Skip to content

72. Startup Compliance

Compliance is the operating discipline that keeps a startup legally usable. It is not the opposite of speed. Done well, it lets you move faster because your bank account, invoices, contracts, tax records, employment records, cap table, and data practices can survive scrutiny.

This is founder guidance, not legal, tax, accounting, or privacy advice. Rules vary by entity, state, sector, revenue, headcount, funding, and customer geography. Use this chapter to set up your system and then verify specifics with a CA, CS, lawyer, privacy counsel, or domain expert.

The core compliance question is: can the company prove that its money, ownership, people, contracts, tax, and data practices are under control?

Compliance is not only about avoiding penalties. It is about making the company usable by serious people: investors, banks, customers, auditors, acquirers, employees, and regulators. A startup with clean records can move faster because it is not constantly reconstructing its own history.

You do not need to personally become a CA, CS, or lawyer. You do need to be the person who insists on a system.

At a minimum, every startup should maintain:

  • A compliance calendar.
  • A document repository.
  • A cap table and share records.
  • A contract repository.
  • A tax and invoicing file.
  • A payroll and contractor file.
  • A data and security register.
  • A list of open legal questions.

The operating question is: “If an investor asks for diligence next month, can we produce the basics without panic?”

For a company, maintain incorporation documents, constitutional documents, board minutes, shareholder approvals, statutory registers, auditor records, annual filings, and changes in directors or shareholding. Do not let the CS become the only person who knows where things are. The founder should at least know what exists, where it is stored, and which filings are due.

Board process feels excessive at the beginning, but it protects decisions. Founder salary, share issuance, ESOP grants, loans, bank authority, major contracts, fundraising, and related-party transactions should not live only in email or memory. If a decision changes ownership, money, control, or liability, ask whether formal approval is needed.

GST questions are not only about registration. They affect pricing, invoicing, place of supply, input tax credit, exports, marketplace sales, SaaS billing, and enterprise procurement. Ask your CA how GST applies before sending the first serious invoice, not after the finance team at a customer rejects it.

If you pay employees, contractors, consultants, vendors, rent, professionals, or interest, TDS may become relevant. Income tax compliance also requires clean books, proper expense classification, advance tax awareness where applicable, and disciplined year-end closure. Sloppy early accounting becomes expensive during a fundraise because you have to reconstruct the story under pressure.

Professional tax, shops and establishment, and labour matters

Section titled “Professional tax, shops and establishment, and labour matters”

These may depend on state, office location, headcount, employment type, and local rules. Do not assume that remote work removes all obligations. If you hire employees, create employment agreements, payroll process, leave policy, reimbursement policy, confidentiality/IP terms, exit process, and a basic employee records system.

FEMA and related rules can appear when there are foreign investors, foreign subsidiaries, overseas customers, cross-border payments, foreign bank accounts, ESOPs for overseas employees, or IP movement across entities. Do not solve this through guesswork. Cross-border mistakes can be slow and expensive to clean up.

Keep founder records, IP assignments, early expense records, domain/repository ownership, advisor promises, and contractor terms clean. The company may be small, but ownership confusion starts here.

Before serious invoicing, clarify entity, bank account, GST position, invoice format, payment terms, accounting system, TDS implications, and who follows up on collections. Revenue that cannot be invoiced or collected cleanly is weaker than it looks.

Create employment and contractor templates, payroll process, leave/reimbursement rules, confidentiality/IP terms, laptop and access policy, exit process, and employee records. People compliance begins before the team feels “large.”

Prepare cap table, board/shareholder approvals, filings, tax records, bank statements, contracts, IP assignments, employment records, compliance tracker, and open legal issues. Diligence rewards founders who can produce documents without drama.

Customers may ask for GST details, incorporation documents, PAN/TAN, bank proof, security answers, privacy policy, data processing terms, insurance, vendor onboarding forms, and contract redlines. Treat enterprise onboarding as a cross-functional workflow, not just sales paperwork.

Indian B2B founders often think the sale is done when the buyer says yes. In enterprise and mid-market sales, the real delay may begin after the verbal yes: vendor registration, GST details, purchase order, security questionnaire, legal review, finance approval, bank verification, and payment terms.

Build a vendor onboarding pack before the first serious enterprise deal. Store it in one folder and keep it current.

Document or detailWhy customers ask
Company incorporation certificateConfirms legal existence.
PAN, TAN, GST registration where applicableNeeded for tax, vendor setup, TDS, GST, and finance workflows.
Registered address and billing addressNeeded for PO, invoices, contract, and compliance records.
Bank account proofNeeded for payment setup and fraud prevention.
Cancelled cheque or bank letter where requestedCommon finance-team requirement.
MSME/Udyam/DPIIT details if applicableMay affect procurement, policy, or internal classification.
Authorized signatory detailsConfirms who can sign agreements and forms.
Board or authorization proof where neededHelps with larger contracts or regulated customers.
Standard invoice templatePrevents GST/TDS/payment-processing rework.
Standard MSA/order form/proposal templateSpeeds legal review and keeps scope consistent.
Privacy policy and data processing positionNeeded if customer/user data is involved.
Security summaryAnswers basic access, hosting, backup, encryption, incident, and support questions.
Insurance details if applicableSome customers require cyber, professional indemnity, or liability cover.
Support and escalation contactsShows the customer who owns delivery after signing.

Assign one owner for the pack. Sales should not invent compliance answers. Finance should not chase product security answers. Engineering should not answer legal questions in random email threads.

Use this routing table:

Customer requestInternal owner
PAN, TAN, GST, bank, invoice, payment termsFinance/ops founder or finance owner
Contract redlines, liability, indemnity, governing lawFounder plus lawyer
Privacy, DPA, data location, deletion, subprocessorsProduct/engineering founder plus privacy/security advisor where needed
Security questionnaireEngineering/security owner, reviewed by founder for promises
PO, vendor registration, payment portalSales/ops owner
Implementation timeline and support SLACustomer success/product founder

For every serious customer, track onboarding as its own pipeline after commercial interest.

FieldExample
Customer
Buyer/champion
Finance/procurement contact
Legal contact
Security/IT contact
Vendor registration statusNot started / submitted / blocked / approved
Contract statusDraft / redline / legal review / signed
PO statusNot required / requested / received
Invoice statusNot raised / raised / accepted / rejected / paid
Payment terms15 / 30 / 45 / 60 / 90 days
Current blocker
Internal owner
Next action and date

This tracker matters because enterprise sales can look healthier than it is. A deal with buyer excitement but no vendor approval, no PO, and 90-day payment terms is not the same as cash.

Watch for:

  • The buyer says “approved” but procurement has not started.
  • The customer wants free implementation before vendor registration.
  • Payment terms are longer than your runway can comfortably support.
  • Security questionnaire asks for controls you do not actually have.
  • Legal terms include unlimited liability, broad indemnity, customer ownership of your product work, or harsh termination rights.
  • GST, TDS, or invoicing treatment is unclear.
  • The customer asks for custom data handling that your product cannot reliably support.
  • Your team is making promises in email that are not in the contract.

Do not treat these as administrative annoyances. They affect cash, liability, implementation, and trust.

After verbal agreement, send a clear note:

Thanks for confirming interest in moving ahead.
To keep the process smooth, can we confirm the onboarding path?
1. Who owns vendor registration from your side?
2. Is a PO required before invoice or implementation?
3. What documents do you need from us for vendor setup?
4. Who will review legal/security/privacy, if applicable?
5. What are the payment terms after invoice acceptance?
6. What date should we target for contract, PO, kickoff, and first payment milestone?
From our side, [name] will own documents and onboarding.

Founders should ask these questions early. It is better to discover procurement reality before allocating implementation time.

If your product handles personal data, customer data, employee data, financial data, health data, children-related data, or confidential business information, privacy cannot be reduced to “we copied a policy page.” India’s data protection framework and rules are active and evolving, and overseas customers may also bring GDPR, SOC 2, HIPAA-like expectations, DPA requirements, or sector rules.

Build a simple data map:

QuestionFounder answer needed
What data do we collect?List user, customer, employee, lead, payment, product usage, support, analytics, and log data.
Why do we collect it?Tie each category to product function, legal obligation, security, billing, support, or analytics.
Where is it stored?Include databases, SaaS tools, spreadsheets, analytics tools, support tools, and backups.
Who can access it?Employees, contractors, vendors, founders, support agents, and integrations.
Who do we share it with?Cloud providers, payment providers, email tools, analytics, CRMs, support tools, and customers.
How long do we keep it?Define retention and deletion logic.
What happens during a breach?Create a response owner, escalation path, notification workflow, and evidence log.

Your privacy policy should match reality. If your product says one thing and your tools do another, the policy is theatre. The better founder habit is to review the data map whenever you add a major integration, analytics tool, AI workflow, payment flow, or enterprise customer.

The Digital Personal Data Protection Act, 2023 is the key official text founders should understand at a high level. Do not reduce it to a link in the footer. Build practical habits: collect less data, explain purpose, control vendor access, protect data with reasonable safeguards, maintain breach response ownership, and review child, health, finance, HR, and sensitive operational use cases with counsel.

Startup India’s DPIIT recognition page describes benefits that may include self-certification pathways for eligible recognised startups under specified labour and environmental laws, along with other benefits such as IPR support and tax exemption routes. Treat this as an official process, not a shortcut. Check current eligibility, apply properly, and store certificates and correspondence in the company repository.

Set up a simple monthly review:

  1. What filings, taxes, payroll, invoices, or payments are due this month?
  2. What contracts were signed, renewed, breached, delayed, or disputed?
  3. What employees, contractors, or vendors joined or left?
  4. What data or security changes happened in the product?
  5. What board, shareholder, or investor approvals are needed?
  6. What documents would be missing if diligence started tomorrow?

Assign each item an owner, due date, and folder link. The founder should review the calendar monthly even if the CA/CS does the work.

Your exact calendar depends on entity, state, registrations, business model, headcount, revenue, sector, and cross-border activity. Still, the founder can organize the system by frequency.

FrequencyWhat to review
WeeklyNew contracts, invoices raised, cash collected, overdue receivables, new hires/contractors, customer data incidents, legal notices.
MonthlyBooks close, payroll, tax-related work, GST/TDS where applicable, vendor payments, bank reconciliation, compliance tracker update.
QuarterlyBoard/investor update, tax estimates, cap table changes, ESOP grants, major contract obligations, privacy/security changes.
AnnualFinancial statements, statutory audit where applicable, income tax filing, ROC filings, renewals, policy review, advisor review.
Event-basedFundraise, share issuance, director change, new office, employee threshold, foreign payment, foreign investor, large contract, dispute, breach, shutdown.

Event-based compliance is where founders get surprised. A company changes, but the calendar stays old. Review the calendar whenever the business model, geography, team, customer type, or funding status changes.

Create a table and keep it visible.

AreaInternal ownerExternal advisorProof of completion
Corporate/ROCFounder or ops ownerCSFiling receipts, minutes, registers, approvals.
Accounting/booksFinance/ops ownerCA/bookkeeperMonthly MIS, ledger, bank reconciliation.
Tax/GST/TDSFinance/ops ownerCAReturns, challans, reconciliations, notices.
Payroll/peopleFounder/HR/opsPayroll advisor/CASalary records, deductions, offer letters, exits.
ContractsFounder/sales/opsLawyerSigned copies, obligation tracker, renewal dates.
IPProduct/founderIP lawyerAssignments, filings, repository/account records.
Data/privacy/securityProduct/engineering/founderPrivacy/security counsel where neededData map, access list, incident log, policy version.

Compliance fails when everyone assumes someone else owns it. Put names next to the work.

Create a live register for issues that are not yet solved. This is more useful than pretending everything is clean.

FieldWhat to record
IssueThe specific gap: missed filing, unsigned contract, GST question, data issue, unclear IP, pending notice.
AreaCorporate, tax, payroll, contracts, data, IP, employment, sector regulation, cross-border.
SeverityLow, medium, high, critical. Define severity by cash, legal, customer, investor, or regulatory impact.
OwnerOne internal person responsible for moving it forward.
AdvisorCA, CS, lawyer, privacy counsel, security consultant, or sector expert.
Next actionThe next concrete step, not a vague “check”.
Due dateWhen the next action must happen.
EvidenceFiling receipt, email, legal opinion, corrected contract, board approval, payment proof, policy version.

The risk register changes founder behaviour. Instead of “we should fix compliance sometime”, the company has named risks, owners, and proof. Investors and acquirers can tolerate known issues more easily than unknown chaos.

If customer, employee, or user data may have been exposed, deleted, misused, or accessed improperly, do not improvise in private messages.

Use a first-24-hour checklist:

  1. Preserve evidence: logs, screenshots, emails, access records, deployment history, vendor alerts.
  2. Limit further exposure: revoke access, rotate keys, pause affected workflow, isolate system where appropriate.
  3. Name an incident owner: one person coordinates facts, advisors, customer communication, and evidence.
  4. Create an incident timeline: what happened, when, who noticed, what systems/data may be affected.
  5. Contact advisors: privacy counsel, security expert, customer contract owner, and leadership as needed.
  6. Review obligations: contracts, data processing terms, applicable law, sector rules, and customer commitments.
  7. Communicate carefully: do not guess publicly; share known facts, actions taken, and next update timing.
  8. Write the postmortem: root cause, affected data, remediation, owner, and preventive controls.

This is not a substitute for legal or security advice. It is a founder response habit. The worst incident response is denial, delay, and undocumented cleanup.

Founders should create a rule for anything unusual:

  • Tax notice.
  • Customer legal notice.
  • Employee dispute.
  • Vendor dispute.
  • Data incident.
  • Missed filing.
  • Payment default.
  • Contract breach.
  • Threat of litigation.
  • Regulatory question.

Do not manage these only on WhatsApp. Create an exception log with date, issue, owner, advisor, documents, current status, next action, and deadline. Most problems become worse because founders delay, under-document, or reply emotionally.

When something looks serious, involve the right advisor early. A small legal bill before a deadline can be cheaper than a large repair effort after one.

A privacy policy is not implementation. Implementation means the product and team behave consistently with what the policy promises.

Build these basics:

  • Data inventory.
  • Access control list.
  • Vendor/subprocessor list.
  • Retention and deletion rules.
  • Incident owner and escalation path.
  • Customer data export/deletion process where applicable.
  • Employee/contractor confidentiality and data access terms.
  • Security basics: 2FA, password manager, least privilege, offboarding, backup, production access rules.

For AI workflows, add:

  • What data can be sent to AI tools?
  • Which tools are approved?
  • Can customer confidential data be used?
  • Is generated output reviewed before use?
  • Are prompts, logs, or training settings creating exposure?

This is not only for enterprise sales. It protects trust before the company is large enough to hire a security team.

Before starting a fundraise, run a mini diligence check:

AreaRed flag to fix
CorporateMissing incorporation docs, board approvals, registers, or cap table mismatch.
TaxUnclear GST/TDS/income tax status, unreconciled revenue, missing challans.
ContractsMissing customer/vendor contracts, unsigned amendments, unclear payment obligations.
PeopleMissing employment/contractor agreements, no IP assignment, informal ESOP promises.
IPFounder/agency code not assigned, domain/repository not company-controlled.
DataCopied privacy policy, no data map, no access controls, no incident process.
DisputesHidden notices, unpaid vendors, employee conflicts, customer claims.

Investors do not expect perfection at seed stage. They do expect founders to know what is clean, what is messy, and what is being fixed.

Build the diligence folder before you need it:

  • Corporate documents.
  • Cap table and share records.
  • Board and shareholder approvals.
  • Tax registrations and filings.
  • Financial statements and bank statements.
  • Customer, vendor, employment, contractor, and agency contracts.
  • IP assignments and trademark/IP records.
  • Data/privacy/security policies.
  • Litigation, notices, disputes, or open claims.
  • Advisor, consultant, and option records.
  • Compliance tracker and open questions.

The folder does not need to be perfect on day one. It needs to exist and improve monthly.

Founders do not need to become lawyers, CAs, or company secretaries. But founders do need a monthly compliance review that makes risk visible.

Run this meeting for 30 minutes once a month with the founder who owns operations, the finance owner, and your CA/CS or internal admin if available.

AreaQuestion
Corporate recordsWere any board, shareholder, share, ESOP, loan, or director matters triggered this month?
TaxAre GST, TDS, income tax, professional tax, payroll, and challans current where applicable?
RevenueAre invoices, credit notes, collections, refunds, and contracts reconciled?
PeopleDid anyone join, leave, convert from contractor to employee, receive ESOP promises, or get access to sensitive systems?
IPDid founders, employees, agencies, interns, or contractors create assets that need assignment?
DataDid we collect, share, export, delete, or expose customer/user data in a new way?
Cross-borderDid we receive foreign money, pay foreign vendors, hire overseas, or sign foreign contracts?
Open risksWhat is messy, late, undocumented, disputed, or dependent on one person?

The output should be a short note: closed items, open items, owner, deadline, advisor needed, and evidence link. If there is no written output, the review did not happen.

Compliance fails because founders rely on memory. Diligence does not ask whether something “was done.” It asks for proof.

Use an evidence standard:

  • Every filing has an acknowledgement, challan, certificate, email, or portal download.
  • Every major decision has a board note, shareholder approval, founder memo, or signed document where appropriate.
  • Every contract has the final signed copy, order form, amendments, renewal terms, and invoice link.
  • Every employee, contractor, intern, agency, and advisor has signed terms and IP/confidentiality coverage.
  • Every tax or payroll payment has proof and reconciliation.
  • Every policy has an owner, date, version, and adoption evidence.
  • Every unresolved issue has an owner and due date.

This may feel heavy for a five-person startup. It is lighter than reconstructing two years of proof during a fundraise.

Not every issue deserves the same urgency. Founders need triage.

SeverityExamplesFounder response
CriticalUnpaid statutory dues, serious data incident, missing IP assignment for core product, founder dispute affecting ownership, regulatory notice.Stop and fix with advisor involvement. Do not bury it.
HighMissing employment/contractor agreements, unsigned customer amendments, late filings, unclear GST/TDS treatment, foreign payment uncertainty.Assign owner and deadline this week.
MediumMessy folder structure, old templates, incomplete policy adoption, missing vendor security review.Add to monthly cleanup.
LowFormatting, naming, non-critical archive cleanup, duplicate copies.Fix when improving the data room.

The founder skill is not pretending everything is equally urgent. It is knowing which compliance gap can damage the company if ignored.

A CA, CS, lawyer, and tax advisor are only useful if the founder gives them context early enough.

Tell advisors before these events, not after:

  • Taking investment, loan, grant, or founder capital.
  • Issuing shares, ESOPs, advisor equity, or convertible instruments.
  • Hiring employees, contractors, agencies, interns, or consultants.
  • Signing enterprise, government, regulated, or cross-border contracts.
  • Collecting payments in foreign currency or paying foreign vendors.
  • Moving IP, creating a subsidiary, or changing entity structure.
  • Handling notices, disputes, layoffs, data incidents, or founder exits.

The cheapest advice usually happens before the action. The most expensive advice happens after founders have already signed, paid, promised, or transferred something.

The first year feels too small for process. Then a customer asks for documents, an investor begins diligence, or a co-founder dispute appears. Build the repository now.

Copied terms, privacy policies, employment letters, or vendor agreements often do not match your product, jurisdiction, or risk. They create false confidence.

Founders sign early contracts to close revenue. That is understandable. But unlimited liability, broad indemnity, unclear data terms, bad payment terms, or customer ownership of your IP can damage the company.

Founders, employees, contractors, agencies, and interns should sign the right assignment and confidentiality documents. Product ownership must be boringly clear.

Misclassified workers, vague contractor scopes, weak exit process, and missing confidentiality/IP language create risk. Every person who can touch product, code, data, customers, or brand should have documented terms.

Even if you are early, write basic rules for access, passwords, production data, customer exports, laptops, vendor tools, incident reporting, and deletion. Security culture starts before the first enterprise customer asks for it.

A compliance calendar is only useful if it creates behaviour. A forgotten spreadsheet is not a system. Build a calendar that makes obligations visible, owned, evidenced, and reviewed.

Use one row per obligation:

FieldWhat to capture
ObligationThe specific filing, payment, review, renewal, approval, notice, or record.
AreaCorporate, tax, payroll, GST, TDS, employment, privacy, IP, contract, sector, cross-border.
TriggerMonthly, quarterly, annual, event-based, contract-based, headcount-based, revenue-based, or notice-based.
OwnerThe internal person who follows up. Do not put only the external advisor’s name.
AdvisorCA, CS, lawyer, payroll vendor, privacy counsel, IP lawyer, security consultant, or sector expert.
Due dateThe date by which the company must act, or the date by which the advisor must confirm.
ProofPortal receipt, challan, board minutes, filing acknowledgement, signed contract, policy version, email confirmation.
StatusNot started, waiting on advisor, waiting on founder, filed, paid, reviewed, disputed, blocked.
Next reviewThe next date this item must be looked at again.

The founder should review four views every month:

  • Due soon: what needs action before the next review?
  • Overdue: what is late and why?
  • Event triggers: did a new customer, hire, investor, foreign payment, data flow, or office location create a new obligation?
  • Evidence gaps: what do we believe is done but cannot prove?

Do not make the calendar over-clever. The best compliance calendar is the one someone opens every month. If you are tiny, a spreadsheet is enough. If you are growing, move it into your operating system, finance workflow, or company wiki. The tool matters less than the ritual: owner, due date, proof, review.

As the company grows, compliance should move from “ask the advisor when something happens” to a small control room. This does not mean the founder becomes a legal expert. It means the founder knows what is owned, what is due, what is risky, and what needs escalation.

Build a monthly control room table:

AreaOwnerCurrent statusEvidenceEscalation trigger
Company recordsGreen/yellow/redBoard/shareholder records, filings, registersMissing or outdated records before fundraise or major decision
Tax and accountingGreen/yellow/redBooks, invoices, returns, advisor notesUnclear revenue treatment, notices, overdue filings
Payroll and peopleGreen/yellow/redOffer letters, contractor agreements, payroll recordsFirst hire, exits, ESOP, contractor IP questions
ContractsGreen/yellow/redSigned agreements, renewals, obligation trackerEnterprise deal, unusual liability, payment dispute
Data and securityGreen/yellow/redPrivacy policy, data map, access list, vendor listSensitive data, breach concern, regulated product, large customer review
IP and brandGreen/yellow/redAssignments, repo access, trademark/domain notesAgency work, founder exit, open-source release, brand conflict
Fundraising readinessGreen/yellow/redCap table, data room, financials, compliance notesInvestor diligence, bridge round, priced round

The founder should ask three questions:

  • What is overdue?
  • What changed in the business this month?
  • What needs advisor review before we repeat or scale it?

Examples of business changes that should trigger review:

  • First paid customer.
  • First international customer.
  • First employee or contractor.
  • First enterprise contract.
  • First sensitive-data workflow.
  • New financial, health, education, children, employment, lending, or regulated claim.
  • New investor instrument.
  • Founder role, equity, or access change.

This control room keeps compliance tied to operating reality. Static checklists go stale. Business events create new obligations and risks.

Founders often know something feels risky but do not know whether to call the CA, CS, lawyer, privacy counsel, security expert, investor, or customer. Build an escalation map before a problem appears.

EventFirst internal ownerExternal advisor to involveProof to preserve
Missed filing, late tax payment, or portal noticeFinance/ops founderCA/CS/tax advisorNotice, due date, challan, filing acknowledgement, advisor note.
Founder equity, share issuance, ESOP, or cap table changeCEO/founderCS/lawyer/tax advisorBoard/shareholder approvals, cap table version, instrument documents.
Enterprise contract with unusual termsSales/founderStartup lawyer, security/privacy advisor where relevantRedline, risk memo, approved exceptions, obligation tracker.
Customer or employee data incidentProduct/engineering founderSecurity expert, privacy counsel, contract ownerTimeline, logs, affected data map, containment actions, communications.
Employee dispute, termination, harassment complaint, or contractor conflictPeople/founderEmployment lawyer/HR advisor/CA where neededContract, communications, payroll records, access log, investigation notes.
Foreign payment, investor, subsidiary, overseas employee, or cross-border IPFinance/founderFEMA/tax/cross-border specialistContract, invoice, bank advice, remittance proof, structure note.
Regulatory claim in product, marketing, or salesProduct/marketing founderSector lawyer/domain expertClaim source, customer-facing copy, review note, approval owner.
Founder exit or serious founder disputeCEO/board/founder groupLawyer, tax advisor, company secretaryAgreement, vesting status, access map, asset list, communication plan.

Define response time by severity:

  • Same day: notices, data incidents, founder disputes, customer legal threats, missed statutory deadlines, or anything that can affect ownership, money, data, or company control.
  • This week: unclear contracts, new employment templates, contractor IP gaps, foreign payment questions, and material vendor/customer risk.
  • This month: folder cleanup, policy versioning, routine document gaps, template refresh, and lower-risk evidence collection.

The escalation map prevents the founder from doing two dangerous things: ignoring a real issue because it feels complicated, or escalating every small issue with panic. The right habit is calm speed: identify the issue, preserve proof, involve the right advisor, and record the decision.

Run this review once a month. It should take 30 minutes for a small startup if the tracker is current.

1. What changed in the business this month?
2. What filings, payments, renewals, notices, approvals, or records are due in the next 45 days?
3. What is overdue?
4. What do we believe is complete but cannot prove?
5. Did we sign any contract with obligations the team must now track?
6. Did we hire, exit, pay, reimburse, issue, collect, refund, or transfer anything that creates a record?
7. Did any customer, vendor, investor, employee, regulator, platform, or bank ask for something we have not documented?
8. What needs advisor review before the next month?

End with a short note:

Compliance review date:
Attendees:
Green items:
Yellow items:
Red items:
Advisor questions:
Owner/date for each open item:

This note becomes diligence evidence later. More importantly, it prevents “I thought someone handled it” from becoming the company’s compliance system.

Create a proof folder with one subfolder per area:

FolderWhat goes inside
CorporateIncorporation docs, board/shareholder approvals, registers, cap table, filings.
Tax/accountingReturns, challans, invoices, ledgers, reconciliations, advisor notes.
Payroll/peopleOffer letters, contractor agreements, payroll records, exits, reimbursements.
ContractsCustomer, vendor, agency, contractor, partnership, lease, and renewal notes.
IP/brandAssignments, trademark notes, repository ownership, domain/social access.
Data/securityPrivacy policy versions, data map, vendor list, incident notes, access reviews.
FundraisingInstruments, investor consents, data room checklists, diligence questions.

Name files by date and topic. A messy proof folder is still better than proof scattered across inboxes, WhatsApp, laptops, and advisor portals.

Compliance is easiest when evidence is collected as work happens. A folder created during diligence is already late.

Create an evidence locker:

FolderEvidence
CompanyIncorporation docs, registrations, board records, cap table.
Tax and filingsGST/TDS/income tax/ROC/professional tax where applicable, filing proofs, advisor notes.
PeopleOffer letters, contractor agreements, payroll records, IP assignments, policy acknowledgments.
CustomersContracts, invoices, DPAs, security questionnaires, support obligations.
VendorsVendor contracts, data access notes, payment proofs, critical vendor list.
Data and privacyPrivacy policy, terms, consent flows, data map, incident process, retention rules.
FundraisingTerm sheets, investment documents, filings, investor rights, board approvals.

This is an operating checklist, not legal advice. Use qualified professionals for interpretation, but do not outsource evidence collection.

Every startup changes: new state, new customer type, new payment method, new employee category, new AI workflow, new foreign customer, new vendor, new product claim. Each change may create compliance questions.

Maintain a log:

ChangePossible compliance questionOwnerAdvisor needed?Status
First enterprise customerContract, data, security, tax, invoicing
First foreign customerExport, tax, FEMA/bank documentation where relevant
First employee in new stateLabour, professional tax, local registration where relevant
First sensitive data workflowConsent, privacy, retention, security
First AI-generated customer outputAccuracy, disclosure, data use, human review

The habit is simple: when the business changes, ask whether obligations changed too.

Founders should not ignore legal, tax, customer, employee, vendor, platform, or government notices. Silence can convert a manageable issue into a serious one.

Protocol:

  1. Save the notice exactly as received.
  2. Record date, source, deadline, and required response.
  3. Assign an internal owner.
  4. Decide whether CA, CS, lawyer, or other expert review is needed.
  5. Stop informal replies until facts are clear.
  6. Gather documents and communication history.
  7. Respond in writing through the right channel.
  8. Save final response and next steps in the evidence locker.

The founder does not need to panic. But the founder should never let official or contractual deadlines drift in chat.

Founders often keep compliance questions scattered across chat, email, and memory. Create a single advisor queue so CA, CS, lawyer, payroll, banker, and internal owners can work from the same reality.

Use this table:

QuestionAreaUrgencyAdvisorOwnerStatusEvidence needed
ROC/MCAHigh/Medium/LowCS
GST/TDS/taxHigh/Medium/LowCA
Contract/data/privacyHigh/Medium/LowLawyer
Payroll/peopleHigh/Medium/LowPayroll/HR/legal
Foreign payment/FEMA/bankingHigh/Medium/LowCA/banker/counsel

Prioritize:

PriorityMeaning
HighHas deadline, money, government, employee, customer, investor, or data-risk impact.
MediumNeeded before next customer, hire, fundraise, or product launch.
LowUseful cleanup or future planning.

This makes advisor calls more productive. Instead of asking vague questions, the founder brings facts, deadlines, documents, and decisions needed.

Compliance has runway just like cash. Some issues can wait. Some become expensive if ignored. Some block fundraising, enterprise sales, hiring, payments, or shutdown.

Classify each issue:

TypeExampleFounder move
FireNotice, deadline, unpaid statutory item, employee/customer complaint, data incident.Assign owner today and get advisor input.
BlockerRequired for fundraising, customer onboarding, payroll, invoicing, or bank process.Put in weekly operating review until closed.
CleanupMissing folder, old contract, stale policy, unclear access.Batch into monthly cleanup sprint.
Future triggerForeign customer, new state, regulated sector, AI/data workflow, ESOP.Log now; review before trigger happens.

Do not let compliance become founder anxiety. Convert it into a queue, owner, deadline, and proof folder.

Not every compliance issue has the same urgency. Some are harmless cleanup. Some become expensive, block deals, or create personal stress for founders. Map the cost of delay so the team knows what to fix now.

Issue typeIf delayedFounder action
ROC/company recordsDiligence delays, penalties, trust lossClose with CS and save proof.
GST/TDS/taxInterest, notices, payment friction, customer invoice issuesReview with CA and track deadlines.
Payroll and contractor paperworkEmployee disputes, IP gaps, tax confusionStandardize contracts and payment records.
Data/privacy/securityEnterprise sales friction, incident risk, trust damageCreate policy, data map, incident owner.
FEMA/foreign receiptsBanking delays, remittance questions, funding complexityConsult CA, banker, and counsel before transaction.
ESOP/equity recordsEmployee trust issues and investor questionsMaintain cap table, grants, approvals, and communications.
Customer/vendor contractsHidden obligations, payment leakage, liabilityReview red flags before signing.

Use this rule:

Fix immediately if the issue affects government deadlines, employee rights, customer trust, investor diligence, bank/payment flow, foreign money, data risk, or ownership.
Batch later if it is only evidence cleanup with no near-term trigger.

This keeps founders from doing two bad things: ignoring serious compliance because it feels boring, and wasting scarce time polishing low-risk paperwork while customers and product need attention.

Calendar compliance catches recurring work. Event-triggered compliance catches change. Most founder surprises happen because the company changed and nobody updated the compliance system.

Run this checklist when any event happens:

EventQuestions to ask
First employeeEmployment agreement, payroll, deductions, leave, IP/confidentiality, equipment, access, and state obligations.
First contractor or agencyScope, payment, GST/TDS treatment, IP assignment, confidentiality, access, and handover.
First enterprise customerContract, DPA/security, GST/invoice, PO/vendor onboarding, SLA, support, and liability.
First foreign paymentFEMA/banking, tax, invoice, contract, withholding, purpose code, and documentation.
First sensitive data workflowPrivacy notice, consent/legal basis, retention, access, breach response, vendor data terms.
First ESOP/advisor equity promiseApproval, plan, tax, communication, vesting, cap table, and signed documents.
First large vendor or cloud commitmentContract owner, renewal, data/security, payment terms, access, and exit plan.
First official notice or complaintDeadline, owner, advisor, documents, communication channel, and response proof.

Use this operating rule:

Whenever the company does something for the first time, ask: what new legal, tax, people, data, IP, finance, or governance obligation did this create?

This does not mean slowing every decision. It means treating new company behavior as a trigger to update the operating system.

Create a compliance tracker with eight tabs: corporate, tax, payroll, contracts, people, data/privacy, IP, and open questions. Add owner, due date, status, folder link, and advisor. Review it every month with founders.