Finance & Risk·6 min read

What a Due Diligence Check Covers Before a Deal

A report that finds nothing has usually looked at nothing. Verification exists to price what the seller knows and the buyer does not.

By Jennifer Roberts— Director, Risk & Compliance
An open filing box of company documents on a boardroom table with a notebook and pen beside it, tall windows and morning light

A corporate due diligence check before a deal is a structured attempt to replace the seller's account of a business with evidence. It covers four broad areas: the company itself and its ownership, its finances and liabilities, its contracts and obligations, and the reputation and conduct of the people behind it. The output is not a verdict on whether to buy. It is a list of what is confirmed, what is contradicted, what could not be established, and what each of those should do to the price and the terms.

The reason the exercise exists is asymmetric information. A seller knows the business intimately and a buyer does not, and a short period of exclusive negotiation does not close that gap. Verification closes some of it, and prices the rest. An owner running the process from the buy side should expect a report that is uncomfortable in places, because a report that finds nothing is usually a report that looked at nothing. One clear description of how the pieces fit together is kept by corporate due diligence before a deal at The Diligence Review, an independent magazine on corporate investigations, due diligence and compliance written in plain English, which covers verification, fraud and investigations, and compliance and digital evidence as three connected desks.

What Does a Corporate Due Diligence Check Actually Cover Before a Deal?

Corporate and legal due diligence establishes what is being sold. That means the constitutional documents, the cap table and the share classes, the registers of directors and shareholders, subsidiaries and their ownership chains, licences, and any litigation or regulatory action past or pending. It also means the things that are easy to overlook and expensive to discover later: change of control clauses in key contracts, guarantees given by the parent, and assets that are used by the business but owned by a person.

Financial due diligence tests whether the numbers mean what they appear to mean. Quality of earnings work separates revenue that will recur from revenue that was pulled forward, normalises owner compensation and one-off items, and examines the working capital the business actually needs to operate. Tax due diligence runs in parallel, because liabilities that are contingent on a future assessment are exactly the kind of item that a balance sheet does not show.

Commercial due diligence asks whether the business is worth what is being paid for it in its market: customers, concentration, pricing power, pipeline and the assumptions behind the forecast. Operational and technology due diligence covers the systems, the data, the key supplier dependencies and the cyber posture. Each of these has a different specialist, and the buyer's job is to make them answer a single question about price rather than five separate academic questions.

How Do You Verify That a Company and Its Beneficial Owners Are Who They Claim to Be?

Start with the public registers and read them properly. In the United Kingdom, Companies House publishes incorporation documents, filings, accounts and the register of people with significant control, which is the closest thing to a public beneficial ownership record in that jurisdiction. Most countries have an equivalent, and the differences between them are exactly where the work is: what has to be filed, how often, and whether the filing is verified before it is published.

Then work outward from the register rather than trusting it. Compare the officers and shareholders with what the seller's documents say, and look for the names that appear in several entities at once, including dissolved ones. Check the addresses, because a registered office shared by dozens of companies is a fact worth understanding rather than a red flag by itself. Cross-reference litigation and enforcement records, insolvency registers and sanctions lists.

For the ownership chain, the questions are specific. Who ultimately controls the entity that is signing, and through what structure. Are there trusts, nominee arrangements or bearer instruments in the chain. Is any part of the chain in a jurisdiction whose records cannot be checked independently. And does the source of the funds used to acquire the business make sense for the parties involved. Anti-money laundering rules exist for the last question in particular, and they are a floor rather than a standard.

What Is a Reputation Audit, and What Can It Find That a Database Cannot?

A reputation audit is the part of the process that searches outside the registers, in media archives, court reporting, regulatory notices and public records across jurisdictions. Its distinctive value is context. A database can tell you that a director was previously at a company that failed; it cannot tell you whether the failure was a market event, a fraud or an ordinary insolvency with creditors paid.

What a reputation audit can surface includes patterns rather than single facts: a director who repeatedly joins companies shortly before they are dissolved, a business that has changed its story about what it sells, a supplier whose public record contradicts the assurances given in a data room, or a matter that was reported in one country and never filed anywhere else. It also has an ethical boundary. Public sources and lawful enquiries only, and no pretext calls to obtain information that the subject would not give knowingly.

The findings feed back into the deal in practical ways: a warranty that needs to be specific rather than general, a retention held back against a risk that cannot be priced, an escrow arrangement, or a decision to walk away when the pattern is clear enough.

Turning the Findings Into a Decision

The report should end in a red-flag schedule, not a narrative. Each item with its source, its severity, its effect on price or terms, and the mechanism that protects the buyer. This is where due diligence connects to the rest of the transaction: the representations and warranties, the indemnities, the conditions to closing and the integration plan.

Two habits make the process worth its cost. Run it in proportion to the risk, so a small acquisition does not consume a large one's budget on scope that will never change the decision. And run it early enough to matter, because a finding that arrives after the price is agreed is a negotiation the buyer has already lost. That is the same logic that governs mergers and acquisitions advisory work and the verification that sits inside it.

The wider lesson is that verification is a discipline rather than a document. The tools are public records, lawful enquiries and structured questioning, and they are the same tools a lender uses before advancing money and a development finance lender uses before funding housing, as our notes on community development finance describe. What separates a good check from a weak one is not access to secret information. It is deciding in advance what would change your mind, and then going to look for it.

About the author

Jennifer Roberts

Director, Risk & Compliance

Jennifer Roberts is our risk and compliance director. With expertise in financial strategy, risk management, and regulatory compliance, she ensures our clients are always protected.

View all articles by Jennifer
Keep reading

Related analysis in Finance & Risk

All Finance & Risk