Corporate Risk Mitigation • Investment & M&A Risk • India • 2026

Pre-Investment & Pre-Acquisition Risk Review in India: Legal Due Diligence, Hidden Liabilities, Contracts, Compliance & Deal Protection 2026

A transaction-grade framework for investors, promoters, lenders and acquirers to identify legal and operational liabilities before signing, pricing or closing a deal.

CorporateOwnership, authority, cap table, charges and related parties
CommercialContracts, customers, vendors, change-of-control and concentration
ComplianceTax, labour, licences, data, litigation and regulatory exposure
Deal protectionPrice, conditions precedent, indemnity, escrow and remediation

A pre-investment or pre-acquisition review should do more than confirm that documents exist. Its purpose is to determine whether the target’s legal position, operating controls and historic conduct support the valuation and deal structure being proposed.

The central transaction question is: what liability will economically transfer to the investor or acquirer if the deal closes? Some risks can be priced, some can be cured before closing, some can be allocated through warranty or indemnity, and some are serious enough to change the transaction itself.

Transaction standard: due diligence should distinguish document absence, technical non-compliance, contingent liability, recurring control weakness and value-threatening red flags. Not every issue deserves the same treatment.

1. Scope the review around the deal

The scope should reflect whether the transaction is a share acquisition, asset acquisition, minority investment, strategic investment, lender diligence, promoter buyout or business transfer. A minority investor may focus heavily on governance and reserved matters, while a buyer of the entire company must assess historic liabilities that will remain inside the entity after closing.

Materiality thresholds should be agreed at the beginning. Without them, diligence becomes a document-counting exercise rather than a decision tool.

See the broader Corporate Risk Mitigation in India pillar.

2. Corporate and ownership review

Review incorporation records, memorandum and articles, statutory registers, share certificates, cap table, shareholder agreements, board and shareholder approvals, beneficial ownership records where applicable, options or convertibles, charges and major inter-company arrangements.

The purpose is to verify who owns what, whether securities were validly issued or transferred, whether rights exist outside the cap table, and whether lenders or third parties hold security or consent rights that can affect the transaction.

3. Related-party and promoter transactions

Promoter-linked rent, purchases, loans, management fees, shared employees, asset transfers and group-company arrangements should be mapped separately. The investor needs to know whether the target’s reported profitability depends on related-party pricing or arrangements that may not continue after closing.

Review approvals, contracts, pricing basis, balances outstanding and whether any obligation must be unwound, novated or continued post-closing.

4. Material contracts and revenue quality

Contracts should be reviewed not only for legal enforceability but for transaction impact. Identify customer concentration, vendor concentration, exclusivity, minimum commitments, termination rights, uncapped liability, indemnities, price escalation, service levels, auto-renewal, assignment restrictions and change-of-control clauses.

A company may have strong revenue but weak contract durability if its top customers can terminate immediately after a change in ownership. Conversely, long-term contracts with severe penalties or uneconomic pricing may become liabilities.

5. Litigation, notices and contingent liabilities

Prepare a single schedule of court cases, arbitration, statutory notices, tax disputes, employee claims, customer disputes, vendor claims, criminal complaints involving business transactions, regulatory proceedings and threatened matters.

For each, record claim value, legal merits, stage, limitation, reserve, counsel view, settlement history and worst-case exposure. Pending disputes should be compared with financial-statement provisions and management representations.

6. Labour, HR and key-person risk

Review employment terms, contractor arrangements, statutory dues, bonus and gratuity exposure, POSH governance, employee disputes, key management contracts, retention arrangements, confidentiality, incentive plans and consultant classification.

Key-person dependency should be identified where customer relationships, technical know-how, licences or operations depend disproportionately on one promoter or employee. The transaction may require retention, non-solicitation, handover or transition arrangements consistent with applicable law.

7. Tax, GST and statutory dues

Tax diligence should reconcile filed returns, financial statements, notices, demands, input-tax-credit issues, TDS exposure, related-party transactions and unresolved assessments. The legal diligence report should identify material exposures and whether they are provided for, disputed or unsupported.

Historic tax risk can survive a change in ownership when the same legal entity continues. Accordingly, known exposures should be dealt with through pricing, conditions precedent, specific indemnities or other negotiated protection.

8. Licences and regulatory continuity

Verify each material licence, registration, consent and approval required for the target’s actual business. Confirm holder name, location, activity scope, expiry, transferability and whether the transaction itself triggers consent, notification or fresh approval.

Sector-specific transactions may require additional analysis under competition, foreign-investment, financial-sector or other regulatory frameworks. Current thresholds and conditions should be checked for the specific deal rather than assumed.

9. Data, cyber and intellectual-property risk

Review ownership and licensing of trademarks, software, domains, databases, code, content and other intellectual property material to the business. For technology or data-heavy companies, check whether employees and contractors have assigned relevant IP and whether critical software dependencies are properly licensed.

Data diligence should cover what personal and confidential data is processed, security controls, breach history, processor contracts, access governance, retention, deletion and incident-response capability. Material cyber incidents or uncontrolled privileged access can affect valuation and integration risk.

10. Fraud, integrity and vendor-risk diligence

Traditional legal diligence can miss integrity risks that are visible in operational data. Depending on the transaction, consider targeted review of vendor concentration, duplicate vendors, related-party indicators, bank-account changes, high manual overrides, whistleblower history, unexplained claims and employee conflicts.

See Corporate Fraud Risk Assessment in India and Vendor & Procurement Fraud Risk in India.

11. Red-flag classification

Level Illustrative issue Deal response
Deal breaker Ownership defect, prohibited business risk, material fraud, unmanageable licence issue Pause, restructure or reconsider transaction
Critical Large contingent liability, major customer termination risk, serious regulatory exposure Specific condition, price adjustment, escrow or indemnity
High Material compliance gap, weak contract protection, key-person dependency Pre-closing cure or post-closing covenant
Medium Documentation weakness or manageable control gap Remediation plan
Low Routine housekeeping Post-closing cleanup

12. Converting diligence into deal protection

Diligence has little value if identified risk is not reflected in transaction documents. Common tools include conditions precedent, conditions subsequent, specific warranties, disclosure schedules, indemnities, retention or escrow, purchase-price adjustments, covenants, consent requirements and post-closing remediation obligations.

The protection chosen should match the risk. A curable filing gap may require a condition precedent; a historic tax exposure may require a specific indemnity; uncertain working-capital or receivable quality may require a pricing mechanism; a serious customer-consent issue may require closing to wait.

13. Board and investment-committee deliverables

  • executive red-flag report;
  • materiality-ranked issue register;
  • corporate and ownership exceptions;
  • contract and customer concentration matrix;
  • litigation and contingent-liability schedule;
  • labour and compliance exposure summary;
  • regulatory and licence matrix;
  • fraud / integrity observations where scoped;
  • financial-impact estimate where possible;
  • conditions precedent list;
  • specific indemnity / escrow recommendations; and
  • 100-day post-closing remediation plan.

14. 100-day post-closing risk plan

Days 0–30: close critical filings and licences, change banking access, preserve key records, confirm key customer/vendor continuity, implement authority controls and assign owners to diligence red flags.

Days 31–60: harmonise contracts, HR policies, compliance calendars, vendor controls, data access and litigation reporting.

Days 61–100: complete deep remediation, integrate risk dashboards, audit conditions subsequent, verify indemnity-trigger documentation and report unresolved material items to the board or investment committee.

15. Frequently asked questions

Is legal due diligence enough for an acquisition?

Not always. Depending on the deal, financial, tax, operational, technology, cyber, environmental and commercial diligence may also be required.

Should every diligence issue reduce the purchase price?

No. Some issues are better cured, insured, indemnified or addressed through a covenant.

What is a red-flag report?

A concise report identifying issues material enough to affect valuation, structure, closing or post-closing risk.

Can a buyer rely only on seller warranties?

Warranties are important but are not a substitute for appropriate diligence. Recoverability and contractual limitations also matter.

When should operational fraud testing be added?

Where the target has recurring losses, whistleblower history, weak controls, large vendor networks, unusual claims or other integrity red flags.

Authoritative references

Firm & Correspondence Information
Fastrack Legal Solutions LLP
Office: B1/32 Basement, Malviya Nagar, New Delhi – 110017
Telephone: +91 76976 71219
Email: advgovind@fastracklegalsolutions.com
Website: fastracklegalsolutions.com
The particulars above are provided solely for identification and correspondence. They do not constitute an advertisement, solicitation, invitation or inducement to engage legal services.
General corporate-risk information only. Transaction diligence and deal protection depend on structure, sector, parties, materiality and current regulatory requirements.

Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.

Leave a Comment

Your email address will not be published. Required fields are marked *