By Phillip Mitchell, Founder & Chief Brokerage Officer, AIExchange.club
Figures are as of October 2026, from the sources linked below. Examples are illustrations, not real deals. This is general information, not legal, tax or financial advice. Use a lawyer and an accountant for the legal and tax checks.
Due diligence is the work of checking that what a seller says about a business is true before you pay for it. For a software business under $1M, that comes down to four questions: is the revenue real, do the customers stay, can you actually own and run the code and accounts, and is there anything the seller left out that changes the price?
This guide is a checklist for buyers of small SaaS, app and AI businesses. Each item says what to ask for, how to verify it, and what a red flag looks like. Download the checklist as a spreadsheet if you'd rather work through it with a status column.
What due diligence is for
The price you agreed in your letter of intent rests on claims: monthly revenue, profit, churn, "it runs itself". Due diligence is the period, often 30 to 90 days according to law-firm guides (Turley Law), when you check those claims. Whatever you find either confirms the price, changes it, or ends the deal.
It sits between the LOI and the binding asset purchase agreement. Anything you find becomes either a lower price or a promise the seller makes in that agreement. If you're new to the whole process, our step-by-step guide to buying an AI or SaaS business shows where this stage fits.
Free due diligence checklist to download
The spreadsheet has three sheets:
- Checklist: every item below, with when to check it, a status dropdown (not started, requested, received, verified, issue) and a notes column.
- Red flags: the findings that should stop, reprice or protect a deal, and what to do about each.
- Revenue check: enter the seller's claimed revenue, the processor export and the bank deposits, and it shows the gap.
Download the checklist (Excel, works in Google Sheets)
Verify, don't collect
The common mistake is collecting documents. A seller can send a screenshot or a spreadsheet of revenue, and both are easy to edit. Verifying means seeing the numbers where they come from. Ask for read-only access to the systems that hold the truth, and use the seller's NDA and the LOI's exclusivity period to justify it.
- Payment processor. Stripe's View Only role can view payments, customers, balance and payouts, download financial reports and export payments and customers. It can't refund, pay out, change settings, manage API keys or invite users (Stripe, User roles).
- Apple App Store. The Finance role in App Store Connect has access to sales and trends and financial reports. The Marketing and Sales roles see sales and trends but not financial reports, and only the Account Holder, Admin and App Manager roles can create or edit app records (Apple, Roles).
- Google Play. A Play Console user can be given a "View financial data" permission for financial and sales reports, plus a read-only permission to view app information and download bulk reports (Google Play Console Help).
- Bank. Statements downloaded together on a call, or a read-only view, rather than a file emailed in advance.
A seller who offers only screenshots, or who won't give any read-only access during diligence, is telling you something. Treat it as a red flag, not a formality.
The due diligence checklist, by area
Work roughly in this order: money and ownership first, because they decide whether to continue, and the rest while you wait for answers. Deal-breakers are marked in the spreadsheet as "Week 1".
Financials
| Check | How to verify | Red flag |
|---|---|---|
| 12 to 24 months of revenue | Processor exports by month, matched to bank deposits (worked example below) | Deposits that don't reconcile after fees and refunds |
| Expenses | Bank and card statements and vendor invoices for hosting, AI API usage and tools | Costs paid personally and missing from the P&L, or API bills climbing faster than revenue |
| Profit (SDE) | Rebuild it yourself from statements, not from the seller's summary | Add-backs with no document behind them |
| Tax returns | Revenue on the returns matches the revenue claimed | A gap the seller can't explain |
| Refunds, disputes and failed payments | Processor reports by month | A rising dispute or refund rate |
| Sales tax or VAT | Registrations and filings, where it applies | Tax collected and not remitted, or never registered where it should be |
Customers and retention
| Check | How to verify | Red flag |
|---|---|---|
| Customer list: start date, plan, price, status | Count matches the processor's customer export | Numbers that don't match, or a list the seller won't share even after the NDA |
| Churn and net revenue retention | Rebuild monthly cohorts from the export instead of taking the seller's figure | Newer cohorts retain worse than older ones, or a "99% retention" with no period |
| Concentration | Share of revenue from the top 3 to 5 customers | One guide flags the top 3 above 30% of revenue (vaulto.sh) |
| Plan mix | Monthly, annual and lifetime plans separated in the export | Lifetime deals or heavy discounts counted as MRR |
| Where customers come from | Search Console, analytics and ad accounts, viewed live | One channel supplies most signups, or organic traffic is falling |
| Support history | Read the last 50 tickets and the store reviews | The same bug or complaint appearing again and again |
Product and code
| Check | How to verify | Red flag |
|---|---|---|
| Who wrote the code | Repository history and contributor list, plus signed IP assignments from contractors | Contractor code with no assignment, so you may not own it |
| Can you build and run it | Read-only repository access, then a build from scratch on your machine or a screenshare | It only runs on the seller's laptop, or secrets are committed in the code |
| Hosting and infrastructure | A list of every service with its monthly cost, from the cloud console | One unbacked-up server, or costs that the P&L doesn't show |
| Open-source and third-party code | A dependency and licence report | Licences that bar commercial use or require you to release your code |
| Security and backups | Ask to see a backup restored, and the incident history | No backups, or a past breach the seller didn't mention |
| Documentation | Ask the seller to walk you through a deployment | Only the seller knows how to deploy or fix it |
Platforms and accounts
These decide whether the business can be handed over at all. List every account and who owns it.
| Check | How to verify | Red flag |
|---|---|---|
| Domain and DNS | Log in to the registrar with the seller, and check the owner and expiry date | The domain is held by a freelancer or a personal email address |
| Payment processor | Read-only role (above), and a written plan for moving customers' saved payment details to your account | No plan. This is the hardest part of a handover |
| App Store account | Finance role for the numbers. Plan the transfer: the Account Holder starts it, and push keys, subscription secrets and any Apple Pay merchant ID need setting up again | An account that can't be transferred, or app review problems |
| Google Play account | "View financial data" permission. Earnings and sales reports stay with the seller's account, so ask for an export before the transfer | No exported history for the buyer |
| Email, social and support inbox | Who owns each login, and whether it can move | The business runs from the seller's personal inbox |
Store transfers have their own rules, covered in how to sell an app.
AI and third-party dependencies
For an AI-powered business this is its own area. Here's what to ask. What buyers check in an AI business has more. For how these checks change the price, see AI company valuation.
| Check | How to verify | Red flag |
|---|---|---|
| Model providers | Which models and vendors, monthly spend by vendor, 12 months of invoices | One provider and no fallback, or spend rising faster than revenue |
| Cost per customer | API cost divided by active customers, and the same figure for the heaviest 10% | Margins that vanish at the top end of usage |
| Provider terms | Read the usage and account terms. Can the keys and account move to you, or must you open new ones? | Keys tied to the seller's personal account |
| Prompts, fine-tunes and data | Who owns them, and where any training data came from | Scraped data or customer data used without permission |
| Retention against the benchmark | A cohort chart. Median gross revenue retention for AI-native products is 40% in ChartMogul's December 2025 data | Far below that, or no cohort chart at all |
| Other third-party APIs | A list with cost, terms and what happens if each is switched off | A service that is being retired, or one that can reprice overnight |
Legal and IP
| Check | How to verify | Red flag |
|---|---|---|
| Who owns the business | Formation documents, and that the seller owns the assets being sold | The assets belong to someone else, or a partner you haven't met |
| Brand and trademarks | Registrations or evidence of use, and a search for conflicting names | Another company uses the same name in the same field |
| Customer terms and privacy policy | Read both, including whether the terms let the business be sold to you | No privacy policy while collecting personal data, or terms that bar transfer |
| Contracts | Vendors, contractors and affiliates, with their end dates | Long lock-ins you'd inherit |
| Disputes and warnings | Ask in writing about claims, takedown notices and app store warnings | An open complaint the seller hadn't disclosed |
Most small software deals are asset sales, so you buy named assets and leave most of the seller's company behind. That's why the asset list matters more than the company's history. Have a lawyer check ownership and the IP assignments.
Owner dependence
| Check | How to verify | Red flag |
|---|---|---|
| Hours the owner works | A list of recurring tasks with hours, and who does support, releases and content | The owner does everything, and none of it is written down |
| Contractors and staff | Roles, pay, how long they've stayed, and whether they'll stay after the sale | A key person who is leaving too |
| Customer relationships | Who talks to the biggest customers | Large accounts that only deal with the founder |
| What the seller does next | Transition support and a non-compete (both are in the LOI) | The seller plans a competing product |
Does $9,000 MRR check out?
This is the check to run first. A listing says $9,000 in monthly recurring revenue. In this illustration the product costs $30 a month and has 300 paying customers. Here's how the claim looks once you follow it from the processor to the bank.
| Step | Source | Amount |
|---|---|---|
| Claimed MRR | The listing | $9,000 |
| Gross card charges, last full month | Processor export (300 charges) | $9,000 |
| Refunds and disputes | Processor export | −$360 |
| Net collected | $8,640 | |
| Card processing fees | 2.9% + $0.30 on 300 charges | −$351 |
| Deposits you'd expect | $8,289 | |
| Deposits in the bank | Bank statement | $8,100 |
| Unexplained gap | $189 |
The fee line uses Stripe's standard US price of 2.9% + 30 cents per successful domestic card payment (Stripe pricing); check the seller's actual rate. Two points come out of this:
- Price on what's left, not the headline. $9,000 is gross. After refunds and fees the business collects $8,289. Profit (SDE) is calculated from the net.
- Chase the gap. $189 may be payout timing, or a transfer to the owner. If it's recurring and unexplained, it's about $2,268 a year, which at 3 times SDE is about $6,800 of price. Ask for the payout report and match each transfer.
The "Revenue check" sheet in the download does these sums for your numbers.
Red flags: walk away, reprice or protect yourself
| Finding | What to do |
|---|---|
| Revenue doesn't reconcile and the seller can't explain it | Ask for the explanation in writing. Walk away if it isn't resolved |
| Screenshots only, no read-only access | Pause. Walk away if the seller still refuses |
| A few customers make up a large share of revenue | Reprice, or put part of the price in an earnout tied to keeping them |
| Retention is worse than the seller quoted | Reprice on the real figure |
| Code written by contractors with no signed IP assignment | Require signed assignments before closing |
| One AI provider and rising cost per customer | Reprice, or tie part of the price to a margin target |
| A store or payment account can't be transferred | Fix the plan before you sign, and make the escrow release depend on the transfer |
| The owner works full time and nothing is documented | Ask for longer transition support or a lower price. If you're borrowing to buy, see how to finance a SaaS acquisition |
How long it takes and who to hire
Law-firm guides often put due diligence at 30 to 90 days, with exclusivity of 60 to 120 days (Turley Law). Small deals can run faster if the seller sends what you ask for quickly. Plan it in three passes:
- Week 1: deal-breakers. Reconcile revenue, get read-only access, confirm who owns the code and accounts, and check retention.
- Weeks 2 and 3: the product. Customers, code, infrastructure and AI dependencies.
- Weeks 3 and 4 onward: the paperwork. Legal, IP, tax and contracts, which feed straight into the purchase agreement.
Hire a deal lawyer for ownership, IP assignments and the purchase agreement, and an accountant or tax adviser for the returns and the tax effect of the structure. The two cost you money but find things you can't.
If you're the seller: have this ready
Buyers who do their job will ask for everything above. The sellers who close fastest have it ready before the first call:
- 12 to 24 months of processor exports and matching bank statements.
- A customer and cohort chart you built from those exports.
- A list of every account, who owns it, and how it transfers.
- Signed IP assignments from every contractor.
- 12 months of vendor and AI API invoices.
- A one-page description of how the business runs week to week.
Our guides on how to sell a SaaS business and how to sell an app cover the rest, and the valuation tool shows what your numbers support.
After due diligence
What you found goes one of three ways. It confirms the price and you move on. It changes the price, which the LOI allowed for if it said the price was subject to diligence. Or it becomes a promise in the asset purchase agreement, where the seller states the facts are true and agrees to cover you if they aren't. Note that the exclusivity clock in your LOI runs while you do all this, so ask for what you need early.
Due diligence checklist FAQs
What documents should a due diligence checklist for a business acquisition include?
For a software business: processor exports and bank statements, tax returns, a customer list with plans and start dates, repository access and IP assignments, a list of accounts and who owns them, vendor and AI API invoices, customer terms and the privacy policy, and any contracts. The checklist above groups them by area.
How do you create a due diligence checklist?
Start with the areas: financials, customers, product, accounts, AI and third-party dependencies, legal, and owner dependence. Add anything specific to the deal, sort items by when to check them, and give each a status. The downloadable spreadsheet is built that way, so you can use it as is or add rows.
What is due diligence in a business acquisition?
It's the buyer's check, between the offer and the final contract, that the seller's claims about revenue, customers, ownership and costs are true. It ends in a confirmed price, a changed price, or a deal that doesn't go ahead.
How long does due diligence take when buying a business?
Law-firm guides often say 30 to 90 days. Small software deals can be quicker when the seller has the exports and account lists ready, and slower when the buyer has to wait for every answer.
Do I need a lawyer and an accountant?
Yes, for different parts. A lawyer checks ownership, IP assignments and the purchase agreement. An accountant or tax adviser reviews the returns and the tax effect of how the deal is structured. You can run the revenue, customer and product checks yourself.
Next step
If you're buying, browse the businesses on our marketplace to see what a listing with verified numbers looks like, and bring this checklist to the first call.
If you're selling, start with your number. Get a value range in a couple of minutes with the estimator below.
What's your SaaS worth?
= $120,000 ARR
45% of revenue is typical
Show the math
An estimate, not an appraisal. It can't see your code, your contracts, or your competitive position. Treat it as a starting range.
Get a full valuation →On AIExchange.club, listing is free and the flat 10% success fee is paid only when your deal closes. The deal room, escrow and in-platform contracts are included (see fees and pricing). We list businesses that are already making money.
List your AI-powered business →
Weighing a deal and want a second opinion? Talk it through with us.

Comments (0)
Be the first to share your thoughts.



