M&A due diligence for a private company in India is a structured legal, financial, tax, corporate, regulatory, labour, commercial and litigation review conducted before acquiring shares, assets, business undertaking or control of a company. A buyer should examine the target company’s incorporation documents, memorandum and articles, shareholding records, statutory registers, ROC filings, share transfers, charges, loans, related-party transactions, material contracts, tax and GST records, labour compliances, property title, intellectual property, litigation, regulatory licences, data-protection practices, FEMA compliance and CCI-notifiability before signing or closing a transaction.
The review is especially important because Indian private companies often carry legacy risks through informal promoter arrangements, undocumented related-party transactions, defective share transfers, unregistered charges, tax notices, labour dues, title defects, employee claims, pending litigation, customer concentration and sectoral licensing gaps. The Companies Act, 2013 contains the principal corporate-law framework for company records, share capital, charges, board powers, related-party transactions and compromises/arrangements/amalgamations. Competition-law review may also be necessary where the transaction qualifies as a “combination” requiring CCI scrutiny, based on applicable asset, turnover, group-level or deal-value thresholds. FEMA and RBI reporting review becomes relevant where the buyer, seller, investor or existing shareholder is a person resident outside India.
Table of Contents
Non-Solicitation Note
This article is intended for general legal awareness and educational purposes only and may be published by Fastrack Legal Solutions LLP. It does not constitute advertisement, solicitation, invitation or inducement for professional engagement. M&A due diligence depends on the transaction structure, sector, target company, shareholder profile, financial position, licences, contracts, employees, tax records, litigation, property assets, financing arrangements, foreign investment status, competition-law thresholds and case-specific documents.
Introduction
A private company acquisition in India should not be approached as a mere signing exercise. Even where the commercial understanding appears settled, the legal and financial position of the target company may contain substantial hidden exposure.
A buyer may be acquiring:
- Shares of the company;
- A business undertaking;
- Selected assets;
- Control rights;
- Intellectual property;
- Customer contracts;
- Employees and operational liabilities;
- Regulatory licences; or
- A combination of the above.
Each transaction structure carries different legal consequences.
A share acquisition usually transfers ownership of the company as a going concern, along with its existing liabilities. An asset acquisition may allow better ring-fencing of liabilities but requires careful review of title, assignment, consents, stamp duty, employee transfer, licence transferability and tax implications. A business transfer or slump sale requires additional scrutiny of undertaking continuity, liabilities, employee transition, GST, income tax and contractual consent.
Therefore, M&A due diligence is not merely a document-collection process. It is a legal risk-mapping exercise that should directly influence valuation, transaction structure, conditions precedent, warranties, indemnities, escrow, price holdback, closing deliverables and post-closing obligations.
Purpose of M&A Due Diligence
The purpose of due diligence is to answer five essential questions:
| Question | Purpose |
|---|---|
| What is being acquired? | Shares, assets, business, undertaking, control or specific rights |
| Who legally owns it? | Seller title, cap table, beneficial ownership and encumbrances |
| What liabilities exist? | Tax, labour, litigation, debt, guarantees, regulatory and contractual exposure |
| What approvals are required? | Board, shareholder, lender, customer, regulator, CCI, FEMA or sectoral approvals |
| How should the deal be protected? | Conditions precedent, indemnity, escrow, disclosure schedule, price adjustment |
A due diligence report should not stop at identifying defects. It should classify risk, quantify exposure where possible, and recommend practical deal protection.
Transaction Structure Review
Before beginning due diligence, the transaction structure must be identified with precision.
| Structure | What Is Acquired | Key Legal Concern |
| Share Purchase | Shares of the target company | Buyer inherits corporate history and liabilities |
| Asset Purchase | Specific identified assets | Title, assignment, stamp duty and transferability |
| Business Transfer / Slump Sale | Business undertaking as a going concern | Tax, employees, licences, contracts and liabilities |
| Share Subscription | Fresh shares issued by target | Dilution, valuation, FEMA, governance rights |
| Merger / Amalgamation | Consolidation under statutory scheme | NCLT process, creditors, shareholders and regulators |
| Joint Venture | Shared ownership/control | Reserved matters, deadlock, exit and governance |
The due diligence checklist should be customised according to the structure. A share purchase requires deep review of legacy liabilities. An asset purchase requires strict title and transferability analysis. A merger or amalgamation requires statutory-scheme and approval review.
Corporate and Secretarial Due Diligence
Corporate due diligence verifies whether the target company has been validly incorporated, properly maintained and duly authorised to carry on its business.
Documents to Review
- Certificate of incorporation.
- Corporate Identification Number and MCA master data.
- Memorandum of Association.
- Articles of Association.
- Registered office records.
- Name-change records, if any.
- Authorised and paid-up share capital.
- Board minutes and shareholder minutes.
- Statutory registers.
- Annual returns and financial statements.
- Auditor appointment records.
- Director appointment and resignation filings.
- Event-based ROC filings.
- Secretarial compliance records.
Key Red Flags
| Red Flag | Deal Impact |
| MOA does not support business activity | Object-clause and authority risk |
| AOA restricts share transfer | Consent or waiver may be required |
| Missing minutes or registers | Governance and approval risk |
| ROC records differ from internal records | Cap table and compliance concern |
| Event-based filings missing | Closing condition or compliance cleanup required |
| Registered office mismatch | Statutory notice and governance issue |
Shareholding and Cap Table Due Diligence
In private company acquisitions, the cap table must be verified thoroughly. The buyer must confirm that the seller has clear and marketable title to the shares proposed to be transferred.
Documents to Review
- Register of members.
- Share certificates.
- Share transfer forms.
- Allotment records.
- PAS-3 filings.
- SH-4 instruments, where applicable.
- Board approvals for transfers and allotments.
- Shareholders’ agreements.
- Rights of first refusal, tag-along and drag-along rights.
- ESOP pool and grants.
- Convertible instruments.
- Preference shares, CCDs and CCPS.
- Pledge or encumbrance over shares.
- Beneficial ownership declarations.
The Companies Act, 2013 includes specific provisions relating to share capital, transfer and transmission of securities, register of members and related corporate records.
Key Red Flags
| Red Flag | Deal Impact |
| Share certificates missing | Seller title may be challenged |
| Cap table mismatch | Closing and ownership risk |
| Prior investor consent required | Transaction may breach SHA/AOA |
| Shares pledged to lender | Transfer cannot proceed free of encumbrance |
| Beneficial owner differs from registered holder | Disclosure and control risk |
| Defective transfer instruments | Validity and stamp-duty issue |
| Undocumented ESOP promises | Employee and dilution disputes |
Charges, Loans and Security Review
A company’s borrowing and security profile must be reviewed before acquisition. Hidden charges, guarantees and promoter-linked borrowings can materially affect valuation.
Documents to Review
- MCA charge index.
- Charge creation and modification forms.
- Loan agreements and sanction letters.
- Security documents.
- Hypothecation deeds.
- Mortgage documents.
- Personal guarantees.
- Corporate guarantees.
- Unsecured loans.
- Inter-corporate deposits.
- Director and promoter loans.
- Bank statements and loan statements.
- No-dues certificates.
- Satisfaction of charge records.
The Companies Act, 2013 contains a dedicated chapter on registration of charges, making charge verification essential in acquisition due diligence.

Key Red Flags
| Red Flag | Deal Impact |
| Unregistered charge | Hidden lender or security risk |
| Charge satisfied but not filed | Title and lender-release issue |
| Personal guarantee by promoters | Release or indemnity may be required |
| Related-party loans | Compliance and valuation concern |
| Corporate guarantee for group entity | Contingent liability exposure |
| SMA/NPA history | Financing and creditworthiness risk |
Related-Party Transaction Review
Private companies frequently have promoter-controlled transactions. These must be examined because they can distort margins, hide cash leakage and create post-closing disputes.
Documents to Review
- MBP-1 disclosures.
- DIR-8 declarations.
- Register of contracts and arrangements.
- Board and shareholder approvals.
- Rent agreements with promoters or group entities.
- Purchases and sales with related entities.
- Loans to or from directors.
- Management-fee arrangements.
- Brand licence or IP-use arrangements.
- Reimbursement records.
- Related-party receivables and payables.
The Companies Act, 2013 contains provisions governing board powers, loans, investments and related-party transactions, which must be considered during a corporate due diligence exercise.
Key Red Flags
| Red Flag | Deal Impact |
| Promoter-owned property used without agreement | Business-continuity risk |
| Inflated purchases from related entity | EBITDA distortion |
| Loans to group companies | Recoverability and governance concern |
| Related-party receivables outstanding | Balance-sheet quality issue |
| No approval trail | Compliance and indemnity risk |
| Services charged without documentation | Tax and cash-leakage risk |
Material Contracts Review
The buyer must know whether important contracts will continue after acquisition and whether any counterparty consent is required.
Contracts to Review
- Customer contracts.
- Supplier agreements.
- Distribution agreements.
- Franchise arrangements.
- Lease deeds.
- Technology and software agreements.
- Loan and security agreements.
- Government contracts and tenders.
- Non-disclosure agreements.
- Non-compete arrangements.
- Exclusivity clauses.
- Change-of-control clauses.
- Assignment restrictions.
- Termination rights.
- Liquidated damages clauses.
Key Red Flags
| Red Flag | Deal Impact |
| Change-of-control consent required | Consent required before closing |
| Major customer can terminate at will | Revenue-continuity risk |
| Assignment prohibited | Asset or business transfer may fail |
| Exclusivity clause | Strategic restriction |
| Heavy liquidated damages | Liability exposure |
| No written contract with key customer | Revenue sustainability concern |
Property and Asset Due Diligence
Where the target owns or uses land, offices, warehouses, factories, machinery or vehicles, title and possession must be examined carefully.
Documents to Review
- Sale deeds.
- Lease deeds.
- Leave and licence agreements.
- Mutation records.
- Property tax receipts.
- Encumbrance documents.
- Mortgage records.
- Possession documents.
- Building approvals.
- Occupancy and completion certificates.
- Industrial land permissions.
- Factory licence.
- Fire NOC.
- Pollution approvals.
- Asset register.
- Insurance records.
Key Red Flags
| Red Flag | Deal Impact |
| Property owned by promoter, not company | Business-continuity and lease risk |
| Unregistered lease | Enforceability and stamp-duty issue |
| Mortgage not disclosed | Encumbrance risk |
| Industrial use without approval | Regulatory closure risk |
| Encroachment or boundary dispute | Litigation exposure |
| Asset register mismatch | Valuation and fraud concern |
Tax and GST Due Diligence
Tax liabilities can survive a transaction and materially affect valuation. A buyer should obtain a clear tax-risk position before closing.
Documents to Review
- Income-tax returns.
- Tax audit reports.
- Assessment orders.
- Notices and demands.
- TDS returns and challans.
- GST registrations.
- GSTR-1, GSTR-3B and annual returns.
- ITC reconciliation.
- E-way bills.
- GST notices and orders.
- Transfer-pricing records.
- International transaction records.
- Advance-tax records.
- Tax litigation documents.
- Contingent-liability disclosures.
Key Red Flags
| Red Flag | Deal Impact |
| GST turnover mismatch | Demand, interest and penalty risk |
| ITC mismatch | Reversal and litigation exposure |
| TDS default | Statutory liability |
| Undisclosed cash sales | Tax and valuation concern |
| Unresolved notices | Escrow or indemnity required |
| Related-party pricing issue | Transfer-pricing and tax risk |
Labour and HR Due Diligence
Employment-related liabilities are often underestimated. Labour dues, PF/ESI defaults, contractor claims and employee disputes can create substantial post-closing exposure.
Documents to Review
- Employee list.
- Appointment letters.
- Employment contracts.
- Contractor and consultant agreements.
- Salary registers.
- PF registration and challans.
- ESI registration and challans.
- Professional tax records, where applicable.
- Bonus records.
- Gratuity exposure.
- Leave encashment.
- Standing orders or service rules.
- POSH policy and ICC records.
- Maternity Benefit Act compliance.
- Shops and Establishments registration.
- Factory licence, where applicable.
- Contract labour licence, where applicable.
- Pending employee disputes.
Key Red Flags
| Red Flag | Deal Impact |
| Employees shown as consultants | Misclassification risk |
| PF/ESI non-compliance | Statutory dues and penalty |
| No POSH compliance | Legal and reputational risk |
| No appointment letters | Employee dispute risk |
| Gratuity not provisioned | Hidden liability |
| Contractor workforce unmanaged | Principal-employer risk |
| Pending labour dispute | Settlement and litigation exposure |
Litigation and Disputes Review
Litigation due diligence must cover both filed cases and potential claims.
Documents to Review
- Civil suits.
- Criminal complaints.
- Cheque-bounce cases.
- Labour disputes.
- Consumer cases.
- RERA cases.
- Tax appeals.
- GST proceedings.
- Arbitration matters.
- MSME claims.
- Insolvency notices.
- SARFAESI notices.
- Police complaints.
- Environmental notices.
- Regulatory show-cause notices.
- Legal notices issued and received.
- Settlement agreements.

Key Red Flags
| Red Flag | Deal Impact |
| Undisclosed litigation | Warranty breach and indemnity claim |
| Criminal complaint involving company/directors | Reputational and operational risk |
| Cheque-bounce cases | Financial stress indicator |
| MSME claim | High interest exposure |
| Insolvency notice | Going-concern concern |
| Arbitration with key customer | Revenue risk |
Regulatory and Licensing Due Diligence
The target’s business may depend on licences or registrations. These must be valid, current and held in the correct name.
Licences to Review
- GST registration.
- Shops and Establishments registration.
- Factory licence.
- FSSAI licence.
- Drug licence.
- Pollution consent.
- Fire NOC.
- Import Export Code.
- MSME/Udyam registration.
- Legal metrology registration.
- Labour licences.
- EPFO and ESIC registration.
- RBI, SEBI or sector-specific approvals, where applicable.
- Municipal permissions
Also Read Mergers , Acquisitions and Amalgamation in India: Legal Framework, Process and Key Risks
Key Red Flags
| Red Flag | Deal Impact |
| Licence in promoter name | Business-continuity risk |
| Expired licence | Penalty or closure exposure |
| Non-transferable licence | Structuring issue |
| Sectoral approval required | Condition precedent |
| Operations beyond licence scope | Regulatory exposure |
| Pending inspection notice | Post-closing risk |
FEMA and FDI Due Diligence
Where foreign investment is involved, FEMA compliance must be reviewed before signing and closing.
Documents to Review
- Existing foreign shareholder records.
- FC-GPR filings.
- FC-TRS filings.
- FLA returns.
- Valuation reports.
- Pricing certificates.
- Sectoral-cap analysis.
- Automatic route or government-approval route review.
- Press Note 3 implications, where applicable.
- Downstream investment records.
- Convertible instrument terms.
- Deferred consideration.
- Escrow arrangement.
- Reporting delays and compounding exposure.
RBI materials under the FEMA non-debt instrument framework recognise reporting and mode-of-payment requirements for investments in India by persons resident outside India.
Key Red Flags
| Red Flag | Deal Impact |
| Foreign investment not reported | FEMA non-compliance |
| Pricing not compliant | Transfer and compounding risk |
| Approval route wrongly treated as automatic | Closing risk |
| Delayed FC-GPR or FC-TRS | Regularisation required |
| Unclear beneficial ownership | KYC and compliance concern |
| Sectoral-cap issue | Transaction restructuring may be required |
Competition Law / CCI Due Diligence
CCI notifiability must be checked in acquisitions, mergers and amalgamations where applicable thresholds are crossed. CCI’s official guidance recognises that only combinations require notification and approval prior to consummation, and that thresholds are based on asset and turnover values at enterprise and group level. CCI material also notes exemptions notified by the Central Government and categories of combinations that may not ordinarily require notification.
Review Points
- Asset and turnover thresholds.
- Group-level thresholds.
- Deal value threshold.
- Substantial business operations in India.
- De-minimis exemption.
- Green channel eligibility.
- Horizontal overlaps.
- Vertical relationships.
- Minority protection versus control rights.
- Standstill and gun-jumping risks.
Key Red Flags
| Red Flag | Deal Impact |
| CCI filing required but ignored | Closing risk and penalty exposure |
| Competitor acquisition | Competition scrutiny |
| Control rights hidden in SHA | Combination analysis required |
| Deal value threshold issue | Filing analysis required |
| Implementation before approval | Gun-jumping concern |
| Market concentration issue | Longer approval timeline |
Intellectual Property and Technology Review
For technology, media, e-commerce, SaaS, fintech and brand-heavy companies, intellectual property may be the core asset.
Documents to Review
- Trademark applications and registrations.
- Copyright ownership records.
- Software source-code ownership.
- Developer agreements.
- IP assignment agreements.
- Freelancer contracts.
- Domain ownership.
- Social-media handle control.
- Brand licence agreements.
- Patent filings.
- Open-source software review.
- SaaS licences.
- Cloud contracts.
- Data hosting arrangements.
- Cybersecurity policies.
Key Red Flags
| Red Flag | Deal Impact |
| Trademark owned by promoter | Brand-continuity risk |
| Source code not assigned to company | IP ownership defect |
| Open-source misuse | Product compliance risk |
| Domain in employee’s name | Control risk |
| Customer data without consent | Data protection exposure |
| Weak cybersecurity controls | Breach and liability risk |
Data Protection and Cybersecurity Review
Digital businesses must be reviewed for data collection, consent, storage, processing, breach response and vendor dependency.
Documents to Review
- Privacy policy.
- Terms of use.
- Consent flow.
- Customer-data categories.
- Employee-data records.
- Vendor data-processing agreements.
- Data storage location.
- Data retention policy.
- Cyber incident history.
- Access-control policies.
- Information-security policy.
- Cloud-hosting contracts.
- Payment-gateway terms.
- API integration records.
Key Red Flags
| Red Flag | Deal Impact |
| No privacy policy | Compliance and user-trust risk |
| Data collected without proper consent | Regulatory and contractual risk |
| Breach history not disclosed | Reputational and liability risk |
| No vendor data agreement | Third-party exposure |
| Weak access control | Cyber-risk valuation discount |
| Customer data not transferable | Deal-structure issue |
Financial Due Diligence
Financial due diligence must test whether the target’s numbers are reliable and whether valuation assumptions are defensible.
Documents to Review
- Audited financial statements.
- Trial balance.
- Management accounts.
- Bank statements.
- Debtors ageing.
- Creditors ageing.
- Inventory records.
- Fixed asset register.
- Cash-flow statements.
- Working-capital cycle.
- Revenue-recognition policy.
- Related-party balances.
- Unsecured loans.
- Contingent liabilities.
- EBITDA adjustments.
- Customer concentration.
- Vendor concentration.
Key Red Flags
| Red Flag | Deal Impact |
| Revenue booked but not collected | Inflated valuation |
| Old receivables | Bad-debt risk |
| High cash transactions | Tax and reliability concern |
| Unexplained loans | Governance and tax risk |
| Inventory mismatch | Fraud and valuation concern |
| Aggressive EBITDA adjustments | Price negotiation issue |
| One customer contributes major revenue | Concentration risk |
M&A Red Flag Matrix
| Risk Level | Examples | Recommended Deal Response |
| Critical | Ownership defect, invalid licence, material tax demand, CCI approval issue | Do not close until resolved |
| High | Litigation, related-party leakage, unregistered charges, FEMA delay | Escrow, indemnity, price adjustment |
| Medium | Missing HR records, minor ROC delays, weak documentation | Pre-closing rectification or post-closing covenant |
| Low | Formatting gaps, minor expired registrations | Compliance action plan |
Due Diligence Report Structure
A professional due diligence report should include:
- Executive summary.
- Transaction structure reviewed.
- Documents reviewed.
- Assumptions and limitations.
- Corporate status.
- Shareholding and title.
- Approvals and authorisations.
- Material contracts.
- Financing and charges.
- Tax and GST position.
- Labour and HR compliance.
- Property and assets.
- IP and technology.
- Data protection and cybersecurity.
- Litigation and disputes.
- Regulatory licences.
- FEMA/FDI compliance.
- CCI analysis.
- Red-flag summary.
- Risk rating.
- Suggested conditions precedent.
- Suggested representations and warranties.
- Suggested indemnities.
- Closing checklist.
- Post-closing compliance plan.
How Due Diligence Should Affect Transaction Documents
Due diligence findings must be reflected in the transaction documents. A report that does not improve the SPA, BTA or closing documents is incomplete.
| Due Diligence Finding | Transaction-Document Impact |
| Tax notice pending | Specific tax indemnity |
| Litigation disclosed | Escrow or price holdback |
| Cap table mismatch | Condition precedent to rectify |
| Charge not satisfied | Lender NOC before closing |
| Related-party receivable | Promoter repayment before closing |
| Licence issue | Closing condition or termination right |
| Employee dues | Seller indemnity |
| IP not assigned | IP assignment before closing |
| FEMA delay | Regularisation before transfer |
| Customer consent required | Consent as closing deliverable |
Buyer’s Document Request List
Corporate and Secretarial
- Certificate of incorporation.
- MOA and AOA.
- Shareholding pattern.
- Register of members.
- Share certificates.
- Board and shareholder minutes.
- ROC forms.
- Annual returns.
- Financial statements.
- Auditor and director records.
Financial and Tax
- Audited accounts for last three financial years.
- Income-tax returns.
- GST returns.
- TDS returns.
- Tax notices and orders.
- Bank statements.
- Ledgers and trial balance.
- Debtors and creditors ageing.
- Loan statements.
Legal and Operational
- Customer contracts.
- Vendor contracts.
- Lease documents.
- Licences and registrations.
- Litigation list.
- Employee list.
- Appointment letters.
- IP documents.
- Insurance policies.
- Data-protection documents.
Common Buyer Mistakes
- Signing a term sheet without exclusivity and proper document access.
- Relying only on management statements.
- Not independently checking MCA records.
- Ignoring related-party transactions.
- Not verifying registered charges.
- Not reviewing tax notices.
- Ignoring employee liabilities.
- Not checking change-of-control clauses.
- Assuming licences are transferable.
- Closing without lender/customer approvals.
- Not checking FEMA compliance in foreign investment cases.
- Failing to convert due diligence findings into indemnities.
- Closing before conditions precedent are completed.
Frequently Asked Questions
1. What is M&A due diligence?
M&A due diligence is the legal, financial, tax, commercial and compliance review of a target company before acquisition, investment, merger, business transfer or asset purchase.
2. Why is due diligence important in private company acquisitions?
It identifies hidden liabilities, ownership defects, tax exposure, employee claims, litigation, licence issues, contractual restrictions and valuation risks before closing.
3. What documents are required for M&A due diligence?
Key documents include incorporation records, MOA, AOA, shareholding records, ROC filings, financial statements, tax returns, contracts, employee records, property documents, licences, litigation documents and bank or loan records.
4. What are common red flags in M&A due diligence?
Common red flags include cap table mismatch, unregistered charges, related-party loans, tax notices, employee dues, hidden litigation, non-transferable licences, property defects, IP ownership gaps and FEMA non-compliance.
5. Is CCI approval required for every acquisition?
No. CCI approval is required only where the transaction qualifies as a notifiable combination under applicable law. Asset, turnover, group-level, exemption and deal-value threshold analysis may be required.
6. What is the difference between share purchase and asset purchase?
In a share purchase, the buyer acquires shares and indirectly takes the target company with its assets and liabilities. In an asset purchase, the buyer acquires selected assets, but must verify title, transferability, consents, tax treatment and assignment requirements.
7. What is the role of due diligence in SPA drafting?
Due diligence findings should be converted into representations, warranties, indemnities, conditions precedent, disclosure schedules, escrow, price adjustment and post-closing covenants.
8. Should labour compliance be reviewed in M&A?
Yes. PF, ESI, gratuity, bonus, employment contracts, consultant classification, POSH, maternity benefit and termination disputes can create hidden liabilities.
Conclusion
M&A due diligence for a private company in India must be conducted as a disciplined legal-risk exercise. It should examine corporate records, shareholding, charges, contracts, tax, GST, labour, property, litigation, licences, FEMA, CCI, intellectual property, data protection and financial integrity.
The value of due diligence lies not merely in identifying issues, but in converting findings into deal protection. The final transaction documents should reflect appropriate conditions precedent, representations, warranties, indemnities, disclosures, escrow arrangements, price holdback, closing deliverables and post-closing obligations.
A buyer should not close a private company acquisition unless ownership, authority, liabilities, approvals, contracts, tax exposure, employee dues, regulatory compliance and litigation position have been properly reviewed and reflected in the transaction structure.
Disclaimer
This article is intended for general legal awareness and educational purposes only and may be published by Fastrack Legal Solutions LLP. It does not constitute advertisement, solicitation, invitation or inducement for professional engagement. M&A transactions depend on structure, sector, documents, valuation, tax, contracts, licences, litigation, financing, FEMA, CCI thresholds and case-specific facts.