Vendor Compliance
Vendor Compliance in India: A Complete Guide to Onboarding, Monitoring and Risk Control
A company can maintain flawless books, file every return on time and still find itself paying for someone else’s non-compliance. That is the peculiar nature of vendor risk in India. If a supplier fails to report an invoice in its GST return, the buyer’s input tax credit is denied — with interest — even though the buyer paid the tax in full and holds a valid invoice. If a labour contractor does not deposit provident fund or ESI contributions for the workers it deployed at a client’s premises, the principal employer becomes liable to make good the shortfall, and to answer the inspection that follows. If a supplier registered as a micro or small enterprise is not paid within the statutory period, the buyer loses the tax deduction for that expenditure entirely, with no ability to cure it by paying before the return is filed. If a vendor operating on site causes an injury, employs someone under age, or handles customer data carelessly, the reputational and legal consequences do not stop at the vendor’s gate. And unlike the company’s own compliance — which finance can see and control — vendor compliance sits with hundreds of independent parties, each with its own registrations, filings and standards, most of whom were onboarded on the strength of a competitive quotation and a cancelled cheque. Vendor compliance is the discipline of closing that gap: verifying who a supplier is before engaging, contracting for the obligations that matter, monitoring performance against them month by month, and acting on defaults while corrections are still possible.
This guide explains what vendor compliance covers in India, the legal exposures that make it necessary, how onboarding and monitoring frameworks are built, the documentation involved, and how Delhi Legal Company supports businesses in managing vendor risk.
Why Vendor Compliance Matters: Where the Liability Actually Falls
Input tax credit under GST. Credit is available to the recipient only where the supplier has reported the supply and paid the tax. A defaulting vendor directly reduces the buyer’s working capital, and recovery from the vendor is a commercial remedy that must be built into the contract, not a statutory right.
Tax deducted at source. The buyer must identify the correct section and rate for each vendor payment, verify PAN validity, and apply any lower deduction certificate strictly within its terms. Errors are the deductor’s liability — including interest, late fee and disallowance of the expense.
Payments to micro and small enterprises. Under the MSMED Act read with the corresponding provision of the Income Tax Act, amounts payable to registered micro and small enterprise suppliers must be paid within the statutory period. Failure attracts compounded interest under the MSMED Act and, more significantly, disallowance of the expenditure for tax purposes — an outcome that cannot be cured by paying before the return due date.
Contract labour and principal employer liability. Where a contractor deploys workers at the company’s premises, the company as principal employer carries statutory obligations — registration where applicable, ensuring the contractor holds a licence, and liability to make good provident fund, ESI and wage payments the contractor fails to make. Liability is not avoided by pointing to the contract.
Workplace and safety obligations. Obligations relating to workplace safety, prevention of sexual harassment, prohibition of child and forced labour, and site safety extend in defined ways to persons working at the company’s premises, whether or not they are on its payroll.
Data protection. Where a vendor processes personal data on the company’s behalf, the company generally retains accountability under the data protection framework, making the processing agreement and the vendor’s security posture a direct compliance matter.
Reputational and contractual exposure. Customer contracts, group policies and lending covenants increasingly require the company to warrant the compliance of its supply chain. A vendor’s failure becomes the company’s breach.
The Vendor Compliance Lifecycle
1. Pre-onboarding due diligence Verification of identity, legal standing, capability and compliance history before any purchase order is issued.
2. Contracting Documentation of compliance obligations, warranties, indemnities, audit rights, payment terms and termination rights.
3. Onboarding and vendor master creation Accurate capture of the vendor’s tax and banking particulars, classification for TDS and GST, and MSME status flagging in the accounting system.
4. Ongoing monitoring Periodic verification of registrations, filing status, statutory payments and performance against contractual obligations.
5. Periodic review and audit Deeper examination of high-risk and high-value vendors, including site verification and records inspection where warranted.
6. Default management A defined escalation path — communication, withholding, set-off, indemnity claim and, where necessary, termination.
7. Exit and records Final settlement, recovery of company property and data, closure certificates and retention of records for the applicable period.
Vendor Due Diligence: What to Verify Before Onboarding
Identity and legal standing
- Constitution documents — certificate of incorporation, partnership deed, LLP agreement or proprietorship proof
- PAN and, for companies and LLPs, the corporate identity number with a check of the Registrar’s records
- Registered address and place of business
- Details of directors, partners or proprietor, and beneficial ownership where relevant
Tax registrations
- GSTIN, with verification of validity, status, registered address and filing history on the portal
- Confirmation of whether the vendor is a regular or composition taxpayer, since the credit position differs entirely
- PAN validity and operative status, which determines the TDS rate
- Lower or nil deduction certificate under Section 197, where claimed
MSME status
- Udyam registration certificate, with verification on the portal
- Classification as micro, small or medium, since the payment timeline and its tax consequence apply to micro and small enterprises
- A standing obligation on the vendor to notify any change in status
Labour and social security registrations
- Provident fund and ESI registration, where the vendor deploys personnel
- Contract labour licence, where applicable, and the company’s own registration as principal employer
- Shops and establishment or factory registration
- Professional tax registration in the relevant States
Sector and activity-specific approvals
- Trade licence, pollution control consent, drug or food licence, import-export code, fire safety clearance, electrical or building approvals — as applicable to the vendor’s activity
- Professional qualifications, empanelment or accreditation where the service requires it
Financial and operational
- Bank account details verified against a cancelled cheque and, where possible, a penny-drop confirmation
- Financial statements or turnover evidence for capability assessment on significant contracts
- Insurance — workmen’s compensation, public liability, professional indemnity or transit cover, as relevant
- References, past performance and litigation check
Integrity screening
- Conflict of interest declaration, including relationships with employees of the company
- Anti-bribery and code of conduct acknowledgement
- Screening against debarment, blacklisting and applicable sanctions lists, particularly for cross-border vendors
What the Vendor Agreement Should Contain
- Scope, service levels and acceptance criteria, so that performance is measurable
- Payment terms aligned with the statutory timeline where the vendor is a micro or small enterprise
- GST clauses — obligation to issue compliant invoices, report supplies correctly and file returns; right to withhold or recover the tax component where credit is denied to the buyer
- E-invoicing warranty where the vendor is covered by the requirement, since an unregistered invoice is not a valid document
- TDS acknowledgement — the vendor’s obligation to furnish PAN and any lower deduction certificate, and acceptance of deduction as required by law
- Labour compliance covenants where personnel are deployed — wages, statutory contributions, licences, and production of proof of payment as a condition of invoice settlement
- Health, safety and site conduct obligations for on-premises work
- Confidentiality and data protection, including a processing agreement where personal data is handled
- Anti-bribery, ethics and conflict of interest undertakings
- Insurance and indemnity, with adequate limits for the risk involved
- Right to audit and inspect records, and to require compliance certificates periodically
- Consequences of default — withholding, set-off, indemnity and termination
- Subcontracting restrictions, so obligations are not diluted down a chain the company cannot see
- Exit obligations — handover, return of property and data, and final settlement
Ongoing Monitoring: The Monthly and Periodic Discipline
Monthly
- Reconciliation of vendor invoices against the auto-generated GST credit statement, and follow-up on invoices not reported
- Verification of GSTIN status for active vendors, to catch cancellations and suspensions
- Correct TDS deduction, deposit and section mapping for each vendor payment
- Ageing review of payables against MSME vendors, with an alert before the statutory period expires
- Collection of statutory payment proof from contractors deploying personnel — challans, ECR and wage registers — before releasing the invoice
Quarterly
- Issue of TDS certificates to vendors
- Compliance certificates or declarations from significant vendors
- Refresh of the vendor master — inactive vendors, changed registrations, updated MSME status
- Review of vendors with recurring GST defaults and decision on continuation
Annually
- Renewal verification of licences, registrations and insurance
- Vendor risk re-rating and performance review
- Audit of high-risk and high-value vendors
- Reconciliation of vendor balances and confirmation of accounts
- Review of the vendor policy, contract templates and screening framework
Risk-Based Vendor Categorisation
Not every vendor justifies the same effort. A practical framework categorises by exposure:
- High risk — labour contractors and manpower suppliers deploying personnel on site, vendors handling personal or confidential data, high-value strategic suppliers, sole-source vendors, cross-border vendors, and those operating in regulated activities
- Medium risk — recurring service providers, professional and technical service vendors, transporters and logistics providers, and those with moderate contract value
- Low risk — one-off suppliers, low-value purchases, standardised goods from established sellers
Due diligence depth, contractual protection, monitoring frequency and audit rights should scale with the category, and the categorisation should be reviewed as the relationship changes.
Common Vendor Compliance Failures
- Onboarding vendors on the strength of a quotation and a cancelled cheque, with no verification of registrations
- Reconciling GST credit annually instead of monthly, by which time the vendor has little incentive to correct
- Not identifying MSME vendors in the accounting system, so payment ageing is never monitored against the statutory period
- Standard payment terms applied uniformly, in conflict with the statutory timeline for micro and small enterprise suppliers
- Deducting TDS at a uniform rate across vendors without mapping the correct section
- Paying labour contractors without obtaining proof that provident fund and ESI were actually deposited
- Relying on the contract alone for labour compliance, where statute imposes liability on the principal employer regardless
- Allowing subcontracting without visibility, so compliance obligations disappear down the chain
- Never refreshing the vendor master, so cancelled GSTINs, expired licences and lapsed insurance go unnoticed
- Having a vendor policy that exists on paper but is not applied to the vendors already onboarded
Documents to Maintain for Each Vendor
- Vendor registration form and onboarding checklist, signed
- Constitution and identity documents
- PAN and GST registration certificate, with verification records
- Udyam registration certificate and current MSME classification
- Provident fund, ESI, contract labour licence and other labour registrations, where applicable
- Sector-specific licences and approvals
- Insurance policies with validity and coverage details
- Executed agreement with all annexures and amendments
- Bank details with verification record
- Declarations — conflict of interest, anti-bribery, code of conduct, MSME status
- Lower deduction certificates and their portal verification
- Periodic compliance certificates and statutory payment proof
- Performance records, correspondence on defaults, and audit reports
- Exit documentation and final settlement records
How Delhi Legal Company Can Help
Delhi Legal Company builds and operates vendor compliance frameworks alongside accounting, GST, TDS and payroll services, so that vendor risk is managed where it actually arises — in the purchase-to-pay cycle.
- Vendor compliance policy and framework. Drafting the vendor policy, risk categorisation matrix, onboarding checklist and approval workflow suited to your sector and scale.
- Due diligence and screening. Verification of constitution, registrations, GSTIN status and filing history, PAN validity, MSME status, labour registrations, licences, insurance and integrity screening before onboarding.
- Contract drafting and review. Vendor agreements, service contracts, manpower and contract labour agreements, non-disclosure and data processing agreements, with compliance covenants, audit rights and indemnities.
- Vendor master governance. Correct capture of tax particulars, TDS section mapping, GST classification and MSME flagging in the accounting system, with periodic cleansing.
- GST credit protection. Monthly reconciliation of purchases against the auto-generated credit statement, identification of defaulting vendors, structured follow-up and advice on withholding and recovery.
- TDS management on vendor payments. Section determination, rate application, verification of lower deduction certificates, deposit, quarterly statements and certificate issuance.
- MSME compliance. Identification and flagging of micro and small enterprise vendors, payables ageing alerts against the statutory period, interest computation where applicable, and reporting requirements.
- Contract labour and principal employer compliance. Registration, licence verification, monthly collection and scrutiny of statutory payment proof, wage register review, and inspection support.
- Vendor audits. Compliance audits of high-risk and high-value vendors, including records inspection and site verification, with findings and corrective action plans.
- Default and dispute management. Notices, withholding and set-off advice, indemnity claims, recovery support and termination assistance.
- Training and process design. Practical training for procurement, accounts payable and operations teams on what to verify, when to escalate and what to document.
- Health check of the existing vendor base. Review of vendors already onboarded to identify missing documentation, expired registrations, GST defaulters, unflagged MSME suppliers and contract gaps.
Our Working Process
- Assessment. We map the vendor base, spend categories, contract types, sectors and existing onboarding practices.
- Risk categorisation. Vendors are classified by exposure, and the required depth of diligence and monitoring is defined for each category.
- Framework design. Policy, checklists, contract templates, declarations and the monitoring calendar are prepared and approved.
- Remediation of the existing base. Documentation gaps are closed, registrations verified, contracts refreshed and the vendor master corrected.
- Ongoing operation. Monthly reconciliation, verification, ageing alerts and statutory proof collection, with a periodic exception report to management.
- Review and audit. Periodic vendor audits, annual re-rating, and refresh of the policy and templates as the business and the law evolve.
Who We Work With
- Manufacturing companies with large supplier bases and on-site contractors
- Companies engaging manpower, security, housekeeping, logistics and facility management contractors
- Retail, e-commerce and distribution businesses with high supplier volumes
- IT and professional services companies with subcontractors and data-handling vendors
- Infrastructure, construction and project companies with layered subcontracting
- Indian subsidiaries of foreign groups required to apply group supplier standards locally
- Companies facing input tax credit denial, MSME interest claims, or labour inspections arising from contractor defaults
Conclusion
Vendor compliance is not a procurement formality. It is the mechanism by which a company ensures that risks created outside its walls do not settle on its own books — as denied input tax credit, disallowed expenditure, contractor liabilities it must make good, or a breach of the warranties it gave its own customers.
Managed well, it costs little more than discipline: verify before onboarding, contract for what matters, monitor monthly, and act on defaults while they can still be corrected. Delhi Legal Company designs and runs that framework alongside your accounting, tax and payroll compliance, so that vendor risk is identified at the point of engagement rather than at the point of assessment.
Get in touch: info@delhilegalcompany.com | +91-9599332456
Frequently Asked Questions (FAQs)
1. What is vendor compliance?
A. Vendor compliance is the framework by which a business verifies, contracts for and monitors the legal and regulatory compliance of its suppliers, contractors and service providers — so that the vendor’s obligations under tax, labour, safety, data protection and sector-specific laws are met, and the buyer is not exposed to the consequences of their failure.
2. Is vendor compliance legally mandatory in India?
A. There is no single statute called vendor compliance, but the obligations arise from several laws at once. Input tax credit conditions under GST, deduction obligations under the Income Tax Act, payment timelines for micro and small enterprises, principal employer liability under contract labour and social security legislation, and accountability under the data protection framework all place the consequences of vendor default on the buyer.
3. Why is the buyer affected if a vendor does not file GST returns?
A. Because input tax credit is available only where the supplier has reported the supply and paid the tax. If the vendor does not file, the credit does not appear in the buyer’s statement and cannot be claimed — regardless of the buyer having a valid invoice and having paid the tax. The buyer’s remedy is contractual, which is why the agreement must provide for withholding or recovery.
4. How can we protect our input tax credit?
A. Reconcile purchases against the auto-generated credit statement every month rather than at year-end, verify GSTIN status periodically, act on inward invoices through the invoice management facility where applicable, follow up with defaulting vendors while the correction window is open, and include contractual rights to withhold or recover the tax component from vendors who fail to report.
5. What should be verified before onboarding a new vendor?
A. Constitution and identity documents, PAN validity, GSTIN status and filing history, MSME registration where claimed, labour registrations and contract labour licence where personnel will be deployed, sector-specific licences, insurance, bank details, and integrity declarations covering conflict of interest and anti-bribery.
6. Why does MSME status of a vendor matter so much?
A. Because amounts payable to registered micro and small enterprises must be paid within the statutory period. Delay attracts compounded interest under the MSMED Act and disallowance of the expenditure under the Income Tax Act — and unlike most other payment-based disallowances, this one cannot be cured by paying before the return due date. Identifying such vendors in the accounting system is therefore essential.
7. How do we confirm whether a vendor is a micro or small enterprise?
A. Obtain the Udyam registration certificate and verify it on the portal, noting the classification, since the payment obligation applies to micro and small enterprises. The vendor should also be contractually obliged to notify any change in classification, and the status should be re-verified periodically.
8. What is principal employer liability?
A. Where a contractor deploys workers at the company’s premises, the company as principal employer carries obligations under contract labour and social security legislation — including registration where applicable, ensuring the contractor holds a valid licence, and liability to make good provident fund, ESI and wage payments the contractor fails to make. This liability arises from statute and cannot be contracted away.
9. What proof should we collect from labour contractors each month?
A. Wage registers and payment proof, provident fund challans and the electronic return, ESI challans, attendance records, and a declaration of statutory compliance for the month. The practical control is to make release of the contractor’s invoice conditional on receiving this documentation.
10. Can we rely on an indemnity clause in the vendor contract?
A. An indemnity is useful, but it is a commercial remedy, not a defence against statutory liability. The authority will proceed against the principal employer or the buyer as the law provides; the indemnity only allows recovery afterwards, and only if the vendor is solvent and traceable. Verification and monitoring remain the primary controls.
11. How does TDS apply to vendor payments?
A. The buyer must determine the correct section and rate for each payment type, verify that the vendor’s PAN is valid and operative, apply a higher rate where it is not, and apply any lower deduction certificate strictly within its stated section, rate, period and monetary limit. Errors fall on the deductor as interest, fee and disallowance.
12. How often should vendor registrations be re-verified?
A. GSTIN status and MSME classification for active vendors are best checked monthly or quarterly, since registrations can be cancelled or reclassified without notice to the buyer. Licences and insurance should be verified at renewal, and the entire vendor master should be reviewed at least annually.
13. Should every vendor undergo the same level of due diligence?
A. No. Diligence should scale with exposure. Labour contractors, data-handling vendors, cross-border suppliers, sole-source and high-value vendors warrant deep verification and audit rights; low-value one-off purchases need only basic verification. A risk categorisation matrix keeps the effort proportionate.
14. What should a vendor agreement contain from a compliance perspective?
A. Compliant invoicing and GST reporting obligations with a right to withhold or recover, e-invoicing warranty where applicable, PAN and TDS acknowledgements, labour compliance covenants with proof as a condition of payment, safety and site conduct obligations, confidentiality and data processing terms, anti-bribery undertakings, insurance and indemnity, audit rights, subcontracting restrictions, and clearly defined consequences of default.
15. Can we audit our vendors?
A. Yes, where the agreement provides for it. Audit rights should be built into contracts with high-risk and high-value vendors at the outset, covering records inspection, site verification and statutory compliance documentation, with reasonable notice provisions.
16. What are our obligations when a vendor handles our customers’ personal data?
A. The company generally remains accountable for personal data processed on its behalf. This calls for a written processing agreement covering permitted purposes, security measures, subcontracting restrictions, breach notification, audit rights and deletion or return of data on exit — supported by an assessment of the vendor’s actual security posture rather than a self-declaration alone.
17. Do vendor employees working at our premises come within our workplace obligations?
A. In defined respects, yes. Obligations relating to workplace safety and prevention of sexual harassment extend to persons working at the premises regardless of who employs them, and prohibitions on child and forced labour apply to work carried out for the company. Site induction, safety briefing and inclusion in the workplace complaints mechanism are standard controls.
18. What should we do when a vendor is found non-compliant?
A. Follow a defined escalation path — document the default, communicate formally with a cure period, withhold the affected payment or the disputed component, invoke set-off or indemnity where the contract allows, and terminate where the default is material or repeated. Ad hoc handling is what turns a vendor default into a dispute.
19. Can we recover GST credit lost due to a vendor’s default?
A. Not from the department, which grants credit only on the basis of what the supplier has reported. Recovery must come from the vendor under the contract — by withholding the tax component until the supply is reported, or by set-off against future payments. Both require a clause agreed before the problem arises.
20. How do we handle vendors who subcontract our work?
A. Restrict subcontracting to prior written approval, require the same compliance obligations to flow down to the subcontractor, retain the right to verify, and keep the principal vendor fully responsible for the subcontractor’s acts and compliance. Uncontrolled subcontracting is where most supply-chain compliance visibility is lost.
21. We already have hundreds of vendors onboarded. Where do we start?
A. With a health check. We review the existing base to identify missing documentation, expired or cancelled registrations, unflagged MSME vendors, chronic GST defaulters and contract gaps, then prioritise remediation by exposure rather than attempting to reprocess every vendor at once.
22. Can vendor compliance be integrated with our accounting and GST work?
A. Yes, and that is where it works best. GST reconciliation, TDS deduction and payables ageing all happen inside the accounting cycle. When the same team handles the books and the vendor framework, defaults are visible in the month they occur rather than in the following year’s audit.
23. How is the fee structured?
A. It depends on the size of the vendor base, risk profile, number of locations, whether contract drafting and remediation of the existing base are included, and the level of ongoing monitoring required. Framework design is usually a one-time fee, with monitoring on a monthly retainer.
24. How do I get started?
A. Write to info@delhilegalcompany.com or call +91-9599332456. We will review your vendor base, current onboarding practice and any live exposures, and share a clear scope and quotation before any work begins.