top of page

Corporate Due Diligence Checklist: 10 Essential Checks

  • Writer: Sentry Private Investigators
    Sentry Private Investigators
  • 3 hours ago
  • 14 min read

Before you sign an acquisition agreement or bring a new commercial partner into your business, polished accounts and confident assurances can still leave important questions unanswered. Are the reported customers committed? Do the directors have undisclosed histories that affect your risk? Does the company control the intellectual property it sells, and are its payment processes vulnerable to fraud?


A sound corporate due diligence checklist turns those claims into evidence. It compares filings, accounts, contracts, ownership records, people, relationships and real-world operations, rather than treating a completed document request as proof that everything is sound. UK company-register access has made documentary checking far more accessible. Companies House made register data free to search on 22 June 2015, and its service recorded 63.9 million filing-history searches by the end of March 2016, compared with 4.7 million on legacy systems. The same service reports that free register data was accessed 1.3 billion times between 2015 and 2016 and over 16 billion times between 2023 and 2024 (Companies House's service review).


The ten checks below set out what to request, what to reconcile, which red flags deserve escalation and when discreet investigation can answer questions paperwork can't. They also point you towards a practical evidence log, a downloadable checklist/template and specialist support from Sentry Private Investigators Ltd for background checks, fraud enquiries, surveillance and TSCM work. You may also find this founder's financial due diligence checklist useful when organising the accounting workstream.


1. Financial Records and Accounting Verification


Accounts tell you what management has reported. They don't automatically tell you whether the business generates the cash, owns the assets or carries the liabilities described during negotiations. Start by requesting statutory accounts for at least three years, together with the latest confirmation statement, charges register and PSC register from Companies House. The British Business Bank's due diligence checklist identifies these filings as a core evidence set for cross-checking ownership, control, liens and filing consistency.


Reconcile the accounts against management packs, bank statements, debt schedules, tax positions and customer records. Look for revenue that doesn't convert into cash, unusual journal entries, related-party payments, unexplained write-offs, inventory that can't be verified and liabilities that appear outside the balance sheet. Bank evidence should support material transactions, not merely sit in a data room as an unread attachment.


Evidence that deserves closer attention


Ask for audit reports, accountant correspondence and management letters where they exist. Then document each issue with the relevant period, ledger or document reference, the explanation provided and the action required. A qualified accountant should assess accounting treatment, while a forensic investigator can examine suspected manipulation, concealed payments or a pattern that suggests fraud.


Practical rule: Treat an explanation as a lead until the underlying record supports it.

Cash-flow pressure can also change the investigation. Late filings, repeated creditor changes, new charges or abrupt officer movements may justify wider checks before you commit. For a fuller transaction-focused approach, review due diligence for acquisitions, particularly where financial evidence conflicts with what management has presented.


Professional workspace with financial balance sheet documents, laptop, magnifying glass, and coffee cup on a wooden desk.



A company can be properly incorporated and still operate outside the rules that govern its sector. Legal and regulatory review should establish which licences, permits, approvals and professional accreditations the business needs, whether they remain valid and whether regulators have raised concerns.


Search the relevant registers and request direct evidence from the target. Financial services businesses should be checked against the Financial Conduct Authority register. Food businesses may require inspection and enforcement information from the Food Standards Agency. Environmental operations should be assessed through the appropriate regulator, including correspondence about pollution, waste, permits or remediation. Companies House filings can reveal corporate events, but they won't replace searches of sector-specific authorities or a review of litigation and threatened claims.


Build a regulatory evidence trail


For each permission, record its holder, scope, expiry or renewal position, operating site and any conditions. Ask for notices, correspondence, settlement agreements, complaints, insurance notifications and legal advice relating to disputes. Verify professional qualifications directly with the issuing body where a person's certification is material to the business.


The risk isn't limited to a fine. A missing approval may interrupt operations, prevent a site from being transferred or create exposure for the acquiring organisation. It can also reveal that management's compliance system is reactive rather than controlled.


Don't force every target through the same rigid list. HMRC's VATF73000 guidance says it is “not prescribing a list of checks that must be carried out”, reflecting a risk-based approach to UK due diligence (HMRC guidance). The government's generic fraud checklist groups warning signs around personal and organisational motives, internal-control weaknesses, transaction indicators and concealment methods. Use that logic to increase scrutiny where the sector, people or transaction creates greater risk.


3. Management and Key Personnel Background Checks


Senior people can create risk that won't appear in the company's accounts. Review directors, board members, beneficial owners and key managers for the experience they claim, their previous appointments, professional conduct and any circumstances that could affect their ability to act responsibly.


Companies House is a useful starting point for previous directorships, dissolved or struck-off companies, officer changes and filing patterns. It isn't a complete character assessment. A person may have used different addresses or names, and a company-level search can miss an issue connected to an individual.


Verify the person, not just the CV


Cross-check qualifications with the institution that issued them. Investigate unexplained employment gaps, sudden career changes, inconsistent job titles and achievements that can't be corroborated. Open-source checks can identify relevant public information, but investigators should distinguish an evidenced fact from an assumption based on social media content.


Sanctions and PEP screening should extend to directors, beneficial owners and key management. UK sanctions-screening guidance recommends collecting identifiers such as full names, dates of birth, company names, registration numbers, addresses and UBO or PSC details before checking official lists, watchlists and internal deny lists.


A company-level search can look clean while a designated individual sits behind the control structure.

For sensitive appointments, a discreet background investigation can verify identity, residence history, professional claims and relevant associations within lawful boundaries. Sentry Private Investigators Ltd can help separate a genuine concern from an unverified rumour, then present findings with source notes and a clear explanation of limitations. Record the consent, lawful basis, search scope and decision made from the result.


4. Ownership Structure and Beneficial Ownership Verification


You need to know who owns the business, who controls decisions and who benefits from the relationship. A named shareholder may not be the ultimate beneficial owner, particularly where shares are held through connected companies, trusts or layered corporate structures.


For UK entities, examine Companies House filings, shareholder information, confirmation statements, share certificates, transfer documents and the PSC register. A person will generally be a PSC where they hold more than 25% of shares or voting rights, can appoint or remove a majority of directors or otherwise exercise significant influence or control (UK company due diligence guidance). Trace indirect holdings rather than stopping at the first corporate name.


Reconcile control across every layer


UK companies, UK Societas, LLPs and ESPs must identify and report people with significant control. The relevant officer must provide PSC information within 14 days of identifying the PSC and update changes within 14 days. The public register must also be confirmed accurate if it hasn't changed in the previous 12 months (PSC summary guidance).


Request beneficial ownership declarations from shareholders and directors, then compare them with filings, banking information, contracts and management explanations. Note nominee arrangements, unexplained control rights, inconsistent addresses and entities that appear repeatedly across the structure.


An infographic detailing six essential components of corporate management and key personnel background check procedures.


Ownership review also supports sanctions and anti-money-laundering escalation. HMRC's guidance requires identity verification and an assessment of the purpose and intended nature of the relationship, while certified digital identities can support customer due diligence and ongoing monitoring. Digital ID improves auditability, but it doesn't replace beneficial ownership review, source-of-funds checks or sanctions and PEP escalation.



5. Intellectual Property and Asset Verification


A business may describe software, brands, designs, patents, domain names and confidential know-how as core assets. Your review must establish whether the target owns them, can transfer them and has maintained the rights needed to use them.


Request registration certificates, renewal records, assignment agreements, developer and contractor agreements, licence schedules and evidence of domain ownership. Trace the chain of title from creation to the present company. A missing assignment from a contractor can leave ownership unclear even where the business has used the work for years.


Test what the business relies on


Review inbound and outbound licences for territory, term, exclusivity, sublicensing, termination and change-of-control provisions. For software businesses, ask how open-source and third-party code is tracked, whether attribution obligations have been met and whether the company has permission to distribute the relevant components.


Search for infringement threats, cease-and-desist letters, disputes, royalty obligations and restrictions on commercial use. A registered right can still have limited practical value if it is close to expiry, poorly maintained or vulnerable to challenge. Trade secrets require operational controls too, including confidentiality clauses, access permissions and departure procedures.


Where the business suspects hidden recording devices or unauthorised monitoring around sensitive IP, office bug sweep services can provide a separate TSCM assessment. That isn't a substitute for an IP lawyer. It addresses a different question, whether the working environment may be exposing confidential information beyond the documentary record.


6. Contracts, Commitments, and Material Agreements Review


Contracts determine what the business is obliged to deliver, pay, maintain or obtain before it can continue trading. Request the material customer, supplier, employment, loan, lease, insurance, distribution, agency and partnership agreements, including amendments, side letters and waivers.


Don't rely only on a seller-provided schedule. Search document repositories, email systems and relevant third parties for agreements that may not have been disclosed. Compare contract terms with invoices, revenue reports and operational practice. A customer described as secure may have a short notice period, weak renewal protection or a right to terminate after a change in ownership.


Focus on terms that alter the deal


Flag assignment restrictions, exclusivity, non-compete obligations, minimum purchase commitments, rebates, service credits, personal guarantees, indemnities and unusual termination rights. Review board minutes for discussions about breaches, disputes, renegotiations or contracts that management has not included in the data room.


For large customer and supplier relationships, structured interviews can test whether the relationship is active and stable. The process must be discreet and carefully controlled, because premature contact can damage the transaction or alert a counterparty unnecessarily.


A document titled Contract on a wooden desk with eyeglasses and a fountain pen nearby.


Write findings in commercial terms. State the affected agreement, the clause, the evidence, the likely consequence and the decision required. A solicitor should advise on enforceability and drafting. An investigator may be better placed to establish whether a relationship, performance history or undisclosed commitment differs from the formal account.


7. Environmental, Health and Safety Compliance and Liabilities


A site visit often tells you what a data room can't. It can reveal neglected maintenance, unsafe storage, unrecorded work practices, missing controls or operational conditions that conflict with management's description of the business.


Request inspection reports, improvement and prohibition notices, environmental correspondence, accident records, near-miss logs, insurance claims, chemical inventories and COSHH assessments. Review historic site uses and any known contamination, waste or remediation issues. Environmental liabilities can follow the asset or operation long after the transaction has completed, so the issue needs legal, technical and financial assessment.


Combine records with observation


An EHS specialist should assess technical hazards and regulatory compliance. Investigators can support discreet workplace enquiries where employees or contractors may be reluctant to speak openly through formal channels. Interviews should seek specific dates, locations, practices and documents, not general impressions.


Look for differences between written policies and what staff say happens during busy periods. Ask how incidents are reported, who investigates them and whether workers believe complaints receive a fair response. Review whether the business has corrected earlier findings or closed them administratively.


Evidence matters most when the site, the records and the people describe the same reality.

Document photographs, visit dates, attendees, source identities and any restrictions on access. Don't trespass, interfere with safety procedures or present an investigator's observations as a technical compliance opinion. Where hazards are immediate, pause the commercial process and obtain qualified advice before arranging further enquiries.


8. Customer and Revenue Concentration Analysis


Revenue quality depends on more than the amount reported. A business may appear profitable while relying heavily on a small group of customers, one intermediary, one contract or a product that has limited switching protection.


Request customer revenue by period, product and location, alongside order history, churn information, pipeline evidence, renewal records, complaints and credit notes. Compare management's forecast with signed commitments and actual buying behaviour. Examine whether key customers can terminate, reduce volumes or move to an alternative provider without significant disruption.


Test relationships discreetly


Customer interviews can reveal service dissatisfaction, dependency on one employee, pricing pressure or a relationship that management has overstated. Contact must be planned with the seller's authority and the transaction team's instructions. Blind or carefully staged enquiries may protect confidentiality, but they still need an honest purpose and lawful handling of personal data.


The NHS Counter Fraud Authority recommends supplier and counterparty checks that can include credit information, county court judgments, trade payment performance, statutory Companies House data and insolvency events. Its guidance also identifies directors, incorporation dates, filing history and address changes as useful Companies House review points (NHS Counter Fraud Authority due diligence guidance).


A concentration concern doesn't automatically end a deal. It may justify retention conditions, stronger warranties, customer-contact planning, a revised valuation or a decision to walk away. Record the evidence and the commercial response rather than labelling the risk without explaining its effect.


9. Employee and Human Resources Due Diligence


People often carry the customer relationships, technical knowledge and operational memory that make a business valuable. HR diligence should establish who works there, what the company owes them and which individuals the deal depends on.


Request an employee census, role and reporting information, compensation records, tenure, employment contracts, bonus arrangements, pension information, policies, grievances, tribunal claims, settlements, disciplinary records and side letters. Protect personal information through controlled access and appropriate redaction. You don't need every employee's private detail in every review, but you do need enough information to identify material obligations and dependency.


Speak with the people behind the records


Confidential interviews with key personnel can test retention likelihood, workplace morale, leadership conduct and the credibility of the integration plan. Employees may disclose commitments that aren't in the standard contract file, such as informal promises, special working arrangements or concerns about a senior manager.


Review whether important staff have valid confidentiality, IP assignment, non-solicitation or restrictive covenant provisions. Check whether the company has key-person insurance where the business depends on a particular individual. Analyse salary and bonus payments for unexplained exceptions, arrears or commitments that could affect post-transaction costs.


The employer background check regulations should guide how you obtain and use screening information. A specialist investigator can help with lawful pre-employment or senior-person checks, but the employer remains responsible for fairness, privacy, relevance and secure handling.


Don't treat an employee list as a risk assessment. The material question is who can leave, what knowledge leaves with them and what obligations remain behind.

10. Corporate Culture, Conduct, and Fraud Risk Assessment


Written controls may look sound while staff bypass them in practice. Review whether senior leaders act on concerns, employees can report misconduct safely and approval processes withstand commercial pressure.


Request whistleblowing records, hotline reports, complaint logs, internal-audit findings, disciplinary outcomes, management responses and board discussions concerning misconduct. Assess patterns, not isolated allegations. Repeated complaints about one manager, unexplained departures, uneven disciplinary decisions or regular overrides of purchasing controls can point to wider governance weaknesses.


Examine the payment path


Procurement and supplier payments require focused testing. UK public-sector guidance recommends reviewing anti-fraud risk assessments, whistleblowing routes, supplier awareness, counter-fraud reviews and controls for third-party bank-detail changes through its procurement fraud review checklist. Check whether equivalent safeguards operate in practice.


Review supplier onboarding, duplicate payments, unusual bank-account changes, urgent payment requests, segregation of approvals and related-party connections. Compare system records with emails, invoices and approval evidence to identify exceptions that routine reporting may miss.


Confidential workplace enquiries can test whether stated procedures match daily practice. Where a specific, lawful question remains, fraud enquiries may involve document analysis, interviews, people tracing or discreet surveillance. Sentry Private Investigators Ltd can help assess that evidence and define proportionate next steps. Surveillance should not become a fishing exercise, and findings must be documented objectively, with limits and uncertainty stated clearly.


10-Point Corporate Due Diligence Comparison


Assessment Area

🔄 Implementation Complexity

⚡ Resource Requirements

⭐📊 Expected Outcomes

💡 Ideal Use Cases

⭐ Key Advantages

Financial Records and Accounting Verification

High 🔄 detailed multi-year accounting review

High ⚡ forensic accountants, audit tools, weeks–months

📊 Accurate financial picture; uncovers hidden liabilities; valuation baseline ⭐⭐⭐⭐⭐

M&A, valuation, fraud detection 💡

Reveals undisclosed debts and fraudulent reporting ⭐

Legal Compliance and Regulatory Status

Moderate–High 🔄 legal/regulatory searches and record reviews

Moderate ⚡ legal counsel, regulator database access

📊 Identifies compliance breaches, litigation risks ⭐⭐⭐⭐

Regulated industries; cross-border deals; licence transfers 💡

Prevents fines, operational disruptions, legal surprises ⭐

Management and Key Personnel Background Checks

Moderate 🔄 individual-level vetting and interviews

Moderate ⚡ investigators, background databases, checks

📊 Flags integrity, disqualifications, hidden liabilities ⭐⭐⭐⭐

Leadership hires, board appointments, M&A key-person risk 💡

Detects fraud risk and undisclosed director issues ⭐

Ownership Structure and Beneficial Ownership Verification

High 🔄 complex ownership mapping, offshore tracing

High ⚡ corporate registries, legal tracing, international checks

📊 Reveals hidden/nominee owners and sanctions risks ⭐⭐⭐⭐

Transactions with opaque shareholders or AML concerns 💡

Clarifies control and prevents money‑laundering exposure ⭐

Intellectual Property and Asset Verification

Moderate–High 🔄 jurisdictional IP searches and document review

Moderate ⚡ IP attorneys, UKIPO/foreign searches, licence audits

📊 Validates IP ownership; identifies infringement/expiry risks ⭐⭐⭐⭐

Tech, pharma, software, and IP‑heavy acquisitions 💡

Protects deal value and uncovers licence encumbrances ⭐

Contracts, Commitments, and Material Agreements Review

High 🔄 large-volume contract analysis, clause review

High ⚡ commercial lawyers, contract managers, time‑intensive

📊 Identifies termination triggers, guarantees, hidden obligations ⭐⭐⭐⭐

Deals reliant on key suppliers/customers or property leases 💡

Reveals change‑of‑control and onerous terms before closing ⭐

Environmental, Health and Safety (EHS) Compliance and Liabilities

Moderate–High 🔄 site audits and regulatory record searches

High ⚡ EHS specialists, site testing, surveys

📊 Uncovers contamination/remediation liabilities and HSE breaches ⭐⭐⭐⭐

Property transactions, manufacturing, industrial sites 💡

Prevents long‑term remediation costs and regulatory exposure ⭐

Customer and Revenue Concentration Analysis

Moderate 🔄 data analysis and customer reference checks

Moderate ⚡ finance teams, CRM data, customer interviews

📊 Measures revenue dependency and retention risk ⭐⭐⭐

Service providers, logistics, firms with few large clients 💡

Identifies single‑customer vulnerabilities to revenue loss ⭐

Employee and Human Resources Due Diligence

Moderate 🔄 review of contracts, pensions, disputes

Moderate ⚡ HR/legal advisors, payroll records, interviews

📊 Reveals pension deficits, litigation, retention risks ⭐⭐⭐⭐

Labour‑intensive businesses, deals with key talent dependencies 💡

Identifies hidden HR liabilities and succession gaps ⭐

Corporate Culture, Conduct, and Fraud Risk Assessment

Moderate 🔄 qualitative interviews and control testing

Moderate ⚡ internal audit, interviews, whistleblower review

📊 Assesses governance quality and fraud indicators ⭐⭐⭐

Integration planning, governance risk, compliance programs 💡

Highlights cultural misalignment and control weaknesses ⭐


Make the Decision With Evidence, Not Assumptions


A checklist only becomes useful when every answer leads to a documented decision. Create a risk register that records the issue, evidence requested, source, date received, reviewer, status, severity, owner and recommended action. Add a field for the commercial consequence, such as price adjustment, warranty, indemnity, remediation before completion, further investigation or no action.


Keep facts separate from interpretation. “The latest confirmation statement lists one PSC, while the shareholder declaration identifies another controlling party” is an evidence statement. “The structure is suspicious” is a conclusion that requires explanation. Link each finding to the document, filing, interview note, photograph or search result that supports it, and preserve the original material with an audit trail.


Route each issue to the right specialist


Not every concern calls for private investigation. Accounting irregularities, tax treatment, contract enforceability, employment rights and environmental liabilities need the appropriate regulated or technical adviser. Investigative support is most useful where the question concerns identity, conduct, relationships, undisclosed activity or real-world behaviour that records can't resolve.


Consider escalating to Sentry Private Investigators Ltd when:


  • Background checks need depth: A director, beneficial owner or senior employee has conflicting identities, unexplained history or concerning business associations.

  • People need tracing: A former director, debtor, witness or connected party is difficult to locate and their identity or involvement matters to the review.

  • Fraud enquiries require evidence: Payment concerns, workplace theft, false claims, supplier manipulation or suspected conflicts need structured enquiries.

  • Surveillance answers a specific question: A defined concern about attendance, unauthorised activity or conduct can't be tested through documents and interviews alone.

  • Confidentiality may be compromised: A TSCM bug sweep can assess offices or meeting spaces where corporate information may be exposed through technical surveillance devices.


Sentry Private Investigators Ltd provides discreet corporate investigations across the UK, with a head office in Birmingham and coverage including Coventry, Wolverhampton, Worcester, London, Derby, Leicester, Lincoln, Northampton, Nottingham, Bedford, Cambridge, Milton Keynes, Luton, Oxford, Peterborough, Manchester, Reading and Essex. The appropriate scope depends on the facts, urgency, legal permissions and the evidence required.


Download a corporate due diligence checklist and template and adapt it to the transaction, sector and risk profile. Before investigating an individual, confirm the lawful purpose, permissions, privacy safeguards and data-protection requirements. A professional investigator should explain what can be checked, how it will be handled and where the evidence has limitations.



Sentry Private Investigators Ltd can support UK businesses with discreet corporate due diligence, background checks, people tracing, fraud enquiries, covert surveillance and TSCM bug sweeps. Visit Sentry Private Investigators Ltd to discuss the evidence you need, the risks you're facing and an investigation plan.


 
 
bottom of page