Anchored to UK statute. Last verified 21 June 2026. View source-of-record.

maduediligencechecklist.co.uk

The UK M&A Due Diligence Checklist

Acquirer scope

Buy-side due diligence checklist


The buy-side investigator's first pass: every severity-A clause across all 14 Schedules. These are the items that, left unanswered, justify walking, re-trading or routing into a specific indemnity. Open a Schedule for severity-B and severity-C items.

Direct answer

A UK buy-side due diligence checklist covers 14 workstreams and roughly 90 severity-A deal-killer items: corporate authority, share-capital reconstruction, QoE adjustments, tax-deed scope, customer-concentration, IP assignment, NSI Act mandatory notification, FCA change-of-control, ICO breach history and ECCTA failure-to-prevent-fraud reasonable-procedures evidence.


Deal-killer screens by Schedule

Schedule I - Corporate

  • I.2
    Review current articles of association and prior versions adopted within the last six years.[CA 2006 s.18]
    Severity A
  • I.4
    Review statutory registers (members, PSC, directors, secretaries, charges).[CA 2006 s.113]
    Severity A
  • I.5
    Verify PSC register against the Companies House public record and identify any discrepancies.[ECCTA 2023 Part 1]
    Severity A
  • I.6
    Reconcile issued share capital against share-certificate counterfoils and Companies House SH01 filings.[CA 2006 s.554]
    Severity A
  • I.9
    Obtain shareholder agreements, drag/tag arrangements and any side letters.
    Severity A
  • I.14
    Identify any unfiled or overdue Companies House filings; check for proposed strike-off.[Companies House]
    Severity A
  • I.20
    Confirm dividend history was lawful (sufficient distributable reserves at each date).[CA 2006 Part 23]
    Severity A

Schedule II - Financial

  • II.1
    Obtain audited statutory accounts for the last three financial years.
    Severity A
  • II.2
    Obtain management accounts to the most recent month-end (P&L, balance sheet, cash flow).
    Severity A
  • II.3
    Tie management accounts back to audited results; explain any variance > 2%.
    Severity A
  • II.5
    Test revenue recognition policy against FRS 102 or IFRS 15 as applicable.[FRC]
    Severity A
  • II.6
    Identify and quantify all QoE adjustments (non-recurring, owner remuneration, normalisations).
    Severity A
  • II.7
    Build a working-capital normalisation: 12-24 month average, seasonality, day-count.
    Severity A
  • II.8
    Define net debt: cash, debt, debt-like items, IFRS 16 lease liabilities, deferred consideration.
    Severity A
  • II.21
    Identify any post-period-end trading variance vs forecast.
    Severity A
  • II.25
    Confirm any covenant compliance reporting to lenders and headroom on each test date.
    Severity A

Schedule III - Tax

  • III.1
    Obtain corporation-tax computations and CT600 returns for the last six years.[CTA 2009]
    Severity A
  • III.2
    Identify any open HMRC enquiries, discovery assessments or pending litigation.
    Severity A
  • III.5
    Review R&D tax-credit claims: methodology, supporting file, advance assurance.[HMRC R&D]
    Severity A
  • III.13
    Review employment-related securities (ERS) returns, EMI option grants and 90-day notifications.
    Severity A
  • III.14
    Confirm EMI option grants meet qualifying-trade and individual-limit conditions.
    Severity A
  • III.15
    Identify any disguised-remuneration or loan-charge exposures.
    Severity A
  • III.21
    Obtain tax-deed draft and reconcile scope to identified exposures.
    Severity A
  • III.22
    Confirm any exit-charge or de-grouping considerations under the proposed deal structure.
    Severity ABuy-side

Schedule IV - Commercial

  • IV.1
    Obtain top-10 customer revenue concentration for the last three years.
    Severity A
  • IV.2
    Test annual customer churn (logo and revenue) over the last three years.
    Severity A
  • IV.4
    Sample top-20 customer contracts for term, renewal, change-of-control and exclusivity.
    Severity A
  • IV.6
    Confirm change-of-control consent requirements in top-customer contracts.
    Severity A
  • IV.12
    Test ARR / NRR / GRR by cohort over the last 24 months.
    Severity A
  • IV.13
    Confirm logo and net-revenue retention against an explicit cohort definition.
    Severity A

Schedule V - Legal

  • V.1
    Obtain schedule of all current and threatened litigation; quantify exposures.
    Severity A
  • V.4
    Confirm assignment of IP from founders, contractors and former employees.
    Severity A
  • V.7
    Sample top-20 material contracts for change-of-control, termination and indemnity.
    Severity A
  • V.12
    Identify any director or officer disqualification, censure or fitness-and-propriety issue.
    Severity A
  • V.13
    Confirm regulatory licences and any consent required on change of control.
    Severity A
  • V.16
    Identify any contractual obligation triggered by the transaction (anti-assignment, MAC).
    Severity A

Schedule VI - Employment

  • VI.1
    Obtain employee census: headcount, role, location, FT/PT, start date.
    Severity A
  • VI.3
    Confirm right-to-work checks held for every employee and contractor.
    Severity A
  • VI.6
    Identify any current grievance, disciplinary or tribunal claim.
    Severity A
  • VI.7
    Confirm bonus, commission and LTIP arrangements and accrued liabilities.
    Severity A
  • VI.8
    Review EMI option grants, vesting and any accelerated-vesting trigger on the transaction.
    Severity A
  • VI.11
    Confirm DB scheme status (if any): funding position, recovery plan, s.75 debt.
    Severity A
  • VI.15
    Confirm TUPE consultation strategy for the proposed transaction (asset deal).[TUPE 2006]
    Severity AAsset-purchase only

Schedule VII - Data privacy

  • VII.9
    Review breach register and any reportable incidents within the last six years.
    Severity A
  • VII.10
    Confirm any ICO enforcement action, audit or undertaking.
    Severity A

Schedule VIII - IT and cyber

  • VIII.5
    Obtain most recent penetration-test report and remediation evidence.
    Severity A
  • VIII.6
    Review security-incident log for the last three years and ICO notifications.
    Severity A
  • VIII.18
    Review historic security incidents impacting customers and notifications.
    Severity A

Schedule IX - Regulatory

  • IX.1
    Confirm whether the target operates in one of the 17 NSI Act sensitive sectors.[NSI Act 2021]
    Severity A
  • IX.2
    If mandatory NSI notification applies, plan for the 30-working-day acceptance period.[NSI Act 2021]
    Severity ABuy-side
  • IX.4
    Assess CMA merger jurisdiction: target UK turnover > £70m or 25% share of supply.[CMA]
    Severity A
  • IX.6
    If target is FCA-authorised, confirm Part XII FSMA change-of-control approval window (60 working days).[FCA change-of-control]
    Severity A
  • IX.7
    Confirm threshold conditions and any current FCA supervisory action.
    Severity A
  • IX.9
    Confirm CQC registrations and inspection ratings (healthcare).[CQC]
    Severity A
  • IX.12
    Identify any pending regulatory investigation or undertakings.
    Severity A

Schedule X - Real estate

  • X.1
    Obtain schedule of all freehold and leasehold property held by the group.
    Severity A
  • X.3
    Review each lease: term, break, rent review, alienation, change-of-control.[LTA 1954]
    Severity A
  • X.5
    Obtain landlord consents required for change of control or assignment.
    Severity A
  • X.13
    Review fire-risk assessment and Building Safety Act 2022 compliance where relevant.[BSA 2022]
    Severity A

Schedule XI - Environmental

  • XI.1
    Commission Phase I ESA on every owned and leased operational site.
    Severity A
  • XI.2
    Commission Phase II ESA (intrusive) where Phase I flags potential contamination.
    Severity ABuy-side
  • XI.3
    Review Part IIA EPA 1990 contaminated-land risk and any local-authority notices.[EPA 1990]
    Severity A
  • XI.5
    Confirm any EA enforcement, prosecution or improvement notice.[Environment Agency]
    Severity A

Schedule XII - Insurance

  • XII.4
    Confirm any policy exclusion or aggregate erosion that affects buyer.
    Severity A
  • XII.10
    Identify any uninsured historical exposures requiring SPA indemnity.
    Severity A

Schedule XIII - ECCTA fraud and anti-bribery

  • XIII.1
    Confirm whether target meets the large-organisation test under ECCTA 2023 s.199.[ECCTA 2023 s.199]
    Severity A
  • XIII.2
    Review failure-to-prevent-fraud reasonable-procedures framework (in force 1 Sep 2025).[ECCTA 2023 s.199]
    Severity A
  • XIII.4
    Confirm Bribery Act 2010 s.7 adequate-procedures programme.[Bribery Act 2010 s.7]
    Severity A
  • XIII.6
    Confirm sanctions-screening of customers, suppliers and counterparties (OFSI list).
    Severity A
  • XIII.9
    Confirm AML / KYC programme if obliged (Money Laundering Regs 2017).
    Severity A
  • XIII.10
    Identify any historic financial-crime investigation or self-report.
    Severity A

Reviewed by Oliver Wakefield-Smith, Founder, Digital SignetLast verified 21 June 2026

This page is anchored to UK primary legislation and named regulator guidance only. Not legal advice. Confirm position with your appointed adviser before signing.