M&A Due Diligence Checklist
The information request list a buyer sends the seller, organised by workstream. For each item: what to request, what the document is actually being used to test, and the finding that should change your price or your mind. Covers financial, legal and IP, tax, people, operations, compliance, data protection and ESG.
How to use this checklist
This is the information request list a buyer sends the seller, organised by workstream. For each item: what to request, what the document is actually being used to test, and the finding that should change your price or your mind.
Two sequencing notes. Request the contract set and the financial detail first — they take longest to produce and drive most findings. And send the whole list at once rather than in waves; drip-feeding requests is the single most reliable way to turn a six-week process into a twelve-week one.
Absence is a finding. A category with nothing disclosed is not a clean category. Anweshna applies a baseline score to blocking categories that disclose nothing at all, on the principle that silence in a deal document is itself worth chasing rather than reading as an all-clear.
Financial
| Request | What it tests | Red flag |
|---|---|---|
| Audited financials, 3 years | Baseline reliability and any auditor qualification | Going-concern language; qualified opinion |
| Monthly management accounts, 24 months | Seasonality, trend, and whether monthly detail reconciles to the annuals | Management accounts that do not tie to audited figures |
| EBITDA bridge with every adjustment supported | Whether adjusted EBITDA is derived or asserted | Large unsupported add-backs; recurring costs called one-time |
| Revenue by customer, product and contract type | Concentration, recurring versus transactional mix | Top customer above 20% of revenue |
| Working capital by month, 24 months | The normalised target, and whether it has been managed pre-sale | Receivables collected hard or payables stretched before the process |
| Debt schedule plus debt-like items | Pensions, deferred consideration, leases, accrued bonuses, unremitted tax | Debt-like items omitted from the seller's net debt bridge |
| Capex history and forward plan | Whether reported margin depends on deferred maintenance | Capex well below depreciation for consecutive years |
| Budget versus actual, 3 years | Credibility of the forecast underpinning the price | Persistent overshoot in management projections |
Legal, contracts and IP
| Request | What it tests | Red flag |
|---|---|---|
| Corporate records and cap table | Clean title to the shares being bought | Unissued options, unresolved founder claims, defective transfers |
| Top 20 customer and supplier contracts | Term, pricing, exclusivity and change-of-control provisions | Change-of-control termination on material revenue |
| Litigation schedule with counsel assessment | Exposure, reserve adequacy and reputational carry | Unreserved claims; matters omitted from the schedule |
| IP register and chain-of-title evidence | Whether the company actually owns its core product | Missing employee or contractor IP assignments |
| Open-source usage report (SBOM) | Copyleft obligations attaching to proprietary code | GPL or AGPL components in the distributed product |
| Licences, permits and regulatory authorisations | Whether they survive the transaction and transfer cleanly | Non-transferable licences central to operations |
| Insurance policies and claims history | Coverage adequacy and prior loss experience | Material uninsured exposure; declined claims |
Tax, people and operations
| Request | What it tests | Red flag |
|---|---|---|
| Tax returns and correspondence, 4 years | Open assessments, audits and disputed positions | Unresolved assessment; aggressive filing position |
| Transfer pricing documentation | Defensibility of intercompany pricing across jurisdictions | No contemporaneous documentation |
| Payroll tax and contractor classification review | Misclassification exposure, often material and unreserved | Long-tenured contractors performing employee roles |
| Employee census with terms and tenure | Cost base, key-person dependency, retention exposure | Concentration of knowledge in one or two individuals |
| Benefit and pension arrangements | Unfunded obligations that behave like debt | Defined-benefit deficit not in the net debt bridge |
| Change-of-control and retention agreements | Cost triggered by the transaction itself | Large parachutes payable on closing |
| Supplier concentration and sourcing map | Single-source dependency and geographic exposure | Sole-source input with no qualified alternative |
| Systems inventory and technical debt assessment | Integration cost and end-of-life exposure | Unsupported core systems; no disaster recovery testing |
Compliance, data and ESG
- Sanctions and counterparty screening records — OFAC and equivalent screening across customers, suppliers and intermediaries. An unscreened intermediary in a high-risk jurisdiction is a finding on its own.
- Anti-bribery programme and third-party due diligence files — FCPA and UK Bribery Act exposure travels with the entity, and agents are where it usually originates.
- Data protection documentation — lawful basis, DPIAs, cross-border transfer mechanisms, retention schedules, and any regulator correspondence.
- Security incident history and penetration test results — including incidents that fell below a disclosure threshold, and the remediation status of critical findings.
- Environmental permits, assessments and remediation obligations — for any owned or long-leased site, together with historical site use.
- Related-party transaction schedule — intercompany balances, management fees, insider loans, and any revenue dependent on an affiliate.
Turning the list into findings
A checklist tells you what to collect. It does not tell you what is in the documents once they arrive, which is where the time actually goes — a mid-market data room routinely runs to thousands of pages, and the first pass is mostly deciding which documents contain anything worth escalating.
That first pass is what automated screening compresses: documents are scored across 15 M&A risk categories, findings are returned with the language that triggered them, and any blocking category scoring 70 or above flags the deal for mandatory human review. Reviewers start with a ranked queue rather than a pile. It structures the screening pass — it does not verify anything independently or replace legal and accounting judgement.
Frequently asked questions
What should be on an M&A due diligence checklist?
At minimum: audited financials and monthly management accounts, an EBITDA bridge with supported adjustments, revenue by customer and contract type, working capital by month, a debt schedule including debt-like items, corporate records and cap table, the top 20 customer and supplier contracts, a litigation schedule, IP register with chain-of-title evidence, an open-source usage report, tax returns and correspondence, employee census and benefit arrangements, sanctions and anti-bribery screening records, data protection documentation, and any environmental obligations.
What is the difference between a due diligence checklist and an information request list?
In practice they are the same document viewed from two sides. The checklist is the buyer's internal view of what must be tested; the information request list is what gets sent to the seller. The useful discipline is to keep them linked, so every requested document has a stated purpose - if you cannot say what a document is being used to test, it is padding the list and slowing the process.
Who prepares the due diligence checklist?
The buy-side deal team assembles it, with input from the specialists running each workstream - accountants for financial and tax, counsel for legal and IP, and technical or environmental advisers as the target requires. In competitive processes sellers increasingly pre-empt it with a vendor due diligence pack assembled against the same standard list.
How do you prioritise a due diligence checklist under time pressure?
Work from what can kill the deal rather than what can reprice it. Ownership of core IP, change-of-control provisions on material revenue, sanctions and bribery exposure, and unreserved litigation all fall into the first category. Working capital and EBITDA adjustments, while they consume the most analyst time, generally move price rather than stopping a transaction.