M&A Due Diligence: The Legal Workstream Checklist for 2026

The middle-market deal that blows up in October blew up in June. A buyer signed an LOI on a $180M SaaS target, ran a six-week diligence sprint, and missed three things.

The target had fine-tuned an internal model on customer support transcripts without DPA consent. Two of its top ten customers held MFN clauses that re-rated pricing on change of control. The Illinois warehouse workforce had been clocking in by fingerprint since 2022.

The first became a privacy class action threat. The second knocked $14M off the synergy model. The third was BIPA, and the R&W carrier would not write over it without a $4M retention.

None of those issues were exotic. All three were on the standard checklist. They got missed because the checklist a lot of deal teams are still running was written before the AI Act, before the FTC's HSR overhaul, and before privacy class actions started showing up as deal-breakers in the schedule of exceptions.

This is the working version of that checklist. Eight workstreams, the 2026-specific gotchas, the time budget, and the three issues missed most often in middle-market deals.

Short answer: a legal due diligence checklist covers eight workstreams: corporate organization, material contracts, litigation, employment, IP, regulatory and compliance, tax, and privacy and data security. In each one you are hunting for the same thing: a fact that survives the closing and lands on the buyer as a liability, a price cut, or a class action. The 2026 version adds an AI inventory, biometric-privacy (BIPA) exposure, forced-labor supply-chain risk, and the indexed HSR filing threshold to the standard list.

TL;DR

  • The eight legal workstreams. Corporate organization, material contracts, litigation, employment, IP, regulatory and compliance, tax, privacy and data security. None new. What changed in 2026 is what lives under each one.
  • 2026 hot issues. AI inventory and EU AI Act exposure, BIPA-style privacy class actions (740 ILCS 14/, California CIPA, Massachusetts wiretap), Uyghur Forced Labor Prevention Act (Public Law 117-78) supply-chain exposure, the indexed HSR threshold (FY 2026 size-of-transaction at $133.9M effective February 17, 2026, up from $126.4M), and SEC Cyber Item 1.05 disclosure history.
  • Typical timeline is 6-12 weeks. Two to three weeks from IOI to LOI, four to six weeks of diligence, two to three weeks of negotiation and signing. The slow lane is now privacy and regulatory, not corporate.
  • The three most-missed issues in middle-market deals. Change-of-control triggers in the customer top 20, employee misclassification in strict ABC-test states (California, Massachusetts, New Jersey), and undisclosed AI use in product or back-office workflows.
Quick check

Per the post, what is the FY 2026 HSR size-of-transaction filing threshold, effective February 17, 2026?

Part of our corporate and transactional lawyer playbooks.

The M&A legal diligence workstream: AI extracts, humans decide

AI owns extraction and first-pass review across hundreds of contracts; judgment on what kills the deal stays human.

The eight workstreams

The categories below go on every diligence request list and into every disclosure schedule. The line items are the 2026 version.

#WorkstreamWhat you are hunting forThe red flag that kills the deal
1Corporate organizationClean chain of title to the equityA cap table that does not reconcile to the primary docs
2Material contractsClauses that survive the deal and bite the buyerChange-of-control trigger or MFN in a top-20 customer
3LitigationExposure, not just the docketA pattern of recent settlements after years of quiet
4EmploymentWhere deal economics moveMisclassified 1099 workforce in an ABC-test state
5IPWho actually owns the product, including any AIUndisclosed fine-tune trained on customer data
6Regulatory and complianceTrade, antitrust, and sector exposureXinjiang supply-chain inputs with no UFLPA map
7TaxStructural items legal should surfaceA 280G parachute hit nobody modeled
8Privacy and data securityThe new deal-killer categoryBiometric (BIPA) collection with no written release

Each row maps to one section below. The first three columns are the standard ask; the last column is what you flag.

1. Corporate organization

The least glamorous workstream, and the one that kills closings when it falls apart.

  • Certificate of incorporation and amendments, stamped Secretary of State filings
  • Bylaws, LLC operating agreements, subsidiary partnership agreements
  • Board minutes and written consents (3 years, 6 for tax-positioned items)
  • Stockholder consents for every charter amendment, equity plan, financing
  • Cap table tied to primary documents: SPAs, option grants, warrants
  • 409A valuations for the last three years matched to board strike-price approval
  • Prior financing docs (SAFEs, notes, preferred) plus the side letters everyone forgets
  • Good standing certificates from state of incorporation and every state of qualification

The cap table reconciliation is the item every deal counsel underestimates. A founder-friendly SAFE from 2019 that converted on the wrong post-money number compounds through every subsequent round. By the closing waterfall it's a six-figure problem.

2. Material contracts

Find the clauses that survive the deal and bite the buyer. Top twenty customers and top twenty vendors by spend are non-negotiable.

  • Top 20 customers by trailing 12-month revenue, full contract files
  • Top 20 vendors by spend, same treatment
  • Change-of-control triggers, assignment clauses, required consents mapped to deal structure
  • MFN clauses that re-rate pricing if the acquirer offers a better price elsewhere in its book
  • Exclusivity and non-compete provisions binding the target
  • Auto-renewal mechanics and the next renewal window for each contract
  • Termination for convenience, notice periods, wind-down obligations
  • Indemnification scope and any uncapped liability (IP infringement, data breach)
  • Source code escrow obligations agreed to and never funded
  • Agreements with sovereigns or sanctioned-jurisdiction counterparties

The MFN is the silent killer. It does nothing in normal operations.

The moment a strategic acquirer with a different price book takes ownership, the MFN can drag revenue down 5-15%.

3. Litigation

About exposure, not just disclosure.

  • Open litigation: caption, court, claims, status, counsel outlook letters
  • Threatened litigation, demand letters, pre-suit mediations (last 24 months)
  • Class actions and putative class actions with any active certification motions
  • Regulatory inquiries: CIDs from state AGs, FTC, DOJ, SEC, HHS-OCR
  • Settlements in the last 36 months with the actual agreements, not press releases
  • Litigation holds in place, any holds lifted or breached
  • Insurance coverage for each pending matter: tower, retentions, denial letters
  • Workers' comp claims pattern (a tell for safety and HR posture)
  • Subpoenas and third-party document requests, including grand jury subpoenas

A target quiet on the litigation front for three years and then settling three EEOC charges in the last quarter is telling you something. Read the pattern, not just the docket.

4. Employment

Where deal economics often move, especially in services businesses.

  • Workforce schedule by state: full-time, part-time, contractor headcount
  • 1099 workers who fail California AB 5, Massachusetts G.L. c. 149 § 148B, or New Jersey's ABC test
  • ERISA plan documents, 5500 filings, compliance audits, DOL inquiries
  • Equity incentive plan and option grants with vesting and acceleration triggers
  • Key personnel agreements: change-of-control, severance, retention, equity acceleration
  • Non-compete and non-solicit covenants, flagged for California, Minnesota, North Dakota, Oklahoma
  • WARN Act notices in the last 24 months and any planned post-closing RIFs
  • Pay equity audit in mandatory-disclosure states (California, Colorado, Washington, New York)
  • Pending EEOC charges, NLRB charges, OSHA citations
  • I-9 audit, H-1B and L-1 caps, pending PERM filings

Single-trigger acceleration on key executives at a $200M target can be a $3M-$8M cash hit at closing. That's the single line item that most directly hits the price.

5. IP

New 2026 center of gravity: the AI inventory.

  • Registered marks, patents, copyrights, domain names with assignment records traced to the target
  • Pending registrations and applications with prosecution history
  • IP ownership through employee invention assignments and contractor IP language
  • Open-source software inventory and license obligations (GPL family especially)
  • Joint development agreements with a clear read on who owns resulting IP
  • Trade secret protections: NDAs, access controls, departing-employee protocols
  • Licenses in and licenses out (embedded third-party software; IP licensed to customers and affiliates)
  • Past IP litigation, oppositions, IPRs, cease-and-desist letters
  • AI inventory: every model trained, fine-tuned, or hosted; every model API consumed; the training data behind each
  • AI output IP allocation under customer contracts

This is where 2026 diligence breaks most. Targets disclose "we use ChatGPT" and don't disclose a custom fine-tune trained on customer support transcripts, with no consent flow, sitting on an S3 bucket. The buyer inherits the privacy exposure, the IP exposure, and the EU AI Act classification risk.

6. Regulatory and compliance

More crossover now with privacy and trade than with industry licensing.

  • Industry licenses by state and federal authority with renewal dates
  • FCPA program, training records, third-party intermediary diligence files
  • OFAC compliance, screening logs, voluntary self-disclosures
  • Export controls: EAR and ITAR classifications for product, hardware, technical data
  • Antitrust: HSR filings by the target in the last five years and any second requests
  • HSR readiness: FY 2026 size-of-transaction threshold is $133.9M effective February 17, 2026 (up from $126.4M), per the FTC's annual update
  • CFIUS exposure under Defense Production Act § 721, mandatory filings for the "TID U.S. business" categories (critical technology, infrastructure, sensitive personal data), and any foreign LP triggering a notice
  • Uyghur Forced Labor Prevention Act (Public Law 117-78) supply-chain audit for manufacturing exposure to Xinjiang or downstream PRC inputs
  • Industry frameworks (HIPAA, GLBA, FERPA, FDA, FCC, state insurance, state banking)
  • Government contracts: FAR/DFARS compliance, mandatory disclosure history, suspension and debarment screening

UFLPA is the supply-chain clause everyone treats as boilerplate and CBP treats as a rebuttable presumption. A target with apparel, solar, polysilicon, or electronics inputs needs an actual tier-1 through tier-3 supply-chain map, not a representation.

7. Tax

Its own discipline. Legal should surface the structural items.

  • Federal income tax returns for the last three years with attachments
  • State income, franchise, gross receipts returns for every state of nexus
  • Sales and use tax returns plus any voluntary disclosure agreements
  • Open audits at federal, state, local level with auditor IDRs
  • Transfer pricing documentation for cross-border affiliate transactions
  • ASC 740 tax reserves with the underlying memos
  • NOL carryforwards, section 382 limitation analysis, change-of-control triggers
  • Sales-tax economic-nexus exposure post-Wayfair for the last six years
  • 280G analysis on any change-of-control payment triggering excess parachute treatment
  • State and local incentive agreements and clawback triggers

The 280G gross-up, when it kicks in, can be a six-figure surprise per executive. Almost always missed in the first pass.

8. Privacy and data security

From afterthought in 2018 to deal-killer in 2026.

  • Privacy policy history with archived versions tied to dates
  • GDPR posture: lead DPA, records of processing activities, DPIAs, open inquiries
  • CCPA and the 2026 CPRA framework: opt-out signals, sensitive personal information handling
  • BIPA exposure: any biometric collection (fingerprints, face scans, voice prints) by workforce or customers in Illinois, with the written release, retention schedule, and destruction policy required by 740 ILCS 14/15
  • California CIPA, Massachusetts and Pennsylvania wiretap exposure: session-replay and chat-monitoring tools
  • Recent incidents: breach notifications sent in the last 36 months with incident files
  • Sub-processor inventory with current DPAs in place
  • Data flow map showing where US, EU, UK personal data sits
  • Cross-border transfer mechanisms (SCCs, UK addendum, EU-US DPF certification)
  • SEC Cyber Item 1.05 disclosure history for any public-company target with the materiality memo
  • AI system risk classification under the EU AI Act for any product offered to EU users

BIPA is the line item doing the most damage right now. Per-violation private right of action with $1,000-$5,000 in statutory damages.

The 2023 Cothron v. White Castle decision from the Illinois Supreme Court (2023 IL 128004, Feb 2023) held each scan is a separate violation. That is the math behind the $228M jury award in Rogers v. BNSF, the first BIPA case tried to verdict. The judge vacated that award and ordered a new damages trial, and the parties then settled for $75M (NatLawReview, 2023). A 200-employee warehouse in Joliet clocking in by fingerprint since 2022 has a real exposure number, and the carrier knows it.

Critical issues by deal stage

A finding is only worth the time if it changes a deal term. Here is how the common ones translate, with typical (not guaranteed) treatment in middle-market deals:

FindingDeal-term responseTypical impact
Top customer holds a change-of-control rightGet consent pre-closing, plus an escrow holdbackClosing condition; part of price held in escrow
Pending litigation, uncertain outcomeSpecial indemnity sized to the exposureEscrow carve-out for that matter
Missing IP assignment from a key contractorSeller must get the assignment before closingDeal does not close until signed
Identified BIPA or biometric exposureSpecial indemnity; carrier often excludes itSeparate escrow; R&W will not cover
Misclassified 1099 workforceReps plus indemnity, or a price cutPer worker, per year; aggregates fast
Undisclosed tax exposureTax indemnity with extended survivalSeller on the hook for several years

Findings land in three places that track the deal stages.

Sign and close. Findings drive the reps and warranties, disclosure schedules, and the MAC clause. Every fact on a schedule is a fact the seller does not indemnify against; every rep without a knowledge qualifier is one the seller is on the hook for whether or not management actually knew.

The 2026 MAC clause has new carve-ins: AI Act enforcement actions show up for EU-facing targets, and supply-chain disruption from forced-labor enforcement is negotiated explicitly rather than left to interpretation.

Closing conditions. Three, in the order they move closings: regulatory clearance (HSR, CFIUS, sector regulators), financing (debt commitments, equity rollover, escrow funding), and third-party consents on the customer top 20, vendor top 20, material leases, embedded software.

The consent workstream is where deals quietly slip a month. A target with 35% concentration where the top three customers each hold change-of-control consent rights is a closing condition disguised as a contractual nicety.

Post-closing. Unfixed findings become indemnification claims, escrow holdbacks, or R&W insurance claims. R&W is standard at $50M+ deal sizes with retentions running 0.75-1% of enterprise value, higher for healthcare and privacy-heavy targets.

BIPA exclusions are common; cyber exclusions vary by carrier. Escrow is shrinking as R&W picks up the load, but special indemnities for known issues (a pending IRS audit, an identified BIPA exposure) still get escrowed.

The hot 2026 issues

Five items that should be on every request list, even if they wouldn't have been three years ago.

AI inventory and EU AI Act exposure. Every target, not just AI-first companies. Ask for every AI/ML system the target has built, hosts, fine-tunes, or consumes via API; the training data behind each; whether it's used on EU data subjects; the AI Act risk classification; and the contract terms with any third-party model provider.

The most common finding is a shadow inventory: marketing fine-tuned a model on support tickets, engineering uses a coding assistant against a private codebase, sales has a chat that records full sessions. None of it is in the privacy policy. All of it transfers.

Privacy class action exposure. The plaintiff bar found three reliable theories: BIPA in Illinois (740 ILCS 14/), CIPA and the wiretap theory in California, and the Massachusetts wiretap statute. Each is per-violation statutory damages with eight-figure verdicts behind it.

Ask for biometric collection on workforce or customers, any session-replay or chat-monitoring tool, and any third-party pixel or SDK firing on properties reachable from California, Illinois, Massachusetts, or Pennsylvania.

Supply chain and forced labor. The Uyghur Forced Labor Prevention Act (Public Law 117-78) creates a rebuttable presumption that goods sourced in whole or part from Xinjiang are barred from import. CBP withhold-release orders have hit apparel, electronics, solar, and food. A target with manufacturing exposure to the PRC needs an actual tier-1 through tier-3 supply-chain map.

HSR threshold and indexation rhythm. The HSR size-of-transaction threshold is indexed annually and revised in February. The prior figure was $126.4M; the FTC's January 2026 update moved it to $133.9M effective February 17, 2026, with filing fees moving too.

The 2024 HSR overhaul (narrative on prior acquisitions, subsidies from foreign entities of concern) expanded the front-end work even for filings that go through cleanly. Build a week of buffer.

SEC Cyber Item 1.05. For any public-company target, the SEC's 2023 rule requires a Form 8-K Item 1.05 filing within four business days of determining a cybersecurity incident is material. Ask for the materiality memo for any incident in the last 36 months, even if no 1.05 was filed. Absence of a 1.05 where the facts arguably warranted one is its own finding.

Time budget

The honest 2026 timeline for a middle-market deal:

  • IOI to LOI: 2-3 weeks. Mostly business-side; legal helps with carve-outs, exclusivity, term sheet.
  • LOI to substantive completion of diligence: 4-6 weeks. The eight workstreams run in parallel. Privacy and regulatory are the long poles now.
  • Diligence to signing: 2-3 weeks. Definitive agreement negotiation, disclosure schedules, R&W binding.
  • Signing to closing: 30-90 days depending on regulatory. Pure financial buyer with no HSR runs 30-45; HSR with no second request, 45-60; CFIUS in the path, 60-90 minimum.

The slowest workstream is not corporate. It is privacy, because every target has a sub-processor inventory nobody has fully mapped, a privacy policy history nobody has versioned, and a session-replay tool somebody installed and forgot. The hour count on privacy diligence for a 200-person SaaS target is now closer to 80 than to 30.

The three most-missed issues in middle-market deals

Three patterns we see repeatedly in middle-market deals that don't show up in BigLaw playbooks because BigLaw is doing different deals.

Customer change-of-control triggers in the top 20. Buyers focus on revenue concentration and miss the contractual right that lets the top customer terminate or re-price the moment ownership changes. The fix is mechanical: pull assignment, change-of-control, and termination-for-convenience clauses for every contract in the top 20 onto one page of the deal memo. Half the time at least one is a closing condition in disguise.

Employee misclassification in strict ABC-test states. A 1099 workforce that looks fine under federal law can be sitting on multi-year wage-and-hour and benefits-misclassification exposure under California AB 5, Massachusetts G.L. c. 149 § 148B, or New Jersey's ABC test.

The exposure is per worker per year and aggregates fast. R&W carriers either exclude it or take a huge retention. Ask for state-by-state contractor headcount, work descriptions, and how each contractor would fare under the ABC test of the state where they work.

Undisclosed AI use in product or back-office workflows. The target's CEO says "we don't really use AI." The product team shipped four LLM-powered features in the last twelve months. Customer support has used an AI summarizer trained on tickets since 2023.

HR uses an AI resume screener that operates in NYC, where it triggers Local Law 144 bias audit obligations. None of this is in the diligence response because nobody asked the right people. The fix: ask engineering, ops, and HR separately, not just legal.

FAQ

What is included in a legal due diligence checklist for M&A? Eight workstreams: corporate organization, material contracts, litigation, employment, IP, regulatory and compliance, tax, and privacy and data security. In each one you collect the documents, then flag any fact that becomes a liability, a price cut, or a class action after the buyer takes over. The 2026 version adds an AI inventory and biometric-privacy exposure to the standard list.

How long does M&A legal due diligence take? A middle-market deal typically runs 6 to 12 weeks from term sheet to signing: 2 to 3 weeks to a signed LOI, 4 to 6 weeks of diligence, and 2 to 3 weeks of negotiation. Signing to closing then adds 30 to 90 days depending on regulatory clearance. Privacy and regulatory are the long poles now, not corporate.

What is the most common red flag in legal due diligence? A customer change-of-control or assignment clause that lets a top-20 customer terminate or re-price when ownership changes. Buyers focus on revenue concentration and miss the contract right sitting underneath it. Pull those clauses for every top-20 contract onto one page; half the time at least one is a closing condition in disguise.

What is BIPA exposure in an acquisition? BIPA is the Illinois Biometric Information Privacy Act (740 ILCS 14/). If the target collects fingerprints, face scans, or voice prints without the written release and retention schedule the statute requires, each scan can be a separate violation at $1,000 to $5,000 (Cothron v. White Castle, 2023 IL 128004). R&W carriers commonly exclude it, so it usually moves to a special indemnity or escrow.

What is the HSR threshold for 2026? The Hart-Scott-Rodino size-of-transaction threshold is $133.9M effective February 17, 2026, up from $126.4M, per the FTC's January 2026 annual update. Deals above it generally require a premerger filing and an antitrust waiting period. Build a week of buffer for the expanded narrative requirements from the 2024 HSR overhaul.

How do due diligence findings become deal terms? A finding either gets fixed before closing (a missing IP assignment), disclosed on a schedule so the seller does not indemnify it, or covered by indemnity, escrow, or a price cut. Known, sized risks like a pending audit or an identified BIPA exposure typically get a special indemnity and a dedicated escrow.

Should you run legal due diligence on a target that says it does not use AI? Yes, and ask engineering, ops, and HR directly. The most common 2026 finding is shadow AI: a support model fine-tuned on tickets, a coding assistant against a private repo, an HR resume screener that triggers bias-audit duties. None of it shows up when only legal is asked.

For related drafting and AI coverage, see Drafting the Schedule of Exceptions in an M&A Deal, the Term Sheet Review Checklist for Corporate Counsel, AI and Corporate Law in 2026, and What a Document Matrix Is, and how to build a litigation chronology from documents with AI.

Pulling change-of-control triggers, MFN clauses, and assignment terms off the top 20 contracts onto one page is exactly the bulk-extraction job Vaquill AI's Document Matrix does: name the fields once, run them across every file in the data room, and get a consistent grid back instead of a folder full of one-off reads. For more on running that extraction, see /features/document-matrix, or start a 7-day trial.

Legal AI that reads your documents and knows the law.
Ask a legal question, review a contract, or search thousands of your files. Every answer shows where it came from. 7-day free trial, no card.
20 min read

New legal AI guides, weekly.

Arshita Anand

Arshita Anand

Co-Founder & CEO · Attorney

Arshita leads product and strategy at Vaquill, building the legal AI suite that solo, small-firm, and in-house US lawyers use to run a matter end to end.