72. Startup Compliance
Compliance is the operating discipline that keeps a startup legally usable. It is not the opposite of speed. Done well, it lets you move faster because your bank account, invoices, contracts, tax records, employment records, cap table, and data practices can survive scrutiny.
This is founder guidance, not legal, tax, accounting, or privacy advice. Rules vary by entity, state, sector, revenue, headcount, funding, and customer geography. Use this chapter to set up your system and then verify specifics with a CA, CS, lawyer, privacy counsel, or domain expert.
The core compliance question is: can the company prove that its money, ownership, people, contracts, tax, and data practices are under control?
Compliance is not only about avoiding penalties. It is about making the company usable by serious people: investors, banks, customers, auditors, acquirers, employees, and regulators. A startup with clean records can move faster because it is not constantly reconstructing its own history.
The founder’s compliance model
Section titled “The founder’s compliance model”You do not need to personally become a CA, CS, or lawyer. You do need to be the person who insists on a system.
At a minimum, every startup should maintain:
- A compliance calendar.
- A document repository.
- A cap table and share records.
- A contract repository.
- A tax and invoicing file.
- A payroll and contractor file.
- A data and security register.
- A list of open legal questions.
The operating question is: “If an investor asks for diligence next month, can we produce the basics without panic?”
India compliance basics
Section titled “India compliance basics”Company and ROC records
Section titled “Company and ROC records”For a company, maintain incorporation documents, constitutional documents, board minutes, shareholder approvals, statutory registers, auditor records, annual filings, and changes in directors or shareholding. Do not let the CS become the only person who knows where things are. The founder should at least know what exists, where it is stored, and which filings are due.
Board meetings and approvals
Section titled “Board meetings and approvals”Board process feels excessive at the beginning, but it protects decisions. Founder salary, share issuance, ESOP grants, loans, bank authority, major contracts, fundraising, and related-party transactions should not live only in email or memory. If a decision changes ownership, money, control, or liability, ask whether formal approval is needed.
GST questions are not only about registration. They affect pricing, invoicing, place of supply, input tax credit, exports, marketplace sales, SaaS billing, and enterprise procurement. Ask your CA how GST applies before sending the first serious invoice, not after the finance team at a customer rejects it.
TDS and income tax
Section titled “TDS and income tax”If you pay employees, contractors, consultants, vendors, rent, professionals, or interest, TDS may become relevant. Income tax compliance also requires clean books, proper expense classification, advance tax awareness where applicable, and disciplined year-end closure. Sloppy early accounting becomes expensive during a fundraise because you have to reconstruct the story under pressure.
Professional tax, shops and establishment, and labour matters
Section titled “Professional tax, shops and establishment, and labour matters”These may depend on state, office location, headcount, employment type, and local rules. Do not assume that remote work removes all obligations. If you hire employees, create employment agreements, payroll process, leave policy, reimbursement policy, confidentiality/IP terms, exit process, and a basic employee records system.
FEMA and cross-border activity
Section titled “FEMA and cross-border activity”FEMA and related rules can appear when there are foreign investors, foreign subsidiaries, overseas customers, cross-border payments, foreign bank accounts, ESOPs for overseas employees, or IP movement across entities. Do not solve this through guesswork. Cross-border mistakes can be slow and expensive to clean up.
Compliance by stage
Section titled “Compliance by stage”Idea and pre-revenue
Section titled “Idea and pre-revenue”Keep founder records, IP assignments, early expense records, domain/repository ownership, advisor promises, and contractor terms clean. The company may be small, but ownership confusion starts here.
First revenue
Section titled “First revenue”Before serious invoicing, clarify entity, bank account, GST position, invoice format, payment terms, accounting system, TDS implications, and who follows up on collections. Revenue that cannot be invoiced or collected cleanly is weaker than it looks.
First employees and contractors
Section titled “First employees and contractors”Create employment and contractor templates, payroll process, leave/reimbursement rules, confidentiality/IP terms, laptop and access policy, exit process, and employee records. People compliance begins before the team feels “large.”
Fundraise
Section titled “Fundraise”Prepare cap table, board/shareholder approvals, filings, tax records, bank statements, contracts, IP assignments, employment records, compliance tracker, and open legal issues. Diligence rewards founders who can produce documents without drama.
Enterprise sales
Section titled “Enterprise sales”Customers may ask for GST details, incorporation documents, PAN/TAN, bank proof, security answers, privacy policy, data processing terms, insurance, vendor onboarding forms, and contract redlines. Treat enterprise onboarding as a cross-functional workflow, not just sales paperwork.
Enterprise Vendor Onboarding Pack
Section titled “Enterprise Vendor Onboarding Pack”Indian B2B founders often think the sale is done when the buyer says yes. In enterprise and mid-market sales, the real delay may begin after the verbal yes: vendor registration, GST details, purchase order, security questionnaire, legal review, finance approval, bank verification, and payment terms.
Build a vendor onboarding pack before the first serious enterprise deal. Store it in one folder and keep it current.
| Document or detail | Why customers ask |
|---|---|
| Company incorporation certificate | Confirms legal existence. |
| PAN, TAN, GST registration where applicable | Needed for tax, vendor setup, TDS, GST, and finance workflows. |
| Registered address and billing address | Needed for PO, invoices, contract, and compliance records. |
| Bank account proof | Needed for payment setup and fraud prevention. |
| Cancelled cheque or bank letter where requested | Common finance-team requirement. |
| MSME/Udyam/DPIIT details if applicable | May affect procurement, policy, or internal classification. |
| Authorized signatory details | Confirms who can sign agreements and forms. |
| Board or authorization proof where needed | Helps with larger contracts or regulated customers. |
| Standard invoice template | Prevents GST/TDS/payment-processing rework. |
| Standard MSA/order form/proposal template | Speeds legal review and keeps scope consistent. |
| Privacy policy and data processing position | Needed if customer/user data is involved. |
| Security summary | Answers basic access, hosting, backup, encryption, incident, and support questions. |
| Insurance details if applicable | Some customers require cyber, professional indemnity, or liability cover. |
| Support and escalation contacts | Shows the customer who owns delivery after signing. |
Vendor onboarding owner
Section titled “Vendor onboarding owner”Assign one owner for the pack. Sales should not invent compliance answers. Finance should not chase product security answers. Engineering should not answer legal questions in random email threads.
Use this routing table:
| Customer request | Internal owner |
|---|---|
| PAN, TAN, GST, bank, invoice, payment terms | Finance/ops founder or finance owner |
| Contract redlines, liability, indemnity, governing law | Founder plus lawyer |
| Privacy, DPA, data location, deletion, subprocessors | Product/engineering founder plus privacy/security advisor where needed |
| Security questionnaire | Engineering/security owner, reviewed by founder for promises |
| PO, vendor registration, payment portal | Sales/ops owner |
| Implementation timeline and support SLA | Customer success/product founder |
Enterprise onboarding tracker
Section titled “Enterprise onboarding tracker”For every serious customer, track onboarding as its own pipeline after commercial interest.
| Field | Example |
|---|---|
| Customer | |
| Buyer/champion | |
| Finance/procurement contact | |
| Legal contact | |
| Security/IT contact | |
| Vendor registration status | Not started / submitted / blocked / approved |
| Contract status | Draft / redline / legal review / signed |
| PO status | Not required / requested / received |
| Invoice status | Not raised / raised / accepted / rejected / paid |
| Payment terms | 15 / 30 / 45 / 60 / 90 days |
| Current blocker | |
| Internal owner | |
| Next action and date |
This tracker matters because enterprise sales can look healthier than it is. A deal with buyer excitement but no vendor approval, no PO, and 90-day payment terms is not the same as cash.
Red flags in onboarding
Section titled “Red flags in onboarding”Watch for:
- The buyer says “approved” but procurement has not started.
- The customer wants free implementation before vendor registration.
- Payment terms are longer than your runway can comfortably support.
- Security questionnaire asks for controls you do not actually have.
- Legal terms include unlimited liability, broad indemnity, customer ownership of your product work, or harsh termination rights.
- GST, TDS, or invoicing treatment is unclear.
- The customer asks for custom data handling that your product cannot reliably support.
- Your team is making promises in email that are not in the contract.
Do not treat these as administrative annoyances. They affect cash, liability, implementation, and trust.
Customer-facing onboarding email
Section titled “Customer-facing onboarding email”After verbal agreement, send a clear note:
Thanks for confirming interest in moving ahead.
To keep the process smooth, can we confirm the onboarding path?
1. Who owns vendor registration from your side?2. Is a PO required before invoice or implementation?3. What documents do you need from us for vendor setup?4. Who will review legal/security/privacy, if applicable?5. What are the payment terms after invoice acceptance?6. What date should we target for contract, PO, kickoff, and first payment milestone?
From our side, [name] will own documents and onboarding.Founders should ask these questions early. It is better to discover procurement reality before allocating implementation time.
Data and privacy
Section titled “Data and privacy”If your product handles personal data, customer data, employee data, financial data, health data, children-related data, or confidential business information, privacy cannot be reduced to “we copied a policy page.” India’s data protection framework and rules are active and evolving, and overseas customers may also bring GDPR, SOC 2, HIPAA-like expectations, DPA requirements, or sector rules.
Build a simple data map:
| Question | Founder answer needed |
|---|---|
| What data do we collect? | List user, customer, employee, lead, payment, product usage, support, analytics, and log data. |
| Why do we collect it? | Tie each category to product function, legal obligation, security, billing, support, or analytics. |
| Where is it stored? | Include databases, SaaS tools, spreadsheets, analytics tools, support tools, and backups. |
| Who can access it? | Employees, contractors, vendors, founders, support agents, and integrations. |
| Who do we share it with? | Cloud providers, payment providers, email tools, analytics, CRMs, support tools, and customers. |
| How long do we keep it? | Define retention and deletion logic. |
| What happens during a breach? | Create a response owner, escalation path, notification workflow, and evidence log. |
Your privacy policy should match reality. If your product says one thing and your tools do another, the policy is theatre. The better founder habit is to review the data map whenever you add a major integration, analytics tool, AI workflow, payment flow, or enterprise customer.
The Digital Personal Data Protection Act, 2023 is the key official text founders should understand at a high level. Do not reduce it to a link in the footer. Build practical habits: collect less data, explain purpose, control vendor access, protect data with reasonable safeguards, maintain breach response ownership, and review child, health, finance, HR, and sensitive operational use cases with counsel.
DPIIT and compliance benefits
Section titled “DPIIT and compliance benefits”Startup India’s DPIIT recognition page describes benefits that may include self-certification pathways for eligible recognised startups under specified labour and environmental laws, along with other benefits such as IPR support and tax exemption routes. Treat this as an official process, not a shortcut. Check current eligibility, apply properly, and store certificates and correspondence in the company repository.
Compliance operating system
Section titled “Compliance operating system”Set up a simple monthly review:
- What filings, taxes, payroll, invoices, or payments are due this month?
- What contracts were signed, renewed, breached, delayed, or disputed?
- What employees, contractors, or vendors joined or left?
- What data or security changes happened in the product?
- What board, shareholder, or investor approvals are needed?
- What documents would be missing if diligence started tomorrow?
Assign each item an owner, due date, and folder link. The founder should review the calendar monthly even if the CA/CS does the work.
Compliance Calendar By Frequency
Section titled “Compliance Calendar By Frequency”Your exact calendar depends on entity, state, registrations, business model, headcount, revenue, sector, and cross-border activity. Still, the founder can organize the system by frequency.
| Frequency | What to review |
|---|---|
| Weekly | New contracts, invoices raised, cash collected, overdue receivables, new hires/contractors, customer data incidents, legal notices. |
| Monthly | Books close, payroll, tax-related work, GST/TDS where applicable, vendor payments, bank reconciliation, compliance tracker update. |
| Quarterly | Board/investor update, tax estimates, cap table changes, ESOP grants, major contract obligations, privacy/security changes. |
| Annual | Financial statements, statutory audit where applicable, income tax filing, ROC filings, renewals, policy review, advisor review. |
| Event-based | Fundraise, share issuance, director change, new office, employee threshold, foreign payment, foreign investor, large contract, dispute, breach, shutdown. |
Event-based compliance is where founders get surprised. A company changes, but the calendar stays old. Review the calendar whenever the business model, geography, team, customer type, or funding status changes.
Compliance Owner Table
Section titled “Compliance Owner Table”Create a table and keep it visible.
| Area | Internal owner | External advisor | Proof of completion |
|---|---|---|---|
| Corporate/ROC | Founder or ops owner | CS | Filing receipts, minutes, registers, approvals. |
| Accounting/books | Finance/ops owner | CA/bookkeeper | Monthly MIS, ledger, bank reconciliation. |
| Tax/GST/TDS | Finance/ops owner | CA | Returns, challans, reconciliations, notices. |
| Payroll/people | Founder/HR/ops | Payroll advisor/CA | Salary records, deductions, offer letters, exits. |
| Contracts | Founder/sales/ops | Lawyer | Signed copies, obligation tracker, renewal dates. |
| IP | Product/founder | IP lawyer | Assignments, filings, repository/account records. |
| Data/privacy/security | Product/engineering/founder | Privacy/security counsel where needed | Data map, access list, incident log, policy version. |
Compliance fails when everyone assumes someone else owns it. Put names next to the work.
Compliance Risk Register
Section titled “Compliance Risk Register”Create a live register for issues that are not yet solved. This is more useful than pretending everything is clean.
| Field | What to record |
|---|---|
| Issue | The specific gap: missed filing, unsigned contract, GST question, data issue, unclear IP, pending notice. |
| Area | Corporate, tax, payroll, contracts, data, IP, employment, sector regulation, cross-border. |
| Severity | Low, medium, high, critical. Define severity by cash, legal, customer, investor, or regulatory impact. |
| Owner | One internal person responsible for moving it forward. |
| Advisor | CA, CS, lawyer, privacy counsel, security consultant, or sector expert. |
| Next action | The next concrete step, not a vague “check”. |
| Due date | When the next action must happen. |
| Evidence | Filing receipt, email, legal opinion, corrected contract, board approval, payment proof, policy version. |
The risk register changes founder behaviour. Instead of “we should fix compliance sometime”, the company has named risks, owners, and proof. Investors and acquirers can tolerate known issues more easily than unknown chaos.
Data Incident First 24 Hours
Section titled “Data Incident First 24 Hours”If customer, employee, or user data may have been exposed, deleted, misused, or accessed improperly, do not improvise in private messages.
Use a first-24-hour checklist:
- Preserve evidence: logs, screenshots, emails, access records, deployment history, vendor alerts.
- Limit further exposure: revoke access, rotate keys, pause affected workflow, isolate system where appropriate.
- Name an incident owner: one person coordinates facts, advisors, customer communication, and evidence.
- Create an incident timeline: what happened, when, who noticed, what systems/data may be affected.
- Contact advisors: privacy counsel, security expert, customer contract owner, and leadership as needed.
- Review obligations: contracts, data processing terms, applicable law, sector rules, and customer commitments.
- Communicate carefully: do not guess publicly; share known facts, actions taken, and next update timing.
- Write the postmortem: root cause, affected data, remediation, owner, and preventive controls.
This is not a substitute for legal or security advice. It is a founder response habit. The worst incident response is denial, delay, and undocumented cleanup.
Notices, Disputes, And Exceptions
Section titled “Notices, Disputes, And Exceptions”Founders should create a rule for anything unusual:
- Tax notice.
- Customer legal notice.
- Employee dispute.
- Vendor dispute.
- Data incident.
- Missed filing.
- Payment default.
- Contract breach.
- Threat of litigation.
- Regulatory question.
Do not manage these only on WhatsApp. Create an exception log with date, issue, owner, advisor, documents, current status, next action, and deadline. Most problems become worse because founders delay, under-document, or reply emotionally.
When something looks serious, involve the right advisor early. A small legal bill before a deadline can be cheaper than a large repair effort after one.
Privacy And Security Implementation
Section titled “Privacy And Security Implementation”A privacy policy is not implementation. Implementation means the product and team behave consistently with what the policy promises.
Build these basics:
- Data inventory.
- Access control list.
- Vendor/subprocessor list.
- Retention and deletion rules.
- Incident owner and escalation path.
- Customer data export/deletion process where applicable.
- Employee/contractor confidentiality and data access terms.
- Security basics: 2FA, password manager, least privilege, offboarding, backup, production access rules.
For AI workflows, add:
- What data can be sent to AI tools?
- Which tools are approved?
- Can customer confidential data be used?
- Is generated output reviewed before use?
- Are prompts, logs, or training settings creating exposure?
This is not only for enterprise sales. It protects trust before the company is large enough to hire a security team.
Fundraising Diligence Readiness
Section titled “Fundraising Diligence Readiness”Before starting a fundraise, run a mini diligence check:
| Area | Red flag to fix |
|---|---|
| Corporate | Missing incorporation docs, board approvals, registers, or cap table mismatch. |
| Tax | Unclear GST/TDS/income tax status, unreconciled revenue, missing challans. |
| Contracts | Missing customer/vendor contracts, unsigned amendments, unclear payment obligations. |
| People | Missing employment/contractor agreements, no IP assignment, informal ESOP promises. |
| IP | Founder/agency code not assigned, domain/repository not company-controlled. |
| Data | Copied privacy policy, no data map, no access controls, no incident process. |
| Disputes | Hidden notices, unpaid vendors, employee conflicts, customer claims. |
Investors do not expect perfection at seed stage. They do expect founders to know what is clean, what is messy, and what is being fixed.
The diligence folder
Section titled “The diligence folder”Build the diligence folder before you need it:
- Corporate documents.
- Cap table and share records.
- Board and shareholder approvals.
- Tax registrations and filings.
- Financial statements and bank statements.
- Customer, vendor, employment, contractor, and agency contracts.
- IP assignments and trademark/IP records.
- Data/privacy/security policies.
- Litigation, notices, disputes, or open claims.
- Advisor, consultant, and option records.
- Compliance tracker and open questions.
The folder does not need to be perfect on day one. It needs to exist and improve monthly.
Monthly Compliance Review
Section titled “Monthly Compliance Review”Founders do not need to become lawyers, CAs, or company secretaries. But founders do need a monthly compliance review that makes risk visible.
Run this meeting for 30 minutes once a month with the founder who owns operations, the finance owner, and your CA/CS or internal admin if available.
| Area | Question |
|---|---|
| Corporate records | Were any board, shareholder, share, ESOP, loan, or director matters triggered this month? |
| Tax | Are GST, TDS, income tax, professional tax, payroll, and challans current where applicable? |
| Revenue | Are invoices, credit notes, collections, refunds, and contracts reconciled? |
| People | Did anyone join, leave, convert from contractor to employee, receive ESOP promises, or get access to sensitive systems? |
| IP | Did founders, employees, agencies, interns, or contractors create assets that need assignment? |
| Data | Did we collect, share, export, delete, or expose customer/user data in a new way? |
| Cross-border | Did we receive foreign money, pay foreign vendors, hire overseas, or sign foreign contracts? |
| Open risks | What is messy, late, undocumented, disputed, or dependent on one person? |
The output should be a short note: closed items, open items, owner, deadline, advisor needed, and evidence link. If there is no written output, the review did not happen.
Evidence, Not Memory
Section titled “Evidence, Not Memory”Compliance fails because founders rely on memory. Diligence does not ask whether something “was done.” It asks for proof.
Use an evidence standard:
- Every filing has an acknowledgement, challan, certificate, email, or portal download.
- Every major decision has a board note, shareholder approval, founder memo, or signed document where appropriate.
- Every contract has the final signed copy, order form, amendments, renewal terms, and invoice link.
- Every employee, contractor, intern, agency, and advisor has signed terms and IP/confidentiality coverage.
- Every tax or payroll payment has proof and reconciliation.
- Every policy has an owner, date, version, and adoption evidence.
- Every unresolved issue has an owner and due date.
This may feel heavy for a five-person startup. It is lighter than reconstructing two years of proof during a fundraise.
Compliance Triage
Section titled “Compliance Triage”Not every issue deserves the same urgency. Founders need triage.
| Severity | Examples | Founder response |
|---|---|---|
| Critical | Unpaid statutory dues, serious data incident, missing IP assignment for core product, founder dispute affecting ownership, regulatory notice. | Stop and fix with advisor involvement. Do not bury it. |
| High | Missing employment/contractor agreements, unsigned customer amendments, late filings, unclear GST/TDS treatment, foreign payment uncertainty. | Assign owner and deadline this week. |
| Medium | Messy folder structure, old templates, incomplete policy adoption, missing vendor security review. | Add to monthly cleanup. |
| Low | Formatting, naming, non-critical archive cleanup, duplicate copies. | Fix when improving the data room. |
The founder skill is not pretending everything is equally urgent. It is knowing which compliance gap can damage the company if ignored.
Advisor Operating Rhythm
Section titled “Advisor Operating Rhythm”A CA, CS, lawyer, and tax advisor are only useful if the founder gives them context early enough.
Tell advisors before these events, not after:
- Taking investment, loan, grant, or founder capital.
- Issuing shares, ESOPs, advisor equity, or convertible instruments.
- Hiring employees, contractors, agencies, interns, or consultants.
- Signing enterprise, government, regulated, or cross-border contracts.
- Collecting payments in foreign currency or paying foreign vendors.
- Moving IP, creating a subsidiary, or changing entity structure.
- Handling notices, disputes, layoffs, data incidents, or founder exits.
The cheapest advice usually happens before the action. The most expensive advice happens after founders have already signed, paid, promised, or transferred something.
Common mistakes
Section titled “Common mistakes”Ignoring early records
Section titled “Ignoring early records”The first year feels too small for process. Then a customer asks for documents, an investor begins diligence, or a co-founder dispute appears. Build the repository now.
Copy-paste legal docs
Section titled “Copy-paste legal docs”Copied terms, privacy policies, employment letters, or vendor agreements often do not match your product, jurisdiction, or risk. They create false confidence.
No contract review
Section titled “No contract review”Founders sign early contracts to close revenue. That is understandable. But unlimited liability, broad indemnity, unclear data terms, bad payment terms, or customer ownership of your IP can damage the company.
No IP assignment
Section titled “No IP assignment”Founders, employees, contractors, agencies, and interns should sign the right assignment and confidentiality documents. Product ownership must be boringly clear.
Poor employment and contractor hygiene
Section titled “Poor employment and contractor hygiene”Misclassified workers, vague contractor scopes, weak exit process, and missing confidentiality/IP language create risk. Every person who can touch product, code, data, customers, or brand should have documented terms.
No data policy
Section titled “No data policy”Even if you are early, write basic rules for access, passwords, production data, customer exports, laptops, vendor tools, incident reporting, and deletion. Security culture starts before the first enterprise customer asks for it.
Compliance Calendar Operating System
Section titled “Compliance Calendar Operating System”A compliance calendar is only useful if it creates behaviour. A forgotten spreadsheet is not a system. Build a calendar that makes obligations visible, owned, evidenced, and reviewed.
Use one row per obligation:
| Field | What to capture |
|---|---|
| Obligation | The specific filing, payment, review, renewal, approval, notice, or record. |
| Area | Corporate, tax, payroll, GST, TDS, employment, privacy, IP, contract, sector, cross-border. |
| Trigger | Monthly, quarterly, annual, event-based, contract-based, headcount-based, revenue-based, or notice-based. |
| Owner | The internal person who follows up. Do not put only the external advisor’s name. |
| Advisor | CA, CS, lawyer, payroll vendor, privacy counsel, IP lawyer, security consultant, or sector expert. |
| Due date | The date by which the company must act, or the date by which the advisor must confirm. |
| Proof | Portal receipt, challan, board minutes, filing acknowledgement, signed contract, policy version, email confirmation. |
| Status | Not started, waiting on advisor, waiting on founder, filed, paid, reviewed, disputed, blocked. |
| Next review | The next date this item must be looked at again. |
The founder should review four views every month:
- Due soon: what needs action before the next review?
- Overdue: what is late and why?
- Event triggers: did a new customer, hire, investor, foreign payment, data flow, or office location create a new obligation?
- Evidence gaps: what do we believe is done but cannot prove?
Do not make the calendar over-clever. The best compliance calendar is the one someone opens every month. If you are tiny, a spreadsheet is enough. If you are growing, move it into your operating system, finance workflow, or company wiki. The tool matters less than the ritual: owner, due date, proof, review.
Compliance Control Room
Section titled “Compliance Control Room”As the company grows, compliance should move from “ask the advisor when something happens” to a small control room. This does not mean the founder becomes a legal expert. It means the founder knows what is owned, what is due, what is risky, and what needs escalation.
Build a monthly control room table:
| Area | Owner | Current status | Evidence | Escalation trigger |
|---|---|---|---|---|
| Company records | Green/yellow/red | Board/shareholder records, filings, registers | Missing or outdated records before fundraise or major decision | |
| Tax and accounting | Green/yellow/red | Books, invoices, returns, advisor notes | Unclear revenue treatment, notices, overdue filings | |
| Payroll and people | Green/yellow/red | Offer letters, contractor agreements, payroll records | First hire, exits, ESOP, contractor IP questions | |
| Contracts | Green/yellow/red | Signed agreements, renewals, obligation tracker | Enterprise deal, unusual liability, payment dispute | |
| Data and security | Green/yellow/red | Privacy policy, data map, access list, vendor list | Sensitive data, breach concern, regulated product, large customer review | |
| IP and brand | Green/yellow/red | Assignments, repo access, trademark/domain notes | Agency work, founder exit, open-source release, brand conflict | |
| Fundraising readiness | Green/yellow/red | Cap table, data room, financials, compliance notes | Investor diligence, bridge round, priced round |
The founder should ask three questions:
- What is overdue?
- What changed in the business this month?
- What needs advisor review before we repeat or scale it?
Examples of business changes that should trigger review:
- First paid customer.
- First international customer.
- First employee or contractor.
- First enterprise contract.
- First sensitive-data workflow.
- New financial, health, education, children, employment, lending, or regulated claim.
- New investor instrument.
- Founder role, equity, or access change.
This control room keeps compliance tied to operating reality. Static checklists go stale. Business events create new obligations and risks.
Compliance Escalation Map
Section titled “Compliance Escalation Map”Founders often know something feels risky but do not know whether to call the CA, CS, lawyer, privacy counsel, security expert, investor, or customer. Build an escalation map before a problem appears.
| Event | First internal owner | External advisor to involve | Proof to preserve |
|---|---|---|---|
| Missed filing, late tax payment, or portal notice | Finance/ops founder | CA/CS/tax advisor | Notice, due date, challan, filing acknowledgement, advisor note. |
| Founder equity, share issuance, ESOP, or cap table change | CEO/founder | CS/lawyer/tax advisor | Board/shareholder approvals, cap table version, instrument documents. |
| Enterprise contract with unusual terms | Sales/founder | Startup lawyer, security/privacy advisor where relevant | Redline, risk memo, approved exceptions, obligation tracker. |
| Customer or employee data incident | Product/engineering founder | Security expert, privacy counsel, contract owner | Timeline, logs, affected data map, containment actions, communications. |
| Employee dispute, termination, harassment complaint, or contractor conflict | People/founder | Employment lawyer/HR advisor/CA where needed | Contract, communications, payroll records, access log, investigation notes. |
| Foreign payment, investor, subsidiary, overseas employee, or cross-border IP | Finance/founder | FEMA/tax/cross-border specialist | Contract, invoice, bank advice, remittance proof, structure note. |
| Regulatory claim in product, marketing, or sales | Product/marketing founder | Sector lawyer/domain expert | Claim source, customer-facing copy, review note, approval owner. |
| Founder exit or serious founder dispute | CEO/board/founder group | Lawyer, tax advisor, company secretary | Agreement, vesting status, access map, asset list, communication plan. |
Define response time by severity:
- Same day: notices, data incidents, founder disputes, customer legal threats, missed statutory deadlines, or anything that can affect ownership, money, data, or company control.
- This week: unclear contracts, new employment templates, contractor IP gaps, foreign payment questions, and material vendor/customer risk.
- This month: folder cleanup, policy versioning, routine document gaps, template refresh, and lower-risk evidence collection.
The escalation map prevents the founder from doing two dangerous things: ignoring a real issue because it feels complicated, or escalating every small issue with panic. The right habit is calm speed: identify the issue, preserve proof, involve the right advisor, and record the decision.
Monthly Compliance Review Script
Section titled “Monthly Compliance Review Script”Run this review once a month. It should take 30 minutes for a small startup if the tracker is current.
1. What changed in the business this month?2. What filings, payments, renewals, notices, approvals, or records are due in the next 45 days?3. What is overdue?4. What do we believe is complete but cannot prove?5. Did we sign any contract with obligations the team must now track?6. Did we hire, exit, pay, reimburse, issue, collect, refund, or transfer anything that creates a record?7. Did any customer, vendor, investor, employee, regulator, platform, or bank ask for something we have not documented?8. What needs advisor review before the next month?End with a short note:
Compliance review date:Attendees:Green items:Yellow items:Red items:Advisor questions:Owner/date for each open item:This note becomes diligence evidence later. More importantly, it prevents “I thought someone handled it” from becoming the company’s compliance system.
Compliance Proof Folder
Section titled “Compliance Proof Folder”Create a proof folder with one subfolder per area:
| Folder | What goes inside |
|---|---|
| Corporate | Incorporation docs, board/shareholder approvals, registers, cap table, filings. |
| Tax/accounting | Returns, challans, invoices, ledgers, reconciliations, advisor notes. |
| Payroll/people | Offer letters, contractor agreements, payroll records, exits, reimbursements. |
| Contracts | Customer, vendor, agency, contractor, partnership, lease, and renewal notes. |
| IP/brand | Assignments, trademark notes, repository ownership, domain/social access. |
| Data/security | Privacy policy versions, data map, vendor list, incident notes, access reviews. |
| Fundraising | Instruments, investor consents, data room checklists, diligence questions. |
Name files by date and topic. A messy proof folder is still better than proof scattered across inboxes, WhatsApp, laptops, and advisor portals.
Compliance Evidence Locker
Section titled “Compliance Evidence Locker”Compliance is easiest when evidence is collected as work happens. A folder created during diligence is already late.
Create an evidence locker:
| Folder | Evidence |
|---|---|
| Company | Incorporation docs, registrations, board records, cap table. |
| Tax and filings | GST/TDS/income tax/ROC/professional tax where applicable, filing proofs, advisor notes. |
| People | Offer letters, contractor agreements, payroll records, IP assignments, policy acknowledgments. |
| Customers | Contracts, invoices, DPAs, security questionnaires, support obligations. |
| Vendors | Vendor contracts, data access notes, payment proofs, critical vendor list. |
| Data and privacy | Privacy policy, terms, consent flows, data map, incident process, retention rules. |
| Fundraising | Term sheets, investment documents, filings, investor rights, board approvals. |
This is an operating checklist, not legal advice. Use qualified professionals for interpretation, but do not outsource evidence collection.
Compliance Change Log
Section titled “Compliance Change Log”Every startup changes: new state, new customer type, new payment method, new employee category, new AI workflow, new foreign customer, new vendor, new product claim. Each change may create compliance questions.
Maintain a log:
| Change | Possible compliance question | Owner | Advisor needed? | Status |
|---|---|---|---|---|
| First enterprise customer | Contract, data, security, tax, invoicing | |||
| First foreign customer | Export, tax, FEMA/bank documentation where relevant | |||
| First employee in new state | Labour, professional tax, local registration where relevant | |||
| First sensitive data workflow | Consent, privacy, retention, security | |||
| First AI-generated customer output | Accuracy, disclosure, data use, human review |
The habit is simple: when the business changes, ask whether obligations changed too.
Notice And Demand Response Protocol
Section titled “Notice And Demand Response Protocol”Founders should not ignore legal, tax, customer, employee, vendor, platform, or government notices. Silence can convert a manageable issue into a serious one.
Protocol:
- Save the notice exactly as received.
- Record date, source, deadline, and required response.
- Assign an internal owner.
- Decide whether CA, CS, lawyer, or other expert review is needed.
- Stop informal replies until facts are clear.
- Gather documents and communication history.
- Respond in writing through the right channel.
- Save final response and next steps in the evidence locker.
The founder does not need to panic. But the founder should never let official or contractual deadlines drift in chat.
Compliance Advisor Queue
Section titled “Compliance Advisor Queue”Founders often keep compliance questions scattered across chat, email, and memory. Create a single advisor queue so CA, CS, lawyer, payroll, banker, and internal owners can work from the same reality.
Use this table:
| Question | Area | Urgency | Advisor | Owner | Status | Evidence needed |
|---|---|---|---|---|---|---|
| ROC/MCA | High/Medium/Low | CS | ||||
| GST/TDS/tax | High/Medium/Low | CA | ||||
| Contract/data/privacy | High/Medium/Low | Lawyer | ||||
| Payroll/people | High/Medium/Low | Payroll/HR/legal | ||||
| Foreign payment/FEMA/banking | High/Medium/Low | CA/banker/counsel |
Prioritize:
| Priority | Meaning |
|---|---|
| High | Has deadline, money, government, employee, customer, investor, or data-risk impact. |
| Medium | Needed before next customer, hire, fundraise, or product launch. |
| Low | Useful cleanup or future planning. |
This makes advisor calls more productive. Instead of asking vague questions, the founder brings facts, deadlines, documents, and decisions needed.
Compliance Runway
Section titled “Compliance Runway”Compliance has runway just like cash. Some issues can wait. Some become expensive if ignored. Some block fundraising, enterprise sales, hiring, payments, or shutdown.
Classify each issue:
| Type | Example | Founder move |
|---|---|---|
| Fire | Notice, deadline, unpaid statutory item, employee/customer complaint, data incident. | Assign owner today and get advisor input. |
| Blocker | Required for fundraising, customer onboarding, payroll, invoicing, or bank process. | Put in weekly operating review until closed. |
| Cleanup | Missing folder, old contract, stale policy, unclear access. | Batch into monthly cleanup sprint. |
| Future trigger | Foreign customer, new state, regulated sector, AI/data workflow, ESOP. | Log now; review before trigger happens. |
Do not let compliance become founder anxiety. Convert it into a queue, owner, deadline, and proof folder.
Compliance Cost Of Delay Map
Section titled “Compliance Cost Of Delay Map”Not every compliance issue has the same urgency. Some are harmless cleanup. Some become expensive, block deals, or create personal stress for founders. Map the cost of delay so the team knows what to fix now.
| Issue type | If delayed | Founder action |
|---|---|---|
| ROC/company records | Diligence delays, penalties, trust loss | Close with CS and save proof. |
| GST/TDS/tax | Interest, notices, payment friction, customer invoice issues | Review with CA and track deadlines. |
| Payroll and contractor paperwork | Employee disputes, IP gaps, tax confusion | Standardize contracts and payment records. |
| Data/privacy/security | Enterprise sales friction, incident risk, trust damage | Create policy, data map, incident owner. |
| FEMA/foreign receipts | Banking delays, remittance questions, funding complexity | Consult CA, banker, and counsel before transaction. |
| ESOP/equity records | Employee trust issues and investor questions | Maintain cap table, grants, approvals, and communications. |
| Customer/vendor contracts | Hidden obligations, payment leakage, liability | Review red flags before signing. |
Delay decision rule
Section titled “Delay decision rule”Use this rule:
Fix immediately if the issue affects government deadlines, employee rights, customer trust, investor diligence, bank/payment flow, foreign money, data risk, or ownership.Batch later if it is only evidence cleanup with no near-term trigger.This keeps founders from doing two bad things: ignoring serious compliance because it feels boring, and wasting scarce time polishing low-risk paperwork while customers and product need attention.
Compliance Event Trigger Checklist
Section titled “Compliance Event Trigger Checklist”Calendar compliance catches recurring work. Event-triggered compliance catches change. Most founder surprises happen because the company changed and nobody updated the compliance system.
Run this checklist when any event happens:
| Event | Questions to ask |
|---|---|
| First employee | Employment agreement, payroll, deductions, leave, IP/confidentiality, equipment, access, and state obligations. |
| First contractor or agency | Scope, payment, GST/TDS treatment, IP assignment, confidentiality, access, and handover. |
| First enterprise customer | Contract, DPA/security, GST/invoice, PO/vendor onboarding, SLA, support, and liability. |
| First foreign payment | FEMA/banking, tax, invoice, contract, withholding, purpose code, and documentation. |
| First sensitive data workflow | Privacy notice, consent/legal basis, retention, access, breach response, vendor data terms. |
| First ESOP/advisor equity promise | Approval, plan, tax, communication, vesting, cap table, and signed documents. |
| First large vendor or cloud commitment | Contract owner, renewal, data/security, payment terms, access, and exit plan. |
| First official notice or complaint | Deadline, owner, advisor, documents, communication channel, and response proof. |
Use this operating rule:
Whenever the company does something for the first time, ask: what new legal, tax, people, data, IP, finance, or governance obligation did this create?This does not mean slowing every decision. It means treating new company behavior as a trigger to update the operating system.
Reader action
Section titled “Reader action”Create a compliance tracker with eight tabs: corporate, tax, payroll, contracts, people, data/privacy, IP, and open questions. Add owner, due date, status, folder link, and advisor. Review it every month with founders.
Official references
Section titled “Official references”- Ministry of Corporate Affairs
- Companies Act, 2013 on India Code
- GST Portal
- Income Tax e-Filing Portal
- Startup India DPIIT Recognition and Benefits
- Digital Personal Data Protection Act, 2023
- CERT-In Directions under section 70B of the IT Act