The complete ROC annual compliance calendar for Indian private limited companies in FY 2026-27, plus what changed this year: RoC adjudication powers, the DIR-3 KYC triennial rule, and revised small company thresholds that do not apply to GCC subsidiaries.
A Series B due diligence process does not stop for a missing AOC-4. It stalls on it.
That is roughly how it goes for a mid-market GCC we spoke with in 2026. The parent company's counsel ran a standard closing checklist against the Indian subsidiary and found two annual returns filed late, one auditor appointment never converted into an ADT-1, and a Director KYC lapse that had quietly deactivated a signing director's DIN eleven months earlier. None of it was fraud. None of it was even unusual. It was a compliance calendar that had lived in one company secretary's inbox, and that company secretary had changed firms in March. The deal did not fall apart, but it closed six weeks late and the escrow terms got worse.
That is the pattern worth naming up front: ROC non-compliance rarely announces itself as a crisis. It accumulates quietly, in a subsidiary nobody in the global finance team looks at closely, until a financing round, an audit, or a regulator forces the question. This guide gives you the calendar itself, form by form and quarter by quarter for FY 2026-27, and it explains why the consequences of missing it now land differently than they did two years ago, particularly for a GCC.
The Registrar of Companies (RoC) is the state-level office of the Ministry of Corporate Affairs (MCA) that every Indian company is registered with and reports to for the life of the entity. "ROC compliance" is shorthand for the full set of recurring and event-triggered filings a company owes the RoC under the Companies Act, 2013: director disclosures, annual accounts, annual returns, statutory registers, KYC on every director, and a long tail of event-based forms triggered by anything from a change of registered office to a new share allotment.
None of it is optional, and none of it is a one-time task completed at incorporation. It runs for the life of the company, every year, whether or not the company did any business that year.
It is tempting to file ROC compliance under "administrative housekeeping," something a company secretary handles in the background while the business gets on with the business. Three things make that framing wrong.
It is the mechanism through which the company retains its legal standing. A private limited company is a separate legal person by virtue of being validly incorporated and maintained under the Companies Act. Persistent non-filing is one of the grounds on which the RoC can strike a company off the register under Section 248, and once struck off, the directors are disqualified from being appointed to any other Indian company for five years under Section 164(2). That is not a fine you budget for. It is a status the company loses.
It is the record global stakeholders actually check. A parent company's auditor consolidating the India subsidiary's numbers relies on the entity's own filings being accurate and current. A lender or acquirer's counsel runs exactly the search that stalled the GCC in the opening example. A bank processing an FDI-related inward remittance checks FC-GPR compliance before it will process the next one. ROC compliance is not internal paperwork; it is the public, checkable record of whether the entity is being run properly, and it is the first thing anyone outside the company looks at when they need to trust it quickly.
Enforcement got faster in 2026, not slower. Until February 2026, most non-compliance matters that escalated beyond a simple late fee went to the National Company Law Tribunal (NCLT), an overloaded forum with more than 30,000 pending matters as of March 2025, where the Economic Survey estimated the backlog could take close to a decade to clear. On 10 February 2026, the MCA gave RoCs first-tier adjudication powers under Section 454 of the Companies Act for minor violations, letting Registrars issue notices, hold hearings and pass penalty orders directly, with appeals routed to an expanded network of Regional Directorates rather than straight to the NCLT. The practical effect is that a compliance gap that might once have sat in a tribunal queue for years can now be adjudicated by the Registrar in months. Faster enforcement is generally good for a company that wants matters resolved. It is not good for a company that was relying on procedural delay as an informal grace period.
Four developments from the past year change how this year's calendar should be read. None of them are cosmetic.
RoC adjudication powers (10 February 2026). Covered above. Registrars can now act directly on minor violations instead of routing them to the NCLT, and the Regional Directorate network expanded from seven locations to ten, adding Ahmedabad, Bengaluru and Chandigarh as appellate seats. Compliance gaps are closer to enforcement than they were a year ago.
The small company threshold rose, and it still excludes subsidiaries. Effective 1 December 2025, the MCA raised the small company thresholds from paid-up capital of Rs 4 crore and turnover of Rs 40 crore to paid-up capital of Rs 10 crore and turnover of Rs 100 crore. Small companies get real relief: no mandatory cash flow statement, an abridged board's report, a minimum of two board meetings a year instead of four, exemption from statutory auditor rotation, and penalties capped at 50% of the standard rate. It is a meaningful compliance discount, and most early-stage India entities now qualify on the numbers alone.
Read the exclusion carefully. A company that is a subsidiary of another company cannot be a small company, regardless of its own paid-up capital or turnover. A GCC is, by definition, a wholly owned subsidiary of its foreign parent. That means the compliance relief the rest of the mid-market gets in 2026 does not reach GCCs at all, however small the India headcount. A 40-person GCC and a 4,000-person Indian conglomerate file under the same full compliance regime.
DIR-3 KYC moved from an annual to a triennial cycle, and the deadline moved. Under G.S.R. 943(E), effective 31 March 2026, Director KYC is no longer an every-September ritual for every director. It now runs on a three-year cycle, and the annual 30 September deadline has been replaced by a 30 June checkpoint for whichever directors fall due that cycle year. A director who filed in September 2025 with no change of contact details will typically not be due again until 2028. But the event-based rule tightened alongside it: any change to a director's mobile number, email address or residential address must be filed within 30 days regardless of where they sit in the three-year cycle, and a missed deadline still deactivates the DIN, with a flat Rs 5,000 reactivation fee. For a GCC with cross-border directors who relocate, change numbers, or hold multiple DINs across group entities, this is the item most likely to be missed precisely because it no longer happens on the same date every year.
A one-time amnesty came and went, and it is a preview of how these things now move. Between roughly February and 15 July 2026, the Companies Compliance Facilitation Scheme (CCFS-2026) let companies clear overdue AOC-4, MGT-7/7A and ADT-1 filings at 10% of the standard additional fee, with immunity from prosecution under Sections 92 and 137 for the filings cleared under the scheme. It has closed. We flag it here for a reason that matters more than the scheme itself: MCA compliance relief windows now open and close within a single financial year, on notice measured in weeks rather than a formal legislative cycle. A calendar built once and left untouched for eighteen months will miss things like this. Build the checking habit, not just the calendar.
FY 2026-27 runs 1 April 2026 to 31 March 2027. The table below groups filings by the quarter in which the underlying reporting period falls, which is how most India company secretaries plan the year; a few due dates land just after the quarter they belong to, and that is noted against each row. Confirm exact dates and applicability against your entity's specific facts before relying on this table; it is general guidance, not a substitute for advice from your company secretary or chartered accountant.
Q1 (April to June 2026): Set the Baseline
Q2 (July to September 2026): Foreign Investment and Director Verification
Q3 (October to December 2026): Accounts, Returns and Auditor
Q4 (January to March 2027): Governance and Registers
Beyond the recurring calendar, the Companies Act requires a filing within a fixed window of specific events. Each of these is individually easy; the failure mode is that nobody owns tracking which events have happened.
- Change in authorised or paid-up share capital: file SH-7 for authorised capital changes, generally within 30 days.
- Allotment or transfer of shares: file PAS-3 for allotments, generally within 15 days.
- Inter-corporate loans given or accepted: board and, where applicable, shareholder approval and disclosure obligations under Section 186.
- Loans given or accepted to or from directors, shareholders or their relatives: separate approval and disclosure requirements under Sections 185 and 186.
- Appointment of a managing or whole-time director or other Key Managerial Personnel, and their remuneration: board and shareholder approval, with MGT-14 filed for the relevant resolution within 30 days.
- Change of registered office: file INC-22, generally within 15 days.
- Appointment, resignation or change of director: file DIR-12, generally within 30 days.
- Creation, modification or satisfaction of a charge on company assets: file CHG-1 or CHG-4, generally within 30 days.
- Opening or closing a bank account, or changing signatories: internal board resolution and bank-side updates, with downstream implications for FEMA reporting if the account receives foreign remittance.
- Appointment or change of statutory auditor: ADT-1 as above, plus board and shareholder process.
Missing any one of these individually is rarely fatal. Missing several in the same year, discovered together during an audit or a financing round, is what turns a compliance gap into a due diligence problem.
Everything above applies to any Indian private limited company. A GCC carries all of it plus a set of pressures a domestically owned company does not.
Subsidiary status removes the small-company relief entirely. As above: whatever the India entity's own headcount or revenue, a wholly owned subsidiary of a foreign parent files under the full compliance regime. There is no glide path where a young, small GCC gets a lighter year-one calendar.
Every filing sits on top of an FEMA layer. A GCC's compliance obligations do not stop at the Companies Act. Share subscription from the parent triggers FC-GPR on the RBI's FIRMS portal within 30 days of allotment. The FLA return above is annual and separate from FC-GPR. Ongoing billing to the parent sits inside transfer pricing rules, with Form 3CEB due alongside the tax return. None of these are RoC filings in the narrow sense, but they run on the same clock, they are checked by the same due diligence counsel, and a lapse in one is read as a signal about the others.
The signing chain runs through directors who may not be resident in India. A private limited company requires at least one India-resident director, but GCC boards typically include directors based with the parent overseas. A DIN deactivation from a missed KYC filing, now running on the less-obvious triennial cycle, can silently remove a signing director's authority on every MCA filing until it is reactivated, and nobody notices until the next filing bounces.
The parent's own audit and governance depend on the subsidiary's record being clean. A global company consolidating its India subsidiary's financials, reporting to its own board on subsidiary governance, or preparing for its own external audit is relying on the India entity's filings being accurate and on time. A compliance gap in the GCC is not contained to the GCC; it surfaces in the parent's own reporting cycle.
Funding, M&A and internal restructuring all run a compliance check first. Whether it is the parent raising its own capital, acquiring another company, or simply restructuring its India footprint, counsel runs an MCA search on every group entity as a first step. A GCC with a clean record is invisible in that process, which is the correct outcome. A GCC with gaps becomes a line item in every subsequent conversation.
The consequences compound rather than stack, and they compound faster under the 2026 enforcement changes.
A missed AOC-4 or MGT-7 accrues an additional fee for every day it stays unfiled, with no fixed ceiling under the current fee schedule. A pattern of persistent default across filings can trigger the RoC issuing notices under its new direct adjudication powers rather than a matter drifting in an NCLT queue. A director who has been in default on filing financial statements or annual returns for a continuous period faces disqualification under Section 164(2), which bars them from being appointed a director of any company for five years, not just the defaulting one, which is a real problem for a GCC director who also sits on other group boards. A DIN deactivated for a missed KYC filing removes that person's ability to sign any MCA form until it is reactivated, which can stall an unrelated filing that happened to need their signature. Persistent, uncured default across multiple years is a ground on which the RoC can move to strike the company off the register altogether under Section 248.
None of these outcomes require intent. They are the mechanical result of a calendar that depended on one person remembering, in a company where the people who would notice a problem are sitting in a different country and a different time zone.
The fix is not more urgency around each individual deadline. It is removing the dependency on any single person's memory or availability.
Put every recurring and event-based filing on a calendar with a named owner and an escalation path, not a spreadsheet one person maintains. When that person is on leave, changes firms, or simply misses a notification, the filing still has to happen.
Separate the recurring calendar from the event-based list, and review the event-based list at every board meeting, not just when someone remembers a change happened. A share allotment, a new director, a bank account change: each needs someone actively asking "did this happen this quarter" rather than waiting to be told.
Track FEMA and Companies Act obligations on the same calendar. They are checked together by every external party who matters, and treating them as two separate workstreams run by two separate advisers is how the gap between them opens.
Re-verify the calendar itself at least twice a year against current rules, not just the filings against the calendar. FY 2026-27 alone brought a threshold change, an adjudication reform, a KYC cycle change and a time-limited amnesty. A calendar built in 2024 and never revisited would be wrong on several counts by now.
Run a quarterly self-audit against the MCA master data for the entity, independent of whoever files the forms. It is the same check a due diligence counsel runs, done on your own timetable instead of theirs.
OpsMaven is an Operations-as-a-Service partner for global companies building and running operations in India. Legal and Compliance is one of five service pillars, delivered SLA-backed with audit-ready documentation alongside HR and People Operations, Finance and Accounting, IT Managed Services, and Admin and Procurement, across India, the US, ANZ and Mexico.
For ROC and statutory compliance specifically, we run:
- The compliance calendar itself: every recurring and event-based filing tracked with named ownership, reviewed against current rules rather than a static template.
- Statutory filings: AOC-4, MGT-7/7A, ADT-1, DPT-3, MSME-1, DIR-3 KYC and the full event-based set, prepared and filed on schedule.
- FEMA overlay: FC-GPR, FLA returns and the transfer pricing documentation that sits alongside them, coordinated with the same calendar rather than run separately.
- Statutory registers and board governance: minute books, registers, board meeting cadence and secretarial standards maintained continuously, not reconstructed before an audit.
- Quarterly compliance review: an independent check against MCA master data, so gaps surface on your schedule rather than a due diligence counsel's.
We work with GCCs and India subsidiaries from incorporation through to acquisition or exit, which is why the failure modes above are the ones we build our checklists around.
Two ways to move forward
What is ROC compliance for a private limited company in India?
ROC compliance is the set of recurring and event-triggered filings a private limited company owes the Registrar of Companies under the Companies Act, 2013, including director disclosures, annual financial statements, the annual return, director KYC, statutory registers, and forms triggered by events such as a change in share capital, a new director, or a change of registered office. It applies for the life of the company, regardless of whether it did business in a given year.
What are the main annual ROC filings and their due dates for FY 2026-27?
DPT-3 (return of deposits) is due by 30 June. The FLA return is due 15 July provisionally and 30 September once audited. Director KYC now runs on a three-year cycle with a 30 June checkpoint for directors due that cycle year, replacing the previous annual 30 September deadline. The AGM is due within six months of financial year-end for an existing company. AOC-4 is due within 30 days of the AGM, and MGT-7 or MGT-7A within 60 days of the AGM. MSME-1 is due twice yearly, 31 October for the April-to-September period and 30 April for the October-to-March period.
What happens if a company misses its ROC filing deadlines?
Late AOC-4 and MGT-7 filings accrue an additional fee for every day of delay with no fixed ceiling under the current fee schedule. Since February 2026, Registrars of Companies can issue notices and pass penalty orders directly for minor violations rather than routing matters to the NCLT, which shortens the time between a missed filing and an enforcement action. Persistent default can lead to director disqualification under Section 164(2) for five years across all companies, DIN deactivation, and, in sustained cases, the company being struck off the register under Section 248.
Do GCCs get any compliance relief as small companies in India?
No. The MCA raised the small company thresholds to paid-up capital of Rs 10 crore and turnover of Rs 100 crore effective 1 December 2025, but the definition explicitly excludes any company that is a subsidiary of another company. A GCC is a wholly owned subsidiary of its foreign parent by definition, so it files under the full compliance regime regardless of its own size in India.
What changed with Director KYC (DIR-3 KYC) in 2026?
Under G.S.R. 943(E), effective 31 March 2026, DIR-3 KYC moved from an annual filing due every 30 September to a three-year cycle with a 30 June checkpoint. A director who filed with unchanged details in 2025 will typically not be due again until 2028. However, any change to a director's mobile number, email or residential address must still be filed within 30 days of the change regardless of the three-year cycle, and a missed deadline deactivates the DIN with a Rs 5,000 reactivation fee.
Why does ROC non-compliance matter more for a GCC than for a typical Indian company?
A GCC's compliance sits underneath a foreign parent's own audit and governance, its FEMA reporting obligations run on the same clock as its Companies Act filings, its board frequently includes non-resident directors whose DIN status can lapse unnoticed, and it does not qualify for small-company relief regardless of size. A GCC also gets checked more often, because parent-company financing, M&A and restructuring activity routinely triggers a due diligence review of every group entity, India included.
Is there a single source of truth for a company's current ROC compliance status?
The MCA's public company master data, searchable on the MCA portal, shows filing history and any flags against a given CIN. It is the same check external counsel and auditors run, which is why a periodic internal review against that same data, rather than trust in an internal tracker, is the more reliable control.
This guide is general information on ROC and MCA compliance for Indian private limited companies and is not legal, tax or company secretarial advice. Statutory forms, thresholds, due dates and penalties referenced here are current as of August 2026, change periodically, and can vary by company classification and state. Confirm your specific compliance position with a qualified company secretary or chartered accountant before acting.
This guide is part of an OpsMaven series on running an India operation properly. See also Setting Up a GCC in India: The Complete Phase-by-Phase Setup Calendar for entity setup mechanics, and the India Expansion Playbook for choosing the right entry mode before you incorporate.
info@opsmaven.com · +91 73869 19955 · www.opsmaven.com