A startup legal audit aims to map risks and safeguard operations before fundraising, scaling up or entering a regulated market. In practice, it checks compliance across the corporate structure, contracts, employment, data, intellectual property, tax and, where relevant, AI and sector regulations.
According to the public-service guidance on business audits, an audit covers legal, tax and employment matters to support reliable decisions. In France, registration and statutory publicity fall under the Code de commerce, and formalities go through the INPI single portal.
Objectives and deliverables of a startup legal audit
- Identify compliance gaps and prioritise risks (legal, financial, reputational).
- Safeguard contracts, governance, the chain of IP rights and data flows.
- Prepare the legal data room for investor due diligence.
- Put in place a 30/60/90-day action plan and a Legal Ops roadmap.
Key deliverables: audit report, scored risk matrix (Critical/Major/Moderate), 30/60/90 roadmap, remediation log, data-room index and reference materials (contract templates, registers).
Recommended method
- Scoping: scope, objectives, expected documents, timetable and leads.
- Document collection and interviews: founders, finance, HR, tech/DPO, sales, product.
- Analysis: checks by area (company law, contracts, employment, GDPR, IP, tax, regulation).
- Gap analysis and scoring: criticality, probability, impacts and quick wins.
- Presentation of findings: priorities, owners, deadlines, KPIs and monitoring.
Legal Ops tip: structure your workflows and roles now to smooth execution. See organising your legal function.
Audit checklist by area
1) Company law and governance
- Company form, objects, registered office, capital, up-to-date articles; registration in the trade and companies register (RCS) and statutory publicity in accordance with the Code de commerce.
- Beneficial ownership register and completed filings; regulated related-party agreements and reports under the governance rules of the Code de commerce (governance/RBE/agreements).
- Minutes (general meetings/board meetings/president’s decisions), delegation of powers/signature authority and commitment rules.
- Shareholders’ agreement consistent with the articles; documented cap table and equity incentive plans (BSPCE/BSA/AGA).
- Use of the INPI single portal for formalities and updates.
2) Key contracts and the contract lifecycle
- Review of customer, supplier and partnership contracts, IT/SaaS licences, hosting providers, leases and financing.
- Sensitive clauses: intellectual property/assignment, confidentiality, subcontracting, service levels, security, compliance (GDPR), liability/limitations, warranties, termination, governing law/jurisdiction.
- Check the essential SaaS terms-of-sale clauses if you sell online.
- Contract process: up-to-date templates, internal approval, electronic signature, evidence-preserving archiving and deadline tracking.
3) Employment, labour and independent contractors
- Employment contracts, amendments, probationary periods, working time, non-compete clauses (compensation), confidentiality and employee inventions.
- Freelancers/umbrella employment: map services, economic dependence, exclusivity and organisational integration; assess the risk of reclassification and undeclared work according to URSSAF.
- Payroll, social and economic committee (CSE) elections (thresholds), health and safety, remote-working arrangements/policy, staff register and pre-employment declarations (DPAE).
4) Personal data and cybersecurity
- Records of processing, legal bases, minimisation, retention periods, information for individuals, rights management, DPO where required, DPIAs for risky processing, transfers outside the EU and standard contractual clauses under the GDPR (Regulation 2016/679).
- Data processing agreements (DPAs), cookie/tracker governance, logging and data-breach procedures.
- Security: policies, access control, encryption, backups, vulnerability management, disaster recovery/business continuity plans, workstation/server hardening and good practice from ANSSI.
- Tools: keep a records-of-processing template up to date and align your DPAs.
5) Intellectual property, software and open source
- Chain of title: founder assignments, employee inventions, provider contributions, NDAs and confidentiality clauses.
- Assets: software (source code), databases, trademarks, domain names, designs; evidence of creation and filings; monitoring and enforcement.
- Open source: SBOM inventory, licences, obligations (attribution, copyleft), usage policies.
- Product licences: scope, restrictions, audit, penalties; consistency with the offering (SaaS, on-premises, API).
6) Tax, finance and e-invoicing
- Corporate income tax/VAT, territoriality, reverse charge, transfer pricing for groups, possible withholding taxes and accounting obligations.
- Invoicing processes and preparation for domestic B2B electronic invoicing within the framework defined by the DGFiP (scope, formats, platforms, checks).
- Public aid/grants: check the state-aid framework and compliance of your schemes with the European Commission (state aid).
7) Sector regulations and AI
- Regulated sectors: health (sensitive data), fintech (AML/CFT, payment services), education, defence, etc. Map licences, approvals, timelines and audits.
- AI: if you develop/deploy AI systems, assess use cases and obligations under the AI Act (EU, 2024) and its categories (risks, provider/deployer obligations). For further detail, see our AI Act guide for French startups.
8) Competition, consumer protection and communications
- Commercial practices, B2C pre-contractual information, withdrawal rights (where applicable), statutory warranties.
- Advertising, claims (performance, security, “AI”), comparison services, influencers: clauses, notices, evidence.
9) Litigation, insurance and ongoing compliance
- Inventory of disputes, pre-litigation matters, formal notices, provisions and covered risks.
- Policies: professional indemnity, cyber, D&O; appropriate limits, exclusions and notification.
- Internal controls: ethics policy, internal reporting, risk-appropriate anti-corruption measures and register maintenance.
Documents to gather (data room)
- Articles, Kbis, RBE, shareholders’ agreement, cap table, minutes/general-meeting records, delegations.
- Customer/supplier/partner contracts, terms of sale/use, templates, NDAs, DPAs, leases, financing, security interests.
- Employment and freelance contracts, payroll, employment registers, internal policies.
- GDPR records, DPIAs, incidents, security policies, technical evidence, audits.
- IP: titles, filings, assignment/licence agreements, open-source SBOM.
- Tax/accounting: tax return packages, VAT, invoices, e-invoicing procedures, aid/grants.
To structure the work effectively, follow our method for preparing your data room.
Typical timetable and leads
- Week 1: scoping, document list, tool access, processing/contract mapping.
- Weeks 2–3: targeted analyses and interviews; initial quick remediation measures (contract templates, DPAs, GDPR notices).
- Week 4: findings presentation, 30/60/90 plan, owners (CEO/governance, CFO/tax, CTO/security, CPO/DPO/GDPR, HR/employment, Head of Sales/contracts).
Tools and automation
- Contract repository, CM/CLM, approval workflows, electronic signatures, clause library.
- Live registers (GDPR, delegations, disputes) and compliance logs.
- No-code automation for the contract lifecycle: see our guide to automating contract management.
Audit report template (structure)
- Executive summary: top 10 risks, quick wins and pre-fundraising must-fixes.
- Risk matrix: criticality, probability, impacts, remediation, owners, deadlines.
- Appendices: checklists by area, contract/processing mapping, data-room index, recommended templates.
Immediate-action mini-checklist (30 days)
- Update articles/minutes, cap table and RBE; safeguard delegated powers.
- Freeze/upgrade templates: NDA, MSA/terms of sale, DPA, IP and liability clauses.
- Maintain complete GDPR records; formalise key DPAs; strengthen access controls and backups.
- Document the chain of IP rights (founders/employees/providers) and open-source use.
- Map e-invoicing and check tax obligations with the DGFiP.
Reminder: non-compliance exposes you to employment reclassification (URSSAF), GDPR penalties (GDPR), invalidity and fundraising delays.
Need a lasting operational framework? Establish regular Legal Ops routines and an annual compliance plan; our guide to structuring the legal function details the steps.
Further reading
Related resources
Frequently asked questions
FAQ
When should you carry out a startup legal audit?
Before fundraising, a pivot/scale-up, entering a regulated sector, M&A, or after 18 to 24 months of activity, to strengthen compliance and reduce risks.
How long does a legal audit take?
3 to 6 weeks depending on document maturity. Allow longer if sector/AI regulations apply or the data room is incomplete.
What deliverables should you expect?
An audit report, scored risk matrix, 30/60/90-day action plan, data-room index, contract templates and compliance registers.
Does the audit cover GDPR and cybersecurity?
Yes. Records of processing, DPAs, transfers, DPIAs, security (ANSSI), incident management and evidence of compliance are essential areas.
How can you prepare effectively?
Centralise key documents, align your templates (NDA/terms of sale/DPA), maintain GDPR records, map contracts and appoint leads for each area.
References
Sources used
- Code de commerce (companies, registration, statutory publicity)
- Direction générale des Finances publiques – Business taxation and electronic invoicing
- Public-service guidance – Carrying out a business audit (legal, tax, employment)
- Code de commerce (governance, regulated related-party agreements, beneficial owners)
- Starting a business: choosing your company’s legal form
- ANSSI — official website
- General Data Protection Regulation (GDPR) – Regulation (EU) 2016/679
- European Commission – State aid and financing innovative businesses
- Single portal for business formalities – INPI
- Code du travail and URSSAF – Undeclared work and reclassification of working relationships
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.