Checklist · Banking

Bank M&A Due Diligence Checklist

A document request list for a bank or credit union acquisition, organised by workstream. For each item: what to ask the target for, what the document is actually being used to test, and the finding that should change your price or stop the deal.

How to use this checklist

This is a document request list, not a summary. Each workstream lists what to ask the target for, what the document is actually being used to test, and the finding that should change your price or stop the deal.

Two sequencing notes. Request the loan tape and the regulatory correspondence file first — they take longest to produce and they drive the findings that matter most. And run the regulatory approval workstream in parallel from day one rather than after commercial diligence closes, because approval risk often sits with the acquirer rather than the target.

On completeness. A category with nothing disclosed is not a clean category. In Anweshna's banking ruleset the five blocking categories carry a baseline score on absence — a filing that says nothing at all about asset quality produces a flagged finding rather than a pass, because silence in a bank disclosure is itself a signal worth chasing.

Credit and asset quality

The heaviest-weighted workstream. Request these first.
RequestWhat it testsRed flag
Loan tape (loan-level)Concentration, vintage, rate and maturity structure, collateralSingle borrower >10% of capital (our screen; the legal limit is 15%/25% — see Sources)
Classified and criticised asset scheduleSubstandard, doubtful and loss-rated credits with migration historyClassified assets >5% of the portfolio (our screen, not a regulatory limit)
ALLL methodology and back-testingWhether the reserve is derived or pluggedReserve flat while classified assets rise
Charge-off and recovery historyWhether losses are recognised promptly or deferredNet charge-offs accelerating against a flat reserve
Concentration reports (CRE, C&D, industry, geography)Exposure against interagency guidance thresholdsC&D ≥100% of total capital, or CRE ≥300% with 50%+ growth over 36 months (71 FR 74580)
OREO schedule with current appraisalsCarrying value, holding cost, disposal timeline, environmental exposureOREO balance growing year over year
TDR and modification logWhether problem credits are being restructured rather than recognisedRising modifications with a static NPL ratio
Loan review and internal audit reportsIndependent view of underwriting disciplineRepeat findings across consecutive reviews

Capital, earnings and liquidity

RequestWhat it testsRed flag
Call reports, trailing 12 quartersCET1, Tier 1, leverage and total risk-based capital trendAny ratio below minimum; leverage <4.0% (undercapitalized — 12 CFR § 324.403)
Capital plan and any restoration planWhether a breach has already occurredA restoration plan exists at all
PCA category determinationStatutory restrictions currently in forceAnything below well capitalised
DTA schedule and valuation allowance analysisWhether reported earnings and capital are realNet income attributable to a DTA release
Non-interest income compositionRecurring versus one-time revenueOne-time items presented as run-rate
NIM trend and repricing gapRate sensitivity of the earnings streamSustained compression with no funding response
Deposit composition and uninsured shareFunding stability under stressHigh uninsured or concentrated deposits
Wholesale and brokered funding detailReliance on rate-sensitive fundingHeavy wholesale reliance with thin liquidity
Contingency funding plan and liquidity stress testsWhether the plan has been tested or merely writtenPlan never exercised; unrealistic assumptions

Regulatory, compliance and financial crime

RequestWhat it testsRed flag
Full regulatory correspondence fileEverything the supervisor has raised, not just formal actionsGaps or withheld items in the file
Consent orders, formal agreements, C&DsLive restrictions the acquirer inheritsAny action — including ones described as resolved
MRAs and MRIAs with remediation statusIssues short of formal action, often the earliest signalAgeing MRAs with slipping remediation dates
Civil Investigative DemandsPre-enforcement investigations in progressAny open CID — unbounded timeline and exposure
CAMELS component and composite trendSupervisory trajectory, not just current standingA downgrade in any component
BSA/AML programme and independent testingWhether the programme functions or merely existsRepeat independent-testing findings
SAR and CTR filing statisticsMonitoring effectiveness and filing disciplineLate SAR filings
OFAC screening configuration and match logSanctions screening coverage and tuningAny OFAC or SDN match
CDD/KYC file sample and remediation backlogCustomer due diligence completenessMaterial CDD/KYC deficiency findings
CRA rating and performance evaluationApproval risk on the combined institutionLess than Satisfactory

Technology, cyber, governance and contracts

  • Core processing contract — term, change-of-control provisions and deconversion fees. Core contract break costs are one of the most commonly underestimated integration line items in a bank deal.
  • Incident history and vendor exposure — including fourth-party dependencies reached through the core provider, and any breach with an unmet notification obligation.
  • Cyber insurance — coverage limits, exclusions, and whether prior incidents were tendered.
  • Board composition, turnover and succession plans — key-person dependency is a real supervisory concern in community institutions.
  • Executive compensation and change-of-control agreements — golden parachute payments at a troubled institution face regulatory restriction, which can strand a retention plan.
  • Branch lease and property schedule — consolidation assumptions in the model depend on exit terms.

The approval file — about the acquirer, not the target

This is the workstream most often started too late. The application turns partly on the acquirer's own record, so assemble these in parallel with target diligence:

  1. Your own supervisory rating, CRA performance evaluation and BSA/AML programme documentation.
  2. Pro-forma capital on day one, including purchase accounting marks on the acquired loan book — the combined institution must be well capitalised at close, not shortly after.
  3. Deposit market share in overlapping markets, with a view on whether concentration invites conditions or divestiture.
  4. A public comment strategy, particularly where branch closures or CRA performance are likely to draw attention.
  5. An integration plan for any inherited enforcement obligation — supervisors will ask how the combined institution will satisfy it.

Sources

Primary sources for the statutory and supervisory figures cited on this page. Each was fetched and read before being cited. Thresholds change — verify current requirements with the relevant agency before relying on them. Screening thresholds that are ours rather than a regulator's are labelled as such in the text and are deliberately not cited here.

  1. Interagency guidance on commercial real estate concentrations, 71 FR 74580 (12 December 2006) — the two supervisory screening criteria: construction, land development and other land loans at 100% or more of total capital; or total commercial real estate loans at 300% or more of total capital and a CRE portfolio that has grown 50% or more over the prior 36 months. “Total capital” means total risk-based capital as reported on Call Report schedule RC-R.
  2. Prompt Corrective Action capital categories, 12 CFR § 324.403 — an institution must hold a leverage ratio of 4.0% or greater to be “adequately capitalized”; below 4.0% it is “undercapitalized”. Also the source for the total risk-based (8.0%), tier 1 (6.0%) and CET1 (4.5%) minimums for that category.
  3. Single-borrower lending limit, 12 CFR § 32.3(a) — a national bank's or savings association's total loans to one borrower may not exceed 15% of capital and surplus, plus a further 10% where the excess is fully secured by readily marketable collateral. The 10% figure used on this page is a screening trigger, not this legal limit.

Frequently asked questions

What documents are needed for bank M&A due diligence?

At minimum: the loan-level loan tape, classified and criticised asset schedules, ALLL methodology and back-testing, concentration reports, the OREO schedule with current appraisals, trailing call reports, the capital plan, the full regulatory correspondence file including MRAs and any consent orders, BSA/AML programme documentation with independent testing results, SAR and CTR filing statistics, deposit composition detail, the core processing contract, and the acquirer's own CRA and supervisory record for the approval application.

How long does bank M&A due diligence take?

For a community bank acquisition, commercial diligence typically runs six to twelve weeks, but the binding constraint is usually regulatory approval rather than diligence itself — that commonly adds three to six months from application, and longer where an enforcement action, CRA concern or public comment is in play. The loan tape and regulatory correspondence file take longest to produce, so request them on day one.

What is the most commonly missed item in bank diligence?

Core processing contract break and deconversion fees, and the ongoing obligations attached to an enforcement action described as resolved. Both are frequently treated as closed items when they carry real cost and real restriction into the combined institution.

Should the acquirer's own record be part of diligence?

Yes. Bank and credit union transactions require prudential approval, and the regulator assesses the acquirer's supervisory rating, CRA performance and BSA/AML programme when reviewing the application. A weak acquirer record can delay or block a transaction regardless of how clean the target is, so it belongs in the diligence plan from the start.

Anweshna Demo