Due Diligence
Executive Summary
Key Takeaways
- ✓ Due diligence is the structured process of investigating and verifying facts about a target before a transaction, distinct from simply relying on the seller's own representations.
- ✓ In a transaction context, due diligence is organized into workstreams — financial, commercial, operational, technical, legal, tax, ESG — each investigating a different dimension of risk.
- ✓ Due diligence is run from one of three postures depending on who commissions it — buy-side, sell-side, or vendor — each with a different objective and intended audience.
- ✓ A due diligence finding only affects a transaction once it is reflected in a model adjustment, a contractual protection, or an explicit risk acceptance decision.
Definition¶
Due diligence is the structured investigation a party to a proposed transaction conducts before committing capital — verifying facts, quantifying risk, and testing the assumptions underlying the deal's price, rather than relying solely on the counterparty's own representations. In an M&A or broader transaction context, it is organized into distinct workstreams and run from one of three commissioning postures, both covered in full on the M&A and Transaction Due Diligence pillar this term belongs to.
Workstreams and Postures¶
Due diligence in a transaction is typically organized into seven workstreams — financial, commercial, operational, technical, legal, tax, and ESG — each investigating a different dimension of risk, and run from one of three postures depending on who commissions the work: buy-side (a prospective acquirer), sell-side (a seller's internal preparation), or vendor (a seller-commissioned, independently prepared report for bidder distribution).
From Finding to Resolution¶
A due diligence finding does not, by itself, change a transaction's outcome. It only takes effect once reflected in one of three ways: a quantified adjustment to the transaction model, a specific contractual protection in the purchase agreement, or an explicit, documented decision to accept the identified risk. See Buy-Side Due Diligence for the full treatment of this resolution discipline.
Audit Considerations¶
- Confirm every material finding across all commissioned workstreams is tracked to one of the three resolution outcomes, not left open
- Confirm the due diligence posture (buy-side, sell-side, vendor) is understood when assessing the independence and reliability of a given report's conclusions
- Confirm findings that translate into model adjustments are actually reflected in the transaction model, not only documented in the workstream report
Continue Reading¶
Prerequisites¶
- M&A and Transaction Due Diligence — the parent pillar
Related Technical Guides¶
Related Glossary¶
Related Comparisons¶
How OXXON tests thisRun a free structural check with FMAE
Frequently Asked Questions
What is due diligence?
The structured investigation a party to a proposed transaction conducts before committing capital, verifying facts and quantifying risk rather than relying solely on the counterparty's own representations.
What are the standard due diligence workstreams in an M&A transaction?
Financial, commercial, operational, technical, legal, tax, and ESG due diligence, each investigating a different dimension of risk and typically led by a different specialist advisor.
What are the three due diligence postures?
Buy-side (commissioned by a prospective acquirer), sell-side (a seller's internal preparation), and vendor (an independently prepared report commissioned by the seller for bidder distribution) — see Buy-Side vs. Sell-Side vs. Vendor Due Diligence for the full comparison.
Does a due diligence finding automatically change the transaction?
No. A finding only affects the outcome once it is reflected in a traceable model adjustment, a contractual protection in the purchase agreement, or an explicit, documented decision to accept the risk — a finding noted only in a report has not, by itself, changed anything.
Related Articles
M&A and Transaction Due Diligence
Transaction due diligence is the structured process by which a party to a proposed transaction — most often a buyer, but also a seller preparing for sale or a lender financing the deal — investigates a target business before committing capital. It is organized into distinct workstreams (financial, commercial, operational, technical, legal, tax, ESG), run from one of three process postures (buy-side, sell-side, or vendor), and its findings feed directly into the financial model used to price the transaction and support the investment decision. This page is the hub for the Knowledge Centre's transaction due diligence content: what due diligence is, how each workstream and process posture differs, and how model risk specifically enters a transaction — the angle this platform is built to address in depth.
Buy-Side Due Diligence
Buy-side due diligence is the due diligence process run by, or on behalf of, a prospective acquirer, investigating a target business before the acquirer commits to a price and signs a transaction agreement. It typically runs in phases — preliminary diligence ahead of a non-binding offer, then confirmatory diligence during an exclusivity period ahead of signing — across the seven standard workstreams, with findings flowing into the acquisition model, the purchase agreement's protective terms, and the final negotiated price.
Sell-Side and Vendor Due Diligence
Sell-side due diligence is a seller's own internal review, run ahead of going to market, to anticipate and pre-empt the findings a buyer's due diligence team is likely to surface. Vendor due diligence is a related but distinct practice: a seller commissions an independent advisor to prepare a formal due diligence report specifically for distribution to multiple prospective bidders, reducing duplicated buyer-side cost and shortening the process timeline. This guide covers both, and the specific point at which a vendor due diligence report's independence needs to be genuine rather than nominal for bidders to actually rely on it.
Data Room
A data room is the controlled repository of documents and information a target company makes available to due diligence teams during a transaction process. Almost universally a virtual data room today, access is permissioned by workstream and phase, with activity logged, so that a seller can disclose progressively more sensitive information as a process moves from preliminary to confirmatory diligence while retaining an auditable record of who accessed what and when.
Red Flag Report
A red flag report is a rapid, high-level assessment of a financial model designed to identify critical or significant issues without conducting a full, exhaustive independent audit. It provides a targeted view of whether a model contains material errors, structural weaknesses, or significant limitations that would affect its fitness for a specific purpose — typically a pending investment decision, a financing transaction, or a commercial negotiation. A red flag report is sometimes called a preliminary model review, a model health check, or a model screening assessment. The defining characteristic is scope limitation: it is a rapid review that identifies significant issues, not a comprehensive verification of every formula and reference.