Investors rarely say “no” because of one missing file. They hesitate because the picture stays blurry — inconsistent metrics, unclear IP ownership, or contracts that raise new questions faster than you can answer them.
This due diligence checklist is designed for startup fundraising rounds across the United Kingdom, the United States, and Canada. You’ll get a structured list of documents across six categories, a recommended preparation order, and practical packaging tips that reduce investor follow-up questions and keep the process moving.
What investors are actually trying to verify
Fundraising due diligence aims to confirm three things: (1) the company is legally sound and the ownership structure is clean, (2) the product and IP are protectable, and (3) the financial story matches the operational reality.
Security and data governance are increasingly part of that picture. The Verizon 2026 DBIR reports that 48% of all breaches now involve ransomware and that the human element remains a dominant factor in most incidents — which is why growth-stage investors now routinely ask about access controls, incident response, and data governance as part of standard diligence.
The IBM Cost of a Data Breach Report 2025 puts the global average breach cost at $4.4M, reinforcing why investors view a company’s security posture as a proxy for operational discipline.
Preparation order: build the foundation before the detail
Preparing in the right order prevents the most common mistakes — sharing financials before the cap table is clean, or providing customer contracts before IP assignments are confirmed.
- Corporate and cap table hygiene: fix ownership structure, option grants, and board approvals before sharing anything with external parties
- Financial reporting alignment: align metric definitions across P&L, management accounts, and investor reporting — then provide supporting detail
- Commercial proof: customer contracts, churn analysis, pipeline report
- IP and product: ownership assignments, architecture overview, security posture
- People and operations: employment documents, incentive plans, key policies
- Risk and compliance: disputes, insurance, privacy and data governance
Due diligence checklist by folder
Folder 1: Corporate, governance, and ownership
- Certificate of incorporation and all amendments
- Shareholder agreement (if applicable) and any side letters
- Board minutes and written resolutions (last 2–3 years)
- Current cap table — including options, warrants, SAFEs, and convertibles
- Summary of any intercompany agreements or subsidiary structure
Common gap: board minutes that are incomplete, unsigned, or missing resolutions for material decisions. Fix this before diligence opens.
Folder 2: Finance and tax
- P&L, balance sheet, and cash flow — monthly, for the last 2 years
- Bank statements and current burn rate / runway calculation
- Revenue recognition policy (even if simple — document it)
- Budget vs actuals and financial forecast with assumptions
- Tax filings and any material correspondence with tax authorities
Common gap: financial model and management accounts using different revenue definitions (ARR, MRR, recognised revenue). Resolve this with a one-page KPI definitions sheet before you share anything.
Folder 3: Commercial — customers, revenue, and pipeline
- Top 10–15 customer contracts (MSAs, SOWs, amendments)
- Standard sales terms and order forms
- Pricing policy and discount approval process
- Churn and retention analysis with cohort tables
- Pipeline report and sales process definition (CRM export where available)
Common gap: contracts have been amended verbally or via email but only the original signed version is in the data room. Include email amendments as attachments alongside the original contract.
Folder 4: Product, technology, and IP
- IP assignment agreements — founders, all early employees, and contractors
- Architecture overview and key dependency map
- Open-source usage register and licence summary
- Patent and trademark registrations (if any) and filing status
- Security policies: access management, incident response plan, data classification
Common gap: early contractors and advisors were not asked to sign IP assignment agreements. This is the single most common diligence red flag in technical startups. Resolve it before the process opens, not during it.
Folder 5: Legal, compliance, and risk
- Standard customer and vendor contract templates
- Material disputes, demand letters, or regulatory correspondence
- Privacy policy and records of processing activities (GDPR/CCPA as applicable)
- Insurance policies — cyber, D&O, professional liability
- Regulatory licences or registrations relevant to the business
Common gap: privacy documentation exists but has not been reviewed since 2022. Stale dates signal to investors that policies are filed but not maintained.
Folder 6: Team and HR
- Employment agreements for founders, C-suite, and key employees
- Standard employment and contractor templates
- Equity incentive plan documents and individual grant letters
- Compensation and bonus policy summary
- Organisation chart and planned hires (use of proceeds)
Common gap: contractor agreements that do not include adequate IP assignment clauses. A contractor without an IP assignment is a liability, particularly in early-stage technology businesses.
How to package documents so investors trust what they see
Organisation is itself a signal. A clearly structured, consistently named room communicates that the business runs with discipline.
Packaging standards:
- Use the six-folder structure above, numbered for easy navigation
- Name files: [YYYY-MM-DD] [DocType] [Subject] [Status] — for example: 2026-05-01 Contract CustomerABC MSA Approved
- Include a one-page ReadMe in the root folder with KPI definitions, contact details, and Q&A rules
- Mark draft documents clearly — do not include them unless specifically requested
- Log every update in a changelog: date, document name, what changed
Tooling: when to use a VDR vs a shared drive
A well-configured shared drive can work when only one firm is diligencing and the relationship is established. As soon as two or more investors are in the room simultaneously, a VDR provides meaningful advantages: view-only access, dynamic watermarking, structured Q&A, and audit logs.
For the full data room structure, see how to structure a Series A data room. To compare VDR tools, use Compare Providers.
FAQ
Share enough to support investor conviction without overexposing your most sensitive commercial and legal materials. Standard practice is staged access: financial and business metrics first, contracts and security materials after confirmed serious interest.
Unclear IP ownership — particularly when early contractors or advisors were not required to sign assignment agreements. It is the most common structural issue in technical startups and the hardest to fix quickly under time pressure.
At least 60–90 days before you plan to run a formal process. Many documents — board minutes, IP assignments, revised contracts — take time to collect and correct. Starting preparation when investor conversations begin is too late.
Start preparing now: use this checklist alongside how to structure a Series A data room to build a room investors can navigate in minutes rather than days.
