This article is written by Shylet Nyamupinga, MVN University.

For decades, Indian businesses operated under a criminal justice framework built around the Indian Penal Code, 1860 (IPC), the Code of Criminal Procedure, 1973 (CrPC), and the Indian Evidence Act, 1872. On 1 July 2024, this framework underwent a historic transformation with the introduction of the Bharatiya Nyaya Sanhita, 2023 (BNS), the Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS), and the Bharatiya Sakshya Adhiniyam, 2023 (BSA). These laws replaced the IPC, CrPC, and Evidence Act respectively, marking one of the most significant legal reforms in independent India.
Many businesses mistakenly assume that criminal laws concern only law enforcement agencies and criminal lawyers. In reality, modern businesses frequently encounter issues involving fraud, cybercrime, data misuse, breach of trust, forgery, financial misconduct, employee offences, and digital evidence. The new criminal laws directly affect how companies investigate misconduct, preserve records, report offences, and defend themselves in legal proceedings.
Understanding these reforms is no longer optional. It has become a critical aspect of corporate governance, risk management, and regulatory compliance.
Keywords
Bharatiya Nyaya Sanhita, Bharatiya Nagarik Suraksha Sanhita, Bharatiya Sakshya Adhiniyam Corporate Compliance Cybercrime
The Shift from Colonial Laws to a Modern Criminal Framework
The new criminal laws were introduced with the objective of modernising India’s justice system and addressing challenges created by technology-driven crimes and contemporary business practices. The BNS replaced the IPC, while the BNSS and BSA modernised criminal procedure and evidence rules.
Unlike the previous framework, the new laws place greater emphasis on digital records, electronic evidence, organised crime, cyber-enabled offences, and efficient investigation procedures. For businesses operating in an increasingly digital economy, these developments are highly significant.
The legal environment in which companies operate today is substantially different from that of even a few years ago. Business leaders who fail to understand these changes may expose their organisations to avoidable legal and financial risks.
Why Businesses Can No Longer Ignore Criminal Law Compliance
Many corporate disputes that begin as commercial disagreements can eventually trigger criminal liability.
Consider the following examples:
- A finance executive manipulates company accounts.
- A contractor creates forged invoices.
- Customer data is leaked due to negligent handling.
- Employees engage in online fraud using company systems.
- Corporate funds are misappropriated.
- Digital records are altered during an internal investigation.
In each of these situations, criminal law implications may arise alongside civil liability.
The new legal framework expands the importance of digital evidence and strengthens procedural mechanisms for investigation. As a result, businesses must ensure that internal compliance systems are capable of responding to criminal law issues promptly and effectively.
Digital Evidence Has Become More Important Than Ever
One of the most significant reforms for businesses is the enactment of the Bharatiya Sakshya Adhiniyam, 2023.
Modern business operations generate enormous volumes of electronic records, including:
- Emails
- WhatsApp communications
- Cloud storage records
- Digital contracts
- Electronic invoices
- CCTV footage
- Financial software logs
Under the new framework, electronic evidence has gained greater recognition and relevance in legal proceedings. Businesses must therefore ensure that digital records are maintained properly and preserved in a manner that supports their admissibility in court.
A company that cannot produce reliable digital evidence may struggle to defend itself against allegations or establish the truth during investigations.
Organised Crime Provisions and Corporate Exposure
The Bharatiya Nyaya Sanhita introduces specific provisions addressing organised crime and related criminal activities. These provisions represent a significant development because organised criminal conduct is no longer viewed solely as a traditional law enforcement concern.
Businesses must conduct enhanced due diligence before engaging with:
- Vendors
- Third-party contractors
- Agents
- Consultants
- Supply-chain partners
Failure to identify unlawful activities within business networks can expose organisations to reputational damage, regulatory scrutiny, and criminal investigations.
Corporate leaders must therefore understand not only their own operations but also the risks associated with external stakeholders.
Cybercrime Is Now a Boardroom Issue
Cybercrime has evolved from a technical concern into a legal and business risk.
Indian businesses increasingly face:
- Phishing attacks
- Data theft
- Ransomware incidents
- Identity fraud
- Payment diversion schemes
- Intellectual property theft
The new criminal law framework acknowledges the growing importance of technology-related offences and strengthens the legal response to such conduct. Businesses that fail to implement cybersecurity measures may face severe financial losses, operational disruption, and legal consequences.
Directors and management teams can no longer treat cybersecurity as merely an IT department responsibility. It is now a matter of corporate governance.
Increased Importance of Internal Investigations
When allegations of misconduct arise, businesses often conduct internal investigations before approaching law enforcement agencies.
Under the new legal framework, internal investigations require careful handling because improperly collected evidence can weaken a company’s position.
Organisations should establish procedures for:
- Preserving electronic records
- Conducting employee interviews
- Maintaining chain of custody
- Reporting suspected offences
- Cooperating with authorities
A structured response can significantly reduce legal exposure and strengthen a company’s credibility during official investigations.
Corporate Fraud and Criminal Breach of Trust
Financial misconduct remains one of the most common risks faced by businesses.
Fraud may involve:
- False accounting entries
- Embezzlement
- Misappropriation of funds
- Procurement fraud
- Insider misconduct
- Falsification of records
The BNS continues to address offences involving criminal breach of trust, conspiracy, cheating, and misappropriation, all of which remain highly relevant to corporate operations.
Businesses should regularly review internal controls, segregation of duties, and audit mechanisms to detect and prevent such misconduct before it escalates into criminal proceedings.
Procedural Changes Businesses Must Understand
The Bharatiya Nagarik Suraksha Sanhita introduces procedural reforms designed to improve efficiency and incorporate technology into criminal investigations. These include greater use of digital processes, electronic communication, and modern investigation techniques.
For businesses, this means:
- Faster reporting mechanisms.
- Increased reliance on electronic documentation.
- Greater emphasis on digital record-keeping.
- More structured investigative procedures.
Recent judicial decisions have also emphasized that proceedings initiated after the implementation of the new laws must comply with the BNSS framework.
Corporate legal teams must therefore familiarise themselves with procedural requirements under the new regime.
The Cost of Ignoring the New Laws
Businesses that fail to adapt may encounter several challenges:
Regulatory Risk: Failure to comply with legal obligations can attract investigations and penalties.
Financial Loss: Fraud, cybercrime, and data breaches can result in significant economic damage.
Reputational Harm: Public confidence can decline rapidly when allegations of criminal misconduct emerge.
Litigation Costs: Criminal proceedings often involve substantial legal expenses and management time.
Operational Disruption: Investigations can affect business continuity and stakeholder relationships.
Understanding the new criminal laws helps organisations anticipate these risks and implement appropriate safeguards.
Case Laws
Central Inland Water Transport Corporation Ltd. v. Brojo Nath Ganguly (1986)
The Supreme Court held that contractual provisions that unfairly exploit unequal bargaining power may be struck down. Although primarily a contract law case, it remains relevant for businesses because it highlights judicial concern regarding unfair corporate practices.
Pioneer Urban Land and Infrastructure Ltd. v. Govindan Raghavan (2019)
The Supreme Court ruled against one-sided contractual clauses imposed by builders on consumers. The judgment reinforced the principle that businesses must operate fairly and responsibly when exercising contractual power.
Bombay High Court on BNS and Predicate Offences under PMLA (2025)
The Bombay High Court clarified that offences under the BNS corresponding to scheduled offences under earlier laws can continue to support proceedings under the Prevention of Money Laundering Act. This demonstrates the continuing importance of corporate compliance under the new criminal law framework.
Conclusion
India’s new criminal laws are not merely legislative replacements for older statutes. They represent a broader shift toward a modern, technology-oriented, and accountability-focused justice system.
For businesses, these reforms create both responsibilities and opportunities. Companies that understand the new framework can strengthen compliance systems, improve risk management, protect digital assets, and respond effectively to legal challenges.
The greatest mistake a business can make is assuming that criminal law belongs exclusively to courts and police stations. In today’s environment, criminal law influences contracts, cybersecurity, employee conduct, financial governance, digital evidence management, and corporate reputation.
Every business, regardless of size, must therefore view legal awareness as an essential component of sustainable growth. Those who adapt early will be better positioned to navigate India’s evolving legal landscape with confidence.
Frequently Asked Questions
1. What are the three new criminal laws in India?
They are the Bharatiya Nyaya Sanhita, 2023 (BNS), Bharatiya Nagarik Suraksha Sanhita, 2023 (BNSS), and Bharatiya Sakshya Adhiniyam, 2023 (BSA). They replaced the IPC, CrPC, and Indian Evidence Act.
2. Why should businesses care about these laws?
Because they affect fraud investigations, cybercrime, digital evidence, employee misconduct, compliance obligations, and corporate risk management.
3. How do the new laws impact digital evidence?
Electronic records such as emails, digital contracts, cloud data, and electronic communications now play a central role in investigations and legal proceedings.
4. Can companies face criminal liability for employee misconduct?
Yes. Depending on the circumstances, companies may face investigations, regulatory scrutiny, or reputational consequences arising from employee actions.
5. What is the biggest compliance challenge under the new laws?
The effective management of digital evidence, cybersecurity risks, and internal investigations is likely to be one of the most significant challenges for modern businesses.


