Compliance Due Diligence: What Investors Actually Check
What VCs and PE investors review during compliance due diligence on Indian startups - labour, tax, ROC, IP and data protection - and how to prepare.
Investors doing due diligence on an Indian startup are not just checking financial statements - they are systematically working through corporate, labour, tax and regulatory filings looking for anything that could become their problem after the round closes, and gaps found here routinely affect valuation, deal terms, or timelines.
Key facts at a glance
- Compliance due diligence typically covers corporate/ROC, labour and employment, tax and GST, IP, contracts, and increasingly data protection.
- Investors commonly review at least the last 3 years of filings, financials and disputes, sometimes longer for tax and litigation history.
- PF and ESI registration status and payment history are checked once headcount crosses the applicable statutory thresholds.
- A POSH Internal Committee is expected wherever a company has 10 or more employees, and its absence is a frequently flagged gap.
- DPDP Act readiness is increasingly reviewed, since full substantive obligations become enforceable from 13 May 2027.
- Findings do not always kill a deal - they often lead to remediation conditions, escrow holdbacks, or valuation adjustments.
- Running an internal compliance review before opening the data room lets founders fix straightforward gaps before an investor's advisors find them.
What "compliance due diligence" actually covers
Due diligence on a funding round is usually split into legal, financial, tax and sometimes technical/IP workstreams, with compliance review sitting mostly inside the legal track. It is less about whether the company is perfect and more about whether the risks are known, quantifiable, and being managed - undisclosed gaps are treated far more seriously than disclosed ones with a remediation plan.
Corporate and ROC records
Investors verify the company's incorporation documents, MOA/AOA, cap table history, and every ROC filing tied to share allotments, board changes, and charges. A clean cap table with matching share certificates, board resolutions, and Form PAS-3 filings for every allotment is one of the fastest things to check and one of the most common places gaps show up, especially around earlier ESOP exercises or SAFE/convertible note conversions.
Labour and employment compliance
This is often underestimated by first-time founders. Investors typically check PF and ESI registration once the relevant headcount thresholds are crossed, employment contract completeness, gratuity accrual, and whether a POSH Internal Committee exists and is properly constituted wherever the company has 10 or more employees. A missing ICC is a recurring red flag precisely because it is cheap and simple to fix, so its absence signals broader compliance neglect rather than being a serious issue on its own.
Tax and GST history
Reviewers look at whether tax returns and GST returns have been filed on time, whether there are any pending assessments, notices, or disputes, and whether TDS obligations have been consistently met. Unresolved tax notices, even for modest amounts, tend to get flagged because they represent unquantified future liability.
Common due diligence document requests
| Category | Typical documents requested |
|---|---|
| Corporate | Incorporation certificate, MOA/AOA, cap table, board minutes, statutory registers |
| Labour | PF/ESI registration and challans, employment contracts, POSH ICC records |
| Tax and GST | Tax returns, GST returns, TDS filings, any notices or assessment orders |
| Contracts | Customer, vendor and lease agreements, especially those with change-of-control clauses |
| IP | Trademark/patent filings, IP assignment agreements from founders and employees |
| Data protection | Privacy policy, data processing agreements, breach history, DPDP readiness |
| Litigation | Pending or past litigation, arbitration, regulatory notices |
Data protection is becoming a standard checkpoint
Where compliance due diligence used to focus almost entirely on labour and tax, data protection readiness is now a routine addition, particularly for consumer-facing or data-heavy startups. Investors want to understand what personal data the company collects, how consent is obtained, whether a privacy policy and data processing agreements exist with vendors, and whether the company has a plan for the DPDP Act's full substantive obligations, which become enforceable from 13 May 2027 with no stated grace period. A startup that has not started this work risks a scramble close to that date, and investors would rather see a plan now than a surprise later.
What happens when due diligence finds a gap
A finding rarely kills a round outright unless it is severe (active litigation with material exposure, undisclosed liabilities, or fraud indicators). More commonly, investors respond in one of a few ways:
- Remediation as a condition to closing - the company must fix specific gaps (for example, register the POSH ICC, complete an overdue ROC filing) before funds are released.
- Escrow or holdback - a portion of the investment is held back pending resolution of an identified risk.
- Representations and warranties adjustments - the definitive agreements are drafted to shift specific, known risks onto the company through indemnities.
- Valuation impact - larger or systemic gaps can affect the negotiated valuation itself.
Preparing before the data room opens
The most effective founders run an internal compliance review before actively fundraising, rather than during it, giving enough runway to fix routine gaps - a missed filing, an unregistered ICC, an outdated employment contract template - quietly, instead of under the time pressure of an active term sheet.
If you are not sure where your company currently stands on the areas investors check, ComplianceCheck's state-wise compliance assessment can give you a clear picture in a few minutes.
Sources
- Ministry of Corporate Affairs - mca.gov.in
- Employees' Provident Fund Organisation - epfindia.gov.in
- Employees' State Insurance Corporation - esic.gov.in
- MeitY (DPDP Act and rules) - meity.gov.in
- Income Tax Department - incometax.gov.in
This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.
Frequently Asked Questions
- What documents do investors typically request first in due diligence?
- Usually the certificate of incorporation, MOA and AOA, cap table, board and shareholder resolutions, statutory registers, past ROC filings, financial statements, and material contracts - these form the baseline document request list.
- Do investors check labour law compliance even for small startups?
- Yes, especially PF and ESI registration and payment history once headcount crosses the applicable thresholds, along with employment contracts, POSH Internal Committee constitution if 10 or more employees, and any pending labour disputes.
- How far back do investors typically look for compliance issues?
- There is no fixed rule, but investors commonly review at least the last 3 years of filings and financials, and longer for specific risk areas like tax assessments or litigation, which can be examined as far back as records are retained.
- Does a startup's DPDP Act readiness get checked during due diligence?
- Increasingly yes, particularly for startups handling significant volumes of personal data, since the DPDP Act's full obligations become enforceable from 13 May 2027 and investors want to know a portfolio company will not face late, costly remediation.
- What is the difference between legal due diligence and financial due diligence?
- Legal due diligence, which includes compliance review, focuses on corporate structure, contracts, regulatory filings and litigation risk; financial due diligence focuses on the accuracy of financial statements, revenue quality and accounting practices - most funded rounds involve both, sometimes by different advisors.
- Can unresolved compliance gaps kill a funding round?
- They can delay or reprice a round even if they do not kill it outright - investors commonly ask for gaps to be fixed before closing, hold back part of the funds in escrow, or adjust valuation and representations in the definitive agreements to account for known risk.
- Should a startup run its own compliance check before fundraising?
- Yes, a pre-emptive internal review before opening data rooms lets founders fix straightforward gaps - like a missed ROC filing or an unregistered POSH Internal Committee - before an investor's advisors find them and use it as a negotiating point.
Check your status
State-Wise Compliance Check
Identifies which state-specific laws apply to your business — Professional Tax, Labour Welfare Fund, and Shops & Establishment deadlines.