A VDR can look fine in a demo and still fail when the mandate gets real. That is usually when the pain shows up: audit trails that do not hold up, access controls that leak across parties, and manual work that slows a DRHP cycle at the worst possible moment. For a SEBI-registered merchant banker, that is not a tool issue. It is a deal-risk issue.
The fix is a weighted scorecard built for Indian M&A and IPO work, not a generic feature checklist. It forces you to test what matters most: vendor due diligence, SEBI fit, security, access control, speed, and cost predictability. This article gives you that evaluation checklist in a practical form you can use to compare vendors, run pilot testing, and make a defensible decision.
Why a weighted scorecard works better than a feature list
A checklist treats every feature like it matters equally. That is a bad fit for Indian M&A, where some gaps are inconvenient and others are deal-stopping.
A good scoring scorecard does three things:
- It ties evaluation to actual regulatory exposure, especially SEBI Repository uploads, audit-trail retention, and insider-trading risk.
- It separates must-have veto items from weighted preferences, so a vendor with a fatal gap does not win on polish.
- It makes vendor due diligence repeatable across deals, which matters when your team is running multiple mandates under deadline pressure.
That is the point here. Do not buy the slickest demo. Use a framework that tells you whether the platform can survive a live IPO or cross-border M&A process.
1. Start with veto criteria before you score anything
Some failures are disqualifying. No amount of nice reporting or AI search should compensate for them.
Use these as binary gates before the weighted evaluation:
- ISO 27001 and SOC 2 Type II should be in place.
- Granular role-based access controls must exist.
- Audit logs must be tamper-evident and exportable.
- India data residency or an India-resident deployment option should be available where your mandate requires it.
- The platform must support secure document access, including DRM-style controls and 2FA.
Why this matters:
- SEBI’s current repository process expects uploads that are relevant, complete, and legible.
- Merchant bankers must preserve records for at least five years.
- Some deal contexts also need longer retention, especially where accounting records are involved.
- If your VDR cannot produce a clean, complete audit package, it creates manual work at exactly the point where timelines are tight.
What to check:
- Can the vendor show a full audit trail for views, downloads, prints, watermark renders, and Q&A?
- Can it export records in a format your compliance team can use without rework?
- Does it support permissioning that is precise enough for a 10-plus-party process?
If the answer is no, stop there.
2. Weight SEBI compliance and audit trail fidelity highest
For Indian M&A and IPOs, this is the core of the scorecard. It deserves the heaviest weight because the failure mode is not cosmetic. It can delay the issue.
Look for these controls:
- Time-stamped, tamper-evident logs for every user action
- Searchable logs by user, document, deal, IP address, device, and time window
- One-click export aligned to the SEBI Repository upload workflow
- Support for folders and templates used in IPO, FPO, QIP, rights issue, and M&A processes
- A clean retention model that supports the five-year SEBI requirement
What “good” looks like:
- Human-readable and machine-readable logs
- Per-document traceability
- Export packages that do not need manual retyping
- A system that makes SEBI Repository preparation faster, not harder
What “bad” looks like:
- Folder-level logging only
- No soft-delete trail
- Manual log reconstruction
- Audit data spread across emails and spreadsheets
If your VDR cannot help with vendor due diligence on the regulatory side, it is not really reducing risk. It is just shifting risk into another system.
3. Score document security as a separate category
Security should not be collapsed into compliance. The two are related, but they are not the same.
This category should cover:
- AES-256 encryption at rest and in transit
- TLS 1.2/1.3 for secure connections
- Dynamic watermarking with viewer identity, IP, and timestamp
- Controls for print, copy, screenshot, and download where supported
- Session controls such as idle timeout, IP whitelisting, and device binding
- Customer-managed key options where required by policy
Why this matters in Indian M&A:
- Pre-DRHP leaks create insider trading exposure.
- Confidential documents often move across legal counsel, auditors, bankers, underwriters, and shareholders.
- A weak viewer can turn one bad handoff into a regulatory problem.
What to test during pilot testing:
- Does the watermark appear on every render, not just the cover page?
- Can downloaded files expire?
- Can printing and copying be controlled at the document level?
- Does the platform support enterprise-grade authentication and device approval?
A platform that only looks secure is not enough. You want controls that keep working after the document leaves the seller’s inbox.
4. Test granular access control for multi-party diligence
Indian M&A is rarely a two-party process. It is a multi-party process with competing information needs, and that is exactly where access control breaks.
Your evaluation checklist should verify:
- Folder- and file-level permissions
- Role-based access for counsel, auditors, bankers, registrars, underwriters, and shareholders
- View-only, download, annotate, upload, and print-disabled modes
- IP and device restrictions by group
- Chinese-wall enforcement between bidders where relevant
- Bulk invite and bulk revoke
What “good” looks like:
- Permissions are visible, not implied
- Inheritance and override rules are clear
- Bidder workspaces stay separate
- Revocation is real, not theoretical
What to watch for:
- Permissions that must be rebuilt every deal
- View access that silently inherits download rights
- Cross-bidder bleed in competitive situations
- Clumsy onboarding that slows the team
In practice, this is where a lot of vendor due diligence gets real. You are not just asking whether the vendor has permissions. You are asking whether those permissions hold under pressure.
5. Give AI document intelligence a useful, not inflated, weight
AI can speed up diligence. It should not be treated like magic.
A practical score should cover:
- OCR for scanned PDFs
- Clause recognition for change-of-control, indemnity, non-compete, IP assignment, and arbitration
- Auto-classification into legal, financial, HR, IP, and contract folders
- Metadata search across full text, tags, date range, and owner
- AI-assisted redaction for PII and privileged content
- Cross-document Q&A that points back to source pages
Why this matters:
- Deal teams waste time hunting for a few critical clauses across thousands of pages.
- Better search and classification can compress review work.
- But precision matters. A false flag can create a second layer of manual review.
What to test:
- Does it handle scanned documents well?
- Can it search full text and metadata together?
- Does it locate clauses reliably in a tagged pilot set?
- Does the redaction workflow respect counsel’s markings?
AI should support the team, not replace judgment. That is the right balance for a scoring scorecard in this category.
6. Measure setup speed and Q&A workflow, not just features
Velocity matters because the deal clock does not wait for configuration delays.
Score the platform on:
- Setup time from contract to live room
- Pre-built IPO and M&A templates
- Q&A routing and approval flow
- Auto-linking answers to source documents
- Mobile access for roadshow and travel use
- API support for programmatic uploads and reporting
What “good” looks like:
- A single admin can launch a room quickly
- Q&A stays inside the platform
- Questions move through a structured approval path
- Answers remain part of the audit trail
What “bad” looks like:
- Weeks of professional-services setup
- Email-based Q&A chains
- No mobile access
- Manual upload work for every new room
This is where the scorecard helps with deal velocity. It keeps you from overvaluing a platform that is secure but slow to run.
7. Check India fit, residency, and regulatory practicality
A platform can be strong globally and still be awkward for Indian M&A.
Your score should include:
- India-resident deployment options
- Alignment with SEBI Repository workflows
- CERT-In readiness for log retention and incident reporting
- DPDPA alignment, including DPIA support where relevant
- FEMA-friendly access for cross-border transactions
- Support for cross-border teams that need read-only access
What to look for:
- India hosting or clear residency options
- Log retention that fits Indian expectations
- Cross-border access that does not break the process
- A deployment model that works for SEBI-facing work
Important nuance: DPDPA does not create a blanket localisation rule. But for merchant bankers, residency and local operational fit are still practical decision points. Do not overstate the law, but do not ignore the reality of regulatory work either.
8. Score pricing on predictability, not just headline price
Price matters, but in mid-market Indian deals, unpredictability is usually the bigger problem.
A useful scorecard should compare:
- Per-page pricing
- Per-user pricing
- Storage-based pricing
- Flat per-deal pricing
- Overages and add-ons
- INR billing and FX clarity
What to look for:
- Clear all-in pricing
- Cap or quota on overages
- No surprise charges for AI or reporting
- Pricing that fits the economics of a mid-market mandate
Why this matters:
- Legacy pricing can create bill shock.
- A mid-market mandate cannot always absorb a large VDR line item.
- Predictable pricing protects deal margins and helps with client conversations.
Do not let low sticker price hide high overage risk. That is one of the easiest mistakes to catch in vendor due diligence if you ask for the full pricing sheet up front.
9. Build the pilot into the decision, not after it
This is where the scorecard becomes real.
A useful pilot should run for 2 to 4 weeks and include:
- Synthetic deal data, not live client files
- At least two Q&A cycles
- One SEBI Repository upload simulation
- Two bidder workspaces, if the process is competitive
- A test of watermarking, permissioning, and audit-log export
Your pilot testing should answer simple yes/no questions:
- Can the team set up the room on time?
- Can compliance export logs without manual reformatting?
- Can the vendor support the workflow under live-deal pressure?
- Does the system prevent cross-pollination between workspaces?
- Does support respond fast enough for a real mandate?
The pilot is not a demo. It is a stress test. If the platform passes the pilot, it is more likely to survive the mandate.
10. Use a simple responsibility matrix so the process does not drift
The scorecard works best when the right people own the right parts.
A practical split looks like this:
- Head of IPO/M&A: accountable for final decision and weights
- VDR admin: responsible for demos, setup, and pilot execution
- Compliance/Legal: responsible for audit trail, SEBI fit, and retention checks
- IT/InfoSec: responsible for security, residency, SSO, and access control
- Finance/Procurement: responsible for pricing and contract terms
- External counsel: consulted on diligence workflow and compliance expectations
This matters because VDR selection is not just a tech buy. It touches risk, process, procurement, and regulatory work. If ownership is fuzzy, the evaluation drifts toward whatever looks easiest in the room.
Common failures to catch early
These are the failures that usually show up too late.
- Manual Repository retyping
If the export does not map cleanly to SEBI needs, the team pays for it later in time and risk.
- Watermark weakness
If screenshots or re-shares are easy, the control is cosmetic.
- Q&A bottlenecks
If questions are not routed well, the deal slows down and ownership gets blurry.
- Permission leakage between bidders
Competitive sales need hard separation, not soft promises.
- Poor log retention
If older records are hard to search or incomplete, the platform is weak for SEBI and internal review.
- AI overconfidence
Clause recognition that looks smart but misses context can create more work, not less.
- Cost overage traps
A low base price can become expensive once users, pages, or add-ons stack up.
These are exactly the kinds of problems a disciplined evaluation checklist should flush out before a contract is signed.
Summary and Next Steps
The right VDR for Indian M&A is not the one with the longest feature list. It is the one that can prove three things: it protects confidential information, it satisfies SEBI-facing compliance needs, and it does not slow the deal down.
If you take one action from this article, make it this: build a living scoring scorecard with veto criteria, weighted pillars, and a 2 to 4 week pilot before you sign anything. That gives you a cleaner vendor due diligence process, a better read on operational risk, and a decision you can defend inside the firm.
FAQ
Why use a weighted scorecard instead of a simple checklist?
A checklist treats every feature as equal. A weighted scorecard forces trade-offs based on real deal risk, which is more useful for SEBI-regulated work.
What is the biggest risk if we skip the scorecard?
You can choose a platform that looks fine in sales meetings but fails on audit trail quality, SEBI fit, or access control when the deal is live.
Which capabilities should be treated as non-negotiable?
Security certifications, granular access control, immutable audit logs, and a deployment model that works for Indian regulatory processes should be treated as veto items.
How much should AI matter in the decision?
AI should matter, but not dominate. It is useful for search, classification, and redaction, but it should support review rather than replace it.
How long should pilot testing run?
A practical pilot is 2 to 4 weeks. That gives enough time to test setup, Q&A, log export, and workspace segregation.
What should the pilot include?
Use synthetic deal data, run at least two Q&A cycles, simulate one SEBI Repository upload, and test watermarking and access controls under realistic conditions.
Is India data residency always legally required?
Not always. But for SEBI-facing work and Indian operational reality, it is often a major buying factor and should be treated seriously.
How should pricing be evaluated?
Look beyond the base price. Check overages, add-ons, user charges, storage charges, and whether the pricing stays predictable across deals.
Who should own the evaluation?
The Head of IPO/M&A should be accountable, with compliance, IT, procurement, and external counsel each owning their part of the review.
Should the scorecard stay fixed?
No. Revisit it after major regulatory changes, vendor incidents, or shifts in your deal mix so it stays relevant.
Book a free demo
Want to see how a secure VDR can support your SEBI obligations, reduce manual work, and keep diligence moving? Book a free demo to validate your current process against a practical, deal-ready scorecard.