Digital Compliance

Compliance and Risk Management in India: Why Your HRMS’s “Compliance Module” Isn’t Enough

Compliance and Risk Management in India: Why Your HRMS’s “Compliance Module” Isn’t Enough

Every HR platform sold in India today claims “compliance” as a feature. Payroll software calculates PF and ESI. HRMS suites add a “statutory compliance module” to the pricing page. And yet compliance managers at manufacturing companies, retail chains, and multi-state service businesses keep discovering the same thing during a labour inspection: the software they bought handles payroll deductions, but nobody actually maintains the Factories Act registers, the Shops & Establishment renewals, or the contractor compliance files the inspector is asking for.

The confusion is understandable – “compliance” is used as a catch-all word across a genuinely fragmented software market, and buyers rarely have time to reverse-engineer what a vendor’s “compliance module” line item actually includes before they’ve already signed a one-year HR platform contract. This is not a training gap. It is a category gap. “Compliance and risk management” for an Indian employer is not one thing – it is at least three distinct workstreams (payroll-statutory, factory/establishment registers, and contract-labour/vendor compliance), and most software on the market was built to solve only the first one.

This article exists to answer the question buyers actually have when they start evaluating tools: does an HRMS compliance module cover what I legally need, or do I need a specialist statutory compliance platform – and how do I tell the difference before an audit forces me to find out?

The regulatory backdrop: why this question matters more in 2026 than it did two years ago

India’s four Labour Codes – the Code on Wages 2019, the Industrial Relations Code 2020, the Code on Social Security 2020, and the Occupational Safety, Health and Working Conditions (OSH) Code 2020 – were notified as effective from 21 November 2025, consolidating 29 central labour statutes. The Ministry of Labour and Employment notified the Central Rules under all four Codes in May 2026. But labour is a Concurrent List subject, which means each state and union territory must separately frame and notify its own rules before the Codes are fully enforceable in that jurisdiction – and as of mid-2026, state-level notification remains a patchwork: some states have finalised their rules, many are still at the draft stage.

The practical consequence for a compliance manager is this: until a state notifies its own rules under the new Codes, the transitional position is that establishments continue to comply with the existing laws and registers – the Factories Act 1948, the state Shops & Establishment Act, the Contract Labour (Regulation & Abolition) Act 1970, the EPF & MP Act 1952, and the ESI Act 1948 – in parallel with early adjustments the Codes already require, such as the 50% wages rule under the Code on Wages (basic plus dearness allowance must equal at least 50% of total remuneration, which directly affects PF, gratuity, and bonus calculations).

That means any compliance tool bought in 2026 has to do two things at once: keep the legacy statutory registers current (because they are still the enforceable requirement in most states), and be ready to absorb the new Code-based obligations as each state notifies its rules. A payroll-only tool that only tracks EPF/ESIC challans was never built to track register-level obligations under the old Acts – which is exactly the gap this article walks through.

Regulatory position current as of August 2026. Central and state rules under the Labour Codes continue to be notified on a rolling basis – verify current status for your operating states at labour.gov.in and indiacode.nic.in before relying on any specific deadline in this article.

The four Labour Codes, in plain terms

Because the Codes are frequently referenced without being explained, here is what each one actually consolidates and why it matters to a compliance tool’s scope:

  • Code on Wages, 2019 – consolidates the Payment of Wages Act, Minimum Wages Act, Payment of Bonus Act, and the Equal Remuneration Act. Its most operationally significant change is the “50% rule”: basic pay plus dearness allowance must equal at least 50% of total remuneration, which directly changes how PF, gratuity, and bonus are calculated on a restructured salary – a payroll engine has to get this right, or every downstream statutory calculation is wrong.
  • Industrial Relations Code, 2020 – consolidates the Trade Unions Act, Industrial Employment (Standing Orders) Act, and Industrial Disputes Act. Introduces changes to fixed-term employment (parity of benefits with permanent employees, including pro-rata gratuity after one year) and revises standing order and layoff/retrenchment thresholds.
  • Code on Social Security, 2020 – consolidates the EPF Act, ESI Act, Maternity Benefit Act, Payment of Gratuity Act, and several others, and for the first time extends social security coverage frameworks toward gig and platform workers.
  • Occupational Safety, Health and Working Conditions (OSH) Code, 2020 – consolidates the Factories Act, the Contract Labour (R&A) Act, the Inter-State Migrant Workmen Act, and related safety legislation. This is the Code that will eventually absorb the Factories Act registers and CLRA obligations discussed throughout this article – once state rules are notified and the transition is complete.

Until a given state notifies its OSH Code rules, the practical reality is that the underlying Factories Act and CLRA registers described in this article remain the enforceable requirement – which is exactly why a compliance tool bought today has to handle the current register-level obligations, not just the eventual Code-based framework.

Common myths this article is written to correct

  • “Our HRMS handles compliance, so we’re covered.” It handles payroll-statutory compliance – EPF, ESIC, PT, LWF. It does not maintain Factories Act registers, S&E renewals, or CLRA contractor documentation.
  • “We don’t have a factory, so the Factories Act doesn’t apply to us.” Correct, in most cases – but the Shops & Establishment Act almost certainly does, and it carries its own state-specific registers and renewal obligations that are just as easy to miss.
  • “Our contractor is responsible for their own workers’ compliance, not us.” Under CLRA, the principal employer carries statutory obligations regardless of what the contractor agreement says internally – this is a common and costly misunderstanding.
  • “The Labour Codes replaced all the old laws, so the old registers don’t matter anymore.” The Codes are in effect, but until state rules are notified for each Code, the transitional position generally keeps the existing Acts and registers operative – treating them as obsolete before your state has actually transitioned is a real compliance gap, not a shortcut.
  • “A compliance score from any GRC dashboard tells us where we stand.” Only if the score is built from actual register and filing status – a score built from self-reported task completion tells you what your team said they did, not what a labour inspector would find.
  • “We’re too small for any of this to apply to us.” Thresholds vary by Act – EPF applies from 20 employees, ESIC typically from 10, and S&E registration is often required from the very first employee or the first commercial premises. “Small” is rarely a reason to be exempt; it’s usually a reason nobody has checked which thresholds have already been crossed.

What an “HRMS compliance module” actually does – and where it stops

When a founder or CHRO buys an HRMS (Keka, greytHR, Zoho People, Darwinbox, HROne, Zimyo, and similar platforms all fall in this category), the “statutory compliance” feature almost always means the payroll-statutory layer:

  • EPF calculation and Electronic Challan-cum-Return (ECR) generation, due by the 15th of the following month under the EPF & MP Act 1952
  • ESIC contribution calculation and challan generation, also due by the 15th of the following month, for establishments with 10+ employees (in most states) drawing wages up to the ESIC wage ceiling
  • Professional Tax (PT) deduction against state-wise slabs
  • Labour Welfare Fund (LWF) deduction where applicable, at the state-notified rate and periodicity
  • Form 16/24Q-style payroll tax outputs and payslip generation

This is genuinely useful – it automates a real, recurring compliance obligation. The problem is what it implies to a buyer who isn’t already a compliance specialist: the module is labelled “statutory compliance,” so a founder reasonably assumes it means all statutory compliance. It doesn’t. An HRMS compliance module, by design, only ever sees the payroll transaction. It has no register for the Factories Act, no contractor license tracker for CLRA, no Shops & Establishment renewal calendar, and no workflow for a labour inspector’s notice. It was never architected to hold that data, because payroll software’s core object is “employee + salary,” not “establishment + register + inspector.”

This is precisely the confusion visible across the market’s own content. Round-ups like 10 HR Compliance Tools for Businesses in India mix outsourced HR compliance services with payroll software in the same “top 10” list – which is itself evidence that even content written for this exact audience doesn’t clearly separate the three different things a buyer might need: a payroll-statutory feature, an outsourced compliance service, and a full statutory-register platform.

What a specialist statutory compliance platform actually covers

A specialist platform – the category Iztty, Ricago, TeamLease RegTech, and Digiliance compete in – is built around the establishment and the register, not the payroll transaction. Concretely, that means:

1. Factory compliance under the Factories Act 1948

Factory registration and licence renewal with tiered expiry alerts, and the statutory registers a factory inspector will ask for on any visit – including Form 25 (register related to overtime), Form 5 (register of adult workers), and Form 17 (register of leave with wages) – along with half-yearly and annual returns to the Chief Inspector of Factories.

2. Shops & Establishment (S&E) Act compliance

Every state administers its own S&E Act, with its own register formats, its own renewal cycles, and its own thresholds for what triggers registration. A retail chain or office-based business operating in five states is not managing one compliance calendar – it is managing five, each with different forms and different renewal windows. This is the single most common blind spot for growing retail and services companies who assume “we’re not a factory, so we’re not covered” – S&E registration is usually mandatory from the first commercial premises.

3. CLRA – contract labour and vendor compliance

Under the Contract Labour (Regulation & Abolition) Act 1970, a principal employer using contract labour through a licensed contractor carries statutory obligations – registration of the establishment, contractor licensing checks, and returns including the half-yearly Form XXIV filed by the contractor (due within 30 days of the close of each half-year, i.e. broadly the end of January and end of July) and the principal employer’s annual return. This is covered in more depth further below, because it is the area where “we thought our vendor handled it” causes the most real legal exposure.

4. Payroll-statutory compliance (EPF/ESIC/PT/LWF)

Yes – a specialist platform still needs to do the same ECR/challan work an HRMS does. The difference is that it does this alongside the register-level work above, in the same system, with the same audit trail, rather than as an isolated payroll feature disconnected from the rest of the establishment’s compliance picture.

5. Digitally-verifiable governance: Maker-Checker-DSC

Every register above eventually needs to be signed – by an authorised signatory, often with a Digital Signature Certificate (DSC) – and needs to be defensible later as evidence that the process was followed, not just that a form exists. This is a workflow requirement, not a data-entry requirement, and it’s the layer most HRMS platforms and most horizontal GRC tools don’t build natively.

HRMS compliance module vs specialist statutory compliance platform vs enterprise GRC: a straight comparison

CapabilityHRMS “compliance module” (Keka, greytHR, Zoho People-type)Specialist statutory compliance platform (Iztty-type)Enterprise GRC platform (Ricago, TeamLease RegTech-type)
EPF/ESIC/PT/LWF challansYes – this is the core featureYesUsually tracked, not always processed end-to-end
Factories Act registers (Form 25, Form 5, Form 17)NoYesOften tracked as a task, not as a native register
State-specific Shops & Establishment registersNoYesYes, typically
CLRA contractor licence and return managementNoYesYes, typically
Vendor/contractor compliance audit + auto-scoringNoYesVaries by vendor
Maker-Checker-DSC digital signing on registersRareYesRare – most rely on manual signing outside the platform
AI-assisted notice/inspection response draftingNoYesVaries by vendor
Breadth (number of Acts tracked)Narrow – payroll-adjacent Acts onlyFocused – labour, factory, S&E, CLRA, payrollVery broad – 1,000+ Acts across sectors, including non-labour regulatory obligations
Buying motionBundled into an HR/payroll suite purchaseStandalone, compliance-team-led purchaseStandalone, often legal/company-secretarial-led enterprise purchase
Best fitSmall office-only businesses with no factory, no contract labour, single stateManufacturers, multi-location retail, staffing firms, anyone with factories, contract labour, or multi-state establishmentsLarge enterprises needing compliance coverage well beyond labour law (environmental, sector-specific, corporate)

None of this makes the HRMS “wrong” – for a 40-person, single-office SaaS company with no factory and no contract labour, the payroll-statutory layer genuinely might be sufficient. The failure mode is buying an HRMS because its compliance module implies full coverage, then discovering the gap only when a factory inspector, a contract-labour audit, or a state S&E renewal notice arrives.

The blind spot in detail: what actually gets missed

To make this concrete rather than abstract, here is what a compliance manager at a multi-state manufacturer or retailer is actually responsible for, beyond payroll, in a given year:

ObligationGoverning ActTypical frequencyWho usually owns it in an HRMS-only setup
Register of adult workers (Form 5)Factories Act 1948Maintained continuously, produced on inspectionOften a spreadsheet, or nobody
Overtime register (Form 25)Factories Act 1948ContinuousOften a spreadsheet
Leave with wages register (Form 17)Factories Act 1948Continuous, annual returnOften manual, reconciled only before inspection
Factory licence renewalFactories Act 1948Annual, state-specificManually tracked in a calendar reminder, frequently missed across multiple factories
S&E registration/licence renewalState S&E ActAnnual or multi-year, state-specificOften owned by whichever branch manager remembers
Contractor licence validity checkCLRA 1970Continuous, before onboarding and periodically thereafterRarely checked systematically
Contractor half-yearly return (Form XXIV)CLRA 1970Within 30 days of close of half-year (Jun/Dec)Assumed to be the contractor’s problem – it is also the principal employer’s exposure
Principal employer annual returnCLRA 1970Annual, by mid-FebruaryFrequently missed entirely
EPF ECR/challanEPF & MP Act 1952Monthly, by the 15thHandled well – this is the HRMS’s strength
ESIC contribution + half-yearly returnESI Act 1948Monthly payment, half-yearly returnPayment handled well; return filing sometimes missed

The pattern is consistent: anything that resembles a payroll transaction is handled well by an HRMS. Anything that is a physical register, a licence, or a contractor relationship is not – because it was never designed into the product.

Contract labour and vendor compliance: where the real legal exposure sits

This is the risk area most founders and even many HR leaders underestimate. Under CLRA, the principal employer – the company that engages a contractor to supply labour, whether for housekeeping, security, packaging, or line staff – carries statutory obligations that do not disappear because a contractor is “responsible” for their own workforce. If a contractor fails to pay EPF, ESIC, or minimum wages to contract workers, the principal employer can carry liability, and in some circumstances can be required to pay wages directly and recover from the contractor.

Managing this well requires:

  • Verifying contractor licence validity before onboarding and at renewal
  • Collecting and auditing the contractor’s own EPF/ESIC/wage registers on a recurring basis, not just at contract signing
  • Auto-calculating a vendor compliance score so a security or housekeeping vendor with a lapsing licence or missed contribution is flagged before it becomes the principal employer’s problem
  • Maintaining the documentation trail that demonstrates the principal employer exercised due diligence – this is the evidence that matters if a labour officer or court later examines liability

No HRMS compliance module is built to manage a third-party vendor’s compliance posture – it has no data model for “vendor” at all. This is a genuinely different problem from payroll, which is why vendor compliance auditing is one of the clearest lines separating a specialist statutory compliance platform from an HRMS add-on.

Why Maker-Checker-DSC matters more than it sounds

A register that exists in a spreadsheet or a basic HRMS export is not, by itself, defensible evidence during an inspection or a dispute. What makes a compliance record defensible is a demonstrable process: someone uploaded and validated the data, someone else independently reviewed and approved (or rejected, with a documented reason), and the final version was digitally signed with a Digital Signature Certificate before being archived.

This four-stage workflow – upload/validate, review/approve-or-reject, DSC signing, auto-archive – is the practical difference between “we have a register” and “we have a register we can defend.” It is a workflow-engineering problem, not a data-storage problem, which is exactly why it tends to be missing from both HRMS compliance modules (built around payroll transactions, not document governance) and many horizontal GRC platforms (built around task/deadline tracking, not statutory document execution).

AI-assisted notice response: the real time cost of doing this manually

When a PF, ESIC, Labour, S&E, or Factories Act notice arrives, the manual process is: someone reads the notice, manually cross-references the allegation against internal records, drafts a formal reply, gathers supporting evidence, and routes it for sign-off – a process that commonly takes several working days when records are scattered across payroll exports, physical registers, and email threads. An AI-assisted approach that can read the notice, extract the allegation and deadline, and draft a structured reply with an evidence checklist compresses that into hours rather than days – the gap that matters most when a notice carries a short statutory response window.

Compliance score: a practical way to see risk before an inspector does

A single number – a live compliance score, broken down act-wise and state-wise, with a low/medium/high risk banding – gives a CFO or CEO a way to ask “where are we exposed?” without reading twenty registers. This is the kind of output a horizontal GRC dashboard can produce at a high level, but it is far more useful when it’s built on the actual underlying registers (Factories Act, S&E, CLRA, payroll-statutory) rather than on self-reported task completion, which is how many enterprise GRC tools currently calculate it.

What non-compliance actually costs: the numbers behind the risk

“Compliance and risk management” is often discussed in abstract terms – audit readiness, reputational risk, governance maturity. For an Indian employer, the risk is also concrete and quantified in the statute itself:

ActProvisionExposure
Factories Act 1948Section 92 (general penalty)Imprisonment up to 2 years, or fine up to ₹1 lakh, or both – for the occupier and the manager individually. A continuing contravention after conviction adds a further fine of up to ₹1,000 for each additional day.
Factories Act 1948Section 92 proviso (safety-related contraventions causing death or injury)Minimum fine of ₹25,000 for a fatality, ₹5,000 for serious bodily injury, in addition to imprisonment.
Factories Act 1948Section 94 (repeat offence)Imprisonment up to 3 years or a fine of not less than ₹10,000 (up to ₹2 lakh), or both.
EPF & MP Act 1952Section 14BDamages on delayed contribution ranging from 5% p.a. (delay up to 2 months) to 25% p.a. (delay over 6 months).
EPF & MP Act 1952Section 7QInterest at 12% p.a. on the unpaid amount, in addition to Section 14B damages.
Contract Labour (R&A) Act 1970General offence provisionsFines and imprisonment apply to both the contractor and, in specific circumstances, the principal employer – alongside the separate civil exposure of being required to pay contract workers’ wages directly if the contractor defaults.

These figures are drawn directly from the bare Act text and are subject to state amendments and the ongoing Labour Codes transition – verify current figures for your state at indiacode.nic.in before using them in any internal risk assessment. The point isn’t the exact rupee figure; it’s that every one of these penalties attaches to a register or a filing an HRMS compliance module was never built to hold – the Factories Act registers, the CLRA return, the timely EPF challan. A tool gap becomes a personal liability gap for the occupier, manager, or principal employer named in the section.

A sector-by-sector view of where the gap actually bites

“Statutory compliance” isn’t experienced the same way in every industry. Here’s how the HRMS-vs-specialist-platform gap plays out by vertical:

Manufacturing & Factories

The most exposed vertical by definition – every registered factory carries Factories Act obligations (Form 25, Form 5, Form 17, licence renewal) that no payroll tool touches. Add contract labour for line staff or housekeeping, and CLRA principal-employer exposure stacks on top. Multi-factory manufacturers additionally face the multi-state register problem described above.

Retail & Shops

Rarely has Factories Act exposure, but almost always has Shops & Establishment Act exposure from the first outlet, multiplied by every state a chain expands into. Retailers frequently underestimate S&E as “just registration” when it also carries ongoing register and renewal obligations per location.

Staffing & Contractors

This vertical is the CLRA relationship – as either the licensed contractor supplying labour or the principal employer engaging it. Vendor compliance auditing and contractor licence tracking aren’t a nice-to-have here; they’re the core of the business’s own legal exposure.

Construction & Infrastructure

Typically layers CLRA (contract and migrant labour), Factories Act-adjacent building and safety obligations, and high workforce turnover that makes manual register-keeping especially error-prone – a strong candidate for automated, DSC-signed record-keeping precisely because the paper trail is what protects the principal contractor in a dispute or accident inquiry.

IT & Technology Services

Often the segment where an HRMS compliance module genuinely is closer to sufficient – office-only, no factory, limited contract labour – but multi-state expansion (opening a second or third city office) still triggers separate S&E registrations that are easy to miss when the compliance owner is a generalist HR function rather than a dedicated compliance manager.

Healthcare & Pharma

Frequently combines S&E obligations for clinics/hospitals with factory-level obligations for manufacturing units (pharma plants), plus significant contract labour for support staff – a combination that makes single-category tools (payroll-only or factory-only) inadequate on their own.

Mining & Logistics/Warehousing

Both carry factory-adjacent safety and register obligations, high reliance on contract labour, and multi-site operations spread across states – the same combination of factors that makes a consolidated, multi-branch platform materially more useful than a spreadsheet-plus-HRMS approach.

A quick glossary, for anyone brought into this conversation mid-way

  • ECR (Electronic Challan-cum-Return): The monthly online return and payment mechanism for EPF contributions, filed via the EPFO Unified Portal, due by the 15th of the following month.
  • DSC (Digital Signature Certificate): A legally recognised digital signature used to sign statutory filings and registers electronically, making the record verifiable and tamper-evident.
  • LWF (Labour Welfare Fund): A state-administered welfare fund that employers and employees contribute to, applicable in roughly 16 Indian states, each with its own rate and contribution periodicity (monthly, half-yearly, or annual depending on the state).
  • S&E (Shops & Establishment Act): State-specific legislation governing working conditions, registers, and licensing for shops, commercial establishments, and offices – distinct from the central Factories Act.
  • CLRA (Contract Labour, Regulation & Abolition Act 1970): Central legislation governing the engagement of contract labour through licensed contractors, and the corresponding obligations of the principal employer.
  • PT (Professional Tax): A state-levied tax on employment/professions, deducted from salary against state-specific slabs, distinct from income tax.
  • Principal employer: Under CLRA, the entity that engages a contractor to supply workers – carries statutory obligations even though the contractor is the direct employer of the contract workforce.
  • Maker-Checker: A two-stage internal control where one person prepares/enters a record and a second, different person independently reviews and approves it before it becomes final – a standard governance control, applied here to statutory registers and filings.

A 30-minute internal gap-check you can run before your next inspection

Before evaluating any software, it’s worth spending half an hour establishing your actual exposure. Walk through this with whoever currently owns “compliance” in your organisation – often an HR generalist, not a dedicated compliance manager:

  1. List every physical location: factories, offices, retail outlets, warehouses. For each, confirm which state’s S&E Act or Factories Act registration applies, and pull the current licence/registration expiry date.
  2. List every contractor or staffing vendor currently supplying labour to any location. For each, confirm licence validity under CLRA and the date you last collected their EPF/ESIC/wage registers.
  3. For every factory location, confirm someone can physically produce Form 25, Form 5, and Form 17 (or your state’s equivalent) within one hour, and confirm who signed the most recent version and how.
  4. Confirm your EPF ECR and ESIC contribution filing history for the last 6 months has no missed 15th-of-the-month deadlines, and that half-yearly ESI and CLRA returns were filed on time.
  5. Ask directly: “If a labour inspector or EPFO/ESIC notice arrived today, who owns the response, and how long would it take them?” If the honest answer involves searching email threads and spreadsheets, that’s your real turnaround time – not the number you’d like it to be.

Most organisations that run this exercise discover their real gap is not in payroll – payroll is usually fine – but in exactly the register, licence, and vendor areas an HRMS was never built to cover.

Multi-state, multi-branch complexity: why point solutions break down

India does not have one labour compliance regime – it has one central framework layered with state-specific rules, forms, and renewal cycles that vary from Maharashtra to Tamil Nadu to Uttar Pradesh. A company with factories in three states and retail outlets in five more is not running one compliance calendar; it is running eight, each with its own S&E renewal date, its own LWF contribution schedule (LWF is applicable in roughly 16 states with different rates and periodicities), and its own state amendments layered on top of the Factories Act and CLRA central rules.

A tool that isn’t architected for role-based, multi-branch access – with Maker, Checker, and DSC-holder roles distinct from each other, and dashboards that consolidate up to an executive view while still letting a plant HR head see only their factory’s registers – either breaks down at scale or forces the compliance team back into spreadsheets to reconcile across locations. This is the practical reason “multi-state compliance management” is treated as a distinct buying criterion rather than a marketing phrase.

Why “we’ll just track it in a spreadsheet” stops working past a certain size

Almost every organisation that eventually buys a specialist compliance platform started with a spreadsheet – a compliance calendar maintained by one person, cross-referenced against a folder of scanned licences and registers. This works, until it doesn’t, and the failure point is predictable: it breaks the moment the person who built the spreadsheet goes on leave, changes roles, or leaves the company, and the tribal knowledge of “which state’s S&E renewal is due when, and where the last signed register is filed” leaves with them.

It also breaks at scale in a specific, measurable way: a single-state, single-factory company can genuinely track five or six recurring obligations manually. A five-state, three-factory company with two staffing vendors is tracking closer to sixty distinct obligations across different frequencies, different forms, and different signing authorities – at which point a spreadsheet’s real failure mode isn’t that it’s inconvenient, it’s that nobody can prove, after the fact, that a specific register was reviewed by a specific person on a specific date. That provability is exactly what a labour inspector, an EPFO officer, or opposing counsel in a dispute will ask for – and “it’s in the spreadsheet” is not, on its own, an answer.

Decision framework: how to tell if your HRMS’s compliance module is actually enough

Run through this before renewing or buying an HRMS on the strength of its “compliance module” line item:

  • Do you operate any factory, warehouse, or manufacturing unit registered under the Factories Act? If yes, you need Factories Act register management – an HRMS module does not provide this.
  • Do you operate in more than one state? If yes, you need a system that tracks state-specific S&E renewal cycles and forms individually, not a single generic “compliance” checklist.
  • Do you engage contract labour through a contractor or staffing vendor for any function – security, housekeeping, packaging, warehouse staff? If yes, you carry CLRA principal-employer obligations that require contractor licence tracking and vendor compliance audits.
  • Do you need a digitally signed, audit-defensible register – not just a stored PDF – for any of the above? If yes, you need a Maker-Checker-DSC workflow, which most HRMS platforms do not offer natively.
  • If a labour inspector visited tomorrow, could you produce Form 25, Form 5, Form 17, your current factory licence, your S&E registration, and your contractor’s Form XXIV within the hour? If the honest answer is no, the gap is real, not theoretical.

If you answered “yes” to any of the first three questions, an HRMS compliance module alone is very likely insufficient, regardless of how the vendor markets it – and the real evaluation should be between a specialist statutory compliance platform (if your primary exposure is labour, factory, S&E, and contract-labour compliance) and an enterprise GRC platform (if you also need coverage across non-labour regulatory domains at enterprise scale).

Where a specialist platform like Iztty fits against both camps

Against the HRMS-with-compliance-bolt-on camp (Keka, greytHR, Zimyo, and similarly reviewed platforms), the gap is breadth: those tools were not built to hold Factories Act registers, S&E state formats, or CLRA contractor data, because their core object is payroll, not the establishment register.

Against the enterprise GRC camp (Ricago, TeamLease RegTech, Digiliance), the differentiation is depth and workflow, not breadth: a specialist platform focused specifically on labour, factory, S&E, payroll, and CLRA compliance can build native Maker-Checker-DSC signing and AI-assisted notice response into the workflow itself, rather than tracking these as generic tasks inside a broader 1,000-plus-Act compliance dashboard. Iztty is built by Futurex Management Solutions, a compliance consulting firm with over a decade of hands-on labour, factory, and CLRA advisory experience – which shapes the platform around how a compliance manager actually works a register, not around a generic risk-management framework applied to labour law after the fact.

In practice, this shows up as a live Compliance Score Meter, an AI Notice Response Assistant that has cut EPF/ESIC notice turnaround from days to hours in representative deployments, digitally signed registers across Labour Welfare Fund, Provident Fund, and Professional Tax filings, and dedicated vendor compliance and CLRA compliance modules that treat contract labour as its own workstream rather than an afterthought. A live compliance calendar keeps every state-specific deadline – Factories Act, S&E, CLRA, and payroll-statutory – in one consolidated view across branches.

Twelve capabilities, mapped to the twelve things a compliance manager actually does

Rather than listing product features in isolation, here is how each capability of a specialist platform like Iztty maps to a real, recurring job a compliance manager, plant HR head, or compliance consultant does across the year:

Job to be donePlatform capability
Track LWF registration and contribution across every LWF-applicable state my company operates inLabour Compliance Management – state-specific LWF rate automation, DSC-signed registers across all applicable states
Keep every factory’s licence and registers current without visiting each siteFactory Compliance Management – Factories Act 1948 registration, tiered licence expiry alerts, Form 25/5/17 registers, returns
Manage S&E registration for every retail outlet or office I openShop & Establishment Compliance – state-specific register formats, licence renewals, 360° multi-location tracking
File EPF/ESIC/PT/LWF correctly and on time every month, without manual challan creationPayroll Compliance Management – Maker-Checker-DSC filing, integrated with Tally, Zoho Payroll, Keka HR
Know which of my vendors is a compliance risk before an inspector finds out for meVendor Compliance Audit – digital contractor audits, auto-calculated compliance scores, principal-employer liability documentation
File CLRA returns on time and prove principal-employer due diligenceCLRA & Ease of Compliance – Forms XII/XIII/XIV/XIX, DSC-signed half-yearly returns
Prove any register was reviewed and approved, not just uploadedMaker-Checker-DSC Workflow Engine – 4-stage review and sign-off with mandatory remarks on rejection
Respond to a labour or EPFO/ESIC notice within its statutory windowAI Notice Response Assistant – OCR notice reading, allegation/deadline extraction, drafted reply with evidence checklist
Know when a gazette notification or state amendment actually applies to my companyRegulatory Change Intelligence – monitors gazette notifications, EPFO/ESIC circulars, and state amendments, and generates matched action tasks for human review
Answer “where are we exposed?” for the board or a CFO in one numberCompliance Score Meter – live 0–100% score, act-wise and state-wise breakdown, risk banding
See every branch’s status in one consolidated view without chasing local HR teamsDashboards & Reporting – multi-branch, multi-state consolidated view, executive dashboards
Let a plant HR head see only their factory while I see everything, without a spreadsheet-sharing workaroundRole-Based Access & Multi-Branch Architecture – Maker/Checker/DSC-holder roles, department-wise access across 28+ states

If you’re a compliance consultant managing multiple client companies

Everything above assumes a single company evaluating its own exposure. If you run a compliance consultancy or a statutory-compliance-as-a-service firm managing filings for multiple client companies, the calculus is different again: you’re not choosing between an HRMS module and a specialist platform for one establishment – you’re choosing infrastructure that has to scale across dozens of client mandates without every client requiring a separate spreadsheet system or a separate login you manage manually.

The requirements that matter most for this persona are role-based multi-tenant access (so each client’s data stays segregated while your team works across all of them), a consolidated dashboard that lets you triage which client’s compliance score just dropped without logging into each account individually, and – critically – the same AI Notice Response capability, because a consultancy managing 40 clients absorbs the multi-day manual notice-response cost 40 times over unless it’s automated. This is precisely the scenario reflected in Iztty’s own representative outcome data: a 40-client compliance consultancy cutting EPF/ESIC notice response from 5 days to 4 hours per notice compounds into a materially different service-delivery capacity across an entire client book, not just one company’s risk posture.

Questions worth asking any vendor before you sign – HRMS, specialist platform, or enterprise GRC

Regardless of which category you land in, these questions separate a platform that will hold up under an actual inspection from one that looks complete in a sales demo:

  • “Show me the Factories Act Form 25 register as it would look for my factory, populated with sample data – not a mockup.” Many platforms describe register coverage in marketing copy without a working, state-correct register format behind it.
  • “Who signs the final register, and how is that signature legally defensible?” A PDF export is not the same as a DSC-signed, Maker-Checker-reviewed record.
  • “If I add a fourth state next quarter, what changes on my end?” This tells you whether the platform’s state coverage is genuinely built-in or requires a custom build/consulting engagement each time you expand.
  • “What happens to my vendor’s compliance score if their EPF payment is late by three days – do I find out, and when?” This distinguishes real-time vendor monitoring from a static, point-in-time audit.
  • “Can I see an actual AI-drafted notice response, not a description of the feature?” Ask for the underlying draft quality, not just the time-savings claim.
  • “What’s included versus billed separately – is CLRA vendor auditing part of the core platform, or an add-on module?” This affects total cost of ownership more than the headline price.

What this means if you’re evaluating right now

If your organisation is office-only, single-state, with no contract labour and no factory registration, your HRMS’s compliance module may genuinely be sufficient – don’t buy a specialist platform you don’t need. If you operate any factory, any multi-state footprint, or engage any contract labour, treat “statutory compliance” as a distinct buying decision from your HRMS, evaluated on register coverage, contractor/vendor auditing, and signing workflow – not on whether the word “compliance” appears in the feature list.

The fastest way to find out where you actually stand is a compliance audit against your specific state and Act exposure, not a generic checklist. Book a free compliance audit or a platform demo to see your current register coverage mapped against what the Factories Act, your state S&E Act, CLRA, and the ongoing Labour Codes transition actually require.


Frequently Asked Questions

1. What is the difference between HRMS and compliance software?

An HRMS is built around payroll and employee records, and its “compliance” feature typically covers EPF, ESIC, Professional Tax, and Labour Welfare Fund calculations and challans. Statutory compliance software is built around the establishment and its legal registers – Factories Act registers, Shops & Establishment renewals, and CLRA contractor/vendor compliance – which an HRMS does not natively track.

2. Do labour codes 2026 change what compliance software needs to handle?

Yes, progressively. The four Labour Codes came into effect on 21 November 2025 and central rules were notified in May 2026, but state-level rules are still being notified on a rolling basis. Until a given state notifies its rules, the transitional position generally requires continued compliance with the existing Acts (Factories Act, S&E Act, CLRA, EPF Act, ESI Act) alongside early Code-based changes such as the 50% wages rule. Compliance software needs to track both the legacy register requirements and the incoming Code-based obligations as each state notifies.

3. How much does a compliance management system cost in India?

Pricing varies widely by vendor and is typically structured by number of establishments/branches, number of employees, and module scope (payroll-statutory only vs full register + vendor compliance coverage). Because pricing changes frequently and isn’t uniformly published, request a quote scoped to your actual state and Act exposure rather than relying on a generic published rate.

4. What is a Factories Act register, and which ones matter most?

Factories Act 1948 registers are physical or digital records a registered factory must maintain and produce on inspection – commonly including the register of adult workers (Form 5), the overtime register (Form 25), and the leave-with-wages register (Form 17), alongside half-yearly and annual returns. Exact form numbering and requirements can vary by state amendment, so verify current formats for your specific state.

5. Is Shops & Establishment Act registration required if I’m not a factory?

Yes, in almost all cases. The S&E Act applies to commercial establishments – offices, shops, and retail outlets – not just factories, and registration is typically required from the point a business opens its first commercial premises in a state. It is state-specific legislation, so requirements, forms, and renewal cycles differ from state to state.

6. Who is liable if a contractor doesn’t pay EPF or ESIC to contract workers?

Under CLRA, the principal employer engaging the contractor can carry liability alongside the contractor if the contractor fails to meet statutory obligations to contract labour, including in some circumstances an obligation to pay wages directly and recover the amount from the contractor. This is why vendor/contractor compliance auditing is a core requirement, not an optional add-on, for any company using contract labour.

7. What is a compliance score, and how is it calculated?

A compliance score is a consolidated metric – typically 0–100% – that reflects how current an organisation’s statutory obligations are across the Acts and states it operates in, usually broken down act-wise and state-wise with a risk banding (low/medium/high). It’s most useful when it’s derived from actual register and filing status rather than self-reported checklist completion.

8. What does “Maker-Checker-DSC” mean in compliance software?

It’s a governance workflow: one person (Maker) uploads and validates a register or filing, a second person (Checker) independently reviews and approves or rejects it with a documented reason, and the approved version is signed using a Digital Signature Certificate before being archived. This creates a defensible audit trail, which matters if a filing is later questioned by a regulator or in a dispute.

9. Can I use my HRMS for payroll and a separate platform for statutory registers?

Yes, and for many multi-state or multi-factory businesses this is the practical setup – the HRMS remains the system of record for employees and salary, while a specialist statutory compliance platform (often integrating with the HRMS via API or file import) handles Factories Act, S&E, and CLRA registers, contractor auditing, and DSC-based filing sign-off.

10. How long does it take to respond to a labour department or EPFO/ESIC notice?

Manually, gathering records across payroll exports, physical registers, and email correspondence to draft a formal reply commonly takes several working days. With AI-assisted notice reading that extracts the allegation and deadline and drafts a structured reply with an evidence checklist against existing digital registers, that turnaround can be reduced to a matter of hours – which matters because statutory response windows are often short.

11. What is the “50% wages rule” under the Code on Wages, and why does it matter for compliance software?

The Code on Wages, 2019 requires that basic pay plus dearness allowance make up at least 50% of an employee’s total remuneration. This changes the base on which PF, gratuity, and bonus are calculated for many salary structures that previously kept basic pay lower. Any payroll-statutory tool – whether inside an HRMS or a specialist platform – needs to apply this correctly, since an incorrect base cascades into incorrect EPF and gratuity calculations.

12. Should a compliance consultancy managing multiple client companies use the same tool as a single company?

Not necessarily the same setup – a consultancy needs multi-tenant, role-based access that segregates each client’s data while letting the consultancy’s team work across all mandates from one dashboard, plus the same AI-assisted notice response capability scaled across every client rather than one company. Platforms that offer a dedicated compliance-consultant account type are built for this explicitly, rather than requiring a separate login per client.