Due diligence is one of those phrases that gets mentioned early in acquisition conversations and then, for many founders, becomes a source of quiet anxiety. You know it’s coming, you know it matters, but the scope of it can feel overwhelming if you’ve never been through the process before.
The good news is that due diligence is rarely as daunting as it sounds, particularly if you’ve kept your house in reasonable order. Here’s a straightforward look at what we typically ask for at Vesta and why each area matters.
Financials
This is usually where due diligence begins, and it tends to be the most detailed area. We’re looking to build a clear picture of the financial health of the business, covering how it has performed over time and why.
Typically, we’ll ask for two to three years of financial statements, including profit and loss accounts, balance sheets and cash flow statements. Alongside those, we’ll want to understand the composition of revenue – how much is recurring versus one-off, how concentrated it is across customers, and how margins have trended. Invoicing records, details of outstanding payables and receivables, and any existing debt or financing arrangements will also form part of this review.
For a software business in particular, recurring revenue quality is something we look at closely. Stable, contracted ARR tells a very different story from revenue that has to be re-won each year.
Legal
The legal review covers the formal structure of the business and anything that could affect the transaction or create liability going forward. This includes the company’s corporate documents – articles of association, shareholder agreements and any existing investment arrangements – as well as the contracts that underpin the business.
Customer and supplier agreements, licensing arrangements and any ongoing or historic disputes or litigation all fall within scope here. Intellectual property is particularly important in software acquisitions: we need to confirm that the IP sits cleanly within the business and that there are no third-party claims or complications around ownership of the codebase or product.
Employees and HR
We want to understand who the people are, how they’re engaged and what obligations the business carries in relation to them. Employment contracts, details of the senior leadership team, payroll records, and information about pension arrangements and any benefits schemes are all part of this picture.
Where there are key individuals whose continued involvement is central to the business, we’ll also want to understand what’s in place to retain them through and beyond the transition.
IT and data
For software businesses, this is an area that warrants particular attention. We’ll look at the technical infrastructure supporting the product, including how it’s hosted, how it’s maintained and how secure it is. Data protection compliance, particularly in relation to GDPR, is something we review carefully, as are any third-party software dependencies or licensing arrangements that could affect the product.
Cybersecurity practices and any history of data incidents are also part of this review. It’s about understanding the risk profile and making sure nothing significant has been left unaddressed.
Commercial and customer information
Beyond the financials, we want to understand the business’s position in its market. That means looking at the customer base in some detail, gathering information on churn rates, contract lengths, renewal history and any customer concentration that could represent risk. Where available, customer satisfaction data or NPS scores help to round out that picture.
We’ll also look at the competitive landscape and any pipeline or backlog information that gives a sense of near-term trading.
Insurance and pensions
Existing insurance policies, including professional indemnity, employers’ liability and any directors’ and officers’ cover, will be reviewed as part of the process. Pension arrangements, particularly where there are defined benefit obligations, are also examined carefully.
A note on how we approach it
Due diligence can feel like scrutiny, but from our perspective it’s more accurately described as understanding. We’re not looking for reasons to walk away or levers to renegotiate at the last minute. We ask these questions because the more clearly we understand a business before completion, the better placed we are to support it well long term.
The process typically takes between two and four months, depending on the size and complexity of the business. Most founders find it manageable, particularly with a good adviser alongside them and clear, organised records to draw from.
If you’re starting to think about what due diligence might look like for your business, our guide to preparing your software company for acquisition is a good place to start. And if you’d like to talk through the process with us directly, we’re always happy to have that conversation.