If you want to become a compliance officer in India, the regulator that governs your employer decides what you need, because no single exam or licence covers the post. A listed company must appoint a qualified Company Secretary, while brokers, banks and social media platforms apply other tests.
SEBI imposed the qualified Company Secretary requirement in Regulation 6(1) of the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015 (the Listing Regulations), which provides that “A listed entity shall appoint a qualified company secretary as the compliance officer”. Under that line, only a member of the Institute of Company Secretaries of India (ICSI) can hold the compliance officer post at a listed company.
The post exists so that a listed company has one officer who answers for its dealings with the regulator. Regulation 6(2) makes that officer responsible for ensuring conformity with the regulatory provisions “in letter and spirit”, for co-ordinating with and reporting to the board, the stock exchanges and the depositories, for the correctness of what the company files, and for monitoring the email address investors use to complain.
Regulation 6 applies to listed entities only, and three other regulators use the same title for posts filled on different tests. The SEBI (Stock Brokers) Regulations, 2026 require every stock broker to appoint a compliance officer without naming a qualification for the post. The Reserve Bank of India (RBI) sets an age limit and an experience threshold for a bank’s Chief Compliance Officer, and the IT Rules require a large social media platform’s Chief Compliance Officer to be a senior employee resident in India.
The listed company’s post has also become a more senior one since late 2024. A proviso SEBI added to Regulation 6(1), in force from December 2024, requires the compliance officer to be a whole-time employee, designated as Key Managerial Personnel and placed not more than one level below the board of directors. SEBI’s April 2025 circular reads that as one level below the Managing Director or a Whole-time Director. On the banking side, the RBI re-issued its conditions for a bank’s Chief Compliance Officer in fresh Directions in 2026 and kept both the 55-year age limit and the 15-year experience requirement.
Which of these compliance officer posts you can hold depends on the test that your target employer’s regulator applies, and one candidate’s position shows how far apart the tests are. A law graduate has spent three years in the compliance team of a stock broker and has no Company Secretary qualification. Two openings come up in the same month: the broker’s own compliance officer post, and the compliance officer post at a listed manufacturing company.
The two openings give two different answers, because two different regulations govern them. Regulation 17 of the Stock Brokers Regulations governs the broker’s post, and it names no degree, but SEBI’s certification standard requires a broker’s compliance officer to pass the NISM-Series-III-A examination. Regulation 6(1) of the Listing Regulations governs the listed company’s post, and it requires ICSI membership, for which no amount of broking experience substitutes.
The broker’s post is therefore open to the graduate after a NISM-Series-III-A pass. The listed company’s post needs the Company Secretary qualification first. A graduate with at least 50% marks can start that qualification at the Executive Programme, without the entrance test, and will then need a position no more than one level below the board, as the 2024 proviso requires.
Which employers must appoint a compliance officer in India?
Four sets of employers must appoint a compliance officer in India by law: listed entities and SEBI-registered intermediaries such as stock brokers, which answer to SEBI; commercial banks and the larger non-banking financial companies, which answer to the RBI; and significant social media intermediaries, which answer to the IT Rules. Outside these four, a company may create a compliance post by choice, and the qualification for it is then whatever that employer asks for.
Compliance officers at listed companies and SEBI intermediaries
Every listed entity must have a compliance officer under Regulation 6(1), and it cannot leave the post empty for long. Regulation 6(1A) requires a vacancy to be filled within three months, and it bars an interim appointment unless the interim officer is appointed under the same laws that govern a fresh appointment to the post. The Listing Regulations carry the rest of a listed company’s disclosure regime, and Regulation 6(2) makes the compliance officer responsible for the company’s conformity with all of it.
Company Secretary posts also exist well beyond listed companies. Section 203 of the Companies Act, 2013, read with Rules 8 and 8A of the Companies (Appointment and Remuneration of Managerial Personnel) Rules, 2014, requires every listed company, and every other company with a paid-up share capital of ₹10 crore or more, to have a whole-time company secretary. In an unlisted company that post carries the company-law filings and not the Regulation 6 duties, which apply only once the company lists.
A stock broker’s compliance officer works under regulations that SEBI issued in January 2026. Regulation 17(1) of the SEBI (Stock Brokers) Regulations, 2026 requires every stock broker to appoint a compliance officer responsible for monitoring compliance with the securities laws and the exchanges’ bye-laws, and for redressing investors’ grievances. Regulation 17(2) then requires that officer to report any non-compliance observed to the stock exchange “immediately and independently”.
A single certification standard applies across seven kinds of intermediary. SEBI’s notification of 11 March 2013 made the NISM-Series-III-A examination (Securities Intermediaries Compliance, Non-Fund) the requisite standard for anyone functioning as the compliance officer of a stock broker, depository participant, merchant banker, underwriter, banker to an issue, debenture trustee or credit rating agency.
Compliance officers at banks, NBFCs and social media platforms
The RBI requires a Chief Compliance Officer (CCO) at every commercial bank under the Reserve Bank of India (Commercial Banks – Compliance Function) Directions, 2026, issued on 31 July 2026. Paragraph 3 applies them to banking companies other than Small Finance Banks, Payments Banks and Local Area Banks, to the corresponding new banks and to the State Bank of India.
Non-banking financial companies (NBFCs) carry the same requirement once they reach the middle or upper layer of the RBI’s scale-based framework. The RBI’s circular of 11 April 2022 required upper-layer NBFCs to have a CCO from 1 April 2023 and middle-layer NBFCs from 1 October 2023, each appointed for a minimum tenure of three years.
Large social media platforms fall under a rule made by a different ministry. Rule 4(1)(a) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (the IT Rules) requires every significant social media intermediary, meaning a platform with at least 50 lakh registered users in India, to appoint a Chief Compliance Officer. The Explanation to the rule defines that officer as a key managerial personnel or other senior employee of the platform who is resident in India. The 2026 amendment to the IT Rules shortened takedown timelines and added labelling duties for synthetic content, and it left this requirement as it was.
Do you need to be a Company Secretary to become a compliance officer?
You need to be a Company Secretary only for the compliance officer post at a listed company, because Regulation 6(1) of the Listing Regulations requires a qualified company secretary and no other qualification satisfies it. The posts at stock brokers, banks, NBFCs and social media platforms name no such qualification, and employers fill them on certification, experience and seniority instead.
The Company Secretary route to a listed company’s compliance officer post
Membership of ICSI is what makes a company secretary “qualified” for Regulation 6. Section 2(1)(c) of the Company Secretaries Act, 1980 defines a company secretary as a member of the Institute, and Section 2(24) of the Companies Act, 2013 adopts that definition for a company secretary whom a company appoints.
The route to membership starts with the CS Executive Entrance Test (CSEET), which a student can take after Class 12. ICSI exempts graduates with at least 50% marks, post-graduates, and those who have passed CS Foundation, CA Intermediate or the CMA Final from the CSEET, and they register directly for the Executive Programme on paying an exemption fee. A law graduate with that score therefore starts at the Executive Programme.
After the Executive Programme comes the Professional Programme. Alongside the examinations, ICSI requires twenty-one months of long-term practical training, preceded by an Executive Development Programme, and a student becomes eligible for membership only after passing the Professional Programme and completing that training.
Membership makes you eligible for the post, but the proviso SEBI added in December 2024 also fixes where in the company the post sits. SEBI’s circular of 1 April 2025 measures “one level below the board” from the Managing Director or a Whole-time Director who sits on the board. Where a company has neither, the circular measures it from the Chief Executive Officer, the Manager or whoever runs the company’s day-to-day affairs.
The proviso therefore ties the post to the listed company’s organisation chart as well as to the member’s qualification. A newly qualified member can hold it only where the company places that member directly below its Managing Director or Whole-time Director, and a company does not meet the proviso by giving the title to a member lower down. The responsibilities and duties of a Company Secretary under company law sit alongside the Regulation 6(2) duties whenever a company gives both roles to the same member.
Can you become a compliance officer without the CS qualification?
You can become a compliance officer without the CS qualification at a stock broker or another SEBI intermediary, where the qualifying test is the NISM-Series-III-A certification rather than ICSI membership. The examination has 100 questions to answer in 120 minutes, with a pass mark of 60%. A wrong answer costs a quarter of the marks that question carries, and the certificate lasts three years before it has to be revalidated through NISM’s continuing professional education programme.
The RBI names no degree for a bank’s CCO. Under its 2026 Directions a bank selects its CCO on experience, age and a fit and proper assessment. For compliance staff generally, paragraph 29 says they should preferably have a fair knowledge of law, accountancy and information technology, and practical experience of business lines and of audit or inspection work. A significant social media intermediary’s CCO is chosen on seniority and residence, not on a qualification.
Those posts are open to law graduates, chartered accountants and finance or audit staff who build the experience the regulator asks for. That experience comes from years in a compliance, audit, legal, finance or risk function, which is the list of functions the RBI counts towards its own threshold.
The route from a compliance team to the chief compliance officer post
You reach the chief compliance officer post after years in a compliance, audit, legal, finance or risk role, because the three rules that fix a seniority for the post all place it at senior-management level. SEBI places a listed company’s compliance officer no more than one level below the board, the RBI places a bank’s CCO not below two levels from the Managing Director and Chief Executive Officer, and the IT Rules require a platform’s CCO to be key managerial personnel or another senior employee.
None of these instruments fixes a qualification for the staff who work under the designated officer, so an employer defines its junior compliance posts for itself. The work at that level follows the officer’s own duties: the filings, the correspondence with the exchange or the regulator, the tracking of investor grievances, and the function-wise compliance manuals that paragraph 36 of the RBI’s Directions asks banks to maintain.
Experience that counts towards a compliance officer post
Experience counts towards a compliance officer post when it is in a function the regulator names, and the RBI names five of them. Paragraph 59 of its 2026 Directions requires a bank’s CCO to have at least 15 years in banking or financial services, of which at least five must be in audit, finance, compliance, legal or risk management.
The RBI reads risk management widely for this purpose. Its proviso to paragraph 59 counts control functions within business lines as risk management, so a regional, zonal or business head who carried control responsibilities for five years or more meets the five-year condition. A lawyer in a bank’s legal department and an officer in its inspection wing both build experience that counts.
The count of years is not the whole of the RBI’s test for the post. Paragraph 60 adds that the CCO shall have a good understanding of the industry and of risk management, knowledge of regulations and the legal framework, and sensitivity to supervisors’ expectations.
Outside banking, no regulator sets a number of years, and seniority follows the employer’s organisation chart. Work in the compliance team of a multinational company builds a record of filings, audits and regulator correspondence, and a candidate who also holds ICSI membership can move from that work to a listed company’s post once the company places them no more than one level below the board.
The RBI’s eligibility test for a bank’s chief compliance officer
A bank’s chief compliance officer must come through a selection process run by the Board, and the RBI’s 2026 Directions add fixed conditions on record, age and experience. Under paragraph 56, a senior-executive committee constituted by the Board recommends candidates in order of merit after a fit and proper evaluation, and the Board takes the final decision.
Under paragraphs 57 to 59, the candidate must have no vigilance case or adverse RBI observation pending, must not be more than 55 years old at appointment, and must have the 15 years of experience with five in a named function. The age limit carries a proviso of its own. A candidate over 55 who has been continuously associated with the compliance function since before turning 55 remains eligible.
Once appointed, the CCO holds a fixed tenure of at least three years, and the bank can transfer or remove the CCO early only in exceptional circumstances, with the Board’s explicit prior approval. The CCO must be a senior executive, preferably a General Manager or equivalent and not below two levels from the MD and CEO, and paragraph 55 allows the bank to recruit the CCO from outside.
The RBI considered loosening these conditions before it issued the final text. A draft published in June 2026 proposed replacing the age and experience limits with a requirement of adequate domain knowledge and relevant experience, with age left to each bank’s internal policy. The Directions issued on 31 July 2026 kept both limits, so the 55-year and 15-year conditions apply to every CCO appointment a commercial bank now makes.
Duties and liability of a compliance officer in India
The duties of a compliance officer in India follow from the regulator that required the appointment, and under the broker and bank rules they include reporting beyond the employer’s own management. A listed company’s officer carries the four Regulation 6(2) duties, which run from ensuring conformity “in letter and spirit” to monitoring the investor-grievance email address.
A stock broker’s compliance officer must report any non-compliance observed to the stock exchange “immediately and independently” under Regulation 17(2), a phrase that points to a report made without first passing through the broker’s management. Regulation 25(4) also sends whistle-blower complaints against the broker’s employees to the compliance officer, except complaints against its directors, key managerial personnel, designated directors and promoter, which go to the audit committee or an analogous body.
A bank’s CCO works under conditions designed to keep the post independent of the bank’s business. The CCO carries no business targets and no reporting line to a business vertical, cannot hold a second role that brings a conflict of interest, and is the bank’s nodal point of contact with the RBI, taking part in the quarterly discussions the RBI holds with the bank. The bank must also inform the RBI’s Senior Supervisory Manager before it appoints a CCO or removes one early.
Personal liability of a Chief Compliance Officer under the IT Rules
The Chief Compliance Officer of a significant social media intermediary carries a personal liability that the Listing Regulations and the RBI’s Directions do not state in the same terms. Rule 4(1)(a) of the IT Rules makes the officer liable in any proceedings relating to third-party information, data or communication links that the platform makes available or hosts, where the officer fails to ensure that the platform observes due diligence under the Information Technology Act, 2000 and the Rules.
The proviso to the rule gives the platform a procedural protection, in that no liability under the Act or the Rules may be imposed on the intermediary without an opportunity of being heard. The residence requirement in the Explanation keeps the officer within reach of proceedings in India, and a candidate who accepts the post accepts that exposure along with the title.
The Chief Compliance Officer is one of three resident officers that Rule 4(1) requires such a platform to appoint. Rule 4(1)(b) adds a nodal contact person for round-the-clock coordination with law enforcement agencies, and Rule 4(1)(c) adds a Resident Grievance Officer, and both must be employees resident in India. The liability clause in Rule 4(1)(a) attaches to the Chief Compliance Officer alone, and not to either of those two officers.
Frequently asked questions
Can a law graduate become a compliance officer without a CS qualification?
A law graduate can become a compliance officer without the CS qualification at a stock broker or another SEBI intermediary after passing NISM-Series-III-A, and at a bank, NBFC or social media platform, where the post is filled on experience and seniority. The compliance officer post at a listed company is the exception, because Regulation 6(1) of the Listing Regulations requires a member of ICSI.
Is NISM Series III-A certification mandatory for a compliance officer?
NISM-Series-III-A certification is mandatory for the compliance officer of a stock broker, depository participant, merchant banker, underwriter, banker to an issue, debenture trustee or credit rating agency, under SEBI’s notification of 11 March 2013. The notification does not extend it to a listed company’s compliance officer, a bank’s CCO or a social media platform’s CCO.
How many years of experience does a bank’s chief compliance officer need?
A bank’s chief compliance officer needs at least 15 years of experience in banking or financial services, of which at least five must be in audit, finance, compliance, legal or risk management, under paragraph 59 of the RBI (Commercial Banks – Compliance Function) Directions, 2026. The candidate must also be no older than 55 at appointment, unless continuously associated with the compliance function since before that age.
Can a listed company appoint an interim compliance officer?
A listed company can appoint an interim compliance officer only if the appointment is made under the laws that apply to a fresh appointment to the post, under the proviso to Regulation 6(1A) of the Listing Regulations. The vacancy itself must be filled within three months.
Does a compliance officer have to be resident in India?
A significant social media intermediary’s Chief Compliance Officer must be resident in India under the Explanation to Rule 4(1)(a) of the IT Rules. Regulation 6 of the Listing Regulations uses no residence test, but it requires a listed company’s compliance officer to be in the whole-time employment of the listed entity.
References
Securities and Exchange Board of India (Listing Obligations and Disclosure Requirements) Regulations, 2015, as amended up to 14 July 2026 (regulations cited: 6(1), 6(1A), 6(2))
Securities and Exchange Board of India (Listing Obligations and Disclosure Requirements) (Third Amendment) Regulations, 2024, notification SEBI/LAD-NRO/GN/2024/218, 12 December 2024
SEBI circular SEBI/HO/CFD/PoD2/CIR/P/2025/47, 1 April 2025, on the position of the compliance officer under Regulation 6
Securities and Exchange Board of India (Stock Brokers) Regulations, 2026 (regulations cited: 17, 25)
SEBI notification LAD-NRO/GN/2012-13/33/1103, 11 March 2013, under the SEBI (Certification of Associated Persons in the Securities Markets) Regulations, 2007 (NISM-Series-III-A)
National Institute of Securities Markets, NISM-Series-III-A: Securities Intermediaries Compliance (Non-Fund) Certification Examination
Reserve Bank of India (Commercial Banks – Compliance Function) Directions, 2026, RBI/DoS/2026-27/408, 31 July 2026 (paragraphs cited: 3, 29, 36, 55 to 59, 61 to 63, 65 to 67, 70, 73)
Reserve Bank of India, Compliance Function and Role of Chief Compliance Officer (CCO) – NBFCs, 11 April 2022
Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (rule cited: 4(1)(a)), and Ministry of Electronics and Information Technology notification S.O. 942(E), 25 February 2021
Companies Act, 2013 (sections cited: 2(24), 203), and Companies (Appointment and Remuneration of Managerial Personnel) Rules, 2014 (rules cited: 8, 8A)
Company Secretaries Act, 1980 (section cited: 2(1)(c))
Institute of Company Secretaries of India, CSEET exemption and long-term practical training requirements
Disclaimer
This article is for informational purposes only and does not constitute legal or career advice. Eligibility for a particular compliance officer post depends on the regulator that governs the employer, the employer’s own policies and the version of the rules in force on the date of appointment.

