Why a Mid-Year Compliance Check Is Non-Negotiable in 2026
This HR compliance checklist covers what Indian employers must address now. The compliance landscape changed significantly in the past eight months. The four Labour Codes are now fully operational, the DPDP Act Rules are in effect, and several states have issued their own amendments to central provisions.
For companies with 100 or more employees, a single compliance gap β a missed ESI filing, an incorrectly structured CTC, or an unsigned data processing agreement β can result in penalties ranging from lakhs to hundreds of crores.
This checklist covers the 10 most critical items every HR and payroll team should audit before September 2026.
The HR Compliance Checklist
1. CTC Structure: The 50% Basic Pay Rule
What changed: Under the Code on Wages, at least 50% of an employee’s CTC must now be classified as “wages” (basic pay + dearness allowance). Allowances like HRA, conveyance, and special allowances cannot constitute more than 50% of total compensation.
What to audit:
- Pull your current salary structures and verify the wages-to-CTC ratio for every employee grade
- If any grade falls below the 50% threshold, restructure before the next payroll cycle
- Recalculate PF, ESI, gratuity, and bonus contributions based on the revised wage definition
Risk if missed: Statutory contribution shortfalls, back-payment demands from EPFO/ESIC, and penalties under the Code on Social Security.
2. Full and Final Settlement: 48-Hour Rule
What changed: Employers must complete the Full and Final (F&F) settlement within 48 hours of an employee’s last working day β whether the separation is resignation, termination, or retrenchment.
What to audit:
- Review your current F&F turnaround time (most companies still take 30β60 days)
- Ensure payroll systems can trigger F&F calculations on the exit date itself
- Document the process so that asset recovery, leave encashment, and gratuity are processed in parallel, not sequentially
Risk if missed: Non-compliance penalties under the Code on Wages, plus reputational risk with departing employees.
3. DPDP Act: Data Processing Agreements
What changed: Under the Digital Personal Data Protection Act, any vendor processing employee data β payroll providers, background verification agencies, benefits administrators β is classified as a “Data Processor.” The employer (Data Fiduciary) must have a signed Data Processing Agreement (DPA) with each such vendor.
What to audit:
- List every vendor that handles employee personal data
- Verify that a signed DPA exists with each one
- Confirm that employee consent covers all current data processing purposes
Risk if missed: Penalties up to βΉ250 crore per data breach incident.
4. Gig and Contract Worker Registration
What changed: The Social Security (Central) Rules, 2026, notified in May, require employers engaging gig or platform workers to register them on a central government portal in real time and contribute 1β2% of annual turnover towards their social security.
What to audit:
- Identify all contract, gig, or platform-based workers engaged by your organisation
- Verify whether the 90-day / 120-day engagement threshold applies
- Confirm that your staffing partners are registered and contributing as required
5. ESI and PF Contribution Accuracy
What to audit:
- Verify ESI applicability: the wage ceiling is now βΉ21,000 per month
- Confirm PF contributions are calculated on the revised wage definition (not the old basic-only formula)
- Cross-check challan submissions for April, May, and June against actual wage disbursements
- Ensure voluntary PF contributions for employees above the ceiling are correctly handled
Risk if missed: Interest and penalties on delayed or short contributions. EPFO audits are increasingly automated and flag discrepancies faster.
6. Leave Policy Alignment
What changed: The Code on Occupational Safety, Health and Working Conditions standardises leave entitlements and working hour limits. Several states have issued their own rules modifying the central provisions.
What to audit:
- Verify that your leave policy matches the applicable state rules for each location where you have employees
- Confirm that leave encashment is calculated on the revised wage definition
- Ensure compensatory off and overtime policies comply with the double-rate overtime mandate
7. Sexual Harassment (POSH) Compliance
What to audit:
- Confirm that your Internal Complaints Committee (ICC) is constituted with the required external member
- Verify that annual POSH training was conducted in the current calendar year
- File the annual report with the District Officer (many companies miss this filing)
Risk if missed: Non-constitution of ICC is a punishable offence. Non-filing of the annual report attracts penalties under the POSH Act.
8. Statutory Registers and Records
What to audit:
- Maintain registers for wages, overtime, leave, fines, and deductions as required under the Labour Codes
- Verify that digital records meet the format and retention requirements specified in the rules
- Ensure that records are accessible for inspection at each establishment
9. State-Specific Labour Welfare Fund Contributions
What to audit:
- Identify all states where your company has employees
- Verify the applicable Labour Welfare Fund contribution rates and due dates for each state
- Confirm that contributions for H1 2026 have been deposited on time
Risk if missed: State-level penalties vary, but delayed contributions typically attract interest at 12β18% per annum.
10. Employment Agreement Updates
What to audit:
- Verify that employment agreements reflect the current wage definition and CTC structure
- Ensure that non-compete and confidentiality clauses comply with applicable state-specific rules
- Update data processing consent clauses to align with the DPDP Act
- Confirm that fixed-term employment contracts include the mandated benefits (gratuity, leave, etc.)
How TMS Can Help
Managing compliance across multiple states, wage codes, and data protection regulations is a full-time operation β and one where errors carry significant financial and legal risk.
TMS handles end-to-end statutory compliance for companies with 100 to 5,000+ employees: payroll processing, PF/ESI contributions, labour welfare fund filings, POSH compliance support, and employee documentation β all aligned with the 2026 Labour Codes and the DPDP Act.
If your HR team is spending more time on compliance checklists than on your people, it is time to talk.
Need Help Staying Compliant?
TMS handles end-to-end statutory compliance for companies with 100 to 5,000+ employees across India.
Sources: Code on Wages 2019 (as implemented 2025), Code on Social Security 2020, DPDP Act 2023 (Rules notified Nov 2025), Social Security (Central) Rules 2026

