M&A Due Diligence

Nine diligence workstreams under one scope and one calendar. Financial, tax, commercial, operational, technology, software, and cyber findings land in a single register the deal team can price, with senior practitioners on the file and deliverables on the deal clock.
Contact us
Definition

What is M&A due diligence?

M&A due diligence is the investigation a buyer or seller runs on a target before a deal closes: what the earnings really are, what the tax and contract positions commit you to, what the technology and security actually cost to run, and which of those facts should change the price or the agreement. Most buyers assemble due diligence services from four or five vendors, then spend the last week of exclusivity reconciling reports that were scoped differently, dated differently, and priced against different assumptions. BD Emerson runs the workstreams together, so one data request list, one set of management interviews, and one findings register produce a single view the deal team can price.

One scope, one calendar. Every workstream works from a single data request list and a single interview schedule, so management answers each question once.
One findings register. Findings are quantified, sourced, and dated in one register, so the deal team can price them instead of reconciling four vendors' reports.
Scope cut to the clock. When exclusivity runs 21 days, the work narrows to the three or four issues that can move price or kill the deal.
Findings that reach the agreement. Each material finding is routed to a representation, an indemnity, an escrow amount, or a price adjustment before signing.
Services

What due diligence services are included?

Nine workstreams, each with its own page and its own deliverable. Few deals need all nine. Pick the ones carrying the risk in this target, and they still run on one calendar against one request list.

Financial due diligence
Quality of earnings
Tax due diligence
Commercial due diligence
Operational due diligence
Technology due diligence
Software and IT due diligence
Cyber due diligence
Vendor and sell-side due diligence

Financial due diligence

We test the numbers behind the model: revenue recognition, working capital and the peg, debt and debt-like items, and the run rate that actually carries into next year. The output is a findings register with each adjustment quantified and sourced to the underlying record.

More

Quality of earnings

A quality of earnings analysis builds normalized earnings from the general ledger up: one-time items, owner compensation, pro forma add-backs, and the adjustments a buyer will accept against the ones they will argue. The bridge from reported to adjusted earnings is documented line by line.

More

Tax due diligence

Federal, state, and local exposure, sales and use nexus, payroll and contractor classification, transfer pricing, and unfiled returns. We size each exposure, name the years still open, and say whether it belongs in an indemnity, an escrow, or the price.

More

Commercial due diligence

Market size, competitive position, customer concentration, churn, win rates, and pipeline quality, tested against what customers say rather than what the management deck claims. Findings tie directly to the revenue assumptions in the model.

More

Operational due diligence

Capacity, supply chain, cost structure, headcount, facilities, and the operating changes the plan assumes. We separate what can be improved inside year one from what needs capital, and we cost both.

More

Technology due diligence

Architecture, technical debt, scalability limits, third-party and open source licensing, and the engineering team's real delivery capacity. Each finding carries a remediation cost and a timeline the model can absorb.

More

Software and IT due diligence

For software targets and IT-heavy businesses: the product itself, the release process, the infrastructure bill, and the internal systems the business runs on. We test whether the product can absorb the growth the plan assumes.

  • Product architecture and scalability limits
  • Source code review and technical debt inventory
  • Open source and third-party license exposure
  • Cloud and infrastructure cost at planned volumes
  • Release cadence, testing coverage, and incident history
  • Engineering headcount, key person risk, and contractor mix
More

Cyber due diligence

Security posture, incident history, data handling, and the compliance commitments already written into customer contracts. BD Emerson performs SOC 2 examinations directly through its CPA attest arm, so security findings and attestation evidence come from one team.

  • Prior breaches, incident history, and disclosure obligations
  • Identity, access, and privileged account controls
  • SOC 2, ISO 27001, and HIPAA commitments already in customer contracts
  • Privacy program, data mapping, and consent posture
  • Vendor and fourth-party risk in the supply chain
  • Remediation cost and timeline for every gap found
More

Vendor and sell-side due diligence

Sell-side diligence run before the buyer arrives. We find what a buyer's team will find, fix or explain it first, and hand over a data room that answers questions instead of raising them.

  • Sell-side quality of earnings and the adjusted earnings bridge
  • Data room build and document readiness review
  • Buyer question log with prepared answers and a named owner per topic
  • Known issues sized and positioned before a buyer surfaces them
  • Carve-out and standalone cost analysis where a unit is separating
  • Management presentation support through confirmatory diligence
More
Our approach

How a diligence engagement runs

Every engagement runs the same way, whatever the workstream mix: one scope, one calendar, one register. Two guides show what the detail looks like inside a single workstream, our financial due diligence checklist and the technology due diligence red flags we look for.
01

Scope against the clock

Scope starts from the deal calendar and the thesis. A full pre-LOI review runs broad across the workstreams that carry risk. A confirmatory review after signing tests a short list of specific assumptions. When exclusivity is 21 days, we cut to the three or four issues that can move price or kill the deal and push the rest to a post-close list. The scope is written down before work starts.

02

One data request list

Every workstream feeds one request list, ranked by what blocks the analysis. Management uploads once instead of answering five versions of the same question. We track open items daily and escalate anything outstanding beyond 48 hours.

03

One set of management interviews

The finance, tax, commercial, operations, technology, and security leads sit in the same sessions rather than repeating themselves across separate vendors. Notes from each session feed the findings register the same day.

04

A findings register the deal team sees weekly

Findings are logged as they are confirmed, each with an amount, a source document, a confidence level, and a recommended treatment. The deal team reads the register every week rather than waiting for a report at the end of the process.

05

Reconcile across workstreams

A tax exposure, a customer contract risk, and a security remediation cost can all land on the same earnings line. We resolve the overlap before the numbers reach the model, so nothing is counted twice and nothing falls between two vendors.

06

Convert findings into deal terms

Each material finding goes to counsel and the deal team with a recommendation: a representation on the fact pattern, an indemnity with a cap and survival period, a specific escrow amount, a price adjustment, or a closing condition. Nothing is left unassigned.

07

Hand off to integration

The register, the models, and the open items go to the integration team with owners and dates attached. The first 100 days start from work already done instead of a fresh discovery project.

contact us

Deal on the clock?

Send the deal calendar, the target's sector, and the workstreams you think you need. We come back with a scope, a fee range, and the names of the practitioners who would run it.

Our Advantage

Why BD Emerson for due diligence

One firm runs the financial, tax, commercial, operational, technology, software, and cyber work on the same engagement. Findings reconcile against each other before they reach the deal team, and the same practitioners carry the open items into integration.

One scope across every workstream

One data request list, one interview schedule, one findings register. Management answers each question once, and the deal team reads a single reconciled view instead of four vendor reports dated a week apart and scoped against different assumptions.

Senior practitioners on the file

The people who scope the work do the work. There is no review chain between the analysis and the person presenting it, which is why findings reach the deal team while there is still time to act on them.

Security and compliance under the same roof

BD Emerson performs SOC 2 examinations directly through its CPA attest arm and runs ISO 27001, HIPAA, and privacy programs. Cyber findings arrive with a remediation cost and a timeline attached, priced the way a capital item would be.

Findings that outlive the report

The register does not stop at closing. Open items carry into the first 100 days with owners, dates, and costs attached, so integration starts from diligence work already done.

Reviews

What our customers say

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

Great consulting firms for scaling security, compliance, and appsec.

Outstanding partner in Technical and Cyber Due Diligence

Appsec maturity and application hardening.

BD Emerson helped us simplfiy our compliance management.

BD Emerson did such a phenomenal job. What started as privacy support quickly became a full partnership across compliance, engineering, and even business operations. They’re embedded with our team. They understand our product. They move fast. They’re simply invaluable.

Adam Ben Jacobs

CTO @ OneStep GPS

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

We had a hard time finding the right company to partner with in support of our compliance journey. Some vendors sell the idea that they do the work, but then you end up doing everything. The ambiguity is what killed our last project. BD Emerson’s team has such great technical knowledge and understands the standard so well that they made us comfortable with moving fast. This has led to us closing major enterprise customers that were previously out of reach because of security and compliance.

Tom Watkins

CEO @ AMI AssetTrack

Lead an enterprise initiative to overhaul the organization's technology stack from ecommerce, corporate tech, and corporate security.

Supported ISO 42001 exercise and served as internal auditor.

Rubrik's privacy and compliance team began with the backbone of BD Emerson. BD Emerson supported building out the privacy program, GRC (ISO 27001, SOC 2, CMMC, FedRAMP), and the appsec function.

We needed a partner who could move quickly, without sacrificing precision. BD Emerson brought the expertise, structure, and speed we were looking for. Their team became an extension of ours, embedding themselves across the organization, guiding us step by step, and giving us confidence in areas we hadn’t tackled before. The internal audit they conducted was so detailed that even the external auditors called it out. Achieving ISO 27001 with zero nonconformities says everything you need to know about the quality of the partnership.

Walid Souilem

CTO @ FGI Worldwide

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

BD Emerson didn’t just help us meet our compliance goals; they integrated security and privacy into the core of our operations. I highly recommend BD Emerson to anyone seeking SOC 2 or GDPR compliance, or simply looking to enhance their security team and boost customer trust in their product and services. Their dedication and expertise have been invaluable to our success.

Padraig Reilly

CEO, Boxcore

BD Emerson understood our business requirements and worked side-by-side with us. The policies and controls we developed together not only meet compliance standards but improve how we operate day to day.

Matt Meierdierks

IT Manager, Lincoln Industries

From day one, BD Emerson brought urgency, clarity, and a sharp understanding of what truly matters to our business — earning and keeping customer trust. They went beyond helping us meet compliance requirements; they helped build a foundation for secure, scalable growth. That kind of partnership is rare.

Jason Marker

CEO @ LifeLenz

BD Emerson didn’t just help us pass an audit—they helped us build a sustainable culture of security.

Alexey Indeev

CTO Spare

BD Emerson was essential in helping our company navigate the daunting process of leveling up our security infrastructure. BD Emerson’s impressive expertise and confidence throughout the process helped our team exceed HIPAA and SOC 2 Type 1 standards quickly, distilling what can be an overwhelming process into a streamlined, organized effort. From day one they began adding value and getting us on course. With their help we delivered on a massive security overhaul with both extreme efficiency and thorough attention to details. Because of BD Emerson’s support, we’ve increased our clients’ trust in Titan Intake and the life-changing work it accomplishes for those seeking specialist referrals.

Patrick Bruce

CEO, Titan Intake

Certificates

Our accreditations

At BD Emerson, we believe that our team's extensive certifications not only set us apart but also ensure that we provide the highest level of service to our clients.
FAQ

Frequently asked questions

What does M&A due diligence cover?

Which workstreams does my deal actually need?

How long does due diligence take?

What do due diligence services cost?

How does buy-side diligence differ from sell-side?

What happens when diligence finds a problem?

How do findings get into the purchase agreement?

What data do you need, and when?

How is confirmatory diligence different from a full review?

Who actually does the work?

How do the workstreams stay reconciled?

Blog

Related Articles

Insights on strategy, transactions, technology, security, and compliance from BD Emerson's practitioners