Due Diligence Checklist: 100 Target Company Questions

Due Diligence Checklist: 100 Target Company Questions

Image: Plausity

Key Takeaways

  • Between 70% and 90% of M&A transactions fail to deliver projected value, frequently due to inadequate due diligence.
  • A modern mid-market acquisition data room holds thousands of documents, overwhelming manual review teams.
  • Rushed due diligence is a primary cause of deal failure, with 31% of failed deals attributing the loss to missed material issues.
  • Transitioning from static checklists to an AI-powered platform turns raw data room files into evidence-backed findings.

Why this matters now

A comprehensive due diligence checklist is the foundational framework private equity deal teams, M&A advisors, and corporate development leads use to systematically uncover risks, evaluate growth potential, and validate deal theses before acquiring a target company. Thorough investigation protects deal value across financial, commercial, operational, legal, technical, and human capital dimensions. Yet between 70% and 90% of mergers and acquisitions fail to deliver their projected value, often because transaction teams rely on static, superficial reviews that miss critical underlying liabilities.

In modern middle-market transactions, virtual data rooms routinely hold thousands of individual documents, including complex customer contracts, financial models, regulatory filings, and technical architecture schemas. Sifting through this volume under compressed transaction timelines creates severe informational bottlenecks for investment committees and advisory teams.

  • Data volume explosion: Modern target companies generate sprawling digital paper trails across fragmented systems, complicating manual document discovery.
  • Compressed exclusivity periods: Deal teams frequently face 30-to-45-day exclusivity windows to evaluate thousands of pages of unstructured data.
  • Dispersed transaction workstreams: Financial, legal, tax, and commercial advisors often work in operational silos, leading to blind spots in cross-discipline risk correlation.
  • Static checklist limitations: Traditional spreadsheets track task completion rather than verifying evidentiary backing or cross-referencing conflicting data points.

When deal teams treat due diligence merely as a box-ticking exercise rather than an evidence-backed risk analysis, material liabilities slip past the investment committee. Establishing a structured, multi-disciplinary review framework is essential to safeguarding capital and establishing realistic post-acquisition value creation roadmaps.

The main practical framework

An effective target company evaluation requires transitioning from static task lists to dynamic, evidence-backed findings. Rather than asking whether a folder exists in the data room, investment professionals must verify the integrity, consistency, and strategic implications of every underlying artefact across all core workstreams.

Structuring due diligence into distinct, interconnected pillars ensures full coverage across the transaction lifecycle. By integrating systematic risk register management into the review process, teams can cross-reference operational findings with financial statements and legal obligations to build an auditable chain of custody for every finding.

Diligence DimensionCore ObjectivePrimary Evidence RequiredKey Risk Focus
Financial DiligenceValidate Quality of Earnings and cash flow sustainabilityAudited financials, general ledgers, tax returns, working capital modelsEBITDA adjustments, revenue recognition, off-balance sheet liabilities
Commercial DiligenceConfirm market positioning, customer durability, and growth thesisCohort data, customer contracts, pipeline reports, competitor benchmarksCustomer concentration, churn velocity, pricing power limits
Operational DiligenceAssess scalability, supply chain resilience, and cost structuresVendor agreements, capacity reports, inventory logs, facility leasesSingle-source supplier dependency, capacity bottlenecks, capex backlogs
Legal & ComplianceUncover litigation exposure, regulatory gaps, and contractual limitsCorporate charters, material contracts, IP assignments, regulatory filingsChange of control clauses, unassigned IP, pending regulatory actions
Technology & AIEvaluate codebase quality, architecture scalability, and technical debtCode repos, architecture diagrams, AI model training logs, security auditsProprietary software replication risk, cyber vulnerabilities, licence non-compliance
HR & ManagementAssess leadership depth, incentive alignment, and cultural stabilityEmployment contracts, org charts, compensation plans, retention agreementsKey-person dependency, unfunded pension obligations, cultural misalignment
Data Room GovernanceEnsure documentation completeness and audit trail integrityIndex logs, version histories, disclosure schedules, Q&A recordsMissing material documents, redacted critical terms, version discrepancies

This structured framework provides the blueprint for the 100-question evaluation model below, enabling investment professionals to interrogate target assets systematically and convert raw data into high-conviction investment decisions.

Practical checklist: Financial, commercial, and operational

The initial stage of target company diligence focuses on the financial foundations, commercial market positioning, and operational infrastructure that drive business valuation. A thorough commercial due diligence audit combined with rigorous financial verification ensures that historical earnings represent sustainable future cash flows.

Financial due diligence (Questions 1-15)

  • Are historical financial statements audited by an accredited independent accounting firm for the past three to five fiscal years?
  • What specific pro-forma Quality of Earnings adjustments have been made to reported EBITDA over the last 36 months?
  • How consistent and compliant are the target company revenue recognition policies under GAAP or IFRS standards?
  • What is the monthly breakdown of recurring, reoccurring, and one-off project revenue across all product lines?
  • What are the historical gross, operating, and net margin trends across individual business units and geographies?
  • How has normalized net working capital fluctuated on a monthly basis over the trailing 24-month period?
  • What is the complete schedule of outstanding interest-bearing debt, capital leases, and off-balance sheet liabilities?
  • Are there material discrepancies between historical financial budgets and actual operational results over the last three years?
  • What is the company capital expenditure history, categorized precisely between maintenance capex and growth capex?
  • How are inventory levels valued, and what are the reserves for obsolete, damaged, or slow-moving stock?
  • What is the aging profile and historical bad-debt loss experience of trade accounts receivable over the past 36 months?
  • Are all federal, state, and local tax filings current, and are there open audits or disputed tax exposures?
  • What transfer pricing policies exist between international subsidiaries, and are they supported by formal studies?
  • What contingent liabilities, earnouts, or deferred consideration obligations remain from prior acquisitions?
  • What is the projected cash conversion cycle, and how does seasonality impact intraday operating liquidity?

Commercial due diligence (Questions 16-30)

  • What is the total addressable market (TAM), serviceable addressable market (SAM), and historical market growth rate?
  • What is the verifiable revenue concentration among the top 10 and top 20 customers over the last three fiscal years?
  • What are the historical annual gross and net revenue retention rates across major customer cohorts?
  • What is the average customer acquisition cost (CAC) broken down by sales channel and direct marketing campaign?
  • What is the average customer lifetime value (LTV) and the resulting LTV-to-CAC ratio by customer segment?
  • How long is the typical sales cycle from initial lead generation to closed-won contract across each product line?
  • What are the annual customer churn rates by both logo count and revenue volume over the last 36 months?
  • What percentage of existing customer relationships are governed by multi-year contracts versus month-to-month terms?
  • What specific value proposition differentiates the company from its top five direct and indirect competitors?
  • How is pricing structured, and when was the target company last able to implement successful price increases?
  • What pipeline coverage ratio exists for projected revenue over the next 12 to 24 months?
  • What are the primary drivers of recent competitive win and loss outcomes based on independent buyer feedback?
  • How dependent is market demand on broader macroeconomic cycles, commodity prices, or interest rate movements?
  • What expansion opportunities exist into adjacent product categories, customer verticals, or geographic regions?
  • Are there significant channel partner dependencies or distributor agreements that represent critical revenue choke points?

Operational due diligence (Questions 31-45)

  • What is the current manufacturing or service delivery capacity utilization, and what are the operational ceilings?
  • Which suppliers represent single-point-of-failure vulnerabilities, and what secondary sourcing alternatives exist?
  • What long-term volume commitments, minimum spend requirements, or pricing escalators exist in key vendor contracts?
  • How resilient is the company supply chain to international geopolitical disruptions, freight spikes, and trade tariffs?
  • What quality assurance and defect tracking protocols are implemented across core production and service lines?
  • What is the detailed maintenance schedule, operating condition, and remaining economic life of core capital assets?
  • Are facility leases structured on market terms, and what are their remaining durations, renewal options, and restoration terms?
  • What business continuity and disaster recovery plans are in place for key physical facilities and operations?
  • How dependent are ongoing operations on outsourced third-party logistics, contract manufacturers, or service providers?
  • What operational bottlenecks currently restrict the company from doubling its output over a 24-month horizon?
  • What environmental, health, and safety (EHS) compliance policies exist, and have any workplace violations occurred?
  • How are procurement processes managed, and what uncaptured volume discounting synergies exist?
  • What enterprise resource planning (ERP) systems manage daily operations, and how integrated are they across facilities?
  • What is the historical cadence and financial cost of warranty claims, product returns, or service SLA penalties?
  • What operational key performance indicators (KPIs) does management track weekly to maintain delivery standards?

Practical checklist: Legal, technology, HR, and data room

The second half of the evaluation framework investigates legal encumbrances, software scalability, organizational design, and data governance. Conducting thorough AI due diligence alongside structured C-level management audits ensures the business possesses legitimate intellectual property rights, sustainable technology infrastructure, and leadership continuity.

Legal and compliance due diligence (Questions 46-60)

  • Is the corporate capitalization table fully reconciled, including all issued shares, options, warrants, and SAFEs?
  • Are all corporate organizational documents, minute books, shareholder agreements, and board resolutions fully up to date?
  • What active, threatened, or settled litigation, arbitration, or regulatory proceedings involve the company?
  • Do customer, supplier, or licensing agreements contain change-of-control or anti-assignment clauses triggered by a deal?
  • Does the company hold clear, unencumbered title and chain of custody for all registered patents, trademarks, and domain names?
  • Have all current and former employees and contractors executed comprehensive IP assignment and confidentiality agreements?
  • Is the company fully compliant with global data privacy frameworks such as GDPR, CCPA, and industry data regulations?
  • What anti-bribery, anti-corruption (FCPA/UK Bribery Act), and international trade sanctions compliance policies are in place?
  • What are the terms, liability caps, indemnification provisions, and warranty limits in standard customer master service agreements?
  • Are all required municipal, state, federal, and international operating licences and permits valid and active?
  • Are there outstanding encumbrances, liens, or security interests registered against company assets or accounts?
  • What related-party transactions, intercompany loans, or personal shareholder arrangements currently exist?
  • Has the company complied with all industry-specific antitrust and competition regulations in its core operating markets?
  • What is the history of regulatory audits or inquiries, and were all identified corrective actions fully resolved?
  • What comprehensive insurance policies exist (D&O, general liability, cyber, E&O), and what are their claim histories?

Technology and AI due diligence (Questions 61-75)

  • What is the overarching architecture of the software stack, and how modular, maintainable, and scalable is it?
  • What open-source software libraries are embedded in proprietary products, and are they compliant with restrictive licences?
  • What proprietary AI models or machine learning algorithms are utilized, and what datasets were used for training?
  • Does the target hold verifiable commercial IP rights and consent for all training datasets used in its AI workflows?
  • What inference economics, compute costs, and cloud infrastructure margins govern the software platform?
  • What automated code testing, continuous integration, and deployment pipelines are maintained by engineering?
  • What technical debt has engineering flagged as requiring immediate refactoring or architectural overhaul?
  • When was the most recent independent third-party penetration test conducted, and what critical vulnerabilities were found?
  • How is role-based access control, cryptographic key management, and sensitive customer data encryption handled?
  • What is the documented mean time to recovery (MTTR) and recovery point objective (RPO) in disaster recovery protocols?
  • What service level agreements (SLAs) are promised to customers, and what has been historical system uptime over 24 months?
  • How is proprietary source code protected, stored, and managed across decentralized developer environments?
  • Are third-party API dependencies monitored for performance reliability, rate limiting, and pricing changes?
  • What automated evaluation harnesses and guardrails are in place to benchmark AI accuracy and prevent hallucinations?
  • Can core software components and data pipelines be replicated easily by well-funded market competitors?

HR and management due diligence (Questions 76-90)

  • What is the full organizational chart, reporting hierarchy, and total headcount by department and geographic location?
  • Which executive positions represent critical key-person dependencies without identified internal succession successors?
  • What employment agreements, non-compete covenants, and severance packages exist for executive team members?
  • What management incentive structures, stock option pools, and bonus schemes are currently outstanding?
  • What has been the historical voluntary and involuntary employee turnover rate by department over the past three years?
  • Are there pending or historical labor disputes, wrongful termination claims, or workplace harassment allegations?
  • Are any employee groups unionized or covered by collective bargaining agreements or European works councils?
  • How are independent contractors classified, and does any worker classification create tax or benefits liability?
  • What is the competitive positioning of employee compensation and benefits packages against current market benchmarks?
  • What is the historical health and workers compensation claim record across operations?
  • What key employees have been identified as essential for post-acquisition business integration and continuity?
  • What retention packages, transaction bonuses, or stay incentives are planned to preserve core talent?
  • What cultural integration challenges have surfaced during prior organizational expansions or leadership transitions?
  • How structured are the company recruitment, employee onboarding, and internal performance management processes?
  • Are all mandatory employee training programs, compliance reviews, and safety certifications documented and current?

Data room readiness and governance (Questions 91-100)

  • Is the virtual data room index structured systematically according to standard M&A taxonomy?
  • Are all uploaded financial models delivered in dynamic Excel formats with unbroken formulas and audit trails?
  • Have customer and employee personally identifiable information (PII) been appropriately redacted from raw files?
  • Is there a documented Q&A log that systematically records and timestamps all advisor inquiries and company responses?
  • Are all material customer and supplier contracts uploaded as complete, fully executed PDF documents including exhibits?
  • Are board meeting minutes, committee records, and shareholder resolutions completely indexed for the past five years?
  • Have all historical corporate restructuring, acquisition, and divestiture files been archived in the repository?
  • Are disclosure schedules aligned directly with the representations and warranties in the draft purchase agreement?
  • Is data room user access monitored, permissioned by workstream, and protected by mandatory multi-factor authentication?
  • Has a closing verification audit been performed to ensure no conflicting versions of material documents exist?

Red flags or common mistakes

Even experienced deal teams encounter severe blind spots during target evaluation. A primary driver of transaction failure is rushed or superficial due diligence, with inadequate diligence cited as a root cause in 31% of failed M&A transactions. Identifying red flags early allows buyers to renegotiate valuation, adjust purchase price mechanisms, or walk away before deploying capital.

  • Unreconciled cap tables and missing equity grants: Incomplete equity ownership records or unrecorded warrant promises that create post-close shareholder disputes.
  • Aggressive revenue recognition practices: Pulling future revenue forward, booking upfront milestone payments prematurely, or masking seasonal churn through non-standard accounting.
  • Undocumented intellectual property ownership: Software developed by third-party contractors or offshore teams without executed, binding IP assignment agreements.
  • Hidden customer concentration and fragile contract terms: Major revenue streams concentrated in top accounts operating on uncommitted, month-to-month terms lacking assignment clauses.
  • Unfunded employee liabilities or hidden off-balance debt: Undisclosed pension deficits, misclassified independent contractor workforces, or off-balance sheet lease commitments.

Relying on high-level spreadsheet summaries without auditing primary source documents frequently leads to unhedged risk exposure. Sustainable value creation playbooks depend on uncovering operational realities before signing binding purchase agreements.

How Plausity supports the workflow

Evaluating thousands of complex data room documents within narrow transaction windows requires modern, technology-enabled infrastructure. Purpose-built diligence tooling accelerates these workflows, enabling investment professionals, private equity analysts, and M&A advisors to extract verifiable intelligence without relying on manual checklist management.

The platform streamlines the end-to-end investigation lifecycle through integrated core capabilities:

  • AI-Analysis Engine: Reads, interprets, and cross-references thousands of heterogeneous data room files, including complex contracts, general ledgers, and technical architecture schemas, to surface underlying risks with full source citation.
  • Data Room Ingestion: Connects directly to electronic data rooms to scan, ingest, and index massive multi-gigabyte document repositories within minutes.
  • Risk Radar: Continuously evaluates identified findings based on materiality, financial impact, and legal exposure, automatically generating prioritized risk registers for the deal team.
  • Collaboration Hub: Aligns internal deal teams and external advisors in a shared workspace, synchronizing workstreams and facilitating real-time finding validation.

The platform is designed to support, organize, and accelerate transaction workflows for human dealmakers and advisory teams, rather than replacing legal, tax, or accounting professionals. By transforming unstructured data into structured findings, teams can validate deal theses with higher speed and greater auditability.

How to use this in your next diligence workflow

To maximize the value of this 100-question checklist, integrate it directly into your team's preliminary deal screening, confirmatory due diligence, and investment committee preparation. Rather than treating these questions as isolated tasks, use them as an interconnected framework to interrogate target data room artefacts systematically.

Leveraging advanced AI diligence workflows enables transaction teams to automate repetitive document extraction, prioritize red flags early in exclusivity, and free up senior professionals to focus on strategic negotiation and value creation structuring.

Deploying Plausity's Report Builder allows deal leads to synthesize complex findings from the data room into deal-ready reports and structured investment committee memos with full source traceability, ensuring that every claim is grounded in verified documentation.

Sources

Frequently Asked Questions

PLAUSITY

AI Summary

Ask an AI assistant to summarise Plausity.