Fastrack Legal Solutions LLP • M&A Risk • Buyer Due Diligence

Hidden Liabilities in M&A Deals in India: 30 Legal Risks Buyers Miss Before Acquisition 2026

A buyer-side framework for identifying liabilities that may not be obvious from the balance sheet but can affect price, closing, financing, indemnity, escrow, integration and the fundamental investment thesis.

FinancialDebt-like items, guarantees, claims and unrecorded commitments.
OperationalCustomer concentration, licences, vendors, assets and key people.
RegulatoryTax, labour, data, competition, FEMA and sector-specific exposure.
Deal ResponseCure, price, indemnify, escrow, restructure or walk away.

The central M&A problem

A buyer does not acquire only the target’s visible assets and liabilities. In a share acquisition, it ordinarily acquires the company together with historic compliance failures, contractual commitments, disputed obligations, employee exposure, unresolved claims, data incidents, customer dependencies and promoter-linked arrangements that remain inside the entity after closing.

The right diligence question is therefore not “what liabilities are shown in the accounts?” but “what facts can cause money, rights, licences, customers or operational capacity to leave the business after we buy it?”

1. Hidden liability is broader than contingent liability

Some risks are accounting contingencies; others are legal or commercial liabilities that have not yet crystallised. Examples include a customer that can terminate on change of control, a promoter-owned trademark, a worker-classification dispute, a regulatory notice not yet quantified, an unreleased charge, an undocumented side agreement or a data incident that has not yet produced a claim.

The broader diligence architecture is set out in our M&A Due Diligence Checklist for Private Companies in India. This article focuses specifically on risks that are easy to underprice or miss.

2. Thirty hidden liabilities buyers should test

# Risk Why It Matters
1 Unreleased charges Debt may be repaid but security or ROC charge may remain unresolved.
2 Personal/corporate guarantees Closing can trigger replacement-security or cross-default issues.
3 Promoter loans May be debt-like, repayable on demand or intertwined with group cash flows.
4 Undocumented related-party balances Can conceal leakage, unrecoverable receivables or value outside the target.
5 Change-of-control termination rights Major customer, vendor, lender or landlord can exit because of the transaction.
6 Side letters and oral arrangements Commercial obligations may not appear in the principal contract repository.
7 Automatic renewals Unfavourable commitments may lock in before closing or integration.
8 Uncapped indemnities Legacy contracts may create open-ended exposure to customers or counterparties.
9 Customer concentration Revenue can fall sharply if one relationship is fragile or promoter-dependent.
10 Supplier dependency Single-source inputs may carry price, continuity or consent risk.
11 Unpaid employee/statutory dues Past shortfalls can become post-closing claims and enforcement exposure.
12 Contractor misclassification Labour and social-security liabilities may be materially understated.
13 Key employee retention obligations Change-of-control payouts, ESOP acceleration or departure can affect value.
14 POSH and workplace complaints Unresolved matters may carry employment, governance and reputational risk.
15 Tax positions not yet assessed No current demand does not mean no historic exposure.
16 GST/input-credit issues Reversal, interest or penalty risk may surface after closing.
17 Transfer-pricing/related-party tax exposure Historic group transactions may be challenged later.
18 Pending or threatened litigation Threatened claims may not appear in formal litigation lists.
19 Internal investigations Fraud, data or misconduct issues can expand far beyond the initial allegation.
20 Regulatory notices A show-cause or inspection finding may threaten licences or operations.
21 Licence-transfer/change-control restrictions The business may not lawfully continue after closing without approval.
22 FEMA/foreign-investment defects Historic pricing, reporting or sectoral violations can require remediation.
23 CCI approval risk A notifiable combination cannot be treated as an ordinary closing formality.
24 Promoter-owned IP Core trademarks, software or know-how may sit outside the target.
25 Open-source/software licence exposure Licence obligations can impair proprietary software value or distribution.
26 Cyber incidents not fully investigated Unknown persistence, exfiltration or notification exposure can survive closing.
27 Data-protection remediation gap Transition to the DPDP framework may require systems and contract changes.
28 Property/title or lease defects Key facilities may lack secure title, permitted use or long-term occupancy.
29 Environmental/safety exposure Historic operations may create remediation, closure or compensation risk.
30 Insurance gaps Known claims may be uninsured, underinsured or excluded from cover.

3. Where hidden liabilities usually hide

They commonly appear in the gap between systems. The finance team may know the payment but not the side letter. Legal may have the contract but not the operational deviation. HR may know the employee dispute but not the financial provision. Procurement may know the vendor relationship but not the promoter connection. The promoter may know a major customer relationship that is never documented in the CRM.

This is why diligence should reconcile documents across departments rather than review each folder in isolation. A corporate legal risk audit approach is useful because it tests obligations, ownership, controls and evidence together.

4. Contract liabilities that are frequently underpriced

Contract review should not stop at term and termination. Test payment rights, service credits, indemnities, liquidated damages, minimum purchase commitments, exclusivity, most-favoured terms, audit rights, change-of-control, data obligations, IP ownership, warranty periods, auto-renewal and uncapped liability.

Our dedicated Contract Risk Audit in India explains the operational control framework. In an acquisition, the output should be converted into a transaction response: obtain consent, terminate or amend the agreement, price the exposure, or allocate it through indemnity.

5. Corporate and promoter liabilities

Review share title, beneficial ownership, options, convertibles, pledges, charges, guarantees, shareholder agreements, promoter loans, related-party arrangements and assets outside the target. The Companies Act, 2013 remains the core statutory framework; current text should be verified through India Code.

For promoter-specific issues, see Promoter Due Diligence in India.

6. Competition-law risk can be a closing liability

The transaction should be tested against the current CCI combinations framework before signing and again before closing if the facts or consideration change. The CCI’s Combinations Regulations, 2024 form part of the current framework. In 2026, the deal-value threshold applies to transactions where value exceeds ₹2,000 crore and the statutory substantial-business-operations-in-India test is met, subject to applicable exemptions and the precise transaction structure.

Competition approval is not a generic post-closing covenant. Where prior approval is required, closing mechanics must respect the statutory regime.

7. Foreign-investment and FEMA history

Where non-resident investors, historic foreign issuances or cross-border transfers are involved, review sectoral caps, route, pricing, payment, reporting, downstream investment, deferred consideration and historic filings. RBI’s Master Direction on Foreign Investment in India and the Foreign Exchange Management (Non-Debt Instruments) framework should be checked against current amendments.

An old reporting defect may be curable; an impermissible sectoral investment or ownership structure may be far more serious. Do not collapse both into a generic “FEMA issue” label.

8. Data and cyber liabilities

A data-intensive target can carry historic security weaknesses, unauthorised employee access, customer-contract notification obligations, untested backups, unresolved cyber incidents or processor arrangements that become expensive after closing. In 2026, diligence should also reflect the staged commencement of the Digital Personal Data Protection Rules, 2025.

Ask not only whether a breach occurred but whether the target can prove what happened, what was affected, whether access persisted, what notifications were made, and what remediation remains open.

9. How to convert hidden liabilities into deal protection

Risk Type Best First Response
Curable pre-closing defect Condition precedent with objective evidence of cure
Quantifiable debt-like exposure Purchase-price adjustment or completion-account treatment
Known historic claim Specific indemnity
Material uncertain contingent risk Indemnity plus escrow/holdback where commercially justified
Operational dependency Consent, transition covenant, retention or restructuring
Fundamental ownership/regulatory illegality Do not close unless satisfactorily cured; reconsider deal if unfixable

For a detailed bridge from diligence findings to transaction drafting, see From Legal Due Diligence to SPA in India.

10. Buyer-side red flags that justify expanding diligence

  • Management repeatedly answers material questions orally but does not provide documents.
  • Financial figures do not reconcile with contracts, statutory filings or operational data.
  • High-value transactions are concentrated around related parties or a small group of employees.
  • Material contracts are unsigned, missing or exist in multiple versions.
  • A major licence, customer or supplier relationship is described as “informal”.
  • Customer or employee data has been downloaded or shared outside ordinary systems.
  • Promoters resist disclosure of group-company arrangements or guarantees.
  • Historic regulatory notices are described as “closed” without a closure order or evidence.
  • Large receivables, write-offs or claims lack supporting documentation.
  • The data room changes materially after red flags are raised.

These facts do not prove wrongdoing. They justify targeted verification, management interviews, deeper forensic review or a revised transaction timetable.

11. Frequently Asked Questions

Can seller warranties replace due diligence?

No. Warranties allocate risk after signing or closing; diligence helps the buyer understand the risk before it becomes dependent on a claim.

What is the difference between price adjustment and indemnity?

A price adjustment changes the economics of what the buyer pays. An indemnity allocates responsibility if a defined loss later crystallises. Some risks may justify both.

Should every contingent liability be put in escrow?

No. Escrow is a commercial security mechanism and should reflect materiality, probability, seller creditworthiness and negotiation. Minor risks may be addressed through ordinary warranties or covenants.

What makes a hidden liability a deal breaker?

A risk becomes potentially fundamental where it undermines title, legality, core licence, material customer retention, key IP, financing, or the accuracy of the buyer’s investment thesis.

Should hidden liabilities be tracked after closing?

Yes. Every open diligence item should move into a post-closing remediation register with owner, deadline, evidence requirement and escalation threshold.

M&A Risk Review

Buyer-side legal due-diligence scoping

Businesses, investors and lenders may use the enquiry form to share the broad nature of an acquisition, investment, hidden-liability or due-diligence requirement for an initial conflict and scope review. The form is intended for professional enquiries and does not constitute solicitation or create an advocate-client relationship.

Open Corporate Enquiry Form

Disclaimer: General legal and transaction-risk information as at 28 August 2026. It is not transaction-specific legal, tax, financial or competition-law advice. Diligence scope and transaction protection must be tailored to the target, deal structure, sector, parties and current law.

Leave a Comment

Your email address will not be published. Required fields are marked *