Checklist

M&A Due Diligence Checklist

The information request list a buyer sends the seller, organised by workstream. For each item: what to request, what the document is actually being used to test, and the finding that should change your price or your mind. Covers financial, legal and IP, tax, people, operations, compliance, data protection and ESG.

How to use this checklist

This is the information request list a buyer sends the seller, organised by workstream. For each item: what to request, what the document is actually being used to test, and the finding that should change your price or your mind.

Two sequencing notes. Request the contract set and the financial detail first — they take longest to produce and drive most findings. And send the whole list at once rather than in waves; drip-feeding requests is the single most reliable way to turn a six-week process into a twelve-week one.

Absence is a finding. A category with nothing disclosed is not a clean category. Anweshna applies a baseline score to blocking categories that disclose nothing at all, on the principle that silence in a deal document is itself worth chasing rather than reading as an all-clear.

Financial

RequestWhat it testsRed flag
Audited financials, 3 yearsBaseline reliability and any auditor qualificationGoing-concern language; qualified opinion
Monthly management accounts, 24 monthsSeasonality, trend, and whether monthly detail reconciles to the annualsManagement accounts that do not tie to audited figures
EBITDA bridge with every adjustment supportedWhether adjusted EBITDA is derived or assertedLarge unsupported add-backs; recurring costs called one-time
Revenue by customer, product and contract typeConcentration, recurring versus transactional mixTop customer above 20% of revenue
Working capital by month, 24 monthsThe normalised target, and whether it has been managed pre-saleReceivables collected hard or payables stretched before the process
Debt schedule plus debt-like itemsPensions, deferred consideration, leases, accrued bonuses, unremitted taxDebt-like items omitted from the seller's net debt bridge
Capex history and forward planWhether reported margin depends on deferred maintenanceCapex well below depreciation for consecutive years
Budget versus actual, 3 yearsCredibility of the forecast underpinning the pricePersistent overshoot in management projections

Tax, people and operations

RequestWhat it testsRed flag
Tax returns and correspondence, 4 yearsOpen assessments, audits and disputed positionsUnresolved assessment; aggressive filing position
Transfer pricing documentationDefensibility of intercompany pricing across jurisdictionsNo contemporaneous documentation
Payroll tax and contractor classification reviewMisclassification exposure, often material and unreservedLong-tenured contractors performing employee roles
Employee census with terms and tenureCost base, key-person dependency, retention exposureConcentration of knowledge in one or two individuals
Benefit and pension arrangementsUnfunded obligations that behave like debtDefined-benefit deficit not in the net debt bridge
Change-of-control and retention agreementsCost triggered by the transaction itselfLarge parachutes payable on closing
Supplier concentration and sourcing mapSingle-source dependency and geographic exposureSole-source input with no qualified alternative
Systems inventory and technical debt assessmentIntegration cost and end-of-life exposureUnsupported core systems; no disaster recovery testing

Compliance, data and ESG

  • Sanctions and counterparty screening records — OFAC and equivalent screening across customers, suppliers and intermediaries. An unscreened intermediary in a high-risk jurisdiction is a finding on its own.
  • Anti-bribery programme and third-party due diligence files — FCPA and UK Bribery Act exposure travels with the entity, and agents are where it usually originates.
  • Data protection documentation — lawful basis, DPIAs, cross-border transfer mechanisms, retention schedules, and any regulator correspondence.
  • Security incident history and penetration test results — including incidents that fell below a disclosure threshold, and the remediation status of critical findings.
  • Environmental permits, assessments and remediation obligations — for any owned or long-leased site, together with historical site use.
  • Related-party transaction schedule — intercompany balances, management fees, insider loans, and any revenue dependent on an affiliate.

Turning the list into findings

A checklist tells you what to collect. It does not tell you what is in the documents once they arrive, which is where the time actually goes — a mid-market data room routinely runs to thousands of pages, and the first pass is mostly deciding which documents contain anything worth escalating.

That first pass is what automated screening compresses: documents are scored across 15 M&A risk categories, findings are returned with the language that triggered them, and any blocking category scoring 70 or above flags the deal for mandatory human review. Reviewers start with a ranked queue rather than a pile. It structures the screening pass — it does not verify anything independently or replace legal and accounting judgement.

Frequently asked questions

What should be on an M&A due diligence checklist?

At minimum: audited financials and monthly management accounts, an EBITDA bridge with supported adjustments, revenue by customer and contract type, working capital by month, a debt schedule including debt-like items, corporate records and cap table, the top 20 customer and supplier contracts, a litigation schedule, IP register with chain-of-title evidence, an open-source usage report, tax returns and correspondence, employee census and benefit arrangements, sanctions and anti-bribery screening records, data protection documentation, and any environmental obligations.

What is the difference between a due diligence checklist and an information request list?

In practice they are the same document viewed from two sides. The checklist is the buyer's internal view of what must be tested; the information request list is what gets sent to the seller. The useful discipline is to keep them linked, so every requested document has a stated purpose - if you cannot say what a document is being used to test, it is padding the list and slowing the process.

Who prepares the due diligence checklist?

The buy-side deal team assembles it, with input from the specialists running each workstream - accountants for financial and tax, counsel for legal and IP, and technical or environmental advisers as the target requires. In competitive processes sellers increasingly pre-empt it with a vendor due diligence pack assembled against the same standard list.

How do you prioritise a due diligence checklist under time pressure?

Work from what can kill the deal rather than what can reprice it. Ownership of core IP, change-of-control provisions on material revenue, sanctions and bribery exposure, and unreserved litigation all fall into the first category. Working capital and EBITDA adjustments, while they consume the most analyst time, generally move price rather than stopping a transaction.

Anweshna Demo