Practical legal intelligence for business owners β no jargon, no textbook language. Just clear, actionable insight.
12 warning signs to look for before you sign any commercial contract.
No spam. Unsubscribe anytime. Your email is safe with us.
A four-year vesting schedule with a one-year cliff is now near-universal in Indian cap tables β yet founders regularly skip it, assuming trust will hold. It doesn't need to; the clause exists precisely for when it doesn't.
The five terms worth getting right from day one: vesting with a cliff, drag-along and tag-along rights so a majority sale can't be blocked by a single holdout, a defined list of reserved matters requiring unanimous or board consent, a deadlock-resolution mechanism for when two equal co-founders disagree, and an explicit IP assignment clause confirming that anything built for the company belongs to the company β not to whoever happened to write the code.
Most of these cost nothing to include and everything to have missed, usually discovered at the worst possible moment: during a fundraise, an exit, or a co-founder split.
Most businesses don't need a compliance department to stay ahead of regulatory change β they need a system. Start by mapping which regulators actually apply to you: sector-specific bodies (RBI, SEBI, TRAI, FSSAI, depending on what you do) plus the general-purpose ones every company deals with β the Ministry of Corporate Affairs and GST authorities.
Against that map, assign one owner per obligation, set a quarterly review cadence, and subscribe directly to official gazette and regulator notifications rather than relying on news coverage, which is often weeks behind and inconsistently accurate.
The businesses that get caught out aren't usually in unfamiliar territory β they're in familiar territory that quietly changed underneath them.
Interconnect Usage Agreements (IUCs) between telecom operators sit within a TRAI-defined framework, but the framework sets a floor, not a full answer β liability caps, quality-of-service obligations, and dispute-escalation routes to TDSAT still need to be negotiated with the same care as any commercial contract.
The most common gap: liability caps drafted to mirror a template rather than the actual traffic volumes and revenue at stake, leaving an operator exposed on exactly the scenario the clause was meant to guard against.
This is grounded in specialised telecom law training early in a career spent largely in-house at British Telecom (BT) India β where interconnect and service-level terms weren't theoretical, they were the daily work.
With India's Digital Personal Data Protection Act (DPDP Act, 2023) now in force, a standard SaaS agreement that doesn't address data processing terms is a gap, not a formality. The clauses worth checking: purpose limitation (the vendor can only use your data for what you contracted them to do), breach notification timelines, sub-processor flow-down obligations (your vendor's vendors inherit the same duties), and audit rights.
Most SaaS agreements are drafted by the vendor, for the vendor. Reading one as a buyer means checking not just what it promises, but what it conveniently leaves silent.
This draws on in-house time at Oracle India, in a product- and licensing-heavy environment where these terms weren't boilerplate β they were the product.
ASCI (the Advertising Standards Council of India) is self-regulation β its rulings carry industry weight but not the force of law. The Consumer Protection Act, 2019 is different: it gives the Central Consumer Protection Authority (CCPA) the power to investigate misleading advertisements directly, order their withdrawal, and impose penalties, independent of any ASCI process.
A claim can clear ASCI review and still create legal exposure if it can't be substantiated on request β 'clinically proven', 'best in class', and similar language are the first things regulators test.
The practical fix is simple and usually skipped: keep the substantiation file before the campaign runs, not after someone asks for it.
The Consumer Protection (E-Commerce) Rules, 2020 require disclosures that many D2C sites still treat as optional: country of origin for each product, a named grievance officer with contact details, and a clearly displayed return, refund, and exchange policy β not buried three clicks deep in a footer link.
These aren't paperwork exercises. Missing disclosures are one of the more common triggers for a CCPA inquiry, and they're entirely within a business's control to fix before it becomes one.
Consumer-facing terms are a recurring thread across two decades of commercial and consumer-dispute-adjacent work β the fixes are usually fast; the businesses that skip them rarely realise until a complaint lands.
A 15% rent escalation every three years is the commonly quoted market benchmark for commercial leases β but 'standard' isn't a legal term, and plenty of leases quietly deviate from it in the landlord's favour, especially on lock-in periods and exit terms.
The clauses worth real scrutiny before signing: the lock-in period (and whether it's enforceable against you but not the landlord), how the security deposit is treated on early exit, and whether RERA applies β commercial leases usually sit outside RERA's residential-focused framework, which changes what protections you can actually rely on.
None of this is complex once someone reads it properly before, not after, the signature.
The POSH Act, 2013 requires every Internal Committee to include an external member β someone from an NGO or with relevant legal expertise, not a familiar face brought in to fill a seat. This single requirement is the most commonly missed part of an otherwise well-intentioned POSH setup.
Beyond composition: quorum rules for hearings, a 90-day statutory timeline to complete an inquiry once a complaint is filed, and real consequences for non-compliance under Section 26 of the Act, including financial penalties.
Setting this up properly once avoids having to explain, later, why it wasn't.
SEBI's Business Responsibility and Sustainability Reporting (BRSR) framework is mandatory for the top 1,000 listed companies by market capitalisation β but its influence reaches well beyond that list, as larger companies increasingly push BRSR-style disclosure requirements down their supply chains as a condition of doing business.
For a business not yet caught by the mandatory threshold, the practical starting point isn't a full reporting framework β it's a materiality assessment (which ESG issues actually matter to your business), a written governance policy, and the internal data-collection systems to back up whatever you eventually report.
Building this before it's required is considerably cheaper than building it under deadline pressure from a customer's procurement team.
Section 177(9) of the Companies Act, 2013 requires certain companies to establish a vigil mechanism β but a policy document alone doesn't satisfy the spirit of the requirement if no one trusts it enough to use it.
What actually makes a whistleblower mechanism work: genuine confidentiality safeguards, an explicit non-retaliation clause with teeth, and a reporting channel that doesn't route complaints through the very people most likely to be implicated.
A code of conduct and a whistleblower policy that people have actually read β and believe β is worth more than either sitting unread in an onboarding folder.
Most compliance calendars fail the same way: they track periodic obligations β ROC annual filings, GST returns β well, and completely miss event-triggered ones, like the filings required after a board change, a share allotment, or a related-party transaction.
The fix is a simple reframe: instead of one calendar organised by date, maintain a register organised by trigger, with a named owner for each category and a defined action the moment that trigger occurs.
This is the same underlying discipline used to set up and run the Dell Contracts Centre of Excellence (COE) in India β not a bigger team, but a better system.
A downloaded HR policy that doesn't match how your team actually works isn't a safety net β it's a liability. If a policy exists on paper but isn't consistently applied, it can be used as evidence against the employer precisely because the company held itself to a standard it didn't follow.
The fix isn't a longer policy β it's a shorter, accurate one: written in language your managers will actually apply, backed by acknowledgment and training records that prove people knew about it, not just that HR published it.
A policy nobody follows is worse, legally, than no policy at all.
The issues that kill deals late are rarely the big, obvious ones β those usually surface early. It's the smaller gaps found in the final stretch of diligence: undisclosed related-party transactions, IP built by a founder personally but never formally assigned to the company, statutory filings that lapsed years ago and were never caught, and contingent liabilities buried inside indemnity clauses in old vendor contracts.
Each of these is fixable if found early β expensive, or deal-ending, if found in week eleven of a twelve-week diligence process.
A pre-diligence self-audit, run before a buyer's lawyers start theirs, is the cheapest insurance a seller can buy.
Indian courts have taken a narrower view of force majeure since 2020 than many businesses expected β generic 'acts of God' language is increasingly read strictly, and a party invoking it has to show the clause actually covers the specific event, not just that something disruptive happened.
For manufacturing and supply agreements specifically: liability for delivery delays, quality-defect responsibility across a multi-tier supply chain, and a clearly defined (not implied) list of triggering events matter more than they used to.
Courts also expect evidence of mitigation β that the party invoking force majeure tried to reduce the impact, not just waited it out.
Finance reports to the board on a handful of consistent metrics every quarter. Legal, in most companies, reports only when something has already gone wrong β which means the board never sees the trend line until it's a crisis.
One metric worth tracking at board level: contract cycle time and risk exposure by counterparty β not as a legal-department vanity number, but as an early-warning system for where the business is taking on risk faster than it's managing it.
This is the kind of legal intelligence built from corporate leadership roles working directly with legal, finance, and business teams β not from reviewing contracts in isolation.
More articles coming every week. Subscribe to get notified.
Short, practical videos breaking down the legal concepts every business owner should understand. No lectures. No jargon. Just clarity.
Add your YouTube embed here
Let's apply this knowledge to your specific situation. Get in touch today.