Resources
/
operating guides

The ROC Annual Compliance Calendar for FY 2026-27

August 25, 2026

Opsmaven HR and People Operations services helping businesses scale teams with structured recruitment and workforce management.

The complete ROC annual compliance calendar for Indian private limited companies in FY 2026-27, plus what changed this year: RoC adjudication powers, the DIR-3 KYC triennial rule, and revised small company thresholds that do not apply to GCC subsidiaries.

A Series B due diligence process does not stop for a missing AOC-4. It stalls on it.

That is roughly how it goes for a mid-market GCC we spoke with in 2026. The parent company's counsel ran a standard closing checklist against the Indian subsidiary and found two annual returns filed late, one auditor appointment never converted into an ADT-1, and a Director KYC lapse that had quietly deactivated a signing director's DIN eleven months earlier. None of it was fraud. None of it was even unusual. It was a compliance calendar that had lived in one company secretary's inbox, and that company secretary had changed firms in March. The deal did not fall apart, but it closed six weeks late and the escrow terms got worse.

That is the pattern worth naming up front: ROC non-compliance rarely announces itself as a crisis. It accumulates quietly, in a subsidiary nobody in the global finance team looks at closely, until a financing round, an audit, or a regulator forces the question. This guide gives you the calendar itself, form by form and quarter by quarter for FY 2026-27, and it explains why the consequences of missing it now land differently than they did two years ago, particularly for a GCC.

What "ROC Compliance" Actually Covers

The Registrar of Companies (RoC) is the state-level office of the Ministry of Corporate Affairs (MCA) that every Indian company is registered with and reports to for the life of the entity. "ROC compliance" is shorthand for the full set of recurring and event-triggered filings a company owes the RoC under the Companies Act, 2013: director disclosures, annual accounts, annual returns, statutory registers, KYC on every director, and a long tail of event-based forms triggered by anything from a change of registered office to a new share allotment.

None of it is optional, and none of it is a one-time task completed at incorporation. It runs for the life of the company, every year, whether or not the company did any business that year.

Why ROC Compliance Is Not Paperwork

It is tempting to file ROC compliance under "administrative housekeeping," something a company secretary handles in the background while the business gets on with the business. Three things make that framing wrong.

It is the mechanism through which the company retains its legal standing. A private limited company is a separate legal person by virtue of being validly incorporated and maintained under the Companies Act. Persistent non-filing is one of the grounds on which the RoC can strike a company off the register under Section 248, and once struck off, the directors are disqualified from being appointed to any other Indian company for five years under Section 164(2). That is not a fine you budget for. It is a status the company loses.

It is the record global stakeholders actually check. A parent company's auditor consolidating the India subsidiary's numbers relies on the entity's own filings being accurate and current. A lender or acquirer's counsel runs exactly the search that stalled the GCC in the opening example. A bank processing an FDI-related inward remittance checks FC-GPR compliance before it will process the next one. ROC compliance is not internal paperwork; it is the public, checkable record of whether the entity is being run properly, and it is the first thing anyone outside the company looks at when they need to trust it quickly.

Enforcement got faster in 2026, not slower. Until February 2026, most non-compliance matters that escalated beyond a simple late fee went to the National Company Law Tribunal (NCLT), an overloaded forum with more than 30,000 pending matters as of March 2025, where the Economic Survey estimated the backlog could take close to a decade to clear. On 10 February 2026, the MCA gave RoCs first-tier adjudication powers under Section 454 of the Companies Act for minor violations, letting Registrars issue notices, hold hearings and pass penalty orders directly, with appeals routed to an expanded network of Regional Directorates rather than straight to the NCLT. The practical effect is that a compliance gap that might once have sat in a tribunal queue for years can now be adjudicated by the Registrar in months. Faster enforcement is generally good for a company that wants matters resolved. It is not good for a company that was relying on procedural delay as an informal grace period.

What Changed for FY 2026-27

Four developments from the past year change how this year's calendar should be read. None of them are cosmetic.

RoC adjudication powers (10 February 2026). Covered above. Registrars can now act directly on minor violations instead of routing them to the NCLT, and the Regional Directorate network expanded from seven locations to ten, adding Ahmedabad, Bengaluru and Chandigarh as appellate seats. Compliance gaps are closer to enforcement than they were a year ago.

The small company threshold rose, and it still excludes subsidiaries. Effective 1 December 2025, the MCA raised the small company thresholds from paid-up capital of Rs 4 crore and turnover of Rs 40 crore to paid-up capital of Rs 10 crore and turnover of Rs 100 crore. Small companies get real relief: no mandatory cash flow statement, an abridged board's report, a minimum of two board meetings a year instead of four, exemption from statutory auditor rotation, and penalties capped at 50% of the standard rate. It is a meaningful compliance discount, and most early-stage India entities now qualify on the numbers alone.

Read the exclusion carefully. A company that is a subsidiary of another company cannot be a small company, regardless of its own paid-up capital or turnover. A GCC is, by definition, a wholly owned subsidiary of its foreign parent. That means the compliance relief the rest of the mid-market gets in 2026 does not reach GCCs at all, however small the India headcount. A 40-person GCC and a 4,000-person Indian conglomerate file under the same full compliance regime.

DIR-3 KYC moved from an annual to a triennial cycle, and the deadline moved. Under G.S.R. 943(E), effective 31 March 2026, Director KYC is no longer an every-September ritual for every director. It now runs on a three-year cycle, and the annual 30 September deadline has been replaced by a 30 June checkpoint for whichever directors fall due that cycle year. A director who filed in September 2025 with no change of contact details will typically not be due again until 2028. But the event-based rule tightened alongside it: any change to a director's mobile number, email address or residential address must be filed within 30 days regardless of where they sit in the three-year cycle, and a missed deadline still deactivates the DIN, with a flat Rs 5,000 reactivation fee. For a GCC with cross-border directors who relocate, change numbers, or hold multiple DINs across group entities, this is the item most likely to be missed precisely because it no longer happens on the same date every year.

A one-time amnesty came and went, and it is a preview of how these things now move. Between roughly February and 15 July 2026, the Companies Compliance Facilitation Scheme (CCFS-2026) let companies clear overdue AOC-4, MGT-7/7A and ADT-1 filings at 10% of the standard additional fee, with immunity from prosecution under Sections 92 and 137 for the filings cleared under the scheme. It has closed. We flag it here for a reason that matters more than the scheme itself: MCA compliance relief windows now open and close within a single financial year, on notice measured in weeks rather than a formal legislative cycle. A calendar built once and left untouched for eighteen months will miss things like this. Build the checking habit, not just the calendar.

The FY 2026-27 ROC Compliance Calendar

FY 2026-27 runs 1 April 2026 to 31 March 2027. The table below groups filings by the quarter in which the underlying reporting period falls, which is how most India company secretaries plan the year; a few due dates land just after the quarter they belong to, and that is noted against each row. Confirm exact dates and applicability against your entity's specific facts before relying on this table; it is general guidance, not a substitute for advice from your company secretary or chartered accountant.

Q1 (April to June 2026): Set the Baseline

Compliance Form Governing provision What it covers Due date Penalty for default
Disclosure of director's interest MBP-1 Section 184(1) Every director discloses interests in other companies, LLPs, firms or bodies corporate, including shareholding At the first board meeting of the financial year, and again whenever the disclosure changes Non-disclosure can attract a fine on the defaulting director; consult your CS on the current quantum, as this provision is within scope of the 2026 decriminalisation reforms in progress
Director disqualification declaration DIR-8 Section 164(2) and Rule 14 of the Companies (Appointment and Qualification of Directors) Rules, 2014 Every director declares they are not disqualified under Section 164(2) Before appointment or reappointment of any director Appointment made without a valid DIR-8 is defective and exposes the company and the appointing officers
Return of deposits DPT-3 Section 73 and Rule 16 of the Companies (Acceptance of Deposits) Rules, 2014 Annual return of outstanding loans, deposits and other specified receipts as at 31 March, including inter-company and shareholder loans a GCC commonly carries On or before 30 June every year (a one-time extension to 31 July applied for FY 2025-26 filings under General Circular 02/2026; do not assume the extension repeats) Substantial fine on the company and every officer in default, escalating for continuing default

Q2 (July to September 2026): Foreign Investment and Director Verification

Compliance Form Governing provision What it covers Due date Penalty for default
Annual return on foreign liabilities and assets FLA Return FEMA, 1999, RBI regulations Every Indian company that has received FDI or made overseas investment, current or prior year, including the standard GCC structure of a foreign parent holding the shares 15 July on a provisional basis if accounts are unaudited, revised by 30 September once audited Penalty under FEMA provisions; persistent non-filing can affect the RBI's view of the entity in future capital transactions
Director KYC DIR-3 KYC Rule 12A, Companies (Appointment and Qualification of Directors) Rules, 2014, as amended by G.S.R. 943(E) Confirms and updates the identity details behind every active DIN 30 June for directors whose three-year cycle falls due that year, or whose DIN is newly issued; within 30 days of any change to mobile, email or address, regardless of cycle Rs 5,000 flat fee to reactivate a deactivated DIN, plus loss of signing authority on all MCA filings until reactivated
Annual General Meeting AGM Section 96 The company's annual shareholder meeting approving accounts, among other business First AGM within 9 months of financial year-end; subsequent AGMs within 6 months of financial year-end, and no more than 15 months between two AGMs Penalty on the company and every officer in default, with a continuing daily fine while the default persists

Q3 (October to December 2026): Accounts, Returns and Auditor

Compliance Form Governing provision What it covers Due date Penalty for default
Half-yearly MSME payment return MSME-1 Section 405 Reports outstanding payments to micro and small enterprise suppliers beyond 45 days from acceptance of goods or services 31 October for the April to September period (the October to March period is due the following 30 April) Substantial fine on the company and every officer in default
Auditor appointment or reappointment ADT-1 Section 139(1) Confirms the statutory auditor's appointment. Filed once for a new auditor's five-year term, or on a casual vacancy or change; annual re-ratification at every AGM is not required once an auditor is appointed for their full term Within 15 days of the general meeting at which the auditor is appointed Fine on the company, escalating with the length of default
Filing of financial statements AOC-4 (or AOC-4 XBRL where applicable) Section 137 and Rule 12, Companies (Accounts) Rules, 2014 Files the audited financial statements, board's report and auditor's report with the RoC Within 30 days of the AGM Additional fee per day of delay, with no fixed ceiling under the current fee schedule; extended default can attract separate penalty proceedings
Annual return MGT-7 (or MGT-7A for small companies and OPCs; not available to a GCC subsidiary) Section 92 and Rule 11, Companies (Management and Administration) Rules, 2014 Files the company's annual return: shareholding, management, and related particulars as at financial year-end Within 60 days of the AGM Additional fee per day of delay, with no fixed ceiling
Certification of annual return MGT-8 Section 92 and Rule 11 Required where paid-up capital is Rs 10 crore or more, or turnover is Rs 50 crore or more; the annual return must then be certified by a Company Secretary in Practice Filed with MGT-7 Defective filing if required certification is missing

Q4 (January to March 2027): Governance and Registers

Compliance Form Governing provision What it covers Due date Penalty for default
Board meetings None (minute book) Section 173 and Secretarial Standard-1 Minimum four board meetings a year with no more than 120 days between two; two meetings a year for OPCs and dormant companies, with at least 90 days between them. Note: a GCC subsidiary does not qualify for the small-company relief of two meetings a year, even where its own capital and turnover would otherwise pass the small-company thresholds Ongoing through the year Governance and audit finding; can support director liability in a broader default
Maintenance of statutory registers None (statutory register) Section 88 Register of directors and KMP and their shareholding, register of members, register of transfers, register of related-party transactions, and others as applicable Maintained continuously Fine on the company for failure to maintain
Half-yearly MSME payment return (second half) MSME-1 Section 405 Covers the October to March period 30 April (first week of the next financial year) Same as above

Event-Based Compliance: The List Most Companies Under-Track

Beyond the recurring calendar, the Companies Act requires a filing within a fixed window of specific events. Each of these is individually easy; the failure mode is that nobody owns tracking which events have happened.

  • Change in authorised or paid-up share capital: file SH-7 for authorised capital changes, generally within 30 days.
  • Allotment or transfer of shares: file PAS-3 for allotments, generally within 15 days.
  • Inter-corporate loans given or accepted: board and, where applicable, shareholder approval and disclosure obligations under Section 186.
  • Loans given or accepted to or from directors, shareholders or their relatives: separate approval and disclosure requirements under Sections 185 and 186.
  • Appointment of a managing or whole-time director or other Key Managerial Personnel, and their remuneration: board and shareholder approval, with MGT-14 filed for the relevant resolution within 30 days.
  • Change of registered office: file INC-22, generally within 15 days.
  • Appointment, resignation or change of director: file DIR-12, generally within 30 days.
  • Creation, modification or satisfaction of a charge on company assets: file CHG-1 or CHG-4, generally within 30 days.
  • Opening or closing a bank account, or changing signatories: internal board resolution and bank-side updates, with downstream implications for FEMA reporting if the account receives foreign remittance.
  • Appointment or change of statutory auditor: ADT-1 as above, plus board and shareholder process.

Missing any one of these individually is rarely fatal. Missing several in the same year, discovered together during an audit or a financing round, is what turns a compliance gap into a due diligence problem.

Why This Hits GCCs Differently

Everything above applies to any Indian private limited company. A GCC carries all of it plus a set of pressures a domestically owned company does not.

Subsidiary status removes the small-company relief entirely. As above: whatever the India entity's own headcount or revenue, a wholly owned subsidiary of a foreign parent files under the full compliance regime. There is no glide path where a young, small GCC gets a lighter year-one calendar.

Every filing sits on top of an FEMA layer. A GCC's compliance obligations do not stop at the Companies Act. Share subscription from the parent triggers FC-GPR on the RBI's FIRMS portal within 30 days of allotment. The FLA return above is annual and separate from FC-GPR. Ongoing billing to the parent sits inside transfer pricing rules, with Form 3CEB due alongside the tax return. None of these are RoC filings in the narrow sense, but they run on the same clock, they are checked by the same due diligence counsel, and a lapse in one is read as a signal about the others.

The signing chain runs through directors who may not be resident in India. A private limited company requires at least one India-resident director, but GCC boards typically include directors based with the parent overseas. A DIN deactivation from a missed KYC filing, now running on the less-obvious triennial cycle, can silently remove a signing director's authority on every MCA filing until it is reactivated, and nobody notices until the next filing bounces.

The parent's own audit and governance depend on the subsidiary's record being clean. A global company consolidating its India subsidiary's financials, reporting to its own board on subsidiary governance, or preparing for its own external audit is relying on the India entity's filings being accurate and on time. A compliance gap in the GCC is not contained to the GCC; it surfaces in the parent's own reporting cycle.

Funding, M&A and internal restructuring all run a compliance check first. Whether it is the parent raising its own capital, acquiring another company, or simply restructuring its India footprint, counsel runs an MCA search on every group entity as a first step. A GCC with a clean record is invisible in that process, which is the correct outcome. A GCC with gaps becomes a line item in every subsequent conversation.

What Happens When Compliance Slips

The consequences compound rather than stack, and they compound faster under the 2026 enforcement changes.

A missed AOC-4 or MGT-7 accrues an additional fee for every day it stays unfiled, with no fixed ceiling under the current fee schedule. A pattern of persistent default across filings can trigger the RoC issuing notices under its new direct adjudication powers rather than a matter drifting in an NCLT queue. A director who has been in default on filing financial statements or annual returns for a continuous period faces disqualification under Section 164(2), which bars them from being appointed a director of any company for five years, not just the defaulting one, which is a real problem for a GCC director who also sits on other group boards. A DIN deactivated for a missed KYC filing removes that person's ability to sign any MCA form until it is reactivated, which can stall an unrelated filing that happened to need their signature. Persistent, uncured default across multiple years is a ground on which the RoC can move to strike the company off the register altogether under Section 248.

None of these outcomes require intent. They are the mechanical result of a calendar that depended on one person remembering, in a company where the people who would notice a problem are sitting in a different country and a different time zone.

Building a Compliance Operating Rhythm That Does Not Depend on Memory

The fix is not more urgency around each individual deadline. It is removing the dependency on any single person's memory or availability.

Put every recurring and event-based filing on a calendar with a named owner and an escalation path, not a spreadsheet one person maintains. When that person is on leave, changes firms, or simply misses a notification, the filing still has to happen.

Separate the recurring calendar from the event-based list, and review the event-based list at every board meeting, not just when someone remembers a change happened. A share allotment, a new director, a bank account change: each needs someone actively asking "did this happen this quarter" rather than waiting to be told.

Track FEMA and Companies Act obligations on the same calendar. They are checked together by every external party who matters, and treating them as two separate workstreams run by two separate advisers is how the gap between them opens.

Re-verify the calendar itself at least twice a year against current rules, not just the filings against the calendar. FY 2026-27 alone brought a threshold change, an adjudication reform, a KYC cycle change and a time-limited amnesty. A calendar built in 2024 and never revisited would be wrong on several counts by now.

Run a quarterly self-audit against the MCA master data for the entity, independent of whoever files the forms. It is the same check a due diligence counsel runs, done on your own timetable instead of theirs.

How OpsMaven Works With Companies on India Compliance

OpsMaven is an Operations-as-a-Service partner for global companies building and running operations in India. Legal and Compliance is one of five service pillars, delivered SLA-backed with audit-ready documentation alongside HR and People Operations, Finance and Accounting, IT Managed Services, and Admin and Procurement, across India, the US, ANZ and Mexico.

For ROC and statutory compliance specifically, we run:

  • The compliance calendar itself: every recurring and event-based filing tracked with named ownership, reviewed against current rules rather than a static template.
  • Statutory filings: AOC-4, MGT-7/7A, ADT-1, DPT-3, MSME-1, DIR-3 KYC and the full event-based set, prepared and filed on schedule.
  • FEMA overlay: FC-GPR, FLA returns and the transfer pricing documentation that sits alongside them, coordinated with the same calendar rather than run separately.
  • Statutory registers and board governance: minute books, registers, board meeting cadence and secretarial standards maintained continuously, not reconstructed before an audit.
  • Quarterly compliance review: an independent check against MCA master data, so gaps surface on your schedule rather than a due diligence counsel's.

We work with GCCs and India subsidiaries from incorporation through to acquisition or exit, which is why the failure modes above are the ones we build our checklists around.

Two ways to move forward

Download the OpsMaven ROC Annual Compliance Calendar (FY 2026-27). The complete quarter-by-quarter calendar from this guide, including the full event-based filing list and the GCC-specific considerations, in a format your finance and legal team can work from directly. Available at www.opsmaven.com.

Book a compliance readiness review. Thirty minutes with our team to run through your current filing status, flag any gaps against the FY 2026-27 calendar, and confirm what, if anything, needs attention before your next AGM or funding conversation. Write to info@opsmaven.com or call +91 73869 19955.

Frequently Asked Questions

What is ROC compliance for a private limited company in India?

ROC compliance is the set of recurring and event-triggered filings a private limited company owes the Registrar of Companies under the Companies Act, 2013, including director disclosures, annual financial statements, the annual return, director KYC, statutory registers, and forms triggered by events such as a change in share capital, a new director, or a change of registered office. It applies for the life of the company, regardless of whether it did business in a given year.

What are the main annual ROC filings and their due dates for FY 2026-27?

DPT-3 (return of deposits) is due by 30 June. The FLA return is due 15 July provisionally and 30 September once audited. Director KYC now runs on a three-year cycle with a 30 June checkpoint for directors due that cycle year, replacing the previous annual 30 September deadline. The AGM is due within six months of financial year-end for an existing company. AOC-4 is due within 30 days of the AGM, and MGT-7 or MGT-7A within 60 days of the AGM. MSME-1 is due twice yearly, 31 October for the April-to-September period and 30 April for the October-to-March period.

What happens if a company misses its ROC filing deadlines?

Late AOC-4 and MGT-7 filings accrue an additional fee for every day of delay with no fixed ceiling under the current fee schedule. Since February 2026, Registrars of Companies can issue notices and pass penalty orders directly for minor violations rather than routing matters to the NCLT, which shortens the time between a missed filing and an enforcement action. Persistent default can lead to director disqualification under Section 164(2) for five years across all companies, DIN deactivation, and, in sustained cases, the company being struck off the register under Section 248.

Do GCCs get any compliance relief as small companies in India?

No. The MCA raised the small company thresholds to paid-up capital of Rs 10 crore and turnover of Rs 100 crore effective 1 December 2025, but the definition explicitly excludes any company that is a subsidiary of another company. A GCC is a wholly owned subsidiary of its foreign parent by definition, so it files under the full compliance regime regardless of its own size in India.

What changed with Director KYC (DIR-3 KYC) in 2026?

Under G.S.R. 943(E), effective 31 March 2026, DIR-3 KYC moved from an annual filing due every 30 September to a three-year cycle with a 30 June checkpoint. A director who filed with unchanged details in 2025 will typically not be due again until 2028. However, any change to a director's mobile number, email or residential address must still be filed within 30 days of the change regardless of the three-year cycle, and a missed deadline deactivates the DIN with a Rs 5,000 reactivation fee.

Why does ROC non-compliance matter more for a GCC than for a typical Indian company?

A GCC's compliance sits underneath a foreign parent's own audit and governance, its FEMA reporting obligations run on the same clock as its Companies Act filings, its board frequently includes non-resident directors whose DIN status can lapse unnoticed, and it does not qualify for small-company relief regardless of size. A GCC also gets checked more often, because parent-company financing, M&A and restructuring activity routinely triggers a due diligence review of every group entity, India included.

Is there a single source of truth for a company's current ROC compliance status?

The MCA's public company master data, searchable on the MCA portal, shows filing history and any flags against a given CIN. It is the same check external counsel and auditors run, which is why a periodic internal review against that same data, rather than trust in an internal tracker, is the more reliable control.

This guide is general information on ROC and MCA compliance for Indian private limited companies and is not legal, tax or company secretarial advice. Statutory forms, thresholds, due dates and penalties referenced here are current as of August 2026, change periodically, and can vary by company classification and state. Confirm your specific compliance position with a qualified company secretary or chartered accountant before acting.

This guide is part of an OpsMaven series on running an India operation properly. See also Setting Up a GCC in India: The Complete Phase-by-Phase Setup Calendar for entity setup mechanics, and the India Expansion Playbook for choosing the right entry mode before you incorporate.

info@opsmaven.com · +91 73869 19955 · www.opsmaven.com

Access the full guide
Enter your details to download the complete playbook and get access to future operational resources.
Please enter full name
Please enter valid email
Please enter company

Thank you for reaching out.

Our team is reviewing your message and will get back to you shortly.
Oops! Something went wrong while submitting the form.

Need help implementing this?

If you're working through similar challenges, OpsMaven can help you design and manage the operational systems behind scale.