Buy-Side Due Diligence Request List for Deal Teams

Buy-Side Due Diligence Request List for Deal Teams: Pageform

Ksenia Moskalenko

Co-Founder @ Pageform | AI-native narrative data rooms for fundraising & deals

Connect with me on X | I want to help you build a better data room!

Connect with me on X | I want to help you build a better data room!

Most diligence checklists you find online are written for the seller. They tell a target what to upload. This one is written for the buyer. If you sit on a corporate development team, a private equity deal team, or an investment bank running buy-side, your job is not to fill a room. Your job is to interrogate one. You send the request list, you chase what is missing, and you turn what you find into a price and a set of conditions. This piece gives you the request list itself, grouped by workstream, with the specific items that most often hide problems. It also covers how to run the acquirer side of the room so nothing falls through the cracks between your advisors, your investment committee, and the seller.

Why the buy-side request list is different from the seller's index

A seller builds a room to tell a clean story. A buyer builds a request list to test whether that story survives contact with the documents. Those are opposite jobs. The seller wants the folder tree to look complete. You want to know what is not there.

Three failures repeat on the buy-side, and all of them trace back to a weak request list. First, the team accepts the seller's index as the scope of diligence, so it only reviews what the seller chose to show. Second, requests live in email and a spreadsheet that nobody reconciles, so open items get lost and resurface the week before signing. Third, findings never make it from the associate reading a contract to the partner writing the investment committee memo, so a real risk gets discovered twice or not at all.

The fix is a request list you own, tracked against the room, tied to the memo you have to write. Build it before you see a single document. Send it as a numbered set so every item has a status. Then work it down.

Financial diligence: what to demand and what to verify

Start here, because the number moves the deal. Ask for audited financials for the last three years, monthly management accounts through the most recent close, and the trial balance behind them. Then go past the headline.

Request the quality of earnings support: a bridge from reported EBITDA to adjusted EBITDA with every add-back itemized. Owner compensation, one-time legal costs, and pro forma cost savings are where sellers pad the number. Make them defend each add-back with source documents, not a summary tab. Ask for the working capital detail by month so you can set the peg you will true up at close, and request an aged accounts receivable and accounts payable listing to see how much of the balance is real and collectible.

Pull revenue by customer and by cohort. Concentration is a pricing input. If the top three customers are half of revenue, that changes both the multiple and the reps you will demand. Ask for the deferred revenue schedule, the debt and debt-like items list, and every off-balance-sheet commitment. The items sellers forget to volunteer are usually earnouts owed, unfunded pension or PTO liabilities, and customer prepayments that are really debt.

Get the corporate record first: the cap table, the stock ledger, all option grants, and every shareholder agreement. A messy cap table can stall a signing for weeks, so confirm who actually owns what before you spend money on outside counsel.

Request all material contracts, and read the change-of-control and assignment clauses in each. In an acquisition, a single consent right in a key customer or supplier contract can hand that counterparty leverage over your timeline. Ask for the full litigation history, open and threatened, plus any regulatory correspondence. Request the IP schedule with assignment confirmation, because unassigned founder or contractor IP is a classic late-stage surprise. If the deal crosses a size threshold, put antitrust filing analysis on the list early, since the waiting period sets your outside date.

Commercial and customer diligence

This workstream tells you whether the revenue is durable. Ask for the pipeline with stage and probability, win-loss data, and churn or retention by cohort. Request the top customer contracts, pricing history, and any recent renewals or losses. A book of business that renews on price alone prices very differently from one that renews on switching cost.

For subscription or recurring models, demand the metrics behind the number: gross and net revenue retention, logo churn, and the calculation files, not just a chart. If the seller cannot produce the underlying data, treat that as a finding, not a delay.

Operational, tech, and HR diligence

Ask for the org chart, a headcount roster with tenure and comp, and the list of key employees whose departure would impair the business. Request the retention and change-of-control arrangements, because you may inherit or need to fund them. Get the employee classification detail, since misclassified contractors are a common and expensive cleanup.

On technology, request the architecture overview, the third-party and open-source license inventory, and the security posture: recent penetration test results, any breach history, and current certifications. For any deal touching customer data, ask for the data processing records and the list of subprocessors. On operations, get the key supplier contracts, insurance policies, and any environmental or facilities reports the asset requires.

Tax and structuring

Request the last three years of returns across all jurisdictions, plus any open audits or notices. Ask for the transfer pricing documentation if the target operates across borders, and the sales and use tax history if it sells into many states. Tax exposures rarely kill a deal, but they reshape the structure and the escrow. Put them on the list early so your structuring is not a scramble at the end.

How to run the acquirer side of the room

A request list only works if the room around it is disciplined. On the buy-side you are usually managing a room the seller controls, plus your own internal room where your team, your advisors, and your investment committee assemble the picture. The second room is where deals are actually won or lost, and it is the one most teams neglect.

Keep one master tracker that maps every request to a status: outstanding, received, under review, or flagged. Reconcile it against the seller's room weekly, not at the end. When a document lands, the reviewer records a finding in the same place, so the person writing the investment committee memo reads conclusions, not raw files. This is exactly the discipline our sell-side room guide asks of the other side of the table, and running your buy-side process with the same rigor is what lets you retrade credibly or walk away early.

Watch engagement, not just delivery. When the seller uploads a revised contract at 11pm the night before your committee meets, that timing is information. Rooms that expose page-level document analytics let you see which revised documents your own reviewers have actually opened, so a late change does not slip past the associate who owns that workstream. Private equity teams running several targets at once lean on this hard, and the mechanics are worth studying in how private equity firms manage due diligence across a portfolio.

Set access rules that match the deal stage. Early on, your outside counsel and QoE provider need scoped access to their workstreams only. As you move toward signing, widen it. Permissions that mirror the workstreams above keep advisor fees down and keep confidential findings inside the team that needs them.

A staged sequence you can act on today

You do not send everything at once. Sequence the list so early findings shape later requests.

In the first pass, request financials, the cap table, material contracts, and the customer list. These four decide whether the deal is real. In the second pass, once the number holds, go deep on quality of earnings, working capital, litigation, IP, and key-employee arrangements. In the confirmatory pass before signing, verify the items that feed reps, escrow, and closing conditions: tax exposures, consents required, and any environmental or security reports. Keep every open item visible until it closes. The deals that slip are the ones where a stale request sat unread in someone's inbox while the clock ran.

FAQ

What is the difference between a buy-side and a sell-side data room?

A sell-side room is the target's room, built to present the business to buyers. A buy-side room is the acquirer's own workspace, where your deal team, advisors, and investment committee collect what the seller provides, record findings, and build the decision. You review the seller's room and run your own. The two serve opposite goals, and strong buyers keep both organized rather than working only inside the seller's folder tree.

How long should buy-side due diligence take?

It depends on deal size and complexity, but a mid-market process often runs four to eight weeks from signed letter of intent to close. The variable that moves that range is not document volume. It is how fast open requests get answered and reconciled. A disciplined tracker that shows every outstanding item, updated weekly, shortens the timeline more than any single tool.

What do buyers most often miss in diligence?

The common misses cluster in a few places: unassigned intellectual property, change-of-control consents buried in key contracts, misclassified contractors, and add-backs in the earnings bridge that do not survive scrutiny. None of these hide well when you send a specific numbered request list and verify against source documents instead of accepting summary tabs.

Can a general file-sharing tool run buy-side diligence?

It can hold files, but it cannot show you which of your own reviewers opened a revised document, cannot map requests to findings, and cannot enforce workstream-level permissions across your advisors. Those gaps are where open items get lost. A room built for structured deal review keeps the request list, the documents, and the findings in one place, which is the whole point of running a buy-side process rather than a shared folder.

Who should own the request list on the deal team?

One person, usually a corporate development lead or a deal associate, owns the master tracker and reconciles it against the room weekly. Workstream leads record findings, but a single owner keeps status accurate. When ownership is split across email threads, requests fall through the cracks, which is the failure mode this checklist exists to prevent.

Run your next acquisition from a room built for the buy-side

The request list only pays off if the room around it turns documents into decisions. Pageform is an AI-native, narrative-driven data room designed for fundraising, sales, and partnership deals, and the same structure that helps sellers present cleanly helps buyers interrogate a target, track every open request, and hand the investment committee findings instead of raw files. See how it fits your next deal at pageform.io.

A