An acquisition can create growth, market access and new capabilities. It can also transfer undisclosed liabilities, weak contracts, overstated revenue, vulnerable systems and integration problems to the buyer.

A due diligence checklist gives the review a defined structure. It helps the acquisition team identify what must be requested, who is responsible for assessing it, which claims require independent verification and how each finding could affect the transaction.

The objective is not to collect every document in the data room. It is to test the assumptions behind the valuation and establish whether the target is legally sound, financially sustainable, commercially credible and operationally ready for integration.

What Is a Due Diligence Checklist?

A due diligence checklist is a structured set of documents, questions and verification tasks used before acquiring or merging with a company. It normally coordinates the work of legal, finance, tax, commercial, operational, HR, technology and security specialists.

The checklist should be tailored to the deal. An asset purchase creates different questions from a share acquisition. A regulated fintech, defence supplier or software company requires different checks from a local services business. Jurisdictions, transaction value, ownership complexity and the buyer’s risk tolerance should also determine the depth of review.

A broader corporate due diligence framework explains how companies, owners and external risks are investigated. The checklist below focuses specifically on the workstreams a buyer should coordinate during an M&A transaction.

1. Legal and Regulatory Due Diligence

Legal due diligence establishes whether the target exists and operates as represented, owns what it claims to own and can complete the transaction without transferring unexpected obligations to the buyer.

Corporate Structure, Ownership and Authority

Review incorporation documents, constitutional documents, shareholder and director records, group structure, subsidiaries, historical restructurings and evidence that the company remains in good standing. Reconcile the cap table with share issuances, options, warrants and shareholder agreements.

Do not stop at the immediate shareholders. Identify ultimate beneficial owners, people who exercise control, related parties and any undisclosed interests that could influence the deal.

Material Contracts

Examine agreements with customers, suppliers, lenders, landlords, distributors, employees and strategic partners. Flag change-of-control, assignment, termination, exclusivity, most-favoured-customer and minimum-purchase provisions. Confirm which consents or waivers are required before closing.

Intellectual Property

Verify ownership of patents, trademarks, copyright, domains, source code, designs and trade secrets. Check whether founders, employees and contractors assigned relevant rights to the company. Review licences, encumbrances, disputes, infringement allegations and the jurisdictions in which protection is valid. Where ownership or misuse remains unclear, intellectual property investigations can connect domains, marketplace activity and corporate records into an evidence trail.

Permits, Compliance and Approvals

Identify licences, certifications and sector permissions required to operate. Review past violations, remediation obligations, regulatory correspondence and pending investigations. The transaction itself may also require merger-control, foreign-investment or sector-specific approval.

For UK-connected deals, teams should consider the current CMA merger regime and whether the acquisition falls within the National Security and Investment Act. Certain acquisitions in defined sensitive areas require clearance before completion.

Disputes, Enforcement and Reputation

Review current, threatened and historical litigation, arbitration, employment claims, regulatory action, judgments and settlement obligations. Compare management disclosures with court and regulator records.

Legal review should be complemented by reputational due diligence, sanctions screening and adverse-media research. A target may have no recorded legal breach yet still carry material exposure through hidden affiliations, political connections, misconduct allegations or high-risk counterparties.

Environmental and Data Obligations

Check environmental permits, contamination risk, remediation duties and claims made about sustainability performance. Review how the target collects, uses, retains, transfers and protects personal data. The UK ICO states that where an acquisition changes the organisation controlling personal data, the parties must address data sharing, lawful basis, transparency, governance and security as part of M&A due diligence.

2. Financial Due Diligence

Financial due diligence tests whether reported performance is accurate, repeatable and sufficient to support the valuation. It should explain how the target generates cash, which earnings are sustainable and where liabilities may be understated.

Historical Statements and Quality of Earnings

Review income statements, balance sheets and cash flow statements for an appropriate historical period. Reconcile statutory statements, available audit reports, management accounts, bank records and filings. Identify one-off items, aggressive recognition practices, unusual adjustments and differences between reported profit and underlying earnings.

Revenue and Costs

Break revenue down by customer, product, geography, channel and contract type. Test whether recorded sales are supported by contracts, invoices and cash receipts. Examine gross margins, fixed and variable costs, exceptional expenses and dependencies on related parties.

Assets, Debt and Other Liabilities

Verify cash, receivables, inventory, equipment, investments and intangible assets. Assess their condition, recoverability and valuation. Review loans, guarantees, security interests, leases, deferred payments, pension obligations and contingent or off-balance-sheet liabilities.

Tax Position

Review tax returns, payments, correspondence, audits, transfer-pricing arrangements, loss carry-forwards and exposures across every relevant jurisdiction. Determine whether the proposed deal structure creates additional tax consequences or limits the use of existing tax assets.

Working Capital, Liquidity and Forecasts

Analyse receivables, payables, inventory cycles and seasonal requirements to determine normal working capital. Test cash conversion, covenant headroom and the company’s ability to meet obligations. Challenge forecasts against historical results, signed contracts, sales pipeline, market conditions and the investment required to deliver projected growth.

If figures conflict with public records, asset trails or ownership data, targeted financial investigations can examine whether the discrepancy indicates misrepresentation or hidden exposure.

3. Operational Due Diligence

Operational due diligence assesses whether the company can continue delivering after the transaction and whether its processes can support the buyer’s integration plan.

Start with the operating model: products and services, locations, production capacity, key processes, quality controls, customer support and performance indicators. Compare documented procedures with how work is actually performed.

The review should also cover:

  • process bottlenecks, manual dependencies and control weaknesses;
  • supplier concentration, lead times, inventory resilience and alternative sources;
  • reliance on founders, individual employees, subcontractors or single facilities;
  • quality failures, warranty claims, returns and service-level performance;
  • health and safety compliance, incidents and unresolved remediation;
  • insurance coverage, claims history and exclusions;
  • business continuity arrangements and recovery dependencies;
  • the cost, timing and operational risk of integration.

When suppliers, intermediaries or distributors are critical to performance, extend the review through third-party due diligence. A contract may appear stable while the party behind it carries sanctions, ownership, solvency or reputational risk.

4. Commercial Due Diligence

Commercial due diligence tests the target’s market narrative. It asks whether demand is real, the competitive position is defensible and the growth plan is supported by evidence.

Market and Competition

Assess market size, segmentation, regulation, structural changes, growth drivers and barriers to entry. Compare management’s assumptions with independent industry and customer evidence. Where published data is incomplete, business intelligence consulting can test claims about demand, competitors, pricing and expansion potential.

Customers and Contracts

Review customer concentration, contract length, renewal and termination rights, pricing changes, churn, complaints, discounts and collection history. A high reported retention rate needs context if customers can cancel easily, revenue depends on one buyer or relationships belong personally to a founder.

Sales, Marketing and Revenue Model

Test the sales pipeline, conversion rates, acquisition cost, channel performance and marketing claims. Separate recurring revenue from project work, one-off sales and pass-through income. Evaluate pricing power, cross-sell assumptions and whether incentives create unsustainable or low-quality revenue.

Products and Growth Plans

Assess the product portfolio, roadmap, product-market fit, innovation capacity and exposure to obsolescence. For geographic expansion, verify local demand, licensing requirements, route to market, required investment and the strength of proposed partners.

Commercial findings should explain not only whether the target can grow, but which assumptions must remain true for the buyer’s investment case to work.

5. Human Resources Due Diligence

People-related liabilities and retention failures can undermine an otherwise sound acquisition. HR due diligence should establish who performs critical work, which obligations transfer and whether the integration plan is realistic.

Review the organisational chart, reporting lines, management responsibilities and dependence on key people. Compare the formal structure with actual decision-making authority. For founders, executives and employees with access to capital, data or critical systems, role-relevant pre-employment screening can verify career claims, affiliations and conflicts of interest.

The HR checklist should cover:

  • employment, executive and contractor agreements;
  • compensation, bonuses, commission, equity incentives and change-of-control payments;
  • pensions, healthcare, leave and other benefit obligations;
  • employee and contractor classification;
  • confidentiality, intellectual-property assignment and restrictive covenants, subject to local enforceability;
  • collective bargaining arrangements and union relationships;
  • workforce location, skills, tenure, vacancies, turnover and absence;
  • policies for recruitment, performance, training, grievances and disciplinary action;
  • health and safety records, complaints, investigations and employment litigation;
  • retention plans for leaders and employees essential to continuity.

Culture should be assessed through evidence rather than slogans. Turnover patterns, employee feedback, incentive design, reporting practices and management behaviour provide more useful integration signals than a generic statement about cultural fit.

6. Real Estate and Asset Due Diligence

This workstream verifies the ownership, value, condition and obligations attached to property and other tangible assets.

Confirm title, liens, security interests, mortgages, easements, zoning, planning restrictions and property taxes. Review leases for rent, renewal, break, assignment and change-of-control terms. Establish whether critical facilities can remain available after closing.

Obtain appropriate valuations and physical inspections for property, equipment, machinery and inventory. Identify deferred maintenance, obsolete stock, required capital expenditure and assets that are leased or shared with related companies rather than owned by the target.

Environmental site assessments should address contamination, hazardous materials, permits and potential remediation. Review utility, maintenance, service and insurance arrangements, as well as any unresolved ownership or boundary dispute. For property-heavy transactions, a dedicated commercial real estate due diligence workstream may be required.

7. IT Systems, Data and Cybersecurity Due Diligence

Technology due diligence examines whether the target’s systems can operate securely, support the business model and integrate without disproportionate cost.

Technology Inventory and Architecture

Map hardware, networks, cloud environments, databases, business applications, code repositories, integrations and critical vendors. Identify unsupported systems, technical debt, single points of failure and infrastructure controlled by founders or third parties.

Ownership, Licences and Contracts

Confirm ownership of software and data assets. Review open-source components, software licences, cloud agreements, outsourcing contracts and change-of-control or assignment terms. Determine whether essential technology remains usable after completion.

Security and Incident History

Assess security governance, identity and access management, privileged accounts, encryption, patching, vulnerability management, logging, backups and employee awareness. Review previous incidents, regulatory notifications, insurance claims, penetration-test reports and whether identified weaknesses were remediated. A broader cyber security risk management review should also consider exposed infrastructure, data leakage, third-party tools and human-factor weaknesses.

Direct scanning, exploitation or authentication testing is not passive document review. Any intrusive validation should be performed only with explicit written authorisation, a defined scope and agreed rules of engagement, consistent with recognised testing guidance such as NIST SP 800-115.

Data Protection and Resilience

Map the categories, locations and flows of personal, confidential and regulated data. Review lawful bases, retention, cross-border transfers, processor contracts, data-subject requests and breach-response procedures. Test disaster recovery and business continuity arrangements against the systems that actually support revenue and operations.

Finally, estimate the cost and timing of integration. A secure standalone platform may still create deal risk if migration, compatibility or vendor lock-in makes the buyer’s operating model uneconomic.

Beyond the Data Room: Turn Findings into a Deal Decision

A seller’s data room is an essential source, but it is not a complete account of the target. Management selects and describes much of its content. Material claims should therefore be compared with corporate registries, court records, regulatory sources, sanctions data, market evidence, local-language media and interviews conducted within the authorised scope.

Create a red-flag register that records:

  • the finding and its source;
  • whether it is confirmed, disputed or still unresolved;
  • the financial, legal, operational or reputational impact;
  • the person responsible for follow-up;
  • the information required to close the issue;
  • the deadline and current status;
  • the proposed transaction response.

Each material finding should lead to a decision. The buyer may decline the deal, adjust the valuation, change the structure, require a condition precedent, seek a consent, negotiate a warranty or indemnity, retain funds in escrow, or place the issue in a funded post-closing integration plan.

This is where independent due diligence intelligence adds value. It tests the people, ownership, affiliations and external risk signals behind the documents, then separates verified facts from open questions and assumptions.

The Checklist Is a Decision Tool

A comprehensive due diligence checklist does not eliminate acquisition risk. It makes uncertainty visible while the buyer can still price it, allocate it contractually, plan around it or walk away.

The strongest process is risk-based, cross-functional and traceable. It connects every material document to a question, every red flag to an owner and every finding to a transaction decision.

For acquisitions, investments and other high-stakes transactions, contact Molfar Intelligence for an independent review of ownership, affiliations, sanctions exposure, litigation, financial signals and reputational risk beyond the data room.

This article provides general information and does not replace transaction-specific legal, tax, accounting, technical or regulatory advice.

Author

Former British Army officer, trained in surveillance and target acquisition, and Bain and Company engagement manager, with more than a decade of experience working in consulting, private equity and venture capital across Western Europe.

Recent posts

View all
View all
White Plus Icon
View all
View all
White Plus Icon

Related posts

View all
View all
White Plus Icon
No items found.
View all
View all
White Plus Icon
Turn Intelligence Into Action
Order a service
Order a service
Black Plus Icon

Our cases

Behind every case is a client who needed clarity in uncertainty. Browse our work to see how we uncover what others miss — and what that means in practice for businesses and decision-makers.

View all cases
View all cases
White Plus Icon
Expanded Plus Icon

Investor Due Diligence: Mitigating Reputational Risks in Defence Tech

Revealed how a high-stakes Defence Tech investment was halted after OSINT-driven due diligence uncovered a co-founder’s links to Russian-origin money laundering and a seized 2.6 billion UAH gambling enterprise, protecting a global firm from severe reputational and regulatory fallout.

Investment

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Pre-Employment Screening for a Spacecraft Manufacturing Role

Conducted a full pre-employment background investigation for a high-security aerospace role, covering court registry checks, financial record verification, ideological risk assessment, and social media OSINT analysis across relevant jurisdictions.

Space

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Sanctions Gaps — Supercam Drone Production Continues

Revealed how Russian drone manufacturers circumvent international sanctions by exploiting a critical design flaw (sanctions applied to company names rather than underlying legal entity identifiers), enabling Supercam to increase production tenfold despite being designated.

Finance

Learn more
Learn more
White Plus Icon
Expanded Plus Icon

Cybersecurity Audit and Internal Data Exposure Mitigation

Conducted a comprehensive cybersecurity audit of a long-standing European IT infrastructure, identified critical internal data leaks involving financial plans and performance reviews, and implemented high-level security protocols to mitigate regulatory and operational risks.

Cybersecurity

Learn more
Learn more
White Plus Icon
Gain the Clarity You Need to Move with Confidence

Let’s connect to explore how tailored intelligence can strengthen your decisions, reveal opportunities, and minimise uncertainty.