In short
A due diligence pack is the questionnaire, document request list and data room index used to investigate a target business before a sale or investment completes. Built for a vendor, it front-loads disclosure so warranty exposure is limited; built for a buyer, it's the framework used to verify what's actually being bought. The same underlying issues — title, contracts, employees, IP, litigation — get investigated from opposite sides of the table.
Vendor due diligence versus buyer due diligence
A vendor due diligence pack is prepared before the business goes to market, or immediately after heads of agreement, so the seller controls the narrative and timing of disclosure rather than reacting to buyer requests under time pressure. Its real function is protective: matters properly disclosed in the data room generally can't later support a warranty claim, because most sale agreements carve out from warranty liability anything fairly disclosed against a specific warranty. A well-organised vendor pack, cross-referenced to a disclosure letter, is one of the most effective tools for limiting post-completion exposure.
A buyer's due diligence questionnaire works the other way — it's the request list used to test what the seller is representing, structured around the categories that actually carry risk in a transaction: corporate and title, material contracts, employees and contractors, intellectual property, litigation and compliance, and financial records. We build buyer questionnaires around the specific transaction structure (share sale exposes the buyer to historical liabilities in a way an asset sale generally doesn't), so a generic checklist isn't the starting point.
Corporate and title verification
This covers confirming the target company's ASIC records match its actual share register and officeholders, that shares being sold are unencumbered and validly issued, and that any prior share transfers were properly documented and stamped where duty applied. For asset sales, title verification extends to confirming the seller actually owns (rather than leases or licenses) the assets being sold, and checking the PPSA register for registered security interests over those assets that would need to be released or discharged before or at completion.
Material contracts and change-of-control risk
We review key customer, supplier and financing contracts for change-of-control clauses that could allow the counterparty to terminate or renegotiate on a sale, assignment restrictions that require consent before a contract can transfer, and exclusivity or non-compete terms that might restrict the buyer's post-completion operations. Identifying these early lets the parties build consent processes into the completion timetable rather than discovering a key supplier contract terminates automatically on settlement day.
Employees, IP and compliance exposure
Employee due diligence checks award and enterprise agreement coverage, outstanding leave and entitlement liabilities, any unresolved disputes or underpayment exposure, and whether key employees are subject to enforceable restraints that would transfer their protection to a buyer. IP due diligence confirms the business actually owns the IP it trades on — trade marks registered in the right entity, software developed by contractors properly assigned, domain names and social accounts controlled by the business rather than an individual. Compliance review covers licences, permits and any regulatory history relevant to the industry, since an unlicensed activity or a lapsed permit found post-completion is a common source of buyer claims.
Structuring the data room and disclosure letter
We index the data room to mirror the warranty schedule in the sale agreement, so each disclosed document maps to the specific warranty it qualifies rather than being dumped in as general disclosure — general disclosure clauses (disclosing 'everything in the data room' against every warranty) are increasingly resisted by buyers and courts have shown limited sympathy for sellers relying on documents a reasonable buyer wouldn't have found. The disclosure letter itself is drafted as a standalone document cross-referenced to specific warranty numbers, which is the single most effective thing a seller can do to convert due diligence findings into real protection.
What the fixed fee covers
- Tailored due diligence questionnaire built around your transaction structure
- Data room index cross-referenced to the warranty schedule
- Review of material contracts for change-of-control and assignment risk
- PPSA search review and title verification for key assets
- Disclosure letter drafting linked to specific warranty numbers
Mistakes we see
- Using a generic due diligence checklist that doesn't reflect share versus asset sale differences
- General disclosure of 'everything in the data room' without linking documents to specific warranties
- Missing change-of-control clauses in material contracts until after signing
- Assuming IP is owned by the business without checking contractor assignment documents
- No PPSA search before completion, leaving undischarged security interests over sold assets
Who this is for
- Sellers preparing a business for sale who want to limit warranty exposure
- Buyers investigating a target business or company before signing
- Investors conducting diligence ahead of a capital injection
- Advisers coordinating a data room across legal, financial and commercial workstreams
Frequently asked questions
- What's the difference between vendor and buyer due diligence?
- Vendor due diligence is prepared by the seller in advance to control disclosure and limit warranty exposure; buyer due diligence is the investigation the buyer runs to verify the target before completing. Both use similar categories of enquiry but serve opposite commercial purposes.
- Does disclosing something in the data room protect us from a warranty claim?
- Generally yes, if the sale agreement's disclosure mechanism is drafted to allow specific disclosure against specific warranties, and the document is genuinely findable and relevant. Broad 'general disclosure' of the whole data room is weaker protection and increasingly resisted by buyers.
- How long does due diligence typically take?
- It depends heavily on business complexity, but a mid-sized business sale typically runs 3–6 weeks for buyer due diligence, with vendor due diligence packs often prepared over 5–10 business days before going to market.
- Do we need to check the PPSA register as part of due diligence?
- Yes, for any asset sale or where a company's assets secure existing finance. Undischarged security interests can follow the asset to a buyer, so identifying and arranging release of registrations before completion is standard practice.
- What happens if due diligence uncovers a serious problem?
- Depending on timing and severity, it can lead to price renegotiation, specific indemnities carved out for the identified risk, conditions precedent requiring the issue be fixed before completion, or in some cases withdrawal from the transaction.
Related
