Use this page as a working list. It is organised the way a disclosure actually unfolds: what goes in first, what follows once bidders are serious, and what you hold back until the end.
A due diligence data room is the controlled online space where a seller, or a company raising capital, places the documents a buyer or investor needs to verify the business before committing. The checklist below assumes a sale of a private company with outside bidders; trim it for a fundraise and extend it for a regulated target.
Why load documents in waves at all?
Because the number of people looking shrinks while the sensitivity of what they see rises. Ten bidders in round one might include a competitor fishing for information. By the confirmatory stage there is usually one preferred buyer under exclusivity.
| Wave | When it opens | Who sees it | Purpose | Typical share of final room |
|---|---|---|---|---|
| Wave 1: first-round pack | With the process letter | All bidders under NDA | Support an indicative offer | 10 to 15% |
| Wave 2: full diligence | After shortlisting | 2 to 4 bidders and advisers | Support a binding offer and draft contract | 70 to 80% |
| Wave 3: confirmatory | Under exclusivity | Preferred bidder, often a clean team | Close out final risks before signing | 10 to 15% |
Plan the waves before you upload anything. It makes the permission set-up almost mechanical, and it stops the classic mistake of a first-round bidder finding the full customer list because a folder was left open.
Three release waves: what to load, and when
What goes into the first-round pack?
Keep it lean. Its job is to let bidders price the business, not to answer every question.
- Information memorandum or management presentation
- Summary historical financials, three years, plus current-year management accounts
- Budget or forecast with key assumptions
- Group structure chart and certificates of incorporation
- Summary of top customers by revenue band, anonymised
- Summary of material contracts, without the contracts themselves
- Headcount summary by function and location, no names
- Overview of owned and leased premises
- Summary of any litigation, with amounts in dispute
What does the full diligence set contain, workstream by workstream?
This is where most of the room is built. Organise it by workstream, because that is how buyers staff their diligence: an accounting firm on finance and tax, lawyers on legal and property, consultants on commercial and IT. A numbered index like our data room index template lets everyone refer to documents by number.
Finance and tax
- Audited or reviewed accounts, three to five years, with management letters
- Monthly management accounts for the last 24 months
- Revenue and margin by customer, product and region
- Working capital analysis and debt schedule
- Bank facility agreements, security documents and covenant compliance
- Tax returns, assessments, and correspondence with tax authorities
- Transfer pricing documentation for cross-border groups
- Sales tax or VAT filings and any open audits
Corporate and legal
- Constitutional documents, shareholder register and cap table
- Board and shareholder minutes, three years
- Shareholder agreements, option plans and any side letters
- All material customer and supplier contracts
- Contracts with change-of-control or exclusivity clauses, flagged
- Licences, permits and regulatory approvals
- Litigation files, claims and settlement agreements
- Insurance policies and claims history
Commercial
- Customer contracts and renewal history for the top 20 accounts
- Pipeline and churn data
- Pricing policy and discount approvals
- Marketing and channel partner agreements
- Competitor analysis prepared for the board, if any
People
- Organisation chart and employee census, anonymised in wave 2
- Standard employment contracts and handbooks
- Senior management contracts, bonus and retention arrangements
- Benefit plan documents and pension or retirement plan funding
- Contractor agreements and classification analysis
- Employment disputes and settlements
IT, data and IP
- Register of registered IP: patents, trademarks, domains
- Invention and IP assignment agreements from founders, staff and contractors
- Software licences and open-source usage report
- Systems architecture overview and key vendor contracts
- Information security policies, recent penetration tests, incident log
- Data protection records: data map, privacy notices, processor agreements
Property and environment
- Title documents and leases for each site
- Surveys and planning or zoning consents
- Environmental reports and permits
- Health and safety records and incident log
Employee and customer records are personal data. Under the GDPR the seller still has to justify sharing them and limit them to what the buyer needs at that stage, a principle the UK regulator spells out in its data sharing guidance. In practice that means anonymised census data in wave 2 and named records only in wave 3, if at all.
What belongs in the confirmatory wave?
Hold these back until a buyer is in exclusivity:
- Named employee data, individual salaries and performance records
- Full customer contracts with pricing for direct competitors of the buyer
- Supplier cost data and margin by contract
- Trade secrets, source code escrow details, detailed product roadmaps
- Unredacted litigation strategy and privileged advice, if shared at all
- Disclosure letter drafts and supporting evidence
If the buyer competes with you, some of this should go only to a clean team: named outside advisers, and sometimes a small number of the buyer’s staff walled off from commercial roles, who review the data and report conclusions in aggregate. US antitrust agencies treat premature exchange of competitively sensitive information, or the buyer taking control before clearance, as a serious risk; the FTC’s guide to the antitrust rules on mergers is a useful starting point on this kind of gun-jumping and your antitrust counsel should set the rules.
Which access level should each document type get?
Folder structure tells reviewers where things are. Permissions decide what they can do with them. This matrix is a sensible default for a competitive sale.
| Document type | View in browser | Download | Redact first | Clean team only | |
|---|---|---|---|---|---|
| Information memorandum | Yes | Yes | Yes | No | No |
| Audited accounts | Yes | Yes | Yes | No | No |
| Management accounts and forecasts | Yes | No | Advisers only | No | No |
| Material contracts, general | Yes | No | Legal advisers only | Sometimes | No |
| Customer contracts with pricing | Yes | No | No | Yes, in wave 2 | Often |
| Employee census | Yes | No | No | Yes, anonymise | No |
| Named employee records | Yes | No | No | Partly | Sometimes |
| Source code or trade secrets | Yes | No | No | Not applicable | Yes |
| Privileged legal advice | Rarely shared | No | No | Yes | Yes |
The platform has to support this. Look for per-group, per-folder rights, view-only mode, dynamic watermarks and built-in or reliable redaction. Our guide to security features that stop leaks covers each.
The fastest way to lose control of a process is to give every bidder the same rights because it was quicker to set up.
See which rooms handle per-group permissions, redaction and clean teams best, scored on deal features and security.
See the rankingsWhat do buyers ask for that sellers forget?
After hundreds of request lists, the same gaps keep appearing:
- Consents. Which contracts need counterparty consent on a change of control, and has anyone checked?
- IP chain of title. Founders who wrote the early code before the company existed, and never assigned it.
- Contractor status. Long-term contractors who look like employees to a tax authority.
- Data processing agreements. Processors handling customer data with no written agreement in place.
- Healthcare data. If the target touches protected health information in the US, buyers will want HIPAA compliance evidence, and you must not upload actual patient records.
- Tax residency and permanent establishment. Remote employees in another country can create a tax presence.
- Related-party transactions. Leases from the founder, loans from family members.
Upload these proactively. Every one you answer before it is asked saves a Q&A round trip and makes you look organised.
How do you keep the checklist honest as the deal moves?
A checklist is only useful if it stays current. A few habits keep it that way.
- Assign an owner per workstream. One name on finance, one on legal, one on people.
- Track against the buyer’s request list. Map every request to an index number or mark it “to follow” with a date.
- Version, do not overwrite. When a document is updated, keep the old version available and visible as superseded.
- Log what was added late. Material uploaded in the final week often ends up in the disclosure letter discussion.
- Freeze before signing. Agree a cut-off and archive the room as it stood at that moment.
How should the checklist change for a fundraise or a regulated target?
The list above is built for a sale. Two common variations pull it in opposite directions.
A venture fundraise needs a fraction of it. Investors at seed and Series A care about the cap table and option plan, the incorporation documents, IP assignments from every founder and early engineer, the financial model and recent management accounts, the top customer contracts and the team. Property, environment and detailed tax usually shrink to a line each. A lean room of 100 to 300 files is normal, and you can often skip the wave structure entirely, since there are no competing bidders to keep apart. See our startup fundraising page for the investor view.
A regulated target needs more. A bank, insurer, healthcare provider or defence supplier adds a regulatory section of its own: licences, regulator correspondence, inspection reports, capital or solvency returns, and any enforcement history. Change-of-control approvals from regulators often take longer than antitrust clearance, so buyers will want this material early, in wave 2 rather than wave 3. Expect a separate workstream of specialist advisers and plan their permission group accordingly.
Whichever variation you run, keep the same discipline: one owner per workstream, documents mapped to index numbers, and a clear record of what was released when.
How long does it take to complete this checklist?
For a well-run private company with clean accounts and a decent filing system, gathering wave 1 takes one to two weeks and wave 2 another three to six. Companies that have never been through diligence often take twice that, mostly chasing signed copies and IP assignments. Start early; the room itself takes a few days to set up, as our five-day setup guide shows. The collecting is the slow part.
Frequently asked questions
How many documents does a typical due diligence data room hold?
A small business sale often has 300 to 1,500 files. A mid-market sale usually lands between 1,500 and 8,000. Large carve-outs can exceed 20,000.
Should I upload everything at the start?
No. Release in waves. First-round bidders need enough to price the deal; the most sensitive information should wait until a preferred bidder is in exclusivity.
What is a clean team in due diligence?
A small, ring-fenced group, usually outside advisers, allowed to review competitively sensitive data and report findings in aggregate, so the buyer's commercial staff do not see it before the deal closes.
Can I use this checklist for a fundraise?
Yes, in reduced form. Investors focus on corporate documents, cap table, financials, key contracts, IP assignments and team. Property, environment and detailed tax are usually lighter.
Who prepares the data room checklist?
Usually the seller's adviser or deal counsel, built against the buyer's request list. The seller's finance and legal leads gather the documents.
