Building a POSH Policy That Isn't Boilerplate
A generic downloaded POSH policy will not protect your business. Here is how to build a POSH policy that actually reflects how your workplace runs.
A POSH policy copied from a template and lightly edited will technically exist, but it will not function well when actually needed. A policy that reflects how your organisation is actually structured, who your ICC members are, where your offices are, how complaints really reach HR, is what protects both employees and the business.
Key facts at a glance
- A POSH policy is legally required for every employer, regardless of size, under the POSH Act, 2013.
- The policy must be displayed at the workplace and accessible to every employee.
- It should name the actual current ICC members and their contact details, not a generic placeholder.
- An Internal Committee is mandatory at 10 or more employees; below that, the policy should direct complaints to the district Local Committee instead.
- Complaint timelines under the Act generally require the inquiry to be completed within 90 days of the complaint.
- A policy reviewed only once, at creation, tends to go stale within a year as staff, locations, and structures change.
Why generic templates fall short
A template policy usually gets the legal boilerplate right, definitions of sexual harassment, a general statement of the complaint process, a nod to confidentiality. What it almost never gets right is the specific operational detail: who exactly is on your ICC right now, what is the actual email address or form to file a complaint, which office locations does this cover, and what happens if the complaint involves someone at a different site or a remote employee. Those gaps are exactly what employees and, if it comes to it, courts or regulators will look for.
Boilerplate policy versus a working policy
| Element | Generic template | Working policy |
|---|---|---|
| ICC members | "The Internal Committee" (unnamed) | Named members with direct contact details, updated on change |
| Complaint channel | Vague reference to "HR" | Specific email, form, or portal link, plus a backup contact |
| Locations covered | Not addressed | Explicitly lists all offices, plants, remote/hybrid arrangements |
| Timelines | States the statutory period only | States the statutory period and internal escalation checkpoints |
| Non-retaliation | Often absent | Explicit clause, plus a separate channel to report retaliation |
| Review cycle | None specified | Annual review, or immediately on ICC or location change |
What a strong POSH policy actually contains
- A clear statement of scope. Every location, every employee category, including contract staff, consultants and interns where applicable, and remote or hybrid work contexts.
- Named ICC members with live contact details. Update this the moment membership changes, an outdated name is a real barrier for an employee trying to file a complaint.
- A specific complaint channel. A named email address, form, or portal, plus a backup route if the primary contact is unavailable or is the subject of the complaint.
- Defined timelines. Reference the statutory inquiry period and add practical internal checkpoints so complainants know roughly what to expect and when.
- Confidentiality and interim relief provisions. State what confidentiality means in practice and what interim measures (leave, transfer, etc.) the ICC can recommend during an inquiry.
- An explicit non-retaliation clause. Covering both complainants and witnesses, with a separate channel to report any retaliation experienced.
- A review commitment. State that the policy is reviewed at least annually, and immediately upon any change to ICC composition or company locations.
Getting the right people to draft it
The strongest policies are usually drafted jointly by HR, the ICC's presiding officer, and someone with legal or compliance expertise. HR brings the operational reality of how the organisation actually functions, the presiding officer brings inquiry-process experience, and legal input keeps the language aligned with the Act's requirements. A policy written by only one of these perspectives tends to either miss practical detail or miss legal nuance.
Keeping it alive, not just on file
A policy is only as good as its last update. Set a recurring reminder, at minimum annually, and trigger an immediate review whenever the ICC changes, a new office opens, or the company's workforce mix shifts meaningfully (for example, a large increase in remote hires). A policy that has not been touched in two years is a strong signal, to a regulator or a court, that POSH compliance is not being actively managed.
If you want to check whether your current POSH policy holds up, ComplianceCheck's POSH assessment gives you a clear picture in a few minutes.
Sources
- Ministry of Women and Child Development - wcd.nic.in
- SHe-Box portal - shebox.wcd.gov.in
- labour.gov.in for related workplace compliance guidance
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- Is a downloaded template POSH policy enough for legal compliance?
- A generic template may cover the minimum required clauses, but it often fails to reflect the employer's actual reporting structure, locations, employee categories and complaint channels, which reduces both its practical usefulness and its credibility if ever examined during a dispute.
- What should a POSH policy include beyond the basic definition of harassment?
- It should include the actual Internal Committee composition and contact details, clear complaint channels, defined timelines, confidentiality commitments, interim relief provisions, an explicit non-retaliation clause, and how the policy applies across all locations and employee categories.
- How often should a company update its POSH policy?
- Whenever the Internal Committee's composition changes, when the company opens a new location, or at least once a year as a routine review, so the policy stays accurate rather than becoming outdated.
- Should a POSH policy name the actual ICC members?
- Yes. Naming the current ICC members and their contact details, and keeping this updated whenever membership changes, is far more useful to employees than a generic reference to an unspecified committee.
- Does a POSH policy need to cover remote or hybrid employees?
- Yes. If any part of the workforce works remotely or in hybrid arrangements, the policy should explicitly state that workplace harassment protections extend to conduct occurring through digital communication and off-site work contexts.
- Who should be involved in drafting a company's POSH policy?
- Ideally HR, the Internal Committee presiding officer, and someone with legal or compliance expertise, so the policy reflects both the statutory requirements and the practical realities of how the organisation actually operates.
Check your status
POSH Act 2013 Compliance
Prevention of Sexual Harassment (POSH) Act 2013 compliance assessment, including Internal Committee (ICC) requirements.