Skip to content
CorpDev Wiki
8 min read

Due Diligence in M&A

Due diligence tests whether the investment case holds and what must change before you commit. A full data room, a completed request list, or a stack of adviser reports does not prove that the right questions were answered.

Start from the few assumptions that drive value, downside, and your ability to deliver the plan, and design the workstreams to test them. Every important finding must end in a decision: revise the case, change the terms, fund an operating action, have the right person accept the risk, or stop.

Explore the illustration Select an element to go deeper

Turn the thesis into questions evidence can answer

Write down the assumptions the deal depends on before you expand the request list. For each one, name the evidence that would support it, the evidence that would disprove it, and the decision it affects. The table shows five common starting points.

Assumption Evidence to request What a finding changes
Revenue will last Customer-level history, contracts, renewal cohorts, reasons for churn, and independently checked customer evidence Forecast, concentration downside, price, or a customer action plan
Reported earnings reflect the real economics Reconciliation from the ledger to management accounts, adjustments, cash conversion, and recurring costs Earnings baseline, valuation, and funding needs
The product can do what we need Architecture, demonstrations, roadmap, deployment limits, and a technical assessment Build-versus-buy choice, integration design, and time to value
Key people and rights will be available Who the business depends on, ownership records, relevant agreements, and counsel's analysis Retention plan, terms, structure, or a decision to stop
Promised benefits can be delivered Baselines, named owners, operating dependencies, costed initiatives, and delivery evidence Benefit timing, integration budget, and value to the buyer

These are starting questions, not a standard scope. The target's business model, geography, structure, and the reason you are buying it decide what else matters.

Give each workstream a decision to support

Appoint an internal lead for each workstream who owns its conclusion, even when advisers do the analysis. Define the scope, exclusions, critical questions, evidence standard, dependencies, and required output.

Each workstream has its own job:

  • Financial: connect revenue and earnings quality to cash flow, working capital, debt-like items, and required investment.
  • Commercial: test customers, competition, positioning, and the assumptions behind the forecast.
  • Legal, tax, people, technology, security, and operations: cover their own exposures and how those affect ownership and delivery.

Findings rarely stay in one workstream. If a contract issue changes retention risk, the commercial and finance leads must see it. If a security fix delays product deployment, technology, integration, and finance must agree on the consequence. The deal lead owns joining these conclusions up.

Ask first for the evidence that could stop the deal

Put first the questions that could invalidate the thesis or that take longest to answer. A deal with uncertain IP ownership needs that work before an elaborate cross-sell model. A carve-out with unknown standalone costs needs separation analysis before anyone trusts the earnings multiple.

Keep a request register. For each request, record the question, why it matters, the owner, the evidence requested, priority, due date, where the response is filed, and whether it is sufficient. An upload marked "received" has not answered the question.

Stage access to sensitive information. Counsel sets the protocol, who may see what, and any limits on outputs. Deals between competitors may need a clean team: a small group allowed to see competitively sensitive data under strict rules. The FTC highlights controls that prevent sensitive information from being shared or misused during diligence and planning. FTC guidance.

Judge how reliable the evidence is

For each important conclusion, keep the source, period, population covered, reconciliation, and limits. Separate four kinds of evidence: what management says, analyses the target prepared, third-party evidence, and facts you confirmed independently.

In practice:

  • A customer sample should say how customers were chosen and who is missing.
  • A forecast review should connect to historical cohorts and real operating drivers.
  • A product demonstration should separate what runs in production from roadmap or prototype.
  • A quality-of-earnings adjustment should show its support and what it means for future cash costs.

When evidence is incomplete, say what cannot be concluded and which decision depends on it. "No issue identified" misleads if nobody examined the relevant population.

Measure how much revenue survives a change of control

Clauses that require a customer's consent, or let the customer walk away, when the supplier changes owner are a standard diligence finding. They often arrive as a legal list of contracts containing such clauses. That list does not tell finance whether a small or a large share of revenue is at risk, or tell the commercial team which customers to call first. The answer needs two sources that sit in different folders and different workstreams: the contracts and the customer revenue schedule.

The work joins them. Build a matrix with one row per customer, one column per contract question, and each customer's revenue alongside. A legal list becomes a number that the valuation, the negotiation, and the customer plan can all use.

A hypothetical example:

Customer Revenue, last 12 months ($m) On change of control Can end for convenience? Source
Customer 1 8.2 Consent required No Master agreement §14.2, p. 11
Customer 2 5.6 May terminate Yes, on 90 days' notice Order form §9, p. 3
Customer 3 4.9 Not found No Master agreement, full text
Customer 4 3.1 No contract No contract Revenue schedule only
Top four customers 21.8

In this example, $13.8 million of the $21.8 million sits in contracts with a consent or termination right, and $3.1 million has no contract to review.

The totals change three pieces of work. Finance can run a downside case on the revenue that needs consent. Counsel can decide which consents to seek before signing and which to make a closing condition. The commercial team gets a call list ranked by revenue.

The check that matters is every "not found." Have a person reread those contracts, because a missed clause looks exactly like a clean contract. Also spot-check a sample of the contracts marked clean, and keep the list of contracts reviewed so a partly extracted file cannot pass as full coverage. Whoever reads the contracts, and any tool reading for them, gets only the documents the clean-team rules allow. The legal workstream lead owns the conclusion.

In CorpDev.Ai

Upload the contracts and the revenue workbook to AI Room. Ask the Analyst your change-of-control and termination questions across the contracts folder. It returns a table you can check against each contract, with the revenue at risk totaled.

AI Room · AI Analyst

Turn each finding into an action

Use one finding card for each important issue:

  • What we found: what the evidence shows, with source and date.
  • Confidence: what remains uncertain, and why.
  • Effect on the deal: on value, downside, timing, or ability to deliver.
  • Recommendation: reprice, restructure, fix, seek a specific contract protection, accept, investigate further, or stop.
  • Where it shows up: the forecast line, contract term, or operating plan that reflects it.
  • Owner and authority: who resolves it and who can accept what remains.
  • Proof of completion: what will show that the agreed action happened.

A contract protection shifts who pays for a problem; it does not fix the problem. Ask counsel what a proposed remedy covers and how it would work in practice, and ask finance what the economic case looks like after it.

When a finding touches contracts, products, sites, people, and systems at once, a company digital twin can keep the evidence that links it to the operations affected. Use it to trace dependencies; specialists still judge the consequence.

Follow each finding into every function it touches

Take a hypothetical software target whose largest customer has a major renewal pending. Commercial diligence finds that the renewal depends on a product feature. Engineering finds the feature needs substantial work. Finance puts a cost and a delay on it.

Filed as "customer concentration," this finding would understate the problem. It changes the revenue forecast, the product roadmap, engineering capacity, and possibly how the price is paid. A sound recommendation shows those linked effects and the evidence still needed. It never leaves the original revenue case untouched while the issue sits in a red appendix.

Label any numbers or timing in the scenario as assumptions, support them where possible, and test the downside. Do not apply generic churn or synergy benchmarks to a business before establishing that it is comparable.

Run reviews around open decisions

Ask workstream leads to report important new evidence, changes to earlier conclusions, dependencies on other workstreams, and decisions needed. Keep request tracking out of these meetings.

Escalate a finding as soon as it threatens the thesis, exceeds the tolerance leadership delegated, needs an executive tradeoff, or cannot be resolved before a commitment. Never hold it for the final report. Keep disagreements between specialists and management on record, with the basis for each view.

Settle every finding before signing, then hand over

Before the signing recommendation, trace every important finding to what was decided about it. Confirm that finance reflected the effects, counsel addressed the agreed legal responses, and operating owners accepted funded actions. List the unresolved matters and who is accepting them.

At closing, hand retained risks, remediation plans, evidence, contract deadlines, and benefit dependencies to named owners. Review progress in the operating forum that receives them. Diligence earns its cost when its conclusions change decisions and execution, not when the reports are delivered.

Continue with issue and risk management, negotiation, and post-merger integration.