Lead with clarity. Operate with truth.
Pierag Consulting is a global consulting firm with a unique business model that blends domestic proficiency with global expertise to serve clients globally. As a consulting organization, our expertise spans across various industries, allowing us to provide tailored solutions that address the unique challenges organizations face.
Our Philosophy
Rethink the Frame
Thinking Beyond the Box
+
We challenge conventional boundaries, bringing fresh perspectives and bold ideas that redefine how businesses solve problems and capture opportunities.
01
Always Heading Upwards
+
Growth is our constant direction. With every engagement, we aim to elevate performance, strengthen resilience, and create long-term impact for our clients.
02
A Multidimensional Approach
+
We bring together diverse expertise, data-driven insights, and human-centered thinking to design solutions that are practical, holistic, and future-ready.
03
Thinking Beyond the Box
+
We challenge conventional boundaries, bringing fresh perspectives and bold ideas that redefine how businesses solve problems and capture opportunities.
01
Always Heading Upwards
+
Growth is our constant direction. With every engagement, we aim to elevate performance, strengthen resilience, and create long-term impact for our clients.
02
A Multidimensional Approach
+
We bring together diverse expertise, data-driven insights, and human-centered thinking to design solutions that are practical, holistic, and future-ready.
03
Thinking Beyond the Box
+
We challenge conventional boundaries, bringing fresh perspectives and bold ideas that redefine how businesses solve problems and capture opportunities.
01
Always Heading Upwards
+
Growth is our constant direction. With every engagement, we aim to elevate performance, strengthen resilience, and create long-term impact for our clients.
02
A Multidimensional Approach
+
We bring together diverse expertise, data-driven insights, and human-centered thinking to design solutions that are practical, holistic, and future-ready.
03
Our Insights
Real Problems, Real Thinking
The ESG landscape is moving from broad commitments to deeper implementation, stronger accountability and greater operational complexity. The September 2026 edition of Pierag’s ESG Perspective brings together key regulatory and market developments shaping how organisations approach sustainability, climate action and ESG reporting. This edition highlights the European Commission’s continued rollout of CBAM implementation and verification guidance, developments in international carbon markets and Article 6 cooperation, and the UAE’s introduction of a dedicated Transition Finance Framework to support decarbonisation across hard-to-abate sectors. It also covers important developments in the circular economy, including the EU Packaging and Packaging Waste Regulation and new rules supporting a more circular automotive sector. In India, the recognition of heatwaves and lightning as notified natural calamities reinforces the growing focus on climate resilience and disaster risk management. Meanwhile, Japan’s efforts to integrate corporate nature-related disclosures into biodiversity policymaking signal the increasing importance of nature and biodiversity data. Beyond regulatory updates, this edition explores a broader question: Can ESG data achieve the same level of credibility as financial data? As sustainability disclosures face increasing scrutiny and assurance expectations, organisations will need more than technology or reporting processes alone. Reliable ESG reporting will require the right combination of accurate source data, technology-enabled transformation, robust governance and professional judgement. The direction is clear — ESG is becoming increasingly embedded in business decision-making, and organisations that strengthen their data, governance and reporting foundations today will be better positioned to navigate what comes next. Read the September 2026 edition of ESG Perspective for a closer look at the regulatory developments and trends shaping the sustainability landscape.
Material weakness remediation is not simply about correcting a control that has failed. It requires organizations to understand and address the broader conditions that contributed to the weakness and build an internal control environment capable of operating effectively over time. In this report, Pierag Consulting analyzes the remediation actions disclosed by 114 U.S. listed companies that subsequently remediated previously reported material weaknesses. The research examines the actions companies took, the approaches most commonly disclosed and the ways organizations combined multiple remediation measures to address underlying control deficiencies. The findings indicate that effective remediation is rarely achieved through a single corrective action. Companies typically take a multi-dimensional approach, strengthening different aspects of their control environment simultaneously. The most frequently disclosed actions included control design and process redesign, personnel and staffing enhancements, training and capability development, management review and monitoring controls, and improvements to policies, documentation and standard operating procedures. The analysis also highlights how remediation actions are often interconnected. Organizations may combine additional capacity with training to strengthen control execution, pair updated documentation with capability building to support consistent adoption, or reinforce technology-based controls with stronger management oversight. At the core of sustainable remediation are five critical dimensions: Design, Capacity, Capability, Oversight and Institutionalization. Together, these dimensions help organizations move beyond addressing the immediate deficiency and focus on building the conditions required for controls to operate consistently and sustainably. This report provides practical insights for management teams and organizations seeking to strengthen their remediation strategies, address the root causes of control deficiencies and build more resilient and sustainable internal control environments. Download and read the full report to explore the detailed findings, remediation patterns and practical insights from our analysis of material weakness remediation disclosures.
The H1 2026 Standard Setters’ Updates provides a consolidated view of the key accounting, financial reporting and regulatory developments from the first half of 2026. It brings together the latest FASB guidance, standards effective in 2026, significant SEC developments and ongoing standard-setting initiatives, helping finance and accounting professionals stay informed about changes shaping the reporting landscape. The update covers important developments such as guidance on paid-in-kind dividends on equity-classified preferred stock and environmental credits and environmental credit obligations, along with accounting standards relating to credit losses, convertible debt, stock compensation, income tax disclosures and joint venture formations that are relevant for 2026 reporting periods. It also highlights key SEC regulatory developments spanning capital raising, public company reporting, private fund reporting, foreign private issuer disclosures, investment companies, climate-related disclosures and market structure. These developments reflect the broader evolution of regulatory expectations and reporting requirements for businesses and financial market participants. Looking ahead, the update provides visibility into FASB projects currently under development, including accounting for crypto asset transfers, private credit disclosures, commodities, transferable tax credits, debt exchanges, digital assets and hedge accounting. It captures the current status of these initiatives and the potential next steps, offering a view of areas that may influence future accounting and disclosure practices. Overall, this update is designed to help finance and accounting teams understand what has changed, identify what is now effective and stay ahead of developments that could shape future reporting requirements. Read the full H1 2026 Standard Setters’ Updates to explore the latest accounting, regulatory and standard-setting developments and understand what they could mean for your reporting landscape.
Security threats are evolving faster than traditional compliance cycles can track. Cloud environments are growing more complex. AI is embedding itself into products and workflows at a pace most security programs were not designed to handle. In this environment, a certification earned once a year and then largely forgotten is not a security posture. It is a snapshot that becomes less accurate with every week that passes. HITRUST's evolution through 2026 reflects this reality directly, and understanding where the framework is heading matters for any organisation thinking seriously about cybersecurity assurance, third-party trust, and AI risk governance. What HITRUST Is and How It Has Evolved HITRUST was founded in 2007 to address the fragmented complexity of HIPAA and HITECH compliance in the healthcare sector. It has since expanded into a harmonised assurance model that consolidates requirements from more than 60 frameworks, regulations, and standards into a single certifiable structure known as the HITRUST Common Security Framework (CSF). [1] The list of sources harmonised within the CSF includes NIST CSF, ISO/IEC 27001, PCI DSS, CMMC, GDPR, and HIPAA. [2] This consolidation has real operational value. Rather than running parallel compliance programs for each applicable framework, organisations can address overlapping requirements through a single control baseline that is assessed and certified by an independent, HITRUST-authorised external assessor. As of May 2026, the current version of the framework is CSF v11.8.0, which introduced further consolidation of requirement statements to reduce overlap and refreshed several authoritative source mappings. [3] The Three Assessment Types: e1, i1, and r2 HITRUST offers three validated assessment and certification options, each designed for a different risk profile and level of required assurance. [4] The e1 assessment covers 44 essential cybersecurity hygiene controls. It is suited for organisations at an earlier stage of security maturity or those establishing a baseline assurance credential with lower-risk profiles. The i1 assessment provides an intermediate level of assurance with a broader control set and implementation-level evidence requirements. It is a one-year validated assessment sitting between the e1 and the more rigorous r2. The r2 assessment is the most comprehensive option. It is a two-year validated assessment that tailors controls to the organisation's specific risk factors using a maturity-based scoring approach. The r2 is typically pursued by organisations in healthcare, financial services, and other sectors where third-party assurance requirements are highest. Notably, 100% of r2 certifications directly validate service provider risks. [5] Choosing the right assessment type depends on the organisation's risk profile, the sensitivity of data being handled, and the assurance expectations of customers and business partners. Why Point-in-Time Assurance Is No Longer Sufficient The traditional audit model operates in preparation and certification cycles. An organisation prepares for an assessment, completes it, receives a certification, and then largely repeats the process when the next cycle approaches. In a stable environment, this approach is manageable. In today's environment, with continuous cloud changes, new vendor dependencies, AI integrations, and rapidly evolving attack techniques, it creates dangerous gaps between what the certificate says and what is actually happening in the control environment. The 2026 HITRUST Trust Report puts the stakes in clear terms. The report found that 99.62% of HITRUST-certified environments remained breach-free in 2025. By contrast, independent surveys indicate that more than 40% of organisations overall have experienced a security breach. [5] That gap reflects the cumulative benefit of structured, validated, and continuously monitored assurance over time, not just the benefit of a certification label. Third-party risk is compounding the pressure. According to the Verizon 2025 Data Breach Investigations Report, which analysed more than 22,000 security incidents and 12,195 confirmed breaches, third-party involvement in breaches doubled from 15% to 30% in a single year. [6] In response, over 80% of HITRUST certifications, including all r2 certifications, are specifically designed to address risks arising from service providers and supply chain dependencies. [5] HITRUST addresses the continuous monitoring gap through formal requirements built into the CSF Assurance Program. After certification, assessed entities are required to implement an ongoing monitoring programme covering configuration management, risk analysis for planned changes, and selective evaluation of security controls throughout the year. [7] This is what continuous assurance looks like in practice: an operational discipline maintained year-round, not a document produced at audit time. The Assurance Intelligence Engine A distinguishing feature of HITRUST's assurance model is its centralised quality review process. Every certification, without exception, undergoes independent quality assurance review by HITRUST before issuance. [5] The Assurance Intelligence Engine (AIE) reinforces this with automated analysis applied to assessment documentation throughout the assessment process, checking for inconsistencies and errors before submission. [8] Together, centralised quality assurance and the AIE produce a level of consistency and credibility that self-attested compliance approaches cannot reliably achieve. HITRUST AI Security Assessment and Certification AI introduces security risks that traditional frameworks were not originally designed to address. When AI systems are embedded in products and workflows, the attack surface expands to include training data integrity, model behaviour, inference vulnerabilities, prompt injection risks, data leakage, and dependencies on third-party model providers. HITRUST launched its AI Security Assessment and Certification in May 2026 to address these risks directly. [8] The certification is built on the same Cyber Threat Adaptive methodology as the core HITRUST CSF and is aligned with NIST, ISO, and OWASP standards related to AI security. According to HITRUST's Q1 2026 Cyber Threat Adaptive analysis, the AI Security Certification maintained over 97% coverage of adversarial AI techniques observed during the period, while the e1, i1, and r2 assessments demonstrated 98.19% and 100% coverage respectively. [9] HITRUST and ISO/IEC 42001: Two Frameworks, One Complete Picture ISO/IEC 42001:2023 is the world's first international standard specifically designed for AI management systems, published in December 2023 by the International Organization for Standardization and the International Electrotechnical Commission. [10] It establishes governance structures, accountability frameworks, risk management protocols, and organisational oversight requirements for AI development and deployment. HITRUST and ISO/IEC 42001 are complementary rather than competing. ISO/IEC 42001 defines how an organisation governs its AI systems at a policy and process level. HITRUST validates that the underlying technical security controls are implemented and functioning. Organisations that need to address both AI governance and AI security will find that both frameworks together produce a more complete assurance picture than either provides independently. [10] Treating HITRUST as an Operational Discipline The most common mistake organisations make with HITRUST is treating it as a project with a start date and an end date. Preparation begins, the assessment is completed, the certificate is issued, and the program goes quiet until the next cycle approaches. This approach misses the operational value that HITRUST delivers when integrated into day-to-day security and risk processes. When HITRUST controls are embedded into ongoing monitoring, automated evidence collection, configuration management, and vendor risk workflows, the gap between preparing for an audit and maintaining an assurance posture closes significantly. When the next assessment cycle arrives, the evidence base already exists. The organisation is validating a posture that has been actively maintained throughout the year, not reconstructing documentation to demonstrate retrospective compliance. This is the shift from audit sprint to assurance engine: from asking when the next audit is, to understanding what the control environment looks like today. Pierag's Technology Risk Advisory practice supports organisations at each stage of this transition, from initial HITRUST readiness assessment through validated assessment preparation, evidence infrastructure design, and ongoing assurance programme management. References [1] HITRUST Alliance. (2026). HITRUST CSF: Cybersecurity and risk management framework. Retrieved from https://hitrustalliance.net/hitrust-framework [2] Microsoft Learn. (2026). Health Information Trust Alliance (HITRUST) Common Security Framework (CSF). Microsoft Compliance Documentation. Retrieved from https://learn.microsoft.com/en-us/compliance/regulatory/offering-hitrust [3] Accorian. (2026, May 27). HITRUST CSF v11.8.0: Key updates. Retrieved from https://www.accorian.com/hitrust-csf-v11-8-0/ [4] A-LIGN. (2026). What is HITRUST? Complete guide to HITRUST certification. Retrieved from https://www.a-lign.com/articles/everything-you-need-to-know-about-hitrust-certification [5] HITRUST Alliance. (2026, April 7). The cybersecurity trust crisis: Why 99.62% of HITRUST certified environments stay breach-free [Press release]. Retrieved from https://hitrustalliance.net/press-releases/the-cybersecurity-trust-crisis-why-99.62-of-hitrust-certified-environments-stay-breach-free-while-third-party-risk-and-exploits-surge [6] Verizon Business. (2025, April 23). 2025 Data Breach Investigations Report [Press release]. Retrieved from https://www.verizon.com/about/news/2025-data-breach-investigations-report [7] HITRUST Alliance. (n.d.). HITRUST CSF Assurance Program Requirements. Retrieved from https://hitrustalliance.net/hubfs/CSF-Assurance-Program-Requirements.pdf [8] HITRUST Alliance. (2026, May 19). HITRUST launches AI Security Assessment with certification [Press release]. Retrieved from https://hitrustalliance.net/press-releases/hitrust_launches_ai_security_assessment_and_certification [9] HITRUST Alliance. (2026, April 30). HITRUST releases its quarterly Cyber Threat Adaptive analysis: The rise of AI-enabled attacks [Press release]. Retrieved from https://hitrustalliance.net/press-releases/hitrust-releases-its-quarterly-cyber-threat-adaptive-analysis-the-rise-of-ai-enabled-attacks [10] International Organization for Standardization. (2023). ISO/IEC 42001:2023: Information technology, artificial intelligence, management systems. Retrieved from https://www.iso.org/standard/42001
The ESG landscape continues to evolve, shaped by changing regulations, emerging market mechanisms, and increasing expectations around the quality, credibility, and use of sustainability information. The August 2026 edition of ESG Perspective brings together key developments across India and global markets, covering sustainability reporting and disclosure, climate and energy policy, clean mobility and transport, and biodiversity and nature conservation. What’s covered in this edition Sustainability Reporting & Disclosure The edition examines significant developments in sustainability reporting, including the European Commission’s revised ESRS under Omnibus I, South Korea’s roadmap for mandatory ISSB-aligned disclosures, Japan’s move towards digital sustainability reporting, and emerging developments in ESG data and disclosure infrastructure. Climate & Energy Policy From developments in carbon farming and climate-risk integration to changes in emissions standards, heating policy, and coal market regulation, this section highlights regulatory developments influencing climate transition and energy markets. Clean Mobility & Transport India’s evolving clean mobility framework takes centre stage, including Delhi’s EV Policy 2026 and the exemption of certain electric and alternative-fuel vehicles from transport permit requirements. These developments signal a broader shift towards policy-led adoption of cleaner transportation. Biodiversity & Nature Conservation The edition also looks beyond climate to emerging biodiversity and nature-related developments, including the IUCN’s assessment of risks associated with deep-sea mining, updates to the EU Deforestation Regulation, and the recognition of new natural and mixed sites under the UNESCO World Heritage framework. The latest developments point to a sustainability landscape moving in different directions across jurisdictions — with simplified reporting requirements in some markets alongside stronger mandates and oversight in others. For businesses, this makes it increasingly important to understand not only what is changing from a regulatory perspective, but also how these developments can influence reporting, governance, risk management, operations, and stakeholder expectations. ESG Perspective is designed as a concise and practical resource for businesses, professionals, and decision-makers seeking to stay informed on the developments shaping the sustainability agenda. Stay ahead of evolving ESG developments. Read the August 2026 edition of ESG Perspective to understand the regulatory shifts, market trends, and sustainability priorities shaping business decisions.
“Caveat Emptor”, a Latin phrase, which means “let the buyer beware”, usually, applies to all contracts of sale and purchase of goods and services. The principle of caveat emptor requires a buyer to assess and investigate the goods and services being bought since once sold, all the risks of such goods and services belong to the buyer and the Sellers is relieved of all the risks of goods and services sold. Caveat Emptor also applies to the sale and purchase of businesses. Accordingly, an Acquirer is required to assess and investigate all the risks and potential losses associated with a business before acquiring the business. The process of making such an assessment and investigation is called due diligence.  Investopedia.com states that “due diligence is an investigation, audit, or review performed to confirm facts or details of a matter under consideration. In the financial world, due diligence requires an examination of financial records before entering into a proposed transaction with another party. Due diligence is a systematic way to analyse and mitigate risk from a business or investment decision. Due diligence involves examining a company's numbers, comparing the numbers over time, and benchmarking them against competitors. The same due diligence strategy will work on many other types of investments.”  While there are many types of due diligences required to be conducted in a M&A transaction, such as operational due diligence, commercial due diligence, legal due diligence, tax due diligence, etc., financial due diligence in most cases is the most important due diligence from an Acquirer’s perspective.   What Is Financial Due Diligence and Why Does It Matter in Indian Transactions?  Financial due diligence (FDD) is the process of independently verifying a business's financial performance and financial position before a deal closes. It covers historical performance especially quality of earnings, working capital trends, debt and debt like items and other assets and liabilities of the Target entity.  According to Grant Thornton's Dealtracker, India recorded over 2,400 M&A and PE transactions in 2025, with total deal value USD 97 billion. Most of such transactions require an FDD. There are also IPOs and qualified institutional placements (QIPs) which also require FDD.   While due diligence has been traditionally conducted by Acquirers/ Investors (called the “buy-side” due diligence), now even the Sellers/ Target entity commission due diligence (called the “sell-side” or “vendor” due diligence). Sell-side or vendor due diligence is usually carried out prior to the identification of potential acquirers/ investors.  Apart from gaining a better understanding of the Target’s business and the assets and liabilities to be acquired, a buy-side FDD enables Acquirers/ Investors to identify issues:  which are deal-breakers i.e., the issues are so material that they may prevent the transaction from taking place (for example, issues impacting viability of the Target business);    which may result in an adjustment to the purchase price (for example, impairment of certain assets); or  which may result in modification of the transaction structure (for example, identification of material contingent liabilities which result in change of the transaction structure from share purchase to asset purchase).  In India, FDD matters for an added reason: the gap between a company's audited statutory accounts and its actual operating picture is often wider than in more mature markets. Mid-market and promoter-led businesses frequently maintain informal records, have complex related-party structures, or carry undisclosed contingent liabilities.  What Does a Buy-Side Financial Due Diligence Actually Cover?  When an Acquirer commissions FDD, the objective is to validate the Target's financial story and identify risks before the deal is priced or structured. The core areas of investigation include:  Quality of Earnings (QoE) Analysis: A QoE analysis normalises reported earnings by removing non-recurring revenues, other income and expenses, and owner-specific costs. The adjusted EBITDA figure that emerges is often materially different from what appears in the audited financial statements. A business reporting INR 20 crore in EBITDA may reveal an adjusted figure of INR 14 crore once non-recurring export incentives and related-party service fees are stripped out.  Working Capital Assessment: The working capital assessment included analyses of receivables ageing, inventory levels, and payables cycles to establish a normalized working capital baseline. Deviations from this baseline at closing often lead to price adjustments, which is why this analysis must be rigorous.  Debt and Off-Balance-Sheet Liabilities: Buyers look for financial obligations that do not appear on the face of the balance sheet, including supplier advances, personal guarantees, contingent liabilities from pending litigation, and lease commitments.  Tax Position and Contingent Tax Liabilities: GST notices, transfer pricing adjustments, and direct tax disputes are common findings in Indian FDD. Buyers need to quantify these exposures before determining deal structure. In certain cases, a specialist tax due diligence may be conducted to identify such items which are then also incorporated in the FDD report.  Related-Party Transactions: Transactions between the Target and its promoters and their relatives, subsidiaries, or associated entities are examined for commercial rationale, arm's-length pricing, and potential cash leakage.  Pierag's Deals Advisory practice conducts buy-side FDD across manufacturing, technology, healthcare, and financial services transactions, covering all of these areas in a single integrated review.  How Should Sellers Prepare for Financial Due Diligence?  Preparation is where sellers consistently underestimate the process. Most sellers assume that having audited financial statements are enough. They are not.  Build a Structured Data Room: A well-organized virtual data room (VDR) accelerates the FDD timeline and reduces the number of information requests raise by the Acquirers. Sellers should organize information by year, separate statutory from management accounts, and pre-load supporting schedules for revenue, expenses, receivables, and payables.  Reconcile Management Accounts with Statutory Accounts: This is the single most common issue found in Indian transactions. When management accounts show different revenue or expense figures than the statutory audit, it immediately raises questions about the reliability of financial information. Sellers need to document and explain every reconciling item even before such information is requested by the Acquirer’s advisors.  Consider Vendor Due Diligence: Vendor Due Diligence (VDD) is a proactive FDD exercise commissioned by the Sellers and made available to prospective buyers. It allows the Sellers to identify problems before buyers do, address them, and present a pre-validated financial narrative. Sellers who use VDD typically experience shorter due diligence periods and fewer late-stage valuation disputes.  Resolve Tax Exposures in Advance: Outstanding GST notices, unresolved TDS demands, or open transfer pricing assessments create uncertainty that buyers will price conservatively. Resolving or quantifying these exposures before the process begins puts the Sellers in a stronger negotiating position.  Pierag's Accounting Advisory team works with sellers to align financial records, close reporting gaps, and build the documentation needed to withstand scrutiny.  What Are the India-Specific Regulatory Considerations in Financial Due Diligence?  India's regulatory environment adds dimensions to FDD that do not exist in most other markets. Every buyer's advisor needs to assess these areas:  FEMA and RBI Compliance For cross-border transactions involving foreign investment, FEMA 20R compliance is a mandatory review area. This includes checking whether the target has obtained required approvals, filed Form FC-GPR, and priced shares in accordance with prescribed valuation norms.  GST Compliance GST liability exposure is a material FDD risk for businesses in manufacturing, retail, logistics, and services. Buyers look for unreconciled GST returns, input tax credit (ITC) mismatches, and pending departmental notices.  Transfer Pricing For businesses with related-party cross-border transactions, transfer pricing documentation under Section 92 to 92F of the Income Tax Act is a significant area of review. Inadequate documentation creates exposure to retrospective adjustments.  SEBI Regulations For listed companies or pre-IPO transactions, SEBI's LODR (Listing Obligations and Disclosure Requirements) regulations govern disclosure obligations that directly affect what financial information must be available and how it must be presented.  Pierag's Business Risk Advisory team supports both buyers and sellers in assessing regulatory compliance exposure as part of a broader transaction risk review.  Takeaway: Regulatory risk in India is not a checkbox. It is a quantifiable financial exposure that must be assessed and priced into every deal.  What Are the Most Common Red Flags Found in Indian Financial Due Diligence?  Experienced advisors see patterns across transactions. The following issues appear consistently:  Revenue concentration: More than 30 to 40 per cent of revenue from a single customer or related party is a commercial and continuity risk.  Divergence between statutory and management accounts: Unexplained differences of 5 per cent or more in revenue or EBITDA between the two sets of accounts are a serious reliability concern.  Unreconciled inter-company balances: Complex group structures with unresolved inter-company receivables or payables often indicate cash flow management issues or undisclosed related-party exposures.  Aggressive revenue recognition: Revenue booked before delivery, or milestone-based revenue not tied to contractual obligations, inflates reported earnings.  Undisclosed contingent liabilities: Pending litigation, bank guarantees, and disputed tax demands that do not appear in financial notes are a frequent source of post-deal disputes.  Unwillingness to share information: It has been noticed in a number of transactions that the Sellers/Target is unwilling to share full information with the due diligence team resulting in distrust between the Acquirers and the Sellers. This has also resulted in some transactions being called off as the Acquirers did not get sufficient comfort over financial numbers of the Target.  Frequently Asked Questions on Financial Due Diligence in India  Q1: What is the typical timeline for financial due diligence in India? For mid-market transactions, FDD typically takes four to eight weeks from the initial data request to delivery of a final report. Large or cross-border deals may take twelve weeks or more. Sellers with organized records and a structured data room can shorten this timeline meaningfully.  Q2: Is financial due diligence mandatory for M&A transactions in India? FDD is not mandated by statute but it is standard practice for PE firms, institutional investors, and foreign acquirers. For listed company transactions, SEBI disclosure requirements create overlapping obligations. Boards of directors increasingly treat FDD as a fiduciary responsibility regardless of formal mandate.  Q3: What is the difference between buy-side and sell-side due diligence? Buy-side FDD is commissioned by the Acquirer to independently verify the target's financials. Sell-side or VDD is commissioned by the Sellers to produce a pre-validated financial assessment that can be shared with multiple buyers. VDD gives sellers control over the process and reduces last-minute surprises.  Q4: How does working capital affect deal pricing in India? Working capital is typically defined as a benchmark in the sale and purchase agreements. If actual working capital at closing differs from the agreed peg, a price adjustment mechanism applies. Disputes over the working capital calculation are among the most common sources of post-deal conflict in Indian transactions, which makes robust analysis at the FDD stage critical.  Q5: What should a startup or high-growth company prepare for investor due diligence? Startups should ensure MIS reports are consistent with statutory filings, cap tables are current and legally clean, GST and TDS compliance is up to date, and any related-party transactions are documented with a clear rationale. Investors will also examine burn rate, revenue recognition policies, and deferred revenue schedules closely. 
A Defined contribution plan  audit is an independent examination of a company's retirement plan financial statements and operations, required under ERISA when a plan crosses certain participant thresholds. Plan sponsors with 100 or more eligible participants at the start of the plan year generally need an audit as part of their Form 5500 filing, performed by a qualified CPA firm independent of the plan sponsor. Audit costs typically range from a few thousand dollars for a small, straightforward plan to well over $25,000 for a large plan with multiple investment options or prior-year errors to remediate. The rest of this guide breaks down the participant-count trigger in detail, what the audit actually examines, and the factors that drive cost up or down. The 100-Participant Rule, Explained Plainly The Employee Retirement Income Security Act (ERISA) requires plans with 100 or more eligible participants at the beginning of the plan year to file as a "large plan" with the Department of Labor, which triggers the independent audit requirement attached to Form 5500. There is an important exception plan sponsors often miss: the 80-120 participant rule. If the number of participants at the beginning of the plan year is between 80 and 120, the plan may file in the same category (large or small) as it filed the prior year. This means a plan that filed as a small plan can continue to do so, without triggering the audit requirement, as long as its beginning-of-year count stays at 120 or below. This buffer exists specifically so growing companies are not forced into an audit the moment they cross 100 participants by a handful of employees. Important recent change: For plan years beginning on or after January 1, 2023, the Department of Labor changed how the 100-participant threshold is counted for defined contribution plans (such as 401(k) plans). Under the prior rule, the count included all eligible employees, whether or not they actually participated. Under the new rule, only participants with an account balance at the beginning of the plan year are counted. This is a significant change. Plans with many eligible-but-non-participating employees may now fall below 100 counted participants and avoid the large-plan audit requirement entirely. The DOL estimated the change would remove the audit requirement for roughly 20,000 defined contribution plans. The 80-120 rule still applies, but now uses this account-balance count. Any assessment of whether a plan needs an audit should use the current account-balance methodology, not the older eligible-employee count. One clarification that prevents miscounts: for defined contribution plans under the current rule, the count is participants with an account balance at the start of the plan year, which includes not just active contributing employees but also terminated or retired employees who still hold a balance in the plan. Sponsors sometimes undercount by looking only at current active contributors. For plan years before 2023, the count was broader still, including all eligible employees regardless of participation. Does Every Growing Plan Trigger an Audit Right Away? Not immediately, because of the 80-120 rule above, but the trigger becomes unavoidable once the plan consistently sits above 120 participants or the sponsor chooses to file as a large plan. A common scenario: a company hires aggressively during a growth year, crosses 100 participants by year's end, and the finance team only realizes the audit requirement applies when preparing the Form 5500 months later, leaving little time to select an auditor and gather records. This is the single most common reason plan sponsors end up paying rush fees or scrambling for an auditor close to the filing deadline. Tracking participant counts each plan year, not just at filing time, avoids this. Filing Deadline: Form 5500 is due the last day of the seventh month after the plan year ends, which is July 31 for a calendar-year plan. A one-time 2.5-month extension to October 15 is available by filing Form 5558 by the original due date. Because the audit report must be attached to a completed Form 5500, the practical deadline for finishing audit fieldwork is tighter than these dates suggest, which is why late auditor selection drives rush fees. What Does a defined contribution plan Auditor Actually Examine? A Defined contribution plan audit,  is not the same as a corporate financial statement audit, even though both result in an opinion. The auditor examines: Plan financial statements, including the statement of net assets available for benefits and changes in those net assets Participant contributions and whether they were remitted to the plan in a timely manner, a frequent source of findings Eligibility and enrollment records, confirming the plan administrator correctly applied plan terms Distributions and loans, checking that they were processed and approved according to the plan document Investment valuations, particularly for plans holding less liquid or non-standard investment options Late remittance of employee contributions is consistently one of the most common findings in EBP audits, since Department of Labor guidance treats delayed deposits as a fiduciary breach even when the delay is short and unintentional. When late remittances are identified, they are correctable. The Department of Labor’s Voluntary Fiduciary Correction Program (VFCP) lets sponsors self-correct delinquent participant contributions by depositing the missed amounts plus lost earnings, and the IRS Employee Plans Compliance Resolution System (EPCRS) covers related qualification failures. Correcting proactively, and documenting the correction, is far less costly than having the issue surface unresolved in an audit or DOL inquiry. Limited Scope Versus Full Scope: A Distinction That Changes the Audit Plan sponsors using a qualifying trustee or custodian, such as a bank or insurance company that certifies investment information, can elect a limited scope audit, where the auditor does not independently verify the certified investment data. A full scope audit requires the auditor to test investment valuations directly, which generally takes more time and costs more. The AICPA  (through SAS 136) has moved away from the term "limited scope" toward "ERISA Section 103(a)(3)(C) audit" under newer auditing standards, but the practical distinction for plan sponsors remains the same: a certified-investment election narrows what the auditor needs to independently test, which affects both audit duration and fee. What Drives the Cost of a ndefined contribution plan Audit? Audit fees vary based on several factors that plan sponsors can usually identify before requesting a proposal: Plan size and complexity: A plan with a single recordkeeper and standard mutual fund investments costs less to audit than one with multiple investment platforms, company stock, or alternative investments. First-year audit versus repeat engagement: A first-time EBP audit typically costs more because the auditor has no prior-year workpapers to build from and needs to understand plan documents and processes from scratch. Audit scope election: A full scope audit, where investment valuations are tested directly rather than relying on trustee certification, generally costs more than a limited scope or Section 103(a)(3)(C) audit. Quality of plan recordkeeping: Plans with clean, well-organized census data, timely contribution records, and an updated plan document typically move through audit fieldwork faster than plans with scattered records across multiple systems or providers. Findings requiring remediation: If the audit uncovers issues like late contribution remittances or eligibility errors, additional time goes into documenting these findings and advising on correction, which adds to the overall fee. For most mid-sized plans, audit fees commonly fall somewhere between $8,000 and $18,000 annually, though this range shifts meaningfully based on the factors above, and sponsors should treat any quote received without a plan census and prior Form 5500 review as a rough estimate at best. What Happens If a Required Audit Is Skipped or Filed Late? Form 5500 filings missing a required audit report, or filed with a qualified or adverse audit opinion that isn't resolved, draw attention from the Department of Labor. The DOL has run targeted enforcement initiatives specifically focused on EBP audit quality, since deficient audits were found across a meaningful share of CPA firms performing this niche audit type in past DOL studies. Selecting a CPA firm with specific Employee Benefit Plan audit experience, rather than a general practice firm doing one occasionally, reduces this exposure. Plan sponsors are personally responsible as fiduciaries for selecting a qualified auditor, so this is not a decision that can be delegated entirely to a recordkeeper or third-party administrator without sponsor oversight. The financial exposure is concrete. Under ERISA Section 502(c)(2), the DOL can assess a civil penalty of up to $2,739 per day, with no maximum, for a late or incomplete Form 5500, and the IRS can separately assess up to $250 per day (capped at $150,000 per plan year). These are two distinct penalties for the same late filing. Sponsors who discover a delinquency before the DOL contacts them can use the Delinquent Filer Voluntary Compliance Program (DFVCP), which caps the penalty at a substantially reduced amount, typically in the range of a few hundred to a few thousand dollars per filing. Where CPA Outsourcing Fits Into This Picture Many CPA firms handling EBP audits face the same constraint every audit season: a narrow filing window, a shortage of staff with EBP-specific training, and a workload that spikes sharply around the same few months. Outsourcing the fieldwork-heavy, repetitive portions of an EBP audit, like testing contribution remittance timing, distribution sampling, and census data reconciliation, to a dedicated outsourcing partner lets the engagement partner focus on judgment-heavy areas and final review. This is the core of what our Assurance & CPA Outsourcing practice supports for US CPA firms: structured EBP audit fieldwork support that follows the engagement partner's methodology and review standards, rather than a generic offshore staffing arrangement. How Pierag Consulting Supports CPA Firms and Plan Sponsors Pierag Consulting works with US CPA firms on Employee Benefit Plan audit fieldwork, financial statement audit support, and compilation engagements through structured CPA outsourcing arrangements. This includes contribution testing, census data reconciliation, and workpaper preparation aligned to the engaging firm's own audit methodology and review process. Frequently Asked Questions How many participants trigger a mandatory defined contribution plan audit? A plan generally needs an audit once it has 100 or more eligible participants at the start of the plan year, though the 80-120 participant rule allows a one-year buffer for plans growing past the 100 mark for the first time. What is the difference between a limited scope and a full scope defined contribution plan audit? A limited scope audit, now often called a Section 103(a)(3)(C) audit, relies on a qualifying trustee's certification of investment data rather than independent testing. A full scope audit requires the auditor to independently verify investment valuations, which generally increases cost and fieldwork time. Why do defined contribution plan audits often find issues with contribution timing? The Department of Labor treats delayed remittance of employee contributions as a fiduciary breach, even for short delays. This is one of the most frequently cited findings in EBP audits because many plan sponsors do not have a documented, consistent remittance timeline. Does a first-year define contribution plan audit cost more than a repeat audit? Yes, typically. A first-year audit requires the auditor to build an understanding of plan documents, processes, and prior history from scratch, since there are no prior-year workpapers to reference, which generally increases the time and cost involved. Who is responsible for selecting a qualified defined contribution plan auditor? The plan sponsor, acting as a fiduciary, is responsible for selecting a qualified, independent auditor. This responsibility cannot be fully delegated to a recordkeeper or third-party administrator without sponsor oversight.
The report highlights a clear shift in the global ESG landscape from policy ambition to execution, enforcement, and measurable accountability. Across jurisdictions, regulators and standard-setters are converging on one direction—making sustainability data more comparable, auditable, and decision-useful. A key theme is the rise of implementation-heavy regulation. In the EU, this is visible through new frameworks such as standardized transport emissions accounting, stricter steel import quotas with traceability requirements, circularity mandates for automotive design, and clarified rules for chemically recycled plastics. These measures collectively reinforce a stronger push toward industrial decarbonization and circular economy adoption backed by enforceable rules rather than voluntary commitments. On the climate and energy transition side, China and the EU emerge as dominant policy drivers. China’s multi-year industrial decarbonization plan and its formal recognition of renewable hydrogen, ammonia, and methanol as part of non-electric renewable energy reflect deep integration of clean fuels into compliance systems. The EU, meanwhile, is accelerating digitalization of energy systems, biomethane market development, and urban mobility transformation to support broader Green Deal objectives. In global sustainability standards and disclosures, major institutions are tightening alignment: ISO introduces net-zero transition planning standards for financial institutions SBTi Version 2.0 shifts focus from target-setting to execution and delivery CDP expands disclosure to include ocean-related data TNFD strengthens nature-related financial reporting frameworks Together, these developments indicate a broader move toward integrated environmental and financial accountability. The social and governance dimension is also evolving rapidly. The ILO’s platform economy convention strengthens protections for digital workers, while the U.S. CBP tightens forced-labor enforcement expectations across global supply chains. In India, CSR regulations now allow structured impact investing through Social Stock Exchange instruments, signaling a shift toward outcome-linked social financing. Across all themes, a consistent message emerges: ESG is no longer a reporting exercise—it is becoming a core governance and risk management discipline, with internal audit and assurance functions playing a critical role in validating data integrity and ESG maturity. Read and download the full ESG Perspective report (July 2026 edition) to access the complete insights and implications for your organization.
Research report | 8-10 Min Read Material weaknesses remain one of the clearest public signals of how well an organization's internal control environment is actually working. But the disclosures themselves rarely tell the full story. A single reported weakness is often the visible symptom of a deeper governance, staffing, or process gap, not an isolated control failure. To understand what is really driving these disclosures, Pierag analyzed material weakness filings from 1,000 U.S. SEC filers across 2025 and 2026. The goal was to identify which themes recur most often, how they cluster together, and what separates companies that remediate quickly from those that report the same weaknesses year after year. What Is a Material Weakness in Internal Controls? A material weakness is a deficiency, or combination of deficiencies, in internal control over financial reporting (ICFR) severe enough that there is a reasonable possibility a material misstatement in the company's financial statements would not be prevented or detected on a timely basis. Under SEC rules, companies must disclose material weaknesses in their annual and quarterly filings, along with management's assessment of ICFR effectiveness. A material weakness disclosure does not necessarily mean a misstatement has occurred. It means the control environment could not reliably catch one if it did. Methodology Pierag reviewed material weakness disclosures reported by 1,000 U.S. SEC filers across fiscal years 2025 and 2026, drawn from annual and quarterly filings. Each disclosure was categorized by theme, cross-referenced against industry classification and filer type (IPO versus non-IPO), and analyzed for co-occurrence patterns, meaning how often two or more weakness themes were reported together within the same filing. The Most Commonly Reported Material Weakness Themes Two themes dominate the dataset by a clear margin: Segregation of Duties - inadequate separation between individuals who initiate, approve, and record transactions, concentrating control in too few hands. Resource Constraints - insufficient qualified accounting and finance personnel to design, operate, and monitor controls at the scale the business requires. Beyond these two leading themes, three additional categories appear consistently across industries: Employee Training and Competency Gaps - control owners who lack sufficient training in accounting standards, company-specific procedures, or the judgment required for complex transactions. IT General Controls (ITGCs) - weaknesses in access management, change management, or system configuration controls supporting financial reporting systems. Financial Reporting Process Deficiencies - breakdowns in period-end close, account reconciliation, or review procedures that support accurate reporting. Why Material Weaknesses Rarely Occur in Isolation One of the most consistent patterns in the data is co-occurrence. Companies that report one material weakness frequently report two or more in the same filing. Segregation of Duties issues, for example, are commonly reported alongside Resource Constraints, since both often stem from the same root cause: a finance function that has not scaled staffing or process design in line with the business. This clustering matters for how organizations should read their own disclosures. A material weakness reported as a single line item is often a symptom of a broader capacity or governance gap, not a standalone control fix. Addressing the individual deficiency without addressing the underlying driver tends to produce a repeat disclosure the following year. Industry-Specific Patterns Material weakness themes are not evenly distributed across sectors. Some industries show a heavier concentration of IT General Controls weaknesses, consistent with reliance on complex or highly customized financial systems. Others show a higher incidence of Resource Constraints, often reflecting leaner finance functions relative to transaction volume or reporting complexity. Understanding where an organization's own industry tends to cluster is a useful diagnostic starting point before conducting an internal gap assessment. IPO Filers vs. Non-IPO Filers The data shows a meaningful difference between newly public companies and established filers. IPO filers are more likely to report material weaknesses tied to Resource Constraints and Financial Reporting Process Deficiencies, consistent with the operational strain of building a public-company-grade control environment on a compressed timeline. Non-IPO filers, by contrast, more frequently report Segregation of Duties and IT General Controls issues, often surfacing as the business has grown in complexity faster than its control structure. What Effective Remediation Looks Like Across the filers studied, organizations making the fastest and most durable progress on remediation share a common approach: they treat material weaknesses as a signal to fix the underlying driver, not just the disclosed symptom. In practice, this means: Redesigning governance structures and reporting lines rather than adding a single approval step Investing in talent and training as a control activity, not a one-time fix Rebuilding financial reporting processes with documented, testable controls Modernizing IT systems and access controls supporting the close process Organizations that address these root causes tend to see material weaknesses resolved and stay resolved. Those that patch individual deficiencies in isolation tend to see new, related weaknesses surface in subsequent periods. Frequently Asked Questions What is the most commonly reported material weakness among SEC filers? Segregation of Duties and Resource Constraints are the two most frequently reported material weakness themes across the 1,000 SEC filers analyzed, ahead of IT controls, employee training, and financial reporting process deficiencies. Do material weaknesses usually occur alone or together? Material weaknesses frequently co-occur. A company reporting a Segregation of Duties issue, for example, often also reports a related Resource Constraints weakness, since both typically trace back to an under-resourced finance function. Is a material weakness the same as a misstatement? No. A material weakness means the control environment could not reliably prevent or detect a material misstatement on a timely basis. It does not confirm that a misstatement actually occurred. Do IPO companies report different material weaknesses than established public companies? Yes. IPO filers more often report Resource Constraints and Financial Reporting Process Deficiencies, reflecting the strain of building public-company controls quickly. Non-IPO filers more often report Segregation of Duties and IT General Controls weaknesses. How long does it typically take to remediate a material weakness? Timelines vary by root cause and company size, but remediation that only fixes the disclosed symptom (rather than the underlying governance, staffing, or process gap) tends to result in the same or a related weakness resurfacing in a later period. Who should read this material weakness research report? The findings are most relevant to CFOs, controllers, audit committee members, and internal audit leaders responsible for ICFR design, SOX 404 compliance, and remediation planning. Get the Full Report This overview covers the top-line findings. The complete report includes the full thematic breakdown, industry-by-industry data, co-occurrence analysis, and practical considerations for management teams, audit committees, and internal audit leaders building a remediation roadmap. Building or strengthening your ICFR environment? Pierag's Business Risk Advisory teams work with audit committees and finance leaders to design controls that hold up under scrutiny, not just on paper. Talk to our team about your control environment. Related reading: Beyond Compliance: Internal Auditor's Role in Implementing SEBI's New RPT Framework | Audit Trail: Ensuring Financial Integrity and Accountability | Emerging Risks and Trends 2026
BRSR Reporting in India: Full Compliance Guide for Listed Companies  India’s sustainability reporting landscape changed permanently on the day SEBI mandated BRSR for the country’s top 1,000 listed companies. Four years into that mandate, one pattern has become impossible to ignore: companies that treat BRSR as a compliance task produce reports that satisfy a regulator. Companies that treat it as a governance discipline produce reports that attract capital, reduce risk, and set the agenda in their sector.  This document is written for CFOs, Company Secretaries, Heads of Sustainability, and Audit Committee members who want to understand not just what BRSR requires, but what separates a credible, investor-ready BRSR report from one that merely fills pages in an Annual Report.  What Is BRSR and Why It Is Not the Same as the Old BRR  The Business Responsibility and Sustainability Report (BRSR) was notified by SEBI in May 2021 and replaced the earlier Business Responsibility Report (BRR). The shift was substantive, not cosmetic. Where the BRR asked companies to describe their policies, BRSR demands quantitative performance data – numbers that can be tracked, trended, compared, and assured.  BRSR is grounded in the National Guidelines on Responsible Business Conduct (NGRBC), issued by the Ministry of Corporate Affairs, which define nine principles of responsible business. Every listed company in the top 1,000 by market capitalisation on BSE and NSE must now disclose how their business performs and not just how it is governed against each of those nine principles.  The nine NGRBC principles cover ethics and transparency (P1), sustainable products and services (P2), employee well-being (P3), stakeholder responsiveness (P4), human rights (P5), environmental stewardship (P6), responsible policy advocacy (P7), inclusive growth (P8), and consumer responsibility (P9). Together, they map onto the three pillars of ESG – environmental, social, and governance making BRSR India’s most comprehensive ESG disclosure framework to date.  Who Must File BRSR and What the Phased Expansion Means  BRSR became mandatory for the top 1,000 listed entities by market capitalisation beginning FY 2022-23. The applicability is assessed at the end of the calendar year i.e., 31 December on the basis of average market capitalisation from 1 July to 31 December, so boards must monitor whether their company is approaching or crossing this threshold. Voluntary adoption is encouraged for companies beyond the top 1,000, and those who begin early are materially better positioned when the mandate reaches them.   More significantly, SEBI has been deliberate about expanding BRSR’s scope in phases. BRSR Core – a defined subset of BRSR indicators within BRSR is applicable to all companies preparing BRSR. External assurance of BRSR Core, however, has been mandated in a phased manner:  for the top 150 listed companies from FY 2023-24, expanding to the top 250 from FY 2024-25, the top 500 from FY 2025-26 and the top 1000 from FY 2026-27. This phased architecture is SEBI’s clearest signal that BRSR is not a one-time disclosure event. It is a permanent, deepening feature of India’s capital market governance.  For companies that are not yet in the top 1,000 but are growing toward that threshold, voluntary BRSR adoption is not just a goodwill gesture. It is a head start on data infrastructure, governance processes, and stakeholder communication that cannot be built overnight. Pierag’s ESG & Sustainability Reporting and Assurance practice works with organisations at every stage of this readiness journey, from first-time voluntary reporters to companies already preparing BRSR and those mandated to undergo assurance requirements.  The Structure of BRSR: What the Three Sections Actually Require  BRSR is divided into three sections, and understanding their purpose is essential to preparing a disclosure that functions as more than a regulatory filing.  Section A – General Disclosures covers the company’s identity and basic profile. It includes details of business activities, product and service categories, locations of plants and offices, employee and worker headcount (permanent and contractual, disaggregated by gender), and the structure of holding, subsidiary, and associate entities. It also requires disclosure of CSR obligations, whether the company has met its prescribed CSR spending for the year, and the company’s grievance redressal mechanism.  Section B – Management and Process Disclosures is where governance is documented. For each of the nine NGRBC principles, the company must disclose whether it has a policy in place, identify who governs that policy (including Board-level oversight), and confirm whether the policy extends to the value chain. This section forms the foundation on which the credibility of Section C rests. Weak governance disclosures in Section B undermine even the most robust data presented in Section C.  Section C – Principle-wise Performance Disclosures is the engine of BRSR. For each principle, companies must report against two categories of indicators: Essential Indicators (mandatory) and Leadership Indicators (voluntary, but increasingly expected by ESG rating agencies and institutional investors). The Essential Indicators alone span a wide range of quantitative metrics, including  greenhouse gas emissions, water and energy usage , waste management practices, employee wellbeing and safety measures, gender diversity, pay ratios, CSR programme outcomes, fairness in customer and supplier engagement, among others.  The credibility of Section C depends almost entirely on the data infrastructure a company has built. Companies that lack systems for tracking Scope 1 and 2 GHG emissions at facility level, or that  do not maintain disaggregated workforce safety data, will discover these gaps  during disclosure preparation often under filing pressure, when there is no time to address them properly.  BRSR Core: The Assurance Mandate That Changes Everything  In July 2023, SEBI introduced BRSR Core, with which the BRSR framework has been further strenghthened.  BRSR Core identifies a subset of Key Performance Indicators (KPIs) that are subject to mandatory assurance by an independent third party. The KPI set spans nine ESG attributes: GHG footprint, water footprint, energy footprint , embracing circularity – details related to waste management by the entity, enhancing employee wellbeing and safety, enabling gender diversity in business, enabling inclusive development, fairness in engaging with customers and suppliers, open-ness of business. In addition, companies are required to assess ESG performance across a defined portion of their upstream and downstream value chain; however, external assurance of value chain disclosures remain voluntary rather than mandatory.  Assurance is a high bar compared to self‑certification. It means the assurance provider must gather sufficient and appropriate evidence to conclude positively that the reported data is free from material misstatement. Self-certification or management attestation does not satisfy this requirement.  This matters for several practical reasons. First, the data underpinning BRSR Core KPIs must be generated by systems that have been designed for external validation. Ad hoc spreadsheet aggregation across business units will not hold up under third-party scrutiny. Second, the internal controls over that data must be documented and tested. Third, material discrepancies between assurance findings and reported figures create regulatory exposure.  Organisations preparing for BRSR Core assurance need a reporting and verification partner who understands both the sustainability framework and the assurance standards. Pierag’s ESG & Sustainability Reporting and Assurance practice is built specifically for this level of rigor. Our team includes professionals from diverse backgrounds – Chartered Accountants, Company Secretaries, Engineers, Environmentalists, Lawyers and specialists with advanced qualifications such as Masters in Sustainability, DipIFR (ACCA,UK), and certifications as GHG Accounting Lead Verifiers under ISO 14064.  The Five Compliance Gaps That Derail Most BRSR Filings  Having worked across listed companies at different stages of BRSR readiness, five failure patterns appear with regularity.  Gap 1: No system for Scope 1 and Scope 2 GHG data. Principle 6 under BRSR requires GHG emissions disclosure, and BRSR Core mandates its assurance. Most companies discover they have utility bills but no standardised protocol for converting them into CO2e figures across business units, fuels, and refrigerants. Building a GHG inventory aligned with a recognised framework (such as the GHG Protocol, ISO 14064, or IPCC Guidelines) takes time and requires clear methodology decisions that should not be made under time pressure.  Gap 2: Value chain blindspots. BRSR requires companies to assess the ESG performance of their upstream and downstream value chain specifically the top suppliers and customers by purchase and sales value. For most Indian manufacturers and service companies, this means engaging counterparties who have never been asked sustainability questions before. Companies that begin the value chain engagement 12 to 18 months early are far better positioned than those who attempt it in the quarter the report is due.  Gap 3: Workforce data that cannot be disaggregated. BRSR requires headcount, turnover, employee wellbeing measures, training participation, and pay data to be broken down by gender, permanent and contractual status, and often by category of employees and worker. HR systems that were not designed with BRSR in mind frequently cannot produce this disaggregation without significant manual effort, which introduces error and is difficult to assure.  Gap 4: Prior-year inconsistencies. BRSR requires prior-year comparatives for most quantitative metrics. Companies that change their data collection methodology over the years – or that simply did not collect certain data points in prior years – face the uncomfortable choice between restating figures or disclosing gaps. Neither option is cost-free from a credibility standpoint, as both raise questions about data reliability and governance maturity.  Gap 5: Fragmented ownership of ESG reporting. BRSR preparation requires data from diverse functions such as Company Secretary, HR, Finance, Operations, Utilities, Marketing, and CSR, among others. When ESG reporting is treated as a siloed exercise led by a single department, the result is incomplete or fragile data. Effective governance demands a coordinated, cross‑functional approach where each function owns its data and internal controls, while oversight is exercised at a higher governance level typically the Board, Audit Committee, or a designated ESG Governance Committee. Without this integration, assurance providers and ESG rating agencies quickly detect inconsistencies, undermining credibility.  BRSR and GHG Reporting: The Scope 3 Question  BRSR’s current mandatory scope for GHG reporting covers Scope 1 (direct emissions from owned or controlled sources) and Scope 2 (indirect emissions from purchased energy). Scope 3  emissions from the value chain, including purchased goods, employee commuting, waste, and the use of sold products is presently a Leadership Indicator and is not yet mandatory.  However, listed companies with global investors, export-oriented businesses, or supply chain partners in the EU are finding that Scope 3 is being asked for regardless of whether SEBI has mandated it. ESG rating agencies score it. Foreign portfolio investors’ questionnaires request it. The EU’s Carbon Border Adjustment Mechanism (CBAM) is making Scope 3 data commercially relevant for exporters of carbon-intensive products such as iron and steel, aluminium, cement, fertilisers, electricity, hydrogen, and related industrial products.  Companies that invest now in comprehensive GHG inventorisation including Scope 3 estimation  are building an asset that serves BRSR and other global frameworks such as IFRS S2, CDP, and export compliance simultaneously. The earlier this work begins, the more reliable the baseline data becomes, and the more defensible the figures are when they eventually come under assurance scrutiny.  Technology-enabled data collection is increasingly central to scalability. Pierag’s Digital Support in ESG solutions help organisations automate emissions data capture, standardise reporting across facilities, and maintain the audit trails that assurance providers require.  The Investor and Capital Market Dimension  BRSR data is not filed in isolation . It  directly shapes how institutional investors – domestic and foreign evaluate listed companies in India.  ESG rating agencies draw on BRSR disclosures to generate company scores. These scores influence index inclusion decisions, ESG fund allocations, and lending covenants attached to green bonds and sustainability-linked loans. A growing share of Indian institutional investors are allocating portions of their portfolios to entities with measurable ESG objectives, and that proportion is rising.  The quality of BRSR reporting is as important as the data itself. A report filed with missing Essential Indicators, absent prior-year comparatives, or internal inconsistencies between sections does not merely lower an ESG rating. It signals to sophisticated investors that the company’s governance culture does not extend to non-financial disclosure. Conversely, a report with independently assured or assessed BRSR Core data, comprehensive Section C disclosures, and clear year-on-year trends tells a story of operational discipline.  Access to sustainable finance in India – green bonds, sustainability-linked loans, ESG-themed equity is becoming materially easier for companies with credible, assured ESG disclosures. SEBI’s independent assurance mandate,  RBI’s renewable energy priority sector classification, and International Capital Market Association (ICMA)-aligned frameworks are converging to make the quality of BRSR disclosures an increasingly important determinant of access to sustainable finance and the terms of capital.  CSR, BRSR, and the Governance Overlap  One area where BRSR compliance intersects with a separate regulatory requirement is CSR. CSR obligations under Section 135 of the Companies Act, 2013 apply to eligible companies, and BRSR Section A requires disclosure of whether these obligations are triggered.  Principle 8 – inclusive growth and equitable development extends this further, requiring details of overall CSR projects, projects in aspirational districts, amount spent, beneficiaries (including vulnerable groups), Social Impact Assessment results, community grievance mechanisms etc..  Integrating CSR reporting with BRSR disclosures creates a coherent, evidence-backed narrative of social value creation. For companies whose CSR compliance is managed separately from their sustainability reporting function, this integration requires deliberate effort – and an honest audit of whether the programmes being funded are generating the kind of outcome data BRSR actually asks for.  Pierag’s CSR Advisory practice helps companies design, implement, and document CSR programmes that produce measurable impact, not just spending records, making Principle 8 disclosures a genuine reflection of community investment rather than a compliance entry.  Building an Assurance-Ready BRSR Programme: A Practical Roadmap  High‑quality BRSR reporting is not a once‑a‑year compliance exercise. Leading companies treat it as a year‑round discipline, embedding ESG data governance into everyday operations. The following staged roadmap reflects how organizations prepare for assurance with consistency and credibility:  Stage 1 – Gap Assessment: Conduct a structured review of current data against all BRSR Indicators. Identify data that does not exist, data that exists but cannot be disaggregated as BRSR requires, and data that exists but lacks the audit trail needed for assurance.   Stage 2 – Data Infrastructure Design: For each data gap identified, design the collection mechanism. This may involve integrating with ERP or HR systems, utility billing feeds, or establishing manual collection templates for facilities without automation. Document  methodologies to support assurance. Technology investment at this stage delivers the highest return.  Stage 3 – Materiality Assessment: Conduct a formal materiality assessment to engage internal and external stakeholders to determine which ESG issues and KPIs are most relevant to the company’s business model, industry, and geography. Under BRSR, disclosure across all nine NGRBC principles and their Essential Indicators is mandatory; materiality instead guides the depth of reporting, the choice of voluntary Leadership Indicators, and the prioritisation of narrative emphasis in Section C. A documented materiality process ensures that disclosures are purposeful, evidence‑based, and aligned with stakeholder priorities, thereby enhancing the credibility of the overall report..  Stage 4 – Internal Controls and Governance: Assign clear ownership for each BRSR KPI to a designated function and accountable individual. Define and document the control activities such as review, reconciliation and approval that govern each metric. Engage  the internal audit function to test a sample of these controls before the external assurance provider arrives.  Stage 5 – Report Preparation and Review: Draft the complete BRSR, ensuring figures are reconciled  across all sections. Conduct a thorough cross-reference check against other regulatory filings, including Annual Report (with its financial statements), stock exchange disclosures, and the prior-year BRSR. Ensure that qualitative narratives in Sections A and B are consistent with quantitative data in Section C.  Stage 6 – Assurance: For companies requiring assurance of BRSR Core, engage the independent assurance provider well in advance of the filing deadline. Assurance engagements typically require 6 to 10 weeks, depending on the size and complexity of the company. Early engagement provides sufficient time to address any findings and implement corrective actions before the final report is published.  Stage 7 – Post-Filing Strategy Review: Use the completed BRSR as a structured input into the following year’s ESG strategy. Review KPIs that underperformed against internal targets or peer benchmarks, and set forward-looking commitments where disclosures exist without defined goals. Brief the Board and Audit Committee on findings and the improvement roadmap.  Building Internal Capability: The Role of ESG Education  One underestimated dimension of BRSR compliance is the gap between what boards and management teams are asked to govern and what they currently understand about ESG and sustainability reporting. Board members who review and approve the BRSR must be able to exercise genuine oversight not simply sign off on a document they cannot interrogate.  This is not just a training issue. It is a governance one. When board members and senior leaders lack fluency in GHG accounting, materiality assessment, or the difference between limited and reasonable assurance, decisions about what to disclose, how to interpret findings, and where to invest in sustainability infrastructure are made without the foundation they require.  Pierag’s ESG Learning Academy provides structured capacity-building programmes for boards, audit committees, sustainability teams, and finance functions. The programmes are delivered through structured ESG self‑paced learning modules, customised workshops, training and capacity‑building sessions, and on‑demand courses and webinars. For companies facing BRSR  requirements, this literacy is not optional, it is a governance prerequisite.  Why Pierag: The CA and Assurance Angle  Most ESG advisory firms approach BRSR primarily as a reporting and communications exercise. Pierag approaches it as an assurance and governance discipline, and that distinction is consequential for listed companies whose disclosures face regulatory scrutiny and investor evaluation.  Our ESG and Sustainability practice is led by professionals from diverse backgrounds – Chartered Accountants, Company Secretaries, Engineers, Environmentalists, and Lawyers complemented by specialists with advanced qualifications such as Masters in Sustainabality, DipIFR (ACCA, UK), the ICAI Diploma in BRSR, and certifications as GHG Accounting Lead Verifiers under ISO 14064. Together, they bring deep experience in assurance engagements across large listed companies in India. We understand what an  assurance provider will test because our team has performed those tests. We know what effective ESG data controls must look like because we have designed , reviewed , and reported on them.  This means that when we help a company prepare for BRSR Core assurance, we are not speculating  about  what the assurance provider may find. We are building the data infrastructure and governance controls that meet an independent, evidence-based standard – the same level of rigor applied in statutory financial audits.  Our broader ESG & Sustainability Services practice covers the full spectrum: sustainability reporting and assurance, GHG inventorisation, Life Cycle Assessment, ESG strategy, CSR advisory, digital ESG tools, and structured capacity building. Whether your organisation is filing its first BRSR or preparing for  assurance of BRSR Core for the first time, we can help you move from reactive compliance to strategic ESG leadership.  Compliance Is the Floor. What You Build Above It Determines Value.  BRSR sets a minimum standard for what listed companies must disclose. It does not prescribe how well companies  should perform against those disclosures, or how strategically they should use the discipline of reporting to improve their operations, governance, and  stakeholder relationships.  The companies that will attract long-term institutional capital, access sustainable finance at competitive rates, and build trust with global supply chain partners are not the ones that merely file a compliant BRSR report. They are the ones that embed sustainability into performance measurement, risk management, and decision making and can demonstrate it through independently assured data.  BRSR makes that demonstration possible. What organisations choose to build above the compliance floor determines whether BRSR remains a cost of compliance or evolves into a source of competitive advantage.  Pierag Consulting is here to help you build above the floor. Talk to our ESG and Sustainability experts.  Explore Pierag’s latest thinking on ESG, sustainability reporting, and responsible business at our Insights Hub. Author – Ashlesha Aggarwal (Consultant)
Business implications for global capability centre strategy in India  Haryana’s Global Capability Centre Policy 2026 is more substantive than a generic investment announcement. The policy was notified effective 27 May 2026 and will remain in force for five years from the date of notification or until superseded by a new policy/amendment. It sets clear entry thresholds, location-linked incentives, employment-linked benefits, and R&D support measures that indicate a deliberate attempt to make Haryana a competitive GCC destination, particularly for higher-value and scalable operations.  Policy highlights at a glance  Eligibility thresholds  Minimum employment threshold: 100 employees on payroll or contract with ESI/PF numbers within 3 years of commencement of operations.  Large unit threshold: INR 125 crore fixed capital investment, or INR 50 crore with 500 direct employees.  Mega unit threshold: INR 400-700 crore fixed capital investment, or INR 125 crore with 1,250 direct employees.  Ultra-mega threshold: INR 1,500-6,000 crore fixed capital investment. Existing Unit Eligibility:  Existing GCC units expanding operations on or after 1 January 2026 are eligible  Investments made in the one-year period preceding policy notification qualify for retroactive benefits Human Resource Development and Night Shifts for Women  Employment generation subsidy: % of average gross monthly salary for 10 years (requires 1+ year continuous employment, valid ESI/PF)  Local employment threshold: >15% of total workforce  Floor subsidy: INR 48,000 p.a. when average monthly salary < INR 48,000  Night shifts for women: Three shifts permitted including night shifts, with mandated transportation and safety provisions  Innovation and R&D Support  Job-readiness support reimburses 50% of a 6-month stipend, up to INR 15,000 per month for 50 interns per annum.  For DSIR or CSIR-recognised R&D centres, capital subsidy is available at 50% of eligible capital cost, up to INR 10-50 crore, to be distributed in 5 annual instalments. Operational cost reimbursement benefit of 50% upto 2 crore per year CAPEX vs OPEX Support What stands out in the policy design  The policy is notable because it does not rely on a single headline incentive. Instead, it combines entry thresholds, location-based capital support, operating cost reimbursements, employment-linked subsidies, women-specific provisions, and innovation incentives into a layered package. This is closer to how new age GCC policies are typically structured: the business case is built across setup, scale, and sustained operations rather than around a one-time benefit.  Another important design feature is the location differentiation. Haryana is effectively signalling that it wants to balance the attractiveness of Gurugram with stronger relative support in other districts, explicitly prioritising investment in non-Gurugram districts to promote balanced regional development and position Tier-2 cities such as Panchkula and Hisar as GCC destinations. That has implications for companies evaluating whether they need immediate access to the NCR corporate ecosystem or are willing to trade some of that proximity for stronger incentive economics elsewhere in the state.  The policy also explicitly addresses women workforce participation through night shift allowances, enhanced subsidies, and safety/transportation provisions, making it more progressive than many earlier industrial policies.  What businesses should assess  For businesses, the policy should be assessed on three levels.   First, there is threshold fit: whether the planned investment and employment model aligns with the policy’s eligibility structure.   Second, there is commercial fit: whether the CAPEX, OPEX, and employment-linked benefits are material enough to change the economics of the proposed GCC.   Third, there is execution fit: whether the company can realistically access, document, and sustain compliance with the benefit conditions over time.  This is particularly relevant for firms planning phased expansion. Since benefits are tied to defined investment and employment thresholds, the sequencing of hiring, fit-out, and operational launch may materially influence the eventual value capture. In other words, policy value here is not just about where a GCC is located, but also how the rollout is planned.  Market implications  The policy strengthens Haryana case as a GCC destination for organisations looking beyond traditional metro concentration. Its combination of NCR adjacency, enterprise density, policy-backed support, specific R&D provisions, women-specific workforce provisions, and streamlined facilitation through the AI-enabled Single Window 2.0 (Intelligent Investment Facilitation Portal) established in Gurugram for streamlined approvals, land allocation, and incentive access makes it especially relevant for companies building more specialised and higher-value centres rather than simple cost-arbitrage units.  At the same time, the policy also raises the competitive bar for companies comparing Indian states. The decision is likely to turn less on headline visibility and more on the detailed interplay between incentive value, location suitability, talent access, and implementation ease.  Closing perspective  For organisations assessing India-based GCC expansion, the Haryana policy is best read as a location strategy input rather than a standalone decision trigger. The policy becomes most meaningful when tested against the intended operating model, talent design, timeline, and long-term scale ambition of the proposed GCC.  That is also where a more measured advisory lens becomes useful: not to oversell the policy, but to evaluate whether it genuinely improves the business case compared with other options. A well-grounded market entry or expansion plan should therefore connect policy interpretation with execution realities such as entity structuring, hiring ramp-up, real estate planning, and governance design.  Pierag Consulting supports organisations with GCC expansion by helping translate policy incentives into a workable business case, operating model design, and execution roadmap across feasibility, setup, and scale phases.
For over a decade, India’s Global Capability Centres (GCCs) operated with a clearly defined value proposition: cheaper, faster, scalable. They were the engines of efficiency—delivering back-office support, technology services, and operational scale at a fraction of global costs. But that narrative has run its course. Today, India stands at a defining moment in the evolution of GCCs. Declared the GCC Capital of the World by NASSCOM in 2024, the country is no longer just an outsourcing destination—it is a strategic nerve center for global enterprises. As we move deeper into this decade, it is increasingly clear that this is India’s decade to lead the GCC transformation globally. The numbers tell a compelling story. India’s GCC market, currently valued at $82.1 billion, is projected to grow to $100–110 billion by 2030. This growth reflects more than scale—it signals a shift in perception. India has decisively transitioned from being a low-cost destination to becoming the world’s preferred hub for high-value digital, engineering, and research work. Yet, despite this progress, one fundamental truth remains: Relevance is no longer driven by cost—it is earned by creating value. The Resource Provider Trap Many organizations still fall into what can be termed the “resource provider trap”—where success is measured by headcount, utilization, and cost arbitrage rather than business outcomes. This approach is increasingly fragile. It leaves organizations exposed to automation, macroeconomic uncertainties, and the growing risk of commoditization. Even more concerning is the disconnect between perception and reality. While over 90% of GCC leaders acknowledge their expanded strategic role, performance metrics in many organizations continue to revolve around full-time equivalents (FTEs) rather than measurable impact. This gap is no longer just an operational inefficiency—it represents a strategic vulnerability. At the same time, global disruptions have highlighted another critical capability: agility and resilience. GCCs have emerged as vital anchors of business continuity. During COVID-19, India-based teams rapidly adapted to remote work models, ensuring uninterrupted operations. More broadly, in scenarios of geopolitical instability or regional disruption at headquarters, GCCs provide a distributed execution model that enables business continuity. In essence, GCCs are no longer just delivery arms—they are risk mitigators and continuity enablers. India’s Moment: Scale Meets Strategic Value India’s GCC ecosystem is not only expanding—it is deepening in capability and influence. The country today hosts over 2,100 GCCs operating across more than 3,700 units, with approximately 506 Forbes Global 2000 companies maintaining a presence in India. This reflects an unparalleled level of global enterprise integration. The growth trajectory remains strong, with projections indicating an 8.3% CAGR between 2025 and 2035. Importantly, expansion is no longer limited to metropolitan hubs. The rise of Tier II cities is reshaping the landscape. Private equity firms are playing a pivotal role in this shift, driven by a combination of supportive government policies, robust digital infrastructure, lower setup costs, and a growing preference among talent to avoid high-cost urban centers. Simultaneously, global corporations are making bold bets on India’s future. Microsoft’s planned $17.5 billion investment between 2026 and 2029 to expand cloud and AI infrastructure, along with Amazon’s $35 billion commitment by 2030, underscores the strategic importance of India in shaping the next wave of technology and innovation. The signal is unmistakable: India is no longer a participant in the global GCC ecosystem—it is leading it. The New Value Playbook The transformation of GCCs from cost centers to value creators is already underway, and investment patterns reveal this shift. Organizations are increasingly channeling resources into technology transformation (25%) and capability development (23%). Leading GCCs are distinguishing themselves through three key shifts: Owning Outcomes, Not Just Activities The traditional model of execution is giving way to ownership. GCCs are no longer evaluated on the volume of work delivered, but on the business outcomes they influence—whether in engineering innovation, financial optimization, or operational excellence. Turning AI into a Competitive Advantage The rapid adoption of generative AI is accelerating this transformation. Forward-looking GCCs are embedding AI into core business processes—not merely to improve efficiency, but to drive innovation and create differentiated value. Anchoring to Enterprise Strategy Alignment with global headquarters is no longer optional. The most successful GCCs operate as integrated extensions of enterprise strategy, playing a direct role in shaping decision-making and enabling growth. These shifts are redefining GCCs as enterprise nerve centers, rather than support functions. Leadership Transformation: From Managers to Micro-CEOs Perhaps the most significant evolution is happening at the leadership level. The role of GCC leaders is expanding beyond operational management into strategic influence. While they may not always hold final decision-making authority, they increasingly shape critical enterprise outcomes. Influence, therefore, is emerging as a key currency. This shift demands a new leadership mindset—one where GCC heads operate as “micro-CEOs”, balancing execution excellence with strategic vision, stakeholder alignment, and value creation. The Real Shift India’s GCC journey has progressed through multiple phases—from cost efficiency to scale, from scale to co-creation. Today, it is entering its most critical phase yet: value leadership. However, there is an important caveat. If organizations continue to anchor their GCC strategy solely in cost savings and talent availability, they risk relegating these centers to processing units rather than strategic enablers. The opportunity is far greater. GCCs have the potential to evolve into innovation engines, decision hubs, and growth catalysts—but only if organizations fully embrace the shift from cost-centric thinking to value-driven execution. Conclusion This transformation is not merely a shift in geography—it is a shift in identity. From resources to revenue drivers, From execution to influence, From support functions to strategic partners. India is not just keeping pace with this shift—it is setting the direction. As the GCC ecosystem continues to evolve, one thing is clear: The future will not belong to the most cost-efficient centers—it will belong to the most value-driven ones.
A New Era of Trade and Climate Policy The European Union’s Carbon Border Adjustment Mechanism (CBAM) is no longer a distant policy experiment. From 1 January 2026, it became a binding financial obligation for exporters of carbon‑intensive products such as iron and steel, aluminium, cement, fertilisers, hydrogen, and electricity. The EU’s goal is simple but ambitious: prevent carbon leakage, where companies shift production to countries with weaker climate rules, undermining global climate progress. This mechanism is not just about Europe. The EU is the world’s largest single market, and by attaching a carbon price to imports, it is effectively exporting its climate standards worldwide. Any exporter who wants access to Europe must either prove low‑carbon production or pay the difference.  The First Price Signal On 7 April 2026, the European Commission published the first official CBAM certificate price: €75.36 per tonne of CO₂ equivalent Uniform across all sectors Based on the average EU ETS auction clearing prices for Q1 2026 This number is only the starting point. What matters more is the carbon intensity of each product. Steel, for example, is far more carbon‑intensive than aluminium, meaning the same certificate price translates into vastly different burdens. India’s Early Exposure  The impact is already visible even before financial obligations began. During the reporting phase alone: Steel and aluminium exports to the EU fell 24.4% from $7.71 billion in FY24 to $5.82 billion in FY25. Iron and steel exports also saw a sharp contraction during the reporting phase, reflecting the compliance burden and uncertainty faced by EU buyers. This contraction reflects the compliance burden of reporting requirements and the uncertainty EU buyers face when suppliers cannot provide verified emissions data. The financial phase will only amplify this pressure.  The Preparedness Gap  Most Indian manufacturers understand CBAM in theory. Far fewer are prepared in practice. True preparedness requires: Verified plant‑level emissions data aligned with EU standards. GHG accounting systems that meet EU methodology, often requiring 40 to 80 staff hours annually. Without verified data, exporters are forced to rely on EU default values. These are deliberately conservative, often higher than actual emissions, designed to push companies toward verification. Relying on them is not neutral; it inflates costs, weakens negotiations, and erodes competitiveness.  The Investment Reality One misconception needs to be addressed: international carbon credits, offsets, or green certificates do not reduce CBAM liability. The mechanism only recognizes documented reductions at source or domestic carbon pricing formally accepted by the EU. That leaves exporters with two options: Decarbonisation at source: requiring significant capital investment. Absorbing the cost: which erodes already thin margins in price‑sensitive markets. Neither path is easy, but waiting is not an option.  The Expanding Scope  CBAM is not stopping at bulk industrial sectors. From January 2028, the EU plans to extend coverage to nearly 180 additional products, including: Fabricated metal products Auto components Machinery parts Plastics and polymers Chemicals For downstream manufacturers, this is not “someone else’s problem.” It is a ticking clock.  The Signal, Not the Endpoint  CBAM is more than a compliance mechanism. It is a signal that carbon intensity is now a trade variable. Key milestones ahead include: Q2 price publication: July 2026 First declaration deadline: September 2027 Scope expansion: January 2028 The companies that act today by building data infrastructure, verifying emissions, and modelling carbon costs will manage this transition on their own terms. Those that wait will be managed by it. Author - Anshit Dhawan ( Senior)
Artificial intelligence is no longer a fringe innovation topic or a limited pilot initiative. It has moved firmly into the enterprise mainstream, and the market conversation has shifted accordingly: from experimentation to scale, governance, operating models, and measurable value creation. That shift matters because adoption is no longer the real test of maturity. Most enterprises today can access leading models, license copilots, launch pilots, and introduce AI-enabled tools into selected functions. Yet the presence of AI in the technology stack does not, by itself, improve business performance. The more important question is whether AI has been embedded in a way that meaningfully improves how work gets done. This is where many enterprise AI programs begin to lose clarity. Attention often centres on model selection, tool comparisons, or the promise of the latest platform release. Those decisions are relevant, but they are not usually what determines long-term value. In practice, the more difficult and more consequential challenge is execution: defining where AI belongs within a business process, where conventional automation is more effective, where human judgment must remain central, and how all of it is governed at scale. Recent enterprise experience has made this distinction increasingly visible. Many of the most instructive AI stories are not about whether the technology works in principle. Instead, they are about cost overruns, unclear returns, weak process fit, inconsistent usage, and the difficulty of scaling tools that were introduced without sufficient operational discipline. That is why enterprise AI strategy should not begin with access to technology. It must begin with the design of work. Shifting the Focus: From Access to Execution A more effective starting point is the business workflow itself. To build a grounded, impactful AI roadmap, leaders must step back from the technology and begin by asking critical diagnostic questions: Process Centrality: Which processes are genuinely central to our operational performance? Friction Points: Where do teams currently lose time to review, rework, handoffs, or fragmented information? Cognitive Demands: Which activities depend most heavily on pattern recognition, contextual interpretation, or complex exception handling? Value Leverage: Where would better support improve quality, consistency, customer experience, or the speed of decision-making? These questions tend to produce a much more grounded roadmap than a technology-first approach. They also lead to an essential realization: not every business problem requires AI, and not every step within an AI-enabled process should be handled by AI. Deconstructing the Workflow Enterprise workflows contain distinct categories of work, and each category demands a different tool. Some steps are deterministic and governed by stable rules. Others are repetitive and process-driven. Some involve ambiguity, unstructured information, or complex contextual interpretation. Others require legal accountability, commercial judgment, or strict compliance oversight. Treating all of these as the same kind of problem is one of the most common errors in enterprise AI design. Strong AI programs are rarely built by maximizing the amount of AI in a process; they are built by assigning the right capability to the right type of task. The vendor invoice process offers a highly practical illustration of this multi-layered framework. Consider a multinational enterprise managing thousands of global suppliers. Seeking a quick win, leadership deploys a generic, off-the-shelf AI co-pilot to automatically read and approve all incoming invoices. In reality, the initiative quickly derails. The generic AI hallucinates on standard tax fields because it does not understand the firm's strict internal data boundaries. It wastes expensive computational power simply routing a PDF from a manager to a VP. Worst of all, it mistakenly approves a disputed, high-value transaction because it lacks the commercial context of an ongoing vendor lawsuit. This failure occurs because the enterprise treats the entire workflow as an "AI problem." In reality, to succeed, the process must be deconstructed into a layered operating model: Rules with Predictable Outcomes: Validating invoice data against purchase orders and tax requirements is entirely rule-based. A classic rules engine is the most cost-effective and reliable tool here. Automating Repetitive Tasks: Procedural steps, including routing approvals and updating ERP systems, are highly repeatable. Standard workflow automation is best suited to these status-based actions. AI Where Context and Judgment Are Required: AI becomes highly valuable during exceptions—unusual charges, incomplete documentation, or subtle inconsistencies. Here, AI can analyze unstructured supporting material, highlight anomalies, and assist a reviewer in narrowing down the issues. Humans When Accountability Counts: Human oversight remains strictly necessary where commercial judgment, regulatory sensitivity, supplier disputes, or high-value decisions require a level of accountability that cannot be delegated to an algorithm. This layered operating model is far more effective than the blanket idea of “AI everywhere.” It respects the unique strengths of rules, automation, AI, and human expertise. Custom Architecture vs. Generic SaaS Because strategic enterprise workflows require this precise, multi-layered coordination, managing the handoffs between strict business rules, standard automation, and cognitive AI assistance requires a cohesive, tailored orchestrator. Generic, off-the-shelf software rarely has the inherent flexibility to stitch these four layers together seamlessly. This raises a critical question for enterprise leaders: when is a standard platform sufficient, and when is custom development justified? The most effective standard operating procedure (SOP) relies on a simple distinction: Core versus Context. Context Workflows (Buy/Standard SaaS): These are non-differentiating processes that every company handles similarly—such as standard payroll processing, routine expense categorization, or basic accounts payable routing. For these, standard, off-the-shelf platform tools are completely sufficient. There is no strategic value in reinventing the wheel. Core Workflows (Build/Custom Orchestration): These are the proprietary processes where an enterprise actually wins its market—whether that is an investment bank's proprietary M&A valuation model, an consulting firm’s technical accounting expertise, or a multinational's complex forecasting engine. This challenge has become top-of-mind as adoption timelines compress. Research from the Wharton School and GBK Collective indicates that generative AI is fast-tracking into the core of the enterprise, with decision-makers increasingly shifting budgets from experimentation to integration. Yet, as adoption accelerates, the gap between high-performing and average organizations becomes clearer. McKinsey’s research indicates that while AI use is now widespread, the ability to translate that use into actual business impact remains highly uneven. Crucially, high-performing organizations are far more likely to redesign workflows fundamentally to support this multi-layered reality, rather than simply overlaying AI onto existing, broken activity. Enterprise value is created not when AI is added on top of work, but when work itself is redesigned to use AI appropriately. In specialized, "Core" environments, durable value typically comes not from buying another off-the-shelf license, but from configuring bespoke solutions that align perfectly with the unique operating model of the business. Governance and the Power of Human Augmentation To support this bespoke architecture, an enterprise operating model must prioritize governance and human enablement from day one. Cost control, usage discipline, data boundaries, and security guardrails cannot be added as an afterthought. The growing emphasis in enterprise research on production readiness and ROI measurement reflects exactly this concern. For instance, ISG’s reporting focuses heavily on spending trends, governance, and scaling challenges, while other market research increasingly evaluates AI not by its novelty, but by its deep integration and structural guardrails. Crucially, those guardrails are not just technical—they are human. One of the most persistent misconceptions is that AI's primary value lies in replacing human labor. In reality, the International Monetary Fund’s (IMF) analysis of labor exposure continually emphasizes complementarity—the immense potential of technology to work alongside people, amplifying their capability rather than substituting it. AI does not create enterprise value simply because it is available. It creates value when employees are trained and empowered to co-pilot with it: Understanding precisely where the technology adds cognitive leverage. Knowing exactly where its outputs must be challenged or verified. Recognizing where over-reliance would introduce unnecessary operational risk. This is particularly relevant in high-stakes functions like finance, legal, procurement, and risk, where work constantly balances structured process and contextual judgment. In these environments, staff education is not a secondary HR workstream; it is a core part of the operational control framework and the ultimate engine of productivity. Strategic Execution: The Path to Lasting Value The broader business case for this disciplined approach is becoming impossible to ignore. Recent market research highlights a widening performance gap between organizations that merely acquire tools and those that build the operational infrastructure to support them. Oxford Economics’ work on enterprise AI maturity, for example, demonstrates that sustainable value is tied directly to deep operational integration rather than simple access. This is reinforced by McKinsey’s findings, which establish a direct link between fundamental workflow redesign and actual value capture. Ultimately, this execution gap translates into a financial one: as IMD’s maturity research points out, a significant performance and margin divide is opening up between operationally mature enterprises and those still struggling to scale their pilots. The implication for enterprise leaders is straightforward. The long-term winners in the AI era are unlikely to be the organizations that deployed the greatest number of tools or announced the largest number of pilots. They are more likely to be the ones that: Identified the right strategic workflows. Intelligently combined rules, automation, AI, and human oversight. Built robust governance frameworks from the outset. Trained their workforce to interact with these capabilities with disciplined, empowered skepticism. AI adoption may open the door, but disciplined execution determines whether that investment translates into durable business value. Sources International Monetary Fund (IMF)- sdnea2024001.pdf ISG (Information Services Group)- isg-one.com/docs/default-source/default-document-library/2025-isg-state-of-enterprise-ai-adoption-r… Wharton School / GBK Collective- ai.wharton.upenn.edu/wp-content/uploads/2025/10/2025-Wharton-GBK-AI-Adoption-Report_Full-Report.pdf Impact AI Series | Oxford Economics IMD Business School- Companies leading in AI adoption use it as a catalyst for reinvention - IMD business school for man…
Every year, April 22nd comes around the same way We see the pictures. The recycling infographics. The posts about caring for the planet. And then April 23rd arrives and most of it just goes away. According to reports, an estimated 62% of consumers said they are willing to change their purchasing habits to limit environmental impact, however, only 31% of people reported that their most recent purchase consisted primarily of sustainable or environmentally friendly items. But 2026 feels different. This year's theme is "Our Power, Our Planet." If one were to consider the circumstances, it would be very clear that in 2025, several hundred environmental regulations were repealed globally, including emissions standards and wetlands protection measures, each of which had taken over a decade to formulate. It was not a few isolated instances of policy changes; it was a systematic reversal of decades-old policies while the vast majority of businesses were preoccupied with other issues. It is not a matter of whether businesses have become aware of the problem. It is a matter of what actions will they take to address it. The Gap Has Never Been About Awareness Every leader we talk to knows climate change is real. Every CxOs we work with knows that disclosing how their company affects the environment is coming, whether they are ready or not. The market is not unaware. The problem is that awareness has not been turning into action. As per a new survey conducted by CRM solutions provider  Salesforce, in partnership with insights and advisory consultancy GlobeScan, while 90% of executives viewed sustainability as important to their organizations’ commercial success, including two-thirds who rate it as “very important,” only 37% consider sustainability to be very integrated into their businesses. The report noted the importance of high quality data for meeting new regulatory sustainability reporting requirements, with the survey finding that 59% of executives expect to have difficulty complying with the new EU Corporate Sustainability Reporting Directive (CSRD), and 31% expecting challenges with the reporting requirements from the IFRS’ International Sustainability Standards Board (ISSB). And under that problem is something just as bad, but harder to notice. For example, a truck that stays motionless and burns up fuel every day. The same goes for the expense of not being sustainable. It builds up quietly. The cost of borrowing goes up. Government scrutiny increases. Investors start losing confidence. The people inside the company start asking questions about what it actually stands for. These are not future worries. They are happening right now. They are just not always easy to spot on a report. Most companies still think of sustainability as something that belongs in an annual document. Not in the room where actual business decisions get made. That thinking is exactly what keeps companies stuck. And it is exactly why April 23rd tends to feel like the morning after a party nobody really planned.  Saying It and Doing It Are Not the Same Thing A net-zero commitment without a way to measure it is just words. A diversity goal without a structure behind it is something that gets said in a meeting and forgotten. The difference between companies that are genuinely making progress and those that are just talking about it comes down to whether sustainability is part of how they actually make decisions, not just how they communicate. Following frameworks like BRSR, GRI, CSRD, and IFRS S1/S2 is not about doing what regulators say. It is about being honest and transparent in a way that holds up. And, this is not niche anymore. For example- as per guidelines, India’s top 1,000 listed companies are now mandated to report under BRSR. Similarly, CSRD will expand ESG reporting requirements to ~50,000 companies in the EU. Companies that have built this properly do not just report differently. They operate differently. The way they buy, the way they use energy, the way they work with suppliers, all of it gets informed by a clearer understanding of what sustainability costs and what it is worth. That clarity, built up over time, is what separates companies that are actually performing from those that are just trying to keep up.  What This Actually Requires from All of Us The real change happens after Earth Day. It is about what people and businesses do not just what they say. People need to be careful about what they buy and try to use energy and stuff. They should think about whether the things they buy're good for the Earth. Companies need to ensure that they practice sustainability by setting measurable, achievable goals based on factual information. They must also consider how their actions will impact the earth and act accordingly to “do the right thing.” They also have to measure how well they are doing and be honest about it. Businesses must be open about what they're doing to help the Earth and sustainability of Earth is very important, for businesses and people. Awareness without measurable actions and accountable actions cannot produce results. "Our Power, Our Planet" Is Not an Invitation. It Is a Question. Climate urgency is intensifying, marked by rising global temperatures, record-breaking warm years, and an increasing frequency of climate-related disasters. It is asking companies what they are doing with the power they already have. The supply chains. The capital. The energy decisions made every single day without a sustainability lens. The people being developed, or not. Each one of those is an opportunity. Most of them are still being left alone. April 22nd is a reminder. But the work does not start or stop on that day. It lives in the decisions companies make every other day of the year. The answer and the work start now. Author - Anshit Dhawan (Senior)
  • 5-9 Mins Read
Compliance management today requires visibility and proactive planning. With numerous regulatory deadlines across Income Tax, GST, FEMA, MCA, SEZ, and STPI, staying organized is essential for businesses to operate smoothly. We have put together the Compliance Calendar for FY 2026–27, designed to help organizations track key due dates and integrate reminders directly into Outlook calendars for better compliance management. Sharing this resource with the hope that it helps teams stay ahead of deadlines and focused on what matters most, building resilient and responsible businesses.
  • 8-10 Min Read
The Shift from Mitigation to Adaptation In the last decade, the main concern of corporate climate strategies has been the reduction of greenhouse emissions and the achievement of the target of net-zero emissions. Although the prevention of global warming is the key, the increasing effects of climate change have made climate adaptation an important concern. The severe weather changes, increase in temperature, water scarcity, and sea level rise are now being witnessed globally, which are negatively affecting supply chains, infrastructure, and commercial operations globally. Businesses are realizing that cutting carbon emission reduction is not enough. In spite of all the mitigation efforts, there are some unavoidable effects of climate change, and enterprises need to start preparing for the new risks. Climate adaptation is shifting from a niche sustainability issue to a critical part of an enterprise’s overall ESG strategy. This shift is illustrated by the financial investment required to address the issue of climate resilience. The Adaptation Gap Report 2024 by the United Nations Environment Programme indicated that developing countries will require between $215 billion and $387 billion annually starting from 2030 to address the issue of climate change. The financial impact of the issue is already apparent. In 2024, the financial losses due to natural disasters across the globe are estimated at $320 billion. Therefore, the financial impact of the issue is already apparent. In this case, adapting to the issue of climate change is no longer only a matter of environmental protection but is becoming a matter of strategic business, as companies must now consider the financial implications of climate-related disruptions on their operations and long-term viability. Understanding Physical Climate Risks for Businesses Physical climate risks, as the name suggests, refer to the direct impacts of climate change on assets, operations, and supply chains. These risks are generally categorized as acute and chronic. Extreme weather events, floods, hurricanes, wildfires, and heatwaves are examples of acute risks that can cause problems with operations. On the other hand, chronic risks involve longer-term climate shifts and may include changes in sea levels, droughts, and increased temperatures. With the rising cases of weather-related disasters, the importance of adaptation to these changes cannot be overemphasized. From 1985 to 2025, losses of around US $7.2 trillion are observed from natural disasters. This, therefore, highlights the rising risk to businesses as a result of these changes. These dangers are not exclusive to any certain industry. Manufacturing facilities situated in flood-prone regions may be compelled to cease operations, while agricultural endeavors may see diminished productivity as a result of climatic alterations. These alterations may be experienced across multiple sectors, including energy and retail. Financial institutions and investors are progressively evaluating physical climate concerns. Financial institutions, including lenders and insurance providers, are evaluating companies' vulnerability to climate-related risks. This has compelled businesses to incorporate risk analysis into their strategy planning. Why Climate Adaptation Is Becoming a Business Priority The importance of putting more emphasis on climate adaptation in corporate ESG agendas has been heightened by multiple factors, including the growing frequency and severity of climate-related disasters and ongoing real-world financial consequences for businesses such as supply chain disruptions, damage to physical infrastructure, and operational delays. There is also greater expectation from regulators and global frameworks regarding the disclosure of climate risk. The Task Force on Climate-related Financial Disclosures suggests that companies should identify both transitional and physical risks and disclose how their strategies will remain resilient to the risks they may face based on the different climate scenarios. There is increasing demand for more transparency from investors about how businesses will manage long-term climate risk. Climate resilience is being viewed by institutional investors as an important indicator of a company’s financial stability. Companies unprepared for the effects of climate may experience more expensive insurance coverage, decreased asset valuation, and/or limited access to funding sources. The case for the economics of adaptation is beginning to come into view as well. As a 2024 analysis by the Boston Consulting Group revealed, there was more than $1 trillion of worldwide climate damage between 2020 and 2024, and so the financial impact of extreme weather events is rising. As a result, climate adaptation is being seen as the new frontier for ESG leadership. Climate-Resilient Business Strategies To address physical climate risks, proactive approaches to adapting to the situation have to be developed. Organizations have to conduct exhaustive assessments of the risks that might be caused by the climatic conditions. In this case, the impact that the climatic conditions might have on the business is analyzed. This is where the use of scenario analysis is important. Another key aspect that has to be addressed is the issue of infrastructure. In this case, the business might have to invest in the construction of facilities that are able to protect the business from the effects of extreme climatic conditions. In this case, the business might have to invest in the construction of facilities that protect the business from floods. In addition, the business might have to invest in the installation of technologies that help to conserve water. In this case, the business might have to invest in the installation of air conditioning units. However, corporate preparedness remains low despite acknowledging the risks that may be caused by climatic conditions. Research done on more than 1,000 publicly listed firms revealed that only 23% of these firms have put in place mechanisms to address this problem. Therefore, investments in infrastructure that is resistant to climate change, sustainable water management, and natural solutions can help to mitigate risks to operation in the long term as well as environmental objectives. This may require collaboration with other actors because risks are often beyond an organization. Governance and ESG Integration Effective climate adaptation practices require robust climate adaptation governance practices and oversight by the board of directors. Climate risk management is an essential part of enterprise risk management practices, ensuring that adaptation practices are consistent with overall corporate governance practices. The board plays an essential part in overseeing the assessment of climate risks, developing resilience goals, and monitoring progress. The transparent communication of risks and adaptation techniques is becoming increasingly expected by various stakeholders and regulatory bodies in firms. The importance of ESG reporting frameworks in prioritizing resilience in overall sustainability reporting is becoming prominent. The transparent communication of adaptation techniques by firms is likely to increase investor trust and readiness for the long-term effects of climate change. Next Step: Climate Resilience in Corporate Strategy As much as the climate risks are rising, adaptation is turning out to be a key component of the sustainability strategy for many firms. Companies that focus only on cutting down emissions and ignore the physical climate dangers may face a shock that threatens their sustainability. According to the World Meteorological Organization, the period between 2015 and 2024 has been the warmest decade on record. This implies that extreme weather occurrences and climate upsets might worsen in the coming future. As a way of countering the effects of climate change, many organizations are going a step further than their net-zero targets and attempting to make their operations more climate-resilient. Companies can better prepare for environmental shocks and keep their operations going by including climate adaptation in their governance structures, risk management frameworks, and investment decisions. In this context, it can be said that the question is no longer whether businesses should prepare for climate impacts but how effectively they can adapt. Companies that treat climate resilience as a strategic priority will be better positioned to navigate climate uncertainty while creating sustainable long-term value. Author - Ayushika Saraswat (Consultant)
  • 8-10 Min Read
The risks that organizations once monitored from a distance are now actively reshaping business models, capital decisions, and strategic priorities. Below are the five risks that every leader should focus on: 1. Cybersecurity – Cyber incidents are no longer just an IT problem. They disrupt operations, delay customer interactions, and attract regulatory scrutiny. 2. Digital Disruption & AI – AI adoption is accelerating faster than governance frameworks can keep up. The question is no longer whether to adopt, it's who is accountable when things go wrong. 3. Business Resilience – Resilience today isn't about recovering after a disruption. It's about sustaining performance while disruption is still underway. 4. Geopolitical Uncertainty – Trade disputes, policy shifts, and regulatory changes are happening without warning. Organizations must embed these into strategic planning, not treat them as external noise. 5. Human Capital – 40% of organizations worldwide identify talent as a key risk. Having a strategy means little without the people ready to execute it. What makes these risks truly complex is how deeply interconnected they are. A cyber incident amplifies operational fragility. Geopolitical shifts strain already-stretched supply chains. Talent gaps slow down an organization's ability to respond to any of it. In this environment, Internal Audit is shifting from process reviewer to risk interpreter. Download & Read our full Point of View below.
  • 8-10 Min Read
ESG Perspective – March 2026 Edition presents a curated overview of key global developments shaping the evolving ESG and sustainability landscape. The edition highlights important regulatory updates, emerging global standards, and market trends across areas such as carbon markets, sustainability reporting and disclosure frameworks, climate policy, circular economy regulations, and sustainable finance. As governments, regulators, and investors continue to strengthen expectations around transparency, accountability, and climate action, businesses are increasingly required to navigate a complex and rapidly evolving ESG environment. This edition distills significant policy announcements, regulatory reforms, and standard-setting initiatives from across jurisdictions into clear, decision-relevant insights. By bringing together these developments in one place, the report aims to help organizations stay informed, anticipate regulatory shifts, and better prepare for the transition toward more sustainable and responsible business practices. Read the full edition for a deeper look at the latest global ESG developments and regulatory insights.
  • 8-10 Mins Read
Standard Setters’ Updates – H2 2025 This edition provides a concise and practical overview of the most significant accounting, regulatory, and sustainability reporting developments from the second half of 2025, helping organizations prepare for upcoming changes in 2026 and beyond. Key Highlights: Major Accounting Standards Updates (ASUs) issued in H2 2025, covering credit losses, internal-use software, derivatives and hedging, purchased loans, government grants, interim reporting, and codification improvements. Simplification and consistency initiatives by FASB, aimed at reducing complexity, improving comparability, and better aligning accounting outcomes with economic substance. Snapshot of FASB current projects, including debt exchanges, environmental credit programs, crypto asset transfers, equity method improvements, and cash flow statement refinements. Regulatory developments from the SEC, including leadership changes, crypto asset guidance, AI and fraud task forces, financial reporting manual updates, and implications of major U.S. fiscal legislation. Sustainability reporting developments, highlighting ISSB exposure drafts and significant simplification of European Sustainability Reporting Standards (ESRS), with reduced reporting burden and enhanced interoperability. Practical effective-date guidance, with appendices outlining ASUs effective in 2025 and 2026 to support timely implementation planning.
  • 15-20 Min Read
Executive Summary By 2026, Global Capability Center (GCC) will no longer be evaluated as offshore delivery constructs. They will be assessed as enterprise assets- capable of influencing growth, resilience, innovation velocity, and risk posture. CXOs today stand at the crossroads of pressure- be it margin compression and regulatory complexity or talent scarcity with accelerated digital disruption, in addition to this are the evolving geopolitical uncertainty. In the said context, GCCs are evolving as strategic arm – given they are intentionally designed, governed and integrated into an enterprise. In this blog we have explored forward looking view of GCCs in 2026, analyzing industry trends with a people-centric, value driven operating philosophy. It outlines how organizations can move beyond cost arbitrage to build GCCs that deliver sustainable enterprise advantage, reflecting Pierag’s belief that enduring performance is created when people, purpose, and strategy are aligned. The 2026 Reality: Why GCCs Are Now a Boardroom Priority The role of the GCC is undergoing structural redefinition. Three forces are driving this shift: 1. Enterprise Complexity Has Outpaced Traditional Models Global organizations now exist and operate in environments characterized by regulatory fragmentation, digital acceleration, and dispersed decision-making. Centralized headquarters alone cannot absorb this complexity. GCCs are increasingly expected to: Own end-to-end business capabilities Act as centers of judgment, not just execution Provide continuity and resilience across markets and cycles A testament to this strategic shift is India as it hosts the largest GCC ecosystem globally, with ~1,700+ centers driving nearly 55% of global GCC share. The market was valued at ~$64.6 billion in 2024 and is projected to exceed $100+ billion by 2030 2. Talent Has Become a Strategic Constraint Availability and screening of adaptable talent is now a growth constraint not just a support function issue. GCCs have now evolved into strategic and dynamic talent hub, shaping organization’s leadership pipeline, capability and knowledge base. Despite global visa and protectionist policy shifts (e.g., H-1B tightening), India’s deep and dynamic talent pool and cost advantage sustain multinational investment and near-term expansion. 3. Technology Without Governance Is a Risk Multiplier AI, automation and digital platforms are innovating faster than governance frameworks. GCCs are especially enabled to balance technological transformations with control, give governance frameworks are embedded by design. For CXOs, the GCC conversation in 2026 is no longer operational. It is strategic, financial, and reputational. Redefining GCC Value: The 2026 Mandate Leading organizations are reframing the GCC value proposition across four dimensions: Strategic Contribution - GCCs are transitioning from support roles to co-owners of outcomes - contributing directly to transformation initiatives, product innovation, and market expansion. Leadership and Decision Ownership - Conversation now is shifting from authority to capability. Mature GCC models in 2026 will become a hub of senior leadership not just nominal delivery roles. Compliance, Trust and Emerging Risk - With the updated and ever evolving geopolitical changes and strict global scrutiny, GCCs are becoming hubs of governance excellence, ensuring control and transparency across geographies. Measurable Enterprise Impact - Boards are not only setting goals for cost savings, but the expectation goes beyond in terms of value creation, resilience, and long-term commitment of growth in the competitive markets. Pierag’s View: Designing GCCs for Enduring Advantage Pierag approaches GCCs as long term enterprise investments rather than planned expansions. The philosophy that guides this long-term vision is straight and simple- organizations scale sustainably when their people are empowered, trusted, and purpose-aligned. People as Strategic Capital In 2026 and the years to come, talent pool will not just be a line item – they will be one of the most important pillars of strategy. Pierag’s GCC approach prioritizes- Leadership depth and readiness for succession Cultural flexibility and adaptability across boundaries Rigorous capability development and growth aligned to enterprise priorities and objectives This process and human focused approach enable GCCs to evolve their role from execution and delivery centers to strategic partners involved in decision making. Operating Models That Evolve with Enterprise Pierag understands that no two organizations are alike and thus supports flexible GCC pathways aligned to risk appetite and growth ambition: COCO for organizations seeking full ownership and operational control COPO for organizations retaining ownership while outsourcing day-to-day operations BOT for phased ownership and de-risked expansion in new markets These models are not endpoints - they are transitional pathways designed to mature with the organization. Governance Embedded from Day One With increasing regulatory compliances and need for data sensitivity, Pierag embeds security, governance and compliance by design into the GCC foundation – ensuring agility without unnecessary exposure. Structured Execution, Adaptive Thinking The simple four step GCC launch process- Evaluate, Design, Build, Operate is executed with discipline while keeping in mind continuous recalibration with evolving business needs and strategic changes. In 2026, the successful and mature GCCs will be those that are purpose-led, trusted and deeply integrated not only by the leadership but also by regulators and employees. Pierag’s stand is clear- sustainable enterprise advantage is built when GCCs are designed around people, integrity, and long-term value, not short-term efficiency. In doing so, organizations transform GCCs from operating leverage into enduring strategic assets.  
  • 4-5 Min Read
Imagine a future where the most valuable currency isn’t gold, dollars, or even Bitcoin—but carbon credits. In a world racing against time to curb climate change, these tradable certificates, each representing the removal or reduction of one metric ton of CO₂, are emerging as the “climate coin” that could redefine global wealth and economic power. The Birth of a Climate Currency Carbon credits were born out of necessity. The Kyoto Protocol in 1997 introduced the concept, allowing developed nations to fund emission-reduction projects in developing countries. This laid the foundation for a global carbon market, a space where environmental responsibility meets economic opportunity. Fast forward to the Paris Agreement in 2015, and the game changed: every nation now sets its own climate targets, and Article 6 created a framework for cross-border carbon trading, making carbon credits a universal language of climate action. Why Carbon Credits Matter Today The urgency is undeniable. The Intergovernmental Panel on Climate Change warns that limiting global warming to 1.5°C requires deep emission cuts. Yet, industries cannot eliminate all emissions overnight. Enter carbon credits—a bridge between ambition and reality. Tech giants like Amazon pledge carbon neutrality by 2040, banking on credits to offset unavoidable emissions. For businesses, these credits are more than compliance tools—they’re strategic assets signaling climate leadership. Global standards are tightening. The EU Emissions Trading System (EU ETS), launched in 2005 as the world’s first major carbon market, now pairs with the Carbon Border Adjustment Mechanism (CBAM), moving to full implementation in 2026, ensuring imported carbon-intensive goods carry a price comparable to the EU’s. In India, the Carbon Credit Trading Scheme (CCTS) and the Indian Carbon Market (ICM), were notified in 2023, laying the groundwork for a structured national carbon credit market. As emission intensity targets are rolled out in 2025, this scheme positions Indian industry to compete in a world where carbon cost will increasingly determine market access. Leading Indian companies, including Mahindra & Mahindra, Tata Steel, Infosys, Hindustan Zinc, and Reliance Industries, are already active participants in carbon markets, signalling how corporate India is integrating carbon credits into business strategy and long-term decarbonisation plans. The Market Behind the Movement Unlike traditional currencies, carbon credits don’t have a fixed global price. Their value depends on project type, certification, and market dynamics. Credits from reforestation or renewable energy projects often fetch premium prices because they deliver biodiversity and community benefits. Verified standards like VCS and Gold Standard ensure integrity, making these credits highly sought after. Today, the carbon market is no longer a niche policy tool—it’s one of the fastest-growing economic systems. In 2025, the global carbon credit sector is estimated to be worth USD 838–933 billion, and projections suggest it could surge to USD 10–17 trillion by 2034, driven by corporate net-zero pledges and rising demand for high-integrity offsets. Compliance carbon trading systems now operate across multiple jurisdictions, covering up to 28% of global emissions and generating more than USD 100 billion in public revenues by late 2024. Momentum is accelerating: companies retired a record 95 million credits in the first half of 2025. Looking ahead, supply could expand 20–35 times by 2050, reaching 4.8 billion tonnes of CO₂e annually in high-quality scenarios, with credit prices expected to climb to USD 60–104 per ton as technologies like direct air capture and nature-based solutions mature. From Paper to Digital: Tokenized Carbon Credits Blockchain technology is transforming carbon credits into digital tokens—secure, traceable, and tradable like cryptocurrency. Each token represents a verified credit, creating transparency and eliminating double-counting. Imagine logging into your digital wallet and seeing not just Bitcoin but climate coins backed by real-world impact. These tokenized credits could soon dominate decentralized finance platforms, merging sustainability with fintech innovation. Challenges on the Horizon Yet, the rise of carbon credits as a “climate coin” comes with real challenges. A major meta-study covering nearly 1 billion tonnes of CO₂ equivalents found that less than 16% of issued credits truly cut emissions. Price swings across project types add uncertainty, and greenwashing remains a major risk. Investigations show that 78% of the top 50 offset projects may be “likely junk,” raising doubts about their integrity. Weak verification and flawed third-party audits deepen these concerns, turning many credits into claims rather than real climate action. The Road Ahead Carbon pricing mechanisms like Sweden’s $130 per ton carbon tax and the EU ETS are pushing companies to rethink emissions as liabilities. Meanwhile, voluntary markets are booming as corporations race toward net-zero commitments. Stricter verification protocols from bodies like the Integrity Council for the Voluntary Carbon Market promise to weed out greenwashing, ensuring every credit delivers genuine climate impact. Could Carbon Credits Rule the Economy? If trends continue, carbon credits might become the most influential economic instrument of the century. They represent survival, responsibility, and opportunity all rolled into one. In a world where climate risk dictates financial stability, the “climate coin” could very well become the currency that matters most.
  • 5-10 Min Read
India’s IT landscape has experienced a dramatic shift over recent decades, moving away from traditional, paper-dependent bookkeeping methods to a vibrant, tech-powered ecosystem. Today, organizations depend on — ranging from enterprise resource planning (ERP) tools to cloud platforms — not only to boost efficiency but also to safeguard compliance, security, and data accuracy of financial reporting. This change entails additional responsibility since keeping thorough records helps to prove financial integrity and responsibility. An audit trail acts as the "black box" of an organization—a kind of financial journal that captures every activity. It records who did what, when, and how within the financial system. This creates a straightforward way to verify the accuracy and accountability of financial records. Think of it as holding a backstage pass that lets you peek behind the curtain—offering complete visibility into every transaction for transparency, tracking access to sensitive data to bolster security, and capturing system changes to ensure compliance. With their growing importance, audit trails are now a legal must-have in India, following regulatory mandates that came into effect on April 1, 2023. The push for audit trail comes straight from the Companies (Accounts) Rules, 2014, where Rule 3(1) says any organization using accounting software—whether it's ERP systems or even web portals—must have a permanent audit trail that can't be turned off. It’s got to automatically track every change, stamp it with a timestamp, and keep those records on hand for audits. Meanwhile, auditors, under Rule 11(g) of the Companies (Audit and Auditors) Rules, 2014, must double-check that this feature was running all year, and wasn't tampered with. This rule isn't just for large organizations—it applies to every Indian organization. Whether it's nonprofits under Section 8 or foreign entities, it covers everything from standalone to consolidated financial statements.
  • 2-3 Min Read
Welcome to our Standard Setters' Updates of FASB & SEC. In this publication, we present a concise overview of the latest developments in financial reporting and highlight key considerations as we move through 2025. The Accounting Updates summarize FASB's new guidance issued in the first half of the current year and highlight the accounting standards that are effective in 2025. The FASB Current Projects section provides an overview and status of the items that FASB is actively working on. The Regulatory Updates section brings you noteworthy updates from the SEC. The Sustainability Reporting Developments section outlines the changes to ISSB’s Disclosure and European Union’s Reporting requirements. The Financial Accounting Standards Board (FASB), in November 2024, issued ASU 2024-03 which requires public business entities to disaggregate expenses in the income statement into specific categories and reconcile those to the totals reported in the financial statements. Subsequently, the Board realized a clarification was needed to avoid confusion regarding when the standard applies, particularly in interim periods. Therefore, the Board issued ASU 2025-01 clarifying the effective date to be the first annual reporting period beginning after December 15, 2026, and interim reporting periods within annual reporting periods beginning after December 15, 2027. In 2022, the Securities and Exchange Commission (SEC) published interpretive guidance as Staff Accounting Bulletin (SAB) No. 121 on Topic 5.FF, Accounting for Obligations to Safeguard Crypto-Assets an Entity Holds for its Platform Users. SAB No. 121 required entities safeguarding crypto-assets to record a liability and a corresponding asset at fair value. However, this guidance created practical challenges and accounting complexities. To address these concerns, the SEC later issued SAB No. 122, rescinding the interpretive guidance published as SAB No. 121. The amendment removes the obligation to recognize a safeguarding liability and corresponding asset, instead directing entities to apply traditional loss contingency guidance under ASC 450-20: Loss Contingencies when accounting for obligations to safeguard crypto-assets. Therefore, the Board issued ASU 2025-02 to inform about SAB No. 122 rescinding the interpretive guidance in SAB No. 121. Entities should apply the rescission of Topic 5.FF on a fully retrospective basis in annual periods beginning after December 15, 2024.
  • 8-9 Min Read
Point of View | 6-8 Min Read Organizations today are navigating a risk landscape that no longer sits still. Technological change, environmental pressure, and shifting societal expectations are blurring the traditional boundaries between risk categories, creating a complex, interconnected environment where a single disruption rarely stays contained to one part of the business. Developing the ability to identify, understand, and mitigate these risks has become essential for organizations aiming for resilient, sustainable growth, not just for risk teams but for leadership as a whole. This shift also creates an opening for internal audit functions specifically. Emerging risks give internal audit teams a genuine opportunity to demonstrate agility, sound judgment, and strategic insight, reinforcing their role as a driver of organizational resilience and long-term value creation, not just a compliance checkpoint. Two risk categories in particular deserve close attention heading into 2026: business continuity and human capital. Business Continuity Risk: From Contained Incidents to Domino Effects Business continuity risks are the probable disruptions that hinder an organization's ability to operate effectively and deliver essential services. These disruptions can originate from multiple sources at once, including natural disasters, technological failures, cybersecurity incidents, geopolitical conflicts, and supply chain breakdowns. The COVID-19 pandemic and the Suez Canal blockage remain two of the clearest recent examples of how severely these risks can disrupt global operations, and both illustrate a pattern that continues to define continuity risk today: these disruptions are highly interconnected and interdependent. A relatively minor disruption in one part of a supply chain or operating model can trigger a cascading effect that produces operational and financial consequences across an entire global organization. Strengthening operational resilience is no longer a defensive, back-office exercise. It is essential for maintaining stakeholder trust and sustaining long-term value delivery, particularly as investors, regulators, and customers increasingly expect organizations to demonstrate they can absorb shocks without losing continuity of service. Human Capital Risk: The Execution Gap Behind Every Strategy Human capital risk is the vulnerability organizations face in attracting, retaining, and developing their talent. Employees remain an organization's most valuable asset and one of its most vital pillars, which means failures in talent management do not stay contained to HR. They ripple directly into business continuity, innovation capacity, and competitive position. An organization can have a well-designed strategy for navigating cyber risk, geopolitical disruption, or digital transformation, but a strategy is only as strong as the people available to execute it. Talent gaps slow an organization's ability to respond to any other risk on this list, which is why human capital risk increasingly gets discussed alongside operational and continuity risk rather than treated as a separate HR concern. Why These Two Risks Are Increasingly Discussed Together Business continuity and human capital risk are not independent categories that happen to appear on the same risk register. They compound each other. A continuity event, whether a cyberattack, a supply chain disruption, or a geopolitical shock, tests an organization's talent bench directly: whether the right people with the right authority and training are in place to respond in real time. Conversely, an organization with unresolved talent gaps going into a disruption will find that disruption harder to contain and slower to recover from. This is exactly the kind of interconnection that internal audit functions are well positioned to surface. Rather than reviewing continuity plans and workforce risk as separate audit engagements, leading internal audit teams are increasingly examining how these risks interact and where a gap in one amplifies exposure in the other. What This Means for Internal Audit and Risk Leaders in 2026 Organizations preparing their 2026 risk agendas should treat business continuity and human capital risk as connected priorities, not parallel checklist items. Practically, this means: Testing continuity plans against realistic scenarios that also account for staffing and skills availability, not just system and process recovery Reviewing whether critical roles have documented succession and cross-training coverage, particularly in functions central to incident response Assessing where talent gaps could slow the organization's response to a continuity event, and prioritizing those gaps ahead of a crisis rather than after one Giving internal audit a mandate to examine risk interconnection directly, rather than auditing each risk category in isolation Frequently Asked Questions What is business continuity risk? Business continuity risk refers to probable disruptions that hinder an organization's ability to operate effectively and deliver essential services, arising from sources such as natural disasters, technology failures, cybersecurity incidents, geopolitical conflict, or supply chain disruption. What is human capital risk? Human capital risk is the vulnerability an organization faces in attracting, retaining, and developing the talent it needs, with direct consequences for business continuity, innovation capacity, and competitive position when not managed effectively. Why are business continuity and human capital risk often discussed together? These risks compound each other. A continuity disruption tests whether an organization has the right talent in place to respond, while unresolved talent gaps make any continuity event harder to contain and slower to recover from. What role does internal audit play in managing emerging risks like these? Internal audit is increasingly positioned to examine how risks like continuity and talent interconnect, rather than auditing each in isolation, giving organizations a clearer view of where one risk gap amplifies exposure elsewhere. What real-world events illustrate business continuity risk? The COVID-19 pandemic and the 2021 Suez Canal blockage are widely cited examples of how a single disruption can cascade into significant global operational and financial consequences. Who should be paying attention to these emerging risks? Chief risk officers, heads of internal audit, COOs, and board risk committees responsible for setting the organization's 2026 risk agenda and resilience priorities. Talk to Our Team Building a risk agenda that connects continuity planning with workforce readiness, rather than treating them separately? Pierag's Business Risk Advisory practice helps organizations design internal audit and risk management approaches built for how today's risks actually interact. Talk to our team about your 2026 risk agenda. Related reading: Emerging Risks and Trends: Navigating What's Next 2026 | Beyond Net Zero: Why Climate Adaptation Is the Next ESG Frontier | Audit Trail: Ensuring Financial Integrity and Accountability
  • 2-5 Min Read
Point of View | 6-8 Min Read Transparent financial reporting depends on more than accurate top-line numbers. Investors, lenders, and other capital providers rely on financial statements to evaluate a company's performance, assess its prospects for future cash flows, and benchmark it against peers, and a critical part of that evaluation is understanding what actually makes up a company's expenses. Expense composition reveals cost structure, operational efficiency, and long-term sustainability in ways that a single aggregated number cannot. Historically, U.S. GAAP did not require consistent disaggregation of income statement expenses, which left companies free to report at very different levels of detail. That inconsistency made it genuinely difficult for investors and analysts to compare financial results across entities and industries, since one company's "operating expenses" line might hide detail another company discloses openly. This is the gap DISE, the Disaggregation of Income Statement Expenses requirement, was built to close. How DISE Came to Be FASB first addressed this gap in July 2023, introducing a proposed Accounting Standards Update titled Income Statement, Reporting Comprehensive Income, Expense Disaggregation Disclosures (Subtopic 220-40): Disaggregation of Income Statement Expenses. After gathering extensive feedback through public comment periods and roundtable discussions with preparers, investors, and auditors, FASB finalized the amendments as ASU 2024-03 in November 2024. The goal is straightforward: enhance the decision-usefulness of financial reporting by requiring companies to disclose disaggregated expense detail within the footnotes of their financial statements, giving users of financial statements a clearer view of cost composition than aggregated income statement line items alone can provide. ASU 2025-01: Clarifying When DISE Actually Applies In January 2025, FASB issued ASU 2025-01, Income Statement, Reporting Comprehensive Income, Expense Disaggregation Disclosures (Subtopic 220-40): Clarifying the Effective Date. This update did not change the substance of the disaggregation requirement itself. It resolved confusion about exactly when the requirement takes effect, particularly around how it applies to interim reporting periods. The clarified effective dates are: Annual reporting periods: beginning after December 15, 2026 Interim reporting periods: within annual reporting periods beginning after December 15, 2027 Early adoption is permitted for companies that want to get ahead of the requirement rather than wait for the mandatory effective date. The updates apply to all public business entities, without exception, based on size or industry. What DISE Requires in Practice At its core, DISE requires public business entities to disaggregate expenses reported in the income statement into specific, defined categories and to reconcile those disaggregated figures back to the totals already reported in the financial statements. Rather than a single "cost of revenue" or "operating expenses" line, users of the financial statements will be able to see the underlying components that build up to those totals, disclosed within the footnotes. This is a meaningfully different level of transparency than most companies currently provide, which is why the practical implementation work matters more than the disclosure itself. What This Means for Finance and Reporting Teams Even with effective dates that sit a full reporting cycle or more away, the practical work behind DISE compliance is not something to defer until the deadline approaches. Building the general ledger structure, cost allocation methodology, and reconciliation process needed to disaggregate expenses credibly, and to reconcile those disaggregated figures back to totals already reported in the financial statements, is a multi-quarter undertaking for most organizations, not a footnote drafted at year-end close. Companies should treat the extended effective date as planning time, not slack in the schedule. Early adopters in particular may find that getting ahead of the requirement gives them a cleaner comparative baseline once the mandatory effective date arrives, rather than a first year of disclosure that reads as rushed against prior periods that used a different level of detail. Frequently Asked Questions What is DISE in accounting? DISE stands for Disaggregation of Income Statement Expenses, a FASB requirement under ASU 2024-03 that requires public business entities to break down income statement expenses into specific categories and reconcile them to the totals already reported in the financial statements. When does DISE take effect? Under ASU 2025-01's clarified effective dates, annual reporting periods beginning after December 15, 2026, must comply, with interim reporting periods within annual reporting periods beginning after December 15, 2027, also required to comply. Early adoption is permitted. What did ASU 2025-01 change compared to ASU 2024-03? ASU 2025-01 did not change the substance of the DISE requirement. It clarified the effective date, resolving confusion about how the requirement applied to interim reporting periods specifically. Why did FASB introduce the DISE requirement? Because U.S. GAAP historically did not require consistent disaggregation of income statement expenses, creating diversity in reporting practices that made it difficult for investors to compare cost structures and operational efficiency across companies and industries. Does DISE apply to all companies? It applies to all public business entities, regardless of size or industry, with no exceptions carved out in the standard. Who should be preparing for DISE now? CFOs, controllers, and financial reporting teams at public business entities, particularly those whose general ledger systems are not currently structured to produce reconciled expense detail at the category level, the standard requires. Talk to Our Team Preparing your general ledger and reporting processes for DISE compliance ahead of the 2026 and 2027 effective dates? Pierag's Accounting Advisory practice helps finance teams build the data structure and reconciliation processes this standard requires, well ahead of the deadline. Talk to our team about your reporting readiness. Related reading: Standard Setters' Updates, H2 2025 Edition | Audit Trail: Ensuring Financial Integrity and Accountability
  • 5 min Read
Point of View | 7-9 Min Read The Securities and Exchange Board of India has fundamentally changed how listed entities document and disclose related party transactions. Through the Industry Standards Forum, comprising ASSOCHAM, CII, and FICCI, in consultation with SEBI, the regulator introduced Industry Standards on "Minimum Information to be Provided for Review by the Audit Committee and Shareholders for Approval of Related Party Transactions." The framework applies to all listed entities in India and is designed to standardize reporting and disclosure requirements, elevating governance, transparency, and oversight of related party transactions across the board. For internal auditors, this is not a disclosure formality to note in passing. It reshapes what evidence must exist before a related party transaction can be approved, and internal audit functions are directly responsible for verifying that evidence is complete and accurate. From April 2025 to September 2025: How the Effective Date Actually Landed SEBI's RPT Industry Standards had a longer runway to implementation than originally announced. The standards were first set to apply to related party transactions entered into on or after April 1, 2025. Following stakeholder feedback requesting more preparation time, SEBI deferred the effective date, first to July 1, 2025, and then, through a revised circular issued June 26, 2025, to a final effective date of September 1, 2025. That September 1, 2025 date is when the standards actually took hold, and it is the date internal auditors and audit committees should treat as the operative compliance baseline. SEBI followed this in October 2025 with a further amendment. A circular dated October 13, 2025 introduced threshold-based relaxation in the minimum information listed entities must furnish, easing the compliance burden for transactions below specific value thresholds while keeping the core disclosure framework intact for larger and more material transactions. Identifying and Classifying Related Party Transactions The framework's starting requirement is accurate identification of all related parties as defined under Regulation 2(1)(zb) of SEBI's LODR Regulations, 2015. From there, transactions must be classified based on materiality into three categories: Material RPTs, which exceed the prescribed value or turnover thresholds Transactions involving promoters or promoter groups that exceed prescribed thresholds Residual RPTs that fall outside the above categories This classification is not a paperwork exercise. It determines the level of scrutiny, documentation, and approval a transaction requires, and misclassification at this stage undermines everything that follows in the approval process. What Internal Auditors Must Verify Internal auditors carry direct responsibility for confirming that adequate documentation exists for every related party transaction placed before the Audit Committee. The minimum information requirements include: Basic details of the related party The relationship and ownership structure connecting the related party to the listed entity The related party's financial performance Details of previous transactions with that related party The value of the proposed transaction Basic details of the proposed transaction itself For specific transaction types, additional documentation is required. This includes proposed transactions involving the sale, purchase, or supply of goods or services, or similar business transactions; loans, inter-corporate deposits, or advances given by the listed entity or its subsidiary; investments made by the listed entity or its subsidiary; and guarantees (excluding performance guarantees), sureties, indemnities, or comfort letters given by the listed entity or its subsidiary. The Internal Auditor's Practical Role Under the Framework Internal audit's role under these standards extends beyond a single compliance check. In practice, it involves: Pre-approval verification: confirming that the minimum information package for a proposed RPT is complete before it reaches the Audit Committee, not after Materiality classification review: independently testing whether transactions have been correctly classified as material, promoter-related, or residual, since misclassification changes the entire approval pathway Documentation completeness testing: sampling RPT files to confirm all required fields, financial performance data, prior transaction history, and transaction-specific disclosures are present and traceable Threshold monitoring: tracking cumulative related party transaction values across a financial year, since transactions that appear immaterial individually can cross materiality thresholds when aggregated Post-October 2025 threshold application: confirming that the relaxed minimum information requirements are being applied correctly only to transactions that genuinely qualify under the October 2025 threshold-based relaxation, rather than applied broadly by default Why This Matters Beyond Compliance Standardized RPT disclosure exists because related party transactions carry inherent conflict-of-interest risk, and inconsistent documentation historically made it difficult for Audit Committees and shareholders to evaluate whether a transaction genuinely served the listed entity's interests. Internal auditors who treat this framework as a genuine governance safeguard, rather than a box-ticking exercise, give Audit Committees the confidence to approve transactions on solid evidentiary ground and give shareholders a clearer basis for trusting that approval process. Frequently Asked Questions When did SEBI's RPT Industry Standards actually take effect? The standards were originally proposed for April 1, 2025, but were deferred twice and took final effect on September 1, 2025, following a revised circular issued June 26, 2025. What are the three categories of related party transactions under the framework? Transactions are classified as material RPTs exceeding prescribed thresholds, transactions involving promoters or promoter groups exceeding prescribed thresholds, or residual RPTs that fall outside both categories. What is the internal auditor's specific responsibility under the RPT standards? Internal auditors must verify that adequate documentation exists for each related party transaction, including related party details, relationship and ownership information, financial performance, prior transaction history, and transaction-specific disclosures, before the transaction reaches the Audit Committee. What changed in October 2025 regarding RPT disclosure requirements? SEBI issued a circular on October 13, 2025 introducing threshold-based relaxation, easing the minimum information requirements for related party transactions below specific value thresholds while keeping full disclosure requirements for larger and material transactions. Which regulation defines a related party under this framework? Related parties are identified under Regulation 2(1)(zb) of SEBI's LODR Regulations, 2015. Who does the RPT Industry Standards framework apply to? The framework applies to all listed entities in India that are required to comply with Regulation 23 of the LODR Regulations, covering approval of related party transactions by the Audit Committee and, where material, by shareholders. Talk to Our Team Strengthening internal audit procedures around related party transaction documentation and materiality classification? Pierag's Business Risk Advisory practice helps internal audit functions build verification processes that hold up to SEBI's current RPT Industry Standards. Talk to our team about your RPT compliance readiness. Related reading: Audit Trail: Ensuring Financial Integrity and Accountability | Standard Setters' Updates, H2 2025 Edition
  • 7-12 Min Read
Explore how audits empower healthcare providers to tackle AI risks, policy shifts, and pricing reforms with confidence.
  • 10-12 Min Read
Our Services
Our Expertise in Action
Tap into the power of our end-to-end capabilities.
Assurance
Assurance
In today’s complex business environment, robust assurance is not merely a regulatory requirement; it is a cornerstone of trust, transparency, and sustainable growth. Stakeholders, investors, and management rely on accurate and reliable financial information to make critical decisions.
Accounting Advisory
Accounting Advisory
Modern organizations operate in an environment where accounting standards and regulations are continually evolving, posing new challenges for finance leaders and teams.
Business Risk Advisory
Business Risk Advisory
In today’s complex regulatory and rapidly evolving business environment, organizations must move beyond reactive risk controls and adopt a proactive, integrated approach to governance, compliance, and operational risk.
Technology Risk Advisory
Technology Risk Advisory
Businesses today are increasingly being exposed to Technology Risks. Today’s interconnected digital risk landscape is an amalgamation of Cyberattacks, Data Privacy regulations, Cloud Adoption, and Artificial Intelligence (AI) driven disruptions.
ESG & Sustainability
ESG & Sustainability
We provide end-to-end ESG & Sustainability solutions designed to help organizations embed responsible business practices, enhance transparency, and meet global standards.
Deals Advisory
Deals Advisory
In today’s dynamic business landscape, transactions demand foresight, precision, and seamless integration. At Pierag, our deals advisory practice supports clients through complex financial events – strategic acquisitions, IPO readiness, and portfolio transformations – with a focus on clarity and control. Our services span comprehensive financial due diligence, transactions advisory, M&A support, and corporate restructuring — […]
Tax
Tax
Our Tax Solutions cover the full spectrum of direct and indirect tax returns and advisory. We assist businesses with accurate preparation, filing, and reconciliation of tax returns across jurisdictions, robust tax accounting and provisioning under global standards, and efficient management of withholding tax obligations.
Driven by our purpose of ‘Inspiring People to do things that Inspire them’ and guided by our values of 'Excellence, Equity, and Empathy', we empower businesses to navigate complexity, build resilience, and achieve sustainable growth.