SaaS Due Diligence Checklist: What Buyers Actually Verify

Most SaaS due diligence checklists tell you which documents to collect. Very few tell you how to confirm those documents are true.
That gap is where deals go wrong. A seller can hand over clean financials, a tidy data room, and a confident growth chart — and the revenue underneath can still be staged, inflated, or about to churn. The buyers who get burned aren't the ones who forgot to ask for a contract. They're the ones who took the numbers at face value.
This checklist covers both halves: what to gather across every diligence category, and — for the financial and revenue sections — how to verify the numbers actually hold. Whether you're a founder getting exit-ready or a buyer sizing up a target, work through it before anyone signs.
When SaaS due diligence happens
Formal due diligence usually begins after a Letter of Intent (LOI) is signed and runs until close — commonly four to six weeks. By then, price is roughly set, so diligence is less about discovery and more about confirmation: the buyer is verifying that what got them to the LOI is real.
For founders, that means the work starts long before the LOI. The time to clean up your data and reconcile your own numbers is months ahead, not the week a buyer asks.
- Financial and revenue due diligence
This is the core of any SaaS deal, because SaaS is valued on the quality of its recurring revenue, not just the size of it.
Committed vs. implied ARR — Is it contracted recurring revenue, or an annualized run-rate that quietly includes one-time fees, services, and usage spikes? Strip those out. MRR composition and movement — New, expansion, contraction, and churned MRR month over month. A healthy top line can hide ugly churn underneath. Revenue recognition — Is revenue recognised as earned, or booked on cash received? Annual prepayments recognised upfront overstate the current period. Churn and net revenue retention (NRR) — Gross churn, logo churn, and NRR by cohort. NRR above 100% is the signal buyers pay premiums for. CAC, LTV, and payback period — What it costs to acquire revenue and how long it takes to earn it back. Refunds and chargebacks — These post weeks after the sale, so a strong month can settle materially lower. Check the trailing reversal rate. Gross margin — Hosting, support, and third-party costs against revenue.
Red flag: revenue that only accelerated in the last 30–60 days before the process began, with nothing in the prior history that resembles it.
- The step most checklists skip: verify the revenue is real
Every item above can be documented and still be fake. A spreadsheet of MRR is a claim, not proof. This is where diligence separates careful buyers from optimistic ones.
Real revenue leaves a trail beyond the billing system. If a business has paying customers, those customers generated behaviour — sessions, signups, logins, engagement. The verification step is checking whether the money and the behaviour agree:
Reconcile revenue against traffic. Does the claimed customer base square with the actual web and product activity? Revenue implying thousands of accounts on top of a few hundred monthly sessions doesn't close. (This is one of the four signatures of fabricated revenue.) Check engagement, not just volume. Bought or bot traffic inflates session counts but behaves inhumanly — near-zero engaged time, single-pageview visits, uniform patterns around the clock. Trace traffic to a believable source. A credible audience has an origin — search, referrals, a paid footprint. Traffic that arrives mostly as unexplained "direct" deserves questions. Confirm the data's provenance. A dashboard screenshot can be edited and can't be re-queried. Insist on source-connected data you can verify live, not static proof that decays the moment it's captured.
We saw exactly this on a recent audit. The billing checked out on its own — a live Stripe connection showed $4,923 in real charges over 90 days. But the same 90 days of analytics told a different story: just 754 sessions, fewer than nine visitors a day, and 91% of them arriving as unattributed "direct" traffic that bounced at 68% and lasted about 34 seconds each. That implies earning roughly $6,500 per thousand visitors — more than 160 times the top of the SaaS benchmark. The money was real; the audience that could explain it wasn't. The plausibility score came back 8 out of 100. Nothing in the billing was forged, and it still didn't survive the cross-check.
Red flag: the billing story and the analytics story don't line up — and no one can explain the gap.
- Customer and retention due diligence Customer concentration — What share of revenue sits with the top 1, 5, and 10 accounts? High concentration is single-point-of-failure risk. Cohort retention curves — Do older cohorts hold, or does every cohort leak? Cohorts reveal what blended churn hides. Contract terms — Length, auto-renewal, cancellation rights, and whether contracts are assignable to a new owner. Pipeline and bookings — For the growth story: is new business real and repeatable, or a one-time push timed to the sale?
- Legal due diligence IP ownership — Confirm the company (not a contractor or ex-founder) owns the code and IP. Get signed assignment agreements. Contract assignability — Whether customer and vendor contracts survive a change of control. Compliance and data privacy — GDPR, SOC 2, and any industry-specific obligations. Where is customer data stored and processed? Outstanding liabilities — Litigation, disputes, unpaid obligations, and open regulatory issues. Corporate structure and cap table — Clean ownership, no surprise equity or option overhangs.
- Technical due diligence Architecture and stack — Is it maintainable and reasonably modern, or a fragile monolith one key person understands? Technical debt — Known issues, deferred maintenance, and what they'll cost the acquirer. Security — Encryption, access controls, vulnerability history, and incident record. Infrastructure and scalability — Whether the system holds up as usage grows. Dependencies — Third-party services and single points of failure the business relies on.
- Operational and team due diligence Founder dependency — Can the business run without the founder? Deep dependency lowers value and complicates transition. Key-person risk — Who else is critical, and are they staying? Documented processes — Onboarding, support, and operational playbooks that let a new owner take over. Org and roles — Team structure, contractor relationships, and cost.
- Deal terms and structure
Diligence findings feed straight into terms — and unverifiable revenue quietly makes every term worse:
Valuation and multiple — Buyers apply a lower multiple to revenue they can't independently confirm. (See the diligence tax.) Escrow and holdback — How much of the price is parked, and for how long. Earnout — How much of the payout is deferred and tied to future performance. Reps and warranties — What the seller is contractually promising, and the indemnification caps. For buyers running a pipeline
A single audit is a snapshot, and you close weeks after you take it — sometimes on numbers that have already moved. Across a pipeline, one-time checks don't scale and can't catch a target that reverts between LOI and close. Continuous verification closes that gap by treating revenue as a stream, not a photograph. (More on why point-in-time diligence misses the risk that matters.)
Put the checklist to work
The categories above are what every serious buyer walks through. The difference between a smooth close and a collapsed one is usually section 2 — whether the revenue can be verified, not just described.
ProofCap does that verification directly: it cross-references live billing data against real traffic and engagement and returns a timestamped, shareable report showing whether the signals agree. Founders can run it before contacting buyers; buyers can run it before signing an NDA. Start with a free footprint scan, or work through the full SaaS due diligence checklist.
FAQs
How long does SaaS due diligence take? Typically four to six weeks from signed LOI to close, though it varies with deal size and complexity. Clean, pre-reconciled data is the biggest lever for keeping it short.
When should a founder start preparing for due diligence? Six to twelve months before going to market. Reconciling financials, cleaning contracts, and documenting processes takes time, and rushing it surfaces the red flags you were trying to avoid.
Can revenue be verified before signing an LOI? Yes. Source-connected verification tools let a buyer confirm that revenue reconciles with real traffic and engagement before committing — which is exactly when you want to catch a problem.
What's the most common SaaS due diligence red flag? Revenue that doesn't match the behaviour around it: strong MRR with little corresponding traffic, engagement, or a believable acquisition source. It's the pattern most staged or inflated numbers share.