Due Diligence Request List

Due Diligence Request List

For Informational Purposes Only

A comprehensive 100+ item due diligence checklist covering 11 categories — from corporate governance and IP to data privacy, cybersecurity, and AI/ML compliance. Designed for venture financings, acquisitions, and mergers.

Download Free Template

What This Document Does

A Due Diligence Request List is the master checklist an investor, acquirer, or lender sends to a target company at the outset of a transaction to request all documents and information needed to evaluate the deal. It’s the roadmap for the entire diligence process — every item the buyer’s lawyers will review before closing.

This template covers 11 categories spanning over 100 individual request items: Corporate Organization and Governance, Financial Information, Intellectual Property, Material Contracts, Litigation and Regulatory, Employment and Labor, Tax, Insurance, Data Privacy and Cybersecurity, Real Property and Environmental, and Regulatory Compliance. It’s designed to work for Series A+ venture financings, M&A transactions, and merger diligence.

The list includes emerging diligence categories that have become standard in 2025–2026: AI/ML intellectual property provenance, data privacy compliance across multiple state regimes, cybersecurity incident history, QSBS qualification analysis, and export control/sanctions compliance. Each category is numbered for easy cross-referencing with a virtual data room.

Why Startups Need This Checklist

Fundraising Preparation

Investors conducting Series A and later-stage diligence will send a list like this. Companies that have their documents organized in advance — corporate records, cap table, IP assignments, financial statements — close rounds faster. Use this list proactively to build your virtual data room before you start fundraising, not after a term sheet arrives.

M&A Transaction Readiness

Acquirers’ counsel will send a comprehensive DD request list as one of the first steps after signing an LOI. The speed and completeness of your response directly affects deal certainty and timeline. Companies that can populate a data room within days signal operational maturity — those that take weeks to locate basic documents create diligence risk that depresses valuations.

Issue Identification

Due diligence isn’t just about checking boxes — it’s about finding problems before closing. Missing IP assignments, improperly classified contractors, expired permits, undisclosed litigation, change-of-control provisions in key contracts — any of these can kill a deal or result in a significant price adjustment. Early self-diligence helps you fix issues proactively.

Representation & Warranty Alignment

The diligence process directly feeds the representations and warranties in the definitive agreement. Everything disclosed in the data room gets scheduled — and everything not disclosed becomes a potential indemnification claim. Understanding what diligence will be requested helps you draft more accurate disclosure schedules and avoid post-closing surprises.

11 Diligence Categories

I. Corporate Organization (13 items)

Charter documents, bylaws, organizational chart, board minutes, capitalization table, stock ledger, stockholder agreements, and corporate governance records. The foundation of any diligence review — establishes who owns what and how the company is governed.

II. Financial Information (12 items)

Audited and interim financials, projections, debt schedules, bank statements, AR/AP aging, off-balance sheet items, management letters, related-party transactions, and CapEx history. Investors and acquirers will spend the most time here.

III. Intellectual Property (10+ items)

Patents, trademarks, copyrights, trade secrets, IP assignments (PIIAAs), license agreements (in/out), open-source audit, IP disputes, and university/government IP rights. Includes an emerging AI/ML IP diligence section covering training data provenance and model ownership.

IV. Material Contracts (10 items)

Major customer and vendor contracts, partnerships, distribution agreements, non-competes, government contracts, change-of-control provisions, and standard form agreements. Focuses on contracts that could be affected by the proposed transaction.

V. Litigation & Regulatory (8 items)

Pending and threatened litigation, settled matters, judgments, government investigations, consent decrees, IP infringement claims, whistleblower complaints, and legal opinions. Any undisclosed litigation is a major diligence red flag.

VI. Employment & Labor (12 items)

Employee roster, employment agreements, handbook, equity plans, outstanding awards, severance/CIC agreements, benefits, contractor classification, employment claims, work visas, and restrictive covenants. Worker classification (1099 vs. W-2) is a frequent diligence issue.

VII. Tax (8 items)

Tax returns, pending audits, NOL carryforwards and Section 382 analysis, R&D credits, sales tax nexus, 409A valuations, and QSBS qualification analysis. The QSBS section has become critical for startup transactions given the potential for 100% capital gains exclusion.

VIII–XI. Insurance, Privacy, Property, Regulatory

D&O and cyber insurance policies, data privacy compliance (GDPR, CCPA, state laws), data breach history, SOC 2/ISO 27001 reports, real property leases, environmental compliance, permits, AML/KYC programs, FCPA compliance, and export controls. These categories have expanded significantly since 2020.

Emerging Diligence Areas (2025–2026)

AI/ML Intellectual Property Provenance

Companies developing AI products face new diligence scrutiny around training data sourcing, model ownership, and regulatory compliance. Investors and acquirers now routinely request: training data licenses and provenance documentation, analysis of any web scraping or copyrighted content use, AI model development agreements, bias auditing procedures, and compliance plans for the EU AI Act and emerging state-level AI regulations.

Multi-State Privacy Law Compliance

With over 15 states having enacted comprehensive privacy laws by 2026, data privacy diligence has become significantly more complex. Beyond CCPA/CPRA and GDPR, companies must now demonstrate compliance with Virginia’s CDPA, Colorado’s CPA, Connecticut’s CTDPA, and others. Diligence now includes privacy program maturity assessments, data mapping exercises, vendor management programs, and cookie consent implementation reviews.

QSBS Qualification Tracking

Section 1202 QSBS status — which can provide up to 100% exclusion of capital gains on qualifying small business stock — has become a critical diligence item for startup transactions. Investors now request detailed QSBS analyses including: C corporation status confirmation, gross asset tracking (under $50M at issuance), active business requirement compliance (80% asset test), and identification of any disqualifying redemptions or non-qualifying activities.

Cybersecurity Incident History & Controls

Post-SolarWinds and in the wake of SEC cybersecurity disclosure rules (effective December 2023), cybersecurity diligence has moved from a checkbox to a substantive review. Requests now include: SOC 2 Type II reports, penetration testing results, incident response plans, breach notification records, cyber insurance coverage, and board-level cybersecurity oversight documentation.

Diligence Scope by Transaction Stage

Category Seed / Series A Series B+ M&A / IPO
Corporate Essential — cap table, charter, stockholder agreements Full review including board minutes Exhaustive — all items
Financial Unaudited financials, burn rate, projections Audited financials, debt, AR/AP Full audit + quality of earnings
IP IP assignments, key licenses, open-source Full IP portfolio review Freedom-to-operate analysis + AI/ML audit
Employment Key employee agreements, option grants Full roster, benefits, classification All items + compensation benchmarking
Privacy/Cyber Privacy policy, basic compliance DPAs, breach history, SOC 2 Full audit including pen tests
Tax 409A, QSBS status Returns, R&D credits, nexus All items + Section 382 analysis

How to Use This Template

1
Tailor to Your Transaction. This list is intentionally comprehensive. For seed-stage deals, focus on Categories I–VI. For M&A, use all categories. Delete items that clearly don’t apply (e.g., real property for a fully remote SaaS company) and add industry-specific items as needed.

2
Set Up a Virtual Data Room. Organize your VDR with folders matching the category numbers (I through XI). This makes it easy for reviewers to find documents and for you to track what’s been provided. Most VDR platforms (Carta, Ansarada, Datasite, or even a well-organized Google Drive) support this structure.

3
Track Responses. Add a “Status” column next to each item: Provided, N/A, In Progress, or Pending. This helps both sides track completion and identify gaps. Aim to provide all available documents within the first week of receiving the request.

4
Flag Sensitive Items. Some items (litigation details, tax positions, trade secrets) may require additional confidentiality protections or attorney-client privilege considerations. Discuss appropriate handling with counsel before uploading sensitive documents to the data room.

5
Use for Self-Diligence. Even if you’re not currently in a transaction, use this list to audit your own corporate records. Many startups discover missing IP assignments, unsigned board consents, or expired contractor agreements only when diligence exposes them. Finding these issues early is always cheaper than finding them at closing.

Disclaimer: This template is provided by Montague Law for informational and educational purposes only and does not constitute legal advice. The scope and depth of due diligence required will vary based on the nature and size of the transaction, industry-specific requirements, regulatory considerations, and the parties’ risk tolerance. Use of this template does not create an attorney-client relationship. All parties should consult with qualified legal counsel to determine the appropriate scope of due diligence for their specific transaction. For legal assistance with your financing or M&A transaction, contact john@montague.law.