When acquiring a company, you inherit all its legal and regulatory liabilities—a concept called "successor liability." Effective diligence is not a legal checkbox exercise but a core part of valuation. This guide provides a tactical framework for uncovering risks in employment, data privacy, IP, and corporate governance, helping you adjust the deal price or walk away before it’s too late.
Key takeaways
- Treat compliance diligence as a valuation exercise, not a legal chore. Problems directly reduce the company’s value.
- Employment issues are the #1 source of hidden M&A risk. Aggressively probe contractor classification and equity hygiene.
- A weak data privacy or security posture can trigger fines that wipe out the value of the deal. Verify their GDPR/CCPA process.
- Contamination from "copyleft" open-source licenses can force you to open-source your own proprietary code.
- Use diligence findings as leverage: negotiate a lower price, demand a specific indemnity, or walk away.
- Start preparing now. Run a self-audit and create a "diligence-ready" data room to maximize your own valuation for a future exit.
You Don’t Just Buy the Code, You Buy the Sins
An acquisition looks like the ultimate growth hack. You can buy a team, a product, or a customer base overnight, leapfrogging your roadmap by years. But the single biggest mistake founders make is believing they are just buying the assets. In a typical startup acquisition (a stock purchase), you are buying the entire legal entity, and with it, every liability it has ever accrued. Every past mistake is now your problem. This is successor liability.
Imagine you acquire a 15-person startup for what seems like a great price. Six months post-close, you discover they misclassified all their engineers as independent contractors. Now you are on the hook for federal and state back taxes, fines, and penalties. A conservative estimate for remediation is 30-40% of the contractors' total historical compensation. If you're talking five engineers paid $150,000 a year for two years, you could easily be looking at a $450,000–$600,000 bill. Your "great deal" just became a financial and operational nightmare.
Regulatory and compliance diligence isn’t a checkbox exercise to hand off to your lawyers. It’s a core part of valuing the company and understanding the true cost of the acquisition. A poorly-run, non-compliant company is worth less. Your job is to find the rot before you sign.
The Core Mistake: Treating Diligence as a Backstop
Founders new to M&A wrongly believe that the "reps and warranties" in the purchase agreement protect them. In the agreement, the seller will represent (or "rep") that they are compliant with all laws. If you discover a breach after the deal closes, your only recourse is to sue the founders you just acquired for that cash.
This is a terrible plan. It’s hostile, expensive, and the outcome is uncertain. You don't want to be suing your new Head of Product. The purpose of diligence is not to have a legal claim later, but to uncover facts now so you can avoid paying for them.
A disorganized or defensive response to your diligence requests is a major red flag. A poor compliance culture is a leading indicator of deeper, hidden problems. Trust the signal.
A Tactical M&A Compliance Checklist
Diligence moves risk from the "unknown" bucket to the "known" bucket. Once a risk is known, you can price it, mitigate it, or walk away. Use this framework to probe the highest-risk areas for early-stage companies.
1. People and Employment: The #1 Hidden Liability
This is where the vast majority of startup skeletons hide. It’s operationally complex, varies state by state, and founders almost always get something wrong.
A complete employee/contractor census: names, titles, locations (state and country), start dates, W2 vs. 1099 status, and compensation history. · Template employment agreements, contractor agreements, and offer letters. · Evidence of employer registration in every state where an employee or contractor resides. · A complete list of all historical and current HR disputes, claims, or agency inquiries. · The full cap table and history of all stock option grants, including board consents and 409A valuation reports.
Contractor Misclassification: The most common problem. If a "contractor" has a company email, a manager, set hours, or uses a company laptop, they are likely a misclassified employee. As the buyer, you will be on the hook for back payroll taxes, unemployment insurance, and workers' comp, plus penalties. Budget 30-40% of their total compensation for remediation. · Geographic Mess: Employees working in states where the company isn’t registered to pay payroll taxes is a guaranteed, expensive cleanup. You'll owe back taxes plus penalties, and the process can take months of administrative pain. · Weak Equity Hygiene: Look for stock options granted without a supporting 409A valuation. The IRS can deem these grants improper, creating a massive tax headache for the employees you want to retain. Fixing this requires expensive legal help and can trigger painful renegotiations. · Unpaid Interns: Unless an internship program meets a very strict, multi-point test, it’s likely an unpaid wage violation. This is low-hanging fruit for plaintiff’s lawyers.
2. Data Privacy and Security: The Ticking Time Bomb
If the target company holds customer data, you aren’t just buying an asset; you’re inheriting a promise to protect it. More importantly, you’re inheriting the liability for any past failure to do so.
Public-facing privacy policy and terms of service (and all historical versions). · Internal data handling policies and procedures. Is there a written security plan? · A list of all third-party vendors that process user data (e.g., AWS, Stripe, Segment) and the associated Data Processing Agreements (DPAs). · Details of any past or present security incidents, data breaches, or user complaints related to privacy. · Any security certifications (like SOC 2) or penetration test results.
No GDPR/CCPA Plan: If they have users in Europe or California, they are subject to these laws. Ask them: "If I sent you a data deletion request right now, walk me through the exact steps you'd take to fulfill it." If they can’t answer, they are non-compliant. GDPR fines can reach 4% of global annual revenue. For a company with $25M in revenue, that’s a potential $1M liability you are inheriting. · "Leaky" Vendor Contracts: Storing customer data with a vendor without a proper DPA is a direct violation of GDPR/CCPA. This shows a fundamental misunderstanding of modern privacy law. · History of Breaches: Any past incident, no matter how small, is a signal. Ask how they handled it. Did they notify users and regulators? A failure to follow proper breach notification laws is a separate and significant liability. · No Written Security Program: This signals that security is an afterthought. The lack of a SOC 2 report in a B2B SaaS company is a major commercial red flag; it suggests they can't pass a basic security audit.
3. Intellectual Property: Is the Code Actually Theirs?
You believe you're buying a proprietary codebase. Diligence is the process of verifying they actually own it, free and clear of any encumbrances.
A complete list of all open-source software (OSS) used in the product, including the specific license for each component. · Copies of all employee and contractor IP assignment agreements (sometimes called PIIAs). · A list of all patent, trademark, and copyright filings. · Any correspondence related to claims of IP infringement.
No OSS Inventory: If they don't have a tool (like FOSSA, Snyk, or Black Duck) to track their open-source dependencies, they are flying blind. This is an immediate, serious red flag. · "Copyleft" License Contamination: Use of OSS under a "viral" license like GPL or AGPL can legally require you to make your own proprietary code that links to it available as open source. This can render the IP you're acquiring worthless, or require a rewrite costing millions. · Missing IP Assignments: Ask this question directly: "Can you confirm that 100% of people who have ever contributed code have signed an IP assignment agreement?" If a key early engineer never signed, they could theoretically walk away and claim ownership of a core part of your product. This can kill a deal or become a source of "hold-up" litigation.
4. Corporate and Financial Integrity
This is about foundational business hygiene. Sloppiness here is a strong signal of sloppiness everywhere else.
Corporate formation documents, bylaws, and board minutes/consents. · An up-to-date cap table, ideally from a platform like Carta or Pulley. · All material customer and vendor contracts. · Audited or reviewed financial statements, prepared by a reputable accounting firm. · Proof of registration to do business in every state where they have an office or employees.
Sloppy Governance: Missing board consents for financing rounds, stock grants, or other major decisions. This creates a chain-of-title risk for the equity and requires expensive legal cleanup. · Problematic Contract Clauses: Look for non-standard "change of control" clauses that could be triggered by your acquisition, forcing a payout or allowing the customer to terminate. Also look for unusual service commitments you can't fulfill profitably. · Sales Tax Nexus: SaaS companies often have an obligation to collect and remit sales tax in states where they have significant revenue, not just employees. Failure to do so creates a state tax liability that you will inherit. · FCPA/Anti-Bribery Risk: For companies with international sales, you need to scrutinize how they compensate sales agents. Poorly documented, high-commission payments can be a cover for bribes, a violation of the Foreign Corrupt Practices Act (FCPA). The DOJ explicitly targets successor liability in this area.
Structuring the Diligence Process
Don't try to boil the ocean at once. A phased approach is faster and more efficient.
Before you spend a dime on lawyers, get the seller on a call and ask a few knockout questions. A "no" to the first question or a hesitant "yes" to the others is a signal to dig deeper before proceeding.
"Can you confirm 100% of employees and contractors have signed IP assignment agreements?" · "Have you experienced any data breaches or security incidents, even minor ones?" · "Do you have a complete open-source inventory and a policy against using copyleft (GPL) licensed code?" · "Are all employees and contractors located in states where you are registered to do business?"
Once you have a signed, non-binding Letter of Intent (LOI), you and your lawyers get access to the virtual data room (VDR). Insist on a clear VDR structure that mirrors your diligence request list. Track every question and response in a shared tracker and hold a weekly diligence call to resolve open issues.
The seller may hesitate to share their most competitive secrets (e.g., customer names, source code) until closing is certain. For these items, you can use a "clean team"—a small, isolated group of your lawyers or a third-party consultant who can review the sensitive data and provide a summary of its quality and risk without leaking the raw data to your core team.
From Diligence Findings to Deal Terms
Finding problems doesn’t always mean you should walk away. It means you need to re-evaluate the deal. You have three tools:
Price Reduction: This is the most common path. Quantify the cost of the fix and treat it as a reduction in the company's value. If you found five misclassified engineers and estimate a $200,000 remediation cost, you should reduce the purchase price by that amount. · Specific Indemnity: For a known, high-risk issue, you can create a special escrow or holdback from the purchase price specifically to cover that risk. If the liability materializes, you use the escrow funds to pay for it. If it doesn't after a set period, the money is released to the seller. · Walk Away: Some problems are too fundamental to solve. IP contamination from a GPL license, evidence of intentional fraud, or a founder culture that is actively hostile to compliance are all valid reasons to kill the deal.
How to Apply This This Week
M&A readiness is a proxy for being a well-run company. Getting your house in order now will maximize your valuation when it's your turn to sell.
Run a Self-Audit: Block two hours this Friday. Go through the checklist above and apply it to your own startup. Write down your top three areas of risk. · Scope the Fix: Schedule a one-hour call with your corporate lawyer. Share your self-audit and ask them to estimate the cost and timeline to fix your #1 issue. It’s often cheaper than you think if you’re proactive. · Build a "Diligence-Ready" Folder: Create a folder in your secure drive. Add your corporate formation docs, standard employment/contract agreements, your cap table, and board consents. A prepared seller looks professional, instills confidence, and faces less friction in a deal process.
Frequently asked questions
- What's the difference between a stock purchase and an asset purchase?
- In a stock purchase, you buy the entire company, inheriting all its past, present, and future liabilities. In an asset purchase, you only buy specific assets (like code or customer lists), leaving most liabilities with the seller. Asset purchases are cleaner but often less tax-advantaged for the seller.
- What is 'successor liability' in an M&A deal?
- It's the legal principle that the acquiring company is held responsible for the liabilities of the target company. If they failed to pay taxes or violated a law before you bought them, you are now legally on the hook to fix it and pay the penalties.
- How much does M&A legal diligence typically cost?
- Costs vary with deal complexity, but for an early-stage startup acquisition, expect to spend $25,000 to $100,000+ on legal and financial diligence. This is a small price to pay to avoid inheriting a seven-figure liability.
- What is Reps & Warranties Insurance (RWI)?
- RWI is an insurance policy that covers losses from breaches of the seller's representations and warranties. It allows you (the buyer) to get paid out by a third-party insurer instead of having to sue the seller, making the deal much less contentious.