top of page

Due Diligence for Acquisitions: UK Guide

  • Writer: Sentry Private Investigators
    Sentry Private Investigators
  • 9 hours ago
  • 10 min read

You're reviewing a target that looks tidy on paper. The accounts reconcile, management is confident, and the data room contains enough documents to create the impression that the difficult work is finished. Then, after completion, a former employee raises a serious complaint, a key customer challenges a change-of-control clause, or a covert recording device is found in an executive meeting room.


That's the reality of due diligence for acquisitions. The risks that damage a buyer after completion are often quiet, poorly documented and absent from the financial model. A proper UK investigation tests the numbers, but it also tests the people, systems, ownership, contracts, regulatory position and reputation behind them.


The Deal That Looked Perfect Until It Wasn't


A buyer acquired a regional services business after a fast financial review. Revenue looked stable, debt was understood and the seller supplied reassuring answers about staff retention. Nobody asked why several experienced employees had left shortly before the sale, or why a senior manager kept communicating with customers through a personal account.


After completion, the buyer discovered that the departing employees had taken detailed knowledge of customer pricing and operational processes with them. One important client was already considering leaving. The issue wasn't visible in the headline accounts, but it affected the value the buyer had purchased.


That's why acquisition diligence must start with the question investigators hear most often: what will bite us after completion?


The answer may sit in financial records, but it may also sit in:


  • Legal ownership, including share registers, board approvals, licences and intellectual property assignments.

  • Tax history, including HMRC correspondence, VAT records and unresolved claims.

  • Commercial resilience, including customer concentration, supplier dependency and change-of-control terms.

  • IT and security, including access controls, breach history and sensitive information held in unsecured systems.

  • People risk, including grievances, settlement agreements, retention problems and potential TUPE exposure.

  • Reputation, including undisclosed disputes, local concerns, county court judgments and conduct allegations.


A buyer also needs a realistic view of valuation. A useful understanding business valuation resource can help explain how earnings, assets, liabilities and commercial assumptions interact, but valuation only works when the underlying facts are reliable.


Practical rule: If the seller's answer is reassuring but the supporting document is missing, treat the gap as a finding, not a comfort.

Sentry Private Investigators Ltd approaches this work from the perspective of practitioners who investigate the facts behind a transaction and, where necessary, help buyers clean up post-close surprises. The order below follows what often fails first, not what appears most important in a conventional checklist.


The Seven Diligence Streams and What Each One Really Checks


A buyer shouldn't treat diligence as one large document review. Each stream answers a different question, and each requires different evidence.


A diagram outlining the seven key due diligence streams for business acquisitions, including financial, legal, tax, commercial, operational, IT, and HR.



Financial diligence asks whether the numbers are true and repeatable. Review audited accounts, management accounts, debtor ageing, bank information, debt schedules and working capital assumptions. Don't accept a clean report as proof that earnings will continue under new ownership.


Legal diligence asks whether you can own and operate what you're buying. Companies House records, articles, shareholder registers, board minutes, material contracts, licences and intellectual property assignments should establish authority, ownership and restrictions. Missing statutory registers or incomplete approvals can create a problem before integration even begins.


Tax and commercial exposure


Tax diligence asks what HMRC already knows. Request HMRC correspondence, VAT records, payroll tax material, R&D claims and evidence supporting tax positions. The issue isn't just unpaid tax. It's whether the transaction structure transfers an exposure that the buyer hasn't priced.


Commercial diligence asks whether customers and contracts will survive the change. Examine customer concentration, renewal terms, complaints, churn explanations, pipeline quality and supplier dependency. Read the actual contracts for assignment, termination and change-of-control provisions.


For teams preparing an evidence pack, this guide for UK SMEs raising funds is also useful because disciplined financial documentation makes both fundraising and acquisition review more efficient.


Operational, IT and people risk


Operational diligence asks whether the business can perform outside the spreadsheet. Check premises, equipment, insurance, service capacity, key-person dependency and process documentation.


IT and cyber diligence asks what is hidden in the systems and walls. Review asset registers, access permissions, breach logs, backups, supplier contracts and penetration-test summaries.


People diligence asks whether the team will stay and remain safe to employ. Examine the employee census, contracts, payroll, pension schedules, sickness patterns, grievances, settlement agreements and disciplinary records.


Reputation


Reputation diligence asks what the offline story says about the brand. Companies House is a starting point, not a complete investigation. Local reporting, court records, insolvency information, former employees, suppliers and customers may reveal a pattern that management hasn't volunteered.


The streams interact. A commercial contract can expose a tax obligation. An IT weakness can explain customer losses. An employee grievance can point to a governance problem. Sequence the work so investigators can test contradictions while legal and financial advisers are still able to change the transaction terms.


Why People Risk Now Sits Above Financial Risk on UK Deals


A workforce isn't an overhead line. It's a collection of claims, expectations, relationships and legal obligations that the buyer inherits or must manage immediately after completion.


The Employment Rights Act 2025 makes that point sharper. Commentary on the reforms says the qualifying period for ordinary unfair dismissal is expected to reduce from two years to six months from 1 January 2027, while the compensation cap is expected to be removed from the same date. Tribunal time limits are expected to extend from October 2026, and mandatory holiday-record keeping is expected from 6 April 2026. These are future-dated changes, so buyers should treat them as transaction planning issues rather than assume the current position will remain unchanged. Lewis Silkin's M&A analysis sets out the implications.


The redundancy consultation exposure is more immediate in transaction planning. The protective award for failing to consult is expected to double to 180 days' pay per affected employee, according to the same analysis. That turns a headcount exercise into a liability assessment. A buyer considering redundancies after completion needs to know whether the seller has consulted properly, whether collective consultation obligations may arise and whether employee information is complete.


What the HR file should prove


Management should be able to explain:


  • Retention: Which employees are essential to customer relationships, technical knowledge or regulated activity?

  • Conduct: Are there unresolved grievances, disciplinary matters, whistleblower complaints or discrimination allegations?

  • Change: Has anyone received a promise of promotion, retention payment or altered terms that isn't reflected in the data room?

  • Transfer: Will TUPE apply, and have employees been informed or consulted where required?

  • Exit: Do settlement agreements, restrictive covenants or notice arrangements create post-completion obligations?


The buyer should request full HR files where legally appropriate, payroll records, holiday records, pension schedules, absence information and active claims. A worker's complaint about surveillance or tracking also deserves careful attention. If you need to locate a former employee or witness discreetly, UK tracing agents can support that task without turning a sensitive inquiry into a public event.


People risk becomes expensive when the buyer discovers it after announcing redundancies, changing reporting lines or challenging inherited practices.

The correct response isn't to delay every deal. It's to price the exposure, obtain suitable warranties and indemnities, preserve evidence, and decide whether the target's culture can be integrated safely.


IT, Cyber and TSCM Checks as One Security Stack


IT diligence, cyber review and Technical Surveillance Counter-Measures should be treated as one security stack. A buyer isn't only asking whether the target's software works. The buyer is asking whether information can be accessed, copied, intercepted or misused during the transaction and after completion.


A diagram illustrating an integrated security stack consisting of IT diligence, cyber review, and TSCM bug sweep.


Start with the digital estate


IT diligence maps the assets. Ask for hardware and software registers, cloud services, administrator accounts, third-party suppliers, backup arrangements, system dependencies and licence terms. Check who owns each account and whether the buyer can lawfully transfer or continue using it.


A cyber review then tests resilience. It should consider patching, identity and access controls, multi-factor authentication, remote access, incident response, staff permissions, breach history and external exposure. A penetration test probes systems from an attacker's perspective. It doesn't replace a governance review, but it can reveal weaknesses that a policy document conceals.


The ICO requires organisations involved in mergers and acquisitions to consider data sharing during due diligence. The buyer should inventory personal-data assets, establish the original collection purpose, identify the lawful basis for sharing, document the transfer and obtain technical advice where different systems create security risks. The ICO due diligence guidance also makes clear that the acquirer inherits the organisation's obligations.


Add physical counter-surveillance where the risk justifies it


TSCM is different from cyber testing. A professional sweep looks for physical surveillance devices, including transmitting microphones, hidden cameras and GPS trackers. Specialists may use RF detectors, spectrum analysers and non-linear junction detectors to identify active transmissions, electronic components or devices concealed inside furniture, vehicles, walls and equipment.


A sweep earns its place where sensitive information is discussed or where there's a credible leakage concern:


  • Boardrooms, where pricing, strategy and completion terms are discussed.

  • R&D laboratories, where product development and intellectual property may be exposed.

  • Executive vehicles, particularly where movements or conversations could be monitored.

  • Server and communications rooms, where physical access can undermine digital controls.

  • Sites linked to internal disputes, especially where staff have raised covert-listening or tracking allegations.


A credible report should identify the areas inspected, equipment used, environmental limitations, photographs where appropriate, findings, device details and recommended next actions. It should distinguish a confirmed device from an anomaly requiring further examination.


Buyers needing specialist TSCM services should brief the team through legal or an authorised deal lead, limit knowledge of the inspection and protect the report as sensitive transaction material.


Red Flags Experienced Investigators Look For First


The first red flag is often not an obvious fraud. It's a pattern that doesn't fit the seller's explanation.


A financial investigator's desk with documents, a magnifying glass over a chart, and investigation notes.


Vendor concentration deserves scrutiny when one supplier controls a critical input, service or route to market. Compare purchase records, contracts, ownership information and management explanations. A dependency may force the buyer into renegotiation immediately after completion.


Related-party transactions should be matched against director interests, Companies House filings, invoices, bank movements and board approvals. Repeated payments to connected businesses may be legitimate, but unexplained pricing or undocumented services can indicate value leakage.


Intercompany loans need a clear purpose, balance and repayment position. A loan that appears in one schedule but not another may signal weak controls or an incomplete group structure.


Corporate gaps are rarely harmless


Missing statutory registers, dormant directors and multiple unexplained resignations can point to governance disorder. Check Companies House filings against internal registers, shareholder information, board minutes and the transaction documents. A discrepancy in the ownership chain can delay signing or leave the buyer arguing about what was transferred.


An unresolved ICO complaint, a data breach that was described only verbally, or a privacy registration that doesn't match the target's activities requires focused follow-up. Don't accept “no issue” as an answer without the underlying correspondence.


The absence of a document in a topic that obviously matters is itself a finding.

Discreet reputation checks should go beyond public corporate records. Review local press, county court judgments, insolvency registers and relevant regulatory material. Where lawful and proportionate, investigators can make discreet enquiries with former employees, suppliers and other informed contacts. That work is especially valuable when the target operates within a close regional market and an obvious enquiry would alert the wrong person.


Covert-listening or GPS-tracking allegations by staff require separate handling. They may indicate a security incident, an employment dispute, unlawful monitoring or a wider culture problem. The investigator should preserve the original allegation, identify who had access, establish dates and distinguish evidence from workplace rumour.



The practical test is simple. Every red flag should lead to a document, a person, a transaction record or an observable fact. If it leads only to reassurance, keep investigating.


Document Checklist and Realistic UK Timeline


Send the seller a structured request rather than asking for “all relevant information”. A clear request exposes gaps early and gives advisers a usable audit trail. A compliance documentation guide can help teams think about how policies, records and approvals should be organised before the formal process begins.


Request documents by diligence stream


Stream

Core evidence

Financial

Three years of audited accounts, management accounts, debtors ageing, debt schedules, cash records and customer concentration analysis

Legal

Share registers, Companies House records, board minutes, constitutional documents, material contracts, licences and IP assignments

Tax

HMRC correspondence, VAT records, payroll tax material, R&D claims and supporting calculations

Commercial

Pipeline data, churn analysis, customer complaints, supplier dependencies and the top twenty customer contracts

People

Full HR files, payroll, pension schedules, settlement agreements, grievance logs, disciplinary records and employee consultation material

IT and security

Asset registers, access lists, breach logs, incident response records, supplier contracts and penetration-test summaries

TSCM

Access to boardrooms, server rooms, executive vehicles, R&D areas and other sensitive locations


The top twenty customer contracts are a useful starting point, not a substitute for reviewing other material agreements. Ask counsel to define materiality by reference to the target's business, not a generic template.


Put the critical path on the deal plan


Start regulatory classification at the beginning. The National Security and Investment Act requires buyers to determine whether a target operates in one of 17 sensitive areas, assess control thresholds, notify the government where required and wait for clearance before completion. The UK government guidance on acquisitions under the NSI Act explains the clearance consequences, including the possibility of conditions or a block.


CMA analysis should run alongside the commercial review. The CMA can investigate where the acquired enterprise's UK turnover exceeds £100 million, or where the transaction creates or increases a 25% share of supply and at least one party has UK turnover above £10 million. The CMA's quick guide to UK merger assessment sets out those mechanics.


The legal form matters too. UK guidance treats acquisitions and joint ventures as mergers where two or more enterprises cease to be distinct. A regional analysis may be decisive, since official guidance also refers to a 33% product or service supply test alongside the £350 million annual turnover condition in the hybrid test, including local markets such as Scotland or London. Check the government guidance on when mergers will be investigated rather than relying only on national market assumptions.


Run quiet investigator checks, witness enquiries and TSCM inspections in parallel with document review. Don't leave them until the final week, when a finding can no longer be investigated or reflected in the purchase agreement.


When to Bring in a Private Investigator or TSCM Team


Bring in an external investigator when the buyer suspects the data room is incomplete, a key person has disappeared, a supplier relationship looks connected, or management's account conflicts with documents. Use an investigator for background checks, discreet enquiries, witness location, asset checks and lawful surveillance where evidence of conduct is required.


Use a TSCM specialist for suspected listening devices, hidden cameras or GPS trackers. The two disciplines overlap, but they aren't interchangeable. An investigator establishes people, behaviour, relationships and chronology. A TSCM team examines physical spaces and electronic anomalies.


The brief should state:


  • The transaction context, including who knows about the deal.

  • The precise concern, without embedding assumptions as facts.

  • The target locations and individuals, with lawful access arrangements.

  • The reporting requirement, including photographs, source notes and an executive summary.

  • The legal route, agreed with the buyer's solicitor or legal adviser.


A proper report should separate verified facts, witness accounts, open questions and professional observations. It should be suitable for board papers and capable of being reviewed by solicitors without overstating what the evidence proves.


Choose on track record, regional coverage, discretion, insurance and reporting quality, not price alone. Sentry Private Investigators Ltd provides business investigations, including background checks, tracing and investigative support for businesses. Regional coverage matters when discreet enquiries must be made in a target's local market, including work arranged through the Private Investigator Leicester service page.



Sentry Private Investigators Ltd can support acquisition teams with discreet background checks, corporate investigations, people tracing and TSCM bug sweeps across the UK. If spreadsheets don't answer what may bite you after completion, visit Sentry Private Investigators Ltd to discuss a confidential, investigator-led brief.


 
 
bottom of page