What due diligence actually tests
Due diligence is, at its core, a verification exercise. A counterparty, whether an investor's legal team, an enterprise procurement function, or an acquirer's advisers, compiles a list of representations the target company has made or implied, then requests documentary evidence for each. The exercise is adversarial in a narrow, procedural sense: the reviewer's professional obligation is to find what does not hold up, not to give the company the benefit of the doubt. A founder who understands this distinction stops treating diligence questions as an inconvenience and starts treating them as a predictable, preparable examination.
The domains examined are consistent across most transactions, though the depth varies with transaction size and counterparty sophistication. Corporate diligence examines incorporation history, share issuances, board authority and statutory compliance. Commercial diligence examines the customer and supplier contracts that generate and consume the company's revenue. Financial diligence examines the accounts, management information and the assumptions behind any forecast. Employment diligence examines who works for the company, under what terms, and whether those terms match reality. Data protection diligence examines what personal data the company processes and on what lawful basis. Intellectual property diligence examines who actually owns the assets the company's value depends upon.
Each domain has a distinct failure mode. Corporate diligence fails when the share register does not match what the company believes its ownership to be. Commercial diligence fails when a material contract turns out to be terminable, or its most valuable customer relationship turns out to rest on an expired agreement never formally renewed. Financial diligence fails when management accounts cannot be reconciled to statutory filings. Employment diligence fails when a long-standing contractor looks, on the facts, like an employee. Data protection diligence fails when the company cannot demonstrate a lawful basis for processing the personal data its business model depends upon. None of these failures are exotic; they are the ordinary consequence of a growing company prioritising commercial momentum over documentary hygiene.
It is worth being clear about what diligence is not. It is not an audit in the formal accounting sense, though financial diligence draws on similar techniques. It is not a legal opinion on the company's prospects. It is a structured attempt to identify risk that the counterparty would otherwise be assuming unknowingly, whether that risk affects valuation, contractual terms, warranty and indemnity negotiations, or, in the enterprise vendor context, whether the counterparty is willing to transact at all. Understood this way, the purpose of preparation is not to eliminate every risk, which is rarely possible, but to ensure risks are identified, disclosed and quantified by the company on its own terms rather than discovered unexpectedly by the reviewer.
The consequence of poor preparation is rarely an outright collapse of the transaction, though that does happen. More commonly it is delay, renegotiated terms, additional warranties and indemnities extracted in the company's favour or against it, and a materially weakened negotiating position at precisely the point value is being determined. A company that arrives with an orderly, well-evidenced record negotiates from a position where the counterparty's questions are answered rather than investigated, and that difference in posture is worth more, in practical terms, than almost any other preparation a founder can undertake.
Corporate diligence: cap table, registers and authority
Corporate diligence begins with the company's incorporation documents, its articles of association, and every subsequent amendment, and traces forward through every share allotment, transfer, option grant and conversion to establish a complete and internally consistent capitalisation history. The most common finding at this stage is a cap table maintained on a spreadsheet that does not match the register of members, which does not match what Companies House holds on public record. Each of these three sources should tell the same story; when they diverge, the reviewer's task becomes reconciling the divergence rather than confirming the ownership, and that reconciliation is the company's cost to bear.
Reconciliation typically uncovers a familiar set of issues: shares issued to an early collaborator that were never formally allotted through a board resolution; a founder share transfer agreed informally and never reflected in the statutory registers; convertible instruments or advance subscription agreements whose conversion terms were never modelled against the fully diluted cap table; and share options granted under an informal understanding that was never documented through a proper scheme or individual option agreement. None of these issues are necessarily fatal to a transaction, but each requires correction, and correction takes time that a live transaction timetable rarely accommodates gracefully.
Authority is the second recurring theme. Diligence reviewers check not only that a decision was taken but that it was taken by the right people with the right authority under the articles of association and any shareholders' agreement. A share allotment approved by a sole director where the articles require board consensus, or a decision taken without the consent rights of a preference shareholder being properly considered, creates a defect that can, in principle, be challenged later. Board minutes and written resolutions are the primary evidence that authority was properly exercised, and their absence is one of the most consistent gaps found in early-stage companies moving toward institutional investment.
The persons with significant control register receives close attention in any transaction involving new investment, because incoming investors and their advisers need an accurate, current picture of who controls the company both before and after the transaction completes. Layered ownership, whether through founder holding vehicles, family trusts, or existing investor entities, must be traced correctly, and any historic misstatement should be identified and corrected before it is found by the counterparty's advisers, since a discovered error late in a process reads very differently to a proactively corrected one identified early.
Finally, statutory filing history is checked for consistency and timeliness: confirmation statements filed on time and matching the underlying registers, accounts filed within statutory deadlines, and any historic late filings or Companies House queries explained rather than left unaddressed. A pattern of late or corrected filings does not usually derail a transaction on its own, but it is read as a proxy for the general standard of administrative discipline within the company, and it shapes how carefully the reviewer scrutinises everything else.
| Finding | Underlying cause | Typical resolution |
|---|---|---|
| Cap table does not match register of members | Transfers or allotments recorded informally, not reflected in statutory registers | Reconcile all sources, file corrective notifications, update registers |
| Share options granted without formal documentation | Informal founder understanding never converted into a scheme or agreement | Retrospective documentation where accurate, or formal grant going forward |
| PSC register does not reflect layered ownership | Trust or holding-company structure not traced to the correct natural person | Obtain constitutional documents, re-determine PSC status, file corrections |
| Missing board minutes for reserved matters | Decisions taken informally without contemporaneous record | Written confirmatory resolutions where accurate; process change going forward |
| Late or inconsistent confirmation statements | Registers not updated continuously through the year | File outstanding corrections; assign ongoing ownership of registers |
Commercial diligence: contracts, concentration and change of control
Commercial diligence examines the contracts that generate the company's revenue and the contracts that expose it to obligation, and it is here that many companies discover, often for the first time in a structured way, exactly how their commercial arrangements were actually documented rather than how they are remembered. The reviewer typically requests every material customer contract, every material supplier and vendor agreement, and any partnership, licensing or reseller arrangement, then assesses term length, renewal mechanics, termination rights, liability caps and, critically, assignment and change-of-control provisions.
Change-of-control clauses deserve particular attention because they are frequently overlooked at the point a contract is signed and become materially significant only when a transaction is contemplated. A clause permitting a customer or supplier to terminate, renegotiate, or require consent upon a change in the company's ownership can directly affect transaction value if a material contract falls within its scope, and if that risk is discovered late, it can require last-minute consent requests to counterparties who now have leverage they did not previously exercise. Reviewing these clauses proactively, well before any transaction is contemplated, allows a company to renegotiate unfavourable terms from a position of ordinary commercial discussion rather than transactional urgency.
Customer concentration is examined closely, because a business whose revenue depends heavily on a small number of counterparties carries a different risk profile than one with a diversified base, and the underlying contracts for those key relationships receive disproportionate scrutiny. A reviewer will typically want to understand contract length, renewal history, any history of disputes or service credits, and whether the relationship rests on a signed agreement at all or has drifted into informal, purchase-order-based trading that lacks the protections a formal contract would provide.
Assignment provisions matter for a related but distinct reason: many corporate transactions are structured as a share sale, which does not usually trigger assignment restrictions because the contracting entity does not change, but some are structured, or later restructured, as an asset transfer or through a new holding company being interposed, either of which can trigger assignment consent requirements buried in supplier or customer terms that nobody has reviewed since the contract was signed. Understanding, before a transaction is structured, which contracts contain assignment restrictions materially affects how the transaction itself should be designed.
Supplier and vendor dependency is reviewed with similar rigour, particularly for any supplier whose service is operationally critical, such as core infrastructure, payment processing, or a key data provider. The reviewer wants evidence that these relationships rest on properly negotiated agreements with appropriate service levels and liability provisions, rather than informal arrangements that leave the company exposed if the supplier's terms change unilaterally or the relationship ends abruptly.
Financial diligence: accounts, management information and forecasting integrity
Financial diligence establishes whether the numbers a company presents to a counterparty can be reconciled to its statutory accounts, its management information systems, and, where relevant, HMRC filings, and whether any forecast presented rests on assumptions that a reviewer can trace back to underlying evidence. The starting point is almost always the statutory accounts filed at Companies House, cross-referenced against management accounts produced internally, since a persistent or unexplained divergence between the two is one of the fastest ways to introduce doubt into a process that otherwise rests on trust.
Revenue recognition receives close attention, particularly for subscription or contract-based businesses where the timing of recognised revenue can differ materially from cash received, and a reviewer will want to understand the accounting policy applied and whether it has been applied consistently period over period. Any change in accounting policy, method of revenue recognition, or presentation of costs between periods should be identifiable and explainable, because unexplained changes are read as an attempt to present a more favourable trend than the underlying business supports, whether or not that was the intention.
Working capital and cash position are examined not only as a snapshot but as a trend, because a reviewer is typically trying to understand the company's actual burn rate, its runway under realistic assumptions, and whether any related-party loans, director advances or informal cash movements exist that are not properly documented through board approval and loan agreements. Undocumented director loans, in particular, are a recurring finding, and while they are frequently immaterial in amount, their existence without proper paperwork signals the same administrative looseness that shows up elsewhere in the record.
Tax compliance forms a distinct but related workstream, with a reviewer typically confirming that corporation tax returns have been filed and paid on schedule, that VAT registration and returns, where applicable, are current and reconciled, that PAYE and National Insurance obligations for any employees are properly discharged, and that no HMRC enquiries or disputes are outstanding and undisclosed. Tax compliance is not usually the source of dramatic findings, but it is one of the most consistently checked areas precisely because the consequences of an undisclosed liability transferring with a transaction are significant.
Forecasts and projections, where presented to investors specifically, are tested less for accuracy, which cannot be verified in advance, than for internal consistency and the reasonableness of stated assumptions. A reviewer wants to see that a forecast's growth assumptions are traceable to a pipeline, a historical conversion rate, or a comparable cohort, rather than to an unsupported top-down growth rate, because the credibility of the forecast is judged heavily on whether its inputs can be defended individually rather than accepted as a package.
Employment, contractor classification and people risk
Employment diligence has become one of the more consequential workstreams in UK transactions, driven substantially by the risk of contractor misclassification, where an individual engaged and treated as a self-employed contractor exhibits, on the actual facts of the working relationship, the characteristics of an employee or a worker under UK employment status tests. The legal consequence of misclassification can include back-payment of employment rights, holiday pay, pension contributions, and in some cases PAYE and National Insurance liabilities, and these exposures transfer with the business in most transaction structures.
The assessment does not rest on what the contract calls the relationship but on the substance of how it operates in practice: the degree of control the company exercises over how, when and where the individual works, whether the individual can genuinely send a substitute to perform the work, the exclusivity or near-exclusivity of the arrangement, and the extent of mutual obligation to offer and accept future work. A contractor engaged full-time for an extended period, integrated into the company's systems and management structure, and unable in practice to substitute another person to perform the role, presents a materially higher misclassification risk regardless of what the contract states.
Employment contracts and offer letters for genuine employees are reviewed for consistency with the company's actual practice, including probationary terms, notice periods, restrictive covenants and any variation from standard terms granted informally to particular individuals. Restrictive covenants deserve particular attention because a covenant that is unenforceably broad offers no real protection despite appearing in the contract, and a reviewer assessing the durability of the company's key relationships and confidential information will discount covenants that would not survive challenge.
Where a company operates any form of equity incentive for employees, whether an approved option scheme or an informal promise of future equity, diligence examines whether the scheme was properly established, whether grants were documented through individual option agreements, and whether the company's understanding of its own fully diluted cap table actually accounts for every promised grant. Undocumented or partially documented equity promises to employees are a recurring and awkward finding, because resolving them fairly, once discovered late, is materially harder than establishing the scheme properly from the outset.
Finally, a reviewer will look for any pattern of employment disputes, grievances, tribunal claims or settlement agreements, since these are read not only for their individual financial exposure but as an indicator of the company's general standard of people management. A single settled dispute, properly documented and closed, rarely derails a transaction; an undisclosed or poorly managed pattern of disputes raises broader questions about the culture and management discipline of the business being assessed.
Data protection and intellectual property ownership
Data protection diligence examines what personal data the company processes, on what lawful basis under UK data protection legislation, and whether the company's actual practice matches its published privacy notices and internal policies. A reviewer typically requests the company's record of processing activities, its data protection impact assessments where relevant, evidence of registration with the Information Commissioner's Office where required, and any data processing agreements in place with third-party processors handling personal data on the company's behalf.
International data transfers receive particular attention for companies with overseas infrastructure, staff or customers, since transferring personal data outside the UK requires an appropriate legal mechanism, and a company that has scaled internationally without formalising these transfer mechanisms carries a compliance exposure that a reviewer will flag regardless of whether any actual harm has resulted. Similarly, a company's incident history, including any personal data breaches and how they were handled, assessed and, where required, reported, is examined as a proxy for the maturity of the company's overall data governance.
Intellectual property diligence addresses a foundational and sometimes uncomfortable question: does the company actually own the assets its value depends upon. For a technology or product business, this means confirming that the intellectual property created by founders prior to incorporation was properly assigned to the company, that intellectual property created by employees was captured through employment contract assignment clauses, and, critically, that intellectual property created by contractors, freelancers or outsourced development agencies was properly assigned through the underlying engagement contract rather than assumed to transfer automatically, which under UK law it frequently does not.
Contractor-created intellectual property is one of the most consequential and most commonly mishandled areas in early-stage companies, because the default legal position, absent an express assignment clause, is that the creator retains ownership even where the company commissioned and paid for the work. A company that has engaged multiple contractors or agencies over its history without consistently including a robust assignment clause in every engagement may find that a material component of its core product was never actually assigned to it, a finding that can materially affect both valuation and transaction structure if discovered late.
Registered intellectual property, including trademarks, patents and registered designs, is checked for ownership consistency, with a particular focus on ensuring that any registration is held in the name of the correct group entity, that renewal fees and deadlines have been maintained, and that no registration has lapsed inadvertently. Trademark ownership sitting in a founder's personal name, rather than the operating company, is a recurring finding that is straightforward to correct but is far better corrected before it is discovered by a counterparty's intellectual property specialist.
Data and IP diligence readiness checklist
- Founder-created intellectual property formally assigned to the company by written deed
- Employment contracts contain robust intellectual property assignment clauses
- Every contractor and agency engagement includes an express IP assignment provision
- Registered trademarks, patents and designs held in the correct group entity's name
- Record of processing activities maintained and kept current
- Data processing agreements in place with all relevant third-party processors
- International data transfer mechanisms documented where personal data crosses borders
- Privacy notices reviewed against actual data processing practice, not aspirational drafting
Building and maintaining a data room
A data room is frequently conceived as a folder assembled hurriedly once a transaction becomes live, and that conception is precisely why so many diligence processes stall in their first weeks. The more durable approach treats the data room as a continuously maintained repository, structured around the same domains a reviewer will examine, updated as documents are created rather than gathered retrospectively under time pressure when institutional memory of where a particular agreement was filed has already faded.
Structure matters as much as content. A well-organised data room follows a consistent folder taxonomy, typically separating corporate documents, commercial contracts, financial records, employment and HR, intellectual property and data protection, and litigation or disputes, with clear version control so that a reviewer is never left uncertain whether a document is the final executed version or an earlier draft. Ambiguity of this kind, though minor individually, accumulates into a broader impression of disorganisation that colours how the reviewer approaches everything else in the room.
Index documents matter more than founders typically expect. A short index summarising what each folder contains, cross-referenced to the corresponding representation or warranty it supports, allows a reviewer to work efficiently and signals that the company understands its own record well enough to guide someone else through it. This single document is frequently the difference between a diligence process that proceeds smoothly and one where the reviewer, lacking a map, submits an extensive list of clarifying questions that could have been pre-empted.
Access control and confidentiality require equal attention, particularly where the data room contains commercially sensitive customer contracts, compensation information or unfiled intellectual property. Staged access, granting broader visibility only as a transaction progresses and appropriate confidentiality undertakings are in place, is standard practice and should be planned before the room is opened rather than improvised once a counterparty requests something the company had not anticipated sharing.
Maintaining the data room as a continuous discipline, rather than a project undertaken once a transaction is anticipated, changes the entire posture of a company heading into diligence. A founder who can produce an up-to-date, well-indexed data room within days of a request demonstrates, before a single document is reviewed, the same operational discipline the reviewer is there to test for. That first impression carries weight through the remainder of the process.
Investor diligence versus enterprise-customer vendor onboarding
Investor diligence and enterprise-customer vendor onboarding examine substantially overlapping ground, but the emphasis, timeline and consequence of failure differ in ways that founders preparing for one often fail to anticipate when the other arrives. Investor diligence is comprehensive and forward-looking: it assesses the company's ownership, governance, contracts, financials, employment and intellectual property because the investor is acquiring an ongoing economic interest in the company's future performance, and any undisclosed liability or structural weakness directly affects the value being paid.
Enterprise vendor onboarding, by contrast, is narrower in scope but often less flexible in its requirements, because the enterprise customer is assessing the company as a supplier it intends to rely upon operationally, and its concerns concentrate heavily on data protection, information security, business continuity, insurance coverage and financial stability, rather than on ownership structure or cap table integrity, which are frequently irrelevant to a customer relationship. A vendor onboarding questionnaire will typically probe security certifications, incident response procedures, sub-processor arrangements and service level commitments in far greater depth than an investor would, while showing little interest in the company's PSC register.
Timeline dynamics also differ materially. Investor diligence typically proceeds over several weeks as part of a negotiated transaction timetable that both parties are incentivised to progress, with issues raised, discussed and negotiated through legal counsel on both sides. Enterprise vendor onboarding is frequently a gating process managed by a procurement function operating against internal service standards, with fixed questionnaires that offer little room for negotiation and where a failure to meet a stated requirement, such as a specific insurance minimum or a security certification, can result in outright rejection rather than a negotiated adjustment.
The consequence of failure differs correspondingly. A weak point discovered in investor diligence typically affects valuation, warranty and indemnity terms, or the structure of the transaction, but rarely ends it outright once significant time has been invested by both sides. A weak point discovered in enterprise vendor onboarding, particularly a missing security certification or an inadequate insurance policy, can result in the company being excluded from the vendor panel entirely, with no negotiation, because the procurement function is applying a threshold test rather than a risk-adjusted judgement.
Companies preparing for enterprise sales cycles should therefore build a distinct, security- and continuity-focused readiness pack well before a specific opportunity arises, covering information security policy, data processing and sub-processor documentation, business continuity and disaster recovery arrangements, and confirmation of appropriate insurance coverage including professional indemnity and cyber liability where relevant. Treating enterprise vendor onboarding as a lighter version of investor diligence, rather than as a distinct discipline with its own gating criteria, is a common and avoidable cause of lost enterprise revenue.
| Dimension | Investor diligence | Enterprise vendor onboarding |
|---|---|---|
| Primary concern | Ownership, valuation, structural and financial risk | Operational reliability, security, continuity |
| Scope | Comprehensive across all corporate domains | Concentrated on security, data and continuity |
| Negotiability | Issues typically negotiated through legal counsel | Fixed thresholds; limited or no negotiation |
| Consequence of a gap | Adjusted valuation or terms; process usually continues | Possible outright exclusion from vendor panel |
| Typical timeline | Several weeks within a transaction timetable | Fixed procurement cycle, often less flexible |
A readiness scoring framework
A useful discipline for any growing company, whether or not a transaction is imminent, is to score its own readiness across each diligence domain honestly, using a simple framework that identifies where remediation effort should be concentrated. We recommend scoring each domain, corporate, commercial, financial, employment, data protection and intellectual property, on a three-point scale: fully evidenced and current, partially evidenced with known gaps, or materially incomplete, and to be specific about what evidence is missing rather than recording a general impression.
The value of this exercise lies less in the score itself than in the honesty of the assessment. Founders and finance teams close to the business often overestimate readiness because they know the underlying facts even where the documentary record does not reflect them; the exercise is only useful if it is conducted, or at minimum reviewed, by someone applying the same sceptical standard an external reviewer would apply, testing whether a document actually exists and matches the claim rather than accepting that it probably does.
Once scored, domains rated as materially incomplete should be prioritised not by ease of remediation but by the likelihood they will be examined early and the severity of consequence if found unresolved. Cap table and PSC register accuracy, for example, are examined in the first days of almost any transaction and carry high consequence if wrong, and should therefore be prioritised even where the remediation itself is more time-consuming than, say, tidying a supplier contract that is unlikely to be examined in depth.
A readiness assessment conducted well ahead of any anticipated transaction allows remediation to proceed calmly, on the company's own timetable, with access to proper legal and accounting advice where correction requires it. A readiness assessment conducted, in effect, by the counterparty during a live process removes that calm entirely, and remediation undertaken under active transaction pressure is both more expensive and more visible to the very party the company is trying to reassure.
We recommend repeating this assessment on a regular cycle, at minimum annually and ideally ahead of any known event such as a funding round, a significant new enterprise contract, or an anticipated exit discussion, so that the company's readiness posture is a known, managed quantity rather than a question mark that only gets answered once someone else asks it.
Readiness scoring domains
- Corporate: cap table, registers, board authority and PSC accuracy
- Commercial: material contracts, concentration, assignment and change-of-control exposure
- Financial: accounts reconciliation, tax compliance, forecast integrity
- Employment: contractor classification, contract consistency, equity documentation
- Data protection: lawful basis, processor agreements, transfer mechanisms
- Intellectual property: assignment chain, registration ownership, renewal status
Strategic considerations: remediation, risk and governance
The most common mistake we observe is treating diligence preparation as a document-collection exercise rather than a substantive review of whether the underlying corporate facts are actually correct. Gathering every contract into a well-organised folder does not resolve a genuine cap table discrepancy or an unassigned piece of intellectual property; it simply presents the problem more clearly to whoever reviews it next. Preparation must include the substantive correction of identified issues, not only their tidy presentation.
A related and equally common error is sequencing remediation by convenience rather than by risk. Founders under time pressure understandably start with whatever is easiest to fix, but a reviewer typically examines corporate and financial fundamentals first, meaning easily corrected but low-consequence issues, such as an outdated employee handbook, deliver little protective value if a fundamental cap table discrepancy remains unresolved and is discovered in the same week. Effective remediation sequencing starts with the domains most likely to be examined early and carrying the highest consequence if wrong.
The practical risk of poor preparation is rarely a single catastrophic failure; it is the accumulation of friction, each unresolved query slowing the process, each newly discovered issue prompting a fresh round of questions, until a transaction that should have closed in weeks stretches into months, during which commercial momentum, investor enthusiasm or a customer's procurement window can each independently evaporate. Time is rarely neutral in a live process, and preparation is, in large part, a discipline of protecting time.
From a governance perspective, the discipline required to prepare well for diligence is the same discipline that should be operating continuously regardless of whether a transaction is contemplated: current registers, contemporaneous board minutes, properly assigned intellectual property, and contracts reviewed for the terms that matter before they need to be relied upon. Viewed this way, diligence preparation is not a separate project but a periodic audit of governance practices that should already be in place, and companies that maintain those practices consistently find that preparing for a specific transaction is a matter of assembly rather than remediation.
Banking and financial infrastructure considerations also intersect with diligence readiness in ways that are easy to overlook: a reviewer examining financial diligence will frequently want to see clean, reconcilable banking records and evidence that the company's banking relationships are stable and appropriately structured for its scale, and a company whose banking history includes unexplained account changes or informal cash movements between related entities introduces exactly the kind of ambiguity that slows a review.
Long-term, the companies that manage diligence most efficiently are not those that never have gaps, since gaps are near-universal even in well-run businesses, but those that have built a culture in which documentation is created as decisions are made, contracts are reviewed for their protective terms before signature rather than after a dispute, and ownership and assignment questions are resolved at the point a relationship begins rather than assumed to resolve themselves. This culture, once established, converts diligence from a periodic crisis into a routine, manageable process.
