A business preparing to be sold typically commissions what M&A practitioners still call a "vendor due diligence" report — even though that same two-word phrase, searched today, mostly turns up something else entirely: checking a supplier before signing a contract. One process assembles financial, legal, and operational records into a report for prospective buyers, before a single conversation starts. The other vets the suppliers a company already works with, checking whether a vendor carries risk that could reach its own operations. Same phrase, two unrelated processes, two different audiences reading this article right now. Both matter. Neither should be confused with the other — and getting that confusion sorted out first is the point of this piece.
Key Takeaways
- Sell-side due diligence — still commonly called "vendor due diligence" (VDD) in M&A — is a seller-initiated review (financial, legal, operational, sometimes reputational) prepared before a business goes to market, distinct from buyer-led due diligence that happens after.
- 46.6% of broken deals (letters of intent that fell apart) in 2025 died specifically on due diligence findings, up from 42.9% in 2024 and 29.7% in 2023 — a rising share, per Axial's 2025 Dead Deal Report.
- "Vendor due diligence" in the supply-chain sense — vetting a third-party supplier or partner — is a completely separate, ongoing discipline (see the disambiguation below); this article covers the M&A one.
- 84% of senior dealmakers expect increased cybersecurity scrutiny during due diligence going forward, per SRS Acquiom's 2026 study — one of several categories where self-reported disclosure benefits from independent confirmation.
- We don't run the sale process or write the VDD report itself. We verify what goes into one — ownership, litigation, reputational and compliance red flags — through open-source and public-record research, the same way we'd verify a claim about any counterparty.
Two Different Things Share One Name
"Vendor due diligence" means the seller in M&A terminology — the company selling itself commissions a report about itself, for the benefit of prospective buyers. It has nothing to do with vetting a vendor you buy goods or services from. Third-party or supplier due diligence is the ongoing practice of checking the risk profile of the companies you rely on — sanctions exposure, ownership structure, financial stability, compliance history — and it applies whether or not anyone involved is buying or selling a business.
The rest of this article is about the M&A meaning: a seller preparing its own business for the scrutiny a buyer would otherwise apply unilaterally.
Why this matters: if you landed here looking for how to check out a supplier or contractor before signing a contract, that's a different page — this one is about preparing a business for sale.
What a Sell-Side Vendor Due Diligence Review Covers
A VDD review is a comprehensive, seller-commissioned analysis of the business being sold, typically compiled with independent advisors well before the business is actively marketed. It's built to answer, from the seller's side, the same categories a buyer's own M&A due diligence checklist would probe anyway:
- Financial due diligence. Earnings quality, cash flow, debt structure, working capital — the numbers a buyer's own financial advisors will independently recompute regardless of what the seller's report says, covered in full in how financial due diligence itself is run, on either side of a deal.
- Legal and compliance review. Contracts, liabilities, intellectual property assignments, regulatory standing.
- Operational and commercial assessment. Supply chain dependencies, customer concentration, competitive positioning.
- Risk identification. Surfacing the issues a buyer would find anyway, early enough that they can be corrected or clearly explained rather than discovered cold during exclusivity.
This is fundamentally different from buyer-side due diligence, which starts once a buyer has access and runs on the buyer's own timeline, methodology, and skepticism. VDD is seller-controlled by design — which is exactly why the report's credibility with a buyer depends on how independently it was actually verified, not just how thoroughly it was written.
Why this matters: a VDD report that reads as comprehensive but was built entirely from management-provided data and internal sign-off carries less weight with a sophisticated buyer than one that shows independent verification behind at least the highest-risk findings. The report format looks the same either way; the credibility doesn't.
Why Sellers Increasingly Can't Skip This
The data suggests the older, informal approach — waiting for a buyer to ask, then reacting — carries more risk than it used to. Axial's Dead Deal Report, published in January 2026 from an analysis of 75 unsuccessful lower-middle-market transactions in 2025, found that 46.6% of broken letters of intent died specifically on due diligence findings — up from 42.9% in 2024 and 29.7% in 2023. Diligence findings, not financing or valuation disagreements, are now the single largest cause of deals that don't close, and the share has grown three years running.
SRS Acquiom's 2026 M&A Due Diligence Study — a Q4 2025 survey of 150 senior investment bank executives conducted with Mergermarket — points to the same pressure from a different angle. Seventy-three percent expect the due diligence process to get more complex over the next 12–24 months. One in five report that timelines have already extended over the past two years, with 57% of that group citing one to three additional months. Eighty-four percent expect increased cybersecurity scrutiny specifically, with 43% expecting it to be significantly greater.
Why this matters: a seller who waits for the buyer to surface every issue is negotiating from behind, on the buyer's timeline, after exclusivity has already narrowed their options. A seller who has already verified the same findings a sophisticated buyer would independently uncover — and addressed or clearly explained them — walks into the same conversation from a materially different position.
Where Self-Reported Data Needs Independent Verification
A VDD report is, by construction, prepared by or for the party with the most to gain from a clean result. That's not a criticism of the practice — it's simply the structural reality buyers already factor in, which is exactly why an advisor's letter of reliance and independent verification of the higher-risk findings matter more than the report's polish.
We don't manage the sale process, write the VDD report, or advise on deal structure — that's the M&A advisor's role, and Initium's own site describes that role well. What we do is verify the specific claims that carry the most consequence if they turn out to be wrong: who actually owns and controls the business, whether litigation or regulatory action exists that didn't make it into the internal file, whether a "key person" has a public history that would concern a buyer, whether a counterparty relationship described as stable is actually as described. That verification runs through open-source intelligence and public-record research — company registries, court records, sanctions and adverse-media databases, ownership filings — the same methodology we'd apply to verify any counterparty claim, regardless of which side of a transaction commissioned it.
Why this matters: the categories where a VDD review is thinnest are usually the ones self-reported data can't fully cover on its own — reputational history, undisclosed litigation, real (not claimed) ownership structure. Those are exactly the categories independent, public-record verification is built to check.
Red Flags Worth Verifying Independently
The categories a VDD review is meant to surface map closely onto categories Molfar investigates directly, each through a different discipline rather than one generic "risk check":
- Undisclosed liabilities, poor compliance history, or financial-crime exposure — verified through AML and financial-crime compliance investigation, which traces ownership and counterparty exposure beyond what internal records show.
- Legal and regulatory violations that didn't make it into the internal file — surfaced through adverse media screening against court records, regulatory actions, and negative press history.
- Reputational exposure that would concern a buyer or its investment committee — assessed through a dedicated reputational due diligence review, the same kind used before an investment or acquisition decision.
- Key-person risk and leadership credibility — verified through background checks on executives, directors, and other public-facing leadership whose history could affect buyer confidence.
- Unclear or disputed intellectual property — checked through IP investigation work that confirms ownership and exposure to infringement or counterfeiting claims.
- Cybersecurity gaps — the category 84% of dealmakers now expect more scrutiny on — assessed through cyber security risk management, which maps external exposure a technical audit alone often misses.
Why this matters: a checklist that lists "cybersecurity gaps" or "IP ownership issues" as red-flag categories is only useful if someone actually verifies each one against outside evidence. Naming the category isn't the same as checking it.
Molfar's Independent Verification Checklist for a Credible VDD
Before a VDD report goes to prospective buyers, we recommend confirming the following independently of what internal management has provided — not because internal data is presumed wrong, but because a buyer's own advisors will check regardless, and finding a gap before they do changes the conversation entirely:
- Confirm actual ownership and control, not just the org chart on file. Beneficial ownership, related-party arrangements, and any indirect control structures should match public registry filings, not just internal cap table records.
- Search for litigation and regulatory action independently of internal legal files. A dispute that management considers resolved or immaterial can still surface in a buyer's own search — confirm it's genuinely closed, not just internally forgotten.
- Run adverse-media and sanctions screening on the business and its key individuals, not only on the counterparties the business itself deals with. Buyers screen the seller too.
- Verify the public-facing history of anyone flagged as a "key person" in the deal — a departure, a past dispute, or an undisclosed conflict of interest is far cheaper to address before a buyer's own background check finds it first.
- Check supplier and customer concentration claims against independent signals, not just the contracts on file — a "diversified customer base" claim should hold up against what's publicly verifiable, not just what internal reporting states.
- Treat every finding the same way regardless of which side commissioned the review. A red flag doesn't become smaller because the seller's own advisor found it first — the point of independent verification is that the finding holds up no matter who's asking.
Why this matters: the value of a VDD report to a buyer is proportional to how much of it survives independent re-checking. A checklist run internally, by the same team with an interest in a clean result, doesn't carry the same weight as one confirmed against outside, public-record evidence — and buyers increasingly know the difference.
FAQ
What is vendor due diligence in M&A?
It's a due diligence review commissioned by the seller (the "vendor" in M&A terminology) before a business goes to market — covering financial, legal, operational, and sometimes reputational risk — intended to give prospective buyers a credible, independently supported view of the business ahead of formal negotiations.
Is this the same as checking a supplier or vendor before doing business with them?
No, and this is a common point of confusion because both use the exact same phrase. Checking a supplier, contractor, or business partner is third-party due diligence (see the disambiguation above) — an ongoing practice unrelated to selling a business. This article covers the M&A meaning specifically.
How is vendor due diligence different from buyer-side due diligence?
VDD is initiated and controlled by the seller, before a buyer is formally engaged, with the goal of surfacing and addressing issues proactively. Buyer-side due diligence begins once a buyer has access to information and runs on the buyer's own methodology and skepticism — the two processes can examine the same business and reach different levels of scrutiny on the same issues.
Who typically commissions a VDD report, and when?
The seller — typically the shareholders or ownership group — usually initiates it well before actively marketing the business, often with independent financial, legal, and (increasingly) reputational and intelligence-based advisors involved alongside the M&A advisor managing the sale process itself.
Does independent verification replace the standard financial and legal VDD workstreams?
No. Financial and legal due diligence are their own specialized disciplines, typically run by accountants and lawyers. Independent, open-source verification is a complementary layer — it checks the claims and categories (ownership, reputation, undisclosed litigation, key-person history) that a financial or legal review alone is less structurally positioned to catch.
Why are due diligence findings killing more deals than they used to?
Axial's 2025 data shows diligence-related findings causing 46.6% of broken deals, up from 42.9% in 2024 and 29.7% in 2023 — a trend consistent with buyers applying more scrutiny, not less, across categories like cybersecurity that used to receive lighter review. A seller preparing for that level of scrutiny in advance is working from a materially different position than one reacting to it after exclusivity has already narrowed their options.