Key Takeaways
- Florida business law protects companies from unfair competition, contract breaches, and partner disputes.
- Acting early saves time, money, and business relationships.
- An experienced business attorney helps you assess risk and choose the right legal strategy.
If you’re acquiring a small or mid-size business, request these items in your first 48 hours after signing the Letter of Intent (LOI): three to five years of financial statements, business tax returns, all material contracts, a list of top customers by revenue, IP and licensing records, real estate leases, employee agreements, and a summary of the target’s IT and cybersecurity posture. That’s the core of any serious business acquisition due diligence checklist, and everything else builds on it.
Before you read another word, do three things:
- Set up a virtual data room (VDR) and assign one person, on your side, to own it.
- Send the seller a written wave-one document request covering financials, customer contracts, and corporate records.
- If the deal is worth more than a few million dollars, line up a Quality of Earnings (QoE) provider or a transaction accountant now, not after you find a problem.
Typical diligence for a small or mid-market deal runs 30 to 45 business days from LOI to closing when the data room is organized and the seller responds quickly. Some deals stretch to 60 or 90 days when the seller’s records are disorganized, when a Quality of Earnings review surfaces unresolved questions, or when the transaction touches regulated industries. A fast close usually means the seller had a clean, pre-built data room. An extended one almost always traces back to missing documents or a seller who wasn’t ready to sell.
Key Takeaways
A thorough business acquisition due diligence checklist combines financial verification, legal and contract review, and customer concentration analysis within a 30 to 75-day window scaled to deal size.
| Point | Details |
|---|---|
| Start the data room immediately | Launch the VDR and send a wave-one request letter within 48 hours of signing the LOI. |
| Verify, don’t assume | Treat compiled financial statements without a CPA review as a finding, not a formality. |
| Watch customer concentration | Flag any single customer above 15 to 20% of revenue for deeper review and possible price adjustment. |
| Engage advisors early | Line up your QoE accountant and transaction attorney in week one, not after problems surface. |
| Get legal review on contracts and closing docs | Fornarolegal supports buyers through contract negotiation, escrow drafting, and closing representation. |
Table of Contents
- What a Business Acquisition Due Diligence Checklist Actually Covers
- What Are the Core Due Diligence Workstreams?
- Financial Due Diligence: What to Request and Verify
- Legal and Corporate Due Diligence: Records and Litigation Checks
- Tax Due Diligence: Returns, Notices, and Exposure
- Commercial and Customer Due Diligence: Concentration and Retention
- Operational, IT, and Cybersecurity Diligence
- HR, Benefits, and Key-Person Risk
- Real Estate, Assets, and Environmental Diligence
- Intellectual Property and Technology Review
- How to Review Material Contracts for Assignability Risk
- Building the Data Room and the Initial Request Letter
- Running the Process and Managing the Risk Register
- When to Bring in Attorneys, Accountants, and Technical Experts
- What Most Buyers Get Wrong About Due Diligence
- How Legal Counsel Reduces Risk During an Acquisition
- Sources
What a Business Acquisition Due Diligence Checklist Actually Covers
Due diligence is the structured investigation a buyer runs on a target company before signing a purchase agreement, and it exists to answer one question: does the business perform the way the seller says it does? That means verifying financial statements, checking legal exposure, confirming tax compliance, testing customer relationships, and inspecting operations, technology, and physical assets. Thomson Reuters frames this as both “hard” diligence (financial and legal data you can verify on paper) and “soft” diligence (culture, key-person dependency, and customer relationships that don’t show up in a spreadsheet but often decide whether revenue survives the transition).
The process usually moves through five phases: data room launch, first-pass document review, management interviews and site visits, cross-functional synthesis into a risk register, and final negotiation on price or terms. DealRoom’s process breakdown lays out a structured seven-step version of this that many advisors use as a template, and it maps closely to the six-week timeline most mid-market deals target when the seller cooperates.
You start diligence once the LOI is signed and exclusivity kicks in, not before. Running it earlier wastes advisor fees on a deal that might not survive negotiation. You can compress the timeline if the seller pre-built a clean data room and the business is simple (one location, few contracts, straightforward revenue). You should extend it when the target has multiple entities, foreign ownership, regulated licenses, or a customer base concentrated in a handful of accounts.
Pro Tip: Front-load the workstreams that carry the most negotiating leverage: financial, legal, customer concentration, and IT/cyber. If you’re going to find a deal-breaker, you want to find it in week two, not week six, while you still have room to renegotiate price or walk away without sunk advisor costs.
What Are the Core Due Diligence Workstreams?
A complete review runs across roughly ten parallel workstreams, and CT Acquisitions’ breakdown of the process notes that buyers typically spend $50,000 to $300,000 on third-party fees for mid-market deals, depending on how many specialists you need and how complicated the target is. Each workstream answers a different question about risk, and skipping one doesn’t save time, it just moves the risk to after closing, where it’s far more expensive to fix.
| Workstream | What It Assesses | Typical Specialist |
|---|---|---|
| Financial | Revenue quality, normalized earnings, working capital | CPA or QoE provider |
| Legal/corporate | Entity structure, litigation, contract validity | Transaction attorney |
| Tax | Compliance history, exposure, structure impact | Tax attorney or CPA |
| Commercial/customer | Concentration, retention, contract terms | Deal team or commercial analyst |
| Operations | Process efficiency, supply chain dependency | Operations consultant |
| HR/benefits | Key-person risk, compliance, liabilities | HR or benefits consultant |
| IT/cybersecurity | Systems, breach history, license compliance | IT security specialist |
| IP/technology | Ownership, licensing, transferability | IP attorney |
| Real estate/assets | Leases, title, equipment condition | Real estate counsel or appraiser |
| Environmental | Contamination, regulatory history | Environmental consultant |
Financial and legal findings drive the most re-trades, but customer concentration and IT/cyber issues are the ones buyers most often underweight until they’ve already signed.
Financial Due Diligence: What to Request and Verify
Pull three to five years of audited or reviewed financial statements, trailing-twelve-month (TTM) profit and loss statements, the full general ledger, trial balance, bank statements, all debt schedules, accounts receivable and payable aging reports, and capital expenditure history going back at least three years. If the seller can only produce compiled statements with no CPA review behind them, treat that as a finding, not a formality.
Once you have the documents, run these checks:
- Reconcile the general ledger to the reported EBITDA line by line.
- Validate every add-back the seller claims (owner salary normalization, one-time legal fees, discretionary perks) against actual invoices or payroll records.
- Test revenue quality at the individual customer level, not just in aggregate, to see whether growth is broad-based or concentrated in one or two accounts.
- Normalize working capital and compare capex trends against depreciation to spot deferred maintenance the seller hasn’t disclosed.
Some adjustments hold up under scrutiny: a genuine one-time legal settlement, a documented above-market owner salary, or a discontinued product line with clear financial separation. Others rarely survive: vague “miscellaneous” add-backs, personal expenses run through the business without receipts, or repeated “non-recurring” items that show up three years running.
Pro Tip: If the deal is worth more than roughly $2 million, commission a third-party Quality of Earnings review even if the seller already has audited financials. A QoE provider tests the numbers the way a buyer would, not the way an auditor checking compliance would, and that difference in perspective is exactly where retrades come from.
Legal and Corporate Due Diligence: Records and Litigation Checks
Request the articles of incorporation or organization, bylaws or operating agreement, the full minute book, stock ledger or cap table, any shareholder or buy-sell agreements, and current good-standing certificates from the state of formation. Gaps in the minute book, missing board resolutions for major decisions, or an outdated cap table are common findings that signal the seller hasn’t kept clean corporate hygiene, which raises the odds of other undisclosed issues.
Review pending and threatened litigation carefully, including anything the seller considers “minor” or “resolved.” Off-balance-sheet litigation exposure, meaning a claim the seller hasn’t reserved for or disclosed because they believe it’s meritless, is one of the more common surprises buyers discover after closing. Ask directly and in writing whether there is any threatened claim, regulatory inquiry, or employee dispute that hasn’t been formally filed yet.
Assignability and change-of-control clauses deserve their own pass. Many customer, vendor, and lease agreements include language that terminates or requires consent when ownership changes. Missing this during diligence can mean losing a top customer contract the week after closing, with no recourse. Our guide on spotting legal red flags in business contracts walks through exactly which clauses tend to hide this risk.
Finally, verify every license, permit, and industry-specific regulatory approval the business needs to operate. A restaurant without a current health permit, a contractor without an active license, or a healthcare business without proper certifications isn’t a paperwork issue, it’s a business you may not be legally allowed to run the day you close.
Pro Tip: Order state good-standing certificates yourself rather than relying on the seller’s copy. They’re inexpensive, take a few days, and catch dissolved or administratively revoked entities that sellers sometimes don’t realize have lapsed.
Tax Due Diligence: Returns, Notices, and Exposure
Collect federal and state tax returns for the prior three to five years, tax provision workpapers, any correspondence with the IRS or state tax authorities, payroll tax filings, sales and use tax filings, and records of any audits or notices received. If the business operates across state lines, check whether it has properly registered and remitted sales tax in every state where it has economic nexus.
Watch for these red flags:
- Recurring adjustments on amended returns, which suggest a pattern of errors rather than a one-time mistake.
- Unpaid or late payroll tax deposits, which can carry personal liability exposure that follows the responsible party, not just the entity.
- Tax positions taken without a supporting memo from a CPA or tax attorney, especially around aggressive expense classifications.
- Large uncertain tax positions sitting on the balance sheet with no clear resolution plan.
Tax exposure directly shapes deal structure. An asset purchase generally shields the buyer from most historical tax liabilities of the entity, while a stock purchase can carry those liabilities forward unless you negotiate specific protections. When tax risk shows up in diligence, buyers typically respond with a purchase price escrow, a specific indemnity tied to the tax exposure, or a straight purchase price reduction. For businesses with a history of IRS scrutiny, a small business IRS audit checklist is a useful reference for understanding what triggers audits in the first place.
Commercial and Customer Due Diligence: Concentration and Retention
Request the top 20 customers by revenue for the last three years, every contract tied to the top accounts, historical churn and retention data, and permission to conduct a handful of customer reference calls. Sellers sometimes resist reference calls out of fear of tipping off customers to a sale, but a buyer who can’t validate customer relationships is buying based on the seller’s word alone.

Calculate concentration at three levels: top-1 customer as a percentage of revenue, top-5, and top-10. A single customer above 15 to 20% of revenue usually triggers deeper scrutiny, and anything above 30% from one account is a structural risk most buyers will want reflected in price or deal structure, not just noted and ignored.
Beyond concentration, ask for net revenue retention (NRR), gross churn rate, and the typical renewal cadence for major contracts. NRR above 100% tells you existing customers are spending more over time, which is a much stronger signal than new customer acquisition alone. A high gross churn rate paired with strong new sales can mask a leaky business that looks healthy in aggregate but is running hard just to stay flat.
Pro Tip: Read every top-customer contract for change-of-control and termination-for-convenience language before you get attached to the revenue number. A contract that lets the customer walk the moment ownership changes turns a “top account” into a coin flip, and that changes what the business is actually worth to you.
Operational, IT, and Cybersecurity Diligence
Request network diagrams, any SOC 2 report or third-party security assessment, a documented breach history, a full software license inventory, contracts with major vendors and cloud providers, and notes on how the business’s data architecture is structured. For a business that runs on point-of-sale systems, custom software, or customer data storage, this workstream can matter as much as the balance sheet.
Watch for these cybersecurity and vendor red flags:
- No documented incident response plan, which suggests the business would struggle to contain a breach if one happened.
- Any undisclosed prior breach or unpatched vulnerability the seller downplays as “handled.”
- Widespread use of unlicensed or improperly licensed software, which creates vendor liability that transfers with the business.
- Single-source suppliers with no backup vendor, especially where that supplier’s contract includes weak service-level terms that may not survive a change of control.
Weigh remediation cost against the purchase price honestly. A $40,000 fix to patch outdated systems on a $3 million acquisition is a rounding error you negotiate into the price. A vendor dependency with no substitute supplier and a fragile service agreement might be a reason to require specific representations, an escrow holdback, or a post-close transition plan before you close at all.
HR, Benefits, and Key-Person Risk
Pull the organizational chart, employment agreements for every key person, nondisclosure and noncompete agreements, the employee handbook, all benefit plan documents including 401(k) and health insurance, and payroll records for the past two to three years. Small businesses often run on the strength of two or three people, and losing any of them in the transition can erase the value you just paid for.
Evaluate key-person dependency directly: does the business run through the owner’s personal relationships, or does it run through documented processes and a real management team? If it’s the former, negotiate retention bonuses or new employment agreements for critical staff before closing, and consider tying part of the purchase price to an earnout with an escrow that depends on those people staying through the transition.
Common HR red flags include undisclosed wage claims, workers classified as independent contractors who function like employees, pending labor disputes, and benefit plans that are underfunded relative to what employees have been promised. Any one of these can turn into a liability that lands on your desk within months of closing, not years.
Real Estate, Assets, and Environmental Diligence
If the business owns or leases property, collect the leases, deeds, mortgages, title reports, surveys, zoning approvals, and any landlord estoppel letters confirming the lease terms are accurate and in good standing. For owned equipment and physical assets, request the fixed asset register, equipment leases, UCC filings against the assets, and maintenance logs showing the equipment has been kept in working order.
Environmental risk deserves particular attention for manufacturing, industrial, automotive, or agricultural businesses. Request any existing Phase I or Phase II environmental site assessments, a hazardous substance inventory, and the history of any remediation efforts or regulatory enforcement actions tied to the property.
- Order a Phase I environmental site assessment for any industrial, manufacturing, or fuel-handling business, even if the seller says the property is clean.
- Escalate to a Phase II assessment if the Phase I identifies a recognized environmental condition.
- Structure an environmental indemnity or escrow if the property has any history of contamination, even resolved contamination, since regulatory reopeners are more common than buyers expect.
- Confirm UCC filings are current and don’t reveal a lien on equipment you assumed was free and clear.
Environmental liabilities are one of the few risk categories that can attach to the property itself, regardless of who caused the contamination, which is exactly why this workstream shouldn’t be skipped on smaller deals just because the purchase price seems too small to justify the cost of an assessment.
Intellectual Property and Technology Review
Request every patent, trademark, and copyright registration the business holds or has applied for, along with assignment documents proving the business actually owns them, not just uses them. Pull all license agreements, NDAs signed with contractors or partners, and any documentation of trade secrets and how the business protects them internally.
- Confirm source code ownership directly, especially for any custom software the business relies on.
- Check third-party code usage and open-source license compliance, since some open-source licenses require disclosure obligations that can affect resale value.
- Review cloud-hosting agreements to confirm they transfer cleanly with a change of ownership.
- Look for developer or contractor agreements that lack “work-for-hire” language, which is one of the most common and most overlooked IP defects in small business acquisitions.
A missing assignment is the classic IP defect: the founder hired a freelance developer years ago, never signed a work-for-hire agreement, and technically the developer, not the business, owns part of the codebase. It’s fixable, usually with a retroactive assignment agreement, but only if you catch it before closing.
How to Review Material Contracts for Assignability Risk
Prioritize customer contracts, supply agreements, vendor master agreements, loan documents, real estate leases, and any OEM or distributor agreements. These are the contracts most likely to contain a clause that quietly reshapes the deal after signing.
Build a simple checklist for each one: does it require notice to the counterparty on a change of control? Does it require the counterparty’s consent before the deal can close? Does either party have a termination right triggered by new ownership? Is the contract set to auto-renew, and if so, on what terms?
The most damaging red flag is a termination-on-change-of-control clause tied to a top customer or a critical supplier. If your top customer can walk the day you close, or your sole supplier can cancel with 30 days’ notice, that’s not a footnote, it’s a reason to renegotiate the purchase price or require the seller to secure a consent or waiver before closing.
Triage every contract with meaningful customer exposure or critical supplier dependency for immediate attention. Everything else, standard vendor agreements, minor service contracts, can wait for the second wave of review. Our guide to reviewing contracts before you sign covers the clause-by-clause approach we use with clients working through exactly this kind of triage.
Building the Data Room and the Initial Request Letter
Structure your VDR to mirror the workstreams, not the seller’s filing system. A clean folder structure looks like: Corporate Records, Financial Statements, Tax, Customer Contracts, Vendor Contracts, Employee/HR, IT/Cybersecurity, Real Estate/Assets, IP, and Litigation. When every document has an obvious home, your team stops wasting time hunting for files and starts spending time analyzing them.
Send your initial request as a condensed one-page wave-one letter rather than a 100-item document dump on day one. Bloomberg Law’s sample request-letter approach recommends sequencing requests: wave one covers financials, corporate records, and top customer contracts; wave two covers HR, IT, and operational documents; wave three covers deeper items like environmental assessments and litigation specifics. This keeps the seller from feeling buried and gives you an early signal, based on how quickly and completely they respond, of how organized the business actually is.
Manage the Q&A process with a tracker, not email threads. Log every request, the date sent, the response deadline, whether the item was provided in full, partially, or refused, and a materiality flag for anything that looks significant. That tracker becomes your audit trail when you get to the negotiating table and need to point to exactly what was disclosed, when, and how completely.
Pro Tip: Treat “not available” as a finding, not a dead end. If a seller can’t produce a document that should exist, whether it’s a signed lease amendment or a customer contract renewal, ask why. Sometimes the honest answer reveals the real risk in the deal.
Running the Process and Managing the Risk Register
A well-run diligence process moves in parallel, not sequentially. Here’s the practical order of operations:
- Launch the data room and send the wave-one request letter within 48 hours of signing the LOI.
- Assign a named owner to each workstream, financial, legal, commercial, IT, HR, so nothing falls through gaps between advisors.
- Schedule management interviews and any site visits in week two, while document review is still underway, not after.
- Commission specialist reports (QoE, environmental, IT security) as soon as you know the deal size justifies the cost.
- Consolidate every workstream’s findings into a single risk register by week four.
- Use the risk register to drive final negotiation on price, structure, or specific contract terms before drafting the purchase agreement.
Build the risk register around a few consistent fields: the finding itself, its likelihood, its potential financial impact, a recommended remedy, the person responsible for tracking it, and its current status. This turns dozens of scattered findings from different advisors into one document you can actually negotiate from.
Certain findings show up again and again as the cause of retrades or outright deal failure: customer concentration above safe thresholds, restated financials, undisclosed or understated litigation, environmental contamination, and contracts that can’t be assigned to the new owner. When you hit one of these, you have three real options: renegotiate the price to reflect the risk, require an escrow or indemnity that specifically covers it, or walk away. Quantify the remediation cost wherever possible. A specific dollar figure, even an estimate, is far more persuasive at the negotiating table than a vague statement that something “concerns you.”

When to Bring in Attorneys, Accountants, and Technical Experts
Most buyers underestimate how early specialist advisors should get involved, and overestimate what a single generalist can catch across ten different workstreams. Here’s a rough guide to who does what and when.
| Advisor | Primary Role | When to Engage |
|---|---|---|
| Transaction attorney | Contract review, entity structure, closing docs | Immediately after LOI |
| QoE accountant | Financial verification, EBITDA normalization | Within first week for deals over $2M |
| Environmental consultant | Phase I/II assessments | As soon as industrial or manufacturing risk is identified |
| IT security specialist | Systems review, breach history | Early, especially for tech-dependent businesses |
| Benefits consultant | Plan funding, compliance review | Mid-diligence, once HR documents arrive |
Fees scale with deal size and complexity. A straightforward small business acquisition might only need attorney and accountant involvement, while a mid-market deal touching multiple states, regulated industries, or cross-border ownership can require the full roster. Certain triggers demand immediate specialist involvement regardless of budget: suspicious accounting patterns that suggest more than a normalization issue, any hint of environmental contamination, or a transaction that could fall under CFIUS review because it involves foreign investment in a sensitive sector. Deals that raise competitive concerns may also draw scrutiny under federal antitrust law, which is another reason to loop in counsel before, not after, you’ve made representations to the seller.
Pro Tip: When you engage an advisor, define the deliverable in writing before the work starts. A QoE report that just confirms the seller’s numbers is worthless. Ask for one that specifically stress-tests the add-backs and flags anything that wouldn’t survive a buyer’s scrutiny.
What Most Buyers Get Wrong About Due Diligence
The biggest mistake I see buyers make isn’t skipping a document, it’s trusting the wrong version of a document. Compiled financial statements, the kind with no CPA opinion behind them, get treated the same as audited statements far too often, and that single decision has cost buyers more in post-close disputes than almost any other diligence shortcut. If the seller can’t produce reviewed or audited financials, that’s not a paperwork gap. It’s information about how the business has been run.
Skipping management interviews is the second mistake, usually made for the wrong reason: buyers worry it will slow the deal down or spook the seller. It’s backwards. A 45-minute conversation with the controller or operations manager surfaces things no document ever will, like which customer relationship actually depends on the departing owner’s personal cell phone number.
The third mistake is treating assignability consents as a closing-day formality instead of a diligence-week priority. If a top customer contract requires consent to assign on a change of control, get that conversation started the moment you identify it, not the week before closing when you have zero leverage left to negotiate around a customer who suddenly realizes they hold all the cards.
If you take one thing from all of this: request customer-level detail on everything, not just aggregate revenue. Aggregate numbers hide concentration, hide churn, and hide the single account that’s actually propping up the deal. Ask for the breakdown before you get emotionally invested in the top-line number.
How Legal Counsel Reduces Risk During an Acquisition
A due diligence checklist tells you what to look for. What it can’t do is negotiate the assignability consent your top customer is suddenly slow-walking, draft the escrow language that actually protects you if a tax exposure surfaces after closing, or catch the corporate governance gap buried in a decade-old operating agreement. That’s where Fornarolegal comes in, working alongside your accountant and other advisors rather than replacing them.

Matthew Fornaro has spent more than 20 years handling business transactions, contract disputes, and corporate structuring for entrepreneurs across South Florida, and that experience shows up most clearly in the parts of diligence that don’t fit neatly into a checklist: contract negotiation, escrow and indemnity drafting, and representation straight through to closing. Legal involvement matters most when you’re facing a material dispute buried in the seller’s litigation history, a regulatory question you can’t answer alone, or a purchase agreement that needs terms most templates don’t cover. If you’re heading into an acquisition and want a lawyer reviewing your data room findings before you sign anything, schedule a consultation to discuss early legal guidance for your deal.
Sources
A few resources are worth bookmarking as you build out your own process, whether you’re assembling a request letter from scratch or want a second reference point for a specific workstream:
- Due Diligence Process: 6 Steps + 6-Week Timeline (2026) — DealRoom
- Mergers and Acquisitions Due Diligence Checklist: 10 Workstreams Buyers Actually Run (2026) — CT Acquisitions
- Due diligence meaning and how to conduct in various sectors — Thomson Reuters
- CFIUS laws and guidance — U.S. Department of the Treasury
Every document you pull during this process, from tax returns to customer contracts, is sensitive. Keep everything inside a secure, access-controlled VDR rather than email attachments, limit access to people who genuinely need it, and confirm your NDA with the seller covers how diligence materials get stored and destroyed if the deal falls through.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Recommended
- Due Diligence Lawyer for Business Acquisition in Miami: A 2026 Guide
- Finding the Right Attorney for Buying a Business in Broward County » Matthew Fornaro, P.A.
- Business Due Diligence Explained for Entrepreneurs
- Florida Commercial Lease Review Checklist for Business Owners: Read This Before You Sign » Matthew Fornaro, P.A.



