenged or verified. Recognizing where over-reliance would introduce unnecessary operational risk. This is particularly relevant in high-stakes functions like finance, legal, procurement, and risk, where work constantly balances structured process and contextual judgment. In these environments, staff education is not a secondary HR workstream; it is a core part of the operational control framework and the ultimate engine of productivity. Strategic Execution: The Path to Lasting Value The broader business case for this disciplined approach is becoming impossible to ignore. Recent market research highlights a widening performance gap between organizations that merely acquire tools and those that build the operational infrastructure to support them. Oxford Economics’ work on enterprise AI maturity, for example, demonstrates that sustainable value is tied directly to deep operational integration rather than simple access. This is reinforced by McKinsey’s findings, which establish a direct link between fundamental workflow redesign and actual value capture. Ultimately, this execution gap translates into a financial one: as IMD’s maturity research points out, a significant performance and margin divide is opening up between operationally mature enterprises and those still struggling to scale their pilots. The implication for enterprise leaders is straightforward. The long-term winners in the AI era are unlikely to be the organizations that deployed the greatest number of tools or announced the largest number of pilots. They are more likely to be the ones that: Identified the right strategic workflows. Intelligently combined rules, automation, AI, and human oversight. Built robust governance frameworks from the outset. Trained their workforce to interact with these capabilities with disciplined, empowered skepticism. AI adoption may open the door, but disciplined execution determines whether that investment translates into durable business value. Sources International Monetary Fund (IMF)- sdnea2024001.pdf ISG (Information Services Group)- isg-one.com/docs/default-source/default-document-library/2025-isg-state-of-enterprise-ai-adoption-r… Wharton School / GBK Collective- ai.wharton.upenn.edu/wp-content/uploads/2025/10/2025-Wharton-GBK-AI-Adoption-Report_Full-Report.pdf Impact AI Series | Oxford Economics IMD Business School- Companies leading in AI adoption use it as a catalyst for reinvention - IMD business school for man…
Research report | 8-10 Min Read Material weaknesses remain one of the clearest public signals of how well an organization's internal control environment is actually working. But the disclosures themselves rarely tell the full story. A single reported weakness is often the visible symptom of a deeper governance, staffing, or process gap, not an isolated control failure. To understand what is really driving these disclosures, Pierag analyzed material weakness filings from 1,000 U.S. SEC filers across 2025 and 2026. The goal was to identify which themes recur most often, how they cluster together, and what separates companies that remediate quickly from those that report the same weaknesses year after year. What Is a Material Weakness in Internal Controls? A material weakness is a deficiency, or combination of deficiencies, in internal control over financial reporting (ICFR) severe enough that there is a reasonable possibility a material misstatement in the company's financial statements would not be prevented or detected on a timely basis. Under SEC rules, companies must disclose material weaknesses in their annual and quarterly filings, along with management's assessment of ICFR effectiveness. A material weakness disclosure does not necessarily mean a misstatement has occurred. It means the control environment could not reliably catch one if it did. Methodology Pierag reviewed material weakness disclosures reported by 1,000 U.S. SEC filers across fiscal years 2025 and 2026, drawn from annual and quarterly filings. Each disclosure was categorized by theme, cross-referenced against industry classification and filer type (IPO versus non-IPO), and analyzed for co-occurrence patterns, meaning how often two or more weakness themes were reported together within the same filing. The Most Commonly Reported Material Weakness Themes Two themes dominate the dataset by a clear margin: Segregation of Duties - inadequate separation between individuals who initiate, approve, and record transactions, concentrating control in too few hands. Resource Constraints - insufficient qualified accounting and finance personnel to design, operate, and monitor controls at the scale the business requires. Beyond these two leading themes, three additional categories appear consistently across industries: Employee Training and Competency Gaps - control owners who lack sufficient training in accounting standards, company-specific procedures, or the judgment required for complex transactions. IT General Controls (ITGCs) - weaknesses in access management, change management, or system configuration controls supporting financial reporting systems. Financial Reporting Process Deficiencies - breakdowns in period-end close, account reconciliation, or review procedures that support accurate reporting. Why Material Weaknesses Rarely Occur in Isolation One of the most consistent patterns in the data is co-occurrence. Companies that report one material weakness frequently report two or more in the same filing. Segregation of Duties issues, for example, are commonly reported alongside Resource Constraints, since both often stem from the same root cause: a finance function that has not scaled staffing or process design in line with the business. This clustering matters for how organizations should read their own disclosures. A material weakness reported as a single line item is often a symptom of a broader capacity or governance gap, not a standalone control fix. Addressing the individual deficiency without addressing the underlying driver tends to produce a repeat disclosure the following year. Industry-Specific Patterns Material weakness themes are not evenly distributed across sectors. Some industries show a heavier concentration of IT General Controls weaknesses, consistent with reliance on complex or highly customized financial systems. Others show a higher incidence of Resource Constraints, often reflecting leaner finance functions relative to transaction volume or reporting complexity. Understanding where an organization's own industry tends to cluster is a useful diagnostic starting point before conducting an internal gap assessment. IPO Filers vs. Non-IPO Filers The data shows a meaningful difference between newly public companies and established filers. IPO filers are more likely to report material weaknesses tied to Resource Constraints and Financial Reporting Process Deficiencies, consistent with the operational strain of building a public-company-grade control environment on a compressed timeline. Non-IPO filers, by contrast, more frequently report Segregation of Duties and IT General Controls issues, often surfacing as the business has grown in complexity faster than its control structure. What Effective Remediation Looks Like Across the filers studied, organizations making the fastest and most durable progress on remediation share a common approach: they treat material weaknesses as a signal to fix the underlying driver, not just the disclosed symptom. In practice, this means: Redesigning governance structures and reporting lines rather than adding a single approval step Investing in talent and training as a control activity, not a one-time fix Rebuilding financial reporting processes with documented, testable controls Modernizing IT systems and access controls supporting the close process Organizations that address these root causes tend to see material weaknesses resolved and stay resolved. Those that patch individual deficiencies in isolation tend to see new, related weaknesses surface in subsequent periods. Frequently Asked Questions What is the most commonly reported material weakness among SEC filers? Segregation of Duties and Resource Constraints are the two most frequently reported material weakness themes across the 1,000 SEC filers analyzed, ahead of IT controls, employee training, and financial reporting process deficiencies. Do material weaknesses usually occur alone or together? Material weaknesses frequently co-occur. A company reporting a Segregation of Duties issue, for example, often also reports a related Resource Constraints weakness, since both typically trace back to an under-resourced finance function. Is a material weakness the same as a misstatement? No. A material weakness means the control environment could not reliably prevent or detect a material misstatement on a timely basis. It does not confirm that a misstatement actually occurred. Do IPO companies report different material weaknesses than established public companies? Yes. IPO filers more often report Resource Constraints and Financial Reporting Process Deficiencies, reflecting the strain of building public-company controls quickly. Non-IPO filers more often report Segregation of Duties and IT General Controls weaknesses. How long does it typically take to remediate a material weakness? Timelines vary by root cause and company size, but remediation that only fixes the disclosed symptom (rather than the underlying governance, staffing, or process gap) tends to result in the same or a related weakness resurfacing in a later period. Who should read this material weakness research report? The findings are most relevant to CFOs, controllers, audit committee members, and internal audit leaders responsible for ICFR design, SOX 404 compliance, and remediation planning. Get the Full Report This overview covers the top-line findings. The complete report includes the full thematic breakdown, industry-by-industry data, co-occurrence analysis, and practical considerations for management teams, audit committees, and internal audit leaders building a remediation roadmap. Building or strengthening your ICFR environment? Pierag's Business Risk Advisory teams work with audit committees and finance leaders to design controls that hold up under scrutiny, not just on paper. Talk to our team about your control environment. Related reading: Beyond Compliance: Internal Auditor's Role in Implementing SEBI's New RPT Framework | Audit Trail: Ensuring Financial Integrity and Accountability | Emerging Risks and Trends 2026
Compliance management today requires visibility and proactive planning. With numerous regulatory deadlines across Income Tax, GST, FEMA, MCA, SEZ, and STPI, staying organized is essential for businesses to operate smoothly. We have put together the Compliance Calendar for FY 2026–27, designed to help organizations track key due dates and integrate reminders directly into Outlook calendars for better compliance management. Sharing this resource with the hope that it helps teams stay ahead of deadlines and focused on what matters most, building resilient and responsible businesses.
  • 8-10 Min Read
The Shift from Mitigation to Adaptation In the last decade, the main concern of corporate climate strategies has been the reduction of greenhouse emissions and the achievement of the target of net-zero emissions. Although the prevention of global warming is the key, the increasing effects of climate change have made climate adaptation an important concern. The severe weather changes, increase in temperature, water scarcity, and sea level rise are now being witnessed globally, which are negatively affecting supply chains, infrastructure, and commercial operations globally. Businesses are realizing that cutting carbon emission reduction is not enough. In spite of all the mitigation efforts, there are some unavoidable effects of climate change, and enterprises need to start preparing for the new risks. Climate adaptation is shifting from a niche sustainability issue to a critical part of an enterprise’s overall ESG strategy. This shift is illustrated by the financial investment required to address the issue of climate resilience. The Adaptation Gap Report 2024 by the United Nations Environment Programme indicated that developing countries will require between $215 billion and $387 billion annually starting from 2030 to address the issue of climate change. The financial impact of the issue is already apparent. In 2024, the financial losses due to natural disasters across the globe are estimated at $320 billion. Therefore, the financial impact of the issue is already apparent. In this case, adapting to the issue of climate change is no longer only a matter of environmental protection but is becoming a matter of strategic business, as companies must now consider the financial implications of climate-related disruptions on their operations and long-term viability. Understanding Physical Climate Risks for Businesses Physical climate risks, as the name suggests, refer to the direct impacts of climate change on assets, operations, and supply chains. These risks are generally categorized as acute and chronic. Extreme weather events, floods, hurricanes, wildfires, and heatwaves are examples of acute risks that can cause problems with operations. On the other hand, chronic risks involve longer-term climate shifts and may include changes in sea levels, droughts, and increased temperatures. With the rising cases of weather-related disasters, the importance of adaptation to these changes cannot be overemphasized. From 1985 to 2025, losses of around US $7.2 trillion are observed from natural disasters. This, therefore, highlights the rising risk to businesses as a result of these changes. These dangers are not exclusive to any certain industry. Manufacturing facilities situated in flood-prone regions may be compelled to cease operations, while agricultural endeavors may see diminished productivity as a result of climatic alterations. These alterations may be experienced across multiple sectors, including energy and retail. Financial institutions and investors are progressively evaluating physical climate concerns. Financial institutions, including lenders and insurance providers, are evaluating companies' vulnerability to climate-related risks. This has compelled businesses to incorporate risk analysis into their strategy planning. Why Climate Adaptation Is Becoming a Business Priority The importance of putting more emphasis on climate adaptation in corporate ESG agendas has been heightened by multiple factors, including the growing frequency and severity of climate-related disasters and ongoing real-world financial consequences for businesses such as supply chain disruptions, damage to physical infrastructure, and operational delays. There is also greater expectation from regulators and global frameworks regarding the disclosure of climate risk. The Task Force on Climate-related Financial Disclosures suggests that companies should identify both transitional and physical risks and disclose how their strategies will remain resilient to the risks they may face based on the different climate scenarios. There is increasing demand for more transparency from investors about how businesses will manage long-term climate risk. Climate resilience is being viewed by institutional investors as an important indicator of a company’s financial stability. Companies unprepared for the effects of climate may experience more expensive insurance coverage, decreased asset valuation, and/or limited access to funding sources. The case for the economics of adaptation is beginning to come into view as well. As a 2024 analysis by the Boston Consulting Group revealed, there was more than $1 trillion of worldwide climate damage between 2020 and 2024, and so the financial impact of extreme weather events is rising. As a result, climate adaptation is being seen as the new frontier for ESG leadership. Climate-Resilient Business Strategies To address physical climate risks, proactive approaches to adapting to the situation have to be developed. Organizations have to conduct exhaustive assessments of the risks that might be caused by the climatic conditions. In this case, the impact that the climatic conditions might have on the business is analyzed. This is where the use of scenario analysis is important. Another key aspect that has to be addressed is the issue of infrastructure. In this case, the business might have to invest in the construction of facilities that are able to protect the business from the effects of extreme climatic conditions. In this case, the business might have to invest in the construction of facilities that protect the business from floods. In addition, the business might have to invest in the installation of technologies that help to conserve water. In this case, the business might have to invest in the installation of air conditioning units. However, corporate preparedness remains low despite acknowledging the risks that may be caused by climatic conditions. Research done on more than 1,000 publicly listed firms revealed that only 23% of these firms have put in place mechanisms to address this problem. Therefore, investments in infrastructure that is resistant to climate change, sustainable water management, and natural solutions can help to mitigate risks to operation in the long term as well as environmental objectives. This may require collaboration with other actors because risks are often beyond an organization. Governance and ESG Integration Effective climate adaptation practices require robust climate adaptation governance practices and oversight by the board of directors. Climate risk management is an essential part of enterprise risk management practices, ensuring that adaptation practices are consistent with overall corporate governance practices. The board plays an essential part in overseeing the assessment of climate risks, developing resilience goals, and monitoring progress. The transparent communication of risks and adaptation techniques is becoming increasingly expected by various stakeholders and regulatory bodies in firms. The importance of ESG reporting frameworks in prioritizing resilience in overall sustainability reporting is becoming prominent. The transparent communication of adaptation techniques by firms is likely to increase investor trust and readiness for the long-term effects of climate change. Next Step: Climate Resilience in Corporate Strategy As much as the climate risks are rising, adaptation is turning out to be a key component of the sustainability strategy for many firms. Companies that focus only on cutting down emissions and ignore the physical climate dangers may face a shock that threatens their sustainability. According to the World Meteorological Organization, the period between 2015 and 2024 has been the warmest decade on record. This implies that extreme weather occurrences and climate upsets might worsen in the coming future. As a way of countering the effects of climate change, many organizations are going a step further than their net-zero targets and attempting to make their operations more climate-resilient. Companies can better prepare for environmental shocks and keep their operations going by including climate adaptation in their governance structures, risk management frameworks, and investment decisions. In this context, it can be said that the question is no longer whether businesses should prepare for climate impacts but how effectively they can adapt. Companies that treat climate resilience as a strategic priority will be better positioned to navigate climate uncertainty while creating sustainable long-term value. Author - Ayushika Saraswat (Consultant)
  • 8-10 Min Read
The risks that organizations once monitored from a distance are now actively reshaping business models, capital decisions, and strategic priorities. Below are the five risks that every leader should focus on: 1. Cybersecurity – Cyber incidents are no longer just an IT problem. They disrupt operations, delay customer interactions, and attract regulatory scrutiny. 2. Digital Disruption & AI – AI adoption is accelerating faster than governance frameworks can keep up. The question is no longer whether to adopt, it's who is accountable when things go wrong. 3. Business Resilience – Resilience today isn't about recovering after a disruption. It's about sustaining performance while disruption is still underway. 4. Geopolitical Uncertainty – Trade disputes, policy shifts, and regulatory changes are happening without warning. Organizations must embed these into strategic planning, not treat them as external noise. 5. Human Capital – 40% of organizations worldwide identify talent as a key risk. Having a strategy means little without the people ready to execute it. What makes these risks truly complex is how deeply interconnected they are. A cyber incident amplifies operational fragility. Geopolitical shifts strain already-stretched supply chains. Talent gaps slow down an organization's ability to respond to any of it. In this environment, Internal Audit is shifting from process reviewer to risk interpreter. Download & Read our full Point of View below.
  • 8-10 Min Read
In December 2025, the Financial Accounting Standards Board (FASB) issued ASU 2025-10, Government Grants (Topic 832), introducing dedicated U.S. GAAP guidance for the accounting of government grants received by business entities. Previously, U.S. GAAP lacked a specific standard for such grants, leading companies to rely on analogies to other guidance such as IAS 20, ASC 450, or Subtopic 958-605. This resulted in inconsistent accounting practices and reduced comparability across financial statements. The new update establishes a structured framework for recognizing, measuring, presenting, and disclosing government grants, improving transparency and consistency in financial reporting. Key Highlights Dedicated Guidance: Topic 832 introduces explicit accounting guidance for government grants received by business entities under U.S. GAAP. Clear Grant Classification: Grants are categorized into: ⇨ Asset-related grants: linked to the purchase or construction of long-lived assets. ⇨ Income-related grants: intended to compensate for expenses or losses. Recognition Criteria: Grants are recognized only when it is probable that the entity will meet grant conditions and receive the grant. Measurement: Grants must generally be measured at fair value at recognition, including non-monetary assets. Accounting Approaches for Asset Grants: ⇨ Deferred Income Approach: Grant recorded as deferred income and recognized over the asset’s useful life. ⇨ Cost Accumulation Approach: Grant reduces the carrying amount of the asset, lowering depreciation over time. Enhanced Disclosures: Entities must provide expanded disclosures on the nature of grants, accounting policies applied, grant terms, contingencies, financial statement impacts, and potential repayment risks. Scope The standard applies to business entities and excludes not-for-profit organizations and employee benefit plans, which already follow separate accounting guidance. Certain transactions such as income tax benefits, government guarantees, and below-market interest loans are also excluded. Impact ASU 2025-10 aligns U.S. GAAP more closely with international practices while maintaining its principles-based structure. The update is expected to improve comparability, reduce diversity in practice, and enhance the transparency of government grant reporting.
  • 7-10 Mins Read
ESG Perspective – March 2026 Edition presents a curated overview of key global developments shaping the evolving ESG and sustainability landscape. The edition highlights important regulatory updates, emerging global standards, and market trends across areas such as carbon markets, sustainability reporting and disclosure frameworks, climate policy, circular economy regulations, and sustainable finance. As governments, regulators, and investors continue to strengthen expectations around transparency, accountability, and climate action, businesses are increasingly required to navigate a complex and rapidly evolving ESG environment. This edition distills significant policy announcements, regulatory reforms, and standard-setting initiatives from across jurisdictions into clear, decision-relevant insights. By bringing together these developments in one place, the report aims to help organizations stay informed, anticipate regulatory shifts, and better prepare for the transition toward more sustainable and responsible business practices. Read the full edition for a deeper look at the latest global ESG developments and regulatory insights.
  • 8-10 Mins Read
Standard Setters’ Updates – H2 2025 This edition provides a concise and practical overview of the most significant accounting, regulatory, and sustainability reporting developments from the second half of 2025, helping organizations prepare for upcoming changes in 2026 and beyond. Key Highlights: Major Accounting Standards Updates (ASUs) issued in H2 2025, covering credit losses, internal-use software, derivatives and hedging, purchased loans, government grants, interim reporting, and codification improvements. Simplification and consistency initiatives by FASB, aimed at reducing complexity, improving comparability, and better aligning accounting outcomes with economic substance. Snapshot of FASB current projects, including debt exchanges, environmental credit programs, crypto asset transfers, equity method improvements, and cash flow statement refinements. Regulatory developments from the SEC, including leadership changes, crypto asset guidance, AI and fraud task forces, financial reporting manual updates, and implications of major U.S. fiscal legislation. Sustainability reporting developments, highlighting ISSB exposure drafts and significant simplification of European Sustainability Reporting Standards (ESRS), with reduced reporting burden and enhanced interoperability. Practical effective-date guidance, with appendices outlining ASUs effective in 2025 and 2026 to support timely implementation planning.
  • 15-20 Min Read
India’s IT landscape has experienced a dramatic shift over recent decades, moving away from traditional, paper-dependent bookkeeping methods to a vibrant, tech-powered ecosystem. Today, organizations depend on — ranging from enterprise resource planning (ERP) tools to cloud platforms — not only to boost efficiency but also to safeguard compliance, security, and data accuracy of financial reporting. This change entails additional responsibility since keeping thorough records helps to prove financial integrity and responsibility. An audit trail acts as the "black box" of an organization—a kind of financial journal that captures every activity. It records who did what, when, and how within the financial system. This creates a straightforward way to verify the accuracy and accountability of financial records. Think of it as holding a backstage pass that lets you peek behind the curtain—offering complete visibility into every transaction for transparency, tracking access to sensitive data to bolster security, and capturing system changes to ensure compliance. With their growing importance, audit trails are now a legal must-have in India, following regulatory mandates that came into effect on April 1, 2023. The push for audit trail comes straight from the Companies (Accounts) Rules, 2014, where Rule 3(1) says any organization using accounting software—whether it's ERP systems or even web portals—must have a permanent audit trail that can't be turned off. It’s got to automatically track every change, stamp it with a timestamp, and keep those records on hand for audits. Meanwhile, auditors, under Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014, must double-check that this feature was running all year, and wasn't tampered with. This rule isn't just for large organizations—it applies to every Indian organization. Whether it's nonprofits under Section 8 or foreign entities, it covers everything from standalone to consolidated financial statements.
  • 2-3 Min Read
Welcome to our Standard Setters' Updates of FASB & SEC. In this publication, we present a concise overview of the latest developments in financial reporting and highlight key considerations as we move through 2025. The Accounting Updates summarize FASB's new guidance issued in the first half of the current year and highlight the accounting standards that are effective in 2025. The FASB Current Projects section provides an overview and status of the items that FASB is actively working on. The Regulatory Updates section brings you noteworthy updates from the SEC. The Sustainability Reporting Developments section outlines the changes to ISSB’s Disclosure and European Union’s Reporting requirements. The Financial Accounting Standards Board (FASB), in November 2024, issued ASU 2024-03 which requires public business entities to disaggregate expenses in the income statement into specific categories and reconcile those to the totals reported in the financial statements. Subsequently, the Board realized a clarification was needed to avoid confusion regarding when the standard applies, particularly in interim periods. Therefore, the Board issued ASU 2025-01 clarifying the effective date to be the first annual reporting period beginning after December 15, 2026, and interim reporting periods within annual reporting periods beginning after December 15, 2027. In 2022, the Securities and Exchange Commission (SEC) published interpretive guidance as Staff Accounting Bulletin (SAB) No. 121 on Topic 5.FF, Accounting for Obligations to Safeguard Crypto-Assets an Entity Holds for its Platform Users. SAB No. 121 required entities safeguarding crypto-assets to record a liability and a corresponding asset at fair value. However, this guidance created practical challenges and accounting complexities. To address these concerns, the SEC later issued SAB No. 122, rescinding the interpretive guidance published as SAB No. 121. The amendment removes the obligation to recognize a safeguarding liability and corresponding asset, instead directing entities to apply traditional loss contingency guidance under ASC 450-20: Loss Contingencies when accounting for obligations to safeguard crypto-assets. Therefore, the Board issued ASU 2025-02 to inform about SAB No. 122 rescinding the interpretive guidance in SAB No. 121. Entities should apply the rescission of Topic 5.FF on a fully retrospective basis in annual periods beginning after December 15, 2024.
  • 8-9 Min Read
Point of View | 6-8 Min Read Organizations today are navigating a risk landscape that no longer sits still. Technological change, environmental pressure, and shifting societal expectations are blurring the traditional boundaries between risk categories, creating a complex, interconnected environment where a single disruption rarely stays contained to one part of the business. Developing the ability to identify, understand, and mitigate these risks has become essential for organizations aiming for resilient, sustainable growth, not just for risk teams but for leadership as a whole. This shift also creates an opening for internal audit functions specifically. Emerging risks give internal audit teams a genuine opportunity to demonstrate agility, sound judgment, and strategic insight, reinforcing their role as a driver of organizational resilience and long-term value creation, not just a compliance checkpoint. Two risk categories in particular deserve close attention heading into 2026: business continuity and human capital. Business Continuity Risk: From Contained Incidents to Domino Effects Business continuity risks are the probable disruptions that hinder an organization's ability to operate effectively and deliver essential services. These disruptions can originate from multiple sources at once, including natural disasters, technological failures, cybersecurity incidents, geopolitical conflicts, and supply chain breakdowns. The COVID-19 pandemic and the Suez Canal blockage remain two of the clearest recent examples of how severely these risks can disrupt global operations, and both illustrate a pattern that continues to define continuity risk today: these disruptions are highly interconnected and interdependent. A relatively minor disruption in one part of a supply chain or operating model can trigger a cascading effect that produces operational and financial consequences across an entire global organization. Strengthening operational resilience is no longer a defensive, back-office exercise. It is essential for maintaining stakeholder trust and sustaining long-term value delivery, particularly as investors, regulators, and customers increasingly expect organizations to demonstrate they can absorb shocks without losing continuity of service. Human Capital Risk: The Execution Gap Behind Every Strategy Human capital risk is the vulnerability organizations face in attracting, retaining, and developing their talent. Employees remain an organization's most valuable asset and one of its most vital pillars, which means failures in talent management do not stay contained to HR. They ripple directly into business continuity, innovation capacity, and competitive position. An organization can have a well-designed strategy for navigating cyber risk, geopolitical disruption, or digital transformation, but a strategy is only as strong as the people available to execute it. Talent gaps slow an organization's ability to respond to any other risk on this list, which is why human capital risk increasingly gets discussed alongside operational and continuity risk rather than treated as a separate HR concern. Why These Two Risks Are Increasingly Discussed Together Business continuity and human capital risk are not independent categories that happen to appear on the same risk register. They compound each other. A continuity event, whether a cyberattack, a supply chain disruption, or a geopolitical shock, tests an organization's talent bench directly: whether the right people with the right authority and training are in place to respond in real time. Conversely, an organization with unresolved talent gaps going into a disruption will find that disruption harder to contain and slower to recover from. This is exactly the kind of interconnection that internal audit functions are well positioned to surface. Rather than reviewing continuity plans and workforce risk as separate audit engagements, leading internal audit teams are increasingly examining how these risks interact and where a gap in one amplifies exposure in the other. What This Means for Internal Audit and Risk Leaders in 2026 Organizations preparing their 2026 risk agendas should treat business continuity and human capital risk as connected priorities, not parallel checklist items. Practically, this means: Testing continuity plans against realistic scenarios that also account for staffing and skills availability, not just system and process recovery Reviewing whether critical roles have documented succession and cross-training coverage, particularly in functions central to incident response Assessing where talent gaps could slow the organization's response to a continuity event, and prioritizing those gaps ahead of a crisis rather than after one Giving internal audit a mandate to examine risk interconnection directly, rather than auditing each risk category in isolation Frequently Asked Questions What is business continuity risk? Business continuity risk refers to probable disruptions that hinder an organization's ability to operate effectively and deliver essential services, arising from sources such as natural disasters, technology failures, cybersecurity incidents, geopolitical conflict, or supply chain disruption. What is human capital risk? Human capital risk is the vulnerability an organization faces in attracting, retaining, and developing the talent it needs, with direct consequences for business continuity, innovation capacity, and competitive position when not managed effectively. Why are business continuity and human capital risk often discussed together? These risks compound each other. A continuity disruption tests whether an organization has the right talent in place to respond, while unresolved talent gaps make any continuity event harder to contain and slower to recover from. What role does internal audit play in managing emerging risks like these? Internal audit is increasingly positioned to examine how risks like continuity and talent interconnect, rather than auditing each in isolation, giving organizations a clearer view of where one risk gap amplifies exposure elsewhere. What real-world events illustrate business continuity risk? The COVID-19 pandemic and the 2021 Suez Canal blockage are widely cited examples of how a single disruption can cascade into significant global operational and financial consequences. Who should be paying attention to these emerging risks? Chief risk officers, heads of internal audit, COOs, and board risk committees responsible for setting the organization's 2026 risk agenda and resilience priorities. Talk to Our Team Building a risk agenda that connects continuity planning with workforce readiness, rather than treating them separately? Pierag's Business Risk Advisory practice helps organizations design internal audit and risk management approaches built for how today's risks actually interact. Talk to our team about your 2026 risk agenda. Related reading: Emerging Risks and Trends: Navigating What's Next 2026 | Beyond Net Zero: Why Climate Adaptation Is the Next ESG Frontier | Audit Trail: Ensuring Financial Integrity and Accountability
  • 2-5 Min Read
Point of View | 6-8 Min Read Transparent financial reporting depends on more than accurate top-line numbers. Investors, lenders, and other capital providers rely on financial statements to evaluate a company's performance, assess its prospects for future cash flows, and benchmark it against peers, and a critical part of that evaluation is understanding what actually makes up a company's expenses. Expense composition reveals cost structure, operational efficiency, and long-term sustainability in ways that a single aggregated number cannot. Historically, U.S. GAAP did not require consistent disaggregation of income statement expenses, which left companies free to report at very different levels of detail. That inconsistency made it genuinely difficult for investors and analysts to compare financial results across entities and industries, since one company's "operating expenses" line might hide detail another company discloses openly. This is the gap DISE, the Disaggregation of Income Statement Expenses requirement, was built to close. How DISE Came to Be FASB first addressed this gap in July 2023, introducing a proposed Accounting Standards Update titled Income Statement, Reporting Comprehensive Income, Expense Disaggregation Disclosures (Subtopic 220-40): Disaggregation of Income Statement Expenses. After gathering extensive feedback through public comment periods and roundtable discussions with preparers, investors, and auditors, FASB finalized the amendments as ASU 2024-03 in November 2024. The goal is straightforward: enhance the decision-usefulness of financial reporting by requiring companies to disclose disaggregated expense detail within the footnotes of their financial statements, giving users of financial statements a clearer view of cost composition than aggregated income statement line items alone can provide. ASU 2025-01: Clarifying When DISE Actually Applies In January 2025, FASB issued ASU 2025-01, Income Statement, Reporting Comprehensive Income, Expense Disaggregation Disclosures (Subtopic 220-40): Clarifying the Effective Date. This update did not change the substance of the disaggregation requirement itself. It resolved confusion about exactly when the requirement takes effect, particularly around how it applies to interim reporting periods. The clarified effective dates are: Annual reporting periods: beginning after December 15, 2026 Interim reporting periods: within annual reporting periods beginning after December 15, 2027 Early adoption is permitted for companies that want to get ahead of the requirement rather than wait for the mandatory effective date. The updates apply to all public business entities, without exception, based on size or industry. What DISE Requires in Practice At its core, DISE requires public business entities to disaggregate expenses reported in the income statement into specific, defined categories and to reconcile those disaggregated figures back to the totals already reported in the financial statements. Rather than a single "cost of revenue" or "operating expenses" line, users of the financial statements will be able to see the underlying components that build up to those totals, disclosed within the footnotes. This is a meaningfully different level of transparency than most companies currently provide, which is why the practical implementation work matters more than the disclosure itself. What This Means for Finance and Reporting Teams Even with effective dates that sit a full reporting cycle or more away, the practical work behind DISE compliance is not something to defer until the deadline approaches. Building the general ledger structure, cost allocation methodology, and reconciliation process needed to disaggregate expenses credibly, and to reconcile those disaggregated figures back to totals already reported in the financial statements, is a multi-quarter undertaking for most organizations, not a footnote drafted at year-end close. Companies should treat the extended effective date as planning time, not slack in the schedule. Early adopters in particular may find that getting ahead of the requirement gives them a cleaner comparative baseline once the mandatory effective date arrives, rather than a first year of disclosure that reads as rushed against prior periods that used a different level of detail. Frequently Asked Questions What is DISE in accounting? DISE stands for Disaggregation of Income Statement Expenses, a FASB requirement under ASU 2024-03 that requires public business entities to break down income statement expenses into specific categories and reconcile them to the totals already reported in the financial statements. When does DISE take effect? Under ASU 2025-01's clarified effective dates, annual reporting periods beginning after December 15, 2026, must comply, with interim reporting periods within annual reporting periods beginning after December 15, 2027, also required to comply. Early adoption is permitted. What did ASU 2025-01 change compared to ASU 2024-03? ASU 2025-01 did not change the substance of the DISE requirement. It clarified the effective date, resolving confusion about how the requirement applied to interim reporting periods specifically. Why did FASB introduce the DISE requirement? Because U.S. GAAP historically did not require consistent disaggregation of income statement expenses, creating diversity in reporting practices that made it difficult for investors to compare cost structures and operational efficiency across companies and industries. Does DISE apply to all companies? It applies to all public business entities, regardless of size or industry, with no exceptions carved out in the standard. Who should be preparing for DISE now? CFOs, controllers, and financial reporting teams at public business entities, particularly those whose general ledger systems are not currently structured to produce reconciled expense detail at the category level, the standard requires. Talk to Our Team Preparing your general ledger and reporting processes for DISE compliance ahead of the 2026 and 2027 effective dates? Pierag's Accounting Advisory practice helps finance teams build the data structure and reconciliation processes this standard requires, well ahead of the deadline. Talk to our team about your reporting readiness. Related reading: Standard Setters' Updates, H2 2025 Edition | Audit Trail: Ensuring Financial Integrity and Accountability
  • 5 min Read
Point of View | 7-9 Min Read The Securities and Exchange Board of India has fundamentally changed how listed entities document and disclose related party transactions. Through the Industry Standards Forum, comprising ASSOCHAM, CII, and FICCI, in consultation with SEBI, the regulator introduced Industry Standards on "Minimum Information to be Provided for Review by the Audit Committee and Shareholders for Approval of Related Party Transactions." The framework applies to all listed entities in India and is designed to standardize reporting and disclosure requirements, elevating governance, transparency, and oversight of related party transactions across the board. For internal auditors, this is not a disclosure formality to note in passing. It reshapes what evidence must exist before a related party transaction can be approved, and internal audit functions are directly responsible for verifying that evidence is complete and accurate. From April 2025 to September 2025: How the Effective Date Actually Landed SEBI's RPT Industry Standards had a longer runway to implementation than originally announced. The standards were first set to apply to related party transactions entered into on or after April 1, 2025. Following stakeholder feedback requesting more preparation time, SEBI deferred the effective date, first to July 1, 2025, and then, through a revised circular issued June 26, 2025, to a final effective date of September 1, 2025. That September 1, 2025 date is when the standards actually took hold, and it is the date internal auditors and audit committees should treat as the operative compliance baseline. SEBI followed this in October 2025 with a further amendment. A circular dated October 13, 2025 introduced threshold-based relaxation in the minimum information listed entities must furnish, easing the compliance burden for transactions below specific value thresholds while keeping the core disclosure framework intact for larger and more material transactions. Identifying and Classifying Related Party Transactions The framework's starting requirement is accurate identification of all related parties as defined under Regulation 2(1)(zb) of SEBI's LODR Regulations, 2015. From there, transactions must be classified based on materiality into three categories: Material RPTs, which exceed the prescribed value or turnover thresholds Transactions involving promoters or promoter groups that exceed prescribed thresholds Residual RPTs that fall outside the above categories This classification is not a paperwork exercise. It determines the level of scrutiny, documentation, and approval a transaction requires, and misclassification at this stage undermines everything that follows in the approval process. What Internal Auditors Must Verify Internal auditors carry direct responsibility for confirming that adequate documentation exists for every related party transaction placed before the Audit Committee. The minimum information requirements include: Basic details of the related party The relationship and ownership structure connecting the related party to the listed entity The related party's financial performance Details of previous transactions with that related party The value of the proposed transaction Basic details of the proposed transaction itself For specific transaction types, additional documentation is required. This includes proposed transactions involving the sale, purchase, or supply of goods or services, or similar business transactions; loans, inter-corporate deposits, or advances given by the listed entity or its subsidiary; investments made by the listed entity or its subsidiary; and guarantees (excluding performance guarantees), sureties, indemnities, or comfort letters given by the listed entity or its subsidiary. The Internal Auditor's Practical Role Under the Framework Internal audit's role under these standards extends beyond a single compliance check. In practice, it involves: Pre-approval verification: confirming that the minimum information package for a proposed RPT is complete before it reaches the Audit Committee, not after Materiality classification review: independently testing whether transactions have been correctly classified as material, promoter-related, or residual, since misclassification changes the entire approval pathway Documentation completeness testing: sampling RPT files to confirm all required fields, financial performance data, prior transaction history, and transaction-specific disclosures are present and traceable Threshold monitoring: tracking cumulative related party transaction values across a financial year, since transactions that appear immaterial individually can cross materiality thresholds when aggregated Post-October 2025 threshold application: confirming that the relaxed minimum information requirements are being applied correctly only to transactions that genuinely qualify under the October 2025 threshold-based relaxation, rather than applied broadly by default Why This Matters Beyond Compliance Standardized RPT disclosure exists because related party transactions carry inherent conflict-of-interest risk, and inconsistent documentation historically made it difficult for Audit Committees and shareholders to evaluate whether a transaction genuinely served the listed entity's interests. Internal auditors who treat this framework as a genuine governance safeguard, rather than a box-ticking exercise, give Audit Committees the confidence to approve transactions on solid evidentiary ground and give shareholders a clearer basis for trusting that approval process. Frequently Asked Questions When did SEBI's RPT Industry Standards actually take effect? The standards were originally proposed for April 1, 2025, but were deferred twice and took final effect on September 1, 2025, following a revised circular issued June 26, 2025. What are the three categories of related party transactions under the framework? Transactions are classified as material RPTs exceeding prescribed thresholds, transactions involving promoters or promoter groups exceeding prescribed thresholds, or residual RPTs that fall outside both categories. What is the internal auditor's specific responsibility under the RPT standards? Internal auditors must verify that adequate documentation exists for each related party transaction, including related party details, relationship and ownership information, financial performance, prior transaction history, and transaction-specific disclosures, before the transaction reaches the Audit Committee. What changed in October 2025 regarding RPT disclosure requirements? SEBI issued a circular on October 13, 2025 introducing threshold-based relaxation, easing the minimum information requirements for related party transactions below specific value thresholds while keeping full disclosure requirements for larger and material transactions. Which regulation defines a related party under this framework? Related parties are identified under Regulation 2(1)(zb) of SEBI's LODR Regulations, 2015. Who does the RPT Industry Standards framework apply to? The framework applies to all listed entities in India that are required to comply with Regulation 23 of the LODR Regulations, covering approval of related party transactions by the Audit Committee and, where material, by shareholders. Talk to Our Team Strengthening internal audit procedures around related party transaction documentation and materiality classification? Pierag's Business Risk Advisory practice helps internal audit functions build verification processes that hold up to SEBI's current RPT Industry Standards. Talk to our team about your RPT compliance readiness. Related reading: Audit Trail: Ensuring Financial Integrity and Accountability | Standard Setters' Updates, H2 2025 Edition
  • 7-12 Min Read
Explore how audits empower healthcare providers to tackle AI risks, policy shifts, and pricing reforms with confidence.
  • 10-12 Min Read
Our Services
Our Expertise in Action
Tap into the power of our end-to-end capabilities.
Assurance
Assurance
In today’s complex business environment, robust assurance is not merely a regulatory requirement; it is a cornerstone of trust, transparency, and sustainable growth. Stakeholders, investors, and management rely on accurate and reliable financial information to make critical decisions.
Accounting Advisory
Accounting Advisory
Modern organizations operate in an environment where accounting standards and regulations are continually evolving, posing new challenges for finance leaders and teams.
Business Risk Advisory
Business Risk Advisory
In today’s complex regulatory and rapidly evolving business environment, organizations must move beyond reactive risk controls and adopt a proactive, integrated approach to governance, compliance, and operational risk.
Technology Risk Advisory
Technology Risk Advisory
Businesses today are increasingly being exposed to Technology Risks. Today’s interconnected digital risk landscape is an amalgamation of Cyberattacks, Data Privacy regulations, Cloud Adoption, and Artificial Intelligence (AI) driven disruptions.
ESG & Sustainability
ESG & Sustainability
We provide end-to-end ESG & Sustainability solutions designed to help organizations embed responsible business practices, enhance transparency, and meet global standards.
Deals Advisory
Deals Advisory
In today’s dynamic business landscape, transactions are no longer just about execution—they demand foresight, precision, and seamless integration. At Pierag, we support clients through complex financial events such as strategic deals, IPO readiness, and portfolio transformations with a focus on clarity and control.
Tax
Tax
Our Tax Solutions cover the full spectrum of direct and indirect tax returns and advisory. We assist businesses with accurate preparation, filing, and reconciliation of tax returns across jurisdictions, robust tax accounting and provisioning under global standards, and efficient management of withholding tax obligations.
Driven by our purpose of ‘Inspiring People to do things that Inspire them’ and guided by our values of 'Excellence, Equity, and Empathy', we empower businesses to navigate complexity, build resilience, and achieve sustainable growth.