Once M&A due diligence starts, the to-do list can get long quickly. Contracts arrive. Financial questions generate follow-ups. New advisers need access. One missing document can hold up another part of the review.
A useful M&A due diligence checklist gives that work some structure. It helps you decide what to examine, assign the right owner, track what’s still missing, and keep a record of how important issues were handled.
Below, you’ll find eight areas commonly covered in a mergers and acquisitions due diligence checklist, plus practical ways to prioritize the review and keep the process organized.
If your transaction also involves a steady flow of NDAs, adviser joinders, engagement letters, or other documents that need signatures, Dropbox Sign can help you prepare, send, sign, and track those requests without adding unnecessary work.
Disclaimer: This information is for general purposes only. It isn’t legal advice and shouldn’t replace counsel from a licensed attorney.
Scope note: This article covers M&A and related commercial transactions. It doesn’t cover vendor due diligence, customer or enhanced due diligence under anti-money-laundering rules, or residential real-estate due diligence.
What is a due diligence checklist for?
A due diligence checklist turns a broad investigation into clear questions, document requests, and owners for each item.
For an acquisition, that might mean confirming who owns the company, testing the assumptions behind its valuation, reviewing important customer contracts, checking software licenses, or establishing whether intellectual property has been properly assigned.
The checklist also helps you keep track of what happens after you make a request. A useful working version might include columns for:
- Item or question
- Owner
- Status
- Evidence received
- Follow-up required
- Resolution
The final decision to proceed with a deal doesn’t tell you how you reached it. But a record of your due diligence can help explain your reasoning.
How thorough should M&A due diligence be?
There’s no single level of review that works for every transaction.
How deep you need to go depends on the target, deal structure, risks, available information, and who’s reviewing what. Deal counsel and the relevant financial, tax, technical, regulatory, and other advisers should determine what needs to be reviewed and to what depth.
Assemble the list around the issues that could affect the deal ehether you’re building a large corporate M&A due diligence checklist or adapting a small business acquisition due diligence checklist for a first deal, A longer request list doesn’t automatically make the diligence better.
M&A due diligence checklist: eight areas to review
Use this framework as a starting point, then adapt it to the business and transaction in front of you.
1. Legal and regulatory
Start by understanding what the company is, who owns it, what obligations it has, and which legal or regulatory issues could carry into the deal.
Your review may include:
- Formation documents, bylaws or operating agreements, and amendments
- Capitalization tables, share ledgers, options, warrants, and convertible instruments
- Board and shareholder minutes, written consents, and relevant corporate resolutions
- Material customer, supplier, financing, and other contracts
- Assignment, change-of-control, termination, and consent provisions
- Licenses, permits, and certifications
- Pending or threatened litigation
- Regulatory actions or inquiries
- Insurance policies and claims history
- Data-protection obligations and known security incidents
Pay particular attention to provisions that could be triggered by the transaction itself. A valuable contract can look very different if the counterparty can terminate it when ownership changes.
2. Financial
Financial due diligence should help you understand how the business has performed, what it owes, what cash it needs, and what assumptions are driving the valuation.
Common areas include:
- Historical financial statements
- Current management accounts
- Quality-of-earnings analysis
- Revenue recognition
- Revenue by customer, product, or geography
- Customer concentration
- Working-capital history
- Debt and leases
- Off-balance-sheet and contingent liabilities
- Tax returns and open audits
- Cash flow and capital expenditure
- Forecasts and the assumptions behind them
Numbers also need context. A forecast may look attractive until you find that much of the expected growth depends on one customer renewal or an unfilled senior role.
3. Commercial and market
Commercial diligence tests whether the story behind the deal matches the evidence.
Review areas such as:
- Market size and growth assumptions
- Competitors and market position
- Customer contracts and renewals
- Churn or retention data where relevant
- Pricing history and discounts
- Sales pipeline and win rates
- Customer acquisition economics
- Product or service roadmap
- Channel and partner agreements
Look for the assumptions the deal depends on, then work backward to the evidence supporting them.
4. Operational
Operational diligence asks a practical question: Can this business continue operating as expected after the transaction?
Consider:
- Core processes and systems
- Critical suppliers
- Supplier concentration
- Inventory and fulfillment
- Facilities and capacity
- Health and safety requirements
- Business-continuity plans
- Disaster-recovery testing
- Integration dependencies and transition needs
This is also where the administrative side of diligence can start multiplying. New advisers join. Another NDA is needed. A specialist engagement letter is waiting for signature.
If you regularly use the same reviewed process documents, Dropbox Sign templates let you prepare frequently reused documents, rather than rebuilding the signature request for every transaction. Automatic reminders can also reduce the time you spend following up with recipients.
5. Workforce and human resources
People-related obligations can affect cost, continuity, and the integration plan.
Review:
- Organizational structure and key roles
- Employment agreements
- Notice and severance terms
- Confidentiality and restrictive-covenant agreements, with enforceability considered under current applicable law
- Compensation, bonuses, and commissions
- Equity and vesting arrangements
- Benefit and pension obligations
- Collective bargaining agreements
- Contractor arrangements and classification
- Employment claims or investigations
- Retention risks involving key people
Don’t stop at headcount. If the deal depends heavily on a small number of people, understand what happens if they leave.
6. Real estate and physical assets
If property, facilities, or equipment matter to the business, review both ownership and the obligations attached to them.
That can include:
- Owned property and title
- Leases and renewal terms
- Assignment or change-of-control provisions
- Mortgages, liens, and property taxes
- Environmental assessments
- Remediation obligations
- Condition of facilities and equipment
- Committed or deferred capital expenditure
7. IT, data, and security
An IT due diligence checklist should establish whether the technology can support the business, whether it’s properly licensed, and what security or integration risks you may inherit.
For software-heavy businesses, this part of the review may also form the core of a technical due diligence checklist or software due diligence checklist.
Review areas such as:
- Systems, applications, infrastructure, and hosting
- Architecture and technical debt
- Scalability and integration constraints
- Software licenses
- Open-source components and license obligations
- Security controls and known vulnerabilities
- Penetration-test results and remediation plans
- Security incidents and data breaches
- Personal-data handling and retention
- Vendors and subprocessors
- Access controls and privileged access
- Backup and disaster-recovery evidence
A technical specialist may need to dig much deeper depending on what you’re acquiring.
8. Intellectual property
For businesses that depend on software, content, brands, designs, inventions, or proprietary processes, ownership is only part of the question. You also need to understand whether those rights can continue to be used as expected after the deal.
Review:
- Registered and unregistered intellectual property
- Pending applications
- Founder, employee, and contractor IP assignments
- Inbound licenses
- Outbound licenses
- Royalty and exclusivity terms
- Assignment and change-of-control restrictions
- Existing or threatened infringement claims
- Ownership disputes and settlements
Where should you spend the most due diligence time?
Don’t review every checklist item to the same depth.
Start with the deal thesis. Then give closer attention to findings that could change the price, structure, contractual protections, integration plan, or decision to proceed.
Useful signals include:
- Deal-critical dependencies: A major customer, key employee, license, technology, supplier, or facility that the deal relies on
- Concentrated risk: Revenue, expertise, system access, or capacity with no easy substitute
- Conflicting information: Figures or explanations that don’t line up with other evidence
- Transaction triggers: Consent, assignment, acceleration, termination, or change-of-control provisions
- Hard-to-fix problems: Liabilities or integration issues that would become difficult or expensive to address after closing
Specialist reports can save you from repeating work, but check their scope, date, assumptions, limitations, and intended audience with the adviser responsible for that area.
How do you keep a useful due diligence record?
A good diligence record lets you follow an issue from the initial request to its resolution. Keep the request list and its revisions. Link each response to the relevant item. Record follow-up questions, missing or conflicting information, reviewer ownership, and how significant issues were handled.
Follow the access, confidentiality, privilege, and retention rules established for the transaction. If an NDA or adviser joinder governs access to particular materials, keep the signed document with the appropriate transaction records.
There’s also an important distinction between your diligence record and your execution record.
The diligence record covers the investigation: requests, evidence, reviews, gaps, and decisions.
The execution record covers signed documents and signing activity. With Dropbox Sign, for example, each signature request includes an audit trail with a time-stamped record, while status tracking and notifications help you follow requests through the signing process.
That audit trail can help you show how a process document was executed. It doesn’t establish that the underlying due diligence investigation was sufficient.
How should you sequence M&A due diligence?
Once you know what you need to review, turn the checklist into a process:
- Put confidentiality arrangements in place: Sign the NDA before sharing information it covers. Add joinders or acknowledgements as advisers join when required.
- Send your initial requests: Start with a broad request list, then use the responses and gaps to shape more targeted follow-up.
- Stage access to sensitive information: Flag customer identities, employee compensation, or source code that may be held back until an appropriate point in the process.
- Run confirmatory review: As the deal progresses, focus on the facts and documents that the transaction agreement will rely on.
- Connect diligence to the transaction documents: Counsel should determine how findings relate to representations, warranties, disclosure schedules, consents, and other deal documentation.
On the seller’s side, doing some of this work before the data room opens can make the process much easier. Identify the owners of key documents, find obvious gaps, and organize the material before requests start arriving.
Keep recurring M&A documents moving with Dropbox Sign
Due diligence involves plenty of investigation, but there’s also a smaller workflow running alongside it: getting the process documents signed so the next step can happen.
An NDA may need to be completed before access is granted. A new adviser may need a joinder. An engagement letter may need signatures before specialist work begins.
With Dropbox Sign, you can prepare, send, sign, and track these documents through a straightforward eSignature workflow. For recurring documents, reusable templates can reduce time-consuming setup. Automated reminders help with follow-up, and status tracking shows what still needs doing.
Dropbox Sign doesn’t run the data room, perform due diligence, determine what must be disclosed, or establish whether an investigation was sufficient. Its role is simpler: helping agreements and signature requests move alongside the transaction.
If recurring signature workflows are creating administrative overhead across your deals, talk to our team about your Dropbox Sign needs.
자주 묻는 질문
What’s included in a due diligence check?
M&A due diligence commonly covers legal and regulatory matters, financial performance and liabilities, commercial assumptions, operations, workforce matters, real estate and physical assets, IT and data security, and intellectual property.
The exact requests should be adapted to the target, transaction, and risks involved. A financial due diligence checklist for one deal, for example, may need much more detail than for another.
Is there a free M&A due diligence checklist?
Yes. You can use the eight areas above as a starting point for your own working checklist.
For each request, consider adding fields for the owner, status, evidence received, follow-up, and resolution. Your advisers should adjust the scope for the particular transaction.
What are the four Ps of due diligence?
There isn’t a single authoritative four-P framework for M&A due diligence.
Rather than fitting a transaction into a fixed four-part model, use a checklist that covers the risks that actually matter to the deal.
Can M&A due diligence documents be signed electronically?
Often, yes. For transactions covered by the federal ESIGN Act, a signature or contract generally can’t be denied legal effect solely because it’s electronic.
The law doesn’t require anyone to accept electronic signatures, preserves other legal requirements, and contains specific exceptions. Deal counsel should confirm the appropriate signing process for each document.
Ready to experience the difference?
진행 상태 확인
Thank you!
Thank you for subscribing!



