
POSH compliance for startups is often treated like a documentation task. A company drafts a policy, names an internal committee and does the bare minimum. The real test is whether employees know what behaviours are alright at the workplace, how to report an incident if they ever feel uncomfortable, understand the redressal process, and trust that their complaint will be handled fairly and confidentially. The Prevention of Sexual Harassment Act, formally the Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013, places responsibilities on employers to create a safe workplace.
Founders often ask, what is compliance under POSH? It is a legal requirement under the POSH Act to have systems in place for prevent, prohibit, and redress sexual harassment. POSH compliance for a company starts with two things: a written POSH policy and a trained Internal Committee that can run the redressal process. Employees should know what POSH is, what different forms of sexual harassment can look like, and what they can do if they face harassment.
Compliance with the POSH Act means having a clear prevention, prohibition and redressal process in place. A complaint should have a defined route into the Internal Committee, with confidentiality maintained throughout the process. The Committee then follows the applicable inquiry process, records the relevant proceedings and reaches its findings in accordance with the POSH framework. Employees should not have to figure out the process while they are already dealing with sexual harassment. While the redressal process is an important part of the POSH committee, an even more important part is the process of prevention and prohibition.
The POSH policy goes beyond “the company’s sexual harassment document.” The policy should explain prohibited behaviour, reporting routes, confidentiality, the complaint process and the role of the Internal Committee where one is required.
A company’s POSH policy should account for the different environments and interactions that employees may encounter. Startups may have remote teams, client dinners, work travel, co-working spaces, informal messaging groups and social media interactions. The policy should make sense in those settings rather than reading like it was written for another organisation.
A POSH policy in any organisation, especially a startup, needs to evolve. If the company expands, adds contractors, changes reporting managers or introduces a hybrid workplace, the POSH policy should be reviewed and revised accordingly.
One of the simplest tests of POSH Act compliance is whether an employee knows what sexual harassment is and where exactly to go if they want to report an incident which they have encountered which is sexual in nature. The route should be easy to find through onboarding materials, an employee handbook, the company portal, and, most importantly, posters in office spaces.
The Internal Committees role is to ensure compliance with regards to sexual harassment is put in place within the organisation and as importantly to spread awareness on sexual harassment within the organisation and also manage sexual harassment complaints. As per the law, any company with ten or more employees has to form an Internal Committee to meet POSH Act compliance. Its job is to receive complaints, inquire into them, and recommend action. Employees should know who the members are, they should be approachable, and the members should be trained every year, because the first real complaint is a bad time to learn the process.
Most employees read the POSH policy once, in their first week, and never think about it again. Compliance under the POSH Act works better when people recall it repeatedly: at onboarding, in manager conversations, and in a short refresher at least once a year, built around situations they’d recognise, like a client dinner that goes wrong or a message in a team chat that crosses a line. That yearly session is also where employees relearn who sits on the Internal Committee and what support they can ask for, so the system feels familiar well before anyone needs it.
Employees know the POSH policy exists, managers know how to handle a disclosure, the Internal Committee is trained, reporting channels are easy to find, and confidentiality is taken seriously.
That is the practical POSH policy meaning founders need to keep in mind. POSH Act compliance is not about producing the longest policy document. It is about building a system that works clearly and consistently when someone needs it. To make this concrete, here is what to have in place, and what’s worth adding if you want to do more than the bare minimum.
If you want to do more than the bare minimum and make a real difference:
Another POSH compliance mistake to avoid is assuming that no complaints automatically means the workplace is safe. It can also mean employees don’t know how to complain or don’t trust the process.
The Prevention of Sexual Harassment Act defines “employee” broadly, so it covers more than people on the payroll. Permanent and temporary staff, contract workers, interns, trainees, probationers and volunteers all count, and so does anyone placed through an agency. For POSH compliance for startups, that means the policy, training and Internal Committee should reach everyone who works with the company, not just the core team.
A startup policy should change as the organisation changes. Review POSH Act compliance when committee members leave, managers join, remote teams expand, offices open, or new categories of workers join the company.
Ankita Jagtiani is a Mumbai-based POSH consultant, ICF-accredited life and youth leadership coach and internationally trained ADHD coach. She runs POSH awareness programs for organisations and helps startups build a setup their employees actually use.