Nearly every organization has a POSH policy document somewhere on its intranet. Far fewer have one that would actually hold up if a court or inspector read it closely. The gap between “we have a policy” and “we have a compliant policy” usually comes down to a handful of clauses nobody thought to include.
Moreover, the POSH Act does not hand employers a template. It specifies outcomes a policy must achieve and leaves the actual drafting to each organization, which is exactly where most policies quietly fall short.
Request a demo today to see how our POSH compliance solutions can help your organization stay compliant and build a safer workplace.
What You’ll Learn in This Guide
This article covers:
- The legal basis that actually requires a written policy
- The nine core elements a compliant policy must contain
- Why a generic downloaded template rarely survives real scrutiny
- A 2025 disclosure rule most existing policies still don’t reflect
- A practical checklist for reviewing your own document
POSH Policy Document: Why a Generic Template Rarely Survives Scrutiny
A document copied from another company’s intranet might satisfy a quick internal checklist. It will not necessarily survive a real inquiry or a court’s scrutiny if the language does not actually match what the Act requires. Therefore, treating the policy as a legal instrument, not a formality, changes how carefully it needs to be drafted.
The Legal Basis: Rule 13, Not Just Good Practice
Under Section 19 of the POSH Act, 2013, read with Rule 13 of the POSH Rules, every employer must formulate and widely disseminate an internal policy for the prevention, prohibition, and redressal of sexual harassment. This is not optional guidance. It is a specific statutory requirement with its own rule number.
Defining Sexual Harassment the Way Section 2(n) Actually Does
The policy must reflect the Act’s own definition, not a paraphrased version. This includes physical contact and advances, a demand or request for sexual favours, sexually coloured remarks, showing pornography, and any other unwelcome physical, verbal, or non-verbal conduct of a sexual nature. It should also spell out related circumstances, such as an implied or explicit promise of preferential treatment in exchange for sexual favours, since these count too.
POSH Policy Document: Scope and Who It Actually Covers
A compliant policy names exactly who it protects and where it applies. This includes employees, interns, contract and temporary staff, and visitors to the workplace. Moreover, coverage should explicitly extend to work travel, off-site events, and online meetings, not just the physical office.
Internal Committee Details Your Policy Must Name
The policy should identify the Internal Committee’s composition, how members are appointed, and how employees can actually reach them. A policy that describes a committee in the abstract, without naming current members or providing contact details, fails the basic test of being genuinely usable.
The Complaint Filing Mechanism, Spelled Out Clearly
Employees need to know exactly how to file a complaint: in what format, within what timeframe, and to whom. A policy that simply says “contact HR” without more detail leaves employees guessing at precisely the moment clarity matters most.
POSH Policy Document: Confidentiality and Non-Retaliation Clauses
The policy must state plainly that details of a complaint stay confidential. It should also make clear that raising a complaint in good faith cannot result in retaliation against the complainant. Employees who do not see this promise in writing are less likely to come forward at all.
Inquiry Timelines and What Happens After
A well-drafted policy states the statutory 90-day inquiry window and what happens once the committee submits its findings. This keeps expectations realistic on both sides and gives the process visible structure.
False Complaints and Annual Reporting, In Writing
The policy should note that malicious or knowingly false complaints can lead to action. However, it should also make clear that a complaint which simply fails to be proven is treated differently. It should also reference the organization’s annual reporting obligation, so employees understand the process has ongoing oversight, not just a one-time inquiry.
A 2025 Rule Most Policies Still Don’t Reflect
Effective July 14, 2025, the Companies (Accounts) Second Amendment Rules, 2025 require companies to disclose specific figures in their Board’s Report. These include the number of sexual harassment complaints received, resolved, and pending for more than 90 days during the year. This is a real shift from simply confirming compliance to reporting actual data. However, many existing POSH policies still describe reporting in only the vaguest terms, without acknowledging this more demanding disclosure standard now sits above it.
POSH Policy Document: A Practical Checklist
- Confirm the policy uses the Act’s own definition of sexual harassment, not a paraphrase
- Name current Internal Committee members and contact details, not just a generic description
- State confidentiality and non-retaliation protections explicitly, in plain language
- Reference both the 90-day inquiry timeline and the annual reporting obligation
- Make the policy available in relevant regional languages, not just English
Common Mistakes That Make a Policy Fall Short
- Copying another company’s policy wholesale without adjusting it to match actual committee structure
- Leaving the policy undated, so nobody can tell if it reflects current committee composition
- Burying the policy somewhere inaccessible, rather than actively distributing it
- Never revisiting it after regulatory changes, like the 2025 disclosure amendment
Request a demo today to see how our POSH compliance solutions can help your organization stay compliant and build a safer workplace.
POSH Compliance Services for Policy Drafting and Review
Many organizations bring in POSH compliance services specifically to draft or review this document against current law, rather than relying on a template that predates the latest regulatory changes. This is exactly the kind of gap a POSH audit catches, often long after the policy was first written.
Conclusion: A POSH Policy Document Is a Legal Instrument, Not a Formality
In conclusion, a POSH policy document carries real legal weight, and the nine core elements it needs are specific, not aspirational. Moreover, regulatory change has not stopped since most existing policies were first drafted, as the 2025 Board Report disclosure rule shows clearly. Therefore, treating this document as something to revisit and strengthen, not just something to have, is what separates genuine compliance from paperwork.
Request a demo today and discover how our expert-led POSH compliance services can help your organization stay compliant, reduce risk, and build a safer workplace.