Legal Compliance Audit for Private Limited Companies in India: Complete 2026 Checklist
A management and board-level framework for private companies to test whether statutory filings, labour compliance, contracts, licences, data practices, tax interfaces, HR records, related-party controls and litigation management are actually operating as intended.
Executive takeaway
For a private limited company, legal compliance is not satisfied merely because annual forms are filed. A defensible compliance position requires the company to know which obligations apply, identify the responsible owner, maintain evidence that the obligation was discharged, escalate failures and close corrective action.
The strongest audit therefore combines statutory compliance, contract controls, employment records, data governance, licences, tax interfaces, litigation tracking and internal accountability. The objective is to distinguish a genuine legal breach from a documentation gap, a control weakness and an unresolved business risk.
1. What a Private Company Compliance Audit Should Cover
A legal compliance audit should begin with the entity’s actual operating profile. Two companies incorporated under the Companies Act, 2013 may have entirely different legal universes depending on turnover, paid-up capital, borrowing, foreign investment, workforce size, number of locations, nature of premises, industry, customer type, use of personal data and whether the business is regulated.
The audit should ordinarily map corporate law and secretarial compliance; director and related-party governance; share capital and financing; labour and employment; PoSH; commercial contracts; vendor and procurement controls; GST and tax interfaces; FEMA where applicable; data protection and cyber security; intellectual property; operational licences; litigation and limitation; insurance; and internal investigations.
For the wider governance model, see our Corporate Legal Risk Audit in India: A Board-Level Checklist for 2026 and the Corporate Risk & Compliance Resources hub.
2. Companies Act, 2013 Compliance Checklist
The Companies Act, 2013 remains the core corporate-law framework. The exact obligation depends on the company’s class, thresholds and facts, but a 2026 audit should at least test whether the corporate record is internally consistent and whether event-based obligations were identified when the underlying event occurred.
A. Constitutional and statutory records
- Memorandum and Articles of Association reflect the current capital and governance arrangements.
- Certificate of incorporation, registered office records and master data are current.
- Applicable statutory registers are maintained and reconcile with MCA filings.
- Share certificates, allotments, transfers and transmissions reconcile with the register of members.
- Beneficial ownership and significant beneficial ownership requirements have been examined where applicable.
B. Board and shareholder processes
- Board and general meetings are held at the legally required frequency for the company’s class.
- Notices, agenda papers, attendance, quorum and minutes are maintained.
- Board resolutions accurately record approvals for borrowings, investments, related parties, bank mandates, contracts, appointments and reserved matters.
- Shareholder approvals are obtained where required by statute or the Articles.
C. Directors, disclosures and conflicts
- Director appointments, resignations and DIN-related filings are current.
- Interested-director disclosures are obtained and updated.
- Related-party transactions are identified before execution and routed through the correct approval process.
- Loans to directors and connected persons are screened under applicable restrictions.
- Board decisions reflect directors’ duties under Section 166, including care, diligence, good faith and conflict management.
D. Annual and event-based filings
- Financial statements and annual returns are filed within applicable timelines.
- Auditor changes, director changes, allotments, charges, registered-office changes and other event-based filings are tracked.
- MCA filings reconcile with signed financial statements, statutory registers and board records.
- Delayed filings, adjudication notices, additional fees or compounding exposure are separately recorded and closed.
Primary legislation should be verified from the Ministry of Corporate Affairs – Companies Act, 2013, together with current rules, notifications and exemptions applicable to private companies.
3. Labour and Employment Compliance in 2026
The four Labour Codes—the Code on Wages, 2019; Industrial Relations Code, 2020; Code on Social Security, 2020; and Occupational Safety, Health and Working Conditions Code, 2020—were brought into effect from 21 November 2025. A 2026 compliance audit should therefore map the operative central framework, transitional rules, state-specific requirements and establishment-specific registrations rather than rely on obsolete pre-Code checklists.
- Employee, worker, contractor and consultant classifications reflect actual engagement.
- Appointment letters and wage structures comply with the operative wage framework.
- EPF, ESI and other applicable social-security obligations are mapped and reconciled.
- Working hours, leave, overtime and records are compliant for the relevant establishment and jurisdiction.
- Contract labour arrangements identify principal-employer and contractor obligations where applicable.
- Termination, retrenchment, disciplinary action and standing-order issues are handled under the correct legal framework.
- Occupational safety and workplace records are maintained where applicable.
- Exit documents, full-and-final settlements, access revocation and confidentiality obligations are consistently applied.
The Ministry of Labour & Employment’s official Labour Codes resources should be checked for operative notifications and implementation material.
4. PoSH Compliance Should Be Audited Separately
PoSH compliance should not be reduced to a clause inside the employee handbook. The Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013 creates a distinct complaint and governance architecture.
- Whether an Internal Committee is required and properly constituted.
- Whether external-member eligibility and appointment records are defensible.
- Whether the policy reflects the statute and actual complaint process.
- Whether employees receive periodic awareness training.
- Whether IC members are trained on inquiry procedure, confidentiality and natural justice.
- Whether annual reporting obligations and records are maintained.
- Whether complaints are being informally handled by HR in a manner that bypasses statutory procedure.
5. Contract Compliance and Authority Matrix
A private company’s most expensive legal exposures often arise outside statutory filings. The audit should test whether the organisation knows who may bind it and whether the executed contract reflects the transaction actually being performed.
- Central contract repository and executed-version control.
- Delegation of authority for customer, vendor, lease, finance, employment and settlement documents.
- Standard templates with controlled deviation approval.
- Payment terms, credit periods and acceptance criteria.
- Indemnity, limitation of liability and warranty exposure.
- Confidentiality, intellectual-property ownership and data-processing clauses.
- Change control, purchase-order hierarchy and oral-instruction risk.
- Termination, renewal, lock-in, notice and survival clauses.
- Arbitration, jurisdiction, governing law and service-of-notice provisions.
- Limitation and claim-preservation mechanisms.
See our detailed Contract Risk Audit in India.
6. Vendor and Procurement Compliance
Vendor onboarding is a legal-risk control as much as a procurement process. The compliance audit should test whether the vendor exists, who owns it, who approved it, whether bank information is independently validated and whether invoices can be reconciled to delivery and contract terms.
- Legal name, GSTIN, PAN, bank account and registered-address verification.
- Ownership, related-party and conflict checks proportionate to risk.
- Maker-checker control for vendor creation and bank changes.
- Purchase-order and approval compliance.
- Invoice matching and delivery evidence.
- Subcontractor and subprocessor controls.
- Confidentiality, data, anti-bribery and audit rights in high-risk contracts.
- Periodic review of inactive, duplicate or unusually concentrated vendors.
For a broader framework, refer to Third-Party Risk Management in India and Vendor & Procurement Fraud Risk.
7. GST, Direct Tax and Financial-Control Interfaces
A legal audit is not a substitute for a tax audit, but legal and tax controls frequently overlap. The audit should identify whether contractual terms, invoices, tax positions, payment controls and corporate records tell the same story.
- GST registrations and places of business correspond to actual operations.
- Invoice, e-invoicing and e-way bill processes are reviewed where applicable.
- Input-tax-credit disputes, blocked credits, reversals and notices are centrally tracked.
- TDS/TCS obligations are mapped to contract and payment categories.
- Inter-company, director and related-party transactions are supported by documentation.
- Large write-offs, credit notes, discounts and settlements have documented approval.
- Tax litigation and notices are included in the legal dispute register.
8. Data Protection and Cyber Compliance
The Digital Personal Data Protection Rules, 2025 were notified in November 2025 with staggered commencement. Rules 1, 2 and 17–21 commenced on publication; Rule 4 is scheduled one year after publication; and Rules 3, 5–16, 22 and 23 are scheduled eighteen months after publication. A 2026 audit should therefore separate currently operative duties from transition preparation.
- Personal-data inventory and processing-purpose mapping.
- Employee, customer, vendor and website data flows.
- Privacy notice and consent architecture where applicable.
- Role-based and privileged-access controls.
- Vendor and cloud processor clauses.
- Retention and deletion schedules.
- Incident-response, breach escalation and evidence preservation.
- Grievance-handling and rights-request processes according to the applicable commencement timeline.
- Contract remediation in advance of later-commencing DPDP obligations.
Companies should verify the current position from the MeitY – Digital Personal Data Protection Rules, 2025 and the official enforcement-timeline material.
For cyber-response preparation, see Cyber & Data Incident Legal Response in India.
9. Licences, Premises and Sector-Specific Compliance
A recurrent compliance failure is assuming that incorporation and GST registration are sufficient to operate. The audit should identify every licence or permission tied to the location, product, workforce or business model.
- Shops and establishments or equivalent state registrations.
- Factory, fire, pollution and environmental permissions where applicable.
- FSSAI, legal metrology, telecom, transport, warehousing or other sector licences where relevant.
- Lease permissions and permitted use of premises.
- Trade licences and local municipal requirements.
- Import-export registrations and customs interfaces where applicable.
- RBI, SEBI, IRDAI or other regulator permissions for regulated businesses.
- Renewal calendars and accountable licence owners.
10. Litigation, Notices and Limitation
Every private company should maintain a central legal-dispute register. It should not depend on the memory of one employee or an email thread.
- All legal notices, summons, arbitrations, court cases and regulatory proceedings are recorded.
- Claimed amount is separated from assessed exposure.
- Limitation dates for claims, appeals, written statements and statutory responses are tracked.
- Interim orders and undertakings are converted into operational action items.
- Evidence preservation and legal holds are implemented where needed.
- Settlements are approved by the correct authority and properly documented.
- Contingent-liability reporting is reconciled with finance and auditors where applicable.
11. Compliance Audit Risk Matrix
| Finding | Example | Expected Action |
|---|---|---|
| Critical | Operating without material licence; major fraud; serious cyber incident; criminal/regulatory exposure. | Immediate containment, senior escalation, evidence preservation and legal action plan. |
| High | Material Companies Act default, labour exposure, repeated related-party or payment-control failure. | Named senior owner, time-bound remediation and follow-up validation. |
| Medium | Incomplete records, contract repository gaps, policy not fully implemented. | Structured corrective action and evidence of closure. |
| Low | Minor housekeeping or isolated documentation inconsistency. | Routine rectification and record update. |
12. What the Final Compliance Report Should Contain
- Executive summary for promoters/board.
- Legal-obligation register.
- Statutory filing and licence calendar.
- Department-wise compliance matrix.
- Critical/high-risk findings.
- Root-cause analysis for repeat failures.
- Remediation plan with owner and due date.
- Evidence required for closure.
- Open legal notices and litigation dashboard.
- Policies/contracts requiring amendment.
- Items requiring external specialist advice.
The report should distinguish between non-compliance, control weakness, documentation gap, unresolved exposure and improvement recommendation. These categories should not be mixed.
13. When Should a Private Company Commission a Legal Compliance Audit?
An audit is especially useful before fundraising, bank financing, acquisition, strategic investment, large enterprise onboarding, government tender participation, major expansion, restructuring, promoter exit, senior-management change or a proposed sale of the business.
It is also appropriate after a warning event: a regulatory notice, employee fraud allegation, PoSH complaint, data breach, vendor misconduct, material tax dispute, repeated litigation, abrupt senior resignation or discovery that key contracts and licences are incomplete.
For a preventive enterprise framework, see Legal Risk Mitigation for Private Companies in India.
Frequently Asked Questions
Is a legal compliance audit compulsory for every private limited company?
No single provision requires every private company to undertake a comprehensive enterprise legal compliance audit under that label. However, every company remains subject to the statutory, contractual, tax, labour and regulatory obligations that apply to it. A structured legal audit is a governance tool to test those obligations.
How is this different from a secretarial audit?
Secretarial audit is a defined statutory mechanism applicable to prescribed classes of companies. A broader legal compliance audit may extend beyond secretarial compliance into contracts, employment, licences, data, litigation, vendors, investigations and operational controls.
How often should it be done?
The frequency should be risk-based. Many companies use an annual enterprise review with quarterly tracking of critical obligations. High-growth or regulated companies may need more frequent reviews.
What is the most important output?
A prioritised remediation register. The company should know what is wrong, why it matters, who owns the correction, the deadline and what evidence will prove closure.
Should all gaps be immediately reported to the board?
No. Reporting should be materiality and risk based. Critical and high-risk matters generally require senior visibility, while low-level housekeeping can be managed through normal compliance processes.
Structured compliance-audit scoping for private companies
Businesses may use the enquiry form to share the broad scope of a corporate, labour, contract, vendor, data, licence, investigation or litigation-compliance issue for an initial conflict and scope review. This does not constitute solicitation or create an advocate-client relationship.