Skip to content

107. India Legal and Compliance Stack

Legal and compliance work is not glamorous, but it is founder leverage. Clean records help you open bank accounts, collect from customers, hire properly, raise money, sell to enterprises, apply for schemes, survive diligence, and exit without chaos.

This page is a founder operating guide, not legal, tax, accounting, or investment advice. Rules change and sector-specific requirements matter. Use this to ask better questions of a CA, CS, lawyer, banker, payroll advisor, or domain expert.

Do not outsource compliance ownership. Outsource execution where needed.

You do not need to become a CA or lawyer. But you should know:

  • What filings exist.
  • Who owns each filing.
  • What the due date or trigger is.
  • What documents prove completion.
  • What happens if it is missed.
  • Where the latest source of truth lives.

A founder who cannot answer these questions may not feel the pain today. They will feel it during fundraising, enterprise procurement, tax notices, diligence, or an exit.

Most Indian startups need a basic operating stack early.

ItemFounder decision
EntityChoose the structure based on fundraising, liability, taxation, governance, and customer expectations. Many VC-funded startups use a private limited company, but this is not the only form.
PAN and TANNeeded for tax identity and deduction obligations where applicable.
GSTUnderstand whether registration is required, when to charge GST, how invoicing works, and how returns will be filed.
Bank accountKeep business and personal money separate from day one.
Accounting systemUse a tool and process that can produce monthly numbers, not only annual cleanup.
PayrollSalary, deductions, reimbursements, contractor payments, and employee records need structure.
ROC and company recordsBoard minutes, shareholder records, filings, resolutions, and registers matter.
Shops and establishmentCheck state-specific requirements based on location and nature of work.
Professional tax and labour registrationsThese vary by state and employee count; verify with advisors.
ContractsCustomer, vendor, employment, contractor, founder, advisor, and confidentiality agreements should be stored and signed properly.
IP assignmentMake sure code, designs, content, inventions, and product work belong to the company where appropriate.

The common pattern: founders delay structure because “we are early.” Then the company grows, records are scattered across email, WhatsApp, Google Drive, and someone else’s laptop. Fixing it later is painful.

DPIIT recognition under Startup India can provide access to benefits such as easier compliance routes, IPR support, tax-related schemes for eligible startups, public procurement support, and other ecosystem programs. The official Startup India portal lists current eligibility and benefits, including company type, age, turnover, original-entity, and innovation/scalability criteria.

Do not treat recognition as a vanity badge. Treat it as an operating asset if it helps with:

  • Grant or scheme applications.
  • Government or enterprise credibility.
  • Public procurement paths.
  • IPR support.
  • Tax exemption applications where eligible.
  • Incubator or state policy benefits.

Before applying, ask:

  • Does our entity type qualify?
  • Do we meet the current eligibility criteria?
  • Which benefit are we actually trying to access?
  • What documents are required?
  • Who will maintain the certificate and related records?
  • Does this affect fundraising, tax, or public procurement plans?

Government schemes can help, but founders should not build the company around schemes. Schemes are support. Customers are the business.

Build a calendar with five categories.

Possible monthly items may include bookkeeping close, payroll, GST-related work, TDS-related work, vendor payments, customer invoicing, bank reconciliation, and management reporting. The exact list depends on your structure, registrations, transactions, and state.

Quarterly work may include tax estimates, board updates, investor MIS, internal financial review, and certain return cycles depending on applicability.

Annual work can include financial statements, statutory audit where applicable, income tax filing, ROC filings for companies, board/shareholder approvals, and other entity-specific requirements.

Some compliance work is triggered by events:

  • Incorporation.
  • Issuing shares or options.
  • Raising money.
  • Changing directors.
  • Opening a new office.
  • Hiring employees in a new state.
  • Crossing a GST, employee, transaction, or sector threshold.
  • Signing large enterprise or government contracts.
  • Exporting services.
  • Collecting sensitive data.

Event-based compliance is where startups often get caught. The company changes, but the calendar does not.

Keep board minutes, cap table updates, shareholder approvals, investor consents, ESOP grants, and major contracts organized. Governance is not only for large companies. Early sloppiness becomes later diligence risk.

Create a simple folder structure:

  • Incorporation and constitutional documents.
  • PAN, TAN, GST, registrations, certificates.
  • Board and shareholder records.
  • Cap table and financing documents.
  • Customer contracts.
  • Vendor contracts.
  • Employee and contractor agreements.
  • ESOP documents.
  • IP assignments.
  • Tax filings and payment challans.
  • Financial statements and monthly MIS.
  • Policies: privacy, security, HR, expenses, procurement.

The founder test: if an investor asked for diligence documents tomorrow, could you share a clean folder without panic?

  • Treating CA/CS/lawyer work as a once-a-year cleanup.
  • Mixing founder and company expenses without records.
  • Forgetting IP assignment from freelancers, early employees, or agencies.
  • Promising ESOPs informally without proper documents.
  • Raising money before understanding board approvals, valuation paperwork, and filings.
  • Ignoring state-level registrations after hiring.
  • Discovering GST, TDS, or export documentation issues only when a customer asks.
  • Using copied contracts without understanding liability, payment terms, data, termination, or dispute clauses.

The founder does not need to personally execute every legal and compliance task, but the founder needs an advisor system that produces clarity.

At minimum, set up:

Advisor or ownerWhat they should ownFounder review rhythm
CA/accountantBooks, taxes, GST where applicable, TDS where applicable, payroll inputs, monthly close.Monthly finance review.
CS/company secretarial supportROC filings, board/shareholder records, share issuances, resolutions, registers.Monthly or event-based review.
LawyerFounder agreements, customer/vendor contracts, fundraising docs, IP, employment/contractor terms, disputes.Before signing material documents.
Payroll/HR opsEmployee records, offer letters, reimbursements, statutory deductions where applicable.Monthly payroll review.
Internal ownerCalendar, proof folder, data room, follow-ups, reminders.Weekly check until stable.

Run advisors with written questions. Do not ask only, “Is everything okay?” Ask:

  • What changed this month?
  • What filings or payments are due in the next 30 days?
  • What event triggered a new obligation?
  • What proof do we have that the task is complete?
  • What should be documented before we forget?
  • What risk are we carrying knowingly?

Good advisors reduce uncertainty. Weak advisor management turns compliance into vague reassurance.

Founders often sign whatever gets the deal done. That can be expensive later.

Prioritize these contract categories:

Before the company becomes valuable, document founder equity, roles, vesting or reverse vesting where relevant, IP assignment, decision rights, exit scenarios, and what happens if someone leaves.

The hard conversation is cheaper before success.

For paid customers, understand:

  • Scope.
  • Deliverables.
  • Payment terms.
  • Taxes.
  • Renewal.
  • Termination.
  • Liability.
  • Data access.
  • Support expectations.
  • Custom work ownership.
  • Dispute jurisdiction.

If the customer sends their own agreement, read it. Enterprise contracts can shift risk onto a small startup quietly.

Every person creating code, design, content, sales material, data, models, processes, or brand work should have clear terms. The company should know whether the work product belongs to it, what confidentiality applies, and what post-engagement obligations exist.

Contractor work without IP assignment is a common diligence problem.

Cloud, payment, CRM, analytics, payroll, email, AI tools, and support tools may handle customer data, payment data, or core operations. The founder should know where critical data lives and what happens if a vendor fails.

Fundraising creates legal work that should be planned, not rushed after a verbal commitment.

Before raising, prepare:

  • Current cap table.
  • Founder/shareholder documents.
  • ESOP plan status, if any.
  • Board/shareholder approvals needed.
  • Financial statements and MIS.
  • Customer contracts and revenue proof.
  • IP assignment documents.
  • Material liabilities and disputes.
  • Existing loans, SAFEs, notes, or side letters.
  • Data room with clean file names.

During fundraising, do not casually promise terms in email or WhatsApp that your lawyer has not reviewed. Valuation is only one part of the deal. Control, liquidation preference, anti-dilution, pro-rata rights, board rights, information rights, ESOP expansion, transfer restrictions, and founder vesting can matter more than the headline number.

If multiple small angels invest, documentation discipline matters even more. Messy angel rounds can create cap table, consent, tax, and communication problems later.

Even early startups need basic discipline if they handle customer data, employee records, financial data, health data, education data, children’s data, location data, payment data, or confidential business data.

Founder checklist:

  • What data do we collect?
  • Why do we collect it?
  • Where is it stored?
  • Who can access it?
  • How do we delete or export it if needed?
  • Which third-party tools process it?
  • What do our privacy policy and customer contracts promise?
  • What happens if data leaks?
  • What security practices do enterprise customers expect before buying?

Do not wait for a security questionnaire to discover your own systems. A simple data map, access policy, backup policy, password manager, two-factor authentication, and incident owner are better than vague confidence.

These issues slow fundraising, enterprise sales, loans, grants, acquisitions, and exits:

  • Founder equity unclear or undocumented.
  • Former contributor claims ownership of product or code.
  • Cap table does not match filings or agreements.
  • Customer revenue cannot be tied to invoices and bank receipts.
  • GST, TDS, payroll, or ROC work is unclear or delayed.
  • ESOPs promised informally.
  • Board/shareholder approvals missing.
  • Contracts signed by the wrong entity or person.
  • Personal and company expenses mixed without records.
  • Open disputes, unpaid vendors, or employee issues hidden until late.
  • Product uses third-party code, data, or AI outputs without understanding license or rights.

Diligence is not an event. It is the result of daily recordkeeping.

Use official sources and advisors for current rules:

Compliance becomes stressful when everyone assumes someone else is handling it. Create a clear ownership matrix.

AreaInternal ownerAdvisorProof to keepReview rhythm
Entity and ROCFounder or company secretary ownerCS/lawyerIncorporation docs, board minutes, filings, registersMonthly check, annual review
PAN, TAN, GSTFinance ownerCARegistrations, challans, returns, notices, repliesMonthly
Accounting and taxFinance ownerCABooks, bank reconciliation, invoices, expense records, tax workingsMonthly close
Payroll and people compliancePeople/finance ownerCA/labour advisorSalary records, offer letters, contractor agreements, statutory recordsMonthly/quarterly
ContractsFounder or legal ownerLawyerCustomer, vendor, employment, contractor, IP, data processing agreementsBefore signing and quarterly review
IP and brandFounder/product ownerLawyer/IP advisorTrademark filings, assignment deeds, contractor IP clauses, open-source notesQuarterly
Data and securityProduct/engineering ownerLawyer/security advisorData map, access review, vendor list, privacy docs, incident logQuarterly or after major change
Fundraising and governanceFounder/finance ownerLawyer/CS/CACap table, board approvals, investor docs, share filingsBefore and after each round/event

For each row, define a backup owner. Founders should not abdicate compliance to advisors. Advisors guide and file; the company owns facts, records, decisions, and deadlines.

Not every compliance item has the same urgency. Build a triage system so founders do not either ignore everything or panic about everything.

SeverityExamplesFounder response
RoutineMonthly close, standard bookkeeping, recurring returns, routine board records.Calendar, owner, proof folder.
ImportantNew customer contract, new state hiring, GST/invoice issue, ESOP grant, contractor IP.Advisor review before action, document decision.
High riskFundraise, share issuance, tax notice, employee dispute, data incident, large enterprise contract.Founder owns, qualified advisor involved, written record.
ExistentialFounder split, regulatory breach, payroll/tax default, major security incident, acquisition diligence issue.CEO/board/advisors/legal/finance war room as needed.

The triage question is simple: what happens if we get this wrong? If the answer affects ownership, cash, customer trust, employee rights, regulated activity, or future fundraising, slow down and get proper help.

Many obligations are triggered by events rather than dates. Keep this checklist close to founder decisions.

Before each event, ask your CA, CS, lawyer, or relevant advisor what changes:

  • Adding or removing a founder, director, shareholder, advisor, or key employee.
  • Issuing shares, options, convertible instruments, loans, or side letters.
  • Hiring in a new state or changing employment/contractor model.
  • Crossing revenue, invoice, employee, transaction, or sector thresholds.
  • Selling to government, enterprise, international, financial, health, education, or regulated customers.
  • Launching a product that handles money, personal data, payroll, lending, insurance, tax, legal decisions, or health data.
  • Opening a new office, warehouse, lab, field team, or physical operations.
  • Changing pricing, refunds, subscription terms, or marketplace money flow.
  • Using third-party code, datasets, AI outputs, or customer data in the product.
  • Preparing for fundraising, debt, grants, tenders, M&A, or shutdown.

The founder does not need to know every rule in advance. The founder does need to know when to ask.

Run a 30-minute monthly review with the internal owner and advisors.

Agenda:

  1. What was filed, paid, signed, issued, or changed this month?
  2. What proof is stored, and where?
  3. What is due in the next 30 and 90 days?
  4. What business event triggered a new obligation?
  5. Which customer, investor, employee, vendor, or regulator issue needs attention?
  6. What document would block fundraising or enterprise diligence if asked today?
  7. Which compliance risk is being accepted knowingly?

The review should produce a short action list with owners and dates. If the answer is always “everything is fine,” ask for evidence. Compliance comfort without proof is not a system.

Once a quarter, run a diligence drill. Pretend an investor, enterprise customer, bank, acquirer, or grant program asks for documents tomorrow.

Can you produce:

  • Incorporation and constitutional documents.
  • Current cap table and share/option records.
  • Board and shareholder approvals.
  • Founder, employee, contractor, advisor, and IP agreements.
  • Customer contracts and invoices tied to bank receipts.
  • GST, tax, payroll, ROC, and other applicable records.
  • Financial statements and monthly MIS.
  • Material vendor contracts and tool list.
  • Data/security/privacy documents where relevant.
  • Notices, disputes, or contingent liabilities.

Score each folder:

  • Green: complete and current.
  • Yellow: mostly available but needs cleanup.
  • Red: missing, unclear, or dependent on one person’s memory.

Fix the red items before you need them. Diligence stress is usually recordkeeping debt becoming visible all at once.

Founders get better outcomes from advisors when they ask precise questions.

Ask:

  • What are the current rules or official sources we should rely on?
  • What applies to us now, and what may apply after we cross a threshold?
  • What is the consequence if we miss this?
  • What document proves completion?
  • What should the board or shareholders approve?
  • What should be in the customer, employee, contractor, or vendor contract?
  • What should we avoid promising in email, WhatsApp, or pitch decks?
  • What would an investor or enterprise buyer ask during diligence?
  • What should we review again after a fundraise, revenue change, hiring change, or product change?

Good advisors should welcome specific questions. Vague reassurance is not enough for a startup that wants to grow cleanly.

Government schemes, incubator grants, state programs, tax exemptions, and public-sector opportunities can help a startup, but they should be treated as structured opportunities, not free money.

Before applying, create a scheme note:

QuestionWhy it matters
Which official page or notification describes the scheme?Avoids relying on forwarded PDFs, social posts, or outdated advice.
What entity type, age, turnover, sector, recognition, or location rules apply?Prevents wasted applications and future misrepresentation risk.
What documents are required?Reveals whether your records are clean enough.
What money, benefit, exemption, market access, or recognition is actually offered?Separates useful help from vanity badges.
What reporting, audit, usage, or milestone obligations follow?Grants can create future obligations.
Does the scheme affect fundraising, pricing, ownership, IP, hiring, procurement, or location decisions?Some benefits come with constraints.
Who internally owns the application and post-approval compliance?Prevents founder memory from becoming the system.

Do not optimize the company around schemes unless the scheme directly supports the business strategy. A grant can extend runway. It should not distort the customer, product, or market choice.

Government And Enterprise Vendor Readiness

Section titled “Government And Enterprise Vendor Readiness”

Many Indian startups want to sell to large enterprises, public-sector buyers, universities, hospitals, banks, or government departments. These buyers often ask for more than a product demo.

Prepare a vendor readiness file:

  • Incorporation documents.
  • PAN, GST, bank details, cancelled cheque, and billing details where applicable.
  • DPIIT recognition certificate if relevant.
  • MSME/Udyam or other registrations if applicable and current.
  • Board authorization or signing authority proof where needed.
  • Product brochure, scope document, and commercial proposal.
  • Standard master service agreement or terms.
  • Privacy policy, data processing terms, and security practices where relevant.
  • Customer references, case studies, or pilot outcomes.
  • Support and escalation process.
  • Insurance, certifications, or audit reports if the category requires them.
  • Invoices, payment terms, tax details, and refund/cancellation terms.

For public-sector and large-enterprise sales, ask early:

  • Is vendor registration required?
  • Is a purchase order mandatory before work starts?
  • Who signs the contract?
  • Who confirms delivery?
  • Who releases payment?
  • Does the buyer need GST invoice format, e-invoice applicability, or TDS handling?
  • Are there tender, GeM, EMD, security, local presence, or compliance requirements?
  • What documents are needed before procurement will even review you?

The sale is not only persuasion. It is operational compatibility with the buyer’s procurement system.

Founders should build an evidence pack that proves the company exists, owns what it sells, pays what it owes, and can be trusted.

Keep these folders current:

FolderContents
EntityIncorporation documents, constitutional documents, board/shareholder records, registers.
Tax and financePAN, TAN, GST, returns, challans, financial statements, MIS, bank reconciliation.
PeopleOffer letters, contractor agreements, consultant agreements, payroll records, exits, invention/IP assignment language.
Product and IPCode ownership, contractor assignments, trademarks, licenses, open-source notes, design/source files.
CustomersContracts, purchase orders, invoices, receipts, delivery proof, support commitments, renewals.
VendorsVendor contracts, invoices, data/security notes, cancellation terms, payment obligations.
Data and securityData map, access list, privacy policy, vendor processors, incident log, backup notes.
FundraisingCap table, term sheets, SHA/SSA documents, side letters, approvals, filings, investor updates.

Set a rule: every material business event creates a document trail within seven days. If the document is missing, the event is not operationally complete.

Compliance Mistakes That Feel Harmless Early

Section titled “Compliance Mistakes That Feel Harmless Early”

These mistakes rarely hurt on day one, but become expensive during fundraising, enterprise sales, exits, disputes, or shutdown:

  • Paying contributors informally without IP assignment.
  • Promising ESOPs in chats before creating proper documents.
  • Mixing founder personal expenses and company expenses.
  • Using one GST invoice pattern for every type of sale without checking facts.
  • Signing customer contracts under the wrong entity name.
  • Letting one founder hold all statutory, bank, and portal access.
  • Assuming a CA, CS, or lawyer has done something without storing proof.
  • Ignoring state-level hiring, shop/establishment, professional tax, or labour triggers.
  • Selling regulated workflows without checking whether the startup needs approvals, licenses, or partner arrangements.
  • Using customer data in demos, AI tools, analytics, or training without understanding consent and contract promises.

The fix is not to become slow. The fix is to create small habits: ask before material actions, store proof, review monthly, and escalate early.

Founder Control Without Founder Bottleneck

Section titled “Founder Control Without Founder Bottleneck”

The founder should not personally do every compliance task forever. But the founder must understand the system well enough to ask sharp questions.

Use this delegation model:

StageFounder roleAdvisor/internal role
Pre-revenueLearn basics, choose advisors, create proof folders.Set up entity, tax, accounting, contracts.
Early revenueReview monthly close, contracts, invoices, collections, filings.Execute filings, bookkeeping, payroll, tax, contract review.
Fundraising or enterprise salesOwn diligence quality and risk decisions.Prepare documents, filings, opinions, cleanup, negotiation support.
ScaleEnsure internal owners, controls, board reporting, audit rhythm.Run recurring processes and flag exceptions.

Delegation is healthy when the founder can answer: what is due, who owns it, what proof exists, and what risk remains?

India compliance guidance changes, and founder memory goes stale. Treat official portals and professional advisors as the source of truth, not old WhatsApp forwards, investor anecdotes, or a template copied from another startup.

Create a review rhythm:

AreaSource-of-truth habitOwner
Entity and filingsVerify due dates, forms, and status with MCA/professional support.CS/founder/finance owner
Tax and GSTVerify registration, returns, notices, invoice treatment, and payment status.CA/finance owner
Payroll and labour triggersVerify state, employee, contractor, benefits, and professional-tax obligations.HR/finance/advisor
Startup recognition and schemesVerify eligibility and benefits on current official Startup India/DPIIT materials.Founder/ops owner
Payments or regulated activityVerify RBI/sector rules and whether partner/license requirements apply.Founder/legal/domain expert
Data and privacyVerify customer promises, consent, retention, vendor use, and security responsibilities.Founder/legal/security owner

Every quarter, ask three questions:

  1. Which compliance assumption are we relying on?
  2. Which official source or advisor confirmed it?
  3. Where is the proof stored?

Do not make the review theatrical. Make it boring. Boring compliance is good. The problem is not that founders miss obscure edge cases; it is that they often miss ordinary proof, ownership, and documentation until a customer, investor, bank, or regulator asks for it.

If advice changes, record the change:

Topic:
Old understanding:
New understanding:
Source/advisor:
Date:
Action required:
Owner:
Proof stored at:

This habit protects the founder from both overconfidence and paralysis. You do not need to become a lawyer. You do need to know which questions deserve professional review and where the answer lives.

Many compliance problems start as casual claims: a line on a website, a sentence in a proposal, a checkbox in a vendor form, a promise in a WhatsApp message, or a confident answer during enterprise procurement. Later, the company discovers that the claim was incomplete, outdated, or unsupported by documents.

Keep a compliance claim ledger for any statement that affects trust, security, tax, data, employment, IP, or regulated activity.

ClaimWhere it appearsProof neededOwnerReview date
”We are GST registered”Invoice, proposal, website, vendor formRegistration, return status, invoice format reviewFinance/CA
”Customer data is secure”Website, enterprise form, sales deckData map, access rules, vendor list, security controlsFounder/security owner
”All IP is owned by the company”Investor data room, customer contractFounder assignments, contractor agreements, employee clausesFounder/legal
”We comply with applicable laws”Contract, procurement documentAdvisor review of the actual obligationLegal/advisor
”We are eligible for a scheme or benefit”Investor update, customer pitchCurrent official source and eligibility proofFounder/ops
”Our team members are contractors”Payroll, contracts, tax treatmentAdvisor-confirmed classification and documentsFinance/HR/advisor

Use three labels:

LabelMeaningFounder action
VerifiedCurrent proof exists and is stored.Use the claim as written.
Needs reviewClaim may be true, but proof or wording needs advisor/source confirmation.Do not use in high-stakes settings until reviewed.
Do not claimThe company cannot currently support it.Remove from deck, website, form, or sales script.

This is especially important for enterprise sales, regulated customers, fintech, healthtech, edtech, HR/payroll, payments, AI workflows using customer data, government tenders, and cross-border business. In those cases, a casual claim can create contract risk, trust damage, or diligence friction.

The rule is simple:

If a claim helps us win trust, we should be able to show why it is true.

The ledger should be reviewed before fundraising, large customer proposals, government applications, security questionnaires, public launches, and major website rewrites.

Do not manage India compliance only by month. Some obligations are triggered by events: hiring, issuing shares, raising money, changing directors, signing leases, crossing revenue thresholds, expanding states, collecting GST, importing/exporting, or handling sensitive data.

Create a trigger calendar:

TriggerWho should be toldEvidence to create
New employee or contractorCA/payroll, HR owner, founderOffer, contract, payroll setup, tax documents, IP assignment.
New customer contractFinance, legal, delivery ownerSigned agreement, invoice terms, GST treatment, data/security obligations.
New state or officeCA/CS, operationsShops and establishment, professional tax, local registrations where applicable.
Equity issuance or fundraiseCS, lawyer, financeBoard/shareholder approvals, filings, cap table, bank evidence.
ESOP grant or exerciseCS, finance, HRPlan approvals, grant letters, vesting, exercise records, tax notes.
New regulated product flowLawyer, compliance advisor, product ownerRegulatory assessment, terms, consent, risk review.
Government scheme or grant applicationFounder, finance, advisorEligibility proof, application, reporting obligations.

The founder does not need to become a compliance expert. But the founder must make sure the team knows when to call the expert.

A CA or CS relationship works better when the founder gives context instead of forwarding random documents at the last minute. Create a one-page operating brief and update it quarterly.

AreaWhat to share
Business modelHow the company makes money, invoices, collects, refunds, and recognizes revenue.
Entity and ownershipEntity details, directors, shareholders, ESOP pool, investor rights.
TeamEmployees, contractors, consultants, state locations, payroll changes.
FundraisingPast rounds, planned rounds, instruments, foreign investors if any.
Customer typesIndia, export, enterprise, government, marketplace, consumer, regulated sector.
SystemsAccounting, payroll, invoicing, payment gateway, expense tools.
Upcoming eventsHiring, office move, fundraise, ESOP grant, big contract, new product, international expansion.

Ask advisors for a risk list, not only filings:

What are the top five compliance or tax risks in our current operating model, and what evidence should we maintain?

That single question often improves the relationship more than another status call.

Investors and acquirers often discover governance gaps late: missing approvals, unsigned minutes, unclear share records, unrecorded options, delayed filings, or mismatched cap tables. Build an evidence pack early.

Keep these records organized:

RecordWhy it matters
Board minutes and resolutionsShows decisions were approved properly.
Shareholder approvalsSupports equity, ESOP, major transactions, and reserved matters.
Cap table historyExplains ownership changes over time.
Share certificates and registersSupports legal ownership evidence.
ESOP plan, grants, vesting, exercisesPrevents employee and diligence confusion.
ROC filing proofsShows statutory actions were completed.
Investor rights and side lettersPrevents surprises during future rounds or exits.

Review the pack before every financing, major ESOP grant, director change, or acquisition conversation. Governance hygiene is cheaper before diligence than during diligence.

Some Indian startup categories carry higher regulatory, compliance, data, licensing, or trust burden from the beginning. Founders should not discover this after building the product, signing customers, or raising money.

Create an early warning system if the startup touches:

AreaWhy to slow down
Money movement, lending, investing, insurance, payroll, tax, accountingFinancial regulation, customer money, reporting, dispute, and liability risk.
Health, diagnostics, medical advice, patient dataSafety, privacy, clinical, and trust risk.
Education outcomes, children, exams, credentialsConsumer protection, claims, data, and reputational risk.
Employment, background checks, HR decisionsPrivacy, discrimination, consent, and documentation risk.
Government, public-sector, tenders, subsidiesEligibility, procurement, reporting, anti-corruption, and documentation risk.
AI using customer data or making recommendationsData handling, accuracy, auditability, and responsibility risk.
Marketplaces with sellers, buyers, payments, logistics, or refundsContract, tax, consumer, dispute, and platform liability risk.

For any high-risk area, write a regulatory question memo:

What exact activity are we performing?
Whose money/data/safety/rights are affected?
Are we advising, enabling, processing, storing, recommending, or deciding?
What licenses, terms, consents, disclosures, or controls might apply?
What claims must we avoid until verified?
Which advisor should review this before launch?
What evidence should we maintain?

This memo is not a substitute for legal advice. It is how the founder asks better questions before mistakes become expensive.

Add compliance review at product checkpoints:

CheckpointQuestion
Idea stageAre we entering a regulated or high-trust category?
MVP stageWhat data, money, claims, or decisions are involved?
Pilot stageWhat should the customer agree to before using it?
Launch stageAre website claims, pricing, terms, and support promises accurate?
Scale stageDo contracts, data practices, filings, and support processes still match reality?

The founder should make compliance visible without making the company slow. A short review at the right time beats panic during diligence or after a customer escalates.

Legal hygiene is mostly boring until it is not. The goal is not to make a young startup bureaucratic. The goal is to avoid preventable ambiguity.

Use these rules:

RuleWhy it matters
Put important promises in writingPrevents memory-based disputes.
Keep signed versions, not only editable draftsDiligence needs evidence.
Separate founder, company, and customer moneyAvoids tax, accounting, and trust confusion.
Assign IP from founders, employees, contractors, and agenciesProtects the product and valuation.
Record equity and ESOP decisions properlyPrevents painful cleanup later.
Review public claims before launchMarketing can create legal risk.
Maintain advisor notes with datesShows what was checked and when.

Before filing away any important decision, ask:

If an investor, acquirer, auditor, government department, or angry counterparty asked for proof two years from now, what would we show?

If the answer is “we would explain it,” create better evidence now. Explanations are weaker than records.

India compliance is not only national. State, sector, customer type, employee location, data type, and payment model can change the obligation set. Founders should not memorize every rule, but they should know when to ask better questions.

Use this triage:

TriggerWhat to check
Hiring employees in a new stateShops and establishment, professional tax, payroll, leave, local registrations.
Selling to regulated sectorsSector-specific licenses, data rules, customer procurement, audit expectations.
Handling payments, lending, insurance, securities, or walletsFinancial regulation, RBI/partner obligations, KYC, risk, customer disclosures.
Working with health, education, children, or sensitive dataPrivacy, consent, safety, security, sector rules, customer contract duties.
Selling to government or PSUsTender terms, registrations, earnest money, performance obligations, dispute terms.
Receiving foreign money or paying foreign vendorsFEMA, tax withholding, invoicing, bank documentation, transfer pricing questions.
Opening offices or field teamsLocal registrations, employment records, expense policies, device/data controls.

Ask this before launching a new segment, state, or regulated workflow:

Does this change create a new legal, tax, employment, data, payment, or sector obligation that was not present in our first market?

If yes, add the question to the advisor queue before the launch, not after a customer, employee, investor, or government notice forces the issue.

Founders often ask a CA, CS, lawyer, payroll vendor, or compliance advisor a question in a call and then lose the answer in memory. That creates risk later because nobody knows what was checked, what was assumed, and what evidence was kept.

Create an advisor handoff tracker:

QuestionAdvisorContext sharedAdvice receivedAction ownerEvidence storedReview trigger
GST treatment for new product packagePricing, invoice flow, customer typeProduct/pricing change
ESOP grant processBoard approval, employee list, plan docsNew grant cycle
Contractor IP assignmentContract, scope, country, payment termsNew contractor/vendor
New state hiring complianceEmployee location, role, payroll setupFirst hire in state

Use this note after every material advisor conversation:

Question asked:
Facts shared:
Advisor response:
What we decided:
Documents/evidence to store:
Owner:
Next review trigger:

This is not a replacement for professional advice. It is how the founder prevents professional advice from becoming vague folklore. Good records also make future advisors, investors, acquirers, and internal operators more confident.

Create a compliance owner table with columns: item, owner, advisor, frequency, proof, next due date, and risk if missed. Fill it for your entity, GST, accounting, payroll, contracts, IP, board records, and tax. Review it monthly until it becomes boring.