Due diligence is not a formality: what it finds can change the price, the terms or whether the deal happens. The definition of due diligence is the reasonable care a buyer or investor takes to check your claims against evidence before signing. For a small SaaS the checks come in 4 kinds: financial, legal, commercial and technical.

What is due diligence? The definition of due diligence, in plain words

Due diligence is the level of reasonable care or attention expected to avoid liability, especially in legal and financial matters. In a deal, it means the buyer or investor reviewing a company’s records and documents before signing, in proportion to what is at stake, so the price and terms rest on checked facts.

That first sentence is Cornell’s Wex definition word for word, and Wex adds that due diligence “commonly involves reviewing financial records and other relevant documentation” before a securities offering or a business acquisition. The Cambridge Dictionary entry gives an everyday sense, action “considered reasonable for people to take in order to keep themselves or others and their property safe”, and a business one: the detailed examination of a company and its financial records before becoming involved in a business arrangement with it.

The meaning of due diligence in simple words is checking before you sign, with the depth of the checking set by what is at stake. The purpose of due diligence, as I read it, is threefold: find what was not disclosed, confirm what was claimed, and set the price and terms on facts rather than on the pitch. What due diligence means in a founder’s week is a request list, a shared folder and a run of follow-up questions, and much of that evidence is the same set of documents that make up what a developer handoff looks like after a sprint.

The concept of due diligence has no single checklist, so there is no such thing as standard due diligence in the sense of one fixed list. The standard is what a reasonable party in that position would check, which is why two deals of the same size can ask for very different things. For the company being examined, the importance of due diligence is plain: every claim in the pitch becomes a request for evidence. That is why due diligence is important to a founder well before any term sheet: the evidence either exists on the day it is asked for, or its absence becomes a finding.

Doing our due diligence: the everyday phrase, and do versus due

Due diligence is spelled with “due”, never “do”: due means necessary or owed, and diligence means careful effort. The everyday meaning of “do your due diligence” is to check before you commit. The phrase is correct in everyday use, and in a deal it names the checking phase before final terms.

Cambridge’s entry for “diligence” gives “the quality of working carefully and with a lot of effort”, and its entry for “due” includes “owed as a debt or as a right” and, in the phrase “due care and attention”, glosses due as “the necessary”. So “do my due diligence” is correct English; only the spelling “do diligence” is wrong.

A deal that is “in due diligence” is in its checking phase. The meaning of “after due diligence” is that the checks are done and the parties move to final terms or walk away.

A buyer who says “I want to do my due diligence” is asking for time to check before committing. At work, where people practice due diligence on a vendor, a hire or a contract, the meaning is taking reasonable steps before the decision and keeping a note of what was checked. When a team agrees “we need to do our due diligence”, the note is the part worth insisting on.

Due diligence is a skill in the way any habit with a method is: a list of what to check, a source for each answer, and a record of what came back, all of which can be learned. Diligence alone is effort; due diligence is effort measured against what the situation calls for.

Due diligence in business, law, finance and audit

Due diligence means something slightly different in 4 fields. In business it is a buyer’s examination of a company. Law uses it for a standard of care and, in US securities law, part of a defense. In finance it is an investor’s or lender’s checks. Auditors use it for a one-off review, not an audit.

FieldWhat the phrase means thereWho does itWhat they read
Business and corporateA buyer or investor examines a company before a dealThe buyer or investor, often with lawyers and accountantsThe books, contracts, people and product
LawA standard of care; in US federal securities law, part of a defense under section 11(b)(3) of the Securities Act of 1933A person other than the issuer, who must prove a reasonable investigation for the parts not taken from an expert or an official sourceThe registration statement and what stands behind it
FinanceAn investor’s or lender’s checks before committing moneyThe investor or lenderFinancial records and the documents behind them
AuditA one-off review for a transaction, as auditors use the phraseAccountants hired for the dealThe records the deal depends on

Most people who define due diligence in business terms mean the first row. Corporate due diligence has the same meaning as the business sense; the word only signals that a company, not a person or a property, is being examined. Cambridge’s business dictionary gives the definition of due diligence in business with an example of the arrangement: “such as buying it or selling its shares to investors”.

Due diligence in law has a narrower meaning. Under section 11 of the Securities Act of 1933, subsection (b)(3) (United States federal law), a person other than the issuer is not liable for a part of a registration statement that does not rest on an expert’s authority or on a public official document if they prove that, “after reasonable investigation”, they had “reasonable ground to believe and did believe”, at the time that part became effective, that the statements were true and that no material fact required to be stated was omitted. Subsection (c) sets the yardstick: the standard of reasonableness is that “required of a prudent man in the management of his own property”. That is what the statute provides, not how any court applies it to a given case, and this page is general information, not legal advice.

The meaning of due diligence in finance is the investor’s or lender’s own checking before money moves. Customer due diligence in anti-money-laundering rules is a separate term for checking who a customer is, and it is not what an investor means.

In auditing, due diligence names a one-off review for a transaction, while an audit is a recurring opinion under auditing standards; the next section sets the two side by side. Three nouns ride along with the phrase, and their meaning is plain: a due diligence review is the work, due diligence documents are what the company hands over (usually in a data room), and the due diligence report is what the reviewer writes.

What it means in practice for a small SaaS

Take one case through the next three parts: a small SaaS raising a seed round from one lead investor who has sent a term sheet and a list of questions. The founder needs three answers: which checks are coming, in what order, and what sets the length of the wait.

Types of due diligence a small SaaS actually meets

Types of due diligence for a small SaaS come down to 4: financial, legal, commercial and technical. Each is a list of requests with evidence behind every answer. Larger deals split these into more streams, such as tax, people and intellectual property, but the four cover a seed round.

TypeWhat the reviewer asksWhat you hand overWho on your side answers
FinancialIs revenue what the deck says, and who owns what?Revenue records, bank statements, the cap table, tax filingsThe founder who runs finance, with the accountant
LegalDoes the company own what it sells, and are its contracts sound?Incorporation papers, IP assignments from every contributor and contractor, customer contracts, privacy termsThe founder, with the company’s lawyer
CommercialWill customers keep paying, and is the market real?The customer list, churn, the pipeline, the market caseThe CEO
TechnicalDoes the product work, and can someone other than its builder run it?Code access, security and data-handling notes, uptime history, dependency licensesWhoever built the product

The table is my framing of the types a small company meets. Bigger deals add tax, people, environmental and intellectual property as streams of their own, and those are sub-streams of the same four rather than new kinds of checking. Asking how many types of due diligence there are, or which three make up “the three types”, has no fixed answer: the count depends on the deal, and I know of no primary source that sets one.

For a seed round the four shrink to a few requests each. For an acquisition they grow into a full data room with a reviewer for every row. The technical row is the one founders of AI-built apps are least ready for, in my reading, and it has its own section further down.

Due diligence process steps, from term sheet to close

Due diligence process steps run in 6 stages: terms agreed in principle, a request list, a data room the company fills, reading and follow-up questions, written findings, and a decision. The decision can change the price, add conditions to fix before close, or end the deal.

  1. 01 Terms are agreed in principle, in a term sheet or letter of intent, usually with a confidentiality agreement. The founder and the lead investor act.
  2. 02 The request list arrives. The investor or its advisers send it.
  3. 03 The company fills a data room with documents and written answers. The founder acts, with whoever holds each record.
  4. 04 The reviewers read, send follow-up questions and hold calls with the people who know the answers. Both sides act.
  5. 05 The findings are written up. The reviewers act, for the investor.
  6. 06 The findings change something or nothing: the price, the terms, conditions to fix before close, or the deal itself. The investor decides.

The order is not fixed everywhere. The SBA’s outline of venture capital funding lists “Go through due diligence review” before the parties agree on a term sheet, and says the investors “will look at your company’s management team, market, products and services, corporate governance documents, and financial statements.” For someone buying a small business, the SBA’s guide to buying a business puts it as “do your due diligence” and lists the documents an attorney and an accountant can help evaluate, from the letter of intent and confidentiality agreement to financial statements and tax returns.

The software version of these steps, seen from the side being read, is in startup technical due diligence.

How long does due diligence take

Due diligence length, by my working rule, is decided by 3 things: the size of the deal, how ready the documents are when the request list arrives, and how many rounds of follow-up the answers cause. A founder controls the second, which is why a data room built before the term sheet saves time.

I give no number here on purpose, because those three drivers decide it. Y Combinator’s seed fundraising guide gives none either. It says “A seed investment can usually be closed rapidly” and advises “Do not spend too much time developing diligence documents for a seed round.”

The second driver is the one to work on. A small folder with the cap table, the signed contracts, the IP assignments and a short technical write-up, put together before anyone asks, removes the first wait. In residential real estate the phrase names a period written into a purchase contract, which is a different use of the words from the one here.

Selling the whole company is a bigger review with its own questions: due diligence of code when selling a business.

What due diligence is not: an audit, a certificate or a formality

Due diligence is not an audit. An audit follows published auditing standards and ends in an auditor’s opinion on whether the financial statements are presented fairly. Due diligence happens once per deal, follows the buyer’s own questions and ends in a private report. Nobody passes it: the buyer reads the findings and decides.

QuestionAuditDue diligence
Who it covers, and who does itIn the United States, the audits of public companies and SEC-registered brokers and dealers, which the PCAOB oversees; the auditor must be independent of the company under auditThe party about to commit money, or the advisers it hires
How oftenRecurring, usually each yearOnce per deal
Against what standardPublished auditing standards, such as PCAOB AS 1000The buyer’s or investor’s own questions
What comes outAn auditor’s report with an opinion on whether the financial statements are presented fairly, in all material respectsA private report, then the buyer’s decision

The audit column comes from PCAOB AS 1000, which governs audits run under PCAOB standards in the United States. There the auditor’s objectives are to “obtain reasonable assurance about whether the financial statements are free of material misstatement, whether due to error or fraud” and to issue a report with an opinion on whether they are “presented fairly, in all material respects”. The PCAOB oversees the audits of public companies and of brokers and dealers registered with the SEC. The due diligence column is my reading.

So the difference between due diligence and audit work is who asks, how often, against which standard and what comes out. “Due diligence audit” is loose usage; its meaning is the second column, a deal review, not an audit under auditing standards.

It is not a certificate either: the reviewer reports what they found, and the buyer decides what it is worth.

Nor is it a formality. Findings move price and terms, and sometimes they end the deal.

Lack of due diligence: what it means when nobody checked

Lack of due diligence means committing without the care the situation called for. For a buyer, it can mean a problem bought at full price. For a founder, it means the reviewer finds the problems first: my audits produced 958 confirmed findings across the 21 third-party apps, about 46 per app.

Those 21 are the third-party apps I audited in June and July 2026, a selected set of audited apps, not a random sample or a rate for AI-built apps in general. The number says how much there was to find in those apps; it says nothing about any one reader’s app.

In US securities law the point is sharper: for any part that does not rely on an expert or an official record, the section 11(b)(3) defense depends on a reasonable investigation having actually happened. The meaning of “no due diligence” in a deal is the extreme case, where whatever the price assumed is taken on trust.

For a founder the phrase cuts the other way too. Not doing due diligence on your own product before someone else does means the reviewer’s list becomes your first look at it.

What is IT due diligence? Due diligence in IT, and what technical due diligence adds

In a deal review, IT due diligence, also called technical due diligence, is the part that reads the product itself. A reviewer looks at 6 areas: the code and architecture, security, data handling, uptime and recovery, open-source licenses, and whether anyone other than the original builder can run the system.

The IT due diligence meaning is the same whether the reviewer calls it IT, technical or technology due diligence. What it covers in depth, and who does the reading, belongs to startup technical due diligence, the process from the side being read. Anyone looking for a technical due diligence wiki entry will not find one on Wikipedia, which has no article under technical, technology or IT due diligence, so this section defines it from the work.

What the reviewer readsThe question behind itEvidence that answers itPage that goes deeper
Code and architectureCan someone new understand and change it?An architecture diagramtechnical documentation for investors
SecurityCan a stranger reach data or money they should not?A security checklist with evidencewhat investors look for in code
Data handlingWhere does customer data live, and who can read it?The data modelthe software due diligence checklist
Uptime and recoveryWhat happens under load, or after a bad deploy?A written capacity statement and a restore recordThe same checklist
Open-source licensesDoes any dependency’s license restrict the business?A license reportThe same checklist, its licenses section
Who can run itCan anyone besides the original builder operate it?A readiness report and runbooksis an MVP production ready

A sports-analytics app I audited kept every table, constraint and row-level security policy only in the hosted dashboard, and its whole authorization posture could not be reviewed, diffed or rebuilt. The full story is in the two-minute Supabase data exposure test. The lesson I take from it is that a reviewer can only credit what is written down where they can read it, and a rule that lives only in a dashboard reads as a rule nobody can check.

Due diligence in engineering can also mean something unrelated to deals: the reasonable care a professional engineer owes in design and safety work, which is a different field.

How it shows up in a hardening sprint

In the Production Hardening Sprint, deliverable 13.6, the technical due diligence pack, bundles the readiness report, architecture diagram, data model, security checklist, and capacity statement into one PDF, and it is verified this way: “Check the pack for completeness, consistent version references, and readable linked evidence.” Deliverable 10.11, the Open-source licence audit, inventories the licenses of every dependency, flags copyleft or unlicensed packages, and replaces or approves each one. Formal third-party certifications and independent audit opinions are separate from these engineering deliverables, and legal advice and certification are separate services. Both deliverables are listed in the published scope.

Common questions about due diligence in a deal

Can you give me an example of due diligence?

An investor asking for bank statements and signed IP assignments before wiring money is doing due diligence. So is a founder who reads a vendor’s security page and data terms before sending it customer data. One is the deal sense, the other the everyday sense; both check claims against evidence before committing.

Who typically performs due diligence?

The party about to commit money performs it, usually with advisers it hires: lawyers, accountants and, for the product, a technical reviewer. The SBA’s guidance for buyers of a small business says to “Consider hiring an attorney and an accountant.” The company being examined does not perform the review; it answers the questions and supplies the documents.

What is another word for due diligence?

There is no exact synonym, so the right word depends on the sense. In the legal sense, “reasonable care” is the closest, and it is the phrase Wex’s definition is built on. In everyday speech, “vetting” or “checking” does the job, and in a deal people often just say “the review”.

Why do people say due diligence?

People say it because the two words together describe care measured against the situation: “due” in the sense of necessary or owed, and “diligence” as careful effort. In the United States, section 11 of the Securities Act of 1933 also made a “reasonable investigation” part of a legal defense.

How do I use due diligence in a sentence?

Use it as a noun for the checking itself, usually with “do” or “did”. An everyday example: “We did our due diligence on the vendor before signing.” A deal example: “The investor’s due diligence covered the code as well as the accounts.”