Complete guide
Due diligence request list: a complete guide
Every category, a sample list to start from, and the mistakes that slow teams down when building and tracking one.
01What categories does a request list cover?
A thorough request list is organized by function, so each category can be sent to and reviewed by the right specialist. The exact categories depend on the deal, but most requests lists include:
- Corporate & governance — formation documents, cap table, board minutes, shareholder agreements
- Financial — audited financial statements, management accounts, budgets and forecasts, debt schedules, tax filings
- Legal — material contracts, litigation history, regulatory correspondence, insurance policies
- Commercial — customer contracts and concentration data, pricing agreements, sales pipeline
- Operational — supplier agreements, facilities leases, IT systems and infrastructure documentation
- HR — employment agreements, org charts, compensation and benefits plans, headcount by function
- IP & regulatory — patents, trademarks, licenses, industry-specific compliance records
02Sample request list items
A few representative line items from each category, to show the level of specificity a request list typically needs:
| Category | Example request |
|---|---|
| Financial | Audited financial statements for the last 3 fiscal years |
| Financial | Monthly management accounts for the trailing 12 months |
| Legal | All material contracts above a stated value threshold |
| Legal | Summary of pending or threatened litigation |
| Commercial | Top 10 customers by revenue, with contract terms |
| Operational | List of all facilities with lease terms and expiration dates |
| HR | Organization chart with headcount by department |
| IP | Schedule of registered patents and trademarks |
For a category-specific financial checklist with more line items, see the financial due diligence checklist.
03How do you build one for a specific deal?
Start from a category template like the one above, then scope it to the deal: strip out categories that don't apply (a services business won't need a detailed inventory schedule; an asset-light company may not need facilities documentation at all), and add deal-specific items based on what's already known about the target — a pending lawsuit mentioned in a management deck, an unusual customer concentration, a recent restructuring. A request list that's copy-pasted without scoping tends to generate noise: irrelevant requests the target ignores, and gaps around the things that actually matter for this specific transaction.
04How is status tracked once requests go out?
Most teams track each line item through a few states: requested, received, under review, and either closed or flagged. The mechanical challenge is keeping that status current as documents arrive out of order, in batches, sometimes without clearly labeling which request they're meant to satisfy. A spreadsheet works for a small list; on a request list running into the hundreds, matching incoming documents to specific line items by hand becomes the actual bottleneck — which is the part Vaultrix's request-list mapping is built to automate, proposing an evidence-found, partially-supported, no-evidence-found, or conflicting status for each item as documents come in.
05Common mistakes
- Sending a generic, unscoped list — wastes the target's time and buries genuinely important requests among boilerplate ones.
- Not versioning the list — as new items get added mid-diligence, teams lose track of which version the target is working from.
- Treating "received" as "reviewed" — a document being uploaded doesn't mean anyone has confirmed it actually answers the request.
- No owner per category — without a specialist assigned to each category, financial and legal items can sit unreviewed while attention goes elsewhere.
- Missing the follow-up loop — a document that raises a new question needs a new request, not a note that gets forgotten.
06Frequently asked questions
How many items are on a typical request list?
It ranges widely — a few dozen for a small acquisition to several hundred for a complex M&A or financial due diligence engagement covering every category.
Who owns the request list during a deal?
Usually the buy-side deal lead or lead advisor owns the overall list, with specialists (financial, legal, commercial) owning review of their own category's items.
Should the request list be shared with the target all at once?
Most teams share the full list upfront so the target can start gathering materials in parallel, then send targeted follow-up requests as early findings raise new questions.