M&A Due Diligence Red Flags
Not every finding in due diligence is the same kind of problem. This is a workstream-by-workstream list of specific red-flag patterns, from financial and legal through commercial, regulatory, operational, and process signals in how the seller runs the data room itself — organised by which ones typically adjust price and which ones can stop a transaction outright.
How to use this list
Organised by workstream, with each red flag stated as a specific pattern rather than a general worry, and a note on whether it typically reprices a deal or threatens it. Not every red flag ends a transaction — most adjust price or structure — but a handful genuinely stop deals, and knowing which is which changes how urgently a finding should be escalated.
Financial red flags
- Revenue growth outpacing cash collection. Receivables growing faster than revenue over consecutive quarters, often signalling channel stuffing or aggressive recognition.
- Gross margin volatility with no clear driver. Unexplained swings suggest either inconsistent cost allocation or a business less stable than its headline numbers show.
- EBITDA add-backs that recur every year. A cost labelled "one-time" that appears in three consecutive years is not one-time.
- Related-party revenue at above-market terms. Inflates reported margin in a way that will not survive a change of ownership.
- Working capital sharply favourable in the months before sale. Receivables collected unusually hard or payables stretched beyond normal terms right before a process.
- Capex consistently below depreciation. Reported margin sustained by deferred maintenance rather than genuine efficiency.
- Auditor going-concern language, even qualified. A near-automatic escalation regardless of management's explanation.
- Restatement history. Any prior restatement puts every other historical figure in question, not just the one restated.
Legal and contractual red flags
- Change-of-control termination rights on concentrated revenue. The buyer's key asset can walk on completion, and consent is not guaranteed.
- A cluster of small claims of the same type. More indicative of a systemic practice than any single large disclosed claim.
- Litigation threatened but not yet filed, undisclosed. Legally not yet a "proceeding," which is why it is frequently omitted from a standard litigation schedule despite being material.
- Unassigned IP created by contractors. Work product belongs to the contractor absent a written assignment, and this is common enough to check as a default.
- Copyleft open-source components in proprietary code. Can impose obligations on the buyer's own product post-close.
- Cap table entries recorded only in board minutes. Not reflected in the share register, a title defect that is routine and fixable but must be caught before closing, not after.
- Non-transferable licences central to operations. A permit or licence essential to the business that does not survive a change of control.
Commercial red flags
- Top customer above 20% of gross margin (not just revenue — margin concentration is usually worse than revenue concentration suggests).
- Deteriorating cohort retention masked by aggregate growth. Total revenue still rising while each successive customer cohort retains worse than the last.
- Pipeline growth concentrated in the months before sale. Worth testing whether it reflects genuine demand or process-timed sales activity.
- Heavy reliance on a single supplier with no qualified alternative. An operational dependency that a change of ownership does not resolve.
- Sales cycle lengthening without acknowledgment in management's forecast. A leading indicator the forecast has not caught up with.
- Key person dependency with no documented succession. Particularly acute where one individual holds most customer relationships or technical knowledge.
Regulatory and compliance red flags
- Any OFAC or SDN sanctions match. Treated as an absolute finding, not a matter of degree.
- An open or recently resolved bribery investigation. Successor liability can travel with the entity even where the investigation is described as closed.
- Merger control exposure — a second request or a substantive competition concern. Can outlast the buyer's appetite for the deal regardless of the underlying business quality.
- Undisclosed data breach, or one with an unmet notification obligation. The disclosure failure is itself informative about management's governance, independent of the breach.
- Unresolved regulatory enforcement, described as resolved. Ongoing monitoring and operational restrictions frequently outlive the headline resolution — particularly material in regulated sectors; see bank M&A due diligence for how this plays out with banking regulators specifically.
- Missing or stale Data Protection Impact Assessments. A gap in a jurisdiction where they are mandatory signals broader compliance immaturity.
Operational and people red flags
- Contractor relationships with employee-like characteristics. Long-tenured, exclusive, and directed — a misclassification exposure that is frequently unreserved.
- Unfunded or underfunded pension obligations not reflected in the seller's own net debt bridge.
- Executive turnover in risk, compliance, or finance roles without a documented replacement plan, often preceding a disclosed problem rather than following one.
- Unsupported core systems with no disaster recovery testing. An integration cost buyers routinely underestimate, particularly where a core platform contract has unfavourable termination or change-of-control terms.
- Large transaction-triggered payouts to management. Change-of-control and retention agreements that create cost specifically because of the deal, separate from the ongoing cost base.
Red flags in how the process itself is run
Some of the most reliable signals are not in the documents but in how the seller manages the process:
- Information delivered in trickles rather than in complete tranches against the request list.
- Native files replaced with scanned images or PDFs of documents that plainly exist in editable form.
- Requested documents that are never delivered, with no explanation offered.
- Management unavailable or unusually guarded in Q&A sessions on specific topics.
- Unusual urgency around signing disproportionate to any competitive dynamic the buyer can independently verify.
Each has innocent explanations individually. In combination, they usually mean either that the seller is not genuinely ready to sell, or that access is being managed deliberately — and both are worth naming to the deal team early rather than absorbing quietly. See the full due diligence checklist for what should be requested by workstream.
Frequently asked questions
What are the most common red flags in M&A due diligence?
Customer or margin concentration, revenue growth outpacing cash collection, EBITDA add-backs that recur every year rather than being genuinely one-time, change-of-control provisions that let key contracts terminate on the transaction, unresolved litigation clusters, unclear ownership of core intellectual property, and sanctions or bribery exposure. Financial red flags usually adjust price; regulatory and title red flags are more likely to stop a deal.
What red flags actually kill an M&A deal rather than just reprice it?
Unverifiable ownership of core intellectual property, an active sanctions match, an unresolved bribery or corruption investigation, a serious merger control or antitrust concern, and change-of-control rights across the majority of a target's revenue with no realistic path to consent. These share a common feature: the risk is unbounded rather than quantifiable, which is what makes them different from findings that simply move price.
Are red flags in how a data room is managed as important as red flags in the documents?
Often more informative, because they are harder to prepare for. Information delivered in trickles rather than complete tranches, native files replaced with scanned PDFs, requested documents never delivered, and management unusually guarded on specific topics each have innocent explanations alone, but in combination they typically indicate either the seller is not genuinely ready or access is being managed deliberately.
Should every red flag be escalated the same way?
No. Quantifiable financial findings should be documented and priced into the adjustment. Unbounded or qualitative findings - regulatory exposure, title defects, sanctions matches - should be escalated immediately to deal leadership rather than held for the final findings register, because they may change whether the deal proceeds at all, not just its price.