Co-Employment Risk in India: What Every US Company Using an EOR Must Contractually Protect

Co-employment risk in India does not disappear simply because an Employer of Record signs the employment agreement. Depending on how the workforce operates, Indian authorities or courts may examine who hires, pays, supervises, disciplines and terminates the employee. Indian law can also impose specific obligations on a principal employer when workers are supplied through another entity.

A defensible EOR model therefore requires more than a clause stating that the EOR is the legal employer. The contract, employment documents, payroll evidence and actual management behaviour must all support the same allocation of responsibilities.

This article provides general risk-management information, not legal or tax advice. Obtain India-specific advice before signing or changing an EOR arrangement.

What must a US company protect?

A US company should require its India EOR agreement to:

  • Give the EOR genuine authority over hiring, employment documentation, payroll, statutory benefits, disciplinary procedures and termination.
  • Separate the client’s control over deliverables from the EOR’s control over employment decisions.
  • Require monthly evidence of wage, tax, provident fund, insurance and other statutory compliance.
  • Provide audit, reimbursement, indemnity, set-off and business-continuity rights.
  • Coordinate workplace safety, harassment complaints, employee investigations, data protection and exits.
  • Prevent employees and EOR personnel from creating unauthorized contractual or tax obligations for the US company.

Most importantly, the company must operate in accordance with these provisions. A well-written agreement cannot correct daily conduct that makes the EOR appear to be only a payroll intermediary.

Which EOR contract clauses are essential in India?

The contract should establish a genuine employer relationship with the EOR, allocate every compliance activity, create an evidence trail and give the client immediate remedies when the EOR defaults.

How should the US company and EOR divide control?

The US company should direct the employee’s work, while the EOR should retain and exercise authority over the employment relationship.

The client should avoid issuing an employment offer in its own name, promising salary increases directly, approving leave outside the EOR system, imposing disciplinary sanctions without EOR involvement or sending a termination notice directly to the worker.

Client managers should report the underlying facts and business requirement. The EOR should assess the employment-law process, prepare the documents, communicate the formal decision and complete the statutory settlement.

What proof of compliance should the EOR provide?

A certificate stating “we are compliant” is not sufficient. The client needs employee-level and filing-level evidence.

The agreement should require a monthly compliance pack containing, where applicable:

  1. Employee roster and employment status.
  2. Gross-to-net payroll reconciliation.
  3. Payslips and bank-payment confirmation.
  4. Provident fund and ESI contribution records.
  5. Tax-withholding calculations and deposit evidence.
  6. Leave, overtime and attendance records.
  7. New-hire, exit and final-settlement reports.
  8. Open employee grievances, notices and government inspections.
  9. Copies of current registrations, licences and insurance certificates.
  10. Confirmation that no unauthorized subcontractor employs the workforce.

EPFO provides facilities through which principal employers can register contractor relationships and upload work orders or outsourced job contracts. EPFO guidance also tells principal employers to confirm contractor compliance for eligible contract employees before releasing bills.

The service agreement should let the client suspend payment when the evidence pack is incomplete. It should also impose a short cure period for missed wages or contributions because delayed statutory payments can quickly affect employees and increase financial exposure.

How should the contract address workplace complaints?

The EOR and client need a written incident-response protocol because both may hold relevant evidence, control different decision-makers or have workplace responsibilities.

India’s workplace sexual-harassment law defines employee broadly enough to include people engaged directly or through an agent or contractor. It also imposes duties on the employer concerning awareness, complaint handling and action where misconduct occurs at the workplace.

The EOR agreement should specify:

  • Which Internal Committee will receive a complaint.
  • How the EOR and client will preserve evidence.
  • Who may place a person on leave or restrict system access.
  • How confidentiality will be maintained.
  • Who conducts the employment-law process.
  • How the parties respond when the accused works for the other organization.
  • Which party reports an incident to an authority when required.

A clause that merely says “the EOR handles HR matters” leaves too much room for delay and conflicting instructions.

Does an EOR remove permanent-establishment risk?

No. An EOR can manage employment compliance, but it does not provide a tax safe harbour.

The India–US tax treaty contains permanent-establishment concepts involving fixed places, services performed through employees or other personnel, and persons acting for an enterprise. The assessment depends on activities, duration, authority, location and other operating facts—not only on whose name appears in the employment agreement.

The EOR contract should therefore prohibit employees from:

  • Signing or habitually negotiating contracts for the US company without authorization.
  • Presenting themselves as officers or legal representatives of the US company.
  • Operating bank accounts or accepting customer payments.
  • Making regulatory representations for the company.
  • Using an India address as the foreign company’s office without tax and legal review.

These restrictions reduce risk, but tax counsel should evaluate the complete India operating model.

What data-protection terms should be included?

The contract should identify which party determines the purpose of employee-data processing and which party processes data on the other’s behalf.

India’s Digital Personal Data Protection framework contemplates the use of a data processor under a valid contract and places security and governance obligations on the relevant data fiduciary. The EOR arrangement should therefore address collection notices, permitted uses, access controls, overseas transfers, security incidents, retention, deletion and assistance with employee requests.

The EOR should not reuse employee, candidate or payroll data for unrelated purposes. Subprocessors should require prior disclosure and equivalent contractual protection.

What are the main EOR red flags?

The highest-risk arrangements combine strong client control with weak EOR substance.

Investigate further when:

  • The EOR cannot produce employment agreements or statutory payment evidence.
  • The client’s name appears as the employer in offer or termination communications.
  • The EOR automatically carries out every client instruction without employment-law review.
  • Client managers approve leave, salary and disciplinary action outside an EOR workflow.
  • Employees receive all policies and HR instructions solely from the client.
  • The EOR uses another staffing company without the client’s knowledge.
  • The provider refuses employee-level audits for “confidentiality” reasons.
  • The provider has no transition process for moving workers to a client subsidiary or GCC.
  • The indemnity is capped at a few months of service fees.
  • The provider promises that an EOR completely removes employment or permanent-establishment risk.

EOR contract checklist for US companies

Before signing, confirm that the agreement answers each of these questions:

  • Who signs and amends the India employment agreement?
  • Who holds the legal authority to discipline and terminate?
  • Which entity pays wages and makes statutory deposits?
  • What evidence must the EOR provide every month?
  • Can the client audit employee-level compliance records?
  • Who pays immediately if wages or contributions are missed?
  • Which liabilities sit outside the general contractual cap?
  • How will the parties manage harassment complaints and investigations?
  • Who owns employee-created intellectual property?
  • Can the EOR appoint subcontractors?
  • What prevents employees from binding the US company?
  • What happens to the workforce if the EOR fails financially?
  • How will employees transfer to a future India entity or GCC?
  • Which records must the EOR retain and deliver after termination?

Key takeaway

An EOR should create a real, compliant employment relationship not a paper employer wrapped around direct employment by the client.

The strongest co-employment risk management combines:

  1. A credible India employer with appropriate registrations and financial capacity.
  2. A detailed client–EOR responsibility matrix.
  3. Monthly documentary verification.
  4. Indemnity, audit, set-off and continuity protections.
  5. Manager training that keeps actual behaviour consistent with the contract.
  6. A planned transition from EOR employment to a subsidiary, captive centre or managed GCC when headcount and business activity justify it.

For companies using an EOR as the first stage of an India expansion, Sansovi’s Employer of record services in India pillar page should connect this risk discussion to the wider decision between an EOR, a managed GCC and a wholly owned India entity.

Primary official sources reviewed

The analysis relies principally on the Ministry of Labour and Employment’s 2026 employer compliance handbook, the Occupational Safety, Health and Working Conditions Code, the Code on Social Security, the 2026 central rules, India Code and official EPFO guidance.

SansoviGCC by GoodWorks Group is India’s Leading End-to-End GCC Solutions Platform to build, operate and scale GCCs.