M&A due diligence is an exhaustive audit of your company. Acquirers look for red flags in four main areas: financials, legal/IP, team/culture, and product/customers. The biggest deal-killer is not the existence of problems, but undisclosed surprises. Proactively identifying and addressing issues like poor financial controls, unclear IP ownership, or high customer concentration is critical to closing the deal.
Key takeaways
- Audit your financials for the 12-18 months pre-diligence. Look for inconsistencies, revenue concentration, and weak cash flow.
- Ensure every line of code and piece of IP is owned by the company, with clear assignment from all employees and contractors.
- Identify key-person dependencies. Have a plan for who runs what if a critical team member leaves post-acquisition.
- Not every red flag is a deal-killer. Proactively disclosing and proposing a solution can build trust and save the deal.
- The biggest red flag of all is a surprise. Be ruthlessly honest with your data room and your acquirer.
- A deal is not closed until the money is in the bank. Stay focused on running the business through the entire diligence process.
Your House Must Be in Order
M&A due diligence is a forensic audit of your business. The buyer’s goal is to verify your claims, uncover hidden risks, and confirm the strategic value of the acquisition. It is intense, invasive, and exhausting. If you aren’t prepared, it will kill your deal.
An acquirer isn't looking for a perfect company. They are looking for a company they understand. The biggest red flag is not the existence of a problem—it’s a problem you didn’t disclose. Surprises destroy trust, and trust is the currency of a successful acquisition.
This guide outlines the major red flags that kill deals, framed so you can get your house in order before you enter a process. Most of these can be mitigated, but only if you find them first.
Financial Red Flags: Numbers Don’t Lie
Your financials are the first wall the diligence team will try to breach. They will have a team of accountants—often from a Big Four firm—combing through every transaction. Your job is to make their job easy and predictable.
The Checklist: Audit Yourself First
Inconsistent or Messy Financials: Do your yearly P&Ls, balance sheets, and cash flow statements all tell the same story? Are your revenue recognition policies standard for your industry (e.g., ARR for SaaS)? Messy, non-standard, or constantly restated financials scream that you don't have control of your own business. · Cash Flow Problems: Profitability on paper means nothing if you can’t pay your bills. Acquirers will scrutinize your operating cash flow. If you are regularly using bridge loans or drawing on a line of credit to make payroll or pay vendors, they will see it as a sign of operational instability. · Unsustainable Revenue Quality: Where does your revenue come from? A sudden, pre-deal spike from a one-time project or by pulling forward contract renewals is a massive red flag. Buyers will normalize revenues to understand the true, recurring run rate of the business. Be prepared to explain every single revenue anomaly. · Customer Concentration: This is a classic. If more than 20-25% of your revenue comes from a single customer, the acquirer sees a huge risk. What if that customer leaves a month after the acquisition closes? You need to show that your revenue is diversified or that your key customer contracts are long-term, stable, and transferable. · Bloated Accounts Receivable (A/R): A large and aging A/R balance suggests your customers aren't paying on time. This is another cash flow killer. Buyers will ask: Why are customers slow to pay? Is it because they are unhappy with the product? Are your collection processes broken?
The Non-Obvious Mistake
Founders often focus only on the P&L. But the diligence team spends just as much time on the balance sheet. They will scrutinize your debt covenants, deferred revenue liabilities, and accrued expenses. A common killer is off-balance-sheet liabilities — for example, a verbal promise for a massive bonus that was never documented. Every material financial obligation must be on the books.
Legal & IP Red Flags: Who Owns Your Company?
This is where deals most often die a sudden death. Financial issues can sometimes be fixed with price adjustments. Fundamental legal and ownership issues are often fatal.
The Checklist: A Clean Cap Table and IP History Are Not Optional
Unclean IP Assignments: Who wrote your code? Who designed your logo? You must have signed intellectual property assignment agreements from every single employee, founder, and contractor, past and present. Without a clean chain of title back to the corporation, you are selling something you don’t fully own. A single freelance developer who used their own laptop and never signed an agreement can hold up a multi-million dollar deal. · Poisonous Open-Source Licenses: Using open source is standard. Using it incorrectly is a catastrophe. Diligence teams use tools like Black Duck to scan your codebase for open-source libraries. If you’ve used code with a "copyleft" license like AGPL in your core, proprietary product, the buyer may argue your entire product must now be open-sourced. This can kill a deal on the spot. · Cap Table Ambiguity: Your capitalization table must be precise and verifiable. This means no handshake equity deals, no vague promises of advisor shares, and properly documented exercise of all options. Any ambiguity creates a risk of future lawsuits from ex-employees or advisors, a risk the acquirer will not want to inherit. · Pending or Threatened Litigation: You must disclose any and all legal threats, even if you feel they are baseless. The acquirer’s legal team will do their own searches and discover them anyway. Hiding a lawsuit is an unforgivable breach of trust. · Tax Non-Compliance: Failure to pay state sales tax, misclassifying employees as contractors, or non-payment of payroll taxes are ticking time bombs. The liability for these errors (plus penalties) transfers to the acquirer. A tax specialist will spend weeks reviewing your filings. Common pitfalls include sales tax nexus issues triggered by remote employees and missteps in R&D tax credit claims.
Team & Culture Red Flags: The People You’re Selling
For many deals, especially acquihires, the team is the primary asset. The diligence process here is about assessing the quality and stability of that asset.
The Checklist: Assess Your Human Capital Risk
Key Person Dependency: Is the entire company reliant on one brilliant engineer or the founder’s sales relationships? The buyer will identify this single point of failure and demand a plan. This usually involves a multi-year retention package for that key person, which will come directly out of your purchase price. · Toxic Culture: The acquirer will interview a dozen or more of your employees. They are trained to spot signs of a toxic environment: backstabbing, fear of management, low morale. A culture mismatch is a leading cause of M&A failure, and buyers are increasingly screening for it. · No Clear Leadership Tier: If the founders are the only ones with any real authority or institutional knowledge, the business is not scalable or integrable. The buyer wants to see a functioning management layer that can run the business. · The Reluctant Founder: If you, the founder, seem disengaged, burned out, or unwilling to commit to a transition period of at least 1-2 years, the buyer will walk. They are buying the business and its leadership. You are part of the package.
Product & Customer Red Flags: Is the Product What You Claim?
Finally, the buyer needs to know that the product works, customers love it, and the market is real.
The Checklist: Validate Your Value Prop
High, Hidden Churn: You might be growing top-line revenue, but if you have a leaky bucket, the buyer will find it. They will analyze cohort retention and logo churn. Be prepared to explain why every single customer left over the past 24 months. · Extreme Technical Debt: Is your product held together with duct tape? If a complete rewrite or massive refactoring is needed just to keep the lights on, the cost of that effort will be factored into the price, or it may make the deal untenable. Be ready for a "clean room" code review. · Disgruntled Customers: The buyer will talk to your customers. If the story they hear on these reference calls is different from the one you told, the deal is in jeopardy. Choose your references wisely, but also be aware they may contact customers not on your list.
From Red Flag to Renegotiation
Not every red flag has to be a deal-killer. The key is proactive disclosure and problem-solving. If you know your customer concentration is too high, don't wait for the buyer to find it. Prepare a slide that addresses it head-on:
"Our largest customer accounts for 30% of our FY23 revenue. This is a risk we actively manage. The contract is three years in length with two years remaining, and we’ve embedded our product deeply into their workflow. Furthermore, here is our pipeline for the next six months, showing our plan to reduce concentration to under 20% by Q4."
By controlling the narrative, you turn a potential red flag into a demonstration of your operational maturity. It shows the buyer you understand risk and are capable of mitigating it. This builds the trust you need to get to the finish line.
How to Apply This Before Your Deal
Before you even think about signing an LOI, run your own sell-side diligence. It’s the single best way to maximize your valuation and your certainty of closing.
Hire a quality M&A-focused law firm and accounting firm. Do this before you have a buyer. Have them audit your cap table, IP assignments, and last two years of financials. · Run a codebase scan. Use a tool like Black Duck or Snyk to find and remediate any problematic open-source licenses now. · Build a preliminary data room. Start assembling the documents: all signed contracts, financial statements, employee agreements, etc. The act of building it will reveal the holes you need to plug. · Role-play the hard questions. Sit down with your co-founders and ask: "What is the ugliest thing about our business? What are we most scared they will find?" Assume they will find it, and prepare the explanation now.
Frequently asked questions
- How long does M&A due diligence typically take?
- Expect 30 to 90 days for a standard deal. For complex acquisitions involving heavy regulatory scrutiny or a large, multinational target, it can extend to several months.
- What's the difference between a red flag and a yellow flag?
- A red flag is a potential deal-killer (e.g., fraudulent accounting, core IP you don't own). A yellow flag is a serious issue that likely requires negotiation, a price reduction, or a specific escrow/indemnity (e.g., high customer concentration, a pending lawsuit).
- Can I fix red flags during the diligence process?
- Sometimes, but it's risky and looks reactive. It's far better to conduct your own internal 'sell-side' diligence and fix issues *before* you go to market. Discovering and fixing problems in real-time erodes buyer trust.
- Do acquirers talk to my customers during diligence?
- Yes, always. They will conduct reference calls with your largest and most strategic customers, and sometimes churned customers. They want to verify your relationship, satisfaction levels, and the product's value proposition.
- What is a 'clean room' in technical due diligence?
- A clean room is a controlled environment where a third-party expert can review your source code without the acquirer's own engineers seeing it directly. This protects your trade secrets if the deal falls apart, preventing any claim you 'tainted' their own development efforts.