On this page

How to Audit Contract Management in India: Step-by-Step Checklist for Finance Managers and Controllers (43B(h), Stamping, Renewals) 

Audit contract management in India with contract compliance, stamping, MSME 43B(h), GST, TDS and renewal controls-MSNA ASSOCIATES
On this page

If you are a finance manager or controller in India, auditing contract management means testing how contracts are approved, executed, paid, renewed, and closed against the Indian Contract Act, 1872, stamp duty rules, GST/TDS, and Section 43B(h) of the Income-tax Act, 1961.

Your vendor contracts are signed, filed, and (mostly) forgotten, until a three-year-old services agreement auto-renews at last year’s pricing, or a payment clause quietly breaches the MSME 45-day rule and costs you a tax deduction you didn’t even know was at risk. Sound familiar?

Under the Indian Contract Act, 1872, and the internal-audit mandate created by Section 138 of the Companies Act, 2013, contracts sit at the intersection of legal risk, tax exposure, and cash flow, which makes them a finance and compliance responsibility as much as a legal one. 

This guide sets out how to audit contract management in a practical, step-by-step way for Indian businesses, with the checks, risks, and control gaps that internal audit teams and compliance officers should be building into their annual plan.

Key Takeaways on Audit Contract Management 

  • A proper contract management audit checklist covers the full lifecycle: drafting, approval, execution, renewal, and closure, not just legal wording.
  • In India, payment-term clauses now carry a direct tax consequence: Section 43B(h) can disallow deductions for vendor dues paid late to micro and small enterprises beyond the 45-day limit.
  • Contract audits in India rest on the Indian Contract Act, 1872. Section 138 of the Companies Act, 2013 applies too, but only to prescribed classes of companies. So do ICAI’s Standards on Internal Audit. There is no single dedicated “contract audit law.”
  • The most frequent control gaps are: no central contract repository, missed renewal windows, unstamped or under-stamped agreements, and vendor payment terms never checked against MSME rules.
  • A contract compliance review should run at least once a year, and more often for high-value, auto-renewing, or related-party contracts.

Scope note: Section 138 applies only to prescribed classes of companies under the Companies Act, 2013, as set out in Rule 13 of the Companies (Accounts) Rules, 2014. LLPs and partnership firms fall outside it. The steps below still work as good practice for any Indian business. 

What Does It Mean to Audit Contract Management?

A contract management audit is an independent review of how an organisation creates, approves, executes, monitors, and closes out its contracts, as distinct from a one-off legal review of a single agreement’s clauses.

How Is a Contract Audit Different From a Legal Contract Review?

The two are often confused because both involve reading contracts closely, but they answer different questions and sit with different teams, as the comparison below shows.

 

Legal Contract Review

Contract Management Audit

Focus

Wording, enforceability, and risk of one contract

Process, controls, and compliance across all contracts

Who typically does it

In-house or external legal counsel

Internal audit, finance controllers, compliance officers

Timing

Before signing

Periodically, after execution

Output

Redlines, legal opinion

Audit findings, control-gap report, remediation plan

Question answered

“Is this clause enforceable?”

“Are our contracts being managed the way policy says they should be?”

In an Indian context, weak contract management shows up as missed renewal negotiations, GST or TDS mismatches against contract terms, and vendor payments that fall outside statutory timelines. 

Why Should Finance Managers and Controllers Own This Audit in India?

Contracts generate financial consequences long after the ink dries: payment obligations, tax positions, provisioning, and revenue recognition all trace back to contract terms. That is why, in most Indian mid-market and growth-stage companies, the responsibility to audit contract management is shared across three roles rather than resting with legal alone.

Role

What They Typically Own in a Contract Audit

Finance Manager

Payment terms, invoice-to-contract matching, MSME 45-day compliance, provisioning for penalty/liquidated-damages clauses

Controller

Contract data integrity in ERP/accounting systems, revenue recognition against contract milestones, month-end contract-related accruals

Compliance Officer

Statutory clause compliance (stamping, GST, data protection, FEMA where cross-border), policy adherence, escalation of high-risk contracts

Internal Audit

Independent testing of the above, sampling contracts, reporting control gaps to the audit committee/board

This division of labour matters because Section 138 of the Companies Act, 2013 makes internal audit mandatory for certain classes of companies, and contract-related control gaps typically fall within that internal audit scope. If your organisation already runs a structured internal audit programme, a contract management review fits naturally as one of its recurring work streams rather than a separate exercise.

How to Audit Contract Management: A Step-by-Step Process

Here is a practical sequence finance and audit teams in India can follow. Each step below moves from what to check, to how it applies to a real contract, to what action to take next.

Step 1: Build a Complete Contract Inventory

You can’t audit a contract you can’t find. So start by putting every active contract, along with the ones that expired recently, into one register. A spreadsheet works, and so does a shared drive or a CLM tool. Include vendor agreements, customer contracts, NDAs, lease deeds, employment contracts that carry commercial terms, and agreements between group companies.

What to note down for each one: contract type, counterparty, value, start and end date, renewal terms, the department that owns it, and the governing law clause.

Step 2: Sort Contracts by Risk and Value

Not every contract needs the same level of testing. A ₹15,000 yearly software subscription and a ₹5 crore manufacturing supply agreement carry very different risks. Group your contracts into high, medium and low before you pick samples.

Thresholds many Indian mid-market companies use:

  • High risk: value above the limit set by the board, auto-renewal clauses, related-party counterparties, or payments to overseas parties
  • Medium risk: regular vendor contracts with moderate value and standard terms
  • Low risk: small-value, short-term or one-time purchase orders

Step 3: Check Each Contract Against Indian Law

This is the step that makes the audit India-specific. Test every sampled contract on these points:

  • The Indian Contract Act, 1872: Confirm free consent, lawful consideration, and a lawful object (Sections 10 and 23), and check that the signatory had authority to bind the company. 
  • Stamp duty: An unstamped or under-stamped instrument is generally inadmissible as evidence until the duty and penalty are paid, so check stamping before execution. 
  • GST: Put the contract next to the actual invoices. The pricing, the invoice terms, and the input tax credit you’ve claimed should all tell the same story.
  • TDS: Check that the contract names the right deduction for the service. Professional fees, contractor payments, and rent are treated differently, so a single clause rarely fits them all.

Step 4: Test Payment Terms Against the MSME 45-Day Rule

This check gets missed often, and it costs real money in tax. Section 43B(h) of the Income-tax Act, 1961 was added by the Finance Act, 2023 and applies from Assessment Year 2024-25. Under it, a business loses the tax deduction for any amount owed to a registered micro or small enterprise that isn’t paid on time. The time limit comes from Section 15 of the MSMED Act, 2006. It is 45 days at most when there is a written agreement, and 15 days when there is none.

The Income-tax Act, 2025 came into force on 1 April 2026, and its matching provision is Section 37(2)(g). Tax years that began before that date, including FY 2025-26, are still governed by the 1961 Act, so Section 43B(h) remains the reference for the year being audited now. Only the section number differs going forward. Label each checklist line with the Act that applies to the year under review. 

What auditors should do:

  • Identify which vendor contracts are with Udyam-registered micro or small enterprises
  • Check whether the contract’s written payment term exceeds 45 days (which does not override the tax deduction ceiling, even if commercially agreed)
  • Cross-verify actual payment dates against invoice acceptance dates
  • Flag any outstanding balances that could trigger disallowance at year-end

Since the disallowed amount is added back to taxable income until actually paid, a gap here shows up as a profitability distortion that a profitability-focused internal audit would otherwise have to explain after the fact.

Which Vendors Fall Inside the Rule?

Only registered micro and small enterprises are covered, and medium enterprises are excluded. Treat purchases from traders and capital expenditure items as contested, and confirm the position with your tax advisor. 

Step 5: Test for Vendor Contract Risks and Fraud Indicators

Contracts are also where related-party transactions, kickback arrangements, and conflict-of-interest exposures tend to hide in plain sight. Testing for vendor contract risks typically includes:

  • Checking vendor master data against employee and director records for undisclosed relationships
  • Reviewing whether high-value contracts went through competitive bidding or sole-sourcing approval
  • Sampling for split purchase orders used to stay below approval thresholds
  • Verifying that contract amendments and side letters were approved at the same authority level as the original agreement

These checks overlap closely with the fraud-risk indicators internal auditors look for more broadly. See this guide on fraud risks and prevention in internal audit for a wider list of red flags.

Step 6: Run a Renewal Tracking Audit

A renewal tracking audit checks whether the business actually has visibility over when contracts are due to auto-renew, escalate in price, or lapse, and whether anyone is acting on that visibility in time.

Common findings:

  • Contracts with auto-renewal clauses and no calendar reminder or system alert set up
  • Price-escalation clauses that were never applied at renewal, resulting in quiet revenue leakage (a pattern examined in more depth in this revenue leakage audit guide)
  • Contracts that renewed automatically despite the counterparty underperforming against SLA terms
  • No formal “renew, renegotiate, or exit” decision recorded before the renewal date

Step 7: Evaluate Contract Lifecycle Controls

Beyond individual contracts, the audit should assess whether contract lifecycle controls, the systems and approval workflows around contracts, are operating as designed:

  • Is there a single source of truth for contract documents, or do departments keep their own copies?
  • Are contract approval limits enforced in the system, or only on paper?
  • Is version control maintained so the executed copy can always be distinguished from earlier drafts?
  • Do departmental contract owners get visibility into obligations they are responsible for tracking (SLAs, deliverables, penalty clauses)?

This step connects directly to the broader question of whether internal controls in business operations are designed to match how the business actually operates, rather than how a policy document says it should.

Step 8: Report Findings and Track Remediation

Close the loop by documenting findings against agreed risk ratings, assigning owners, and setting remediation deadlines, consistent with how internal audit observations are reported and tracked more broadly. For guidance on structuring findings so they actually drive action rather than sitting in a report, see this piece on internal audit reporting.

How Do Contract Audit Findings Feed Into Your Tax Audit MSME Reporting?

Payment dates from your contract audit become the evidence behind the tax auditor’s Section 43B(h) reporting.

The FY 2025-26 tax audit report is due by 30 September 2026 unless CBDT notifies an extension. CBDT Notification 27/2024 added specific Section 43B(h) reporting to Form 3CD. MSME classification criteria were also revised in March 2025, so re-check each vendor’s Udyam status.

Event

Date

Position

Goods accepted from a small-enterprise vendor under a written agreement

10 February 2026

45-day ceiling applies

45-day deadline

27 March 2026

Payment due

Year-end

31 March 2026

Unpaid amount disallowed for FY 2025-26

A payment on 15 April 2026 does not rescue the FY 2025-26 deduction.

Audit Contract Management Checklist for Indian Businesses

Audit contract management checklist for Indian businesses covering MSME 43B(h), stamping, GST, TDS, renewals, vendor risk and lifecycle controls-MSNA ASSOCIATES

Use the table below as a working checklist to plan sampling and evidence collection for each audit cycle, rather than a one-time reference.

Audit Area

Key Checks

Documents to Collect

Contract inventory

All active/expired contracts logged centrally

Contract register, ERP contract module export

Legal validity

Free consent, consideration, lawful object per Indian Contract Act, 1872

Executed agreement, board/authority approval

Stamping

Adequate stamp duty paid or e-stamped as per state rules

Stamp certificate, franking receipt

Tax alignment

GST clause matches actual invoicing; TDS section correctly identified

Invoices, GST returns, TDS challans

MSME payment terms

Written payment period ≤ 45 days; actual payment dates tested

Udyam certificate, payment ledger

Renewal tracking

Auto-renewal and escalation clauses identified and monitored

Renewal calendar/system alerts

Vendor risk

Related-party and conflict-of-interest checks performed

Vendor master, related-party disclosures

Lifecycle controls

Approval authority matrix enforced; version control maintained

Approval workflow logs, document version history

Reporting

Findings documented, risk-rated, and assigned owners

Audit report, remediation tracker

What Control Gaps Do Auditors Commonly Find in Indian Contracts?

Most of these gaps recur across industries because they stem from process habits rather than one-off mistakes, which is why they show up in audit after audit until a control is actually fixed.

Risk

Why It Happens

What to Do

No central contract repository

Contracts stored across emails, personal drives, and department folders

Consolidate into one register or CLM tool with restricted access

Missed renewal windows

No calendar or system-based reminder for auto-renewal dates

Build a renewal tracking audit into the quarterly close checklist

Unstamped or under-stamped agreements

Agreements signed digitally without following state stamping rules

Route all high-value contracts through a stamping-compliance check before execution

Payment terms never checked against MSME rules

Payment terms negotiated commercially without tax input

Cross-check every vendor against Udyam registration before finalising terms

 

Expert Insights: What Internal Auditors Look For in 2026

Four practices are worth building into the 2026 audit cycle: 

  • Payment-term testing is now a tax exercise, not just a compliance one. Because Section 43B(h) ties tax deductibility to actual payment timelines, a standing quarterly MSME vendor check works better than a year-end scramble. 
  • Contract data fits naturally into audit analytics. Where an organisation already uses data analytics for other audit areas, contract value, renewal dates, and payment terms are natural additions to that dataset. See this overview of data analytics in internal audit for how this is typically structured.
  • Contract risk belongs in the same risk-assessment cycle as operational risk, not after it. This distinction is explained further in Internal Audit and Risk Assessment: Understanding the Key Differences.
  • Smaller businesses can start light. A simple contract register and a short checklist are enough to begin, as covered in how internal audit helps SMEs in India.

Recommendations for Audit Contract Management Going Into FY 2026-27

These are the changes worth prioritising in the next audit cycle rather than treating contract review as a static, once-a-year checklist.

  • Build the MSME 45-day payment check into the monthly close process, not just the year-end tax computation, so disallowances are caught early rather than discovered during tax filing.
  • Set a materiality threshold in writing, so contract sampling is consistent from one audit cycle to the next, rather than left to auditor judgement each time.
  • Where the business already runs a Virtual CFO or outsourced finance function, contract audit findings on payment terms and cash flow exposure are a natural input into cash flow planning, an area covered by Virtual CFO services in India.
  • Treat renewal tracking as a standing agenda item at quarterly management reviews, not a one-time clean-up exercise.

Reviewing contract controls against these steps can show where payment terms, stamping and renewals need attention. A qualified professional can assess how this applies to your organisation’s contracts. 

Strengthen Your Contract Management Controls

Consider obtaining professional guidance to evaluate your organisation’s contract controls and address identified gaps in line with applicable requirements.

Frequently Asked Questions About Audit Contract Management

How often should a business audit contract management in India?

Most internal audit plans in India schedule a contract compliance review annually, with high-value or auto-renewing contracts reviewed more frequently, often at each renewal date rather than waiting for the annual cycle.

No standalone provision mandates a separate contract audit, but Section 138 requires internal audit for prescribed classes of companies, and contract controls typically get covered under that internal audit scope.

A contract audit examines the process and controls governing contracts as a whole, whereas a contract compliance review tests individual contracts against specific legal, tax, or regulatory requirements, and most engagements in practice blend both.


Discover more from MSNA & Associates LLP

Subscribe to get the latest posts sent to your email.

Found Valuable? Share it to peers

Why Trust MSNA

Get In Touch With Our Team Today

If you need any assistance in Internal Audit, Virtual CFO, Accounting/Bookkeeping for India, US & UAE, Financial Planning & Advisory, connect with our team today!

Talk To Our Team

Fill the form below, our team will connect with you shortly