Skip to content

Compliance Checklist

Compliance is not a founder’s favorite topic, but it is part of trust.

This page is not legal, tax, or accounting advice. Use it as a preparation checklist before speaking with a CA, CS, lawyer, payroll partner, or internal finance owner.

The founder’s job is not to personally execute every filing. The founder’s job is to make sure the company has owners, records, reminders, and professional review before avoidable issues become expensive.

Keep these organized from the beginning:

  • Incorporation documents
  • PAN and tax identity records
  • Board and shareholder records
  • Cap table
  • Founder agreements
  • Share issuance records
  • ESOP plan and grants, if any
  • Registered office records
  • Bank account documents
  • Auditor, CA, CS, and legal contact details

Founder question: if an investor, acquirer, bank, or regulator asks for this document, can we find the latest version in ten minutes?

The compliance burden changes by stage. Use this as a founder planning guide before speaking with professionals.

StageFounder focus
Idea and pre-incorporationAvoid premature complexity, but document founder contributions, IP, domain ownership, and any serious customer/vendor promise.
IncorporationChoose entity deliberately, document founder ownership, open bank/accounting systems, and set up professional advisors.
First revenueConfirm invoicing, GST/TDS questions, payment terms, contract templates, revenue classification, and collections process.
HiringUse written offers, contractor agreements, IP/confidentiality terms, payroll records, access controls, and exit process.
FundraisingPrepare cap table, board/shareholder records, due diligence folder, ESOP plan, filings, investor docs, and use-of-funds records.
Enterprise salesPrepare contracts, security/privacy answers, insurance if needed, data handling, vendor onboarding, and renewal/termination tracking.
Expansion or exitClean financials, contracts, IP, tax records, regulatory exposure, employee records, and data/security posture.

Do not treat compliance as one giant cleanup. Treat it as stage-appropriate hygiene.

Review with your CA:

  • Accounting system setup
  • Chart of accounts
  • Revenue classification
  • Recurring versus one-time revenue
  • GST applicability and invoicing treatment
  • TDS or withholding obligations where relevant
  • Expense documentation
  • Vendor payments
  • Customer collections
  • Bank reconciliation
  • Monthly management reports

Do not let tax and accounting live only in WhatsApp messages and scattered spreadsheets. Early mess becomes later diligence pain.

For employees, interns, consultants, and contractors, keep:

  • Offer letters or engagement letters
  • Compensation details
  • Joining documents
  • IP assignment language where appropriate
  • Confidentiality obligations
  • Payroll records
  • Reimbursement records
  • Leave and attendance process
  • Exit documents and access removal checklist

Founder mistake: hiring fast without collecting paperwork, then trying to repair records during fundraising, audits, or disputes.

Store signed versions of:

  • Customer contracts
  • Pilot agreements
  • Vendor agreements
  • Agency contracts
  • Contractor agreements
  • Partnership agreements
  • NDAs
  • Data processing or security addendums where relevant
  • Renewal and termination notices

For each important contract, know:

  • Effective date
  • Renewal date
  • Payment terms
  • Termination rights
  • Liability caps
  • Data or confidentiality obligations
  • Owner inside the company

Review:

  • Founder IP assignment
  • Employee IP assignment
  • Contractor IP assignment
  • Open-source dependency awareness
  • Domain ownership
  • Trademark search and filing plan where relevant
  • Logo, design, copy, and content ownership
  • Customer permission for case studies and logos

IP issues are easiest to fix before people leave, vendors disappear, or the company becomes valuable.

Map:

  • What customer data you collect
  • Where it is stored
  • Who can access it
  • Which vendors process it
  • How long you retain it
  • How customers can ask questions
  • What security controls exist
  • What happens during an incident

If you sell to enterprise customers, prepare a basic security and privacy response pack before sales asks for it.

Create a calendar with:

  • Monthly items
  • Quarterly items
  • Annual items
  • Event-based items, such as funding, share issuance, board actions, hiring, and major contracts
  • Renewal dates
  • Filing owners
  • Professional reviewer
  • Evidence link after completion

The calendar should not be owned only by an external advisor. Someone inside the company must know what is due and whether it was done.

Certain events should trigger a compliance review even if the calendar is quiet.

EventReview
New co-founder or equity promiseFounder agreement, vesting, board/shareholder approvals, cap table, tax/legal advice.
First customer contractContract template, invoicing, GST/TDS, data/security promises, payment terms.
First employee or contractorOffer/engagement letter, payroll/contractor status, IP/confidentiality, access management.
Fundraising conversation becomes seriousData room, cap table, board records, filings, ESOP, financial model, investor docs.
New country or stateTax, invoicing, employment, data, contract, and regulatory implications.
Handling sensitive customer dataPrivacy notice, data map, access control, retention, vendor processing, security review.
Major vendor or agencyContract, IP ownership, data access, payment terms, termination rights.
Shutdown or sale discussionsObligations, records, employee/customer communication, contracts, taxes, IP, data.

Event triggers catch issues that monthly calendars miss.

Before meeting a CA, CS, lawyer, payroll partner, or tax advisor, prepare:

FieldNotes
Company entity and structure
Current founders/shareholders
Employees, contractors, interns
Revenue lines and customer types
States/countries where customers are located
Vendor and contractor locations
Funding history and planned funding
ESOP or equity promises
Regulated activities, if any
Customer data collected
Open questions

Advisors can help faster when founders bring context instead of scattered screenshots.

Use a simple folder structure from the beginning.

FolderExamples
01 Company recordsIncorporation, PAN, GST, board/shareholder records, registered office.
02 Ownership and equityCap table, founder agreements, share issuance, ESOP.
03 Finance and taxInvoices, bank statements, filings, reconciliations, management reports.
04 CustomersContracts, SOWs, renewals, amendments, data/security addendums.
05 Vendors and contractorsAgreements, invoices, IP/confidentiality terms.
06 PeopleOffer letters, payroll, contractor records, exits, access removal.
07 IP and brandAssignments, trademarks, domains, licenses, open-source notes.
08 Security and dataData map, access review, incident notes, vendor processing.
09 Fundraising and governanceDecks, memos, investor docs, board notes, approvals.

Name files with date, party, and document type. Clean naming saves hours during diligence.

Use this before fundraising, debt, strategic partnership, or acquisition conversations.

AreaGreenYellowRed
Company recordsOrganized and currentMostly present, some missing linksScattered or unclear
Cap tableCurrent and reconciledNeeds advisor reviewFounder/investor ownership unclear
ContractsSigned versions storedSome unsigned or email-only termsMaterial contracts missing
IPFounder/employee/contractor assignments organizedSome older gapsCore IP ownership uncertain
FinanceRevenue, invoices, bank, and accounting reconcileManual cleanup neededNumbers conflict across sources
Payroll/peopleRecords and exits cleanSome paperwork missingSalary, contractor, or exit disputes
Security/dataAccess and data map knownPartial reviewUnknown access or customer data exposure risk

Yellow is normal early. Red should become a founder priority before the company enters a high-trust transaction.

Once a month, ask:

  • What was due?
  • What was completed?
  • What is blocked?
  • Which documents are missing?
  • Which contracts need renewal or closure?
  • Which payments or invoices need reconciliation?
  • Which founder decision needs professional review?

This can take fifteen minutes if the system is clean. It can take weeks if ignored.

Not every compliance issue deserves the same founder attention. Use this ladder to decide what gets handled by the team, what needs advisor review, and what needs founder escalation.

SeverityExampleResponse
LowMissing document link, outdated folder name, minor contract metadata gap.Assign owner and cleanup date. Review in the next operating review.
MediumInvoices not reconciled, unsigned vendor paperwork, contractor records incomplete, access removal not confirmed.Put into weekly review until closed. Ask advisor if legal, tax, IP, or payroll interpretation is needed.
HighFounder equity unclear, core IP assignment missing, customer data obligations unknown, tax/GST issue unresolved, investor diligence mismatch.Founder owns the cleanup plan. Professional advisor reviews before fundraising, enterprise sale, or expansion.
CriticalRegulated activity uncertainty, legal notice, customer data incident, payroll dispute, major tax demand, misleading investor/customer document.Stop casual handling. Bring in qualified professional support, document facts, and communicate deliberately.

The point is not to panic. The point is to stop treating all issues as the same. A missing folder link and an unclear founder equity promise do not belong in the same queue.

For every meaningful compliance item, keep evidence. “Our CA handled it” is not evidence unless the company can find the confirmation, filing, receipt, document, or workpaper.

ItemEvidence to save
Filing completedAcknowledgement, receipt, form copy, advisor confirmation, date completed.
Contract signedFully executed PDF, amendment history, renewal date, owner.
Tax/invoice reviewAdvisor note, invoice sample, classification decision, open questions.
Employee/contractor onboardingSigned offer or agreement, IP/confidentiality terms, identity/payroll documents where applicable.
Board/shareholder approvalMeeting note, resolution, consent, filing link if any.
Access reviewTool list, admin list, removed users, exceptions, next review date.

Use one simple rule: if the company later needs to prove that something happened, save the proof now.

Founders do not need a complex governance system early. They need a clear dashboard.

MetricGreenWarning
Compliance calendarAll current-month items have owner and due date.Due dates live only with an external advisor.
Contract repositorySigned contracts are searchable by customer/vendor/date.Important terms are buried in email or WhatsApp.
IP paperworkFounders, employees, and contractors have documented ownership/assignment where relevant.Core product work was done without clear paperwork.
Finance reconciliationRevenue, invoices, bank collections, and receivables are reviewed monthly.Numbers differ between deck, model, invoices, and bank.
Access hygieneAdmin access is reviewed and offboarding removes access quickly.Ex-employees, contractors, or agencies retain access.
Advisor cadenceCA/CS/legal questions are batched and reviewed before key events.Professional review happens only during crisis.

Review this dashboard monthly, and before fundraising, enterprise procurement, debt, strategic partnership, or acquisition conversations.

Treat these as urgent cleanup signals:

  • No single source for company documents
  • Founder equity not documented clearly
  • Contractors built core IP without proper assignment
  • Revenue numbers do not match invoices and bank collections
  • Important contracts exist only in email threads
  • Employees or vendors retain access after leaving
  • Compliance due dates are known only to one external person
  • Investors ask diligence questions and the team scrambles

Compliance work should be boring, visible, and owned.

Use this rhythm:

RhythmAction
Weekly when messyClean missing records, invoices, contracts, and access.
Monthly when stableReview calendar, payments, contracts, payroll, and advisor questions.
Before fundraisingRun diligence readiness table and close red gaps.
After major eventsUpdate records after funding, share issuance, hiring, exits, major contracts, or product data changes.

The goal is not to become a compliance expert. The goal is to make the company trustworthy and easy to review.

When you meet a CA, CS, lawyer, payroll advisor, or sector specialist, bring a clean pack. It saves time and reduces vague advice.

Advisor topicBring
Company recordsIncorporation documents, cap table, board/shareholder notes, current questions.
Tax/accountingRevenue model, invoice samples, bank statements, expense categories, open tax/GST/TDS questions.
ContractsCustomer/vendor templates, unusual clauses, renewal dates, unsigned or email-only agreements.
Employment/contractorsOffer/contractor templates, IP/confidentiality terms, payroll records, exits, ESOP questions.
Data/securityProduct data map, customer data handled, access list, subprocessors/vendors, incident questions.
FundraisingCurrent cap table, past instruments, proposed terms, investor residency/type, use of funds.

Do not ask advisors, “Is everything okay?” Ask specific questions with documents in front of them.

Run a review when these events happen.

EventReview
First paid customerInvoice/tax treatment, contract terms, payment path, data/security obligations.
First hire or contractorOffer/contract, payroll/advisor setup, IP/confidentiality, access provisioning.
Fundraise startsCap table, filings, data room, financials, contracts, previous instruments.
Enterprise dealSecurity, data, liability, SLA, procurement, commercial terms, support promise.
New regulated featureLegal/sector review before launch, not after customer complaints.
Founder equity changeDocumentation, approvals, tax/legal/advisor review.
Shutdown or asset saleStakeholder obligations, records, data, vendors, employees, investors, filings.

Calendars catch routine work. Event triggers catch the moments when the company changes shape.

For material issues, write a short memo.

FieldNotes
Issue
Business decision affected
Facts known
Documents reviewed
Advisor consulted
Options
Chosen path
Risk accepted
Owner and date
Evidence saved

This memo is not a substitute for professional advice. It is a way to make founder decisions traceable.

Some compliance questions can wait for a routine review. Others need immediate advisor attention.

SituationEscalation
First version of routine customer/vendor contractScheduled lawyer review.
First hire, ESOP promise, or contractor IP arrangementLawyer/HR/payroll advisor before signing.
Fundraise, share issuance, or investor instrumentLawyer, CS, and tax/accounting review before execution.
Customer data, regulated data, financial/health/children data, or breach concernLegal/security/sector expert review immediately.
Tax notice, legal notice, employee dispute, customer claim, or regulator communicationProfessional advisor immediately.
Shutdown, asset sale, founder exit, or major equity changeLawyer, CS, accountant, and board/investor process review.

Use this triage:

Risk levelFounder action
LowRecord the issue, owner, and next review date.
MediumAsk advisor before repeating the activity or signing more agreements.
HighPause the action until advice is received and documented.

The most expensive compliance issues often begin as “small exceptions.” Escalate when the exception could affect ownership, money, data, employees, customers, regulated activity, or fundraising diligence.

If the company already has scattered documents, unclear owners, or pending advisor questions, do not try to fix everything in one weekend. Run a focused 90-day cleanup sprint.

PeriodFocusOutput
Days 1-15InventoryList company records, contracts, finance files, people records, IP documents, access lists, and open advisor questions.
Days 16-30Risk sortMark each gap low, medium, high, or critical using the severity ladder. Founder owns high and critical items.
Days 31-45OwnershipAssign internal owner, external advisor, due date, evidence location, and next decision for each important gap.
Days 46-60Core cleanupClose missing founder, equity, IP, contract, payroll, invoice, and access items that could affect fundraising, sales, or disputes.
Days 61-75Process setupCreate the compliance calendar, repository structure, naming convention, and monthly review habit.
Days 76-90Diligence rehearsalRun the diligence readiness table and ask: what would still embarrass us if an investor, enterprise customer, bank, or acquirer asked tomorrow?

The sprint should produce fewer open loops, not a beautiful folder with the same unresolved risks. Track each issue until it has one of four outcomes: closed, advisor-reviewed, accepted risk, or blocked with next action.

Compliance fails when everyone assumes the CA, CS, lawyer, founder, or finance person is handling it. Write an owner map.

AreaInternal ownerExternal reviewerReview rhythm
Company records and filingsFounder/opsCS/lawyer where neededMonthly and event-based
Accounting and taxFinance/founderCA/tax advisorMonthly
Payroll and people recordsPeople/opsPayroll advisor/lawyerMonthly and on every joiner/exit
ContractsFounder/sales/opsLawyerBefore signing and renewal
IP and brandFounder/product/opsLawyer/IP advisorOn new contractor, employee, vendor, or brand asset
Data and securityFounder/engineeringLegal/security advisor when sensitiveQuarterly or before enterprise deals
Fundraising/data roomFounder/financeLawyer, CS, CABefore and during raise

The internal owner does not need to be an expert. They need to know what is due, where evidence lives, which advisor to ask, and when the founder must decide.

When fundraising, enterprise procurement, debt, acquisition, or a serious partnership starts, compliance gaps stop being abstract. They become blockers, valuation pressure, delay, or trust loss. Use a closure board instead of a vague “cleanup” list.

GapWhy it mattersRisk levelInternal ownerAdvisor/reviewerEvidence neededDue dateStatus
Missing founder IP assignmentCore product ownership may be questioned.HighLawyerSigned assignment or advisor-reviewed fix
Unsigned customer pilot termsRevenue and obligations may be unclear.Medium/HighLawyer/salesExecuted agreement or cleanup note
Revenue does not match bank collectionsInvestor/acquirer may distrust financials.HighCAReconciliation and explanation
Contractor access still activeSecurity and IP risk.MediumEngineering/opsAccess removal proof
ESOP promise not documentedEmployee trust and cap table risk.HighLawyer/CSGrant record, board approval, employee communication
Data subprocessors not listedEnterprise/security review risk.MediumLegal/securityVendor list and data-use note

Run the board weekly until every material item has one of four states:

StateMeaning
ClosedEvidence exists and is stored.
Advisor-reviewedRisk is understood and documented, even if no perfect fix exists.
Accepted riskFounder, board/advisors, and relevant stakeholders understand the risk.
BlockedThe next action, owner, and escalation are explicit.

Do not mark a gap as closed because someone “will handle it.” A gap closes when the company can show the document, reconciliation, approval, advisor note, or evidence trail.

Founders often underuse advisors by asking broad questions like “Is this okay?” Better questions create better answers.

AreaBetter advisor question
Incorporation and structureGiven our funding plan, customer geography, and founder situation, what structure creates the least avoidable future friction?
GST/tax/invoicingWhat exactly should our invoice look like for this revenue type, and what records should we save every month?
Contractor and IPDoes this agreement clearly assign the work product to the company, and what happens if the contractor reuses code or assets?
ESOPWhat should employees understand about grant size, vesting, exercise, tax, and liquidity before we make promises?
Customer contractsWhich clauses create disproportionate risk for our stage, and what fallback language should we use?
Data/securityWhat data are we collecting, who processes it, and what minimum policy, access, and incident records should exist now?
FundraisingWhat documents must be clean before sending the data room, and which gaps could slow closing?
Shutdown or saleWhat obligations survive after operations stop, and what records must be preserved?

After every advisor meeting, write a short note:

Question asked:
Documents reviewed:
Advisor answer:
Decision for the company:
Risk accepted:
Owner:
Evidence saved at:
Review trigger:

This keeps professional advice connected to operating decisions. It also prevents founders from relying on vague memory months later when investors, customers, employees, or acquirers ask for proof.

Before sharing a data room, run this mini-audit. It is designed for founders, not lawyers. The goal is to catch trust-breaking gaps before an investor, enterprise customer, bank, or acquirer catches them.

Diligence questionProof to prepareOwnerDo not say
Who owns the company?Current cap table, share issuance records, founder agreements, investor instruments, ESOP summary.Founder/CS/lawyer”The cap table is roughly this.”
Who owns the product/IP?Founder, employee, contractor, agency, and vendor IP/confidentiality documents; domain and repository ownership.Founder/legal/product”Our developer built it, so it is ours.”
Are revenues real and reconciled?Invoices, bank collections, receivables aging, refunds/credits, revenue recognition note.Finance/CA/founder”MRR is what we expect to collect.”
Are customer obligations clear?Signed contracts, SOWs, pilots, SLAs, data/security addendums, renewal dates, support promises.Sales/ops/legal”The agreement is in email somewhere.”
Are people and ESOP promises clean?Offer letters, contractor agreements, payroll records, exits, ESOP grants/promises, vesting communication.Founder/people/legal”We verbally promised equity but will sort it later.”
Are taxes and filings current enough?GST/TDS/income tax/accounting status, advisor notes, open demands, pending filings, reconciliation.Finance/CA”Our CA has everything” without evidence.
What customer/user data do you handle?Data map, privacy policy, access list, vendor/subprocessor list, incident record, retention/deletion policy.Founder/engineering/legal”We do not have data risk” before mapping data.
Are there hidden disputes or notices?Legal notices, tax notices, employee/vendor/customer disputes, settlement notes, advisor position.Founder/legal/finance”Nothing material” without asking the right owners.
Is the round use of funds credible?Runway model, hiring plan, milestone plan, burn assumptions, bridge scenario, board/founder approval where needed.Founder/finance”We will use it for growth.”

If a serious investor asked for diligence tomorrow, the founder should be able to answer these in 48 hours:

CheckPass condition
Single source of truthThe latest deck, memo, model, cap table, and CRM use the same numbers and definitions.
Proof folderEvery important claim has a supporting file, note, contract, metric export, or advisor-reviewed explanation.
Open gaps listKnown gaps are listed with risk level, owner, advisor, and expected closure date.
Advisor contextCA, CS, lawyer, and key operators know a raise or diligence event is happening.
Founder answer bankThe founder can explain top risks honestly without improvising or hiding.

If the company fails this check, do not panic. Create a two-week diligence cleanup sprint and tell investors what is true. Trust is built faster by clear gaps than by confident confusion.