M&A Due Diligence: The Complete Guide
M&A due diligence is the investigation a buyer runs on a target company before completing an acquisition. It tests whether the earnings are real, whether the liabilities are disclosed, whether the contracts survive a change of control, and whether anything in the target's history becomes the buyer's problem after closing. This guide covers the full process, a workstream checklist, the financial analyses that drive most valuation adjustments, and what happens to findings once diligence closes.
What is M&A due diligence?
M&A due diligence is the investigation a buyer runs on a target company between signing a letter of intent and completing an acquisition. Its purpose is to test the assumptions the offer was built on: that the earnings are real and repeatable, that the liabilities are disclosed, that the contracts survive a change of control, and that nothing in the target's history will become the buyer's problem after closing.
It is not an audit. An audit gives an opinion on whether financial statements are fairly stated. Diligence asks a different question — whether this business is worth the price on these terms — and ranges far beyond the financial statements into contracts, litigation, tax, technology, people and regulatory standing.
Buyer and seller perspectives
The buyer is looking for reasons to reduce the price, restructure the deal, or walk. The seller is managing disclosure: obligated to be truthful, not obligated to volunteer everything, and increasingly likely to run sell-side diligence first so that problems are found and framed on the seller's terms rather than discovered by the buyer.
Where it sits in the deal
Diligence normally begins after a non-binding letter of intent establishes price and exclusivity, and runs until the definitive agreement is signed. That sequence matters: the buyer has already named a number before knowing what it is buying, so most diligence findings arrive as arguments to revise a price that is already on the table.
Why due diligence matters
The economics are asymmetric. Diligence costs a fraction of the transaction value; a missed liability can exceed it. Five categories of problem account for most of the damage.
- Earnings that do not repeat. One-time gains, related-party revenue, deferred maintenance and under-investment all inflate the number a multiple is applied to. A single point of EBITDA overstatement is multiplied by the whole valuation multiple.
- Undisclosed or under-reserved liabilities. Litigation, tax exposure, environmental remediation, employment claims and warranty obligations that arrive after closing.
- Contracts that do not survive. Change-of-control provisions can terminate the customer contracts, licences or leases the acquisition was actually for.
- Concentration. A business where one customer is 40% of revenue is a different asset from one where the top ten are 40%, at the same EBITDA.
- Regulatory and compliance exposure. Sanctions, bribery, data protection and merger-control issues can delay closing, impose penalties, or make the transaction unapprovable.
The M&A due diligence process
A typical buy-side process, in order. Steps 4 through 9 run in parallel rather than in sequence.
- Letter of intent and exclusivity. Price, structure and an exclusivity window that sets the diligence clock.
- Scoping and team assembly. Deal team, accountants, counsel, and specialists for tax, technology, environmental or regulatory work as the target requires.
- Information request list. Issued to the seller, organised by workstream. Its quality determines the quality of everything downstream.
- Data room opens. The seller populates a virtual data room; the buyer's team is granted role-based access.
- Financial diligence. Quality of earnings, working capital, net debt, revenue recognition.
- Legal diligence. Corporate records, material contracts, litigation, IP ownership, employment.
- Commercial diligence. Market position, customer concentration, pipeline, competitive dynamics.
- Tax, technology, operational and regulatory diligence. Run concurrently by specialists.
- Management presentations and Q&A. Where documentary gaps get tested against the people who ran the business.
- Site visits. Facilities, inventory condition, and the difference between the reported operation and the observed one.
- Findings consolidation. Workstream outputs are ranked by materiality into a single red-flag register.
- Valuation and structure adjustment. Findings become price reductions, escrow, earn-outs, specific indemnities or representations and warranties insurance.
- Definitive agreement negotiation. Diligence findings drive the disclosure schedules and the indemnity package.
- Investment committee or board approval, then signing and closing.
M&A due diligence checklist
| Workstream | What to review | Example red flags |
|---|---|---|
| Financial | Quality of earnings, working capital, net debt, revenue recognition, forecasts | Going-concern language, material weakness, restatement history |
| Legal & merger control | Corporate records, material contracts, litigation, antitrust review status | Change-of-control termination rights; a second request |
| Tax | Returns, audits, transfer pricing, payroll and indirect tax | Unresolved assessments; aggressive transfer-pricing positions |
| Commercial & operational | Customer concentration, supplier dependency, pipeline, key personnel | Single-customer concentration; single-source supply |
| HR & labour | Employment terms, benefits, disputes, works councils, contractor classification | Wage-and-hour exposure; forced-labour indicators in the supply chain |
| IP & licensing | Ownership chain, assignments, open-source usage, infringement claims | Unassigned core IP; copyleft contamination of the product |
| Technology & AI governance | Architecture, technical debt, model and vendor dependency, training-data provenance | Unverifiable training-data chain of custody; EU AI Act classification gaps |
| Cybersecurity | Incident history, controls, penetration testing, vendor exposure | Undisclosed breach; unremediated critical findings |
| Data privacy | Lawful basis, DPIAs, cross-border transfers, retention, enforcement history | Regulator enforcement notice; missing DPIAs |
| Sanctions, AML & bribery | Counterparty screening, FCPA exposure, third-party intermediaries | OFAC/SDN exposure; unresolved FCPA investigation |
| ESG & environmental | Permits, contamination, remediation obligations, reporting | Remediation order; Superfund exposure |
| Related party | Intercompany transactions, management fees, insider loans | Revenue dependent on related parties |
Financial due diligence in depth
This is where most valuation adjustments originate, and where a general checklist is least useful. Four analyses do the work.
Quality of earnings
A QoE analysis rebuilds reported EBITDA into a number that reflects the business a buyer is actually acquiring. Typical adjustments remove one-time gains and losses, normalise owner compensation to market, add back genuinely non-recurring costs, strip out related-party revenue on non-market terms, and correct for revenue recognised early or costs deferred late. The output — adjusted or normalised EBITDA — is what the multiple is applied to, which is why a single adjustment is magnified by the whole multiple.
Net working capital
Deals are usually done on a cash-free, debt-free basis with a normalised working capital target. Setting that target is contested precisely because it moves cash at closing: the buyer wants a target high enough that the business is delivered funded, the seller wants it low. The analysis needs twelve to twenty-four months of monthly data to expose seasonality, and it should test whether recent working capital has been managed — receivables collected hard, payables stretched — specifically to flatter the pre-sale period.
Net debt and debt-like items
Beyond borrowings sit items that behave like debt without being labelled as such: unfunded pension obligations, deferred and contingent consideration from prior acquisitions, capitalised leases, accrued but unpaid bonuses, unremitted tax, customer deposits and deferred revenue where the cost of delivery has not been incurred. Each is a claim on the business the buyer will fund after closing.
Revenue quality and concentration
Test whether revenue is contracted or transactional, recurring or one-time, and how it is distributed. Customer concentration is the single most common commercial red flag: examine the top ten customers by revenue and by margin, their contract terms, their renewal history, and whether any of them has change-of-control termination rights — because a concentrated customer with an exit right is a valuation issue and a deal risk at the same time.
Legal due diligence in depth
Legal diligence answers three questions: can the buyer actually acquire what it thinks it is acquiring, does anything terminate on the transaction, and what is already owed to someone else.
Title and corporate housekeeping
Start with whether the shares being sold exist and belong to the sellers. Cap tables in founder-led businesses are frequently wrong in the same specific ways: options granted informally and never documented, share transfers recorded in board minutes but never in the register, convertible instruments whose conversion mechanics were never modelled, and departed founders whose claims were settled by conversation rather than deed. None of these is exotic, and each is capable of delaying a signing.
Change-of-control provisions
This is where legal diligence most directly touches valuation. A change-of-control clause lets a counterparty terminate, renegotiate or demand consent when the company is sold. The clauses that matter most sit in the contracts the acquisition was actually for: the anchor customer agreements, the licence to the technology the product depends on, the premises lease, the bank facilities. A business whose top three customers can each walk on completion is worth materially less than the same business on assignable terms, and the discovery is binary rather than gradual.
Litigation and contingent exposure
Read the litigation schedule against the reserve. The pattern worth looking for is not a large disclosed claim — those are priced — but a cluster of small matters of the same type, which usually indicates a systemic practice rather than a series of accidents. Employment claims, customer disputes over the same contract term, and repeat regulatory complaints all read that way. Ask specifically for matters threatened but not filed; they are frequently omitted because they are not yet formally proceedings.
Intellectual property ownership
The failure mode here is chain of title. Code written by contractors without a written assignment belongs to the contractors. Employee-created IP in some jurisdictions requires an express assignment rather than vesting automatically. Open-source components under copyleft licences can impose obligations on proprietary code that incorporates them, which is a live issue where a product was assembled quickly. For a technology target, unverifiable ownership of the core product is one of the few findings that genuinely stops a transaction rather than repricing it. See IP & licensing screening.
Commercial due diligence in depth
Financial diligence establishes what the business earned. Commercial diligence asks whether it will keep earning it.
Customer concentration, properly measured
Concentration is usually reported by revenue, which understates it. Measure it three ways: by revenue, by gross margin, and by contribution to growth. A customer at 12% of revenue but 30% of gross margin is a bigger exposure than the headline suggests. Then overlay contract term and change-of-control rights, because concentration plus an exit right is a different risk from concentration alone.
Cohort behaviour and churn
Aggregate retention hides the thing you want to know. Split customers into cohorts by the period they were acquired and track each cohort's revenue over time. Healthy businesses show older cohorts flat or expanding; deteriorating ones show each successive cohort retaining worse than the last, which aggregate churn masks entirely while total revenue is still growing. Gross and net revenue retention should be presented separately — net retention flattered by expansion within a shrinking customer count is a specific and common misdirection.
Pipeline quality
Test the forecast against conversion history rather than against management's confidence. Useful measures: win rate by stage over eight quarters, average sales cycle and whether it is lengthening, the share of pipeline created in the last quarter versus carried forward, and how much of the forecast depends on a small number of large opportunities. Pipeline that grew sharply in the months before a sale process warrants particular attention.
Market position
Where practical, talk to customers. Referenced calls arranged by the seller have obvious limits, but even a constrained set will surface whether the product is embedded or replaceable, whether pricing has held, and whether the competitive story management tells matches what buyers of the product actually believe. Win/loss data, where it exists, is more informative than any market-sizing exercise.
Red flags: what reprices, what kills
Not every finding is the same kind of problem. The useful distinction is between findings that adjust a number and findings that remove the basis for the transaction.
Findings that usually reprice
- EBITDA adjustments — one-time items treated as recurring, owner compensation below market, related-party revenue on non-market terms. Quantifiable, and deducted at the multiple.
- Working capital shortfall against a normalised target — moves cash at closing rather than changing the deal.
- Debt-like items omitted from the seller's bridge — pension deficits, deferred consideration, accrued bonuses, unremitted tax.
- Deferred capex — reported margin supported by under-investment, corrected by a forward spend assumption.
- Quantified tax exposure — an assessment or a documented position, typically handled by indemnity or escrow.
Findings that can end a transaction
- Unverifiable ownership of core IP — the buyer cannot acquire what the seller does not own, and this is rarely fixable inside a deal timetable.
- Sanctions exposure or an open bribery investigation — successor liability travels with the entity, exposure is unbounded until resolved, and it can make approval unobtainable. See sanctions & AML screening.
- Change-of-control rights across concentrated revenue — where the asset being bought can walk on completion and consent is not forthcoming.
- Systemic revenue recognition problems — not a timing difference but a practice, which puts every historical number in question.
- Undisclosed material breach — particularly with unmet notification obligations, because the liability is unquantified and the disclosure failure is itself informative about management.
- Merger control exposure — a second request or a serious substantive concern can outlast the buyer's appetite regardless of the underlying business.
The pattern worth noticing. Financial findings are usually quantifiable and therefore priceable. Regulatory, compliance and title findings are frequently unbounded, and unbounded risk is what buyers walk away from. This is why screening for the second category early — before the expensive financial work — is a sequencing decision rather than a thoroughness one.
How long it takes and what it costs
Ranges vary widely by deal size and complexity, but the shape is consistent.
| Deal size | Typical diligence period | What usually drives the timeline |
|---|---|---|
| Small (under $10m) | 3–6 weeks | Seller record quality; owner-manager availability |
| Mid-market ($10m–$250m) | 6–12 weeks | QoE depth, multi-jurisdiction tax, contract volume |
| Large / regulated | 3–9 months | Merger control, sector regulator approval, second requests |
Cost scales with scope rather than deal value, and third-party fees — accountants for QoE, counsel for legal, specialists for environmental or technology — dominate. The variable that most reliably extends both timeline and cost is the quality of the seller's own records: a poorly organised data room converts a six-week process into a twelve-week one without changing the underlying business at all.
The data room, and what it tells you
A virtual data room is where diligence physically happens, and its condition is itself evidence.
What a good data room looks like
Indexed by workstream, consistently named, complete versions rather than extracts, with a maintained Q&A log so answers are visible to the whole buy-side team rather than trapped in individual email threads. Documents dated and superseded versions removed.
What a poor one signals
Scanned images of documents that exist natively in digital form, contracts uploaded without their schedules and amendments, financial data supplied as PDF rather than workbook, and material added in trickles rather than tranches. Each of these has an innocent explanation and each also extends the timeline; in combination they usually mean either that the seller is not ready or that access is being managed deliberately. Both are worth naming early rather than absorbing quietly.
Practical points
- Ask for native file formats. A financial model as a workbook is diligence; the same model as a PDF is a presentation.
- Track what was requested and never delivered. The gap between the request list and the room contents is a finding in its own right, and it is easy to lose track of under time pressure.
- Use the Q&A log as evidence. Answers given in the room become part of the disclosure record and inform the representations later negotiated.
- Control access by role. Clean-team arrangements matter where the buyer is a competitor and the material is commercially sensitive — see deal rooms and clean-team access.
Who performs due diligence: buy-side and sell-side
Buy-side
Run by or for the acquirer. A corporate development team or private equity deal team coordinates, with accountants on QoE and tax, counsel on legal, and specialists as needed. The output is a findings register that feeds price, structure and the indemnity package.
Sell-side (vendor) diligence
Commissioned by the seller before going to market. The seller finds its own problems first, fixes what it can, and prepares a defensible position on the rest. It compresses the buyer's timeline, reduces the number of surprises that justify a price reduction, and is increasingly standard in competitive processes. It does not replace buy-side work — a buyer relying solely on a seller-commissioned report has misunderstood who the report was written for.
How diligence changes by deal type
The workstreams are constant; the emphasis is not.
| Deal type | Where the emphasis goes | Most common failure |
|---|---|---|
| Strategic acquisition | Integration cost, customer overlap, cultural and systems fit, merger control | Synergies assumed in the price that diligence never tested |
| Private equity platform | Quality of earnings, management depth, growth runway, exit optionality | Management team assessed as adequate for the current business rather than the plan |
| Bolt-on to an existing platform | Systems and process compatibility, customer overlap, contract assignability | Integration complexity underestimated because the target is small |
| Carve-out from a larger group | Standalone cost base, shared services and TSA scope, contract novation | Stranded costs and TSA duration priced optimistically |
| Distressed acquisition | Liquidity runway, creditor position, employee and pension liabilities, title | Compressed timeline used to justify skipping title and liability work |
| Cross-border | Tax structure, employment law, FX and repatriation, sanctions and local licensing | Home-jurisdiction assumptions applied to local employment and tax rules |
Carve-outs deserve particular care because the target does not yet exist as a standalone business. Historical financials reflect a cost base subsidised by the parent, and the diligence question is what the business costs to run alone — a genuinely different exercise from validating reported numbers.
Common mistakes
- Starting the expensive work first. Quality of earnings is the most costly workstream and rarely the one that ends a deal. Screening for title, sanctions and change-of-control exposure early costs little and occasionally saves the entire budget.
- Treating a clean audit as a clean bill of health. An audit opines on whether statements are fairly stated under a framework. It says nothing about customer concentration, contract assignability or IP ownership.
- Accepting vendor diligence as a substitute. Sell-side reports are competent and useful, and they were commissioned by the other side. They compress the timeline; they do not discharge the buyer's own work.
- Confusing findings with a register. Twelve workstreams each producing a document is not a diligence output. Findings have to be consolidated and ranked by materiality, or the investment committee receives volume instead of a view.
- Letting exclusivity expire before the hard questions. Sequence the findings most likely to be deal-breaking into the first half of the window, while there is still leverage to negotiate on them.
- Ignoring what was not disclosed. An empty category is not a clean category. Absence of documentation in an area where documentation should exist is a finding, and it is the one most often lost in a large data room.
- Diligencing the business and not the transaction. Change-of-control provisions, consent requirements, regulatory approvals and transaction-triggered payments are risks created by the deal itself rather than found in the business, and they are routinely under-examined.
How AI is changing M&A due diligence
The bottleneck in diligence has never been analysis. It is reading. A mid-market data room routinely holds thousands of pages, and the first pass — deciding which documents contain something worth escalating — consumes analyst time disproportionate to its difficulty.
That first pass is what document screening automates. The workflow changes from read everything, then decide what matters to score everything, then read what scored. Documents are scored across risk categories, findings are surfaced with the quoted language that triggered them, and reviewers start with a ranked queue instead of a pile.
What this does not do. Automated screening does not verify anything independently, does not conduct primary research, does not interview management, and does not replace legal or accounting judgement. It structures and accelerates the initial screening pass. Treating a risk score as a diligence conclusion is a category error — the score tells you where to look, not what to think.
Anweshna scores documents across 15 M&A risk categories plus 8 banking-specific categories, applies a hard threshold so that any blocking category scoring 70 or above flags the deal for mandatory human review, and returns the finding with the language that produced it. For regulated targets there is a dedicated bank M&A ruleset built around examiner thresholds rather than general corporate ones.
What happens after diligence
Findings convert into deal terms through four mechanisms, roughly in order of how often they are used:
- Price adjustment. A quantified finding — an EBITDA adjustment, a working capital shortfall, a tax exposure — is deducted directly.
- Structural protection. Escrow or holdback for contingent items; an earn-out where the disagreement is about future performance rather than past facts.
- Specific indemnity. For identified, unquantified risks such as pending litigation, with its own cap and survival period distinct from the general indemnity.
- Conditions and covenants. Remediation required before closing, or a closing condition tied to a specific consent or approval.
Representations and warranties insurance increasingly sits alongside these, particularly in competitive processes, transferring the general indemnity risk to an insurer. Underwriters price on the quality of the diligence performed — a thin process produces broader exclusions, so diligence rigour affects the insurance outcome as well as the price.
The remaining case is walking away. It is the least common outcome and the most valuable one when a finding is genuinely unpriceable: an unresolved bribery investigation, unverifiable IP ownership in the core product, or a regulatory position that makes approval unlikely.
Frequently asked questions
What is M&A due diligence?
M&A due diligence is the investigation a buyer runs on a target company between signing a letter of intent and completing an acquisition. It tests whether the earnings are real and repeatable, whether liabilities are fully disclosed, whether contracts survive a change of control, and whether anything in the target's history will become the buyer's problem after closing. It covers financial, legal, tax, commercial, operational, HR, IP, technology, cybersecurity, data privacy, regulatory and ESG workstreams.
How long does M&A due diligence take?
For a small transaction under $10m, typically three to six weeks. For mid-market deals between $10m and $250m, six to twelve weeks. For large or regulated transactions, three to nine months, driven mainly by merger control and sector regulator approval rather than by the commercial work. The single biggest variable is the quality of the seller's records - a poorly organised data room can double the timeline without changing the underlying business.
What is the difference between due diligence and an audit?
An audit gives an opinion on whether financial statements are fairly stated according to an accounting framework. Due diligence asks whether a business is worth a specific price on specific terms, and extends well beyond the financial statements into contracts, litigation, tax, technology, people and regulatory standing. A clean audit opinion does not mean a target will survive diligence.
What is a quality of earnings analysis?
A quality of earnings analysis rebuilds reported EBITDA into a number reflecting the business a buyer is actually acquiring. It removes one-time gains and losses, normalises owner compensation to market rates, adds back genuinely non-recurring costs, strips out related-party revenue on non-market terms, and corrects revenue recognised early or costs deferred late. The resulting adjusted EBITDA is what the valuation multiple is applied to, so each adjustment is magnified by the full multiple.
What are the most common red flags in M&A due diligence?
Customer concentration, revenue that is not repeatable, change-of-control provisions that let key contracts terminate on the transaction, undisclosed or under-reserved litigation and tax exposure, unclear ownership of core intellectual property, unreported cybersecurity incidents, and sanctions or bribery exposure. Financial red flags usually reprice a deal; regulatory and compliance red flags are more likely to stop one.
What is the difference between buy-side and sell-side due diligence?
Buy-side diligence is run by or for the acquirer, and its output feeds price, deal structure and the indemnity package. Sell-side or vendor diligence is commissioned by the seller before going to market so that problems are found and framed on the seller's terms. Sell-side work compresses the buyer's timeline but does not replace buy-side diligence - a buyer relying solely on a seller-commissioned report has misunderstood who it was written for.
Can AI do M&A due diligence?
AI can automate the first pass - screening large document sets to identify which contain material risk signals, and surfacing findings with the language that triggered them. It does not verify anything independently, conduct primary research, interview management, or replace legal and accounting judgement. The appropriate use is to structure and accelerate initial screening so reviewers start with a ranked queue rather than an undifferentiated pile of documents.
Sources
Primary sources for the statutory figures cited on this page. Thresholds and timelines change — verify current requirements with the relevant agency before relying on them.
- Hart-Scott-Rodino Antitrust Improvements Act, 15 U.S.C. § 18a — premerger notification to the Federal Trade Commission and the Antitrust Division of the Department of Justice, the statutory waiting period, and the effect of a request for additional information (a “second request”) on that period.