Compliance is the part of HR nobody wants to own. It's invisible when it works and expensive when it doesn't. There's no dashboard your CEO checks to see how compliant you are this month. You only find out you got it wrong when a notice arrives, or an employee's PF doesn't show up where it should, and by then the mistake is already a few months old.
This guide is about the software that's supposed to take that worry off your plate. What HR compliance software actually does, which Indian statutory rules it needs to handle, and how to tell a system that genuinely keeps you compliant from one that just calculates a few deductions and calls it a day.
If you're still deciding whether to buy an HR system at all, start with our longer buyer's guide. This piece assumes you're past that and want to get the compliance part right.
What "HR Compliance" Actually Means Here
Strip away the jargon and compliance is one thing: doing what the law requires for every person you employ, and being able to prove you did it. In India that mostly breaks into three buckets.
There's statutory payroll, the deductions and contributions the government mandates, PF, ESI, professional tax, TDS on salary, and the returns you file for each. There's labour law, minimum wages, working hours, leave entitlements, gratuity, bonus, and the registers you're supposed to maintain under various Acts. And there's workplace compliance, things like POSH (the anti-sexual-harassment law), which needs a committee, an annual report, and records whether or not you ever have a complaint.
Software mainly helps with the first two, and increasingly with the paperwork side of the third. The thing to understand is that most of this applies from your very first employee in many states, not once you cross some comfortable headcount. Compliance isn't a big-company problem you'll grow into. It's there on day one.
Why Compliance Is the Part That Bites Hardest
Most HR mistakes are annoying but recoverable. A leave balance is wrong, you fix it, the employee grumbles, everyone moves on. Compliance mistakes are different, because a third party with the power to fine you is keeping score, and they don't send reminders.
Miss a PF deposit and the penalty isn't just the amount you owe. There's interest, and there's damages on top, which can run as high as the contribution itself for a long delay. Get an ESI applicability call wrong and you can be liable for contributions going back months, plus interest, discovered during an inspection you didn't schedule. Deduct the wrong TDS and it's the employee who feels it first, at filing time, in the worst possible way, right when they're expecting a refund and getting a demand instead.
The quiet damage is worse than the fines, though. Compliance mistakes erode trust in a way that's hard to win back. An employee whose PF isn't getting deposited, or whose Form 16 doesn't tally with their payslips, stops believing the company has its act together, and that belief is expensive to rebuild. This is exactly why compliance ROI works like insurance. Invisible right up until the day it very much isn't.
The Indian Statutory List, in Plain English
Here's what a system needs to handle for an Indian company, without the legalese. You don't need to become an expert in any of these, but you should recognise the names when a vendor claims to cover them.
PF (Provident Fund). Applies once you hit 20 employees, and often earlier if you opt in. Both you and the employee contribute 12% of basic wages. The software should calculate it, generate the monthly ECR file for the EPFO portal, and keep track of the wage ceiling and the members' details. Getting the basic-wage definition right here is where a lot of systems quietly go wrong.
ESI (Employees' State Insurance). Applies at 10 employees in most states, for anyone earning up to ₹21,000 a month. You contribute 3.25%, the employee 0.75%. Whether someone is "in" or "out" of ESI changes the moment their salary crosses the threshold, and the software needs to handle that mid-cycle without you doing the maths by hand.
Professional Tax (PT). This one is state-specific, and that's the catch. Maharashtra, Karnataka, West Bengal, Tamil Nadu and others each have their own slabs, their own due dates, their own forms. A company with staff in three states has three different PT rules running at once. Software that only knows one state's slab isn't compliance software, it's a calculator.
TDS on salary. You deduct income tax across the year based on each employee's declared investments and chosen regime, deposit it monthly, file quarterly returns (Form 24Q), and issue Form 16 at year-end. The hard part isn't the deduction, it's keeping the old and new tax regimes, the investment declarations, and the proof-of-investment stage all lined up so the year-end numbers actually tally.
The smaller ones that still matter. Labour Welfare Fund (LWF), again state-specific and easy to forget. Gratuity, payable after five years of service, which you should be tracking as a liability long before anyone qualifies. Bonus under the Payment of Bonus Act. Minimum wages, which vary by state, skill level and sometimes district, and get revised more often than people expect. None of these are optional, and all of them are the kind of thing that slips when one person is tracking it in their head.
If you want the full mechanics of how these deductions and filings work, our Indian payroll compliance guide goes deeper than this section can. Here we're staying on what the software should do about them.
What Compliance Software Should Actually Do
Good compliance software does four things, and it's worth being strict about all four.
It calculates every statutory deduction correctly, from the same attendance and salary data your payroll already runs on. This matters more than it sounds. If compliance figures come from a separate sheet that someone updates by hand, you've built the exact gap where errors live. The number that goes into PF should be the same number payroll used, automatically, with no retyping.
It generates the actual files you have to submit, not just the amounts. There's a real difference between software that tells you "PF payable this month is ₹X" and software that hands you the ECR text file ready to upload to the EPFO portal, the ESI contribution file, the Form 24Q return, the PT challan for each state. The first still leaves the hard, error-prone part to you. Ask to see the actual output files in the demo, not a summary screen.
It keeps the registers and records the law expects you to maintain. Muster rolls, wage registers, the POSH annual report, statutory registers under the various Acts. Most companies discover these exist only when an inspector asks, and then spend a frantic week reconstructing them. Software that maintains them quietly in the background is doing real work you won't notice until the day you need it.
And it stays current when the rules change, without waiting for you to notice. This is the one that separates real compliance software from a spreadsheet with formulas. Wage ceilings move, PT slabs get revised, a new labour code section gets notified, and someone has to update the logic. With good software that someone is the vendor, and it happens before the deadline, not after you've filed wrong. Ask directly: when did they last ship a compliance update, and what was it? A vague answer is an answer.
The New Labour Codes, and Why "Kept Current" Matters
India spent years consolidating dozens of old labour laws into four codes, on wages, on social security, on industrial relations, and on occupational safety. These came into force at the centre in late 2025, with states still finalising their own rules through 2026, so this isn't a "someday" change any more, it's landing on payrolls now. A few things shift in ways that hit payroll directly.
The big one is the definition of "wages." The codes set a floor where basic pay plus DA must be at least 50% of total pay, so if your allowances run higher than that, the excess gets pulled back into wages for statutory purposes. Either way, basic wage goes up for a lot of companies, which means PF and gratuity contributions go up with it. That's not a small tweak. It changes the cost of every salary you run, and it changes the numbers you file.
You don't need to track the notification dates yourself, and honestly you shouldn't try. This is precisely the work you're paying compliance software to absorb. When the rules shift, your system's logic should shift with them, pushed by the vendor, and your only job should be to notice your payroll numbers moved and understand why. If a vendor can't tell you clearly how they're handling the wage-code transition, that tells you how they'll handle the next change too.
Your Compliance Checklist Before You Buy
Run any system you're considering through these questions before you sign. Get the answers in writing, not in a sales conversation you'll forget the details of.
Does it handle every state you operate in? Not "India," specifically your states. PT and LWF are state-by-state, and a system that's solid in Karnataka may know nothing about West Bengal's slabs. Name your states and make them confirm each one.
Does it generate the actual filing files? ECR for PF, the ESI file, Form 24Q, PT challans. Ask to see a real one on screen. "We support PF" and "here's the ECR file you upload" are different levels of support.
How do mid-cycle changes get handled? An employee crosses the ESI ceiling, or joins mid-month, or their basic changes. The software should sort the applicability out on its own. Make them show you.
When did they last ship a compliance update? A specific recent date is the right answer. "Our team keeps it updated" is not.
Does it maintain statutory registers? Wage register, muster roll, the POSH report. If an inspector walked in next week, could you produce these from the system in an afternoon, or would you be rebuilding them from scratch?
Who's liable if the calculation is wrong? Read this clause carefully. Most vendors give you the tool but keep the liability on you, which is normal, but you should know exactly where you stand before, not after.
This checklist is also the answer to the single most common compliance mistake, which is assuming the software handles all this and never actually confirming it. Confirm it.
What It Costs, and What a Mistake Costs
Compliance is rarely priced as a separate line. It's usually baked into an HRMS or payroll subscription, somewhere in the ₹40 to ₹120 per employee per month range depending on what else you're buying. For most companies it adds little or nothing on top of payroll, because the two share the same data anyway.
Now weigh that against the other side. A single missed PF filing can attract interest plus damages that run into the tens of thousands, sometimes more than a full year of the software. A wrong ESI applicability call, discovered in an inspection, can mean back-contributions across every affected employee for months. And the audit that follows a red flag costs you something no invoice shows, which is the days your finance and HR people spend reconstructing records instead of doing their jobs.
Do the maths the honest way. The software isn't buying you a feature. It's buying down the odds of a mistake whose downside is many times its annual cost. That's the whole case, and for compliance it's an easy one to make.
Mistakes Companies Make With Compliance
The most common one, by a distance: assuming compliance is handled without ever asking, in writing, which filings the system actually produces for the states you operate in. Vendors say "fully compliant" the way restaurants say "fresh." Make them be specific.
Close behind is running payroll and compliance off different data. The moment your statutory figures come from a separate sheet that someone maintains by hand, you've recreated the problem the software was meant to solve, and you've put it in the highest-stakes place possible.
Then there's treating it as a big-company concern. PF at 20 employees, ESI at 10, PT and TDS from your first payslip in many states, these thresholds arrive earlier than founders expect, and "we'll sort compliance out once we're bigger" is how the back-dated liability starts quietly accruing.
A quieter one is forgetting the non-payroll side entirely. POSH needs a committee and an annual report whether or not you've ever had a complaint. Statutory registers need maintaining whether or not anyone's asked to see them. These don't show up in payroll software's headline features, so they get missed, right up until an inspection makes them urgent.
And the last one is buying for today's rules and never revisiting. The labour codes are changing the ground under everyone's feet. A system that was compliant when you bought it isn't automatically compliant two years later. That's exactly why "kept current by the vendor" belongs on your must-have list, not your nice-to-have one.
Questions People Ask
Isn't my payroll software already handling compliance?
Partly, usually. Most payroll tools calculate PF, ESI and TDS. The gap is often in the filing files, the state-specific pieces like PT and LWF, the statutory registers, and staying current when rules change. Confirm all of those specifically rather than assuming "payroll" covers the whole of "compliance."
Do I need separate compliance software?
Rarely. Compliance works best built into the same system that runs your attendance and payroll, because it needs the same data. A standalone compliance tool sitting beside your payroll usually just recreates the data gap. Look for one system that does both.
We operate in multiple states. Does that change things?
A lot. PT, LWF and minimum wages all vary by state, and some have their own registers and due dates. Multi-state is exactly where cheap tools fall down. Name every state you operate in and make the vendor confirm each one before you sign.
What happens to my old compliance records when I switch systems?
This is worth asking before you migrate. You want your historical filings, challans and Form 16s either carried over or exportable and safely stored, because you may need them years later during an assessment. Don't let them get stranded in a system you're leaving.
How do I know the software is keeping up with the labour codes?
Ask when they last shipped a compliance update and what it covered. Ask specifically how they're handling the new wage definition. A vendor who answers both clearly is doing the work. A vague answer usually means you'll be the one who notices the rule changed, which defeats the point.
Where This Leaves You
Compliance is the quietest part of HR software and the one with the sharpest downside. You don't need to become an expert in PF ceilings or PT slabs. You need a system that calculates them correctly, hands you the actual files to submit, keeps the records the law expects, and updates itself when the rules move, all from the same data your payroll already runs on.
Before you buy, run the checklist. Name your states. Ask to see a real filing file, not a summary. Ask when the last compliance update shipped. Get the answers in writing. Those few questions separate software that genuinely protects you from software that just does arithmetic.
If you'd like to see how Engage handles statutory compliance for your specific states and headcount, book a free demo and bring the states you operate in. Twenty minutes of watching it generate a real ECR file tells you more than any "fully compliant" claim on a pricing page.

