Due Diligence Data Room Folder Structure: Complete Index Guide
Build a due diligence data room folder structure for corporate, financial, commercial, legal, tax, people, technology, security and transaction records.
A due diligence data room folder structure should help reviewers find approved evidence while preserving the seller's or company's control over sensitive information. The best structure follows the request list and transaction, not a generic template copied without review.
Commercial disclosure: VDR Directory is published by the team behind SendNow.
Folders are only one part of the design. A reliable room also needs document owners, status, classification, groups, release phases, Q&A, and an archive plan. A beautifully numbered hierarchy can still fail if the wrong users inherit access or draft files are published automatically.
This guide is a starting framework, not legal, tax, accounting, privacy, or transaction advice. Adapt it with the responsible advisers.
Commercial disclosure: VDR Directory is published by the team behind SendNow. SendNow is mentioned for limited initial document distribution and not as a complete replacement for a structured multi-party diligence room.
Design principles
Use a shallow, numbered hierarchy. Keep top-level sections stable, align request IDs to folders, and use descriptive filenames. Separate internal staging from external publication. Assign each document one authoritative owner and status.
Avoid duplicating the same file in multiple sections. Use cross-references in the request register when one document answers several questions. Duplication creates inconsistent versions and makes the closing archive harder to reconcile.
Do not encode confidential information in filenames. A restricted investigation or employee name can leak through search or notifications even if the file is inaccessible.
Recommended top-level index
The following structure fits many corporate transactions:
- Process and room guidance
- Corporate organization and governance
- Capitalization and ownership
- Financial information
- Commercial, customers and suppliers
- Material contracts
- Legal, compliance and disputes
- Tax
- People, employment and benefits
- Technology, intellectual property and data
- Information security and privacy
- Operations, assets and real estate
- Insurance and risk
- ESG and environmental matters
- Transaction, financing and closing
- Restricted and clean-team materials
Remove irrelevant sections and add industry-specific areas where necessary. A biotech licensing room, real-estate portfolio, and SaaS acquisition should not have identical indices.
1. Process and room guidance
Include a readme, room index, request register, process letter, timetable, contact list, Q&A instructions, definitions, and document conventions. Explain dates, currencies, entities, and data-room cut-off.
Do not expose internal owners or reviewer notes to external groups. Maintain the operational request register in a restricted work area if it contains internal commentary.
2. Corporate organization and governance
Potential subfolders include formation documents, bylaws or operating agreements, subsidiaries, qualifications, organization charts, board and shareholder records, powers of attorney, registers, and corporate policies.
Distinguish current governing documents from superseded versions. Identify missing records and remediation status rather than hiding gaps. Restrict privileged governance advice.
3. Capitalization and ownership
Include the capitalization table, securities issuances, option plans, warrants, convertible instruments, shareholder agreements, investor rights, transfer restrictions, repurchases, and ownership registers. Provide a reconciliation date and owner.
Keep personal tax identifiers, bank details, and unneeded holder information out of broad access. Use redacted or aggregated schedules where they answer the request.
4. Financial information
Create subfolders for audited statements, management accounts, general-ledger summaries, budgets, forecasts, revenue, costs, working capital, cash, debt, assets, liabilities, and accounting policies. Include a metric dictionary and reconciliation notes.
Separate historical actuals from forecasts. Label currencies, periods, and consolidation scope. Add readme files for complex spreadsheets. Do not publish hidden tabs, comments, or broken external links.
5. Commercial, customers and suppliers
Organize market material, pipeline, bookings, revenue concentration, customer cohorts, churn or retention, pricing, channel partners, key suppliers, and dependencies. Start with aggregated analysis and a contract register.
Customer-level pricing and margins can be competitively sensitive. Use staged access, redaction, or clean-team review where required. Respect confidentiality provisions in third-party contracts.
6. Material contracts
Use a contract register with counterparty, entity, type, effective date, term, renewal, termination, change-of-control, assignment, exclusivity, financial value, and owner. Link each register row to the approved agreement and amendments.
Subfolders may include customer, supplier, partner, licensing, financing, real estate, reseller, government, and related-party contracts. Keep drafts separate from executed copies.
7. Legal, compliance and disputes
Include litigation summaries, claims, investigations, regulatory licences, correspondence, compliance programs, consents, permits, policies, and remediation trackers. Distinguish factual summaries from privileged legal analysis.
Counsel should review disclosure and privilege. Use restricted areas where necessary. Do not upload broad counsel communications in response to an ambiguous request.
8. Tax
Organize federal, state, local, and international returns; provision and reconciliation material; audits; correspondence; attributes; transfer pricing; sales and indirect tax; payroll tax; property tax; elections; and transaction-specific analyses.
Tax returns contain sensitive identifiers. Restrict access and consider reviewed extracts. The final structure should follow the entities and jurisdictions in scope.
9. People, employment and benefits
Include organization charts, headcount summaries, key employment agreements, incentive plans, policies, contractor arrangements, benefits, pensions, union or works-council matters, immigration, disputes, and compliance summaries.
Use aggregated data first. Redact addresses, government identifiers, health information, bank details, and other unnecessary personal data. Create a restricted specialist folder for employee-level records if required.
10. Technology, intellectual property and data
Potential subfolders include architecture, product roadmap, software inventory, open-source process, development practices, IP registrations, assignments, licences, domains, source-code escrow, technical debt, critical vendors, data flows, and business continuity.
Do not upload credentials, secrets, source code, or detailed exploit information unless a specific, approved process requires it. Use summaries and supervised reviews where appropriate.
11. Information security and privacy
Include governance, risk assessments, policies, independent assurance, penetration-test summaries, vulnerability management, incident response, incidents, access control, logging, privacy notices, records of processing, retention, data-subject requests, and vendor risk.
Separate public assurance from restricted findings. Link remediation items to owners and dates. A policy is not evidence that a control operated; include suitable reviewed evidence where needed.
12. Operations, assets and real estate
Organize facilities, leases, equipment, inventory, supply chain, manufacturing, service delivery, quality, environmental permits, business continuity, and disaster recovery. For real estate, create property-level subfolders using a consistent template.
Identify owned versus leased assets and connect schedules to financial statements. Avoid uploading unreviewed site photographs or records containing personal data.
13. Insurance and risk
Include policy schedules, certificates, claims history, coverage summaries, broker reports, renewal status, and risk registers. Restrict sensitive claims details and privileged coverage advice.
State coverage periods and named insured entities. Review change-of-control, run-off, notice, and tail considerations with advisers.
14. ESG and environmental matters
Include environmental permits, assessments, emissions or energy data, health and safety, supply-chain policies, sustainability reports, diversity metrics, and remediation matters where relevant. Define methodologies and reporting boundaries.
Avoid unsupported claims. Separate externally assured metrics from internal estimates and forecasts.
15. Transaction, financing and closing
Use this area for process letters, term sheets, transaction agreements, disclosure schedules, financing, approvals, regulatory filings, conditions precedent, funds flow, closing checklists, executed documents, and post-closing obligations.
Separate drafts from execution copies. Label signature status. At close, reconcile the final set and transfer it to the approved records repository.
16. Restricted and clean-team materials
Do not use one restricted folder for everything. Create purpose-specific areas for personal information, privileged review, customer-level competitive data, security findings, lenders, and clean teams. Each should have defined membership, approver, permitted use, release phase, and expiry.
The FTC has recommended protocols and clean teams where competitively sensitive information must be exchanged in pre-merger diligence. Counsel should design the protocol; the VDR should implement it.
Staging versus external structure
Maintain two layers:
- Internal staging: source files, drafts, reviewer notes, redaction work, and approval evidence.
- External published room: only approved documents organized for reviewers.
Contributors should upload to staging. Reviewers confirm scope, version, classification, metadata, and target audience. Release approvers authorize publication. An administrator publishes and a second person verifies access.
This workflow is more important than the folder names.
File naming convention
Use request ID, descriptive title, entity or period, and status where helpful. Examples:
- 04.03 Audited Financial Statements FY2025 Executed
- 05.07 Top Customer Revenue Analysis FY2024-FY2026 Redacted
- 06.12 Supplier Agreement Vendor X Executed 2024-05-10
Avoid duplicate "final" labels, ambiguous acronyms, personal names in restricted matters, and operating-system-problem characters. Keep paths short enough to survive archive extraction.
Permission overlay
The folder index should connect to a matrix. List internal team, counsel, each bidder or lender, clean team, specialists, and administrators against folder classes and actions.
Test list, search, preview, download, print, upload, question, invite, and export. A user who cannot open a file should also not see its sensitive filename in search or notifications.
Small initial distribution
Before the full room opens, a company may share an approved teaser or deck through SendNow document tracking with recipient gating, expiration, watermarking, revocation, and engagement information. Verify current features and complete a suitable review.
Move to the structured VDR when the process requires the indexed sections, external groups, Q&A, restricted folders, and archive described above.
Quality-control checklist
Before launch:
- Reconcile every released file to the request register.
- Confirm owner, period, entity, status, and version.
- Remove hidden data and unrelated personal information.
- Validate redaction with a second reviewer.
- Open every file and check readability.
- Test search and OCR for representative documents.
- Verify permissions with external test accounts.
- Test direct links, notifications, and mobile access.
- Freeze and record the initial release set.
- Confirm Q&A, support, incident, and archive procedures.
Archive mapping
At close, export the index, final files, versions, users, groups, permissions, Q&A, activity, and release history required by the organization. Open the archive outside the platform and verify links and representative files.
Preserve a readme explaining the room, dates, parties, currencies, index, and known limitations. Assign a custodian, retention rule, and access group.
Change control during diligence
Maintain a release log with document ID, earlier version, new version, reason, approver, target groups, publication time, and notification decision. Perform a post-release check through a recipient test account. This prevents the folder tree from drifting away from the approved request register as the transaction accelerates.
Review the index weekly for empty folders, duplicates, stale drafts, broken references, and temporary exceptions. Structural cleanup should never delete evidence needed for the transaction record; archive or supersede items under the approved procedure.
For related guidance, review the due diligence hub, M&A data-room checklist, and VDR setup guide.
Final recommendation
Use the folder structure as a navigation and control layer, not as a substitute for governance. Keep it shallow, align it to the request register, separate staging from publication, avoid duplicates, and overlay it with tested groups and classification.
The strongest index allows an external reviewer to find the approved evidence and allows the room owner to explain exactly why each document was present, who could access it, and where the final record now lives.
Sources and verification notes
- FTC guidance on antitrust safeguards during pre-merger diligence
- NIST SP 800-207: Zero Trust Architecture
- NIST SP 800-92: Guide to Computer Security Log Management
- CISA guidance on protecting stored data
- FTC Safeguards Rule
Sources were reviewed on September 29, 2026. Diligence scope, legal duties, and VDR capabilities vary. Verify current requirements with responsible advisers.