An acquisition can create growth, market access and new capabilities. It can also transfer undisclosed liabilities, weak contracts, overstated revenue, vulnerable systems and integration problems to the buyer.
A due diligence checklist gives the review a defined structure. It helps the acquisition team identify what must be requested, who is responsible for assessing it, which claims require independent verification and how each finding could affect the transaction.
The objective is not to collect every document in the data room. It is to test the assumptions behind the valuation and establish whether the target is legally sound, financially sustainable, commercially credible and operationally ready for integration.
What Is a Due Diligence Checklist?
A due diligence checklist is a structured set of documents, questions and verification tasks used before acquiring or merging with a company. It normally coordinates the work of legal, finance, tax, commercial, operational, HR, technology and security specialists.
The checklist should be tailored to the deal. An asset purchase creates different questions from a share acquisition. A regulated fintech, defence supplier or software company requires different checks from a local services business. Jurisdictions, transaction value, ownership complexity and the buyer’s risk tolerance should also determine the depth of review.
A broader corporate due diligence framework explains how companies, owners and external risks are investigated. The checklist below focuses specifically on the workstreams a buyer should coordinate during an M&A transaction.
1. Legal and Regulatory Due Diligence
Legal due diligence establishes whether the target exists and operates as represented, owns what it claims to own and can complete the transaction without transferring unexpected obligations to the buyer.
Corporate Structure, Ownership and Authority
Review incorporation documents, constitutional documents, shareholder and director records, group structure, subsidiaries, historical restructurings and evidence that the company remains in good standing. Reconcile the cap table with share issuances, options, warrants and shareholder agreements.
Do not stop at the immediate shareholders. Identify ultimate beneficial owners, people who exercise control, related parties and any undisclosed interests that could influence the deal.
Material Contracts
Examine agreements with customers, suppliers, lenders, landlords, distributors, employees and strategic partners. Flag change-of-control, assignment, termination, exclusivity, most-favoured-customer and minimum-purchase provisions. Confirm which consents or waivers are required before closing.
Intellectual Property
Verify ownership of patents, trademarks, copyright, domains, source code, designs and trade secrets. Check whether founders, employees and contractors assigned relevant rights to the company. Review licences, encumbrances, disputes, infringement allegations and the jurisdictions in which protection is valid. Where ownership or misuse remains unclear, intellectual property investigations can connect domains, marketplace activity and corporate records into an evidence trail.
Permits, Compliance and Approvals
Identify licences, certifications and sector permissions required to operate. Review past violations, remediation obligations, regulatory correspondence and pending investigations. The transaction itself may also require merger-control, foreign-investment or sector-specific approval.
For UK-connected deals, teams should consider the current CMA merger regime and whether the acquisition falls within the National Security and Investment Act. Certain acquisitions in defined sensitive areas require clearance before completion.
Disputes, Enforcement and Reputation
Review current, threatened and historical litigation, arbitration, employment claims, regulatory action, judgments and settlement obligations. Compare management disclosures with court and regulator records.
Legal review should be complemented by reputational due diligence, sanctions screening and adverse-media research. A target may have no recorded legal breach yet still carry material exposure through hidden affiliations, political connections, misconduct allegations or high-risk counterparties.
Environmental and Data Obligations
Check environmental permits, contamination risk, remediation duties and claims made about sustainability performance. Review how the target collects, uses, retains, transfers and protects personal data. The UK ICO states that where an acquisition changes the organisation controlling personal data, the parties must address data sharing, lawful basis, transparency, governance and security as part of M&A due diligence.
2. Financial Due Diligence
Financial due diligence tests whether reported performance is accurate, repeatable and sufficient to support the valuation. It should explain how the target generates cash, which earnings are sustainable and where liabilities may be understated.
Historical Statements and Quality of Earnings
Review income statements, balance sheets and cash flow statements for an appropriate historical period. Reconcile statutory statements, available audit reports, management accounts, bank records and filings. Identify one-off items, aggressive recognition practices, unusual adjustments and differences between reported profit and underlying earnings.
Revenue and Costs
Break revenue down by customer, product, geography, channel and contract type. Test whether recorded sales are supported by contracts, invoices and cash receipts. Examine gross margins, fixed and variable costs, exceptional expenses and dependencies on related parties.
Assets, Debt and Other Liabilities
Verify cash, receivables, inventory, equipment, investments and intangible assets. Assess their condition, recoverability and valuation. Review loans, guarantees, security interests, leases, deferred payments, pension obligations and contingent or off-balance-sheet liabilities.
Tax Position
Review tax returns, payments, correspondence, audits, transfer-pricing arrangements, loss carry-forwards and exposures across every relevant jurisdiction. Determine whether the proposed deal structure creates additional tax consequences or limits the use of existing tax assets.
Working Capital, Liquidity and Forecasts
Analyse receivables, payables, inventory cycles and seasonal requirements to determine normal working capital. Test cash conversion, covenant headroom and the company’s ability to meet obligations. Challenge forecasts against historical results, signed contracts, sales pipeline, market conditions and the investment required to deliver projected growth.
If figures conflict with public records, asset trails or ownership data, targeted financial investigations can examine whether the discrepancy indicates misrepresentation or hidden exposure.
3. Operational Due Diligence
Operational due diligence assesses whether the company can continue delivering after the transaction and whether its processes can support the buyer’s integration plan.
Start with the operating model: products and services, locations, production capacity, key processes, quality controls, customer support and performance indicators. Compare documented procedures with how work is actually performed.
The review should also cover:
- process bottlenecks, manual dependencies and control weaknesses;
- supplier concentration, lead times, inventory resilience and alternative sources;
- reliance on founders, individual employees, subcontractors or single facilities;
- quality failures, warranty claims, returns and service-level performance;
- health and safety compliance, incidents and unresolved remediation;
- insurance coverage, claims history and exclusions;
- business continuity arrangements and recovery dependencies;
- the cost, timing and operational risk of integration.
When suppliers, intermediaries or distributors are critical to performance, extend the review through third-party due diligence. A contract may appear stable while the party behind it carries sanctions, ownership, solvency or reputational risk.
4. Commercial Due Diligence
Commercial due diligence tests the target’s market narrative. It asks whether demand is real, the competitive position is defensible and the growth plan is supported by evidence.
Market and Competition
Assess market size, segmentation, regulation, structural changes, growth drivers and barriers to entry. Compare management’s assumptions with independent industry and customer evidence. Where published data is incomplete, business intelligence consulting can test claims about demand, competitors, pricing and expansion potential.
Our market research guide explains how to frame the question, select primary and secondary evidence, and turn findings into a decision-ready assessment.
Customers and Contracts
Review customer concentration, contract length, renewal and termination rights, pricing changes, churn, complaints, discounts and collection history. A high reported retention rate needs context if customers can cancel easily, revenue depends on one buyer or relationships belong personally to a founder.
Sales, Marketing and Revenue Model
Test the sales pipeline, conversion rates, acquisition cost, channel performance and marketing claims. Separate recurring revenue from project work, one-off sales and pass-through income. Evaluate pricing power, cross-sell assumptions and whether incentives create unsustainable or low-quality revenue.
Products and Growth Plans
Assess the product portfolio, roadmap, product-market fit, innovation capacity and exposure to obsolescence. For geographic expansion, verify local demand, licensing requirements, route to market, required investment and the strength of proposed partners.
For cross-border growth, international market research can test how demand, competition, regulation, language and routes to market differ between countries.
Commercial findings should explain not only whether the target can grow, but which assumptions must remain true for the buyer’s investment case to work.
5. Human Resources Due Diligence
People-related liabilities and retention failures can undermine an otherwise sound acquisition. HR due diligence should establish who performs critical work, which obligations transfer and whether the integration plan is realistic.
Review the organisational chart, reporting lines, management responsibilities and dependence on key people. Compare the formal structure with actual decision-making authority. For founders, executives and employees with access to capital, data or critical systems, role-relevant pre-employment screening can verify career claims, affiliations and conflicts of interest.
The HR checklist should cover:
- employment, executive and contractor agreements;
- compensation, bonuses, commission, equity incentives and change-of-control payments;
- pensions, healthcare, leave and other benefit obligations;
- employee and contractor classification;
- confidentiality, intellectual-property assignment and restrictive covenants, subject to local enforceability;
- collective bargaining arrangements and union relationships;
- workforce location, skills, tenure, vacancies, turnover and absence;
- policies for recruitment, performance, training, grievances and disciplinary action;
- health and safety records, complaints, investigations and employment litigation;
- retention plans for leaders and employees essential to continuity.
Culture should be assessed through evidence rather than slogans. Turnover patterns, employee feedback, incentive design, reporting practices and management behaviour provide more useful integration signals than a generic statement about cultural fit.
6. Real Estate and Asset Due Diligence
This workstream verifies the ownership, value, condition and obligations attached to property and other tangible assets.
Confirm title, liens, security interests, mortgages, easements, zoning, planning restrictions and property taxes. Review leases for rent, renewal, break, assignment and change-of-control terms. Establish whether critical facilities can remain available after closing.
Obtain appropriate valuations and physical inspections for property, equipment, machinery and inventory. Identify deferred maintenance, obsolete stock, required capital expenditure and assets that are leased or shared with related companies rather than owned by the target.
Environmental site assessments should address contamination, hazardous materials, permits and potential remediation. Review utility, maintenance, service and insurance arrangements, as well as any unresolved ownership or boundary dispute. For property-heavy transactions, a dedicated commercial real estate due diligence workstream may be required.
7. IT Systems, Data and Cybersecurity Due Diligence
Technology due diligence examines whether the target’s systems can operate securely, support the business model and integrate without disproportionate cost.
Technology Inventory and Architecture
Map hardware, networks, cloud environments, databases, business applications, code repositories, integrations and critical vendors. Identify unsupported systems, technical debt, single points of failure and infrastructure controlled by founders or third parties.
Ownership, Licences and Contracts
Confirm ownership of software and data assets. Review open-source components, software licences, cloud agreements, outsourcing contracts and change-of-control or assignment terms. Determine whether essential technology remains usable after completion.
Security and Incident History
Assess security governance, identity and access management, privileged accounts, encryption, patching, vulnerability management, logging, backups and employee awareness. Review previous incidents, regulatory notifications, insurance claims, penetration-test reports and whether identified weaknesses were remediated. A broader cyber security risk management review should also consider exposed infrastructure, data leakage, third-party tools and human-factor weaknesses.
Direct scanning, exploitation or authentication testing is not passive document review. Any intrusive validation should be performed only with explicit written authorisation, a defined scope and agreed rules of engagement, consistent with recognised testing guidance such as NIST SP 800-115.
Data Protection and Resilience
Map the categories, locations and flows of personal, confidential and regulated data. Review lawful bases, retention, cross-border transfers, processor contracts, data-subject requests and breach-response procedures. Test disaster recovery and business continuity arrangements against the systems that actually support revenue and operations.
Finally, estimate the cost and timing of integration. A secure standalone platform may still create deal risk if migration, compatibility or vendor lock-in makes the buyer’s operating model uneconomic.
Beyond the Data Room: Turn Findings into a Deal Decision
A seller’s data room is an essential source, but it is not a complete account of the target. Management selects and describes much of its content. Material claims should therefore be compared with corporate registries, court records, regulatory sources, sanctions data, market evidence, local-language media and interviews conducted within the authorised scope.
Create a red-flag register that records:
- the finding and its source;
- whether it is confirmed, disputed or still unresolved;
- the financial, legal, operational or reputational impact;
- the person responsible for follow-up;
- the information required to close the issue;
- the deadline and current status;
- the proposed transaction response.
Each material finding should lead to a decision. The buyer may decline the deal, adjust the valuation, change the structure, require a condition precedent, seek a consent, negotiate a warranty or indemnity, retain funds in escrow, or place the issue in a funded post-closing integration plan.
This is where independent due diligence intelligence adds value. It tests the people, ownership, affiliations and external risk signals behind the documents, then separates verified facts from open questions and assumptions.
The Checklist Is a Decision Tool
A comprehensive due diligence checklist does not eliminate acquisition risk. It makes uncertainty visible while the buyer can still price it, allocate it contractually, plan around it or walk away.
The strongest process is risk-based, cross-functional and traceable. It connects every material document to a question, every red flag to an owner and every finding to a transaction decision.
For acquisitions, investments and other high-stakes transactions, contact Molfar Intelligence for an independent review of ownership, affiliations, sanctions exposure, litigation, financial signals and reputational risk beyond the data room.
This article provides general information and does not replace transaction-specific legal, tax, accounting, technical or regulatory advice.