Jul 28 ‘26
30 min read
No time to read? Get a quick AI summary
Private equity dealmaking is more active, more expensive, and less forgiving. McKinsey’s Global Private Markets Report 2026, in its private equity chapter, “Private equity: Clearer view, tougher terrain,” states that buyout and growth deals above $500 million rose 44% in 2025, while median PE purchase multiples increased to 11.8x EBITDA.
At the same time, overall buyout deal count fell 5%, showing that private capital deal volume remained selective even as larger deals returned.
That raises the cost of weak diligence. Small misses in EBITDA, working capital, or customer risk can become expensive after close.
This guide gives GPs a practical checklist across eight workstreams, with re-trade triggers, purchase price adjustment mechanics, and a downloadable request list.
Key takeaways
- PE diligence should separate underwritable numbers from management’s case, especially around EBITDA, cash conversion, working capital, and net debt
- Workstreams run in parallel after the LOI, but commercial and financial screening usually decides whether deeper due diligence is justified
- Re-trade discussions usually come from four inputs: underwritable EBITDA, normalized working capital, closing equity value, or known liability exposure
- The GP uses a private equity data room to manage review discipline, Q&A, evidence, and post-close records, while the target uses it to control disclosure
What is private equity due diligence?
Private equity (PE) due diligence is a structured review of a target company’s financials, operations, contracts, technology, people, tax position, and ESG risks before a PE firm invests. It tests whether the business supports the investment thesis, valuation, deal terms, and a post-close value creation plan.
GP-side vs. LP-side due diligence
In private equity, the general partner (GP) is the legal entity that manages a PE fund. In practice, people often use “GP” to refer to the private equity firm or fund manager responsible for sourcing, acquiring, managing, and exiting portfolio companies.
The limited partner (LP) is an investor that commits capital to the PE fund, such as a pension fund, endowment, insurer, sovereign wealth fund, family office, or fund of funds.
Both private equity managers (GPs) and private equity investors (LPs) can initiate the due diligence process. GP-side due diligence reviews a target company prior to acquisition. LP-side due diligence reviews a private equity fund manager before an investor commits capital.
This guide focuses on GP-side, target-company due diligence, with LP-side diligence included only for comparison.
How PE due diligence differs from M&A and VC due diligence
PE firms often use leveraged buyouts (LBOs), in which debt can account for 60% to 80% of the total transaction price. This is why private equity due diligence is usually more financially and operationally intensive than venture capital or many corporate M&A reviews. That debt load shifts the focus of diligence to financial health, earnings quality, cash conversion, debt capacity, and the operating plan the GP needs to execute after closing.
Private equity due diligence checklist
A PE due diligence checklist typically covers eight core workstreams:
- Financial due diligence. Tests EBITDA quality, cash conversion, working capital, debt, and forecasts
- Commercial due diligence. Tests market position, market growth, customer retention, pricing power, competition, and revenue durability
- Operational due diligence. Assesses processes, capacity, suppliers, KPIs, scalability, and margin improvement potential
- Legal due diligence. Reviews ownership, contracts, litigation, intellectual property, consents, licenses, and regulatory compliance
- Tax due diligence. Checks tax filings, reserves, audits, sales tax, payroll tax, tax attributes, and structure issues
- IT and cybersecurity due diligence. Reviews the target company’s IT infrastructure, cyber controls, data flows, licensing, and resilience
- Human resources and management due diligence. Evaluates leadership, key talent, incentives, retention risk, and workforce obligations
- ESG due diligence. Assesses material environmental, social, and governance risks, data quality, and reporting expectations
Download a private equity due diligence checklist
Need a practical way to organize requests during diligence? Use our private equity due diligence checklist to track document requests across financial, commercial, operational, legal, tax, IT, HR, and ESG workstreams.
The spreadsheet includes a master request list, workstream-specific tabs, status tracking fields, delivery and review columns, and seller response notes. It’s provided in XLSX format, making it ready to upload into virtual data room checklist tools that commonly accept spreadsheet-based request lists.
How PE due diligence workstreams run in a live deal
PE diligence usually moves through four stages:
- Pre-NDA screening
- Post-NDA review
- Full post-LOI diligence
- Final bid/signing
The timeline is tight. A typical mid-market process usually runs 6–12 weeks. Large-cap, regulated, carve-out, or cross-border deals can take 12 weeks or longer because there are more advisors, lender requests, regulatory issues, third-party consents, and dependencies to manage.
GPs usually start with commercial and financial screening because those areas can be tested with public information, a teaser, a confidential information memorandum (CIM), or a management presentation.
As access expands, often after a letter of intent (LOI) or exclusivity agreement, all workstreams deepen in parallel. Their findings inform valuation, financing, protections in the sale-and-purchase agreement (SPA), closing conditions, and the 100-day plan.
Here’s how due diligence runs at each stage.
| Deal stage | Workstreams that usually start | Why they matter at this point |
| Pre-NDA / screening | Commercial, high-level financial, management, and ESG screen | Tests whether the opportunity fits the fund’s mandate and investment opportunity |
| Post-NDA / limited access | Commercial, financial, legal, tax, IT screen | Identifies early deal-breakers before the GP spends the full diligence budget |
| Full diligence | Financial, commercial, operational, legal, tax, IT/cyber, HR, ESG | Tests valuation, financial metrics, risk allocation, and value creation plan |
| Final bid/signing | Financial, legal, tax, HR, IT, ESG | Converts findings into price, SPA protections, closing conditions, escrows, and 100-day actions |
Financial due diligence
The core work of financial due diligence is to reconcile reported performance to source data and test whether EBITDA, cash flow, working capital, and net debt support the deal model.
The financial due diligence checklist tests:
- Whether the reported EBITDA is repeatable
- Whether add-backs are supported by evidence
- Whether revenue recognition matches contracts and delivery
- Whether run-rate adjustments tie to actual pricing, headcount, customer, or cost changes
- Whether cash conversion supports interest, amortization, covenants, and downside cases
- Whether the working capital peg reflects normal operating needs
- Whether net debt and debt-like items are complete
Cash flow deserves separate attention. A company can report attractive margins while still consuming cash through slow collections, inventory buildup, deferred revenue obligations, heavy capital expenditures, or unfavorable payment terms.
Typical red flags
- Aggressive revenue recognition
- Unsupported EBITDA add-backs
- Deteriorating net working capital
- Slow collections or aging receivables
- Inventory build-up or weak reserves
- Forecasts that do not reconcile with historical performance
- Net debt or debt-like items are excluded from the equity value bridge
Commercial due diligence
Commercial due diligence tests whether the revenue story still holds after the GP looks beyond the CIM and management model. The work should tie market evidence, customer behavior, and competitive pressure back to the investment thesis. That means confirming:
- Market size
- Competitive landscape
- Competitive advantage
- Category growth
- Market share trajectory
- Customer retention/concentration
- Pricing power
- Pipeline quality
It also means testing whether management’s forecast depends on actual product demand, signed contracts, visible renewal behavior, or existing sales capacity.
Typical red flags
- Market growth below management’s forecast
- One customer accounts for 20% or more of total revenue (concentration risk)
- Customer churn hidden by new-logo growth
- Top customers are reducing spend or delaying renewals
- Pipeline coverage is too thin for the first-year budget
- Win rates are declining in priority segments
- Pricing pressure from larger competitors
- Product differentiation is weaker than the sales story
- Growth plan depends on unproven geographies or channels
Operational due diligence
Operational due diligence tests whether the target can deliver the plan without relying on post-close heroics. For a GP, the key question is whether the forecast is supported by operational efficiency, capacity, suppliers, systems, and management discipline already inside the business:
- Target company’s operations can support scale
- KPIs are reliable enough for board reporting
- Capacity is sufficient for the growth plan
- Vendor concentration doesn’t create continuity risk
- Supply continuity and service levels are stable
- Automation gaps and manual bottlenecks are understood
- Capex needs are reflected in the value creation plan
If margin expansion depends on operational improvements, such as procurement savings, better throughput, lower rework, or higher utilization, the GP needs evidence that those levers are achievable within the hold period.
Typical red flags
- Capacity constraints that require additional capex
- Single-source vendors that create supply continuity risk
- Weak KPIs that require a post-close reporting reset
- Manual processes that slow scaling
- High error rates, repeated fixes, service failures, or supplier disputes
- Expansion assumptions that depend on systems, sites, or teams that the business does not yet have
Legal due diligence
Legal due diligence should tell the GP whether it can acquire, control, and operate the business without any rights issues that would weaken the investment case. The review should focus on closing certainty, enforceability, ownership, consents, and buyer protection:
- The target is validly formed and authorized to complete the transaction
- Ownership, equity rights, options, warrants, and shareholder approvals are clean
- Key customer, supplier, financing, and operating contracts remain enforceable after close
- Change-of-control, assignment, termination, and consent requirements are known
- Litigation, regulatory correspondence, licenses, and permits are quantified
- IP ownership supports the investment thesis
Typical red flags
- Missing board or shareholder approvals
- Change-of-control or assignment restrictions in key contracts
- Pending or threatened litigation
- Expired licenses, permits, or regulatory filings
- IP created by founders, employees, or contractors without a clear assignment
- Customer or supplier termination rights triggered by the deal
- Financing documents with consent requirements or default risk
Tax due diligence
Tax due diligence should show whether the GP is buying a clean tax position or inheriting exposure that needs to be priced, structured, or protected in the purchase agreement.
The review should cover both compliance and deal structure, because tax findings can affect cash leakage after close as much as historical liabilities:
- Tax returns are complete across relevant jurisdictions
- Tax reserves are adequate
- Sales and use tax exposure is understood
- Payroll and withholding taxes are compliant
- Transfer pricing is supportable for multi-jurisdiction targets
- Net operating losses (NOLs), credits, and other tax attributes are usable
- The proposed structure avoids unnecessary leakage
Typical red flags
- Unfiled or late tax returns
- Open audits or unresolved tax authority correspondence
- Aggressive tax positions without adequate reserves
- Sales tax nexus gaps
- Payroll or withholding tax exposure
- Undocumented transfer pricing
- NOLs limited by ownership-change rules
- Tax liens or unpaid pre-closing liabilities
IT and cybersecurity due diligence
IT due diligence should start early enough to affect the bid. The review should test whether systems, infrastructure, cyber controls, and data practices can support the investment case without creating avoidable Day 1 exposure.
The IT review should focus on areas most likely to create post-close incidents:
- Core systems can support the growth plan
- Infrastructure is stable, scalable, and monitored
- Access controls cover privileged users, critical systems, and AI tools
- Prior incidents are known, remediated, and documented
- Software licensing and open-source use are compliant
- Personal data flows are mapped across systems, vendors, and AI applications
- Backup, disaster recovery, and business continuity plans are tested
- AI-generated code is subject to secure coding standards, code review, dependency scanning, and human approval before production
AI use now deserves specific attention. IBM’s 2025 Cost of a Data Breach Report found that 97% of organizations that reported an AI-related security incident lacked proper AI access controls, and 63% lacked AI governance policies to manage AI or prevent shadow AI.
Typical red flags
- Prior breach with incomplete remediation
- Weak privileged access controls
- No tested disaster recovery plan
- Unsupported legacy systems
- Unlicensed or restricted-use software
- Unmapped personal data flows
- Shadow AI tools with no access controls or governance
- Weak review controls for AI-assisted development
HR due diligence
HR due diligence tests whether the people who drive revenue, operations, customer relationships, and technical knowledge will still be there after close.
The review should confirm:
- Who actually runs the business day to day
- Whether customer, technical, or operating knowledge sits with too few people
- Whether the second layer of management is strong enough
- Whether employment agreements, compensation, and incentives support the post-close plan
- Whether change-in-control payments or benefit obligations create hidden costs
- Whether retention risk threatens execution
Typical red flags
- Key person dependency in sales, operations, finance, or technology
- No retention plan for management or critical employees
- Weak second layer below founders or owner-operators
- Change-in-control payouts that increase deal cost
- Unfunded benefit or pension obligations
- High regrettable attrition
- Misclassified contractors or unresolved employee claims
ESG due diligence
Bain & Company, in collaboration with the Institutional Limited Partners Association ILPA), notes “LPs now factor ESG issues into investment decisions and consider how they will affect private equity (PE) investments”.
Because LPs evaluate whether GPs integrate ESG into investment decisions, GPs need to demonstrate how they assess material ESG risks during target-company underwriting.
The review should confirm whether:
- Environmental liabilities are identified
- Health and safety exposure is understood
- Labor practices don’t create hidden risk
- Governance controls can support institutional ownership
- ESG data is reliable enough for LP and lender reporting
- Sector-specific ESG issues are materiality-tested
Typical red flags
- Environmental permits are missing or expired
- Remediation liabilities are not quantified
- Health and safety incidents show poor controls
- Labor violations or grievance patterns are unresolved
- Governance policies exist, but aren’t enforced
- ESG data is incomplete or inconsistent
- No owner is assigned to post-close remediation
When a private equity investment due diligence checklist justifies a re-trade
Re-trade triggers are diligence findings that give the GP a basis to revisit price, structure, or buyer protections after the letter of intent. Not all red flags found in confirmatory diligence justify a re-trade.
A GP usually has a stronger position when the finding changes one of four deal inputs: underwritable EBITDA, normalized working capital, closing equity value, or known liability exposure.
The most material re-trade triggers are:
- QoE reduces supportable EBITDA versus the LOI case
- Net working capital is below the level needed to run the business normally
- Net debt or debt-like items were excluded from the seller’s equity value bridge
- Customer concentration, churn, or contract loss changes the revenue base
- Tax, litigation, regulatory, cyber, or environmental exposure creates a quantifiable liability
Purchase price adjustments
The adjustment should match the finding:
- EBITDA issues usually affect enterprise value through the agreed-upon multiple
- Working capital issues usually affect the peg or closing accounts mechanism
- Debt-like items reduce equity value at closing
- Known liabilities are usually handled through escrow, special indemnity, holdback, or a closing condition
The seller conversation should be evidence-led. Strong re-trades show the gap between the LOI assumptions and the confirmatory diligence record. The GP should tie each proposed adjustment to source documents, QoE findings, customer diligence, legal review, or advisor analysis.
The role of the virtual data room in PE due diligence
A virtual data room (VDR) is a secure hub for the target company’s confidential materials during PE diligence. In most processes, the target or sell-side advisor opens the VDR, uploads documents, sets permissions, and invites the GP’s deal team.
The GP then reviews materials, assigns work to internal and external advisors, submits follow-up requests, and uses Q&A to clarify issues with management or the sell-side advisor. Some GPs also run their own VDR pipeline and invite targets to upload materials against a standard diligence request list.
In either setup, the due diligence data room helps the GP coordinate document review, track open questions, preserve evidence behind the investment decision, and keep diligence organized by workstream.
The VDR’s role changes as access expands:
| Deal phase | How the VDR is typically used |
| Pre-NDA screening | Internal storage for screening notes, sector research, early request lists, and investment committee materials, if the GP runs its own workspace |
| Limited access | Controlled sharing of CIM, management presentation, summary financials, and selected commercial materials |
| Full diligence | Workstream-level document review, advisor access, Q&A tracking, request-list management, and escalation of open items |
| Closing and archive | Final exchange of signed agreements, disclosure schedules, financing documents, board approvals, and closing deliverables |
After close, the archived VDR gives the GP a diligence record for integration, audit requests, warranty claims, and post-closing disputes.
LP-side due diligence on PE funds
In LP-side due diligence, a limited partner evaluates whether a private equity fund manager can deploy capital, manage risk, report transparently, and return cash over the fund’s life.
The industry reference point is the ILPA Due Diligence Questionnaire (DDQ), which ILPA describes as a standardized framework for investor diligence of managers and ongoing monitoring.
What LPs evaluate
LP diligence typically focuses on the fund manager, the strategy, and the controls behind the product:
- Track record and attribution, including IRR, TVPI, DPI/DVPI, RVPI, realized vs. unrealized value, cash flows, loss deals, benchmarks, and performance with and without credit facilities
- Investment strategy, sourcing, underwriting process, portfolio construction, leverage, value creation approach, monitoring, and exit discipline
- Team stability, succession planning, key person provisions, investment committee roles, turnover, bandwidth, and GP commitment
- Alignment of interests, including carry allocation, GP contribution, co-investment policy, fee offsets, clawback, and conflicts management
- Fund terms, including management fees, preferred return or hurdle, waterfall, expenses, side letters, LPAC rights, indemnification, transfer rights, and recycling
- Governance, risk, compliance, legal history, regulatory exams, conflicts policy, AML/CFT, insurance, and internal controls
- Accounting, valuation, audit, fund administration, reporting, investor portal, capital call notices, distribution notices, and GIPS reporting, where applicable
- Data security, technology tools, third-party providers, cyber policies, business continuity, disaster recovery, and breach history
- ESG, responsible investment, climate-related processes, ESG KPIs, incident reporting, and DEI metrics at the firm and portfolio-company level
Post-close 100-day plan
In the first 100 days, the private equity teams should prioritize maintaining continuity, then move quickly from underwriting assumptions to an operating plan that management can execute.
Day 1: Take control without disrupting the business
Day 1 should establish authority and continuity:
- Set decision rights, reporting lines, and board cadence
- Communicate the ownership change to employees, key customers, and critical vendors
- Lock down cash controls, banking access, approval limits, and signing authority
- Confirm payroll, benefits, and retention arrangements for key employees
- Escalate urgent legal consents, IT access, cyber risks, and compliance items
Day 30: Reset the operating baseline
The first month should establish an ownership baseline with clear owners and near-term actions:
- Set the first 13-week cash forecast and working capital plan
- Build the KPI dashboard for board and management reporting, covering key financial metrics, current revenue growth, and the main drivers of future growth.
- Assign owners to customer retention, churn, pipeline, and pricing actions
- Prioritize operational bottlenecks, vendor risks, and capacity fixes
- Approve hiring, retention, or role changes for management gaps
- Convert tax, legal, ESG, and IT findings into budgets, deadlines, and accountable owners
Day 60: Launch value creation initiatives
By Day 60, the GP should move to measurable execution:
- Start pricing, procurement, sales, margin, or account-retention initiatives
- Begin cybersecurity, systems, reporting, and data remediation
- Resolve priority contract, regulatory, tax, and ESG actions
- Align management incentives with the investment thesis
Day 100: Lock the execution rhythm
By Day 100, the board and management team should have a funded operating plan with KPIs, owners, milestones, and a 12-month value creation roadmap.
Category
Due diligenceFAQ
Private equity due diligence is a structured review of a target company before a PE firm invests. It tests whether the company’s financials, operations, contracts, risks, and value-creation potential support the investment thesis and purchase price.
Mid-market PE due diligence often takes 6–12 weeks, depending on deal complexity, data room readiness, lender requirements, and the number of workstreams involved. Larger or highly regulated deals can take longer.
The main phases are pre-NDA screening, limited post-NDA review, full confirmatory diligence after serious buyer interest, and final diligence before signing and closing. Each phase gives the GP progressively deeper access to the target company’s information.
A private equity portfolio company due diligence checklist usually covers financial, commercial, operational, legal, tax, IT and cybersecurity, HR and management, and ESG diligence. A comprehensive due diligence checklist should also include document requests, red flags, and post-close 100-day priorities.
Exploratory due diligence helps the GP decide whether the opportunity is worth pursuing before committing major time or cost. Confirmatory due diligence tests the deal assumptions in detail before signing, financing, and closing.