IP Due Diligence: What It Covers and the Checklist
IP due diligence is the workstream that confirms a target actually owns, controls, and can defend the intellectual property the purchase price assumes: its patents, software code, trademarks, trade secrets, data, and domain names. It answers four questions. Does the company hold clean title, with every inventor, employee, and contractor assignment in place? Is the IP encumbered by licenses, exclusivity grants, open source obligations, or government rights that limit what a buyer can do with it? Is it defensible and unexpired, with fees paid and no live disputes? And does the company have the rights it needs to the third-party IP it depends on? Most IP diligence findings are fixable, but only before signing, and the ones discovered afterward become indemnity claims rather than price adjustments. This article covers what the work examines, the findings that reprice deals, and the checklist.
Why IP diligence is its own workstream
In a technology, life sciences, media, or brand-driven company, intellectual property is most of the enterprise value, yet it does not appear on the balance sheet at anything like that value and it is not tested by financial diligence. Legal diligence reviews the contracts and litigation. Technology diligence reviews the code and architecture. IP diligence sits between them and asks the ownership and rights question specifically, because a product that works perfectly and generates revenue is still a problem if a former contractor owns a third of the codebase or a copyleft license obliges the company to publish it. The workstream is run by IP counsel with technical support, and in software deals it overlaps deliberately with the code-level work covered in our software due diligence checklist.
Chain of title: the finding that reprices most often
Ownership starts with the people who created the IP. In the US, an employee's inventions and copyrightable work generally belong to the employer only where an agreement says so or the work-for-hire doctrine applies, and contractor work belongs to the contractor unless assigned in writing. IP diligence therefore inventories every person who contributed to the IP and matches each one to a signed invention assignment or work-for-hire agreement with present-tense assignment language. The gaps found are predictable: founders who wrote the first version before the company existed, offshore development shops with no assignment clause, a departed engineer who was never papered, and university or government research where institutional or Bayh-Dole rights attach. For registered IP, the chain continues into the public record: patent and trademark assignments recorded with the USPTO, correct legal entity names after reorganizations, and no security interests still recorded from a paid-off loan. A break in the chain is usually curable with a confirmatory assignment while the counterparty is cooperative, which is an argument for finding it early.
Encumbrances: what the company has already given away
The second question is what rights third parties hold. Inbound licenses tell the buyer what the company depends on and whether those licenses survive a change of control; a key platform license terminable on assignment is a closing condition, not a footnote. Outbound licenses tell the buyer what it cannot do: an exclusive license in a field of use or territory removes that market from the acquirer's plan, and most-favored-customer or source code escrow terms constrain pricing and control. Joint development agreements can leave co-ownership of improvements with a partner. Government funding can attach march-in rights and domestic manufacturing preferences. Standards participation can carry licensing commitments on essential patents. Each encumbrance is mapped against the buyer's intended use of the asset, because a restriction that does not touch the plan is a disclosure item and one that does is a price item.
Open source: the software-specific exposure
Software targets carry a distinct IP risk in the open source components inside their code. Permissive licenses such as MIT and Apache impose attribution obligations that are routinely unmet but cheaply fixed. Copyleft licenses, GPL and especially AGPL, can require the company to publish source code it considers proprietary if the component is combined and distributed or, for AGPL, offered over a network in the wrong way. Diligence runs a software composition analysis scan of the codebase, reconciles it to the company's declared inventory, and evaluates each copyleft component for how it is used. The finding that reprices deals is an AGPL library embedded in the core product; the finding that merely costs money is a missing attribution file. Companies with no open source policy and no inventory should expect the scan to find things they did not know they shipped.
Validity, enforceability, and freedom to operate
Registered rights have to be alive and worth holding. Diligence confirms patent maintenance fees and trademark renewals are current, examines prosecution histories for narrowed claims, and reviews any inter partes review, opposition, or litigation. Trade secrets, which protect much of a software or process company's value, are only protectable if the company took reasonable measures to keep them secret, so diligence looks for confidentiality agreements, access controls, and marking practices, and finds that trade secret protection often exists on paper and not in practice. Freedom to operate asks the inverse question: whether the company's products infringe someone else's rights, examined through demand letters, known competitor patents, and any indemnity claims from customers. A full freedom-to-operate opinion is expensive and usually reserved for deals where a single product carries the value.
Data, brands, and the assets people forget
Three categories are routinely under-diligenced. Data assets, including training data for machine learning models, carry ownership and consent questions: whether the company had the right to collect and use the data, whether customer contracts permit the use, and whether the terms survive a change of control. Trademarks and domain names carry registration gaps, marks used but never registered, and domains held in a founder's personal account. And documentation itself, the specifications, designs, and process know-how that make the IP usable, is often held by individuals rather than the company. The buyer's technology team and IP counsel should walk these together, because the technical view of what matters and the legal view of what is owned rarely match on the first pass, a gap explored in our article on technology due diligence red flags.
The IP due diligence checklist
A working checklist covers eight areas, each with a defined evidence request. The IP inventory: every patent, application, registered mark, copyright registration, domain, and material trade secret, with jurisdiction, status, and owner of record. Chain of title: assignment agreements for every founder, employee, and contractor who contributed, and recorded assignments for registered rights. Inbound licenses: every license the products depend on, with change-of-control and termination terms flagged. Outbound licenses and encumbrances: exclusivity, field-of-use, territory, MFN, escrow, and co-ownership terms. Open source: a composition scan reconciled to the declared inventory with copyleft components evaluated for use. Validity and disputes: maintenance status, prosecution history, litigation, oppositions, demand letters sent and received. Trade secret protection: confidentiality agreements, access controls, and exit procedures. Data and privacy rights: the basis for collecting and using data assets and whether it survives the deal. The output is a findings register rated by whether each item is a closing condition, a price or indemnity item, or a post-close cleanup.
How findings reach the purchase agreement
IP diligence findings land in the deal documents in predictable places. Clean title and non-infringement become seller representations and warranties, with the diligence findings scheduled as exceptions. Known gaps, an unsigned contractor assignment or a copyleft component awaiting remediation, become closing conditions or specific indemnities with an escrow sized to the exposure, because representations and warranties insurance excludes known issues. Change-of-control consents on critical inbound licenses become closing deliverables. And where a finding is large enough to threaten the thesis, an exclusive license the buyer needed to be non-exclusive or a co-owner who will not sell, the finding becomes a price conversation or a decision to walk. The register that IP diligence produces should therefore carry, next to each finding, the mechanism recommended to address it, so counsel can draft from the register rather than rediscover it.
Sell-side: the IP audit
Sellers who run this examination on themselves before a process, sometimes called an IP audit, fix the assignment gaps while former contractors still answer email, clean the open source inventory, and record the assignments that were never filed. Each item costs a few hours to fix a year out and a negotiation under exclusivity if the buyer finds it first. BD Emerson runs IP and technology diligence together inside our technology due diligence practice, pairing IP counsel review with code-level analysis so that ownership findings and technical findings arrive in one register with costs attached, for buyers pricing a deal and for sellers who want the asset to survive scrutiny.
