A licence cancelled in 2024, a plant still running in 2026
A firecracker unit in Uttar Pradesh's Kaushambi district exploded at the end of August 2026. Eleven people were killed. Eight of them were children. Five more were injured, and the blast destroyed not only the factory building but six other houses around it. NDRF, SDRF, police, fire brigade and Air Force personnel were deployed at the site.
The detail that should stop any procurement head in India is not the casualty count. It is the paperwork. The unit had been granted an explosives licence in 2019, originally valid until 2026. That licence was cancelled in 2024. The unit kept operating anyway, and an inquiry is under way into how that happened.
Two years of production after cancellation. Two years during which the unit could issue a GST invoice, receive payment into a current account, file returns, and appear in any buyer's vendor master as a compliant, verified supplier. Nothing in the commercial paper trail changes when a statutory operating licence is cancelled. The invoices look identical.
Most Indian vendor onboarding files verify identity and tax status: GSTIN, PAN, bank details, Udyam registration, maybe an ISO certificate. Very few verify that the vendor is currently permitted to run the process it is running. For a supplier doing something ordinary, that gap is a compliance annoyance. For a supplier handling explosives, solvents, compressed gases, hot work or effluent, it is the difference between a contained loss and an uninsured one.
Where the buyer's exposure actually comes from
A buyer who never set foot in the supplier's shed can still end up funding the consequences of what happens there. Four routes matter in Indian practice.
Product liability. Chapter VI of the Consumer Protection Act, 2019 created a statutory product liability action that can be brought against a product manufacturer, a product service provider and a product seller. A seller is not automatically insulated by pointing at the factory upstream. Where the seller exercised substantial control over the design, testing or manufacture of the product, altered it, failed to take reasonable care in assembling, inspecting or maintaining it, or where the manufacturer cannot be identified, the action lands on the seller. Anyone selling own-brand or private-label goods made by a third-party unit is, commercially and often legally, the manufacturer in the consumer's eyes. See our note on product liability for how the term is used in policy wordings.
Vicarious and occupier liability. Where the vendor's workers operate on your premises, or the vendor is a contractor rather than a supplier at arm's length, the principal employer's obligations under the Contract Labour (Regulation and Abolition) Act, 1970 and liability under the Employees' Compensation Act, 1923 can attach to you when the contractor defaults. This is the ground covered in vendor and contractor insurance requirements.
Contractual assumption. Large buyers routinely give customers, landlords or platform partners indemnities covering the supply chain. If you have promised a retailer that goods are made in compliance with all applicable laws, an unlicensed supplier puts you in breach of that promise whatever your own conduct was.
Regulatory and disclosure exposure. BRSR value chain reporting asks listed entities about their supply chain, and enforcement attention after an incident of this kind reaches buyers as well as the unit, particularly where the buyer's volumes plainly exceeded what the licensed capacity could have produced.
Why GSTIN and PAN checks miss this entirely
Vendor onboarding in most Indian corporates is built around payment risk and tax risk, because those are the risks finance owns. The standard file answers three questions: does this entity exist, can we pay it without input-credit trouble, and will it survive the contract term.
Licence currency is a different class of data, and it fails every assumption the tax checks rely on.
- No single registry. Explosives and firework manufacture is licensed under the Explosives Act, 1884 and the Explosives Rules, 2008, administered by the Petroleum and Explosives Safety Organisation. Factory registration sits with the state factory inspectorate under the Factories Act, 1948. Consent to operate comes from the State Pollution Control Board. Boiler registration, fire NOC and trade licences each have their own issuer. There is no one portal that returns a yes or a no.
- Cancellation is invisible downstream. A vendor whose GST registration is suspended shows up as suspended when you check the portal. A vendor whose explosives licence is cancelled shows up as nothing at all, because no commercial system is watching.
- Expiry is not the only failure mode. Onboarding teams that do collect licences usually diary the expiry date. The Kaushambi unit's licence was not expired. On its face it ran to 2026. It had been cancelled two years before that date, which a diary of expiry dates would never have caught.
- The document you hold is a photocopy of a moment. A scanned licence proves the vendor held a licence on the day it was scanned. It proves nothing about today.
The wording problem: wilful breach of statute and contractual liability
Assume the incident happens and a claim reaches your liability programme. Two standard features of Indian liability wordings decide whether the loss is transferred or retained.
The first is the exclusion for liability arising out of wilful or deliberate non-compliance with any statutory provision, which appears in public liability, product liability and combined general liability wordings sold in the Indian market. It attaches to the conduct of the insured and its management, so a supplier's breach does not by itself defeat the buyer's cover. The argument opens where the buyer knew, or where the buyer's own contract and audit records show it had undertaken to verify licences and did not. An onboarding file that contains a licence copy dated four years earlier, with no re-verification and no exception logged, is a poor document to hand an insurer after eleven deaths.
The second is the contractual liability exclusion. Liability the insured assumes under contract, beyond what would attach at law absent the contract, is typically outside cover unless a contractual liability extension is bought and the indemnity disclosed. So the back-to-back promise you gave your retailer about supplier compliance may be the piece that is uninsured.
Two extensions are worth naming at renewal for buyers with hazardous-process suppliers:
- A vendors' liability or suppliers' extension, which brings claims arising from goods supplied by named or unnamed vendors inside the policy rather than leaving the argument to the definition of your product.
- A contractual liability extension matched to the actual indemnities in your customer contracts, not a generic add-on.
On the supplier's own side, a unit handling hazardous substances is required to carry mandatory statutory cover under the Public Liability Insurance Act, 1991, which funds no-fault relief to victims and feeds the Environment Relief Fund. That scheme is explained in no-fault claims under the Public Liability Insurance Act. Its limits are sized to the owner's paid-up capital, which for a small unit is small, and a unit operating without a current licence is unlikely to be carrying the statutory policy at all. The practical consequence is that the deep pocket in the chain is the buyer, and subrogation recovery against a dissolved village-scale unit returns nothing.
What a licence-currency check consists of
The check is cheap. What makes it work is treating licence status as a live field with an owner and a re-check date, not an attachment in a folder.
- Map the permission to the process, not the vendor. Ask what the unit physically does: does it store or use explosives, solvents, LPG or ammonia, run a boiler, do hot work, discharge effluent, employ workers above the Factories Act threshold. Each answer names a specific licence and a specific issuer.
- Capture the licence as structured data. Licence number, issuing authority, date of grant, validity to, licensed premises address, licensed quantity or capacity, and named licensee. Five fields in the vendor master beat a PDF nobody opens.
- Verify with the issuer, not the vendor. Where the authority publishes a status lookup, check it. Where it does not, a written confirmation request to the issuing office, or a site visit that photographs the licence displayed at the premises alongside the plant, is the fallback. A vendor-supplied scan verifies nothing.
- Re-check on a cadence, and treat cancellation as its own event. Annual re-verification for hazardous processes, with a contractual duty on the vendor to notify any suspension, cancellation, show-cause notice or prosecution within seven days. Expiry diaries alone would not have caught Kaushambi.
- Reconcile capacity against purchase orders. Your own purchase data tells you whether the licensed quantity is plausible. This check costs nothing and catches the unit that is quietly subcontracting to an unlicensed neighbour.
- Log exceptions with a decision-maker's name. Where you proceed despite a gap, the file should show who accepted it and why. That record protects you in an inquiry far better than silence.
Contract and certificate mechanics that make the check enforceable
A verification programme without contractual teeth is a filing exercise. Four clauses do the work.
A statutory permissions representation and warranty. The vendor represents that it holds every licence, consent and registration required for the process, that none is suspended or cancelled, and that it will notify the buyer within seven days of any change. Tie a suspension right and a termination right to breach of that warranty, so procurement can stop shipments without a commercial negotiation.
An insurance schedule sized to your exposure. Vendor limits are usually set against the vendor's turnover, which is the wrong denominator. The relevant number is the loss the vendor's product or process can cause to your customers and to third parties. For hazardous-process suppliers, specify product liability, public liability including the statutory cover where the vendor handles hazardous substances, and employees' compensation for the vendor's workers. The drafting and enforceability side is covered in third-party vendor indemnity requirements.
A certificate of insurance obtained from the insurer or broker, not the vendor. The certificate should state policy number, period, limits, and that premium has been paid. A cover note is not a policy, and a policy in force on the day of onboarding is not a policy in force on the day of the loss. Diary certificate expiry the same way you diary licence status.
Restraint on waivers. Buyers copy waiver-of-subrogation clauses across templates without thinking about which direction the recovery runs. Waiving your insurer's subrogation rights against a hazardous-process supplier converts a recoverable loss into a retained one, and it does so at exactly the moment the recovery would have been worth having. Additional-insured status and cross-liability wording are worth negotiating. A blanket subrogation waiver is not.
What to tell your own underwriter
Liability proposal forms ask about outsourced manufacture and hazardous operations, and the duty of utmost good faith means the answers must reflect what you actually know. If your programme has no visibility into supplier licence status, saying so is safer than an implied assurance you cannot support.
There is an upside to running the check properly, and it belongs in the renewal presentation rather than in a compliance binder. Underwriters pricing a product liability or general liability programme for an Indian manufacturer, retailer or marketplace are pricing an unknown tail of supplier conduct. Evidence that narrows it is worth money:
- The count of vendors, split by process hazard tier rather than by spend.
- How many hazardous-tier vendors are verified against the issuing authority, and the re-verification cadence.
- Open exceptions, with the reason and the accountable owner.
- Contractual insurance requirements by tier, and the certificate compliance rate against them.
- Any suspension or termination actually executed on a licence failure, which is the single most persuasive data point because it proves the control has consequences.
After an incident, the first document an insurer's investigator asks for is the onboarding and monitoring file for the vendor concerned. The quality of that file, assembled before the loss, does more to protect the claim than any argument made after it.
A workable first pass for a buyer with several hundred vendors
Verifying every supplier's every permission is not realistic, and attempting it is how these programmes stall. Tier by physical hazard and accept that most of the base needs nothing.
Start by tagging vendors whose process involves any of the following: explosives or pyrotechnics, flammable solvents, compressed or liquefied gas, chemical reaction, foundry or hot work, boilers, electroplating or effluent discharge, and any manufacture of goods sold under your own brand. In most vendor bases that is a small fraction of the count and a large share of the tail risk.
For that tier, do the full check: structured licence fields, issuer verification, annual re-check, capacity reconciliation, notification warranty, insurance schedule and certificate. For everyone else, keep the existing GST and PAN onboarding and add one question about whether the process involves a licensed activity, which re-tiers a vendor when their operations change.
Two habits keep it alive after the first sweep. Give one named person ownership of the hazardous-tier list, because a control with no owner decays inside a year. And re-run the tiering when a vendor's volume grows sharply, since the unit that quietly moved to a second shed to meet your order is precisely the unit whose licence no longer matches what it is doing.
