M&A Data Room Checklist and Folder Guide
Last verified: September 21, 2026
A well-organized M&A data room checklist provides a structured framework for managing disclosure materials, facilitating systematic review, and organizing transaction documentation. This guide provides a complete folder structure, staged permission model, and buy-side workflow for mid-market and enterprise transactions. Every section below is designed to help you set up or audit a virtual data room (VDR) for an M&A deal.
What Belongs in an M&A Data Room
An M&A data room serves as the single repository for all disclosures during a transaction. The sell-side team populates it with corporate, financial, legal, and operational documentation. The buy-side team reviews, cross-references, and submits questions through the platform's Q&A module.
Operational vs. Legal Requirements: Data room preparation involves both operational practices (such as standardized folder indexing, OCR document formatting, and Q&A routing) and strict legal or regulatory requirements (such as HSR antitrust filings, PIIAA chain-of-title verification, and tax authority compliance). Deal teams should distinguish administrative file management from formal legal obligations advised by counsel.
The checklist below covers the eight primary document categories required by most institutional buyers and their advisors. The structure follows conventions used by transaction advisory firms and legal counsel, though specific deals may require additional categories depending on industry, jurisdiction, and deal size.
The Complete Folder Structure
1.0 Corporate Records and Governance
This section establishes that the target company is a legally valid entity in good standing.
- 1.1 Certificate of Incorporation / Articles of Organization: The filed charter and all subsequent amendments.
- 1.2 Bylaws or Operating Agreement: Current governing documents of the entity.
- 1.3 Board Minutes and Resolutions: Minutes from Board of Directors meetings for the past three to five years, plus all Unanimous Written Consents (UWCs).
- 1.4 Capitalization Table: A fully diluted cap table showing all common stock, preferred stock, options, warrants, SAFEs, and convertible notes. Export from a cap table management platform if available.
- 1.5 Shareholder and Voting Agreements: Investor Rights Agreements (IRAs), Right of First Refusal (ROFR) agreements, and any co-sale or drag-along provisions.
- 1.6 Organizational Chart: A legal entity hierarchy showing all subsidiaries, joint ventures, and holding companies.
- 1.7 Good Standing Certificates: Current certificates from each jurisdiction where the entity is qualified to do business.
2.0 Financial Information
Buyers use this section to verify EBITDA, revenue quality, and working capital. This is typically the most scrutinized area.
- 2.1 Audited Financial Statements: Income statements, balance sheets, and cash flow statements for the past three fiscal years, prepared by an independent CPA firm.
- 2.2 Interim (Unaudited) Financials: Year-to-date and trailing twelve months (TTM) statements, compared against the same prior-year period.
- 2.3 Financial Projections: The management operating model and multi-year forecast with documented assumptions.
- 2.4 General Ledger Detail: Detailed GL exports to support a Quality of Earnings (QoE) analysis. The AICPA's guide to agreed-upon procedures provides context on how QoE analyses are typically scoped.
- 2.5 Debt and Credit Agreements: All promissory notes, revolving credit facilities, equipment leases, and UCC filings.
- 2.6 Accounts Receivable and Payable Aging: Detailed aging reports, typically in 30-day buckets (0–30, 31–60, 61–90, 90+ days).
- 2.7 Capital Expenditure Schedules: Historical CapEx and projected future capital requirements, separated by maintenance and growth.
3.0 Tax Documentation
Tax liabilities can materially affect purchase price. The buyer's tax advisors will review this section for exposure.
- 3.1 Federal, State, and Local Tax Returns: Complete filings for the past three to five years.
- 3.2 Tax Authority Correspondence: Any notices, settlement agreements, or audit communications with the IRS or state tax agencies. The IRS Examination Process overview explains how tax audits proceed and what documentation the IRS typically requests.
- 3.3 Sales and Use Tax Records: Nexus analysis and sales tax collection documentation.
- 3.4 Transfer Pricing Studies: For entities with intercompany transactions, documentation of arm's-length pricing.
- 3.5 Section 409A Valuations: Independent appraisals supporting the strike price of employee stock options.
4.0 Material Contracts and Customer Data
This section assesses commercial viability and customer concentration.
- 4.1 Top Customer Contracts: Fully executed Master Services Agreements (MSAs), order forms, and SLAs for the top 20 to 50 customers by revenue.
- 4.2 Vendor and Supplier Contracts: Agreements with critical suppliers, hosting providers, and strategic partners.
- 4.3 Standard Contract Templates: The company's standard Terms of Service, Privacy Policy, and NDA.
- 4.4 Change-of-Control Provisions: A schedule identifying contracts that require counterparty consent upon an acquisition or assignment.
- 4.5 Customer Retention Data: Net Revenue Retention (NRR) and Gross Revenue Retention (GRR) cohort analyses.
5.0 Human Resources and Employee Benefits
Labor costs and employment liabilities are material concerns for any buyer.
- 5.1 Employee Census (Anonymized): A spreadsheet listing active employees, titles, start dates, base salaries, and equity grants. Names are typically redacted until late-stage diligence.
- 5.2 Independent Contractor Agreements: Contracts for all 1099 workers, reviewed for misclassification risk.
- 5.3 Executive Employment Agreements: C-suite contracts including severance, non-compete clauses, and change-of-control provisions.
- 5.4 Benefit Plans: Health insurance, 401(k) or pension plans, and summary plan descriptions.
- 5.5 Employee Handbook: Current HR policies, PTO policy, and code of conduct.
- 5.6 Collective Bargaining Agreements: If applicable, all union agreements.
6.0 Intellectual Property and Technology
For technology companies, IP is often the primary asset under acquisition. Buyers must verify the complete chain of title.
- 6.1 Patents and Trademarks: Schedules of issued, pending, and abandoned registrations, plus domain name ownership records.
- 6.2 IP Assignment Agreements: Signed agreements from all employees and contractors assigning created IP to the company.
- 6.3 Open Source Software (OSS) Audit: A report listing all open-source libraries used, with their license types (MIT, Apache, GPL, etc.) and compliance status.
- 6.4 Software Escrow Agreements: If applicable, agreements where source code is held by a third party for the benefit of customers.
- 6.5 Architecture Documentation: High-level system architecture, data flow diagrams, and infrastructure overviews.
7.0 Legal, Regulatory, and Compliance
- 7.1 Active and Threatened Litigation: Pleadings, settlement agreements, and attorney-assessed risk summaries.
- 7.2 Regulatory Licenses and Permits: Industry-specific authorizations.
- 7.3 Environmental Assessments: Phase I and Phase II Environmental Site Assessments for companies with physical operations or real property.
- 7.4 Data Privacy and Security Compliance: GDPR, CCPA, and SOC 2 audit reports.
8.0 Real Estate and Physical Assets
- 8.1 Real Estate Leases: All commercial leases and amendments.
- 8.2 Owned Property: Deeds, title insurance policies, and appraisals.
- 8.3 Equipment Schedules: Leased or owned equipment inventories.
Access Control: Staged Disclosure Model
A data room should not be fully open to every bidder from day one. Documents should be released in phases based on the buyer's progression:
| Stage | Trigger | What to Grant | What to Withhold |
|---|---|---|---|
| Stage 1: Preliminary | Signed NDA, no LOI | High-level financials, corporate overview, anonymized customer data | Specific contracts, salaries, trade secrets, source code |
| Stage 2: Deep Diligence | Signed LOI, exclusivity | Detailed GL data, material contracts, tax filings, legal histories | Unredacted competitive pricing, Clean Room materials |
| Stage 3: Clean Room | Final-stage confirmatory | Unredacted pricing, customer lists, strategic roadmaps | Available only to walled-off third-party advisors or Clean Team members |
For transactions between competitors, antitrust requirements (such as those outlined in the Hart-Scott-Rodino Act) may require a formal Clean Team arrangement to prevent the exchange of competitively sensitive information before regulatory clearance.
Buy-Side Diligence Workflow
While the seller populates the data room, the buy-side team must systematically review it. Key workflows include:
Q&A Process: Buyers should use the VDR's built-in Q&A module rather than email. When a reviewer finds an ambiguous change-of-control clause, they submit a question linked to the specific document. The sell-side team reviews, approves internally, and publishes the response within the platform. This creates an auditable disclosure record. For a detailed look at how to structure this process, see our M&A Q&A workflow guide.
Quality of Earnings (QoE) Analysis: The buyer's accounting firm uses the financial and tax folders to produce a QoE report verifying that the seller's adjusted EBITDA is accurate and sustainable.
Legal Diligence Report: Buy-side counsel reviews corporate governance, contracts, and IP folders to produce a risk report. The findings directly inform the representations, warranties, and indemnification provisions in the definitive purchase agreement.
For teams evaluating M&A-specific data room platforms, our comparison of M&A data room software covers feature requirements and pricing structures.
Common Mistakes to Avoid
- Missing IP assignments. If any founder, employee, or contractor lacks a signed Proprietary Information and Inventions Assignment Agreement (PIIAA), this creates a chain-of-title defect that buyers will flag.
- Unstructured file naming. Use a strict alphanumeric index (e.g.,
1.0 Corporate,1.1 Articles of Incorporation). Without numbering, files sort alphabetically and destroy the logical review flow. - Incomplete redaction. Personally Identifiable Information (PII) must be redacted from employee records in early-stage disclosures to comply with applicable privacy laws.
- Overloading the data room. Dumping thousands of unlabeled files into a single folder — sometimes called a "data dump" — signals disorganization and can extend due diligence timelines significantly.
- No version control. When documents are updated during the Q&A phase, prior versions should be archived, not deleted. Buyers need to track changes over time.
Verification Checks Before Launch
Before opening the data room to prospective buyers, run through this pre-launch verification:
- Every folder follows the numbered index structure
- All documents are searchable PDFs (not scanned images without OCR)
- The cap table reconciles with the most recent board-approved version
- IP assignment agreements exist for every current and former employee and contractor
- Redactions are applied consistently to all early-stage disclosure documents
- The Q&A module is configured with appropriate routing and approval workflows
- Access permissions are set for Stage 1 only — Stage 2 and Clean Room folders are restricted
When preparing to share diligence documents with multiple bidder groups, a platform that supports granular permissions and secure PDF sharing can help manage staged disclosure without creating separate file repositories for each party.
Post-Closing Disclosure Schedule Reconciliation
At the conclusion of due diligence, transaction counsel uses the data room file index to draft formal Disclosure Schedules (such as Schedule 3.8 for Material Contracts, Schedule 3.14 for Intellectual Property, and Schedule 3.19 for Environmental Liabilities) attached to the Definitive Purchase Agreement. Sell-side teams must cross-reference every document ID in the VDR against the final disclosure index to ensure that exceptions flagged during Q&A are formally disclosed. Proper schedule reconciliation protects the seller under contractual representation and warranty indemnification provisions.
When This Checklist Does Not Apply
This checklist is designed for mid-market and enterprise M&A transactions involving operating companies. It may not be sufficient or appropriate for:
- Asset-only purchases where the buyer acquires specific assets (real property, equipment, IP) without the corporate entity. See our real estate data room checklist for property-specific requirements.
- Private credit or debt financing where the emphasis shifts heavily toward cash flow analysis and covenant compliance. See our private credit data room guide.
- Cross-border transactions that may require additional documentation for foreign regulatory approvals, transfer pricing, and localized data residency.
- Highly regulated industries (healthcare, defense, banking) that require additional compliance documentation beyond what is listed here.
Summary
A standardized M&A data room checklist reduces friction during due diligence by ensuring that both sides of the transaction can locate, review, and discuss documents efficiently. The checklist above covers eight core categories, a staged access model, and verification checks designed for mid-market deals. Adapt the specific folders and document requirements based on your industry, jurisdiction, and deal complexity.
Sources and Verification Notes
- AICPA — Forensic and Valuation Services: Guidelines on agreed-upon procedures and Quality of Earnings analyses. aicpa.org/resources/landing/forensic-and-valuation-services
- FTC — Hart-Scott-Rodino Act: Pre-merger notification requirements and antitrust guidelines for M&A transactions. ftc.gov/legal-library/browse/statutes/hart-scott-rodino-antitrust-improvements-act-1976
- IRS — Examination Process: Overview of how tax audits are conducted and what documentation is typically requested. irs.gov/businesses/small-businesses-self-employed/irs-audits
- NVCA — Model Legal Documents: Standardized legal templates for corporate structure verification in venture-backed companies. nvca.org/model-legal-documents
Editorial Disclosure: VDR Directory is published by the team behind SendNow. Where SendNow features are mentioned, the same evaluation criteria apply as for all other platforms reviewed on this site.