GCC
17 min Read

GCC Compliance Requirements in India: The Complete 2026 Checklist

Mayank Pratap Singh
Mayank Pratap Singh
Co-founder & CEO of Supersourcing

Most enterprises budget six to eight weeks to incorporate a GCC in India and treat that as the finish line. It isn’t. Incorporation opens a second, longer clock  FEMA filings triggered by the transaction date of the first funding tranche, ROC deadlines tied to financial year end, state labour registrations triggered by the first hire in a new city  and that clock doesn’t pause for anyone who didn’t know it started.

The regulatory backdrop has also shifted faster than most setup guides have caught up with. Four consolidated Labour Codes took effect in November 2025. The Digital Personal Data Protection Rules were notified the same month. FEMA’s export and import framework tightened again in 2026. And transfer pricing  along the single most scrutinized line item for any GCC  just got a materially higher safe harbour threshold under Budget 2026. None of these changes are optional reading; each one resets part of the compliance calendar a GCC has to run.

India’s GCC base is still expanding, but not consolidating  industry forecasts put the country on track for 2,400–2,500+ centers and at least $100 billion in GCC revenue by 2030, up from 2,117 centers and roughly $98.4 billion today.

That growth trajectory is exactly why the compliance conversation matters now rather than later  every new center entering this market inherits the same tightened regulatory surface, and the ones that build FEMA, ROC, labour, DPDP, and transfer pricing readiness into their setup from day one spend far less time firefighting in year two. This guide is to build sequences, phase by phase.

TL;DR

This guide covers everything a foreign enterprise needs to stay compliant while running a GCC compliance requirements India program  from entity setup and FEMA filings to labour codes, data protection, and tax. It's written for legal, finance, and HR leaders who already decided to build a Global Capability Center in India and now need the operating playbook, not the pitch deck.

The single biggest number to hold onto: India now hosts 2,117 GCCs generating roughly $98.4 billion in revenue, a 32% jump since FY2021  which also means the compliance apparatus around GCCs has tightened just as fast, with new FEMA export rules, four consolidated Labour Codes, and the Digital Personal Data Protection framework all landing in the same 18-month window. Miss the sequencing on any one of these and you're looking at penalties, frozen bank remittances, or a stalled ESOP rollout.

By the end of this guide, you'll be able to build your own gcc regulatory compliance calendar  entity registration through ROC, FEMA, labour, tax, and data protection  and know exactly which filings are non-negotiable in year one versus which ones only kick in once you cross a headcount or revenue threshold.

 

What Is GCC Compliance in India?

GCC compliance requirements India is the full set of statutory obligations  corporate (ROC/MCA), foreign exchange (FEMA/RBI), tax (income tax, GST, transfer pricing), labour, and data protection (DPDP Act)  that a Global Capability Center must satisfy on entity registration and then on a recurring basis to legally operate as an Indian subsidiary of a foreign parent.

It is commonly confused with:

  • IT services vendor compliance  a GCC is a captive, wholly owned or majority-owned entity delivering work exclusively to its own parent; a vendor serves multiple clients and carries a different tax and transfer-pricing profile.
  • SEZ/STPI registration alone  SEZ or STPI status affects customs, GST, and export documentation, but it does not replace ROC, FEMA, labour, or DPDP obligations, which apply regardless of scheme.
  • One-time incorporation compliance  registering the company with the Ministry of Corporate Affairs (MCA) is the starting line, not the finish line; most of what breaks GCCs happens in month 14 onward, not month one.

"gcc compliance requirements india growth dashboard"

Why GCC Compliance Matters: The Business Case

Compliance isn’t a legal formality bolted onto the real work; it directly shapes cost, speed, and risk for the India entity and, by extension, the global parent.

  • Capital movement risk: Under FEMA, equity instruments must be allotted within 60 days of receiving inward foreign investment, and Form FC-GPR must be filed on the RBI’s FIRMS portal within 30 days of allotment. Miss either step and the parent’s funding round or capitalization plan for the India entity stalls.
  • Director-level exposure: Directors of a company that fails to file annual returns (MGT-7) or financial statements (AOC-4) for three consecutive years are disqualified from holding directorships anywhere in India for five years, under Section 164(2) of the Companies Act, 2013.
  • Tax exposure that compounds: Transfer pricing is now the single most scrutinized area for GCCs. A mispriced intercompany services agreement doesn’t just trigger a fine, it can trigger a multi-year audit that reprices every year it touches.
  • Talent and cost math: A 50–100 person GCC typically costs $500K–$3M to stand up, with all-in per-engineer costs of $25K–$80K a year  40–60% below US-equivalent cost. Statutory costs (12% employer PF, up to 3.25% employer ESI where applicable) sit inside that number, and getting them wrong distorts your entire cost-arbitrage case to the board.
  • Deal continuity: For companies with foreign investment, FEMA non-compliance can additionally complicate future funding rounds or an eventual exit, since acquirers and investors run FEMA/FLA filing history as a standard diligence item.
  • Ease-of-doing-business tailwinds are real but partial: under India’s Ease of Doing Business push, the government has decriminalized 3,400+ provisions and removed 42,000+ compliances across sectors  genuine friction reduction, but it changes the penalty structure on compliance failures, not the underlying obligation to file.
  • Scheme choice changes the cost curve, not just the tax line: stacking SEZ/STPI benefits with the Budget 2026 transfer pricing safe harbour and available state subsidies can trim effective operating cost by another 15–30%  but only if the scheme decision is made correctly at setup, since unwinding it later is one of the more expensive corrections a GCC can make.

The Core Problem Most Buyers Face

Most first-time GCC builders underestimate the compliance surface by 3–4x. They budget for incorporation, a PAN, a GST number, and a lawyer on retainer  and stop there. What actually happens in year one:

  • The FEMA clock starts silently. Several FEMA filings are triggered by a transaction date, not a calendar date  the moment shares are allotted or funds inbound, a filing window opens whether or not anyone on the India team notices.
  • State-by-state labour variance gets missed. A single GCC in Bengaluru must simultaneously satisfy central labour codes, Karnataka state rules, municipal regulations, and Shops & Establishments obligations  and a second office in Gurugram or Pune resets much of that state-specific list.
  • Transfer pricing documentation is treated as a year-end task. It should be built into the intercompany services agreement from day one; retrofitting a local file, master file, and Country-by-Country Report after the fact is materially harder and invites scrutiny.

THE WALKTHROUGH: From Incorporation to Steady-State Compliance

Phase 1  Entity Structuring & Registration

Before any GCC compliance calendar exists, the entity itself has to be structured correctly; this single decision cascades into every filing obligation that follows.

Choosing the entity type:

  • Most GCCs incorporate as a Private Limited Company under the Companies Act, 2013, registered through the MCA portal; this is the default for control, IP ownership, and eventual scaling.
  • A branch office is a narrower option used mainly for liaison or limited-scope activity; it carries its own filing (Form FC-3, filed with the ROC within six months of financial year close).
  • The SEZ vs. STPI vs. Non-STPI (DTA) decisions should be made in the same conversation as location and entity choice, not after  unwinding a scheme choice later is materially harder than getting it right once.

"fema compliance gcc filing timeline"

SEZ, STPI, or neither  the practical difference:

Model Where it can operate Tax position (2026) Compliance trade-off
SEZ Must sit inside a notified zone under a Development Commissioner Section 10AA income-tax holiday only for units that commenced before April 1, 2021; new units get customs/GST benefits, no income-tax holiday Export obligation, positive Net Foreign Exchange (NFE) requirement, periodic reporting
STPI Any office location in India Income-tax holiday under Section 10A expired March 2011; customs duty exemptions remain Must typically export a high share of services; monthly/periodic export certification
Non-STPI (DTA) Any office location, no export mandate Flat corporate rate under Section 115BAA (22% base, ~25.17% effective with surcharge and cess) No export-ratio constraint; simplest ongoing compliance, no scheme-specific reporting
  • Both SEZ and STPI units must certify software/services exports  historically via the Softex form, being replaced by a monthly Export Declaration Form (EDF) under FEMA 23(R)/2026 from October 1, 2026  within 30 days of month-end.
  • A GIFT City location is worth evaluating specifically for BFSI or fintech GCCs, given its regulatory sandbox and extended tax positioning.

Budget bands for Phase 1 setup:

  • Legal + incorporation + initial statutory registrations: typically a fraction of overall setup cost, but timeline-critical  plan 4–8 weeks for MCA incorporation plus PAN, TAN, GST, and Professional Tax registrations before the entity can legally employ anyone.
  • Full 50–100 person GCC stand-up cost: $500K–$3M, inclusive of real estate, technology, and first-year statutory overhead.

Phase 2  FEMA and RBI Compliance Setup

This is where most first-time India entities stumble, because FEMA obligations are transaction-triggered, not calendar-triggered.

The core FEMA filings to build a checklist around:

  1. Form FC-GPR  filed within 30 days of allotment whenever the Indian entity issues equity shares, compulsorily convertible debentures, or compulsorily convertible preference shares to a person resident outside India. Filed via the Authorised Dealer (AD) Category-I bank on the RBI’s FIRMS portal.
  2. 60-day allotment rule  equity instruments must be allotted within 60 days of receiving the foreign investment; if not, the money must be refunded within 15 days after that 60-day window expires.
  3. Form FC-TRS  filed generally within 60 days of a share transfer between a resident and non-resident.
  4. Form DI  required within 30 days for any downstream investment made by an Indian entity that has itself received foreign investment.
  5. Annual Return on Foreign Liabilities and Assets (FLA)  an annual filing to the RBI for any company with foreign investment; if audited financials differ materially from the provisional figures used, a revised return is due by September 30.
  6. Form ODI / ECB-2  relevant only if the India entity itself makes overseas investments or raises external commercial borrowings; ECB-2 is a monthly filing through the AD bank.

Red flag: a Late Submission Fee (currently ₹7,500) applies to delayed RBI filings, but the bigger risk is that continued non-compliance can constitute a FEMA contravention under Section 13 of the Foreign Exchange Management Act, 1999  a materially different and more serious category of exposure than a late fee.

2026 tightening to know: updated FEMA export and import regulations require export proceeds to be realised within 15 months, mandate EDF declarations for all service exports, and expand Authorised Dealer oversight  including routing advances through the same AD and stricter set-off rules across goods and IT services. Build this into your AD bank relationship management, not just your filing calendar.

Phase 3  Corporate (ROC/MCA) Compliance Cadence

ROC filings for subsidiary entities follow a fixed annual rhythm plus event-based triggers.

Annual, fixed-date obligations:

  • AGM within six months of financial year end.
  • Form AOC-4 (financial statements) and Form MGT-7 (annual return) filed with the ROC.
  • DIR-3 KYC for every director, annually.
  • Statutory audit by an ICAI-registered Chartered Accountant  mandatory for every Indian company regardless of size.
  • Income tax return (Form ITR-6) by October 31 of the assessment year, extending to November 30 where transfer pricing provisions apply  which they do for virtually every foreign-owned GCC.

Event-triggered obligations:

  • Form PAS-3 whenever new shares are issued.
  • Amendments to the compliance register whenever board composition, registered office, or capital structure changes.

Penalty red flags:

  • Beyond a ₹100/day late fee on each of AOC-4 and MGT-7, missing the AGM triggers a flat penalty of ₹1 lakh on the company plus ₹5,000 per officer in default.
  • Three consecutive years of non-filing triggers automatic director disqualification for five years under Section 164(2).
  • Persistent non-filing can lead to the company being struck off the ROC register entirely.

Documentation discipline: maintain a centralised compliance register  board resolutions, valuation reports, bank acknowledgements, and every filed form  for at least five years, and register early on the RBI’s FIRMS, FLAIR, and PRAVAAH portals before a filing requirement actually arises, so the account isn’t the bottleneck when a deadline hits.

"labour law compliance india payroll checklist"

Phase 4  Labour Law and Payroll Compliance

What changes for GCC payroll specifically:

  • Wage definition standardized: under the Code on Wages, “wages”  meaning Basic + Dearness Allowance  must equal at least 50% of gross CTC. If your current salary structure has Basic below that threshold, it needs restructuring, and that restructuring raises PF, ESI, gratuity, and leave-encashment liabilities.
  • PF threshold: establishments with 20 or more employees must register for Provident Fund; employer contribution runs around 12% of the PF wage.
  • ESI wage ceiling: ₹21,000/month  most GCC engineering hires sit above this and are exempt, but junior hires, interns, and support staff may still fall within it, and the establishment must register if headcount thresholds are met regardless of how many individual employees are actually covered.
  • Bonus eligibility: statutory bonus applies to employees earning up to ₹21,000/month.
  • Equal pay: explicit statutory prohibition on gender-based wage discrimination.

State-specific obligations that don’t disappear under the Codes:

  • Professional Tax  registration required within 30 days of hiring the first employee in a given state; late registration penalties typically range ₹1,000–₹5,000 depending on the state.
  • Shops & Establishments Act  annual return deadlines vary by state: Karnataka (January 31), Delhi (January 30), Gujarat and Tamil Nadu (February 1), Maharashtra (April 30). A multi-city GCC needs a state-by-state calendar, not one master date.
  • Labour Welfare Fund (LWF)  state-specific, with semi-annual contribution windows in several states.

Checklist  monthly payroll compliance routine:

  1. PF deposit by the 15th of the following month.
  2. ESI challan filed on schedule where applicable.
  3. TDS on salaries deducted and deposited.
  4. State Professional Tax and LWF contributions on their state-specific schedule.
  5. Attendance, leave, and overtime registers updated and audit-ready.

Phase 5  Data Protection (DPDP Act) Compliance

The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025  notified by MeitY on November 13, 2025  now give India a defined, phased implementation roadmap, with full substantive compliance expected by May 13, 2027.

Why this matters specifically for a GCC: most GCCs process employee data, customer data inherited from the global parent’s systems, or both  and the DPDP Act applies to digital personal data processed within India, as well as processing outside India where it relates to offering goods or services to individuals in India, which captures a large share of GCC data flows by default.

What to build now, ahead of the deadline:

  • Governance structure and a designated point of accountability for data processing decisions.
  • Privacy notices that meet DPDP Rules requirements  consent language, purpose limitation, and retention periods.
  • Breach notification workflow  the obligation to report a personal data breach is one of the Act’s core mechanisms, and a workflow retrofitted under deadline pressure is where most gaps appear.
  • Significant Data Fiduciary (SDF) assessment  larger-scale or higher-sensitivity data processing triggers heightened obligations, including specific governance and audit requirements; most enterprise-scale GCCs should assume this classification applies and plan accordingly rather than wait for a determination.

Trust signal: penalties under the DPDP Act can reach ₹250 crore (roughly $30 million) for serious violations, a figure that should reframe DPDP readiness as a board-level risk item, not a legal-team checklist line.

"sez stpi compliance india comparison chart"

Phase 6  Tax Compliance and Transfer Pricing

Corporate tax: most GCCs elect the Section 115BAA regime  a 22% base rate, approximately 25.17% effective with surcharge and cess  trading certain exemptions for rate simplicity.

GST: applies to services the GCC provides, including intercompany services to the parent; export of services is typically zero-rated, with GST refund of accumulated input credit available under both SEZ and STPI regimes.

Transfer pricing  the highest-scrutiny area for any GCC:

  • Documentation requirements  local file, master file, and Country-by-Country Report (CbCR) where thresholds apply  must be prepared before the tax return is filed, not after.
  • Budget 2026 changed the calculus: a uniform 15.5% safe harbour margin now applies, with the eligibility threshold raised from ₹300 crore to ₹2,000 crore in parent revenue, electable for five years. This single change now covers over 1,000 existing GCCs that previously sat outside safe harbour eligibility.
  • Opting into safe harbour, where eligible, trades a small margin premium for materially lower audit and litigation risk  model this decision with your CFO before the first intercompany invoice is issued, not at the first audit.

Industry signal on where scrutiny concentrates: in a recent industry survey, 81% of GCC leaders named transfer pricing as their top regulatory priority, followed by SEZ/STPI regulations at 67% and labour laws at 60%  which tracks closely with where this guide has spent the most detail.

Phase 7  Ongoing Monitoring, Audit Readiness & Scaling/Exit Compliance

Compliance doesn’t plateau once the first-year filings clear  it shifts from a setup checklist to a running system, and that system needs owners, not just deadlines.

Building the compliance calendar as a system, not a spreadsheet:

  1. Assigning a single accountable owner per filing category (FEMA, ROC, labour, tax, DPDP)  cross-functional gaps, not missing knowledge, are the most common reason a deadline slips.
  2. Reconcile the compliance register (board resolutions, filed forms, bank acknowledgements) quarterly, not just at year-end  this is also what an auditor or acquirer will ask to see first.
  3. Re-run the transfer pricing model whenever the intercompany services agreement, headcount mix, or function profile changes materially  not only at the annual filing deadline.
  4. Track state-level regulatory changes separately from central ones  Professional Tax rates, LWF contribution windows, and Shops & Establishments return dates each move independently and don’t get a national news cycle when they change.

Scaling headcount or adding a location:

  • Every new state adds its own Professional Tax registration (due within 30 days of the first hire there), its own Shops & Establishments annual return date, and often its own LWF cycle  treats a second city as a second compliance calendar, not an addendum to the first.
  • Material headcount growth can shift PF/ESI registration thresholds and, at scale, can change which transfer pricing safe harbour and the entity falls into  re-check both whenever headcount crosses a round number.

Offboarding, downsizing, or exit:

  • Employee separations must follow the applicable state Shops & Establishments and labour code notice and settlement requirements  full and final settlement timelines are a common inspection trigger if handled inconsistently.
  • Winding down a branch office requires closing out Form FC-3 obligations and RBI reporting before deregistration; winding down a subsidiary requires ROC strike-off or liquidation procedures layered on top of final tax and FEMA closure filings.
  • If the exit is an acquisition or a transfer of the India entity rather than a wind-down, FEMA share-transfer filings (Form FC-TRS) and updated FLA reporting both apply  plan for this in the deal timeline, since RBI-side filings are rarely fast enough to match an aggressive signing-to-close window.

"gcc regulatory compliance ownership models"

Case Studies

Fintech scale-up, 100+ engineer hiring program: A fintech GCC scaling past 100 engineers in India needed hiring velocity and entity-side compliance moving in lockstep  Professional Tax registrations, PF onboarding, and ESI eligibility checks all had to clear before offer-to-joining could compress to the 7–10 working day cycle the business needed. The lesson: compliance readiness is a hiring-speed input, not a parallel track.

Engineering-hiring GCC, multi-city expansion: A GCC expanding from a single Bengaluru office to a second location saw its Shops & Establishments and Professional Tax obligations effectively double overnight  two separate annual-return dates, two separate state PT registrations, two separate LWF cycles. Centralizing the compliance calendar before the second office opened, rather than after, avoided a missed first-year filing.

Recruitment-automation GCC, transfer pricing readiness: A GCC preparing for its first transfer pricing audit found that building the intercompany services agreement and local file documentation into the initial commercial contract  instead of reconstructing it retroactively  cut the audit preparation timeline from months to weeks, and avoided the kind of reconstructed documentation that invites deeper scrutiny.

Decision Framework: Compliance Ownership Models

Model Cost Control Speed to compliant operation Risk profile
In-house compliance team Highest fixed cost Full control Slowest to build (hiring + ramp) Lowest ongoing risk once mature; highest early-stage risk while ramping
Outsourced compliance (CA firm + labour law consultant) Mid, variable Shared control Fast to start Depends heavily on vendor quality and coordination across FEMA/ROC/labour silos
Employer of Record (EOR) for early-stage headcount Lowest fixed cost Lower control, faster launch Fastest  EOR already holds registrations Good for pilot-stage GCCs; limits IP and long-term entity control
GCC-setup partner managing entity + compliance handoff Mid-to-high, front-loaded High control after handoff Moderate  entity setup plus compliance build takes weeks, not months Lowest long-term risk if the handoff to an in-house or retained team is structured well

Most enterprises use a hybrid: an EOR or setup partner to launch fast, transitioning to an in-house compliance function once headcount and complexity justify the fixed cost  typically somewhere past the 50–75 employee mark.

How to apply this framework yourself: map your own GCC against three variables: expected headcount in 18 months, number of states you’ll operate in, and how sensitive your leadership is to control versus speed. A single-city, sub-50-headcount pilot almost always favors EOR or an outsourced compliance retainer. A multi-city, 100+ headcount build with its own IP and long-term roadmap almost always justifies an in-house function from month one, even if a setup partner handles the initial registrations.

What Most Teams Get Wrong

  • They treat SEZ/STPI as a tax decision only. It’s also an operational-flexibility decision  and SEZ unit’s dedicated-campus and export-obligation requirements sit uneasily with hybrid or remote-friendly working models that most GCCs now run.
  • They assume the old tax holiday still applies. Both the SEZ Section 10AA holiday and the STPI Section 10A holiday are effectively closed to new entrants started after their respective sunset dates. New GCCs compete on customs, GST, and compliance efficiency, not on an income-tax holiday that no longer exists for them.
  • They underweight state-level labour variance. Central Labour Codes get the headlines, but Professional Tax, LWF, and Shops & Establishments obligations remain fully state-specific; a compliance calendar built only around the central codes will still miss real deadlines.
  • They treat DPDP as a “when it’s enforced” problem. With a phased runway already running and penalties up to ₹250 crore, the actual work  consent architecture, breach workflows, SDF assessment  takes long enough to build that starting at the deadline is functionally starting late.
  • They build the transfer pricing file after the fact. Documentation reconstructed to match a fiscal year that already closed reads differently to an auditor than documentation built alongside the actual intercompany agreement.
  • They pick a location before pricing the compliance load. A second-city expansion doesn’t just add rent, it adds a full second set of state labour registrations and deadlines that a one-city compliance calendar was never built to hold.
  • They confuse “compliant on paper” with “audit-ready.” Filing a form on time is necessary but not sufficient. An inspector or auditor wants to see the underlying register (attendance, leave, wage computation, board resolutions) behind that filing. A GCC can be current on every deadline and still fail an inspection because supporting documentation wasn’t maintained alongside it. One recurring pattern in labour inspections of otherwise-compliant IT and GCC entities: the company was currently on income tax and GST, but received a notice purely because attendance and leave registers under the applicable Shops & Establishments Act had not been kept up to date.
  • They let the AD banking relationship become purely transactional. FEMA’s 2026 tightening expands Authorised Dealer oversight  routing advances through the same AD, AD discretion on third-party payments, SBLC or guarantee requirements for advance imports. Treating the AD bank as a filing mailbox rather than a compliance partner leaves GCCs slower to adapt when these rules shift again.

Cost & Timeline Reality Check

Setup timeline:

  • MCA incorporation, PAN, TAN, GST, Professional Tax registration: 4–8 weeks before the entity can legally employ staff.
  • Full statutory readiness (FEMA account registrations on FIRMS/FLAIR/PRAVAAH, labour registrations, initial DPDP governance groundwork): often runs in parallel with hiring, targeting readiness by the time the first cohort joins  roughly the same 7–10 working day hiring cycle most GCC talent partners quote per role, once the entity itself is live.

Ongoing annual compliance cost drivers:

  • Statutory audit, ROC filings, and FEMA filing management: typically a CA/company secretary retainer plus per-filing fees.
  • Labour compliance (PF/ESI/PT/LWF administration): scales with headcount and number of states.
  • Transfer pricing documentation: an annual local file/master file exercise, heavier in the first year of a new engagement model or after a material change in the intercompany agreement.

What drives costs up:

  • Multi-state operations (each state adds its own PT/LWF/S&E calendar).
  • SEZ election (adds NFE and export-performance reporting on top of standard filings).
  • Falling outside the transfer pricing safe harbour threshold, which increases both documentation depth and audit exposure.

What drives costs down:

  • Electing the ₹2,000 crore-threshold safe harbour where eligible (Budget 2026), trading a fixed margin for materially lower dispute risk.
  • Single-state, single-city operation in year one, consolidating the compliance calendar before expanding.
  • Building DPDP and transfer pricing documentation into initial contracts rather than retrofitting them later.

"gcc compliance requirements india cost timeline"

A rough year-one compliance cost map:

Category What it covers Cost pattern
Entity & ROC Incorporation, AOC-4/MGT-7/DIR-3 KYC, statutory audit Mostly fixed, CA/CS retainer-based
FEMA & RBI FC-GPR, FLA, FIRMS/FLAIR/PRAVAAH portal management Fixed retainer plus per-transaction filing fees
Labour & payroll PF/ESI/PT/LWF administration, Shops & Establishments returns Scales with headcount and number of states
Tax & transfer pricing Corporate tax return, local file/master file, CbCR where applicable Heaviest in year one and after any intercompany agreement change
DPDP readiness Governance setup, consent architecture, breach workflow Front-loaded one-time build, lighter maintenance after

Read this as directional, not a quote; actual figures depend on headcount, state count, and scheme election, and any firm number should come from your CA firm or GCC setup partner against your specific structure.

Getting the Setup Right the First Time

None of this compliance load is optional, and very little of it is intuitive to a team building its first India entity. The pattern across the case studies above is consistent: GCCs that build FEMA, ROC, labour, DPDP, and transfer pricing readiness into the initial entity and contract structure spend far less time and money fixing gaps in year two than GCCs that treat compliance as a follow-up task.

Supersourcing’s GCC setup practice works from the same principle: dedicated account management, NDA-backed IP protection, and a structure built around India’s actual regulatory calendar rather than a generic incorporation template. If you’re mid-decision on entity structure, scheme choice, or your first transfer pricing model, the next step is a scoped conversation, not another checklist: talk to the Supersourcing GCC team.

Frequently Asked Questions

What is a GCC and how is it different from an IT services company? 

A GCC (Global Capability Center) is a captive entity  wholly or majority owned by its foreign parent  delivering work exclusively to that parent. An IT services company serves multiple external clients. This distinction matters directly for transfer pricing, since intercompany-only revenue is priced and documented differently than third-party services revenue.

What are the mandatory ROC filings for a GCC in India? 

At minimum: an AGM within six months of financial year end, Form AOC-4 (financials) and Form MGT-7 (annual return), annual DIR-3 KYC for each director, and a statutory audit by an ICAI-registered CA. Event-based filings like Form PAS-3 apply whenever new shares are issued.

What FEMA compliances apply to a GCC set up as a subsidiary? 

Core filings include Form FC-GPR (within 30 days of share allotment), the 60-day equity allotment rule, Form FC-TRS for resident/non-resident share transfers, Form DI for downstream investment, and the annual FLA return. All are transaction- or date-triggered, so tracking has to start the moment foreign capital moves.

Is SEZ or STPI better for a GCC in India? 

Neither carries an income-tax holiday for new entrants anymore  both sunset clauses have passed. The real difference is operational: STPI allows any office location with no dedicated-campus requirement, while SEZ requires sitting inside a notified zone and meeting export-performance obligations. Choose based on operating-model flexibility, not tax alone.

How do the new Labour Codes affect GCC payroll compliance? 

The four consolidated Codes standardize the wage definition (Basic must be at least 50% of gross CTC), which can raise PF, ESI, gratuity, and leave-encashment liabilities if your current structure doesn’t already meet that ratio. State-level obligations like Professional Tax and Shops & Establishments continue unchanged alongside the Codes.

What is the DPDP Act and does it apply to GCCs? 

The Digital Personal Data Protection Act, 2023, and its 2025 Rules govern how digital personal data is collected, processed, and secured in India, with a phased compliance runway toward May 2027. It applies to most GCCs by default, since they typically process employee and often customer data connected to India.

How much does GCC compliance cost annually in India? 

It scales with headcount, number of states, and scheme choice (SEZ/STPI add reporting layers). Statutory audit, ROC filings, payroll compliance administration, and transfer pricing documentation are the four recurring cost centers; multi-state operations and falling outside the transfer pricing safe harbour threshold are the two biggest cost drivers.

What happens if a GCC misses a ROC or FEMA filing deadline? 

ROC-side, late AOC-4/MGT-7 filings draw a per-day fee, and missing an AGM triggers a flat ₹1 lakh company penalty plus ₹5,000 per officer; three consecutive years of non-filing triggers director disqualification. FEMA-side, delayed filings draw a Late Submission Fee, and continued non-compliance can constitute a formal contravention under FEMA Section 13  a more serious exposure than a late fee alone.

Author

  • Mayank Pratap Singh - Co-founder & CEO of Supersourcing

    With over 11 years of experience, he has played a pivotal role in helping 70+ startups get into Y Combinator, guiding them through their scaling journey with strategic hiring and technology solutions. His expertise spans engineering, product development, marketing, and talent acquisition, making him a trusted advisor for fast-growing startups. Driven by innovation and a deep understanding of the startup ecosystem, Mayank continues to connect visionary companies and world-class tech talent.

    View all posts

Related posts