If you are a finance manager or controller in India, auditing contract management means testing how contracts are approved, executed, paid, renewed, and closed against the Indian Contract Act, 1872, stamp duty rules, GST/TDS, and Section 43B(h) of the Income-tax Act, 1961.
Your vendor contracts are signed, filed, and (mostly) forgotten, until a three-year-old services agreement auto-renews at last year’s pricing, or a payment clause quietly breaches the MSME 45-day rule and costs you a tax deduction you didn’t even know was at risk. Sound familiar?
Under the Indian Contract Act, 1872, and the internal-audit mandate created by Section 138 of the Companies Act, 2013, contracts sit at the intersection of legal risk, tax exposure, and cash flow, which makes them a finance and compliance responsibility as much as a legal one.
This guide sets out how to audit contract management in a practical, step-by-step way for Indian businesses, with the checks, risks, and control gaps that internal audit teams and compliance officers should be building into their annual plan.
Key Takeaways on Audit Contract Management
- A proper contract management audit checklist covers the full lifecycle: drafting, approval, execution, renewal, and closure, not just legal wording.
- In India, payment-term clauses now carry a direct tax consequence: Section 43B(h) can disallow deductions for vendor dues paid late to micro and small enterprises beyond the 45-day limit.
- Contract audits in India rest on the Indian Contract Act, 1872. Section 138 of the Companies Act, 2013 applies too, but only to prescribed classes of companies. So do ICAI’s Standards on Internal Audit. There is no single dedicated “contract audit law.”
- The most frequent control gaps are: no central contract repository, missed renewal windows, unstamped or under-stamped agreements, and vendor payment terms never checked against MSME rules.
- A contract compliance review should run at least once a year, and more often for high-value, auto-renewing, or related-party contracts.
Scope note: Section 138 applies only to prescribed classes of companies under the Companies Act, 2013, as set out in Rule 13 of the Companies (Accounts) Rules, 2014. LLPs and partnership firms fall outside it. The steps below still work as good practice for any Indian business.
What Does It Mean to Audit Contract Management?
A contract management audit is an independent review of how an organisation creates, approves, executes, monitors, and closes out its contracts, as distinct from a one-off legal review of a single agreement’s clauses.
How Is a Contract Audit Different From a Legal Contract Review?
The two are often confused because both involve reading contracts closely, but they answer different questions and sit with different teams, as the comparison below shows.
Legal Contract Review | Contract Management Audit | |
Focus | Wording, enforceability, and risk of one contract | Process, controls, and compliance across all contracts |
Who typically does it | In-house or external legal counsel | Internal audit, finance controllers, compliance officers |
Timing | Before signing | Periodically, after execution |
Output | Redlines, legal opinion | Audit findings, control-gap report, remediation plan |
Question answered | “Is this clause enforceable?” | “Are our contracts being managed the way policy says they should be?” |
In an Indian context, weak contract management shows up as missed renewal negotiations, GST or TDS mismatches against contract terms, and vendor payments that fall outside statutory timelines.
Why Should Finance Managers and Controllers Own This Audit in India?
Contracts generate financial consequences long after the ink dries: payment obligations, tax positions, provisioning, and revenue recognition all trace back to contract terms. That is why, in most Indian mid-market and growth-stage companies, the responsibility to audit contract management is shared across three roles rather than resting with legal alone.
Role | What They Typically Own in a Contract Audit |
Finance Manager | Payment terms, invoice-to-contract matching, MSME 45-day compliance, provisioning for penalty/liquidated-damages clauses |
Controller | Contract data integrity in ERP/accounting systems, revenue recognition against contract milestones, month-end contract-related accruals |
Compliance Officer | Statutory clause compliance (stamping, GST, data protection, FEMA where cross-border), policy adherence, escalation of high-risk contracts |
Internal Audit | Independent testing of the above, sampling contracts, reporting control gaps to the audit committee/board |
This division of labour matters because Section 138 of the Companies Act, 2013 makes internal audit mandatory for certain classes of companies, and contract-related control gaps typically fall within that internal audit scope. If your organisation already runs a structured internal audit programme, a contract management review fits naturally as one of its recurring work streams rather than a separate exercise.
How to Audit Contract Management: A Step-by-Step Process
Here is a practical sequence finance and audit teams in India can follow. Each step below moves from what to check, to how it applies to a real contract, to what action to take next.
Step 1: Build a Complete Contract Inventory
You can’t audit a contract you can’t find. So start by putting every active contract, along with the ones that expired recently, into one register. A spreadsheet works, and so does a shared drive or a CLM tool. Include vendor agreements, customer contracts, NDAs, lease deeds, employment contracts that carry commercial terms, and agreements between group companies.
What to note down for each one: contract type, counterparty, value, start and end date, renewal terms, the department that owns it, and the governing law clause.
Step 2: Sort Contracts by Risk and Value
Not every contract needs the same level of testing. A ₹15,000 yearly software subscription and a ₹5 crore manufacturing supply agreement carry very different risks. Group your contracts into high, medium and low before you pick samples.
Thresholds many Indian mid-market companies use:
- High risk: value above the limit set by the board, auto-renewal clauses, related-party counterparties, or payments to overseas parties
- Medium risk: regular vendor contracts with moderate value and standard terms
- Low risk: small-value, short-term or one-time purchase orders
Step 3: Check Each Contract Against Indian Law
This is the step that makes the audit India-specific. Test every sampled contract on these points:
- The Indian Contract Act, 1872: Confirm free consent, lawful consideration, and a lawful object (Sections 10 and 23), and check that the signatory had authority to bind the company.
- Stamp duty: An unstamped or under-stamped instrument is generally inadmissible as evidence until the duty and penalty are paid, so check stamping before execution.
- GST: Put the contract next to the actual invoices. The pricing, the invoice terms, and the input tax credit you’ve claimed should all tell the same story.
- TDS: Check that the contract names the right deduction for the service. Professional fees, contractor payments, and rent are treated differently, so a single clause rarely fits them all.
Step 4: Test Payment Terms Against the MSME 45-Day Rule
This check gets missed often, and it costs real money in tax. Section 43B(h) of the Income-tax Act, 1961 was added by the Finance Act, 2023 and applies from Assessment Year 2024-25. Under it, a business loses the tax deduction for any amount owed to a registered micro or small enterprise that isn’t paid on time. The time limit comes from Section 15 of the MSMED Act, 2006. It is 45 days at most when there is a written agreement, and 15 days when there is none.
The Income-tax Act, 2025 came into force on 1 April 2026, and its matching provision is Section 37(2)(g). Tax years that began before that date, including FY 2025-26, are still governed by the 1961 Act, so Section 43B(h) remains the reference for the year being audited now. Only the section number differs going forward. Label each checklist line with the Act that applies to the year under review.
What auditors should do:
- Identify which vendor contracts are with Udyam-registered micro or small enterprises
- Check whether the contract’s written payment term exceeds 45 days (which does not override the tax deduction ceiling, even if commercially agreed)
- Cross-verify actual payment dates against invoice acceptance dates
- Flag any outstanding balances that could trigger disallowance at year-end
Since the disallowed amount is added back to taxable income until actually paid, a gap here shows up as a profitability distortion that a profitability-focused internal audit would otherwise have to explain after the fact.
Which Vendors Fall Inside the Rule?
Only registered micro and small enterprises are covered, and medium enterprises are excluded. Treat purchases from traders and capital expenditure items as contested, and confirm the position with your tax advisor.
Step 5: Test for Vendor Contract Risks and Fraud Indicators
Contracts are also where related-party transactions, kickback arrangements, and conflict-of-interest exposures tend to hide in plain sight. Testing for vendor contract risks typically includes:
- Checking vendor master data against employee and director records for undisclosed relationships
- Reviewing whether high-value contracts went through competitive bidding or sole-sourcing approval
- Sampling for split purchase orders used to stay below approval thresholds
- Verifying that contract amendments and side letters were approved at the same authority level as the original agreement
These checks overlap closely with the fraud-risk indicators internal auditors look for more broadly. See this guide on fraud risks and prevention in internal audit for a wider list of red flags.
Step 6: Run a Renewal Tracking Audit
A renewal tracking audit checks whether the business actually has visibility over when contracts are due to auto-renew, escalate in price, or lapse, and whether anyone is acting on that visibility in time.
Common findings:
- Contracts with auto-renewal clauses and no calendar reminder or system alert set up
- Price-escalation clauses that were never applied at renewal, resulting in quiet revenue leakage (a pattern examined in more depth in this revenue leakage audit guide)
- Contracts that renewed automatically despite the counterparty underperforming against SLA terms
- No formal “renew, renegotiate, or exit” decision recorded before the renewal date
Step 7: Evaluate Contract Lifecycle Controls
Beyond individual contracts, the audit should assess whether contract lifecycle controls, the systems and approval workflows around contracts, are operating as designed:
- Is there a single source of truth for contract documents, or do departments keep their own copies?
- Are contract approval limits enforced in the system, or only on paper?
- Is version control maintained so the executed copy can always be distinguished from earlier drafts?
- Do departmental contract owners get visibility into obligations they are responsible for tracking (SLAs, deliverables, penalty clauses)?
This step connects directly to the broader question of whether internal controls in business operations are designed to match how the business actually operates, rather than how a policy document says it should.
Step 8: Report Findings and Track Remediation
Close the loop by documenting findings against agreed risk ratings, assigning owners, and setting remediation deadlines, consistent with how internal audit observations are reported and tracked more broadly. For guidance on structuring findings so they actually drive action rather than sitting in a report, see this piece on internal audit reporting.
How Do Contract Audit Findings Feed Into Your Tax Audit MSME Reporting?
Payment dates from your contract audit become the evidence behind the tax auditor’s Section 43B(h) reporting.
The FY 2025-26 tax audit report is due by 30 September 2026 unless CBDT notifies an extension. CBDT Notification 27/2024 added specific Section 43B(h) reporting to Form 3CD. MSME classification criteria were also revised in March 2025, so re-check each vendor’s Udyam status.
Event | Date | Position |
Goods accepted from a small-enterprise vendor under a written agreement | 10 February 2026 | 45-day ceiling applies |
45-day deadline | 27 March 2026 | Payment due |
Year-end | 31 March 2026 | Unpaid amount disallowed for FY 2025-26 |
A payment on 15 April 2026 does not rescue the FY 2025-26 deduction.
Audit Contract Management Checklist for Indian Businesses
Use the table below as a working checklist to plan sampling and evidence collection for each audit cycle, rather than a one-time reference.
Audit Area | Key Checks | Documents to Collect |
Contract inventory | All active/expired contracts logged centrally | Contract register, ERP contract module export |
Legal validity | Free consent, consideration, lawful object per Indian Contract Act, 1872 | Executed agreement, board/authority approval |
Stamping | Adequate stamp duty paid or e-stamped as per state rules | Stamp certificate, franking receipt |
Tax alignment | GST clause matches actual invoicing; TDS section correctly identified | Invoices, GST returns, TDS challans |
MSME payment terms | Written payment period ≤ 45 days; actual payment dates tested | Udyam certificate, payment ledger |
Renewal tracking | Auto-renewal and escalation clauses identified and monitored | Renewal calendar/system alerts |
Vendor risk | Related-party and conflict-of-interest checks performed | Vendor master, related-party disclosures |
Lifecycle controls | Approval authority matrix enforced; version control maintained | Approval workflow logs, document version history |
Reporting | Findings documented, risk-rated, and assigned owners | Audit report, remediation tracker |
What Control Gaps Do Auditors Commonly Find in Indian Contracts?
Most of these gaps recur across industries because they stem from process habits rather than one-off mistakes, which is why they show up in audit after audit until a control is actually fixed.
Risk | Why It Happens | What to Do |
No central contract repository | Contracts stored across emails, personal drives, and department folders | Consolidate into one register or CLM tool with restricted access |
Missed renewal windows | No calendar or system-based reminder for auto-renewal dates | Build a renewal tracking audit into the quarterly close checklist |
Unstamped or under-stamped agreements | Agreements signed digitally without following state stamping rules | Route all high-value contracts through a stamping-compliance check before execution |
Payment terms never checked against MSME rules | Payment terms negotiated commercially without tax input | Cross-check every vendor against Udyam registration before finalising terms |
Expert Insights: What Internal Auditors Look For in 2026
Four practices are worth building into the 2026 audit cycle:
- Payment-term testing is now a tax exercise, not just a compliance one. Because Section 43B(h) ties tax deductibility to actual payment timelines, a standing quarterly MSME vendor check works better than a year-end scramble.
- Contract data fits naturally into audit analytics. Where an organisation already uses data analytics for other audit areas, contract value, renewal dates, and payment terms are natural additions to that dataset. See this overview of data analytics in internal audit for how this is typically structured.
- Contract risk belongs in the same risk-assessment cycle as operational risk, not after it. This distinction is explained further in Internal Audit and Risk Assessment: Understanding the Key Differences.
- Smaller businesses can start light. A simple contract register and a short checklist are enough to begin, as covered in how internal audit helps SMEs in India.
Recommendations for Audit Contract Management Going Into FY 2026-27
These are the changes worth prioritising in the next audit cycle rather than treating contract review as a static, once-a-year checklist.
- Build the MSME 45-day payment check into the monthly close process, not just the year-end tax computation, so disallowances are caught early rather than discovered during tax filing.
- Set a materiality threshold in writing, so contract sampling is consistent from one audit cycle to the next, rather than left to auditor judgement each time.
- Where the business already runs a Virtual CFO or outsourced finance function, contract audit findings on payment terms and cash flow exposure are a natural input into cash flow planning, an area covered by Virtual CFO services in India.
- Treat renewal tracking as a standing agenda item at quarterly management reviews, not a one-time clean-up exercise.
Reviewing contract controls against these steps can show where payment terms, stamping and renewals need attention. A qualified professional can assess how this applies to your organisation’s contracts.
Strengthen Your Contract Management Controls
Frequently Asked Questions About Audit Contract Management
How often should a business audit contract management in India?
Most internal audit plans in India schedule a contract compliance review annually, with high-value or auto-renewing contracts reviewed more frequently, often at each renewal date rather than waiting for the annual cycle.
Is a contract management audit mandatory under the Companies Act, 2013?
No standalone provision mandates a separate contract audit, but Section 138 requires internal audit for prescribed classes of companies, and contract controls typically get covered under that internal audit scope.
What is the difference between a contract audit and a contract compliance review?
A contract audit examines the process and controls governing contracts as a whole, whereas a contract compliance review tests individual contracts against specific legal, tax, or regulatory requirements, and most engagements in practice blend both.
Related
Discover more from MSNA & Associates LLP
Subscribe to get the latest posts sent to your email.
