What SLAs Matter in EOR Partnerships?

Onboarding speed is the number every EOR leads with. It’s rarely the number that costs you money. Here’s what to verify before you sign, built around India’s actual statutory deadlines.

Five SLA categories carry real financial and legal exposure in an EOR contract: onboarding and time-to-hire, payroll processing accuracy against statutory deadlines, compliance and regulatory filing turnaround, issue resolution and escalation response, and data security certification. Of these, statutory filing accuracy is the one most buyers skip in vendor evaluation and the one that generates the largest downstream liability, because in India, EPF, ESI, and TDS deadlines are fixed by law, not negotiable between you and your provider.

Every EOR provider markets onboarding speed. Fewer publish what happens after day one, when payroll, tax withholding, and social security contributions become a recurring monthly obligation with fixed government deadlines and real penalties for missing them. If you’re evaluating an Employer of Record for an India build, the SLA conversation needs to move past “how fast can you hire” and into “what happens when a filing is late, and whose liability is it.”

This is a working framework, not a universal industry standard. Use it as a starting checklist for your own RFP and legal review, not a substitute for one.

1. Onboarding and Time-to-Hire SLA

This is the number every provider leads with, and it’s the easiest to verify. Across the EOR market, standard onboarding, from signed offer to first payroll run, typically falls in a 2 to 5 business day range once documents are ready. Complex cases, work visas, senior leadership contracts, or multi-state statutory registration, commonly extend that to 1 to 2 weeks, and can stretch to 4 to 6 weeks where local compliance requirements are heavier.

The gap between a 3-day quote and a 3-week reality usually isn’t the provider’s processing speed. It’s document readiness on your side and how many sub-processors sit between the provider’s platform and the actual in-country registration. Ask specifically whether the provider employs directly through an owned entity in India, or routes through a third-party local partner. Each additional layer adds latency the marketing page won’t mention.

2. Payroll Processing and Statutory Deadline SLA

This is where an EOR relationship stops being about convenience and starts being about liability transfer. In India, payroll compliance runs on fixed monthly government deadlines that apply regardless of what your contract says. Your EOR’s internal SLA should sit comfortably ahead of these dates, not up against them.

Obligation Statutory Due Date Penalty for Delay
TDS deposit 7th of the following month (March deductions: 30 April) ₹200 per day late fee on the return, interest on unpaid tax, and potential prosecution exposure for non-deposit
EPF contribution (ECR) 15th of the following month (no grace period) 12% annual interest plus 5–25% damages under Section 14B of the EPF Act
ESI contribution 15th of the following month 12% annual interest plus 5–25% damages on the arrears
New employee ESI registration Within 10 days of the joining date Coverage gap exposure and back-dated liability on the establishment

None of these dates are set by your EOR. They’re set by the EPFO, ESIC, and the Income Tax Department. What your EOR contract should guarantee is the internal buffer, how many days before each statutory deadline the provider commits to having your payroll finalized, contributions calculated, and challans generated. A provider whose internal SLA runs payroll close to the 15th, rather than well before it, has no margin for a bank holiday, a portal outage, or a late headcount change.

Why this matters more than onboarding speed

A missed onboarding SLA delays one hire by a few days. A missed statutory filing SLA creates a compounding liability, interest accrues daily, damages scale with the length of delay, and in TDS cases, the exposure includes potential prosecution under the Income Tax Act. This is the SLA category with the least room for a vendor’s “we’ll make it up next cycle.”

3. Compliance and Regulatory Filing SLA

Beyond monthly payroll deposits, your EOR should commit to turnaround times for the filings that don’t happen every month but still carry deadlines: quarterly TDS returns, half-yearly ESI returns, annual PF returns, Professional Tax filings where applicable, and any Labour Code-driven documentation. Ask for the provider’s internal filing calendar, not just the payment calendar, and confirm who absorbs the penalty if a filing error originates on their side versus a delay caused by incomplete data from you.

4. Issue Resolution and Escalation SLA

What happens when something goes wrong matters as much as how fast things go right. A defensible SLA defines a maximum response time for payroll disputes, a named escalation path beyond a shared support inbox, and continuity commitments on your account manager. A provider that rotates account owners every quarter erodes institutional knowledge of your specific setup right when you need it most.

5. Data Security and Certification SLA

Employee PII, salary data, and bank details flow through your EOR’s systems continuously. At minimum, confirm current SOC 2 Type II and ISO 27001 certification status, and ask for a signed GDPR-equivalent data processing agreement if any of your stakeholders sit in a jurisdiction that requires one. Certifications lapse and get renewed; ask for the current certificate, not a marketing page reference to it.

Get Your India Payroll Compliance Calendar Reviewed

If you’re comparing EOR providers or auditing your current one, we’ll map your actual filing obligations against the provider’s committed SLA in a focused 30-minute session, no generic sales pitch.

Book a GCC Strategy Call

Where Liability Actually Sits When an SLA Is Missed

Most EOR contracts are written by the provider, which means the default liability language usually favors the provider. Before you sign, get clarity on three specific scenarios, because “the EOR handles compliance” is a marketing sentence, not a legal allocation of risk.

Scenario one: the provider misses a statutory deadline with complete, on-time data from you. This should be entirely the provider’s liability, including any interest or damages levied by EPFO, ESIC, or the Income Tax Department. If your contract is silent on this, the statutory penalty could default to the establishment named on the registration, which in some structures is still exposed to your parent entity depending on how the EOR relationship is structured.

Scenario two: you provide incomplete or late headcount data, and the filing slips as a result. Reasonable contracts split this differently, and it’s worth negotiating a defined cutoff date, for example five working days before the statutory deadline, after which the provider’s SLA clock stops if your data hasn’t arrived. Without a defined cutoff, disputes over whose delay caused the miss become expensive arguments after the fact.

Scenario three: a filing error originates from a system or process failure at the provider, not a data issue. This is where certification evidence, SOC 2 Type II and ISO 27001 status, becomes more than a checkbox. It signals whether the provider has an internal control environment that catches errors before they become statutory penalties, or whether errors are caught by the government first.

None of this needs to be adversarial. A provider that has already thought through these three scenarios and can answer them in a sentence each is signaling operational maturity. A provider that redirects to “our SLA covers that” without specifics is signaling the opposite.

How to Verify an SLA Before You Sign

A published SLA is a promise. It isn’t evidence. Before signing, request the provider’s actual performance data, not the target they advertise.

What to ask for in vendor evaluation

  • Last 90 days of on-time statutory filing rate, not the SLA target
  • Payroll error rate over the same period, with root-cause categories
  • Confirmation of owned legal entity in India versus a third-party sub-processor
  • Named escalation contact and average response time on the last 10 support tickets
  • Current SOC 2 Type II and ISO 27001 certificates, dated
  • Who bears financial liability for a provider-caused compliance penalty, in writing

SansoviGCC by GoodWorks Group is India’s Leading End-to-End GCC Solutions Platform to build, operate and scale GCCs.