107. India Legal and Compliance Stack
Legal and compliance work is not glamorous, but it is founder leverage. Clean records help you open bank accounts, collect from customers, hire properly, raise money, sell to enterprises, apply for schemes, survive diligence, and exit without chaos.
This page is a founder operating guide, not legal, tax, accounting, or investment advice. Rules change and sector-specific requirements matter. Use this to ask better questions of a CA, CS, lawyer, banker, payroll advisor, or domain expert.
The Founder Principle
Section titled “The Founder Principle”Do not outsource compliance ownership. Outsource execution where needed.
You do not need to become a CA or lawyer. But you should know:
- What filings exist.
- Who owns each filing.
- What the due date or trigger is.
- What documents prove completion.
- What happens if it is missed.
- Where the latest source of truth lives.
A founder who cannot answer these questions may not feel the pain today. They will feel it during fundraising, enterprise procurement, tax notices, diligence, or an exit.
Core Setup
Section titled “Core Setup”Most Indian startups need a basic operating stack early.
| Item | Founder decision |
|---|---|
| Entity | Choose the structure based on fundraising, liability, taxation, governance, and customer expectations. Many VC-funded startups use a private limited company, but this is not the only form. |
| PAN and TAN | Needed for tax identity and deduction obligations where applicable. |
| GST | Understand whether registration is required, when to charge GST, how invoicing works, and how returns will be filed. |
| Bank account | Keep business and personal money separate from day one. |
| Accounting system | Use a tool and process that can produce monthly numbers, not only annual cleanup. |
| Payroll | Salary, deductions, reimbursements, contractor payments, and employee records need structure. |
| ROC and company records | Board minutes, shareholder records, filings, resolutions, and registers matter. |
| Shops and establishment | Check state-specific requirements based on location and nature of work. |
| Professional tax and labour registrations | These vary by state and employee count; verify with advisors. |
| Contracts | Customer, vendor, employment, contractor, founder, advisor, and confidentiality agreements should be stored and signed properly. |
| IP assignment | Make sure code, designs, content, inventions, and product work belong to the company where appropriate. |
The common pattern: founders delay structure because “we are early.” Then the company grows, records are scattered across email, WhatsApp, Google Drive, and someone else’s laptop. Fixing it later is painful.
Startup India And Government Schemes
Section titled “Startup India And Government Schemes”DPIIT recognition under Startup India can provide access to benefits such as easier compliance routes, IPR support, tax-related schemes for eligible startups, public procurement support, and other ecosystem programs. The official Startup India portal lists current eligibility and benefits, including company type, age, turnover, original-entity, and innovation/scalability criteria.
Do not treat recognition as a vanity badge. Treat it as an operating asset if it helps with:
- Grant or scheme applications.
- Government or enterprise credibility.
- Public procurement paths.
- IPR support.
- Tax exemption applications where eligible.
- Incubator or state policy benefits.
Before applying, ask:
- Does our entity type qualify?
- Do we meet the current eligibility criteria?
- Which benefit are we actually trying to access?
- What documents are required?
- Who will maintain the certificate and related records?
- Does this affect fundraising, tax, or public procurement plans?
Government schemes can help, but founders should not build the company around schemes. Schemes are support. Customers are the business.
Compliance Calendar
Section titled “Compliance Calendar”Build a calendar with five categories.
1. Monthly
Section titled “1. Monthly”Possible monthly items may include bookkeeping close, payroll, GST-related work, TDS-related work, vendor payments, customer invoicing, bank reconciliation, and management reporting. The exact list depends on your structure, registrations, transactions, and state.
2. Quarterly
Section titled “2. Quarterly”Quarterly work may include tax estimates, board updates, investor MIS, internal financial review, and certain return cycles depending on applicability.
3. Annual
Section titled “3. Annual”Annual work can include financial statements, statutory audit where applicable, income tax filing, ROC filings for companies, board/shareholder approvals, and other entity-specific requirements.
4. Event-Based
Section titled “4. Event-Based”Some compliance work is triggered by events:
- Incorporation.
- Issuing shares or options.
- Raising money.
- Changing directors.
- Opening a new office.
- Hiring employees in a new state.
- Crossing a GST, employee, transaction, or sector threshold.
- Signing large enterprise or government contracts.
- Exporting services.
- Collecting sensitive data.
Event-based compliance is where startups often get caught. The company changes, but the calendar does not.
5. Board, Investor, And Governance
Section titled “5. Board, Investor, And Governance”Keep board minutes, cap table updates, shareholder approvals, investor consents, ESOP grants, and major contracts organized. Governance is not only for large companies. Early sloppiness becomes later diligence risk.
Data Room From Day One
Section titled “Data Room From Day One”Create a simple folder structure:
- Incorporation and constitutional documents.
- PAN, TAN, GST, registrations, certificates.
- Board and shareholder records.
- Cap table and financing documents.
- Customer contracts.
- Vendor contracts.
- Employee and contractor agreements.
- ESOP documents.
- IP assignments.
- Tax filings and payment challans.
- Financial statements and monthly MIS.
- Policies: privacy, security, HR, expenses, procurement.
The founder test: if an investor asked for diligence documents tomorrow, could you share a clean folder without panic?
India-Specific Mistakes
Section titled “India-Specific Mistakes”- Treating CA/CS/lawyer work as a once-a-year cleanup.
- Mixing founder and company expenses without records.
- Forgetting IP assignment from freelancers, early employees, or agencies.
- Promising ESOPs informally without proper documents.
- Raising money before understanding board approvals, valuation paperwork, and filings.
- Ignoring state-level registrations after hiring.
- Discovering GST, TDS, or export documentation issues only when a customer asks.
- Using copied contracts without understanding liability, payment terms, data, termination, or dispute clauses.
Advisor Operating System
Section titled “Advisor Operating System”The founder does not need to personally execute every legal and compliance task, but the founder needs an advisor system that produces clarity.
At minimum, set up:
| Advisor or owner | What they should own | Founder review rhythm |
|---|---|---|
| CA/accountant | Books, taxes, GST where applicable, TDS where applicable, payroll inputs, monthly close. | Monthly finance review. |
| CS/company secretarial support | ROC filings, board/shareholder records, share issuances, resolutions, registers. | Monthly or event-based review. |
| Lawyer | Founder agreements, customer/vendor contracts, fundraising docs, IP, employment/contractor terms, disputes. | Before signing material documents. |
| Payroll/HR ops | Employee records, offer letters, reimbursements, statutory deductions where applicable. | Monthly payroll review. |
| Internal owner | Calendar, proof folder, data room, follow-ups, reminders. | Weekly check until stable. |
Run advisors with written questions. Do not ask only, “Is everything okay?” Ask:
- What changed this month?
- What filings or payments are due in the next 30 days?
- What event triggered a new obligation?
- What proof do we have that the task is complete?
- What should be documented before we forget?
- What risk are we carrying knowingly?
Good advisors reduce uncertainty. Weak advisor management turns compliance into vague reassurance.
Contracts That Matter Early
Section titled “Contracts That Matter Early”Founders often sign whatever gets the deal done. That can be expensive later.
Prioritize these contract categories:
Founder and ownership documents
Section titled “Founder and ownership documents”Before the company becomes valuable, document founder equity, roles, vesting or reverse vesting where relevant, IP assignment, decision rights, exit scenarios, and what happens if someone leaves.
The hard conversation is cheaper before success.
Customer contracts
Section titled “Customer contracts”For paid customers, understand:
- Scope.
- Deliverables.
- Payment terms.
- Taxes.
- Renewal.
- Termination.
- Liability.
- Data access.
- Support expectations.
- Custom work ownership.
- Dispute jurisdiction.
If the customer sends their own agreement, read it. Enterprise contracts can shift risk onto a small startup quietly.
Employee and contractor agreements
Section titled “Employee and contractor agreements”Every person creating code, design, content, sales material, data, models, processes, or brand work should have clear terms. The company should know whether the work product belongs to it, what confidentiality applies, and what post-engagement obligations exist.
Contractor work without IP assignment is a common diligence problem.
Vendor and tool agreements
Section titled “Vendor and tool agreements”Cloud, payment, CRM, analytics, payroll, email, AI tools, and support tools may handle customer data, payment data, or core operations. The founder should know where critical data lives and what happens if a vendor fails.
Fundraising And Governance Triggers
Section titled “Fundraising And Governance Triggers”Fundraising creates legal work that should be planned, not rushed after a verbal commitment.
Before raising, prepare:
- Current cap table.
- Founder/shareholder documents.
- ESOP plan status, if any.
- Board/shareholder approvals needed.
- Financial statements and MIS.
- Customer contracts and revenue proof.
- IP assignment documents.
- Material liabilities and disputes.
- Existing loans, SAFEs, notes, or side letters.
- Data room with clean file names.
During fundraising, do not casually promise terms in email or WhatsApp that your lawyer has not reviewed. Valuation is only one part of the deal. Control, liquidation preference, anti-dilution, pro-rata rights, board rights, information rights, ESOP expansion, transfer restrictions, and founder vesting can matter more than the headline number.
If multiple small angels invest, documentation discipline matters even more. Messy angel rounds can create cap table, consent, tax, and communication problems later.
Data, Privacy, And Security Hygiene
Section titled “Data, Privacy, And Security Hygiene”Even early startups need basic discipline if they handle customer data, employee records, financial data, health data, education data, children’s data, location data, payment data, or confidential business data.
Founder checklist:
- What data do we collect?
- Why do we collect it?
- Where is it stored?
- Who can access it?
- How do we delete or export it if needed?
- Which third-party tools process it?
- What do our privacy policy and customer contracts promise?
- What happens if data leaks?
- What security practices do enterprise customers expect before buying?
Do not wait for a security questionnaire to discover your own systems. A simple data map, access policy, backup policy, password manager, two-factor authentication, and incident owner are better than vague confidence.
Diligence Red Flags
Section titled “Diligence Red Flags”These issues slow fundraising, enterprise sales, loans, grants, acquisitions, and exits:
- Founder equity unclear or undocumented.
- Former contributor claims ownership of product or code.
- Cap table does not match filings or agreements.
- Customer revenue cannot be tied to invoices and bank receipts.
- GST, TDS, payroll, or ROC work is unclear or delayed.
- ESOPs promised informally.
- Board/shareholder approvals missing.
- Contracts signed by the wrong entity or person.
- Personal and company expenses mixed without records.
- Open disputes, unpaid vendors, or employee issues hidden until late.
- Product uses third-party code, data, or AI outputs without understanding license or rights.
Diligence is not an event. It is the result of daily recordkeeping.
Official Links To Verify
Section titled “Official Links To Verify”Use official sources and advisors for current rules:
India Compliance Ownership Matrix
Section titled “India Compliance Ownership Matrix”Compliance becomes stressful when everyone assumes someone else is handling it. Create a clear ownership matrix.
| Area | Internal owner | Advisor | Proof to keep | Review rhythm |
|---|---|---|---|---|
| Entity and ROC | Founder or company secretary owner | CS/lawyer | Incorporation docs, board minutes, filings, registers | Monthly check, annual review |
| PAN, TAN, GST | Finance owner | CA | Registrations, challans, returns, notices, replies | Monthly |
| Accounting and tax | Finance owner | CA | Books, bank reconciliation, invoices, expense records, tax workings | Monthly close |
| Payroll and people compliance | People/finance owner | CA/labour advisor | Salary records, offer letters, contractor agreements, statutory records | Monthly/quarterly |
| Contracts | Founder or legal owner | Lawyer | Customer, vendor, employment, contractor, IP, data processing agreements | Before signing and quarterly review |
| IP and brand | Founder/product owner | Lawyer/IP advisor | Trademark filings, assignment deeds, contractor IP clauses, open-source notes | Quarterly |
| Data and security | Product/engineering owner | Lawyer/security advisor | Data map, access review, vendor list, privacy docs, incident log | Quarterly or after major change |
| Fundraising and governance | Founder/finance owner | Lawyer/CS/CA | Cap table, board approvals, investor docs, share filings | Before and after each round/event |
For each row, define a backup owner. Founders should not abdicate compliance to advisors. Advisors guide and file; the company owns facts, records, decisions, and deadlines.
Compliance Triage System
Section titled “Compliance Triage System”Not every compliance item has the same urgency. Build a triage system so founders do not either ignore everything or panic about everything.
| Severity | Examples | Founder response |
|---|---|---|
| Routine | Monthly close, standard bookkeeping, recurring returns, routine board records. | Calendar, owner, proof folder. |
| Important | New customer contract, new state hiring, GST/invoice issue, ESOP grant, contractor IP. | Advisor review before action, document decision. |
| High risk | Fundraise, share issuance, tax notice, employee dispute, data incident, large enterprise contract. | Founder owns, qualified advisor involved, written record. |
| Existential | Founder split, regulatory breach, payroll/tax default, major security incident, acquisition diligence issue. | CEO/board/advisors/legal/finance war room as needed. |
The triage question is simple: what happens if we get this wrong? If the answer affects ownership, cash, customer trust, employee rights, regulated activity, or future fundraising, slow down and get proper help.
Event Trigger Checklist
Section titled “Event Trigger Checklist”Many obligations are triggered by events rather than dates. Keep this checklist close to founder decisions.
Before each event, ask your CA, CS, lawyer, or relevant advisor what changes:
- Adding or removing a founder, director, shareholder, advisor, or key employee.
- Issuing shares, options, convertible instruments, loans, or side letters.
- Hiring in a new state or changing employment/contractor model.
- Crossing revenue, invoice, employee, transaction, or sector thresholds.
- Selling to government, enterprise, international, financial, health, education, or regulated customers.
- Launching a product that handles money, personal data, payroll, lending, insurance, tax, legal decisions, or health data.
- Opening a new office, warehouse, lab, field team, or physical operations.
- Changing pricing, refunds, subscription terms, or marketplace money flow.
- Using third-party code, datasets, AI outputs, or customer data in the product.
- Preparing for fundraising, debt, grants, tenders, M&A, or shutdown.
The founder does not need to know every rule in advance. The founder does need to know when to ask.
Monthly Compliance Review
Section titled “Monthly Compliance Review”Run a 30-minute monthly review with the internal owner and advisors.
Agenda:
- What was filed, paid, signed, issued, or changed this month?
- What proof is stored, and where?
- What is due in the next 30 and 90 days?
- What business event triggered a new obligation?
- Which customer, investor, employee, vendor, or regulator issue needs attention?
- What document would block fundraising or enterprise diligence if asked today?
- Which compliance risk is being accepted knowingly?
The review should produce a short action list with owners and dates. If the answer is always “everything is fine,” ask for evidence. Compliance comfort without proof is not a system.
Due Diligence Drill
Section titled “Due Diligence Drill”Once a quarter, run a diligence drill. Pretend an investor, enterprise customer, bank, acquirer, or grant program asks for documents tomorrow.
Can you produce:
- Incorporation and constitutional documents.
- Current cap table and share/option records.
- Board and shareholder approvals.
- Founder, employee, contractor, advisor, and IP agreements.
- Customer contracts and invoices tied to bank receipts.
- GST, tax, payroll, ROC, and other applicable records.
- Financial statements and monthly MIS.
- Material vendor contracts and tool list.
- Data/security/privacy documents where relevant.
- Notices, disputes, or contingent liabilities.
Score each folder:
- Green: complete and current.
- Yellow: mostly available but needs cleanup.
- Red: missing, unclear, or dependent on one person’s memory.
Fix the red items before you need them. Diligence stress is usually recordkeeping debt becoming visible all at once.
Advisor Question Bank
Section titled “Advisor Question Bank”Founders get better outcomes from advisors when they ask precise questions.
Ask:
- What are the current rules or official sources we should rely on?
- What applies to us now, and what may apply after we cross a threshold?
- What is the consequence if we miss this?
- What document proves completion?
- What should the board or shareholders approve?
- What should be in the customer, employee, contractor, or vendor contract?
- What should we avoid promising in email, WhatsApp, or pitch decks?
- What would an investor or enterprise buyer ask during diligence?
- What should we review again after a fundraise, revenue change, hiring change, or product change?
Good advisors should welcome specific questions. Vague reassurance is not enough for a startup that wants to grow cleanly.
Scheme And Grant Due Diligence
Section titled “Scheme And Grant Due Diligence”Government schemes, incubator grants, state programs, tax exemptions, and public-sector opportunities can help a startup, but they should be treated as structured opportunities, not free money.
Before applying, create a scheme note:
| Question | Why it matters |
|---|---|
| Which official page or notification describes the scheme? | Avoids relying on forwarded PDFs, social posts, or outdated advice. |
| What entity type, age, turnover, sector, recognition, or location rules apply? | Prevents wasted applications and future misrepresentation risk. |
| What documents are required? | Reveals whether your records are clean enough. |
| What money, benefit, exemption, market access, or recognition is actually offered? | Separates useful help from vanity badges. |
| What reporting, audit, usage, or milestone obligations follow? | Grants can create future obligations. |
| Does the scheme affect fundraising, pricing, ownership, IP, hiring, procurement, or location decisions? | Some benefits come with constraints. |
| Who internally owns the application and post-approval compliance? | Prevents founder memory from becoming the system. |
Do not optimize the company around schemes unless the scheme directly supports the business strategy. A grant can extend runway. It should not distort the customer, product, or market choice.
Government And Enterprise Vendor Readiness
Section titled “Government And Enterprise Vendor Readiness”Many Indian startups want to sell to large enterprises, public-sector buyers, universities, hospitals, banks, or government departments. These buyers often ask for more than a product demo.
Prepare a vendor readiness file:
- Incorporation documents.
- PAN, GST, bank details, cancelled cheque, and billing details where applicable.
- DPIIT recognition certificate if relevant.
- MSME/Udyam or other registrations if applicable and current.
- Board authorization or signing authority proof where needed.
- Product brochure, scope document, and commercial proposal.
- Standard master service agreement or terms.
- Privacy policy, data processing terms, and security practices where relevant.
- Customer references, case studies, or pilot outcomes.
- Support and escalation process.
- Insurance, certifications, or audit reports if the category requires them.
- Invoices, payment terms, tax details, and refund/cancellation terms.
For public-sector and large-enterprise sales, ask early:
- Is vendor registration required?
- Is a purchase order mandatory before work starts?
- Who signs the contract?
- Who confirms delivery?
- Who releases payment?
- Does the buyer need GST invoice format, e-invoice applicability, or TDS handling?
- Are there tender, GeM, EMD, security, local presence, or compliance requirements?
- What documents are needed before procurement will even review you?
The sale is not only persuasion. It is operational compatibility with the buyer’s procurement system.
Evidence Pack For India Compliance
Section titled “Evidence Pack For India Compliance”Founders should build an evidence pack that proves the company exists, owns what it sells, pays what it owes, and can be trusted.
Keep these folders current:
| Folder | Contents |
|---|---|
| Entity | Incorporation documents, constitutional documents, board/shareholder records, registers. |
| Tax and finance | PAN, TAN, GST, returns, challans, financial statements, MIS, bank reconciliation. |
| People | Offer letters, contractor agreements, consultant agreements, payroll records, exits, invention/IP assignment language. |
| Product and IP | Code ownership, contractor assignments, trademarks, licenses, open-source notes, design/source files. |
| Customers | Contracts, purchase orders, invoices, receipts, delivery proof, support commitments, renewals. |
| Vendors | Vendor contracts, invoices, data/security notes, cancellation terms, payment obligations. |
| Data and security | Data map, access list, privacy policy, vendor processors, incident log, backup notes. |
| Fundraising | Cap table, term sheets, SHA/SSA documents, side letters, approvals, filings, investor updates. |
Set a rule: every material business event creates a document trail within seven days. If the document is missing, the event is not operationally complete.
Compliance Mistakes That Feel Harmless Early
Section titled “Compliance Mistakes That Feel Harmless Early”These mistakes rarely hurt on day one, but become expensive during fundraising, enterprise sales, exits, disputes, or shutdown:
- Paying contributors informally without IP assignment.
- Promising ESOPs in chats before creating proper documents.
- Mixing founder personal expenses and company expenses.
- Using one GST invoice pattern for every type of sale without checking facts.
- Signing customer contracts under the wrong entity name.
- Letting one founder hold all statutory, bank, and portal access.
- Assuming a CA, CS, or lawyer has done something without storing proof.
- Ignoring state-level hiring, shop/establishment, professional tax, or labour triggers.
- Selling regulated workflows without checking whether the startup needs approvals, licenses, or partner arrangements.
- Using customer data in demos, AI tools, analytics, or training without understanding consent and contract promises.
The fix is not to become slow. The fix is to create small habits: ask before material actions, store proof, review monthly, and escalate early.
Founder Control Without Founder Bottleneck
Section titled “Founder Control Without Founder Bottleneck”The founder should not personally do every compliance task forever. But the founder must understand the system well enough to ask sharp questions.
Use this delegation model:
| Stage | Founder role | Advisor/internal role |
|---|---|---|
| Pre-revenue | Learn basics, choose advisors, create proof folders. | Set up entity, tax, accounting, contracts. |
| Early revenue | Review monthly close, contracts, invoices, collections, filings. | Execute filings, bookkeeping, payroll, tax, contract review. |
| Fundraising or enterprise sales | Own diligence quality and risk decisions. | Prepare documents, filings, opinions, cleanup, negotiation support. |
| Scale | Ensure internal owners, controls, board reporting, audit rhythm. | Run recurring processes and flag exceptions. |
Delegation is healthy when the founder can answer: what is due, who owns it, what proof exists, and what risk remains?
Official Source Review Rhythm
Section titled “Official Source Review Rhythm”India compliance guidance changes, and founder memory goes stale. Treat official portals and professional advisors as the source of truth, not old WhatsApp forwards, investor anecdotes, or a template copied from another startup.
Create a review rhythm:
| Area | Source-of-truth habit | Owner |
|---|---|---|
| Entity and filings | Verify due dates, forms, and status with MCA/professional support. | CS/founder/finance owner |
| Tax and GST | Verify registration, returns, notices, invoice treatment, and payment status. | CA/finance owner |
| Payroll and labour triggers | Verify state, employee, contractor, benefits, and professional-tax obligations. | HR/finance/advisor |
| Startup recognition and schemes | Verify eligibility and benefits on current official Startup India/DPIIT materials. | Founder/ops owner |
| Payments or regulated activity | Verify RBI/sector rules and whether partner/license requirements apply. | Founder/legal/domain expert |
| Data and privacy | Verify customer promises, consent, retention, vendor use, and security responsibilities. | Founder/legal/security owner |
Every quarter, ask three questions:
- Which compliance assumption are we relying on?
- Which official source or advisor confirmed it?
- Where is the proof stored?
Do not make the review theatrical. Make it boring. Boring compliance is good. The problem is not that founders miss obscure edge cases; it is that they often miss ordinary proof, ownership, and documentation until a customer, investor, bank, or regulator asks for it.
If advice changes, record the change:
Topic:Old understanding:New understanding:Source/advisor:Date:Action required:Owner:Proof stored at:This habit protects the founder from both overconfidence and paralysis. You do not need to become a lawyer. You do need to know which questions deserve professional review and where the answer lives.
Compliance Claim Ledger
Section titled “Compliance Claim Ledger”Many compliance problems start as casual claims: a line on a website, a sentence in a proposal, a checkbox in a vendor form, a promise in a WhatsApp message, or a confident answer during enterprise procurement. Later, the company discovers that the claim was incomplete, outdated, or unsupported by documents.
Keep a compliance claim ledger for any statement that affects trust, security, tax, data, employment, IP, or regulated activity.
| Claim | Where it appears | Proof needed | Owner | Review date |
|---|---|---|---|---|
| ”We are GST registered” | Invoice, proposal, website, vendor form | Registration, return status, invoice format review | Finance/CA | |
| ”Customer data is secure” | Website, enterprise form, sales deck | Data map, access rules, vendor list, security controls | Founder/security owner | |
| ”All IP is owned by the company” | Investor data room, customer contract | Founder assignments, contractor agreements, employee clauses | Founder/legal | |
| ”We comply with applicable laws” | Contract, procurement document | Advisor review of the actual obligation | Legal/advisor | |
| ”We are eligible for a scheme or benefit” | Investor update, customer pitch | Current official source and eligibility proof | Founder/ops | |
| ”Our team members are contractors” | Payroll, contracts, tax treatment | Advisor-confirmed classification and documents | Finance/HR/advisor |
Use three labels:
| Label | Meaning | Founder action |
|---|---|---|
| Verified | Current proof exists and is stored. | Use the claim as written. |
| Needs review | Claim may be true, but proof or wording needs advisor/source confirmation. | Do not use in high-stakes settings until reviewed. |
| Do not claim | The company cannot currently support it. | Remove from deck, website, form, or sales script. |
This is especially important for enterprise sales, regulated customers, fintech, healthtech, edtech, HR/payroll, payments, AI workflows using customer data, government tenders, and cross-border business. In those cases, a casual claim can create contract risk, trust damage, or diligence friction.
The rule is simple:
If a claim helps us win trust, we should be able to show why it is true.The ledger should be reviewed before fundraising, large customer proposals, government applications, security questionnaires, public launches, and major website rewrites.
Compliance Calendar By Trigger
Section titled “Compliance Calendar By Trigger”Do not manage India compliance only by month. Some obligations are triggered by events: hiring, issuing shares, raising money, changing directors, signing leases, crossing revenue thresholds, expanding states, collecting GST, importing/exporting, or handling sensitive data.
Create a trigger calendar:
| Trigger | Who should be told | Evidence to create |
|---|---|---|
| New employee or contractor | CA/payroll, HR owner, founder | Offer, contract, payroll setup, tax documents, IP assignment. |
| New customer contract | Finance, legal, delivery owner | Signed agreement, invoice terms, GST treatment, data/security obligations. |
| New state or office | CA/CS, operations | Shops and establishment, professional tax, local registrations where applicable. |
| Equity issuance or fundraise | CS, lawyer, finance | Board/shareholder approvals, filings, cap table, bank evidence. |
| ESOP grant or exercise | CS, finance, HR | Plan approvals, grant letters, vesting, exercise records, tax notes. |
| New regulated product flow | Lawyer, compliance advisor, product owner | Regulatory assessment, terms, consent, risk review. |
| Government scheme or grant application | Founder, finance, advisor | Eligibility proof, application, reporting obligations. |
The founder does not need to become a compliance expert. But the founder must make sure the team knows when to call the expert.
CA-CS Operating Brief
Section titled “CA-CS Operating Brief”A CA or CS relationship works better when the founder gives context instead of forwarding random documents at the last minute. Create a one-page operating brief and update it quarterly.
| Area | What to share |
|---|---|
| Business model | How the company makes money, invoices, collects, refunds, and recognizes revenue. |
| Entity and ownership | Entity details, directors, shareholders, ESOP pool, investor rights. |
| Team | Employees, contractors, consultants, state locations, payroll changes. |
| Fundraising | Past rounds, planned rounds, instruments, foreign investors if any. |
| Customer types | India, export, enterprise, government, marketplace, consumer, regulated sector. |
| Systems | Accounting, payroll, invoicing, payment gateway, expense tools. |
| Upcoming events | Hiring, office move, fundraise, ESOP grant, big contract, new product, international expansion. |
Ask advisors for a risk list, not only filings:
What are the top five compliance or tax risks in our current operating model, and what evidence should we maintain?That single question often improves the relationship more than another status call.
Board And ROC Evidence Pack
Section titled “Board And ROC Evidence Pack”Investors and acquirers often discover governance gaps late: missing approvals, unsigned minutes, unclear share records, unrecorded options, delayed filings, or mismatched cap tables. Build an evidence pack early.
Keep these records organized:
| Record | Why it matters |
|---|---|
| Board minutes and resolutions | Shows decisions were approved properly. |
| Shareholder approvals | Supports equity, ESOP, major transactions, and reserved matters. |
| Cap table history | Explains ownership changes over time. |
| Share certificates and registers | Supports legal ownership evidence. |
| ESOP plan, grants, vesting, exercises | Prevents employee and diligence confusion. |
| ROC filing proofs | Shows statutory actions were completed. |
| Investor rights and side letters | Prevents surprises during future rounds or exits. |
Review the pack before every financing, major ESOP grant, director change, or acquisition conversation. Governance hygiene is cheaper before diligence than during diligence.
Regulated-Sector Early Warning System
Section titled “Regulated-Sector Early Warning System”Some Indian startup categories carry higher regulatory, compliance, data, licensing, or trust burden from the beginning. Founders should not discover this after building the product, signing customers, or raising money.
Create an early warning system if the startup touches:
| Area | Why to slow down |
|---|---|
| Money movement, lending, investing, insurance, payroll, tax, accounting | Financial regulation, customer money, reporting, dispute, and liability risk. |
| Health, diagnostics, medical advice, patient data | Safety, privacy, clinical, and trust risk. |
| Education outcomes, children, exams, credentials | Consumer protection, claims, data, and reputational risk. |
| Employment, background checks, HR decisions | Privacy, discrimination, consent, and documentation risk. |
| Government, public-sector, tenders, subsidies | Eligibility, procurement, reporting, anti-corruption, and documentation risk. |
| AI using customer data or making recommendations | Data handling, accuracy, auditability, and responsibility risk. |
| Marketplaces with sellers, buyers, payments, logistics, or refunds | Contract, tax, consumer, dispute, and platform liability risk. |
For any high-risk area, write a regulatory question memo:
What exact activity are we performing?Whose money/data/safety/rights are affected?Are we advising, enabling, processing, storing, recommending, or deciding?What licenses, terms, consents, disclosures, or controls might apply?What claims must we avoid until verified?Which advisor should review this before launch?What evidence should we maintain?This memo is not a substitute for legal advice. It is how the founder asks better questions before mistakes become expensive.
Compliance-by-design checkpoints
Section titled “Compliance-by-design checkpoints”Add compliance review at product checkpoints:
| Checkpoint | Question |
|---|---|
| Idea stage | Are we entering a regulated or high-trust category? |
| MVP stage | What data, money, claims, or decisions are involved? |
| Pilot stage | What should the customer agree to before using it? |
| Launch stage | Are website claims, pricing, terms, and support promises accurate? |
| Scale stage | Do contracts, data practices, filings, and support processes still match reality? |
The founder should make compliance visible without making the company slow. A short review at the right time beats panic during diligence or after a customer escalates.
Founder Legal Hygiene Rules
Section titled “Founder Legal Hygiene Rules”Legal hygiene is mostly boring until it is not. The goal is not to make a young startup bureaucratic. The goal is to avoid preventable ambiguity.
Use these rules:
| Rule | Why it matters |
|---|---|
| Put important promises in writing | Prevents memory-based disputes. |
| Keep signed versions, not only editable drafts | Diligence needs evidence. |
| Separate founder, company, and customer money | Avoids tax, accounting, and trust confusion. |
| Assign IP from founders, employees, contractors, and agencies | Protects the product and valuation. |
| Record equity and ESOP decisions properly | Prevents painful cleanup later. |
| Review public claims before launch | Marketing can create legal risk. |
| Maintain advisor notes with dates | Shows what was checked and when. |
The “future diligence” test
Section titled “The “future diligence” test”Before filing away any important decision, ask:
If an investor, acquirer, auditor, government department, or angry counterparty asked for proof two years from now, what would we show?If the answer is “we would explain it,” create better evidence now. Explanations are weaker than records.
State And Sector Compliance Triage
Section titled “State And Sector Compliance Triage”India compliance is not only national. State, sector, customer type, employee location, data type, and payment model can change the obligation set. Founders should not memorize every rule, but they should know when to ask better questions.
Use this triage:
| Trigger | What to check |
|---|---|
| Hiring employees in a new state | Shops and establishment, professional tax, payroll, leave, local registrations. |
| Selling to regulated sectors | Sector-specific licenses, data rules, customer procurement, audit expectations. |
| Handling payments, lending, insurance, securities, or wallets | Financial regulation, RBI/partner obligations, KYC, risk, customer disclosures. |
| Working with health, education, children, or sensitive data | Privacy, consent, safety, security, sector rules, customer contract duties. |
| Selling to government or PSUs | Tender terms, registrations, earnest money, performance obligations, dispute terms. |
| Receiving foreign money or paying foreign vendors | FEMA, tax withholding, invoicing, bank documentation, transfer pricing questions. |
| Opening offices or field teams | Local registrations, employment records, expense policies, device/data controls. |
Founder triage question
Section titled “Founder triage question”Ask this before launching a new segment, state, or regulated workflow:
Does this change create a new legal, tax, employment, data, payment, or sector obligation that was not present in our first market?If yes, add the question to the advisor queue before the launch, not after a customer, employee, investor, or government notice forces the issue.
Advisor Handoff Tracker
Section titled “Advisor Handoff Tracker”Founders often ask a CA, CS, lawyer, payroll vendor, or compliance advisor a question in a call and then lose the answer in memory. That creates risk later because nobody knows what was checked, what was assumed, and what evidence was kept.
Create an advisor handoff tracker:
| Question | Advisor | Context shared | Advice received | Action owner | Evidence stored | Review trigger |
|---|---|---|---|---|---|---|
| GST treatment for new product package | Pricing, invoice flow, customer type | Product/pricing change | ||||
| ESOP grant process | Board approval, employee list, plan docs | New grant cycle | ||||
| Contractor IP assignment | Contract, scope, country, payment terms | New contractor/vendor | ||||
| New state hiring compliance | Employee location, role, payroll setup | First hire in state |
Use this note after every material advisor conversation:
Question asked:Facts shared:Advisor response:What we decided:Documents/evidence to store:Owner:Next review trigger:This is not a replacement for professional advice. It is how the founder prevents professional advice from becoming vague folklore. Good records also make future advisors, investors, acquirers, and internal operators more confident.
Reader Action
Section titled “Reader Action”Create a compliance owner table with columns: item, owner, advisor, frequency, proof, next due date, and risk if missed. Fill it for your entity, GST, accounting, payroll, contracts, IP, board records, and tax. Review it monthly until it becomes boring.