contract clauses

Audit Rights Clauses: What They Let the Other Side Inspect

Adira EditorialLegal AI desk14 min read

An audit rights clause gives one party a contractual right to inspect the other party's records, systems, or premises to check that a promise is being kept, correctly reported user counts in a SaaS deal, honestly declared sales in a royalty deal, or lawful handling of personal data in a data processing deal. The one thing most people get wrong: they read it as a formality that never actually gets used, then get blindsided when a vendor shows up asking for system logs, or a customer refuses to let anyone near its books. In India this clause runs almost entirely on what your contract says, there is no dedicated "Audit Rights Act", so the words on the page carry more weight here than in areas where a statute fills the gaps. Adira, which publishes this guide, makes contract review and CLM software, so we have a commercial interest in your reading clauses like this carefully, but the explanation below stands on its own regardless of what you buy or don't buy from us.

Plain meaning

Strip the drafting away and an audit clause says: "You may look at specific records of mine, on specific terms, to check I am telling the truth about something this contract depends on." That "something" is almost always a number or a practice, revenue a licensee owes royalty on, active users a SaaS customer bills against, security controls a data processor claims to run, and the clause exists because the party controlling that number has no natural incentive to over-report it against its own interest.

The clause does four things in one paragraph: names who can audit whom, defines scope, sets mechanics (frequency, notice, who conducts it), and decides who pays and what follows if the audit finds a problem. Miss any one, and the "right" on paper becomes either unusable or a tool for harassment, depending on which side got the vague version.

Who it protects and what triggers it

Audit rights are usually one-directional and asymmetric by design, like indemnity clauses. The party relying on a self-reported number, a franchisor collecting royalty on the franchisee's sales, a SaaS vendor billing on active seats, a data fiduciary trusting a processor's word that it encrypts data at rest, is the one who needs the audit right. The other side is the one whose self-report is being checked.

The trigger is not "whenever someone feels like it." A properly drafted clause ties the right to a defined event: a fixed audit window (once every 12 months is common), a suspected discrepancy above a stated threshold, a security incident, or a regulator's own inspection power flowing through the contract, exactly how RBI's outsourcing rules and the DPDP Act's fiduciary-processor structure work, covered below. A clause letting either side audit "at any time, for any reason" has turned a verification tool into a standing threat.

What to look for

Six mechanics decide whether an audit clause is workable or a landmine, and most are absent from a one-line "Licensor may audit Licensee's books" sentence:

  1. Scope. Records reasonably necessary to verify the specific thing being checked, usage logs, sales ledgers, security controls, or "any records relating to this Agreement," a fishing licence?
  2. Frequency. A cap (once, or twice, in any 12-month period is standard), or unlimited?
  3. Notice. How many days' advance written notice, with a carve-out for cause where a suspected breach justifies acting faster?
  4. Who conducts it. An independent chartered accountant or security auditor bound by confidentiality, or the auditing party's own staff?
  5. Cost allocation, and whether it shifts. Who pays normally, and does it flip to the audited party on a material discrepancy, commonly a stated percentage under-reporting?
  6. Confidentiality and remediation. Are findings themselves confidential, and is there a defined cure period before termination, or is any discrepancy an instant default?

The Indian position: no dedicated statute, but two regimes raise the stakes

Audit rights clauses are not a defined contract type under the Indian Contract Act, 1872, the way indemnity (Section 124) or guarantee (Section 126) are. They are enforced the ordinary way any lawful contractual term is enforced under Section 10 of the Act, which makes agreements between competent parties, for lawful consideration and object, binding as written. That means the clause's specificity is doing all the work. There is no default statutory audit right to fall back on if your contract's version is vague, unlike indemnity, where Sections 124-125 fill gaps left by the drafting.

Two regimes change this calculus for specific deal types, and both matter to the queries this page is written for.

Data processing deals, under the DPDP Act. Section 8(2) of the Digital Personal Data Protection Act, 2023 makes a written contract a precondition before a Data Fiduciary can even hand data to a processor:

"A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract." Source: Digital Personal Data Protection Act, 2023, official text (MeitY)

Because the fiduciary, not the processor, carries the compliance and penalty risk if something goes wrong, a data processing agreement with no audit or inspection right over the processor's technical and organisational measures is a real gap, liability with no way to verify the thing you're liable for. For the largest players, this is not optional: Section 10(2)(b) requires a Significant Data Fiduciary to appoint its own check on itself:

"appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act." Source: Section 10, DPDP Act, 2023

Section 10(2)(c) separately requires a Significant Data Fiduciary to undertake "periodic Data Protection Impact Assessment" and "periodic audit" as ongoing measures, not one-off exercises.

Regulated entities, under RBI's outsourcing rules. If your counterparty is a bank, NBFC, or other RBI-regulated entity, its regulator has already told it what its vendor contracts must contain. The RBI Master Direction on Outsourcing of Information Technology Services, 2023 (effective 1 October 2023) requires the regulated entity to be able to run regular audits of its service provider, through its own internal or external auditors, and lets regulated entities pool audit resources or use a shared, independent third-party auditor for a common vendor rather than each running a separate audit. It also preserves RBI's own right to inspect the service provider and sub-contractors directly, including one based abroad. See the RBI notification. If you sell into Indian banks or NBFCs, your audit clause is not really negotiable in substance, your customer's regulator has already set the floor.

What happens if the other side blocks your audit: the Amritsar Gas Service problem

There is no widely reported Indian judgment interpreting an audit-rights clause the way Gajanan Moreshwar interprets indemnity, most audit disputes settle by negotiation, a fee true-up, or arbitration, not a published court decision. But there is a genuinely useful Supreme Court authority on the question every audit clause eventually raises: what can a court do if the other side simply refuses to cooperate with an ongoing contractual obligation?

In Indian Oil Corporation Ltd v Amritsar Gas Service, (1991) 1 SCC 533, decided 19 November 1990, the Corporation terminated an LPG distributorship agreement on 30 days' notice under a termination-for-convenience clause. An arbitrator ordered the distributorship restored. The Supreme Court set that aside, holding that a distributorship agreement terminable on notice is a "determinable" contract, and that specific performance, an order forcing the relationship to continue, was not available. The distributor's remedy was compensation for the 30-day notice period, not restoration. Read the judgment on Indian Kanoon.

The relevant statutory hook is Section 14(1)(b) of the Specific Relief Act, 1963 (as renumbered by the 2018 amendment), which bars specific enforcement of:

"a contract the performance of which involves the performance of a continuous duty which the court cannot supervise." Source: Section 14, Specific Relief Act, 1963

Why this matters for an audit clause specifically: cooperating with an audit, granting access, producing records over time, answering an auditor's questions, is exactly the kind of ongoing, supervised conduct Indian courts are historically reluctant to force through an injunction. If your counterparty simply stonewalls an audit, do not assume a judge will march in and personally supervise their compliance. A well-drafted clause has to supply its own teeth, a right to suspend service, a right to treat refusal as a material breach entitling termination, or a contractual presumption against the refusing party in any fee dispute, rather than relying on a court to force cooperation it may not be equipped to police.

Red flags

NormalRed flagWhy it matters
Audit capped at once, sometimes twice, in any 12-month periodAudits allowed at any time, with no frequency limitTurns a verification tool into a standing operational disruption, or a harassment lever
10-30 business days' written notice, shorter only for a suspected breachNo notice requirement, or auditor may appear same-dayNo time to prepare records or protect unrelated confidential material in the same systems
Audit conducted by an independent, mutually acceptable chartered accountant or security auditor, bound by confidentialityAuditor is the counterparty's own staff, or a firm that is a competitor of the audited partySensitive commercial or technical data ends up in a rival's hands, not just verified
Scope limited to records reasonably necessary to verify the specific metric or obligationScope says "any and all records relating to this Agreement"A fishing expedition into information that has nothing to do with what is actually being checked
Auditing party bears its own cost, shifting to the audited party only if a material discrepancy (commonly 5% or more under-reporting) is foundAudited party always bears the cost, even when the audit finds nothing wrongRemoves any real deterrent against speculative audits and penalises a compliant party for someone else's suspicion
Audit findings are themselves confidential, usable only to resolve the specific dispute they relate toNo confidentiality obligation on the auditor or the party receiving the reportFindings, which often include real financial or security detail, can leak or be used for unrelated commercial advantage
A defined cure period and dispute process before any penalty, fee true-up, or termination follows a discrepancyAny discrepancy, however small, triggers immediate termination or a liquidated penaltyDisproportionate consequence for an honest reporting error, no room to correct and continue
Data processing agreement includes an explicit right for the fiduciary to audit or inspect the processor's technical and organisational measuresData processing addendum is silent on audit or inspection rights entirelyUnder Section 8 of the DPDP Act the fiduciary stays liable for the processor's processing with no contractual way to check on it

Bad clause versus better clause

Bad: "Company may, at any time, audit Customer's use of the Service, including access to Customer's systems, personnel and records, and Customer shall bear all costs of any such audit."

What is wrong: no frequency cap, no notice requirement, scope is essentially unlimited ("systems, personnel and records"), no mention of who conducts the audit or their independence, no confidentiality obligation over what is found, and the customer pays regardless of the outcome.

Better: "Company may, no more than once in any 12-month period, and on not less than 15 business days' prior written notice, audit Customer's records reasonably necessary to verify Customer's compliance with the user-count and usage reporting obligations in Clause [X]. The audit shall be conducted during Customer's normal business hours by an independent chartered accountant bound by confidentiality obligations no less strict than those in this Agreement, and shall not unreasonably disrupt Customer's operations. Company shall bear the cost of the audit unless it reveals under-reporting of 5% or more of the amount properly due, in which case Customer shall bear the reasonable cost of that audit. All findings shall be treated as Confidential Information and used solely to resolve the discrepancy identified. Customer shall have 30 days from the audit report to cure any confirmed under-reporting before Company may treat it as a breach of this Agreement."

What changed and why: a frequency cap and real notice period protect the audited party's operations, scope is tied to the specific obligation being checked rather than "everything," an independent auditor with confidentiality obligations replaces unrestricted access, the cost shift only applies past a stated threshold instead of punishing every audit, findings are protected as confidential, and a cure period replaces automatic default.

How it interacts with related clauses

Audit rights rarely stand alone, three sibling clauses decide whether the right does what it promises. Payment terms define the number being audited, a royalty base, a true-up formula, a seat count, if that definition is vague, the audit is verifying an ambiguous target. Confidentiality should extend explicitly to audit findings, without this link, an audit exposes sensitive data with no protection once the report exists. And subcontracting matters for data deals specifically: if your processor uses sub-processors, your audit right needs to reach them too, or a Section 8(2) DPDP gap can sit one layer down where your contract never looked.

You can mark up how an audit clause lines up against your payment terms and confidentiality obligations directly in a document, for free, using Weave, Adira's free browser tool, before you send a contract back for negotiation.

US and global contrast

US and UK commercial contracts use audit clauses just as often, particularly in software licensing, the standard mechanism behind BSA and vendor "true-up" audits, and franchise royalty agreements, with broadly similar mechanics: notice, scope, cost-shift on material discrepancy. The real difference is regulatory density around data. The EU's GDPR writes a processor's obligation to allow and contribute to controller audits directly into the statute (Article 28(3)(h)). India's DPDP Act has no equivalent express audit-right provision for ordinary Data Fiduciaries, only the accountability rule in Section 8 and the mandatory self-audit for Significant Data Fiduciaries under Section 10, so an Indian data processing agreement has to build the audit mechanic in by contract, far more deliberately than a GDPR-governed one needs to.

FAQ

Who usually holds the audit right, the customer or the vendor? It depends on who is relying on a self-reported number. In SaaS usage deals the vendor typically audits the customer's usage or seat counts to catch under-licensing. In royalty and franchise deals, and in data processing agreements, the party paying or the party legally accountable, the licensor, the franchisor, the data fiduciary, typically audits the other side.

How much notice must be given before an audit? There is no statutory notice period in India, it is whatever the contract says. Ten to thirty business days' written notice is standard commercial practice, often with a shorter, cause-based exception if a specific breach is already suspected.

Who pays for an audit? Normally the party requesting it. A cost-shift to the audited party is standard, but only if the audit finds a material discrepancy, commonly a stated percentage of under-reporting, not for every audit regardless of outcome. If your contract makes you pay even when the audit finds nothing wrong, that is a red flag, not a norm.

Can the auditor be a competitor of the party being audited? It should not be able to. A well-drafted clause requires an independent, mutually acceptable auditor, often a named accountancy firm, bound by confidentiality. Silence on who can conduct the audit leaves this open to abuse.

Does a data processing agreement need its own audit right, separate from the main contract? Yes, in practice. Section 8(2) of the DPDP Act requires a valid contract before a Data Fiduciary can engage a processor at all, and the fiduciary stays accountable for the processor's compliance. Without an explicit audit or inspection right, the fiduciary has taken on that accountability with no contractual way to verify it is deserved.

What happens if we simply refuse to allow an audit? Refusal is usually a defined material breach, entitling the other side to suspend service, terminate, or draw an adverse inference on the disputed number. As Indian Oil Corporation v Amritsar Gas Service illustrates in a related context, do not assume a court will force ongoing cooperation through an injunction, the remedy your contract gives you matters more than the theoretical right to sue for compliance.

This guide gets you to understanding what an audit rights clause does and what Indian law says around it. It does not tell you whether a specific clause in your contract is enforceable, proportionate, or worth pushing back on in your situation, that depends on the rest of your contract and the facts of your relationship, and is not legal advice. Talk to a lawyer before you rely on, or refuse to comply with, an audit clause in a live negotiation or dispute.

Frequently asked questions

Who usually holds the audit right, the customer or the vendor?
It depends on who is relying on a self-reported number. In SaaS usage deals the vendor typically audits the customer's usage or seat counts to catch under-licensing. In royalty and franchise deals, and in data processing agreements, the party paying or the party legally accountable, the licensor, the franchisor, the data fiduciary, typically audits the other side.
How much notice must be given before an audit?
There is no statutory notice period in India, it is whatever the contract says. Ten to thirty business days' written notice is standard commercial practice, often with a shorter, cause-based exception if a specific breach is already suspected.
Who pays for an audit?
Normally the party requesting it. A cost-shift to the audited party is standard, but only if the audit finds a material discrepancy, commonly a stated percentage of under-reporting, not for every audit regardless of outcome. A contract that makes you pay even when the audit finds nothing wrong is a red flag, not a norm.
Can the auditor be a competitor of the party being audited?
It should not be able to. A well-drafted clause requires an independent, mutually acceptable auditor, often a named accountancy firm, bound by confidentiality. A clause silent on who can conduct the audit leaves this open to abuse.
Does a data processing agreement need its own audit right, separate from the main contract?
Yes, in practice. Section 8(2) of the Digital Personal Data Protection Act, 2023 requires a valid contract before a Data Fiduciary can engage a Data Processor at all, and the fiduciary stays accountable for the processor's compliance regardless of what the processor promised. Without an explicit audit or inspection right in the data processing terms, the fiduciary has taken on that accountability with no contractual way to verify it is deserved.
What happens if we simply refuse to allow an audit?
Refusal is usually a defined material breach in a well-drafted clause, entitling the other side to suspend service, terminate, or draw an adverse inference on the disputed number. Indian courts are historically reluctant to force ongoing cooperation through an injunction, as the reasoning in Indian Oil Corporation Ltd v Amritsar Gas Service illustrates for continuing contractual duties generally, so the practical remedy your contract gives you matters more than a theoretical right to sue for compliance.
Was this useful?

See how Adira drafts in your voice and reads contracts from your side.

Explore the showroom

Working through a contract like this? Weave is Adira’s free tool to read, mark up, and connect any contract in your browser — no account needed.

Try Weave — free