Module 2 · Chapter 7

Due Diligence

Caveat emptor means no one is going to warn the buyer. Due diligence is how the buyer warns itself: the workstreams, the data room, the Q&A discipline, what you as the junior will actually review — and the one document in the Sunrise data room that reshaped the whole deal.

≈ 19 min read 10-question test Follows the Sunrise data room

7.1Why buyers investigate — and the five things a finding can become

Recall from Chapter 1 the principle that shapes everything a share buyer does: caveat emptor — let the buyer beware. With narrow exceptions, a seller of shares has no duty to volunteer the bad news. The courts will hold a seller to the promises written into the SPA; they will not conduct the buyer’s investigation for it. Due diligence — universally, DD — is that investigation: the buyer’s structured review of the target before it commits. It is self-help, in a legal system that offers no other kind.

Be clear-eyed about what DD is for: it is not an academic study, and a DD report is not a biography of the target. Every finding is worth exactly the deal consequence it produces — and for any problem DD turns up, there are only five things the buyer can do with it:

  1. Fix it before completion. Some problems can simply be cured while the deal is negotiated: a missing filing made, a landlord’s consent obtained, an unsigned IP assignment signed. Cheapest and cleanest, where the problem co-operates.
  2. Make it a condition. If the fix takes time or depends on a third party, completion can be made conditional on it happening — the deal signs, but does not complete until the problem is resolved. Regulatory approval, as in Sunrise (clause 5.1), is the classic conditional fix.
  3. Cover it with a warranty or an indemnity. Leave the risk with the seller by contract: a warranty where the buyer wants the seller to stand behind a fact, or a specific indemnity. A specific indemnity is a euro-for-euro promise to reimburse a particular identified risk if it materialises.
  4. Chip the price. Where the problem is real and reasonably quantifiable — an unpaid tax bill, a needed systems upgrade — reduce the consideration by roughly that amount.
  5. Walk away. Rare, but findings do kill deals: fraud, a business operating outside its licence, a liability that swallows the deal rationale. Better to lose the deal costs than buy the problem.

The routes combine freely — one finding might be partly fixed, partly priced and partly indemnified. What a finding must never do is end up nowhere.

Key point

A DD finding that does not end in one of the five outcomes has achieved nothing — except, as section 7.6 explains, to make the buyer’s legal position actively worse. The craft of due diligence is not finding things; it is converting what you find into deal consequences.

A DD finding Fix it before completion Condition to completion Warranty / indemnity Chip the price Walk away consents obtained, filings made completion waits for the fix THE SUNRISE ROUTE clause 10.2 indemnity quantifiable issues reduce the price deal-breakers only rare, but real the responses roughly escalate — from co-operative fix to no deal
Five destinations for every due diligence finding. The routes can be combined; what a finding must never do is stall in the report and reach none of them.

7.2The workstreams — and who runs them

“Due diligence” is not one investigation but several, run in parallel by different professionals. On a mid-sized private deal like Sunrise you can expect most of the following:

WorkstreamWho runs it (on Sunrise)What it looks for
LegalThe buyer’s solicitors (Blackwood & Steel LLP) Title to the shares, contracts, litigation, employment, IP, data protection — anything that belongs in, or should change, the SPA.
FinancialReporting accountants (Calder Fox LLP) Quality of earnings, debt and debt-like items, working capital — the numbers behind the price.
TaxUsually the same accountants (Calder Fox LLP) Historic tax compliance and exposures — feeds the tax covenant (Chapter 12).
Commercial / marketThe buyer’s own team, sometimes strategy consultants Market position, customer concentration, competitor threats — is the business plan believable?
RegulatorySpecialist regulatory lawyers, usually within the legal team Licence scope, regulatory capital, AML systems, the relationship with the regulator.
IT and cyberTechnical specialists System architecture, security, resilience, technical debt, past incidents.
ESGIncreasingly, a dedicated adviser Sanctions exposure, supply chain, environmental and governance red flags.

The workstreams are only as good as the traffic between them. If Calder Fox spots monthly management fees flowing from the Target to Meridian, the lawyers need to know — those payments matter for the locked box and Permitted Leakage. Someone on the buyer side, on Sunrise Priya Nair in corporate development, coordinates the whole exercise and owns the consolidated issues list.

7.3How the process actually works

Scoping. You cannot read everything. A trading business of any size holds thousands of documents, and DD runs for weeks, not years. So the first task is to agree with the client what matters: which workstreams, which risks, and above what size. That last item is the materiality threshold — for example, “review all contracts with an annual value above €250,000, plus the contracts with the ten largest clients”. Notice that the Sunrise SPA uses the same €250,000 line in the seller’s pre-completion covenants (clause 6.2(d)) and in the contracts warranty (paragraph 6.1 of Schedule 3). That symmetry is deliberate: the diligence scope and the contractual protections should describe the same universe of “what matters”, with no gap between them.

The data room. The seller does not post documents to each bidder; it opens a virtual data room (VDR) — a permissioned online document library run by a specialist provider. On Sunrise it is hosted by Vaultline Limited under the project name “Sunrise” (see the definition of Data Room in the SPA). Three features matter to you. Structure: the room is organised into numbered folders that mirror the DD request list — corporate, financial, contracts, employment, IP, regulatory and so on — and every document has a number, like 7.4.1. Permissions: the seller controls who sees what; the most sensitive documents may be visible to external advisers only, or opened up late in the process. Watermarking: each page is stamped with the viewer’s name and firm — deterring leaks and evidencing exactly what was available to whom. That evidence matters, because at signing the data room is frozen and archived (on Sunrise, onto USB drives delivered to the Buyer’s Solicitors). Its contents are about to acquire a second legal life, described in section 7.6.

Q&A. Documents raise questions, and the questions go through a formal Q&A process on the data room platform: one consolidated, numbered list of written questions from the buyer’s side, answered in writing by the seller’s side. The discipline is strict — one list, no side-channels — and for good reasons. A written log is an audit trail: everyone sees the same answers, the answers can be checked against the warranties later, and (in an auction) the seller can show all bidders were treated alike. A friendly phone call to the target’s CFO produces none of that — just an unrecorded answer the buyer cannot rely on. And deduplicate before you submit: nothing erodes a seller’s confidence faster than three versions of the same question from three different advisers.

Reporting. Each workstream distils its review into a report, and the first scoping decision is what kind:

Red-flag report

  • Exceptions-based: reports only issues above the agreed materiality level.
  • Each issue comes with a recommendation — one of the five outcomes.
  • Faster and cheaper; now the market norm on private deals.
  • Risk: anything below the threshold goes unreported by design.

Full-scope report

  • Describes everything reviewed, issue or not.
  • Useful where the buyer is new to the sector, or lenders and insurers want the detail.
  • Slower and more expensive.
  • Risk: the one finding that matters is buried on page 214.

Reliance. A DD report is advice, and advice comes with liability — so the report states exactly who may rely on it: the addressee client, and nobody else. Third parties with a genuine need are added by a reliance letter, usually with a cap on the firm’s liability to them. Typically the third party is a bank financing the purchase, or a warranty-and-indemnity insurer where the deal uses W&I insurance (Sunrise does not, but many deals do). If you are ever asked to “just send the report over” to someone new, that is a supervisor question, not a favour.

7.4Legal due diligence — what you will actually review

The legal workstream is where you come in: junior lawyers do the first-pass reading. Here is the standard territory, and what you are looking for in each part of it.

A regulated target adds a further layer, and on a fintech deal it is often the layer that decides the deal. Four checks matter most. Licence scope against actual activities: read the authorisation, then look at what the business really does — an activity outside the licence is unauthorised business, a serious breach the buyer inherits. Solaris’s CASP authorisation covers custody, exchange and execution (Schedule 1, Part A); if DD found, say, a live staking product, alarm bells. Regulatory capital: is the firm meeting its requirements, with headroom? AML/CTF systems: policies, the compliance officer’s reports, screening tools, and sample customer files. Regulator correspondence: read every letter between the firm and its supervisor for the last few years. Supervisors write to firms when something is wrong — and the Central Bank of Ireland had written to Solaris.

7.5The document that reshaped the deal

In late May 2026, one of Blackwood & Steel’s associates was re-triaging the late uploads to folder 7.4 of the data room — regulatory correspondence. The associate opened document 7.4.1, a file that had only appeared in the room on 28 May. It was an inspection letter from the Central Bank of Ireland to Solaris dated 6 March 2026. Section 5 of the letter flagged failures in the Target’s automated transaction monitoring between January and September 2024, a backlog of thousands of unreviewed alerts, and required a remediation programme. For an AML-supervised crypto firm, that is not paperwork: it carries the possibility of a fine, a costly alert-by-alert clearance, and awkward reading for the very regulator whose approval the deal needs.

Run the letter through the five outcomes and watch each door close. Fix it before completion? No — remediation would take many months, and the historic monitoring failures cannot be un-happened; the fine risk stays whatever is fixed. Make it a condition? No — a condition that the CBI closes the matter without a fine could leave the deal hanging for years, and Meridian would never sign up to it. Chip the price? The exposure was too uncertain to price: the outcome could plausibly be anywhere from remediation costs alone to a multi-million-euro penalty, and any fixed discount would overpay one side for risk. Walk away? Disproportionate — the deal rationale (the MiCA licence, the platform, the client base) was intact, and the problem was bounded and remediable. That leaves contractual risk transfer — and even there, a warranty alone would not do. The matter was now known and would certainly be disclosed. Section 7.6 explains why disclosure defeats a warranty claim. And warranty damages require proof of loss. What Atlas needed was euro-for-euro cover for a specific, identified risk: a specific indemnity.

So the finding fed straight into the drafting. The letter became a defined term — the “Legacy AML Matter”, defined by reference to the very document the associate found, Data Room document 7.4.1 — and the risk became clause 10.2:

Clause 10.2AML indemnity

“The Seller shall indemnify the Buyer, for itself and on behalf of each Group Company, on demand against all Losses arising out of or in connection with the Legacy AML Matter, including: (a) any fine or penalty imposed by the CBI; (b) the costs of the transaction-monitoring remediation programme required by the CBI; and (c) reasonable professional fees incurred in connection with the matters in (a) and (b).”

Read in the SPA →

Example — Project Sunrise

The indemnity was not conceded; it was traded. Meridian’s opening position was that the letter was disclosed, the warranties covered regulatory compliance, and nothing more was needed. Atlas’s answer: a disclosed matter gives a buyer no warranty claim at all, so the “protection” was empty. The landing zone, weeks later: a specific indemnity, but capped at €8,000,000 (clause 9.4(b)), time-limited to four years (clause 9.1(c)), free of the de minimis, basket and buyer-knowledge limitations (clause 10.3). The trade also obliged Atlas to run the remediation diligently and cost-effectively (clause 10.4). The headline price stayed €42m. One document, found by one associate doing a careful first-pass read, produced a defined term, a clause, a cap and a covenant.

7.6DD and disclosure — two sides of one coin

Now the twist that makes diligence discipline a legal necessity rather than good housekeeping. At signing, the seller delivers a disclosure letter making disclosures against the warranties — and, as is market practice, the Sunrise letter discloses the entire data room generally. The SPA gives that disclosure teeth:

Clause 8.3Warranties qualified by disclosure

“The Warranties (other than the Fundamental Warranties) are qualified by all matters Disclosed.”

Read in the SPA →

And “Disclosed” means “fairly disclosed in the Disclosure Letter or the Data Room, in each case with sufficient detail to enable a reasonable buyer to identify the nature and scope of the matter disclosed”. Read those two provisions together and the consequence lands: everything the buyer read in the data room — and everything it could have read — is everything it cannot complain about later. If a matter was fairly disclosed there, the warranty is qualified and the claim is gone, whether or not anyone on the buyer’s side actually opened the document. The SPA adds a second lock for matters the deal team actually knew about outside the data room. Under clause 9.6, the seller is not liable for a warranty claim where a member of the Buyer’s Deal Team had actual knowledge of the matter and its likely consequences at signing.

So due diligence and disclosure are the same machine viewed from opposite ends. DD converts unknown risks into known ones; disclosure then converts known risks into the buyer’s risks — unless the buyer does something with the knowledge before signing. That “something” is the five outcomes from section 7.1. It is also why the Legacy AML Matter became an indemnity rather than resting on the regulatory warranties: Schedule 3, paragraph 5.3 even carves the matter out of the warranty expressly. Disclosure gets its full treatment in Chapter 11.

Watch out

The worst failure in due diligence is not missing a problem — it is finding one and letting it die in the report. A finding that never reaches the deal team and the SPA drafters costs the buyer twice. It paid for the discovery. And because the document sits in a disclosed data room (clause 8.3), or the deal team knew (clause 9.6), the related warranty claim is dead on arrival. A finding that reaches nobody is worse than useless. If you spot something material, escalate it the day you find it, and check it lands on the consolidated issues list — never assume someone else has told the drafting team.

7.7The craft: reviewing well

Finally, technique. First-pass document review is where juniors either build a reputation for reliability or quietly lose one. The habits that separate the two:

Read the index first. Before opening a single document, read the whole data room index. It tells you the shape of what exists — and, just as importantly, what is conspicuously missing. No folder of board minutes for 2024? No regulatory correspondence at all for a supervised firm? Absences are findings too, and they become Q&A questions.

Triage by materiality. Your scope and thresholds tell you where the risk lives. Skim everything in your allocation to classify it; read deeply only what the triage earns. Ten minutes on each of the five contracts that matter beats two minutes on each of twenty-five that do not.

Note as you go, in the agreed template. Every review uses a standard note form — fill it in while the document is open. “I’ll write it up on Friday” is how findings evaporate. And record document references precisely: “Data Room 7.4.1”, never “the CBI letter” — the whole system of definitions, disclosure and indemnities runs on exact references.

Flag, don’t conclude. Your job at first pass is to spot and escalate, not to adjudicate. Never record a speculative legal conclusion in writing — “this is clearly a GDPR breach” — without a supervisor’s sign-off. DD notes get circulated, quoted and sometimes fought over later; a junior’s off-the-cuff conclusion has a way of resurfacing at the worst moment. Describe the facts, flag the concern, ask the question.

Draft report entries in a fixed shape. Issue → facts → why it matters → recommended action. The recommendation should always point at one of the five outcomes.

Drafting note

A well-formed red-flag entry reads like this: Issue: change of control — platform services agreement. Facts: the agreement with Vantage Markets Ltd (Data Room 3.2.14, annual value €1.1m) permits the counterparty to terminate on 30 days’ notice if control of the Target changes (clause 18.3). Why it matters: Completion will trigger the right; Vantage is a top-five client by revenue. Recommended action: seller to seek counterparty consent before signing; if not obtained, consider a completion condition or price discussion. SPA team: note warranty at Schedule 3, paragraph 6.2.” Four sentences, one document reference, one clear route out. That is the whole genre.

Keep the Q&A log tidy. One live list, numbered, each question owned by a named reviewer, answers pasted in verbatim with their date. The log is evidence — of what was asked, what was answered and what was never explained — and on a contested deal it will be re-read line by line.

Due diligence tells the buyer what the business is; the next question is what it is worth. On to Chapter 8 and valuation.