Vendor Due Diligence: A Seller's Guide
Vendor due diligence is the process a seller runs on its own business before a buyer runs it for them. Rather than waiting for an acquirer's advisers to arrive and start hunting, the seller commissions an independent review of the same ground, in advance, and goes to market knowing what will be found. The logic is simple: in a sale process, information you already have is protection, and information the other side finds first is leverage.
It is now standard practice on UK mid-market and private equity deals, and the workstream that most often costs the seller money is technology.
What vendor due diligence actually is
A vendor due diligence exercise produces an independent report, commissioned and paid for by the seller, that examines the business the way a buyer's diligence would. It is shared with bidders under reliance, so they can rely on its findings rather than duplicating the work from scratch.
Two things follow from that. First, the report has to be honest. A VDD report that reads like a sales brochure is worthless, because the first bidder who finds something it omitted will discount everything else in it. Second, because it is written for the buy side, it has to answer the questions the buy side asks, in the order they ask them.
Vendor due diligence vs commercial due diligence
The two get conflated. Commercial due diligence asks whether the market, the proposition and the growth case stack up. It is a question about the future. Vendor due diligence describes who runs it and for whom, not what it covers, and a full VDD exercise usually spans several disciplines at once: financial, tax, legal, commercial, operational and technology.
So "commercial vendor due diligence" is not a contradiction. It is the commercial workstream of a seller-commissioned exercise. Buy-side diligence is the mirror image, run by the acquirer, and we have written separately on what acquirers miss in technology due diligence when they run it themselves.
What a VDD report is for
Sellers commission VDD for four reasons, and they are worth separating because they pull in different directions:
- Speed. A credible report shortens the buyer's own process, which shortens the period in which the deal can fall apart.
- Competitive tension. Several bidders can work from the same pack at the same time, which is difficult to arrange if each is running its own review.
- Control of the narrative. Issues framed and costed by the seller land very differently from issues discovered by a buyer's adviser at week six.
- Runway. This is the one most sellers underuse. Run early enough, VDD is not a disclosure exercise at all. It is a list of things you still have time to fix.
Why UK sellers are running it earlier
The pattern we see across PE-backed and founder-owned businesses is that VDD has crept forward in the timeline. It used to sit alongside the information memorandum, a few weeks before bidders arrived. Increasingly it sits twelve to eighteen months out.
The reason is that a report delivered at the start of a process can only describe. A report delivered a year out can be acted on. The remediation window is where the value is, and it closes long before the data room opens.
What vendor due diligence covers
The standard workstreams
A typical UK mid-market VDD pack covers financial performance and quality of earnings, tax structure and exposures, legal and contractual position, commercial and market case, operations, people, and technology. The weighting varies with the business. A software company's technology chapter will be the fattest section in the pack; a distribution business may treat it as a footnote, sometimes wrongly.
Where technology sits
Technology is the workstream most likely to be underweighted by the seller and overweighted by the buyer. Finance and legal have decades of established practice, a clear owner in the business, and advisers who have run the exercise a thousand times. Technology often has none of that. It is assessed late, by whoever is available, against no consistent standard, and the findings arrive without a price attached.
Why technology is the usual weak spot
The issues that move a price
A buyer's technology diligence is, in practice, a risk hunt. The things it reaches for are consistent:
- Technical debt that turns the growth plan into a rebuild, and the rebuild into a cost the buyer wants funded out of the price.
- Key-person risk, where one engineer holds the working knowledge of the platform and no succession exists.
- Cyber security and resilience gaps, which have moved from a technical finding to a board-level valuation question.
- Cloud and infrastructure cost that is structurally higher than the buyer's model assumes, quietly reducing forecast margin.
- Data, privacy and compliance exposure, including the AI question buyers now ask as a matter of routine.
None of these are fatal on their own. Each is a reason to argue the number down.
The issues that stop a deal
A smaller set is binary. Unclear IP or code ownership, where contractor agreements never assigned rights. Change-of-control clauses that let a critical supplier walk away, or reprice, the moment the shares change hands. Licensing that does not survive the transaction.
These do not shave a turn off the multiple. They stop the process while lawyers work out whether the thing being sold is the thing that was described. Found by the seller a year out, most are routine paperwork. Found by a buyer at week eight, they are a crisis.
Turning findings into fixes
The gap between a good VDD report and a better price is execution, and it is where most exercises quietly fail. A list of forty findings handed to a management team already running the business, six months before a sale process, does very little on its own. The team is busy, the incentives point elsewhere, and nobody owns the list.
Remediation has to be sequenced against the exit timeline, not against engineering preference: deal-killers first, valuation risks next, cosmetics last or never. It needs named owners, realistic effort, and a mechanism for the changes to stick in the business rather than be reversed the week after they are made. That is the discipline our Embedded Change Model™ exists to enforce, and it is the difference between a report that describes the problem and a programme that closes it. Where the fix is a broader remediation effort, our programme recovery and transformation work picks it up from there.
A cheaper first step
Full vendor due diligence is a significant commitment, and it is the right one when a process is genuinely in view. If you are twelve months out and want to know whether the technology chapter is going to be a problem before you spend anything, there is a lighter starting point.
ExitReady assesses your technology across the ten domains an acquirer's diligence actually examines: architecture and scalability, technical debt, cyber security and resilience, data and compliance, key-person risk, delivery practices, cloud cost, IP and licensing, vendor and change-of-control risk, and the product and AI story. The assessment takes minutes, and the readiness score, the domain heatmap and the count of critical deal-killers are free. The full board-ready report, with every deal-killer explained and a prioritised remediation roadmap sequenced against your timeline, is £2,500.
Set against a turn on the multiple of a £20m deal, that is inexpensive insurance. There is more detail in our note on technology exit readiness and what a buyer's diligence will find.
Frequently asked questions
What is vendor due diligence?
Vendor due diligence is an independent review of a business commissioned by the seller before a sale, covering the same ground a buyer's advisers would examine. The resulting report is shared with bidders under reliance, so they can depend on its findings rather than repeating the work.
What is the difference between vendor due diligence and commercial due diligence?
Vendor due diligence describes who commissions the work, the seller, and covers several disciplines at once. Commercial due diligence is one of those disciplines, examining the market and the growth case. A commercial vendor due diligence report is simply the commercial chapter of a seller-commissioned exercise.
Who pays for vendor due diligence?
The seller, which is precisely why the report has to be credible. Bidders discount a report that reads as advocacy, and any material omission undermines the parts that were accurate.
When should we start?
Earlier than most people do. Twelve to eighteen months before a process gives you time to fix what the report finds. Commissioned six weeks out, it is a disclosure exercise rather than a value exercise.
What does a vendor due diligence checklist cover for technology?
At minimum: architecture and scalability, technical debt, cyber security and resilience, data privacy and compliance, key-person risk, delivery practices, cloud and infrastructure cost, IP and code ownership, vendor and change-of-control risk, and the product and AI roadmap. The last three are where deals most often break.
Where to start
You cannot fix in diligence what you did not prepare for. If a sale is on the horizon, the useful question is not what your advisers will say about the business, but what a buyer will find in it. Run the free assessment to see where your technology stands today, or talk to us about your exit timeline.