The Due Diligence Report: What It Contains and How to Read One
A due diligence report is the document a buyer's advisors deliver at the end of a diligence workstream: what they examined, what they found, how serious each finding is, and what it means for price, structure, and the plan after close. In a full M&A process there are several, one per workstream, financial, tax, legal, commercial, operational, technology, and cybersecurity, and the deal team's job is to read them together. A good report leads with conclusions, rates every finding by severity, separates what was verified from what was inferred, and states what it could not test. A weak one describes the data room. This article covers the structure of a diligence report, how findings are rated, what a red-flag report leaves out, and how boards, investment committees, and lenders should read one.
The structure of a diligence report
Reports across workstreams share a shape. An executive summary states the conclusion, the three to five findings that matter most, and their implications for the deal. A scope section defines what was examined, the period covered, the sources relied on, and the limitations, including data requested and not received. The findings section works through the workstream's areas, each with the evidence, the finding, its severity, and the recommended action. A price and structure section translates the findings into adjustments: a normalized EBITDA, a working capital target, a debt-like item, an indemnity or escrow recommendation, a closing condition. Appendices hold the detail: the adjusted financials, the customer interview tallies, the control test results, the code scan output. The summary is what the investment committee reads; the appendices are what the lawyers drafting the purchase agreement read, and both have to be right.
How findings are rated
Severity ratings make a report usable, and the scale should be defined in the report itself. A common scheme has four levels. Deal-breakers: findings that undermine the thesis or expose the buyer to liability it will not accept, such as unlicensed revenue or a systemic compliance failure. Price and structure items: findings with a quantifiable effect on value or risk, such as an EBITDA adjustment, a capital expenditure the model omitted, or an exposure that belongs in an indemnity. Conditions and remediation: findings that must be fixed before or shortly after close, such as an assignment gap or an access control failure, with owner and timeline. Observations: findings worth knowing that do not move the deal. The discipline is that each finding carries one rating, a dollar or risk quantification where possible, and a recommended mechanism, so that the deal team can act on the report without re-reading it. Findings rated only as high, medium, and low without a mechanism are a signal that the advisor has not finished the thinking.
What each workstream's report contains
The financial report, usually a quality of earnings report, rebuilds EBITDA with each adjustment documented, analyzes revenue quality and working capital, and identifies debt-like items, the analysis outlined in our financial due diligence checklist. The tax report identifies historical exposures, structuring options, and attributes that transfer. The legal report covers corporate records, material contracts and their change-of-control terms, litigation, IP ownership, employment, and regulatory compliance. The commercial report assesses market, customers, position, and the growth plan against evidence. The operational report assesses people, processes, systems, and capacity against the plan. The technology report covers architecture, code quality, scalability, technical debt, and the cost to remediate. The cybersecurity report covers the security program, control effectiveness, incident history, and the exposure the buyer inherits. Read together, they answer the four deal questions: what is the business worth, what could go wrong, what will it cost to fix, and what has to be true after close.
Red-flag reports and full reports
A red-flag report is a deliberately narrow first pass, delivered in one to two weeks, that answers a single question: is there anything here that should stop the buyer from proceeding to full diligence? It covers the highest-risk areas at a scan level, reports only findings above a severity threshold, and defers everything else. Buyers use it before committing the cost of full diligence or before submitting a binding offer. The trap is treating a clean red-flag report as clearance, since its scope excludes most of what full diligence tests. The full report follows exclusivity, covers the complete scope, and is the document the price is negotiated on.
How to read a diligence report
Readers with decisions to make should read a report in a particular order. Start with the scope and limitations, because a finding's weight depends on what was and was not examined, and a report that could not access the general ledger or interview customers has told you something before its first finding. Then the executive summary for the conclusion and the material findings. Then the price and structure section, cross-referenced against the deal model to confirm every adjustment landed. Then the findings in the areas that carry the thesis, read for evidence rather than assertion: what documents, samples, or interviews support each one. Investment committees should ask what the advisor was unable to conclude on and why. Lenders read for debt-like items, working capital, and anything that affects covenant capacity. Boards read for liability and reputational exposure. And every reader should note the date of the report and the period it covers, because a report on financials through the prior fiscal year says nothing about the quarter in which the deal is closing.
Vendor reports: when the seller commissions the diligence
In competitive processes, the seller sometimes commissions a report for buyers to rely on, most often a financial vendor due diligence report and sometimes commercial. The report is written by an independent firm to the standard buyers expect, and buyers typically receive reliance letters that let them hold the author accountable. Vendor reports compress timelines and level the information field across bidders, and buyers should still read them as advocacy-adjacent: the scope was set by the seller, the adjustments are the seller's best defensible case, and confirmatory work on the areas that matter to the specific buyer remains prudent. The mechanics are covered in our guide to vendor due diligence.
Reading across the reports
The most valuable findings in a diligence process are often the contradictions between reports, and no single advisor is responsible for surfacing them. The commercial report says customers see the product as differentiated; the financial report shows discounting deepening every quarter. The operational report says the delivery organization is at capacity; the growth plan the commercial team reconciled assumes it doubles. The technology report identifies a platform at end of life; the operational report's system replacement estimate assumes it survives the hold period. The legal report lists a customer contract with a change-of-control termination right; the financial report counts that customer in recurring revenue. Someone on the deal team has to read every report with the others in hand, list the contradictions, and resolve each one into a single view of the business. The best-run processes hold a cross-workstream findings session before the price is finalized, with each advisor in the room, precisely to force that reconciliation. Buyers who receive seven reports and file them separately have paid for diligence without receiving it.
What makes a report worth its fee
The difference between a useful report and an expensive summary of the data room is whether the advisor reached conclusions and priced them. Every finding should answer the question the deal team will ask: so what, in dollars, structure, or time. Findings should be traceable to evidence the reader can inspect. The report should say plainly what it could not test. And it should be written for the decision, which means the summary can be read in ten minutes by someone who will never open the appendix. BD Emerson delivers financial, technology, cybersecurity, and operational diligence reports in exactly this form through our M&A due diligence practice, with each finding rated, quantified, and mapped to the deal mechanism that addresses it, so that the report changes the price rather than decorating the file.
