Last verified: 26 June 2026
In May 2008, a team of lawyers and accountants sat across a table in a due diligence meeting that would later cost a Japanese pharmaceutical giant roughly US$2.4 billion. Daiichi Sankyo was buying a controlling stake in Ranbaxy, then India’s largest drug maker. The legal due diligence in this M&A deal looked thorough on paper. What the buy-side team never got was the one thing that mattered: the seller’s knowledge that the company was already in the crosshairs of US regulators over data integrity. An arbitral tribunal later found that the sellers had concealed the source and severity of those regulatory problems at the diligence stage. The Delhi High Court enforced the resulting award in Daiichi Sankyo Company Ltd. v. Malvinder Mohan Singh, (Delhi High Court, 31 January 2018).
That deal is now the standard cautionary tale in every Indian M&A classroom. And it teaches one lesson better than any textbook: due diligence is only as good as the questions you ask and the answers you insist on verifying.
Here’s the uncomfortable truth for anyone starting out in transactions. Most legal due diligence on Indian deals is run by associates who learned the process on the job, working off a checklist someone forwarded them three deals ago. The checklist was probably built before the 2023 amendments to the Competition Act, before the four Labour Codes came into force in November 2025, before the DPDP Rules were notified, and before the Income Tax Act, 2025 replaced the 1961 statute. A 2019 checklist run on a 2026 deal misses real liabilities.
This guide rebuilds that checklist from scratch, for the law that actually applies today. It walks through what legal due diligence in an M&A transaction covers, area by area, the order in which a deal team actually runs it, the red flags that reprice or kill deals, and how every finding should flow into the share purchase agreement. It’s written for the person doing the work: the associate reviewing the data room at 11 p.m., the in-house counsel scoping a bolt-on acquisition, the law student who wants to understand what corporate lawyers really do.
You’ll see specific sections, specific filings, and specific 2026 thresholds throughout. That’s deliberate. Vague diligence is worthless diligence.
Legal due diligence in M&A is the buyer’s structured investigation of a target company’s legal affairs before signing or closing, to identify liabilities, confirm what’s being bought, and price risk into the deal. A complete checklist covers twelve areas: corporate structure, share capital, material contracts, litigation, employment and labour, intellectual property, real estate, regulatory licences and competition approval, tax, data protection, financing and security, and (for cross-border deals) FEMA and FDI compliance.
Before getting into the twelve areas, it helps to be clear on what diligence is for, who runs it, and the choices that get made before a single document is reviewed. Those scoping decisions shape everything that follows.
What legal due diligence in M&A actually involves
Legal due diligence is the investigation a buyer conducts into the legal standing of a target before committing to buy it. Think of it as the legal equivalent of a building survey before you purchase a house. You’re checking that the seller owns what they claim to own, that the structure is sound, and that there are no hidden charges registered against it.
The purpose is threefold. First, confirmation: does the target actually own its assets, shares, and contracts? Second, risk identification: what liabilities, disputes, or compliance gaps come attached? Third, deal mechanics: what needs to be fixed before closing, what needs a price adjustment, and what needs a specific indemnity in the contract? Every finding feeds one of those three buckets.
Who runs it, and on which side
On a typical Indian deal, the buy-side law firm runs diligence with input from the buyer’s accountants (financial and tax diligence) and sometimes technical or environmental consultants. The associate team does the document review; a partner signs off on the due diligence report (DDR). On the other side, the target and its counsel populate the data room and respond to queries.
There’s also vendor due diligence, where the seller commissions its own diligence report up front, often in a competitive auction, to hand to bidders. It speeds the process but you should never treat a vendor’s report as a substitute for your own review. The seller paid for it. Read it for leads, then verify independently.
Full, confirmatory, or red-flag diligence
Not every deal gets the full treatment. The scope depends on deal size, structure, and risk appetite. A full-scope review examines everything. A red-flag review (sometimes called high-level or top-up diligence) looks only for deal-breakers and material liabilities, leaving routine items aside. Confirmatory diligence happens between signing and closing to check nothing material has changed.
So which one does your deal need? The honest answer is that it depends on what you’re buying and how. That brings us to the single most important distinction in the whole exercise.
Share deal versus asset deal: why the structure changes the checklist
In a share acquisition, the buyer purchases the shares of the target and inherits the company whole: every asset, every contract, and crucially every liability, known and unknown. In an asset acquisition (a business transfer or slump sale), the buyer cherry-picks specific assets and liabilities and leaves the rest behind with the seller.
This matters enormously for diligence. In a share deal, you’re inheriting the company’s entire litigation history, tax exposure, and contingent liabilities, so diligence must be exhaustive. In an asset deal, you can be more targeted, but you have to verify clean title to each asset being transferred and check that contracts can actually be assigned. The mistake we see most often is running an asset-deal-depth review on a share deal. You end up owning liabilities nobody looked for.
Before you start: scoping the diligence
Diligence done well starts before any document is opened. What does good scoping look like in practice? It means agreeing the boundaries of the exercise so the team isn’t drowning in immaterial paper while the real risks go unexamined.
Set materiality thresholds early
Reviewing every Rs. 5,000 vendor invoice on a Rs. 500-crore deal is a waste of a junior’s week. Agree materiality thresholds with the client at the outset: contracts above a certain annual value, litigation above a certain claim amount, liabilities above a defined figure. Everything below the line gets sampled, not read line by line. Set the number too high and you miss things; set it too low and you bury the team. For a mid-market Indian deal, contract review thresholds in the Rs. 25 lakh to Rs. 1 crore range are common, but calibrate to the target’s size.
The due diligence request list
The diligence request list (DDRL) is the document you send the target listing everything you want to see. A good request list is organised by the same twelve areas covered below, with specific asks under each: certified copies of the memorandum and articles, the statutory registers, the last three years of board and shareholder resolutions, all material contracts, the litigation docket, and so on. A weak request list is generic and invites a generic, incomplete response.
The data room and the NDA
Documents are shared through a virtual data room (VDR), an access-controlled online repository. Before the room opens, a non-disclosure agreement governs confidentiality and the permitted use of information. Worth flagging: the NDA should be in place before any sensitive information moves, and for competitively sensitive data between competitors, a clean team arrangement (where only designated outside advisers, not commercial staff, see the data) protects against competition-law exposure during the deal itself.
One practical point that catches out junior teams. The data room index is not the same as a complete record. Sellers control what goes in. The absence of a document is itself a finding, and “not provided” deserves a follow-up query, not a shrug. We cover how to manage that in the workflow section. As covered in iPleaders’ broader walkthrough of how mergers and acquisitions work in India, scoping is where deals are quietly won or lost.
The legal due diligence checklist: twelve areas
This is the core of the exercise. Each area below lists what you’re verifying, the specific Indian documents and filings to demand, and the issues to watch for. Run them in roughly this order: corporate first (because nothing else means anything if the company isn’t validly constituted), then capital, contracts, and the rest.
1. Corporate structure and constitutional documents
Start with the certificate of incorporation, the memorandum and articles of association, and the current shareholding structure including any holding, subsidiary, and associate companies. You’re confirming the company exists, is in good standing, and is structured the way the seller represents. Pull the master data and the index of charges from the MCA portal and cross-check against what’s in the data room.
Examine the statutory registers maintained under the Companies Act, 2013: the register of members, register of directors, and register of charges. Review board and shareholder resolutions for the last three to five years, with particular attention to anything requiring a special resolution. Has the company filed its annual returns (Form MGT-7) and financial statements (Form AOC-4) on time? Persistent late filings signal a company that treats compliance casually, and that habit usually extends to areas you can’t see.
2. Share capital and ownership
Here you verify exactly what you’re buying. Confirm the authorised, issued, and paid-up capital, and trace the cap table back through every allotment, transfer, buy-back, and bonus issue. Check that share certificates were issued, that stamp duty was paid on transfers, and that statutory filings (such as the return of allotment in Form PAS-3) were made.
Look hard for encumbrances on the shares: pledges, liens, or any security interest. Check for outstanding ESOPs, convertible instruments, warrants, or any agreement that could dilute the holding post-closing. Then comes the document that derails more deals than any other: an existing shareholders’ agreement with pre-emption rights, tag-along, drag-along, or rights of first refusal. If a minority shareholder has a right of first refusal over the shares you’re buying, your entire deal may need their waiver first.
3. Material contracts
This is where the company’s commercial reality lives. Review all material customer, supplier, distribution, licensing, joint venture, and financing contracts against your materiality threshold. For each, you’re checking term, termination rights, exclusivity, liability caps, and governing law.
The clause that matters most in an acquisition? The change-of-control provision. Many commercial contracts let the counterparty terminate, or trigger a consent requirement, if the target changes hands. A target whose three biggest customer contracts can all be cancelled on a change of control is worth far less than its revenue suggests. Flag every change-of-control and assignment-restriction clause; these become conditions precedent (third-party consents) or price adjustments. For the mechanics of the clauses you’ll be reading, iPleaders’ clause-by-clause guide to drafting a master service agreement breaks down what each term actually does.
Watch also for non-compete and exclusivity obligations that bind the target, related-party contracts (which may be on non-arm’s-length terms and need scrutiny under Section 188 of the Companies Act, 2013), and any contract whose value depends on a single key person.
4. Litigation and disputes
Demand a complete litigation docket: pending civil suits, criminal complaints, arbitrations, consumer cases, tax appeals, labour disputes, and regulatory proceedings, plus any threatened claims. For each material matter, assess the claim amount, the stage, the likely outcome, and whether it’s provided for in the accounts.
Don’t rely solely on the seller’s list. Run independent searches: case status on the eCourts portal, the relevant High Court and tribunal websites, and the NCLT for any insolvency proceedings. A pending petition under the Insolvency and Bankruptcy Code, 2016 against the target is close to a deal-stopper, because it can trigger a moratorium and strip the board of control. The real question isn’t just “what’s pending” but “what’s coming,” so look at correspondence threatening litigation, not only filed cases.
5. Employment and labour
This area changed materially in late 2025, and a pre-2025 checklist will get it wrong. The four Labour Codes (the Code on Wages, 2019; the Industrial Relations Code, 2020; the Code on Social Security, 2020; and the Occupational Safety, Health and Working Conditions Code, 2020) were brought into force across the country with effect from 21 November 2025, consolidating 29 earlier central labour laws.
What does that mean for diligence? Review the target’s employment contracts, the appointment letters now mandated under the OSH Code, HR policies, and the standing orders. Verify compliance with the uniform definition of “wages” under the Code on Wages, 2019, which sets a floor of 50% of total remuneration as basic wages and changes gratuity, provident fund, and full-and-final settlement calculations. Check provident fund and ESI contributions, gratuity provisioning, and POSH compliance (the internal committee and annual filings under the Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013). For the broader picture of what compliant employment documentation looks like in 2026, see iPleaders’ guide on drafting an employment agreement in India.
One frequently overlooked exposure: misclassified contractors and gig workers, who now fall within the social-security net under the Code on Social Security, 2020. A target with a large “consultant” workforce may be carrying an undeclared liability.
6. Intellectual property
For many targets, especially in technology, pharma, and consumer goods, the IP is the asset. Confirm ownership of registered trademarks, patents, copyrights, and designs through the relevant registry records, and verify that registrations are current and renewal fees paid. For unregistered IP and software, trace the chain of title.
Here’s the trap that catches technology deals. Code written by an independent contractor belongs to the contractor unless there’s a written assignment, regardless of who paid for it. So check that all developer and contractor agreements contain valid IP assignment clauses. Review in-licensed IP for change-of-control restrictions, scrutinise any open-source software in the product (which can carry copyleft obligations), and confirm there’s no pending infringement litigation either by or against the target.
7. Real estate and assets
Verify title to all owned immovable property through the title deeds and the encumbrance certificate from the sub-registrar, and check for registered mortgages or charges. For leased premises, review every lease and leave-and-licence agreement for term, renewal rights, rent escalation, and, again, change-of-control or assignment restrictions that could disrupt the target’s operations after the deal.
Confirm that property is held in the company’s name (not, as sometimes happens in promoter-run companies, in a director’s personal name), that property tax is paid, and that the use complies with local zoning and building approvals. For manufacturing targets, environmental clearances and pollution-control board consents belong here too.
8. Regulatory licences and competition approval
List every licence, registration, permit, and approval the target needs to operate, from GST registration and the shops-and-establishment licence to sector-specific approvals (an NBFC’s RBI registration, a pharma company’s drug licences, an FSSAI licence for food businesses). Confirm each is valid, in the company’s name, and not due to lapse, and check whether any is non-transferable or requires fresh approval on a change of control.
Then there’s the deal’s own competition clearance. Under the Competition Act, 2002 (as amended by the Competition (Amendment) Act, 2023, with the Competition Commission of India (Combinations) Regulations, 2024 effective from 10 September 2024), a transaction crossing the notification thresholds needs prior CCI approval before closing. The party-level threshold (revised on 7 March 2024) is combined assets of over Rs. 2,500 crore or turnover of over Rs. 7,500 crore in India. There’s also a deal-value threshold: any transaction valued above Rs. 2,000 crore needs approval where the target has substantial business operations in India. A de minimis “small target” exemption applies where the target’s Indian assets are not more than Rs. 450 crore or its Indian turnover not more than Rs. 1,250 crore, but note that this exemption fell away above the Rs. 2,000-crore deal-value line. Because these figures are revised periodically, confirm the current notification before advising. iPleaders covers the full framework in its guide to CCI merger control, the deal value threshold and the Green Channel.
9. Tax
Tax diligence is usually led by accountants, but legal counsel must understand the exposures because they end up in the indemnities. Review income-tax returns and assessment orders for the last several years, GST filings and reconciliations, TDS compliance, and any pending tax litigation or demands. Contingent tax liabilities are among the most common deal repricers.
Two 2026 points. First, the Income Tax Act, 2025 replaces the Income-tax Act, 1961 with effect from 1 April 2026, reorganising the statute around a single “Tax Year”; it’s largely a structural rewrite rather than a rate change, but assessment references in older documents now map to new sections. Second, for cross-border or holding-structure deals, the ghost of indirect-transfer taxation still matters. The Supreme Court’s decision in Vodafone International Holdings B.V. v. Union of India, (2012) 6 SCC 613 held that an offshore transfer of shares in a foreign holding company was not taxable in India, but the law was later amended, so the taxability of any layered acquisition structure must be checked carefully rather than assumed.
10. Data protection and IT
This area barely existed on Indian diligence checklists three years ago. It does now. The Digital Personal Data Protection Act, 2023 has its rules in place: the Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, with the substantive compliance obligations phased in and the bulk of them taking effect from 13 May 2027.
For a target that processes personal data (which, in practice, is almost every consumer-facing business), review the privacy notices, consent mechanisms, data-processing agreements with vendors, and any history of data breaches. A target that has been cavalier about data handling carries forward-looking compliance cost and potential penalty exposure. iPleaders’ operational compliance guide to the DPDP Rules, 2025 sets out exactly what a compliant data operation should look like, which doubles as your diligence yardstick. Alongside data, review IT contracts, software licences, and cybersecurity posture.
11. Financing, debt and security
Map the target’s entire debt stack: term loans, working-capital facilities, debentures, and inter-corporate deposits. For each, review the financing agreement for the interest rate, repayment schedule, financial covenants, events of default, and (the recurring theme) change-of-control clauses, which in lending documents frequently trigger mandatory prepayment or lender consent.
Pull the register of charges and the MCA index of charges to confirm what security has been created over the company’s assets, and check that satisfied charges have actually been released (Form CHG-4 filed). An unreleased charge over an asset you think is unencumbered is a classic diligence miss. Personal guarantees given by promoters, and any security over the very shares you’re acquiring, belong here too.
12. FEMA, FDI and cross-border compliance
For any deal with a foreign buyer or foreign-held target, foreign-exchange compliance is non-negotiable. Confirm past foreign investment was reported correctly (the FC-GPR and FC-TRS filings under the Foreign Exchange Management Act, 1999), that pricing complied with the RBI’s pricing guidelines, and that the target’s sector permits the proposed foreign investment under the FDI policy.
Two specific traps. Sectors under the government (approval) route need prior approval before the investment, not after. And under Press Note 3 of 2020, any investment from an entity in a country sharing a land border with India (China, Bangladesh, Pakistan and others) requires government approval regardless of sector, with beneficial ownership traced through the structure. Miss this and the deal can be unwound.
The step-by-step diligence workflow
Knowing the twelve areas is one thing. Running them as a coherent process under deal pressure is another. Here’s how a buy-side team actually moves from kick-off to a usable due diligence report.
- Kick-off and scoping. Agree the scope (full, red-flag, or confirmatory), materiality thresholds, timeline, and team allocation with the client. Decide who reviews which of the twelve areas and who owns the master tracker.
- Issue the request list. Send the structured DDRL and confirm data-room access. A good request list mirrors your checklist so responses slot straight into your review.
- First-pass review and indexing. Work through the data room area by area, indexing documents against the request list and noting gaps. “Not provided” items go straight into the query log.
- Raise queries. Send numbered, specific queries to the target’s counsel. Track every query and every response. Vague queries get vague answers; “please confirm whether contract X contains a change-of-control clause and provide the executed copy” gets you the document.
- Maintain the issues tracker. The heart of the exercise. Every finding goes into a single tracker with the issue, the document reference, the risk rating (high, medium, low), and the proposed deal solution (condition precedent, indemnity, price adjustment, or accept).
- Escalate red flags immediately. Don’t wait for the final report to tell the client about a deal-breaker. A pending insolvency petition or a fundamental title defect gets escalated the day you find it.
- Prepare the due diligence report. The DDR summarises findings by area, flags material risks, and translates each into a recommended action. Most clients want an executive summary of red and amber issues up front, with detail behind it.
- Feed findings into the documents. The DDR is not the end. Every material finding must convert into specific language in the share purchase agreement and the disclosure letter. Diligence that doesn’t shape the contract was an academic exercise.
How long does all this take? On a mid-market Indian deal, three to six weeks for full diligence is typical, though auction timetables and confirmatory-only scopes compress it. The pacing pressure is real, which is exactly why the issues tracker matters: it stops findings from getting lost between the review and the drafting.
Red flags that reprice or kill deals
Some findings are routine. Others change the deal. Which ones should set off alarms? After enough transactions, a pattern emerges of the issues that consistently force a renegotiation, a fresh indemnity, or a walk-away.
Undisclosed or contingent litigation tops the list, especially tax demands and regulatory proceedings that haven’t been provided for. A pending IBC petition is close to fatal. Defective title to a key asset (the factory the whole valuation rests on, held in a promoter’s name rather than the company’s) stops deals cold. So do change-of-control clauses clustered in the target’s most valuable contracts, because they convert “recurring revenue” into “revenue the counterparties can cancel the day after closing.”
Then there’s the category the Daiichi-Ranbaxy saga made famous: concealment. The arbitral tribunal in that matter found the sellers had been aware of serious regulatory issues at the time of the diligence meeting and had not disclosed them. When the documents don’t add up, when “not provided” answers cluster around one sensitive area, when management is evasive on a specific topic, treat the silence as a finding. The better approach, in our view, is to assume the gap hides something and price or paper around it rather than hoping it’s nothing.
Other repeat offenders: unreleased charges on supposedly clean assets, large undeclared employee liabilities (gratuity and PF shortfalls, misclassified contractors), missing or lapsing licences, related-party transactions on non-arm’s-length terms, and FEMA reporting failures on past foreign investment. None of these necessarily kills a deal. All of them change its price or its paper.
How findings flow into the transaction documents
Diligence and drafting are not separate workstreams. The whole point of finding a problem is to allocate its risk in the contract. So where does each finding land?
Conditions precedent
Anything that must be fixed before closing becomes a condition precedent (CP) in the share purchase agreement: third-party consents for change-of-control contracts, regulatory approvals (including CCI clearance where required), release of charges, or rectification of a title defect. The deal doesn’t close until the CPs are satisfied or waived.
Representations and warranties
Warranties are the seller’s contractual statements about the target (that the accounts are accurate, that there’s no undisclosed litigation, that title is clean). Diligence tells you which warranties to insist on and where to push for specificity. A breach gives the buyer a damages claim. The seller, in turn, qualifies its warranties through the disclosure letter.
The disclosure letter
This is the seller’s formal carve-out from the warranties: a document disclosing exceptions, so the seller isn’t liable for things it has flagged. Reviewing the disclosure letter against your diligence findings is one of the most important late-stage tasks. A finding you made that the seller then “discloses” is a finding you can no longer claim on unless you’ve negotiated a specific indemnity for it.
Specific indemnities
For a known, quantifiable risk (a pending tax demand of a specific amount, an identified litigation), the buyer negotiates a specific indemnity: a rupee-for-rupee promise to reimburse that loss, usually outside the general warranty caps and baskets. This is precisely how a diligence red flag becomes a protected position. Note that indemnity and damages interact with Section 74 of the Indian Contract Act, 1872 on the recovery of stipulated sums, so the drafting of caps, baskets, and de minimis thresholds matters.
Escrow, holdback and W&I insurance
Where there’s risk that survives closing, part of the consideration may sit in escrow or be held back for a defined period to secure indemnity claims. Increasingly on larger Indian deals, warranty and indemnity (W&I) insurance transfers the risk of unknown warranty breaches to an insurer, which itself relies on the quality of your diligence. A thin diligence report means a narrow policy. The insurer reads your DDR before they price the cover.
Listed-company and public M&A specifics
Everything above applies to private deals. When the target is a listed company, an extra regulatory layer sits on top, and diligence has to account for it.
The acquisition of shares or control in a listed company is governed by the SEBI (Substantial Acquisition of Shares and Takeovers) Regulations, 2011, the Takeover Code. Crossing 25% of voting rights, or acquiring control regardless of the percentage, triggers a mandatory open offer to public shareholders for at least 26% more. There’s also a creeping-acquisition allowance of up to 5% per financial year within defined limits. Diligence on a listed target therefore includes the target’s own securities-law compliance: disclosures under the Takeover Code and the SEBI (Prohibition of Insider Trading) Regulations, 2015, and its LODR (Listing Obligations and Disclosure Requirements) filings.
Why does this change the diligence? Because for a listed target, much of the public information is already disclosed, but the deal mechanics (open offer pricing, timing, and the inability to access non-public price-sensitive information without triggering insider-trading concerns) constrain what diligence you can even do pre-announcement. iPleaders explains the trigger-and-pricing mechanics in detail in its guide to the open offer under the SEBI Takeover Code.
Common mistakes lawyers make in M&A diligence
Most diligence failures aren’t exotic. They’re the same handful of process errors, repeated. Recognise them and you’ll already be ahead of where many associates start.
The first is treating the data room index as a complete record. Sellers populate the room; absence is not proof of non-existence. Every “not provided” is a query, not a closed item. The second is running the wrong depth for the structure, the asset-deal review on a share deal we flagged earlier, which leaves inherited liabilities unexamined.
The third, and the costliest, is diligence that never reaches the contract. A beautiful 80-page DDR that doesn’t translate into CPs, warranties, and indemnities protects nobody. The third reads well and changes nothing. The fourth is using a stale checklist: applying pre-2025 employment law, pre-2024 competition thresholds, or pre-DPDP data rules to a 2026 deal. The law moved; the checklist has to move with it.
Two more worth naming. Over-relying on vendor due diligence without independent verification, because the seller commissioned it. And tunnel vision on the documents while ignoring the soft signals: evasive management, clustered gaps, last-minute disclosures. Frankly, this gets overlooked, and it’s where the Daiichi lesson lives. The documents told one story; what wasn’t in them told the real one.
Quick-reference checklist
For the associate who wants the one-page version to keep beside the data room, here’s the condensed checklist across all twelve areas. Treat each as a prompt, not a substitute for the detail above.
- Corporate: incorporation certificate, MoA and AoA, statutory registers, board and shareholder resolutions, MGT-7 and AOC-4 filing history, good standing.
- Share capital: cap table traced through every allotment and transfer, stamp duty on transfers, encumbrances, ESOPs and convertibles, shareholders’ agreement and pre-emption rights.
- Material contracts: term, termination, exclusivity, liability caps, and above all change-of-control and assignment clauses; related-party contracts under Section 188.
- Litigation: full docket plus independent eCourts, High Court, tribunal and NCLT searches; threatened claims; IBC exposure.
- Employment and labour: contracts and appointment letters, Labour Codes compliance (effective 21 November 2025), PF/ESI/gratuity, POSH, contractor misclassification.
- Intellectual property: registrations and renewals, chain of title, contractor IP assignments, open-source obligations, infringement claims.
- Real estate: title deeds, encumbrance certificate, leases and change-of-control clauses, property held in company name, zoning and environmental approvals.
- Regulatory and competition: all licences valid and transferable; CCI notification analysis against the 2026 thresholds.
- Tax: returns, assessments, GST and TDS compliance, contingent demands; Income Tax Act, 2025 transition; indirect-transfer exposure on layered structures.
- Data protection: DPDP readiness, consent and notice mechanisms, processor agreements, breach history.
- Financing and security: full debt stack, covenants and change-of-control triggers, register of charges, released charges (CHG-4), promoter guarantees.
- FEMA and FDI: FC-GPR/FC-TRS reporting, pricing compliance, sectoral route, Press Note 3 land-border check.
Frequently asked questions
What is legal due diligence in M&A?
It’s the buyer’s structured legal investigation of a target company before signing or closing an acquisition. The aim is to confirm what’s being bought, identify liabilities and compliance gaps, and translate each finding into the transaction documents through conditions precedent, warranties, or indemnities.
How long does legal due diligence take in an Indian M&A deal?
Full-scope diligence on a mid-market Indian deal typically takes three to six weeks, depending on the target’s size and the quality of the data room. Red-flag or confirmatory reviews are faster. Auction timetables often compress the schedule, which makes scoping and a disciplined issues tracker essential.
What is the difference between a share deal and an asset deal for diligence?
In a share deal the buyer inherits the whole company, including all liabilities known and unknown, so diligence must be exhaustive. In an asset deal the buyer acquires specific assets and liabilities, so the review is more targeted but must confirm clean title to each asset and that contracts can be assigned.
What are the biggest red flags in M&A due diligence?
Undisclosed or contingent litigation and tax demands, a pending insolvency petition, defective title to a key asset, change-of-control clauses in major contracts, unreleased charges, large undeclared employee liabilities, and any sign of concealment by the seller. Each either reprices the deal or, in the worst cases, ends it.
When is CCI approval required for an acquisition in India?
CCI approval is needed before closing when the transaction crosses the notification thresholds under the Competition Act, 2002. As revised on 7 March 2024, the party-level threshold is combined Indian assets over Rs. 2,500 crore or turnover over Rs. 7,500 crore, and a separate deal-value threshold catches transactions valued above Rs. 2,000 crore where the target has substantial business operations in India. Confirm the current notification, as the figures are revised periodically.
How have the 2025 Labour Codes changed employment due diligence?
The four Labour Codes came into force on 21 November 2025, consolidating 29 central labour laws. Diligence must now check compliance with the new uniform “wages” definition (basic wages at least 50% of total remuneration), mandatory appointment letters under the OSH Code, and social-security coverage for gig and contract workers, which can expose undeclared liabilities in targets with large consultant workforces.
Does the DPDP Act affect M&A due diligence?
Yes. With the Digital Personal Data Protection Rules, 2025 notified on 13 November 2025 and substantive obligations phasing in (largely from 13 May 2027), a target’s data-handling practices now carry compliance cost and penalty exposure. Diligence should review privacy notices, consent mechanisms, processor agreements, and breach history.
What is a disclosure letter and why does it matter?
The disclosure letter is the seller’s formal carve-out from its warranties, listing exceptions so it isn’t liable for items it has flagged. It matters because a risk you found in diligence, once “disclosed,” can no longer be claimed under the general warranties unless you’ve negotiated a specific indemnity for it. Reviewing the disclosure letter against your findings is a critical late-stage task.
What is the difference between due diligence and a due diligence report?
Due diligence is the investigation itself; the due diligence report (DDR) is the deliverable that summarises findings by area, rates risks, and recommends actions. The DDR is not the finish line. Its findings must then convert into specific language in the share purchase agreement and the disclosure letter.
Can a buyer rely on vendor due diligence?
Use it for leads, not as a substitute. Vendor diligence is commissioned and paid for by the seller, so a prudent buyer reads it for context and then independently verifies the material points. Relying on it without verification is one of the more common and avoidable diligence mistakes.
What happens if due diligence finds a problem?
It gets allocated in the contract. Issues to be fixed before closing become conditions precedent; known quantifiable risks become specific indemnities; broader risks are covered by warranties, escrow, holdbacks, or W&I insurance; and serious unfixable problems can justify a price reduction or walking away.
Is legal due diligence different for a listed company?
Yes. A listed target adds a securities-law layer: the SEBI Takeover Code (with its open-offer triggers at 25% or on acquiring control), insider-trading rules that limit access to non-public information pre-announcement, and LODR compliance. Much information is already public, but the deal mechanics constrain what diligence is even permissible before the deal is announced.
References
Case law
- Daiichi Sankyo Company Ltd. v. Malvinder Mohan Singh & Ors. (Delhi High Court, 31 January 2018). Indian Kanoon
- Vodafone International Holdings B.V. v. Union of India, (2012) 6 SCC 613. Indian Kanoon
Statutes and regulations
- Companies Act, 2013 (sections cited include 188 on related-party transactions; filings MGT-7, AOC-4, PAS-3, CHG-4)
- Competition Act, 2002 (as amended by the Competition (Amendment) Act, 2023); Competition Commission of India (Combinations) Regulations, 2024. CCI
- Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025. PIB notification
- Code on Wages, 2019; Industrial Relations Code, 2020; Code on Social Security, 2020; Occupational Safety, Health and Working Conditions Code, 2020 (in force 21 November 2025)
- Income-tax Act, 1961 and Income Tax Act, 2025 (in force 1 April 2026)
- Insolvency and Bankruptcy Code, 2016
- Indian Contract Act, 1872 (section 74)
- Foreign Exchange Management Act, 1999 and the FDI policy (including Press Note 3 of 2020)
- SEBI (Substantial Acquisition of Shares and Takeovers) Regulations, 2011; SEBI (Prohibition of Insider Trading) Regulations, 2015; SEBI (LODR) Regulations, 2015
- Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013
This article is for informational and educational purposes only and does not constitute legal advice. Statutory thresholds and effective dates referenced here are revised periodically; verify the current position before relying on them. For specific legal guidance on a transaction, consult a qualified legal professional.





