From Legal Due Diligence to SPA in India: How M&A Red Flags Change Price, Indemnity, Escrow & Closing

By Adv. Govind Bali
Fastrack Legal Solutions LLP

Legal due diligence in an acquisition is not complete when lawyers deliver a list of defects. The real purpose of M&A due diligence is to answer a more commercially significant question: what should the buyer do about each risk before it acquires the target?

A due-diligence finding should ordinarily lead to one or more transaction responses: price adjustment → condition precedent → remediation before closing → specific indemnity → escrow or holdback → representation and warranty → covenant → closing deliverable → restructuring of the transaction → or, in an extreme case, withdrawal from the deal.

That is the point at which due diligence stops being merely an investigation exercise and becomes deal protection.

For the underlying diligence workstream, see our M&A Due Diligence Checklist for Private Companies in India and M&A Legal Due Diligence page.


Due Diligence Should Change the Deal

A weak due-diligence report says: “The target has pending litigation of ₹4 crore.”

A transaction-focused report says:

  • Risk: ₹4 crore litigation involving a pre-closing event.
  • Probability: Medium/High.
  • Potential exposure: ₹4 crore plus interest and costs.
  • SPA treatment: Specific indemnity.
  • Economic protection: Escrow, holdback or negotiated price protection.
  • Closing requirement: Updated litigation status and no material adverse order before closing.
  • Post-closing responsibility: Clearly allocated conduct of defence and settlement authority.

The second formulation helps the investment committee, finance team and transaction lawyers actually decide the deal. That should be the standard.


What Happens After Legal Due Diligence?

Once diligence is substantially complete, findings should be divided into transaction-response categories.

Finding Typical Transaction Response
Minor compliance defect Post-closing covenant
Curable but important defect Condition precedent
Quantifiable historic liability Price adjustment, holdback or specific indemnity
Uncertain contingent liability Indemnity + escrow + survival period
Fundamental legality, title or regulatory problem Restructure or reconsider acquisition

The buyer should resist treating every red flag alike. A missed procedural filing is not equivalent to disputed ownership of key shares, defective title to a major property, systemic fraud, loss of core intellectual property, a major tax exposure or a critical customer contract terminable on change of control.


The Due Diligence-to-SPA Risk Matrix

A useful acquisition model is:

Finding → Legal Exposure → Financial Exposure → Probability → Closing Impact → SPA Protection → Post-Closing Owner

Red Flag Possible Exposure Deal Treatment
Unregistered or unsatisfied charge Secured-creditor or title risk Condition precedent + release documentation
Undisclosed litigation Claim or decree exposure Specific indemnity
Material tax demand Historic tax liability Tax indemnity + escrow
Related-party leakage Value leakage/governance Price adjustment + covenant
Change-of-control consent missing Contract termination Consent as condition precedent
Key IP not owned by target Business-model risk Assignment before closing
Employee dues or compliance gap Labour liability Indemnity + remediation
Data/privacy gap Regulatory and customer risk Remediation + warranty/indemnity
Foreign-investment defect FEMA/regulatory risk Pre-closing correction or approval
Competition approval required Closing legality Regulatory condition precedent
Fraud indicators Unknown wider liability Enhanced investigation or pause deal

1. Corporate Records: Are You Buying What the Seller Says It Owns?

In a share acquisition, one of the first questions is deceptively simple: who actually owns the shares being sold?

The diligence team should reconcile the cap table against legally operative records, including:

  • share certificates;
  • register of members;
  • allotment records;
  • share-transfer records;
  • beneficial-interest declarations;
  • significant-beneficial-ownership filings;
  • shareholder agreements;
  • articles of association;
  • options and ESOPs;
  • convertible securities and warrants;
  • pledges, liens and encumbrances;
  • board and shareholder approvals; and
  • ROC filings.

The Companies Act, 2013 governs the statutory corporate framework, including registers, beneficial ownership, charges and related corporate records.

Cap-table red flags that should affect the SPA

Share certificates do not reconcile with the register: correct the discrepancy before closing where possible.

Founder claims 60% but records show 55%: this is a fundamental ownership problem, not a minor disclosure issue.

Unrecorded transfer or undisclosed option pool: the buyer may be acquiring a smaller fully diluted economic interest than expected.

Investor rights survive acquisition: pre-emption, ROFR, tag, drag, veto and anti-dilution rights may need to be waived, terminated or intentionally carried forward.


2. Charges and Security Interests

ROC charge review matters because repayment of a loan and legal release of security are not the same thing. A target may say a facility was repaid years ago while the charge remains unsatisfied or original security documents remain with the lender.

The buyer should ask:

  • Was the debt actually discharged?
  • Was security legally released?
  • Was satisfaction recorded?
  • Does the lender retain original title or security documents?
  • Is another continuing facility linked to the security?
  • Does the transaction trigger lender consent or mandatory prepayment?

Possible SPA response: discharge as condition precedent, lender no-dues certificate, release deed, satisfaction filing, original-document delivery and a specific seller indemnity for historic defects.


3. Related-Party Transactions and Value Leakage

Related-party review should identify promoter loans, director advances, group-company payments, related vendors, related-party leases, shared employees, management fees, guarantees, preferential arrangements and assets used by the business but owned outside the target.

Section 188 of the Companies Act regulates specified related-party transactions and should be reviewed together with the target’s approvals and disclosures.

The legal question is only one part of the analysis. The commercial question is: is value being extracted from the target?

Leakage protection

In a locked-box or similar structure, the SPA may need to define prohibited leakage such as extraordinary dividends, promoter payments, management fees, related-party transfers, unusual bonuses, asset transfers, debt repayments to sellers, guarantees or other value transfers outside the ordinary course.


4. Material Contracts: Change of Control Can Destroy Deal Value

One of the highest-value legal diligence exercises is review of the target’s material contracts: major customers, suppliers, lenders, landlords, distributors, technology providers, licensors, logistics providers, cloud vendors, consultants and strategic partners.

For each agreement, test whether the transaction triggers:

  • change-of-control consent;
  • termination rights;
  • assignment restrictions;
  • acceleration;
  • renegotiation;
  • exclusivity changes;
  • price changes; or
  • notice obligations.

A company valued because of three major contracts may be worth materially less if those contracts can terminate on acquisition.

Change-of-control red flag → condition precedent

Where a critical contract requires consent, a stronger protection is often: closing will not occur unless written change-of-control consent is obtained. That prevents the buyer from closing into a known operational risk instead of relying only on a post-closing damages claim.

For contract-stage risk review, see our Contract Risk Audit.


5. Revenue Concentration Is Also a Legal Risk

If three customers represent most of the target’s revenue, legal diligence should do more than confirm that the contracts exist. It should examine remaining term, termination for convenience, price revision, minimum commitment, exclusivity, service levels, penalties, change-of-control rights, dispute history, overdue receivables and whether the relationship depends personally on the promoter.

Where a major customer is likely to leave after acquisition, the finding may affect valuation, not merely SPA drafting.


6. Litigation Due Diligence: Do Not Just List Cases

For each material case, identify:

  1. amount claimed;
  2. realistic exposure;
  3. procedural stage;
  4. interim orders;
  5. strength of documents;
  6. counterclaims;
  7. possible settlement;
  8. insurance coverage;
  9. business interruption risk; and
  10. whether the liability relates to pre-closing conduct.

Known litigation risk → specific indemnity

A known case is often better addressed through a specific indemnity rather than disappearing into a generic warranty. The negotiation then turns to cap, escrow, survival, defence control, settlement authority, insurer recoveries and whether the exposure should also reduce purchase price.


7. Warranty vs Indemnity

Warranty: a contractual statement concerning the state of the target or transaction—for example, that accounts are accurate, material contracts are valid, litigation is disclosed, taxes are filed or IP is owned.

Indemnity: a contractual allocation of financial responsibility for a specified loss or category of loss—for example, an identified tax assessment, pending employee claim, historic data breach or known customer dispute.

Known diligence risks should not be hidden inside generic warranties where a specific allocation is commercially justified.


8. When Should a Risk Affect Purchase Price?

Not every legal risk should be left for post-closing indemnification. Some findings change what the business is worth today.

Examples include revenue dependent on an unenforceable arrangement, expenses paid personally by promoters and omitted from EBITDA, a major customer already terminating, materially understated employee liabilities or a regulatory issue affecting an entire business line.

Price adjustment is often appropriate where the issue changes current enterprise value. Indemnity is often more suitable where a defined liability from historic conduct may crystallise after closing. Some findings require both.


9. Escrow and Holdback

An indemnity is only as valuable as the seller’s ability to satisfy it. If the seller receives the entire consideration and later dissipates the funds, even a carefully drafted indemnity may become another recovery proceeding.

Escrow or holdback can therefore convert contractual protection into economic security.

It is commonly considered for material tax assessments, unresolved litigation, incomplete remediation, disputed employee liabilities, regulatory exposure, customer claims or founder obligations continuing after closing.


10. Conditions Precedent: Fix Before You Buy

Where a material risk can be corrected before closing, a condition precedent may provide better protection than a later indemnity claim.

Examples include obtaining regulatory or lender approval, releasing charges, securing landlord or customer consent, terminating conflicting shareholder arrangements, assigning intellectual property, regularising licences, paying statutory dues and correcting corporate filings.

If the risk can realistically be eliminated before closing, do not unnecessarily convert it into a post-closing claim.


11. Conditions Subsequent: Use Carefully

Some remediation cannot reasonably be completed before closing. A condition subsequent may then be appropriate, but it should specify the responsible party, deadline, evidence of completion and consequence of failure. Material items may also require indemnity or retention support.


12. Foreign Investment and FEMA Due Diligence

Where a non-resident buyer, investor or historic shareholder is involved, FEMA analysis becomes central. Foreign investment is regulated through FEMA, the Foreign Exchange Management (Non-Debt Instruments) Rules, 2019 and RBI’s payment/reporting framework.

RBI’s Master Direction on Foreign Investment in India explains the interaction with the NDI Rules, while the Mode of Payment and Reporting of Non-Debt Instruments Regulations addresses payment and reporting requirements.

Review should cover sectoral eligibility, caps, automatic or approval route, pricing, historic issuances and transfers, FC-GPR/FC-TRS reporting, downstream investment, deferred consideration, escrow arrangements and historic contraventions.

SPA response: pre-closing regularisation where feasible, allocation of cost and specific indemnity for historic non-compliance.


13. Competition Law and CCI

Indian acquisitions must be tested against the Competition Act and the current combinations framework. The CCI’s Combinations Regulations, 2024 and current notifications/rules form part of that assessment.

The transaction team should test current asset/turnover thresholds, exemptions, control implications and the deal-value/substantial-business-operations framework where relevant. This is especially important for technology, digital, data, pharma and asset-light businesses where transaction value may not correlate with historic assets or turnover.

Competition-law applicability should be revalidated for the specific deal at signing and before closing if facts change.


14. Labour and Employment Due Diligence in 2026

Employment diligence should reflect the operative labour-code framework rather than rely on a pre-2025 checklist. The Ministry of Labour’s current Labour Codes page records the four codes, implementation materials and 2026 Central Rules.

Review should cover employee classification, wages, statutory benefits, social security, gratuity, bonus, leave, working conditions, standing orders where applicable, disciplinary processes, contractors, employment contracts, senior-management exits and pending disputes.

For a dedicated workstream, see Employment & HR Legal Due Diligence.

Employee liabilities can affect purchase price

Where diligence identifies unpaid statutory dues, understated gratuity exposure, contractor liabilities or material employment claims, the response may require a debt-like adjustment, specific indemnity and remediation condition rather than a generic employment warranty.


15. Key Employees and Founder Dependency

Some businesses legally belong to the company but commercially depend on a handful of people. Review key employee departures, notice periods, retention arrangements, ESOPs, change-of-control payments, confidentiality, IP assignment, customer ownership, non-solicitation and founder transition obligations.

A buyer may decide that retention of specified individuals is a closing condition rather than merely an HR matter.


16. Employee Fraud and Internal Investigation Red Flags

Traditional diligence relies heavily on documents supplied by management. That becomes dangerous when management or insiders may be involved in misconduct.

Warning signs include unexplained customer migration, related vendors, duplicate payments, unusual credit notes, customer-data downloads, deleted emails, large manual adjustments, suspicious expense claims, unexplained receivable write-offs or employees moving rapidly to competitors.

Where such indicators arise, ordinary legal diligence may need to expand into forensic review + internal investigation + access-log analysis + financial reconciliation.


17. Intellectual Property Due Diligence

A technology or brand-led target may discover that critical code, trademarks or other IP were created or held by founders, freelancers, employees, overseas contractors or group companies rather than the target itself.

Check employment IP clauses, contractor assignments, trademarks, copyright, patents, designs, domains, source-code repositories, licences, open-source obligations and infringement claims.

IP red flag → pre-closing assignment. If a founder personally owns the core trademark or software, an executed assignment and transfer of credentials may provide materially stronger protection than a broad warranty.


18. Data Protection and Cyber Due Diligence

Data diligence is increasingly central for data-intensive acquisitions. MeitY published the Digital Personal Data Protection Rules, 2025, together with an enforcement timeline and related notifications.

Review should include categories of personal data, processing purposes, consent and notice architecture, processors, cloud providers, security safeguards, breach history, retention, deletion, children’s data where relevant, vendor contracts and incident-response systems.

Cybersecurity red flags can be deal red flags

A disclosed “minor cyber incident” should trigger questions about what was accessed, whether customer or personal data was exfiltrated, persistence, ransomware, regulator/customer notifications, forensic review, insurance response and threatened litigation.


19. Tax Due Diligence

Tax review should identify not only outstanding demands but potential exposure arising from income tax, GST, withholding, transfer pricing, employee taxation, related-party arrangements, historic restructuring and aggressive positions.

Transaction responses may include tax indemnity, escrow, price adjustment, conduct-of-tax-claims provisions and seller consultation or control rights.


20. Real Estate and Property Used by the Target

Where operations depend on factories, warehouses, offices or logistics facilities, verify ownership or leasehold rights, title chain, renewal, permitted use, mortgages, access, approvals, construction legality, litigation and change-of-control provisions.

A business acquisition can fail operationally if the buyer acquires the company but the target cannot legally remain in its principal facility.


21. Regulatory Licences

For a regulated business, the key question is not simply whether a licence exists. The diligence team should ask whether it is valid, transferable, renewable, compliant with conditions, subject to notices, or affected by a change in control.

If prior regulator approval is required, it should generally be treated as a regulatory condition precedent rather than left for post-closing correction.


22. Environmental, Safety and Operational Compliance

For industrial targets, review environmental consents, pollution-control permissions, waste handling, hazardous materials, occupational safety, accidents, closure directions and remediation liabilities.

Some liabilities may economically survive a change in ownership even where the historic violation predates the buyer.


23. Insurance

Review policy limits, exclusions, deductibles, claims history, pending notifications, D&O cover, cyber cover, property cover, business interruption and product/professional liability where relevant.

A pending claim may carry very different economic exposure if insurance responds fully.


24. The Disclosure Letter

Representations and warranties operate together with seller disclosures. If the SPA states that there is no material litigation but the disclosure letter identifies specified cases, those disclosures may qualify the warranty depending on the agreed drafting.

The buyer should review the disclosure letter against diligence findings line by line and negotiate what constitutes fair or sufficient disclosure. A bulk data-room dump should not automatically become blanket disclosure unless the agreed standard clearly permits it.


25. Warranty Caps, Baskets and De Minimis Claims

SPA negotiations commonly involve:

  • De minimis: individual claims below an agreed amount are disregarded.
  • Basket: claims become recoverable once aggregate losses cross a threshold.
  • Cap: maximum seller liability.
  • Survival period: period within which claims must be notified.

These are commercial allocations of risk and should be negotiated with the actual diligence findings in mind.

Known risk should not disappear into a general warranty cap

If there is a known material tax or litigation exposure, the buyer may require it to sit outside the general warranty cap as a specific indemnity.


26. Material Adverse Change / Material Adverse Effect

Between signing and closing, the business may deteriorate. Transaction documents may therefore address major customer loss, regulatory suspension, destruction of key assets, major litigation, insolvency indicators, business shutdown or other sufficiently material events.

The definition must be drafted carefully because the parties often disagree over what level of deterioration is truly material.


27. Interim Operating Covenants

Between signing and closing, the seller may covenant to operate in the ordinary course and not undertake specified actions without consent, such as issuing shares, incurring unusual debt, selling material assets, entering major contracts, terminating key employees, paying extraordinary dividends or settling major litigation.


28. Bring-Down of Warranties at Closing

Representations may be given at signing and repeated at closing. A bring-down mechanism requires the seller to confirm that negotiated representations remain true at closing, subject to the agreed materiality and disclosure standards.


29. Closing Deliverables

A transaction should have a precise closing checklist, potentially including:

  • share-transfer instruments and original certificates;
  • board and shareholder resolutions;
  • director resignations and appointments;
  • lender releases;
  • customer and landlord consents;
  • regulatory approvals;
  • IP assignments;
  • bank-authority changes;
  • statutory registers;
  • data-room archive;
  • employment documents;
  • escrow agreement;
  • disclosure letter; and
  • completion accounts or agreed closing statement.

30. Post-Closing Integration Is Part of Legal Risk

Closing does not eliminate diligence findings. A remediation register should survive closing and assign every open item to an owner and deadline.

Risk Owner Deadline Status
Employment compliance gap HR/Legal 30 days Open
IP registration Legal/IP 60 days Open
Vendor contract renewal Procurement 45 days Open
Data-retention remediation DPO/IT 90 days Open
Litigation strategy Litigation team 15 days Open

The diligence report should feed directly into a post-closing legal integration plan.


What Should Make a Buyer Walk Away?

Not every transaction should close. Potential deal breakers include:

  • seller cannot prove title to the shares;
  • core licence cannot survive the acquisition;
  • systemic fraud;
  • fundamental financial data cannot be reconciled;
  • key IP is not owned and cannot be acquired;
  • undisclosed debt is substantial;
  • regulatory illegality affects the core business;
  • critical customers will terminate;
  • liabilities exceed the deal economics;
  • management obstructs diligence; or
  • material documents appear falsified.

A transaction lawyer’s job is not to make every deal close. It is to help the client understand what it is actually buying.


Red Flag Severity Model

Green: no material issue.

Amber: manageable through ordinary contractual protection or post-closing remediation.

Red: material risk requiring pre-closing correction, economic adjustment, specific indemnity or senior approval.

Deal breaker: risk undermines ownership, legality, valuation or the fundamental business thesis.


M&A Due Diligence Decision Table

Finding Best First Response
Small filing defect Remediate
Unpaid statutory liability Pay before closing or price adjust
Known litigation Specific indemnity
Uncertain historic liability Escrow + indemnity
Key consent missing Condition precedent
Core IP outside target Assignment before closing
Fraud indicators Enhanced forensic investigation
Foreign-investment defect Regulatory remediation
CCI approval required Regulatory condition precedent
Employee exposure Quantify + indemnity/adjustment
Data-protection weakness Remediation covenant + warranty
Major customer likely to leave Revalue transaction
Seller cannot prove share title Do not close until cured

Frequently Asked Questions

Is legal due diligence only a checklist exercise?

No. Its most valuable function is to convert findings into transaction decisions: price, conditions precedent, indemnities, warranties, escrow, covenants, closing deliverables and post-closing remediation.

What is the difference between a red flag and a deal breaker?

A red flag may still be manageable through remediation or contractual/economic protection. A deal breaker undermines the fundamental legality, ownership or commercial rationale of the acquisition.

Should every risk be covered by indemnity?

No. If a material risk can be corrected before closing, a condition precedent may provide stronger protection. If the issue changes business value, purchase-price adjustment may be more appropriate.

What is a specific indemnity?

It allocates responsibility for an identified risk—such as an existing tax dispute, employee claim or litigation matter—instead of relying only on general warranties.

Why is escrow used?

Escrow provides an identifiable pool of funds against which agreed post-closing claims may be satisfied, reducing pure seller-credit risk.

Should historic FEMA compliance be reviewed?

Yes where non-resident investment or share transfers are involved. Historic issuance, transfer, pricing, payment and reporting compliance should form part of the diligence workstream.

Does every acquisition need CCI approval?

No. Applicability depends on the Competition Act, current thresholds, deal structure and available exemptions. The current CCI framework must be tested for the particular transaction.

Should labour diligence consider the labour codes?

Yes. Current diligence should be aligned with the operative labour-code framework and applicable Central/State rules rather than using an obsolete pre-implementation checklist.

Is data protection an M&A diligence issue in India?

Yes, particularly for data-driven businesses. Personal-data practices, cyber incidents, processors, retention and the applicable DPDP implementation framework can materially affect regulatory and commercial exposure.

When should a buyer reconsider the transaction?

Where diligence reveals an unfixable ownership defect, core regulatory illegality, systemic fraud, loss of the core licence/IP/customer base, liabilities disproportionate to value, or information that invalidates the investment thesis.


Key Takeaways

The most important M&A diligence principle is: a red flag without a deal response is an incomplete finding.

Every material issue should answer six questions:

  1. What happened?
  2. What law or contract does it affect?
  3. What is the potential financial exposure?
  4. Can it be corrected before closing?
  5. If not, how will the SPA allocate it?
  6. Who owns the remediation after closing?

The transaction workflow should be:

Due diligence → quantify exposure → classify risk → decide whether to cure, price or allocate → draft SPA protection → verify closing → track post-closing remediation.

That is how legal due diligence protects deal value rather than merely producing a report.


Authoritative Legal and Regulatory Sources


Disclaimer

This article is intended for general legal awareness and educational purposes only. It is not intended as advertisement or solicitation and does not constitute transaction-specific legal advice. M&A structuring, competition-law approval, foreign-investment compliance, tax treatment, indemnity architecture and regulatory requirements must be assessed against the particular transaction, parties, sector and applicable law at signing and closing.

Leave a Comment

Your email address will not be published. Required fields are marked *